Multi-metric system trustworthy verification method, device, computer equipment and storage medium
By detecting the communication information between programs when the system is running, pausing the program to be detected and obtaining its behavioral characteristic status, and using preset characteristic functions for trustworthy verification, the problem of reduced security of system credibility after multi-channel data access is solved, and the effect of dynamically improving system security is achieved.
Patent Information
- Application Number
- CN202111675610.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-31
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2041-12-31
AI Technical Summary
The existing system trustworthiness verification method performs measurements before the system is started, which causes the system trustworthiness to be affected after the access of multi-channel external data, thereby reducing security.
The measurement trigger table is queried through the communication information between the detection programs, the program to be detected is paused and its behavioral feature state is obtained, the preset feature function is used to obtain the predicted behavioral feature state, and the credibility value is determined after comparison for verification.
It improves the security of the system during program execution, dynamically detects the credibility of the program, and enhances the protection of the system.
Smart Images

Figure CN114491551B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method, apparatus, computer device, and storage medium for authenticating a multi-metric system. Background Art
[0002] In recent years, internet technology has rapidly developed, and various industries have gradually undergone digital transformation. With the integration of smart terminals, mobile devices, and monitoring devices, digital platforms are gradually gathering vast amounts of digital resources. Through access and analysis of these digital resources, network service simulations can be achieved. All data is exposed to the internet and its transmission space. Data access, exchange, communication, and system input and output all introduce various types of data attacks. External dangers abound in the internet environment, posing significant threats to data privacy, integrity, and security. Therefore, trusted network and platform security mechanisms have been proposed within the internet architecture to prevent untrusted data entities and processes from running in the system and maintain environmental security. Therefore, measuring the trustworthiness of a system has become a key research issue.
[0003] Currently, the method for verifying the credibility of a system is usually to measure the security of the initial environment before the system is started. When external data from multiple channels is connected, the trusted environment of the system will be affected and change. Changes caused by some transmission effects of real-time processes will make the system untrustworthy and reduce system security.
[0004] Therefore, the current system trust verification method has the defect of insufficient security. Summary of the Invention
[0005] Based on this, it is necessary to provide a multi-metric system trusted verification method, device, computer equipment and storage medium that can improve security in response to the above technical problems.
[0006] A method for verifying the credibility of a multi-metric system, the method comprising:
[0007] Upon detecting that a program to be detected satisfies a measurement trigger condition, suspending a detection program communicating with the program to be detected and obtaining a current behavioral characteristic state of the program to be detected based on the detection program; the measurement trigger condition is determined by querying a measurement trigger table based on communication information between the program to be detected and the detection program; the measurement trigger table includes a correspondence between communication information of multiple programs and trigger conditions;
[0008] Obtaining a predicted behavior characteristic state of the program to be detected according to a preset characteristic function;
[0009] According to the comparison result of the current behavior feature state and the predicted behavior feature state, the credibility value of the program to be detected is obtained, and the credibility verification of the program to be detected is performed based on the credibility value.
[0010] In one embodiment, the method further comprises:
[0011] In response to startup information of the system where the program to be detected is located, obtaining program code of the program in the system, and extracting corresponding multiple pieces of dishonesty evidence based on the program code;
[0012] Merging the same type of breach of trust evidence among the plurality of breach of trust evidences to obtain a plurality of characteristic attributes;
[0013] For each of the characteristic attributes, obtaining a characteristic credibility value corresponding to the characteristic attribute based on the number of pieces of dishonesty evidence corresponding to the characteristic attribute and the attribute influence factor corresponding to the characteristic attribute;
[0014] An initial credibility value of the program code is determined based on the plurality of feature credibility values, and a program corresponding to a program code having an initial credibility value greater than or equal to a preset credibility threshold is used as the program to be detected.
[0015] In one embodiment, for each of the characteristic attributes, obtaining a characteristic credibility value corresponding to the characteristic attribute according to the number of pieces of untrustworthy evidence corresponding to the characteristic attribute and the attribute influence factor corresponding to the characteristic attribute includes:
[0016] For each of the characteristic attributes, obtaining the attribute influence factor corresponding to the characteristic attribute according to the ratio of the influence factor parameter corresponding to the characteristic attribute and the attribute weight corresponding to the characteristic attribute;
[0017] The feature credibility value corresponding to the feature attribute is obtained according to an exponential function with the product of the attribute influence factor and the number of untrustworthy evidences corresponding to the feature attribute as an exponent.
[0018] In one embodiment, the method further comprises:
[0019] Obtain multiple preset malicious codes;
[0020] For each of the preset malicious codes, insert the preset malicious code into the program to be detected, and obtain the running result of the program to be detected for the preset malicious code;
[0021] Obtaining a predicted running result of the program to be detected for the malicious code output by the detection program;
[0022] Obtain a comparison result between the operation result and the predicted operation result. If the comparison result is passed, determine the corresponding feature matching degree according to the operation result and the predicted operation result, and generate the metric trigger table according to the multiple feature matching degrees.
[0023] In one embodiment, determining the corresponding feature matching degree according to the operation result and the predicted operation result, and generating the metric trigger table according to the plurality of feature matching degrees includes:
[0024] Obtaining an initial characteristic value corresponding to the program to be detected according to the running result;
[0025] Obtaining, based on the initial characteristic value, a characteristic matching degree between the operation result and the predicted operation result;
[0026] If the feature matching degree is greater than a preset matching degree threshold, determining that the program to be detected has passed the measurement of the preset malicious code, and generating a detection trigger time for the preset malicious code;
[0027] The metric trigger table is generated according to the plurality of preset malicious codes and the plurality of detection trigger times.
[0028] In one embodiment, after performing credibility verification on the program to be detected based on the credibility value, the method further includes:
[0029] If the program to be detected passes the trustworthy verification, performing a trustworthiness attribute check on the system according to the initial characteristic value of the program to be detected, the output isolation degree of the program to be detected, and a plurality of trustworthiness values corresponding to the program to be detected;
[0030] If the credibility attribute verification result is passed, obtaining an information flow corresponding to the communication between the program to be detected and the detection program; the information flow includes a plurality of behavioral features of the program to be detected and the detection program;
[0031] Inputting the information flow into a finite automaton, replacing unobservable behavioral features in the information flow with preset security and trustworthy features through the finite automaton, and obtaining an initial value of the finite automaton;
[0032] converting the state of the finite automaton to form a trusted state subset corresponding to the initial value;
[0033] According to each behavior feature in the trusted state subset, the trusted verification result of the program to be detected is checked.
[0034] In one embodiment, the performing of a credibility attribute verification on the system based on the initial credibility value, the output isolation of the program to be detected, and multiple credibility values corresponding to the program to be detected includes:
[0035] Obtaining a comparison result between the initial characteristic value and a preset credibility threshold;
[0036] Respectively obtaining the actual behavior characteristics and the predicted behavior characteristics output by the program to be tested and the testing program for the same system state;
[0037] Obtaining multiple continuous credibility values output by the program to be tested based on multiple continuous credibility verifications, and respectively obtaining comparison results of the multiple continuous credibility values with preset credibility thresholds;
[0038] If the initial feature value is greater than a preset credibility threshold, the actual behavior feature is consistent with the predicted behavior feature, and the multiple consecutive credibility values are all greater than the preset credibility threshold, it is determined that the credibility attribute verification has passed.
[0039] A multi-metric system trustworthy verification device, the device comprising:
[0040] a response module configured to detect that a program to be detected satisfies a measurement trigger condition, suspend a detection program communicating with the program to be detected, and obtain a current behavioral characteristic state of the program to be detected based on the detection program; the measurement trigger condition is determined by querying a measurement trigger table based on communication information between the program to be detected and the detection program; the measurement trigger table includes a correspondence between communication information of multiple programs and trigger conditions;
[0041] An acquisition module, configured to acquire a predicted behavior characteristic state of the program to be detected according to a preset characteristic function;
[0042] The detection module is used to obtain the credibility value of the program to be detected based on the comparison result of the current behavior feature state and the predicted behavior feature state, and perform credibility verification on the program to be detected based on the credibility value.
[0043] A computer device includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.
[0044] A computer-readable storage medium stores a computer program, which implements the steps of the above method when executed by a processor.
[0045] The above-mentioned multi-metric system trust verification method, device, computer equipment and storage medium, when detecting that the program to be detected meets the measurement trigger condition based on the communication information between programs during the operation of the software process, suspends the detection program that communicates with the program to be detected and obtains the current behavior characteristic state of the program to be detected according to the detection program, and obtains the predicted behavior characteristic state of the program to be detected according to the preset characteristic function, and then obtains the credibility value of the program to be detected based on the comparison result between the current behavior characteristic state and the predicted behavior characteristic state, and performs trustworthy verification on the program to be detected based on the credibility value. Compared with the traditional method of measuring the initial environment security only before the system is started. This solution improves the security of the system where the program is located by performing trustworthy verification on these programs when the program in the system is running and the program's running information is detected to meet the trigger condition of trustworthy verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 1 is a flow chart of a method for verifying the trustworthiness of a multi-metric system in one embodiment;
[0047] Figure 2 A schematic diagram of the structure of a multi-metric system trustworthy verification model in one embodiment;
[0048] Figure 3 1. A schematic diagram of a flow chart of static trustworthy verification steps of a multi-metric system in one embodiment;
[0049] Figure 4 A schematic diagram of the structure of an active link trust model in one embodiment;
[0050] Figure 5 A schematic flow chart of a multi-metric system trustworthiness verification step in another embodiment;
[0051] Figure 6 A structural block diagram of a multi-metric system trustworthy verification device in one embodiment;
[0052] Figure 7 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0053] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0054] In one embodiment, Figure 1As shown, a method for verifying the trustworthiness of a multi-metric system is provided. This embodiment uses the method applied to a terminal as an example. It is understood that the method can also be applied to a server, or to a system including a terminal and a server, and implemented through interaction between the terminal and the server. In this embodiment, the method includes the following steps:
[0055] Step S202, it is detected that the program to be detected meets the measurement trigger condition, the detection program communicating with the program to be detected is suspended and the current behavioral feature state of the program to be detected is obtained according to the detection program; the measurement trigger condition is determined by querying the measurement trigger table based on the communication information between the program to be detected and the detection program; the measurement trigger table includes the correspondence between the communication information of multiple programs and the trigger conditions.
[0056] The program to be tested can be a program requiring trusted verification. The program to be tested can be a program running in a system that may include multiple programs. During runtime, these programs communicate with each other through processes, generating corresponding information flows, such as communication information. The terminal can then determine whether trusted verification of the program is required based on the communication information between programs in the system. For example, the terminal can detect the information flows between programs in the system. When the communication information in the information flow meets the trigger conditions in a pre-defined measurement trigger table, the terminal can initiate a trusted verification process. In this verification process, the program receiving the communication information can serve as the program being tested, or the measured, and the program sending the communication information can serve as the testing program, or the measurer. The measurement trigger table can include a correspondence between the communication information of multiple programs and the trigger conditions. This means that the terminal can dynamically detect programs as they run in the system and, when the trusted verification trigger conditions are met, perform real-time trusted verification on the corresponding programs.
[0057] When the trusted verification process is initiated, the terminal can suspend the detection program that is communicating with the program to be detected, for example, by suspending all processes of the detection program. Furthermore, the terminal can obtain the current behavioral characteristic state of the program to be detected, for example, by using a measurement characteristic calculation function to find the characteristic state of the measured object from the measurer, that is, to find the current behavioral characteristic state of the detected program from the detection program. This current behavioral characteristic state can be the detected program's response to received communication information, such as the different types of performance characteristics reflected when the detected program is attacked by multiple unexpected behaviors.
[0058] Step S204: obtaining the predicted behavior characteristic state of the program to be detected according to the preset characteristic function.
[0059] Among them, the preset characteristic function can be a function used to calculate action characteristics. When the terminal performs trustworthy verification on the detected program, it needs to predict the next expected action state characteristics corresponding to the current behavioral characteristic state of the detected program. The terminal can calculate the next expected action state characteristics of the current person being measured based on the characteristic function, that is, the terminal can obtain the predicted behavioral characteristic state of the program to be detected based on the characteristic function.
[0060] Step S206 , obtaining a credibility value of the program to be detected based on the comparison result between the current behavior feature state and the predicted behavior feature state, and performing credibility verification on the program to be detected based on the credibility value.
[0061] After obtaining the current behavior feature state of the program being tested and the next predicted behavior feature state of the program being tested, the terminal can compare the current behavior feature state with the predicted behavior feature state. The terminal can obtain the comparison result of the above comparison and, based on the comparison result, obtain the credibility value of the program being tested. The terminal can then perform credibility verification on the program being tested based on the credibility value to determine whether the program being tested is trustworthy. For example, since the measured objects that need to be measured during the dynamic credibility verification process are all in a paused state, the credibility of the measured points can be calculated using the static measurement calculation method. That is, the terminal can determine whether the range of the current behavior feature state and the predicted behavior feature state are consistent. The terminal can then determine the credibility value of the program being tested based on the degree of consistency between the current behavior feature state and the predicted behavior feature state. The terminal can then judge the calculated credibility value. If the calculated credibility value is within the credibility value range, the terminal can output an evaluation report; if it is not within the credibility value range, the terminal can optimize the feature library and adjust and optimize the network status parameters. The feature library contains various types of behavioral features generated by the program for various types of communication information.
[0062] In the above-mentioned multi-metric system trust verification method, when the program to be detected meets the measurement trigger condition based on the communication information between programs during the operation of the software process, the detection program that communicates with the program to be detected is suspended and the current behavior characteristic state of the program to be detected is obtained according to the detection program, and the predicted behavior characteristic state of the program to be detected is obtained according to the preset characteristic function, and then the credibility value of the program to be detected is obtained based on the comparison result between the current behavior characteristic state and the predicted behavior characteristic state, and the program to be detected is trusted and verified based on the credibility value. Compared with the traditional method of measuring the initial environment security only before the system is started. This solution improves the security of the system where the program is located by performing trust verification on these programs when the program's running information is detected to meet the trigger condition of trust verification when the program is running in the system.
[0063] In one embodiment, the method further includes: in response to startup information of a system where a program to be detected is located, obtaining program code of the program in the system, and extracting corresponding multiple pieces of evidence of default based on the program code; merging the same type of evidence of default among the multiple pieces of evidence of default to obtain multiple characteristic attributes; for each characteristic attribute, obtaining a characteristic credibility value corresponding to the characteristic attribute based on the number of pieces of evidence of default corresponding to the characteristic attribute and the attribute influence factor corresponding to the characteristic attribute; determining an initial credibility value of the program code based on the multiple characteristic credibility values, and taking the program corresponding to the program code whose initial credibility value is greater than or equal to a preset credibility threshold as the program to be detected.
[0064] In this embodiment, before the terminal performs real-time dynamic trust verification, it also needs to perform initial trust verification on each program in the system. Figure 2 As shown, Figure 2 This is a schematic diagram of the structure of a multi-metric system trust verification model in one embodiment. The process of terminal trust verification includes static verification and dynamic verification. Static verification can be performed during system initialization, and dynamic verification can be performed during program execution. This allows for multi-level trust testing of the network and system, meeting the security detection requirements of the system's initial state and dynamic processes, and providing a multi-angle trust measurement method. The conclusions of the static and dynamic verifications are interconnected. The dynamic process can only be further executed if the conclusion of the static part is trustworthy. The dynamic part initiates the trust check based on the instructions given by the static part. The conclusion of the dynamic part can reflect different types of performance characteristics reflected by various unexpected behavioral attacks on the software or program during operation. Some of these characteristics exist in the existing feature library, while some are new features. The trusted feature template library should evaluate the conclusions, re-import the new features, and transmit them to the static trust module. The static part adjusts the existing detection code according to the actual situation to avoid the situation where the dynamic link is untrustworthy due to the untrustworthy initialization state.
[0065] Upon detecting the startup information of the system containing the program to be detected, the terminal can obtain the program code of each program in the system and, based on the program code, extract multiple pieces of untrustworthy evidence for the program to be detected. The untrustworthy evidence is composed of multiple dimensions of network feature slices. The terminal can merge pieces of untrustworthy evidence of the same type from the multiple pieces of untrustworthy evidence, thereby obtaining multiple characteristic attributes. For each characteristic attribute, the terminal can obtain a corresponding feature credibility value based on the number of pieces of untrustworthy evidence corresponding to the characteristic attribute and the attribute influence factor corresponding to the characteristic attribute. The terminal can perform the above process for each of the multiple characteristic attributes to obtain feature credibility values, thereby determining the initial credibility value of the program code based on the multiple feature credibility values. The attribute influence factor of the characteristic attribute can include an influence factor parameter and an attribute weight. The terminal can also select programs corresponding to program codes with initial credibility values greater than or equal to a preset credibility threshold as the program to be detected. In other words, only programs that pass the initial credibility verification can undergo dynamic credibility verification during actual operation.
[0066] Specifically, if Figure 3 As shown, Figure 3 The following is a flow chart of the static trust verification steps of a multi-metric system in one embodiment. When the terminal performs static trust verification, the static part adopts the following method: Figure 3 The multi-dimensional untrustworthy attribute measurement model shown in the figure compiles the trusted detection source code based on the network characteristic attributes. The terminal can also adjust the trusted detection reference parameters based on the conclusions of dynamic detection. When the network is just started, static trusted detection needs to be started. The terminal can extract the detection code and extract the untrustworthy evidence from it. The untrustworthy evidence is composed of multiple dimensions of network characteristic slices. Multiple pieces of evidence of the same type can be combined into a certain characteristic attribute. Each attribute is set with an attribute correlation parameter based on its connection relationship with the credibility, which is generally expressed as a weight. Finally, the weight values of multiple untrustworthy attributes are calculated to obtain the network initialization credibility value.
[0067] The feature credibility value may be calculated using a function consisting of the number of untrustworthy evidences associated with the feature attribute and the attribute influence factor corresponding to the feature attribute. For example, in one embodiment, for each feature attribute, the feature credibility value corresponding to the feature attribute is obtained based on the number of untrustworthy evidences associated with the feature attribute and the attribute influence factor corresponding to the feature attribute. This includes: for each feature attribute, obtaining the attribute influence factor corresponding to the feature attribute based on the ratio of the influence factor parameter corresponding to the feature attribute and the attribute weight corresponding to the feature attribute; and obtaining the feature credibility value corresponding to the feature attribute based on an exponential function whose exponent is the product of the attribute influence factor and the number of untrustworthy evidences associated with the feature attribute.
[0068] In this embodiment, each characteristic attribute may be composed of multiple pieces of untrustworthy evidence, and the terminal may obtain the attribute influence factor corresponding to each characteristic attribute based on the ratio of the influence factor parameter corresponding to the characteristic attribute and the attribute weight corresponding to the characteristic attribute. In addition, the terminal may also obtain the characteristic credibility value corresponding to the characteristic attribute based on an exponential function with the product of the attribute influence factor and the number of untrustworthy evidence corresponding to the characteristic attribute as an exponential. For example, for the trustworthy verification of the system, the key to the static partial trustworthy test is the definition of the functional relationship between the credibility and the number of untrustworthy evidence affecting the attribute, and generally the more untrustworthy evidence there is, the lower the credibility of the attribute, and the lower the final comprehensive credibility level. The greater the impact of untrustworthy evidence on the attribute, the faster the attribute decreases as the number of untrustworthy evidence increases. Then the terminal may set the number of untrustworthy evidence to be n i , the attribute credibility under the breach of trust evidence is u i , the relationship between the two is expressed as: Among them, λ i is the i-th attribute influencing factor of the breach of trust evidence, with a value less than 1, n i is the number of breach of trust evidences that affect the i-th attribute. The impact factor λ of breach of trust evidence on attribute credibility is inversely proportional to the attribute weight α, which can be expressed as:
[0069]
[0070] Because the relationship between dishonesty and credibility is inverse, so a i The weight of the i-th attribute is expressed as k i The influence factor parameter of the i-th attribute is inversely proportional to . Therefore, the terminal can convert the above expression of credibility and the number of breach of trust evidence into:
[0071]
[0072] Static trust models typically use known attribute weights based on historical test results. When k decreases, attribute credibility changes slowly; as k increases, evidence of breach of trust decreases, leading to lower credibility. Terminals can customize the attribute types in static trust models based on network and system characteristics, typically including functionality, reliability, maintainability, and survivability, and define weights for each attribute. Static trust models are compiled into software code, which allows terminals to reflect the mapping between different attributes and breach of trust evidence, as well as the assigned mapping weights. When a terminal receives a static trust check request, it launches the check code once and inputs it into the network, concurrently testing the trustworthiness of various modules and components. The output trust report includes information such as errors, warnings, and coding scores. Errors indicate processes and results that affect network operation; warnings provide recommendations to prevent defensive programming practices; and coding scores provide suggestions for coding formatting and other issues, such as unused functions and duplicate code. The terminal can also be equipped with expansion units to test and supplement more types of breach of trust evidence, continuously improve the detection code function, and ultimately form a dynamic breach of trust evidence library that can store and check breach of trust evidence. The checked breach of trust evidence is stored in the breach of trust evidence library. If breach of trust evidence with the same description already exists, the old breach of trust evidence can be replaced with the new one, so that the breach of trust evidence library is updated in real time.
[0073] Through the above embodiment, the terminal can perform initial trust verification when the system network is started, and only programs that pass the initial trust verification can perform dynamic trust verification, thereby improving the security of system operation.
[0074] In one embodiment, it also includes: obtaining multiple preset malicious codes; for each preset malicious code, inserting the preset malicious code into the program to be detected, and obtaining the running result of the program to be detected for the preset malicious code; obtaining the predicted running result of the program to be detected for the malicious code output by the detection program; obtaining the comparison result of the running result and the predicted running result, if the comparison result is passed, determining the corresponding feature matching degree according to the running result and the predicted running result, and generating a measurement trigger table according to the multiple feature matching degrees.
[0075] In this embodiment, the static trust verification performed by the static trust model is mainly used to test and verify the state of network and system initialization. However, different types of security risks will be introduced during the execution of different network processes. The static model cannot continuously deal with multiple types of dynamic risks. Therefore, a dynamic trust model is also included, such as Figure 4 As shown, Figure 4The figure is a structural diagram of the active link trust model in one embodiment. The dynamic trust model can perform trust analysis on the business chain of the process execution progress step by step, obtain the trustworthiness of the trust chain, and thus determine the dynamic comprehensive trust status of the network. The object of the dynamic trust model test set in the terminal is the information flow of the interaction between entities. Multiple process access requests may be issued in parallel during the same period, and the recipient may receive multiple information flows. Once the entity process is indirectly interfered with by the system or outside, it will generate unexpected access actions, thereby destroying the trust chain between entities. By capturing the characteristics of the destructive behavior and establishing a process access trust policy, the terminal can avoid the transmission of interference relationships, thereby improving the credibility of the system.
[0076] The terminal can pre-establish a metric trigger table to determine the timing for active trust verification of programs in the system. Since the metric trigger table includes the correspondence between communication information and trigger conditions, and the situation that triggers trust verification is usually when unexpected malicious behavior is inserted into the communication between the detected program and the detection program, the terminal can establish a metric trigger table based on the preset malicious behavior. The terminal can obtain multiple preset malicious codes and, for each preset malicious code, insert the preset code into the program to be detected, obtaining the execution result of the program to be detected in response to the preset malicious code. The terminal can also obtain a predicted execution result output by the detection program that communicates with the program to be detected. The predicted execution result can be the execution result of how the detection program predicts the program to be detected will respond to the malicious code. The terminal can also compare the above execution result with the predicted execution result to obtain a corresponding comparison result. If the comparison result is passed, for example, the deviation between the execution result and the predicted execution result is within a certain range, the terminal can determine the corresponding feature matching degree based on the execution result and the predicted execution result. The terminal can obtain multiple feature matching degrees based on the above multiple preset malicious codes, and thus the terminal can generate a metric trigger table based on the multiple feature matching degrees. Thus, the terminal can perform real-time dynamic trust verification on the programs in the system based on the measurement trigger table.
[0077] The aforementioned feature extraction involves using system software testing to perform trustworthy checks on a large number of historical behaviors. Information flow objects are designed as metric and measured objects based on the detection relationship. For example, the program being tested can be the measured object, and the testing program communicating with the program being tested can be the metric. The terminal then damages the measured object by setting a series of unexpected attack behaviors, identifying its behavioral responses and thereby setting reasonable initial measurement values. The real-time trust measurement solution then performs dynamic trust measurement in three layers: prediction, feature extraction, and active trust measurement. For example, the terminal can pre-generate measurement point values. During the initial measurement value pre-generation phase, malicious behaviors can be inserted into the software in the form of software code. Each behavior executed by the software generates a measurement event, enabling the metric to perform trust measurement. The terminal can aggregate the results of multiple measurement point operations to form a system preset point initial state set, completing the functional initialization of the measurement points and evaluating the operational state changes of the loaded measured points.
[0078] Through this embodiment, the terminal can obtain the feature matching degree based on the preset malicious code, thereby obtaining a measurement trigger table based on the feature matching degree, and perform trustworthy verification on the program in the system based on the measurement trigger table, thereby improving the security of the system.
[0079] In one embodiment, the corresponding feature matching degree is determined according to the running result and the predicted running result, and a measurement trigger table is generated according to multiple feature matching degrees, including: obtaining the initial feature value corresponding to the program to be detected according to the running result; obtaining the feature matching degree between the running result and the predicted running result according to the initial feature value; if the feature matching degree is greater than a preset matching degree threshold, determining that the program to be detected has passed the measurement of the preset malicious code, and generating a detection trigger time for the preset malicious code; generating a measurement trigger table according to multiple preset malicious codes and multiple detection trigger times.
[0080] In this embodiment, the terminal can obtain a measurement trigger table based on multiple feature matching degrees. The terminal can obtain the initial feature value corresponding to the behavioral feature generated by the program to be detected for the current preset malicious code based on the above-mentioned operation result, and the initial feature value can be saved in the trust root. The terminal can obtain the feature matching degree of the above-mentioned operation result and the predicted operation result based on the initial feature value. If the terminal determines that the above-mentioned feature matching degree is greater than the preset matching degree threshold, the terminal can determine that the measurement of the preset malicious code by the program to be detected is passed, and the terminal can also generate a detection trigger time for the preset malicious code. Therefore, after the terminal performs the above-mentioned processing on the feature matching degrees corresponding to multiple preset malicious codes, it can form corresponding multiple groups of correspondences based on multiple preset malicious codes and multiple detection trigger times, and generate the above-mentioned measurement trigger table. Therefore, the terminal can perform dynamic trust verification based on the measurement trigger table.
[0081] For example, after pre-setting the measurement point values described above, the terminal can actively extract dynamic features to form a measurement trigger table. The terminal first determines whether the measurement point is consistent with the detected measured point range. If not, this indicates an incorrect trigger range. The terminal then uses a feature behavior identification method to select a root of trust. The root of trust stores the initial feature values of the measurement point. Based on the behavioral characteristics of the measured point, the terminal uses a SIM-like function to match the behavioral content features of the measurement point with the reference features of the root of trust. Once the terminal determines that the measurement has passed, it generates a measurement trigger table to control the triggering time of the active measurement. This allows the terminal to generate a measurement trigger table based on the correspondence between multiple preset malicious codes and trigger times.
[0082] Through the above embodiment, the terminal can form a measurement trigger table based on the correspondence between multiple preset malicious codes and trigger times, so that the terminal can perform trustworthy verification on programs in the system based on the measurement trigger table, thereby improving the security of the system.
[0083] In one embodiment, after the program to be detected is trusted and verified based on the credibility value, it also includes: if the program to be detected passes the trustworthy verification, the system is checked for credibility attributes according to the initial characteristic value of the program to be detected, the output isolation of the program to be detected, and multiple credibility values corresponding to the program to be detected; if the credibility attribute verification result is passed, the information flow corresponding to the communication between the program to be detected and the detection program is obtained; the information flow includes multiple behavioral characteristics of the program to be detected and the detection program; the information flow is input into a finite automaton, and the unobservable behavioral characteristics in the information flow are replaced by preset safe and trustworthy characteristics through the finite automaton to obtain the initial value of the finite automaton; the state of the finite automaton is converted to form a trusted state subset corresponding to the initial value; and the trusted verification result of the program to be detected is checked according to each behavioral characteristic in the trusted state subset.
[0084] In this embodiment, dynamic and static measurement results are interconnected. The results of each independent system serve as a reference for the other's subsequent calculations, further enhancing the integrity of the trusted measurement library. For both static and dynamic measurement libraries, terminals must verify their real-time integrity and security, necessitating verification of the trusted chain transfer model. This is a dynamic verification method that utilizes finite state automata to automatically check the properties between the measurer and measured systems, providing necessary and sufficient conditions for system trustworthiness. When verified by an instance, the observable property check passes.
[0085] For the program to be tested that has passed the above-mentioned trustworthy verification, the terminal can first perform a credibility attribute verification on the system based on the initial characteristic value of the program to be tested, the output isolation of the program to be tested, and the multiple credibility values corresponding to the program to be tested. Among them, the initial characteristic value can be used to determine whether the initial trust root of the system meets the requirements, the output isolation can be used to determine the consistency of the real behavior and the predicted behavior, and the multiple credibility values can be used to determine the trusted transmission properties of the system. When the terminal determines that the program to be tested has passed the above-mentioned credibility attribute verification, the terminal can obtain the information flow generated by the communication between the program to be tested and the detection program, and the information flow contains the behavioral characteristics of multiple programs to be tested and the detection program. The terminal can input the information flow into a finite automaton, and replace the unobservable behavioral characteristics in the information flow with preset safe and trustworthy characteristics through the finite automaton, thereby obtaining the initial value of the finite automaton. Among them, the finite automaton is also called a sequential machine, an abstract mathematical model of a finite discrete digital system. A finite automaton M is given by a five-tuple (X, Y, S, δ, λ), where X, Y, and S are all non-empty finite sets, respectively called M's input set, output set, and state set; δ is a mapping from the Cartesian product set S×X to S, called M's next-state function; and λ is a single-valued mapping from S×X to Y, called M's output function. When δ is a single-valued mapping, M is called a deterministic finite automaton; when δ is a multi-valued mapping, M is called a non-deterministic finite automaton. Finite automata have three functions: as sequence converters, transforming input sequences into output sequences; as sequence identifiers, identifying whether an input sequence possesses a certain property; and as sequence generators, generating sequences with the required property. The terminal can also transform the states of the finite automaton to obtain a trusted state subset corresponding to the initial value of the finite automaton. The terminal can also verify the trustworthiness of the program under test based on the behavioral characteristics of the trusted state subset.
[0086] For example, the terminal can use the system initial trusted root to meet the trustworthiness requirements, the isolation of the system real-time process output and the system's trustworthy transfer properties as the attribute check basis of the finite state machine. In the initial state G0 of the finite state machine, by continuously self-looping and detecting actions in the security domain, the system's state machine G is generated. i , it is included in the trust judgment process only when and only when the three properties set above are met. Specifically, the terminal can use the security and trust features in the finite automaton to replace all unobservable actions in the high-security level security domain to obtain the initial value of the finite automaton; the terminal can transform the finite automaton state to form a trusted state subset; the terminal can check the consistency of all states. If the low-security level security domain is defined in all states, it means that the state is consistent; when the terminal detects that the system meets the three system verification properties, it is consistent only when all possible states are consistent.
[0087] Among them, the system waits for the first access request of the entity process. Since the requirements for dynamic credibility judgment of the existing system are too strict and it is difficult to directly check the attributes of the entity process, the terminal can calculate the access sequence of the received information flow, obtain its minimum access action sequence, and simplify it. That is, starting from the high security level domain, replace all unobservable actions, and de-loop the self-looping actions that may exist in the initial state of the downgraded security domain, thereby completing the credibility check of the entire system.
[0088] Through this embodiment, the terminal can verify the credibility transferability of the system after credibility verification based on the finite automaton, thereby improving the security of the system.
[0089] In one embodiment, the system is verified for credibility attributes based on the initial credibility value, the output isolation of the program to be detected, and multiple credibility values corresponding to the program to be detected, including: obtaining the comparison result of the initial characteristic value and the preset credibility threshold; respectively obtaining the real behavior characteristics and predicted behavior characteristics output by the program to be detected and the detection program for the same system state; obtaining multiple continuous credibility values output by the program to be detected based on multiple continuous credibility verifications, and respectively obtaining the comparison results of the multiple continuous credibility values with the preset credibility threshold; if the initial characteristic value is greater than the preset credibility threshold, the real behavior characteristics and the predicted behavior characteristics are consistent, and the multiple continuous credibility values are all greater than the preset credibility threshold, it is determined that the credibility attribute verification has passed.
[0090] In this embodiment, before checking the trustworthy verification result, the terminal performs a trustworthiness attribute verification on the program to be tested corresponding to the trustworthy verification result in the system. The terminal can obtain the comparison result of the above-mentioned initial characteristic value and the preset trustworthiness threshold; the terminal can also obtain the real behavior characteristics output by the program to be tested in a system state, and the predicted behavior characteristics output by the detection program for the same system state; the terminal can also obtain multiple continuous trustworthiness values output by the program to be tested based on multiple continuous trustworthy verifications, and respectively obtain the comparison results of the multiple continuous trustworthiness values with the preset trustworthiness threshold to obtain multiple comparison results. The terminal can judge each of the above-mentioned information obtained. If the terminal determines that the initial characteristic value is greater than the preset trustworthiness threshold, the real behavior characteristics are consistent with the predicted behavior characteristics, and the multiple continuous trustworthiness values are all greater than the preset trustworthiness threshold, then the terminal can determine that the trustworthiness attribute verification of the program to be tested has passed. Among them, the comparison between the above-mentioned initial characteristic value and the preset credibility threshold can be used to determine whether the initial trusted root of the system meets the credibility requirements; the comparison results between the above-mentioned real behavior characteristics and the predicted behavior characteristics can allow users to determine whether the system meets the isolation of real-time process output; the comparison results of the above-mentioned multiple continuous credibility values with the preset credibility threshold can be used to determine whether the system meets the trusted transfer property.
[0091] For example, for the verification of credibility attributes, the terminal can first study and design the necessary and sufficient conditions for network credibility judgment. The credibility attributes of the system test should meet the following three conditions: (1) The initial trusted root of the system meets the credibility requirements: the result of static measurement optimizes the terminal state of the system to make it have real-time credibility. When the terminal detects that the trusted root is started in the next stage, the trusted root can achieve state transition and smoothly start the system credibility test function; (2) The real-time process in the system meets the output isolation: multiple information flow processes occur simultaneously in the system. It is necessary to ensure that the result of each measurement is evaluated under the state of a single process running to avoid interference in the test chain effects between multiple processes. Therefore, the isolation of the measurement action should be verified during credibility verification. After the measurement action is executed, the terminal can obtain a system expected action sequence predicted by the current real state output by the system. The terminal can also obtain a standard expected action sequence extracted in advance by the measurer. The terminal can only regard the measurement action as completed when it detects that the two are equivalent; (3) The system should meet the trusted transfer property: the trusted state of the current process is transferred from the previous state of the same node in the system. Since the state s i -1 Trusted, the terminal can determine the state s i It is also trustworthy. Therefore, during the transitive verification of trustworthiness, the terminal must verify that the states of all points in the system at different times have been trusted and that there is a certain degree of transitivity between the states. Through this dynamic detection method, the terminal can automatically check the properties between the measurer and the measured system using a finite state automaton, providing the necessary and sufficient conditions for system trustworthiness. When verified by an instance, the observable property check result is considered passed. By verifying the trustworthy model through properties, the terminal can ensure the real-time security and consistency of the model in both static and dynamic processes, thereby improving network trustworthiness.
[0092] Through this embodiment, the terminal can verify the credibility attribute of the program to be detected based on multiple conditions, thereby improving the security of the system.
[0093] In one embodiment, Figure 5 As shown, Figure 5This is a flow chart illustrating the trust verification steps for a multi-metric system in another embodiment. The process includes the following: After performing initial static trust verification on programs in the system, the terminal can pre-generate the aforementioned metric trigger table. Dynamic trust verification is then performed on programs to be tested in the system that have passed static trust verification. The program to be tested can serve as the measured, and the testing program communicating with the program to be tested can serve as the measurer. For example, during the active measurement phase, when the measured and measurer information are consistent, the terminal can perform active measurement. The terminal uses the measurer to initiate a measurement detection event for the running measured entity based on the measurement timings contained in the trigger table, calculate integrity and behavior metrics, and perform dynamic metric assessment of system behavior based on a pre-defined feature model. The feature-preset active measurement model is a relatively abstract dynamic process that can adapt to the dynamic measurement mechanisms of software and systems, performing feature matching and metric value calculation for different entity objects. For example, when the terminal determines that the status between the measurer and the measured meets the trigger condition, it can initiate a trigger measurement event and pause all currently running processes of the measurer. According to the measurement feature calculation function, the characteristic state of the measured object is found from the measurer, and then the next expected action state feature of the current measured object is calculated based on the characteristic function; since the measured objects that need to be measured are all in a paused state at this time, the terminal can calculate the credibility value of the measured point according to the static measurement calculation method; when the terminal detects that the calculation result is within the credibility value range, it outputs an evaluation report; if the terminal detects that the calculation result is not within the credibility value range, it optimizes the feature library, and can adjust and optimize the network status parameters.
[0094] Through the above-described embodiments, when a program in the system is running and its operating information meets the trigger conditions for trusted verification, the terminal performs trusted verification on these programs, thereby improving the security of the system where the program resides. Furthermore, the terminal utilizes the advantages of a combination of static and dynamic trusted measurement to meet the security control requirements of both the initial state and the real-time process state. The two are mutually compatible and operate in tandem, with dynamic assessment results optimizing the static model and new evidence of breach of trust optimizing the dynamic model. The entire trust chain transmission process maintains a real-time optimized form, meeting the complexity analysis of the system's static and dynamic evolution processes and the propagation and aggregation of the trust network. The terminal transforms the traditional trust link model to obtain a trusted measurement model, reducing trust transmission losses. By separating and abstracting the subject and object of trust measurement into the measurer and the measured, and isolating and protecting the measurer, the security and trustworthiness of the trust transmission node are ensured.
[0095] In addition, the terminal can pre-set the measurement points of the active measurement model based on feature thresholds in the trusted code. When the measured entity re-enters the system, the terminal can use the measurer to pre-calculate the detection opportunity, thus completing the active measurement process and avoiding losses caused by in-depth attacks by malicious behavior. The terminal uses the static trust model to compile the source code of the trusted detection attributes and extract multi-dimensional trustless evidence from the network. It then calculates the weights of the trustless attributes and comprehensively calculates the network's trustworthiness. Based on the multi-dimensional attribute feature extraction method, the terminal can comprehensively verify the trustworthiness of the system's initialization state, ensuring the static security of the network.
[0096] It should be understood that although Figure 1 、 Figure 3 as well as Figure 5 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. In addition, Figure 1 、 Figure 3 as well as Figure 5 At least part of the steps may include multiple steps or multiple stages. These steps or stages are not necessarily performed at the same time, but can be performed at different times. The order of execution of these steps or stages is not necessarily one by one, but can be performed in turn or alternately with other steps or at least part of the steps or stages in other steps.
[0097] In one embodiment, Figure 6 As shown, a multi-metric system trust verification device is provided, including: a response module 500, an acquisition module 502 and a detection module 504, wherein:
[0098] The response module 500 is used to detect that the program to be detected meets the measurement trigger condition, suspend the detection program communicating with the program to be detected, and obtain the current behavioral feature state of the program to be detected based on the detection program; the measurement trigger condition is determined by querying the measurement trigger table based on the communication information between the program to be detected and the detection program; the measurement trigger table includes the correspondence between the communication information of multiple programs and the trigger condition.
[0099] The acquisition module 502 is used to acquire the predicted behavior characteristic state of the program to be detected according to a preset characteristic function.
[0100] The detection module 504 is configured to obtain a credibility value of the program to be detected based on a comparison result between the current behavior feature state and the predicted behavior feature state, and perform credibility verification on the program to be detected based on the credibility value.
[0101] In one embodiment, the above-mentioned device also includes: a static detection module, which is used to respond to the startup information of the system where the program to be detected is located, obtain the program code of the program in the system, and extract the corresponding multiple evidences of default based on the program code; merge the same type of evidence of default among the multiple evidences of default to obtain multiple characteristic attributes; for each characteristic attribute, according to the number of evidences of default corresponding to the characteristic attribute and the attribute influence factor corresponding to the characteristic attribute, obtain the characteristic credibility value corresponding to the characteristic attribute; according to the multiple characteristic credibility values, determine the initial credibility value of the program code, and use the program corresponding to the program code whose initial credibility value is greater than or equal to the preset credibility threshold as the program to be detected.
[0102] In one embodiment, the static detection module is specifically configured to obtain, for each characteristic attribute, an attribute influence factor corresponding to the characteristic attribute based on the ratio of the influence factor parameter corresponding to the characteristic attribute and the attribute weight corresponding to the characteristic attribute; and obtain a characteristic credibility value corresponding to the characteristic attribute based on an exponential function with the product of the attribute influence factor and the number of pieces of untrustworthy evidence corresponding to the characteristic attribute as an exponent.
[0103] In one embodiment, the above-mentioned device also includes: a generation module for obtaining multiple preset malicious codes; for each preset malicious code, inserting the preset malicious code into the program to be detected, and obtaining the running result of the program to be detected for the preset malicious code; obtaining the predicted running result of the program to be detected for the malicious code output by the detection program; obtaining the comparison result between the running result and the predicted running result, if the comparison result is passed, determining the corresponding feature matching degree according to the running result and the predicted running result, and generating a measurement trigger table according to the multiple feature matching degrees.
[0104] In one embodiment, the above-mentioned generation module is specifically used to obtain the initial characteristic value corresponding to the program to be detected based on the running result; based on the initial characteristic value, obtain the characteristic matching degree between the running result and the predicted running result; if the characteristic matching degree is greater than the preset matching degree threshold, determine that the program to be detected passes the measurement of the preset malicious code, and generate a detection trigger time for the preset malicious code; generate a measurement trigger table based on multiple preset malicious codes and multiple detection trigger times.
[0105] In one embodiment, the above-mentioned device also includes: an inspection module, which is used to, if the program to be detected passes the trustworthy verification, perform a trustworthy attribute verification on the system based on the initial characteristic value of the program to be detected, the output isolation of the program to be detected, and multiple trustworthy values corresponding to the program to be detected; if the trustworthy attribute verification result is passed, obtain the information flow corresponding to the communication between the program to be detected and the detection program; the information flow includes multiple behavioral characteristics of the program to be detected and the detection program; input the information flow into a finite automaton, and replace the unobservable behavioral characteristics in the information flow with preset safe and trustworthy characteristics through the finite automaton to obtain the initial value of the finite automaton; convert the state of the finite automaton to form a trusted state subset corresponding to the initial value; and check the trusted verification result of the program to be detected based on each behavioral characteristic in the trusted state subset.
[0106] In one embodiment, the above-mentioned inspection module is specifically used to obtain the comparison result between the initial characteristic value and the preset credibility threshold; obtain the real behavior characteristics and predicted behavior characteristics output by the program to be detected and the detection program for the same system state respectively; obtain multiple continuous credibility values output by the program to be detected based on multiple continuous credibility verifications, and obtain the comparison results of multiple continuous credibility values with the preset credibility threshold respectively; if the initial characteristic value is greater than the preset credibility threshold, the real behavior characteristics and the predicted behavior characteristics are consistent, and multiple continuous credibility values are all greater than the preset credibility threshold, it is determined that the credibility attribute verification has passed.
[0107] The specific definitions of the multi-metric system trustworthiness verification device can be found in the definitions of the multi-metric system trustworthiness verification method above and will not be repeated here. Each module in the multi-metric system trustworthiness verification device described above can be implemented in whole or in part through software, hardware, or a combination thereof. Each of these modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.
[0108] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 7As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a multi-metric system trust verification method is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a key, trackball or touchpad provided on the computer device housing, or an external keyboard, touchpad or mouse.
[0109] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0110] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the above-mentioned multi-metric system trustworthiness verification method when executing the computer program.
[0111] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the computer program implements the above-mentioned multi-metric system trustworthiness verification method.
[0112] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0113] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0114] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.
Claims
1. A method for credible verification of a multi-metric system, characterized in that: The method comprises: Upon detecting that a program to be detected satisfies a measurement trigger condition, suspending a detection program communicating with the program to be detected and obtaining a current behavioral characteristic state of the program to be detected based on the detection program; the measurement trigger condition is determined by querying a measurement trigger table based on communication information between the program to be detected and the detection program; the measurement trigger table includes a correspondence between communication information of multiple programs and trigger conditions; Obtaining a predicted behavior characteristic state of the program to be detected according to a preset characteristic function; Obtaining a credibility value of the program to be detected based on a comparison result of the current behavior feature state and the predicted behavior feature state, and performing credibility verification on the program to be detected based on the credibility value; If the program to be tested passes the trustworthy verification, the system is subjected to a trustworthy attribute verification based on the initial characteristic value of the program to be tested, the output isolation of the program to be tested, and the multiple trustworthy values corresponding to the program to be tested; the initial characteristic value is used to determine whether the initial trustworthy root of the system meets the requirements, the output isolation is used to determine the consistency between the real behavior and the predicted behavior, and the multiple trustworthy values are used to determine the trustworthy transmission property of the system; if the result of the trustworthy attribute verification is passed, the information flow corresponding to the communication between the program to be tested and the detection program is obtained; the information flow includes multiple behavioral characteristics of the program to be tested and the detection program; the information flow is input into a finite automaton, and the unobservable behavioral characteristics in the information flow are replaced by preset safe and trustworthy characteristics through the finite automaton to obtain the initial value of the finite automaton; the state of the finite automaton is converted to form a trusted state subset corresponding to the initial value; according to each behavioral characteristic in the trusted state subset, the trustworthy verification result of the program to be tested is checked.
2. The method according to claim 1, characterized in that The method further comprises: In response to startup information of the system where the program to be detected is located, obtaining program code of the program in the system, and extracting corresponding multiple pieces of dishonesty evidence based on the program code; Merging the same type of breach of trust evidence among the plurality of breach of trust evidences to obtain a plurality of characteristic attributes; For each of the characteristic attributes, obtaining a characteristic credibility value corresponding to the characteristic attribute based on the number of pieces of dishonesty evidence corresponding to the characteristic attribute and the attribute influence factor corresponding to the characteristic attribute; An initial credibility value of the program code is determined based on the plurality of feature credibility values, and a program corresponding to a program code having an initial credibility value greater than or equal to a preset credibility threshold is used as the program to be detected.
3. The method according to claim 2, characterized in that For each of the characteristic attributes, obtaining a characteristic credibility value corresponding to the characteristic attribute according to the number of pieces of dishonesty evidence corresponding to the characteristic attribute and the attribute influence factor corresponding to the characteristic attribute includes: For each of the characteristic attributes, obtaining the attribute influence factor corresponding to the characteristic attribute according to the ratio of the influence factor parameter corresponding to the characteristic attribute and the attribute weight corresponding to the characteristic attribute; The feature credibility value corresponding to the feature attribute is obtained according to an exponential function with the product of the attribute influence factor and the number of untrustworthy evidences corresponding to the feature attribute as an exponent.
4. The method according to claim 1, wherein The method further comprises: Obtain multiple preset malicious codes; For each of the preset malicious codes, insert the preset malicious code into the program to be detected, and obtain the running result of the program to be detected for the preset malicious code; Obtaining a predicted running result of the program to be detected for the malicious code output by the detection program; Obtain a comparison result between the operation result and the predicted operation result. If the comparison result is passed, determine the corresponding feature matching degree according to the operation result and the predicted operation result, and generate the metric trigger table according to the multiple feature matching degrees.
5. The method according to claim 4, characterized in that The determining the corresponding feature matching degree according to the operation result and the predicted operation result, and generating the metric trigger table according to the plurality of feature matching degrees, includes: Obtaining an initial characteristic value corresponding to the program to be detected according to the running result; Obtaining, based on the initial characteristic value, a characteristic matching degree between the operation result and the predicted operation result; If the feature matching degree is greater than a preset matching degree threshold, determining that the program to be detected has passed the measurement of the preset malicious code, and generating a detection trigger time for the preset malicious code; The metric trigger table is generated according to the plurality of preset malicious codes and the plurality of detection trigger times.
6. The method according to claim 1, characterized in that The performing of a credibility attribute check on the system according to the initial characteristic value of the program to be detected, the output isolation of the program to be detected, and a plurality of credibility values corresponding to the program to be detected includes: Obtaining a comparison result between the initial characteristic value and a preset credibility threshold; Respectively obtaining the actual behavior characteristics and the predicted behavior characteristics output by the program to be tested and the testing program for the same system state; Obtaining multiple continuous credibility values output by the program to be tested based on multiple continuous credibility verifications, and respectively obtaining comparison results of the multiple continuous credibility values with preset credibility thresholds; If the initial feature value is greater than a preset credibility threshold, the actual behavior feature is consistent with the predicted behavior feature, and the multiple consecutive credibility values are all greater than the preset credibility threshold, it is determined that the credibility attribute verification has passed.
7. A multi-metric system trustworthy verification device, characterized in that: The device comprises: a response module configured to detect that a program to be detected satisfies a measurement trigger condition, suspend a detection program communicating with the program to be detected, and obtain a current behavioral characteristic state of the program to be detected based on the detection program; the measurement trigger condition is determined by querying a measurement trigger table based on communication information between the program to be detected and the detection program; the measurement trigger table includes a correspondence between communication information of multiple programs and trigger conditions; An acquisition module, configured to acquire a predicted behavior characteristic state of the program to be detected according to a preset characteristic function; a detection module, configured to obtain a credibility value of the program to be detected based on a comparison result of the current behavior characteristic state with the predicted behavior characteristic state, and perform credibility verification on the program to be detected based on the credibility value; The checking module is used to check the credibility attributes of the system according to the initial characteristic value of the program to be checked, the output isolation of the program to be checked and multiple credibility values corresponding to the program to be checked if the program to be checked passes the credibility verification; the initial characteristic value is used to determine whether the initial credibility root of the system meets the requirements, the output isolation is used to determine the consistency of the real behavior and the predicted behavior, and the multiple credibility values are used to determine the trusted transmission property of the system; if the credibility attribute verification result is passed, obtain the information flow corresponding to the communication between the program to be checked and the detection program; the information flow includes multiple behavioral characteristics of the program to be checked and the detection program; input the information flow into a finite automaton, and replace the unobservable behavioral characteristics in the information flow with preset safe and trusted characteristics through the finite automaton to obtain the initial value of the finite automaton; convert the state of the finite automaton to form a trusted state subset corresponding to the initial value; and check the trusted verification result of the program to be checked according to each behavioral characteristic in the trusted state subset.
8. The device according to claim 7, characterized in that The device further includes a static detection module, configured to: In response to startup information of the system where the program to be detected is located, obtaining program code of the program in the system, and extracting corresponding multiple pieces of dishonesty evidence based on the program code; Merging the same type of breach of trust evidence among the plurality of breach of trust evidences to obtain a plurality of characteristic attributes; For each of the characteristic attributes, obtaining a characteristic credibility value corresponding to the characteristic attribute based on the number of pieces of dishonesty evidence corresponding to the characteristic attribute and the attribute influence factor corresponding to the characteristic attribute; An initial credibility value of the program code is determined based on the plurality of feature credibility values, and a program corresponding to a program code having an initial credibility value greater than or equal to a preset credibility threshold is used as the program to be detected.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.