BMC intrusion protection method and device, BMC and computer equipment
By setting up isolated service modules and security detection modules in BMC and realizing security detection and defense of BMC, the problem of insufficient resistance to APT attacks is solved, the security and credibility of BMC are improved, and an effective dynamic defense chain is formed.
Patent Information
- Application Number
- CN202311524436.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2043-11-14
AI Technical Summary
The prior art is difficult to effectively improve the resistance of the substrate management controller (BMC) to advanced long-term threat (APT) attacks, resulting in the threat of the security and reliability of the BMC.
By setting up communication isolation service modules and security detection modules in the BMC, and isolating the storage media accessed by the service modules and security detection modules, security detection and defense of the BMC are achieved. The security detection module acquires the data stored in the storage medium associated with the service module, analyzes the data to perceive the security situation of the service module, and restarts the BMC through the downgrade startup mode when an APT attack is detected.
Through this in-depth defense solution, the BMC's resistance to APT attacks is improved, the security and credibility of the BMC are ensured, and a dynamic defense chain of defense->detection->degradation->recovery is formed.
Smart Images

Figure CN120017290A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the computer field, and in particular to a BMC intrusion protection method, device, BMC and computer equipment. Background Art
[0002] At present, attacks on computer equipment have gradually transformed from decentralized attacks to organized and targeted advanced persistent threats (APT). As a security center, the baseboard management controller (BMC) in computer equipment can authenticate the components in computer equipment to prevent components from being counterfeited, tampered or replaced, and ensure the safety and reliability of components. Therefore, how to improve the ability of BMC to resist APT attacks and ensure the safety and reliability of BMC is an urgent problem to be solved. Summary of the invention
[0003] The present application provides a BMC intrusion protection method, apparatus, BMC and computer equipment, thereby effectively improving the BMC's ability to resist APT attacks and ensuring the BMC is secure and reliable.
[0004] In a first aspect, a BMC intrusion protection method is provided, and the method is applied to the BMC in a computer device. The BMC includes a business module and a security detection module, the business module is used to provide management functions for components in the computer device, and the security detection module is used to perform security detection on the BMC. Among them, the business module and the security detection module are isolated in communication, and the storage medium accessed by the business module and the security detection module are isolated. The method includes: the security detection module obtains data stored in the storage medium associated with the business module, analyzes the data to perceive the security situation of the business module, and obtains a security detection result. When the security detection result indicates that the BMC has been attacked by an APT, the BMC is restarted in a degraded startup mode.
[0005] Compared with the BMC's defense strategy that only relies on border defense, APT attacks break through border defense, and BMC is breached by APT attacks, reducing the value of BMC as a trusted center. The present application provides a defense-in-depth solution, that is, on the basis of defense, BMC adds intrusion detection capabilities; by isolating the business module and the security detection module, the security detection module is prevented from being affected when the business module is attacked by APT; moreover, the security detection module analyzes the data of the BMC's business module to perceive the security situation of the business module. When the BMC may be attacked by APT, it can also restart the BMC while ensuring the recoverability of the basic business or BMC, thus forming a dynamic defense chain of defense->detection->downgrade->recovery, which effectively improves the BMC's ability to resist APT attacks and ensures the security and trustworthiness of the BMC.
[0006] In one possible implementation, a security detection result is obtained based on data stored in a storage medium associated with the business module, including: based on data stored in a first storage medium associated with the business module, detecting the operation security of the business module and obtaining a security detection result, wherein the first storage medium is used to store data required for the operation of the business module.
[0007] Therefore, by analyzing the data during the operation of the business module, the operation security of the business module can be detected, that is, the operating environment security when the BMC implements management operations on the components in the computer equipment can be detected. For example, by analyzing the data stored in the memory associated with the business module, by detecting the memory security, it can be perceived that the BMC may be attacked by APT, and the ability of the BMC to resist APT attacks can be improved.
[0008] In another possible implementation, a security check result is obtained based on data stored in a storage medium associated with the business module, including: based on data stored in a second storage medium associated with the business module, detecting data security of the business module to obtain a security check result, wherein the second storage medium is used to store persistent data of the business module.
[0009] Therefore, by analyzing the persistent data of the business module, the data security of the business module can be detected. For example, by analyzing the data stored in the non-volatile memory associated with the business module, by detecting data security, it can be perceived that the BMC may be attacked by APT, thereby improving the BMC's ability to resist APT attacks.
[0010] In another possible implementation, obtaining a security detection result according to data stored in a storage medium associated with the business module includes: obtaining a security detection result according to trusted root verification data of the BMC.
[0011] Since the trusted root is the basis of trust in the trusted computer system, the trusted root of BMC is used to perform integrity verification on the data of the business module, that is, to check whether the database is in a consistent state and whether the data has been modified based on the integrity constraints. This reduces the possibility that the trusted root may be tampered with, improves the ability of BMC to resist APT attacks, and ensures that BMC is safe and reliable.
[0012] In another possible implementation, obtaining a security detection result based on data stored in a storage medium associated with the business module includes: obtaining the security detection result by analyzing data based on an advanced threat analysis system.
[0013] The remote system provides intrusion detection capabilities that require high computing power, solving the problem of insufficient computing power of the BMC embedded processor. The BMC and the remote system work together to realize the perception that the BMC may be attacked by APT, thereby improving the BMC's ability to resist APT attacks.
[0014] In another possible implementation, restarting the BMC in the degraded startup mode includes: restarting the security detection module, and mounting a storage medium associated with the security detection module.
[0015] In another possible implementation, after restarting the security detection module and mounting the storage medium associated with the security detection module, the method also includes: restarting the security detection module according to the restart instruction, mounting the storage medium associated with the security detection module, and restarting the business module, mounting the storage medium associated with the business module.
[0016] In some embodiments, a storage medium associated with the security detection module stores initial data for restarting the service module, the security detection module configures the initial data to the storage medium associated with the security detection module, and the service module restarts according to the initial data.
[0017] Under the premise of protecting the firmware security of BMC by secure boot, memory security is ensured by resetting, and only the storage media associated with the security detection module is mounted to ensure data security. The existing APT attack data can be cleared to block APT attacks. After blocking the attack, the operation of the security detection module can maintain the operating capacity of the core business of the operating system, providing basic functions that can be remotely managed without losing management.
[0018] In a second aspect, a security detection device is provided, the security detection device comprising modules for executing the BMC intrusion protection method in the first aspect or any possible design of the first aspect. For example, the security detection device comprises a communication module, a detection module and a control module.
[0019] The detection module is used to obtain security detection results based on the data stored in the storage medium associated with the business module. The data is used to perceive the security situation of the business module. The security detection results are used to indicate the possibility of the BMC being attacked by advanced long-term threats (APTs).
[0020] The control module is used to determine that the BMC is attacked by APT according to the security detection result, and restart the BMC in a degraded startup mode.
[0021] In one possible implementation, when the detection module obtains a security detection result based on data stored in a storage medium associated with the business module, it is specifically used to: detect the operation safety of the business module based on data stored in a first storage medium associated with the business module to obtain a security detection result, and the first storage medium is used to store data required for the operation of the business module.
[0022] In another possible implementation, when the detection module obtains a security detection result based on the data stored in the storage medium associated with the business module, it is specifically used to: detect the data security of the business module based on the data stored in the second storage medium associated with the business module to obtain a security detection result, and the second storage medium is used to store the persistent data of the business module.
[0023] In another possible implementation, when the detection module obtains the security detection result according to the data stored in the storage medium associated with the business module, it is specifically used to obtain the security detection result according to the trusted root verification data of the BMC.
[0024] In another possible implementation, when the detection module obtains the security detection result according to the data stored in the storage medium associated with the business module, it is specifically used to: analyze the data based on the advanced threat analysis system to obtain the security detection result.
[0025] In another possible implementation, when the control module restarts the BMC in the degraded startup mode, it is specifically used to: restart the security detection module, and mount the storage medium associated with the security detection module.
[0026] In another possible implementation, after the control module restarts the security detection module and mounts the storage medium associated with the security detection module, it is also used to: restart the security detection module according to the restart instruction, mount the storage medium associated with the security detection module, and restart the business module, and mount the storage medium associated with the business module.
[0027] In a third aspect, a BMC is provided, which includes a business module and a security detection module. The business module is used to provide management functions for components in a computer device, and the security detection module is used to perform security detection on the BMC. The business module and the security detection module are isolated in communication, and the storage media accessed by the business module and the security detection module are isolated. The security detection module is used to execute the operating steps of the method in the first aspect or any possible implementation of the first aspect.
[0028] In a fourth aspect, a computer device is provided, the computer device comprising a processor, a memory and the BMC as described in the third aspect, the BMC being used to execute the operation steps of the method in the first aspect or any possible implementation of the first aspect.
[0029] In a fifth aspect, a computer-readable storage medium is provided, comprising: computer software instructions; when the computer software instructions are executed in a processor, the processor executes the operating steps of the method described in the first aspect or any possible implementation of the first aspect.
[0030] In a sixth aspect, a computer program product is provided. When the computer program product is run on a computer, the computer is caused to execute the operation steps of the method described in the first aspect or any possible implementation manner of the first aspect.
[0031] The technical effects brought about by any design method in the second to sixth aspects can refer to the technical effects brought about by the first aspect or different design methods in the first aspect, and will not be repeated here.
[0032] Based on the implementations provided in the above aspects, this application can also be further combined to provide more implementations. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 A schematic diagram of the structure of a baseboard management controller provided in this application;
[0034] Figure 2 A schematic diagram of the structure of another baseboard management controller provided in this application;
[0035] Figure 3 A flowchart of a BMC intrusion protection method provided in this application;
[0036] Figure 4 A schematic diagram of the structure of a safety detection device provided in this application;
[0037] Figure 5 A schematic diagram of the structure of a computer device provided in this application. DETAILED DESCRIPTION
[0038] To facilitate understanding, the main terms involved in this application are first explained.
[0039] Baseboard management controller (BMC): A chip integrated into the motherboard or plugged into the motherboard in the form of Peripheral Component Interconnect Express (PCIe), which is a dedicated controller used to manage the server. For example, device information management, server status management, remote control management of the server, maintenance management, etc.
[0040] Root of Trust (ROT): Also known as the root of trust, it is the basis of trust in a trusted computer system. The root of trust includes the root of trusted measurement, the root of trusted storage, and the root of trusted reporting.
[0041] Advanced Persistent Threat (APT): Also known as advanced persistent threat, it is a complex and persistent network attack. Advanced persistent threat contains three elements: advanced, long-term, and threat. Advanced means that executing APT attacks requires a higher degree of customization and complexity than traditional attacks, and it takes a lot of time and resources to study and determine the target's vulnerabilities. Long-term means that in order to achieve a specific purpose, it is necessary to continuously observe the target and maintain long-term access to the target. The threat emphasizes that the target is a high-value organization. Once the attack is successful, it will often cause huge economic losses to the target, or even a devastating blow.
[0042] The attack phases of advanced persistent threats include information collection, external penetration, command control, internal spread, and data leakage. From targeting to successful attack, there are multiple stages, which can be called an attack chain in the security field.
[0043] APT attackers are usually an organization. After selecting a target, APT attackers collect all information related to the target. The information includes the target's organizational structure, office location, products and services, address book, email address, meeting schedule, portal website directory structure, internal network architecture, deployed network security equipment, external open ports, office OS and email system used by corporate employees, and the system and version used by the company's World Wide Web (web) server.
[0044] After the information is collected, malware is developed and deployed in the target. Malware is usually a small remote control tool, which can be called a remote administration tool (Remote Administration Tool or Remote Access Trojan, RAT), which is used to establish a command and control channel (Command and control channels, C&C) with the control server.
[0045] When a user uses a client program or browser with a vulnerability to open a file containing malware, the malware will hit the vulnerability, download and install the malware, and successfully attack the target. Malicious programs usually also elevate permissions or add administrator users. For example, malicious programs are started at startup, and even quietly closed or modified in the background the host firewall settings, so that the malicious program is as undetectable as possible.
[0046] Since hosts within the same organization often use the same system and similar application software environments, they have the same vulnerabilities to a large extent. After compromising an intranet host, malicious programs will spread horizontally to other hosts in the subnet or vertically to the company's internal servers. Since remote management tools have keyboard logging and screen recording functions, it is easy to obtain users' domain passwords, email passwords, and various server passwords.
[0047] The attack process also uses anonymous networks, encrypted communications, and clearing traces to protect itself. When sending confidential information outward, various technical means are also used to avoid being discovered by network security equipment. On the one hand, confidential information is broken up into small pieces, encrypted or obfuscated to prevent data leakage prevention (DLP) equipment from discovering leaks through keyword scanning; on the other hand, the sending rate is limited to try not to exceed the detection threshold of various security devices.
[0048] In order to solve the problem that BMC cannot resist APT attacks, the present application provides a BMC intrusion protection method, that is, setting a business module and a security detection module with communication isolation in the BMC, isolating the storage medium accessed by the business module and the security detection module, the business module is used to provide management functions for components in the computer equipment, and the security detection module is used to implement security detection on the BMC. The security detection module obtains the data stored in the storage medium associated with the business module, analyzes the data to perceive the security situation of the business module, and obtains the security detection result. If the security detection result indicates that the BMC has been attacked by APT, the BMC is restarted in a degraded startup mode.
[0049] Compared with the BMC's defense strategy that only relies on boundary defense, that is, through firewalls, interface encapsulation, restricting operating system login, identity and access management (IAM) technology to limit attacker behavior, lack of perception of behavior during the attack process, as BMC exposes more and more interfaces to the outside, it is easy to form vulnerabilities such as command injection, database injection, buffer overflow, etc., resulting in APT attacks breaking through the defense boundary, BMC being breached by APT attacks, and reducing the value of BMC as a trusted center. This application provides a depth defense solution, that is, on the basis of defense, BMC adds intrusion detection capabilities; by isolating the business module and the security detection module, the security detection module is prevented from being affected when the business module is attacked by APT; moreover, the security detection module analyzes the data of the BMC's business module to perceive the security situation of the business module. When predicting that BMC may be attacked by APT, it can also restart BMC while ensuring the recoverability of basic business or BMC, thus forming a dynamic defense chain of defense->detection->downgrade->recovery, effectively improving BMC's ability to resist APT attacks and ensuring BMC security and reliability.
[0050] The method provided in the present application can be applied to computer equipment including a BMC, for example, an inference server, a training server, an inference card, a training card, a cabinet server, a blade server or a rack server.
[0051] The BMC intrusion protection method provided by the present application is described in detail below with reference to the accompanying drawings. Figure 1 This is a schematic diagram of the structure of a baseboard management controller provided in this application. Figure 1 As shown, the baseboard management controller 100 includes a processor 110 , a bus 120 , a storage 130 , a communication interface 140 and a memory 150 (also referred to as a main memory unit). The processor 110 , the storage 130 , the memory 150 and the communication interface 140 are connected via the bus 120 .
[0052] The processor 110 is the control center of the baseboard management controller 100. The processor 110 may be a central processing unit (CPU). The processor 110 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), systems on chip (SoC) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. For ease of description, the following embodiments are described by taking the processor 110 as a CPU as an example.
[0053] Figure 1 The baseboard management controller 100 may include one or more processors. The processor may be a multi-core processor, that is, the processor includes one processor core or multiple processor cores. For example, Figure 1 The processor 110 shown in FIG. 1 includes N processor cores. A processor herein may refer to one or more devices, circuits, and / or computing units for processing data (eg, computer program instructions).
[0054] In some embodiments, the processor 110 runs a business module 111 and a security detection module 112. The business module 111 is used to provide management functions for components in a computer device including the baseboard management controller 100. The security detection module 112 is used to perform security detection on the baseboard management controller 100, that is, to detect the operating environment security and data integrity security of the business module 111. For example, the security detection module 112 obtains data stored in a storage medium associated with the business module 111, analyzes the data to perceive the security situation of the business module 111, and obtains a security detection result. When the security detection result indicates that the baseboard management controller 100 has been attacked by an APT, the baseboard management controller 100 is restarted in a degraded startup mode. This improves the ability of the BMC to resist APT attacks and ensures that the BMC is secure and reliable.
[0055] The service module 111 and the security detection module 112 may be processes or threads running on the same processor 110. The service module 111 and the security detection module 112 are isolated from each other in communication. Alternatively, the service module 111 and the security module 112 may also be processes or threads running on different processors.
[0056] For example, the business module 111 is prohibited from obtaining the user information and user group information of the security detection module 112. For another example, the business module 111 is prohibited from obtaining the process information in the security detection module 112. For another example, the business module 111 is prohibited from sharing the bus with the security detection module 112, with the exception of the business whitelist message bus. For another example, the business module 111 is prohibited from system calls other than the whitelist. The whitelist range may include a security detection interface, an upgrade function interface, a configuration function interface, and a security management interface. The security detection interface is used to allow the security detection module 112 to detect the data of the business module 111 required for APT attacks. The upgrade function interface is used to allow the security detection module 112 to upgrade the data of the business module 111. The configuration function interface is used to allow the security detection module 112 to configure the data of the business module 111. The security management interface is used to allow the security detection module 112 to manage the data of the business module 111. The storage media accessed by the business module 111 and the security detection module 112 are isolated. For example, the memory accessed by the business module 111 is isolated from the memory accessed by the security detection module 112. For another example, the flash memory accessed by the business module 111 is isolated from the flash memory accessed by the security detection module 112. For another example, the business module 111 is prohibited from rewriting the file information in the storage medium accessible to the security detection module 112. For another example, the security detection module 112 is prohibited from reading the file information in the storage medium accessible to the business module 111, and the security detection module 112 can read the data in the storage medium accessible to the business module 111 required for intrusion detection.
[0057] It should be noted that if the business module 111 and the security detection module 112 access different areas of the same storage medium, the different areas of the same storage medium are isolated from each other. For example, by restricting access to different areas of the same storage medium through permission control, different areas of the same storage medium are isolated. By using access control lists, role permissions, etc., authorized users or roles are allowed to access specific areas to prevent unauthorized users from obtaining sensitive information.
[0058] For example, the business module 111 can access the first area in the memory 130, and the first area in the memory 130 is used to store the persistent data of the business module 111. The security detection module 112 can access the second area in the memory 130, and the second area in the memory 130 is used to store the persistent data of the security detection module 112. The first area and the second area in the memory 130 are isolated from each other.
[0059] The business module 111 can access the first area in the memory 150, and the first area in the memory 150 is used to store data when the business module 111 is running. The security detection module 112 can access the second area in the memory 150, and the second area in the memory 150 is used to store data when the security detection module 112 is running. The first area and the second area in the memory 150 are isolated from each other.
[0060] Optionally, inter-process isolation implements communication isolation between the business module 111 and the security detection module 112 and isolation of the accessed storage medium. For example, Linux namespace technology is used to implement communication isolation between the business module 111 and the security detection module 112 and isolation of the accessed storage medium.
[0061] Therefore, in the same operating system of BMC, the system security isolation is formed through users (such as: user name isolation, privileged user and ordinary user isolation), files (such as: storage isolation), inter-process communication isolation, and inter-component communication isolation, and the business module of BMC is isolated from the security detection module of BMC. The storage media used by the two modules are isolated, and the business module is only allowed to access the security detection module through the business interface / system managed by the whitelist, so as to minimize the exposure surface and prevent the security detection module from being affected when the business module is attacked by APT. The security of the security detection module is improved, and then the security detection module analyzes the data of the business module of BMC to perceive the security situation of the business module, which improves the ability of BMC to resist APT attacks and ensures the security and reliability of BMC.
[0062] The memory 150 may be a volatile memory pool. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM) and direct rambus RAM (DR RAM). The memory 150 is used to store data required by the business module 111 when it is running. For example, data such as BMC firmware, business data and network configuration.
[0063] The memory 130 may be a non-volatile memory pool. The non-volatile memory may be a read-only memory (ROM), a disk, or a flash memory. The memory 130 is used to store persistent data of the service module 111, such as user information, alarm data, fault diagnosis data, BMC event subscription range, and alarm reporting level.
[0064] The communication interface 140 is used to realize the communication between the baseboard management controller 100 and external devices or devices. For example, the baseboard management controller 100 communicates with the processor, memory, storage and peripherals in the computer device. In the present application, the communication interface 140 can transmit the data of the business module 111 to the advanced threat analysis system, and the advanced threat analysis system analyzes the data to obtain the security detection result.
[0065] The bus 120 may include a path for transmitting information between the above components (such as the processor 110, the memory 150 and the storage 130). In addition to the data bus, the bus 120 may also include a power bus, a control bus and a status signal bus. However, for the sake of clarity, various buses are marked as bus 120 in the figure. The bus 120 may be a Peripheral Component Interconnect Express (PCIe) bus, or an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a computer express link (CXL), a cache coherent interconnect for accelerators (CCIX), DDR or an embedded multimedia card (EMMC) control protocol. The bus 120 can be divided into an address bus, a data bus, a control bus, etc.
[0066] It is worth mentioning that Figure 1 In the example, the baseboard management controller 100 includes a processor 110 and a memory 130. Here, the processor 110 and the memory 130 are respectively used to indicate a type of device or equipment. In a specific embodiment, the number of each type of device or equipment can be determined according to business requirements.
[0067] In some embodiments, the baseboard management controller 100 may include multiple processors, and the business module 111 and the security detection module 112 may run on different processors. The baseboard management controller 100 may include multiple memories and multiple memories, so that the business module 111 and the security detection module 112 access different memories and memories, and realize communication isolation between the business module 111 and the security detection module 112, and isolation of the storage media accessed by the business module 111 and the security detection module 112.
[0068] For example, Figure 2As shown, the baseboard management controller 100 may include a processor 110 and a processor 160. The processor 110 runs a business module 111. The processor 160 runs a security detection module 112. The baseboard management controller 100 includes a memory 130 and a memory 170. The business module 111 can access the memory 130, and the memory 130 is used to store persistent data of the business module 111. The security detection module 112 can access the memory 170, and the memory 170 is used to store persistent data of the security detection module 112. The memory 130 and the memory 170 are isolated from each other.
[0069] The baseboard management controller 100 includes a memory 150 and a memory 180. The business module 111 can access the memory 150. The memory 150 is used to store data when the business module 111 is running. The security detection module 112 can access the memory 180, and the memory 180 is used to store data when the security detection module 112 is running. The memory 150 and the memory 180 are isolated from each other.
[0070] In other embodiments, the storage medium associated with the security detection module 112 may also store the trusted root of the baseboard management controller 100. For example, the trusted root of the baseboard management controller 100 and the persistent data of the security detection module 112 are stored in the same storage medium, and the memory 130 or the memory 170 in the baseboard management controller 100 stores the trusted root of the baseboard management controller 100 and the persistent data of the security detection module 112. For another example, the trusted root of the baseboard management controller 100 and the persistent data of the security detection module 112 are stored in different storage media. The trusted root of the BMC is used to perform integrity verification on the data of the business module 111.
[0071] As a possible implementation, the business module 111 and the security module 112 may also be implemented by hardware. Accordingly, the business module 111 and the security module 112 may be implemented by one logic circuit or by two logic circuits to respectively implement the functions of the business module 111 and the security module 112 .
[0072] Next, the BMC intrusion protection method process provided by the present application is introduced in conjunction with the accompanying drawings. Figure 3 Here we use Figure 1 The service module 111 and the security detection module 112 of the baseboard management controller 100 shown in the figure are used as an example to detect an APT attack on the baseboard management controller 100.
[0073] Step 310: The security detection module obtains data stored in a storage medium associated with the business module.
[0074] The data stored in the memory accessed by the business module is obtained, and the data stored in the memory includes the data required by the BMC to implement management operations on the components. For example, the security detection module obtains the software programs, business data, network configuration and other data running on the BMC from the memory accessed by the business module.
[0075] The data stored in the flash memory accessed by the business module is obtained. The data stored in the flash memory includes the persistent data of the BMC. For example, the persistent data includes the persistent data required during the operation of the BMC software program, such as alarm data and fault diagnosis data. The persistent data can also include the customer's business module management configuration data for the BMC, such as the BMC event subscription scope and alarm reporting level.
[0076] In some embodiments, the security detection module may periodically obtain data stored in a storage medium associated with the business module, analyze the data, and determine whether the BMC is subject to an APT attack, so as to promptly block the APT attack on the BMC.
[0077] Step 320: The security detection module obtains a security detection result according to the data stored in the storage medium associated with the business module.
[0078] The security detection module analyzes the security situation of the data perception business module and obtains the security detection result. The security detection result is used to indicate the possibility that the BMC is attacked by APT. For example, the security detection result can indicate that the BMC is attacked by APT. The security detection result can also indicate that the BMC may be attacked by APT. The security detection result can also indicate that the BMC is not attacked by APT.
[0079] In some embodiments, the security detection module detects the operational security of the business module based on the data stored in the memory accessed by the business module to obtain a security detection result. Operational security can also be called memory security.
[0080] For example, the security detection module analyzes the programs running on the BMC to determine whether the programs running on the BMC contain malicious programs. If a malicious program is injected into the program running on the BMC, the program is controlled to jump so that the pointer jumps to the attacking program when the BMC program is running, causing an attack on the BMC. If the program running on the BMC contains a malicious program, it is determined that the BMC is under APT attack.
[0081] For another example, the security detection module analyzes the BMC basic data to determine whether the BMC basic data has been tampered with. APT attackers tamper with the BMC basic data, for example, tamper with user information and configuration items, so that APT attackers can create users at will. APT attackers control the BMC as legitimate users, causing attacks on the BMC. The BMC basic data has been tampered with to determine whether the BMC has been attacked by APT.
[0082] For another example, the security detection module analyzes the network status to determine whether there is abnormal traffic accessing the BMC. Abnormal traffic may be generated during the attack on the BMC. If there is abnormal traffic accessing the BMC, it is determined whether the BMC is under APT attack.
[0083] In other embodiments, the security detection module detects data security of the business module based on data stored in a flash memory associated with the business module to obtain a security detection result.
[0084] For example, the security detection module analyzes the BMC basic data to determine whether the BMC basic data has been tampered with. The APT attacker tampered with the BMC basic data in the flash memory, allowing the APT attacker to create users at will. The APT attacker controls the BMC as a legitimate user, causing an attack on the BMC. The BMC basic data has been tampered with, and it is determined that the BMC has been attacked by APT.
[0085] For another example, the security detection module analyzes the security log and can also determine whether there is abnormal data in the security log. During the process of the BMC being attacked, the security log may contain abnormal data. If there is abnormal data in the security log, it is determined that the BMC has been attacked by APT.
[0086] The above-mentioned security detection module is used as an example to illustrate the security detection of BMC. The detection content of the security detection module described in this application includes but is not limited to data related to the BMC execution management operation process, such as programs, basic data, network status, etc., and may also include integrity verification.
[0087] For example, the security detection module may perform integrity verification on data stored in a memory associated with the business module.
[0088] For example, integrity check is performed on the code segment in the memory, hash calculation is performed on the code segment during initial loading to obtain a trusted root, and the trusted root is stored in a storage medium associated with the security detection module. When the BMC runs the code segment, the hash value of the code segment is obtained, and the hash value is compared with the trusted root for integrity check. If the hash value is the same as the trusted root, it means that the program running by the BMC does not contain malicious programs, and it is determined that the BMC has not been attacked by APT; if the hash value is different from the trusted root, it means that the program running by the BMC contains malicious programs, and it is determined that the BMC has been attacked by APT.
[0089] For another example, the security detection module can perform integrity check on the data stored in the flash memory associated with the business module. The security detection module can perform integrity check on the initial data of the BMC. The initial data includes program files, configuration files, and data files stored in the flash memory associated with the business module.
[0090] The security detection module can perform hash calculation on the data in the flash memory to obtain a hash value, and compare the hash value with the trusted root of the BMC. If the hash value is the same as the trusted root of the BMC, it means that the data in the flash memory has not been tampered with and the BMC has not been attacked by APT; if the hash value is different from the trusted root of the BMC, it means that the data in the flash memory may have been tampered with and the BMC has been attacked by APT.
[0091] For example, the integrity of the configuration file is checked, a hash calculation is performed on the configuration file to obtain a trusted root, and the trusted root is stored in a storage medium associated with the security detection module. After the configuration file is modified, a new trusted root is immediately generated, and the trusted root stored in the storage medium associated with the security detection module is updated. The configuration file can be detected during the BMC running code segment, for example, the hash value of the configuration file is compared with the trusted root to determine whether it is the same, and whether the BMC is attacked by APT.
[0092] In addition, since the BMC program may have vulnerabilities, APT attackers have long studied the vulnerabilities in the BMC program and gradually penetrated through the vulnerabilities to attack the BMC. It can be recovered in the downgraded boot mode, and the program security can be guaranteed by upgrading the BMC program (such as upgrading the BMC firmware). For example, download the BMC program upgrade from the official website and provide a patch program. The traditional secure boot ensures the integrity of the program.
[0093] Optionally, if the computing power of the processor in the BMC is insufficient to support the analysis of data obtained from the storage medium associated with the business module, the remote system can be used to analyze the obtained data, thereby realizing the perception that the BMC may be attacked by APT and improving the ability of the BMC to resist APT attacks.
[0094] For example, this embodiment may further include step 321, analyzing data based on the advanced threat analysis system to obtain security detection results. The BMC may send data to the advanced threat analysis system, obtain security detection results from the advanced threat analysis system data, and the BMC receives security detection results fed back by the advanced threat analysis system.
[0095] Step 330: The security detection module determines that the BMC is attacked by APT according to the security detection result, and restarts the BMC in a degraded startup mode.
[0096] When it is sensed that the BMC is under an APT attack, the security detection module controls the BMC to be restarted in a degraded startup mode, or the BMC receives a restart instruction to restart the BMC in a degraded startup mode.
[0097] The degraded startup mode can refer to resetting the memory associated with the business module, restarting the security detection module, mounting the storage medium associated with the security detection module, not starting the business module, and not mounting the storage medium associated with the business module, ensuring the high-security operating environment of the BMC, blocking the APT attack path, ensuring the core business of the BMC, and providing remote recovery and configuration capabilities.
[0098] After the operating environment of the BMC is safe, the BMC receives a restart instruction to restart the BMC, that is, restart the security detection module, mount the storage medium associated with the security detection module, restart the business module, and mount the storage medium associated with the business module.
[0099] In some embodiments, the security detection result indicates that the data security of the business module is subject to an APT attack, that is, the data stored in the flash memory associated with the business module is subject to an APT attack, the security detection module configures the backed-up initial data to the flash memory associated with the business module, and the business module restarts the business module and the storage medium associated with the business module according to the initial data of the business module. The initial data can be stored in the flash memory associated with the security detection module.
[0100] The BMC intrusion protection method provided by the present application is that on the basis of boundary defense, BMC adds intrusion detection capability. Under the premise of protecting firmware security through secure startup, it can block all existing APT attacks by comprehensively analyzing memory security and data security, ensuring memory security through reset, and only mounting the storage medium associated with the security detection module to ensure data security. After blocking the APT attack, due to the normal operation of the security detection module, the operating ability of the core business of the operating system can be maintained, and basic functions that can be managed remotely can be provided, such as upgrades and configuration management. After ensuring the memory security and data security of the BMC, restart the BMC, that is, restart the business module and the security detection module. Thus, a dynamic defense chain of defense->detection->downgrade->recovery is formed, forming a BMC in-depth defense solution, which effectively improves the BMC's ability to resist APT attacks and ensures that the BMC is safe and reliable.
[0101] Optionally, the BMC can also feed back security detection results to the display terminal, and display the security detection results, so that the system administrator can timely know the security status of the BMC, restart the BMC in a degraded startup mode, and block APT attacks.
[0102] It is understandable that in order to implement the functions in the above embodiments, the BMC includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0103] Combined with the above Figures 1 to 3 , describes in detail the BMC intrusion protection method provided by this application, and will be combined with Figure 4 , describing the safety detection device provided according to the present application.
[0104] Figure 4 The following is a schematic diagram of the structure of possible authentication devices provided by the present application. These authentication devices can be used to implement the functions of the remote device or the computer device in the above method embodiment, so as to achieve the beneficial effects of the above method embodiment. In this embodiment, the authentication device can be as follows: Figure 1 The device shown may also be a module (such as a chip) applied to a server.
[0105] like Figure 4 As shown, the safety detection device 400 includes a communication module 410, a detection module 420, a control module 430 and a storage module 440. The safety detection device 400 is used to implement the above Figure 3 The function of the security detection module in the method embodiment shown in FIG.
[0106] The communication module 410 is used to obtain data stored in a storage medium associated with the business module. For example, the communication module 410 is used to execute Figure 3 Step 310.
[0107] The detection module 420 is used to analyze the data stored in the storage medium associated with the business module to obtain a security detection result. For example, the detection module 420 is used to perform Figure 3 Step 320.
[0108] The control module 430 is used to determine that the BMC is attacked by APT according to the security detection result, and restart the BMC in a degraded startup mode. Figure 3 Step 330.
[0109] Optionally, the detection module 420 is used to detect the operation safety of the business module according to the data stored in the first storage medium associated with the business module to obtain a safety detection result, and the first storage medium is used to store the data required for the operation of the business module.
[0110] Optionally, the detection module 420 is used to detect data security of the business module according to data stored in a second storage medium associated with the business module to obtain a security detection result, and the second storage medium is used to store persistent data of the business module.
[0111] The storage module 440 is used to store data required for security detection, security detection programs, and initial data of the backup service module.
[0112] It should be understood that the safety detection device 400 of the embodiment of the present application can be implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), and the above-mentioned PLD can be a complex programmable logical device (CPLD), a field programmable gate array (FPGA), a generic array logic (GAL), a data processing unit (DPU), an acceleration card, an offload card or any combination thereof. It can also be implemented by software Figure 3 The BMC intrusion protection method shown in the figure and its various modules may also be software modules, and the security detection device 400 and its various modules may also be software modules.
[0113] The safety detection device 400 according to the embodiment of the present application may correspond to the method described in the embodiment of the present application, and the above and other operations and / or functions of each unit in the safety detection device 400 are respectively to achieve Figure 3 For the sake of brevity, the corresponding processes of each method in are not repeated here.
[0114] Figure 5 This is a schematic diagram of the structure of a computer device provided in this application. Figure 5 As shown, the computer device 500 includes a processor 510, a memory 520, a storage 530, a PCIe card 540, a BMC 550, and a communication interface 560. The processor 510, the memory 520, the storage 530, the PCIe card 540, the BMC 550, and the communication interface 560 are connected via a bus 570.
[0115] The processor 510 is the control center of the computer device 500. The processor 510 may be a high-power computing unit with computing capability, such as a central processing unit (CPU), a graphics processing unit (GPU), a data processing unit (DPU), a neural processing unit (NPU), and an embedded neural-network processing unit (NPU). The processor 510 includes one processor core or multiple processor cores.
[0116] In some embodiments, processor 510 includes registers and cache memory.
[0117] The cache memory is used to store instructions or data that may be accessed multiple times by the processor core in the processor 510 , thereby increasing the speed at which the processor processes data and preventing the processor from frequently accessing the memory 520 .
[0118] The register is used to store instructions or data that may be accessed multiple times by the processor core in the processor 510. Since the access speed of the register is higher than the access speed of the cache memory, the instructions or data that may be accessed multiple times by the processor core can be stored in the register first, which can further improve the speed of the processor processing data.
[0119] Optionally, the processor 510 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0120] The memory 520 (also referred to as a main memory unit) may be a volatile memory pool or a non-volatile memory pool, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct memory bus random access memory (DR RAM).
[0121] The memory 530 may be a persistent storage medium, such as a disk, such as a mechanical hard disk or a solid state disk. The PCIe card 540 may refer to a peripheral device. For example, the PCIe card 540 includes a network card, etc. The communication interface 560 is used to implement communication between the computer device 500 and an external device or device.
[0122] The BMC 550 is used to manage other components in the computer device 500 , such as the processor 510 , the memory 520 , the storage 530 , the PCIe card 540 , and the communication interface 560 .
[0123] In the present application, the BMC 550 includes a service module 551 and a safety detection module 552. For the functions of the service module 551 and the safety detection module 552, reference may be made to the description of the service module and the safety detection module in the above embodiments.
[0124] The bus 570 may include a path for transmitting information between the above components (such as the processor 510, the memory 520, the storage 530, the PCIe card 540 and the communication interface 560). In addition to the data bus, the bus 570 may also include a power bus, a control bus and a status signal bus. However, for the sake of clarity, various buses are marked as bus 570 in the figure. The bus 570 may be a Peripheral Component Interconnect Express (PCIe) bus, or an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a computer express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. The bus 570 can be divided into an address bus, a data bus, a control bus, etc.
[0125] Figure 5 The device structure shown in the figure does not constitute a limitation on the computer device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently. For example, the computer device may also include an artificial intelligence card, a read card, a GPU, a DPU, and an NPU.
[0126] The components described in this application may be processors, memories, memory, registers, cache memories, network cards, circuit boards, etc. included in computer equipment. The BMC included in the computer equipment may perform APT attack detection on the BMC according to the BMC intrusion protection method provided in this application, resist APT attacks, and ensure that the BMC is safe and reliable.
[0127] It should be understood that the BMC 550 in the computer device 500 according to this embodiment may correspond to the security detection device 400 in this embodiment, and may correspond to the computer device 500 executing the security detection device 400 according to this embodiment. Figure 3 The corresponding subject in any method, and the above and other operations and / or functions of each module in the safety detection device 400 are respectively to achieve Figure 3 For the sake of brevity, the corresponding processes of each method in are not repeated here.
[0128] The present application provides a cluster, which may include multiple computer devices, which include multiple components and a BMC. The BMC may perform APT attack detection on the BMC according to the BMC intrusion protection method provided by the present application, resist APT attacks, and ensure that the BMC is safe and reliable. The BMC can perform trustworthy authentication on the components in the computer device to prevent the components from being counterfeited, tampered with, or replaced, and ensure the safety and reliability of the components.
[0129] The present application also provides a chip that can realize the above Figures 1 to 5 The chip can be an independent chip or a chip integrated in the BMC.
[0130] The method steps in this embodiment can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a computing device. Of course, the processor and the storage medium can also exist in a computing device as discrete components.
[0131] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instruction is loaded and executed on a computer, the process or function described in the embodiment of the present application is executed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device or other programmable device. The computer program or instruction may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer program or instruction may be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired or wireless means. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, for example, a floppy disk, a hard disk, a tape; it may also be an optical medium, for example, a digital video disc (DVD); it may also be a semiconductor medium, for example, a solid state drive (SSD). The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.
Claims
1. A baseboard management controller BMC intrusion protection method, characterized in that: The method is applied to a BMC in a computer device, the BMC comprising a business module and a security detection module, the business module is used to provide management functions for components in the computer device, the security detection module is used to perform security detection on the BMC, the business module and the security detection module are isolated in communication, the storage medium accessed by the business module and the security detection module are isolated, the method is performed by the security detection module, and the method comprises: Obtaining a security detection result according to data stored in a storage medium associated with the business module, wherein the data is used to perceive the security situation of the business module, and the security detection result is used to indicate the possibility that the BMC is subject to an advanced long-term threat APT attack; It is determined according to the security detection result that the BMC is attacked by the APT, and the BMC is restarted in a degraded startup mode.
2. The method according to claim 1, characterized in that: Obtaining a security detection result according to data stored in a storage medium associated with the business module includes: The operation safety of the business module is detected according to the data stored in the first storage medium associated with the business module to obtain the safety detection result, and the first storage medium is used to store the data required for the operation of the business module.
3. The method according to claim 1, characterized in that Obtaining a security detection result according to data stored in a storage medium associated with the business module includes: According to the data stored in the second storage medium associated with the business module, the data security of the business module is detected to obtain the security detection result, and the second storage medium is used to store the persistent data of the business module.
4. The method according to claim 2 or 3, characterized in that: Obtaining the safety detection result includes: The data is verified according to the trusted root of the BMC to obtain the security detection result.
5. The method according to claim 2 or 3, characterized in that: Obtaining the safety detection result includes: The security detection result is obtained by analyzing the data based on an advanced threat analysis system.
6. The method according to claim 1, characterized in that Restarting the BMC in a degraded boot mode includes: Restart the security detection module and mount the storage medium associated with the security detection module.
7. The method according to claim 6, characterized in that After restarting the security detection module and mounting the storage medium associated with the security detection module, the method further includes: According to the restart instruction, the security detection module is restarted, and the storage medium associated with the security detection module is mounted; and the business module is restarted, and the storage medium associated with the business module is mounted.
8. A safety detection device, characterized in that: include: A detection module, used to obtain a security detection result based on data stored in a storage medium associated with the business module, wherein the data is used to perceive the security situation of the business module, and the security detection result is used to indicate the possibility that the BMC is attacked by an advanced long-term threat APT; The control module is used to determine that the BMC is attacked by the APT according to the security detection result, and restart the BMC in a degraded startup mode.
9. A baseboard management controller BMC, characterized in that: The BMC includes a business module and a security detection module, the business module is used to provide management functions for components in the computer device, the security detection module is used to perform security detection on the BMC, the business module and the security detection module are isolated in communication, the storage medium accessed by the business module and the security detection module are isolated, and the security detection module is used to execute the operating steps of the method described in any one of claims 1 to 7.
10. A computer device, characterized in that: The computer device comprises a processor, a memory and a baseboard management controller BMC as claimed in claim 9, wherein the BMC is used to execute the operation steps of the method as claimed in any one of claims 1 to 7.
Citation Information
Patent Citations
Method, device and server for managing firmware of basic input and output system
CN109446815A
Security detection system, method and device and storage medium
CN113868667A
BMC security protection method and device and readable storage medium
CN114866254A
Firmware starting method, chip and computing equipment
CN115935335A
Baseboard management controller system operation method, apparatus and device, and storage medium
CN116225812A
Cited By
Processor circuit, server, data access method, authentication method and medium
CN120387193A
Processor circuit, server, data access method, authentication method and medium
CN120387193B
BMC-based trusted computing method, server, storage medium and electronic equipment
CN120850362A
End point detection and response method and electronic equipment
CN121051737A
Endpoint detection and response method, electronic device
CN121051737B