Virtual machine escape behavior detection method and device

By obtaining virtual machine network traffic and information in the host machine, analyzing behavioral characteristics and establishing a trusted policy library, the problem of detecting virtual machine escape attacks is solved, and real-time interception and recording of escape behaviors are achieved without affecting the operation of the virtual machine.

CN114707144BActive Publication Date: 2025-09-12SICHUAN BANGCHEN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210301960.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-24
Publication Date
2025-09-12
Estimated Expiration
2042-03-24

AI Technical Summary

Technical Problem

In the existing technology, virtual machine escape attacks are difficult to be effectively monitored and identified, resulting in threats to the security of the host machine and virtual environment, and it is impossible to strengthen them without affecting the normal operation of the virtual machine.

Method used

By obtaining the network traffic and related information of the virtual machine in the host machine, extracting behavioral features, analyzing and determining whether escape behavior has occurred, and establishing a trusted behavior policy library, the virtual machine process is restricted to run within the specified operating range, and escape behavior is intercepted in real time.

Benefits of technology

Without affecting the normal operation of the virtual machine, it can effectively detect and intercept virtual machine escape behavior, reduce the risks brought by escape attacks, and facilitate post-analysis and tracing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114707144B_ABST
    Figure CN114707144B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for detecting virtual machine escape behavior, which relates to the field of computer security technology. The method includes S1 obtaining the network traffic of the virtual machine and related information of the host machine in the host machine; S2 extracting behavioral features from the network traffic of the virtual machine and related information of the host machine; S3 analyzing the extracted behavioral features to obtain analysis results; S4 judging whether the virtual machine has escaped behavior, and if so, intercepting the escape behavior, recording and issuing an alarm; the device includes a detection module, a control terminal, a trusted behavior policy library and a database, which can effectively detect the escape behavior of the virtual machine without changing the operating environment of the virtual machine and the normal operation of the virtual machine; maintaining trusted behavior policies in multiple dimensions of network traffic, process, network connection, file operation and file integrity, establishing a trusted behavior policy library, and restricting the virtual machine process to run only within the specified operating behavior range, thereby detecting virtual machine escape attack behavior to the greatest extent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer security technology, and in particular to a method and device for detecting virtual machine escape behavior. Background Art

[0002] With the development of computer technology and cloud computing, virtualization technology has garnered significant attention and is being widely applied in areas such as malware detection, privacy protection, and cloud computing. Virtualization technology can split a single computer into multiple logical computers, each running a different operating system, allowing applications to run in independent environments without interfering with each other. Virtualization technology has a wide range of applications. In cloud computing, it significantly improves computer efficiency and resource utilization, serving as an effective means of allocating computing resources. In information security, virtualization, as a dynamic analysis environment, can automatically analyze unknown samples, recording their operations within a virtual machine (sandbox) environment to determine their true intent. Furthermore, malicious samples running within the sandbox do not modify the real environment, making it an ideal analysis environment. In the area of ​​privacy protection, virtualization technology can be used to modify device and operating system fingerprints at any time, preventing traceability and protecting user identities.

[0003] Typically, the logical computer created from a physical computer is called a virtual machine (sandbox), while the physical computer is called the host. A virtual machine is a relatively independent computing environment within the host machine, offering good security features. However, due to inherent flaws and limitations in virtualization software, programs running within the virtual machine can exploit vulnerabilities to bypass the underlying operating environment and use the host machine to perform privileged operations. This technique is known as a virtual machine escape.

[0004] Once a virtual machine successfully escapes from a host, it can perform various operations with the host's privileges, threatening the security of the host and all virtual machines within the entire virtual environment. Furthermore, due to environmental constraints, it is often impossible to control the applications running within a virtual machine, making it impossible to harden the virtual machine itself, and only passive monitoring is possible. Therefore, in such situations, monitoring and identifying virtual machine escape attacks is particularly important. Summary of the Invention

[0005] The purpose of the present invention is to design a method and device for detecting virtual machine escape behavior in order to solve the above problems.

[0006] The present invention achieves the above-mentioned purpose through the following technical solutions:

[0007] The virtual machine escape behavior detection method includes:

[0008] S1. Obtain network traffic of the virtual machine and related information of the host machine in the host machine;

[0009] S2, extracting behavioral features from the network traffic of the virtual machine and the relevant information of the host machine;

[0010] S3, analyzing the extracted behavioral features to obtain analysis results;

[0011] S4. Determine whether the virtual machine has escaped based on the analysis results. If escape occurs, intercept, record, and issue an alarm.

[0012] A virtual machine escape behavior detection device includes:

[0013] Detection module: The detection module is installed in the host machine, and the detection module obtains the network traffic of the virtual machine and the relevant information of the host machine, and performs analysis and detection on them;

[0014] Control terminal; the control terminal is used to receive virtual machine escape behavior events uploaded by the detection module in real time and issue warnings to relevant personnel. The data signal output terminal of the detection module is connected to the data signal input terminal of the control terminal;

[0015] Trusted behavior strategy library; the trusted behavior strategy library stores trusted behavior strategies, and the signal end of the trusted behavior strategy library is connected to the signal end of the detection module;

[0016] The database is used to store the virtual machine escape behavior event, and the data signal output end of the control end is connected to the data signal input end of the database.

[0017] The beneficial effects of the present invention are: effectively detecting the escape behavior of a virtual machine without changing the operating environment of the virtual machine and without affecting the normal operation of the virtual machine; by maintaining trusted behavior policies in multiple dimensions such as network traffic, processes, network connections, file operations, and file integrity, establishing a trusted behavior policy library, and restricting virtual machine processes to run only within a specified operating behavior range, thereby detecting virtual machine escape attack behaviors to the greatest extent; at the same time, recording the escape behavior of the virtual machine, and intercepting the virtual machine that generates the escape behavior event in real time according to the policy, which can reduce the risks brought by the escape attack behavior and facilitate subsequent analysis and tracing. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 This is a flow chart of the virtual machine escape behavior detection method of the present invention;

[0019] Figure 2 This is a structural block diagram of a virtual machine escape behavior detection device according to the present invention;

[0020] Figure 3 Generate a trusted behavior policy library flow chart for the present invention. DETAILED DESCRIPTION

[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more apparent, the technical solutions of the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings of the embodiments of the present invention. It should be understood that the described embodiments are only a portion of the embodiments of the present invention, not all of them. Generally, the components of the embodiments of the present invention described and illustrated in the drawings herein may be arranged and designed in a variety of different configurations.

[0022] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.

[0023] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.

[0024] In the description of the present invention, it should be understood that the terms "upper", "lower", "inside", "outside", "left", "right", etc. indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, or are the orientations or positional relationships in which the inventive product is conventionally placed when in use, or are the orientations or positional relationships conventionally understood by those skilled in the art. These are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or component referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present invention.

[0025] Furthermore, the terms “first”, “second”, etc. are merely used for distinguishing descriptions and should not be understood as indicating or implying relative importance.

[0026] In the description of the present invention, it should also be noted that, unless otherwise expressly specified or limited, terms such as "disposed" and "connected" should be understood in a broad sense. For example, "connected" can mean a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can also mean internal communication between two components. Those skilled in the art will be able to understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0027] The specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0028] The virtual machine escape behavior detection method includes:

[0029] S1. Obtain network traffic of the virtual machine and related information of the host machine in the host machine, wherein the related information includes a process list, a network connection list, and system information of a specified file and directory list of the host machine system.

[0030] S2. Extract behavioral features from the network traffic of the virtual machine and the related information of the host machine. The behavioral features of the network traffic include five-tuple information. The behavioral features of the process list include process ID, user, process type, process name and execution command. The behavioral features of the network connection list include five-tuple information, connection type, startup process ID, user, process name and execution command. The behavioral features of the specified file and directory list include read, write, modify, create and delete operations on the specified file and directory list.

[0031] S3. Analyze the extracted behavioral features to obtain analysis results, including:

[0032] Initialize the label and set the analysis result to 0;

[0033] The five-tuple information of network traffic is combined with the ID of the virtual machine to form a six-tuple information to determine whether the host machine performs network connection access with other virtual machines. If so, the analysis result is increased by 1, otherwise the analysis result is increased by 0;

[0034] Determine whether there is an abnormal process in the host machine based on the behavioral characteristics of the process list. If so, add 1 to the analysis result; otherwise, add 0 to the analysis result.

[0035] Determine whether there is an abnormal network connection in the host machine based on the behavioral characteristics of the network connection list. If so, add 1 to the analysis result; otherwise, add 0 to the analysis result.

[0036] Calculate the MD5 value of the specified file to check the integrity of the specified file and determine whether the specified file has been maliciously modified or replaced. If so, add 1 to the analysis result; otherwise, add 0 to the analysis result.

[0037] Determine whether the virtual machine accesses a file or directory that is not specified in the trusted behavior policy library. If so, add 1 to the analysis result; otherwise, add 0 to the analysis result.

[0038] S4. Determine whether the virtual machine has escaped based on the analysis results. If the analysis result is greater than 0, an escape has occurred. The virtual machine is intercepted by blocking traffic from the virtual machine, destroying the virtual machine, or immediately destroying the virtual machine after saving a snapshot. The escape behavior is recorded and stored in the database. The operation and maintenance personnel are then alerted via email, text message, etc., and an alarm query and security event display interface are provided.

[0039] The trusted behavior policy library stores trusted behavior policies. Trusted behavior policies are generated based on the hardened operating system, and the hardened operating system autonomously learns to generate a preset trusted behavior policy library, which is adjusted and updated by maintenance personnel. In S3, it specifies whether the behavioral characteristics of file and directory lists are included in the trusted behavior policy library. Trusted behavior policies refer to the access rules of virtual machines, which define the objects and operation sets allowed to be accessed. The policy only allows virtual machine processes to perform specified operation behaviors, ensuring that the virtual machine does not escape and ensuring the safe operation of the host machine.

[0040] The detection method also includes periodic detection of the host machine's process status, network connection status and file integrity, and adjusting the detection cycle according to the virtual machine resource occupancy and host machine load. The adjustment method is: when the virtual machine resource occupancy and host machine load exceed the pre-set threshold, the detection cycle is extended; if they do not exceed, the original detection cycle is used.

[0041] A virtual machine escape behavior detection device includes:

[0042] Detection module: The detection module is installed in the host machine, and the detection module obtains the network traffic of the virtual machine and the relevant information of the host machine, and performs analysis and detection on them;

[0043] Control terminal; the control terminal is used to receive virtual machine escape behavior events uploaded by the detection module in real time and issue warnings to relevant personnel. The data signal output terminal of the detection module is connected to the data signal input terminal of the control terminal;

[0044] Trusted behavior strategy library; the trusted behavior strategy library stores trusted behavior strategies, and the signal end of the trusted behavior strategy library is connected to the signal end of the detection module;

[0045] The database is used to store the virtual machine escape behavior event, and the data signal output end of the control end is connected to the data signal input end of the database.

[0046] Taking KVM virtual machines as an example, the virtual network cards (vnet0, vnet1...vnetn) of all virtual machines are monitored in real time, and the correspondence between virtual network cards and virtual machines is obtained using the virsh management tool, while all network traffic packets sent from the virtual machines are captured; the / proc file system is used to obtain the process list and network connection list information in the host operating system; the inotify mechanism is used to monitor the files and directories of the file system, and the operation event attributes of specified files and directories are monitored, such as common read operations (IN_ACCESS), write operations (IN_MODIFY), create operations (IN_CREATE), delete operations (IN_DELETE), and file metadata change operations (IN_ATTRIB). At the same time, an integrity sample library (snapshot) of the specified file is constructed as a comparison standard for the integrity of the specified file.

[0047] The behavioral features extracted from the analysis are:

[0048] Analyze all network traffic from the virtual network card, extract the five-tuple information of the traffic data packet (source IP, source port, destination IP, destination port, protocol), and combine it with the virtual machine ID to form a six-tuple information. For example, for the use case of privacy protection, users use the virtual machine sandbox to perform network access to prevent identity fingerprints from being identified and traced. However, users do not perform network connection access to the host itself or other virtual machines. If such behavior is found, it indicates that an application in the sandbox may be escaping.

[0049] From the obtained process list, behavioral features such as process ID, user, process type, process name, and execution command are extracted; the sandbox appears as an independent process on the host machine, and the user can perform any application operation in the sandbox without affecting the normal operation of the host machine; once an abnormal process is found in the host machine, it may be caused by a virtual machine escape attack.

[0050] For the obtained network connection list, extract the network connection five-tuple information, connection type, startup process ID, user, process name, execution command and other behavioral characteristics; in the reinforced operating system environment, all applications that can connect to the outside world are controllable and have been added to the trusted behavior policy library. Once an abnormal network connection is found, it may be caused by a virtual machine escape attack.

[0051] Perform integrity checks on the calculated MD5 values ​​of the specified files and directories being monitored. In a hardened operating system environment, by establishing an integrity sample library (snapshot) of the specified files, files can be prevented from being maliciously modified or replaced. Once an abnormal network connection is found, it may be caused by a virtual machine escape attack.

[0052] Get read, write, modify, create, and delete operations on specified files and directories. The sandbox appears as an independent process on the host machine. Normally, the sandbox can only access specified image files or shared directories. If a sandbox process is found to access files or directories not specified in the trusted behavior policy library, it indicates that an application in the sandbox may be attempting to escape.

[0053] The trusted behavior policy library is invoked by the detection module to perform real-time monitoring of network traffic data and file operations. It also periodically checks process status, network connection status, and the integrity of specified files. The detection period is dynamically adjusted based on virtual machine resource usage and host load. The default detection period for process status and network connection status is 10 seconds, and the default detection period for file integrity is 1 hour. Any operations not listed in the trusted behavior policy library are reported to the control end for processing.

[0054] When it is detected that the operation behavior does not match the trusted behavior policy library, the behavior is reported to the control end. The control end intercepts the abnormal operation behavior event based on the abnormal behavior, records the event and issues an alarm.

[0055] The control end intercepts and handles virtual machine escape events during the event. Specific implementation steps include: receiving virtual machine escape behavior events uploaded by the detection module in real time, processing the information, and storing it in a database. Real-time interception of virtual machine escape behaviors occurs by blocking network traffic from the virtual machine, destroying the virtual machine, or saving a snapshot and immediately destroying it. Alerts to operations and maintenance personnel are sent via email or text message based on the information, and an interface for alarm query and security event display is provided. Post-event analysis is performed using recorded abnormal operation behavior logs combined with saved snapshots.

[0056] The technical solution of the present invention is not limited to the above-mentioned specific embodiments. Any technical variations made according to the technical solution of the present invention fall within the protection scope of the present invention.

Claims

1. A method for detecting virtual machine escape behavior, characterized in that: include: S1. Obtain network traffic of the virtual machine and related information of the host machine in the host machine; the related information includes system information of the host machine system process list, network connection list, specified file and directory list; S2, extracting behavioral features from the network traffic of the virtual machine and the relevant information of the host machine; The behavioral characteristics of network traffic include five-tuple information. The behavioral characteristics of the process list include process ID, user, process type, process name, and execution command. The behavioral characteristics of the network connection list include five-tuple information, connection type, startup process ID, user, process name, and execution command. The behavioral characteristics of the specified file and directory list include read, write, modify, create, and delete operations on the specified file and directory list. S3, analyzing the extracted behavioral features to obtain analysis results; Specifically include: Initialize the label and set the analysis result to 0; The five-tuple information of network traffic is combined with the ID of the virtual machine to form a six-tuple information to determine whether the host machine performs network connection access with other virtual machines. If so, the analysis result is increased by 1, otherwise the analysis result is increased by 0; Determine whether there is an abnormal process in the host machine based on the behavioral characteristics of the process list. If so, add 1 to the analysis result; otherwise, add 0 to the analysis result. Determine whether there is an abnormal network connection in the host machine based on the behavioral characteristics of the network connection list. If so, add 1 to the analysis result; otherwise, add 0 to the analysis result. Calculate the MD5 value of the specified file to check the integrity of the specified file and determine whether the specified file has been maliciously modified or replaced. If so, add 1 to the analysis result; otherwise, add 0 to the analysis result. Determine whether the virtual machine accesses a file or directory that is not specified in the trusted behavior policy library. If so, add 1 to the analysis result; otherwise, add 0 to the analysis result. S4. Determine whether the virtual machine has escaped based on the analysis results. If escape occurs, intercept, record, and issue an alarm.

2. The virtual machine escape behavior detection method according to claim 1, characterized in that: In S4, it is determined whether the analysis result is greater than 0, and the virtual machine has escaped.

3. The virtual machine escape behavior detection method according to claim 1, characterized in that: The trusted behavior policy library stores trusted behavior policies, which are access rules for virtual machines. They define the objects and operation sets that virtual machines are allowed to access. In S3, they specify whether the behavioral characteristics of file and directory lists are included in the trusted behavior policy library.

4. The virtual machine escape behavior detection method according to claim 1, characterized in that: The interception method further includes constructing an integrity sample library of the specified file, where the integrity sample library is used as a comparison standard for the integrity of the specified file.

5. The virtual machine escape behavior detection method according to claim 1, characterized in that: The interception method includes blocking traffic from the virtual machine, destroying the virtual machine, and immediately destroying the virtual machine after saving a snapshot.

6. The method for detecting virtual machine escape behavior according to claim 1, wherein: The detection method also includes periodic detection of the host machine's process status, network connection status, and file integrity, and adjusting the detection period according to the virtual machine resource usage and host machine load.

7. A virtual machine escape behavior detection device, configured to implement the virtual machine escape behavior detection method according to any one of claims 1 to 6, characterized in that: include: Detection module; The detection module is installed in the host machine, and the detection module obtains the network traffic of the virtual machine and the relevant information of the host machine, and performs analysis and detection on them; Control terminal; the control terminal is used to receive virtual machine escape behavior events uploaded by the detection module in real time and issue warnings to relevant personnel. The data signal output terminal of the detection module is connected to the data signal input terminal of the control terminal; Trusted behavior policy library; The trusted behavior strategy library stores the trusted behavior strategy, and the signal end of the trusted behavior strategy library is connected to the signal end of the detection module; The database is used to store the virtual machine escape behavior event, and the data signal output end of the control end is connected to the data signal input end of the database.

Citation Information

Patent Citations

  • Method and system for detecting malicious acts of virtual machine

    CN104715201A

  • Virtual machine anomaly detecting method, device and system

    CN105718303A