A startup protection method, device, electronic device and storage medium

By blocking and removing the communication data flow of the dedicated network port during the startup process of the substrate management controller and performing abnormal detection, the problem of insufficient protection capability during the startup process of the substrate management controller is solved, ensuring the normal startup of the server.

CN115168867BActive Publication Date: 2025-06-13INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210761635.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-30
Publication Date
2025-06-13
Estimated Expiration
2042-06-30

AI Technical Summary

Technical Problem

The substrate management controller has weak protection capabilities during startup and is vulnerable to external attacks, resulting in failure to start normally.

Method used

When the substrate management controller enters the startup boot process, the communication data stream sent through the dedicated network port is blocked; after initialization is completed, the operation information to be detected is extracted from the communication data stream, and abnormal detection and shielding are performed.

Benefits of technology

It effectively resists attacks on the server through the dedicated network port of the substrate management controller, ensuring that the substrate management controller can start normally.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115168867B_ABST
    Figure CN115168867B_ABST
Patent Text Reader

Abstract

The present invention provides a startup protection method, device, electronic equipment and storage medium, which relate to the field of servers. The method comprises: when it is detected that a baseboard management controller enters a startup boot process, shielding a communication data stream sent to the baseboard management controller through a dedicated network port of the baseboard management controller; when it is detected that the dedicated network port completes the initialization operation, unshielding the communication data stream, and extracting operation information to be detected from the communication data stream; performing abnormal detection on the operation information to be detected, and when it is determined that the operation information to be detected contains abnormal information, shielding the abnormal operation corresponding to the operation information to be detected; in each link of the startup of the baseboard management controller, targeted protection can be performed on the threat from the dedicated network port of the baseboard management controller, thereby effectively ensuring the normal startup of the baseboard management controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of servers, and particularly to a startup protection method, device, electronic device, and computer-readable storage medium. Background Art

[0002] The baseboard management controller (BMC) is a core component in a server. It is provided with a dedicated network interface (BMC NIC, network interface controller), and externally, communication with the baseboard management controller and the server can be carried out through this dedicated network interface. In related technologies, since the protection ability of the baseboard management controller is weak during the startup process, external attackers will interfere with the startup process of the baseboard management controller through the dedicated network interface of the baseboard management controller, which may easily lead to the failure of the baseboard management controller to start.

[0003] Therefore, how to resist attacks on the server through the dedicated network interface of the baseboard management controller during the startup process of the baseboard management controller is a technical problem that those skilled in the art need to face. Summary of the Invention

[0004] The purpose of the present invention is to provide a startup protection method, device, electronic device, and computer-readable storage medium, which can provide targeted protection against threats from the dedicated network interface of the baseboard management controller in all aspects of the startup of the baseboard management controller, and thus can effectively ensure the normal startup of the baseboard management controller.

[0005] To solve the above technical problems, the present invention provides a startup protection method, including:

[0006] When it is detected that the baseboard management controller enters the startup boot process, the communication data stream sent to the baseboard management controller through the dedicated network interface of the baseboard management controller is blocked;

[0007] When it is detected that the baseboard management controller completes the initialization operation of the dedicated network interface, the blocking of the communication data stream is released, and the operation information to be detected is extracted from the communication data stream;

[0008] The operation information to be detected is subjected to anomaly detection, and when it is determined that the operation information to be detected contains abnormal information, the abnormal operation corresponding to the operation information to be detected is blocked.

[0009] Optionally, the anomaly detection of the operation information to be detected includes:

[0010] Signature information is extracted from the operation information to be detected, and the signature information is verified for signature;

[0011] When it is determined that the signature information is invalid, it is determined that the operation information to be detected includes the abnormal information.

[0012] Optionally, the performing abnormality detection on the operation information to be detected includes:

[0013] Extracting the source IP address to be detected from the operation information to be detected;

[0014] When it is determined that the source IP address to be detected does not belong to the designated source IP address, it is determined that the operation information to be detected includes the abnormal information.

[0015] Optionally, after shielding the abnormal operation corresponding to the operation information to be detected, the method further includes:

[0016] Determining whether there is operation information corresponding to the abnormal operation in the communication data stream that has completed the shielding process;

[0017] If so, the dedicated network port is software shielded until it is detected that the server enters the system boot process, and the software shielding of the dedicated network port is released.

[0018] Optionally, the performing software shielding on the dedicated network port includes:

[0019] The driver of the dedicated network port is searched and the driver is shielded.

[0020] Optionally, after removing the software shielding of the dedicated network port, the method further comprises:

[0021] Determining whether there is operation information corresponding to the abnormal operation in the communication data stream;

[0022] If so, the operation information corresponding to the abnormal operation is forwarded to the designated interface of the baseboard management controller, so that the preset code logic in the designated interface responds to the abnormal operation and guides the attack end corresponding to the abnormal operation to enter an infinite loop state.

[0023] Optionally, after detecting that the baseboard management controller enters the startup boot process, the method further includes:

[0024] Recording the execution duration corresponding to each step in the boot process executed by the baseboard management controller, and determining whether the execution duration is greater than the preset execution time of the corresponding target step;

[0025] If yes, the baseboard management controller is controlled to re-execute the previous step of the target step.

[0026] The present invention also provides a startup protection device, comprising:

[0027] A first shielding module, configured to shield a communication data stream sent to the baseboard management controller through a dedicated network port of the baseboard management controller when it is detected that the baseboard management controller enters a startup boot process;

[0028] A to-be-detected operation information extraction module, configured to lift the shielding of the communication data stream and extract to-be-detected operation information from the communication data stream when it is detected that the baseboard management controller completes an initialization operation on the dedicated network port;

[0029] A second shielding module, configured to perform anomaly detection on the to-be-detected operation information and shield an abnormal operation corresponding to the to-be-detected operation information when it is determined that the to-be-detected operation information contains anomaly information.

[0030] The present invention further provides an electronic device, including:

[0031] A memory, configured to store a computer program;

[0032] A processor, configured to implement the startup protection method as described above when executing the computer program.

[0033] The present invention further provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are loaded and executed by a processor, the startup protection method as described above is implemented.

[0034] The present invention provides a startup protection method, including: shielding a communication data stream sent to the baseboard management controller through a dedicated network port of the baseboard management controller when it is detected that the baseboard management controller enters a startup boot process; lifting the shielding of the communication data stream and extracting to-be-detected operation information from the communication data stream when it is detected that the dedicated network port completes an initialization operation; performing anomaly detection on the to-be-detected operation information and shielding an abnormal operation corresponding to the to-be-detected operation information when it is determined that the to-be-detected operation information contains anomaly information.

[0035] It can be seen that when the present invention detects that the baseboard management controller enters the startup boot process, it can first block the communication data stream sent to the baseboard management controller through the dedicated network port of the baseboard management controller to prevent the interference of the external communication data stream on the startup boot process of the baseboard management controller. Subsequently, when it is determined that the baseboard management controller has completed the initialization operation of the dedicated network port, at this time, to avoid the interference of no network communication on the subsequent startup process of the baseboard management controller, the shielding of the communication data stream can be lifted, and the abnormal detection of the to-be-detected operation information included in the communication data stream can be continued. When it is found that the to-be-detected operation information contains abnormal information, the abnormal operation corresponding to the operation information is blocked, that is, it can perform targeted protection against the threats from the dedicated network port of the baseboard management controller in each link of the startup of the baseboard management controller, and thus can effectively ensure the normal startup of the baseboard management controller. The present invention also provides a startup protection device, an electronic device, and a computer-readable storage medium, which have the above beneficial effects. Description of the Drawings

[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.

[0037] Figure 1 It is a flowchart of a startup protection method provided by an embodiment of the present invention;

[0038] Figure 2 It is a structural block diagram of a startup protection device provided by an embodiment of the present invention. Detailed Embodiments

[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0040] The Baseboard Management Controller (BMC) is a core component in a server. It is equipped with a dedicated network interface controller (BMC NIC). Externally, communication with the BMC and the server can be carried out through this dedicated network interface. In the related art, since the protection ability of the BMC is weak during the startup process, external attackers can interfere with the startup process of the BMC through the dedicated network interface of the BMC, which may easily cause the BMC to fail to start. In view of this, the present invention can provide a startup protection method, which can specifically protect against threats from the dedicated network interface of the BMC in all links of the BMC startup process, thereby effectively ensuring the normal startup of the BMC. Please refer to Figure 1 , Figure 1 is a flowchart of a startup protection method provided by an embodiment of the present invention. The method may include:

[0041] S101. When it is detected that the BMC enters the startup boot process, block the communication data stream sent to the BMC through the dedicated network interface of the BMC.

[0042] The Baseboard Management Controller startup boot process (BMC Boot) is the first process that the Baseboard Management Controller needs to execute during startup. In this process, the controller will perform a series of initial boot operations such as kernel loading. Since in this process, various complex protection mechanisms in the Baseboard Management Controller are still in the loading or pending loading state and cannot be used normally, the controller basically has no ability to resist external attacks in this startup process and is easily controlled by external attackers through read-write attacks. For example, an external attacker can send a control signal to the Baseboard Management Controller through the dedicated network port of the Baseboard Management Controller to prevent the controller from starting normally, or control the Baseboard Management Controller to add abnormal data to the system kernel, thereby threatening the security of the Baseboard Management Controller and the server. It should be noted that although the above dedicated network port has not been initialized during the Baseboard Management Controller startup boot process, it can still receive some basic read-write signals, which provides the possibility for external attackers to attack the Baseboard Management Controller and the server. Exactly for this reason, the embodiments of the present invention need to specifically detect the communication data stream sent to the Baseboard Management Controller through the dedicated network port of the Baseboard Management Controller to avoid the situation where the Baseboard Management Controller cannot start or unsafe factors are loaded into the system kernel following the Baseboard Management Controller startup boot process. Specifically, as described above, during the Baseboard Management Controller startup boot process, the dedicated network port of the controller has not actually been initialized. At this time, the Baseboard Management Controller and the server will not use this dedicated network port to communicate with the outside world. Therefore, in this process, all communication data streams sent to the Baseboard Management Controller through the dedicated network port of the Baseboard Management Controller can be blocked. Specifically, all communication data received in this process can be ignored or discarded.

[0043] Of course, it is understandable that, since the baseboard management controller does not have a strong protection capability when executing the boot process, it may still release some communication data, and this part of the communication data will interfere with the baseboard management controller's execution of the boot process, for example, causing the baseboard management controller to be unable to complete the boot process. Therefore, in order to further reduce the impact of external interference on the baseboard management controller, the baseboard management controller itself can also detect the situation of executing the boot process, and automatically repair when it is determined that the baseboard management controller has a startup abnormality. Specifically, the corresponding execution time can be preset for each step in the boot process; at the same time, the execution duration corresponding to each step in the boot process executed by the baseboard management controller is recorded, and it is determined whether this execution duration exceeds the corresponding preset execution time. If it exceeds, it can be determined that the baseboard management controller has an abnormal situation and needs to be repaired. Furthermore, when an abnormal step is found, the baseboard management controller can be controlled to re-execute the previous step of the step to guide the baseboard management controller to restart, so as to avoid the situation where it cannot be started due to interference with a certain step. It should be noted that the embodiment of the present invention does not limit the preset execution time corresponding to each step in the boot process of the baseboard management controller, and can be set according to actual application requirements.

[0044] In a possible case, after detecting that the baseboard management controller enters the startup boot process, the following steps may also be included:

[0045] Step 11: Record the execution duration corresponding to each step in the boot process executed by the baseboard management controller, and determine whether the execution duration is greater than the preset execution time of the corresponding target step; if so, proceed to step 12; if not, ignore;

[0046] Step 12: Control the baseboard management controller to re-execute the previous step of the target step.

[0047] S102: when it is detected that the baseboard management controller completes the initialization operation on the dedicated network port, the shielding of the communication data stream is released, and the operation information to be detected is extracted from the communication data stream.

[0048] It should be noted that after the baseboard management controller completes the startup boot process, it will execute the kernel initialization process. In the latter process, the baseboard management controller will initialize each hardware unit it contains, including the initialization of the dedicated network port. The embodiments of the present invention do not limit the initialization method of the dedicated network port of the baseboard management controller, and relevant technologies of the baseboard management controller can be referred to. After completing the initialization of the dedicated network port, the baseboard management controller can communicate with the outside world through this network port. Moreover, in the subsequent startup process, the baseboard management controller also needs to communicate with the outside world through the dedicated network port. Therefore, after determining that the dedicated network port has been initialized, the embodiments of the present invention will automatically lift the shielding of the communication data stream in the dedicated network port. Of course, it can be understood that external attacks will still interfere with the startup of the baseboard management controller and the server through the dedicated network port. Therefore, the embodiments of the present invention will extract the operation information to be detected from the communication data stream in real time to detect abnormal operations in a timely manner.

[0049] S103. Perform anomaly detection on the operation information to be detected, and when it is determined that the operation information to be detected contains anomaly information, shield the abnormal operation corresponding to the operation information to be detected.

[0050] It should be noted that the embodiments of the present invention do not limit how to perform anomaly detection on the operation information to be detected. For example, it can be required that the operation information sent by the outside to the server contains signature information, which is signed by the secret key held by the server. Then, when receiving the operation information to be detected, the signature information it contains can be verified. If the signature is found to be invalid, it can be determined that the operation information to be detected contains anomaly information.

[0051] In a possible situation, performing anomaly detection on the operation information to be detected may include:

[0052] Step 21: Extract signature information from the operation information to be detected and verify the signature information;

[0053] Step 22: When it is determined that the signature information is invalid, determine that the operation information to be detected contains anomaly information.

[0054] It should be noted that the embodiments of the present invention do not limit the specific signature method and the specific signature verification method, and relevant signature technologies can be referred to. Further, anomaly detection of the operation information to be detected can also be performed by verifying the source IP address it contains. Specifically, the server usually communicates with only a small number of devices in the internal network, that is, the communication data received by the server usually comes from only a few internal network devices. Therefore, as long as the IP addresses of the above internal network devices are recorded and it is determined that the source IP address in the operation information to be detected does not belong to the above specified source IP addresses, it can be determined that the operation information to be detected contains anomaly information.

[0055] In a possible case, performing anomaly detection on the operation information to be detected may include:

[0056] Step 31: extracting the source IP address to be detected from the operation information to be detected;

[0057] Step 32: When it is determined that the source IP address to be detected does not belong to the designated source IP address, it is determined that the operation information to be detected contains abnormal information.

[0058] After determining that the operation information to be detected contains abnormal information, it can be determined that the operation corresponding to the information is an abnormal operation, and then the abnormal operation needs to be shielded. Of course, considering that the baseboard management controller may still fail to shield the abnormal operation, after the shielding process, the shielded communication data stream can still be re-detected to determine whether it still contains the operation information corresponding to the abnormal operation. If so, it can be determined that the previous shielding is not in place. At this time, in order to ensure the normal startup of the baseboard management controller and the server, the dedicated network port can be first shielded by software until the server enters the system boot process, that is, when the server has stronger protection capabilities, the shielding of the dedicated network port can be lifted.

[0059] In a possible case, after shielding the abnormal operation corresponding to the operation information to be detected, the following may also be included:

[0060] Step 41: determine whether there is operation information corresponding to the abnormal operation in the communication data stream that has completed the shielding process; if so, proceed to step 42; if not, ignore;

[0061] Step 42: Perform software shielding on the dedicated network port until it is detected that the server enters the system boot process, and then release the software shielding on the dedicated network port.

[0062] Of course, it is understandable that when the dedicated network port is blocked, it will affect some startup processes of the baseboard management controller and the server. At this time, in order to facilitate the operation and maintenance personnel to check, the corresponding alarm information can be generated and recorded for the convenience of the operation and maintenance personnel to check. It should be noted that the embodiment of the present invention does not limit the specific method of software blocking of the dedicated network port. In order not to affect the execution of other initialization operations by the dedicated network port, the driver of the dedicated network port can be blocked.

[0063] In one possible scenario, software shielding of the dedicated network port may include:

[0064] Step 51: Find the driver of the dedicated network port and block the driver.

[0065] Based on the above embodiments, when the present invention detects that the baseboard management controller enters the startup boot process, it can first block the communication data stream sent to the baseboard management controller through the dedicated network port of the baseboard management controller to prevent external communication data streams from interfering with the startup boot process of the baseboard management controller; subsequently, when it is determined that the baseboard management controller has completed the initialization operation of the dedicated network port, at this time, to avoid the interference of no network communication on the subsequent startup process of the baseboard management controller, the shielding of the communication data stream can be lifted, and the abnormal detection of the operation information to be detected included in the communication data stream can be continued; when it is found that the operation information to be detected includes abnormal information, the abnormal operation corresponding to the operation information is blocked, that is, it is possible to perform targeted protection against threats from the dedicated network port of the baseboard management controller in each link of the startup of the baseboard management controller, and thus effectively ensure the normal startup of the baseboard management controller.

[0066] Based on the above embodiments, the embodiments of the present invention can also protect the startup process of the server. Specifically, when it is determined that the server enters the system boot process, if the operation information corresponding to the abnormal operation is still extracted from the dedicated network port, without affecting the normal operation of the server, the attack behavior can also be dealt with by guiding the attacker into a crash infinite loop. In a possible situation, after lifting the software shielding of the dedicated network port, it may further include:

[0067] S201. Determine whether there is operation information corresponding to an abnormal operation in the communication data stream; if so, proceed to step S202; if not, ignore it.

[0068] It should be noted that the detection of abnormal operations here still uses the above signature verification and source IP verification means, and reference can be made to the above embodiments.

[0069] S202. Forward the operation information corresponding to the abnormal operation to the designated interface of the baseboard management controller, so that the preset code logic in the designated interface responds to the abnormal operation and guides the attack end corresponding to the abnormal operation into an infinite loop state.

[0070] In the embodiments of the present invention, an additional designated interface is added to the baseboard management controller. Multiple groups of code logics are preset in this interface, and these code logics are all transformed based on the existing code logic of the baseboard management controller. They can not only respond to abnormal operations, but also guide the supply end corresponding to the abnormal operation into an infinite loop state, that is, a virtual space can be provided for the attacker, and the attack behavior of the attacker can be restricted in this space, so as to effectively cope with external attacks without affecting the normal operation of the server. It should be noted that the embodiments of the present invention do not limit the above preset code logic, and it can be set according to actual application requirements.

[0071] Based on the above embodiments, the embodiments of the present invention can use a preset interface and code logic to guide an attacker into a crashing infinite loop, and thus can effectively cope with external attacks without affecting the normal operation of the server.

[0072] The following introduces the above-mentioned startup protection method based on specific examples. The above process specifically includes:

[0073] 1. The FT2000 + ARM server is powered on, and the baseboard management controller starts to boot.

[0074] 2. Before entering the BMC boot startup, the security protection starts. It will automatically block the communication data in the BMC NIC and will automatically determine whether there is an abnormal attack that endangers the abnormal startup of the BMC.

[0075] 3. If there is an abnormal attack behavior, protective measures will be taken to optimize the startup space. Specifically, multiple link trainings will be adopted, that is, the BMC will be guided to repeatedly execute the previous step corresponding to the abnormal step, so as to timely detect and repair the abnormality, so as to ensure the security and normality of the BMC during the boot startup. At the same time, a log will be reported for the security attack that appears to remind the server maintenance personnel that there is an unstable security factor intrusion.

[0076] 4. After determining that the BMC NIC has completed initialization, a dynamic security digital signature verification of the security trusted root is performed on the entered file program in real time. The BMC NIC is mainly used by the BMC of the server, and a design scheme of layer-by-layer protection of dynamic nodes is adopted for the abnormal digital signature verification of security. If the abnormality cannot be blocked, it can be safely blocked by closing the interface.

[0077] 5. When the server enters the system boot, it will further determine whether it is under an abnormal attack.

[0078] 6. If it is under an abnormal attack, the abnormal attack can be guided to a specified interface in the BMC to induce it to attack the BMC to provide a series of pseudo-code logics. The present invention can design a small system process of BMC pseudo-code for external attackers to attack and feedback real-time simulation of abnormal parameter sequences to the attackers, and finally induce unstable security attacks to enter the fatigue sleep state.

[0079] The following introduces the startup protection device, electronic device and computer-readable storage medium provided by the embodiments of the present invention. The startup protection device, electronic device and computer-readable storage medium described below can be correspondingly referred to each other with the startup protection method described above.

[0080] Please refer to Figure 2 , Figure 2 which is a structural block diagram of a startup protection device provided by an embodiment of the present invention. The device may include:

[0081] The first shielding module 201 is configured to shield the communication data stream sent to the baseboard management controller through the dedicated network port of the baseboard management controller when it is detected that the baseboard management controller enters the startup boot process;

[0082] The operation information to be detected extraction module 202 is configured to lift the shielding of the communication data stream and extract the operation information to be detected from the communication data stream when it is detected that the baseboard management controller completes the initialization operation of the dedicated network port;

[0083] The second shielding module 203 is configured to perform anomaly detection on the operation information to be detected, and shield the abnormal operation corresponding to the operation information to be detected when it is determined that the operation information to be detected contains anomaly information.

[0084] Optionally, the second shielding module 203 includes:

[0085] The signature verification sub-module is configured to extract signature information from the operation information to be detected and perform signature verification on the signature information;

[0086] The first determination sub-module is configured to determine that the operation information to be detected contains anomaly information when it is determined that the signature information is invalid.

[0087] Optionally, the second shielding module 203 includes:

[0088] The IP extraction sub-module is configured to extract the source IP address to be detected from the operation information to be detected;

[0089] The second determination sub-module is configured to determine that the operation information to be detected contains anomaly information when it is determined that the source IP address to be detected does not belong to the specified source IP address.

[0090] Optionally, the device may further include:

[0091] The first judgment module is configured to judge whether there is operation information corresponding to an abnormal operation in the communication data stream for which the shielding process has been completed;

[0092] The dedicated network port shielding module is configured to, if so, perform software shielding on the dedicated network port until it is detected that the server enters the system boot process, and then lift the software shielding on the dedicated network port.

[0093] Optionally, the dedicated network port shielding module may include:

[0094] The driver shielding sub-module is configured to find the driver program of the dedicated network port and shield the driver program.

[0095] Optionally, the device may further include:

[0096] A second judgment module, configured to judge whether there is operation information corresponding to an abnormal operation in the communication data stream;

[0097] A guiding module, configured to, if so, forward the operation information corresponding to the abnormal operation to a specified interface of the baseboard management controller, so that the preset code logic in the specified interface responds to the abnormal operation and guides the attacking end corresponding to the abnormal operation into an infinite loop state.

[0098] Optionally, the device may further include:

[0099] A recording module, configured to record the execution duration corresponding to each step in the startup boot process executed by the baseboard management controller, and judge whether the execution duration is greater than the execution time preset for the corresponding target step;

[0100] A repair module, configured to, if so, control the baseboard management controller to re-execute the previous step of the target step.

[0101] An embodiment of the present invention further provides an electronic device, including:

[0102] A memory, configured to store a computer program;

[0103] A processor, configured to implement the steps of the startup protection method as described above when executing the computer program.

[0104] Since the embodiments of the electronic device part correspond to the embodiments of the startup protection method part, for the descriptions of the embodiments of the electronic device part, please refer to the descriptions of the embodiments of the startup protection method part, which will not be repeated here.

[0105] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the startup protection method in any of the above embodiments are implemented.

[0106] Since the embodiments of the computer-readable storage medium part correspond to the embodiments of the startup protection method part, for the descriptions of the embodiments of the storage medium part, please refer to the descriptions of the embodiments of the startup protection method part, which will not be repeated here.

[0107] The embodiments in the specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description in the method part.

[0108] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered as exceeding the scope of the present invention.

[0109] The steps of the methods or algorithms described in combination with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0110] The above has introduced in detail a startup protection method, device, electronic device, and computer-readable storage medium provided by the present invention. Specific examples are used herein to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.

Claims

1. A startup protection method, It is characterized in that include: When it is detected that the baseboard management controller enters the boot process, shielding the communication data stream sent to the baseboard management controller through the dedicated network port of the baseboard management controller; When it is detected that the baseboard management controller completes the initialization operation on the dedicated network port, the shielding of the communication data stream is released, and the operation information to be detected is extracted from the communication data stream; Performing anomaly detection on the operation information to be detected, and when it is determined that the operation information to be detected contains abnormal information, shielding the abnormal operation corresponding to the operation information to be detected; The performing abnormality detection on the operation information to be detected includes: Extracting signature information from the operation information to be detected, and performing signature verification on the signature information; When it is determined that the signature information is invalid, determining that the operation information to be detected includes the abnormal information; Extracting the source IP address to be detected from the operation information to be detected; When it is determined that the source IP address to be detected does not belong to the designated source IP address, it is determined that the operation information to be detected includes the abnormal information.

2. The startup protection method according to claim 1, It is characterized in that After shielding the abnormal operation corresponding to the operation information to be detected, the method further includes: Determining whether there is operation information corresponding to the abnormal operation in the communication data stream that has completed the shielding process; If so, the dedicated network port is software shielded until it is detected that the server enters the system boot process, and the software shielding of the dedicated network port is released.

3. The startup protection method according to claim 2, It is characterized in that The software shielding of the dedicated network port includes: The driver of the dedicated network port is searched and the driver is shielded.

4. The startup protection method according to claim 2, It is characterized in that After the software shielding of the dedicated network port is released, the following steps are performed: Determining whether there is operation information corresponding to the abnormal operation in the communication data stream; If so, the operation information corresponding to the abnormal operation is forwarded to the designated interface of the baseboard management controller, so that the preset code logic in the designated interface responds to the abnormal operation and guides the attack end corresponding to the abnormal operation to enter an infinite loop state.

5. The startup protection method according to any one of claims 1 to 4, It is characterized in that After detecting that the baseboard management controller enters the boot process, the following steps are also included: Recording the execution duration corresponding to each step in the boot process executed by the baseboard management controller, and determining whether the execution duration is greater than the preset execution time of the corresponding target step; If yes, the baseboard management controller is controlled to re-execute the previous step of the target step.

6. A start-up protection device, It is characterized in that include: A first shielding module is used to shield the communication data stream sent to the baseboard management controller through the dedicated network port of the baseboard management controller when it is detected that the baseboard management controller enters the startup boot process; The operation information extraction module to be detected is used to lift the shielding of the communication data stream and extract the operation information to be detected from the communication data stream when it is detected that the baseboard management controller has completed the initialization operation of the dedicated network port; The second shielding module is used to perform anomaly detection on the operation information to be detected, and when it is determined that the operation information to be detected contains anomaly information, shield the abnormal operation corresponding to the operation information to be detected; The second shielding module includes: The signature verification sub-module is used to extract signature information from the operation information to be detected and perform signature verification on the signature information; The first determination sub-module is used to determine that the operation information to be detected contains the anomaly information when it is determined that the signature information is invalid; The IP extraction sub-module is used to extract the source IP address to be detected from the operation information to be detected; The second determination sub-module is used to determine that the operation information to be detected contains the anomaly information when it is determined that the source IP address to be detected does not belong to the specified source IP address.

7. An electronic device, characterized in that, it includes: a memory for storing computer programs; a processor for implementing the startup protection method according to any one of claims 1 to 5 when executing the computer program.

8. A computer-readable storage medium, characterized in that, the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, the startup protection method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Method for dynamic setting management function at management interface of intelligent interface

    CN101001167A

  • Method for performing communication through API and device

    CN108847997A