Malicious program identification method and device, equipment, storage medium and program product
By monitoring the network connection functions of sample programs in computer devices and obtaining plaintext network communication data, and using hook functions to identify malicious programs, the problem of difficulty in identifying encrypted communication malicious programs in existing technologies is solved, and accurate identification and reduction of security risks are achieved.
Patent Information
- Application Number
- CN202410305999.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-15
- Publication Date
- 2025-09-16
AI Technical Summary
Existing technologies make it difficult to effectively identify malicious programs, especially those that use encrypted communication methods, resulting in increased network security risks.
By monitoring whether the sample programs in the computer device call the network connection function and obtaining the plaintext network communication data, analyzing whether there are malicious instructions, and using user-mode and kernel-mode hook functions to monitor and match data, malicious programs can be identified.
It achieves accurate identification of malicious programs, provides substantial evidence, reduces security risks, and improves identification accuracy and explainability.
Smart Images

Figure CN120654235A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a method, apparatus, device, storage medium, and program product for identifying malicious programs. Background Art
[0002] Malicious programs are computer code or software that installs and runs on a user's computer or other terminal without explicit user notification or permission, and engages in activities that infringe upon the user's legitimate rights and interests, such as stealing, encrypting, altering, and deleting data, and monitoring users. Examples include computer viruses, ransomware, backdoor programs, keyloggers, password stealers, Word and Excel macro viruses, boot sector viruses, script viruses, Trojans, crimeware, spyware, and adware. With the continuous advancement of malicious program technology, approximately 80% of malicious programs now use encrypted communication, making their identification more difficult and posing a significant challenge to enterprise network security. Therefore, a malicious program identification method is urgently needed to promptly detect security risks and mitigate the damage caused by malicious programs. Summary of the Invention
[0003] This application provides a method, apparatus, device, storage medium, and computer program for identifying malware, which can solve the problem of difficulty in identifying malicious programs in related technologies. The technical solution is as follows:
[0004] In a first aspect, a method for identifying malware is provided, the method comprising: monitoring whether a sample program running in a computer device calls a network connection function, the network connection function being a function used to support network communication of an application; if the sample program calls the network connection function, obtaining network communication data, the network communication data being network connection parameters provided when the sample program calls the network connection function, or data received when the sample program calls the network connection function; if there is at least one malicious instruction in the network communication data, determining that the sample program is a malicious program, the malicious instruction being used by a malicious server to instruct a malicious program to perform malicious operations on a computer device on which the malicious program is installed.
[0005] The present application can obtain network communication data when a sample program calls a network connection function. Since the network communication data is the network connection parameters provided by the sample program when calling the network connection function, or the data received by the sample program when calling the network connection function, and the network communication data is plain text data, by analyzing the network communication data, it is possible to directly determine whether malicious instructions are contained in the network communication data. If malicious instructions are contained in the network communication data, it is possible to determine that the sample program is a malicious program and obtain substantial evidence that the malicious program performs malicious operations on the computer device, thereby achieving accurate identification of the malicious program.
[0006] There are multiple implementation methods for monitoring whether a sample program running on a computer device calls a network connection function. Two of these implementation methods are described below.
[0007] The first implementation method is to inject a user-state hook function into the sample program when it is detected that the sample program is started, and monitor the sample program through the user-state hook function to determine whether the sample program calls the network connection function; or inject a kernel-state hook function into the kernel of the computer device, and monitor the computer device through the kernel-state hook function to determine whether the sample program calls the network connection function.
[0008] The second implementation method is to monitor whether the sample program loads the network dynamic link library DLL. The network DLL is used to implement data interaction between the application and the peer device in accordance with the standard definition. The network DLL includes at least one network connection function. If the sample program loads the network DLL, it is monitored whether the sample program calls any one of the at least one network connection function.
[0009] The implementation process of monitoring whether a sample program calls any one of at least one network connection function includes: injecting a third user-state hook function into the sample program, and monitoring the sample program through the third user-state hook function to determine whether the sample program calls any one of the at least one network connection function; or, injecting a third kernel-state hook function into the kernel of a computer device, and monitoring the computer device through the third kernel-state hook function to determine whether the sample program calls any one of the at least one network connection function.
[0010] Optionally, the network DLL includes a WinINet DLL. In this case, the at least one network connection function includes at least one of the following: an initialization function, a first connection function, a request creation function, a request sending function, and a first data reading function; wherein the initialization function is used to initialize the sample program so that the sample program uses the WinINet DLL, the first connection function is used to establish a connection between the sample program and the network, the request creation function is used to create a network request, the request sending function is used to send the network request to a specified server, and the first data reading function is used to read received data.
[0011] Optionally, when processing an HTTPS request, the at least one network connection function further includes an SSL setting function, which is used to set SSL options, including at least one of the SSL protocol version, encryption strength, and whether to provide a client certificate.
[0012] Optionally, the network DLL includes OpenSSL DLL, and the at least one network connection function includes at least one of the following: a structure creation function, a second connection function, a client handshake function, a server handshake function, a second data reading function, and a data writing function; wherein the structure creation function is used to create an SSL structure, the second connection function is used to connect the SSL structure to the socket, the client handshake function is used to start an SSL handshake or a TLS handshake when the computer device acts as a client, the server handshake function is used to start an SSL handshake or a TLS handshake when the computer device acts as a server, the second data reading function is used to read data from an SSL or TLS connection, and the data writing function is used to write data to an SSL or TLS connection.
[0013] Optionally, before monitoring whether the sample program calls the network connection function, the security software can also monitor the startup operation of the program in the computer device. That is, the security software can also monitor whether a new program is started in the computer device. If the security software determines that a new program has been started in the computer device, the newly started program is used as a sample program and the step of monitoring whether the sample program calls the network connection function is executed, or the step of monitoring whether the sample program loads the network dynamic link library (DLL) is executed.
[0014] Since the present application starts monitoring the network communication behavior of the sample program at the beginning of the sample program startup, malicious operations of the sample program can be discovered in a timely manner, thereby reducing the security risks of computer equipment.
[0015] In actual applications, if the sample program sends data to the network side, it is necessary to use the data to be sent as part or all of the network connection parameters corresponding to the network connection function to realize network communication. If the sample program receives data from the network side, it is necessary to receive data from the network side by calling the network connection function, so as to obtain the data sent to the sample program by the network side. Therefore, by obtaining the network communication data, the data to be sent or received by the sample program can be accurately obtained.
[0016] Optionally, after acquiring the network communication data, the security software can also match the network communication data with malicious instructions in a malicious instruction set to determine whether there is at least one malicious instruction in the network communication data, and the malicious instruction set includes multiple malicious instructions.
[0017] Since malware and malicious servers usually encrypt network communication data at the transport layer, for the data sent by the sample program to the network side, the data to be sent in the embodiment of the present application is obtained on the end side. At this time, the data to be sent has not been encrypted. Therefore, the data to be sent is a plaintext message. For the data sent by the network side to the sample program, the sample program in the embodiment of the present application receives data from the network side by calling the network connection function. At this time, the data sent by the network side has reached the application layer. In this case, the data received by the sample program has been decrypted. Therefore, the received data is also a plaintext message. In other words, the network communication data are all plaintext messages. This helps to match the network communication data with the malicious instructions in the malicious instruction set, achieve in-depth analysis of the network communication behavior of the sample program, and effectively improve the accuracy of malicious program identification. In addition, the method of analyzing plaintext messages in the present application has strong interpretability, so that technical personnel can better analyze the behavior patterns of malicious programs.
[0018] Optionally, the malicious instruction set includes at least one of the following types of instructions: information stealing instructions, remote control instructions, denial of service attack instructions, and secret traffic brushing instructions; wherein, the information stealing instructions indicate that the malicious server interacts with a malicious program to steal information from a computer device, the remote control instructions indicate that the malicious server interacts with a malicious program to remotely control a computer device, the denial of service attack instructions indicate that the malicious server interacts with a malicious program to conduct a denial of service attack on a computer device, and the secret traffic brushing instructions indicate that the malicious server interacts with a malicious program to enable a computer device to access the network or click without the user's authorization, so as to increase the number of visits or clicks.
[0019] Optionally, the information stealing instructions include but are not limited to at least one of the following instructions: a system username and password sending instruction, a browser cookie sending instruction, a digital wallet sending instruction, a system information sending instruction, a keyboard record sending instruction, and a screenshot instruction; wherein the system username and password sending instruction instructs to send the system username and password in the computer device to the malicious server, the browser cookie sending instruction instructs to send the browser cookie in the computer device to the malicious server, the digital wallet sending instruction instructs to send relevant information of the digital wallet in the computer device to the malicious server, the system information sending instruction instructs to send the system information in the computer device to the malicious server, the keyboard record instruction instructs to send the keyboard record in the computer device to the malicious server, the keyboard record is used to record the content entered by the user on the keyboard of the computer device, and the screenshot instruction instructs to take a screenshot of the screen in the computer device or capture the window content; the remote control instructions include but are not limited to Limited to at least one of the following instructions: an online host information acquisition instruction, a process termination instruction, and a network connection information acquisition instruction; wherein, the online host information acquisition instruction instructs the computer device to obtain the online host information, the process termination instruction instructs to terminate the process running on the computer device, and the network connection information acquisition instruction instructs the computer device to obtain network connection information; the denial of service attack type instructions include but are not limited to at least one of the following instructions: a waiting instruction, a flood attack instruction; wherein, the waiting instruction indicates that the computer device is in a waiting state, and the flood attack instruction instructs to send excessive data to the computer device; the dark traffic type instructions include but are not limited to at least one of the following instructions: a fraud instruction, a promotion information pop-up instruction, and a network traffic attraction instruction; wherein, the fraud instruction instructs to defraud users through online paid promotion information, the promotion information pop-up instruction instructs to consume the system resources of the computer device by popping up promotion information multiple times, and the network traffic attraction instruction instructs to attract website visits or user traffic through various strategies and technical means.
[0020] Optionally, when the sample program calls a network connection function, the security software can also suspend the running of the sample program.
[0021] Since malicious programs usually interact with malicious servers through the network, if a sample program calls a network connection function, it means that the sample program is about to send data through the network or parse and execute the received data. If the sample program is a malicious program, it poses a security risk. Therefore, when it is determined that the sample program calls a network connection function, the security software can avoid security risks by pausing the running of the sample program.
[0022] Optionally, in the case where the sample program is determined to be a malicious program, the security software can also release memory resources allocated for the sample program to terminate the execution of the sample program.
[0023] Since malicious programs can pose a security threat to computer devices, if the sample program is determined to be a malicious program, the security software can terminate the running of the sample program to further reduce information leakage of the computer device and ensure the security of the computer device.
[0024] In a second aspect, a malware identification device is provided, wherein the malware identification device has the function of implementing the malware identification method described in the first aspect. The malware identification device includes at least one module configured to implement the malware identification method described in the first aspect.
[0025] In a third aspect, a computer device is provided, comprising a processor and a memory, wherein the memory is configured to store a computer program for executing the malware identification method provided in the first aspect. The processor is configured to execute the computer program stored in the memory to implement the malware identification method provided in the first aspect.
[0026] Optionally, the computer device may further include a communication bus, which is used to establish a connection between the processor and the memory.
[0027] In a fourth aspect, a computer-readable storage medium is provided, wherein the storage medium stores a computer program. When the computer program runs on a computer or a processor, the computer or the processor executes the steps of the malware identification method described in the first aspect.
[0028] In a fifth aspect, a computer program product is provided. The computer program product includes computer instructions that, when executed on a computer or processor, cause the computer to perform the steps of the malware identification method described in the first aspect. Alternatively, a computer program is provided that, when executed on a computer or processor, causes the computer or processor to perform the steps of the malware identification method described in the first aspect.
[0029] The technical effects obtained in the above-mentioned second, third, fourth and fifth aspects are similar to those obtained by the corresponding technical means in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application;
[0031] Figure 2 This is a flowchart of a method for identifying malware provided by an embodiment of the present application;
[0032] Figure 3 This is a flowchart of another malware identification method provided by an embodiment of the present application;
[0033] Figure 4 This is a schematic diagram of the structure of a malware identification device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0034] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.
[0035] For ease of understanding, before explaining in detail the malicious program identification method provided in the embodiment of the present application, the nouns, application scenarios and implementation environment involved in the embodiment of the present application are first introduced.
[0036] First, the nouns involved in the embodiments of the present application are introduced.
[0037] Endpoint Detection and Response (EDR): EDR is a security solution used to protect computer devices. By deploying a specific software agent on a computer, it monitors and records various activities on the device in real time, including file operations, network communications, and process startups and shutdowns, enabling timely detection and response to potential security threats. EDR technology can quickly detect and respond to malicious code, network attacks, and other security incidents, improving network security.
[0038] Command and control (C2) system: The C2 system is used to remotely control infected computer devices or network devices. The attacker sends instructions to the infected device through the C2 system to control it to perform specific operations, such as transmitting data, executing malicious code, launching attacks, etc. The C2 system is usually implemented by the attacker implanting malicious programs or backdoor programs on the infected device, and communicating and controlling through the network connection established with the infected device. The C2 system can be used for various malicious activities, such as stealing sensitive information, launching distributed denial of service attacks, and spreading malicious programs. In the embodiments of the present application, the malicious program and the malicious server can be regarded as a C2 system. In some scenarios, the malicious server is also called a C2 server or CC server.
[0039] User-mode hooks: User-mode hooks run in user space and are used to monitor and modify the behavior of user-level applications, thereby changing program behavior and expanding functionality.
[0040] Inline hook: The normal application programming interface (API) function call process is for the caller (i.e., the process) to call the function in the loaded dynamic link library through the function name. The inline hook hijacks the function execution process by inserting a jump instruction in the header of the called function.
[0041] Import Address Table (IAT) hook: The IAT is a data structure that contains the addresses of imported functions used by applications at runtime. IAT hooking works by modifying function pointers in the IAT, redirecting the originally intended function to a custom function. This way, when the application executes, calling the hooked function actually executes the custom function. Using IAT hooking, you can intercept and modify application function calls to implement custom behaviors, such as logging, modifying function parameters, or return values.
[0042] Kernel-state hooking is a method for modifying and intercepting kernel events such as system calls, interrupts, and exceptions within the operating system kernel. By inserting a hook function into the kernel, kernel behavior can be modified or kernel events can be intercepted, thereby expanding or restricting certain operating system features. Kernel-state hooking operates at the lower-level hypervisor (Hypervisor) level. The Hypervisor is the infrastructure for virtual machine management, responsible for managing and coordinating the operation of virtual machines (VMs).
[0043] Cookies are data (usually encrypted) stored on a user's local device to identify the user. These data are either temporarily or permanently stored on the user's client computer. In layman's terms, they refer to cached data, which can include personal information such as usernames, passwords, registered accounts, and mobile phone numbers.
[0044] Dynamic link library (DLL): a function library that can be dynamically called by a program.
[0045] Secure Sockets Layer (SSL): A security protocol implemented on a transport communication protocol that uses public key technology.
[0046] Transport layer security (TLS): is a protocol used to provide confidentiality and data integrity between two communicating applications. The protocol consists of two parts: the TLS Record Protocol (TLSRecord) and the TLS Handshake Protocol (TLS Handshake).
[0047] Processes and programs: Programs are static, while processes are dynamic. A program is binary code stored on some medium, and a process corresponds to the execution of a program. A process is a single execution of a program, and a process always corresponds to at least one specific program. A program can correspond to multiple processes, and the same program can run on different data sets, thus forming several different processes. Several processes can execute the same program code concurrently, while the same process can execute several programs sequentially.
[0048] Next, the application scenarios involved in the embodiments of this application are introduced.
[0049] Malicious programs are computer code or software that installs and runs on a user's computer or other terminal without explicit user notification or permission, and engages in activities that infringe upon the user's legitimate rights and interests, such as stealing, encrypting, altering, and deleting data, and monitoring users. Examples include computer viruses, ransomware, backdoor programs, keyloggers, password stealers, Word and Excel macro viruses, boot sector viruses, script viruses, Trojans, crimeware, spyware, and adware. With the continuous advancement of malicious program technology, approximately 80% of malicious programs now use encrypted communication, making their identification more difficult and posing a significant challenge to enterprise network security.
[0050] Related technologies primarily use machine learning methods to identify malicious programs on the traffic side. Specifically, by analyzing the contextual traffic corresponding to a large amount of normal network traffic and a large amount of malicious network traffic, contextual traffic corresponding to malicious network traffic with obvious distinction and contextual traffic corresponding to normal network traffic are selected as inputs to a classifier to train a network model and thereby construct a malicious traffic identification model. The contextual traffic includes transport layer security (TLS) flows, domain name system (DNS) flows, and hypertext transfer protocol (HTTP) flows. For any encrypted network traffic to be identified, the encrypted network traffic is used as input to the malicious traffic identification model to obtain an identification result for the encrypted traffic output by the malicious traffic identification model. If the identification result indicates that the encrypted traffic is malicious traffic, the program sending or receiving the malicious traffic is determined to be a malicious program.
[0051] However, in the aforementioned machine learning-based methods, the malware identification model has poor interpretability. Technicians often struggle to understand the features used by the model to determine whether network traffic is malicious. This makes it impossible for them to verify and adjust the identification results, thereby reducing their confidence in the detection results. Furthermore, this method does not directly analyze encrypted traffic, but rather analyzes the contextual traffic corresponding to the encrypted traffic (i.e., the aforementioned TLS, DNS, and HTTP flows). This can only indirectly prove that the encrypted traffic may be malicious, but fails to provide substantive evidence to prove that the encrypted traffic actually performs malicious operations on computer devices.
[0052] Based on this, an embodiment of the present application provides a method for identifying malicious programs. The method can obtain network communication data when a sample program calls a network connection function. Since the network communication data is the network connection parameters provided by the sample program when calling the network connection function, or is the data received by the sample program when calling the network connection function, and the network communication data is plaintext data, by analyzing the network communication data, it is possible to directly determine whether malicious instructions are contained in the network communication data. If malicious instructions are contained in the network communication data, the sample program can be determined to be a malicious program, and substantial evidence can be obtained that the malicious program performs malicious operations on the computer device. In this way, the malicious program can be accurately identified.
[0053] The malware identification method provided in the embodiments of the present application may be executed by a processor in a computer device, or by security software running on the computer device. The computer device includes, but is not limited to, a server, a host, a personal computer, a mobile phone, or a workstation. The security software may be EDR software, etc., which is not limited in the embodiments of the present application.
[0054] It should be noted that the application scenarios and execution entities described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Ordinary technicians in this field can know that with the emergence of new application scenarios and the evolution of equipment, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0055] Please refer to Figure 1 , Figure 1 This is a schematic diagram of a computer device according to an embodiment of the present application. The computer device may be Figure 1 The computer device 101 shown in FIG. The computer device includes at least one processor 101 , a communication bus 102 , a memory 103 and at least one communication interface 104 .
[0056] The processor 101 may be a general-purpose central processing unit (CPU), a network processor (NP), a microprocessor, or one or more integrated circuits for implementing the solution of the present application, such as an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0057] The communication bus 102 is used to transmit information between the above components. The communication bus 102 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.
[0058] The memory 103 may be a read-only memory (ROM), a random access memory (RAM), an electrically erasable programmable read-only memory (EEPROM), an optical disc (including a compact disc read-only memory (CD-ROM), a compact disc, a laser disc, a digital versatile disc, a Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 103 may exist independently and be connected to the processor 101 via the communication bus 102. The memory 103 may also be integrated with the processor 101.
[0059] The communication interface 104 uses any device, such as a transceiver, for communicating with other devices or communication networks. The communication interface 104 includes a wired communication interface and may also include a wireless communication interface. For example, the wired communication interface may be an Ethernet interface. The Ethernet interface may be an optical interface, an electrical interface, or a combination thereof. The wireless communication interface may be a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof.
[0060] In a specific implementation, as an embodiment, the processor 101 may include one or more CPUs, such as Figure 1 CPU0 and CPU1 are shown in the figure.
[0061] In a specific implementation, as an embodiment, a computer device may include multiple processors, such as Figure 1 1 and 105. Each of these processors can be a single-core processor or a multi-core processor. A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0062] In a specific implementation, as an embodiment, the computer device may further include an output device 106 and an input device 107. The output device 106 communicates with the processor 101 and can display information in a variety of ways. For example, the output device 106 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 107 communicates with the processor 101 and can receive user input in a variety of ways. For example, the input device 107 can be a mouse, a keyboard, a touch screen device, or a sensor device.
[0063] In some embodiments, the memory 103 is used to store the program code 110 for executing the solution of the present application, and the processor 101 can execute the program code 110 stored in the memory 103. The program code 110 may include one or more software modules, and the computer device can implement the following by using the processor 101 and the program code 110 in the memory 103. Figure 2 The embodiment provides a method for identifying malicious programs.
[0064] Based on the above description, the execution subject of the embodiment of the present application can be a processor in a computer device or a security software in a computer device. For the sake of convenience of description, the following text uses the execution subject as the security software in a computer device as an example to introduce the method for identifying malicious programs in the embodiment of the present application. Figure 2 This is a flowchart of a method for identifying malicious programs provided by an embodiment of the present application. Figure 2 , the method includes the following steps.
[0065] Step 201: Monitor whether a sample program running in a computer device calls a network connection function, where the network connection function is a function used to support an application program to perform network communication.
[0066] It should be noted that the sample program in the embodiments of the present application refers to any application program running on a computer device.
[0067] There are multiple implementation methods for monitoring whether a sample program running on a computer device calls a network connection function. Two of these implementation methods are described below.
[0068] The first implementation method is to inject a user-state hook function into the sample program when it is detected that the sample program is started, and monitor the sample program through the user-state hook function to determine whether the sample program calls the network connection function; or inject a kernel-state hook function into the kernel of the computer device, and monitor the computer device through the kernel-state hook function to determine whether the sample program calls the network connection function.
[0069] In order to distinguish from the user-state hook function and kernel-state hook function in the following text, the user-state hook function in the first implementation is called the first user-state hook function, and the kernel-state hook function in the first implementation is called the first kernel-state hook function.
[0070] Optionally, the first user-mode hook includes but is not limited to an inline hook or an import address table (IAT) hook.
[0071] Optionally, the first kernel mode hook includes but is not limited to a model specific register (MSR) hook or an extended page table (EPT) hook.
[0072] It should be noted that the detailed implementation of injecting a user-mode hook function into the sample program and a kernel-mode hook function into the computer kernel can be found in related hook technologies and will not be elaborated here. The implementation of detecting whether the sample program has been launched will be described in detail later in this article and will not be discussed in detail here.
[0073] The second implementation method is to monitor whether the sample program loads the network dynamic link library DLL. The network DLL is used to implement data interaction between the application and the peer device in accordance with the standard definition. The network DLL includes at least one network connection function. If the sample program loads the network DLL, it is monitored whether the sample program calls any one of the at least one network connection function.
[0074] The implementation process of monitoring whether the sample program loads the network DLL includes: hooking the dynamic library loading function in the operating system of the computer device through the second hook function to monitor whether the sample program loads the network DLL, and the dynamic library loading function is used to load the network DLL.
[0075] Optionally, the second hook function can be a second user-state hook function. In this case, the security software can inject the second user-state hook function into the sample program and monitor the sample program through the second user-state hook function to determine whether the sample program loads the network dynamic link library DLL.
[0076] As an example, the second user-mode hook includes but is not limited to an inline hook or an IAT hook.
[0077] Optionally, the second hook function can be a second kernel-state hook function. In this case, the security software can inject the second kernel-state hook function into the kernel of the computer device and monitor the computer device through the second kernel-state hook function to determine whether the sample program loads the network DLL.
[0078] As an example, the second kernel state hook includes but is not limited to an MSR hook or an EPT hook.
[0079] Optionally, the dynamic library loading function includes but is not limited to a LoadLibrary function or a LdrLoadDll function.
[0080] Optionally, the implementation process of monitoring whether the sample program calls any one of at least one network connection function includes: injecting a third user-state hook function into the sample program, and monitoring the sample program through the third user-state hook function to determine whether the sample program calls any one of the at least one network connection function; or, injecting a third kernel-state hook function into the kernel of a computer device, and monitoring the computer device through the third kernel-state hook function to determine whether the sample program calls any one of the at least one network connection function.
[0081] Optionally, the third user-mode hook includes but is not limited to an inline hook or an IAT hook. The third kernel-mode hook includes but is not limited to an MSR hook or an EPT hook.
[0082] Optionally, the network DLL includes a WinINet DLL. In this case, the at least one network connection function includes at least one of the following: an initialization function, a first connection function, a request creation function, a request sending function, and a first data reading function.
[0083] Among them, the initialization function is used to initialize the sample program so that the sample program uses WinINet DLL, the first connection function is used to establish a connection between the sample program and the network, the request creation function is used to create a network request, the request sending function is used to send the network request to the specified server, and the first data reading function is used to read the received data.
[0084] Optionally, when processing an HTTPS request, the at least one network connection function further includes an SSL setting function, which is used to set SSL options, including at least one of the SSL protocol version, encryption strength, and whether to provide a client certificate.
[0085] For example, the initialization function may be an InternetOpen function, the first connection function may be an InternetConnect function, which is used to establish a connection with an Internet server in the WinINet library to open a Hypertext Transfer Protocol (HTTP), Hypertext Transfer Protocol Secure (HTTPS), or File Transfer Protocol (FTP) session, the request creation function may be an HttpOpenRequest function, which is used to create an HTTP or HTTPS request handle, and the request sending function may be an HttpSendRequest function, which is used to send an HTTP request to an HTTP server or an HTTPS request to an HTTPS server. The first data reading function may be an InternetReadFile function, which is used to read data received from an HTTP server or an HTTPS server. The SSL setting function can set SSL options for the InternetSetOption function. The option identifiers that can be used by the InternetSetOption function include INTERNET_OPTION_SECURITY_FLAGS and INTERNET_OPTION_SECURITY_CERTIFICATE_STRUCT. By setting the INTERNET_OPTION_SECURITY_FLAGS option, the SSL protocol version and encryption strength can be specified. By setting the INTERNET_OPTION_SECURITY_CERTIFICATE_STRUCT option, the client certificate can be provided.
[0086] Optionally, the network DLL includes OpenSSL DLL, and the at least one network connection function includes at least one of the following: a structure creation function, a second connection function, a client handshake function, a server handshake function, a second data reading function, and a data writing function.
[0087] Among them, the structure creation function is used to create an SSL structure, the second connection function is used to connect the SSL structure to the socket, the client handshake function is used to start the SSL handshake or TLS handshake when the computer device acts as a client, the server handshake function is used to start the SSL handshake or TLS handshake when the computer device acts as a server, the second data read function is used to read data from the SSL or TLS connection, and the data write function is used to write data to the SSL or TLS connection.
[0088] For example, the structure creation function may be the SSL_new function, which is used to create a new SSL structure, which is the basis for SSL / TLS communication. The second connection function may be the SSL_set_fd function, which is used to connect the SSL structure to the socket. The client handshake function may be the SSL_connect function, which is used to initiate an SSL or TLS handshake on the socket when the computer device acts as a client. The server handshake function may be the SSL_accept function, which is used to initiate an SSL or TLS handshake on the socket when the computer device acts as a server. The second data reading function may be the SSL_read function, which is used to read data on the SSL or TLS connection. The data writing function may be the SSL_write function, which is used to write data to the SSL or TLS connection.
[0089] Optionally, when the network DLL includes OpenSSL DLL, the at least one network connection function also includes at least one of the following: OpenSSL library initialization function, create SSL context function, certificate loading function, create SSL connection function, server connection function, set SSL connection function, execute SSL handshake function, certificate verification function, send HTTPS request function, and read HTTPS response function.
[0090] For example, the OpenSSL library initialization function can be the SSL_library_init function and the SSL_load_error_strings function. The SSL context creation function can be the SSL_CTX_new function, which is used to create a new SSL context, which is the basis for the SSL connection. The certificate loading function can be the SSL_CTX_load_verify_locations function, which is used to load the trusted CA certificate (certification authority), which is a necessary step for HTTPS connection. The SSL connection creation function can be the SSL_new function, which is used to create a new SSL connection. The server connection function can be the BIO_new_ssl_connect function, which is used to connect to an HTTPS server. The SSL connection setting function can be the BIO_set_conn_hostname function, which is used to set the server's host name and port. The SSL handshake execution function can be the SSL_do_handshake function, which is used to execute the SSL handshake. The certificate verification function can be the SSL_get_verify_result function, which is used to verify the server's SSL certificate. The HTTPS request sending function can be the BIO_write function, which is used to send an HTTPS request. The HTTPS response reading function can be the BIO_read function, which is used to read an HTTPS response.
[0091] Optionally, before monitoring whether the sample program calls the network connection function, the security software can also monitor the startup operation of the program in the computer device. That is, the security software can also monitor whether a new program is started in the computer device. If the security software determines that a new program has been started in the computer device, the newly started program is used as a sample program and the step of monitoring whether the sample program calls the network connection function is executed, or the step of monitoring whether the sample program loads the network dynamic link library (DLL) is executed.
[0092] For example, there are many ways to monitor program startup operations in a computer device, such as kernel-level (i.e., kernel-mode) monitoring and user-space (user-mode) monitoring. Kernel-level monitoring refers to monitoring system calls, process creation, and other operations at the operating system kernel level through hook technology or driver programs to capture newly started programs on the system and record related information. User-space monitoring refers to obtaining information about new programs in user space by monitoring the operating system's event logs, process tables, API calls, and other methods to monitor newly started programs on the operating system. This is not limited in the embodiments of the present application.
[0093] Since the embodiment of the present application starts monitoring the network communication behavior of the sample program at the beginning of the sample program startup, malicious operations of the sample program can be discovered in a timely manner, reducing the security risks of computer equipment.
[0094] Step 202: If the sample program calls the network connection function, network communication data is obtained. The network communication data is the network connection parameters provided by the sample program when calling the network connection function, or the data received by the sample program when calling the network connection function.
[0095] In actual applications, if the sample program sends data to the network side, it is necessary to use the data to be sent as part or all of the network connection parameters corresponding to the network connection function to realize network communication. If the sample program receives data from the network side, it is necessary to receive data from the network side by calling the network connection function, so as to obtain the data sent to the sample program by the network side. Therefore, by obtaining the network communication data, the data to be sent or received by the sample program can be accurately obtained.
[0096] If the sample program sends data to the network, the security software can directly use the network connection parameters provided by the sample program when calling the network connection function as the network communication data. If the sample program receives data from the network, the security software can obtain the data received by the sample program by calling the network connection function according to relevant technologies, thereby obtaining the network communication data.
[0097] Optionally, after acquiring the network communication data, the security software can also match the network communication data with malicious instructions in a malicious instruction set to determine whether there is at least one malicious instruction in the network communication data, and the malicious instruction set includes multiple malicious instructions.
[0098] Since malicious programs usually encrypt traffic at the transport layer, for the data sent by the sample program to the network side, the data to be sent in the embodiment of the present application is obtained on the end side. At this time, the data to be sent has not been encrypted, so the data to be sent is a plaintext message. For the data sent by the network side to the sample program, the sample program in the embodiment of the present application receives data from the network side by calling the network connection function. At this time, the data sent by the network side has reached the application layer. In this case, the data received by the sample program has been decrypted, so the received data is also a plaintext message. In other words, the network communication data are all plaintext messages, which helps to match the network communication data with the malicious instructions in the malicious instruction set, realize in-depth analysis of the network communication behavior of the sample program, and effectively improve the accuracy of malicious program identification. In addition, the method of analyzing plaintext messages in the embodiment of the present application has strong interpretability, so that technical personnel can better analyze the behavior patterns of malicious programs.
[0099] There are many ways to match the network communication data with the malicious instructions in the malicious instruction set. In practical applications, this can be achieved through matching algorithms such as regular expressions, and the embodiments of the present application do not limit this.
[0100] Optionally, the malicious instruction set includes at least one of the following types of instructions: information stealing instructions, remote control instructions, denial of service attack instructions, and secret traffic brushing instructions; wherein, the information stealing instructions indicate that the malicious server interacts with a malicious program to steal information from a computer device, the remote control instructions indicate that the malicious server interacts with a malicious program to remotely control a computer device, the denial of service attack instructions indicate that the malicious server interacts with a malicious program to conduct a denial of service attack on a computer device, and the secret traffic brushing instructions indicate that the malicious server interacts with a malicious program to enable a computer device to access the network or click without the user's authorization, so as to increase the number of visits or clicks.
[0101] Next, we will introduce information stealing instructions, remote control instructions, denial of service attack instructions, and hidden traffic instructions respectively.
[0102] (1) Information stealing instructions
[0103] In some embodiments, the information stealing instructions include system username and password sending instructions, browser cookie sending instructions, digital wallet sending instructions, system information sending instructions, keyboard recording sending instructions, or screenshot sending instructions.
[0104] Among them, the system username and password sending instruction instructs to send the system username and password of the computer device to the malicious server for theft. The browser cookie sending instruction instructs to send the browser cookie of the computer device to the malicious server; the digital wallet sending instruction instructs to send the relevant information of the digital wallet of the computer device to the malicious server; the system information sending instruction instructs to send the system information of the computer device to the malicious server, including but not limited to the kernel name, host name, operating system version, processor type and hardware architecture; the keyboard recording instruction instructs to send the keyboard recording of the computer device to the malicious server, which is used to record the content entered by the user on the keyboard of the computer device; the screenshot instruction instructs to take a screenshot of the screen of the computer device or capture the window content.
[0105] Optionally, system username and password sending instructions include but are not limited to / etc / passwd, / etc / shadow, SAM, and SYSTEM.
[0106] Among them, / etc / shadow and / etc / passwd are two important files used to store user account information in Linux and other Unix-like operating systems. / etc / passwd is a plain text file that stores basic information about operating system users. Each line in the / etc / passwd file uses the same format and contains the following fields: username, password placeholder (when the password placeholder is x, it means that the account requires a password to log in, and the actual encrypted password is stored in / etc / shadow; when the password placeholder is empty, the account can log in without a password), user identifier (UID), group identifier (GID), user information, etc.; / etc / shadow is used to store the encrypted password of the user account and other password-related security information. SAM represents the SAM file in the Windows operating system. This SAM file is one of the key files in the Windows operating system for storing user account password data. SYSTEM represents the SYSTEM file in the Windows operating system. This SYSTEM file is another key file in the Windows operating system and contains core system configuration and settings information.
[0107] Optionally, the browser cookie sending instructions include but are not limited to cookies.sqlite, Login Data and Cookies.
[0108] Among them, cookies.sqlite is an SQLite database file, which is used to store browser cookie information; Login Data refers to the database file used by the browser to store user login information.
[0109] Optionally, the digital wallet sending instructions include but are not limited to wallet.dat, keystore, and seed phrases.
[0110] Among them, wallet.dat is an essential file in the Bitcoin Core wallet used to store all private key information and transaction records. The wallet.dat file contains private key information, transaction records, and more. The private key information is the key to controlling Bitcoin. Through the private key, users can obtain and transfer Bitcoin. The transaction record records the transaction history of all Bitcoin in the wallet, including the input and output of each transaction. The keystore is a repository that can be used to store a series of secret keys, key pairs, or certificates. Seed phrases, also known as mnemonics or seed phrases, are a set of keywords used to recover encrypted wallets. They usually consist of 12 to 24 words and are used to generate and recover the wallet's private key. These words store numbers or other data in a way that is easy for users to remember and repeat, thus constituting a critical security element of cryptocurrency accounts and an important privacy information storage tool for cryptocurrency wallets.
[0111] Optionally, the system information sending instruction includes but is not limited to systeminfo, uname -a.
[0112] Among them, Systeminfo is a command used in Windows system to display the system information of the operating system; uname -a is a command commonly used in Unix and Linux systems to display the system information of the current system.
[0113] Optionally, keyboard logging sending instructions include but are not limited to keylog, GetAsyncKeyState, and SetWindowsHookEx.
[0114] Keylog, also known as a keyboard logger or keyboard recorder, is used to record user keyboard interactions. GetAsyncKeyState is a function used to determine the state of a specified virtual key when a function is called, confirming whether the user is currently pressing a key on the keyboard. SetWindowsHookEx is a function in the Windows API that installs an application-defined hook procedure in the message processing chain.
[0115] Optionally, the screenshot instruction includes but is not limited to screenshot, PrintWindow, and BitBlt.
[0116] Screenshot is a function that captures an image of the computer screen or a specific area of the screen. PrintWindow copies the contents of a specified window to a device context. BitBlt is a function used to implement screenshots, which performs a block transfer of color data corresponding to a rectangle of pixels.
[0117] (2) Remote control instructions
[0118] In some embodiments, the remote control instruction includes an online host information acquisition instruction, a process termination instruction, or a network connection information acquisition instruction.
[0119] The online host information acquisition instruction instructs the computer device to acquire online host information; the process termination instruction instructs the computer device to terminate the process running on the computer device; and the network connection information acquisition instruction instructs the computer device to acquire network connection information.
[0120] Optionally, online host information acquisition instructions include but are not limited to hostname, ipconfig, and ifconfig.
[0121] Among them, hostname is used to display or set the host name of the system. In Unix and Unix-like systems (such as Linux), the hostname command can be used to view or change the host name. In Windows systems, the hostname command can be used to view the host name; ipconfig is a command-line tool under Windows systems, used to display all current TCP or Internet Protocol (IP) network configuration values, refresh Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) settings. For example, the local machine's IP address, subnet mask, default gateway and other information. ifconfig is a command-line tool under Unix and Unix-like systems (such as Linux), used to configure and display network interface parameters, such as the network card's IP address, subnet mask, MAC address and other information.
[0122] Optionally, the process termination instruction includes but is not limited to kill, TerminateProcess, and SIGKILL.
[0123] Kill is a command in Unix-like systems that terminates a process; TerminateProcess is a function in the Windows API that forcibly terminates a process. SIGKILL is a signal sent to a process to cause it to terminate immediately.
[0124] Optionally, network connection information acquisition instructions include but are not limited to netstat, ss, and lsof -i.
[0125] Among them, netstat is a command used to display network-related information such as network connections, routing tables, and interface statistics. ss is a command used to view system socket information. lsof -i is a command used to display network connection information.
[0126] (3) Denial of service attack instructions
[0127] In some embodiments, the denial of service attack type instruction includes a wait instruction or a flood attack instruction.
[0128] The wait instruction instructs the computer device to be in a wait state, and the flood attack instruction instructs sending excessive data to the computer device.
[0129] Optionally, the waiting instruction includes but is not limited to nop, sleep, and wait.
[0130] Among them, nop is an instruction that does not perform any operation. Sleep is a function or instruction commonly used in programming to pause the currently executing thread or process for a specified period of time. Wait is an instruction that makes the current thread or process wait for another thread, process, or event.
[0131] Optionally, the flood attack instructions include but are not limited to flood, SYN, UDP, ICMP and DDoS.
[0132] The term "flood" is often used to describe a type of network attack in which an attacker sends a large number of data packets or requests to a computer device with the goal of exhausting its resources or bandwidth, rendering it unable to function properly. Examples include Internet Control Message Protocol (ICMP) floods and User Datagram Protocol (UDP) floods.
[0133] SYN means that the attacker sends a large number of SYN requests to the target server, but does not complete the final stage of the three-way handshake (that is, does not send an ACK packet). This causes the server to maintain a large number of half-open connections, eventually exhausting its resources and becoming unable to process normal connection requests.
[0134] UDP represents a type of attack, namely a UDP flood attack, in which an attacker sends a large number of UDP packets to a computer device. Since UDP is connectionless, the attacker can send a large number of junk packets, causing the computer device to be unable to process normal data traffic.
[0135] ICMP refers to a type of attack, namely an ICMP flood attack, in which the attacker sends a large number of ICMP requests or responses to a computer device in order to exhaust its resources or bandwidth.
[0136] DDoS is a common distributed denial of service (DDoS) attack method in which attackers use multiple computers or a "botnet" to send a large number of requests or traffic to computer devices, aiming to prevent them from providing services to normal users.
[0137] (4) Dark traffic instructions
[0138] In some embodiments, the dark traffic-generating instructions include fraudulent instructions, promotional information pop-up instructions, or network traffic attraction instructions.
[0139] Among them, the fraud instructions instruct to defraud the users of computer devices through online paid promotional information, the promotional information pop-up instructions instruct to consume the system resources of computer devices by popping up promotional information multiple times, and the network traffic attraction instructions instruct to attract website visits or user traffic through various strategies and technical means.
[0140] Optionally, the fraudulent instructions include but are not limited to click fraud; the promotional information pop-up instructions include but are not limited to adware; and the network traffic attraction instructions include but are not limited to traffic generation.
[0141] Click fraud refers to fraudulent online advertising that pays per click. Adware refers to software that frequently displays pop-up ads after installation, consuming system resources and slowing down device performance. Traffic generation, in the online world, refers to the practice of attracting website visits or user traffic through various strategies and techniques.
[0142] In some embodiments, when the sample program calls a network connection function, the security software can also suspend the execution of the sample program.
[0143] Since malicious programs usually interact with malicious servers through the network, if a sample program calls a network connection function, it means that the sample program is about to send data through the network or parse and execute the received data. If the sample program is a malicious program, it poses a security risk. Therefore, when it is determined that the sample program calls a network connection function, the security software can avoid security risks by pausing the running of the sample program.
[0144] Step 203: If there is at least one malicious instruction in the network communication data, the sample program is determined to be a malicious program, and the malicious instruction is used by the malicious server to instruct the malicious program to perform malicious operations on the computer device where the malicious program is installed.
[0145] If there is at least one malicious instruction in the network communication data, it means that there is a security risk in the content of the sample communication through the network. Therefore, it can be determined that the sample program is a malicious program.
[0146] Optionally, after determining that the sample program is a malicious program, the security software can also display a prompt interface, where the prompt interface is used to prompt the user that the sample program is a malicious program.
[0147] In some embodiments, if the network communication data does not contain at least one malicious instruction, it is determined that the sample program is not a malicious program.
[0148] If there is no at least one malicious instruction in the network communication data, it means that there is no security risk in the content of the sample communication through the network. Therefore, it can be determined that the sample program is not a malicious program.
[0149] Optionally, after determining that there is no at least one malicious instruction in the network communication data, the security software can also display an inquiry interface, which is used to inquire whether the network communication behavior of the sample program is a user-authorized behavior. In response to a first confirmation operation triggered by the user, it is determined that the sample program is not a malicious program, and the first confirmation operation indicates that the network communication behavior of the sample program is a user-authorized behavior; in response to a second confirmation operation triggered by the user, it is determined that the sample program is a malicious program, and the second confirmation operation indicates that the network communication behavior of the sample program is not a user-authorized behavior.
[0150] As an example, the inquiry interface includes a first confirmation button and a second confirmation button. The user can trigger the first confirmation button in the inquiry interface to trigger the first confirmation operation. The user can also trigger the second confirmation button in the inquiry interface to trigger the second confirmation operation.
[0151] In some embodiments, when it is determined that the sample program is a malicious program, the security software can also release the memory resources allocated to the sample program to terminate the execution of the sample program.
[0152] Since malicious programs can pose a security threat to computer devices, if the sample program is determined to be a malicious program, the security software can terminate the running of the sample program to further reduce information leakage of the computer device and ensure the security of the computer device.
[0153] Optionally, when it is determined that the sample program is not a malicious program, the security software can also resume the operation of the sample program.
[0154] Next, it will be passed Figure 3 The malicious program identification method provided in this application is introduced again.
[0155] Please refer to Figure 3 The security software can also monitor the startup operation of the program in the computer device. If the security software determines that a new program has been started in the computer device, the newly started program is used as a sample program, and the dynamic library loading function in the operating system of the computer device is hooked through the second hook function to monitor whether the sample program loads the network DLL. If the sample program loads the network DLL, it monitors whether the sample program calls any one of the at least one network connection functions. If the sample program calls the network connection function, the network communication data is obtained, and then the network communication data is matched with the malicious instructions in the malicious instruction set to determine whether there is at least one malicious instruction in the network communication data. If there is at least one malicious instruction in the network communication data, the sample program is determined to be a malicious program. If there is no at least one malicious instruction in the network communication data, the sample program is determined not to be a malicious program.
[0156] The embodiments of the present application provide a method for identifying malicious programs. The method can obtain network communication data when a sample program calls a network connection function. Since the network communication data is the network connection parameters provided by the sample program when calling the network connection function, or is the data received by the sample program when calling the network connection function, and the network communication data is plaintext data, by analyzing the network communication data, it is possible to directly determine whether malicious instructions are contained in the network communication data. If malicious instructions are contained in the network communication data, the sample program can be determined to be a malicious program, and substantial evidence can be obtained that the malicious program performs malicious operations on a computer device. In this way, the malicious program can be accurately identified.
[0157] Since the embodiment of the present application starts to monitor the network communication behavior of the sample program at the beginning of the sample program startup, it can timely discover the malicious operation of the sample program and reduce the security risk of the computer equipment. If the sample program sends data to the network side, the data to be sent needs to be used as part or all of the network connection parameters corresponding to the network connection function to realize network communication. If the sample program receives data from the network side, in order to obtain the data sent by the network side to the sample program, therefore, by obtaining the network communication data, the data to be sent or received by the sample program can be accurately obtained. Since the network communication data are all plain text, this helps to match the network communication data with the malicious instructions in the malicious instruction set, realize in-depth analysis of the network communication behavior of the sample program, and effectively improve the accuracy of malicious program identification. In addition, the method of analyzing plain text messages in the embodiment of the present application has strong interpretability, so that technical personnel can better analyze the behavior pattern of malicious programs.
[0158] Since malicious programs typically interact with malicious servers over the network, if a sample program calls a network connection function, it indicates that the sample program is about to send data over the network or parse and execute received data. If the sample program is malicious, it poses a security risk. Therefore, if the security software determines that the sample program calls a network connection function, it can suspend the sample program to avoid security risks. If the sample program is determined to be malicious, the security software can terminate the sample program to further reduce information leakage from the computer device and ensure the security of the computer device.
[0159] Figure 4 This is a schematic diagram of the structure of a malware identification device provided by an embodiment of the present application. The malware identification device can be implemented by software, hardware, or a combination of both to form part or all of the above-mentioned computer device. Figure 4 The device includes: a monitoring module 401, an acquisition module 402 and a first determination module 403.
[0160] The monitoring module 401 is used to monitor whether the sample program running in the computer device calls the network connection function, which is a function used to support the application program to perform network communication. The detailed implementation process refers to the corresponding content in the above embodiments and will not be repeated here.
[0161] Acquisition module 402 is configured to acquire network communication data when the sample program calls the network connection function. The network communication data may be network connection parameters provided by the sample program when calling the network connection function, or data received by the sample program when calling the network connection function. The detailed implementation process is described in the corresponding sections of the above embodiments and will not be repeated here.
[0162] The first determination module 403 is configured to determine that the sample program is a malicious program if at least one malicious instruction is present in the network communication data. The malicious instruction is used by the malicious server to instruct the malicious program to perform malicious operations on the computer device where the malicious program is installed. The detailed implementation process is referred to the corresponding content in the above embodiments and will not be repeated here.
[0163] Optionally, the monitoring module 401 is specifically configured to:
[0164] In the case of monitoring the startup of the sample program, injecting a user-mode hook function into the sample program, and monitoring the sample program through the user-mode hook function to determine whether the sample program calls a network connection function; or
[0165] A kernel-state hook function is injected into the kernel of the computer device, and the computer device is monitored through the kernel-state hook function to determine whether the sample program calls the network connection function.
[0166] Optionally, the device further comprises:
[0167] The second determination module is configured to match the network communication data with malicious instructions in a malicious instruction set to determine whether there is at least one malicious instruction in the network communication data, where the malicious instruction set includes a plurality of malicious instructions.
[0168] Optionally, the malicious instruction set includes at least one of the following types of instructions: information stealing instructions, remote control instructions, denial of service attack instructions, and secret traffic brushing instructions; wherein, information stealing instructions indicate that a malicious server interacts with a malicious program to steal information from a computer device, remote control instructions indicate that a malicious server interacts with a malicious program to remotely control a computer device, denial of service attack instructions indicate that a malicious server interacts with a malicious program to conduct a denial of service attack on a computer device, and secret traffic brushing instructions indicate that a malicious server interacts with a malicious program to enable a computer device to access the network or click without user authorization, so as to increase the number of visits or clicks.
[0169] Optionally, the information stealing instructions include but are not limited to at least one of the following instructions: a system username and password sending instruction, a browser cookie sending instruction, a digital wallet sending instruction, a system information sending instruction, a keyboard record sending instruction, and a screenshot instruction; wherein the system username and password sending instruction instructs sending the system username and password in the computer device to the malicious server, the browser cookie sending instruction instructs sending the browser cookie in the computer device to the malicious server, the digital wallet sending instruction instructs sending relevant information of the digital wallet in the computer device to the malicious server, the system information sending instruction instructs sending system information in the computer device to the malicious server, the keyboard record instruction instructs sending the keyboard record in the computer device to the malicious server, the keyboard record is used to record the content entered by the user on the keyboard of the computer device, and the screenshot instruction instructs taking a screenshot of the screen in the computer device or capturing the window content;
[0170] Remote control instructions include but are not limited to at least one of the following instructions: an online host information acquisition instruction, a process termination instruction, and a network connection information acquisition instruction; wherein the online host information acquisition instruction instructs the computer device to acquire online host information, the process termination instruction instructs the computer device to terminate a process running on the computer device, and the network connection information acquisition instruction instructs the computer device to acquire network connection information;
[0171] Denial of service attack instructions include but are not limited to at least one of the following instructions: a wait instruction, a flood attack instruction; wherein the wait instruction indicates that the computer device is in a wait state, and the flood attack instruction indicates that excessive data is sent to the computer device;
[0172] Secret traffic-brushing instructions include but are not limited to at least one of the following instructions: fraud instructions, promotional information pop-up instructions, and network traffic attraction instructions; wherein, the fraud instructions indicate defrauding users through online paid promotional information, the promotional information pop-up instructions indicate consuming the system resources of the computer device by popping up promotional information multiple times, and the network traffic attraction instructions indicate attracting website visits or user traffic through various strategies and technical means.
[0173] Optionally, the monitoring module 401 is specifically configured to:
[0174] Monitor whether the sample program has loaded a network dynamic link library (DLL), which is used to implement data interaction between the application and the peer device in accordance with standard definitions, and includes at least one network connection function;
[0175] If the sample program loads the network DLL, it is monitored whether the sample program calls any one of the at least one network connection function.
[0176] Optionally, the network DLL includes a WinINet DLL, and the at least one network connection function includes at least one of the following: an initialization function, a first connection function, a request creation function, a request sending function, and a first data reading function;
[0177] Among them, the initialization function is used to initialize the sample program so that the sample program uses WinINet DLL, the first connection function is used to establish a connection between the sample program and the network, the request creation function is used to create a network request, the request sending function is used to send the network request to the specified server, and the first data reading function is used to read the received data.
[0178] Optionally, the network DLL includes an OpenSSL DLL, and the at least one network connection function includes at least one of the following: a structure creation function, a second connection function, a client handshake function, a server handshake function, a second data reading function, and a data writing function;
[0179] Among them, the structure creation function is used to create a secure socket layer SSL structure, the second connection function is used to connect the SSL structure to the socket, the client handshake function is used to start the SSL handshake or transport layer security TLS handshake when the computer device acts as a client, the server handshake function is used to start the SSL handshake or TLS handshake when the computer device acts as a server, the second data read function is used to read data from the SSL or TLS connection, and the data write function is used to write data to the SSL or TLS connection.
[0180] Optionally, the device further comprises:
[0181] The pause module is used to pause the running of the sample program.
[0182] Optionally, the device further comprises:
[0183] The termination module is used to release the memory resources allocated for the sample program to terminate the running of the sample program.
[0184] Optionally, the apparatus is applied to security software running in a computer device.
[0185] The embodiments of the present application can obtain network communication data when a sample program calls a network connection function. Since the network communication data is the network connection parameters provided by the sample program when calling the network connection function, or is the data received by the sample program when calling the network connection function, and the network communication data is plaintext data, by analyzing the network communication data, it is possible to directly determine whether malicious instructions are contained in the network communication data. If malicious instructions are contained in the network communication data, it is possible to determine that the sample program is a malicious program and obtain substantial evidence that the malicious program performs malicious operations on the computer device, thereby achieving accurate identification of the malicious program.
[0186] Since the embodiment of the present application starts to monitor the network communication behavior of the sample program at the beginning of the sample program startup, it can timely discover the malicious operation of the sample program and reduce the security risk of the computer equipment. If the sample program sends data to the network side, the data to be sent needs to be used as part or all of the network connection parameters corresponding to the network connection function to realize network communication. If the sample program receives data from the network side, in order to obtain the data sent by the network side to the sample program, therefore, by obtaining the network communication data, the data to be sent or received by the sample program can be accurately obtained. Since the network communication data are all plain text, this helps to match the network communication data with the malicious instructions in the malicious instruction set, realize in-depth analysis of the network communication behavior of the sample program, and effectively improve the accuracy of malicious program identification. In addition, the method of analyzing plain text messages in the embodiment of the present application has strong interpretability, so that technical personnel can better analyze the behavior pattern of malicious programs.
[0187] Since malicious programs typically interact with malicious servers over the network, if a sample program calls a network connection function, it indicates that the sample program is about to send data over the network or parse and execute received data. If the sample program is malicious, it poses a security risk. Therefore, if the security software determines that the sample program calls a network connection function, it can suspend the sample program to avoid security risks. If the sample program is determined to be malicious, the security software can terminate the sample program to further reduce information leakage from the computer device and ensure the security of the computer device.
[0188] It should be noted that the malware identification device provided in the above embodiments uses the division of the aforementioned functional modules as an example for malware identification. In actual applications, the aforementioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the malware identification device provided in the above embodiments and the malware identification method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0189] An embodiment of the present application further provides a computer-readable storage medium, wherein the storage medium stores instructions. When the instructions are executed on a computer or a processor, the computer or the processor executes the steps of the malware identification method described in the above embodiment.
[0190] The present application also provides a computer program product comprising instructions that, when executed on a computer or processor, cause the computer or processor to perform the steps of the malware identification method described in the above embodiments. Alternatively, the present application also provides a computer program that, when executed on a computer or processor, causes the computer or processor to perform the steps of the malware identification method described in the above embodiments.
[0191] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., a digital versatile disc (DVD)), or a semiconductor medium (e.g., a solid state disk (SSD)). It is worth noting that the computer-readable storage medium mentioned in the embodiments of the present application may be a non-volatile storage medium, in other words, a non-transient storage medium.
[0192] It should be understood that the "plurality" mentioned herein refers to two or more. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in order to facilitate a clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit them to be different.
[0193] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the network communication data involved in the embodiments of this application is obtained with full authorization.
[0194] The above description is an embodiment provided for this application and is not intended to limit this application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of this application should be included in the scope of protection of this application.
Claims
1. A method for identifying malicious programs, characterized in that: The method comprises: monitoring whether a sample program running in a computer device calls a network connection function, wherein the network connection function is a function used to support an application program to perform network communication; If the sample program calls the network connection function, network communication data is obtained, where the network communication data is network connection parameters provided by the sample program when calling the network connection function, or data received by the sample program when calling the network connection function; If there is at least one malicious instruction in the network communication data, the sample program is determined to be a malicious program, and the malicious instruction is used by a malicious server to instruct the malicious program to perform malicious operations on the computer device where the malicious program is installed.
2. The method according to claim 1, wherein The monitoring of whether the sample program running in the computer device calls the network connection function includes: In the case of monitoring the startup of the sample program, injecting a user-mode hook function into the sample program, and monitoring the sample program through the user-mode hook function to determine whether the sample program calls the network connection function; or A kernel-state hook function is injected into the kernel of the computer device, and the computer device is monitored through the kernel-state hook function to determine whether the sample program calls the network connection function.
3. The method according to claim 1 or 2, wherein: After acquiring the network communication data, the method further includes: The network communication data is matched with malicious instructions in a malicious instruction set to determine whether at least one malicious instruction exists in the network communication data, where the malicious instruction set includes a plurality of malicious instructions.
4. The method according to claim 3, wherein The malicious instruction set includes at least one of the following types of instructions: information theft instructions, remote control instructions, denial of service attack instructions, and hidden traffic brushing instructions; Among them, the information stealing instructions indicate that the malicious server steals information from the computer device by interacting with the malicious program, the remote control instructions indicate that the malicious server remotely controls the computer device by interacting with the malicious program, the denial of service attack instructions indicate that the malicious server performs a denial of service attack on the computer device by interacting with the malicious program, and the traffic brushing instructions indicate that the malicious server interacts with the malicious program to enable the computer device to access the network or click without the user's authorization, so as to increase the number of visits or clicks.
5. The method according to claim 3, wherein The information stealing instructions include but are not limited to at least one of the following instructions: a system username and password sending instruction, a browser cookie sending instruction, a digital wallet sending instruction, a system information sending instruction, a keyboard record sending instruction, and a screenshot instruction; wherein the system username and password sending instruction instructs to send the system username and password in the computer device to the malicious server, the browser cookie sending instruction instructs to send the browser cookie in the computer device to the malicious server, the digital wallet sending instruction instructs to send relevant information of the digital wallet in the computer device to the malicious server, the system information sending instruction instructs to send the system information in the computer device to the malicious server, the keyboard record instruction instructs to send the keyboard record in the computer device to the malicious server, the keyboard record is used to record the content entered by the user on the keyboard of the computer device, and the screenshot instruction instructs to take a screenshot of the screen in the computer device or capture the window content; The remote control instructions include but are not limited to at least one of the following instructions: an online host information acquisition instruction, a process termination instruction, and a network connection information acquisition instruction; wherein the online host information acquisition instruction instructs the computer device to acquire online host information, the process termination instruction instructs the computer device to terminate the process running on the computer device, and the network connection information acquisition instruction instructs the computer device to acquire network connection information; The denial of service attack type instruction includes but is not limited to at least one of the following instructions: a wait instruction, a flood attack instruction; wherein the wait instruction indicates that the computer device is in a wait state, and the flood attack instruction indicates that excessive data is sent to the computer device; The dark traffic-brushing instructions include but are not limited to at least one of the following instructions: fraud instructions, promotional information pop-up instructions, and network traffic attraction instructions; wherein, the fraud instructions indicate defrauding users through online paid promotional information, the promotional information pop-up instructions indicate consuming the system resources of the computer device by popping up promotional information multiple times, and the network traffic attraction instructions indicate attracting website visits or user traffic through various strategies and technical means.
6. The method according to any one of claims 1 to 5, wherein: The monitoring of whether the sample program running in the computer device calls the network connection function includes: Monitoring whether the sample program loads a network dynamic link library (DLL), wherein the network DLL is used to implement data interaction between the application program and the peer device in accordance with standard definitions, and the network DLL includes at least one network connection function; If the sample program loads the network DLL, it is monitored whether the sample program calls any one of the at least one network connection function.
7. The method according to claim 6, wherein The network DLL includes a WinINet DLL, and the at least one network connection function includes at least one of the following: an initialization function, a first connection function, a request creation function, a request sending function, and a first data reading function; Among them, the initialization function is used to initialize the sample program so that the sample program uses WinINetDLL, the first connection function is used to establish a connection between the sample program and the network, the request creation function is used to create a network request, the request sending function is used to send the network request to the specified server, and the first data reading function is used to read the received data.
8. The method according to claim 6, wherein The network DLL includes an OpenSSL DLL, and the at least one network connection function includes at least one of the following: a structure creation function, a second connection function, a client handshake function, a server handshake function, a second data reading function, and a data writing function; Among them, the structure creation function is used to create a secure socket layer SSL structure, the second connection function is used to connect the SSL structure to the socket, the client handshake function is used to start the SSL handshake or transport layer security TLS handshake when the computer device acts as a client, the server handshake function is used to start the SSL handshake or TLS handshake when the computer device acts as a server, the second data read function is used to read data from the SSL or TLS connection, and the data write function is used to write data to the SSL or TLS connection.
9. The method according to any one of claims 1 to 8, wherein In the case where the sample program calls the network connection function, the method further includes: Pause the execution of the sample program.
10. The method according to any one of claims 1 to 9, wherein In the case where the sample program is determined to be a malicious program, the method further includes: The memory resources allocated for the sample program are released to terminate the running of the sample program.
11. The method according to claims 1 to 10, characterized in that The method is executed by security software running in the computer device.
12. A malicious program identification device, characterized in that: The device comprises: A monitoring module, configured to monitor whether a sample program running in a computer device calls a network connection function, wherein the network connection function is a function for supporting an application program to perform network communication; an acquisition module, configured to acquire network communication data if the sample program calls the network connection function, wherein the network communication data is network connection parameters provided by the sample program when calling the network connection function, or data received by the sample program when calling the network connection function; The first determination module is configured to determine that the sample program is a malicious program if there is at least one malicious instruction in the network communication data, wherein the malicious instruction is used by a malicious server to instruct the malicious program to perform malicious operations on a computer device on which the malicious program is installed.
13. A computer device, characterized in that: The computer device includes a memory and a processor; The memory is used to store computer programs; The processor is configured to execute the computer program to implement the steps of the method according to any one of claims 1 to 11.
14. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program runs on a computer or a processor, the computer or the processor executes the method according to any one of claims 1 to 11.
15. A computer program product, characterized in that The computer program product comprises computer instructions, and when the computer instructions are executed by a computer or a processor, the steps of the method according to any one of claims 1 to 11 are performed.