Security Protection Method and Electronic Device
By loading a new kernel entry address in the processor register and using the virtual machine manager to detect instructions, the problem of operating system prone to crash is solved, and the stability and data protection of a secure operating environment are achieved to prevent malicious tampering.
Patent Information
- Application Number
- CN202111163923.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-30
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-09-30
AI Technical Summary
In the prior art, malicious programs tamper with important settings of applications by modifying configuration files, threatening user information and property security, and the kernel of the operating system is vulnerable to attack and causing crashes.
By loading a new kernel entry address in the processor's registers, replacing the original kernel entry address with the virtual machine manager, and ensuring that the kernel entry address has not been modified through detection instructions, entering a secure running environment, using filtering functions to redirect and encrypt data operations, avoiding operating system crashes.
It significantly improves the security of the system, prevents operating system crashes, ensures the safe operation of the kernel, protects important data from being tampered with, and improves the data security of the application.
Smart Images

Figure CN113900732B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of security protection, and particularly to a security protection method and an electronic device. Background Art
[0002] The configuration file of an application stores important parameters and initialization settings. Modifying the configuration file can control and affect the behavior of the application. For example, the new Microsoft Edge browser uses the Chromium kernel. While the open-source Chromium project enables developers to be familiar with the program architecture, it also exposes information such as the storage location of important configurations, data structures, and encryption and decryption algorithms. Chromium stores important content such as the home page, default search engine, and plugins in plain text on the Secure Preferences configuration file and uses the digest generated by the HMAC algorithm to verify the validity of the data. This allows malicious programs to tamper with the home page and silently install plugins by modifying the configuration file, thereby making profits and seriously threatening the information and property security of users. Summary of the Invention
[0003] This application provides a security protection method and an electronic device. The technical solutions adopted in the embodiments of this application are as follows:
[0004] In a first aspect of this application, a security protection method is provided, including:
[0005] Obtain a control instruction for entering the kernel;
[0006] Based on the control instruction, load a new kernel entry address in a target register, where the new kernel entry address is used to point to a secure operating environment based on the kernel, and the target register is a register of the processor;
[0007] Obtain a detection instruction for reading the value of the target register;
[0008] Based on the detection instruction, the virtual machine monitor writes the original kernel entry address into the target register, and in response to the detection instruction, the virtual machine monitor reads the original kernel entry address from the target register.
[0009] In some embodiments, the loading of the new kernel entry address in the target register based on the control instruction includes:
[0010] Based on the control instruction, load the new kernel entry address from a special module register of the processor, where the new kernel entry address replaces the original kernel entry address and is stored in the special module register.
[0011] In some embodiments, based on the detection instruction, the virtual machine monitor writes the original kernel entry address to the target register, and in response to the detection instruction, the virtual machine monitor reads the original kernel entry address from the target register, including:
[0012] Based on the detection instruction, the virtual machine monitor writes the original kernel entry address to a general-purpose register of the processor, and in response to the detection instruction, the virtual machine monitor reads the original kernel entry address from the general-purpose register.
[0013] In some embodiments, the virtual machine monitor writing the original kernel entry address to a general-purpose register of the processor and the virtual machine monitor reading the original kernel entry address from the general-purpose register in response to the detection instruction includes:
[0014] The virtual machine monitor controls the instruction pointer of the processor to skip the detection instruction to prevent the processor from executing the detection instruction, where the detection instruction is used to indicate writing the value of the special module register to the general-purpose register and reading the value of the general-purpose register;
[0015] The virtual machine monitor writes the original kernel entry address to the general-purpose register;
[0016] The virtual machine monitor returns the control of the processor to the operating system and reads the original kernel entry address from the general-purpose register to determine that the value of the special module register has not been modified.
[0017] In some embodiments, the virtual machine monitor controlling the instruction pointer of the processor to skip the detection instruction to prevent the processor from executing the detection instruction includes:
[0018] When the detection instruction is received, the operating system hands over the control of the processor to the virtual machine monitor;
[0019] The virtual machine monitor controls the instruction pointer of the processor to skip the detection instruction to prevent the processor from executing the detection instruction.
[0020] In some embodiments, the method further includes:
[0021] Based on the new kernel entry address, a new kernel entry program is called;
[0022] The new kernel entry program calls a filtering function, and the filtering function is used to determine whether the control instruction is used to indicate calling a first target function and to indicate creating a first target file at a first target address using the first target function;
[0023] In the case where the control instruction is used to indicate calling the first target function and indicating to create the first target file at the first target address by using the first target function, call the first target function to create a second target file at the redirected second target address.
[0024] In some embodiments, the method further includes:
[0025] Call a new kernel entry program based on the new kernel entry address;
[0026] Call a filtering function through the new kernel entry program, and use the filtering function to determine whether the control instruction is used to call the first target function and indicate to open the first target file at the first target address by using the first target function;
[0027] In the case where the control instruction is used to indicate calling the first target function and indicating to open the first target file by using the first target function, call the first target function to open a second target file at the redirected second target address.
[0028] In some embodiments, the method further includes:
[0029] Call a new kernel entry program based on the new kernel entry address;
[0030] Call a filtering function through the new kernel entry program, and use the filtering function to determine whether the control instruction is used to call the second target function and indicate to write data to the second target file by using the second target function;
[0031] In the case where the control instruction is used to call the second target function to write data to the second target file, encrypt the data to be written, and call the second target function to write the encrypted data to the second target file.
[0032] In some embodiments, the method further includes:
[0033] Call a new kernel entry program based on the new kernel entry address;
[0034] Call a filtering function through the new kernel entry program, and use the filtering function to determine whether the control instruction is used to call the third target function and indicate to read data from the second target file by using the third target function;
[0035] In the case where the control instruction is used to call the third target function to read data from the second target file, call the third target function to read the encrypted data from the second target file and decrypt the encrypted data.
[0036] The second aspect of the present application provides an electronic device, which at least includes a memory and a processor. A program is stored on the memory, and when the processor executes the program on the memory, the following method is implemented:
[0037] Obtain a control instruction for entering the kernel;
[0038] Based on the control instruction, load a new kernel entry address into the target register. The new kernel entry address is used to point to a secure operating environment based on the kernel, and the target register is a register of the processor;
[0039] Obtain a detection instruction, which is used to read the value of the target register;
[0040] Based on the detection instruction, the virtual machine manager writes the original kernel entry address into the target register, and in response to the detection instruction, the virtual machine manager reads the original kernel entry address from the target register.
[0041] In the security protection method of the embodiment of the present application, the original kernel entry address in the target register is replaced with a new kernel entry address. Based on this new kernel entry address, it is possible to enter the secure operating environment of the kernel. Performing operations in this secure operating environment has a relatively high security factor. When the kernel protection system generates a detection instruction to detect the value of the target register, the virtual machine manager writes the original kernel entry address into the target register, so that the kernel protection system determines that the value of the target register has not been modified, to avoid the operating system crashing and ensure that the secure operating environment of the kernel can operate normally. Furthermore, it makes it possible to perform operations in this secure operating environment of the kernel, and can significantly improve the system security factor. Description of the Drawings
[0042] Figure 1 It is a system architecture diagram of an electronic device configured with a virtual machine manager and a virtual machine;
[0043] Figure 2 It is a schematic diagram of the interaction process between the virtual machine manager and the operating system of the virtual machine;
[0044] Figure 3 It is a flowchart of the security protection method of the embodiment of the present application;
[0045] Figure 4 It is a system architecture diagram of the electronic device of the embodiment of the present application;
[0046] Figure 5 It is a structural block diagram of the electronic device of the embodiment of the present application. Detailed Embodiments
[0047] The various solutions and features of the present application are described herein with reference to the accompanying drawings.
[0048] It should be understood that various modifications can be made to the embodiments applied herein. Therefore, the above specification should not be construed as limiting, but merely as an example of the embodiments. Those skilled in the art will envision other modifications within the scope and spirit of the present application.
[0049] The accompanying drawings, which are included in and constitute a part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.
[0050] These and other features of the present application will become apparent from the following description of the preferred forms of the embodiments, given by way of non-limiting example with reference to the accompanying drawings.
[0051] It should also be understood that although the present application has been described with reference to some specific examples, those skilled in the art can surely implement many other equivalent forms of the present application, which have the features as described in the claims and thus are all within the protection scope defined thereby.
[0052] When combined with the accompanying drawings, the above and other aspects, features, and advantages of the present application will become more apparent in view of the following detailed description.
[0053] Specific embodiments of the present application are hereinafter described with reference to the accompanying drawings; however, it should be understood that the embodiments applied are merely examples of the present application and can be implemented in various ways. Well-known and / or repetitive functions and structures are not described in detail to avoid obscuring the present application with unnecessary or redundant details. Therefore, the specific structural and functional details applied herein are not intended to be limiting, but merely serve as a basis for the claims and a representative basis for teaching those skilled in the art to use the present application in substantially any suitable detailed structure in a variety of ways.
[0054] This specification may use the phrases "in one embodiment", "in another embodiment", "in yet another embodiment", or "in other embodiments", each of which may refer to one or more of the same or different embodiments according to the present application.
[0055] Embodiments of the present application provide a security protection method, which is applied to an electronic device configured with a virtual machine manager. The electronic device may be configured with one or more virtual machines, and each virtual machine is respectively equipped with its own operating system. For example, as shown in Figure 1 the electronic device is configured with three virtual machines, and each virtual machine is configured with its own operating system and application programs.
[0056] The virtual machine monitor and the operating system can alternately obtain the control right of the processor of the electronic device. Specifically, in cooperation with Figure 2 As shown, when a Vmexit event is triggered, the operating system of the virtual machine hands over the control right of the processor to the virtual machine monitor. When a Vmresume event is triggered, the virtual machine monitor hands over the control right of the processor to the operating system of the virtual machine.
[0057] Figure 3 The flowchart of the security protection method according to the embodiment of the present application is shown in Figure 3 As shown, the security protection method according to the embodiment of the present application may specifically include the following steps:
[0058] S101, obtain a control instruction to enter the kernel.
[0059] Among them, the control instruction may be, for example, a control instruction generated by an application program to enter the kernel of the operating system, that is, the control instruction may be an instruction generated by the electronic device during the operation of the application program. Alternatively, the control instruction may also be, for example, a control instruction sent by an input device.
[0060] The control instruction can be used to request to call a function or program in the kernel to perform corresponding operations. For example, it requests to call a function to open a file, requests to call a function to read data from a file, requests to call a function to write data to a file, or requests to call a program to perform other operations. Here, the function or program requested to be called by the control instruction is not specifically limited, and the specific operation requested to be performed by the control instruction is not limited either, as long as it is a control instruction pointing to the kernel of the operating system.
[0061] S102, based on the control instruction, load a new kernel entry address into the target register, where the new kernel entry address is used to point to a secure operating environment based on the kernel, and the target register is a register of the processor.
[0062] The kernel of the operating system is equipped with a kernel entry program. The kernel entry program actually serves as the entry of the kernel, and under the guidance of this kernel entry program, the running environment of the kernel can be entered. The kernel entry program is configured with a kernel entry address. The control instruction to enter the kernel loads the kernel entry address located in the target register. Based on this kernel entry address, the kernel entry program is run, and under the guidance of the kernel entry program, the running environment of the kernel is entered.
[0063] When the manufacturer of the operating system releases the operating system, a kernel entry program has been configured for the kernel. In this application, it is the original kernel entry program, which can be denoted as the first kernel entry program. After the operating system is installed on the electronic device, the original kernel entry address pointing to the original kernel entry program will be stored in the target register of the processor, and the original kernel entry address can be denoted as the first kernel entry address.
[0064] To prevent the kernel of the operating system from being modified and threatening the security of the operating system, the manufacturer of the operating system usually configures a kernel protection system in the kernel. The kernel protection system will regularly detect whether the value in the target register has been replaced. If the value in the target register has been replaced, the kernel protection system will trigger the operating system to crash.
[0065] This application configures a new kernel entry program for the kernel of the operating system, as well as a new kernel entry address pointing to the new kernel entry program. The new kernel entry program can be denoted as the second kernel entry program, and the new kernel entry address can be denoted as the second kernel entry address. By replacing the original kernel entry address stored in the target register with the new kernel entry address, thus, when a control instruction to enter the kernel is obtained, the new kernel entry address will be loaded. Based on the new kernel entry address, the new kernel entry program will be run, and under the guidance of the new kernel entry program, it can enter a secure operating environment of a kernel with higher security. Performing operations in this secure operating environment of the kernel will significantly improve the security of data.
[0066] However, obviously, when the kernel protection system detects whether the first kernel entry address in the target register has been replaced, it will trigger the operating system to crash. To prevent the operating system from crashing and ensure that the secure operating environment of the kernel can run normally, this application also performs the following operations.
[0067] S103, obtain a detection instruction, where the detection instruction is used to read the value of the target register.
[0068] This detection instruction is an instruction generated based on the kernel protection system. This detection instruction is used to read the value of the target register of the processor to determine whether the data including the first kernel entry address in the target register has been modified.
[0069] S104, based on the detection instruction, the virtual machine manager writes the original kernel entry address into the target register, and the virtual machine manager responds to the detection instruction and reads the original kernel entry address from the target register.
[0070] When a detection instruction is obtained, a VmExit event will be triggered, and the operating system will transfer the control of the processor to the virtual machine manager. The virtual machine manager will respond to the detection instruction and write the original kernel entry address into the target register. Subsequently, a Vmresume event will be triggered to transfer the control of the processor back to the operating system, enabling the kernel protection system to read the original kernel entry address from the target register and determine that the value of the target register has not been modified. In this way, the operating system will not crash, ensuring that the secure operating environment of the kernel can operate normally.
[0071] In the security protection method according to the embodiment of the present application, the original kernel entry address in the target register is replaced with a new kernel entry address. Based on this new kernel entry address, the secure operating environment of the kernel can be entered. Performing operations in this secure operating environment has a relatively high security factor. When the kernel protection system generates a detection instruction to detect the value of the target register, the virtual machine manager writes the original kernel entry address into the target register, enabling the kernel protection system to determine that the value of the target register has not been modified, so as to avoid the operating system from crashing and ensure that the secure operating environment of the kernel can operate normally. Furthermore, it makes it possible to perform operations in the secure operating environment of this kernel, significantly improving the system security factor.
[0072] It should be noted that the new kernel entry address corresponds to the original kernel entry address, and the new kernel entry program also corresponds to the original kernel entry program. The so-called original refers to the kernel entry address and kernel entry program configured by the operating system vendor when releasing the operating system, which are the original kernel entry address and original kernel entry program. In this application, the kernel entry address and kernel entry program configured to form the secure operating environment of the kernel are the new kernel entry address and new kernel entry program.
[0073] In some embodiments, loading the new kernel entry address in the target register based on the control instruction includes:
[0074] Based on the control instruction, loading the new kernel entry address from the special module register of the processor. The new kernel entry address replaces the original kernel entry address and is stored in the special module register.
[0075] Specifically, the target register of the processor includes a special module register. Usually, the kernel entry address is stored in this target register. When the operating system is installed on the electronic device, the original kernel entry address is stored in this special module register. In this application, the original kernel entry address in the special module register is replaced with a new kernel entry address.
[0076] Thus, when a control instruction entering the kernel is obtained, a new kernel entry address can be loaded from the special module register. Based on this new kernel entry address, a new kernel entry program is run. Under the guidance of this new kernel entry program, a secure operating environment of the kernel is entered, as Figure 4 shown. Performing operations in this secure operating environment of the kernel has a relatively high security factor and can significantly improve the security of the system and data.
[0077] In some embodiments, based on the detection instruction, the virtual machine manager writes the original kernel entry address to the target register, and in response to the detection instruction, the virtual machine manager reads the original kernel entry address from the target register, including:
[0078] Based on the detection instruction, the virtual machine manager writes the original kernel entry address to a general-purpose register of the processor, and in response to the detection instruction, the virtual machine manager reads the original kernel entry address from the general-purpose register.
[0079] Specifically, the target register of the processor further includes a general-purpose register. As shown in conjunction with Figure 4 this, actually, the detection instruction is used to indicate writing the value of the special module register to the general-purpose register, and then reading the written data from the general-purpose register to determine whether the value of the special module register has been modified.
[0080] On this basis, when the detection instruction is obtained, an exit event of the virtual machine manager is triggered, and the control right of the processor is handed over from the operating system to the virtual machine manager. The virtual machine manager writes the original kernel entry address to this general-purpose register. Then, a reply event is triggered to hand over the control right of the processor back to the operating system, and an operation of reading data from the general-purpose register is performed. At this time, the data that can be read is the original kernel entry address, and the kernel protection system will confirm that the value of the special module register has not been modified.
[0081] In an alternative embodiment, the virtual machine manager writing the original kernel entry address to the general-purpose register of the processor and the virtual machine manager reading the original kernel entry address from the general-purpose register in response to the detection instruction includes:
[0082] The virtual machine manager controls the instruction pointer of the processor to skip the detection instruction to prevent the processor from executing the detection instruction, where the detection instruction is used to indicate writing the value of the special module register to the general-purpose register and reading the value of the general-purpose register;
[0083] The virtual machine manager writes the original kernel entry address to the general-purpose register;
[0084] The virtual machine monitor returns the control of the processor to the operating system and reads the original kernel entry address from the general-purpose register to determine that the value of the special module register has not been modified.
[0085] Since the current value of the special module register is the new kernel entry address instead of the original kernel entry address, if the current value of the special module register is written into the general-purpose register according to the detection instruction, the kernel protection system will detect that the original value of the special module register (i.e., the original kernel entry address) has been modified, and then trigger an operating system crash.
[0086] Continue to cooperate Figure 4 As shown, after the virtual machine monitor takes over the control of the processor, it runs the exit event handler, skips the detection instruction from the virtual machine monitor level for the instruction pointer of the processor, and writes the original kernel entry address into the general-purpose register. Since the pointer position of the processor is not modified from the operating system level, when the virtual machine monitor returns the control of the processor to the operating system, the operating system cannot recognize that the pointer position of the processor has been modified and will consider that the detection instruction has been executed, that is, the current value of the special module register has been written into the general-purpose register. The processor will no longer execute the operation of writing the current value of the special module register into the general-purpose register and will start executing from the next instruction of the detection instruction in the kernel protection system. Specifically, it will execute the operation of reading data from the general-purpose register. At this time, the original kernel entry address can be read from the general-purpose register, and it is judged whether the read data is the same as the kernel entry address configured when the operating system is released. If they are the same, it is determined that the value of the special module register has not been modified, and the operation of triggering an operating system crash is prohibited.
[0087] In some embodiments, the method further includes:
[0088] S115, calling a new kernel entry program based on the new kernel entry address;
[0089] S116, calling a filtering function through the new kernel entry program, and using the filtering function to determine whether the control instruction is used to indicate calling a first target function and indicating using the first target function to create a first target file at a first target address;
[0090] S117, in the case where the control instruction is used to indicate calling the first target function and indicating using the first target function to create the first target file at the first target address, calling the first target function to create a second target file at a redirected second target address.
[0091] Optionally, when a control instruction is obtained, a new kernel entry address is loaded from a special module register based on the control instruction; based on the new kernel entry address, a new kernel entry program is called; and under the guidance of the new kernel entry program, a secure operating environment of the kernel is entered.
[0092] In the secure operating environment of the kernel, a filtering function is called by the new kernel entry program, and the filtering function is used to determine whether the control instruction is used to indicate calling a first target function (NtCreateFile), and it is indicated to create a first target file at a first target address by using the first target function.
[0093] Optionally, the filtering function can determine whether the control instruction is used to call the first target function to perform a file creation operation. If so, it continues to determine whether the process that creates the control instruction belongs to a first target application. If so, it determines whether the target address of the control instruction is the first target address. If so, it is redirected to a second target address, and the first target function is called to create a second target file at the redirected second target address.
[0094] Further, when it is determined that the control instruction is used to call the first target function, a preset form can be called to determine whether the process that creates the control instruction belongs to the first target application in the preset form, determine whether the target address of the control instruction is the first target address in the preset form, and based on the preset form, be redirected to a second target address associated with the first target address.
[0095] The first target file can be a default configuration file or a default data file of the first target application, and the second target file can be an actual configuration file or an actual data file of the first target application. That is, when the first target application sends a control instruction to indicate creating a configuration file or a data file at a default location, it will be redirected to the second target address, and an actual configuration file or an actual data file will be created at the second target address. In this way, the purpose of hiding the real configuration file or data file can be achieved. Illegal elements cannot obtain the real configuration file and the real data file in a static state, and the data security of the application program can be improved.
[0096] In some embodiments, the method further includes:
[0097] S125, calling a new kernel entry program based on the new kernel entry address;
[0098] S126, calling a filtering function through the new kernel entry program, and using the filtering function to determine whether the control instruction is used to call a first target function, and indicating to open a first target file at a first target address by using the first target function;
[0099] S127. When the control instruction is used to indicate the invocation of the first target function and to indicate the use of the first target function to open the first target file, the first target function is invoked to open the second target file at the redirected second target address.
[0100] When the first target application has created a configuration file or a data file, a control instruction can be generated to indicate the use of the first target function (NtCreateFile) to open its configuration file or data file. At this time, based on a preset form, the filtering function can determine whether the process that created this control instruction belongs to the first target application. If so, based on the preset form, it can be determined whether the target address of this control instruction is the first target address. If so, based on the preset form, it is redirected to the second target address associated with the first target address, and the first target function (NtCreateFile) is invoked to open the second target file at the second target address. In this way, the purpose of hiding the actual configuration file or actual data file of the application is achieved, and it is ensured that the application can smoothly open the actual configuration file and actual data file during the normal operation process to ensure the normal operation of the application.
[0101] In some embodiments, the method further includes:
[0102] S135. Based on the new kernel entry address, a new kernel entry program is invoked;
[0103] S136. The filtering function is invoked through the new kernel entry program, and the filtering function is used to determine whether the control instruction is used to invoke the second target function and to indicate the use of the second target function to write data to the second target file;
[0104] S137. When the control instruction is used to invoke the second target function to write data to the second target file, the data to be written is encrypted, and the second target function is invoked to write the encrypted data to the second target file.
[0105] Optionally, when a control instruction is obtained, a new kernel entry address is loaded from a special module register based on the control instruction. Based on the new kernel entry address, a new kernel entry program is called, and under the guidance of the new kernel entry program, the secure operating environment of the kernel is entered. In the secure operating environment of the kernel, the new kernel entry program calls a filtering function, and the filtering function is used to determine whether the control instruction is used to call a second target function (NtWriteFile); if so, the filtering function can determine whether the process that created the control instruction belongs to a first target application; if so, it can be determined whether the target address of the control instruction is a redirected second target address; if so, the data to be written is encrypted, and the second target function is called to write the encrypted data to a second target file. Encrypting the data and writing it to an actual configuration file or actual data file can prevent the actual configuration file or actual data file from being statically analyzed and resulting in data leakage, and can further improve the security of the data.
[0106] In some embodiments, the method further includes:
[0107] S145, calling a new kernel entry program based on the new kernel entry address;
[0108] S146, calling a filtering function through the new kernel entry program, and using the filtering function to determine whether the control instruction is used to call a third target function, and indicating to use the third target function to read data from the second target file;
[0109] S147, when the control instruction is used to call the third target function to read data from the second target file, calling the third target function to read the encrypted data from the second target file and decrypting the encrypted data.
[0110] Optionally, when a control instruction is obtained, a new kernel entry address is loaded from a special module register based on the control instruction. Based on the new kernel entry address, a new kernel entry program is called, and under the guidance of the new kernel entry program, the secure operating environment of the kernel is entered. In the secure operating environment of the kernel, the new kernel entry program calls a filtering function, and the filtering function is used to determine whether the control instruction is used to call a third target function (NtReadFile); if so, the filtering function can determine whether the process that created the control instruction belongs to a first target application; if so, it can be determined whether the target address of the control instruction is a redirected second target address; if so, the third target function is called to read the encrypted data from the second target file and decrypt the encrypted data. In this way, while improving data security, it ensures that the application program can normally call the configuration file or data file to ensure the normal operation of the application program.
[0111] It should be noted that although the operations performed by the present application in the secure operating environment of the kernel are exemplarily described by taking the creation, opening, writing data, and reading data of files as examples in the above embodiments respectively, in specific implementation, the operations that can be performed in the secure operating environment of the kernel are not limited to the above operations.
[0112] cooperate with Figure 4 As shown, in specific implementation, a virtual machine manager and one or more virtual machines can be pre-configured on the electronic device. An operating system is installed on the virtual machine. An exit event handler is configured at the virtual machine manager level. When an exit event is triggered, the virtual machine manager takes over the control right of the processor and processes the exit event based on the exit event handler. After the exit event handler finishes processing the exit event, a resume event is triggered, and the control right of the processor is returned to the operating system of the virtual machine to continue executing the application program in the operating system.
[0113] The kernel of the operating system is equipped with a kernel entry program. The kernel entry program actually serves as the entry of the kernel, and the operating environment of the kernel can be entered under the guidance of this kernel entry program. The kernel entry program is configured with a kernel entry address, and the kernel entry address is stored in a special module register. The control instruction for entering the kernel needs to load the kernel entry address from the special module register. Based on this kernel entry address, the kernel entry program is run, and the operating environment of the kernel is entered under the guidance of the kernel entry program. When the operating system vendor releases the operating system, a kernel entry program has been configured for the kernel, that is, the original kernel entry program. After the operating system is installed on the electronic device, the original kernel entry address pointing to the original kernel entry program is stored in a special register.
[0114] The present application configures a new kernel entry program for the kernel of the operating system, as well as a new kernel entry address pointing to this new kernel entry program. This new kernel entry program can be compatible with the functions of the original kernel entry program and is configured with a filtering function. If specific system service functions need to be filtered, for example, NtCreateFile function, NtReadFile function, NtWriteFile function, etc. By replacing the original kernel entry address stored in the special module register with this new kernel entry address, thus, when a control instruction for entering the kernel is obtained, this new kernel entry address will be loaded. Based on this new kernel entry address, the new kernel entry program is run, and the filtering function can be invoked under the guidance of this new kernel entry program, and the corresponding function requested to be invoked by the control instruction is called by the filtering function. In specific implementation, monitoring functions, control functions, etc. can also be inserted before and after the filtering function to form a highly secure secure operating environment of the kernel.
[0115] To prevent the kernel of the operating system from being modified and threatening the security of the operating system, the manufacturer of the operating system configures a kernel protection system in the kernel. The kernel protection system periodically detects some key positions of the kernel, and the special module register is one of the positions that need to be detected by the kernel protection system. In this application, the original kernel entry address in the special module register is replaced with a new kernel entry address. If the kernel protection system discovers that the original kernel entry address in the special module register has been replaced, it will trigger a blue screen of the operating system, resulting in the inability to actually run the secure operating environment expected by this application.
[0116] To solve this problem, the detection instruction can be pre-configured to trigger an exit event (Vmexit). When the kernel protection system generates a detection instruction to request writing the low part (LowPart) of the special module register into the RAX register in the general-purpose register and writing the high part (highPart) of the special module register into the RDX register. At this time, an exit event will be triggered, and the virtual machine manager will receive the control right of the processor from the operating system of the virtual machine, and the exit event handler will process the exit event according to the established control logic. Specifically, the instruction pointer of the control processor skips the detection instruction, writes the saved original kernel entry address into the RAX register and the RDX register respectively, and then triggers a resume event (Vmresume) to return the control right of the processor to the operating system. The processor will continue to execute the next instruction after the detection instruction in the kernel protection system, read the values of the RAX register and the RDX register, and the kernel protection system will determine that the value of the special module register has not been modified, and the operating system will not crash.
[0117] The control instruction for entering the kernel does not trigger an exit event, can load the new kernel entry address in the special module register, run the new kernel entry program, and enter the secure operating environment of the kernel under the guidance of this new kernel entry program.
[0118] When the application program sends a control instruction to request to call the NtCreatFile function to open the configuration file, the new kernel entry program calls the filtering function to judge the target address of the control instruction. If the process that generates the control instruction belongs to the pre-configured application program and the target address is the pre-configured address, when the filtering function calls the NtCreatFile function, it will modify the target address to another pre-set target address, redirect to another configuration file indicated by this other target address, open this other configuration file through the NtCreatFile function, or create another configuration file at this other target address through the NtCreatFile function.
[0119] When the application sends a control instruction to request calling the NtWriteFile function to write data to another redirected configuration file, the new kernel entry program calls the filtering function. Through the filtering function, it determines whether the process that generates the control instruction belongs to a pre-configured application, and judges whether the target address of the control instruction is another redirected target address. If so, it performs streaming encryption on the data to be written, and calls the NtWriteFile function to write the encrypted data to the other configuration file.
[0120] When the application sends a control instruction to request calling the NtReadFile function to read data from another redirected configuration file, the new kernel entry program calls the filtering function. Through the filtering function, it determines whether the process that generates the control instruction belongs to a pre-configured application, and judges whether the target address of the control instruction is another redirected target address. If so, it calls the NtReadFile function to read the encrypted data from the other configuration file, and performs streaming decryption on the encrypted data to be able to obtain the corresponding data.
[0121] See Figure 4 and Figure 5 As shown in, the embodiment of the present application further provides an electronic device, which at least includes a memory 201 and a processor 202. A program is stored on the memory 201, and when the processor 202 executes the program on the memory 201, the following method is implemented:
[0122] Obtain a control instruction entering the kernel;
[0123] Based on the control instruction, load a new kernel entry address in the target register. The new kernel entry address is used to point to a secure operating environment based on the kernel, and the target register is a register of the processor.
[0124] Obtain a detection instruction, where the detection instruction is used to read the value of the target register.
[0125] Based on the detection instruction, the virtual machine manager writes the original kernel entry address to the target register, and in response to the detection instruction, the virtual machine manager reads the original kernel entry address from the target register.
[0126] In some embodiments, when the processor 202 executes the program on the memory 201, it is specifically used to implement the following method:
[0127] Based on the control instruction, load the new kernel entry address from the special module register of the processor. The new kernel entry address replaces the original kernel entry address and is stored in the special module register.
[0128] In some embodiments, when the processor 202 executes the program on the memory 201, it is specifically configured to implement the following method:
[0129] Based on the detection instruction, the virtual machine manager writes the original kernel entry address into the general-purpose register of the processor, and in response to the detection instruction, the virtual machine manager reads the original kernel entry address from the general-purpose register.
[0130] In some embodiments, when the processor 202 executes the program on the memory 201, it is specifically configured to implement the following method:
[0131] The virtual machine manager controls the instruction pointer of the processor to skip the detection instruction to prevent the processor from executing the detection instruction, where the detection instruction is used to indicate writing the value of the special module register into the general-purpose register and reading the value of the general-purpose register;
[0132] The virtual machine manager writes the original kernel entry address into the general-purpose register;
[0133] The virtual machine manager returns the control of the processor to the operating system, reads the original kernel entry address from the general-purpose register, and determines that the value of the special module register has not been modified.
[0134] In some embodiments, when the processor 202 executes the program on the memory 201, it is specifically configured to implement the following method:
[0135] When the detection instruction is received, the operating system hands over the control of the processor to the virtual machine manager;
[0136] The virtual machine manager controls the instruction pointer of the processor to skip the detection instruction to prevent the processor from executing the detection instruction.
[0137] In some embodiments, when the processor 202 executes the program on the memory 201, it is further configured to implement the following method:
[0138] Based on the new kernel entry address, call a new kernel entry program;
[0139] Call a filtering function through the new kernel entry program, and use the filtering function to determine whether the control instruction is used to indicate calling a first target function and indicate creating a first target file at a first target address using the first target function;
[0140] In the case where the control instruction is used to indicate calling the first target function and indicating to create the first target file at the first target address by using the first target function, call the first target function to create a second target file at the redirected second target address.
[0141] In some embodiments, when executing the program on the memory 201, the processor 202 is further configured to implement the following method:
[0142] Based on the new kernel entry address, call a new kernel entry program;
[0143] Call a filtering function through the new kernel entry program, and use the filtering function to determine whether the control instruction is used to call the first target function and indicate to open the first target file at the first target address by using the first target function;
[0144] In the case where the control instruction is used to indicate calling the first target function and indicating to open the first target file by using the first target function, call the first target function to open a second target file at the redirected second target address.
[0145] In some embodiments, when executing the program on the memory 201, the processor 202 is further configured to implement the following method:
[0146] Based on the new kernel entry address, call a new kernel entry program;
[0147] Call a filtering function through the new kernel entry program, and use the filtering function to determine whether the control instruction is used to call the second target function and indicate to write data to the second target file by using the second target function;
[0148] In the case where the control instruction is used to call the second target function to write data to the second target file, encrypt the data to be written and call the second target function to write the encrypted data to the second target file.
[0149] In some embodiments, when executing the program on the memory 201, the processor 202 is further configured to implement the following method:
[0150] Based on the new kernel entry address, call a new kernel entry program;
[0151] Call a filtering function through the new kernel entry program, and use the filtering function to determine whether the control instruction is used to call the third target function and indicate to read data from the second target file by using the third target function;
[0152] When the control instruction is used to call the third target function to read data from the second target file, the third target function is called to read the encrypted data from the second target file, and the encrypted data is decrypted.
[0153] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, an electronic device, a computer-readable storage medium, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code. When implemented by software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.
[0154] The above-mentioned processor can be a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above-mentioned PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0155] The above-mentioned memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0156] The above-mentioned readable storage medium can be a magnetic disk, an optical disk, a DVD, a USB, a read-only memory (ROM), or a random access memory (RAM), etc. The present application does not limit the specific form of the storage medium.
[0157] The above embodiments are only exemplary embodiments of the present application and are not used to limit the present application. The protection scope of the present application is defined by the claims. Those skilled in the art can make various modifications or equivalent replacements within the essence and protection scope of the present application, and such modifications or equivalent replacements should also be regarded as falling within the protection scope of the present application.
Claims
1. A security protection method, comprising: Obtaining a control instruction for entering the kernel; Based on the control instruction, loading a new kernel entry address into a target register, where the new kernel entry address is used to point to a kernel-based secure operating environment, and the target register is a register of a processor; Obtaining a detection instruction for reading the value of the target register; Based on the detection instruction, having a virtual machine manager write the original kernel entry address into the target register, and having the virtual machine manager respond to the detection instruction by reading the original kernel entry address from the target register.
2. The method according to claim 1, wherein The loading a new kernel entry address into a target register based on the control instruction includes: Based on the control instruction, loading the new kernel entry address from a special module register of the processor, where the new kernel entry address is stored in the special module register to replace the original kernel entry address.
3. The method according to claim 2, wherein The having a virtual machine manager write the original kernel entry address into the target register and having the virtual machine manager respond to the detection instruction by reading the original kernel entry address from the target register includes: Based on the detection instruction, having the virtual machine manager write the original kernel entry address into a general register of the processor, and having the virtual machine manager respond to the detection instruction by reading the original kernel entry address from the general register.
4. The method according to claim 3, wherein, The having the virtual machine manager write the original kernel entry address into a general register of the processor and having the virtual machine manager respond to the detection instruction by reading the original kernel entry address from the general register includes: Controlling, by the virtual machine manager, the instruction pointer of the processor to skip the detection instruction to prevent the processor from executing the detection instruction, where the detection instruction is used to indicate writing the value of the special module register into the general register and reading the value of the general register; Writing, by the virtual machine manager, the original kernel entry address into the general register; Having the virtual machine manager return the control of the processor to the operating system and reading the original kernel entry address from the general register to determine that the value of the special module register has not been modified.
5. The method according to claim 4, wherein The controlling, by the virtual machine manager, the instruction pointer of the processor to skip the detection instruction to prevent the processor from executing the detection instruction includes: When receiving the detection instruction, having the operating system hand over the control of the processor to the virtual machine manager; Controlling, by the virtual machine manager, the instruction pointer of the processor to skip the detection instruction to prevent the processor from executing the detection instruction.
6. The method according to claim 1, wherein, The method further includes: Based on the new kernel entry address, calling a new kernel entry program; Calling, through the new kernel entry program, a filtering function, and using the filtering function to determine whether the control instruction is used to indicate calling a first target function and to indicate using the first target function to create a first target file at a first target address. When the control instruction is used to indicate the invocation of the first target function and to indicate the creation of the first target file at the first target address using the first target function, the first target function is invoked to create a second target file at the redirected second target address.
7. The method according to claim 1, wherein, The method further includes: Invoking a new kernel entry program based on the new kernel entry address; Invoking a filtering function through the new kernel entry program, and using the filtering function to determine whether the control instruction is used to invoke a first target function and to indicate the opening of a first target file at a first target address using the first target function; When the control instruction is used to indicate the invocation of the first target function and to indicate the opening of the first target file using the first target function, the first target function is invoked to open a second target file at the redirected second target address.
8. The method according to claim 6 or 7, wherein The method further includes: Invoking a new kernel entry program based on the new kernel entry address; Invoking a filtering function through the new kernel entry program, and using the filtering function to determine whether the control instruction is used to invoke a second target function and to indicate writing data to the second target file using the second target function; When the control instruction is used to invoke the second target function to write data to the second target file, encrypting the data to be written, and invoking the second target function to write the encrypted data to the second target file.
9. The method according to claim 6 or 7, wherein The method further includes: Invoking a new kernel entry program based on the new kernel entry address; Invoking a filtering function through the new kernel entry program, and using the filtering function to determine whether the control instruction is used to invoke a third target function and to indicate reading data from the second target file using the third target function; When the control instruction is used to invoke the third target function to read data from the second target file, invoking the third target function to read the encrypted data from the second target file and decrypting the encrypted data.
10. An electronic device, at least including a memory and a processor, where a program is stored on the memory, and when the processor executes the program on the memory, the following method is implemented: Obtaining a control instruction for entering the kernel; Loading a new kernel entry address into a target register based on the control instruction, where the new kernel entry address is used to point to a secure operating environment based on the kernel, and the target register is a register of the processor; Obtaining a detection instruction for reading the value of the target register; Based on the detection instruction, the virtual machine manager writes the original kernel entry address to the target register, and in response to the detection instruction, the virtual machine manager reads the original kernel entry address from the target register.
Citation Information
Patent Citations
Driving separation system inside virtual machine and method
CN102938035A
System and method for kernel rootkit protection in a hypervisor environment
US20130097355A1