
计 算 机 研 究 与 发 展
DOI
:
10.7544∕issn1000G1239.2021.20200937
JournalofCom
p
uterResearchandDevelo
p
ment 58
(
5
):
1035 1044
,
2021
收稿日期
:
2020
-
11
-
09
;
修回日期
:
2021
-
02
-
04
基金项目
:
国家自然科学基金项目
(
61872279
);
陕西省重点研发计划项目
(
2020GYG004
,
2019ZDLGY12G06
)
Thisworkwassu
pp
ortedb
y
theNationalNaturalScienceFoundationofChina
(
61872279
)
andtheKe
y
ResearchandDevelo
p
ment
Pro
g
ramofShaanxiProvince
(
2020GYG004
,
2019ZDLGY12G06
)
.
面向数字货币特征的细粒度代码注入攻击检测
孙
聪
1
李 占 魁
1
,
2
陈
亮
1
马 建 峰
1
乔 新 博
1
1
(
西安电子科技大学网络与信息安全学院
西安
710071
)
2
(
华为技术有限公司
西安
710075
)
(
suncon
g
@xidian.edu.cn
)
Di
g
italCurrenc
y
FeaturesOrientedFineGGrainedCodeIn
j
ectionAttackDetection
SunCon
g
1
,
LiZhankui
1
,
2
,
ChenLian
g
1
,
MaJianfen
g
1
,
andQiaoXinbo
1
1
(
Schoolo
f
C
y
berEn
g
ineerin
g
,
XidianUniversit
y
,
Xian
710071
)
2
(
HUAWEITechnolo
g
iesCo
.
,
Ltd
,
Xian
710075
)
Abstract Di
g
italcurrencieshavedevelo
p
edra
p
idl
y
andemer
g
edasacriticalform ofour
p
a
y
ment
s
y
stem.Conse
q
uentl
y
,
thea
pp
licationsand
p
latformsofdi
g
italcurrenciesandtheir
p
a
y
mentservices
areextensivel
y
ex
p
osedtovariousex
p
loitsb
y
malware.Inat
yp
icalscenario
,
modernransomware
usuall
y
levera
g
esdi
g
italcurrenciesasthe medium of
p
a
y
ment.ThestateGofGtheGartcodein
j
ection
attackdetectionshaverarel
y
consideredsuch di
g
italcurrenc
y
Grelated memor
y
features
,
thuscan
hardl
y
identif
y
the maliciousbehaviorsofransomware.To miti
g
atethisissue
,
we
p
ro
p
oseafineG
g
rainedschemeofmemor
y
forensicstofacilitatethedetectionofhostGbasedcodein
j
ectionattackswith
theabilit
y
toidentif
y
ransomware.Weca
p
turethedi
g
italcurrenc
y
Grelatedmemor
y
featuresexhibited
inthe
p
rocedureofinducin
g
thevictims
p
a
y
ment.Weincor
p
oratesuchmemor
y
featuresintoasetof
g
eneralmemor
y
featuresandim
p
lementafineG
g
raineddetections
y
stem oncodein
j
ectionattacks.
Accordin
g
totheex
p
erimentalresults
,
thenewschemeofmemor
y
forensicseffectivel
y
im
p
rovesthe
p
erformanceofthestateGofGtheGartdetections
y
stem ondifferentmetrics.Meanwhile
,
oura
pp
roach
enablesthe detection s
y
stems of hostGbased codein
j
ection attacksto ca
p
turethe behaviors of
ransomware
p
recisel
y
.Moreover
,
theextractionofthenewl
yp
ro
p
osedmemor
y
featuresisefficient
,
andourdetections
y
stemisca
p
ableofdetectin
g
unknownmalwarefamilies.
Ke
y
words codein
j
ectionattack
;
machinelearnin
g
;
memor
y
forensics
;
ransomware
;
di
g
italcurrenc
y
摘
要
数字货币的迅速发展使其被越来越多的恶意软件利用
.
现有勒索软件通常使用数字货币作为支
付手段
,
而现有代码注入攻击检测手段缺乏对相关恶意特征的考虑
,
使得其难以有效检测勒索软件的恶
意行为
.
针对此问题
,
提出了一种细粒度的 代码注 入攻击 检测内 存特征 方案
,
利用勒 索软件 在引导 被攻
击者支付过程中表现的数字货币内存特征
,
结合多种通用的细粒度内存特征
,
实现了一种细粒度的代码
注入攻击检测系统
.
实验结果表明
:
新的内存特征方案能够在多个指标上有效提升现有检测系统内存特
征方案的检测性能
,
同时使得基于主机的代码注入攻击检测系统能够准确检测勒索软件行为
,
系统还具
有较好的内存特征提取性能及对未知恶意软件家族的检测能力
.
关键词
代码注入攻击
;
机器学习
;
内存取证
;
勒索软件
;
数字货币
中图法 分类号
TP309.5
评论