一种检测进程访问行为的方法、系统、装置及介质

By configuring corresponding process access policies and permission declaration tables for each application, the problem of existing technologies being able to detect only one type of process is solved, enabling accurate detection of access behavior for each process and improving the security and detection efficiency of the client system.

CN115329334BActive Publication Date: 2026-07-17BEIJING TOPSEC NETWORK SECURITY TECH +2

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING TOPSEC NETWORK SECURITY TECH
Filing Date
2022-09-19
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In existing technologies, due to limited client storage space, detection can only be performed on one type of process, making it impossible to accurately detect the access behavior of each process, which affects the security of process access behavior.

Method used

Configure corresponding process access policies for each application, refine the detection of process access behavior through permission declaration tables and query mapping tables, ensure that each process has the corresponding policy, and load the access policy loader and target function into the kernel for detection.

Benefits of technology

It improves the accuracy and efficiency of process access behavior detection, ensures that each process's access behavior has a clear strategy, and enhances the security and detection speed of the client system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115329334B_ABST
    Figure CN115329334B_ABST
Patent Text Reader

Abstract

本申请实施例提供一种检测进程访问行为的方法、系统、装置及介质,该方法包括:获取至少一组进程访问策略,其中,所述一组进程访问策略对应一个应用程序,所述进程访问策略是通过所述应用程序设置在目标系统的内核中的;基于所述至少一组进程访问策略,对第i进程的访问行为进行检测,获得检测结果,其中,所述目标系统可运行多个进程,所述第i进程为所述多个进程中的任意一个;根据所述检测结果判断是否允许所述第i进程执行所述访问行为。通过本申请的一些实施例能够针对每一个应用程序使用相对应的进程访问策略,从而能够提高进程访问行为检测的准确性。
Need to check novelty before this filing date? Find Prior Art