System and method for verifying a digital signature of a file
The system and method for verifying digital signatures through a certificate and credential database effectively addresses the inaccuracies and vulnerabilities in existing antivirus technologies, enhancing security and reducing false positives by authenticating and validating digital signatures.
Patent Information
- Application Number
- JP2024140752
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-09-06
- Filing Date
- 2024-08-22
- Publication Date
- 2026-01-13
- Estimated Expiration
- 2039-11-21
AI Technical Summary
Existing antivirus technologies face challenges in accurately verifying digital signatures, leading to high rates of false positives (Type I errors) and failures to identify malicious files (Type II errors), with current methods being slow and vulnerable to attacks.
A system and method for verifying digital signatures that includes a certificate database and credential database to authenticate and validate digital signature certificates, ensuring integrity and trustworthiness of files, using hardware and software tools to classify files as trusted or untrusted.
This approach significantly reduces Type I errors by accurately verifying digital signatures, enhances security by detecting and preventing malicious files, and provides faster verification processes compared to conventional systems.
Smart Images

Figure 0007797587000001 
Figure 0007797587000002 
Figure 0007797587000003
Abstract
Description
[Technical Field]
[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application was filed on December 28, 2018, and is incorporated herein by reference in its entirety. This application claims the benefit of Russian Federal Patent Application No. 2018147246 filed in the United States. , filed September 6, 2017, which is also incorporated herein by reference in its entirety. "System and method for resilience against attacks in verifying digital signatures of files" System and Method for Attack Resiliency in Verifying Digital Signatures This application is related to U.S. Patent Application Serial No. 16 / 563,207, entitled "Potentially Insulating a Fluorescent Lamp in a Microwave Oscillator."
[0002] (Technical field) The embodiments generally relate to computerized digital signatures, and more particularly to digital signatures. and digital signature file certificate checking. [Background technology]
[0003] (background) Malicious applications are becoming more common, increasing the risk of unauthorized access and use. Improved anti-virus software aimed at protecting user data and devices from malicious use. Antivirus technology is needed. In the never-ending race, developers are especially focused on two areas of malicious file detection: We are faced with the important task of reducing type I errors (false positives). A type II error is when a malicious file is identified as malicious. The problem is the failure to identify certain files as malicious.
[0004] To reduce the number of Type I errors, developers of antivirus applications should, for example, Removes files identified as malicious using heuristic analysis. They use various techniques to ensure that the information is not removed or isolated. One such technique is the use of credit funds. This involves checking the file against a database of known files. The check is based on the database of trusted files that have been identified as malicious. ID (e.g., MD5 or SHA-1 checksum) and if the same ID is found there, The decision to classify the file as malicious is cancelled. To reduce Type I errors Another method is to use an electronic digital signature ("DS" or simply "DS") on files that are identified as malicious. This is a check of the "digital signature" (the "digital signature").
[0005] To check the digital signature, antivirus applications use the CryptoAPI Use the DS checking tool built into your operating system ("OS"), such as For example, US Patent Application Publication No. 2017 / 0257361A1 states that An approach for validating executable code based on the results of DS checks is described. However, this approach has the drawbacks of being relatively slow in DS checks and vulnerable to criminals. There are some drawbacks, such as vulnerability to attacks. You need to deal with attacks against it.
[0006] Therefore, the effectiveness of digital signatures is important in reducing Type I and Type II errors. Or reliability needs to be checked reliably and efficiently. Summary of the Invention [Means for solving the problem]
[0007] (overview) The embodiments of the present application substantially fulfill the above-mentioned needs of the industry. In particular, the embodiments described herein The embodiment verifies the validity and authenticity of the digital signature and digital signature certificate in an existing system. The present invention provides a system and method for more efficient and accurate evaluation.
[0008] In one embodiment, a system for verifying a digital signature of at least one file is provided. A certificate database configured to store multiple certificates; a credential database configured to store: Computer hardware of at least one processor and the at least one processor a memory operatively connected to said data transfer device; and said data transfer device containing instructions, said instructions being When executed on a computer platform, the computer platform: A small number of digital signatures containing a DS certificate with transaction center data and DS certificate data. At least one file is obtained and the DS certificate is checked to see if it has the required DS certificate integrity. and authenticating the issuing center certificate with the certificate database. Determine whether the DS certificate is valid and whether the at least one file is a required file. The digital signature is verified by checking that the digital signature has validity and that the digital signature is valid. If the DS certificate is valid, the DS certificate data is used to Determine whether the DS certificate can be trusted by searching the associated credential data; If the digital signature is valid and the DS certificate is trusted, then at least Implement a checking tool that is configured to classify a single file as trusted. do.
[0009] In one embodiment, a method for verifying a digital signature of at least one file comprises: A small number of digital signatures containing a DS certificate with issuing center data and DS certificate data. obtaining at least one file; and determining whether the DS certificate has the required DS certificate integrity. by checking that the issuing center certificate is valid and by authenticating the issuing center certificate. determining whether the DS certificate is valid; determining whether the at least one file is a required file; The digital signature is verified by checking that the digital signature has validity and that the digital signature is valid. determining whether the DS certificate is valid; if so, verifying the DS certificate; by searching the credential database for credential data related to the data. determining whether the DS certificate can be trusted; and determining whether the digital signature is valid and If the DS certificate is trusted, the at least one file is classified as a trusted file. The method includes the step of:
[0010] In one embodiment, the computing device includes at least one processor and a memory operatively connected to the processor; and instructions, the instructions being transmitted to the processor; When executed, the processor: Obtain at least one file with a digital signature containing a DS certificate, and By checking whether the certificate has a valid DS certificate integrity, and determining whether the DS certificate is valid by authenticating the at least one file; by checking that the file has the required file integrity and that the DS certificate is valid. If the DS certificate is valid, by searching a credential database for credential data related to the certificate data. Determine whether the DS certificate is trustworthy and verify that the digital signature is valid and the DS certificate is valid. If the certificate is trusted, classify the at least one file as trusted. Implement the check tool configured in
[0011] The above summary does not encompass each illustrated embodiment or every implementation of the present subject matter. The drawings and the detailed description that follow illustrate various embodiments and are not intended to be illustrative. A more specific example will be given.
[0012] BRIEF DESCRIPTION OF THE DRAWINGS The subject matter of the present invention will become more readily apparent from the following detailed description of various embodiments when considered in conjunction with the accompanying drawings, in which: would be more fully understood. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is a block diagram of a system for verifying a digital signature of a file, according to one embodiment. [Figure 2] FIG. 2 is a block diagram of a system for verifying a digital signature of a file according to another embodiment. [Figure 3] FIG. 3 is a flowchart of a method for verifying a digital signature of a file, according to one embodiment. [Figure 4]FIG. 4 is a flowchart of a method for combating attacks on a computing device, according to one embodiment. [Figure 5] FIG. 5 is a block diagram of a computer system configured to implement an embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0014] While the various embodiments are susceptible to various modifications and alternative forms, details thereof are provided by way of example only. Although shown in the drawings and described in detail, certain embodiments which describe the claimed invention It should be understood that the present invention is not intended to be limited to the scope of the invention as defined in the claims. All modifications, equivalents, and alternatives falling within the spirit and scope of the subject matter defined in the claim. is intended to include.
[0015] Detailed Description of the Drawings The following definitions and concepts are used throughout the description of specific embodiments.
[0016] For example, in one embodiment, a malicious application is a computer or have the ability to cause damage to user data on a computer (in other words, the computer system) applications that exploit the The damage can be for the purpose of theft, as well as for example unauthorized storage or Computers containing data stored on the computer for the purpose of exploiting resources such as performing calculations. It can consist of unauthorized access to computer resources.
[0017] In one embodiment, a trusted application is a computer or its user that is not vulnerable to harm. An application can be a trusted piece of software. If developed by a trusted source (e.g., a trusted site), If it is downloaded from a site included in the database, or if it is downloaded from an application ID ( or other data that allows the application to be precisely identified - e.g. The hash value of the application file is stored in the trusted application database. Manufacturer IDs, such as digital certificates, can also be used to It can be stored in a credit application database.
[0018] In one embodiment, an untrusted application is an application that is not trusted but is recognized as malicious. For example, it may refer to applications that are not trusted or malicious. The assessment of the presence of the virus can be done by an antivirus application. The application is deemed malicious after using an antivirus check, for example. It can be certified.
[0019] In one embodiment, a malicious file is a component of a malicious application. and contains program code (e.g., executable or interpreted code). It can be.
[0020] In one embodiment, an untrusted file is a component of an untrusted application, A file that contains program code (e.g., executable code or interpreted code) obtain.
[0021] In one embodiment, a trust file is a file that is a component of a trust application. This could be the case.
[0022] In one embodiment, checking the DS of a file is performed if the file being checked is It is defined as checking whether the DS is signed by the owner of the certificate attached to the DS. In the first stage of the check, the decrypted file from the DS of the file The checksum is a file check obtained using the algorithm specified in the DS certificate. Compare the checksum from the DS file with the public key specified in the DS certificate. If the checksums match, the file integrity is confirmed. The next step is to check the validity of the DS certificate, which is done in the same way: The embodiment verifies the integrity of the DS certificate of the file and the identity of the person who issued the DS certificate of the file. Check the validity of the certification center's certificate (this process continues up to the root certificate) The certificate is issued when its integrity is confirmed and the certification of the certification center that issued it is If the certificate is valid, it is also considered valid; otherwise, the certificate is invalid. If the DS certificate is considered valid and the file is considered to have the required integrity, In other embodiments, a DS certificate is considered valid if If the signature is successful and the file has not been modified since it was signed, the DS is considered valid. If not, the DS is considered invalid. In a specific embodiment, the DS certificate: The certificate attached to the DS of the file that allows checking the validity of the DS of the file (" In a specific embodiment, the certificate is a certificate conforming to the X.509 standard. This means a statement.
[0023] In one embodiment, the tool of the system for checking the DS of a file in the present invention is an application specific integrated circuit (ASIC) or field programmable gate array using hardware such as FPGAs, or integrated with a microprocessor system, for example. A combination of software and hardware, such as a series of program instructions, and a neuroscience Actual devices, systems, components, and groups of components designed as optical chips The functionality of the system tools described above may be provided solely by hardware or by the corresponding The functionality of a system tool is partly software and partly hardware. In some embodiments, the two Some or all of the data may be transferred to a processor of a computerized device (e.g., The components of the system may be implemented using a single computer. The design can be performed within a single computer or distributed across multiple linked computers.
[0024] In one embodiment, the DS checking system includes a checking tool and a certificate database. In another embodiment, the system includes a security tool.
[0025] Referring to FIG. 1, a system for verifying a digital signature of a file, according to one embodiment, is shown. In one embodiment, the system includes a checking tool and In one embodiment, the checking tool 120 collects data (e.g., For example, data received from a network) to the user computer 140. In one embodiment, the user The data sent to the computer 140 may be a file 110. can be a router or any other computing device such as a proxy server. In an embodiment, data transfer device 135 is designed to store data for later distribution. For example, the data transfer device 135 may be a computer device that is later transferred to an employee's computer. Update files for multiple computers on a company network for transferring files to the An update server may be provided for receiving the
[0026] In one embodiment, the system further includes a security tool 125. As such, the security tool 125 also resides in the data transfer device 135 .
[0027] In one embodiment, the system includes a certificate database 130 and a credential database 131. 31, each of which is adapted to be operatively connected to the checking tool 120. The databases 130 and 131 are configured as follows. It may reside on a remote server connected to the device 135 (eg, via a network).
[0028] The file 110 may include a file with a DS. For example, the file 110 may be an executable file. In another embodiment, the executable file may be a Windows or script file. It is used by operating systems from the Unix family, especially Windows OS, Ubuntu Linux OS, MacOS, etc. It is an executable file for the operating system.
[0029] Referring to FIG. 2, a system for verifying a digital signature of a file according to another embodiment is shown. Specifically, Figure 2 shows an alternative implementation of the check system. In the illustrated embodiment, the security tool 125 and the checking tool 120 are connected to a user computer device. 140. Also, the certificate database 130 and the trust database 140 are connected to the check tool 120. The certificate database 131 is accessible to a computer device 140 or to the computer using a network. The data may reside on a remote server connected to the computer device 140.
[0030] Referring again to both Figures 1 and 2, the certificate database 130 is configured to store certificates. In one embodiment, the certificate database 130 also stores information about whether a certificate has been revoked. In certain embodiments, the method stores information about each certificate indicating whether it has been The document database 130 is compatible with Windows and Unix families, such as Windows, Ubuntu Linux, Or certificates for multiple (at least two) operating systems, such as MacOS (so The certificate database 130 therefore stores various operations The rating system certificate can be stored, but this is The system's DS check system tool is used separately as in the conventional system. In addition, in one embodiment, the certificate database 130 stores the root certificate Only the certificate and the certification center's certificate will be stored.
[0031] The credentials database 131 is configured to store credentials. In one embodiment, the credential database 131 does not store the certificates themselves, but rather In one particular embodiment, the certificate data is Similar to database 130, credential database 131 stores information about certificates for multiple operating systems. It is configured to store information about the
[0032] In the context of this disclosure, an "OS Certificate" (or simply an "OS Certificate") is a certificate issued by an OS (or A certificate for one OS family may be present in the system storage, but a certificate for another OS family may be present in the system storage. This situation can occur for several reasons: It is possible.
[0033] For example, an OS developer may choose to remove encryption algorithms that the developer considers cryptographically weak. In one particular example, Windows The developer uses the SHA-1 encryption algorithm when checking the validity of the DS in the Windows 10 OS. (and therefore, certificates that specify this algorithm) will cease to be used.
[0034] Another example is the use of a cryptographically strong encryption algorithm to check the validity of the DS. Support for system storage of certificates with .NET Framework 2.0 or later may not be present or may be left to the OS developer. It may be added later. The Windows 7 OS provides one such example, and in this example, Only the SHA-1 encryption algorithm was supported, but SP1 was the only update for SHA Added A-256 support.
[0035] In another example, an OS developer may issue a set of specifications to software developers related to a particular subsystem. The certificates stored in the system storage device do not need to be added. For example, the certificates stored in the Windows 8 OS only need to be added. The root certificate used to check the DS for Metro applications is the Windows 7 OS certificate. The certificate is not present in the system storage.
[0036] Another example is a MacOS developer using the DS checker to check the DS of a Windows executable. Do not add any certificates (especially root certificates) to your Mac system storage (and vice versa) In other words, the system storage of one OS checks the executable files of other OSes. It may not include the certificates used to authenticate the user (especially the root certificate).
[0037] Similar to the examples provided herein, certificates from existing system storage (e.g., There are numerous other reasons for the exclusion of a root certificate, including but not limited to:
[0038] As discussed above, in certain embodiments, the system store of certificates includes The database may include a database containing the checks for DSs, such as file DSs. It is used by the DS check system tool for the "OS Developer" in the above example. This means that the contents of the system store of certificates and the DS (especially the methods used to check the validity of DS and certificates) This includes information technology experts who determine the encryption algorithms used in specific implementations. So, the data stored in databases 130 and 131 is used by such information technology professionals. can be added, modified, and deleted.
[0039] Referring again to FIGS. 1 and 2, the checking tool 120 may use the following to determine if a DS is valid: to check the DS of file 110 and if the certificate is valid and trusted It is designed to check the certificate of the file DS110 to verify its validity. The integrity is checked in two stages, which are carried out simultaneously and independently of each other. can be done.
[0040] The first step is to check the integrity of the file 110. For this purpose, a tool 120 The decryption checksum of the file 110 from the DS of the file 110 is calculated using the algorithm specified in the certificate of the DS. The checksum of the file 110 is compared with the checksum of the file 110 obtained using the algorithm. The checksum is checked using the public key specified in the DS certificate. If so, the checking tool 120 checks the integrity of the file, i.e., the file 110 Determine whether it has been changed.
[0041] The second stage of the DS check of the file 110 checks the validity of the DS certificate. In this case, the checking tool 120 may, for example, select a certificate from the certificates available in the certificate database 130. Checks the validity of a certificate by building a certificate chain up to a root certificate. The DS certificate of file 110 (and any other certificate) is Proper integrity (checking certificate integrity is similar to checking file integrity above) and the certificate of the certification center that issued the DS certificate in file 110. In one embodiment, the DS certificate of the file 110 is also considered valid. All certificates used to check the certificate are stored in the certificate database 130. The sequential check of certificate validity involves building a certificate chain. For example, when the check tool 120 checks the certificate of the DS of the file 110, You can create a certificate chain up to the root certificate stored in the database 130. If the certificates in the certificate chain are properly consistent and the If the last certificate in the chain is a root certificate, the DS certificate in the file 110 is valid. If not, the DS certificate in file 110 is considered valid. In one embodiment, the DS of the file 110 If the certificate is invalid, the checking tool 120 identifies the file as an untrusted file. Determine.
[0042] If the DS certificate of the file 110 is valid, the check tool 120 checks whether the following conditions are met: If so, the DS certificate of the file 110 can be recognized as trustworthy: (or the ID of such a certificate - e.g., a SHA-1 or SHA-256 checksum, or A vector value that reliably identifies the certificate exists in the credential database 131, or the certificate The issuing certification center's certificate is trusted. In one embodiment, it is certified as trusted. For a DS certificate to be valid, further conditions must be met. In particular, the certificate data The database 130 must not contain information that a certificate has been revoked. In some embodiments, additional conditions must be met for a DS certificate to be recognized as trustworthy. In particular, DS certificates must not be expired (the certificate itself must not contain The indicated period has not yet ended)
[0043] In one embodiment, for a certificate to be recognized as valid, the certificate database 131 It is sufficient to include information about the certificate (e.g., the certificate ID). Certification of S's certificate is not done as a separate step. Rather, it is a matter of whether DS's certificate can be trusted. This is confirmed at the stage of checking the validity of the DS certificate of the file 110.
[0044] In one embodiment, the checking tool 120 also determines the category of the file 110. (Or to classify files into a category; in other words, to The tool 120 is configured to verify that the DS of the file is valid. If the DS certificate is trustworthy, the file 110 is recognized as trustworthy (file The file 110 is determined to belong to the category of trusted files, in other words, the file 110 is determined to be trusted. (classifying files into categories).
[0045] DS-Check is used to check the validity of the DS certificate and therefore the validity of the DS of the file 110. By using the database 130 instead of the check system tool, the check tool 1 20 has advantages over conventional systems, such as being part of the OS and being compatible with that OS. The system certificate store, which stores the certificates used to sign only certain types of files, storage device (e.g., system storage of certificates in Windows OS is similar to executable files in Unix-type systems) Unlike the default DS check, which does not store certificates including root certificates, The database 130 is used to sign files for any operating system. In one embodiment, if the file is an executable file for the OS, the The file corresponds to the OS. This allows the DS certificate of the file 110 to be recognized as valid. The decision to determine whether the DS of the file 110 is valid and whether the DS of the file 110 is valid is also made. The category of the file 110 determined based on the DS and the DS certificate is correct. This ensures accuracy, especially reduction of type I errors.
[0046] The security tool 125 is configured to protect the device 140 from untrusted files. In one embodiment, protection includes prohibiting the execution of non-trusted files or In yet another embodiment, the security tool The rule 125 prevents the transfer of untrusted files to the computing device 140. For example, The blocking tool 125 can block the transfer of the file 110 to the computing device 140 . In another embodiment, the security tool 125 may: The untrusted file never reaches the computing device 140 .
[0047] In one embodiment, the security tool 125 performs a DS-check on the user computing device 140. It is further configured to detect attacks made against system tools. The system tools provided with the operating system and are used to verify the DS certificate and / or Or it can be a software tool designed to check the DS itself. The ntrust.dll library serves the functions of such tools in the Windows OS, while Keychain or the GateKeeper software component is installed on such a MacOS operating system. In one embodiment, the attack against the DS-Check system tool is Modify or replace one or more system program modules that check DS certificates. In this case, the detection of attacks against DS certificate checking tools may lead to a security risk. The assurance tool 125 is one or more system programs that check whether a DS certificate is malicious. It is also configured to determine the RAM module.
[0048] As described herein and as already pointed out, system tools can be used to check the DS certificate. The specific ability to check is based on the limited certificates available to DS certificate-checking system tools. A set of certificates (e.g., in the Windows certificate store or the MacOS Keychain certificate store) The certificates may be restricted by a limited set of certificates.
[0049] Referring to FIG. 3, a method for verifying a digital signature of a file, according to one embodiment, A flowchart of the method of FIG. 3 is shown. The method of FIG. 3 may be performed, for example, by the system of FIG. It is possible.
[0050] At 301, the checking tool 120 checks the file 110, etc., to be further transferred. In this case, the file 110 is a data file containing a checking tool 120. The data is then transferred over the network by a data transfer device 135 to a user computer device 140. In an embodiment, intercepting the file 110 involves intercepting data from the file 110 or the file 110. In another embodiment, the method includes receiving data related to the The file 110 cannot be intercepted until the file 110 is identified as a trusted file. , interrupting the transfer of the file 110 to the computing device 140 (using the security tool 125) The method further includes:
[0051] Subsequently, the file DS is checked. In particular, at 302, the checking tool 120 checks whether the file The DS certificate of the file 110 is checked to see if the DS certificate has the proper integrity. If the certificate of the certification center that issued the DS certificate is valid, it is valid. The validity of the certificate is checked using the certificate database 130. The certificate database 130 may store certificates with an indication of whether each certificate is trustworthy. Therefore, the credentials from the certificate database 130 may include the certificate of the authentication center. The process for checking the validity of a certificate chain is It can continue up to the first credential in the certificate chain or up to a root certificate.
[0052] At 303, the checking tool 120 determines if the DS certificate is valid and if the file 110 is in proper If the file is consistent, the DS of the file is determined to be valid. The S certificate is generated if the certificate is valid and if the certificate database 130 determines that the DS certificate is trusted. If the DS Certificate contains information that the certificate can be used, or if the certificate of the certification center that issued the DS Certificate is trusted, If it can be done, it is certified as trustworthy. The execution of 303 and 304 is independent of each other, This can be done in any order.
[0053] If the DS certificate is trusted and the DS is valid, then at 305 the file 110 is In other words, the file 110 is classified - the file is identified as a trusted file. If not, the file 110 is determined to be untrusted at 306. It is classified as a file for use.
[0054] If the file 110 is not classified as a trusted file, the security tool The file 11 is then deleted, and the file 125 stops all further transfers to the user computing device 140. Delete all data associated with 0 (e.g., residing in data transfer device 135), or The file 110 can be quarantined.
[0055] The method implemented by this system is a system tool based certificate checking solution. For example, the certificate database 130 can be used by various operators. In order to include a certificate for the operating system, an embodiment may Compared to a similar system that checks only family certificates, Less false responses when determining categories. More specifically, the valid (and trusted) Executable files with certificates can be trusted using only the Windows OS certificate store. Therefore, the embodiment solves this problem; Type I error when determining the category of a file by storing the family certificate The importance of this solution is that the check tool 120 An enterprise may have multiple user computing devices 140 with a single operating system. This is evident when the router or proxy server of the corporate network is present. In the network, the data transfer device 135 may transfer DS certificates belonging to different operating systems. The file 110 containing the certificate is transferred. The check tool 120 and the security tool 125 "Filter" files downloaded from the network (e.g., corporate networks) (blocking file transfers to computing devices 140 included in the network) do.
[0056] In yet another embodiment, tools 120 and 125 reside on a user computing device. The method allows a user to configure a device 140 having an OS different from the OS controlling the device 140. DS signed files that will be launched in a virtual machine installed on This allows for a reduction in the number of incorrect responses when determining the 110 categories. Since sources 130 and 131 contain information about certificates for various operating systems, The check tool checks whether the executable file of an OS different from the OS that controls the user computer device 140 is This is achieved by the fact that the certificate of the file can be checked accurately.
[0057] Referring to FIG. 4, in accordance with one embodiment, a method for combating attacks against a computer device is provided. 4 is a flowchart of a method for performing the method of FIG. It can be implemented.
[0058] At 400, the security tool 125 generates one or more systems for checking the DS of the file. Detect attacks against user computing devices 140 that target system tools. At 01, the security tool 125 searches for unclassified files 110. For example, The tool 125 finds the ID of the file 110 (e.g., SH A-1 or MD5 checksum). The file database is The file 110 belongs to a category of files, e.g., trusted files or non-trusted files. The security tool 125 may include data indicating that the file is If the category of the file 110 cannot be determined using the provided request, the following method In this case, the file 110 is accessed by any new For example, a file may be downloaded from a network. downloaded, created on a computing device, or already present on the computing device 140 A new or modified file obtained by modifying an existing file. It can be yl.
[0059] Next, a DS check of the file is performed. At 402, the check tool 120 checks the file 110 The DS certificate is checked. If the DS certificate has the proper integrity, If the certificate of the certification center that issued the DS certificate is valid, the DS certificate is considered valid. The validity of the certificate can be checked using the certificate database 130. The certificate database 130 includes a certificate center that has an indication of whether each certificate is trustworthy. Therefore, the credentials from the certificate database 130 are valid. The process of checking the validity of a certificate chain is The certificate may continue up to the first valid certificate in the application or to the root certificate.
[0060] At 403, the checking tool 120 determines if the DS certificate is valid and if the file 110 is needed. If so, the file's DS is validated. If the DS certificate of the file is valid, and the certificate database 130 If the certificate contains information that the DS Certificate is trustworthy, or if the certificate of the certification center that issued the DS Certificate is If the authentication information is trustworthy, it is deemed to be trustworthy. In an embodiment, 403 and 404 are mutually independent. These steps are separate and can be performed in any order.
[0061] If the DS certificate is trusted and the DS is valid, then at 405 the file 110 is In other words, the file 110 is classified - the file is identified as a trusted file. If not, the file 110 is determined to be untrusted at 406. It is classified as a file for use.
[0062] If the file 110 is not classified as a trusted file, the security tool The file 125 stores data (e.g., For example, the file's data may be deleted or the file 110 may be quarantined.
[0063] The method shown in Figure 4 is a countermeasure to system tool-based certificate checking solutions. For example, attacks against DS check system tools can be performed using the Check system tool components may be replaced or damaged and may be incorrectly To function, the DS check system tool accurately checks the certificate of the file DS. This makes it impossible to determine whether the DS is valid and whether the certificate can be trusted. This makes it impossible to accurately determine the category of a DS-signed file based on whether it is An example of such an attack is the substitution of components in the DS Check System tool. Therefore, security tools, especially antivirus applications, are required to detect and handle vulnerable DS checks. Based on the information about DS validity and DS certificate validity provided by the network system tools Malicious files can be classified as trusted files by determining their category based on the The embodiments described herein detect attacks against DS check system tools. If such an attack is detected, the certificate may be revoked or revoked. Determine the category of the file 110 using the certificate database 130, which provides all the authentic information This solves the above problem.
[0064] In one embodiment, the attack against the DS check system tool is a more complex attack; e.g. , may be part of a persistent targeted attack. In this case, the security tool 125 It is extremely important to protect the computer device 140 from attacks. The tool 125 checks all files that appear on the device 140 during an attack on the DS check system tool. For example, the duration can be determined by the attack type. The time of the attack may be within 24 hours of the time of the attack (not from the time the attack was detected). For example, this can be determined by the date and time of the change of the components in the DS check system tool. In this case, the check can be performed as part of a check initiated by the security assurance tool 125. Files that are not identified as trusted files using tool 120 are identified by tool 125. Such files are identified as potentially malicious, for example by a classification algorithm. or for more detailed analysis using neuronal networks, or for information security It can be sent to a remote server for expert analysis. The tool 125 receives a decision from the remote server authorizing all files and determines whether the files are malicious. If identified, the security assurance tool 125 will detect the persistent targeted attack and Take necessary steps (e.g., delete or quarantine) with respect to files identified as containing cormorant.
[0065] In another embodiment, the systems and methods described herein include a DS check system tool is under attack, but also when the components of such DS check system tools before it is loaded into RAM (for example, when the Windows OS starts and Wintrust.dll is not yet loaded into RAM). If you are unable to use the DS Check System Tool at all for some reason, such as when It also has advantages when this is not possible.
[0066] The use of the checking tool 120 to check the validity of the DS of the file 110 is advantageous in that it (The system storage device does not have a valid DS because it does not have a certificate for multiple OS files.) In addition to having the benefit of validity checks (reducing the number of Type I errors when a test is deemed valid), Also increase the speed.
[0067] One of the reasons for the faster speed of DS validity checks using Tool 120 is the System tools (especially Windows OS tools) are used to check the validity of certificates. To load a list of revoked certificates and determine if a certificate has been revoked. In these traditional methods, the entire list of revoked certificates is checked. In contrast, the checking tool 120 checks each certificate for the presence of Simply call the certificate database 130 that can mark it as revoked This checks whether the certificate has been revoked. The file 120 checks the validity of the DS of the file 110 faster than the DS check system tool. .
[0068] Another reason for the faster speed of DS validity check using the check tool 120 is that the database This is because the server 130 does not store copies of the certificate. For example, in the case of a conventional DS check system tool, In tools such as Windows OS tools, a copy of the certificate is added to the Windows certificate store. When a certificate is issued, it is reissued with the same public key. The creation and checking of multiple certificate chains for a certificate is prevented.
[0069] Another reason for the faster speed of DS validity check using the check tool 120 is that the This is because the system tools can be extensible. For example, in the Windows OS, An external application that complements the DS certificate validity logic by performing a check on allows the use of the CryptoAPI interface, which allows the validity of the DS The speed of judgment will be slower.
[0070] Referring to FIG. 5, aspects of the invention described herein may be implemented in accordance with various embodiments. 5, a diagram illustrating in more detail a computer system 500 capable of
[0071] The computer system 500 includes one or more processing units 521, system memory, and A computer device such as a personal computer 520 including a network 522 and a system bus 523 The system bus 523 may include one or more processing units 521. Various system components, including associated memory, are included. The processing unit 521 is a multi-processor capable of processing information stored in a computer-readable medium. The system bus 523 may include any bus structure known in the art. The system bus 523 is implemented as a bus memory or a bus memory controller, a peripheral bus and a local bus that can interact with any other bus structure. The memory may be a non-volatile memory such as a read-only memory (ROM) 524 or a random access memory. The system may include volatile memory such as RAM 525. A basic input / output system (BIOS) 526 may include, for example, During boot of the operating system using the OM524, the personal computer 520 It contains the basic procedures that ensure the transfer of information between elements.
[0072] The personal computer 520 then connects to the hard drive 520 for reading and writing data. 27, a magnetic disk drive 5 for reading and writing to a removable magnetic disk 529 28, and for removable optical disks 531 such as CD-ROMs, DVD-ROMs, and other optical media. The hard drive 527 includes an optical drive 530 for reading and writing data from and to the hard drive 527. 528 and optical drive 530 are connected to hard drive interface 532, magnetic drive and an optical drive interface 534. These drives and corresponding computer information media are connected to the computer instructions, data structures, program modules, and other data for personal computers. This provides an energy independent means for storing the data 520.
[0073] The system shown includes a hard drive 527, a removable magnetic drive 529, and a removable hard drive 528. A removable optical disk 530 is included, which is connected to the system bus 523 via a controller 555. , other types of computer media capable of storing data in computer-readable form ( Solid state drives, flash memory cards, digital disks, random access memory It should be understood that it is also possible to use a memory such as a RAM.
[0074] The computer 520 includes a file system in which a recorded operating system 535 is stored. system 536, as well as additional program applications 537 and other program engines 538. , and program data 539. The user can input the program data using input devices (keyboard 540, mouse 542) can be used to enter commands and information into the personal computer 520. Input devices (not shown), such as a microphone, joystick, game console, scanner, etc. Such input devices are typically connected to the system bus. connected to the computer system 520 via serial port 546, but these are different Type, e.g., parallel port, game port, or universal serial bus (USB) A monitor 547 or other type of display device may also be connected using The monitor is connected to the system bus 523 via an interface such as a video adapter 548. In addition to the input jack 547, the personal computer 520 may also have other peripheral outputs such as speakers and a printer. A device (not shown) may be provided.
[0075] The personal computer 520 may operate in a network environment; in this case, 549。 Remote computer 549. The personal computer(s) 549 may be used to access the contents of the personal computer 520 shown in FIG. A similar personal computer having most or all of the above elements mentioned in the description A computer or server. A computer network also includes routers, network servers, other network nodes, such as a network station, a peering device, or another network node. The device may also include:
[0076] Network connections are available for Local Area Networks (LANs) 550 and World Area Networks. Such a network can be a network of corporate computers. Used in data networks or corporate intranets, usually with access to the Internet In a LAN or WAN network, the personal computer 520 may A local area network 550 via an adapter or network interface 551 When using a network, the personal computer 520 is connected to a modem 554 or other means of connection to a world area network such as the Internet. The modem 554 may be an internal or external device and may be connected to the serial port 546. These network connections are merely examples. It does not necessarily reflect the actual network configuration; Obviously, there are other ways to establish a connection using technical communication means between the data. cormorant.
[0077] Various implementations of systems, devices, and methods have been described herein. The embodiments are presented by way of example only and are not intended to limit the scope of the claimed invention. Moreover, various features of the previously described embodiments may be combined in various ways to form multiple It is understood that further embodiments may be made. Furthermore, various materials, sizes, shapes, Although the configuration, location, etc. have been described for use in the disclosed embodiments, may be utilized without departing from the scope of the claimed invention. .
[0078] Those skilled in the art will appreciate that the subject matter of the present invention may be realized by the features exemplified in any of the individual embodiments described above. It will be understood that the embodiments described herein may include fewer features than those described above. means to present exhaustively the ways in which the various features of the subject can be combined. Thus, embodiments are not mutually exclusive combinations of features; rather , various embodiments may be selected from different individual embodiments, as will be understood by those skilled in the art. It may include a combination of different individual features. Furthermore, elements described with respect to one embodiment may Unless otherwise specified, other embodiments may be used even if not described in such an embodiment. It can be implemented in various ways.
[0079] A dependent claim is a claim that expresses a specific combination with one or more other claims. Although the invention may refer to a combination of the subject matter of a dependent claim with the subject matter of each other dependent claim, other embodiments may refer to a combination of the subject matter of a dependent claim with the subject matter of each other dependent claim. or a combination of one or more features with other dependent or independent claims. Such combinations are not contemplated unless it is expressly stated that the particular combination is not intended. Unless otherwise suggested herein.
[0080] Any incorporation by reference of the above documents is expressly expressly expressly disclaimed. All incorporation by reference of the above documents is expressly prohibited.
[0013] The present application is further limited so that any claims therein are not incorporated by reference herein. All incorporation by reference of the above documents is expressly incorporated herein by reference. , especially so that any definitions provided in the literature are not incorporated herein by reference. Limited to.
[0081] For purposes of claim interpretation, a claim may contain "means for" or "means for" Unless the specific term "steps" is used, the provisions of 35 U.S.C. § 112(f) is expressly intended not to apply. The present application provides the following aspects of the invention. (Aspect 1) A system and method for verifying a digital signature of a file. (Aspect 2) 1. A system for verifying a digital signature of at least one file, comprising: A certificate database configured to store multiple certificates; a credential database configured to store credential data; and 1. A data transfer device comprising: Computer hardware of at least one processor and the at least one processor memory operatively connected to the processor; and the data transfer device including instructions; When the instructions are executed on a computer platform, the computer platform Room: A digital signature containing a DS certificate with issuing center data and DS certificate data. Get at least one file that By checking whether the DS certificate has the required DS certificate integrity, and The DS certificate is validated by authenticating the issuing center certificate with the certificate database. Determine whether there is The at least one file has the required file integrity and the DS certificate is valid determining whether the digital signature is valid by checking whether If the DS Certificate is valid, verify the credential data associated with the DS Certificate data. Determine whether the DS certificate can be trusted by searching for If the digital signature is valid and the DS certificate is trusted, Implement a checking tool that is configured to classify one file as a trusted file. The system. (Aspect 3) The checking tool determines that the digital signature is invalid or the DS certificate is invalid. If the file is not trusted, the at least one file is treated as an untrusted file. further configured to classify the The data transfer device further includes instructions, the instructions being transmitted to the computer platform. When executed, the computer platform If the file is classified as untrusted by the checking tool, a security feature configured to restrict access to the at least one file in the device; 3. The system of claim 2, wherein the system implements a fault detection tool. (Aspect 4) The plurality of certificates in the certificate database are associated with a first operating system. a first certificate for a first operating system and a second certificate for a second operating system, The method of claim 2, wherein the operating system and the second operating system are different. system. (Aspect 5) The credential data in the credential database is used for at least two operations 3. The system of embodiment 2, comprising data for a rating system. (Aspect 6) The checking tool determines, using a first processor process, that the digital signature is valid. and using a second processor process to determine whether the DS certificate is The first processor process is configured to determine whether the second processor process is valid. 3. The system of claim 2, wherein the processor process is executed concurrently and independently. (Aspect 7) The security tool: prohibiting the transfer of said at least one file to said user computing device. 、 prohibiting the at least one file from being executed on the user computing device; prohibiting the at least one file from being opened on the user computing device; deleting the at least one file; or and quarantining the at least one file on the user computer. 4. The system of claim 3, wherein the system is configured to restrict access to the file on the computer device. Tem. (Aspect 8) When the checking tool obtains the at least one file, the security tool The rule classifies the at least one file as a trusted file or a non-trusted file. and suspending the transfer of the at least one file to the user computing device until 8. The system of embodiment 7, further configured as follows: (Aspect 9) Checking whether said at least one file has said required file integrity. That can: obtaining a decrypted digital signature checksum from said digital signature; deriving a checksum algorithm from said DS Certificate; performing a file check of the at least one file using the checksum algorithm; Calculating sum; The digital signature checksum is converted into the file checksum using the public key of the DS certificate. To compare; and If the digital signature checksum matches the file checksum, then determining that another file has the required file integrity. system. (Aspect 10) authenticating said issuing center certificate; creating a certificate chain from the plurality of certificates; Whether each of the multiple certificates in the certificate chain has the required certificate integrity Checking; One of the certificates in the certificate chain is associated with the issuing center data. Check that the Checking whether the root certificate is the last certificate in the certificate chain; and Each of the plurality of certificates in the certificate chain has the required certificate integrity. one of the plurality of certificates in the certificate chain is associated with the issuing center data; If the root certificate is the last certificate in the certificate chain, the issuing center data 3. The system of claim 2, further comprising determining that the data is valid. (Aspect 11) Retrieving credential data associated with said DS certificate data includes: The credential data includes the DS certificate, the ID of the DS certificate, or a identifying the DS certificate data including at least one of the vector values that distinguish In the credential data, the certification center from the certification center that issued the DS certificate The system of embodiment 2 further includes identifying a certificate. (Aspect 12) The certificate database is configured to store revocation data for the plurality of certificates. and determining whether the DS certificate can be trusted: Compare the DS certificate with the revocation data to determine if the DS certificate has expired 12. The system of embodiment 11, further comprising: (Aspect 13) The plurality of certificates stored in the certificate database include a root certificate and a certificate center certificate. 3. The system of claim 2, wherein the authentication information includes only the certificate of the authentication target. (Aspect 14) the credential data includes a plurality of credentials or identities of the plurality of credentials. 2. The system described in 2. (Aspect 15) 1. A method for verifying a digital signature of at least one file, comprising: A digital signature including a DS certificate containing issuing center data and DS certificate data Obtaining at least one file; By checking whether the DS certificate has the required DS certificate integrity and determining whether the DS certificate is valid by authenticating the transaction center certificate; ; The at least one file has the required file integrity and the DS certificate is valid. determining whether the digital signature is valid by checking whether the digital signature is valid; If the DS Certificate is valid, the credential data associated with the DS Certificate data is trusted. The step of determining whether the DS certificate can be trusted by looking it up in a certificate database. and If the digital signature is valid and the DS certificate is trusted, then The method further comprises the step of classifying the file as a trusted file. (Aspect 16) The digital signature is invalid or the DS certificate is invalid or untrusted. if not, classifying the at least one file as a non-trusted file; and If the at least one file is classified as an untrusted file, the user computer and further comprising restricting access to the at least one file on the data device. The method described in 15. (Aspect 17) The step of restricting access to files on the user computing device comprises: a step of prohibiting the transfer of the at least one file to the user computing device; Top, prohibiting the at least one file from being executed on the user computing device. 、 prohibiting the at least one file from being opened on the user computing device. P, deleting the at least one file; or quarantining the at least one file. method. (Aspect 18) Upon obtaining the at least one file, the at least one file is added to a trusted file. the user of the at least one file until the file is classified as a trusted or untrusted file. 20. The method of embodiment 16, further comprising the step of interrupting the transfer to the computing device. (Aspect 19) At least one processor and a memory; and A computing device including instructions that, when executed by a processor, cause the processor to The processor: A digital signature containing a DS certificate with issuing center data and DS certificate data. Get at least one file that By checking whether the DS certificate has the required DS certificate integrity, and determining whether the DS certificate is valid by authenticating the issuing center certificate; The at least one file has the required file integrity and the DS certificate is valid determining whether the digital signature is valid by checking whether If the DS Certificate is valid, the credential data associated with the DS Certificate data is trusted. Determine whether the DS certificate is trustworthy by searching it in a public certificate database, and hand If the digital signature is valid and the DS certificate is trusted, Implement a checking tool that is configured to classify one file as a trusted file. The computer device. (Aspect 20) The checking tool determines that the digital signature is invalid or the DS certificate is invalid. If the file is not trusted, the at least one file is treated as an untrusted file. further configured to classify the The computing device further includes instructions that, when executed by the processor, The processor determines that the at least one file is a non-trusted file by the checking tool. If the file is classified as a file, the at least one file on the user's computer device 20. The method of claim 19, further comprising: Computer equipment. (Aspect 21) computer device operating system (OS); and and further comprising instructions that, when executed by the processor, cause the processor to: a virtual machine including a virtual machine OS different from the computer device OS; 20. The computing device of embodiment 19, wherein a file is executable only on the virtual machine OS.
Claims
1. 1. A system for verifying a digital signature of at least one file, comprising: a certificate database configured to store multiple certificates; a credential database configured to store credential data; and 1. A data transfer device comprising: computer hardware of at least one processor and memory operatively connected to the at least one processor; and the data transfer device including instructions; When the instructions are executed on a computer platform, the computer platform: obtaining the at least one file having a digital signature including a DS certificate having certification center information and DS certificate identification information; determining whether the DS certificate is valid by checking whether the DS certificate has the required DS certificate integrity and by authenticating the certificate of the certification center that issued the DS certificate in the certificate database; determining whether the at least one file has the required file integrity and whether the digital signature is valid by checking whether the DS certificate is valid; If the DS certificate is valid, determining whether the DS certificate can be trusted by retrieving credential data associated with the DS certificate identity; and The system implements a checking tool configured to classify the at least one file as a trusted file if the digital signature is valid and the DS certificate is trusted.
2. the checking tool is further configured to classify the at least one file as an untrusted file if the digital signature is invalid or the DS certificate is invalid or untrusted; 2. The system of claim 1, wherein the data transfer device further includes instructions that, when executed on the computer platform, cause the computer platform to implement a security tool configured to restrict access to the at least one file on a user computer device if the at least one file is classified as an untrusted file by the checking tool.
3. 2. The system of claim 1, wherein the plurality of certificates in the certificate database includes a first certificate for a first operating system and a second certificate for a second operating system, the first operating system and the second operating system being different.
4. 10. The system of claim 1, wherein the credential data in the credential database includes data for at least two operating systems.
5. 2. The system of claim 1, wherein the checking tool is configured to determine whether the digital signature is valid using a first processor process and to determine whether the DS certificate is valid using a second processor process, the first processor process running concurrently and independently of the second processor process.
6. The security tool: prohibiting the transfer of said at least one file to said user computing device; prohibiting the at least one file from being executed on the user computing device; prohibiting the at least one file from being opened on the user computing device; deleting the at least one file; or 3. The system of claim 2, configured to restrict access to the file on the user computing device by at least one of quarantining the at least one file.
7. 7. The system of claim 6, wherein when the checking tool obtains the at least one file, the security tool is further configured to suspend transfer of the at least one file to the user computing device until the at least one file is classified as a trusted file or a non-trusted file.
8. Checking whether the at least one file has the required file integrity includes: obtaining a decrypted digital signature checksum from the digital signature; deriving the checksum algorithm from the DS Certificate; calculating a file checksum for the at least one file using the checksum algorithm; comparing the digital signature checksum with the file checksum using the public key of the DS certificate; and 2. The system of claim 1, further comprising determining that the at least one file has the required file integrity if the digital signature checksum matches the file checksum.
9. authenticating the certificate of the certification center that issued the DS certificate: creating a certificate chain from the plurality of certificates; checking whether each of the plurality of certificates in the certificate chain has required certificate integrity; checking whether one of the plurality of certificates in the certificate chain is associated with the certification center information; Checking whether the root certificate is the last certificate in the certificate chain; and 2. The system of claim 1, further comprising determining that the certification center information is valid if each of the plurality of certificates in the certificate chain has the required certificate integrity, one of the plurality of certificates in the certificate chain is associated with the certification center information, and the root certificate is the last certificate in the certificate chain.
10. Retrieving credential data associated with the DS certificate identity information includes: Identifying in the credential data the DS certificate identification information, which includes at least one of the DS certificate, an ID of the DS certificate, or a vector value identifying the DS certificate; or 2. The system of claim 1, further comprising identifying in the credential data a certification center that issued a certificate from a certification center that issued the DS certificate.
11. The certificate database is further configured to store revocation data for the plurality of certificates, and determining whether the DS certificate can be trusted includes:
11. The system of claim 10, further comprising comparing the DS certificate with the revocation data to determine if the DS certificate has expired.
12. 2. The system of claim 1, wherein the plurality of certificates stored in the certificate database includes only a root certificate and a certificate of a certification center that issued the DS certificate.
13. The system of claim 1 , wherein the credential data includes a plurality of credentials or identities of the plurality of credentials.
14. 1. A method for verifying a digital signature of at least one file, comprising: obtaining the at least one file having a digital signature including a DS certificate having certification center information and DS certificate identification information; determining whether the DS certificate is valid by checking whether it has the required DS certificate integrity and by authenticating the certificate of the certification center that issued the DS certificate; determining whether the at least one file has the required file integrity and whether the digital signature is valid by checking whether the DS certificate is valid; If the DS certificate is valid, determining whether the DS certificate can be trusted by searching a credential database for credential data associated with the DS certificate identity; and If the digital signature is valid and the DS certificate is trusted, classifying the at least one file as a trusted file.
15. If the digital signature is invalid or the DS certificate is invalid or untrusted, classifying the at least one file as an untrusted file; and 15. The method of claim 14, further comprising restricting access to the at least one file on a user computing device if the at least one file is classified as an untrusted file.
16. The step of restricting access to the file on the user computing device comprises: prohibiting the transfer of said at least one file to said user computing device; prohibiting the at least one file from being executed on the user computing device; prohibiting the at least one file from being opened on the user computing device; deleting the at least one file; or 16. The method of claim 15, further comprising at least one of the steps of: quarantining the at least one file.
17. 16. The method of claim 15, further comprising the step of, upon obtaining the at least one file, suspending transfer of the at least one file to the user computing device until the at least one file is classified as a trusted file or a non-trusted file.
18. at least one processor and memory operatively connected to the at least one processor; and A computing device comprising instructions that, when executed on a processor, cause the processor to: obtaining at least one file having a digital signature including a DS certificate having certification center information and DS certificate identification information; determining whether the DS certificate is valid by checking whether the DS certificate has the required DS certificate integrity and by authenticating the certificate of the certification center that issued the DS certificate; determining whether the at least one file has the required file integrity and whether the digital signature is valid by checking whether the DS certificate is valid; If the DS certificate is valid, determining whether the DS certificate can be trusted by searching a credential database for credential data associated with the DS certificate identity; and The computer device implementing a checking tool configured to classify the at least one file as a trusted file if the digital signature is valid and the DS certificate is trusted.
19. the checking tool is further configured to classify the at least one file as an untrusted file if the digital signature is invalid or the DS certificate is invalid or untrusted; 20. The computer device of claim 18, further comprising instructions that, when executed by the processor, cause the processor to implement a security tool configured to restrict access to the at least one file of a user computer device if the at least one file is classified as an untrusted file by the checking tool.
20. Computer device operating system (OS); and 20. The computer device of claim 18, further comprising instructions that, when executed by the processor, cause the processor to implement a virtual machine including a virtual machine OS that is different from the computer device OS, and wherein the at least one file is executable only on the virtual machine OS.
Citation Information
Patent Citations
Information processor, information processing method and program
JP2013045400A
Method and device for providing application integrity verification
JP2018503153A
Malware detection using digital certificates
JP2018520437A
Silent-mode signature testing in Anti-malware processing
US20110126286A1
System and method for day-zero authentication of activex controls
US20130055369A1