Executable entity reputation intelligence: a novel intelligence supporting IT governance
Online published: 2024-07-08
Copyright
Currently, IT governance faces increasingly complex challenges in network security. Traditional defense mechanisms have struggled to cope with the evolving tactics of attacks, revealing numerous limitations in existing defensive technologies. Addressing these issues, from the core of cyber security confrontation, the concept of executable entity reputation intelligence was proposed . It explored five dimensions: publisher reputation, content reputation, behavioral reputation, location reputation and distribution reputation. Through concrete case analysis, it demonstrated the effectiveness of multi-dimensional reputation evaluation based on executable entity reputation intelligence and underscored its pivotal role in supporting IT governance. This innovative concept introduces a new theoretical framework and methodology for IT governance, empowering cyber security practitioners to better identify threats, devise IT governance strategies, so then enhance overall security posture, resulting in more significant defensive achievements.
XIAO Xinguang , TONG Zhiming , LI Shilei , CHEN Enjun . Executable entity reputation intelligence: a novel intelligence supporting IT governance[J]. Journal of Cybersecurity, 2024 , 2(2) : 107 -118 . DOI: 10.20172/j.issn.2097-3136.240209
表 1 现有执行体治理相关技术的价值和局限性Table 1 Value and limitations of existing techniques in executable entity governance |
| 技术类型 | 价值 | 局限性 |
| 反病毒引擎技术[9] | 提供对海量的已知威胁的精准识别,识别粒度包括分类、家族、变种等。 提供威胁的配套知识,包括执行体的历史应用和攻击活动关联、技战术解释和攻击组织的精准指向等 | 反病毒引擎主体上是基于模式识别构建的,其机理决定了它是一种终究可以被免杀绕过的资源。 反病毒引擎本身依赖于场景内对执行对象的获取能力,如果缺乏前端输入,则无法发挥价值 |
| 威胁情报技术[10] | 通过生产Hash、IP、URL等具有明确指向性的信标威胁情报[11],利用安全产品的扩展能力,可达成相对快捷的运营、消费闭环 | 其面向文件对象层面主要依赖于Hash,但Hash规则面对高级威胁事实上早已失效,因为高级威胁采用文件不落地、“一场景一载荷”等手段,信标已然处于情报痛苦金字塔的最底层[12]。 面向工具的情报,虽然有类似Yara规则的机制,但是总体上仍缺少统一的消费机制。 TTP层面的情报,对于目前的安全产品体系而言非常难以消费[13] |
| 系统主防技术[14] | 系统主防技术是一种动态对抗机制[15],能够实现执行体在动作级别的发现和评价,可以约束执行体的资源访问和操作。 可以作为防御环境的主动塑造的一部分。 是一种动态拒止能力 | 对系统资源高度依赖,常态化占用系统资源,在自身出现不稳定和误报的情况下会对业务的连续性和系统稳定性产生影响 |
| 可信计算技术[16] | 解决了执行体的发布者身份鉴别问题,能有效地支撑验证执行体是否由原厂发布。 提供了在执行体启动和运行时的可信验证 | 难以有效覆盖脚本、宏等非二进制编译执行体。 数字证书系统本身存在盗用、冒用、滥用等问题,申请数字证书的代价极低,在每天所捕获的恶意样本中,目前约有40%带有可验证通过的数字签名,在多起攻击事件中,均发现了盗用其他厂商的签名证书进行签名的情况。 在信任传导机制下,可信根的问题会传导至整个信任链[17],继而引发系统性的安全风险 |
| 内存对抗技术 | 过去20多年操作系统在内存安全层面的增强技术,如数据执行保护[18]、地址随机化[19]、堆栈平衡等,有效地降低了缓冲区溢出的攻击成功率 | 对应用层面的漏洞往往无效。 对独立文件载体的恶意代码执行无效 |
表 2 执行体信誉情报的部分评估方法和评价指标Table 2 Partial assessment methods and evaluation indicators of executable entity reputation intelligence |
| 信誉类型 | 评估方法 | 评价指标 |
| 发布者信誉 | 检查软件开发者的历史记录,包括过去发布的程序的安全性、质量和合规性。 查看软件开发者的认证和授权信息,包括数字签名、证书等。 分析软件开发者的信誉评级和用户评价,了解其声誉和信任度 | 过去发布的程序的安全性评分。 数字签名和证书的有效性和信任度。 用户评价和反馈的数量和质量 |
| 内容信誉 | 使用静态和动态分析工具对执行体的结构和属性进行检查,识别其中的风险性和脆弱性。 检查执行体中是否含有已知的恶意指令或数据。 分析执行体的功能和行为,判断其合规性和规范性 | 静态和动态分析结果的风险评分。 含有恶意指令或数据的检测结果。 功能和行为的合规性的评估结果 |
| 行为信誉 | 监控执行体的操作记录和系统交互,检测是否存在异常行为。 分析执行体的网络通信模式和数据传输行为,识别是否有异常的网络活动。 考察执行体的操作权限和访问控制,了解其是否符合安全策略和规定 | 异常操作和系统交互的检测次数和频率。 异常网络通信和数据传输的分析结果。 操作权限和访问控制的符合性评估 |
| 位置信誉 | 检查执行体的存储路径和文件夹关联,确定其在系统中的位置。 分析执行体的存储名称和存储路径的合法性和完整性 | 存储路径和文件夹关联的合法性和完整性评估结果 |
| 分布信誉 | 分析执行体在网络资产群中的分布情况和出现频率,识别其在群组和全局中的地位。 检测执行体在时间轴上的出现情况,了解其在特定时空中的流行度和生僻度。 考察执行体与其他节点的互动模式和通信频率,评估其在网络中的影响力和信任度 | 分布情况和出现频率的分析结果。 时间轴上出现情况的统计数据。 与其他节点的互动模式和通信频率的评估结果 |
表 3 执行体信誉情报说明Table 3 Description of executable entity reputation intelligence |
| 信誉类型 | 共性能力 | 可扩展性 | 可运营性 |
| 发布者信誉 | 通过对发布者的历史记录、用户反馈及其他相关信息进行评估,形成对发布者在特定领域或用途中的信誉水平的判断能力,产生决策价值 | 验证方式可扩展,不仅可通过签名验证、版权归属验证、开发者身份验证进行信誉验证,还支持验证维度的可扩展,包括但不限于内容中的邮件、账号等进行发布信誉验证。 知识输出可扩展,除了发布者信誉基础判定结果外,还支持判定依据、判定标签等可扩展,支撑联合信誉判定和治理清晰化 | 通过对软件开发者或厂商的合法性及信誉进行采集分析,形成对现有开发者或厂商的具有历史信誉的标识信息,并持续追踪更新数据,最终形成对历史以来所有大型厂商及知名开发者的信誉评估能力;同时用户可以自主维护自身场景下的发布者信誉库 |
| 内容信誉 | 通过对执行体的开发者、内容完整性、数字签名、组成成分等方面的评估,形成对内容真实性和可信度的判断能力,产生用户信任和风险评估的价值 | 验证方式可扩展,内容信誉库中不仅支持MD5类型哈希信誉,还支持SHA1、SHA256等哈希信誉。 知识输出可扩展,除了基本的信誉状态、威胁度、置信度、病毒名外,还支持高阶知识包括应用类别、功能描述、编译打包信息等 | 通过对已知操作系统、系统软件、各大软件厂商发布的软件及现有网络空间活跃的恶意代码的系统采集和整理,形成对已知执行体内容的唯一标识信息,并持续更新数据,最终形成对已知执行体内容信誉评估能力;同时用户可以自主维护自身场景下的内容信誉库 |
| 行为信誉 | 通过对文件或软件的行为分析、行为历史记录等方面进行评估,形成对文件在系统中的行为信誉判断能力,产生对系统安全和稳定性的价值 | 验证方式可扩展,行为信誉库中不仅包含用户态下的恶意行为、可疑行为和常规行为,还可以扩展到内核形态下的bootkit、rootkit[21]等。 知识输出可扩展,除了基本的信誉状态、威胁度、置信度、病毒名外,还支持高阶知识包括行为战术、技术、防御方法等 | 通过对已知执行体运行时调用的系统函数序列以及特定代码片段的分析整理,形成对特定运行行为的标识信息,并持续更新行为的种类及实现模式,最终形成对特定行为的信誉评估能力;同时用户可以自主维护自身场景下的行为信誉库 |
| 位置信誉 | 通过对执行体的存储路径(包括系统和常用软件的文件名和文件路径)的安全性进行评估,形成对文件存储路径的信誉判断能力,产生对磁盘落地文件可信性的价值 | 验证方式可扩展,位置信誉库中不仅包含系统或常用软件的文件名、文件路径、文件路径名等位置信息,还可包含升级补丁、开源软件形成的文件名和文件路径信誉。 知识输出可扩展,除了基本的信誉状态、威胁度、置信度、病毒名外,还支持高阶知识包括归属信息、应用类别、功能描述等 | 通过对已有操作系统及各大软件厂商提供的软件的全部执行体所在路径进行采集统计整理,形成所有执行体的默认已知路径信息,并持续更新,最终形成对特定执行体所在路径的信誉评估能力;同时用户可以自主维护自身场景下的位置信誉库 |
| 分布信誉 | 通过统计执行体在时空中的分布生僻度和流行度,包括但不限于技术栈生僻度、执行体首次出现时间等,形成对执行体的分布信誉判定能力,产生对执行体分布的安全性和传播可靠性的价值 | 验证方式可扩展,分布信誉基线库中不仅包含群组的生僻度、流行度分布信誉,还可包含全局分布信誉。 知识输出可扩展,除了基本的信誉状态、威胁度、置信度、病毒名外,还支持高阶知识包括流行度、用户使用量等 | 通过对特定执行体在整个网络空间环境下所有已知网络资产中的分布情况进行采集和统计,以及对该执行体在整个网络空间时间轴上出现的情况进行统计,形成该执行体在整个网络时空的生僻度和流行度信息,并持续跟进更新,最终形成对特定执行体的生僻度和流行度的评估能力;同时可以自主维护用户自身场景下的分布信誉库 |
表 4 root.exe的多维信誉评估结果Table 4 Multi-dimensional reputation assessment results of root.exe |
| 基础信息 | filename: root.exe hash: cb6cd09f6a25744a8fa6e4b3e4d260c5 size: 289792 format: BinExecute/Microsoft.EXE path: c:\progra~1\common~1\svstem\MSADC | ||
| 信誉维度 | 单点信誉状态 | 威胁等级 | 置信度 |
| 发布者信誉 | - | - | - |
| 内容信誉 | yes | 无威胁 | 95 |
| 行为信誉 | yes | 无威胁 | 95 |
| 位置信誉 | unknown | - | 0 |
| 分布信誉 | - | - | - |
| 多维信誉 评估结果 | 综合信誉评估结果:可疑 威胁等级:中 置信度:50 处置建议:删除文件 | ||
表 5 攻击者劫持的EXE文件的多维信誉评估结果Table 5 Multi-dimensional reputation assessment results of the EXE file hijacked by the attacker |
| 基础信息 | filename: checx.exe hash: 54b3233604c2ac3ef0baca691b656222 size: 409752 format: BinExecute/Microsoft.EXE path: C:\ProgramData\NX-122a.10.130.isuhfuhSIUDHF.10.130\checx.exe | ||
| 信誉维度 | 单点信誉状态 | 威胁等级 | 置信度 |
| 发布者信誉 | yes | 无威胁 | 95 |
| 内容信誉 | yes | 无威胁 | 95 |
| 行为信誉 | yes | 无威胁 | 95 |
| 位置信誉 | unknown | - | 0 |
| 分布信誉 | yes | 无威胁 | 80 |
| 多维信誉 评估结果 | 综合信誉评估结果:可疑 威胁等级:中 置信度:45 处置建议:删除文件 | ||
表 6 使用被盗私钥签名的执行体多信誉评估结果Table 6 Multi-dimensional reputation evaluation results diagram of the executable signed with stolen private key |
| 基础信息 | filename: nigletdrv.sys hash: 674d63320361225c3292738cbdc91e6b size: 12304 format: BinExecute/Microsoft.SYS | ||
| 信誉维度 | 单点信誉状态 | 威胁等级 | 置信度 |
| 发布者信誉 | yes | 无威胁 | 95 |
| 内容信誉 | unknown | - | 0 |
| 行为信誉 | unknown | - | 0 |
| 位置信誉 | unknown | - | 0 |
| 分布信誉 | - | - | - |
| 多维信誉 评估结果 | 综合信誉评估结果:可疑 威胁等级:中 置信度:35 处置建议:删除文件 | ||
| 1 |
孟秀转,于秀艳,郝晓玲,等. IT治理:标准、框架与案例分析[M]. 北京:清华大学出版社,2012.
MENG X Z,YU X Y,HAO X L,et al. IT governance:standards,frameworks and case studies[M]. Beijing:Tsinghua University Press,2012.
|
| 2 |
WEILL P,ROSS J W. IT governance:how top performers manage IT decision rights for superior results[M]. Boston:Harvard Business School Press ,2004.
|
| 3 |
李建方, 张士铎. 高级可持续威胁攻击关键技术探究[J]. 中国传媒大学学报(自然科学版), 2016, 23 (3): 51- 55.
LI J F, ZHANG S D. Research on advanced persistent threat attack techniques[J]. Journal of Communication University of China (Science and Technology), 2016, 23 (3): 51- 55.
|
| 4 |
DEHGHANTANHA A,CONTI M. Cyber threat intelligence[M]. Berlin:Springer,2018.
|
| 5 |
安天科技集团股份有限公司. 执行体治理为什么是IT治理的基石[EB/OL]. (2023-01-19)[2024-01-19]. https://zhuanlan. zhihu. com/p/600109739.
Antiy Technology Group Co.,Ltd. Why executable entity governance is the cornerstone of IT governance[EB/OL]. (2023-01-19)[2024-01-19]. https://zhuanlan.zhihu.com/p/600109739.
|
| 6 |
谌志华. 安全基线管理在企业中的应用[J]. 计算机安全, 2013, (3): 19- 22.
SHEN Z H. The application of security baseline management in enterprises[J]. Computer Security, 2013, (3): 19- 22.
|
| 7 |
肖新光. 强化网络安全的公共安全属性[J]. 中国信息安全, 2023, (4): 43- 44.
XIAO X G. Strengthening the public safety attribute of cybersecurity[J]. China Information Security, 2023, (4): 43- 44.
|
| 8 |
肖新光. 强化公共安全服务属性牵引网络安全结构性升级[C]//2023网络安全优秀创新成果大赛. 武汉:中国网络安全产业联盟,2023,9(2):11-12.
XIAO X G. Strengthening public safety services to drive structural upgrades in cybersecurity [C] // 2023 Cybersecurity Excellence and Innovation Competition. Wuhan:China Cybersecurity Industry Alliance,2023,9(2):11-12.
|
| 9 |
李兆星. 反病毒引擎的自主创新与发展[J]. 信息网络安全, 2010, (5): 56- 58.
LI Z X. Independent innovation and development of anti-virus engine[J]. Information and Network Security, 2010, (5): 56- 58.
|
| 10 |
TOUNSI W, RAIS H. A survey on technical threat intelligence in the age of sophisticated cyber attacks[J]. Computers & Security, 2018, 72 (1): 212- 233.
|
| 11 |
ZIBAK A,SIMPSON A. Cyber threat information sharing:perceived benefits and barriers[C]//Proceedings of the 14th International Conference on Availability,Reliability and Security. New York:Association for Computing Machinery,2019:1-9.
|
| 12 |
SKOPIK F, SETTANNI G, FIEDLER R. A problem shared is a problem halved: a survey on the dimensions of collective cyber defense through security information sharing[J]. Computers & Security, 2016, 60 (7): 154- 176.
|
| 13 |
HUTCHINS E M, CLOPPERT M J, AMIN R M. Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains[J]. Leading Issues in Information Warfare & Security Research, 2011, 1 (1): 80- 106.
|
| 14 |
DENNING D E. An intrusion-detection model[J]. IEEE Transactions on Software Engineering, 1987, 13 (2): 222- 232.
|
| 15 |
SHINDER D,TITTEL E. Scene of the cybercrime:computer forensics handbook[M]. Waltham:Syngress Publishing,2002.
|
| 16 |
冯登国, 秦宇, 汪丹, 等. 可信计算技术研究[J]. 计算机研究与发展, 2011, 48 (8): 1332- 1349.
FENG D G, QIN Y, WANG D, et al. Research on trusted computing technology[J]. Computer Research and Development, 2011, 48 (8): 1332- 1349.
|
| 17 |
ADAMS C,LLOYD S. Understanding PKI:concepts,standards and deployment considerations[M]. Boston:Addison-Wesley Professional,2002.
|
| 18 |
高迎春, 周安民, 刘亮. Windows DEP 数据执行保护技术研究[J]. 信息安全与通信保密, 2013, (7): 77- 79,82.
GAO Y C, ZHOU A M, LIU L. Data-execution prevention technology in Windows System[J]. Information Security and Communications Privacy, 2013, (7): 77- 79,82.
|
| 19 |
徐鑫, 张松年, 胡建伟. 基于任意函数地址的 ASLR 绕过技术研究[J]. 信息网络全, 2016, 16 (7): 47- 52.
XU X, ZHANG S N, HU J W. Research on ASLR bypass technology based on arbitrary function address[J]. Netinfo Security, 2016, 16 (7): 47- 52.
|
| 20 |
沈昌祥, 张焕国, 王怀民, 等. 可信计算的研究与发展[J]. 中国科学: 信息科学, 2010, 40 (2): 139- 166.
SHEN C X, ZHANG H G, WANG H M, et al. Research and development of trusted computing[J]. Science China: Information Sciences, 2010, 40 (2): 139- 166.
|
| 21 |
BLUNDEN B,BOOKSX I. The rootkit arsenal:escape and evasion in the dark corners of the system[M]. Boston:Jones and Bartlett Publishers,2012.
|
| 22 |
MOORE D,SHANNON C,CLAFFY K C. Code-red:a case study on the spread and victims of an internet worm[C]//The Second Internet Measurement Workshop. San Diego:San Diego Supercomputer Center,University of California,2002:273-284.
|
| 23 |
ZHU S F,ZHANG Z Y,YANG L M,et al. Benchmarking label dynamics of virusTotal engines[C]//In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security (CCS '20). New York:Association for Computing Machinery,2020:2081-2083.
|
| 24 |
安天CERT. "游蛇”黑产团伙利用微信传播恶意代码的活动分析[EB/OL]. (2023-08-22)[2024-03-01]. https://www. antiy. cn/research/notice&report/research_report/SnakeTrojans_Analysis. html.
AntiyCERT. Analysis of the Malicious Code Dissemination Activities by the "SwimSnake" Black Market Group through WeChat [EB/OL]. (2023-08-22)[2024-03-01]. https://www.antiy.cn/research/notice&report/research_report/SnakeTrojans_Analysis.html.
|
| 25 |
HARITHA U, LOKANADHAM N T. A survey on windows component loading vulnerabilities[J]. International Journal of Advanced Research in Computer Engineering and Technology, 2013, 2 (5): 1780- 1783.
|
| 26 |
HPWARD M,LEBLANC D. Writing Secure Code (2nd Edition)[M]. Redmond:Microsoft Press,2002.
|
| 27 |
BELLARE M,ROGAWAY P. Entity authentication and key distribution[C]// Proceedings of the 13th Annual International Cryptology Conference on Advances in Cryptology. Berlin:Spnnger-Verlag,1993:232-249.
|
| 28 |
曾孜. 网络安全中的数字签名技术分析与应用[J]. 计算机系统应用, 2001, (8): 33- 35.
ZENG Z. Analysis and application of digital signature technology in network security[J]. Computer Systems & Applications, 2001, (8): 33- 35.
|
| 29 |
张玉清, 董颖, 柳彩云, 等. 深度学习应用于网络空间安全的现状、趋势与展望[J]. 计算机研究与发展, 2018, 55 (6): 1117- 1142.
ZHANG Y Q, DONG Y, LIU C Y, et al. Situation, trends and prospects of deep learning applied to cyberspace security[J]. Journal of Computer Research and Development, 2018, 55 (6): 1117- 1142.
|
| 30 |
刘敖迪, 杜学绘, 王娜, 等. 区块链技术及其在信息安全领域的研究进展[J]. 软件学报, 2018, 29 (7): 2092- 2115.
LIU A D, DU X H, WANG N, et al. Research progress of blockchain technology and its application in information security[J]. Journal of Software, 2018, 29 (7): 2092- 2115.
|
/
| 〈 |
|
〉 |