A continuous immune security management and control system and method based on trusted computing
By adopting a continuous immune security control system based on trusted computing in network security defense, traditional network security defense is solved, and the problem that traditional network security defense is difficult to resist unknown vulnerabilities and high false alarm rates is achieved, and continuous immunity to unknown threats and more effective security protection is achieved.
Patent Information
- Application Number
- CN202111212810.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-18
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-10-18
AI Technical Summary
Traditional network security defense technology is difficult to effectively resist unknown software and hardware vulnerability attacks in the system, prevent potential backdoor attacks, and deal with complex and intelligent penetrating network intrusions, and the whitelist alarm mechanism has the problem of high false alarm rates.
A continuous immune security control system based on trusted computing is adopted, including trusted protection module, blockchain tamper-proof module and active confrontation module. The trusted protection module automatically generates a whitelist by combining operation and maintenance strategies. The blockchain tamper-proof module is used to prevent whitelist tampering, actively combats the module to monitor and analyze processes within the whitelist, and updates the whitelist according to the security situation.
It significantly reduces the possibility that the system or application is attacked by unknown viruses or malware, reduces the false alarm rate, achieves continuous immunity to unknown threats, and provides more effective security protection.
Smart Images

Figure CN113886816B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a continuous immune security management and control system and method based on trusted computing. Background Art
[0002] The traditional defense idea is to establish a multi-level defense system including firewalls, security gateways, intrusion detection, virus detection, access control and data encryption on the basis of the existing network architecture, and identify attacks based on the data, code, behavior and other characteristics of known viruses. However, with the application of new technologies such as cloud computing, big data, 5G, and the Internet of Things, the security boundary has gradually blurred, and new network security risks and an expanding attack surface have come with it. The continuous disclosure of network security incidents in recent years and the serious consequences brought about by them have gradually exposed the defects of traditional network security defense technology, especially the difficulty in effectively resisting unknown software and hardware vulnerability attacks in the system, the difficulty in preventing potential backdoor attacks, and the difficulty in effectively responding to various types of increasingly complex and intelligent penetration network intrusions. Traditional blocking and killing are outdated. The traditional "old three" of virus killing, firewalls, and intrusion detection are difficult to deal with human attacks and are easily exploited by attackers. The traditional idea of finding vulnerabilities and patching is not conducive to overall security. Therefore, it is necessary to build a trusted computing standard system and implement an immune mechanism to ensure that the logical combination for completing computing tasks is not tampered with or destroyed, and to achieve correct computing.
[0003] For example, a Chinese document with the publication number of authorization announcement CN104573516B discloses a trusted environment management method and platform for industrial control systems based on security chips, the method comprising: 1) the industrial control terminal registers with the management server based on the security chip; 2) the industrial control terminal measures the integrity of each running process; 3) the management party reviews the measurement information on the management server and prepares a white list; 4) the industrial control terminal downloads the white list customized by the managed party from the management server, imports it into the operating system kernel, and then manages the running processes to prevent malicious code from untrusted, unknown and uncontrollable program processes from causing system damage to the industrial control terminal, stealing confidential information and industrial production damage, thereby improving the security defense capabilities of the industrial control system.
[0004] For another example, the Chinese patent document with the publication number of authorization announcement number CN104035999B discloses a safe web browsing system based on personalized recommendation control by parents, including a web browsing module, a parent control module and a content filtering system. The web browsing module is used to display the information related to the subject specified by the parents. The parent control module includes a parent-specified subject library, a parent-prohibited subject library, a blacklist address list, a whitelist address list and a graylist address list. The web filtering system module includes a query module, a text classification module and a result processing module. Parents can use the subject options given by the system to make intuitive selections, and search for relevant information in the display module according to the subject classification specified by the parents, and display them prominently by category classification; the web pages browsed by children are filtered by the web content filtering module so that children can access safe web pages.
[0005] However, the above existing technologies all have the following technical deficiencies: once the whitelist policy is confirmed, the system will issue an alarm if the subsequent process does not match the whitelist - but in fact, many inconsistencies are caused by benign changes such as system upgrades, application updates, and network changes, and there is no malicious code attacking the host, which results in a high false alarm rate. If the administrator checks one by one, it will waste time. If it is ignored, the whitelist alarm mechanism will become a formality. Once a real security threat invades the user, the system cannot provide effective security protection for the user. Therefore, it is necessary to improve the deficiencies of the existing technology.
[0006] In addition, on the one hand, there are differences in understanding among those skilled in the art; on the other hand, the inventor studied a large number of documents and patents when making the present invention, but due to space limitations, not all details and contents are listed in detail. However, this does not mean that the present invention does not have the characteristics of these prior arts. On the contrary, the present invention already has all the characteristics of the prior art, and the applicant reserves the right to add relevant prior art to the background technology. Summary of the invention
[0007] In view of the shortcomings of the prior art, the present invention provides a continuous immune security management and control system based on trusted computing. The continuous immune security management and control system at least includes a trusted protection module, a blockchain anti-tampering module and an active confrontation module.
[0008] The trusted protection module is configured to automatically generate a whitelist that complies with the operation specifications in combination with the user's operation and maintenance strategy to establish a legal access strategy and operation behavior strategy for the user. The whitelist mainly relies on a trusted computing mechanism in its implementation. One of the core goals of trust is to confirm that the system or application is running in a predictable state expected by the design goal to ensure the integrity of the core files. In general, trusted verification can significantly reduce the possibility of the system or application being damaged by unknown viruses or malware attacks.
[0009] The blockchain anti-tampering module is configured to at least obtain the whitelist and add the whitelist to the blockchain to prevent the whitelist from being illegally tampered with.
[0010] The active confrontation module can at least be used to monitor and analyze the processes or programs in the whitelist. In the case where the active confrontation module can obtain the security situation of the user, the trusted protection module can continuously update the whitelist based on the security situation monitored by the active confrontation module. The active confrontation module can quickly adjust the user's logical topology based on the monitored security situation and process the monitored abnormal activities to achieve self-organized confrontation against all unknown threats, thereby generating continuous immunity to unknown threats.
[0011] According to a preferred embodiment, the trusted protection module of the security protection system includes at least a whitelist generation unit and a user entity behavior analysis unit.
[0012] The whitelist generation unit is configured to generate a whitelist that matches the security requirements of the user based on the application scenarios of different users and / or the security situation monitored by the active confrontation module. Preferably, the active confrontation module can also monitor the security situation of the user server in a time sequence. Preferably, the security situation at least includes the user system version information. Preferably, the security situation can also include updates of applications used by users, changes in the network used by users, etc. The user server can be a personal computer, a workstation, etc. The system version information can be basic information of the system version, the time and interval of system version upgrade or downgrade, etc. The application can be various application software used by the user. Particularly preferably, the active confrontation module can identify the system version information of the user. The active confrontation module can also identify updates of applications used by users and changes in the network used by users. For example, if the user's server is gradually upgraded over time, the active confrontation module determines that the security situation of the user is benign. When the security situation of the user is benign, the whitelist generation unit is configured to be able to regard the abnormal activities related to the system upgrade discovered by the user entity behavior analysis unit as benign anomalies, and add the benign anomalies into the original whitelist. When the user's server is gradually degraded or remains unchanged over time, the active confrontation module determines that the user's security situation is malicious. When the user's security situation is malicious, the whitelist generation unit is configured to regard the abnormal activities related to the system upgrade found by the user entity behavior analysis unit as real abnormalities, and send the real abnormalities to the active confrontation module for early warning or alarm.
[0013] The user entity behavior analysis unit is configured to at least monitor and analyze the processes or programs on the whitelist run by the user to detect whether there are any abnormalities in the processes or programs on the whitelist run by the user, and send the monitored security situation of the user to the active confrontation module.
[0014] According to a preferred embodiment, since the whitelist strategy is confirmed, as long as the subsequent process does not conform to the whitelist, the system will warn. But in fact, the warnings caused by many behaviors that do not conform to the original whitelist monitored by the active confrontation module are caused by benign changes such as system upgrades, application updates, and network changes, and there is no malicious code attacking the host, which has caused a very high false alarm rate. If the administrator checks one by one, it will be a waste of time. If it is ignored, the whitelist warning mechanism will become a formality. Once the real security threat invades the user, the system cannot provide effective security protection for the user. To this end, the solution provided by the present invention makes the whitelist mechanism further intelligent, so that the whitelist can be continuously adjusted with the changes of user status (such as system upgrades, application updates) and / or security situation (such as network changes, etc.), so as to effectively provide users with continuous immune security protection. Therefore, the trusted protection module also includes a whitelist database unit. The user entity behavior analysis unit can send the monitored abnormal situation to the active confrontation module. The active confrontation module can also monitor the security situation of the user.
[0015] In response to the active confrontation module monitoring the security situation of the user, the whitelist database unit is configured to at least collect whitelists of multiple different users to form a new whitelist database, so as to analyze and compare the whitelists monitored as abnormal by the user entity behavior analysis unit through the whitelist database to reduce the false alarm rate of the user entity behavior analysis unit. The trusted whitelist in the whitelist database is obtained by the whitelist database unit seeking the maximum intersection of the whitelists of multiple different users.
[0016] According to a preferred embodiment, the trusted protection module can continuously update the whitelist, and the steps (methods) for continuous updating are:
[0017] If the user entity behavior analysis unit analyzes and compares the whitelist monitored by the user entity behavior analysis unit as an abnormal state through the whitelist database and finds that the whitelist of the abnormal state is within the scope of the whitelist database, the user entity behavior analysis unit determines the whitelist of the abnormal state as a false alarm. At the same time, the whitelist generation unit obtains the above instruction to immediately update the whitelist of the corresponding server and add the benign anomaly found by the user entity behavior analysis unit to the original whitelist; if the user entity behavior analysis unit analyzes and compares the whitelist monitored by the user entity behavior analysis unit as an abnormal state through the whitelist database and finds that the whitelist of the abnormal state is not within the scope of the whitelist database, the user entity behavior analysis unit determines the whitelist of the abnormal state as a real alarm and sends the activities of the whitelist of the abnormal state to the active confrontation module; if the user entity behavior analysis unit compares and analyzes the whitelist database once or more and confirms that the abnormal whitelist behavior is a security threat, the whitelist generation unit obtains the above instruction to immediately update the whitelist of the corresponding server and deletes the abnormal whitelist found by the user entity behavior analysis unit from the original whitelist. Through this configuration, the user entity behavior analysis unit continuously interacts with the whitelist database to continuously modify and update the original whitelist, thereby reducing the false alarm rate and missed alarm rate of the user entity behavior analysis unit.
[0018] According to a preferred embodiment, the active confrontation module is capable of at least acquiring abnormal activities monitored by the user entity behavior analysis unit, and generating a response strategy that matches the user's security needs based on the security situation monitored by the active confrontation module.
[0019] According to a preferred embodiment, the user entity behavior analysis unit includes:
[0020] The sample data parsing subunit is configured to obtain the data information related to the risk scenario collected by the data collection module, and parse the data information related to the risk scenario collected by the data collection module according to the established log template to obtain key log sample data.
[0021] The sample data classification subunit is configured to classify the key log sample data according to the established sample data classification dimension to obtain several categories of key log valid sample data.
[0022] The model building subunit is configured to build an anomaly detection model based on the valid sample data of the several types of key logs and the machine learning training model.
[0023] According to a preferred embodiment, the method for the sample data acquisition subunit to acquire system operation log source sample data associated with user entity behavior includes: encapsulating the system operation log source sample data associated with user entity behavior acquired from the sample data source to obtain an event, and using the event as the sample data unit to acquire the system operation log source sample data associated with user entity behavior.
[0024] According to a preferred embodiment, the method in which the sample data parsing subunit parses and processes the system operation log source sample data according to an established log template to obtain key log sample data includes: establishing multiple log templates according to the message type of the system operation log source sample data; and parsing and processing the system operation log source sample data according to the established multiple log templates to obtain key log sample data.
[0025] According to a preferred embodiment, the steps of the method are: automatically generating a whitelist that complies with the operating specifications through a trusted protection module in combination with the user's operation and maintenance strategy to establish a legal access strategy and operation behavior strategy for the user; obtaining the whitelist through a blockchain anti-tampering module, and adding the whitelist to the blockchain to prevent the whitelist from being illegally tampered with; monitoring and analyzing the processes or programs in the whitelist through an active confrontation module, and the trusted protection module continuously updates the whitelist based on the security situation monitored by the active confrontation module; the active confrontation module quickly adjusts the user's logical topology based on the monitored security situation, and processes the monitored abnormal activities to achieve self-organized confrontation against all unknown threats, thereby generating continuous immunity to unknown threats.
[0026] According to a preferred embodiment, the trusted protection module automatically generates a whitelist that complies with the operating specifications in combination with the user's operation and maintenance strategy to establish a legal access strategy and an operation behavior strategy for the user. The steps are as follows: the whitelist generation unit generates a whitelist that matches the user's security needs based on the application scenarios of different users and / or the security situation monitored by the active confrontation module; the user entity behavior analysis unit monitors and analyzes the processes or programs on the whitelist run by the user to detect whether there are any abnormalities in the processes or programs on the whitelist run by the user, and sends the monitored security situation of the user to the active confrontation module. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 is a simplified schematic diagram of a preferred embodiment of the present invention;
[0028] Figure 2 It is a simplified schematic diagram of a preferred implementation of the user entity behavior analysis unit of the present invention.
[0029] Reference numerals list
[0030] 1: Trusted protection module; 2: Blockchain anti-tampering module; 3: Active confrontation module;
[0031] 101: whitelist generation unit; 102: user entity behavior analysis unit;
[0032] 102a: sample data acquisition subunit; 102b: sample data analysis subunit;
[0033] 102c: sample data classification unit; 102d: model building unit. DETAILED DESCRIPTION
[0034] The following is a detailed description with reference to the accompanying drawings.
[0035] Before describing the present system, in order to better understand the technical solution of the present invention, the relevant contents of trusted computing are briefly described first.
[0036] The basic principle of trusted computing is to establish a trust root that is safe and reliable, with physical security, management security, and technical security, and then establish a reliable trust chain. It is extended to the entire computer system to ensure the trustworthiness of the entire computer system. From the trust root, hardware platform, and the entire operating system to the application user, measurement and authentication are carried out step by step, and trust is carried out step by step, so that the entire computer system runs in a trusted state, creating a trusted computing environment for the entire computer system. The trust root, hardware platform, operating system, and application user as a whole become a trusted computer system.
[0037] Trusted computing is to build an immune system for computers. Trusted computing means that security protection is performed while computing, so that the computing results are always consistent with expectations, and the entire computing process is measurable and controllable without interference. Trusted computing and protection coexist. Therefore, this system based on trusted computing has functions such as identity recognition, state measurement, and confidential storage. It can identify non-self components in a timely manner, thereby destroying and rejecting harmful substances that enter the body.
[0038] The trusted computing environment hierarchy can be described as:
[0039] Based on cryptography (including cryptographic algorithms, cryptographic protocols, certificate management, etc.), trusted computing nodes are built with chips as the pillars, motherboards as the tablets, and trusted basic support software as the core. Based on the network, multiple trusted computing nodes form a trusted information system, and then based on the application system, a trusted application support environment is further built.
[0040] Specifically, the trusted computing environment level mainly includes the following aspects:
[0041] 1) Bottom-level hardware layer: At the bottom-level hardware layer, the trusted cryptographic module (TCM / TPM) is added to the basic hardware platform, and the core root of trust (CRTM) is implanted into the BOOT ROM of the hardware platform to ensure that the bottom layer can be started securely and controllably.
[0042] 2) Secure operating system level: In the secure operating system level, the provision of trusted services is completed by the trusted service module (TSM). As a software module supporting the cryptographic module in the trusted computing system, it realizes the adaptation of the operating system and TCM, and at the same time, it also reinforces the TCM.
[0043] 3) Application level: In the application level, specific application services are implemented at this level. To ensure that all application services can run in a secure and trusted environment, the trusted computing environment system must be a trusted environment from the underlying hardware to the upper-layer applications. The trusted root must be associated with all application services, and the trust chain is authenticated. In this way, the entire environment is trusted, and the safe and stable operation of all services can be achieved in this environment.
[0044] like Figure 1 and Figure 2 A continuous immune security management and control system based on trusted computing is shown, which is characterized by at least including:
[0045] The trusted protection module 1 is configured to automatically generate a whitelist that complies with the operation specifications in combination with the user's operation and maintenance strategy, so as to establish a legal access strategy and operation behavior strategy for the user.
[0046] The blockchain anti-tampering module 2 is configured to at least obtain the whitelist and add the whitelist to the blockchain to prevent the whitelist from being illegally tampered with.
[0047] The active confrontation module can at least be used to monitor and analyze the processes or programs in the whitelist. In the case where the active confrontation module can obtain the security situation of the user, the trusted protection module 1 can continuously update the whitelist based on the security situation monitored by the active confrontation module;
[0048] The active confrontation module can quickly adjust the user's logical topology based on the monitored security situation and process the monitored abnormal activities to achieve self-organized confrontation against all unknown threats, thereby generating continuous immunity to unknown threats.
[0049] Preferably, the active confrontation module can monitor the user's behavior or activities to fight against ROOT authority hackers. Preferably, the whitelist can include: a system process whitelist and a user behavior whitelist.
[0050] According to a preferred embodiment, the trusted protection module 1 at least includes a whitelist generation unit 101 and a user entity behavior analysis unit 102. The whitelist generation unit 101 is configured to generate a whitelist that matches the security needs of the user based on the application scenarios of different users and / or the security situation monitored by the active confrontation module. The user entity behavior analysis unit 102 is configured to at least be able to monitor and analyze the processes or programs on the whitelist run by the user to monitor whether there are any abnormalities in the processes or programs on the whitelist run by the user. Preferably, the whitelist generation unit 101 can automatically generate a trusted and reliable program whitelist, and use the hardware trusted chip to instantly detect and prevent the operation of unknown programs.
[0051] Since the whitelist can only specify which programs or processes can be run, but there is no way to solve the problems such as how the programs are run, when they are run, and by whom, etc., the user entity behavior analysis unit 102 can be set to solve this problem well. That is, the user entity behavior analysis unit 102 can be used to monitor the programs or processes on the whitelist to obtain the running time of the processes or users on the whitelist, who is running them, etc. in real time.
[0052] The user entity behavior analysis unit 102 can send abnormal behavior to the active confrontation module in a very short time after discovering the problem, and the active confrontation module can automatically defend without the administrator rushing online or even going to the computer room to handle it. Through this configuration method, the user entity behavior analysis unit 102 can accurately know which programs a machine can only run or how to run the program. Since the white list can only specify which programs or processes can be run, but there is no way to solve the problems such as how the program is run, when it is run, and by whom it is run, etc., and setting the user entity behavior analysis unit 102 can solve this problem well. That is, the user entity behavior analysis unit 102 can monitor the programs or processes on the white list to obtain the running time of the processes or users on the white list in real time, who is running, etc. In turn, because trusted computing itself has helped the white list reduce a lot of noise, the sample volume or analysis pressure that the user entity behavior analysis unit 102 needs to analyze will be reduced to a very low level. In this way, a very fast and very accurate analysis engine may be created. For example, if there is no white list, once the hacker obtains the highest management authority, its subsequent actions cannot be known. Hackers can install a variety of programs and erase past activity.
[0053] The steps of the method for the whitelist generation unit 101 to generate a whitelist may be:
[0054] 1) Establishing a multi-layer neural network layer, the neural network layer includes a data acquisition layer, a data preliminary processing layer, a data deep processing layer, a security layer, a learning layer and a protection layer;
[0055] 2) Obtain data: Obtain data information through the data acquisition layer;
[0056] 3) Preprocessing data: classify and process the data through the data processing layer;
[0057] 4) Deep processing of data: the data classified in step 3) is put into the queue and sent to the deep processing layer for processing in the order of relevant priorities. After the deep processing layer processes, the relevant baseline correspondence is formed;
[0058] 5) Data decoding: After data processing, it is sent to the security layer, and the protocol decoding engine in the security layer performs deep decoding on the protocol;
[0059] 6) Whitelist modeling: The decoded data is sent to the learning layer, which uses the self-learning module to learn. The subsequent decoded data is compared and analyzed with the baseline of the self-learning module to form a security whitelist;
[0060] 7) Danger handling: If unsafe communication behavior is found in step 6), the network connection is cut off through the protection layer and an alarm is issued for the abnormality.
[0061] Particularly preferably, the whitelist data generated by the whitelist generation unit 101 in an automated manner can be embedded in the blockchain to achieve data integrity and credibility, and prevent unknown threats in an exhaustive and purposeful manner. In specific implementation, the whitelist generation unit 101 autonomously learns to form a whitelist to ensure that only programs in the whitelist are run on the protected machine. If a person executes a program outside the whitelist (such as a system backdoor, virus, ransomware, penetration tool), the whitelist generation unit 101 will alarm or block. In this way, the protection mechanism based on trusted technology enables the system to resist a wide range of attacks. Even if the intrusion is a new type of attack that has never occurred and the characteristics have never been defined, the whitelist generation unit 101 or other units with similar functions will still be blocked because their behavior is "illegal".
[0062] Through this configuration, that is, by combining the whitelist with UEBA technology, the persistent immune system can use big data to analyze abnormal behaviors of the whitelist, thereby greatly reducing the demand for large data sets for user profiling technology. A more streamlined and focused user profile helps reduce misjudgments, improve identification speed, and achieve accurate perception of threats. Send graded alarm notifications before threats occur. The trusted protection module 1 of the persistent immune system uses artificial intelligence machine learning technology to discover system weaknesses from the whitelist; the active confrontation module automatically formulates active confrontation strategies for perceived and predicted future threats; the active confrontation module can also use container technology to distribute security measures at high speed on the intruder's attack path before the intruder takes the next attack method, so as to achieve the first-time response and disposal; the active confrontation module uses big data analysis methods to intelligently generate threat intelligence for the specific scenario of the intrusion, and provide support for security operation and maintenance personnel to make timely decisions and implement manual disposal, so as to better understand the next behavior of hackers and their attacks.
[0063] According to a preferred embodiment, the trusted protection module 1 further includes a whitelist database unit. In the case where the user entity behavior analysis unit 102 is capable of sending the monitored abnormal situation to the active confrontation module, the whitelist database unit is configured to at least collect whitelists of multiple different users to form a new whitelist database, so as to analyze and compare the whitelist monitored as abnormal by the user entity behavior analysis unit 102 through the whitelist database, so as to reduce the false alarm rate of the user entity behavior analysis unit 102.
[0064] If the user entity behavior analysis unit 102 analyzes and compares the whitelist monitored by the user entity behavior analysis unit 102 as abnormal state through the whitelist database and finds that the whitelist of abnormal state is not within the scope of the whitelist database, the user entity behavior analysis unit 102 sends an instruction to immediately update the whitelist of the corresponding user server to the whitelist generation unit 101. The whitelist generation unit 101 obtains the above instruction and immediately updates the whitelist of the corresponding server.
[0065] Through this configuration, the whitelist generation unit 101 can continuously update the whitelist according to changes in the security situation to avoid security intrusions from occurring during the time interval from when the user entity behavior analysis unit 102 discovers abnormal behavior to when the administrator responds.
[0066] When the whitelist strategy is confirmed, the file data of each process loading will be recorded and compared with the records in the whitelist to achieve security protection during the process loading process. However, although the shortcomings of the blacklist mechanism are avoided, the whitelist mechanism has two other disadvantages, making this mechanism now appear bloated:
[0067] First, each time a process is started, a new batch of detection results will be recorded for comparison with the records in the whitelist. As time goes by, the amount of data will gradually become very large, not only will the call data become slower and slower, but it will also bring a heavy burden to the local host database; secondly, when the whitelist strategy is confirmed, as long as the subsequent process does not match the whitelist, the system will alarm-but in fact, many inconsistencies are caused by benign changes such as system upgrades, application updates, and network changes, and there is no malicious code attacking the host, which results in a very high false alarm rate. If the administrator checks one by one, it will waste time. If it is ignored, the whitelist alarm mechanism will become a formality. Once a real security threat invades the user, the system cannot provide effective security protection for the user. In this regard, the solution provided by the present invention makes the whitelist mechanism further intelligent, so that it can be applied in more fields.
[0068] First, in order to solve the problem of huge data volume, a distributed asynchronous storage method is adopted. Distributed means that data and programs can be located not on one server, but distributed to multiple servers. Through this configuration method, not only the problems of tight central host resources and response bottlenecks in traditional centralized systems are overcome, but also the security and consistency of data are guaranteed. At the same time, when managing and using these data, the system will save a copy of the same data in the cache, so that the cached data can be directly called during processing, and there is no need to obtain it from the database, which greatly improves the processing efficiency. In addition, even if the cached data is cleared, it actually has little impact, because the data is still backed up in the server. As for the problem of excessively high false alarm rate, the whitelist database unit can form a whitelist database based on data from the network, community, etc.
[0069] Preferably, the trusted protection module 1 can at least collect whitelists of users in a plurality of substantially similar fields or application scenarios, and integrate the plurality of whitelists to form a whitelist database that can be used in the field or application scenario.
[0070] Preferably, the whitelist database is a whitelist content that has been used by multiple different users and confirmed to be safe. Preferably, if a process or program can be trusted to run on users exceeding the first threshold, the process or program can be added to the whitelist database. Preferably, the first threshold can be flexibly set according to actual scenario requirements.
[0071] Preferably, the user entity analysis unit compares the abnormal behavior that does not belong to the whitelist with the whitelist database once or multiple times. Preferably, if the abnormal behavior that does not belong to the whitelist is within the range of the trusted list of the whitelist database, the user entity analysis unit determines the abnormal behavior that does not belong to the whitelist as a trusted behavior, thereby reducing false warnings and improving the accuracy of abnormality detection by the user entity analysis unit.
[0072] For example, in actual use, if an abnormality occurs in the user's production environment, such as machine A has an abnormality, but the whitelist database finds that this abnormality also exists in other users' production environments and is credible, then the user entity analysis unit determines that it is a benign abnormality, and then the user entity analysis unit will not alarm, nor will it send the behavior to the active confrontation module. The user entity analysis unit compares similar abnormalities with the whitelist database once or more times. If there are still unknown abnormalities in the end, the user entity analysis unit determines that the abnormality is a clear alarm, and then quickly sends the behavior to the active confrontation module, and the active confrontation module immediately responds accordingly.
[0073] Preferably, the whitelist of the security protection system can be automatically generated by the whitelist generation unit 101. Preferably, the whitelist generation unit 101 can also create a whitelist by manually adding according to the needs of the real scene. Through this configuration, the flexibility and convenience of the whitelist in daily use can be greatly improved.
[0074] Secondly, each time the process starts, the whitelist generation unit 101 will record a batch of new detection results monitored by the user entity behavior analysis unit 102 for comparison with the records of the whitelist. As time goes by, the amount of data will gradually become very large. Not only will the whitelist generation unit 101 call data more and more slowly, but it will also bring a heavy burden to the local host database. In view of the problem of large amount of data, the whitelist generation unit 101 adopts a distributed asynchronous storage method. Distributed means that the data and programs on the whitelist may not be located on one server, but are distributed to multiple servers. Preferably, the above-mentioned servers can be different servers of the same user, or servers of other users or platforms. Preferably, the whitelists generated by the whitelist generation unit 101 at different times can be saved by different servers in turn. Through this configuration method, not only the problems of tight central host resources and response bottlenecks of traditional centralized systems are overcome, but also the security and consistency of data are guaranteed. At the same time, when managing and using these data, the system will save a copy of the same data in the cache, so that the cached data can be directly called during processing, and it is no longer necessary to obtain it from the database, which greatly improves the processing efficiency of the whitelist. In addition, even if the cached data is cleared, it actually has little impact because the data is still backed up in the server.
[0075] According to a preferred embodiment, the active confrontation module is capable of at least acquiring abnormal activities monitored by the user entity behavior analysis unit 102, and generating a response strategy that matches the user's security needs based on the security situation monitored by the active confrontation module.
[0076] Preferably, the user entity behavior analysis unit 102 can send the monitored abnormal activities to the active confrontation module.
[0077] Preferably, the active confrontation module can autonomously conduct confrontation according to the abnormal activities sent by the user entity behavior analysis unit 102 .
[0078] For example, the user entity behavior analysis unit 102 can find that a virus or program is not on the whitelist and automatically isolate it. At the same time, when the user entity behavior analysis unit 102 detects a large number of abnormal scans of port 445, the user entity behavior analysis unit 102 can send the detected abnormalities to the active confrontation module. The active confrontation module can automatically adjust the firewall rules to block the path for the virus to spread further.
[0079] According to a preferred embodiment, the active confrontation module is capable of at least acquiring abnormal activities monitored by the user entity behavior analysis unit 102, and generating a response strategy that matches the user's security needs based on the security situation monitored by the active confrontation module.
[0080] The active confrontation module automatically formulates active confrontation strategies for the perceived and predicted threats. Using container technology, the first response and disposal can be achieved in the scanning and initial stages before the intruder takes the next step of attack. For the specific scenario where the intrusion occurs, big data analysis methods are used to intelligently generate threat intelligence to provide support for security operation and maintenance personnel to make timely decisions and implement manual disposal. Since the security situation monitored by the active confrontation module generates a response strategy that matches the user's security needs, which is an existing technology and can be easily obtained by technicians in this field, the details of this technology will not be described here.
[0081] According to a preferred embodiment, the user entity behavior analysis unit 102 includes:
[0082] The sample data acquisition subunit 102a is configured to acquire system operation log source sample data associated with user entity behavior;
[0083] The sample data parsing subunit 102b is configured to parse the system operation log source sample data according to the established log template to obtain key log sample data;
[0084] The sample data classification unit 102c is configured to classify the key log sample data according to the established sample data classification dimension to obtain several types of key log valid sample data;
[0085] The model building unit 102d is used to build an anomaly detection model based on the valid sample data of the several types of key logs and the machine learning training model.
[0086] Preferably, the user entity behavior may include: time, location, person, interaction and content of interaction. For example, user search: at what time, on what platform, with a specific ID and what the search content is.
[0087] In this embodiment, by loading a monitoring code (or also called a tracking point) on the sample data source, the monitoring code can be used to monitor whether the user clicks the registration button, the orders downloaded by the user, etc.
[0088] In this embodiment, the existence form of the system operation log source sample data is not limited, such as a txt document or a list. In this embodiment, the system operation log source sample data is stored on various terminals used by users. In this embodiment, considering that the system operation log source sample data may be a large amount of unstructured sample data, direct use will lead to low efficiency in sample data processing and consume a lot of computing power. For this reason, in this embodiment, after obtaining the system operation log source sample data, pre-processing or pre-analysis is performed to achieve the purpose of structuring, and the subsequent steps directly use the structured system operation log source sample data, thereby improving the efficiency of sample data processing and saving computing power. In this implementation, a series of parsing rules such as parsed log keywords, parsed sample data step size, sample data format or structure are defined in the log template to parse and process the system operation log source sample data to obtain key log sample data. Alternatively, the log template can also be called a sample data parsing model. In this embodiment, since the terminals used by users vary greatly in product form, or the operating systems of the terminals are also different, for this reason, a log template is configured for each type of product form or each type of operating system. In this embodiment, as mentioned above, the user entity behavior caused by the user entity behavior usually includes the following five dimensions: time, place, person, interaction, and content of interaction, so that the key log sample data can actually also include the five dimensions.
[0089] In addition, as mentioned above, the terminals where the user entity behavior occurs have various product forms, or have different operating systems, which results in the key log sample data actually also having these dimensions. Therefore, in this embodiment, in order to effectively reflect the user entity behavior, the key log sample data can be classified and processed through the multiple sample data classification dimensions of step S103 to obtain several types of key log valid sample data, and the key log valid sample data is also called Log Key.
[0090] In this embodiment, the anomaly monitoring model can be established by training the neural network model according to the valid sample data of the several types of key logs. Specifically, the neural network model is not particularly limited, for example, it can be LSTM. When performing anomaly detection, the anomaly detection model can be based on a density method or a distance method.
[0091] According to a preferred embodiment, the method for the sample data acquisition subunit 102a to acquire system operation log source sample data associated with user entity behavior includes: encapsulating the system operation log source sample data associated with user entity behavior acquired from the sample data source to obtain an event, and acquiring the system operation log source sample data associated with user entity behavior using the event as the sample data unit.
[0092] The system operation log source sample data is directly associated with the user entity behavior. In other words, the user entity behavior can be indirectly reflected through the system operation log source sample data.
[0093] In this embodiment, a monitoring code may be loaded on the sample data source, and the monitoring code may be used to monitor whether the user clicks the registration button, the order downloaded by the user, and the like.
[0094] According to a preferred embodiment, the method in which the sample data parsing subunit 102b parses and processes the system operation log source sample data according to an established log template to obtain key log sample data includes: establishing multiple log templates according to the message type of the system operation log source sample data; and parsing and processing the system operation log source sample data according to the established multiple log templates to obtain key log sample data.
[0095] In this implementation, the log template defines a series of parsing rules such as parsed log keywords, parsed sample data step, sample data format or structure, to parse the system operation log source sample data to obtain key log sample data. The log template can be called a sample data parsing model.
[0096] In this embodiment, since the terminals used by users vary greatly in product form, or the operating systems of the terminals are also different, a log template is configured for each type of product form, or each type of operating system.
[0097] According to a preferred embodiment, the steps of the continuous immune security management and control method based on trusted computing are: automatically generate a whitelist that complies with the operating specifications through a trusted protection module 1 in combination with the user's operation and maintenance strategy to establish a legal access strategy and operation behavior strategy for the user; obtain the whitelist through a blockchain anti-tampering module 2, and add the whitelist to the blockchain to prevent the whitelist from being illegally tampered with; monitor and analyze the processes or programs in the whitelist through an active confrontation module, and the trusted protection module 1 continuously updates the whitelist based on the security situation monitored by the active confrontation module; the active confrontation module quickly adjusts the user's logical topology based on the monitored security situation, and processes the monitored abnormal activities to achieve self-organized confrontation against all unknown threats, thereby generating continuous immunity to unknown threats.
[0098] According to a preferred embodiment, the trusted protection module 1 automatically generates a whitelist that meets the operation specifications in combination with the user's operation and maintenance strategy to establish a legal access strategy and operation behavior strategy for the user in the following steps: the whitelist generation unit 101 generates a whitelist that matches the user's security needs based on the application scenarios of different users and / or the security situation monitored by the active confrontation module; the user entity behavior analysis unit 102 monitors and analyzes the processes or programs on the whitelist run by the user to monitor whether there are any abnormalities in the processes or programs on the whitelist run by the user, and sends the monitored security situation of the user to the active confrontation module. Preferably, users include but are not limited to: servers, information systems, etc.
[0099] Preferably, the blockchain anti-tampering module 2 can arrange the whitelist on the blockchain so that the whitelist cannot be tampered with by security threats. If the security threat wants to tamper with the above whitelist, it must simultaneously break through all blockchain nodes to make changes, and it must also run faster than the consensus speed of the blockchain. Through this configuration, the blockchain anti-tampering module 2 uses high-speed blockchain technology to store audit information, whitelist information, etc. to prevent behavior records from being tampered with.
[0100] Preferably, the user entity behavior analysis unit 102 can combine machine learning technology to continuously analyze the user's server. Preferably, the user entity behavior analysis unit 102 can collect sufficient data and appropriate analysis to discover abnormal behaviors such as lateral movement, data transmission, and continuous reconnection.
[0101] Preferably, the system process whitelist is the system processes that the security protection system can trust.
[0102] Preferably, the user behavior whitelist may be behaviors that the user is allowed to execute.
[0103] Preferably, the user entity behavior analysis unit 102 can introduce the full-time and space context, combine the historical baseline and group comparison, and present the alarm in the complete full-time and space context, without spending time on manual association, reducing the time for verification, investigation, and response. Preferably, when an attack event occurs, the user entity behavior analysis unit 102 can connect events, entities, anomalies, etc. to grasp the overall picture of the entire attack event and quickly perform verification and accident response. Preferably, the user entity behavior analysis unit 102 can automatically build a behavior baseline through unsupervised and semi-supervised machine learning. Through this configuration, the user entity behavior analysis unit 102 can capture subtleties that humans cannot perceive or recognize from the behavior data, find the abnormalities hidden under the appearance, that is, find abnormal malicious users from normal users within the whitelist range, and find abnormal malicious behaviors from the user's normal behavior; at the same time, machine learning-driven behavior analysis can avoid the difficulty and ineffectiveness of manually setting thresholds.
[0104] Preferably, the user entity behavior analysis unit 102 can construct a network graph using entities and relationships between entities extracted from events, alarms, exceptions, and accesses.
[0105] Preferably, the data sources accessed by the user entity behavior analysis unit 102 mainly include hosts, terminals, network devices, security devices, business systems, application systems, physical security systems, etc.
[0106] Preferably, the formats of the accessed data sources mainly include two categories: logs and network traffic, as well as various contextual data within the organization.
[0107] Preferably, the user entity behavior analysis unit 102 is combined with the enterprise business system settings, and uses UEBA technology to make AI portraits of users and systems. Based on the formed user portraits, it is determined whether there are abnormal operations and abnormal processes in the users and information systems, and further monitoring and risk warning are carried out for the abnormalities.
[0108] Preferably, the portrait may include but is not limited to: frequently used user IDs, application names, most occupied system resources, etc. Through the portrait description, the user behavior can be compared and identified, the user's abnormal operation can be quickly determined, and the intrusion path can be predicted by behavioral analysis to obtain accurate threat perception, and a graded alarm notification can be sent in advance before the threat occurs.
[0109] It should be noted that the above specific embodiments are exemplary, and those skilled in the art can come up with various solutions inspired by the disclosure of the present invention, and these solutions also belong to the disclosure scope of the present invention and fall within the protection scope of the present invention. Those skilled in the art should understand that the present invention description and its drawings are illustrative and do not constitute a limitation of the claims. The protection scope of the present invention is defined by the claims and their equivalents.
[0110] The present invention specification contains multiple inventive concepts, and the applicant reserves the right to file a divisional application based on each inventive concept. The present invention specification contains multiple inventive concepts, such as "preferably", "according to a preferred embodiment" or "optionally" all indicate that the corresponding paragraph discloses an independent concept, and the applicant reserves the right to file a divisional application based on each inventive concept.
Claims
1. A continuous immune security management and control system based on trusted computing, characterized in that: At least: A trusted protection module (1) is configured to automatically generate a whitelist that complies with the operation specification in combination with the user's operation and maintenance strategy to establish a legal access strategy and operation behavior strategy for the user, wherein the whitelist includes a system process whitelist and a user behavior whitelist; A blockchain anti-tampering module (2) is configured to at least obtain the whitelist and add the whitelist to the blockchain to prevent the whitelist from being illegally tampered with; The active confrontation module (3) is at least capable of monitoring and analyzing the processes or programs in the whitelist. Wherein, when the active confrontation module (3) is able to obtain the security situation of the user, the trusted protection module (1) is able to continuously update the whitelist based on the security situation monitored by the active confrontation module (3); The active confrontation module (3) can quickly adjust the user's logical topology structure based on the monitored security situation and process the monitored abnormal activities to achieve self-organized confrontation against unknown threats, thereby generating continuous immunity to unknown threats. The trusted protection module (1) at least includes a whitelist generation unit (101) and a user entity behavior analysis unit (102), wherein: The whitelist generation unit (101) is configured to generate a whitelist matching the security requirements of the user based on application scenarios of different users and / or the security situation monitored by the active confrontation module (3); The user entity behavior analysis unit (102) is configured to at least monitor and analyze the processes or programs on the whitelist run by the user, so as to detect whether there are any abnormalities in the processes or programs on the whitelist run by the user, and to send the security situation of the user obtained through monitoring to the active confrontation module (3).
2. The continuous immune safety management and control system according to claim 1, characterized in that: The trusted protection module (1) further comprises a whitelist database unit, wherein: When the user entity behavior analysis unit (102) is capable of sending the monitored abnormal situation to the active confrontation module (3), the whitelist database unit is configured to at least be able to collect whitelists of multiple different users to form a whitelist database, so as to reduce the false alarm rate of the user entity behavior analysis unit (102) by analyzing and comparing the whitelist monitored as abnormal by the user entity behavior analysis unit (102) through the whitelist database.
3. The continuous immune safety management and control system according to claim 2, characterized in that: The trusted protection module (1) is capable of continuously updating the whitelist, and the method of continuously updating includes: If the user entity behavior analysis unit (102) analyzes and compares the whitelist monitored by the user entity behavior analysis unit (102) as an abnormal state through the whitelist database and finds that the whitelist in the abnormal state is within the scope of the whitelist database, the user entity behavior analysis unit (102) determines the whitelist in the abnormal state as an erroneous alarm, and the whitelist generation unit (101) obtains the above instruction to immediately update the whitelist of the corresponding server and add the benign anomaly found by the user entity behavior analysis unit (102) into the original whitelist.
4. The continuous immune safety management and control system according to claim 3, characterized in that: The active confrontation module (3) is at least capable of acquiring abnormal activities monitored by the user entity behavior analysis unit (102), and generating a response strategy that matches the user's security needs based on the security situation monitored by the active confrontation module (3).
5. The continuous immune safety management and control system according to claim 4, characterized in that: The user entity behavior analysis unit (102) comprises: A sample data acquisition subunit (102a), configured to acquire system operation log source sample data associated with user entity behavior; The sample data parsing subunit (102b) is configured to parse the system operation log source sample data according to the established log template to obtain key log sample data; A sample data classification unit (102c) is configured to classify the key log sample data according to the established sample data classification dimension to obtain several types of key log valid sample data; The model building unit (102d) is used to build an anomaly detection model based on the valid sample data of the several types of key logs and the machine learning training model.
6. The continuous immune safety management and control system according to claim 5, characterized in that: The method for the sample data acquisition subunit (102a) to acquire system operation log source sample data associated with user entity behavior comprises: encapsulating the system operation log source sample data associated with user entity behavior acquired from the sample data source to obtain an event, and using the event as a sample data unit to acquire the system operation log source sample data associated with user entity behavior.
7. The continuous immune safety management and control system according to claim 6, characterized in that: The method in which the sample data parsing subunit (102b) parses the system operation log source sample data according to the established log template to obtain key log sample data comprises: establishing multiple log templates according to the message type of the system operation log source sample data; and parsing the system operation log source sample data according to the established multiple log templates to obtain key log sample data.
8. A method for using the continuous immune security management and control system based on trusted computing according to any one of claims 1 to 7, characterized in that: The method comprises the following steps: automatically generating a whitelist that complies with the operation specification by combining the trusted protection module (1) with the user's operation and maintenance strategy, so as to establish a legal access strategy and operation behavior strategy for the user; Obtaining the whitelist through a blockchain anti-tampering module (2), and adding the whitelist to the blockchain to prevent the whitelist from being illegally tampered with; The active confrontation module (3) monitors and analyzes the processes or programs in the whitelist. The trusted protection module (1) continuously updates the whitelist based on the security situation monitored by the active confrontation module (3); The active confrontation module (3) quickly adjusts the user's logical topology based on the monitored security situation and processes the monitored abnormal activities to achieve self-organized confrontation with all unknown threats, thereby generating continuous immunity to unknown threats.
9. The method according to claim 8, characterized in that The steps of the trusted protection module (1) automatically generating a whitelist that complies with the operation specifications in combination with the user's operation and maintenance strategy to establish a legal access strategy and operation behavior strategy for the user are as follows: The whitelist generation unit (101) generates a whitelist matching the security requirements of the user based on the application scenarios of different users and / or the security situation monitored by the active confrontation module (3); The user entity behavior analysis unit (102) monitors and analyzes the processes or programs on the whitelist run by the user to detect whether there are any abnormalities in the processes or programs on the whitelist run by the user, and sends the security situation of the user obtained through monitoring to the active confrontation module (3).
Citation Information
Patent Citations
Safe web browsing system based on parents' personalized recommendation and control
CN104035999B
A method and platform for trusted environment management of industrial control systems based on security chips
CN104573516B
White list updating method based on trusted process tree
CN101788915A
Execution system and execution method for white list based on trust chain
CN106529282A
A program white list strategy fusion method and a fusion system
CN109740341A