BMC intrusion protection method and apparatus, and BMC and computer device

By setting up isolated business modules and security detection modules in the BMC, analyzing the data and sensing security situation, and restarting the BMC when an APT attack is detected, the problem of insufficient BMC defense capabilities is solved, and higher security and trustworthiness and defense capabilities are achieved.

WO2025103207A1PCT designated stage expired Publication Date: 2025-05-22HUAWEI TECH CO LTD

Patent Information

Application Number
PCT/CN2024/130578
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-14
Filing Date
2024-11-07
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

When facing advanced long-term threat (APT) attacks, existing BMCs lack defense capabilities, resulting in the attacked person breaking through the boundary defense and reducing the security and credibility of the BMC.

Method used

By setting up communication isolation service modules and security detection modules in the BMC, and isolation of storage media accessed by the service modules and security detection modules, the security detection module analyzes the data of the service module to perceive the security situation. When an APT attack is detected, the downgrade startup mode restarts the BMC to form a dynamic defense chain of defense->detection->degradation->recovery.

Benefits of technology

It effectively improves the BMC's ability to resist APT attacks, ensures the security and trustworthiness of the BMC, prevents the security detection module from affecting the security detection module when the business module is attacked, and restarts the BMC while ensuring the recovery ability of the basic business or BMC.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024130578_22052025_PF_FP_ABST
    Figure CN2024130578_22052025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a BMC intrusion protection method and apparatus, and a BMC and a computer device. The method is applied to a BMC in a computer device. The BMC comprises a service module and a security detection module, which are in communication isolation, wherein a storage medium accessed by the service module is isolated from a storage medium accessed by the security detection module; and the service module is used for providing a management function for components in a computer device, and the security detection module is used for carrying out security detection on the BMC. The method comprises: a security detection module acquiring data stored in a storage medium associated with a service module; analyzing the data and sensing the security situation of the service module, so as to obtain a security detection result; and when the security detection result indicates that a BMC has been subjected to an APT attack, restarting the BMC in a degraded start mode. A defense-in-depth scheme is used, namely, an intrusion detection capability has been added to a BMC on the basis of defense, so that a dynamic defense chain of defense, detection, degradation and recovery is formed, thereby enhancing the capability of the BMC to resist APT attacks and ensuring the security and trustworthiness of the BMC.
Need to check novelty before this filing date? Find Prior Art

Description

BMC intrusion protection method, device, BMC and computer equipment

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 14, 2023, with application number 202311524436.6 and application name “BMC intrusion protection method, device, BMC and computer equipment”, all of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of computers, and in particular to a BMC intrusion protection method, device, BMC, and computer equipment. Background Art

[0003] Currently, attacks on computer equipment are gradually evolving from decentralized attacks to organized, targeted advanced persistent threats (APTs). The Baseboard Management Controller (BMC) in computer equipment serves as a security hub, authenticating components and preventing counterfeiting, tampering, or replacement, ensuring their safety and reliability. Therefore, improving BMCs' ability to defend against APT attacks and ensuring their security and reliability is a pressing issue.

[0004] Summary of the Invention

[0005] The present application provides a BMC intrusion protection method, apparatus, BMC, and computer equipment, thereby effectively improving the BMC's ability to resist APT attacks and ensuring the BMC's security and reliability.

[0006] In a first aspect, a BMC intrusion protection method is provided, which is applied to the BMC in a computer device. The BMC includes a business module and a security detection module. The business module is used to provide management functions for components in the computer device, and the security detection module is used to perform security detection on the BMC. The business module and the security detection module are isolated from each other in communication, and the storage media accessed by the business module and the security detection module are isolated. The method includes: the security detection module obtains data stored in the storage medium associated with the business module, analyzes the data to perceive the security status of the business module, and obtains security detection results. If the security detection results indicate that the BMC has been attacked by an APT, the BMC is restarted in a degraded startup mode.

[0007] Compared with the BMC's defense strategy that only relies on border defense, APT attacks break through border defense, and BMC is breached by APT attacks, which reduces the value of BMC as a trusted center. This application provides a defense-in-depth solution, that is, on the basis of defense, BMC adds intrusion detection capabilities; by isolating the business module and the security detection module, it prevents the security detection module from being affected when the business module is attacked by APT; moreover, the security detection module analyzes the data of the BMC's business module to perceive the security situation of the business module. When the BMC may be attacked by APT, it can also restart the BMC while ensuring the recoverability of the basic business or BMC, thus forming a dynamic defense chain of defense->detection->degradation->recovery, which effectively improves the BMC's ability to resist APT attacks and ensures the security and trustworthiness of the BMC.

[0008] In one possible implementation, a security detection result is obtained based on data stored in a storage medium associated with the business module, including: detecting the operation security of the business module based on data stored in a first storage medium associated with the business module to obtain a security detection result, wherein the first storage medium is used to store data required for the operation of the business module.

[0009] Therefore, by analyzing the data stored in the business modules during operation, the operational security of the business modules can be tested. Specifically, the security of the operating environment when the BMC performs management operations on computer components can be tested. For example, by analyzing the data stored in the memory associated with the business modules and testing the memory security, the BMC can be detected as potentially vulnerable to APT attacks, thereby improving the BMC's ability to resist APT attacks.

[0010] In another possible implementation, a security detection result is obtained based on data stored in a storage medium associated with the business module, including: detecting data security of the business module based on data stored in a second storage medium associated with the business module to obtain a security detection result, where the second storage medium is used to store persistent data of the business module.

[0011] Therefore, by analyzing the business module's persistent data, the data security of the business module can be tested. For example, by analyzing the data stored in the non-volatile memory associated with the business module, the BMC can be detected by testing data security to detect possible APT attacks, thereby improving the BMC's ability to resist APT attacks.

[0012] In another possible implementation, obtaining a security detection result based on data stored in a storage medium associated with the business module includes obtaining a security detection result based on trusted root verification data of a BMC.

[0013] Since the trusted root serves as the basis of trust in a trusted computer system, the BMC's trusted root is used to perform integrity verification on the data of the business module. That is, based on the integrity constraints, it is checked whether the database is in a consistent state and whether the data has been modified. This reduces the possibility of the trusted root being tampered with, improves the BMC's ability to resist APT attacks, and ensures the security and trustworthiness of the BMC.

[0014] In another possible implementation, obtaining a security detection result based on data stored in a storage medium associated with the business module includes: obtaining the security detection result by analyzing data based on an advanced threat analysis system.

[0015] The remote system provides intrusion detection capabilities, which require high computing power, to address the insufficient computing power of the BMC's embedded processor. The BMC and remote system work together to detect potential APT attacks, improving the BMC's ability to defend against them.

[0016] In another possible implementation, restarting the BMC in the degraded startup mode includes: restarting the security detection module and mounting a storage medium associated with the security detection module.

[0017] In another possible implementation, after restarting the security detection module and mounting the storage medium associated with the security detection module, the method also includes: restarting the security detection module according to the restart instruction, mounting the storage medium associated with the security detection module, and restarting the business module, mounting the storage medium associated with the business module.

[0018] In some embodiments, a storage medium associated with the security detection module stores initial data for restarting the service module. The security detection module configures the initial data to the storage medium associated with the security detection module, and the service module restarts according to the initial data.

[0019] While secure boot protects the BMC firmware, memory security is ensured through a reset, and only storage media associated with the security detection module is mounted to ensure data security. This eliminates existing APT attack data and blocks APT attacks. After the attack is blocked, the security detection module maintains the core operating system's operational capabilities, providing basic remote management capabilities without losing control.

[0020] In a second aspect, a security detection device is provided, comprising modules for executing the BMC intrusion protection method of the first aspect or any possible design of the first aspect. For example, the security detection device comprises a communication module, a detection module, and a control module.

[0021] The detection module is used to obtain security detection results based on the data stored in the storage media associated with the business module. The data is used to perceive the security situation of the business module, and the security detection results are used to indicate the possibility of the BMC being attacked by advanced persistent threats (APTs).

[0022] The control module is configured to determine, based on a security detection result, that the BMC is under an APT attack and restart the BMC in a degraded startup mode.

[0023] In one possible implementation, when the detection module obtains a security detection result based on the data stored in the storage medium associated with the business module, it is specifically used to: detect the operation security of the business module based on the data stored in the first storage medium associated with the business module to obtain a security detection result, and the first storage medium is used to store the data required for the operation of the business module.

[0024] In another possible implementation, when the detection module obtains a security detection result based on the data stored in the storage medium associated with the business module, it is specifically used to: detect the data security of the business module based on the data stored in the second storage medium associated with the business module to obtain a security detection result, and the second storage medium is used to store the persistent data of the business module.

[0025] In another possible implementation, when the detection module obtains the security detection result according to the data stored in the storage medium associated with the business module, it is specifically configured to obtain the security detection result according to the trusted root verification data of the BMC.

[0026] In another possible implementation, when the detection module obtains the security detection result based on the data stored in the storage medium associated with the business module, it is specifically used to: obtain the security detection result by analyzing the data based on the advanced threat analysis system.

[0027] In another possible implementation, when the control module restarts the BMC in the degraded startup mode, it is specifically configured to: restart the security detection module and mount a storage medium associated with the security detection module.

[0028] In another possible implementation, after the control module restarts the security detection module and mounts the storage medium associated with the security detection module, it is also used to: restart the security detection module according to the restart instruction, mount the storage medium associated with the security detection module, and restart the business module, and mount the storage medium associated with the business module.

[0029] In a third aspect, a BMC is provided, which includes a business module and a security detection module. The business module is used to provide management functions for components in a computer device, and the security detection module is used to perform security detection on the BMC. The business module and the security detection module are isolated from each other in communication, and the storage media accessed by the business module and the security detection module are isolated. The security detection module is used to execute the operating steps of the method in the first aspect or any possible implementation of the first aspect.

[0030] In a fourth aspect, a computer device is provided, comprising a processor, a memory, and a BMC as described in the third aspect, wherein the BMC is configured to execute the operation steps of the method in the first aspect or any possible implementation of the first aspect.

[0031] In a fifth aspect, a computer-readable storage medium is provided, comprising: computer software instructions; when the computer software instructions are executed in a processor, the processor executes the operating steps of the method described in the first aspect or any possible implementation of the first aspect.

[0032] In a sixth aspect, a computer program product is provided. When the computer program product is run on a computer, the computer is caused to execute the operating steps of the method described in the first aspect or any possible implementation of the first aspect.

[0033] The technical effects brought about by any design method in the second to sixth aspects can be referred to the technical effects brought about by the first aspect or different design methods in the first aspect, and will not be repeated here.

[0034] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] FIG1 is a schematic structural diagram of a baseboard management controller provided by the present application;

[0036] FIG2 is a schematic structural diagram of another baseboard management controller provided by the present application;

[0037] FIG3 is a flow chart of a BMC intrusion protection method provided by the present application;

[0038] FIG4 is a schematic structural diagram of a safety detection device provided by the present application;

[0039] FIG5 is a schematic structural diagram of a computer device provided in this application. DETAILED DESCRIPTION

[0040] To facilitate understanding, the main terms involved in this application are first explained.

[0041] Baseboard management controller (BMC): A dedicated controller integrated into the motherboard or plugged into the motherboard using a standard such as Peripheral Component Interconnect Express (PCIe). This controller manages server functions, for example, device information, server status, remote server control, and maintenance.

[0042] Root of Trust (ROT): Also known as the root of trust, it serves as the basis for trust in a trusted computer system. This includes the measurement root, storage root, and reporting root.

[0043] Advanced Persistent Threat (APT): Also known as advanced persistent threat, APT is a sophisticated, persistent cyberattack. It encompasses three key elements: advanced, long-term, and threat. Advanced refers to the fact that executing an APT attack requires a higher level of customization and sophistication than traditional attacks, necessitating significant time and resources to research and identify vulnerabilities in the target. Long-term refers to the need for continuous observation and long-term access to the target in order to achieve a specific objective. The threat emphasizes that the target is a high-value organization, and a successful attack often results in significant financial losses or even devastating consequences.

[0044] The attack phases of advanced persistent threats include information gathering, external penetration, command and control, internal spread, and data exfiltration. From targeting to successful attack, there are multiple stages involved, a process known in the security field as the attack chain.

[0045] APT attackers are typically an organization. After selecting a target, they gather all relevant information about it. This information includes the target's organizational structure, office location, products and services, contact list, email addresses, meeting schedules, portal website directory structure, internal network architecture, deployed network security devices, open ports, the office operating system and email system used by employees, and the operating system and version of the company's World Wide Web (web) servers.

[0046] After information collection is complete, malware is developed and deployed on the target. Malware is typically a small remote control tool, also known as a Remote Administration Tool (RAT), used to establish a command and control channel (C&C) with a control server.

[0047] When a user opens a file containing malware using a vulnerable client program or browser, the malware exploits the vulnerability, downloads and installs the malware, and successfully attacks the target. Malicious programs often elevate privileges or add administrator users. For example, they might launch the program at startup or even quietly disable or modify the host firewall settings in the background, minimizing detection.

[0048] Because hosts within an organization often share the same operating system and similar application software environments, they often share common vulnerabilities. Once a host is compromised, malicious programs can spread horizontally to other hosts within the subnet or vertically to internal corporate servers. Remote management tools with keylogging and screen recording capabilities can easily obtain user domain passwords, email passwords, and various server passwords.

[0049] The attack also employs self-protection measures such as anonymous networks, encrypted communications, and the erasure of traces. Various technical measures are also employed to prevent detection by network security devices when transmitting confidential information. This involves breaking down confidential information into smaller pieces, encrypting, or obfuscating it to prevent data leakage prevention (DLP) devices from detecting leaks through keyword scanning. Furthermore, the transmission rate is limited to minimize the detection threshold of various security devices.

[0050] In order to solve the problem that BMC cannot resist APT attacks, the present application provides a BMC intrusion protection method, namely, setting up a business module and a security detection module with communication isolation in the BMC, isolating the storage medium accessed by the business module and the security detection module, the business module is used to provide management functions for components in the computer equipment, and the security detection module is used to perform security detection on the BMC. The security detection module obtains the data stored in the storage medium associated with the business module, analyzes the data to perceive the security situation of the business module, and obtains the security detection result. If the security detection result indicates that the BMC has been attacked by APT, the BMC is restarted in degraded startup mode.

[0051] Compared with the BMC's defense strategy that only relies on boundary defense, that is, restricting the attacker's behavior through firewalls, interface encapsulation, restricting operating system login, and Identity and Access Management (IAM) technology, it lacks the ability to perceive the behavior during the attack process. As the BMC exposes more and more interfaces to the outside world, it is easy to form vulnerabilities such as command injection, database injection, and buffer overflow, causing APT attacks to break through the defense boundary and the BMC to be breached by APT attacks, reducing the value of BMC as a trusted center. The present application provides a defense-in-depth solution, that is, on the basis of defense, the BMC adds intrusion detection capabilities; by isolating the business module and the security detection module, it prevents the security detection module from being affected when the business module is attacked by APT; moreover, the security detection module analyzes the data of the BMC's business module to perceive the security situation of the business module. When it predicts that the BMC may be attacked by APT, it can also restart the BMC while ensuring the recoverability of the basic business or BMC, thus forming a dynamic defense chain of defense->detection->degradation->recovery, effectively improving the BMC's ability to resist APT attacks and ensuring the security and trustworthiness of the BMC.

[0052] The method provided in this application can be applied to computer devices including a BMC, such as an inference server, a training server, an inference card, a training card, a cabinet server, a blade server, or a rack server.

[0053] The BMC intrusion protection method provided by this application is described in detail below with reference to the accompanying drawings. Figure 1 is a schematic diagram of the structure of a baseboard management controller provided by this application. As shown in Figure 1, the baseboard management controller 100 includes a processor 110, a bus 120, a memory 130, a communication interface 140, and a memory 150 (also referred to as a main memory unit). The processor 110, the memory 130, the memory 150, and the communication interface 140 are connected via the bus 120.

[0054] The processor 110 is the control center of the baseboard management controller 100. The processor 110 can be a central processing unit (CPU). The processor 110 can also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), system on chip (SoC) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc. For ease of description, the following embodiments are described by taking the processor 110 as a CPU as an example.

[0055] The baseboard management controller 100 in FIG1 may include one or more processors. The processor may be a multi-core processor, i.e., the processor includes one processor core or multiple processor cores. For example, the processor 110 shown in FIG1 includes N processor cores. A processor herein may refer to one or more devices, circuits, and / or computing units for processing data (e.g., computer program instructions).

[0056] In some embodiments, the processor 110 runs a business module 111 and a security detection module 112. The business module 111 is used to provide management functions for components in a computer device that includes the baseboard management controller 100. The security detection module 112 is used to perform security detection on the baseboard management controller 100, that is, to detect the operating environment security and data integrity security of the business module 111. For example, the security detection module 112 obtains data stored in a storage medium associated with the business module 111, analyzes the data to perceive the security status of the business module 111, and obtains a security detection result. When the security detection result indicates that the baseboard management controller 100 has been attacked by an APT, the baseboard management controller 100 is restarted in a degraded startup mode. This improves the BMC's ability to resist APT attacks and ensures that the BMC is secure and reliable.

[0057] The service module 111 and the security detection module 112 may be processes or threads running on the same processor 110. The service module 111 and the security detection module 112 are isolated from each other in terms of communication. Alternatively, the service module 111 and the security detection module 112 may be processes or threads running on different processors.

[0058] For example, the business module 111 is prohibited from obtaining user information and user group information from the security detection module 112. Another example is that the business module 111 is prohibited from obtaining process information from the security detection module 112. Another example is that the business module 111 is prohibited from sharing a bus with the security detection module 112, with the exception of the business whitelist message bus. Another example is that the business module 111 is prohibited from making system calls other than those on the whitelist. The whitelist scope may include the security detection interface, the upgrade function interface, the configuration function interface, and the security management interface. The security detection interface allows the security detection module 112 to detect data from the business module 111 required for APT attacks. The upgrade function interface allows the security detection module 112 to upgrade the data in the business module 111. The configuration function interface allows the security detection module 112 to configure the data in the business module 111. The security management interface allows the security detection module 112 to manage the data in the business module 111. The storage media accessed by the business module 111 and the security detection module 112 are isolated. For example, the memory accessed by the business module 111 is isolated from the memory accessed by the security detection module 112. For another example, the flash memory accessed by the business module 111 is isolated from the flash memory accessed by the security detection module 112. For another example, the business module 111 is prohibited from rewriting file information in a storage medium accessible to the security detection module 112. For another example, the security detection module 112 is prohibited from reading file information in a storage medium accessible to the business module 111. However, the security detection module 112 can read data in a storage medium accessible to the business module 111 that is required for intrusion detection.

[0059] It should be noted that if the business module 111 and the security detection module 112 access different areas of the same storage medium, the different areas of the same storage medium are isolated from each other. For example, by restricting access to different areas of the same storage medium through permission control, the different areas of the same storage medium can be isolated. By using access control lists, role permissions, etc., authorized users or roles are allowed to access specific areas, preventing unauthorized users from obtaining sensitive information.

[0060] For example, the business module 111 can access a first area in the memory 130, which is used to store persistent data of the business module 111. The security detection module 112 can access a second area in the memory 130, which is used to store persistent data of the security detection module 112. The first area and the second area in the memory 130 are isolated from each other.

[0061] Business module 111 can access a first area in memory 150, which is used to store data during the operation of business module 111. Security detection module 112 can access a second area in memory 150, which is used to store data during the operation of security detection module 112. The first and second areas in memory 150 are isolated from each other.

[0062] Optionally, inter-process isolation implements communication isolation between the business module 111 and the security detection module 112 and isolation of the accessed storage medium. For example, Linux namespace technology is used to implement communication isolation between the business module 111 and the security detection module 112 and isolation of the accessed storage medium.

[0063] Therefore, within the same BMC operating system, system security isolation is achieved through user (e.g., username isolation, privileged user and ordinary user isolation), file (e.g., storage isolation), inter-process communication isolation, and inter-component communication isolation. This isolates the BMC's business module from the BMC's security detection module, and the storage media used by the two modules. Access to the security detection module is limited to the business module through whitelisted business interfaces / systems, minimizing exposure and preventing the security detection module from being affected when the business module is attacked by an APT. This improves the security of the security detection module, and the security detection module analyzes the BMC's business module data to perceive the security status of the business module, enhancing the BMC's ability to resist APT attacks and ensuring BMC security and trustworthiness.

[0064] Memory 150 may be a volatile memory pool. Volatile memory may be random access memory (RAM), which serves as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DR RAM). Memory 150 is used to store data required by the business module 111 during operation. For example, data such as BMC firmware, business data, and network configuration.

[0065] Memory 130 can be a non-volatile memory pool. Non-volatile memory can be read-only memory (ROM), a disk, or flash memory. Memory 130 is used to store persistent data of service module 111, such as user information, alarm data, fault diagnosis data, BMC event subscription scope, and alarm reporting level.

[0066] Communication interface 140 is used to enable communication between baseboard management controller 100 and external devices or components. For example, baseboard management controller 100 communicates with the processor, memory, storage, and peripherals in a computer device. In this application, communication interface 140 can transmit data from service module 111 to the advanced threat analysis system, which analyzes the data to obtain security detection results.

[0067] The bus 120 may include a path for transmitting information between the above-mentioned components (such as the processor 110, the memory 150, and the storage 130). In addition to the data bus, the bus 120 may also include a power bus, a control bus, and a status signal bus. However, for the sake of clarity, various buses are labeled as bus 120 in the figure. The bus 120 may be a Peripheral Component Interconnect Express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a computer express link (CXL), a cache coherent interconnect for accelerators (CCIX), DDR, or an embedded multi-media card (EMMC) control protocol. The bus 120 can be divided into an address bus, a data bus, a control bus, etc.

[0068] It is worth noting that Figure 1 only takes the baseboard management controller 100 including 1 processor 110 and 1 memory 130 as an example. Here, the processor 110 and the memory 130 are respectively used to indicate a type of device or equipment. In a specific embodiment, the number of each type of device or equipment can be determined according to business requirements.

[0069] In some embodiments, the baseboard management controller 100 may include multiple processors, and the business module 111 and the security detection module 112 may run on different processors. The baseboard management controller 100 may include multiple memories and multiple memories, allowing the business module 111 and the security detection module 112 to access different memories and memories, thereby achieving communication isolation between the business module 111 and the security detection module 112, as well as isolation of the storage media accessed by the business module 111 and the security detection module 112.

[0070] For example, as shown in FIG2 , baseboard management controller 100 may include processor 110 and processor 160. Processor 110 runs business module 111. Processor 160 runs security detection module 112. Baseboard management controller 100 includes memory 130 and memory 170. Business module 111 can access memory 130, which is used to store persistent data of business module 111. Security detection module 112 can access memory 170, which is used to store persistent data of security detection module 112. Memory 130 and memory 170 are isolated from each other.

[0071] Baseboard management controller 100 includes memory 150 and memory 180. Business module 111 can access memory 150, which stores data during the operation of business module 111. Security detection module 112 can access memory 180, which stores data during the operation of security detection module 112. Memory 150 and memory 180 are isolated from each other.

[0072] In other embodiments, the storage medium associated with the security detection module 112 may also store the root of trust of the baseboard management controller 100. For example, the root of trust of the baseboard management controller 100 and the persistent data of the security detection module 112 may be stored on the same storage medium, and the memory 130 or the memory 170 in the baseboard management controller 100 may store the root of trust of the baseboard management controller 100 and the persistent data of the security detection module 112. In another example, the root of trust of the baseboard management controller 100 and the persistent data of the security detection module 112 may be stored on different storage media. The BMC's root of trust is used to perform integrity verification on the data of the business module 111.

[0073] As a possible implementation, the business module 111 and the security module 112 can also be implemented by hardware. Accordingly, the business module 111 and the security module 112 are implemented by one logic circuit, or the functions of the business module 111 and the security module 112 can be implemented by two logic circuits respectively.

[0074] Next, the BMC intrusion protection method provided by the present application is described with reference to the accompanying drawings, as shown in Figure 3. Here, the service module 111 and the security detection module 112 of the baseboard management controller 100 shown in Figure 1 are used as an example to detect an APT attack on the baseboard management controller 100.

[0075] Step 310: The security detection module obtains data stored in a storage medium associated with the business module.

[0076] The security detection module obtains data stored in the memory accessed by the business module. This data includes data required by the BMC to manage components. For example, the security detection module obtains data such as software programs running on the BMC, business data, and network configuration from the memory accessed by the business module.

[0077] Obtain data stored in the flash memory accessed by the business module. This data includes BMC persistent data. For example, this persistent data includes data required by BMC software programs during operation, such as alarm data and fault diagnosis data. Persistent data can also include customer-configured data for BMC business module management, such as BMC event subscription scopes and alarm reporting levels.

[0078] In some embodiments, the security detection module may periodically obtain data stored in a storage medium associated with the business module, analyze the data, and determine whether the BMC is under an APT attack, so as to promptly block the APT attack on the BMC.

[0079] Step 320: The security detection module obtains a security detection result based on the data stored in the storage medium associated with the business module.

[0080] The security detection module analyzes the security status of the data perception business module and obtains security detection results. The security detection results indicate the possibility of the BMC being attacked by an APT. For example, the security detection result may indicate that the BMC has been attacked by an APT. The security detection result may also indicate that the BMC may have been attacked by an APT. The security detection result may also indicate that the BMC has not been attacked by an APT.

[0081] In some embodiments, the security detection module detects the operational security of the business module based on the data stored in the memory accessed by the business module and obtains a security detection result. Operational security can also be called memory security.

[0082] For example, the security detection module analyzes the programs running on the BMC to determine whether they contain malicious programs. If a malicious program is injected into the BMC program, the module controls the program jump so that the pointer jumps to the attacking program during the BMC program execution, thus initiating an attack on the BMC. If the BMC program contains malicious programs, the BMC is confirmed to be under an APT attack.

[0083] For example, the security detection module analyzes BMC basic data to determine whether it has been tampered with. An APT attacker tampered with BMC basic data, such as user information and configuration items, allowing the attacker to create arbitrary users and control the BMC as a legitimate user, launching an attack against the BMC. If BMC basic data is tampered with, the module determines whether the BMC has been attacked by an APT.

[0084] For example, the security detection module analyzes the network status to determine whether there is abnormal traffic accessing the BMC. Abnormal traffic may be generated during a BMC attack. If there is abnormal traffic accessing the BMC, it is determined whether the BMC is under an APT attack.

[0085] In other embodiments, the security detection module detects data security of the business module based on data stored in a flash memory associated with the business module to obtain a security detection result.

[0086] For example, the security detection module analyzes BMC basic data to determine whether it has been tampered with. An APT attacker tampered with the BMC basic data in the flash memory, allowing the attacker to create arbitrary users. The APT attacker then controlled the BMC as a legitimate user, launching an attack against the BMC. The tampering of the BMC basic data indicates that the BMC has been attacked by an APT.

[0087] For example, the security detection module can analyze security logs to determine whether there are any abnormal data in the security logs. During a BMC attack, the security logs may contain abnormal data. If there is abnormal data in the security logs, it is determined that the BMC has been attacked by an APT.

[0088] The above-mentioned security detection module illustrates the security detection of BMC. The detection content of the security detection module described in this application includes but is not limited to data related to the BMC execution management operation process, such as programs, basic data, network status, etc., and may also include integrity verification.

[0089] For example, the security detection module may perform integrity verification on data stored in a memory associated with the business module.

[0090] For example, the integrity of the code segment in memory is checked. During initial loading, a hash calculation is performed on the code segment to obtain a root of trust, which is then stored in a storage medium associated with the security detection module. When the BMC runs the code segment, it obtains the hash value of the code segment and compares it with the root of trust for an integrity check. If the hash value matches the root of trust, the program running on the BMC does not contain malicious programs, confirming that the BMC has not been attacked by an APT. If the hash value differs from the root of trust, the program running on the BMC does contain malicious programs, confirming that the BMC has been attacked by an APT.

[0091] For another example, the security detection module can perform an integrity check on data stored in the flash memory associated with the business module. The security detection module can also perform an integrity check on the BMC's initial data. Initial data includes program files, configuration files, and data files stored in the flash memory associated with the business module.

[0092] The security detection module performs a hash calculation on the data in the flash memory to obtain a hash value, and then compares the hash value with the BMC's root of trust. If the hash value matches the BMC's root of trust, it indicates that the data in the flash memory has not been tampered with and the BMC has not been attacked by APTs. If the hash value differs from the BMC's root of trust, it indicates that the data in the flash memory may have been tampered with and the BMC has been attacked by APTs.

[0093] For example, the configuration file is integrity checked, a hash calculation is performed on the configuration file to generate a root of trust, and the root of trust is stored on the storage medium associated with the security detection module. If the configuration file is modified, a new root of trust is immediately generated, and the root of trust stored on the storage medium associated with the security detection module is updated. While the BMC is running the code segment, the configuration file can be checked, for example, by comparing the configuration file's hash value with the root of trust to determine whether the BMC is vulnerable to an APT attack.

[0094] Furthermore, because BMC programs may have vulnerabilities, APT attackers have long exploited these vulnerabilities, gradually infiltrating and attacking the BMC. Recovery is possible in degraded boot mode, and program security can be maintained by upgrading the BMC program (e.g., upgrading the BMC firmware). For example, BMC program upgrades and patches can be downloaded from the official website. Traditional secure boot ensures program integrity.

[0095] Optionally, if the computing power of the processor in the BMC is insufficient to support the analysis of data obtained from the storage medium associated with the business module, the obtained data can be analyzed with the help of a remote system, thereby realizing the perception that the BMC may be subject to APT attacks and improving the BMC's ability to resist APT attacks.

[0096] For example, this embodiment may further include step 321, analyzing data based on the advanced threat analysis system to obtain security detection results. The BMC may send data to the advanced threat analysis system, obtain security detection results from the advanced threat analysis system data, and the BMC receives security detection results fed back by the advanced threat analysis system.

[0097] Step 330: The security detection module determines that the BMC is under an APT attack based on the security detection result, and restarts the BMC in a degraded startup mode.

[0098] When the BMC is detected to be under an APT attack, the security detection module controls the BMC to be restarted in a degraded startup mode, or the BMC receives a restart instruction to restart the BMC in a degraded startup mode.

[0099] Degraded startup mode can mean resetting the memory associated with the business module, restarting the security detection module, mounting the storage medium associated with the security detection module, not starting the business module, and not mounting the storage medium associated with the business module. This ensures a high-security operating environment for the BMC, blocks APT attack paths, ensures core BMC services, and provides remote recovery and configuration capabilities.

[0100] After the BMC operating environment is safe, the BMC receives a restart instruction to restart the BMC, that is, restart the security detection module, mount the storage medium associated with the security detection module, restart the business module, and mount the storage medium associated with the business module.

[0101] In some embodiments, if a security detection result indicates that the data security of a business module has been subjected to an APT attack, i.e., data stored in a flash memory associated with the business module has been subjected to an APT attack, the security detection module configures backed-up initial data to the flash memory associated with the business module, and the business module restarts the business module and the storage medium associated with the business module based on the initial data of the business module. The initial data may be stored in the flash memory associated with the security detection module.

[0102] The BMC intrusion protection method provided by this application is to add intrusion detection capabilities to the BMC on the basis of boundary defense. Under the premise of protecting firmware security through secure startup, it can block all existing APT attacks by conducting a comprehensive analysis of memory security and data security, ensuring memory security through reset, and only mounting the storage medium associated with the security detection module to ensure data security. After blocking the APT attack, due to the normal operation of the security detection module, the operating capability of the core business of the operating system can be maintained, and basic functions that can be remotely managed can be provided, such as upgrades and configuration management. After ensuring the memory security and data security of the BMC, the BMC is restarted, that is, the business module and the security detection module are restarted. This forms a dynamic defense chain of defense->detection->degradation->recovery, forming a BMC in-depth defense solution, which effectively improves the BMC's ability to resist APT attacks and ensures the security and reliability of the BMC.

[0103] Optionally, the BMC can also feed back security detection results to the display terminal to display the security detection results so that the system administrator can promptly know the security status of the BMC and restart the BMC in a degraded startup mode to block APT attacks.

[0104] It is understood that in order to implement the functions in the above embodiments, the BMC includes hardware structures and / or software modules that perform the corresponding functions. Those skilled in the art should readily appreciate that, in conjunction with the various exemplary units and method steps described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a hardware-driven manner by computer software depends on the specific application scenario and design constraints of the technical solution.

[0105] The BMC intrusion protection method provided by the present application is described in detail above with reference to FIG. 1 to FIG. 3 . The security detection device provided by the present application will be described below with reference to FIG. 4 .

[0106] Figure 4 is a schematic diagram of the structure of possible authentication devices provided by this application. These authentication devices can be used to implement the functions of the remote device or computer device in the above method embodiments, thereby also achieving the beneficial effects of the above method embodiments. In this embodiment, the authentication device can be the device shown in Figure 1, or it can be a module (such as a chip) applied to the server.

[0107] As shown in Figure 4, the safety detection device 400 includes a communication module 410, a detection module 420, a control module 430, and a storage module 440. The safety detection device 400 is used to implement the functions of the safety detection module in the method embodiment shown in Figure 3 above.

[0108] The communication module 410 is used to obtain data stored in a storage medium associated with the service module. For example, the communication module 410 is used to execute step 310 in FIG. 3 .

[0109] The detection module 420 is used to analyze the data stored in the storage medium associated with the business module to obtain a security detection result. For example, the detection module 420 is used to execute step 320 in FIG. 3 .

[0110] The control module 430 is configured to determine, based on the security detection result, that the BMC is under an APT attack and restart the BMC in a degraded boot mode. For example, the control module 430 is configured to execute step 330 in FIG3 .

[0111] Optionally, the detection module 420 is configured to detect the operational safety of the business module based on data stored in a first storage medium associated with the business module to obtain a safety detection result, and the first storage medium is used to store data required for the operation of the business module.

[0112] Optionally, the detection module 420 is configured to detect data security of the business module based on data stored in a second storage medium associated with the business module to obtain a security detection result, and the second storage medium is used to store persistent data of the business module.

[0113] The storage module 440 is used to store data required for security detection, security detection programs, and initial data of the backup service module.

[0114] It should be understood that the safety detection device 400 of the embodiment of the present application can be implemented by an application-specific integrated circuit (ASIC), or a programmable logic device (PLD), and the above-mentioned PLD can be a complex programmable logical device (CPLD), a field programmable gate array (FPGA), a generic array logic (GAL), a data processing method (DPU), an accelerator card, an offload card or any combination thereof. When the BMC intrusion protection method shown in Figure 3 can also be implemented by software, and its various modules can also be software modules, the safety detection device 400 and its various modules can also be software modules.

[0115] According to the embodiment of the present application, the safety detection device 400 can correspond to executing the method described in the embodiment of the present application, and the above-mentioned and other operations and / or functions of each unit in the safety detection device 400 are respectively for implementing the corresponding processes of each method in Figure 3. For the sake of brevity, they will not be repeated here.

[0116] FIG5 is a schematic diagram of the structure of a computer device provided in this application. As shown in FIG5 , computer device 500 includes a processor 510, memory 520, storage 530, PCIe card 540, BMC 550, and communication interface 560. Processor 510, memory 520, storage 530, PCIe card 540, BMC 550, and communication interface 560 are connected via bus 570.

[0117] Processor 510 is the control center of computer device 500. Processor 510 can be a high-power computing unit with computing capabilities, such as a central processing unit (CPU), a graphics processing unit (GPU), a data processing unit (DPU), a neural processing unit (NPU), or an embedded neural-network processing unit (NPU). Processor 510 includes one or more processor cores.

[0118] In some embodiments, processor 510 includes registers and cache memory.

[0119] The cache memory is used to store instructions or data that may be accessed multiple times by the processor core in the processor 510 , thereby increasing the speed at which the processor processes data and preventing the processor from frequently accessing the memory 520 .

[0120] Registers are used to store instructions or data that may be accessed multiple times by the processor core in processor 510. Since register access speed is higher than cache memory access speed, instructions or data that may be accessed multiple times by the processor core can be stored in registers first, which can further increase the speed at which the processor processes data.

[0121] Alternatively, the processor 510 may be another general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0122] Memory 520 (also referred to as main memory) can be a volatile memory pool or a non-volatile memory pool, or can include both volatile and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0123] The memory 530 may be a persistent storage medium, such as a disk, such as a mechanical hard drive or a solid-state drive. The PCIe card 540 may be a peripheral device. For example, the PCIe card 540 may include a network card. The communication interface 560 is used to enable communication between the computer device 500 and external devices or components.

[0124] The BMC 550 is used to manage other components in the computer device 500 , such as the processor 510 , the memory 520 , the storage 530 , the PCIe card 540 , and the communication interface 560 .

[0125] In this application, the BMC 550 includes a service module 551 and a security detection module 552. For the functions of the service module 551 and the security detection module 552, reference can be made to the description of the service module and the security detection module in the above embodiment.

[0126] The bus 570 may include a path for transmitting information between the above-mentioned components (such as the processor 510, the memory 520, the storage 530, the PCIe card 540, and the communication interface 560). In addition to the data bus, the bus 570 may also include a power bus, a control bus, and a status signal bus. However, for the sake of clarity, various buses are labeled as bus 570 in the figure. The bus 570 may be a Peripheral Component Interconnect Express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. The bus 570 can be divided into an address bus, a data bus, a control bus, etc.

[0127] The device structure shown in Figure 5 does not limit the computer device, and may include more or fewer components than shown, or combine certain components, or arrange the components differently. For example, the computer device may also include an artificial intelligence card, a read card, a GPU, a DPU, and an NPU.

[0128] The components described in this application may be processors, memory, internal storage, registers, cache memory, network cards, and circuit boards included in computer devices. The BMC included in the computer device can perform APT attack detection on the BMC according to the BMC intrusion protection method provided in this application to resist APT attacks and ensure the security and reliability of the BMC.

[0129] It should be understood that the BMC550 in the computer device 500 according to this embodiment may correspond to the security detection device 400 in this embodiment, and may correspond to the corresponding subject executing any method in Figure 3, and the above-mentioned and other operations and / or functions of each module in the security detection device 400 are respectively for implementing the corresponding processes of each method in Figure 3. For the sake of brevity, they will not be repeated here.

[0130] This application provides a cluster that can include multiple computer devices, each of which includes multiple components and a baseboard management (BMC). The BMC can perform APT attack detection on the BMC based on the BMC intrusion protection method provided in this application, thereby resisting APT attacks and ensuring the security and reliability of the BMC. This allows the BMC to authenticate the components in the computer devices, preventing them from being counterfeited, tampered with, or replaced, thereby ensuring the security and reliability of the components.

[0131] The present application also provides a chip that can implement the functions of the business module and the security detection module in Figures 1 to 5 above. The chip can be an independent chip or a chip integrated in the BMC.

[0132] The method steps in this embodiment can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a computing device. Of course, the processor and storage medium can also exist as discrete components in a computing device.

[0133] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the process or function described in the embodiments of the present application is performed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device or other programmable device. The computer program or instruction can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instruction can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired or wireless means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid state drive (SSD). The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A baseboard management controller BMC intrusion protection method, characterized in that: The method is applied to a BMC in a computer device, the BMC comprising a business module and a security detection module, the business module is used to provide management functions for components in the computer device, the security detection module is used to perform security detection on the BMC, the business module and the security detection module are isolated in communication, the storage medium accessed by the business module and the security detection module are isolated, the method is performed by the security detection module, and the method comprises: Obtaining a security detection result according to data stored in a storage medium associated with the business module, wherein the data is used to perceive the security situation of the business module, and the security detection result is used to indicate the possibility that the BMC is subject to an advanced long-term threat APT attack; It is determined according to the security detection result that the BMC is attacked by the APT, and the BMC is restarted in a degraded startup mode.

2. The method according to claim 1, characterized in that Obtaining a security detection result according to data stored in a storage medium associated with the business module includes: The operation safety of the business module is detected according to the data stored in the first storage medium associated with the business module to obtain the safety detection result, and the first storage medium is used to store the data required for the operation of the business module.

3. The method according to claim 1, characterized in that Obtaining a security detection result according to data stored in a storage medium associated with the business module includes: According to the data stored in the second storage medium associated with the business module, the data security of the business module is detected to obtain the security detection result, and the second storage medium is used to store the persistent data of the business module.

4. The method according to claim 2 or 3, characterized in that: Obtaining the safety detection result includes: The data is verified according to the trusted root of the BMC to obtain the security detection result.

5. The method according to claim 2 or 3, characterized in that: Obtaining the safety detection result includes: The security detection result is obtained by analyzing the data based on an advanced threat analysis system.

6. The method according to claim 1, characterized in that Restarting the BMC in a degraded boot mode includes: Restart the security detection module and mount the storage medium associated with the security detection module.

7. The method according to claim 6, characterized in that After restarting the security detection module and mounting the storage medium associated with the security detection module, the method further includes: According to the restart instruction, the security detection module is restarted, and the storage medium associated with the security detection module is mounted; and the business module is restarted, and the storage medium associated with the business module is mounted.

8. A safety detection device, characterized in that: include: A detection module, used to obtain a security detection result based on data stored in a storage medium associated with the business module, wherein the data is used to perceive the security situation of the business module, and the security detection result is used to indicate the possibility that the BMC is attacked by an advanced long-term threat APT; The control module is used to determine that the BMC is attacked by the APT according to the security detection result, and restart the BMC in a degraded startup mode.

9. A baseboard management controller BMC, characterized in that: The BMC includes a business module and a security detection module, the business module is used to provide management functions for components in the computer device, the security detection module is used to perform security detection on the BMC, the business module and the security detection module are isolated in communication, the storage medium accessed by the business module and the security detection module are isolated, and the security detection module is used to execute the operating steps of the method described in any one of claims 1 to 7.

10. A computer device, characterized in that: The computer device comprises a processor, a memory and a baseboard management controller BMC as claimed in claim 9, wherein the BMC is used to execute the operation steps of the method as claimed in any one of claims 1 to 7.

Citation Information

Patent Citations

  • BMC intrusion protection method and device, BMC and computer equipment

    CN120017290A

  • Method, device and server for managing firmware of basic input and output system

    CN109446815A

  • Management controller-based verification of platform certificates

    US20230342446A1

  • Chip, method for generating private key, and method for trusted verification

    WO2020073206A1

  • Trusted computing method, chip, and server

    WO2023160166A1

Cited By

  • Vehicle safety detection method and related device

    CN120567504A

  • Method and system for constructing TPCM trusted root based on multi-core BMC

    CN120763943A

  • Active defense strategy updating method and device based on threat intelligence collection

    CN122316793A