Cloud desktop black and white list control method, device and equipment
Patent Information
- Application Number
- CN202210687871.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-17
- Publication Date
- 2026-09-04
- Estimated Expiration
- 2042-06-17
AI Technical Summary
[0004]目前云桌面实现软件黑白名单控制策略通常在用户态实现,但这种实现方式存在无法阻止软件的安装,无法阻止杀毒软件的运行等缺陷
[0019] Technical Effects: This invention installs a first driver in the cloud desktop for implementing software blacklist/whitelist control. The first driver registers a first callback function at the operating system layer. When the operating system operates on a process handle, the first callback function is triggered and executed. The first callback function obtains process information and controls the installed and running software according to the software blacklist/whitelist control policy issued by the cloud desktop management platform. This invention can restrict or allow only the installation and operation of specific software, improving the security and controllability of the cloud desktop.
Smart Images

Figure CN115202807B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of cloud computing and communication technology, and in particular to a cloud desktop blacklist / whitelist control method, apparatus, and device. Background Technology
[0002] In the current context, cloud desktops are widely used in enterprise office environments. Cloud desktops bring convenience and efficiency to enterprise operations and maintenance, while enterprises are paying increasing attention to the security of cloud desktops and expect to have control over the software running on them.
[0003] Virtual Desktop Infrastructure (VDI) hosts a user's desktop environment as virtual machines on a high-performance server, providing a user experience almost identical to that of a physical personal computer (PC). Ordinary users can use their cloud desktops on various terminal devices such as PCs and thin clients to complete daily office tasks. Administrators can achieve visual management and batch deployment of all cloud desktop resources to meet the needs of a large number of users. VDI mainly includes terminal devices, cloud desktop clients, desktop connection protocols, a cloud desktop management platform, a virtualization management platform, agent proxies, infrastructure components, and a desktop resource pool. The desktop resource pool is a pool of virtual machines (VMs) providing cloud desktop services. The cloud desktop client runs on the terminal device, connects to the cloud desktop management platform via the desktop connection protocol, and connects to the virtual machine allocated by the cloud desktop management platform after the login account is authenticated and authorized by the authentication system.
[0004] Currently, cloud desktop implementations of software blacklist / whitelist control strategies are typically implemented in user space. However, this approach has drawbacks, such as the inability to prevent software installation or the operation of antivirus software. Summary of the Invention
[0005] In view of this, the present invention provides a cloud desktop blacklist / whitelist control method, apparatus and device to improve the security and controllability of cloud desktops.
[0006] Based on one aspect of the embodiments of the present invention, the present invention provides a cloud desktop blacklist / whitelist control method, the method being applied to a cloud desktop, the method comprising:
[0007] When the cloud desktop starts, the first driver is loaded, and the first driver calls the operating system kernel's callback registration function to register the first callback function;
[0008] The first callback function controls the software running on the cloud desktop according to the software blacklist / whitelist control policy issued by the cloud desktop management platform.
[0009] Furthermore, when the first callback function is called, process information is obtained based on the input parameters passed to the first callback function; when the software blacklist / whitelist control policy is a blacklist policy and the name of the software to be installed or run is determined to be in the software blacklist based on the process information, process creation is prohibited; otherwise, process creation is allowed; when the software blacklist / whitelist control policy is a whitelist policy and the name of the software to be installed or run is determined to be in the software whitelist or is a system process based on the process information, process creation is allowed; otherwise, process creation is prohibited.
[0010] Furthermore, the first driver is loaded through the Agent module of the cloud desktop; the first driver obtains the software blacklist / whitelist control policy from the cloud desktop management platform through the Agent when it starts up.
[0011] Furthermore, the method also includes: when the software blacklist / whitelist control policy in the cloud desktop management platform is updated, the Agent calls the driver IO control interface to send and update the software blacklist / whitelist control policy to the first driver.
[0012] Furthermore, the method also includes: the first callback function is further used to write the process information that is prohibited from installation or running into a specified location in the registry; and to monitor the changes in the specified location in the registry through a monitoring interface, and report the process information that is prohibited from installation or running into the cloud desktop management platform.
[0013] Based on embodiments of the present invention, the present invention also provides a cloud desktop blacklist / whitelist control device, which is applied to a cloud desktop and includes:
[0014] The proxy module is used to load the first driver when the cloud desktop starts.
[0015] The first driver is used to obtain the software blacklist / whitelist control policy issued by the cloud desktop management platform and call the callback registration function of the operating system kernel to register the first callback function; the first callback function controls the software running on the cloud desktop according to the software blacklist / whitelist control policy issued by the cloud desktop platform.
[0016] Furthermore, when the first callback function is invoked, the first driver obtains process information based on the input parameters passed to the first callback function; when the software blacklist / whitelist control policy is a blacklist policy and the name of the software to be installed or run is determined to be in the software blacklist based on the process information, the first driver prohibits process creation; otherwise, process creation is allowed; when the software blacklist / whitelist control policy is a whitelist policy and the name of the software to be installed or run is determined to be in the software whitelist or is a system process based on the process information, the first driver allows process creation; otherwise, process creation is prohibited.
[0017] Furthermore, when the first driver starts up, it obtains the software blacklist / whitelist control policy from the cloud desktop management platform through the Agent; when the software blacklist / whitelist control policy in the cloud desktop management platform is updated, the Agent calls the driver IO control interface to send and update the software blacklist / whitelist control policy to the first driver.
[0018] Furthermore, the device also includes: the first callback function of the first driver registration is further used to write the process information that is prohibited from installation or running into a specified location in the registry; the agent module monitors the changes in the specified location in the registry through a monitoring interface and reports the process information that is prohibited from installation or running to the cloud desktop management platform.
[0019] Technical Effects: This invention installs a first driver in the cloud desktop for implementing software blacklist / whitelist control. The first driver registers a first callback function at the operating system layer. When the operating system operates on a process handle, the first callback function is triggered and executed. The first callback function obtains process information and controls the installed and running software according to the software blacklist / whitelist control policy issued by the cloud desktop management platform. This invention can restrict or allow only the installation and operation of specific software, improving the security and controllability of the cloud desktop. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments of the present invention or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those skilled in the art, other drawings can be obtained from these drawings of the embodiments of the present invention.
[0021] Figure 1 A flowchart illustrating the steps of a cloud desktop blacklist / whitelist control method according to an embodiment of the present invention;
[0022] Figure 2 This is a schematic diagram of the structure of a cloud desktop blacklist / whitelist control system provided in an embodiment of the present invention;
[0023] Figure 3 This is a schematic diagram of the electronic device structure for implementing the cloud desktop software blacklist / whitelist control method provided by the present invention. Detailed Implementation
[0024] The terminology used in this embodiment of the invention is for the purpose of describing particular embodiments only and is not intended to limit the embodiments of the invention. The singular forms “a,” “the,” and “the” as used in this embodiment are also intended to include the plural forms unless the context clearly indicates otherwise. The term “and / or” as used in this invention refers to any or all possible combinations comprising one or more of the associated listed items.
[0025] It should be understood that although the terms first, second, third, etc., may be used to describe various information in embodiments of the present invention, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of embodiments of the present invention, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" may also be interpreted as "when," "when," or "in response to a determination."
[0026] In some specific cloud desktop scenarios, customers need to prevent certain software from running on the cloud desktop to provide a relatively stable system environment. Administrators want to be able to issue software blacklist control policies for cloud desktops to prohibit the installation, startup, and running of software processes on the blacklist. In other cloud desktop application scenarios, such as educational applications, for the stability and security of the teaching environment, users want to allow only teaching-related applications and necessary system software to run on the cloud desktop. They require cloud desktop administrators to configure software whitelist control policies to prevent the installation, startup, and running of non-whitelisted software on the cloud desktop.
[0027] Based on the above requirements, the purpose of this invention is to provide a cloud desktop blacklist / whitelist control method to meet the cloud desktop's control requirements for software blacklists / whitelists. The basic idea of this invention is to provide a device driver for implementing software blacklist / whitelist control, load this device driver in the cloud desktop, register callback functions at the operating system layer through this driver, and monitor the software installed and running on the cloud desktop through the callback functions, blocking software applications that do not comply with the software blacklist / whitelist control policies issued by the cloud management platform.
[0028] Figure 1 The flowchart illustrates the steps of a cloud desktop blacklist / whitelist control method according to an embodiment of the present invention. This method is applied to the host machine where the cloud desktop is located. The cloud desktop client first logs into the cloud desktop management platform through the remote desktop protocol. Under the control of the cloud desktop management platform, a remote connection with the cloud desktop is established. The cloud desktop management platform issues software blacklist / whitelist control policies to the cloud desktop based on the configuration.
[0029] Step 110. Load the first driver when the cloud desktop starts;
[0030] In a VDI architecture, when each cloud desktop (i.e., the virtual machine providing cloud desktop services) starts up, the cloud desktop management platform determines, based on the configuration, whether to enable the software blacklist or whitelist control policy for that cloud desktop. Typically, software blacklist and whitelist control policies are mutually exclusive; by default, configuring either control policy will not take effect.
[0031] If a software blacklist / whitelist control policy is enabled, the cloud desktop management platform can control the loading of the first driver on the cloud desktop. The first driver is used to implement the software blacklist / whitelist control function. The first driver can also be loaded by default when the cloud desktop starts, but the control function needs to be enabled according to instructions.
[0032] Step 120. The first driver obtains the software blacklist / whitelist control policy from the cloud desktop management platform;
[0033] FirstDriver can obtain software blacklist / whitelist control policies from the cloud desktop management platform in two ways: one is that FirstDriver actively retrieves them from the cloud desktop management platform when it starts or restarts, and the other is that it actively pushes them to the cloud desktop when the cloud desktop management platform changes the software blacklist / whitelist control policies. The two methods can be used in combination.
[0034] In the VDI framework, cloud desktops all include an Agent module, through which the cloud desktop management platform distributes control policies to the cloud desktops. Therefore, in the VDI framework, software blacklist / whitelist control policies can be distributed to the first driver through the Agent module.
[0035] In one embodiment of the present invention, the application layer module can call CreateFile to open the device file of the first driver, and then call the DeviceIoControl interface to send various control codes, i.e., command words, to the first driver. The first driver can then perform specific tasks according to the control codes. The application layer module can use the SystemBuffer field in the IRP (I / O Request Package) request to carry the sent policy information.
[0036] Drivers can define control codes using the CTL_CODE macro and perform control code operations within the IRP_MJ_DEVICE_CONTROL implementation. Different control codes (e.g., those starting with IOCTL_ or FSCTL_) can invoke different types of functions within the device driver. IRP (I / O Request Package) is short for data request packet. When an application initiates a CreateFile or ReadFile API operation on the device, it encapsulates the relevant parameter information into an IRP packet, which is then passed to the driver via IoCallDriver.
[0037] In this embodiment of the invention, the first driver can be dynamically controlled to acquire and switch software blacklist / whitelist control policies via the DeviceIoControl interface. For example, when the cloud desktop management platform changes the software blacklist / whitelist control policy of cloud desktop 1 from a blacklist control policy to a whitelist control policy, it sends the new software whitelist control policy to the Agent of cloud desktop 1. The Agent instructs the first driver to switch the previous software blacklist control policy to a software whitelist control policy by calling the DeviceIoControl interface in conjunction with control codes.
[0038] Step 130. The first driver calls the operating system kernel's callback registration function to register the first callback function;
[0039] In some versions of the Windows operating system, the operating system kernel has callback registration functions such as the ObRegisterCallbacks function, which can be used to register a list of callback functions for process, thread, and desktop handle operations.
[0040] The first driver can register a first callback function for the cloud desktop to execute software blacklist / whitelist control policies via the ObRegisterCallbacks function. Specifically, the registered first callback function, the object type (ObjectType), and the operation type (OB_Operation) that the first callback function listens for can be set in the OB_CALLBACK_REGISTRATION parameter structure of the ObRegisterCallbacks function. The first callback function will be triggered to execute when the operating system operates on the process or thread handle. The operation type (OB_Operation) can include creation and run operations.
[0041] Prior to Vista, similar callback function registration could be achieved by registering system hooks. The underlying principle is similar and will not be elaborated upon here.
[0042] The following describes an example of implementing the first driver and the first callback function:
[0043] (1) In the first driver entry function DriverEntry, the first callback function is registered by calling ObRegisterCallbacks and added to the callback list of the operating system;
[0044] The DriverEntry function is the first function called after the driver is loaded; it is responsible for initializing the driver program. An example of the driver entry function is shown below:
[0045]
[0046] (2) Set the first callback function using PsSetCreateProcessNotifyRoutineEx, and register the set first callback function to the operating system's callback list using ObRegisterCallbacks:
[0047]
[0048] Once the first callback function is registered, it will be executed when a new process is created. The operating system will pass the parent process ID and the child process (the newly created process) ID to the first callback function, which will then obtain the process information by using the ID.
[0049] The NotifyRoutine parameter is the first callback function set. The Remove parameter controls the addition and removal of callback functions. If this parameter is set to TRUE, the callback function is removed from the callback routine list; if this parameter is set to FALSE, the callback function is added to the callback routine list.
[0050] (3) When the first callback function is triggered and executed, process information is obtained, and corresponding policy control processing is performed based on the process information.
[0051] The following is an example of the function interface definition for the first callback function:
[0052]
[0053] PCREATE_PROCESS_NOTIFY_ROUTINE_EX declares the first callback function implemented by the first driver.
[0054] When the first callback function is invoked, process information is obtained based on the input parameters passed to it. For example, process information can be obtained through the process information structure PS_CREATE_NOTIFY_INFO, where the CommandLine field contains information related to the process's command line. This invention can determine whether the installed software is prohibited from installation and execution by analyzing the information in this structure. Process permissions can be controlled through the CreationStatus field.
[0055]
[0056] Starting with Vista, the system provides PsSetCreateProcessNotifyRoutineEx to register process notifications. The difference between it and PsSetCreateProcessNotifyRoutine is that it can control the result of process creation (via CreateInfo->CreationStatus).
[0057] The first callback function can match the software blacklist / whitelist control policy based on the passed process information. For example, according to the platform policy, if the command line information when the process starts contains the name of software in the software blacklist, then the installation and running of that software will be prohibited; if it is a whitelist policy, then only software in the whitelist and the default programs of the Windows system will be run.
[0058] Specifically, you can prevent a process from running by setting its creation status to DENIED, for example, CreateInfo->CreationStatus = STATUS_ACCESS_DENIED.
[0059] Step 140. The first callback function monitors the installed or started program process according to the software blacklist / whitelist control policy, and determines whether to allow it to run (including the case of installation or startup). If allowed, proceed to step 150; otherwise, proceed to step 160.
[0060] Step 150. Allow the process to run if it is in the whitelist or not in the blacklist;
[0061] Step 160. If the running program process is not in the whitelist or is in the blacklist, prevent the process from running.
[0062] The first callback function compares the obtained process information with the software blacklist / whitelist control policy obtained from the cloud desktop management platform. If the blacklist control policy is currently in use, the process is prohibited from running if the name of the created or running software is in the blacklist; otherwise, it is allowed to run. If the whitelist control policy is currently in use, the process is allowed to run if the name of the created or running software is in the whitelist; otherwise, it is prohibited from running.
[0063] In order to enable users or administrators to know which software installations and operations have been blocked, one embodiment of the present invention also provides a function for recording and displaying policy result information.
[0064] Step 170. The first callback function writes the information of the prohibited processes to a specified location in the registry. The cloud desktop application layer monitors the changes in the specified location in the registry through the monitoring interface and reports the information of the prohibited processes by the first driver to the cloud desktop management platform.
[0065] The first driver writes the intercepted running process information to a specified registry location. It can register an interface that can monitor changes in the specified registry location through the Agent module, such as the RegNotifyChangeKeyValue interface, to monitor whether the registry at the specified location has changed. When a change at the specified location is captured, the captured information on the processes that are prohibited from installation or running is reported to the cloud desktop management platform for recording, querying and display.
[0066] The cloud desktop software blacklist / whitelist control method provided by this invention aims to restrict or allow only the installation and operation of specific software based on administrator-defined blacklist / whitelist control policies, thereby improving the security and controllability of cloud desktops. This invention installs a device driver (i.e., a first driver) in the cloud desktop to perform software blacklist / whitelist control. The first driver registers a first callback function at the operating system layer. When the operating system operates on a process handle, the first callback function is triggered to execute. The first callback function obtains process information and performs policy control on the installed and running software according to the software blacklist / whitelist control policy issued by the cloud desktop management platform. The software blacklist control policy and the software whitelist control policy are mutually exclusive and support both exact and fuzzy matching. This invention enables the permission of only specified processes to run, achieving a stable and controllable operating environment and preventing malicious programs from disrupting system stability.
[0067] Figure 2 This is a schematic diagram of a cloud desktop blacklist / whitelist control system according to an embodiment of the present invention. In this system, the cloud desktop blacklist / whitelist control 200 is applied to the cloud desktop 220. The cloud desktop management platform 210 sends the software blacklist / whitelist control policy to the first driver 201 through the Agent 202 located in the cloud desktop 220. The first driver 201 also realizes the control of the software blacklist / whitelist of the cloud desktop by registering a first callback function.
[0068] Figure 3 This is a schematic diagram of the electronic device structure for implementing the cloud desktop software blacklist / whitelist control method provided by the present invention. The device 300 includes: a processor 310 such as a central processing unit (CPU), a communication bus 320, a communication interface 340, and a storage medium 330. The processor 310 and the storage medium 330 can communicate with each other via the communication bus 320. The storage medium 330 stores a computer program, which, when executed by the processor 310, implements the functions of each step of the method provided by the present invention.
[0069] The storage medium may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Alternatively, the storage medium may be at least one storage device located remotely from the aforementioned processor. The processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0070] It should be recognized that embodiments of the present invention can be implemented or carried out by computer hardware, a combination of hardware and software, or by computer instructions stored in non-transitory memory. The methods can be implemented using standard programming techniques, including a non-transitory storage medium configured with a computer program within the computer program, wherein such a storage medium causes the computer to operate in a specific and predefined manner. Each program can be implemented in a high-level procedural or object-oriented programming language to communicate with the computer system. However, if desired, the program can be implemented in assembly or machine language. In any case, the language can be a compiled or interpreted language. Furthermore, for this purpose, the program can run on a programmed application-specific integrated circuit. Moreover, the operations of the processes described in this invention can be performed in any suitable order unless otherwise indicated by the invention or otherwise clearly contradicted by the context. The processes (or variations and / or combinations thereof) described in this invention can be executed under the control of one or more computer systems configured with executable instructions and can be implemented by hardware or a combination thereof as code (e.g., executable instructions, one or more computer programs, or one or more applications) that commonly executes on one or more processors. The computer program includes a plurality of instructions executable by one or more processors.
[0071] Furthermore, the method can be implemented in any suitable type of computing platform, including but not limited to personal computers, minicomputers, mainframes, workstations, networked or distributed computing environments, standalone or integrated computer platforms, or in communication with charged particle tools or other imaging devices. Aspects of the invention can be implemented as machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into a computing platform, such as a hard disk, optical read and / or write storage medium, RAM, ROM, etc., such that it is readable by a programmable computer, and when the storage medium or device is read by the computer, it can be used to configure and operate the computer to perform the processes described herein. Furthermore, the machine-readable code, or portions thereof, can be transmitted via wired or wireless networks. The invention includes these and other different types of non-transitory computer-readable storage media when such media comprises instructions or programs that implement the steps described above in conjunction with a microprocessor or other data processor. When programmed according to the methods and techniques described in the invention, the invention also includes the computer itself.
[0072] The above description is merely an embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the present invention should be included within the scope of protection of the present invention.
Claims
1. A cloud desktop blacklist / whitelist control method, characterized in that, This method is applied to cloud desktops and includes: When the cloud desktop starts, the first driver is loaded. The first driver calls the callback registration function of the operating system kernel to register the first callback function. When a new process is created, the execution of the first callback function is triggered. The first callback function controls the software running on the cloud desktop according to the software blacklist / whitelist control policy issued by the cloud desktop management platform; When the first callback function is called, process information is obtained based on the input parameters passed to the first callback function, including the ID of the newly created process and the ID of the parent process of the new process; When the software blacklist / whitelist control policy is a blacklist policy and the name of the software to be installed or run is determined to be in the software blacklist based on the process information, process creation is prohibited; otherwise, process creation is allowed. When the software whitelist / blacklist control policy is a whitelist policy and the name of the software to be installed or run is determined to be in the software whitelist or by the system based on the process information, process creation is allowed; otherwise, process creation is prohibited.
2. The method according to claim 1, characterized in that, The first driver is loaded via the Agent module of the cloud desktop; At startup, the first driver obtains the software blacklist / whitelist control policy from the cloud desktop management platform via the Agent.
3. The method according to claim 2, characterized in that, The method further includes: When the software blacklist / whitelist control policy in the cloud desktop management platform is updated, the Agent calls the driver IO control interface to send and update the software blacklist / whitelist control policy to the first driver.
4. The method according to claim 1, characterized in that, The method further includes: The first callback function is also used to write information about processes that are prohibited from being installed or run to a specified location in the registry; The system monitors changes in a specified location in the registry via a monitoring interface and reports information on processes that are prohibited from installation or operation to the cloud desktop management platform.
5. A cloud desktop blacklist / whitelist control device, characterized in that, This device is used in cloud desktops and includes: The proxy module is used to load the first driver when the cloud desktop starts. The first driver is used to obtain the software blacklist / whitelist control policy issued by the cloud desktop management platform and call the callback registration function of the operating system kernel to register the first callback function. When a new process is created, the execution of the first callback function is triggered. The first callback function controls the software running on the cloud desktop according to the software blacklist / whitelist control policy issued by the cloud desktop platform. When the first callback function is called, the first driver obtains process information based on the input parameters passed to the first callback function, including the ID of the newly created process and the ID of the parent process of the new process; When the software blacklist / whitelist control policy is a blacklist policy and the name of the software to be installed or run is determined to be in the software blacklist based on the process information, the first driver prohibits the creation of the process; otherwise, the creation of the process is allowed. When the software blacklist / whitelist control policy is a whitelist policy and the name of the software to be installed or run is determined to be in the software whitelist or by the system based on the process information, the first driver allows process creation; otherwise, process creation is prohibited.
6. The apparatus according to claim 5, characterized in that, At startup, the first driver obtains the software blacklist / whitelist control policy from the cloud desktop management platform via the Agent. When the software blacklist / whitelist control policy in the cloud desktop management platform is updated, the Agent calls the driver IO control interface to send and update the software blacklist / whitelist control policy to the first driver.
7. The apparatus according to claim 5, characterized in that, The device further includes: The first callback function registered by the first driver is also used to write information about processes that are prohibited from being installed or run into a specified location in the registry; The proxy module monitors changes in a specified location in the registry through a monitoring interface and reports the information on processes that are prohibited from installation or operation to the cloud desktop management platform.
8. An electronic device, characterized in that, It includes a processor, a communication interface, a storage medium, and a communication bus, wherein the processor, the communication interface, and the storage medium communicate with each other through the communication bus; Storage medium used to store computer programs; A processor, when executing a computer program stored on a storage medium, performs the steps of the method described in any one of claims 1-4.
Citation Information
Patent Citations
Process blacklist and whitelist control method based on Windows system
CN102855430A
Software protection method, system and equipment of Windows system and medium
CN114238947A
Cloud desktop software management and control method and system, server and readable storage medium
CN114254270A