Data security sandbox isolation method
By using the principle of least permissions, hardware virtualization technology and virtual LAN technology in the data security sandbox for isolation, and combining real-time monitoring and code auditing, the performance overhead, complexity and security vulnerabilities in the sandbox technology are solved, and efficient and secure data isolation and protection are achieved.
Patent Information
- Application Number
- CN202510088860.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-06-20
AI Technical Summary
The existing data security sandbox technology has performance overhead, complexity, compatibility issues, security vulnerabilities, resource limitations, monitoring and debugging difficulties, and low user acceptance.
By using the principle of least permissions to plan the permission allocation of applications and users, combining hardware virtualization technology and virtual LAN technology for preliminary isolation, and deploying real-time monitoring tools for code auditing and behavior monitoring, secondary isolation and data encryption processing based on evaluation results.
It significantly reduces performance overhead, improves the overall operating efficiency of the system, reduces resource waste, ensures efficient utilization of resources, and effectively prevents the security risks brought about by abuse of permissions, enhancing data security and system stability.
Smart Images

Figure CN120180425A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and particularly relates to a data security sandbox isolation method. Background Art
[0002] The security sandbox technology aims to protect user privacy and system security. It achieves this goal by creating a restricted running environment for application programs. This technology encompasses creating isolated environments, application redirection, establishing independent virtual environments, and incorporates system security measures such as the defense-in-depth design principle and multi-layer protection barriers. Data security sandboxes generally rely on virtualization technologies, including operating system-level virtualization (such as container technology, like the lightweight virtualization provided by Docker), and hardware-assisted virtualization (HAV), which utilizes the virtualization support provided by the CPU and other hardware components to build fully isolated virtual machines (VMs), each equipped with an independent operating system and resources.
[0003] The core function of the sandbox is to provide isolation, specifically including: process isolation, restricting process permissions and resource access, such as chroot or cgroups in the Linux system; memory isolation, ensuring that processes within the sandbox cannot access or tamper with the memory spaces of other processes; network isolation, controlling the network access of the sandbox by setting up virtual network interfaces and rules.
[0004] To further enhance security, the sandbox implements strict access control policies, such as restricting access permissions to the file system, network, and devices, and typically runs programs within the sandbox as low-privilege users to reduce potential risks. In addition, the sandbox also incorporates various background technology supports such as monitoring and auditing, security policy formulation, and snapshot recovery.
[0005] With the development of container technologies and orchestration tools (such as Docker and Kubernetes), the sandbox technology has also made significant progress. However, although these technologies have enhanced isolation and resource management capabilities, they have also brought new security challenges. For example, although namespaces and control groups achieve resource isolation, there are still security risks. The following are some problems faced when using sandbox technology:
[0006] 1. Performance Overhead: Sandbox technology often comes with additional performance overhead because it introduces an isolation layer on top of the regular operating system, which may affect application performance and system resource efficiency.
[0007] 2. Complexity: Configuring and maintaining a sandbox environment can be a complex process. For enterprises and developers, mastering and implementing sandbox technology usually requires a high level of technical expertise and rich experience.
[0008] 3. Compatibility issues: Some sandbox technologies may not be compatible with all applications or systems. Especially when specific hardware requirements or system calls are involved, applications may encounter obstacles when running in a sandbox environment.
[0009] 4. Security vulnerabilities: The sandbox itself may also have security vulnerabilities; if the sandbox implementation is insufficient or misconfigured, attackers may find ways to escape, thereby threatening the security of the host system.
[0010] 5. Resource limitations: Sandboxes usually limit the resources available to applications (such as CPU, memory, network bandwidth), which in some cases affects the performance and functionality of the applications.
[0011] 6. Difficulties in monitoring and debugging: Due to the isolation characteristics of the sandbox, it may be more difficult to monitor and debug applications in the sandbox, and normal debugging tools and monitoring means may be interfered with.
[0012] 7. User acceptance: Sandbox technology may raise some privacy concerns among users. Especially when it comes to the processing of personal data or sensitive information, users may be cautious about the use of sandbox technology.
[0013] Therefore, how to provide a data security sandbox isolation method is an urgent problem to be solved at present. Summary of the Invention
[0014] Embodiments of the present invention provide a data security sandbox isolation method to solve the above-mentioned technical problems existing in the prior art.
[0015] To have a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. This summary part is not a general review, nor is it to identify key / important constituent elements or delineate the protection scope of these embodiments. Its sole purpose is to present some concepts in a simple form as a preface to the subsequent detailed description.
[0016] According to the first aspect of the embodiments of the present invention, a data security sandbox isolation method is provided.
[0017] In one embodiment, a data security sandbox isolation method includes:
[0018] According to the principle of least privilege, plan the permission allocation for applications and users, and use hardware virtualization technology and virtual local area network technology to initially isolate the communication between the sandbox environment and the external network;
[0019] Based on the initial isolation result, clean up the sandbox environment and deploy real-time monitoring tools to record the activities and operation logs inside the sandbox;
[0020] Based on the results recorded by the real-time monitoring tool, conduct code auditing on the applications running inside the sandbox, and monitor the running behavior of the applications through the dynamic analysis tool to evaluate the resistance of the sandbox to escape attacks;
[0021] According to the evaluation results, use container technology and user-level sandbox technology to perform secondary isolation on the sandbox environment, encrypt the data inside the sandbox, and back up the sandbox environment based on the encryption result.
[0022] In one embodiment, the planning of the permission allocation for applications and users according to the principle of least privilege, and the initial isolation of the communication between the sandbox environment and the external network by using hardware virtualization technology and virtual local area network technology includes:
[0023] Conduct a requirements analysis on each application and user role, determine the minimum resource access level required to perform tasks, and based on the minimum resource access level, determine the principle of least privilege;
[0024] Based on the determined principle of least privilege, create and apply an access control list, and combine it with a security permission model to allocate the access permissions of applications and users to resources;
[0025] According to the allocated resource access permissions, configure the sandbox environment by using hardware virtualization technology, and initially isolate the communication between the sandbox environment and the external network by combining virtual local area network technology.
[0026] In one embodiment, the creating and applying an access control list based on the determined principle of least privilege, and combining it with a security permission model to allocate the access permissions of applications and users to resources includes:
[0027] Based on the determined principle of least privilege, use a control list generation algorithm to create a corresponding access control list for each resource;
[0028] According to security requirements and business characteristics, select role-based access control as the security permission model;
[0029] Map the created access control list to the security permission model to allocate the corresponding resource access permissions to applications and users.
[0030] In one embodiment, the configuring the sandbox environment by using hardware virtualization technology according to the allocated resource access permissions, and initially isolating the communication between the sandbox environment and the external network by combining virtual local area network technology includes:
[0031] According to the allocated resource access permissions, use hardware virtualization technology to select a virtualization platform, and use the selected virtualization platform to create virtual machine instances to build the sandbox environment;
[0032] Apply resource restriction algorithms in the constructed sandbox environment, and design and define network policies according to business requirements and security requirements.
[0033] Based on the defined network policies, use stateful inspection firewall algorithms to control the connection status of the communication between the sandbox environment and the external network.
[0034] According to the connection status controlled by the firewall, use virtual local area network (VLAN) technology to divide the external network into several subnet segments, and set up an isolation area for the services communicating between the sandbox environment and the external network for preliminary isolation.
[0035] In one embodiment, the step of using VLAN technology to divide the external network into several subnet segments according to the connection status controlled by the firewall, and setting up an isolation area for the services communicating between the sandbox environment and the external network for preliminary isolation includes:
[0036] According to the connection status controlled by the firewall, analyze the scale and traffic characteristics of the external network, and combine with the service requirements for the communication between the sandbox environment and the external network to obtain security isolation requirements.
[0037] Based on the security isolation requirements, use VLAN technology to plan the division of the external network, determine the number of VLANs, and assign corresponding identifiers to each VLAN.
[0038] According to the identifier assignment strategy, plan the subnet segments within each VLAN, create VLANs on the switch, and assign corresponding physical ports to each VLAN.
[0039] Configure the subnet segments in the corresponding physical ports, determine the coverage range of the isolation area according to the service requirements, and configure relevant devices in the isolation area to monitor the traffic in the isolation area for preliminary isolation.
[0040] In one embodiment, the formula for using VLAN technology to plan the division of the external network, determine the number of VLANs, and assign corresponding identifiers to each VLAN based on the security isolation requirements is:
[0041] VLAN ID = (P mod N) + 1;
[0042] In the formula, VLAN ID represents the VLAN identifier; P represents the port number; mod represents the remainder after P is divided by N; N represents the total number of VLANs.
[0043] In one embodiment, the step of auditing the code of the applications running inside the sandbox using the results recorded by real-time monitoring tools, and monitoring the running behavior of the applications through dynamic analysis tools to evaluate the resistance of the sandbox to escape attacks includes:
[0044] Extract the running application code from the sandbox environment based on the results recorded by the real-time monitoring tool, conduct code auditing on the extracted application code, and identify and fix security vulnerabilities based on the auditing results;
[0045] Use static analysis tools to analyze the repair results, and combine dynamic analysis tools to monitor the running behavior of the application, identify and record abnormal activities;
[0046] According to the recorded abnormal activities and code auditing results, deploy intrusion detection and prevention mechanisms in the sandbox environment, formulate and execute an escape attack test plan, and evaluate the resistance of the sandbox to escape attacks through the test plan.
[0047] In one embodiment, the deploying intrusion detection and prevention mechanisms in the sandbox environment according to the recorded abnormal activities and code auditing results, formulating and executing an escape attack test plan, and evaluating the resistance of the sandbox to escape attacks through the test plan includes:
[0048] Generate a rule set according to the recorded abnormal activities and code auditing results, and deploy intrusion detection and prevention mechanisms in the sandbox environment based on the rule set;
[0049] Based on the deployed intrusion detection and prevention mechanisms, determine the objectives and scope of the escape attack test, build a test case library in combination with sandbox escape technologies, and formulate an escape attack test plan based on the built test case library;
[0050] Establish an automated test framework, automatically run the escape attack test plan in the test case library, and collect escape attack test feedback data;
[0051] Use the collected escape attack test feedback data to define quantitative evaluation indicators, and use statistical analysis algorithms to evaluate the resistance of the sandbox to escape attacks.
[0052] In one embodiment, the secondarily isolating the sandbox environment using container technology and user-level sandbox technology according to the evaluation results, encrypting the data inside the sandbox, and backing up the sandbox environment based on the encryption processing results includes:
[0053] According to the evaluation results, select a container platform and use container technology to create corresponding isolation containers for each application;
[0054] Use user-level sandbox technology to define security policies for each isolation container, and secondarily isolate the communication between the sandbox environment and the external network through the security policies;
[0055] Based on the results of the secondary isolation, use the Huffman algorithm to encrypt the data inside the sandbox to obtain encrypted data;
[0056] Backup the encrypted data according to a preset backup policy.
[0057] In one embodiment, the encryption process of the data inside the sandbox using the Huffman algorithm based on the secondary isolation result to obtain the encrypted data includes:
[0058] Analyze the data inside the sandbox based on the secondary isolation result, and count the frequency of each character appearing in the data;
[0059] Use the counted character frequencies as weights to construct a corresponding Huffman tree using the Huffman algorithm;
[0060] According to the constructed Huffman tree, generate corresponding Huffman codes for each character, and compress the data inside the sandbox based on the Huffman codes for data encryption processing to obtain the encrypted data.
[0061] According to the second aspect of the embodiments of the present invention, a data security sandbox isolation system is provided.
[0062] In one embodiment, the data security sandbox isolation system includes: a permission allocation and preliminary isolation module, a sandbox cleaning and monitoring deployment module, a code review and behavior monitoring module, and a secondary isolation and data encryption module;
[0063] The permission allocation and preliminary isolation module is used to plan the permission allocation of applications and users according to the principle of least privilege, and use hardware virtualization technology and virtual local area network technology to preliminarily isolate the communication between the sandbox environment and the external network;
[0064] The sandbox cleaning and monitoring deployment module is used to clean the sandbox environment based on the preliminary isolation result, and deploy real-time monitoring tools to record the activities and operation logs inside the sandbox;
[0065] The code review and behavior monitoring module is used to perform code auditing on the applications running inside the sandbox using the results recorded by the real-time monitoring tools, and monitor the running behavior of the applications through dynamic analysis tools to evaluate the resistance of the sandbox to escape attacks;
[0066] The secondary isolation and data encryption module is used to perform secondary isolation on the sandbox environment using container technology and user-level sandbox technology according to the evaluation result, and encrypt the data inside the sandbox, and back up the sandbox environment based on the encryption processing result.
[0067] According to the third aspect of the embodiments of the present invention, a computer device is provided.
[0068] In some embodiments, the computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.
[0069] According to a fourth aspect of the embodiments of the present invention, a computer-readable storage medium is provided.
[0070] In one embodiment, a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0071] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:
[0072] The present invention significantly reduces performance overhead through hardware virtualization technology, improves the overall operating efficiency of the system, reduces resource waste, and ensures the efficient use of resources. At the same time, by following the principle of least privilege, the permissions of application programs in the sandbox are strictly controlled, effectively preventing security risks caused by permission abuse; in addition, real-time monitoring of activities in the sandbox can detect and respond to abnormal behaviors in a timely manner, further ensuring the security of data and the stability of the system.
[0073] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0074] The drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present invention and used together with the specification to explain the principles of the present invention.
[0075] Figure 1 is a flowchart of a data security sandbox isolation method shown according to an exemplary embodiment;
[0076] Figure 2 is a schematic block diagram of a data security sandbox isolation system shown according to an exemplary embodiment;
[0077] Figure 3 is a schematic structural diagram of a computer device shown according to an exemplary embodiment;
[0078] Figure 4 is a flowchart of the operation of a data security sandbox in a data security sandbox isolation method shown according to an exemplary embodiment;
[0079] Figure 5 is an architecture diagram of a data security sandbox isolation method shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0080] The following description and the accompanying drawings fully disclose specific embodiments herein, enabling those skilled in the art to practice them. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. The scope of the embodiments herein includes the entire scope of the claims and all available equivalents of the claims. In this document, terms such as "first", "second", etc. are only used to distinguish one element from another, without requiring or implying any actual relationship or order between these elements. In fact, the first element can also be called the second element, and vice versa. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a structure, device or equipment comprising a series of elements not only includes those elements but also other elements not explicitly listed, or elements inherent to such structure, device or equipment. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the structure, device or equipment comprising the said element. The various embodiments herein are described in a progressive manner, with each embodiment highlighting the differences from other embodiments. For the same or similar parts among the various embodiments, reference may be made to each other.
[0081] In this document, terms such as "longitudinal", "lateral", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. This is only for the convenience of describing this document and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation on the present invention. In the description of this document, unless otherwise specified and defined, the terms "mounted", "connected", "coupled" should be understood in a broad sense. For example, it can be a mechanical connection or an electrical connection, or it can be the communication inside two elements. It can be directly connected or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms can be understood according to specific circumstances.
[0082] In this document, unless otherwise stated, the term "plurality" means two or more.
[0083] In this document, the character " / " indicates that the objects before and after are in an "or" relationship. For example, A / B means: A or B.
[0084] In this document, the term "and / or" is a description of the associative relationship of an object, indicating that three relationships can exist. For example, A and / or B means: A or B, or, A and B these three relationships.
[0085] It should be understood that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless otherwise clearly stated in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the figure may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0086] Each module in the device or system of the present application can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.
[0087] Without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0088] Figure 1 An embodiment of a data security sandbox isolation method of the present invention is shown.
[0089] In this alternative embodiment, the data security sandbox isolation method includes:
[0090] Step 101, according to the principle of least privilege, plan the permission allocation of application programs and users, and use hardware virtualization technology and virtual local area network technology to initially isolate the communication between the sandbox environment and the external network.
[0091] In this alternative embodiment, the step of according to the principle of least privilege, planning the permission allocation of application programs and users, and using hardware virtualization technology and virtual local area network technology to initially isolate the communication between the sandbox environment and the external network includes:
[0092] Conduct a requirements analysis on each application program and user role, determine the minimum resource access level required to execute tasks, and based on the minimum resource access level, determine the principle of least privilege.
[0093] Based on the determined principle of least privilege, create and apply an access control list, and combine it with a security permission model to allocate the access permissions of application programs and users to resources.
[0094] In this alternative embodiment, the step of based on the determined principle of least privilege, creating and applying an access control list, and combining it with a security permission model to allocate the access permissions of application programs and users to resources includes:
[0095] Based on the determined principle of least privilege, use an access control list generation algorithm to create corresponding access control lists for each resource;
[0096] According to security requirements and business characteristics, select role-based access control as the security permission model;
[0097] Map the created access control lists to the security permission model to assign corresponding resource access permissions to applications and users.
[0098] It should be added that the principle of least privilege includes: ensuring that applications within the sandbox can only access the resources necessary to execute their functions; using access control lists (ACLs) and security permission models to restrict access to resources.
[0099] According to the assigned resource access permissions, use hardware virtualization technology to configure the sandbox environment, and combine virtual local area network technology to initially isolate the communication between the sandbox environment and the external network.
[0100] In this alternative embodiment, the step of using hardware virtualization technology to configure the sandbox environment according to the assigned resource access permissions and initially isolating the communication between the sandbox environment and the external network by combining virtual local area network technology includes:
[0101] According to the assigned resource access permissions, use hardware virtualization technology to select a virtualization platform, and use the selected virtualization platform to create virtual machine instances to build the sandbox environment.
[0102] Apply a resource restriction algorithm in the constructed sandbox environment, and design and define network policies according to business requirements and security requirements.
[0103] Based on the defined network policies, use the stateful inspection firewall algorithm to control the connection status of the communication between the sandbox environment and the external network.
[0104] According to the connection status controlled by the firewall, use virtual local area network technology to divide the external network into several subnet segments, and set up an isolation area for the services of the communication between the sandbox environment and the external network for initial isolation.
[0105] In this alternative embodiment, the step of using virtual local area network technology to divide the external network into several subnet segments according to the connection status controlled by the firewall and setting up an isolation area for the services of the communication between the sandbox environment and the external network for initial isolation includes:
[0106] According to the connection status controlled by the firewall, analyze the scale and traffic characteristics of the external network, and combine the service requirements of the communication between the sandbox environment and the external network to obtain security isolation requirements.
[0107] Based on the security isolation requirements, use virtual local area network (VLAN) technology to plan the division of the external network, determine the number of VLANs, and assign corresponding identifiers to each VLAN.
[0108] In this alternative embodiment, the formula for using VLAN technology to plan the division of the external network based on security isolation requirements, determine the number of VLANs, and assign corresponding identifiers to each VLAN is as follows:
[0109] VLAN ID = (P mod N) + 1;
[0110] In the formula, VLAN ID represents the VLAN identifier; P represents the port number; mod represents the remainder after P is divided by N; N represents the total number of VLANs.
[0111] According to the identifier assignment strategy, plan the subnet segments within each VLAN, create VLANs on the switch, and assign corresponding physical ports to each VLAN.
[0112] It should be noted that the formula for planning the subnet segments within each VLAN according to the identifier assignment strategy, creating VLANs on the switch, and assigning corresponding physical ports to each VLAN is as follows:
[0113]
[0114] In the formula, Bandwidth VLANi represents the bandwidth of the i-th VLAN; Total Bandwidth represents the total network bandwidth; Number of VLANs represents the number of VLANs.
[0115] Configure the subnet segments in the corresponding physical ports, determine the coverage range of the isolation area according to service requirements, and configure relevant devices in the isolation area to monitor the traffic in the isolation area for preliminary isolation.
[0116] It should be noted that the formula for configuring the subnet segments in the corresponding physical ports, determining the coverage range of the isolation area according to service requirements, and configuring relevant devices in the isolation area to monitor the traffic in the isolation area for preliminary isolation is as follows:
[0117] Subnet Mask = 32 - log2(Hosts Per VLAN);
[0118]
[0119] In the formula, Subnet Mask represents the subnet segment; Hosts Per VLAN represents the number of hosts within each VLAN; Traffic IsolationZoneRepresents the total data traffic volume in the isolation area; n represents the total number of all VLANs participating in traffic statistics; i represents the index value; Traffic VLANi Represents the traffic of the i-th VLAN.
[0120] In addition, hardware virtualization technologies (such as Intel VT-x, AMD-V) are used to enhance the isolation of the virtualization layer; strict network isolation is implemented to restrict the communication between the sandbox and the external network.
[0121] Step 102, based on the preliminary isolation result, clean up the sandbox environment and deploy a real-time monitoring tool to record the activities and operation logs inside the sandbox.
[0122] It should be added that cleaning up the sandbox environment includes: removing or disabling unnecessary services and applications in the sandbox environment; applying the latest security patches and updates.
[0123] Recording the activities and operation logs inside the sandbox includes: real-time monitoring of the activities inside the sandbox, including system calls, network communications, and file accesses, and recording detailed logs for easy auditing and incident response.
[0124] Step 103, using the results recorded by the real-time monitoring tool, conduct code auditing on the applications running inside the sandbox, and monitor the running behaviors of the applications through a dynamic analysis tool to evaluate the resistance of the sandbox to escape attacks.
[0125] In this alternative embodiment, the using the results recorded by the real-time monitoring tool, conducting code auditing on the applications running inside the sandbox, and monitoring the running behaviors of the applications through a dynamic analysis tool to evaluate the resistance of the sandbox to escape attacks includes:
[0126] Using the results recorded by the real-time monitoring tool, extract the running application code from the sandbox environment, conduct code auditing on the extracted application code, and identify and fix security vulnerabilities based on the audit results.
[0127] Use a static analysis tool to analyze the repair results, combined with a dynamic analysis tool to monitor the running behaviors of the applications, and identify and record abnormal activities.
[0128] It should be added that conduct code auditing on the applications running in the sandbox to identify potential security vulnerabilities; use a static analysis tool to detect security defects in the code; use a dynamic analysis tool to monitor the running-time behaviors of the applications to identify abnormal activities.
[0129] According to the recorded abnormal activities and code audit results, deploy an intrusion detection and prevention mechanism in the sandbox environment, formulate and execute an escape attack test plan, and evaluate the resistance of the sandbox to escape attacks through the test plan.
[0130] It should be noted that the (IDS / IPS) mechanism is deployed in the sandbox environment to detect and prevent malicious behaviors.
[0131] In this alternative embodiment, the steps of deploying an intrusion detection and prevention mechanism in the sandbox environment according to the recorded abnormal activities and code audit results, formulating and executing an escape attack test plan, and evaluating the resistance of the sandbox to escape attacks through the test plan include:
[0132] Generating a rule set based on the recorded abnormal activities and code audit results, and deploying an intrusion detection and prevention mechanism in the sandbox environment based on the rule set;
[0133] Based on the deployed intrusion detection and prevention mechanism, determining the objectives and scope of the escape attack test, constructing a test case library in combination with sandbox escape techniques, and formulating an escape attack test plan based on the constructed test case library;
[0134] Establishing an automated test framework, automatically running the escape attack test plan in the test case library, and collecting escape attack test feedback data;
[0135] Using the collected escape attack test feedback data to define quantitative evaluation metrics, and using statistical analysis algorithms to evaluate the resistance of the sandbox to escape attacks.
[0136] It should be noted that the resistance of the sandbox environment to escape attacks is regularly tested and evaluated; measures are taken to prevent common sandbox escape techniques, such as side-channel attacks.
[0137] In addition, automated tools are used to ensure that the configuration of the sandbox complies with security best practices; the sandbox configuration is regularly reviewed and updated.
[0138] Step 104: According to the evaluation results, use container technology and user-level sandbox technology to perform secondary isolation on the sandbox environment, encrypt the data inside the sandbox, and back up the sandbox environment based on the encryption result.
[0139] In this alternative embodiment, the steps of using container technology and user-level sandbox technology to perform secondary isolation on the sandbox environment according to the evaluation results, encrypting the data inside the sandbox, and backing up the sandbox environment based on the encryption result include:
[0140] According to the evaluation results, select a container platform and use container technology to create corresponding isolation containers for each application.
[0141] Using user-level sandbox technology, define security policies for each isolation container, and perform secondary isolation on the communication between the sandbox environment and the external network through the security policies.
[0142] It should be noted that a user-level sandbox is implemented to ensure the isolation of application programs of different users; container technologies (such as Docker) are used to provide an independent running environment.
[0143] Based on the secondary isolation result, the Huffman algorithm is used to encrypt the data inside the sandbox to obtain encrypted data.
[0144] In this alternative embodiment, the step of using the Huffman algorithm to encrypt the data inside the sandbox based on the secondary isolation result to obtain encrypted data includes:
[0145] Based on the secondary isolation result, analyze the data inside the sandbox and count the frequency of each character appearing in the data;
[0146] Use the counted character frequencies as weights and construct a corresponding Huffman tree using the Huffman algorithm;
[0147] According to the constructed Huffman tree, generate corresponding Huffman codes for each character, and compress the data inside the sandbox based on the Huffman codes for data encryption processing to obtain encrypted data.
[0148] It should be noted that encryption technology is used to protect the data and communication inside the sandbox; a strong authentication mechanism is implemented to ensure that only authorized users can access the sandbox; in addition, the working process of the data security sandbox is as Figure 4 shown.
[0149] Backup the encrypted data according to the preset backup policy.
[0150] It should be noted that the sandbox environment is backed up regularly so that it can be quickly restored in case of an attack.
[0151] In addition, as Figure 5 shown, the architecture of the data security sandbox isolation method includes: operation control, core functions, basic components, and a trusted environment.
[0152] Figure 2 An embodiment of a data security sandbox isolation method of the present invention is shown.
[0153] In this alternative embodiment, a data security sandbox isolation system includes: a permission allocation and preliminary isolation module 201, a sandbox cleaning and monitoring deployment module 202, a code review and behavior monitoring module 203, and a secondary isolation and data encryption module 204;
[0154] The permission allocation and preliminary isolation module 201 is used to plan the permission allocation of application programs and users according to the principle of least privilege, and use hardware virtualization technology and virtual local area network technology to preliminarily isolate the communication between the sandbox environment and the external network;
[0155] The sandbox cleaning and monitoring deployment module 202 is used to clean the sandbox environment based on the preliminary isolation result, deploy a real-time monitoring tool, and record the activities and operation logs inside the sandbox;
[0156] The code review and behavior monitoring module 203 is used to perform code auditing on the application programs running inside the sandbox by using the results recorded by the real-time monitoring tool, monitor the running behaviors of the application programs through a dynamic analysis tool, and evaluate the resistance of the sandbox to escape attacks;
[0157] The secondary isolation and data encryption module 204 is used to perform secondary isolation on the sandbox environment by using container technology and user-level sandbox technology according to the evaluation result, encrypt the data inside the sandbox, and back up the sandbox environment based on the encryption result.
[0158] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as Figure 3 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store static information and dynamic information data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in the above method embodiment are implemented.
[0159] Those skilled in the art can understand that Figure 3 the structure shown in
[0160] is only a block diagram of a part of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0161] In addition, the present invention also provides a computer device, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiment are implemented.
[0162] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided by the present invention can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0163] The present invention is not limited to the structures that have been described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A data security sandbox isolation method, characterized in that: The method includes: According to the principle of least privilege, plan the permission allocation of applications and users, and use hardware virtualization technology and virtual LAN technology to initially isolate the sandbox environment from the communication with the external network; Based on the preliminary isolation results, the sandbox environment is cleaned up and real-time monitoring tools are deployed to record activities and operation logs within the sandbox; Using the results recorded by real-time monitoring tools, we conduct code audits on applications running inside the sandbox, and use dynamic analysis tools to monitor the running behavior of applications and evaluate the sandbox's resistance to escape attacks. According to the evaluation results, container technology and user-level sandbox technology are used to perform secondary isolation on the sandbox environment, and the data inside the sandbox is encrypted. The sandbox environment is backed up based on the encryption results.
2. A data security sandbox isolation method according to claim 1, characterized in that: According to the principle of least privilege, the permission allocation of applications and users is planned, and hardware virtualization technology and virtual LAN technology are used to initially isolate the sandbox environment from the communication with the external network, including: Conduct a requirements analysis for each application and user role to determine the minimum resource access level required to perform tasks, and determine the principle of least privilege based on the minimum resource access level; Create and apply access control lists based on the established principle of least privilege, combined with a security permissions model to assign application and user access rights to resources; Based on the allocated resource access rights, hardware virtualization technology is used to configure the sandbox environment, and virtual LAN technology is used to initially isolate the communication between the sandbox environment and the external network.
3. A data security sandbox isolation method according to claim 2, characterized in that: The creation and application of access control lists based on the principle of least privilege and the combination of security permission models to allocate application and user access rights to resources include: Based on the principle of least privilege, a control list generation algorithm is used to create a corresponding access control list for each resource; According to security requirements and business characteristics, role-based access control is selected as the security permission model; Map the created access control list to the security permission model and assign corresponding resource access permissions to applications and users.
4. A data security sandbox isolation method according to claim 3, characterized in that: The configuration of the sandbox environment using hardware virtualization technology based on the allocated resource access rights and the preliminary isolation of the sandbox environment from the external network using virtual LAN technology include: Based on the allocated resource access rights, use hardware virtualization technology to select a virtualization platform, and use the selected virtualization platform to create a virtual machine instance and build a sandbox environment; Apply resource limiting algorithms in the constructed sandbox environment, design and define network policies based on business needs and security requirements; Based on the defined network policy, the connection status between the sandbox environment and the external network communication is controlled using the state inspection firewall algorithm; According to the connection status controlled by the firewall, the external network is divided into several subnet segments using virtual LAN technology, and an isolation zone is set up for the sandbox environment to communicate with the external network services for preliminary isolation.
5. A data security sandbox isolation method according to claim 4, characterized in that: The method of dividing the external network into several subnet segments using virtual LAN technology according to the connection status controlled by the firewall and setting up an isolation zone for the sandbox environment to communicate with the external network for preliminary isolation includes: Analyze the external network size and traffic characteristics based on the connection status controlled by the firewall, and obtain security isolation requirements based on the service requirements of the sandbox environment and external network communications; Based on the security isolation requirements, use virtual LAN technology to plan the division of the external network, determine the number of virtual LANs, and assign corresponding identifiers to each virtual LAN; According to the identifier allocation strategy, plan the subnet segments within each virtual LAN, create virtual LANs on switches, and allocate corresponding physical ports to each virtual LAN; Configure subnet segments in the corresponding physical ports, determine the coverage of the isolation area based on service requirements, configure relevant equipment in the isolation area, and monitor the traffic in the isolation area for preliminary isolation.
6. A data security sandbox isolation method according to claim 5, characterized in that: The formula for planning the division of the external network based on the security isolation requirement and using the virtual local area network technology, determining the number of virtual local area networks, and assigning a corresponding identifier to each virtual local area network is: VLAN ID = (P mod N) + 1; In the formula, VLAN ID represents the virtual LAN identifier; P represents the port number; mod represents the remainder after P is divided by N; and N represents the total number of VLANs.
7. A data security sandbox isolation method according to claim 1, characterized in that: The results recorded by the real-time monitoring tool are used to audit the code of the application running inside the sandbox, and the running behavior of the application is monitored by the dynamic analysis tool to evaluate the sandbox's resistance to escape attacks, including: Using the results recorded by the real-time monitoring tool, extract the running application code from the sandbox environment, perform code audit on the extracted application code, and identify and fix security vulnerabilities based on the audit results; Use static analysis tools to analyze the repair results, and use dynamic analysis tools to monitor the running behavior of the application to identify and record abnormal activities; Based on the recorded abnormal activities and code audit results, deploy intrusion detection and prevention mechanisms in the sandbox environment, formulate and execute escape attack test plans, and evaluate the sandbox's resistance to escape attacks through the test plan.
8. A data security sandbox isolation method according to claim 7, characterized in that: Based on the recorded abnormal activities and code audit results, intrusion detection and defense mechanisms are deployed in the sandbox environment, and an escape attack test plan is formulated and executed. The test plan is used to evaluate the sandbox's resistance to escape attacks, including: Generate rule sets based on recorded abnormal activities and code audit results, and deploy intrusion detection and prevention mechanisms in the sandbox environment based on the rule sets; Based on the deployed intrusion detection and defense mechanisms, determine the target and scope of the escape attack test, build a test case library in combination with sandbox escape technology, and formulate an escape attack test plan based on the built test case library; Establish an automated testing framework to automatically run the evasion attack test plans in the test case library and collect evasion attack test feedback data; Using the collected escape attack test feedback data, quantitative evaluation indicators are defined, and statistical analysis algorithms are used to evaluate the sandbox's resistance to escape attacks.
9. A data security sandbox isolation method according to claim 1, characterized in that: According to the evaluation results, the sandbox environment is secondary isolated using container technology and user-level sandbox technology, and the data inside the sandbox is encrypted. The sandbox environment is backed up based on the encryption results, including: Based on the evaluation results, select a container platform and use container technology to create corresponding isolated containers for each application. Use user-level sandbox technology to define security policies for each isolated container, and use security policies to perform secondary isolation between the sandbox environment and external network communications; Based on the secondary isolation result, the Huffman algorithm is used to encrypt the data inside the sandbox to obtain encrypted data; The encrypted data is backed up according to the preset backup strategy.
10. A data security sandbox isolation method according to claim 9, characterized in that: Based on the secondary isolation result, the Huffman algorithm is used to encrypt the data inside the sandbox, and the encrypted data obtained includes: Based on the secondary isolation results, the data inside the sandbox is analyzed and the frequency of each character appearing in the data is counted; The statistical character frequencies are used as weights, and the corresponding Huffman tree is constructed using the Huffman algorithm; According to the constructed Huffman tree, a corresponding Huffman code is generated for each character, and the data inside the sandbox is compressed based on the Huffman code to perform encryption processing on the data to obtain encrypted data.