Operating system command line configuration method and system in a mimicking environment
By introducing command line mapping tables and event adjudication mechanisms in the mimic system, the problem that multiple heterogeneous operating systems in the mimic system cannot be unified in control and command line vulnerabilities is solved, and the system's security and practicality are improved.
Patent Information
- Application Number
- CN202111617814.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-28
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-12-28
AI Technical Summary
There are multiple heterogeneous operating systems in the mimicry system, which makes it impossible to control the operating system through unified commands, and there are vulnerabilities in the operating system command line, endangering the system security.
Introduce command line mapping tables in the operating systems of all online heterogeneous executors, block the execution permissions of external users of the operating system command line, provide a unified command line access interface, and judge the command execution results through the event adjudication mechanism to avoid exploitation.
It realizes unified control and security improvement of multiple heterogeneous operating systems in a mimicry system, avoiding security threats caused by operating system command line vulnerabilities.
Smart Images

Figure CN114356461B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of mimicry defense technology, and in particular to a method and system for configuring an operating system command line in a mimicry environment. Background Art
[0002] Mimicry defense technology has changed the rules of the game for cyberspace defense and provided a new solution for network devices to achieve network security. When designing a mimicry system, heterogeneity is often achieved at the operating system level. Due to the existence of multiple operating systems, on the one hand, when operating and debugging the system, it is often necessary to visit each operating system one by one to locate the problem; on the other hand, the vulnerability problems existing in the operating system command line are often unable to be solved.
[0003] How the mimicry system can provide a unified system command line access interface and solve the vulnerability problems existing in the command lines of heterogeneous operating systems themselves is of great significance to improving the practicability of the mimicry system.
[0004] In order to solve the above problems, people have been seeking an ideal technical solution. Summary of the invention
[0005] The purpose of the present invention is to address the deficiencies in the prior art and thus provide a method and system for configuring an operating system command line in a mimicking environment.
[0006] In order to achieve the above object, the technical solution adopted by the present invention is:
[0007] A first aspect of the present invention provides a method for configuring an operating system command line in a mimicking environment, the method comprising the following steps:
[0008] Step 1: pre-store command line mapping tables in N online heterogeneous execution bodies respectively, and shield the external user execution permissions of the operating system command lines of the N online heterogeneous execution bodies respectively;
[0009] The command line mapping table is a mapping relationship table between user command lines and operating system commands, and different operating systems of online heterogeneous execution bodies correspond to different command line mapping tables;
[0010] Step 2: N online heterogeneous executors respectively monitor in real time whether they have received a user command line from the input agent;
[0011] In response to the received user command line, searching a pre-stored command line mapping table for an operating system command corresponding to the user command line;
[0012] Step 3, after finding the operating system command corresponding to the user command line, the corresponding online heterogeneous execution body runs the found operating system command, obtains the command execution result corresponding to the operating system command, and sends the command execution result to the arbitrator;
[0013] Step 4, the arbiter receives the command execution results sent by N online heterogeneous executors, and makes event decisions based on the received command execution results;
[0014] When the event adjudication is passed, the adjudicator aggregates the command execution results sent by the N online heterogeneous executors to generate a normalized adjudication result, and sends the normalized adjudication result to the N online heterogeneous executors respectively;
[0015] Step 5, N online heterogeneous executors respectively monitor in real time whether they have received the normalized decision result from the arbitrator;
[0016] In response to the received normalized decision result, the corresponding online heterogeneous executor returns the normalized decision result to the output agent;
[0017] Step 6, after receiving the normalized decision results sent by the N online heterogeneous executors, the output agent verifies the data return function of the corresponding online heterogeneous executors based on the normalized decision results;
[0018] When it is determined that the data return function of a certain online heterogeneous executor is in an abnormal state, the corresponding online heterogeneous executor is cleaned;
[0019] When it is determined that the data return functions of all online heterogeneous execution bodies are in a normal state, the N normalized decision results are decided; after the decision is passed, a new normalized decision result is generated, and the process goes to step 7;
[0020] Step 7: The output agent forwards the new normalized decision result to the client.
[0021] A second aspect of the present invention provides an operating system command line configuration system in a mimic environment, the system comprising N online heterogeneous executors, each of which comprises a command line receiver, a command line mapping table memory, a command executor, a command execution result outputter and a command line echoer, the command line mapping table memory is used to pre-store a command line mapping table, the command line mapping table is a mapping relationship table between a user command line and an operating system command, and the command executor is configured to shield the execution permission status of an external user of the operating system command line;
[0022] The command line receiver is configured to: monitor in real time whether a user command line is received from the input agent, and in response to the received user command line, search for an operating system command corresponding to the user command line from a pre-stored command line mapping table, and transmit the command to the command executor;
[0023] The command executor is configured to: not directly execute the received user command line, but execute the found operating system command, obtain the command execution result corresponding to the operating system command, and transmit the command execution result to the command execution result outputter;
[0024] The command execution result outputter is configured to: send the command execution result to the arbiter, monitor in real time whether a normalized ruling result is received from the arbiter, and transmit the received normalized ruling result to the command line echoer; wherein the normalized ruling result is data generated by aggregating the command execution results sent by N online heterogeneous executors when the event ruling is passed by the arbiter;
[0025] The command line echoer is configured to transmit the received normalized decision result to the output agent.
[0026] The beneficial effects of the present invention are:
[0027] 1) The present invention shields the execution authority of external users of the operating system command line by introducing a command line mapping table in the operating system of all online heterogeneous executors, and all online heterogeneous executors provide a unified command line access interface to the outside world. Therefore, when the mimic system has multiple different operating systems, it is not necessary to access the operating system of each online heterogeneous executor one by one to locate the problem when the mimic system is operated and debugged. This solves the problem that the operating system cannot be controlled by a unified command after the operating system is heterogeneous, and improves the practicality and security of multiple heterogeneous operation command line operations under the mimic system.
[0028] 2) The present invention respectively shields the external user execution permissions of the operating system command lines of N online heterogeneous executors, and uses the event adjudication mechanism to judge the command execution results. When the event adjudication is passed, the command execution results sent by the N online heterogeneous executors are aggregated and authenticated to avoid the situation where the mimic system is attacked due to vulnerabilities in the operating system command line;
[0029] 3) The output agent authenticates the normalized decision results sent by the online heterogeneous executors. First, it determines whether the normalized decision results have been aggregated by the arbitrator. If the key value in the custom header data head passes the verification, it means that the normalized decision results have been aggregated by the arbitrator. On the other hand, it performs a large number decision on the custom string content. The consistent decision results are sent to the user terminal for display. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a timing diagram of the operating system command line configuration method in the mimicking environment of the present invention;
[0031] Figure 2 is a flow chart of generating a normalized adjudication result of the present invention;
[0032] Figure 3 is a flow chart of generating a new normalized adjudication result of the present invention;
[0033] Figure 4 It is a structural schematic diagram of the operating system command line configuration system in the mimicking environment of the present invention. DETAILED DESCRIPTION
[0034] The technical solution of the present invention is further described in detail below through specific implementation methods.
[0035] Example 1
[0036] Attached Figure 1 A timing diagram of a method for configuring an operating system command line in a mimicking environment is shown, and the method for configuring an operating system command line in a mimicking environment includes the following steps:
[0037] Step 1: pre-store command line mapping tables in N online heterogeneous execution bodies respectively, and shield the external user execution permissions of the operating system command lines of the N online heterogeneous execution bodies respectively;
[0038] The command line mapping table is a mapping relationship table between user command lines and operating system commands;
[0039] Step 2: N online heterogeneous executors respectively monitor in real time whether they have received a user command line from the input agent;
[0040] In response to the received user command line, the corresponding online heterogeneous executive body does not directly respond to the user command line sent by the non-input agent, but searches for an operating system command corresponding to the user command line from a pre-stored command line mapping table;
[0041] Step 3, after finding the operating system command corresponding to the user command line, the corresponding online heterogeneous execution body runs the found operating system command, obtains the command execution result corresponding to the operating system command, and sends the command execution result to the arbitrator;
[0042] Step 4, the arbiter receives the command execution results sent by N online heterogeneous executors, and makes event decisions based on the received command execution results;
[0043] When the event adjudication is passed, the adjudicator aggregates the command execution results sent by the N online heterogeneous executors to generate a normalized adjudication result, and sends the normalized adjudication result to the N online heterogeneous executors respectively;
[0044] The normalized decision result includes the key value, the custom string content and the command execution results of N online heterogeneous execution bodies;
[0045] Step 5, N online heterogeneous executors respectively monitor in real time whether they have received the normalized decision result from the arbitrator;
[0046] In response to the received normalized decision result, the corresponding online heterogeneous executor returns the normalized decision result to the output agent;
[0047] Step 6, after receiving the normalized decision results sent by the N online heterogeneous executors, the output agent verifies the data return function of the corresponding online heterogeneous executors based on the normalized decision results;
[0048] When it is determined that the data return functions of all online heterogeneous execution bodies are in a normal state, adjudicating the N normalized adjudication results;
[0049] After the ruling is passed, a new normalized ruling result is generated and the process goes to step 7;
[0050] Step 7: The output agent forwards the new normalized decision result to the client.
[0051] It can be understood that for a certain user command line sent by the client to the input agent, the user command line received by N online heterogeneous executors from the input agent is the same; it can be understood that the entire online heterogeneous executor platform provides a unified command line access interface to the outside world, so when performing operation and maintenance debugging on the mimic system, there is no need to access the operating system of each online heterogeneous executor one by one to locate the problem.
[0052] It should be noted that blocking the execution permissions of external users of the operating system command line blocks the execution permissions of the operating system user, mainly to prevent the privilege escalation vulnerability in the operating system command line;
[0053] For example, the Linux system distinguishes between root users and non-root users (users). Root users can perform any operation on the operating system and use any command; user users can often only use some Linux commands or use partial permissions of Linux commands. However, some command lines may have privilege escalation vulnerabilities. Since Linux code is open source, the vulnerabilities in the Linux command line are more easily exploited and discovered, and there is a risk of exploiting user command line vulnerabilities to elevate permissions to root user mode permissions. The command line mapping table pre-stored in the online heterogeneous executable in the present invention presents custom commands (non-Linux system commands) to the outside world, and there is no distinction between root users and user users for external users. Therefore, the present invention can avoid Linux privilege escalation vulnerabilities and vulnerabilities in the Linux system's own command line.
[0054] On the other hand, even if different Linux systems are used, the command lines of the Linux systems are basically the same, so the existing vulnerabilities are exactly the same. For the problem of mimicry escape caused by common mode vulnerabilities between command lines, the present invention can also effectively shield the occurrence of common mode vulnerabilities by using a command line mapping table.
[0055] Specifically, the program to which the command line mapping table in the online heterogeneous execution body is attached is run as root.
[0056] In a specific implementation, the input / output proxy (shellProxy) is designed using the open source zebra framework, which can customize command lines and perform hierarchical and decentralized processing of command lines; shellProxy supports three access methods: ssh, telnet, and serial. When a user accesses shellProxy, a command line terminal will be returned to the client (user), and the client (user) will operate the above command through the command line terminal. At the same time, shellProxy communicates with the back-end online heterogeneous executor through TCP, and shellProxy sends the user command line (command characters) entered by the client (user) to the back-end online heterogeneous executor;
[0057] First, define the operating system in the mimic environment to support two hierarchical modes: display viewing and configuration. Ordinary users can view, and privileged users can configure. User command line information is shown in the following table:
[0058]
[0059] It can be understood that the commands supported in display mode include file path viewing, file list viewing, file content viewing, process list viewing, disk usage viewing, memory usage viewing, operating system information viewing, network information viewing, etc., and the commands supported in configuration mode include network configuration.
[0060] In a specific implementation, three online heterogeneous executors are set, online heterogeneous executor 1 uses the centos operating system, online heterogeneous executor 2 uses the ubuntu operating system, and online heterogeneous executor 3 uses the fedora operating system;
[0061] The command line mapping table corresponding to the centos operating system is shown in the following table:
[0062]
[0063] The command line mapping table corresponding to the Ubuntu operating system is shown in the following table:
[0064]
[0065] The command line mapping table corresponding to the Fedora operating system is shown in the following table:
[0066]
[0067] It can be understood that after the operating system is heterogeneous, the online heterogeneous executors use different operating systems, different operating systems correspond to different command line mapping tables, and the user command line and the operating system command corresponding to the same mapping ID in the same command line mapping table are different; the operating system command line external user execution permissions of N online heterogeneous executors are pre-shielded. On the one hand, the external user's call to the operating system command is shielded, and on the other hand, the call to the system command is only allowed after the "command line mapping table" is searched.
[0068] It should be noted that due to the heterogeneity of the operating systems of online heterogeneous executors, in most cases, the return results of the operating system command lines of each online heterogeneous executor are often inconsistent. Figure 2 The specific steps of step 4 are shown below:
[0069] Step 401: the arbiter determines whether command execution results sent by N online heterogeneous executors are received within a first preset time period.
[0070] If yes, it is determined that the event adjudication is passed, and the process goes to step 402; otherwise, it is determined that the event adjudication is not passed, and the corresponding online heterogeneous execution body is cleaned;
[0071] Step 402, generating a key value and a custom string content, and generating custom header data head based on the key value and the custom string content; wherein the custom string content includes time information and a custom tag;
[0072] Aggregate the command execution results sent by N online heterogeneous executors to obtain an aggregated execution result;
[0073] Step 403, concatenating the custom header data head and the aggregation execution result to generate a normalized decision result;
[0074] Step 404: Send the normalized decision result to N online heterogeneous executors respectively.
[0075] It can be understood that the arbiter identifies whether the online heterogeneous executors are threatened by determining whether the N online heterogeneous executors issue command execution results within the same time range (within the first preset time period), and no longer compares the data content of the command execution results; if the online heterogeneous executors issue command execution results within the same time range, the arbiter aggregates the N command execution results and generates a normalized arbitration result after aggregation.
[0076] In another specific implementation, three online heterogeneous executors are configured, and the first preset time period is 1 second. If the arbitrator does not simultaneously receive the command execution results sent by the three online heterogeneous executors within 1 second, it is considered that the event arbitration has failed, and the executors that have not normally issued command execution results are cleaned.
[0077] The process of sequentially verifying and executing three online heterogeneous executors (the following three cleanings are sent three times by the same user command line) is as follows:
[0078] (1) For the first time, the arbiter receives the command execution result sent by online heterogeneous executor 1. If it does not receive the command execution results sent by online heterogeneous executor 2 and online heterogeneous executor 3 within 1 second, it assumes that there is a problem with online heterogeneous executor 2. The arbiter notifies the scheduler to clean up online heterogeneous executor 2.
[0079] (2) After the cleaning of online heterogeneous executor 2 is completed for the second time, if the arbiter receives the command execution results sent by online heterogeneous executors 1 and 2 within 1 second, but does not receive the command execution results sent by online heterogeneous executor 3, it is again assumed that there is a problem with online heterogeneous executor 1 and online heterogeneous executor 2, and the scheduler cleans online heterogeneous executors 1 and 2;
[0080] (3) For the third time, if online heterogeneous executors 1 and 2 can still issue command execution results after being cleaned, and have not received command execution results sent by online heterogeneous executor 3, it is considered that there is a problem with online heterogeneous executor 3, and the scheduler cleans online heterogeneous executor 3.
[0081] In another specific implementation, the process of generating the normalized decision result is as follows:
[0082] The user logs in through the client and inputs the user interface provided by the input agent and enters the "show path" command character (user command line). The input agent sends the "show path" command character to the three online heterogeneous executors through the TCP protocol. After receiving the "show path" command character (user command line), the online heterogeneous executor 1 finds the corresponding operating system command "pwd" from the command line mapping table, and then executes the "pwd" command (operating system command), and sends the command execution result " / home / test1" of the "pwd" command to the arbitrator; similarly, the online heterogeneous executor 2 sends the command execution result " / home / test2" to the arbitrator, and the online heterogeneous executor 3 sends the command execution result " / home / test3" to the arbitrator;
[0083] After receiving the command execution results sent by the three online heterogeneous executors, the arbiter determines whether they are received within the first preset time period. If so, the three command execution results are aggregated. If the command execution results of the online heterogeneous executors are A ( / home / test1), B ( / home / test2), and C ( / home / test3), the aggregated normalized decision result is {head, / n / r, nos1:A, / n / r, nos2:B, / n / r, nos3:C}; wherein the custom header data head is custom information, consisting of a unique identifier key value and a custom string content;
[0084] The key value is used to identify that this command line is output by the arbitrator. If the preset algorithm for generating the key value is md5, then key = md5 (nos1:A+nos2:B+nos3:C+mimic), concatenate the nos1:A, nos2:B, nos3:C, and mimic strings, perform md5 operations, and finally generate the key; the custom string content is composed of time+"mimic operationcmd result"; " / n / r" is a line break character;
[0085] Aggregate the command execution results sent by N online heterogeneous executors to obtain the aggregated execution result [nos1:A, / n / r, nos2:B, / n / r, nos3:C];
[0086]
[0087] According to the above generation rules, the normalized decision result of the "pwd" command aggregated by the arbiter is shown in the above table; among them, the custom header data head=key value+custom string content, and the custom string content=time information time and custom label; for example, ab0b4feb5fe18d1b34011dc3b404f5bd is the key value in the custom header data head, 2021-9-28 11:07:08 is the time information time, mimic operation cmd result is the custom label, and the rest is the aggregated execution result.
[0088] It can be understood that the key value is calculated using the MD5 algorithm (under normal circumstances, external users do not know which algorithm is used for verification), and is mainly used to determine whether the content data has been modified. If only the content value is modified, and the verification algorithm is unknown, the generated key value cannot correspond, so as to determine whether the message has been tampered with and identify the user. In order to prevent the modification of the key and content at the same time, the message authentication code can be used.
[0089] It should be noted that the arbiter sends the aggregated normalized arbitrating results to the online heterogeneous executor and finally to the output agent; when the output agent compares and judges the N normalized arbitrating results, it uses the following method: Figure 3 The specific steps of step 6 are shown below:
[0090] Step 601, determining whether the normalized decision results sent by N online heterogeneous executors are received, if yes, go to step 602, otherwise go to step 606;
[0091] Step 602: for each normalized decision result, extract the key value in the custom header data head of the normalized decision result, the custom label in the custom header data head, and the aggregate execution result;
[0092] Generate the Nkey value based on the extracted custom tags and the aggregated execution results, and determine whether the Nkey value is consistent with the extracted key value to verify whether the key value in the corresponding normalized adjudication result is correct;
[0093] If they are consistent, it is determined that the data return function of the corresponding online heterogeneous executor is in a normal state, and the process goes to step 603; otherwise, it is determined that the data return function of the corresponding online heterogeneous executor is in an abnormal state, and the corresponding online heterogeneous executor is cleaned;
[0094] Step 603, determining whether the data return functions of all online heterogeneous execution bodies are in a normal state, if so, extracting the custom string content in the custom header data head of each normalized decision result, and making a decision on the custom string content in the N normalized decision results according to a preset decision strategy;
[0095] When the ruling fails, the corresponding online heterogeneous executor is cleaned;
[0096] When the decision is passed, the content decision result is output and the process goes to step 604;
[0097] Step 604, generating new custom header data Nhead, wherein the new custom header data Nhead is the content adjudication result;
[0098] Step 605, concatenating the new custom header data Nhead and the aggregate execution result to generate a new normalized decision result; wherein the aggregate execution result is an aggregate execution result in the normalized decision result through large number decision;
[0099] Step 606, determine whether the waiting time exceeds the second preset time period, if so, end the waiting, otherwise go to step 601.
[0100] Specifically, since the custom string content includes time (time information) + mimic operation cmdresult (custom label), time (time information) represents the time of command line aggregation, which can be used to estimate the response time of the client request command; the custom string content in the N normalized decision results is decided according to the preset decision strategy, and the following is executed:
[0101] (1) Only the mimic operationcmd result (custom label) in the custom string content of the N normalized decision results is judged as a large number, and the time (time information) is not judged as a large number;
[0102] (2) Time-based decision: The time for command line aggregation is configured to be 1-2S. After the introduction of mimicry, if the time in the custom string content of a normalized decision result is not within the 1-2S time range, the request is considered abnormal and the decision fails. If the time in the custom string content of N normalized decision results is within the 1-2S time range, the decision is considered to pass.
[0103] (3) Combine the decision strategy in (1) with the decision strategy in (2) to make a decision on the custom string content.
[0104] It should be noted that the output agent first determines whether the key value in the custom header data head of each normalized decision result is correct, and generates Nkey value (new key value) again according to the preset algorithm for generating key value (the same method as the arbitrator generates key), and determines whether the Nkey value is equal to the key value in the custom header data head of the normalized decision result:
[0105] If the key verification of an online heterogeneous executor fails, it means that there is a problem with the data return function and the data has been tampered with. The output agent directly notifies the scheduling module to clean the executor that failed the verification:
[0106] When the keys of all online heterogeneous executors are successfully verified, the content is judged. After the judgment is successful, the key value in the custom header data head of any normalized judgment result that passes the majority judgment is stripped to generate a new custom header data Nhead, and then the new custom header data Nhead + aggregated execution result is sent to the user.
[0107] It should be noted that the key value in the custom header data head of the normalized decision result is stripped because the key value is only used to verify whether the content data has been tampered with in the link from the decider to the output agent, so the key value does not need to be exposed to the user.
[0108] Example 2
[0109] Based on Example 1, this example provides a specific implementation method of an operating system command line configuration system in a mimicking environment;
[0110] As attached Figure 4As shown, the operating system command line configuration system under the mimic environment includes N online heterogeneous executors, each of which includes a command line receiver, a command line mapping table memory, a command executor, a command execution result outputter and a command line echoer, the command line mapping table memory is used to pre-store a command line mapping table, the command line mapping table is a mapping relationship table between a user command line and an operating system command, and the command executor is configured to shield the execution permission status of an external user of the operating system command line;
[0111] The command line receiver is configured to: monitor in real time whether a user command line is received from the input agent, and in response to the received user command line, search for an operating system command corresponding to the user command line from a pre-stored command line mapping table, and transmit the command to the command executor;
[0112] The command executor is configured to: not directly execute the received user command line, but execute the found operating system command, obtain the command execution result corresponding to the operating system command, and transmit the command execution result to the command execution result outputter;
[0113] The command execution result outputter is configured to: send the command execution result to the arbiter, monitor in real time whether a normalized ruling result is received from the arbiter, and transmit the received normalized ruling result to the command line echoer; wherein the normalized ruling result is data generated by aggregating the command execution results sent by N online heterogeneous executors when the event ruling is passed by the arbiter;
[0114] The command line echoer is configured to transmit the received normalized decision result to the output agent for display.
[0115] Specifically, the input proxy implements the proxy of ssh, telnet, and serial protocols. On the one hand, it provides a user input / output interface to external users, and on the other hand, it forwards the commands entered by the user (user command line) to the back-end online heterogeneous executor. In order to maintain the consistency of the back-end protocol, TCP is uniformly used between the input proxy and the online heterogeneous executor for communication, and ssh, telnet, and serial protocols are flexibly selected for communication with external users.
[0116] Furthermore, the operating system command line configuration system in the mimic environment also includes an output agent, which is configured as follows:
[0117] After receiving the normalized decision results sent by the N online heterogeneous executors, verifying the data return function of the corresponding online heterogeneous executors based on the normalized decision results;
[0118] When it is determined that the data return function of a certain online heterogeneous executor is in an abnormal state, the corresponding online heterogeneous executor is cleaned;
[0119] When it is determined that the data return functions of all online heterogeneous execution bodies are in a normal state, the N normalized decision results are decided; after the decision is passed, a new normalized decision result is generated, and the new normalized decision result is forwarded to the client.
[0120] Furthermore, the operating system command line configuration system in the mimicking environment also includes a arbitrator, which is configured to:
[0121] Determine whether command execution results sent by N online heterogeneous executors are received within a first preset time period,
[0122] If yes, the event is judged to be adjudicated, a key value and a custom string content are generated, and custom header data head is generated based on the key value and the custom string content; the command execution results sent by N online heterogeneous executors are aggregated to obtain an aggregated execution result; the custom header data head and the aggregated execution result are concatenated to generate a normalized adjudication result, and the normalized adjudication result is sent to the N online heterogeneous executors respectively; wherein the custom string content includes time information and a custom tag;
[0123] Otherwise, the event adjudication is determined to have failed, and the corresponding online heterogeneous executor is cleaned.
[0124] Furthermore, when generating a new normalized decision result, the output agent is configured to:
[0125] Determine whether the normalized decision results sent by N online heterogeneous executors are received,
[0126] If the normalized decision results sent by N online heterogeneous executors are received, then:
[0127] For each normalized decision result, extract the key value in the custom header data head of the normalized decision result, the custom label in the custom header data head, and the aggregated execution result respectively; generate the Nkey value based on the extracted custom label and the aggregated execution result, and determine whether the Nkey value is consistent with the extracted key value. If they are consistent, determine that the data return function of the corresponding online heterogeneous executor is in a normal state; otherwise, determine that the data return function of the corresponding online heterogeneous executor is in an abnormal state, and clean the corresponding online heterogeneous executor;
[0128] Determine whether the data return function of all online heterogeneous execution bodies is in a normal state, and if so, judge the custom character string content in the N normalized judgment results according to the preset judgment strategy; when the judgment is passed, generate new custom header data Nhead, wherein the new custom header data Nhead is the content judgment result;
[0129] The new custom header data Nhead and the aggregate execution result are concatenated to generate a new normalized decision result; wherein the aggregate execution result is an aggregate execution result in the normalized decision result through large number decision;
[0130] If the normalized decision result sent by the N online heterogeneous executors is not received, then: determine whether the waiting time exceeds the second preset time period, if so, end the waiting, otherwise re-determine whether the normalized decision result sent by the N online heterogeneous executors is received.
[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or some technical features can be replaced by equivalents without departing from the spirit of the technical solution of the present invention, which should be included in the scope of the technical solution for protection of the present invention.
Claims
1. A command line configuration method for an operating system in a mimicking environment. Features: The following steps are involved: Step 1: pre-store command line mapping tables in N online heterogeneous execution bodies respectively, and shield the external user execution permissions of the operating system command lines of the N online heterogeneous execution bodies respectively; The command line mapping table is a mapping relationship table between user command lines and operating system commands; Step 2: N online heterogeneous executors respectively monitor in real time whether they have received a user command line from the input agent; In response to the received user command line, searching a pre-stored command line mapping table for an operating system command corresponding to the user command line; Step 3, after finding the operating system command corresponding to the user command line, the corresponding online heterogeneous execution body runs the found operating system command, obtains the command execution result corresponding to the operating system command, and sends the command execution result to the arbitrator; Step 4, the arbiter receives the command execution results sent by N online heterogeneous executors, and makes event decisions based on the received command execution results; When the event adjudication is passed, the adjudicator aggregates the command execution results sent by the N online heterogeneous executors to generate a normalized adjudication result, and sends the normalized adjudication result to the N online heterogeneous executors respectively; The step 4 specifically includes: Step 401: the arbiter determines whether command execution results sent by N online heterogeneous executors are received within a first preset time period. If yes, it is determined that the event adjudication is passed, and the process goes to step 402; otherwise, it is determined that the event adjudication is not passed, and the corresponding online heterogeneous execution body is cleaned; Step 402, generating a key value and a custom string content, and generating custom header data head based on the key value and the custom string content; wherein the custom string content includes time information and a custom tag; Aggregate the command execution results sent by N online heterogeneous executors to obtain an aggregated execution result; Step 403, concatenating the custom header data head and the aggregation execution result to generate a normalized decision result; Step 404, sending the normalized decision result to N online heterogeneous executors respectively; Step 5, N online heterogeneous executors respectively monitor in real time whether they have received the normalized decision result from the arbitrator; In response to the received normalized decision result, the corresponding online heterogeneous executor returns the normalized decision result to the output agent; Step 6, after receiving the normalized decision results sent by the N online heterogeneous executors, the output agent verifies the data return function of the corresponding online heterogeneous executors based on the normalized decision results; When it is determined that the data return functions of all online heterogeneous execution bodies are in a normal state, adjudicating the N normalized adjudication results; After the ruling is passed, a new normalized ruling result is generated and the process goes to step 7; The step 6 specifically includes: Step 601, determining whether the normalized decision results sent by N online heterogeneous executors are received, if yes, go to step 602, otherwise go to step 606; Step 602: for each normalized decision result, extract the key value in the custom header data head of the normalized decision result, the custom label in the custom header data head, and the aggregate execution result; Generate the Nkey value based on the extracted custom tags and aggregation execution results, and determine whether the Nkey value is consistent with the extracted key value; If they are consistent, it is determined that the data return function of the corresponding online heterogeneous executor is in a normal state, and the process goes to step 603; otherwise, it is determined that the data return function of the corresponding online heterogeneous executor is in an abnormal state, and the corresponding online heterogeneous executor is cleaned; Step 603, determining whether the data return functions of all online heterogeneous execution bodies are in a normal state, and if so, judging the user-defined character string content in the N normalized judgment results according to a preset judgment strategy; When the ruling fails, the corresponding online heterogeneous executor is cleaned; When the decision is passed, the content decision result is output and the process goes to step 604; Step 604, generating new custom header data Nhead, wherein the new custom header data Nhead is the content adjudication result; Step 605, concatenating the new custom header data Nhead and the aggregate execution result to generate a new normalized decision result; wherein the aggregate execution result is an aggregate execution result in the normalized decision result through large number decision; Step 606, determine whether the waiting time exceeds the second preset time period, if so, end the waiting, otherwise go to step 601; Step 7: The output agent forwards the new normalized decision result to the client.
2. A command line configuration system for operating systems in a mimicking environment, Features: It includes N online heterogeneous executors, each of which includes a command line receiver, a command line mapping table memory, a command executor, a command execution result outputter and a command line echoer, the command line mapping table memory is used to pre-store a command line mapping table, the command line mapping table is a mapping relationship table between a user command line and an operating system command, and the command executor is configured to shield the execution permission status of an external user of the operating system command line; The command line receiver is configured to: monitor in real time whether a user command line is received from the input agent, and in response to the received user command line, search for an operating system command corresponding to the user command line from a pre-stored command line mapping table, and transmit the command to the command executor; The command executor is configured to: not directly execute the received user command line, but to execute the found operating system command, obtain the command execution result corresponding to the operating system command, and transmit the command execution result to the command execution result outputter; The command execution result outputter is configured to: send the command execution result to the arbiter, monitor in real time whether a normalized ruling result is received from the arbiter, and transmit the received normalized ruling result to the command line echoer; wherein the normalized ruling result is data generated by aggregating the command execution results sent by N online heterogeneous executors when the event ruling is passed by the arbiter; The command line echoer is configured to transmit the received normalized decision result to the output agent.
3. According to the system for configuring the operating system command line in a virtual environment according to claim 2, Features: Also included is an output agent, which is configured to: After receiving the normalized decision results sent by the N online heterogeneous executors, verifying the data return function of the corresponding online heterogeneous executors based on the normalized decision results; When it is determined that the data return function of a certain online heterogeneous executor is in an abnormal state, the corresponding online heterogeneous executor is cleaned; When it is determined that the data return functions of all online heterogeneous execution bodies are in a normal state, the N normalized decision results are decided; after the decision is passed, a new normalized decision result is generated, and the new normalized decision result is forwarded to the client.
4. According to claim 3, the operating system command line configuration system in a mimic environment, Features: Also included is an arbiter configured to: Determine whether command execution results sent by N online heterogeneous executors are received within a first preset time period, If yes, the event is judged to be adjudicated, a key value and a custom string content are generated, and custom header data head is generated based on the key value and the custom string content; the command execution results sent by N online heterogeneous executors are aggregated to obtain an aggregated execution result; the custom header data head and the aggregated execution result are concatenated to generate a normalized adjudication result, and the normalized adjudication result is sent to the N online heterogeneous executors respectively; wherein the custom string content includes time information and a custom tag; Otherwise, the event adjudication is determined to have failed, and the corresponding online heterogeneous executor is cleaned.
5. According to the system for configuring the operating system command line in a virtual environment according to claim 4, Features: When generating a new normalized decision result, the output agent is configured to: Determine whether the normalized decision results sent by N online heterogeneous executors are received, If the normalized decision results sent by N online heterogeneous executors are received, then: For each normalized decision result, extract the key value in the custom header data head of the normalized decision result, the custom tag in the custom header data head, and the aggregated execution result; generate an Nkey value based on the extracted custom tag and the aggregated execution result, and determine whether the Nkey value is consistent with the extracted key value. If they are consistent, it is determined that the data return function of the corresponding online heterogeneous execution body is in a normal state; Otherwise, it is determined that the data return function of the corresponding online heterogeneous executor is in an abnormal state, and the corresponding online heterogeneous executor is cleaned; Determine whether the data return function of all online heterogeneous execution bodies is in a normal state, and if so, adjudicate the custom character string content in the N normalized adjudication results according to a preset adjudication strategy; when the adjudication is passed, generate new custom header data Nhead, wherein the new custom header data Nhead is the content adjudication result; The new custom header data Nhead is concatenated with the aggregation execution result to generate a new normalized decision result; The aggregate execution result is the aggregate execution result of the normalized decision result through the large number decision; If the normalized decision result sent by the N online heterogeneous executors is not received, then: determine whether the waiting time exceeds the second preset time period, if so, end the waiting, otherwise re-determine whether the normalized decision result sent by the N online heterogeneous executors is received.
Citation Information
Patent Citations
Mimicry distribution system and method and medium
CN111083113A
Mimic defense system based on certificate identity authentication, and certificate issuing method
WO2021179449A1