Whitelist updating method, device, network device and storage medium
By updating the whitelist configuration file in the flash platform firmware elastic partition and using a neural network model to identify and update SMBus data that does not meet instruction requirements, the problem of poor BMC access security caused by static configuration is solved, thereby improving the security and reliability of the server.
Patent Information
- Application Number
- CN202511037425.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-25
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-07-25
AI Technical Summary
Statically configuring the SMBus data whitelist results in poor BMC access security.
By obtaining a whitelist configuration file corresponding to a hardware device set in the elastic partition of the flash platform firmware, a system management bus data set is obtained through the system management bus protocol every first time period, and a neural network model is used to identify system management bus instructions that do not meet the instruction requirements, the whitelist configuration file is updated and written into the elastic partition of the flash platform firmware.
Improves the matching of SMBus data and whitelist, dynamically adjusts the whitelist, intercepts access, and enhances the security, reliability, and predictability of BMC.
Smart Images

Figure CN120546998B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of communication technologies, and in particular to a whitelist updating method, apparatus, network device, and storage medium. Background Art
[0002] In the rapidly developing information age, the maturity of IoT technology and the breakthroughs in artificial intelligence (AI) are profoundly changing the development path of data center and server technologies. With the widespread adoption of whole-cabinet server delivery models and the expansion of data center scale, server technology faces unprecedented opportunities and challenges. For example, the Platform Firmware Resilience (PFR) security monitoring solution statically configures a System Management Bus (SMBus) data whitelist to block SMBus commands not specified in the configuration file from accessing the Baseboard Management Controller (BMC) firmware, thereby preventing malicious data attacks. Summary of the Invention
[0003] The present disclosure provides a whitelist updating method, apparatus, network device, and storage medium, which are mainly intended to solve the problem of poor BMC access security caused by static configuration of SMBus data whitelist.
[0004] According to a first aspect of the present disclosure, a whitelist updating method is provided, comprising:
[0005] Obtaining a whitelist configuration file corresponding to each hardware device in a hardware device set in a flash memory platform firmware elastic partition, wherein the hardware device set includes at least one device connected to a system management bus;
[0006] Obtaining a system management bus data set corresponding to the set of hardware devices once every first period of time through a system management bus protocol, and identifying the system management bus data set using a first neural network model to obtain system management bus instructions corresponding to each of the hardware devices that do not meet instruction requirements;
[0007] The whitelist configuration files corresponding to the hardware devices are updated according to the system management bus instructions corresponding to the hardware devices, and the updated whitelist files are written into the flash memory platform firmware elastic partition.
[0008] According to a second aspect of the present disclosure, a whitelist updating device is provided, comprising:
[0009] a file acquiring unit, configured to acquire a whitelist configuration file corresponding to each hardware device in a hardware device set in a flash memory platform firmware elastic partition, wherein the hardware device set includes at least one device connected to a system management bus;
[0010] a set acquisition unit, configured to acquire, through a system management bus protocol, a system management bus data set corresponding to the hardware device set once every first period, and identify the system management bus data set using a first neural network model to acquire system management bus instructions corresponding to each hardware device that do not meet instruction requirements;
[0011] The whitelist updating unit is configured to update the whitelist configuration files corresponding to the hardware devices according to the system management bus instructions corresponding to the hardware devices, and write the updated whitelist files into the flash platform firmware elastic partition.
[0012] According to a third aspect of the present disclosure, a network device is provided, including:
[0013] at least one processor; and
[0014] a memory communicatively connected to the at least one processor; wherein,
[0015] The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the method described in the first aspect.
[0016] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute the method described in the first aspect.
[0017] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method as described in the first aspect above.
[0018] According to the present disclosure, a whitelist configuration file corresponding to each hardware device in a hardware device set in a flash platform firmware elastic partition is obtained, wherein the hardware device set includes at least one device connected to a system management bus; a system management bus data set corresponding to the hardware device set is obtained once every first time period through a system management bus protocol, and the system management bus data set is identified using a first neural network model to obtain system management bus instructions corresponding to each hardware device that do not meet instruction requirements; a whitelist configuration file corresponding to each hardware device is updated according to the system management bus instructions corresponding to each hardware device, and the updated whitelist file is written to the flash platform firmware elastic partition. Therefore, PFR can be introduced into the neural network model, and the configured whitelist can be updated using the obtained data set. This can reduce the situation where a statically configured whitelist allows SMBus data not in the configuration file to access the BMC, resulting in lower BMC security. This can improve the matching of SMBus data with the whitelist, dynamically adjust the whitelist, intercept access, improve the intelligent monitoring capability of PFR, and improve the security, reliability, and predictability of the server.
[0019] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings are used to better understand the present invention and do not constitute a limitation of the present invention.
[0021] Figure 1 A background diagram of a whitelist updating method provided in an embodiment of the present disclosure;
[0022] Figure 2 A flowchart of a whitelist updating method provided in an embodiment of the present disclosure;
[0023] Figure 3 This is a schematic diagram illustrating another whitelist updating method provided in an embodiment of the present disclosure;
[0024] Figure 4 A hardware link diagram of a PFR overall system provided by an embodiment of the present disclosure;
[0025] Figure 5A layout diagram of the Platform Firmware Resilience Complex Programmable Logic Device (PFRCPLD) and Unified Flow Management (UFM) area provided in an embodiment of the present disclosure;
[0026] Figure 6 This is a schematic diagram of an example of a recurrent neural network model provided in an embodiment of the present disclosure;
[0027] Figure 7 An example schematic diagram of forward propagation provided by an embodiment of the present disclosure;
[0028] Figure 8 An example schematic diagram of an S-shaped activation function (Sigmoid Activation Function) provided in an embodiment of the present disclosure;
[0029] Figure 9 An example schematic diagram of back propagation of a recurrent neural network model provided in an embodiment of the present disclosure;
[0030] Figure 10 This is a schematic diagram of an example of a recurrent neural network model provided in an embodiment of the present disclosure;
[0031] Figure 11 This is a schematic diagram illustrating an example of a whitelist updating method provided in an embodiment of the present disclosure;
[0032] Figure 12 A schematic diagram of the structure of a whitelist updating device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0033] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0034] In some embodiments, the entire PFR process can be divided into two phases, T-1 and T0. PFRCPLD enters the T-1 phase by setting the srst GPIO. During T-1, PFRCPLD first checks whether the active hardware (Active HW) or firmware (Firmware) is functioning properly and whether a recovery area upgrade is required. Once the PFRCPLD is functioning properly, it then verifies whether the Active FW of the BMC or Platform Controller Hub (PCH) is functioning properly and whether a recovery upgrade is required. If the BMC or PCH Active FW is normal, the process enters the T0 phase, where the BMC or PCH boots normally. The watchdog timer (WDT) signal is used to determine boot completion. If boot fails, the process enters the T-1 phase for recovery. To prevent malicious attacks, Serial Peripheral Interface (SPI) whitelist command filtering continues during the T0 phase to protect the platform FW.
[0035] According to some embodiments, Figure 1 A background diagram of a whitelist update method is shown below. Figure 1 As shown, the following steps may be included:
[0036] S1: Create a PFR tuple project package to manage PFR solutions. This package is mainly used to meet special PFR requirements. Based on the base project, a code package is created that contains the basic base project but is different from the base project.
[0037] S2: Add board IDs (boardid) and U-Boot device tree source files (U-BootDeviceTreeSource, uboot dts files) adapted to different projects, and perform independent maintenance for special underlying requirements;
[0038] S3: Modify the SPI clock frequency to prevent BMC from hanging;
[0039] S4: Obtain the Supply Chain Management ID (SCMID) of the management board to distinguish between PFR and non-PFR models;
[0040] S5: Adapting to 256MB Flash Memory (FLASH) manufacturers, adding FLASH drivers, caused FLASH to be unrecognizable, resulting in the BMC being unable to start;
[0041] S6: Divide the 256MB FLASH partition into the following: Universal Boot Loader (U-Boot), U-Boot Environment (u-boot-env), kernel, Read-Only File System (rofs), Platform Firmware Management (pfm), Read-Write File System (rwfs), Rescue Image (rc-image), Staging BMC (stg-BMC), Staging PFR CPLD (stg-pfr-cpld), Staging CPLD (stg-cpld), and Reserved 2 (rsvd2).
[0042] S7: Create an upgrade module for upgrading the BMC, Basic Input / Output System (BIOS), and Platform Firmware Resilience Complex Programmable Logic Device (PFRCPld).
[0043] S8: PFR image management package, first loads the PFM configuration whitelist, compresses the PFM partition in the form of page size, generates Inter-Integrated Circuit (I2C) rule data, and creates a PFM partition binary file (bin file).
[0044] S9: End.
[0045] The following describes the whitelist updating method, apparatus, network device, and storage medium according to embodiments of the present disclosure with reference to the accompanying drawings.
[0046] Figure 2 This is a flow chart of a whitelist update method provided by an embodiment of the present disclosure. Figure 2 As shown, the method comprises the following steps:
[0047] Step 101: Obtain a whitelist configuration file corresponding to each hardware device in a hardware device set in a flash memory platform firmware elastic partition, wherein the hardware device set includes at least one device connected to a system management bus;
[0048] According to some embodiments, the execution subject of the embodiments of the present disclosure may be, for example, a network device, which may also be referred to as a server. Specifically, the network device may be, for example, a BMC server. The BMC server does not specifically refer to a fixed server. For example, when the server identifier changes, the BMC server may also change accordingly. The BMC server may be, for example, a server management unit.
[0049] According to some embodiments, a BMC (Baseboard Management Controller) is the core control unit of a server and a motherboard processor based on the ARM architecture used to manage the server. OpenBMC is an open-source software framework for building a complete BMC-specific Linux system image. OpenBMC utilizes a novel Boost ASIO technology, offering advantages over traditional BMC development, such as modular programming, modular debugging, and asynchronous solution management. In the server field, the BMC, as a core component, plays a significant role in server performance monitoring, sensor monitoring (threshold sensors and discrete sensors), fault alarms, power consumption loss, logging (such as the System Event Log (SEL) and Fault Diagnostic Log (IDL)), thermal management, component monitoring, BIOS interaction, Kernel-based Virtual Machine (KVM) decoding, network configuration, and fault diagnosis.
[0050] According to some embodiments, the Flash Platform Firmware Flexible Flash PFM partition can be used to store, for example, a whitelist file, i.e., a whitelist configuration file. The Flash Platform Firmware Flexible Flash PFM partition does not specifically refer to a fixed partition. For example, if the partition size corresponding to the Flash Platform Firmware Flexible Flash PFM partition changes, the Flash Platform Firmware Flexible Flash PFM partition can also change accordingly.
[0051] In some embodiments, a hardware device set may be, for example, a collection of at least one hardware device. The hardware device set does not specifically refer to a fixed set. For example, when the number of hardware devices included in the hardware device set changes, the hardware device set may also change accordingly. For example, when a hardware device in the hardware device set changes, the hardware device set may also change accordingly.
[0052] According to some embodiments, the hardware device may be a device connected to the BMC server via the SMBus, including but not limited to a mailbox, a complex programmable logic device (CPLD), and a platform controller hub (PCH).
[0053] In some embodiments, the whitelist configuration file may be, for example, a whitelist configuration file set according to a received configuration instruction. The name of the whitelist configuration file is not limited. For example, the whitelist configuration file may also be referred to as a first whitelist file, a configuration file, etc. Different hardware devices may correspond to different whitelist configuration files. The whitelist configuration file does not specifically refer to a fixed file. For example, when a hardware device changes, the whitelist configuration file may also change accordingly. For example, when a configuration modification instruction is received, the whitelist configuration file may also change accordingly.
[0054] In some embodiments, a whitelist configuration file corresponding to each hardware device of a hardware device set in a Flash PFM partition may be obtained, wherein the hardware device set includes at least one device connected to a system management bus.
[0055] Step 102: acquiring a system management bus (SMB) data set corresponding to the hardware device set using a SMB protocol at first intervals, and identifying the SMB data set using a first neural network model to obtain SMB instructions corresponding to each hardware device that do not meet instruction requirements.
[0056] According to some embodiments, the first duration may be, for example, the duration of an interval for obtaining a system management bus (SMB) data set. The first duration may also be referred to as a first preset duration. The first duration may be determined, for example, based on the amount of data corresponding to the SMB data set, or based on a predicted amount of data for the SMB data set. Specifically, for example, if predicted data corresponding to the SMB data set indicates that the amount of data in the SMB data set is increasing, the value of the first duration may be reduced.
[0057] According to some embodiments, the SMBus protocol may be, for example, a two-wire serial bus communication protocol, a subset of the I2C bus, and is primarily used for low-speed device communication, particularly hardware devices related to system management and power management.
[0058] According to some embodiments, a system management bus data set may be, for example, a data set corresponding to a hardware device set. The system management bus data set may also be referred to as an SMBus data set, or as an SMBus command set. A system management bus data set does not specifically refer to a fixed set. For example, when the amount of data corresponding to the system management bus data set changes, the system management bus data set may also change accordingly. For example, when the hardware device set changes, the system management bus data set may also change accordingly.
[0059] In some embodiments, the first system management bus data set may include, for example, a subset of system management bus data corresponding to each hardware device in the hardware device set. The first system management bus data set does not specifically refer to a fixed set. For example, when the data acquisition time point changes, the first system management bus data set may also change accordingly.
[0060] In some embodiments, a neural network model, for example, can be used to identify a system management bus (SMB) data set and is a trained model. This neural network model is not specifically a fixed model. This neural network model can include a recurrent neural network model, a convolutional neural network model, and the like. The first of the first neural network models is used to distinguish it from the remaining neural network models. This first neural network model can, for example, be a trained model that can be used for data recognition.
[0061] In some embodiments, the instruction requirement may be, for example, an instruction to determine whether a system management bus instruction poses a threat to the operation of the BMC server. The instruction requirement is not specific to a fixed requirement. For example, when identifying historical system management bus data sets, the instruction requirement may be modified accordingly.
[0062] In some embodiments, the system management bus instruction may also be referred to as a system management bus command.
[0063] In some embodiments, a system management bus data set corresponding to a set of hardware devices is obtained once every first period of time through a system management bus protocol, and a first neural network model is used to identify the system management bus data set to obtain system management bus instructions corresponding to each hardware device that do not meet the instruction requirements.
[0064] Step 103 : updating the whitelist configuration file corresponding to each hardware device according to the system management bus instruction corresponding to each hardware device, and writing the updated whitelist file into the flash platform firmware elastic partition.
[0065] According to some embodiments, a whitelist configuration file corresponding to each hardware device may be updated according to a system management bus instruction corresponding to each hardware device, and the updated whitelist file may be written into the Flash PFM partition.
[0066] Through the present disclosure, a whitelist configuration file corresponding to each hardware device in a hardware device set in a flash platform firmware elastic partition is obtained, wherein the hardware device set includes at least one device connected to a system management bus; a system management bus data set corresponding to the hardware device set is obtained once every first time period through a system management bus protocol, and a first neural network model is used to identify the system management bus data set to obtain a system management bus instruction corresponding to each hardware device that does not meet the instruction requirements; a whitelist configuration file corresponding to each hardware device is updated according to the system management bus instruction corresponding to each hardware device, and the updated whitelist file is written to the flash platform firmware elastic partition. Therefore, PFR can be introduced into the neural network model, and the configured whitelist can be updated using the obtained data set. The static configuration whitelist can be reduced so that SMBus data not in the configuration file accesses the BMC, resulting in lower BMC security. The matching of SMBus data and the whitelist can be improved, the whitelist can be dynamically adjusted, access can be intercepted, the intelligent monitoring capability of PFR can be improved, and the security, reliability and predictability of the server can be improved.
[0067] It should be noted that the embodiments of the present disclosure may include multiple steps. For the convenience of description, these steps are numbered, but these numbers do not limit the execution time slots or execution order between the steps; these steps can be implemented in any order, and the embodiments of the present disclosure do not limit this.
[0068] Furthermore, in a possible implementation of this embodiment, Figure 3 This is a flow chart of another whitelist updating method provided by the embodiment of the present disclosure. Figure 3 As shown, the method comprises the following steps:
[0069] Step 201: Obtain a whitelist configuration file corresponding to each hardware device in a hardware device set in a flash memory platform firmware elastic partition, wherein the hardware device set includes at least one device connected to a system management bus;
[0070] The relevant process may be as described above, and will not be described in detail here.
[0071] According to some embodiments, Figure 4 This is a PFR overall system hardware link diagram provided by the embodiment of the present disclosure. Figure 4As shown in the figure, CPLD Platform Rot represents the PFRCPLD hardware architecture, BMC represents the server management unit, and PCH represents the BIOS boot unit. The SPI interface protocol reads data from the flash memory to recover or update the firmware version. The SPI filter filters unauthorized SPI commands. The mailbox bridges communication between the CPLD and the PCH or BMC, reading register data and writing various states via the SMBus protocol.
[0072] According to some embodiments, the purpose of PFR is to protect platform assets (Protection), detect malicious or erroneous behaviors such as damaged firmware (Detection), and restore platform firmware (Recovery) to a good image state.
[0073] Protection: Ensure the integrity of server firmware and key data, and ensure data authenticity and integrity during the upgrade process;
[0074] Detection: Detects when server firmware and critical data are damaged;
[0075] Recovery: When the server firmware FW and key data are damaged, restore the FW.
[0076] According to some embodiments, PFR utilizes a CPLD as the core of the entire PFR technology and defines a special pre-boot state, T-1 (T minus 1). After the system is powered on, it first enters T-1. During this phase, all other firmware with potential boot interfaces (such as the PCH, central processing unit (CPU), management engine (ME), and baseboard management system (BMC)) are in reset. Only the PFR CPLD is powered on and boots up. The PFR CPLD first verifies the BMC FLASH and BIOS FLASH. If the verification fails, the PFR CPLD erases the failed FLASH area and uses the RECOVER partition image file to restore the ACTIVE partition FLASH data. If the verification succeeds, the system enters normal boot mode in Bootguard, followed by T0 mode. In T0 mode, the PFR CPLD monitors and filters SPI data. A whitelist can be configured. Data that does not meet the whitelist criteria is blocked from transmission or writing to the FLASH, effectively filtering out malicious data.
[0077] According to some embodiments, in the security architecture of PFR, BIOS FLASH and BMC FLASH are divided into three parts, namely, the active ACTIVE area, the recovery RECOVERY area, and the STAGING area. ACTIVE stores uncompressed, directly executed firmware, RECOVERY stores compressed backup files, and STAGING is a temporary buffer for upgrades. When the device starts, the PFR CPLD will verify the ACTIVE area. After the verification passes, the device starts from the ACTIVE area. When the verification fails, the PFR CPLD will restore the image in the RECOVERY area to the ACTIVE area, and then restart. When the system firmware is upgraded, the PFR CPLD will verify the upgrade package. After the verification is successful, the firmware will first be placed in the STAGING area, and then the system will restart. After the restart, the CPLD will write the new firmware to the ACTIVE area and the RECOVERY area.
[0078] According to some embodiments, Figure 5 A PFRCPLD UFM area layout diagram provided by the embodiment of the present disclosure. Figure 5 The names and functions of each area are as follows:
[0079] UFM0: Used to store provisioning information and the address segments of various storage areas in the flash memory (for example, the storage area can be at least one of Active, Recovery, and Staging). If the provisioning test fails, the system will not operate normally.
[0080] UFM1: stores the CPLD recovery update status. The first word = 0 is being updated, and all words are set to 1 after completion.
[0081] CFM0: Stores the firmware and hardware used for recovery. During power-on, if an abnormality occurs and recovery is required, the data in CFM0 is used for execution. If all other conditions are normal, the system quickly switches to CFM1.
[0082] CFM1: stores the active firmware and hardware. During normal power-on, the firmware and hardware in CFM1 are used.
[0083] In some embodiments of the root association, in the PFR Provison Information, PFR can correspond to two states, Provision and UN-provision. In the provision state, PFR can support BMC, BIOS or CPLD upgrades, and in the unprovison state, PFR upgrades are not supported. Provison data is crucial for PFRCPLD to perform reliable operations and must be stored in a secure area (UFM0) and independent of user operations. PFRCPLD receives provison data generated by BPM through Mailbox and stores it in UFM. After storage, there will be an execution lock LOCK. Once LOCKed, the root key, flash setting offset, and periodic interval timer (PIT) password can no longer be modified.
[0084] In the data authentication in PFR, PFRCPLD uses the key to verify the various types of data in the SPI FLASH, and a CSK segment is reserved before PFM and CAPSULE.
[0085] According to some embodiments, data block Block1 contains a signature chain that is used to sign BLOCK0. Block1 is composed of three types of data structures:
[0086] Root entry: includes the public components of the root key;
[0087] CSK entry: includes the public component of the CSK signed by the root key;
[0088] Block0 entry: includes the signature of Block0 using the CSK.
[0089] According to some embodiments, after performing Block 0 verification, the PFR is required to compare the calculated hash value of the protected content with the hash value provided in Block 0.
[0090] According to some embodiments, in Key Cancellation, in the event that a key is stolen, KeyCancellation can inform that the key has been stolen and is no longer valid for signing data, and a temporary key will be generated to solve the problem.
[0091] According to some embodiments, PFR Decommission may be used to erase the provison information of the UFM area, and after the erasure, the PFRCPLD is in an unprovison state.
[0092] According to some embodiments, the Platform Firmware Manifest (PFRMCPLD) can provide a data structure. Each platform provides key information to the CPLD through the PFM, including the platform's FLASH area and SMBus data filtering rules, as well as read and write rules for the FLASH partition. This area structure data is configured with different whitelist data based on the different platform projects.
[0093] Step 202: acquiring a system management bus data set corresponding to the hardware device set through the system management bus protocol once every first time period;
[0094] The relevant process may be as described above, and will not be described in detail here.
[0095] According to some embodiments, the first duration may be, for example, 2 seconds.
[0096] Step 203: obtaining an activation function corresponding to the recurrent neural network model according to the output requirement information corresponding to the recurrent neural network model;
[0097] The relevant process may be as described above, and will not be described in detail here.
[0098] In some embodiments, the output requirement information may be used to indicate requirements for output information. The output requirement information does not specifically refer to a fixed requirement information. For example, the output requirement information may include the accuracy of the output information, the duration of the output information, etc.
[0099] In some embodiments, the activation function is an important component of a neural network model. It introduces nonlinearity into each neuron in the neural network, enabling the network to learn and perform more complex tasks. The activation function in the disclosed embodiments does not specifically refer to a fixed function.
[0100] According to some embodiments, the activation function includes at least one of a sigmoid activation function, a softmax activation function, a hyperbolic tangent tanh activation function, and a rectified linear unit (ReLU) activation function.
[0101] In some embodiments, for example, when the output requirement information is k-category classification information, softmax can be selected as the activation function.
[0102] According to some embodiments, in the recurrent neural network model, for example, a hyperbolic tangent activation function or a ReLU activation function may be selected.
[0103] In some embodiments, for example, when the output requirement information is binary classification information, a S-shaped activation function may be selected as the activation function.
[0104] According to some embodiments, the method further comprises:
[0105] Obtain the loss function corresponding to each time step in the first neural network model;
[0106] Using the loss function corresponding to each time step, obtain the loss function corresponding to the first neural network model;
[0107] The loss function is used to update the weight set of the first neural network model to obtain the second neural network model. Therefore, the loss function can be used to update the weight set of the neural network model, thereby improving the accuracy of neural network model acquisition, improving the accuracy of instruction acquisition, improving the accuracy of whitelist acquisition, and improving the security of BMC services.
[0108] According to some embodiments, the loss function is a mean square error loss function.
[0109] According to some embodiments, the method further comprises:
[0110] Acquire a historical system management bus data set corresponding to the hardware device set every second time period, wherein the historical system management bus data set includes a training data set, a verification data set, and a test data set;
[0111] Training the third neural network model using the training data set to obtain a fourth neural network model;
[0112] Updating the model parameters of the fourth neural network model using the validation data set to obtain a fifth neural network model;
[0113] The fifth neural network model is tested using the test data set, and if the test results meet the result requirements, the first neural network model is obtained. Therefore, the accuracy of neural network model training and the accuracy of neural network model acquisition can be improved, and the security of instruction acquisition can be improved.
[0114] According to some embodiments, the method further comprises:
[0115] Through the dependency interface corresponding to the neural network model, the sixth neural network model corresponding to the current application scenario in the PyTorch library is called, and the third neural network model is constructed based on the sixth neural network model. Different models can be trained for different application scenarios, which can improve the accuracy of whitelist updates, improve reliability and flexibility.
[0116] According to some embodiments, the current application scenario may include, for example, a hardware device set or a data volume.
[0117] According to some embodiments, Figure 6 This is an example diagram of a recurrent neural network model, such as Figure 6 As shown, the instruction can also be called a command, and the SMBus command at the first moment is x <1> , the first SMBus command is input into a neural network layer. The hidden layer of the first neural network can control the neural network model to predict the output and determine whether this is an SMBus command that meets the command requirements. What the recurrent neural network model does is that when it reads the second SMBus command in the sentence, assuming it is x <2> , it is not just x <2> Then we predict y(^) <2> , some information from time step 1 is also input. Specifically, the activation value of time step 1 is passed to time step 2. Then, at the next time step, the recurrent neural network model inputs the SMBus command x <3> , try to predict and output the prediction result y(^) <3> , and so on, until the last time step, input x <tx>, then output y(^) <ty>At least in this example, Tx = Ty. If Tx and Ty are different, the structure of the neural network model can be modified accordingly. So at each time step, the recurrent neural network model can pass an activation value to the next time step for calculation.
[0118] According to some embodiments, for example, you can first enter a <0> , which is a zero vector. In the forward propagation process, the activation value a is first calculated by formula (1) <1> Then calculate y by formula (2) <1> .
[0119] a <1> = g1 (waa a <0> + wax x <1> + ba )(1)
[0120] y(^) <1> = g2 (wya a <1> + by )(2)
[0121] Among them, wa and ba are weight matrices, and g1 and g2 are activation functions.
[0122] According to some embodiments, a notational convention is used in formulas to represent these matrix subscripts. For example, in the case of wax, the second subscript indicates that wax is multiplied by a quantity of type x, and the first subscript a indicates that it is used to calculate a variable of type a. Similarly, wya is multiplied by a quantity of type a to calculate a quantity of type y(^).
[0123] According to some embodiments, where the output is y, for named entity recognition y can only be 0 or 1, the second activation function g can be a sigmoid activation function. Where, at time t,
[0124] a <t>= g1 (is a<t−1> + anything <t>+ is )(3)
[0125] y(^) <t>= g2 (wya a <t>+ by )(4)
[0126] The above formula defines the forward propagation of the recurrent neural network model, which can be obtained from the zero vector a <0> Start with a <0> and x <1> To calculate a <1> and y(^) <1> Then use x <2> and a <1> Calculate a together <2> and y(^) <2> Wait, like Figure 7 In this way, the forward propagation is completed from left to right.
[0127] According to some embodiments, the Sigmoid activation function may be, for example, as shown in formula (5), and its function curve may be, for example, as shown in Figure 8 As shown:
[0128] (5)
[0129] Among them, S(x): represents the output of the Sigmoid function;
[0130] x: represents the input value, which can be any real number;
[0131] e: represents the base of natural logarithm, approximately equal to 2.71828;
[0132] e -x : represents e to the power of -x, that is, e to the power of -x.
[0133] According to some embodiments, the output range of the Sigmoid activation function is between 0 and 1 and can be used as the output function of the model. It is used to output a probability value in the range of 0 to 1, such as for representing the category of a binary classification or for representing the confidence level. The Sigmoid activation function has the characteristic of smooth gradient, which facilitates derivation and prevents sudden gradient changes during model training.
[0134] According to some embodiments, Figure 9 FIG2 is a schematic diagram illustrating an example of back propagation of a recurrent neural network model according to an embodiment of the present disclosure, wherein the calculation direction of back propagation is substantially opposite to that of forward propagation. The purpose of back propagation is to update weights to reduce prediction errors.
[0135] According to some embodiments, for example, there is an input sequence, x <1> , x <2> , x <3> Until x <tx>Then use x <1> There is also a <0> Calculate the activation term at time step 1 and use x <2> and a <1> Calculate a <2> , then calculate a <3> Wait until a <tx>.
[0136] In order to calculate a <1> , we can calculate a by using the weight matrices wa and ba <1> The weight matrices wa and ba will be used in each subsequent time step, so continue to use these parameters to calculate a <2> , a <3> All these activations depend on the parameters wa and ba. <1> , the neural network model can calculate the first prediction value <1> , then go to the next time step and continue to calculate <2> , <3> , and so on, until <ty>In order to calculate , requires parameters wy and by, which will be used for all these nodes.
[0137] According to some embodiments, in order to calculate the back propagation, the defined element loss function may be, for example, Formula (6):
[0138] L1 <t> ( <t> , y <t> ) = −y <t>log <t> − (1 − <t>)log(1 − <t>)(6)
[0139] Among them, the loss function corresponds to a specific word in the sequence. For example, if it is a person’s name, then y <t>The value of is 1, and the neural network model will output the probability value of the word being a name, such as 0.1. This is defined as the standard logistic regression loss function, also known as the cross entropy loss function.
[0140] Therefore, the loss function can be a loss function about the predicted value of a word at a single position or at a certain time step t.
[0141] According to some embodiments, the loss function for the entire sequence is defined as L2 as formula (7)
[0142]
[0143] (7)
[0144] t = 1
[0145] Therefore, through <1> The corresponding loss function can be calculated, so the loss function of the first time step is calculated, and then the loss function of the second time step is calculated, and then the third time step, until the last time step. Finally, in order to calculate the overall loss function, the final L is calculated through the above equation, that is, the loss function of each individual time step is added up.
[0146] Therefore, after backpropagation, all appropriate quantities can be calculated and the parameters can be updated using gradient descent via their derivatives.
[0147] According to some embodiments, you can import recurrent neural network model library functions, add recurrent neural network model dependency interfaces, etc. Import the neural network model library torch.nn, the algorithm optimizer package torch.optim, and the data loading and processing tool torch.utils.data from PyTorch. Import the PyTorch library tools and set up a model training environment.
[0148] According to some embodiments, in order to improve the validity and prediction accuracy of SMBus data, an automated script is used to collect SMBus security instructions of different models on all current projects as whitelist instructions, and instructions for operating the power management module, EEPROM, system controller, etc. are regarded as risk instructions and are not planned in the whitelist. The collection cycle is once every 5 seconds, and the collection time is 5*24 hours. The two-dimensional data collected from different projects and different models are imported into a json file and stored in a two-dimensional array sample format. The data are divided into training set, validation set, and test set in a ratio of 8:1:1. The training set is used for model training, the validation set is used for model parameter optimization, and the purpose of the test set is to verify the accuracy and reliability of the model.
[0149] According to some embodiments, Figure 10 This is an example diagram of a recurrent neural network model, such as Figure 10 As shown, model training uses the PyTorch library's torch.nn.RNN() interface to create a recurrent neural network and add a fully connected layer to map hidden states to outputs. The RNN model consists of an input layer, a hidden layer, and an output layer. The model is initialized with 4 input features, 6 hidden layer neurons, and 2 output layer neurons. The loss function used in the initial model is MSEloss(). MSE has a smooth, continuous, and universally differentiable curve, making it easy to use the gradient descent algorithm. After building the PyTorch training project based on the neural network model above, model training will begin.
[0150] According to some embodiments, the neural network model of the present disclosure can be trained 100 times, with 32 samples used for each parameter update. The neural network model constructed above is trained by inputting the dataset data. After training, the performance of the final model is evaluated on the test set. The model with the highest final prediction accuracy is output, using the final prediction accuracy as the criterion, and loaded into the openBMC pfr-manager service model.
[0151] Step 204: Using a recurrent neural network model and an activation function, identify the system management bus data of the first time step in the system management bus data set, and identify the system management bus data of the second time step based on the activation value of the first time step, the recurrent neural network model, and the activation function, to obtain the system management bus instructions corresponding to each hardware device that do not meet the instruction requirements, where the first time step is the previous time step adjacent to the second time step.
[0152] The relevant process may be as described above, and will not be described in detail here.
[0153] According to some examples, the first time step does not specifically refer to a fixed time step. The first time step and the second time step may be adjacent time steps, that is, the activation value of the previous time step may affect the prediction of the next time step.
[0154] In some embodiments, a recurrent neural network model and an activation function can be used to identify the system management bus data of the first time step in the system management bus data set, and the system management bus data of the second time step can be identified based on the activation value of the first time step, the recurrent neural network model and the activation function to obtain the system management bus instructions corresponding to each hardware device that do not meet the instruction requirements, where the first time step is the previous time step adjacent to the second time step.
[0155] Step 205 : updating the whitelist configuration file corresponding to each hardware device according to the system management bus instruction corresponding to each hardware device, and writing the updated whitelist file into the flash platform firmware elastic partition.
[0156] The relevant process may be as described above, and will not be described in detail here.
[0157] According to some embodiments, for example, the model obtained above can be loaded into the pfr-manager project of the openBMC meta-pfr tuple. After the BMC server is started, the pfr-manager management service is pulled up, and the management service is controlled to poll every 2 seconds. The pfr-manager service is controlled to load the neural network model file generated in the above training, obtain SMBus data in real time to predict security commands, and generate the latest SMBus whitelist configuration file. The whitelist configuration file is updated every 2 seconds, and the SMBus security instructions in the whitelist configuration file are dynamically written to the FLASH PFM partition, which can be used by PFRCPLD to parse the whitelist security instructions and filter commands other than security instructions, that is, threat instructions, to prevent threat attacks on the OPENBMC firmware.
[0158] According to some embodiments, Figure 11 This is an example diagram of a whitelist update method. Figure 11 As shown, the following steps may be included:
[0159] S1: Create a PFR tuple engineering package to manage PFR solutions. This package is mainly used to meet special PFR requirements. Based on the base project, a code package is created that contains the base project but is different from the base project.
[0160] S2: Add boardid and uboot dts files adapted to different projects, and perform independent maintenance for special underlying requirements;
[0161] S3: Modify the SPI clock frequency to prevent BMC from hanging;
[0162] S4: Get the SCMID of the management board to distinguish between PFR and non-PFR models;
[0163] S5: Adapting to 256MB FLASH manufacturers, adding FLASH driver, the FLASH cannot be recognized, resulting in the problem that BMC cannot start;
[0164] S6: Divide the 256MB FLASH partition into: u-boot, u-boot-env, kernel, rofs, pfm, rwfs, rc-image, stg-BMC, stg-pfr-cpld, stg-cpld, rsvd2;
[0165] S7: Upgrade module creation, used to upgrade BMC, BIOS, and pfrcpld;
[0166] S8: PFR image management package, first loads the PFM configuration whitelist, compresses the PFM partition in the form of page size, generates I2C rule data, and creates the PFM partition bin file.
[0167] S9: PFR-MANAGER is used to dynamically load the neural network model and predict the output of SMBus threat-type instructions. It will be synchronously updated to the PFM whitelist every 2 seconds and the latest whitelist data will be written to the PFM partition in FLASH for PFRCPLD to parse, thereby preventing illegal data from invading the BMC.
[0168] S10: End.
[0169] In one or related embodiments, an activation function corresponding to the recurrent neural network model can be obtained based on the output requirement information corresponding to the recurrent neural network model; the recurrent neural network model and the activation function are used to identify the system management bus data of the first time step in the system management bus data set, and the system management bus data of the second time step is identified based on the activation value of the first time step, the recurrent neural network model and the activation function, to obtain the system management bus instructions corresponding to each hardware device that do not meet the instruction requirements, and the first time step is the previous time step adjacent to the second time step; therefore, the accuracy of instruction acquisition can be improved, the accuracy of whitelist updates can be improved, and the security of BMC server access can be improved.
[0170] According to an embodiment of the present disclosure, the present disclosure also provides a whitelist updating device.
[0171] For example, Figure 12 This is a schematic diagram of the structure of a whitelist updating device provided by an embodiment of the present disclosure. The whitelist updating device 1200 includes: a file acquisition unit 1201, a collection acquisition unit 1202 and a whitelist updating unit 1203; wherein,
[0172] A file acquisition unit 1201 is configured to acquire a whitelist configuration file corresponding to each hardware device in a hardware device set in a flash memory platform firmware elastic partition, wherein the hardware device set includes at least one device connected to a system management bus;
[0173] The set acquisition unit 1202 is configured to acquire a system management bus (SMB) data set corresponding to the hardware device set using the SMB protocol at a first interval, and identify the SMB data set using a first neural network model to obtain SMB instructions corresponding to each hardware device that do not meet instruction requirements.
[0174] The whitelist updating unit 1203 is configured to update the whitelist configuration file corresponding to each hardware device according to the system management bus instruction corresponding to each hardware device, and write the updated whitelist file into the flash platform firmware elastic partition.
[0175] Furthermore, where the first neural network model is a recurrent neural network model, the set acquisition unit 1202 is further configured to:
[0176] According to the output requirement information corresponding to the recurrent neural network model, an activation function corresponding to the recurrent neural network model is obtained;
[0177] A recurrent neural network model and an activation function are used to identify the system management bus data of the first time step in the system management bus data set, and the system management bus data of the second time step are identified based on the activation value of the first time step, the recurrent neural network model and the activation function, to obtain the system management bus instructions that do not meet the instruction requirements corresponding to each hardware device, where the first time step is the previous time step adjacent to the second time step.
[0178] Furthermore, the activation function includes at least one of a sigmoid activation function, a softmax activation function, a tanh activation function, and a ReLU activation function.
[0179] Furthermore, the set acquisition unit 1202 is further configured to:
[0180] Obtain the loss function corresponding to each time step in the first neural network model;
[0181] Using the loss function corresponding to each time step, obtain the loss function corresponding to the first neural network model;
[0182] The loss function is used to update the weight set of the first neural network model to obtain a second neural network model.
[0183] Furthermore, the loss function is a mean square error loss function.
[0184] Furthermore, the set acquisition unit 1202 is further configured to:
[0185] Acquire a historical system management bus data set corresponding to the hardware device set every second time period, wherein the historical system management bus data set includes a training data set, a verification data set, and a test data set;
[0186] Training the third neural network model using the training data set to obtain a fourth neural network model;
[0187] Updating the model parameters of the fourth neural network model using the validation data set to obtain a fifth neural network model;
[0188] The fifth neural network model is tested using the test data set, and when the test result meets the result requirement, the first neural network model is obtained.
[0189] Furthermore, the set acquisition unit 1202 is further configured to:
[0190] Through the dependency interface corresponding to the neural network model, call the sixth neural network model corresponding to the current application scenario in the pytorch library, and build the third neural network model based on the sixth neural network model.
[0191] It should be noted that, for the description of the features in the embodiment corresponding to the whitelist updating device, reference can be made to the relevant description of the embodiment corresponding to the whitelist updating method, which will not be repeated here.
[0192] An embodiment of the present disclosure further provides a network device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any of the above-mentioned whitelist updating method embodiments.
[0193] An embodiment of the present disclosure further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps of any of the above-mentioned whitelist updating method embodiments when running.
[0194] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.
[0195] An embodiment of the present disclosure further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in any of the above-mentioned whitelist updating method embodiments are implemented.
[0196] An embodiment of the present disclosure further provides another computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above-mentioned whitelist updating method embodiments are implemented.
[0197] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0198] The above is a detailed introduction to a whitelist update method provided by the present disclosure. This article uses specific examples to illustrate the principles and implementation methods of the present disclosure. The description of the above embodiments is only used to help understand the method of the present disclosure and its core ideas. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present disclosure, several improvements and modifications can be made to the present disclosure, and these improvements and modifications also fall within the scope of protection of the claims of the present disclosure.< / t> < / t> < / t> < / t> < / t> < / t> < / t> < / t> < / ty> < / tx> < / tx> < / t> < / t> < / t> < / t> < / ty> < / tx>
Claims
1. A whitelist updating method, characterized in that: include: Obtaining a whitelist configuration file corresponding to each hardware device in a hardware device set in a flash memory platform firmware elastic partition, wherein the hardware device set includes at least one device connected to a system management bus; Obtaining a system management bus data set corresponding to the set of hardware devices once every first period of time through a system management bus protocol, and identifying the system management bus data set using a first neural network model to obtain system management bus instructions corresponding to each of the hardware devices that do not meet instruction requirements; The whitelist configuration files corresponding to the hardware devices are updated according to the system management bus instructions corresponding to the hardware devices, and the updated whitelist files are written into the flash memory platform firmware elastic partition.
2. The method according to claim 1, characterized in that in, The first neural network model is a recurrent neural network model, and the method further includes: According to the output requirement information corresponding to the recurrent neural network model, obtaining an activation function corresponding to the recurrent neural network model; The system management bus data of the first time step in the system management bus data set is identified using the recurrent neural network model and the activation function, and the system management bus data of the second time step is identified based on the activation value of the first time step, the recurrent neural network model and the activation function, to obtain the system management bus instructions that do not meet the instruction requirements corresponding to each hardware device, where the first time step is the previous time step adjacent to the second time step.
3. The method according to claim 2, characterized in that The activation function includes at least one of a sigmoid activation function, a softmax activation function, a hyperbolic tangent activation function, and a rectified linear unit activation function.
4. The method according to claim 1, wherein The method further comprises: Obtaining a loss function corresponding to each time step in the first neural network model; Using the loss function corresponding to each time step, obtaining a loss function corresponding to the first neural network model; The loss function is used to update the weight set of the first neural network model to obtain a second neural network model.
5. The method according to claim 4, characterized in that The loss function is a mean square error loss function.
6. The method according to claim 1, characterized in that The method further comprises: Acquire a historical system management bus data set corresponding to the hardware device set every second time period, wherein the historical system management bus data set includes a training data set, a verification data set, and a test data set; Using the training data set to train the third neural network model to obtain a fourth neural network model; Updating the model parameters of the fourth neural network model using the verification data set to obtain a fifth neural network model; The fifth neural network model is tested using a test data set, and the first neural network model is obtained if the test result meets the result requirement.
7. The method according to claim 6, characterized in that The method further comprises: Through the dependency interface corresponding to the neural network model, the sixth neural network model corresponding to the current application scenario in the pytorch library is called, and the third neural network model is constructed according to the sixth neural network model.
8. A whitelist updating device, characterized in that: include: a file acquiring unit, configured to acquire a whitelist configuration file corresponding to each hardware device in a hardware device set in a flash memory platform firmware elastic partition, wherein the hardware device set includes at least one device connected to a system management bus; a set acquisition unit, configured to acquire, through a system management bus protocol, a system management bus data set corresponding to the hardware device set once every first period, and identify the system management bus data set using a first neural network model to acquire system management bus instructions corresponding to each hardware device that do not meet instruction requirements; The whitelist updating unit is configured to update the whitelist configuration files corresponding to the hardware devices according to the system management bus instructions corresponding to the hardware devices, and write the updated whitelist files into the flash platform firmware elastic partition.
9. A network device, characterized in that: include: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Communication number detection method and system based on deep learning
CN113242356A
Server control method and device, storage medium and electronic device
CN117131495A