Branch record implementation method and system
By loading the branch record driver in a Linux system with KPTI enabled and mapping data between the kernel and user address space, the problem of not being able to use Intel BTS drivers is solved, and the system security is improved.
Patent Information
- Application Number
- CN202110231792.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-02
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-03-02
AI Technical Summary
After enabling KPTI, the kernel in Linux system does not load the Intel BTS driver by default, resulting in the inability to use the branch recording function based on Intel BTS, affecting system security.
Load the branch record driver with KPTI enabled, collect branch record jump data and save it to the kernel address space, and map it in the user address space to ensure the normal use of the data.
Ensure that after enabling KPTI, the data captured by the driver can be normally used to record the driver, improve system security, prevent CPU exceptions and system crashes, and achieve security protection for the current operating system.
Smart Images

Figure CN114996710B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of system security technologies, and particularly to a method, system, electronic device, and computer-readable storage medium for implementing branch recording. Background Art
[0002] Before the discovery of the "Meltdown" hardware security flaw in x86 CPUs, the process address space was divided into a kernel address space and a user address space. Among them, the kernel address space is mapped to the entire physical address space, while the user address space can only be mapped to a specified physical address space. The kernel address space and the user address space share a page global directory table, that is, the page directory (Page Global Directory, PGD) represents the entire address space of the process. The Meltdown vulnerability precisely takes advantage of this point. Attackers illegally access the kernel address and the time window for the CPU to handle exceptions, and obtain kernel data through memory access microinstructions.
[0003] To mitigate the "Meltdown" hardware security flaw in x86 CPUs, currently, the Kernel Page-Table Isolation (KPTI) technology can be adopted. KPTI is a strengthening technology in the Linux kernel. It mainly makes the kernel address space and the user address space use two sets of page tables (that is, use two PGDs), aiming to better isolate the memory of the user address space and the kernel address space to improve security and mitigate the "Meltdown" hardware security flaw in x86 CPUs.
[0004] Currently, the vast majority of Linux systems have enabled the KPTI function, and KPTI has been merged into the Linux kernel. In the Linux system, after enabling KPTI, due to the incompatibility between Intel BTS (Branch Trace Store) and the KPTI technology characteristics, the kernel does not load the Intel BTS driver by default, which also causes that after the kernel enables KPTI, any function provided by Intel BTS cannot be used.
[0005] It should be noted that the above content is not used to limit the scope of protection of the application. Summary of the Invention
[0006] The main objective of this application is to propose a method, system, electronic device, and computer-readable storage medium for implementing branch recording, aiming to solve the problem of how to normally use the branch recording function in the state of enabling KPTI.
[0007] To achieve the above objective, an embodiment of this application provides a method for implementing branch recording, and the method includes:
[0008] Load the branch record driver in the state where the kernel page table isolation is enabled in the current operating system;
[0009] Collect the branch record jump data of the current process of the current operating system through the branch record driver;
[0010] Save the branch record jump data to the kernel address space of the current process; and
[0011] When the current process is in the user address space, map the branch record jump data in the kernel address space to the user address space.
[0012] Optionally, the branch record driver is a branch trace store BTS driver that saves the branch record jump data to the memory space.
[0013] Optionally, the memory space corresponding to the current process includes the kernel address space and the user address space. When the current process is in the kernel address space or the user address space, the branch record jump data collected by the branch record driver is saved to the kernel address space.
[0014] Optionally, the mapping of the branch record jump data in the kernel address space to the user address space includes:
[0015] Obtain the memory data of the continuous address space in the kernel address space for saving the branch record jump data, and map it to the corresponding position in the user address space.
[0016] Optionally, the obtaining the memory data of the continuous address space in the kernel address space for saving the branch record jump data and mapping it to the corresponding position in the user address space includes:
[0017] Locate the first continuous address space applied by the branch record driver in the kernel address space for saving the branch record jump data;
[0018] Read the memory data in the first continuous address space;
[0019] Apply for a second continuous address space corresponding to the first continuous address space in the user address space;
[0020] Copy the memory data to the second continuous address space in the user address space.
[0021] Optionally, the method further includes:
[0022] Obtain the branch record jump data from the kernel address space and the user address space respectively.
[0023] Optionally, the obtaining of the branch record jump data from the kernel address space and the user address space respectively includes:
[0024] When the current process is in the kernel address space, obtaining the branch record jump data from the kernel address space;
[0025] When the current process is in the user address space, obtaining the mapped branch record jump data from the user address space.
[0026] In addition, to achieve the above object, an embodiment of the present application further provides a branch record implementation system, which includes:
[0027] A loading module, configured to load a branch record driver in a state where the kernel page table isolation is enabled in the current operating system;
[0028] An acquisition module, configured to acquire branch record jump data of the current process of the current operating system through the branch record driver;
[0029] A saving module, configured to save the branch record jump data to the kernel address space of the current process;
[0030] A mapping module, configured to map the branch record jump data in the kernel address space to the user address space when the current process is in the user address space.
[0031] To achieve the above object, an embodiment of the present application further provides an electronic device, which includes: a memory, a processor, and a branch record implementation program stored on the memory and executable on the processor. When the branch record implementation program is executed by the processor, the branch record implementation method as described above is implemented.
[0032] To achieve the above object, an embodiment of the present application further provides a computer-readable storage medium, on which a branch record implementation program is stored. When the branch record implementation program is executed by a processor, the branch record implementation method as described above is implemented.
[0033] The branch record implementation method, system, electronic device, and computer-readable storage medium proposed by the embodiments of the present application can ensure that the data captured by the branch record driver can still be used normally after the KPTI is enabled in the current operating system, so as to use the data to perform security protection on the current operating system and improve system security. Description of the Drawings
[0034] Figure 1 An application environment architecture diagram for implementing various embodiments of the present application;
[0035] Figure 2 Flow chart of a method for implementing branch recording proposed in the first embodiment of this application;
[0036] Figure 3 Schematic diagram of a PGD distribution of the user address space and the kernel address space in this application;
[0037] Figure 4 For Figure 2 Refined flow chart of step S206 in
[0038] Figure 5 Schematic diagram of page table mapping for the said step S206;
[0039] Figure 6 Flow chart of a method for implementing branch recording proposed in the second embodiment of this application;
[0040] Figure 7 Schematic diagram of the hardware architecture of an electronic device proposed in the third embodiment of this application;
[0041] Figure 8 Schematic diagram of the modules of a branch recording implementation system proposed in the fourth embodiment of this application;
[0042] Figure 9 Schematic diagram of the modules of a branch recording implementation system proposed in the fifth embodiment of this application. Detailed implementation manners
[0043] In order to make the objectives, technical solutions and advantages of this application clearer, the following further elaborates on this application in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.
[0044] It should be noted that the descriptions involving "first", "second", etc. in the embodiments of this application are only for descriptive purposes and cannot be construed as indicating or implying their relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. Additionally, the technical solutions between various embodiments may be combined with each other, but it must be based on the ability of those of ordinary skill in the art to implement. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by this application.
[0045] Please refer to Figure 1 , Figure 1An application environment architecture diagram for implementing various embodiments of the present application. The present application can be applied to an application environment including, but not limited to, the current operating system 2, the memory space 4, and the branch record driver 6.
[0046] Among them, the current operating system 2 is a Linux operating system, and the current operating system 2 also includes a currently executing current process 20. In the state where KPTI is enabled in the current operating system 2, the current process 20 corresponds to two address spaces in the memory space 4, namely the kernel address space 40 and the user address space 42.
[0047] The branch record driver 6 is used to collect the branch record jump data of the current process 20 of the current operating system 2 and save it to the kernel address space 40.
[0048] Embodiment 1
[0049] As Figure 2 shown, it is a flowchart of a branch record implementation method proposed in the first embodiment of the present application. It can be understood that the flowchart in the embodiment of this method is not used to limit the order of execution steps. According to needs, some steps in this flowchart can also be added or deleted.
[0050] The method includes the following steps:
[0051] S200, load the branch record driver in the state where the current operating system enables KPTI (Kernel Page Table Isolation).
[0052] In this embodiment, the current operating system is a Linux operating system. The branch record driver is a BTS driver, and the BTS driver saves branch information (branch record jump data below) to the memory space.
[0053] After KPTI is enabled in the Linux operating system, the memory space corresponding to each process includes two address spaces. The first address space is the kernel address space, which can only be accessed in kernel mode and can create mappings to the kernel and users. The second address space is called the shadow address space (user address space). However, due to context switching, part of the kernel address must be included in the shadow address space to establish mappings to interrupt entry and exit. In the Linux operating system, the KPTI patch places the PGD of the kernel address space and the PGD of the user address space continuously in an 8KB memory space to improve the speed of CR3 switching. This space must be 8K-aligned, so that the CR3 switching operation is converted into a set or clear operation of the 13th bit (from low to high) of the CR3 value. For example, refer to Figure 3 shown, it is a schematic diagram of the PGD distribution of the user address space and the kernel address space.
[0054] In the traditional Linux operating system, due to the incompatibility between the BTS and KPTI technical features, the BTS driver is not loaded by default in the kernel. In order to use the branch record jump data collected by the BTS driver for system security detection in this embodiment, the BTS driver is loaded into the kernel of the current operating system (Linux operating system) when KPTI is enabled in the current operating system. For example, the BTS driver is loaded into the kernel through the loading command modprobe of the Linux operating system and the like.
[0055] S202, collect the branch record jump data of the current process of the current operating system through the branch record driver.
[0056] The branch record driver (BTS driver) is located in the kernel layer of the operating system. The purpose is to collect the branch record jump data in real time when the current process of the current system is running, and save the collected branch record jump data. In addition, the data collection of the branch record driver can be controlled to be turned on or off at any time, so as to collect the branch record jump data of the specified process.
[0057] S204, save the branch record jump data to the kernel address space of the current process.
[0058] The memory space corresponding to the current process includes the kernel address space and the user address space. When the current process is in the kernel address space or the user address space, the branch record jump data collected by the branch record driver is saved to the kernel address space.
[0059] S206, when the current process is in the user address space, map the branch record jump data in the kernel address space to the user address space.
[0060] After KPTI is enabled in the Linux operating system, the PGD of each process is divided into the PGD of the kernel address space and the PGD of the user address space. Only a very small number of key pages in the user-mode page table are mapped to the kernel address space for handling system interrupts, exceptions, etc. When the CPU is running, the BTS driver will record the branch record jump data into the memory space at any time. If the current process is in the user address space, the BTS driver will write the branch record jump data into the kernel address space, but at this time the user-mode page table cannot query the kernel address space, resulting in a page fault of the CPU and then causing the system to crash.
[0061] Therefore, in this embodiment, when the current process is in the user address space, it is necessary to obtain the memory data of the continuous address space in the kernel address space for storing the branch record jump data and map it to the corresponding position in the user address space. When the current process is in the kernel address space, the branch record jump data can be directly read from the kernel address space without mapping.
[0062] Specifically, further refer to Figure 4 , which is a refined flowchart of step S206 above. It can be understood that this flowchart is not used to limit the order of execution steps. According to needs, some steps in this flowchart can also be added or deleted. In this embodiment, step S206 specifically includes:
[0063] S2060, locate the first continuous address space in the kernel address space applied by the branch record driver for storing the branch record jump data.
[0064] S2062, read the memory data in the first continuous address space.
[0065] S2064, apply for a second continuous address space in the user address space corresponding to the first continuous address space.
[0066] S2066, copy the memory data to the second continuous address space in the user address space.
[0067] For example, refer to Figure 5 shown, which is a page table mapping diagram of step S206. Figure 5 The memory data of the first continuous address space in the lower kernel address space in [] is mapped to the second continuous address space in the upper user address space.
[0068] When the branch record jump data needs to be used subsequently, if the current process is in the user address space, the BTS driver will write the branch record jump data into the kernel address space. At this time, the user-mode page table cannot query the kernel address space. However, since the branch record jump data in the kernel address space has been mapped to the user address space in this embodiment, the user-mode page table can query the branch record jump data from the user address space for normal use without causing a CPU exception.
[0069] The branch record implementation method proposed in this embodiment can ensure that after the current operating system enables KPTI, the data captured by the branch record driver can still be used normally, so as to use this data to perform security protection on the current operating system and improve system security.
[0070] Embodiment 2
[0071] As Figure 6 shown, it is a flowchart of a branch record implementation method proposed in the second embodiment of the present application. In the second embodiment, on the basis of the first embodiment, the branch record implementation method further includes step S308. It can be understood that the flowchart in the embodiment of the present method is not used to limit the order of executing steps. According to needs, some steps in this flowchart can also be added or deleted.
[0072] The method includes the following steps:
[0073] S300, load the branch record driver in the state where KPTI is enabled in the current operating system.
[0074] In this embodiment, the current operating system is the Linux operating system. The branch record driver is the BTS driver, and the BTS driver saves branch information (branch record jump data hereinafter) to the memory space.
[0075] After KPTI is enabled in the Linux operating system, the memory space corresponding to each process includes two address spaces. The first address space is the kernel address space, which can only be accessed in kernel mode and can create mappings to the kernel and users. The second address space is called the shadow address space (user address space). However, due to context switching, part of the kernel address must be included in the shadow address space to establish mappings to interrupt entry and exit. In the Linux operating system, the KPTI patch places the PGD of the kernel address space and the PGD of the user address space continuously in an 8KB memory space in order to improve the speed of CR3 switching. This space must be 8K-aligned, so that the CR3 switching operation is converted into a set or clear operation of the 13th bit (from low to high) of the CR3 value.
[0076] In the traditional Linux operating system, due to the incompatibility between the technical characteristics of BTS and KPTI, the kernel does not load the BTS driver by default. And in this embodiment, in order to use the branch record jump data collected by the BTS driver for system security detection, in the state where KPTI is enabled in the current operating system (Linux operating system), the BTS driver is loaded into the kernel of the current operating system. For example, the BTS driver is loaded into the kernel through the loading command modprobe of the Linux operating system.
[0077] S302, collect the branch record jump data of the current process of the current operating system through the branch record driver.
[0078] The branch trace driver (BTS driver) is located in the kernel layer of the operating system. Its purpose is to collect the branch trace jump data during the runtime of the current process of the current system in real time and save the collected branch trace jump data. Additionally, the data collection of the branch trace driver can be controlled to be turned on or off at any time, so as to collect the branch trace jump data of a specified process.
[0079] S304, save the branch trace jump data to the kernel address space of the current process.
[0080] The memory space corresponding to the current process includes the kernel address space and the user address space. When the current process is in the kernel address space or the user address space, the branch trace jump data collected by the branch trace driver is saved to the kernel address space.
[0081] S306, when the current process is in the user address space, map the branch trace jump data in the kernel address space to the user address space.
[0082] Since after enabling KPTI in the Linux operating system, the PGD of each process is divided into the PGD of the kernel address space and the PGD of the user address space, and only a very small number of and critical pages in the user-mode page table are mapped to the kernel address space for handling system interrupts, exceptions, etc. When the CPU is running, the BTS driver will record the branch trace jump data into the memory space at any time. If the current process is in the user address space, the BTS driver will write the branch trace jump data into the kernel address space, but at this time the user-mode page table cannot query the kernel address space, resulting in a page fault exception of the CPU and then causing the system to crash.
[0083] Therefore, in this embodiment, when the current process is in the user address space, it is necessary to obtain the memory data of the continuous address space in the kernel address space for saving the branch trace jump data and map it to the corresponding position in the user address space. And when the current process is in the kernel address space, the branch trace jump data can be directly read from the kernel address space without mapping.
[0084] S308, obtain the branch trace jump data from the kernel address space and the user address space respectively.
[0085] When the current process is in the kernel address space, obtain the branch record jump data from the kernel address space; when the current process is in the user address space and it is impossible to obtain the branch record jump data saved in the kernel address space, then obtain the mapped branch record jump data from the user address space. Therefore, in the above two cases, the branch record jump data can be queried and used normally without causing CPU exceptions.
[0086] The obtained branch record jump data can be used to perform security detection on the current process of the current operating system. For example, by comparing the branch record jump data with trusted data to determine whether there is a threat to the current operating system.
[0087] The branch record implementation method proposed in this embodiment can ensure that after KPTI is enabled in the current operating system, the data captured by the branch record driver can still be used normally, so as to use this data to perform security protection on the current operating system and improve system security.
[0088] Embodiment Three
[0089] As Figure 7 shown, this is a schematic diagram of the hardware architecture of an electronic device 20 proposed in the third embodiment of the present application. In this embodiment, the electronic device 20 may include, but is not limited to, a memory 21, a processor 22, and a network interface 23 that are communicatively connected to each other through a system bus. It should be noted that Figure 7 only the electronic device 20 with components 21-23 is shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. In this embodiment, the electronic device 20 may be the client 2.
[0090] The memory 21 at least includes one type of readable storage medium, and the readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disc, etc. In some embodiments, the memory 21 may be an internal storage unit of the electronic device 20, such as the hard disk or memory of the electronic device 20. In other embodiments, the memory 21 may also be an external storage device of the electronic device 20, such as a plug-in hard disk equipped on the electronic device 20, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Of course, the memory 21 may also include both the internal storage unit of the electronic device 20 and its external storage device. In this embodiment, the memory 21 is generally used to store the operating system and various application software installed in the electronic device 20, such as the program code of the branch record implementation system 60, etc. In addition, the memory 21 may also be used to temporarily store various types of data that have been output or will be output.
[0091] In some embodiments, the processor 22 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 22 is generally used to control the overall operation of the electronic device 20. In this embodiment, the processor 22 is used to run the program code stored in the memory 21 or process data, such as running the branch record implementation system 60, etc.
[0092] The network interface 23 may include a wireless network interface or a wired network interface, and the network interface 23 is generally used to establish a communication connection between the electronic device 20 and other electronic devices.
[0093] Embodiment 4
[0094] As Figure 8 shown, a module schematic diagram of a branch record implementation system 60 is proposed in the fourth embodiment of this application. The branch record implementation system 60 can be divided into one or more program modules, and one or more program modules are stored in a storage medium and executed by one or more processors to complete the embodiments of this application. The program modules referred to in the embodiments of this application refer to a series of computer program instruction segments that can complete specific functions. The following description will specifically introduce the functions of each program module in this embodiment.
[0095] In this embodiment, the branch record implementation system 60 includes:
[0096] A loading module 600, configured to load a branch record driver in a state where KPTI is enabled in the current operating system.
[0097] In this embodiment, the current operating system is a Linux operating system. The branch record driver is a BTS driver, and the BTS driver saves branch information (branch record jump data hereinafter) to a memory space.
[0098] After KPTI is enabled in the Linux operating system, the memory space corresponding to each process includes two address spaces. The first address space is the kernel address space, which can only be accessed in kernel mode and can create mappings to the kernel and users. The second address space is called the shadow address space (user address space). However, due to context switching, part of the kernel address must be included in the shadow address space to establish mappings to interrupt entry and exit. In the Linux operating system, to improve the speed of CR3 switching, the PGD of the kernel address space and the PGD of the user address space are continuously placed in an 8KB memory space. This space must be 8K-aligned, so that the CR3 switching operation is converted into an operation of setting or clearing the 13th bit (from low to high) of the CR3 value.
[0099] In a traditional Linux operating system, due to the incompatibility between the technical characteristics of BTS and KPTI, the BTS driver is not loaded by default in the kernel. In this embodiment, in order to use the branch record jump data collected by the BTS driver for system security detection, the BTS driver is loaded into the kernel of the current operating system (Linux operating system) in a state where KPTI is enabled in the current operating system. For example, the BTS driver is loaded into the kernel through a loading command such as modprobe in the Linux operating system.
[0100] An acquisition module 602, configured to acquire branch record jump data of the current process of the current operating system through the branch record driver.
[0101] The branch record driver (BTS driver) is located in the kernel layer of the operating system, and its purpose is to collect branch record jump data during the operation of the current process of the current system in real time and save the collected branch record jump data. In addition, the data acquisition of the branch record driver can be controlled to be turned on or off at any time, so as to acquire branch record jump data of a specified process.
[0102] A saving module 604, configured to save the branch record jump data to the kernel address space of the current process.
[0103] The memory space corresponding to the current process includes the kernel address space and the user address space. When the current process is in the kernel address space or the user address space, the branch record jump data collected by the branch record driver is saved to the kernel address space.
[0104] The mapping module 606 is used to map the branch record jump data in the kernel address space to the user address space when the current process is in the user address space.
[0105] Since after enabling KPTI in the Linux operating system, the PGD of each process is divided into the PGD of the kernel address space and the PGD of the user address space, and only a very small number of key pages in the user-mode page table are mapped to the kernel address space for handling system interrupts, exceptions, etc. When the CPU is running, the BTS driver will record the branch record jump data into the memory space at any time. If the current process is in the user address space, the BTS driver will write the branch record jump data into the kernel address space, but at this time, the user-mode page table cannot query the kernel address space, resulting in a page fault exception of the CPU and then causing the system to crash.
[0106] Therefore, in this embodiment, when the current process is in the user address space, it is necessary to obtain the memory data of the continuous address space in the kernel address space for saving the branch record jump data and map it to the corresponding position in the user address space. This process specifically includes:
[0107] (1) Locate the first continuous address space in the kernel address space applied by the branch record driver for saving the branch record jump data.
[0108] (2) Read the memory data in the first continuous address space.
[0109] (3) Apply for a second continuous address space in the user address space corresponding to the first continuous address space.
[0110] (4) Copy the memory data to the second continuous address space in the user address space.
[0111] When the current process is in the kernel address space, the branch record jump data can be directly read from the kernel address space without mapping.
[0112] When the branch record jump data needs to be used subsequently, if the current process is in the user address space, the BTS driver will write the branch record jump data into the kernel address space. At this time, the user-mode page table cannot query the kernel address space. However, since the branch record jump data in the kernel address space has been mapped to the user address space in this embodiment, the user-mode page table can query the branch record jump data from the user address space for normal use without causing a CPU exception.
[0113] Embodiment Five
[0114] As Figure 9 shown, the figure is a schematic diagram of modules of a branch record implementation system 60 proposed in the fifth embodiment of the present application. In this embodiment, the branch record implementation system 60 further includes an acquisition module 608 in addition to the loading module 600, the acquisition module 602, the saving module 604, and the mapping module 606 in the fourth embodiment.
[0115] The acquisition module 608 is configured to acquire the branch record jump data from the kernel address space and the user address space respectively.
[0116] When the current process is in the kernel address space, the branch record jump data is acquired from the kernel address space; when the current process is in the user address space and the branch record jump data saved in the kernel address space cannot be acquired, the mapped branch record jump data is acquired from the user address space. Therefore, in the above two cases, the branch record jump data can be queried for normal use without causing a CPU exception.
[0117] The acquired branch record jump data can be used to perform security detection on the current process of the current operating system. For example, by comparing the branch record jump data with trusted data to determine whether there is a threat to the current operating system.
[0118] The branch record implementation system proposed in this embodiment can ensure that after the KPTI is enabled in the current operating system, the data captured by the branch record driver can still be used normally, so as to use the data to perform security protection on the current operating system and improve system security.
[0119] Embodiment Six
[0120] The present application also provides another implementation manner, that is, to provide a computer-readable storage medium storing a branch record implementation program, and the branch record implementation program can be executed by at least one processor, so that the at least one processor executes the steps of the branch record implementation method as described above.
[0121] It should be noted that in this text, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or device comprising such element.
[0122] The serial numbers of the embodiments of the present application above are for description only and do not represent the superiority or inferiority of the embodiments.
[0123] Obviously, those skilled in the art should understand that the various modules or steps of the above embodiments of the present application can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Optionally, they can be implemented by program code executable by the computing device, so that they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order from here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to be implemented. Thus, the embodiments of the present application are not limited to any specific combination of hardware and software.
[0124] The above are only the preferred embodiments of the embodiments of the present application, and do not limit the patent scope of the embodiments of the present application. Any equivalent structural or equivalent process transformation made by using the description and drawings of the embodiments of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the embodiments of the present application.
Claims
1. A method for implementing branch recording, characterized in that, The method includes: Loading a branch record driver in a state where kernel page table isolation is enabled in the current operating system; Collecting branch record jump data of the current process of the current operating system through the branch record driver; Saving the branch record jump data to the kernel address space of the current process; and When the current process is in the user address space, mapping the branch record jump data in the kernel address space to the user address space; Wherein, saving the branch record jump data to the kernel address space of the current process includes: obtaining memory data of a continuous address space in the kernel address space for saving the branch record jump data, and mapping it to a corresponding position in the user address space; Wherein, obtaining memory data of a continuous address space in the kernel address space for saving the branch record jump data, and mapping it to a corresponding position in the user address space includes: Locating a first continuous address space applied by the branch record driver in the kernel address space for saving the branch record jump data; Reading the memory data in the first continuous address space; Applying for a second continuous address space corresponding to the first continuous address space in the user address space; Copying the memory data to the second continuous address space in the user address space.
2. The branch record implementation method according to claim 1, wherein The branch record driver is a branch trace store (BTS) driver that saves the branch record jump data to a memory space.
3. The branch record implementation method according to claim 1, wherein The memory space corresponding to the current process includes the kernel address space and the user address space. When the current process is in the kernel address space or the user address space, the branch record jump data collected by the branch record driver is saved to the kernel address space.
4. The branch record implementation method according to claim 1, wherein, The method further includes: Obtaining the branch record jump data from the kernel address space and the user address space respectively.
5. The branch record implementation method according to claim 4, wherein The obtaining the branch record jump data from the kernel address space and the user address space respectively includes: When the current process is in the kernel address space, obtaining the branch record jump data from the kernel address space; When the current process is in the user address space, obtaining the mapped branch record jump data from the user address space.
6. A branch record implementation system, characterized in that, The system includes: A loading module for loading a branch record driver in a state where kernel page table isolation is enabled in the current operating system; A collecting module for collecting branch record jump data of the current process of the current operating system through the branch record driver; A saving module for saving the branch record jump data to the kernel address space of the current process; A mapping module for mapping the branch record jump data in the kernel address space to the user address space when the current process is in the user address space; Wherein, saving the branch record jump data to the kernel address space of the current process includes: obtaining memory data of a continuous address space in the kernel address space for saving the branch record jump data, and mapping it to a corresponding position in the user address space; Among them, obtaining the memory data of the continuous address space in the kernel address space for storing the branch record jump data and mapping it to the corresponding position in the user address space includes: Locating the first continuous address space applied by the branch record driver in the kernel address space for storing the branch record jump data; Reading the memory data in the first continuous address space; Applying for a second continuous address space corresponding to the first continuous address space in the user address space; Copying the memory data to the second continuous address space in the user address space.
7. An electronic device, characterized in that, The electronic device includes: a memory, a processor, and a branch record implementation program stored on the memory and executable on the processor. When the branch record implementation program is executed by the processor, it implements the branch record implementation method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, A branch record implementation program is stored on the computer-readable storage medium. When the branch record implementation program is executed by a processor, it implements the branch record implementation method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Kernel control flow anomaly detection method based on hardware mechanism
CN107506638A
Attack detection method and device
CN110059477A