A method for monitoring the PAM authentication module based on eBPF
By using eBPF technology in Linux systems, the PAM authentication module is monitored, which solves the problems of high invasiveness and untimely effectiveness in the existing technology, and realizes high-performance and low-invasive PAM authentication module monitoring.
Patent Information
- Application Number
- CN202211045272.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-30
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2042-08-30
AI Technical Summary
When monitoring PAM authentication events in Linux systems, the prior art has problems such as high system intrusion, failure to take effect in time and failure to system startup.
Using an eBPF-based method, we search for the dynamic library files of the PAM module, parse the ELF Header and Section, associate the eBPF machine code program and the function position of the PAM module, and form an eBPF observer to realize monitoring of the PAM authentication module.
It achieves higher speed and performance, low intrusion and safer monitoring, avoids the need for system restarts, and ensures protection of kernel source code.
Smart Images

Figure CN115408692B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security authentication, and particularly relates to a method for monitoring a PAM authentication module based on eBPF. Background Art
[0002] The system security of a server is of crucial importance. Confirming that the users using applications or services in the system are indeed the users themselves, restricting the time period during which a specified user can access services, and restricting the usage rate of system resources by various applications or services are all important aspects of system security. When designing the Linux system, a strategy is adopted to centralize different underlying authentication mechanisms into a high-level API, thus saving developers the trouble of designing and implementing various complex authentication mechanisms themselves. Specifically, it uses a security verification method that is based on modular design and has a pluggable function, and is an independent verification method outside the application. Therefore, most Linux distributions integrate the PAM (Pluggable Authentication Modules) technology during implementation. All applications are uniformly managed by PAM to perform authentication work, so that the program body no longer needs to concern itself with authentication issues. PAM provides a central mechanism for authenticating all services and can be applied to applications such as login, remote login (telnet, rlogin, fsh, ftp, PPP), and su. System administrators formulate different authentication strategies for different applications through PAM configuration files. Application developers call authentication methods by using PAM APIs in service programs, while developers of PAM service modules use PAM SPI to write modules (mainly to export some functions pam_sm_xxxx( ) for the PAM interface library to call), and add different authentication mechanisms to the system. The PAM interface library (libpam) reads the configuration file and connects the application program with the corresponding PAM service module.
[0003] eBPF (extended Berkeley Packet Filter) is a general-purpose execution engine that provides the general ability to efficiently and securely execute specific code based on system or program events. The users of this general ability are no longer limited to kernel developers. eBPF can consist of executed bytecode instructions, stored objects, and Helper functions. The bytecode instructions must be verified by the BPF Verifier before being executed in the kernel. Also, in a kernel with BPFJIT mode enabled, the bytecode instructions will be directly converted into native instructions executable by the kernel and run. eBPF has also gradually played an important role in fields such as observability (tracing, performance tuning, etc.), security, and networking. Well-known Internet companies such as Facebook, NetFlix, and CloudFlare have widely adopted various programs based on eBPF technology for performance analysis, problem troubleshooting, load balancing, and prevention of DDoS attacks. According to relevant information, a series of eBPF-related tools are built into the machines of Facebook. There are various types of eBPF observations. Among them, the uprobes type is mainly used for debugging and tracing the user space. It is a relatively lightweight mechanism. Essentially, a set of handlers is inserted at specified probe points (such as a certain line of a function, the entry and exit addresses of a function, or a specified address in the kernel). When the kernel executes this set of handlers, it can obtain the context information currently being executed, such as the current function name, the parameters processed by the function, and the return value of the function. It can also obtain information about registers and even global data structures.
[0004] The current existing technologies mainly implement the monitoring of running PAM authentication events from two aspects. One is the technology based on dynamic library modification. By modifying the relevant logic inside the dynamic library, adding its own monitoring code at the original function entry to obtain relevant parameters, variables, memory data, etc., and then compiling and generating a new PAM dynamic library. When the Linux system starts, this new PAM dynamic library is loaded first to achieve the monitoring and recording of the original PAM functions. This method has a greater intrusion into the system. Not only does it need to wait for the system to restart and cannot take effect in a timely manner, but also if there is an error in this newly compiled PAM dynamic library, it will cause the system startup to fail. The other is to hook the running PAM dynamic library based on ptrace, similar to setting breakpoints for authentication functions in the PAM module by gdb and obtaining data such as the current memory, registers, and variable values. However, the usage scenario of this method is very limited. Summary of the Invention
[0005] In view of the shortcomings and deficiencies in the above-mentioned existing technologies, the present invention proposes a method for monitoring the PAM authentication module based on the pam_get_authtok interface function of the PAM module and the general ability of eBPF to efficiently and securely execute specific code based on system or program events, so as to achieve effects such as higher speed and performance, and low invasiveness.
[0006] To achieve the above object, the technical solution adopted by the present invention is a method for monitoring the PAM authentication module based on eBPF, which includes the following steps:
[0007] S1: Search for the pluggable authentication module dynamic library file libpam.so in the Linux system;
[0008] S2: Use an ELF parsing tool to parse the searched libpam.so file to obtain the ELF Header and each ELF Section;
[0009] S3: Parse the types of each section in the ELF Header. The function names are stored in the sections with sh_type being SHT_SYMTAB and SHT_DYNAMIC. Traverse the sh_type of the ELF Header to find the positions of the corresponding sections, and extract the SHT_SYMTAB segment and the SHT_DYNAMIC segment according to these positions;
[0010] S4: Traverse the SHT_SYMTAB segment and the SHT_DYNAMIC segment to find the function positions of the PAM authentication module, the PAM account module, the PAM session module, and the PAM password module;
[0011] S5: Associate the eBPF machine code program produced through programming, underlying virtual machine compilation, verification, and just-in-time compilation with the function positions of the above-mentioned PAM modules to form an eBPF observer for user space events in the kernel;
[0012] S6: The eBPF observer receives the eBPF events triggered by the kernel probes;
[0013] S7: The eBPF observer reads the context data of eBPF;
[0014] S8: Parse the context data and assign the relevant data to the variables of the PAM module;
[0015] S9: Write the variable data of the PAM module into the PAM security event information to realize the monitoring of the PAM security of the Linux system.
[0016] Since all dynamic library files of the Linux system are stored in the / lib directory, the / usr / lib directory, and other directories specified in / etc / ld.so.conf, when searching for the dynamic library file of the pluggable authentication module in Step 1, the directories to be searched preferentially include the / lib directory, the / usr / lib directory, and / etc / ld.so.conf.
[0017] In Step 5, the generation of the eBPF machine code program includes the following steps:
[0018] S31: Write the eBPF program code;
[0019] S32: Compile the foregoing eBPF program code into a bytecode program through low-level virtual machine compilation;
[0020] S33: Compile the bytecode program through a validator and a JIT just-in-time compiler to generate an eBPF machine code program.
[0021] Furthermore, the eBPF events triggered by the kernel probe in Step 6 include login, passwd, ssh, su, and sudo.
[0022] Compared with the prior art, the present invention has the following beneficial technical effects:
[0023] 1. It has higher speed and performance. Since eBPF can be regarded as a minimum "virtual" machine with an eBPF interpreter and a JIT compiler, after the function of monitoring the PAM password is compiled into bytecode, eBPF will be called to load and execute, instead of repeatedly calling a new interpreter for the bytecode, thus greatly improving the speed and performance.
[0024] 2. It has a more secure and less invasive nature. Since the eBPF program is sandboxed, this technology can only execute the specified monitoring PAM password events in a limited way in a secure environment. Therefore, the kernel source code is still protected and unchanged, and the verification step can ensure that resources will not be blocked by programs running infinite loops.
[0025] 3. It has more convenient programmability. Using eBPF helps to increase the richness of the environment's features without adding an extra layer. Similarly, since the code runs directly in the kernel, data can be stored between eBPF events without the need to dump data like other tracing programs. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 It is a flowchart of an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0027] The present invention will be further described in detail below with reference to the accompanying drawings.
[0028] As Figure 1 shown, the process of a specific embodiment for monitoring the PAM authentication module of the present invention includes the following steps:
[0029] 1. Search for the pluggable authentication module dynamic library libpam.so file in the Linux system. Since all dynamic library files of the Linux system are stored in the / lib directory, / usr / lib directory, and other directories specified in / etc / ld.so.conf, these three directories are searched first to find the pluggable dynamic library files among them.
[0030] 2. Since the pluggable dynamic library file is in ELF format, use an ELF parsing tool to parse the dynamic library file to obtain each Section and the ELF Header therein.
[0031] 3. Parse the types of each Section in the ELF Header. According to the definition of the Linux system, function names are stored in the sections with sh_type being SHT_SYMTAB and SHT_DYNAMIC. Traverse the sh_type of the ELF header to find the positions of the corresponding sections, and extract the SHT_SYMTAB segment and SHT_DYNAMIC segment based on these positions.
[0032] 4. Traverse the SHT_SYMTAB segment and SHT_DYNAMIC segment to find the function positions of the authentication module, account module, session module, and password module therein.
[0033] 5. Associate the eBPF machine code program with the function positions of each PAM module to form an observation of user space events in the kernel.
[0034] 6. Trigger eBPF events through the login / passwd / ssh / su / sudo kernel probes.
[0035] 7. Use an eBPF observer to read the context data of eBPF.
[0036] 8. Use eBPF to parse the context data and assign the relevant data to the variables of the PAM module (including username, password, etc.).
[0037] 9. Write the PAM module variable data into the PAM security event information to achieve the monitoring of PAM security in the Linux system.
[0038] Among them, the eBPF machine code program in the above step 5 is generated through the following three steps:
[0039] Step 1: First, program the eBPF program to implement the corresponding functions.
[0040] Step 2: Compile the eBPF program into a bytecode program through LLVM (Low Level Virtual Machine) compilation.
[0041] Step 3: Compile it into a machine code program through a validator and a JIT (Just-In-Time) compiler.
[0042] As described in the above embodiments, the present invention effectively solves the monitoring of Linux system authentication, that is, by using eBPF technology, a sandbox program for PAM authentication monitoring is run in the Linux kernel. Without modifying the kernel source code or loading kernel modules, by making the Linux kernel programmable, the monitoring and recording of applications such as login / passwd / ssh / su / sudo in the Linux system are realized. The monitored content includes authentication, authorization management, session start and end, password change, etc.
[0043] Because it has an eBPF interpreter and a JIT compiler, after the function of monitoring PAM passwords is compiled into bytecode, it will call eBPF to load and execute, without repeatedly calling a new interpretation of the bytecode. Therefore, there is a significant improvement in speed and performance. The eBPF program is sandboxed, and this technology can only execute the specified password events for monitoring PAM in a limited way in a secure environment. Thus, the kernel source code is still protected and unchanged. The verification step ensures that resources will not be blocked by programs running infinite loops. Using eBPF helps to increase the feature richness of the environment without adding additional layers. Similarly, since the code runs directly in the kernel, data can be stored between eBPF events, rather than dumping data like other tracing programs.
[0044] It should be noted that the above description of the specific implementation manners is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for monitoring the PAM authentication module based on eBPF, characterized in that, It includes the following steps: S1: Search for the pluggable authentication module dynamic library file libpam.so in the Linux system; S2: Use an ELF parsing tool to parse the searched libpam.so file to obtain the ELF Header and each ELF Section; S3: Parse the types of each section in the ELF Header. The function names are stored in the sections where sh_type is SHT_SYMTAB and SHT_DYNAMIC. Traverse the sh_type of the ELF Header to find the positions of the corresponding sections, and extract the SHT_SYMTAB segment and the SHT_DYNAMIC segment based on these positions; S4: Traverse the SHT_SYMTAB segment and the SHT_DYNAMIC segment to find the function positions of the PAM authentication module, PAM account module, PAM session module, and PAM password module; S5: Associate the eBPF machine code program produced through programming, low-level virtual machine compilation, verification, and just-in-time compilation with the function positions of the above-mentioned PAM modules to form an eBPF observer for user space events in the kernel; S6: The eBPF observer receives eBPF events triggered by kernel probes; S7: The eBPF observer reads the context data of eBPF; S8: Parse the context data and assign the relevant data to the variables of the PAM module; S9: Write the variable data of the PAM module into the PAM security event information to implement the monitoring of PAM security in the Linux system.
2. The method for monitoring the PAM authentication module based on eBPF according to claim 1, characterized in that, The directories preferentially searched when searching for the pluggable authentication module dynamic library file in step 1 include the / lib directory, the / usr / lib directory, and / etc / ld.so.conf.
3. The method for monitoring the PAM authentication module based on eBPF according to claim 1, characterized in that, The generation of the eBPF machine code program in step 5 includes the following steps: S31: Write eBPF program code; S32: Through low-level virtual machine compilation, compile the aforementioned eBPF program code into a bytecode program; S33: Through the verifier and JIT just-in-time compiler, compile the bytecode program to generate a BPF machine code program.
4. The method for monitoring the PAM authentication module based on eBPF according to claim 1, characterized in that, The eBPF events triggered by the kernel probes in step 6 include login, passwd, ssh, su, sudo.
Citation Information
Patent Citations
Strong identity authentication system and strong identity authentication method based on PAM architecture
CN108881222A
Performance analysis method and device for storage server and electronic equipment
CN111756575A