The invention provides a file-free
attack detection method, device and equipment and a computer readable medium, and belongs to the field of network and
information security. According to the scheme, in the process of monitoring the key process, the calling behavior fragments related to the memory can be continuously collected, and the calling behavior sequence is obtained; performing
dynamic feature extraction on the calling behavior sequence to obtain
memory behavior features of the key process, such as
memory behavior fingerprints, execution chain node representation and the like; and executing a corresponding
anomaly detection method based on the
memory behavior characteristics, such as a
fingerprint matching method corresponding to a memory behavior
fingerprint, an abnormal path scoring method corresponding to execution chain node representation and the like, and obtaining an
anomaly detection result without file
attack. According to the scheme, the calling behavior sequence of the memory related to the key process is collected for
dynamic feature extraction, single-point, continuous and multi-section behavior anomalies can be comprehensively recognized, potential
attack behaviors can be mined, linkage analysis is carried out on the
link level, continuous and anti-interference detection is achieved, and high elasticity and flexible configuration are achieved.