Malicious code concealment attack identification method and device based on trusted node network

By using a trusted node network-based approach and analyzing the trustworthiness and characteristics of data packet transmission paths, a twin-generated isolated environment is generated to identify malicious code. This solves the efficiency problem of the zero-trust model in low-traffic scenarios and achieves efficient malicious code identification.

CN121173596BActive Publication Date: 2026-02-03BEIJING GUODIANTONG NETWORK TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511705328.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-20
Publication Date
2026-02-03
Estimated Expiration
2045-11-20

AI Technical Summary

Technical Problem

In scenarios where network traffic containing malicious code accounts for a small percentage, the existing zero-trust model leads to a large number of invalid identification processes, affecting packet processing efficiency.

Method used

The method based on trusted node networks determines the trustworthiness of data packet transmission paths, generates data packet characteristics and risk probabilities, generates a twin-like isolated environment for data packet operations, and records state information through an environment listener to identify hidden attacks.

Benefits of technology

It improves the accuracy of malicious code identification, while reducing redundant identification of data packets without malicious code, thus improving data packet processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121173596B_ABST
    Figure CN121173596B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a method and device for identifying malicious code hiding attack based on a trusted node network. A specific embodiment of the method comprises: determining the data packet credibility of a target data packet according to the data packet transmission path corresponding to the target data packet; in response to the data packet credibility being less than a first dynamic threshold, generating data packet features according to the target data packet and the data packet transmission path; generating a data packet risk probability for the target data packet according to the data packet features; in response to the data packet risk probability being greater than a second dynamic threshold, generating an isolated environment according to the node environment of a target network node; executing data packet operations corresponding to the target data packet in the isolated environment, and recording the environmental changes of the isolated environment through an environmental monitor; and identifying a hidden attack according to the environmental state information. The embodiment improves the data packet processing efficiency while ensuring the accuracy of identifying data packets containing malicious codes.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of computer technology, and in particular, to a malicious code hidden attack identification method and device based on a trusted node network. BACKGROUND

[0002] Malicious code refers to code that is harmful to computers, networks or servers, etc., which is usually spread through network channels, and affects the normal operation of computer systems, networks or servers through intrusion, damage or disablement, etc., and causes the stored data to be destroyed or leaked. At present, in the process of identifying malicious code, a zero trust model is usually used to identify data packets. However, in the scenario where the proportion of network traffic (data packets) containing malicious code is small, a large number of invalid identification processes exist, thereby affecting the data packet processing efficiency. SUMMARY

[0003] The summary section of the present application is used to introduce the concepts in a brief form, which will be described in detail in the specific embodiments section. The summary section of the present application is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.

[0004] Some embodiments of the present application propose a malicious code hidden attack identification method and device based on a trusted node network to solve the technical problems mentioned in the background section.

[0005] In a first aspect, some embodiments of the present application provide a method for identifying a malicious code hidden attack based on a trusted node network, the method comprising: in response to receiving a target data packet, determining a data packet trustworthiness of the target data packet according to a data packet transmission path corresponding to the target data packet, wherein the data packet transmission path comprises: a set of path nodes; a path node is a trusted network node included in the trusted node network or a non-trusted network node outside the trusted node network; in response to the data packet trustworthiness being less than a first dynamic threshold, generating a data packet feature according to the target data packet and the data packet transmission path, wherein the data packet feature is composed of a static data packet feature and a dynamic data packet feature; generating a data packet risk probability for the target data packet according to the data packet feature, wherein the data packet risk probability represents a probability that the target data contains malicious code; in response to the data packet risk probability being greater than a second dynamic threshold, generating an isolated environment according to a node environment of a target network node, wherein the target network node is a trusted network node corresponding to a destination address of the target data packet, and the isolated environment is provided with an environment listener; executing a data packet operation corresponding to the target data packet in the isolated environment, and recording an environment change of the isolated environment through the environment listener to generate environment state information; and identifying a hidden attack according to the environment state information to generate an attack identification result.

[0006] In a second aspect, some embodiments of the present application provide an apparatus for identifying a malicious code hidden attack based on a trusted node network, the apparatus comprising: a determination unit configured to, in response to receiving a target data packet, determine a data packet trustworthiness of the target data packet according to a data packet transmission path corresponding to the target data packet, wherein the data packet transmission path comprises: a set of path nodes; a path node is a trusted network node included in the trusted node network or a non-trusted network node outside the trusted node network;

[0007] The first generating unit is configured to generate a data packet feature according to the target data packet and the data packet transmission path in response to the data packet credibility being less than the first dynamic threshold, wherein the data packet feature is composed of a static data packet feature and a dynamic data packet feature; the second generating unit is configured to generate a data packet risk probability for the target data packet according to the data packet feature, wherein the data packet risk probability represents a probability that the target data contains malicious code; the twin generating unit is configured to generate an isolated environment according to a node environment of a target network node in response to the data packet risk probability being greater than a second dynamic threshold, wherein the target network node is a trusted network node corresponding to a destination address of the target data packet, and the isolated environment is correspondingly provided with an environment listener; the recording unit is configured to execute a data packet operation corresponding to the target data packet in the isolated environment, and record an environment change of the isolated environment through the environment listener to generate environment state information; and the hidden attack identification unit is configured to perform hidden attack identification according to the environment state information to generate an attack identification result.

[0008] In a third aspect, some embodiments of the present application provide an electronic device, including: one or more processors; a storage device having one or more programs stored thereon, when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any of the implementation manners of the first aspect.

[0009] In a fourth aspect, some embodiments of the present application provide a computer readable medium having a computer program stored thereon, wherein the program is executed by a processor to implement the method described in any of the implementation manners of the first aspect.

[0010] The above various embodiments of the present application have the following beneficial effects: through the malicious code hiding attack identification method based on the trusted node network of some embodiments of the present application, the data packet processing efficiency is improved under the premise of ensuring the accuracy of identifying data packets containing malicious codes. Specifically, the reason for low processing efficiency is that the zero trust model is based on "zero trust", and each data packet transmitted needs to be identified accordingly. However, in the scenario where the proportion of network traffic containing malicious codes is small, a large number of invalid identification processes exist. Based on this, the malicious code hiding attack identification method based on the trusted node network of some embodiments of the present application first determines the data packet credibility of the target data packet according to the data packet transmission path corresponding to the target data packet in response to receiving the target data packet, wherein the data packet transmission path includes a set of path nodes; the path node is a trusted network node included in the trusted node network or a non-trusted network node outside the trusted node network. In practice, different network nodes have different credibility, resulting in differences in the credibility of the corresponding sent data packets. Therefore, the present application divides the network nodes into trusted network nodes and non-trusted network nodes, and preliminarily judges the credibility of the data packet in combination with the non-trusted network nodes and trusted network nodes contained in the data transmission path corresponding to the (target) data packet. Secondly, in response to the data packet credibility being less than a first dynamic threshold, data packet features are generated according to the target data packet and the data packet transmission path, wherein the data packet features are composed of static data packet features and dynamic data packet features. Then, according to the data packet features, a data packet risk probability for the target data packet is generated, wherein the data packet risk probability represents the probability that the target data contains malicious codes. In practice, when the data packet credibility is less than the first dynamic threshold, the corresponding data packet feature extraction and data packet risk probability mapping are performed again. Compared with the zero trust model, through the division of network nodes and the setting of the first dynamic threshold, the normal data packet is "zero processed", thereby improving the data packet processing efficiency. Further, in response to the data packet risk probability being greater than a second dynamic threshold, an isolated environment is generated according to the node environment of the target network node, wherein the target network node is a trusted network node corresponding to the destination address of the target data packet, and the isolated environment is provided with an environment monitor. In addition, the data packet operation corresponding to the target data packet is executed in the isolated environment, and the environment changes of the isolated environment are recorded through the environment monitor to generate environment state information. In practice, part of the malicious code has higher concealment, and it is difficult to distinguish through the analysis of the data packet. Therefore, it is necessary to run the corresponding data packet operation in the real environment and listen to the influence on the environment. In order to avoid damage to the real environment, the isolated environment is constructed by using the twin method to run in the isolated environment. Finally, hidden attack identification is performed according to the environment state information to generate an attack identification result.In summary, the layered packet recognition is realized in this way, and especially the redundant recognition of the packet without malicious code is reduced, so that the packet processing efficiency is improved on the premise of ensuring the accuracy of the packet with malicious code. BRIEF DESCRIPTION OF DRAWINGS

[0011] The above and other features, aspects, and advantages of various embodiments of the present application will become more apparent with reference to the following detailed description and accompanying drawings. Identical or similar components shown throughout the figures are identified with the same or similar reference numerals. It is to be understood that the drawings are designed solely for purposes of illustration and not as a definition of the limits of the application.

[0012] Figure 1 is a flowchart of some embodiments of the method for recognizing a malicious code hiding attack based on a trusted node network according to the present application;

[0013] Figure 2 is a schematic diagram of the process of packet transmission to a trusted node network;

[0014] Figure 3 is a schematic diagram of the process of obtaining a node snapshot;

[0015] Figure 4 is a schematic diagram of the process of generating a local environment state feature;

[0016] Figure 5 is a schematic diagram of the process of generating an attack recognition result;

[0017] Figure 6 is a schematic diagram of the structure of some embodiments of the apparatus for recognizing a malicious code hiding attack based on a trusted node network according to the present application;

[0018] Figure 7 is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present application. DETAILED DESCRIPTION

[0019] Embodiments of the present application will be described below in greater detail with reference to the accompanying drawings. Although some embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms, and should not be interpreted as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided so as to more thoroughly and completely understand the present application. It should be understood that the drawings and embodiments of the present application are only for illustrative purposes, and are not intended to limit the scope of protection of the present application.

[0020] It should also be noted that, for the convenience of description, only the parts related to the present application are shown in the drawings. The embodiments in the present application and the features in the embodiments can be combined with each other without conflict.

[0021] It should be noted that the concepts of "first" and "second" mentioned in this invention are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0022] It should be noted that the terms "a" and "a plurality of" used in this invention are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0023] The names of the messages or information exchanged between the multiple devices in the embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of these messages or information.

[0024] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0025] refer to Figure 1 The present invention illustrates a flowchart 100 of some embodiments of a method for identifying malicious code hiding attacks based on a trusted node network according to the present invention. This method for identifying malicious code hiding attacks based on a trusted node network includes the following steps:

[0026] Step 101: In response to receiving the target data packet, determine the data packet credibility of the target data packet based on the data packet transmission path corresponding to the target data packet.

[0027] In some embodiments, the execution subject (e.g., a computing device) of the malicious code hiding attack identification method based on a trusted node network can determine the data packet trustworthiness of the target data packet based on the data packet transmission path corresponding to the target data packet in response to receiving the target data packet.

[0028] The aforementioned data packet transmission path includes: a set of path nodes. Path nodes are trusted network nodes included in the trusted node network or untrusted network nodes outside the trusted node network. A trusted node network is a network composed of trusted network nodes. Trusted network nodes are network nodes located within a trusted node network. Untrusted network nodes are network nodes located outside a trusted node network. The target data packet is a data packet to be transmitted to a trusted network node included in the trusted node network. Data packet trustworthiness characterizes the degree of trustworthiness of the target data packet.

[0029] In practice, the trusted network nodes in a trusted node network can jointly maintain a node address table. The node address table contains the node addresses (e.g., IP addresses) corresponding to each trusted network node in the trusted node network. Therefore, when any trusted network node in the trusted node network (e.g., a trusted network node located at the boundary of the trusted node network) receives a data packet, it can determine whether the data packet was sent to a trusted network node by checking the destination address of the data packet.

[0030] In practice, the more trusted node networks (path nodes) a target data packet passes through during transmission, the higher its credibility. Therefore, the credibility of a data packet can be mapped based on the proportion of path nodes in the path node set that are trusted node networks.

[0031] As an example, Figure 2 This diagram illustrates the process of data packet transmission to a trusted node network, which includes: trusted network nodes A1, A2, A3, A4, A5, A6, A7, A8, and A9. The data packet is transmitted via the Internet to trusted network node A2. Specifically, the data packet is first transmitted via the Internet to untrusted node B1, and then from untrusted node B1 to trusted network node A5. Since the trusted network nodes in the trusted node network jointly maintain a node address table, trusted network node A5, upon receiving the data packet, can determine whether the data packet was intended for a trusted network node within the trusted node network based on the destination address. Similarly, other trusted network nodes within the trusted node network can also use the same method to determine whether a data packet was intended for a trusted network node within the trusted node network upon receiving it.

[0032] It should be noted that the aforementioned computing device can be either hardware or software. When the computing device is hardware, it can be implemented as a distributed cluster composed of multiple servers or terminal devices, or as a single server or terminal device. When the computing device is software, it can be installed within the hardware devices listed above. It can be implemented as, for example, multiple software programs or software modules used to provide distributed services, or as a single software program or software module. No specific limitations are made here. In particular, the computing device can be a trusted network node located within a trusted node network. For example, the computing device can be a trusted network node located at the boundary of the trusted node network. In this case, the trusted network node located at the boundary can perform unified attack identification on data packets sent to the trusted node network. Alternatively, the computing device can be a trusted network node located within a trusted node network. In this case, any trusted network node within the trusted node network can perform attack identification on received data packets.

[0033] In some optional implementations of certain embodiments, the execution entity determines the data packet reliability of the target data packet based on the data packet transmission path corresponding to the target data packet, which may include the following steps:

[0034] Step S1: Generate a node identifier array.

[0035] The node identifier array mentioned above is initially empty. The node identifier array is a variable-length array. Specifically, the node identifier array can be implemented using a linked list.

[0036] Step S2: Based on the path node set and the node identifier array, perform the following identifier array update steps:

[0037] Step S21: Reverse the process and extract the path node at the end of the path node set as the target path node.

[0038] As an example, the set of path nodes can be [path node R1, path node R2, path node R3, path node R4, path node R5, path node R6, path node R7]. Path nodes R1, R2, and R5 can be untrusted network nodes, while path nodes R3, R4, R6, and R7 can be trusted network nodes. Therefore, in the first iteration, the target path node can be path node R7.

[0039] Step S22: In response to the node identity information corresponding to the target path node indicating that the target path node is an untrusted network node, add the first node identifier to the node identifier array to obtain the updated node identifier array, and end the above identifier array update step.

[0040] The first node identifier can be "-1". Node identity information represents the identity of the node corresponding to the path node. This node identity information can include: node type. The node type can represent whether the path node is a trusted network node or an untrusted network node.

[0041] Step S23: In response to the node identity information corresponding to the target path node indicating that the target path node is a trusted network node, add the second node identifier to the node identifier array to obtain the updated node identifier array, take the set of path nodes after removing the target path node as the path node set, take the updated node identifier array as the node identifier array, and re-execute the above identifier array update step.

[0042] The second node identifier can be "1". Specifically, the values ​​of the first node identifier and the second node identifier are different, and the specific values ​​are not limited as long as the first node identifier and the second node identifier are different.

[0043] As an example, since the target path node is path node R7 in the first iteration, the updated node identifier array is [1]. At this time, path node R7 can be removed from the path node set to form a new path node set. Since path node R5 is an untrusted network node, the identifier array update step ends after the third iteration, and the updated node identifier array is [-1,1,1].

[0044] Step S3: In response to the updated node identifier array having an array length of 1, the preset data packet confidence level is determined to be the aforementioned data packet confidence level.

[0045] Specifically, when the trusted node network is highly sensitive to target data packets sent by the untrusted node network, the preset data packet trustworthiness value can be set to a lower value (e.g., "0"). The preset data packet trustworthiness value can be in the range of [0, 0.5].

[0046] Step S4: In response to the updated node identifier array having an array length greater than 1, determine the identifier proportion.

[0047] The aforementioned identifier proportion represents the proportion of the second node identifier in the updated node identifier array.

[0048] As an example, the updated node identifier array is [-1,1,1], and the identifier ratio can be 2 / 3.

[0049] Step S5: Map the credibility of the identifier proportions to obtain the credibility of the above data packets.

[0050] In practice, analysis has shown that the value range of the identifier ratio is [0.5, 1). Therefore, the identifier ratio can be directly used as the corresponding data packet credibility.

[0051] Specifically, when a target data packet is transmitted through path nodes, it may be modified by those nodes, especially by path nodes from untrusted network nodes. Therefore, reconstructing the updated node identifier array in reverse can effectively determine the location of the target data packet when it was most recently transmitted through an untrusted path node. Meanwhile, since trusted network nodes are reliable, a higher percentage of identifiers indicates a higher frequency or probability of the target data packet being identified by trusted network nodes, making the corresponding data packet content more reliable.

[0052] Step 102: In response to the data packet confidence level being less than the first dynamic threshold, generate data packet characteristics based on the target data packet and the data packet transmission path.

[0053] In some embodiments, the execution entity may generate data packet characteristics based on the target data packet and the data packet transmission path in response to a data packet confidence level being less than a first dynamic threshold.

[0054] The data packet characteristics consist of static data packet characteristics and dynamic data packet characteristics. Static data packet characteristics represent a static description of the target data packet after decapsulation. Dynamic data packet characteristics represent a dynamic description of the transmission process corresponding to the target data packet.

[0055] In practice, the first dynamic threshold can be dynamically set based on the sensitivity of the trusted node network to risk. When the sensitivity is low, a higher threshold value can be set. When the sensitivity is high, a lower threshold value can be set.

[0056] As an example, static packet characteristics may include, but are not limited to: protocol type, message body specifications, and whether it has been tampered with. Dynamic packet characteristics may include, but are not limited to: the time interval between two adjacent path nodes transmitting the target packet, link status, and path node type.

[0057] In some optional implementations of certain embodiments, the execution entity generates data packet characteristics based on the target data packet and the data packet transmission path, including:

[0058] Step S1: Parse the target data packet to obtain the parsed data.

[0059] The parsed data includes the protocol type, protocol version, protocol-related field descriptions, and message body corresponding to different layers.

[0060] In practice, a seven-layer protocol model can be used to parse the target data packet and obtain the parsed data.

[0061] Step S2: Based on the keyword list, perform keyword matching on the parsed data to generate matching results.

[0062] The keyword list mentioned above is a pre-constructed list of words containing keywords targeting malicious code. The matching result includes: a matching identifier and a set of tuples. The matching identifier indicates whether the match is successful. The tuples include: keyword and word position, where the word position is the position of the keyword in the parsed data.

[0063] In practice, different malicious codes may contain different characteristics, such as specific keywords. Therefore, by constructing a keyword list, it is possible to quickly match the parsed data to determine whether it contains malicious code.

[0064] As an example, the WannaCry ransomware worm contains the special keyword "WNcry@2ol7" for file decompression.

[0065] Step S3: Extract the metadata information of the parsed data.

[0066] The metadata information may include, but is not limited to: source address, destination address, source port, destination port, ACK (Acknowledge Character) identifier, checksum identifier, window size value, data offset, and TCP (Transmission Control Protocol) identifier.

[0067] As an example, when parsing data packets layer by layer using a seven-layer protocol model, the corresponding protocol-related field descriptions can be extracted. From this, the protocol-related field descriptions and message bodies can be further extracted to obtain metadata information.

[0068] Step S4: Extract metadata features from the above metadata information to obtain metadata features.

[0069] In practice, the Word2Vec model can be used to encode metadata information and obtain metadata features.

[0070] Step S5: Scan the linked libraries associated with the parsed data to obtain a list of linked library description information.

[0071] The library description information may include, but is not limited to: library name, interface name, and calling protocol type. The library name represents the name of the linked library. The interface name represents the specific interface name within the linked library called during the resolution process. The calling protocol type represents the protocol type used to call the linked library.

[0072] In practice, during the parsing process of step S1 above, the link libraries used in different layers of parsing can be scanned to obtain a list of link library description information.

[0073] Step S6: Extract features from each link library description in the above list of link library description information to generate link library description features and obtain a set of link library description features.

[0074] In practice, to ensure that the library description features and metadata features reside in the same feature space, the Word2Vec model is also used to extract features from the library description information to generate library description features.

[0075] Step S7: Perform feature fusion on the above matching results, the above metadata features, and the above set of linked library description features to obtain the above static data packet features.

[0076] In practice, before feature fusion, the keywords included in the matching results need to be encoded using the Word2Vec model. Then, the encoded matching results, metadata features, and link library description feature set are concatenated to obtain static data packet features.

[0077] Step S8: Extract the path structure features of the above data packet transmission path as the dynamic data packet features.

[0078] In practice, dynamic data packet characteristics may include, but are not limited to, the time interval between two adjacent path nodes transmitting the target data packet, link status, and path node type. The time interval is a continuous value, while the link status and path node type are discrete identifiers. Therefore, the dynamic data packet characteristics can be obtained by normalizing the time interval between two adjacent path nodes transmitting the target data packet and then concatenating it with the link status and path node type.

[0079] Step 103: Generate the packet risk probability for the target packet based on the packet characteristics.

[0080] In some embodiments, the aforementioned execution entity may generate a data packet risk probability for a target data packet based on data packet characteristics.

[0081] Among them, the packet risk probability represents the probability that the target packet contains malicious code.

[0082] In practice, packet trustworthiness is only a preliminary judgment on whether the target data contains malicious code, based on the trustworthiness of the path nodes. Therefore, when the packet trustworthiness is less than the first dynamic threshold, further risk probability prediction is needed by combining the packet features corresponding to the target packet. Specifically, there are differences in the feature dimensions between static and dynamic packet features. In particular, the dimension of dynamic packet features increases dynamically as the packet transmission path grows. Therefore, based on the feature dimensions of static packet features, the dynamic packet features are processed by feature phasing and zero padding, and then concatenated with the static packet features to obtain the concatenated packet features. Finally, a pre-trained classifier is used as input to output the corresponding packet risk probability. The classifier can be a multi-classifier, trained through supervised training. The training samples can be constructed based on the collected packets and their corresponding transmission paths, and the training labels can be manually labeled based on the degree of harm to the trusted node network from the collected packets.

[0083] Step 104: In response to the packet risk probability being greater than the second dynamic threshold, an isolated environment is generated based on the node environment of the target network node.

[0084] In some embodiments, the aforementioned execution entity may generate an isolated environment twin based on the node environment of the target network node in response to a packet risk probability greater than a second dynamic threshold.

[0085] The target network node is a trusted network node corresponding to the destination address of the target data packet, and the isolation environment is equipped with an environment listener.

[0086] In practice, when the probability of a data packet risk determined by combining data packet characteristics exceeds a second dynamic threshold, it indicates a greater risk of the target data packet containing malicious code. Therefore, it is necessary to construct a virtual environment to execute data packet operations to determine whether the target data packet contains malicious behavior. Since the trusted network nodes in a trusted node network can jointly maintain a node address table, the target network node can be determined given the destination address of the target data packet. To avoid the risks associated with directly running data packet operations on the target network node, this invention generates an isolated environment based on the node environment of the target network node and executes data packet operations within this isolated environment. This prevents the target data packet from affecting the trusted node network when it contains malicious code. Specifically, a virtual machine can be used to construct a node environment identical to the target network node on the trusted network node that receives the target data packet, serving as the isolated environment.

[0087] In some optional implementations of certain embodiments, the aforementioned execution entity generates an isolated environment twin based on the node environment of the target network node, including:

[0088] Step S1: Determine the twin pattern.

[0089] The aforementioned twin modes include: local twin mode and remote twin mode. Local twin mode represents building an isolated environment on a trusted network node that receives the target data packet. Remote twin mode represents building an isolated environment on a trusted network node dedicated to building the isolated environment.

[0090] In practice, a trusted network node that receives the target data packet may not meet the requirements for creating an isolation environment. For example, insufficient computing power may prevent the creation of an isolation environment. Therefore, it is necessary to determine the specific twin mode by combining the computing power of the trusted network node that received the target data packet with the computing power requirements for creating the isolation environment corresponding to the target network node. Furthermore, to reduce the need to determine whether the computing power requirements match, the twin mode of each trusted network node can be uniformly set to remote twin mode by default.

[0091] Step S2: In response to the above twin mode being a local twin mode, send a first snapshot acquisition request to the above target network node.

[0092] The first snapshot acquisition request is used to request a corresponding node snapshot from the target network node, and the node snapshot represents the node environment of the target network node.

[0093] In practice, since the trusted network nodes in a trusted node network can jointly maintain a node address table, the node address of the target network node can be determined. Therefore, the node address of the target network node can be used as the destination address to send a first snapshot acquisition request to the target network node.

[0094] Step S3: In response to receiving the node snapshot sent by the target network node, a local twin is generated based on the node snapshot to obtain the isolation environment.

[0095] In practice, when the twin mode is local twin mode, an isolated environment can be generated locally on the trusted network node that received the target data packet by constructing a virtual environment and combining it with node snapshots. The isolated environment is isolated from the actual operating environment of the trusted network node that received the target data packet, thus preventing the node security of the trusted network node from being affected when the target data packet contains malicious code. Furthermore, when the node environment of the target network node changes, an incremental snapshot can be generated and sent to the trusted network node running the isolated environment (either the trusted network node that received the target data packet or the trusted network node that is the isolated network node). Moreover, there is unidirectional isolation between the isolated environment and the node environment of the target network node; that is, data packet operations corresponding to the target data packet in the isolated environment will not be transmitted back to the target network node.

[0096] Step S4: In response to the above twin mode being a remote twin mode, request the isolation of network nodes.

[0097] Among them, the isolated network node is a trusted network node specifically generated for the isolated environment.

[0098] In practice, an isolated network node can be requested from the control node corresponding to the trusted node network and used for controlling the trusted node network. The control node can be one of the trusted network nodes.

[0099] As an example, see further. Figure 2 In this system, trusted network node A7 can act as the control node, and trusted network node A8 can act as the isolation node. Therefore, trusted network node A5 can request the use of the isolation node (trusted network node A8) from the control node (trusted network node A7).

[0100] Step S5: In response to the successful application, send a second snapshot acquisition request to the aforementioned target network node.

[0101] The second snapshot request is a first snapshot request whose source address is redirected to the isolated network node. Upon receiving the node snapshot, the isolated network node generates a local twin to obtain the isolated environment.

[0102] In practice, since trusted network nodes within a trusted node network can jointly maintain a node address table, assuming a successful isolation node application, the trusted network node receiving the target data packet knows the node address corresponding to the isolation network node. Simultaneously, the trusted network node receiving the data packet knows the isolation network node corresponding to the destination address of the target data packet. Therefore, the isolation network node can intercept the first snapshot retrieval request sent by the trusted network node receiving the target data packet, redirect the original address of the first snapshot retrieval request, and send it to the isolation network node. It then establishes a communication link with the isolation network node through a three-way handshake, thereby receiving the node snapshot sent by the target network node and directly creating an isolation environment on the isolation network node based on the node snapshot.

[0103] As an example, see Figure 3 The diagram illustrates the node snapshot acquisition process. Trusted network node A5 can be the trusted network node receiving the target data packet, trusted network node A8 can be the isolated network node, and trusted network node A2 can be the target network node. First, trusted network node A5 sends a first snapshot acquisition request to trusted network node A2. Second, trusted network node A8 intercepts the first snapshot acquisition request and redirects the source address of the first snapshot acquisition request to its own node address, using this as the second snapshot acquisition request, and sends it to trusted network node A2. Next, according to the TCP (Transmission Control Protocol) protocol, a communication connection is established between trusted network node A8 and trusted network node A2 through a three-way handshake, and the node snapshot sent by trusted network node A2 is received. Further, after receiving the node snapshot, trusted network node A8 creates an isolated environment based on the node snapshot. Since all trusted network nodes in the trusted node network are trustworthy, by intercepting and redirecting requests, a communication connection can be directly established between the isolated network node and the target network node in remote twin mode, and the node snapshot can be directly transmitted. In particular, in remote twin mode, the first snapshot acquisition request can include the target data packet, so that the isolated network node can directly obtain the target data packet after intercepting the first snapshot request, thereby eliminating the need to create a communication connection with the trusted network node that created and received the target data packet, thus reducing the number of communication connection creations.

[0104] Step 105: Execute the data packet operation corresponding to the target data packet in the isolated environment, and record the environmental changes of the isolated environment through the environment listener to generate environmental status information.

[0105] In some embodiments, the aforementioned execution entity can perform data packet operations corresponding to the target data packet within an isolated environment, and record environmental changes in the isolated environment through an environment listener to generate environmental status information.

[0106] In practice, when the twin mode is local twin mode, the environment listener is set on the trusted network node that receives the target data packet. When the twin mode is remote twin mode, the environment listener is set on the isolated network node. Specifically, the environment listener can monitor environmental changes in the isolated environment through process monitoring, especially the environmental changes before and after the execution of the data packet operation corresponding to the target data packet.

[0107] In some optional implementations of certain embodiments, the execution entity performs data packet operations corresponding to the target data packet within the isolated environment, and records environmental changes in the isolated environment through an environment listener to generate environmental state information, including:

[0108] Step S1: Using the environment listener, generate operation log records for the data packets corresponding to the target data packets mentioned above, and obtain the operation log record sequence.

[0109] In practice, after the data packet operation corresponding to the target data packet is executed, the environment listener will monitor newly generated or changed processes. For newly generated processes, it will directly generate corresponding operation log records. For changed processes, it will record the changes before and after the process as corresponding operation log records.

[0110] Step S2: Extract the content of the operation log records in the above operation log record sequence to obtain the above environment status information.

[0111] In practice, after the operation of the target data packet is executed, multiple operation log records will be generated directly or in association. Due to the stealth of malicious code execution and the fact that malicious code mainly aims to illegally obtain permissions, illegally tamper with and obtain data, it is possible to extract operation log records that are related to the malicious code's corresponding behavior, such as permission changes, data changes, data acquisition, and network behavior, from the operation log record sequence as environmental status information.

[0112] Step 106: Identify hidden attacks based on environmental status information to generate attack identification results.

[0113] In some embodiments, the aforementioned execution entity can perform covert attack identification based on environmental state information to generate attack identification results.

[0114] Among them, the attack identification result represents the identification result of whether the operation of the target data packet corresponding to the data packet is executed in the isolated environment.

[0115] In practice, by decoupling static analysis (data packet credibility and data packet risk probability analysis) and dynamic analysis (attack identification result analysis), the identification can be carried out selectively layer by layer according to the risk level, which can effectively alleviate the pressure of data packet identification.

[0116] In some optional implementations of certain embodiments, the execution entity performs covert attack identification based on the aforementioned environmental state information to generate an attack identification result, including:

[0117] Step S1: Extract environmental status index values ​​from the above environmental status information to obtain an environmental status index value matrix.

[0118] In this matrix, the vertical dimension corresponds to different environmental status indicators, and the horizontal dimension corresponds to the change of the same environmental status indicator over time. Environmental status indicators may include: data permission status indicators, cache status indicators, memory status indicators, external storage status indicators, and channel occupancy indicators.

[0119] In practice, environmental status information can be used to determine whether changes in environmental status indicators are triggered. When a change is triggered, it is horizontally filled into the environmental status indicator value matrix according to the time dimension, thus obtaining the environmental status indicator value matrix. In particular, multiple changes in environmental status indicators may be triggered under the same time dimension. In this case, the indicator values ​​of the multiple triggered environmental status indicators correspond to the same time dimension, thus ensuring time alignment among the indicator values ​​of multiple environmental status indicators triggered under the same time dimension.

[0120] Step S2: Extract features from the above environmental state index value matrix to generate environmental state features.

[0121] In practice, malicious code execution is often covert, potentially executing by modifying normal operations or concealing itself behind numerous normal operations. The environmental state indicator matrix describes the overall environmental state changes after the execution of operations corresponding to the target data packet. Therefore, directly using the environmental state indicator matrix as input might lead to overlooking malicious operations due to an excessively large receptive field. Thus, for each environmental state indicator, the environmental state indicator matrix is ​​vertically segmented with the start and end times of the corresponding indicator value change process as the horizontal dimension, thereby obtaining local environmental state features under multiple small receptive fields, which are then used as the environmental state features.

[0122] As an example, see Figure 4 The diagram illustrates the generation process of local environmental state features, where the matrix dimension of the environmental state index value matrix can be 7×6. Figure 6The environmental status index value matrix represents the values ​​of seven different environmental status indicators as they change over time. The horizontal dimension corresponds to the time dimension, while the vertical dimension corresponds to different environmental status indicators.

[0123] Specifically, the seven different environmental status indicators are: Environmental Status Indicator Q1, Environmental Status Indicator Q2, Environmental Status Indicator Q3, Environmental Status Indicator Q4, Environmental Status Indicator Q5, and Environmental Status Indicator Q6. Among them, the indicator values ​​corresponding to Environmental Status Indicator Q1 are [Indicator Value S11, Indicator Value S11, Indicator Value S12, Indicator Value S12, Indicator Value S12, Indicator Value S13, Indicator Value S13]. The indicator values ​​corresponding to Environmental Status Indicator Q2 are [Indicator Value S21, Indicator Value S21, Indicator Value S21, Indicator Value S21, Indicator Value S22, Indicator Value S23, Indicator Value S23]. The indicator values ​​corresponding to Environmental Status Indicator Q3 are [Indicator Value S31, Indicator Value S32, Indicator Value S32, Indicator Value S32, Indicator Value S32, Indicator Value S32]. The values ​​for environmental status indicator Q4 are [Indicator value S41, Indicator value S41, Indicator value S41, Indicator value S42, Indicator value S42, Indicator value S42]. The values ​​for environmental status indicator Q5 are [Indicator value S51, Indicator value S52, Indicator value S52, Indicator value S52, Indicator value S52, Indicator value S52]. The values ​​for environmental status indicator Q6 are [Indicator value S61, Indicator value S62, Indicator value S62, Indicator value S63, Indicator value S63, Indicator value S63, Indicator value S64].

[0124] Taking environmental state index Q1 as an example, the corresponding index value changed three times. Therefore, using the start and end times of the index value change process corresponding to environmental state index Q1 as the horizontal dimension, the environmental state index value matrix is ​​vertically segmented to obtain three local environmental state features. The corresponding feature dimensions are 2×6, 3×6, and 2×6, respectively. The three local environmental state features are: [[Indicator value S11, Indicator value S11], [Indicator value S21, Indicator value S21], [Indicator value S31, Indicator value S32], [Indicator value S41, Indicator value S41], [Indicator value S51, Indicator value S52], [Indicator value S61, Indicator value S62]], [[Indicator value S11, Indicator value S11], [ ... 2. Indicator values ​​S12, S21, S22, S32, S41, S52, S62, S63, S64] and S13, S23, S32, S42, S52, S63, S64]. Similarly, for the environmental state indicator Q2, three local environmental state features are obtained, with corresponding feature dimensions of 4×6, 1×6, and 2×6, respectively. For environmental state indicator Q3, two local environmental state features are obtained, with corresponding feature dimensions of 1×6 and 6×6, respectively. For environmental state indicator Q4, two local environmental state features are obtained, with corresponding feature dimensions of 3×6 and 4×6, respectively. For environmental state indicator Q5, two local environmental state features are obtained, with corresponding feature dimensions of 1×6 and 6×6, respectively. For environmental state indicator Q6, four local environmental state features are obtained, with corresponding feature dimensions of 1×6, 2×6, 3×6, and 1×6, respectively. In summary, for... Figure 4 Sixteen local environmental state features can be extracted and used as environmental state features.

[0125] Step S3: Based on the above environmental state characteristics and the pre-trained hidden attack identification model, generate the above attack identification results.

[0126] In practice, the hidden attack detection model includes K encoders, one decoder, and an attack detection result classifier. Each of the K encoders corresponds to an environment state indicator; that is, each encoder is responsible for independently encoding each environment state feature from at least one local environment state feature corresponding to its environment state indicator, obtaining an encoded vector. Both the encoders and decoder adopt a Transformer-based structure. The attack detection result classifier is a multi-classifier.

[0127] As an example, see Figure 5 The diagram illustrates the generation process of the attack identification result. The K encoders are: Encoder E1, Encoder E2, Encoder E3, Encoder E4, Encoder E5, and Encoder E6. Encoder E1 corresponds to the environment state indicator Q1, encoding the three local environment state features corresponding to Q1 to obtain three encoding vectors. Encoder E2 corresponds to the environment state indicator Q2, encoding the three local environment state features corresponding to Q2 to obtain three encoding vectors. Encoder E3 corresponds to the environment state indicator Q3, encoding the two local environment state features corresponding to Q3 to obtain two encoding vectors. Encoder E4 corresponds to the environment state indicator Q4, encoding the two local environment state features corresponding to Q4 to obtain two encoding vectors. Encoder E5 corresponds to the environment state indicator Q5, encoding the two local environment state features corresponding to Q5 to obtain two encoding vectors. Encoder E6 corresponds to the environmental state indicator Q6, encoding the four local environmental state features corresponding to Q6 to obtain four encoded vectors. Therefore, a total of 16 encoded vectors are obtained. These 16 encoded vectors are concatenated and used as input to the decoder to obtain the decoded vector. The decoded vector is then input to the attack identification result classifier to obtain the classification vector. The classification vector corresponds to the confidence level of different attack types; specifically, the attack type with the highest confidence level is used as the attack identification result. This method achieves state encoding, decoding, and classification from the perspective of environmental state indicators. By dynamically controlling the feature size in conjunction with state changes, compared to the conventional fixed convolutional kernel size approach, it pays more attention to the state changes of independent environmental state indicators. Simultaneously, by retaining the changes of other environmental state indicators during the state change process of independent environmental state indicators, it avoids the problem of insufficient attention to changes in other environmental state indicators due to an excessively small receptive field, thus ensuring the effectiveness of the classification results.

[0128] In some optional implementations of some embodiments, the above method further includes:

[0129] Step S1: In response to the attack identification result indicating that the target data packet is abnormal, the following processing steps are performed:

[0130] Step S22: Discard the target data packets mentioned above.

[0131] In practice, a trusted network node that receives a target data packet can discard the target data packet to stop further packet forwarding.

[0132] Step S23: Determine whether the starting address of the target data packet is in the address gray list.

[0133] In practice, a trusted node network comprises trusted network nodes that jointly maintain an address gray list. This gray list stores the source address corresponding to the first occurrence of a packet anomaly. Therefore, by using the address gray list, it can be determined whether the starting address of a target packet has previously sent a packet with an anomaly.

[0134] Step S24: In response to the fact that the starting address of the target data packet is in the address gray list, remove the starting address of the target data packet from the address gray list and add the starting address of the target data packet to the address black list to obtain the updated address gray list and the updated address black list.

[0135] The address blacklist can be a list of addresses jointly maintained by trusted network nodes in a trusted node network, used to store the source addresses corresponding to data packets that have repeatedly shown abnormalities.

[0136] Step S25: Distribute the updated address gray list and the updated address black list to the trusted network nodes included in the trusted node network.

[0137] Step S26: In response to the data packet's credibility being greater than or equal to the first dynamic threshold or the data packet's risk probability being less than or equal to the second dynamic threshold, the target data packet is forwarded.

[0138] In practice, the target data packet can be forwarded directly to the target network node. Alternatively, depending on the network status of the trusted node network, the target data packet can be forwarded to the target network node via multi-hop transmission.

[0139] The above embodiments of the present invention have the following beneficial effects: The malicious code hiding attack identification method based on trusted node networks of some embodiments of the present invention improves data packet processing efficiency while ensuring the accuracy of identifying data packets containing malicious code. Specifically, the reason for low processing efficiency is that the zero-trust model, based on "zero trust," requires corresponding identification of each transmitted data packet. However, in scenarios where the proportion of network traffic containing malicious code is relatively small, this leads to a large number of invalid identification processes. Therefore, the malicious code hiding attack identification method based on trusted node networks of some embodiments of the present invention first, in response to receiving a target data packet, determines the data packet trustworthiness of the target data packet according to the data packet transmission path corresponding to the target data packet. The data packet transmission path includes: a set of path nodes; the path nodes are trusted network nodes included in the trusted node network or untrusted network nodes outside the trusted node network. In practice, different network nodes have different trustworthiness, resulting in differences in the trustworthiness of corresponding transmitted data packets. Therefore, the present invention preliminarily judges the trustworthiness of data packets by dividing network nodes into trusted and untrusted network nodes and combining the untrusted and trusted network nodes contained in the data transmission path corresponding to the (target) data packet. Secondly, in response to the data packet's credibility being less than a first dynamic threshold, data packet features are generated based on the target data packet and its transmission path. These features consist of static and dynamic characteristics. Next, based on these features, a data packet risk probability is generated for the target data packet, where the risk probability represents the probability that the target data packet contains malicious code. In practice, when the data packet's credibility is less than the first dynamic threshold, corresponding data packet feature extraction and risk probability mapping are performed. Compared to the zero-trust model, by dividing network nodes and setting the first dynamic threshold, "zero processing" of normal data packets is achieved, thereby improving data packet processing efficiency. Further, in response to the data packet risk probability being greater than a second dynamic threshold, an isolated environment is generated based on the target network node's node environment. The target network node is a trusted network node corresponding to the destination address of the target data packet, and an environment listener is configured in the isolated environment. Additionally, data packet operations corresponding to the target data packet are executed within the isolated environment, and environmental changes in the isolated environment are recorded by the environment listener to generate environmental state information. In practice, some malicious code possesses higher levels of concealment, making it difficult to identify solely through packet analysis. Therefore, it is necessary to run the corresponding packet operations in a real-world environment and monitor their impact. To avoid damaging the real-world environment, a twin approach is employed to construct an isolated environment, which is then used for isolated execution. Finally, based on the aforementioned environmental state information, stealth attack identification is performed to generate attack identification results.In summary, this method achieves hierarchical packet identification, especially reducing redundant identification of packets that do not contain malicious code, thereby improving packet processing efficiency while ensuring the accuracy of identifying packets containing malicious code.

[0140] Further reference Figure 6 As an implementation of the methods shown in the above figures, the present invention provides some embodiments of a malicious code hiding attack identification device based on a trusted node network. These device embodiments are similar to... Figure 1 Corresponding to the method embodiments shown, this malicious code hiding attack identification device based on trusted node networks can be specifically applied to various electronic devices.

[0141] like Figure 6 As shown, a malicious code hiding attack identification device 600 based on a trusted node network in some embodiments includes: a determining unit 601, a first generating unit 602, a second generating unit 603, a twin generating unit 604, a recording unit 605, and a hiding attack identification unit 606. The determining unit 601 is configured to, in response to receiving a target data packet, determine the data packet trustworthiness of the target data packet based on the data packet transmission path corresponding to the target data packet. The data packet transmission path includes a set of path nodes; the path nodes are trusted network nodes included in the trusted node network or untrusted network nodes outside the trusted node network. The first generating unit 602 is configured to, in response to the data packet trustworthiness being less than a first dynamic threshold, generate data packet features based on the target data packet and the data packet transmission path. The data packet features consist of static data packet features and dynamic data. The system comprises: a packet feature set; a second generation unit 603 configured to generate a packet risk probability for the target packet based on the packet features, wherein the packet risk probability represents the probability that the target packet contains malicious code; a twin generation unit 604 configured to generate an isolated environment based on the node environment of the target network node in response to the packet risk probability being greater than a second dynamic threshold, wherein the target network node is a trusted network node corresponding to the destination address of the target packet, and the isolated environment is equipped with an environment listener; a recording unit 605 configured to perform packet operations corresponding to the target packet within the isolated environment and record environmental changes of the isolated environment through the environment listener to generate environment state information; and a hidden attack identification unit 606 configured to perform hidden attack identification based on the environment state information to generate an attack identification result.

[0142] It is understandable that the units described in the malicious code hiding attack identification device 600 based on a trusted node network are similar to those in the reference device. Figure 1The steps in the described method correspond to each other. Therefore, the operations, features, and beneficial effects described above for the method are also applicable to the malicious code hiding attack identification device 600 based on trusted node networks and the units contained therein, and will not be repeated here.

[0143] The following is for reference. Figure 7 It shows a schematic diagram of the structure of an electronic device (e.g., a computing device) suitable for implementing some embodiments of the present invention. Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality or scope of the embodiments of the present invention. Figure 7 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The memory may include a non-volatile storage medium and internal memory. The non-volatile storage medium may store an operating system and a computer program. The computer program includes program instructions that, when executed, cause the processor to perform any of the methods described above. The processor provides computational and control capabilities to support the operation of the entire computer device. The internal memory provides an environment for the execution of the computer program in the non-volatile storage medium; when executed by the processor, the computer program causes the processor to perform any of the methods described above. The network interface is used for network communication, such as sending assigned tasks. Those skilled in the art will understand that... Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present invention and does not constitute a limitation on the computer device to which the present invention is applied. A specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0144] It should be understood that the processor can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among these, a general-purpose processor can be a microprocessor or any conventional processor.

[0145] In one embodiment, the processor is configured to run a computer program stored in a memory to perform the following steps: In response to receiving a target data packet, determining the data packet trustworthiness of the target data packet based on the data packet transmission path corresponding to the target data packet, wherein the data packet transmission path includes: a set of path nodes; the path nodes are trusted network nodes included in a trusted node network or untrusted network nodes outside the trusted node network; In response to the data packet trustworthiness being less than a first dynamic threshold, generating data packet features based on the target data packet and the data packet transmission path, wherein the data packet features consist of static data packet features and dynamic data packet features; Generating a data packet risk probability for the target data packet based on the data packet features, wherein the data packet risk probability characterizes the probability that the target data packet contains malicious code; In response to the data packet risk probability being greater than a second dynamic threshold, generating an isolated environment based on the node environment of the target network node, wherein the target network node is a trusted network node corresponding to the destination address of the target data packet, and the isolated environment is equipped with an environment listener; Executing data packet operations corresponding to the target data packet within the isolated environment, and recording environmental changes in the isolated environment through the environment listener to generate environment state information; Performing stealth attack identification based on the environment state information to generate attack identification results.

[0146] This invention also provides a computer-readable storage medium storing a computer program, the computer program including program instructions, and the method implemented when the program instructions are executed can be referred to the various embodiments of the above methods of this invention.

[0147] The aforementioned computer-readable storage medium may be an internal storage unit of the computer device described in the foregoing embodiments, such as a hard disk or memory of the computer device. Alternatively, the aforementioned computer-readable storage medium may be an external storage device of the computer device, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the computer device.

[0148] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0149] The above description is merely a selection of preferred embodiments of the present invention and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention as described in the embodiments is not limited to specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of the present invention.

Claims

1. A method for identifying malicious code hiding attacks based on trusted node networks, characterized in that, include: In response to receiving a target data packet, the data packet trustworthiness of the target data packet is determined according to the data packet transmission path corresponding to the target data packet, wherein the data packet transmission path includes: a set of path nodes; the path nodes are trusted network nodes included in the trusted node network or untrusted network nodes outside the trusted node network; In response to the data packet's credibility being less than a first dynamic threshold, a data packet feature is generated based on the target data packet and the data packet's transmission path. The data packet feature consists of static data packet features and dynamic data packet features. The static data packet feature represents a static description of the target data packet after decapsulation, while the dynamic data packet feature represents a dynamic description of the transmission process corresponding to the target data packet. Based on the data packet characteristics, a data packet risk probability is generated for the target data packet, wherein the data packet risk probability represents the probability that the target data packet contains malicious code; In response to the data packet risk probability being greater than a second dynamic threshold, an isolation environment is generated based on the node environment of the target network node, wherein the target network node is a trusted network node corresponding to the destination address of the target data packet, and the isolation environment is equipped with an environment listener. Within the isolated environment, perform data packet operations corresponding to the target data packet, and record environmental changes in the isolated environment through an environment listener to generate environmental status information; Based on the environmental state information, a concealment attack is identified to generate an attack identification result, including: Environmental status index values ​​are extracted from the environmental status information to obtain an environmental status index value matrix. The vertical dimension of the environmental status index value matrix corresponds to different environmental status indicators, and the horizontal dimension of the environmental status index value matrix corresponds to the index value changes of the same environmental status indicator along the time dimension. The environmental status indicators include: data permission status indicators, cache status indicators, memory status indicators, external storage status indicators, and channel occupancy indicators. The environmental state index value matrix is ​​subjected to feature extraction to generate environmental state features, including: for each environmental state index, the environmental state index value matrix is ​​vertically segmented with the start and end time of the corresponding index value change process as the horizontal dimension, so as to obtain local environmental state features under multiple small receptive fields, which are used as environmental state features. Based on the environmental state features and the pre-trained hidden attack identification model, the attack identification result is generated. The hidden attack identification model includes K encoders, 1 decoder, and an attack identification result classifier. Each encoder in the K encoders corresponds to an environmental state index. Each encoder is responsible for independently encoding each environmental state feature in at least one local environmental state feature corresponding to the corresponding environmental state index to obtain an encoding vector. Both the encoder and the decoder adopt a Transformer-based structure, and the attack identification result classifier is a multi-classifier.

2. The method for identifying malicious code hiding attacks based on trusted node networks according to claim 1, characterized in that, The method further includes: In response to the attack identification result indicating that the target data packet has a data packet anomaly, the following processing steps are performed: The target data packet is discarded; Determine whether the starting address of the target data packet is in the address graylist; In response to the fact that the starting address of the target data packet is in the address gray list, the starting address of the target data packet is removed from the address gray list and the starting address of the target data packet is added to the address black list, resulting in an updated address gray list and an updated address black list. The updated address gray list and the updated address black list are synchronously distributed to the trusted network nodes included in the trusted node network; In response to the data packet's credibility being greater than or equal to a first dynamic threshold or the data packet's risk probability being less than or equal to a second dynamic threshold, the target data packet is forwarded.

3. The method for identifying malicious code hiding attacks based on trusted node networks according to claim 2, characterized in that, The step of determining the data packet reliability of the target data packet based on the data packet transmission path corresponding to the target data packet includes: Generate a node identifier array, wherein the node identifier array is initially an empty array; Based on the set of path nodes and the array of node identifiers, perform the following identifier array update steps: Reverse the process and extract the path node at the end of the path node set as the target path node; In response to the node identity information corresponding to the target path node indicating that the target path node is an untrusted network node, the first node identifier is added to the node identifier array to obtain the updated node identifier array, and the identifier array update step is ended. In response to the node identity information corresponding to the target path node indicating that the target path node is a trusted network node, the second node identifier is added to the node identifier array to obtain the updated node identifier array, the set of path nodes after removing the target path node is used as the path node set, the updated node identifier array is used as the node identifier array, and the identifier array update step is re-executed. In response to the updated node identifier array having an array length of 1, the preset data packet confidence level is determined as the data packet confidence level; In response to the updated node identifier array having an array length greater than 1, an identifier proportion is determined, wherein the identifier proportion represents the proportion of the second node identifier in the updated node identifier array; The credibility of the data packet is obtained by mapping the credibility ratio of the identifiers.

4. The method for identifying malicious code hiding attacks based on trusted node networks according to claim 3, characterized in that, The step of generating data packet characteristics based on the target data packet and the data packet transmission path includes: The target data packet is parsed to obtain the parsed data; Based on the keyword list, keyword matching is performed on the parsed data to generate matching results. The keyword list is a pre-constructed word list containing keywords targeting malicious code. The matching results include: a matching identifier and a set of tuples. The matching identifier indicates whether the match is successful. The tuples include: keyword and word position, where the word position is the position of the keyword in the parsed data. Extract the metadata information of the parsed data; Metadata features are extracted from the metadata information to obtain metadata features; Scan the linked libraries associated with the parsed data to obtain a list of linked library description information; Feature extraction is performed on each link library description in the list of link library description information to generate link library description features, resulting in a set of link library description features; The static data packet features are obtained by fusing the matching results, the metadata features, and the set of linked library description features. The path structure features of the data packet transmission path are extracted and used as the dynamic data packet features.

5. The method for identifying malicious code hiding attacks based on trusted node networks according to claim 4, characterized in that, The step of performing the data packet operation corresponding to the target data packet within the isolated environment, and recording environmental changes in the isolated environment through an environment listener to generate environmental state information, includes: An environment listener is used to generate operation log records for the data packet operations corresponding to the target data packet, resulting in an operation log record sequence. The environmental status information is obtained by extracting the content of the operation log records in the operation log record sequence.

6. The method for identifying malicious code hiding attacks based on trusted node networks according to claim 5, characterized in that, The step of generating an isolated environment based on the node environment of the target network node includes: Determine the twin mode, wherein the twin mode includes: a local twin mode and a remote twin mode; In response to the twin mode being a local twin mode, a first snapshot acquisition request is sent to the target network node, wherein the first snapshot acquisition request is used to request a corresponding node snapshot from the target network node, and the node snapshot represents the node environment of the target network node; In response to receiving the node snapshot sent by the target network node, a local twin is generated based on the node snapshot to obtain the isolated environment; In response to the twin mode being a remote twin mode, an isolated network node is requested, wherein the isolated network node is a trusted network node specifically generated for the isolated environment; In response to a successful application, a second snapshot acquisition request is sent to the target network node. The second snapshot acquisition request is a first snapshot acquisition request whose source address is redirected to the isolated network node. The isolated network node performs local twin generation after receiving the node snapshot to obtain the isolated environment.

7. A malicious code hiding attack identification device based on a trusted node network, characterized in that, include: The determining unit is configured to, in response to receiving a target data packet, determine the data packet trustworthiness of the target data packet based on the data packet transmission path corresponding to the target data packet, wherein the data packet transmission path includes: a set of path nodes; the path nodes are trusted network nodes included in the trusted node network or untrusted network nodes outside the trusted node network; The first generation unit is configured to generate data packet features based on the target data packet and the data packet transmission path in response to the data packet confidence level being less than a first dynamic threshold. The data packet features consist of static data packet features and dynamic data packet features. The static data packet features characterize a static description of the target data packet after decapsulation, and the dynamic data packet features characterize a dynamic description of the transmission process corresponding to the target data packet. The second generation unit is configured to generate a data packet risk probability for the target data packet based on the data packet characteristics, wherein the data packet risk probability characterizes the probability that the target data packet contains malicious code; The twin generation unit is configured to generate an isolated environment based on the node environment of the target network node in response to the data packet risk probability being greater than a second dynamic threshold. The target network node is a trusted network node corresponding to the destination address of the target data packet, and the isolated environment is equipped with an environment listener. The recording unit is configured to perform data packet operations corresponding to the target data packet within the isolated environment, and to record environmental changes in the isolated environment through an environment listener to generate environmental status information; A concealed attack identification unit is configured to identify concealed attacks based on the environmental state information to generate an attack identification result, including: Environmental status index values ​​are extracted from the environmental status information to obtain an environmental status index value matrix. The vertical dimension of the environmental status index value matrix corresponds to different environmental status indicators, and the horizontal dimension of the environmental status index value matrix corresponds to the index value changes of the same environmental status indicator along the time dimension. The environmental status indicators include: data permission status indicators, cache status indicators, memory status indicators, external storage status indicators, and channel occupancy indicators. The environmental state index value matrix is ​​subjected to feature extraction to generate environmental state features, including: for each environmental state index, the environmental state index value matrix is ​​vertically segmented with the start and end time of the corresponding index value change process as the horizontal dimension, so as to obtain local environmental state features under multiple small receptive fields, which are used as environmental state features. Based on the environmental state features and the pre-trained hidden attack identification model, the attack identification result is generated. The hidden attack identification model includes K encoders, 1 decoder, and an attack identification result classifier. Each encoder in the K encoders corresponds to an environmental state index. Each encoder is responsible for independently encoding each environmental state feature in at least one local environmental state feature corresponding to the corresponding environmental state index to obtain an encoding vector. Both the encoder and the decoder adopt a Transformer-based structure, and the attack identification result classifier is a multi-classifier.

8. An electronic device, characterized in that, include: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the malicious code hiding attack identification method based on trusted node networks as described in any one of claims 1 to 6.

9. A computer-readable medium, characterized in that, It stores a computer program, wherein the computer program, when executed by a processor, implements the malicious code hiding attack identification method based on a trusted node network as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Malicious code dynamic detection method and apparatus

    CN106228067A

  • Method for quickly and accurately identifying abnormal attack IP address

    CN115694950A