Attack behavior detection method and device based on process chain, computer equipment, storage medium and computer program product

By generating and updating an array of matching results for each process, the problem of poor matching efficiency caused by process tree expansion is solved, thus improving the efficiency and accuracy of attack behavior detection.

CN120930135APending Publication Date: 2025-11-11HANGZHOU YIGE CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511019009.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-23
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing attack detection methods based on process chains suffer from poor matching efficiency due to the expansion of the process tree depth.

Method used

By generating a matching result array for each process, updating the child process's array based on the parent process's matching result array, and matching the detected behavior against the preset attack matching result array to determine whether to block the process.

Benefits of technology

It improves the efficiency of detecting whether a process is part of an attack process chain, reduces query time complexity, and improves the efficiency of blocking processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120930135A_ABST
    Figure CN120930135A_ABST
Patent Text Reader

Abstract

The invention relates to an attack behavior detection method and device based on a process chain, computer equipment, a storage medium and a computer program product. The method comprises the following steps: under the condition that a process creation event is detected, performing matching processing on each piece of process information of a created process and preset process information corresponding to each to-be-detected behavior, and generating a matching result array corresponding to the process based on a matching result; under the condition that the process has the parent process, updating the matching result array of the process based on the matching result array of the parent process and the matching result array of the process; and under the condition that the target process executing any to-be-detected behavior is detected, if the matching result array of the target process is matched with the preset attack matching result array, blocking the target process. By adopting the method, the attack detection and blocking efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, computer device, storage medium, and computer program product for detecting attack behavior based on process chain. Background Technology

[0002] Process chain-based attack detection and defense is a core technology in modern network security protection. Its main function is to deeply identify complex attack paths, accurately block malicious activity chains, and significantly improve proactive defense capabilities. The principle behind this method is to maintain multiple attack detection rules. Each rule includes a suspicious activity of a process to be detected (e.g., loading an unsigned dynamic link library file) and conditions that each process in the process chain must meet (e.g., the process is signed, its parent process is unsigned, and its parent-parent process is an instant messaging process). When a process is detected executing the activity to be detected, the system checks whether each process in the process chain meets the conditions to determine whether to block the process.

[0003] In related technologies, the above principle is typically implemented by maintaining a process information tree. Each node in the tree contains process information, such as process path, signature information, user information, company information, etc. When a process triggers an activity to be detected, the process information tree needs to be traversed to match the attack detection rules with the process information tree. This approach suffers from the drawback of the process tree's depth expanding infinitely, leading to poor matching efficiency. Summary of the Invention

[0004] Therefore, it is necessary to provide a method, apparatus, computer device, storage medium, and computer program product for detecting attack behavior based on process chains to address the aforementioned technical problems.

[0005] Firstly, this application provides a method for detecting attack behavior based on process chains. The method includes:

[0006] Upon detecting a process creation event, the process information of the created process and the preset process information corresponding to each detected behavior are matched, and a matching result array corresponding to the process is generated based on the matching results; the preset process information includes information that needs to be matched for all processes in the process chain;

[0007] If the process has a parent process, the matching result array of the process is updated based on the matching result array of the parent process and the matching result array of the process.

[0008] If a target process is detected performing any of the behaviors to be detected, the matching result array of the target process is matched with the preset attack matching result array corresponding to the behavior to be detected, and if the matching result array of the target process matches the preset attack matching result array, the target process is blocked.

[0009] In one embodiment, each element in the matching result array corresponds to one of the preset process information;

[0010] The step of generating the matching result array corresponding to the process based on the matching results includes:

[0011] For any of the preset process information, if there is process information that matches the preset process information, the element corresponding to the preset process information in the matching result array is set to a first value, or if there is no process information that matches the preset process information, the element is set to a second value.

[0012] In one embodiment, updating the matching result array of the process based on the matching result array of the parent process and the matching result array of the process includes:

[0013] A first target element is determined from the matching result array of the parent process, and a second target element corresponding to the first target element is determined from the matching result array of the process; wherein, the first target element is an element that is not the second value;

[0014] Based on the values ​​of the first target element and the second target element, the value of the second target element is updated so that the updated value is different from the value of the first target element, the first value, and the second value.

[0015] In one embodiment, the step of updating the value of the second target element based on the value of the first target element and the value of the second target element includes any one of the following:

[0016] The values ​​of the first target element, the second target element, and a preset value are summed; wherein the preset value is a value that is greater than or equal to the first value and greater than the second value.

[0017] The integer part of the first target element, the value of the second target element, the first preset value, and the second preset value are accumulated; wherein the first value, the second value, and the first preset value are integers, the second preset value is a decimal, and the value of the second preset value is determined based on the value of the first target element.

[0018] In one embodiment, each element in the matching result array corresponds to a process information that matches the preset process information;

[0019] The step of generating the matching result array corresponding to the process based on the matching results includes:

[0020] For any of the process information, if there is preset process information that matches the process information, a third value corresponding to the process information is determined based on the number value corresponding to the preset process information and / or the number value of the behavior to be detected corresponding to the preset process information.

[0021] Set the element in the matching result array that corresponds to the process information to the third value.

[0022] In one embodiment, the method further includes:

[0023] If a process exit is detected, and the process has child processes and the child processes have corresponding matching result arrays, then the matching result arrays corresponding to the process are deleted.

[0024] Secondly, this application also provides an attack behavior detection device based on process chain. The device includes:

[0025] The first matching module is used to match the process information of the created process with the preset process information corresponding to each behavior to be detected when a process creation event is detected, and generate a matching result array corresponding to the process based on the matching results; the preset process information includes the information of all processes in the process chain that need to be matched;

[0026] An update module is used to update the matching result array of the process based on the matching result array of the parent process and the matching result array of the process when the process has a parent process.

[0027] The second matching module is used to match the matching result array of the target process with the preset attack matching result array corresponding to the target behavior when a target process performing any of the detected behaviors is detected, and to block the target process when the matching result array of the target process matches the preset attack matching result array.

[0028] In one embodiment, each element in the matching result array corresponds to one of the preset process information;

[0029] The first matching module is also used for:

[0030] For any of the preset process information, if there is process information that matches the preset process information, the element corresponding to the preset process information in the matching result array is set to a first value, or if there is no process information that matches the preset process information, the element is set to a second value.

[0031] In one embodiment, the update module is further configured to:

[0032] A first target element is determined from the matching result array of the parent process, and a second target element corresponding to the first target element is determined from the matching result array of the process; wherein, the first target element is an element that is not the second value;

[0033] Based on the values ​​of the first target element and the second target element, the value of the second target element is updated so that the updated value is different from the value of the first target element, the first value, and the second value.

[0034] In one embodiment, the update module is further configured to:

[0035] The values ​​of the first target element, the second target element, and a preset value are summed; wherein the preset value is a value that is greater than or equal to the first value and greater than the second value.

[0036] The integer part of the first target element, the value of the second target element, the first preset value, and the second preset value are accumulated; wherein the first value, the second value, and the first preset value are integers, the second preset value is a decimal, and the value of the second preset value is determined based on the value of the first target element.

[0037] In one embodiment, each element in the matching result array corresponds to a process information that matches the preset process information;

[0038] The first matching module is also used for:

[0039] For any of the process information, if there is preset process information that matches the process information, a third value corresponding to the process information is determined based on the number value corresponding to the preset process information and / or the number value of the behavior to be detected corresponding to the preset process information.

[0040] Set the element in the matching result array that corresponds to the process information to the third value.

[0041] In one embodiment, the device further includes:

[0042] The deletion module is used to delete the matching result array corresponding to the process if the process has child processes and the child processes have corresponding matching result arrays when the process exits.

[0043] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement any of the methods described above.

[0044] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements any of the above methods.

[0045] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements any of the above methods.

[0046] The aforementioned attack detection method, apparatus, computer device, storage medium, and computer program product based on process chains calculate a matching result array for each process. This array represents the matching status between the process information and preset process information. If the process has a parent process, the matching result array for that process is also updated based on the parent process's matching result array, ensuring that the updated array reflects the matching status of process information and preset process information for all processes in the process chain to which the process belongs. When a process executes the behavior to be detected, it can be determined whether the process might be part of an attack process chain and whether it needs to be blocked, based on whether each element in the preset attack matching result array pre-constructed for the behavior to be detected is the same as each element in the matching result array. In this embodiment, information on whether all processes in the process chain match preset process information is stored in an array. Since the time complexity of querying the array is significantly lower than that of querying a tree structure, the efficiency of detecting whether a process is part of an attack process chain and determining whether to block the process is improved. Attached Figure Description

[0047] Figure 1 This is a flowchart illustrating an attack behavior detection method based on process chains in one embodiment;

[0048] Figure 2 This is a flowchart illustrating the calculation and updating of the matching result array in one embodiment;

[0049] Figure 3 A flowchart for calculating and updating the matching result array in another embodiment;

[0050] Figure 4 This is a structural block diagram of an attack behavior detection device based on process chain in one embodiment;

[0051] Figure 5 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0052] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0053] In one embodiment, such as Figure 1 As shown, a method for detecting attack behavior based on process chains is provided. This embodiment illustrates the method by applying it to a server. It is understood that this method can also be applied to terminals, and to systems including both terminals and servers, and is implemented through interaction between the terminal and the server. In this embodiment, the method includes the following steps:

[0054] Step 102: When a process creation event is detected, the process information of the created process and the preset process information corresponding to each behavior to be detected are matched, and an array of matching results corresponding to the process is generated based on the matching results; the preset process information includes the information of all processes in the process chain that need to be matched.

[0055] In this embodiment, the server can detect processes created on the server by registering callback functions that are invoked when a process is created, viewing system logs, etc. When the server detects the creation of a process, it obtains the process information of that process. The specific process information to be obtained can be set by those skilled in the art based on the information required for attack detection. For example, process information may include: process name, process signature, name of the developer to which the process belongs, etc.

[0056] After obtaining the process information, the server matches the process information with the preset process information corresponding to each behavior to be detected. Each behavior to be detected corresponds to one or more preset process information, and the behavior to be detected and its corresponding preset process information constitute an attack detection rule.

[0057] The preset process information includes information that needs to be matched for all processes in a process chain. For example, if the attack detection rule is that the current process's signature information is signed, the current process's parent process's signature information is unsigned, and the name of the parent-parent process is "Instant Messaging," then the preset process information corresponding to the behavior to be detected would be: Name: Instant Messaging; Signature Information: Unsigned; Signature Information: Signed. It should be noted that it is not necessary to specify which level of the process chain each preset process information corresponds to.

[0058] Matching process information with the preset process information corresponding to each behavior to be detected can mean performing a match using the preset process information and the actual process information for each behavior to be detected separately. For example, if the preset process information for behavior 1 to be detected includes process name A1 and process name B1, and the preset process information for behavior 2 to be detected includes process name A1 and process signature B2, then performing a match using the preset process information and the actual process information for each behavior to be detected separately means: first, for behavior 1 to be detected, determine whether process name A1 matches the actual process name, and determine whether process name B1 matches the actual process name. Then, for behavior 2 to be detected, determine whether process name A1 matches the actual process name, and determine whether process signature B2 matches the actual process signature. In this case, the matching result array can be used to indicate which behavior to be detected the process information matches, and to indicate which preset process information within that behavior matches the actual process information.

[0059] In one embodiment, each element in the matching result array corresponds to a process information that matches preset process information. The method for generating the matching result array in this case includes:

[0060] For any process information, if there is a preset process information that matches the process information, a third value corresponding to the process information is determined based on the number value corresponding to the preset process information and / or the number value of the behavior to be detected corresponding to the preset process information.

[0061] Set the element corresponding to the process information in the matching results array to the third value.

[0062] In this embodiment, the matching result array is used to reflect whether there is preset process information that matches the process information of this process. For example, if the process information of this process includes name, signature, and developer name, then the matching result array is an array containing three elements, each element corresponding to a process information.

[0063] If a preset process information exists that matches the process information of this process, then the element corresponding to the process information can be assigned a value based on at least one of the preset process information's ID value and the ID value of the behavior to be detected to which the preset process information belongs. The ID value can be set by those skilled in the art according to actual needs, as long as the ID value of each behavior to be detected and the ID value of each preset process information are unique.

[0064] When calculating the third value using only the preset process information or the ID value of the behavior to be detected, the ID value can be used as the third value. If it is necessary to calculate the third value based on both the preset process information and the ID value of the behavior to be detected, the ID value corresponding to the preset process information can be used as the integer part of the third value, and the ID value of the behavior to be detected can be used as the decimal part of the third value. Alternatively, the ID value corresponding to the preset process information can be used as the decimal part of the third value, and the ID value of the behavior to be detected can be used as the integer part of the third value, so that the third value can reflect both the preset process information and the ID value of the behavior to be detected.

[0065] The advantage of generating the matching result array in this way is that it does not need to record the preset process information that did not match the process information, thus saving storage space used by the matching result array. However, this method may require expanding the size of the array when inheriting the matching result array from the parent process, and the storage space used by each array is not fixed.

[0066] Matching process information with the preset process information corresponding to each behavior to be detected can also refer to the process of aggregating and deduplicating the preset process information for each behavior to be detected, and then matching the process information with the aggregated preset process information one by one. Taking behavior 1 and behavior 2 to be detected as examples, matching one by one means: first, aggregating and deduplicating the preset process information for behaviors 1 and 2 to obtain a preset process information set: process name A1, process name B1, and process signature B2. Then, matching the name of the current process with process name A1 and process name B1 respectively, and matching the signature of the current process with process signature B2.

[0067] In this case, each element in the matching result array corresponds to a preset process information. The methods for generating the matching result array in this case include:

[0068] For any preset process information, if there is a process information that matches the preset process information, the element corresponding to the preset process information in the matching result array is set to the first value; or if there is no process information that matches the preset process information, the element is set to the second value.

[0069] In this embodiment, the matching result array is used to reflect whether there is process information that matches the preset process information. For example, if the preset process information includes process name A1, process name B1, process signature B2, and developer information C3, then the matching result array is an array containing four elements, each element corresponding to a preset process information.

[0070] If a process matching the preset process information exists in the current process, the element in the matching result array corresponding to the preset process information can be assigned a first value. If no matching process information exists in the current process, the element in the matching result array corresponding to the preset process information can be assigned a second value. This application does not limit the specific values ​​of the first and second values, as long as they are different. For example, the first value can be 1, and the second value can be 0.

[0071] The advantage of generating the matching result array in this way is that the size of the matching result array is fixed, and the preset process information corresponding to each element in the matching result array is also fixed, which facilitates the subsequent inheritance of the parent process's matching result array and the comparison between the preset attack matching result array and the matching result array.

[0072] Step 104: If the process has a parent process, update the matching result array of the process based on the matching result array of the parent process and the matching result array of the process.

[0073] In this embodiment of the application, if a process has a parent process, the process needs to inherit the matching result array of the parent process so that the final matching result array of the process can reflect the matching results of all processes in the process chain.

[0074] This application does not impose specific limitations on how the matching result array of the parent process is inherited. As long as each element in the updated matching result array can simultaneously reflect the value of the matching result array of the parent process at that element and the value of the matching result array of the current process at that element, it is acceptable.

[0075] In one example, the value of the matching result array of the current process at that element can be used as the integer part of the updated value, and the value of the matching result array of the parent process at that element can be used as the decimal part of the updated value. For example, if the first value is 1, the second value is 0, the value of the parent process at that element is 1.011, and the value of the current process at that element is 0, then the updated value could be 0.1011. In this way, the value of each element can clearly reflect which level of the process chain, counting upwards from the current process, matches the preset process information. The drawback of this method is that when the process chain is long, the number of decimal places may exceed the upper limit of the number of bits that the operating system can accurately store.

[0076] In another example, where each element in the aforementioned matching result array corresponds to a process information, the way to inherit the parent process's matching result array could be:

[0077] The first target element and the second target element are determined from the matching result array of the parent process, and the third target element corresponding to the first target element is determined from the matching result array of the process; wherein, the first target element is an element that has a corresponding third target element;

[0078] Based on the values ​​of the first target element and the third target element, the value of the third target element is updated.

[0079] Add each second target element to the matching results array of the process.

[0080] In this embodiment, since the values ​​of elements in the matching result array are determined based on the unique ID value corresponding to the preset process information or the behavior to be detected, elements corresponding to the same ID value can be determined from the matching result arrays of the parent process and the current process. Such elements are called first target elements in the parent process's matching result array and third target elements in the current process's matching result array. If the ID values ​​of some elements in the parent process's array do not correspond to those in the current process's array, then these elements in the parent process belong to the second target elements.

[0081] In order to ensure that the value of the updated element can reflect which level of process in the process chain matches the preset process information, after updating the value of the third target element based on the values ​​of the first target element and the third target element, the updated value should not be equal to any third value that can be calculated on that element.

[0082] For example, if the method for determining the third value is to use the number value as the decimal part of the third value, then the value of the third target element can be updated in the following way:

[0083] The integer part of the first target element, the integer part of the third target element, and the preset value are summed.

[0084] The number value is used as the decimal part of the cumulative processing result to obtain the updated value of the third target element.

[0085] In this embodiment, the integer part of the third value can be any value, for example, it can be set to 0. The number value is used as the decimal part of the third value. Since the decimal part of the element value remains unchanged each time the element value is updated, it is easier to obtain the corresponding number value of the element from the element value, and it is also easier to determine which elements in the matching result array of the parent process are the first target elements.

[0086] The preset value can be any integer value greater than the integer part of the third value, such as 1, 2, etc. In this way, after inheriting the matching result array of the parent process, the integer part of the element can reflect how many processes in the process chain match the behavior to be detected or the preset process information corresponding to that number value.

[0087] Furthermore, the preset value can also be calculated in real time based on the integer part of the first target element. For example, it can be fixed at twice the integer part of the first target element.

[0088] After updating the value of the third target element, the remaining second target elements are added to the matching result array of the process to obtain the complete updated array.

[0089] In another example, where each element in the aforementioned matching result array corresponds to a preset process information, the way to inherit the matching result array from the parent process can be:

[0090] The first target element is determined from the matching result array of the parent process, and the second target element corresponding to the first target element is determined from the matching result array of the process; wherein, the first target element is an element that is not a second value;

[0091] Based on the values ​​of the first target element and the second target element, the value of the second target element is updated so that the updated value is different from the value of the first target element, the first value, and the second value.

[0092] In this embodiment of the application, the first target element is an element in the parent process that is not a second value. Such an element represents that the process information of at least one process in the process chain matches the preset process information corresponding to the element. Therefore, it is necessary to inherit the value of such an element into the element value of this process so as to retain the information that the process information of at least one process matches the preset process information corresponding to the element in the element value of this process.

[0093] Since each element in the matching result array corresponds to a specific preset process, the matching result array of the parent process can be traversed. If the traversed element is not the second value, it can be determined that the element is the first target element. At the same time, the element with the same index as the first target element in the matching result array of the current process is the second target element.

[0094] After updating the second target element based on the values ​​of the first target element and the second target element, the updated value should be different from the value of the first target element, as well as the first and second values ​​that the second target element may have, so that the updated value can reflect that the value is inherited from the upstream process chain of this process.

[0095] In one embodiment, updating the value of the second target element based on the value of the first target element and the value of the second target element includes any one of the following:

[0096] The values ​​of the first target element, the second target element, and the preset value are summed; where the preset value is a value that is greater than or equal to the first value and greater than the second value.

[0097] The integer part of the first target element, the value of the second target element, the first preset value, and the second preset value are accumulated; wherein the first value, the second value, and the first preset value are integers, the second preset value is a decimal, and the value of the second preset value is determined based on the value of the first target element.

[0098] In this embodiment of the application, when the values ​​of the first target element, the second target element, and the preset value are accumulated, in order to ensure that the result obtained after the accumulation process is different from the first value, the second value, and the value of the first target element, the preset value needs to be a value that is greater than or equal to the first value and greater than the second value.

[0099] As in the aforementioned embodiments, the preset value can be a fixed value or it can be calculated based on the value of the first target element. For example, it can be 2 times, 3 times, or other times the value of the first target element.

[0100] The process of updating the value of the second target element in this case is illustrated with a practical example. Figure 2 As shown, assuming the preset process information includes: process name: instant messaging, process signature: no signature, process signature: signed, then the matching result array is an array with three elements.

[0101] exist Figure 2 In the process chain, the process information for level 1 process is: Process Name: Instant Messaging, Process Signature: Signed. The process information for level 2 process is: Process Name: A, Process Signature: Unsigned. The process information for level 3 process is: Process Name: B, Process Signature: Signed.

[0102] If the first value is set to 1, the second value to 0, and the default value to 1, then when the first-level process is created, the array of matching results generated for the first-level process will be: [1,0,1].

[0103] When the second-level process is created by the first-level process, the matching result array generated for the second-level process is [0, 1, 0]. It then inherits the matching result array from the first-level process. The first target elements in the first-level process's matching result array are the first and third elements. The values ​​of these elements are added to the corresponding values ​​in the second-level process's matching result array, and a preset value is added to the sum. The final matching result array obtained for the second-level process is [2, 1, 2].

[0104] As can be seen, since the second value in this example is 0, if the values ​​of the first and third elements in the two arrays are directly summed, the sum will be the same as the first value, making it impossible to distinguish whether the second-level process matches the preset process information or the first-level process matches the preset process information. Therefore, a preset value needs to be set to avoid this situation.

[0105] When the level 3 process is created by the level 1 process, the matching result array generated for the level 3 process is [0,0,1]. Then, it inherits the matching result array from the level 2 process. The first target elements in the level 2 process's matching result array are the 1st, 2nd, and 3rd elements. The values ​​of these elements are added to the corresponding values ​​in the level 3 process's matching result array, and a preset value is added to the sum. The final matching result array obtained for the level 3 process is [3,2,4].

[0106] The probability of identical matching result arrays across different process chains can be reduced by setting more refined preset process information. Alternatively, the matching result array can be updated as follows to reduce the probability of identical arrays: the integer part of the first target element, the value of the second target element, the first preset value, and the second preset value are summed; where the first value, the second value, and the first preset value are integers, the second preset value is a decimal, and the value of the second preset value is determined based on the value of the first target element.

[0107] In this example, the values ​​of the elements in the updated matching result array are divided into an integer part and a decimal part. The integer part is used to reflect how many levels of processes in the process chain match the preset process information, as well as the approximate position of these processes in the process chain. The decimal part is used to further reflect the position of these processes in the process chain.

[0108] The process of updating the value of the second target element in this case is illustrated with a practical example. Figure 3 As shown, assuming the preset process information includes: Developer Name: A, Process Signature: No Signature, then the matching result array is an array with two elements. The first value is set to 1, the second value to 0, and the first preset value is 1. The second preset value is the sum of the integer and decimal parts of the first target element's value.

[0109] Figure 3 There are two process chains. The process information for the first-level process in chain 1 is: Developer Name: A, Process Signature: Unsigned. The process information for the second-level process is: Developer Name: B, Process Signature: Unsigned. The process information for the third-level process is: Developer Name: A, Process Signature: Signed.

[0110] The process information for the first-level process in process chain 2 is: Developer name: A, Process signature: Unsigned. The process information for the second-level process is: Developer name: A, Process signature: Signed. The process information for the third-level process is: Developer name: B, Process signature: Unsigned.

[0111] In this special case, if the two process chains are calculated by accumulating the values ​​of the first target element, the second target element, and the preset value as described above, the final matching result array will be [4,4]. However, in reality, only process chain 1 may be the process chain that matches the attack detection rule. In this special case, process chain 2 may be incorrectly blocked.

[0112] When using this method, the matching result arrays for process chains 1 and 2 will be [4.3, 4.4] and [4.4, 4.3] respectively, resolving the issue of overlapping matching result arrays for process chains in special cases. Furthermore, since the decimal part rarely exceeds three digits, it avoids the problem of the decimal part exceeding the operating system's storage limit.

[0113] In one embodiment, the above method further includes:

[0114] If a process exit is detected, and the process has child processes with corresponding matching result arrays, then the matching result array corresponding to the process is deleted.

[0115] In this embodiment, the matching result array of a process already contains all the information of the matching result array corresponding to its parent process. The reason for retaining the matching result array of the parent process is only because it is also necessary to monitor whether the parent process executes the behavior to be detected. Therefore, if a process with child processes and corresponding matching result arrays of child processes exits, the matching result array corresponding to the parent process can be deleted, thereby saving storage space.

[0116] Step 106: If a target process is detected performing any of the behaviors to be detected, the matching result array of the target process is matched with the preset attack matching result array corresponding to the behavior to be detected. If the matching result array of the target process matches the preset attack matching result array, the target process is blocked.

[0117] In this embodiment, when the server detects that a target process is executing any of the behaviors to be detected, it reads a preset attack matching result array corresponding to the target process. The preset attack matching result array is pre-calculated based on the known attack process chain corresponding to the behavior to be detected, according to the rules in the aforementioned embodiments.

[0118] The server then matches the preset attack matching result array with the target process's matching result array. If every element in the preset attack matching result array has the same value as the corresponding element in the target process's matching result array, then the preset attack matching result array and the target process's matching result array are considered to match. In this case, the target process may be part of an attack process chain, and the server can block the target process.

[0119] The attack behavior detection method based on process chains provided in this application calculates a matching result array for each process. This array represents the matching status between the process information and preset process information. If the process has a parent process, the matching result array for this process is updated based on the parent process's matching result array, ensuring that the updated array reflects the matching status of all processes in the process chain and the preset process information. When a process executes the behavior to be detected, it can determine whether the process might be part of an attack process chain and whether it needs to be blocked, based on whether each element in the preset attack matching result array (pre-constructed for the behavior to be detected) matches each element in the matching result array. This application stores information on whether all processes in the process chain match the preset process information in an array. Since the time complexity of querying the array is significantly lower than that of querying a tree structure, the efficiency of detecting whether a process is part of an attack process chain and determining whether to block the process is improved.

[0120] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0121] Based on the same inventive concept, this application also provides a process chain-based attack behavior detection device for implementing the above-mentioned process chain-based attack behavior detection method. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more process chain-based attack behavior detection device embodiments provided below can be found in the limitations of the process chain-based attack behavior detection method described above, and will not be repeated here.

[0122] In one embodiment, such as Figure 4 As shown, a process chain-based attack behavior detection device 400 is provided, including: a first matching module 402, an update module 404, and a second matching module 406, wherein:

[0123] The first matching module 402 is used to match the process information of the created process with the preset process information corresponding to each behavior to be detected when a process creation event is detected, and generate a matching result array corresponding to the process based on the matching results; the preset process information includes information that needs to be matched for all processes in the process chain.

[0124] The update module 404 is used to update the matching result array of the process based on the matching result array of the parent process and the matching result array of the process when the process has a parent process.

[0125] The second matching module 406 is used to match the matching result array of the target process with the preset attack matching result array corresponding to the target behavior when a target process performing any of the detected behaviors is detected, and to block the target process when the matching result array of the target process matches the preset attack matching result array.

[0126] In one embodiment, each element in the matching result array corresponds to one of the preset process information;

[0127] The first matching module 402 is also used for:

[0128] For any of the preset process information, if there is process information that matches the preset process information, the element corresponding to the preset process information in the matching result array is set to a first value, or if there is no process information that matches the preset process information, the element is set to a second value.

[0129] In one embodiment, the update module 404 is further configured to:

[0130] A first target element is determined from the matching result array of the parent process, and a second target element corresponding to the first target element is determined from the matching result array of the process; wherein, the first target element is an element that is not the second value;

[0131] Based on the values ​​of the first target element and the second target element, the value of the second target element is updated so that the updated value is different from the value of the first target element, the first value, and the second value.

[0132] In one embodiment, the update module 404 is further configured to:

[0133] The values ​​of the first target element, the second target element, and a preset value are summed; wherein the preset value is a value that is greater than or equal to the first value and greater than the second value.

[0134] The integer part of the first target element, the value of the second target element, the first preset value, and the second preset value are accumulated; wherein the first value, the second value, and the first preset value are integers, the second preset value is a decimal, and the value of the second preset value is determined based on the value of the first target element.

[0135] In one embodiment, each element in the matching result array corresponds to a process information that matches the preset process information;

[0136] The first matching module 402 is also used for:

[0137] For any of the process information, if there is preset process information that matches the process information, a third value corresponding to the process information is determined based on the number value corresponding to the preset process information and / or the number value of the behavior to be detected corresponding to the preset process information.

[0138] Set the element in the matching result array that corresponds to the process information to the third value.

[0139] In one embodiment, the device further includes:

[0140] The deletion module is used to delete the matching result array corresponding to the process if the process has child processes and the child processes have corresponding matching result arrays when the process exits.

[0141] Each module in the above-mentioned device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0142] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 5 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a process chain-based attack detection method.

[0143] Those skilled in the art will understand that Figure 5 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0144] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.

[0145] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.

[0146] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0147] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0148] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0149] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0150] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for detecting attack behavior based on process chains, characterized in that, The method includes: Upon detecting a process creation event, the process information of the created process and the preset process information corresponding to each detected behavior are matched, and a matching result array corresponding to the process is generated based on the matching results; the preset process information includes information that needs to be matched for all processes in the process chain; If the process has a parent process, the matching result array of the process is updated based on the matching result array of the parent process and the matching result array of the process. If a target process is detected performing any of the behaviors to be detected, the matching result array of the target process is matched with the preset attack matching result array corresponding to the behavior to be detected, and if the matching result array of the target process matches the preset attack matching result array, the target process is blocked.

2. The method according to claim 1, characterized in that, Each element in the matching result array corresponds to a preset process information; The step of generating the matching result array corresponding to the process based on the matching results includes: For any of the preset process information, if there is process information that matches the preset process information, the element corresponding to the preset process information in the matching result array is set to a first value, or if there is no process information that matches the preset process information, the element is set to a second value.

3. The method according to claim 2, characterized in that, The step of updating the matching result array of the process based on the matching result array of the parent process and the matching result array of the process includes: A first target element is determined from the matching result array of the parent process, and a second target element corresponding to the first target element is determined from the matching result array of the process; wherein, the first target element is an element that is not the second value; Based on the values ​​of the first target element and the second target element, the value of the second target element is updated so that the updated value is different from the value of the first target element, the first value, and the second value.

4. The method according to claim 3, characterized in that, The step of updating the value of the second target element based on the value of the first target element and the value of the second target element includes any one of the following: The values ​​of the first target element, the second target element, and a preset value are summed; wherein the preset value is a value that is greater than or equal to the first value and greater than the second value. The integer part of the first target element, the value of the second target element, the first preset value, and the second preset value are accumulated; wherein the first value, the second value, and the first preset value are integers, the second preset value is a decimal, and the value of the second preset value is determined based on the value of the first target element.

5. The method according to claim 1, characterized in that, Each element in the matching result array corresponds to a process information that matches the preset process information; The step of generating the matching result array corresponding to the process based on the matching results includes: For any of the process information, if there is preset process information that matches the process information, a third value corresponding to the process information is determined based on the number value corresponding to the preset process information and / or the number value of the behavior to be detected corresponding to the preset process information. Set the element in the matching result array that corresponds to the process information to the third value.

6. The method according to claim 1, characterized in that, The method further includes: If a process exit is detected, and the process has child processes and the child processes have corresponding matching result arrays, then the matching result arrays corresponding to the process are deleted.

7. A process chain-based attack behavior detection device, characterized in that, The device includes: The first matching module is used to match the process information of the created process with the preset process information corresponding to each behavior to be detected when a process creation event is detected, and generate a matching result array corresponding to the process based on the matching results; the preset process information includes the information of all processes in the process chain that need to be matched; An update module is used to update the matching result array of the process based on the matching result array of the parent process and the matching result array of the process when the process has a parent process. The second matching module is used to match the matching result array of the target process with the preset attack matching result array corresponding to the target behavior when a target process performing any of the detected behaviors is detected, and to block the target process when the matching result array of the target process matches the preset attack matching result array.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.