An intrusion detection method for IOS-XE system based on container

By deploying self-built containers on IOS-XE routers and combining information extraction and intrusion behavior determination modules, real-time intrusion detection of IOS-XE systems is realized, solving the problem of difficulty in detecting web injection and CLI command injection vulnerabilities in the existing technology, and improving detection capabilities and accuracy.

CN115941245BActive Publication Date: 2025-06-13Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211245979.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-10-08
Filing Date
2022-10-12
Publication Date
2025-06-13
Estimated Expiration
2042-10-12

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect the widespread Web injection vulnerability and CLI command injection vulnerability exploitation process in IOS-XE systems, and the real-time detection capabilities are insufficient.

Method used

Deploy self-built containers on IOS-XE routers, use self-built containers to carry intrusion detection system, establish network communication with IOSd processes through VPG virtual interface, and combine information extraction modules and intrusion behavior determination modules to realize real-time monitoring and analysis of network data, status information and log information.

Benefits of technology

Real-time intrusion detection of IOS-XE systems is realized, and it can effectively detect web injection and CLI injection attacks, making up for the lack of UTD services that only detect transit traffic, and provides detection methods for configuring hidden attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941245B_ABST
    Figure CN115941245B_ABST
Patent Text Reader

Abstract

The present invention provides an intrusion detection method for an IOS-XE system based on containers. A self-built container is deployed on a router, and the self-built container is used to carry the intrusion detection system. The intrusion detection system includes an information extraction module and an intrusion behavior determination module. The information extraction module extracts information and stores the extracted information in a database deployed in the self-built container. The intrusion judgment module reads network data, status information, and log information from the database to determine intrusion behavior, and outputs the detection result to a Web server for display. The real-time detection method for the IOS-XE system based on containers provided by the present invention, combined with the current research on attack behaviors against Cisco routers, can detect intrusion behaviors such as password cracking, configuration hiding, and backdoor implantation, making up for the deficiency that the UTD service of the IOS-XE system only detects transit traffic, and can effectively detect Web injection attacks and CLI injection attacks widely existing in this system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of computer network security, and particularly relates to an intrusion detection method for an IOS-XE system based on containers. Background Art

[0002] Current intrusion detection achievements for Cisco routers focus on the IOS operating system, mainly performing offline detection based on router information extraction, and cannot detect vulnerability exploitation behaviors such as Web injection and CLI (Command Line Interface) injection widely existing in the IOS-XE (Internetwork Operating System - Extended Edition) system, resulting in poor detection real-time performance.

[0003] By analyzing and summarizing the current research achievements on Cisco device intrusion detection, it is found that the following problems exist: ① The current research achievements mainly focus on the IOS operating system. Although most methods can be transplanted to the IOS-XE system, the real-time detection ability is insufficient; ② The current research achievements fail to effectively detect the process of exploiting Web injection vulnerabilities and CLI command injection vulnerabilities widely existing in the IOS-XE system. Summary of the Invention

[0004] Aiming at the problem that current intrusion detection fails to effectively detect the process of exploiting Web injection vulnerabilities and CLI command injection vulnerabilities widely existing in the IOS-XE system, the present invention provides an intrusion detection method for an IOS-XE system based on containers.

[0005] The present invention provides an intrusion detection method for an IOS-XE system based on containers. A self-built container is deployed on the router, and the intrusion detection system is carried by the self-built container. The self-built container establishes network connection with the IOSd process of the router through a VPG virtual interface.

[0006] The intrusion detection system includes an information extraction module and an intrusion behavior determination module. The information extraction module includes extracting network data of the router, querying the status information of the router, and extracting the log information of the router, and storing the extracted network data, status information, and log information in a database deployed in the self-built container.

[0007] The intrusion detection module reads network data, status information, and log information from the database to determine intrusion behavior, and outputs the detection results to the Web server for display. The intrusion behavior is determined using a hybrid detection method that combines misuse detection and anomaly detection. Misuse detection refers to establishing feature rules for known attack behaviors. When the monitored information matches the feature rules, it is determined as an intrusion behavior. Anomaly detection analyzes the characteristics of normal operations. When the difference between the monitored information and the characteristics of normal operations exceeds the threshold, an intrusion warning message is generated.

[0008] IOS-XE routers support two types of containers, KVM (Kernel-based Virtual Machine) and LXC (Linux container). Among them, the KVM-based container has an independent kernel and file system, and the LXC-based container shares the kernel with IOS-XE. The self-built container described in the present invention is based on LXC.

[0009] Furthermore, extracting the network data of the router includes the following steps:

[0010] Step 1: Mirror the data into the container using the ERSPAN method;

[0011] Step 2: After the data enters the container, strip the GRE protocol header added by the ERSPAN function to the data packet to obtain the original data format;

[0012] Step 3: Decrypt the https encrypted data traffic;

[0013] Step 4: After decrypting the https encrypted data traffic, extract the Web requests sent by the user;

[0014] Step 5: Capture and detect data traffic of non-http and non-https protocols.

[0015] Furthermore, the router obtains the router status information through the CLI command line. The status information includes running configuration, user information, login information, etc.

[0016] For. The prerequisite for obtaining the status information is to solve the detection problem of configuration hiding attacks to prevent the obtained status information from being filtered and replaced by attackers. The extraction of status information provided by the present invention also includes the detection of configuration hiding attack behaviors. The detection of configuration hiding attack behaviors includes:

[0017] (1) Configuration hiding attack detection based on information comparison: Use a TCL script to read the running-config file in the virtual directory system on the router, then use the RC4 encryption algorithm to encrypt the file content, and finally return the encrypted result to obtain the real configuration information. Simulate logging in to the router, execute the configuration viewing command, obtain the suspicious configuration information, and compare the real configuration information with the suspicious configuration information to determine whether the router has suffered a configuration hiding attack.

[0018] (2) Real-time extraction of TCL scripts based on keyword matching: Remotely transmit the heap file in the router's system directory through router_command_execute and receive the heap file in a loop. Combine the keywords of the tbc file and the characteristics of the TCL script to achieve automatic positioning and extraction analysis of the TCL scripts executed in the memory of the IOS-XE router.

[0019] (3) System integrity verification: Calculate the hash values of the firmware, IOSd file, and loaded dynamic link libraries offline and establish an initial index file. At the same time, query the hash values of the IOSd process and all the code segments of the loaded dynamic link libraries in the container in real time, and compare them with the hash values in the index file to determine whether the system image is complete.

[0020] The router log information contains rich user operation behavior information, including user commands, configuration modifications, user logins, etc. Use the router archive and EEM functions, combined with the log server deployed in the container, to record all the information input by the user at the CLI interface, so as to obtain complete log information.

[0021] The beneficial effects of the present invention:

[0022] ① A real-time detection method for the IOS-XE system based on containers is proposed. Combining the current research on attack behaviors against Cisco routers, it can detect intrusion behaviors such as password cracking, configuration hiding, and backdoor implantation. ② It makes up for the deficiency that the UTD service of the IOS-XE system only detects transit traffic and can effectively detect Web injection attacks and CLI injection attacks widely existing in this system. ③ A configuration hiding attack detection method applicable to IOS and IOS-XE systems is proposed, which can resist known configuration hiding attacks. Description of the Drawings

[0023] Figure 1 System architecture diagram of the method of the present invention.

[0024] Figure 2 Diagram of the method for obtaining the running configuration.

[0025] Figure 3 Configure the hidden detection effect diagram.

[0026] Figure 4 Misuse detection rule diagram.

[0027] Figure 5 Anomaly detection rule diagram.

[0028] Figure 6 Behavior determination flow chart. DETAILED DESCRIPTION

[0029] The present invention is further described below in conjunction with the accompanying drawings and embodiments.

[0030] Embodiment 1: There are three main methods for intrusion detection on Cisco routers. The first is an information extraction method based on core dump files, which extracts router status information, including running TCL scripts and running configurations, through the core dump files that come with the router; the second is an information automation extraction method based on TCL scripts, which uses TCL scripts supported by routers to obtain various dynamic information of routers in real time, including logs, running configurations, port openings, logged-in users, etc., and comprehensively determines attack behaviors based on various types of information; the third is to use the SnortIPS container that comes with the router to monitor transit traffic and determine intrusion behaviors in combination with detection rules.

[0031] The above-mentioned intrusion detection method has the following problems: First, the method of extracting information from the core dump file requires offline analysis and cannot monitor the real-time status changes of the router; second, the current detection method for Cisco routers cannot cope with the common Web injection and CLI injection vulnerability exploitation behaviors and configuration hiding attacks in the IOS-XE system; third, the SnortIPS container does not consider whether the traffic with the destination address of the router is malicious.

[0032] According to the above router intrusion detection method and existing problems, the present invention provides a new container-based IOS-XE system intrusion detection method.

[0033] First, by deploying a user-controllable intrusion detection container on the IOS-XE router, the router operation status is monitored in real time in the container, focusing on the user's input in the CLI, and combining detection rules to determine attack behavior, solving the problem of real-time monitoring and CLI command injection vulnerability detection; second, focusing on the network traffic whose destination IP address is the router, to make up for the deficiency of UTD that only detects transit traffic, focusing on the user's Web request, and solving the problem of Web injection vulnerability detection; third, focusing on the detection method of configuration hiding and the extraction method of TCL scripts running in the router memory, to solve the previous problem of being unable to determine configuration hiding and TCL backdoor implantation attack behavior in real time.

[0034] The intrusion detection method provided by the present invention is divided into the following two modules: an information extraction module and an intrusion behavior determination module. The information extraction module solves problems such as the decryption of https encrypted traffic and the detection of configuration hiding attacks, extracts network data mirrored from the IOSd port, queries the status information of the router in real time, and the router log information sent by the IOSd; the intrusion behavior determination module reads the traffic, router status, and log information extracted by the information extraction module, combines the intrusion behavior determination algorithm to determine the intrusion behavior, and outputs the detection result to the Web server for display.

[0035] The system operation process of the method of the present invention is as Figure 1 shown. First, configure ERSPAN (Remote Port Mirroring) and log services in the IOSd to obtain router interface data and router log information; then, receive router network data, router status data, and log data in the container in real time, and save them to the database deployed in the container; finally, the intrusion behavior determination module reads the information from the database and combines the detection rules to determine the intrusion behavior.

[0036] The present invention uses a hybrid detection method that combines misuse detection and anomaly detection to realize the determination of intrusion behavior. Misuse detection refers to establishing characteristic rules for known attack behaviors. When the monitored information matches the characteristic rules, it is determined as an intrusion behavior; anomaly detection analyzes the characteristics of normal operations. When the difference between the monitored information and the characteristics of normal operations exceeds the threshold, an intrusion warning message is generated.

[0037] Misuse detection detects attack behaviors through the characteristics of known attacks and relies on accurate attack behavior rules. The known intrusion behaviors of the IOS-XE system mainly include Web injection, CLI injection, firmware backdoor implantation, etc. Misuse detection rules are constructed by analyzing relevant attack methods as Figure 4 shown.

[0038] For example, if a CLI command is included in the detected Web access request, it can be determined that there is a Web injection attack because there should be no CLI command in the Web request. The misuse detection rules are extracted from known attack behaviors, and the detection rules have strong pertinence. In detecting known intrusion behaviors, the false positive rate and false negative rate are very low. As more router attack methods are revealed, attack characteristics can be extracted according to the attack methods and the misuse detection rules can be supplemented, so that the system detection ability can be continuously improved.

[0039] The purpose of choosing to use anomaly detection is to make up for the lack of the ability of misuse detection in detecting unknown attack behaviors, mainly based on the differences between the operations of attackers and normal user operations to realize intrusion behavior detection.

[0040] Router attackers often use the legitimate functions provided by routers to achieve deep intrusion behaviors, and it is difficult to determine intrusion behaviors through a single behavior. Therefore, different weight values are set for different behavior characteristics for comprehensive judgment. Only when the weight value exceeds the threshold will an alarm be output to the user, and the weight value is set differently according to the suspicious degree of abnormal behaviors. The constructed abnormal detection rule table is as follows Figure 5 shown.

[0041] There will be false alarms and missed alarms in the detection based on abnormal behaviors. Therefore, a reasonable threshold needs to be set to achieve a balance between the false alarm rate and the accuracy rate.

[0042] The present invention also provides a behavior determination algorithm. The operation process of the behavior determination algorithm is as follows Figure 6 shown. First, information is cyclically read from the information database and pattern-matched with misuse rules. If there is a matching item, it is directly determined that there is an intrusion behavior; otherwise, the information is continuously pattern-matched with abnormal rules, and the weight of the abnormal matching items is calculated. When the weight value exceeds the threshold, an alarm is given to the user.

[0043] The calculation method of misuse detection is as shown in formula (1):

[0044] (1)

[0045] Among them, i represents the fixed id value of the user who operates on the router, and this value is jointly determined by the binary group composed of the IP address and the source port; x represents the original detection information obtained from the database, X represents the set of misuse rules, 𝑓 𝑖 (x) represents the result of misuse detection.

[0046] The calculation method of abnormal detection is as shown in formula (2):

[0047] (2)

[0048] Among them, the meanings of i and x are the same as above, Y represents the set of abnormal rules, Y(x) represents the weight value obtained by matching the abnormal detection rule table, 𝑔𝑖 represents the abnormal degree value of user i, and the initial value is 0. The calculation of this value is a process of multiple accumulations, and this value will be temporarily saved in the database after each matching. For example, if there are 3 operation records of the user with the id value <172.16.1.2,23665> on the router, which respectively match the 2nd, 6th, and 7th items in the abnormal detection rule table, then the final abnormal degree 𝑔𝑖 of this user is 0.27.

[0049] In summary, the intrusion behavior determination method is as shown in formula (3):

[0050] (3)

[0051] In order to balance missed alarms and false alarms, the threshold is set to 0.25 based on actual experiments. When 𝐹𝑖 (x) is equal to 0, no alarm is given; when 𝐹𝑖 (x) is equal to 1, a medium-risk alarm is given to remind the administrator that there may be an intrusion; when 𝐹𝑖 (x) is equal to 2, a high-risk alarm is given.

[0052] Example 2: The present invention implements intrusion behavior detection based on self-built containers in the Cisco IOS-XE system, and makes a self-built container based on LXC. The self-built container and the IOSd process establish network communication through the VPG virtual interface. The biggest difference between the self-built container and the guestshell container that comes with the router is that the dohost function of the guestshell container can query the router status information. The dohost function depends on the unix socket mapped to the container when the guestshell container is started. The dohost function cannot be ported to the user-built container, so the first problem to be solved is how to query the router status from the container.

[0053] The present invention studies the simulated login of IOS-XE system and realizes the command execution interface router_command_execute, which facilitates the detection system to query the router status in real time and provides support for the detection system to realize router information extraction, TCL script remote execution and configuration hidden detection.

[0054] The multiple functions of the router can provide a large amount of original detection data for attack behavior detection. Through the study of current router attack methods, the present invention will focus on extracting original detection data from the following aspects.

[0055] The first is Web request information. After collecting statistics on the vulnerability information of IOS-XE routers, the results show that IOS-XE routers have a large number of Web vulnerabilities. To detect this type of vulnerability, we must first obtain all Web requests and implement detection based on the behavior of the vulnerability. Web services commonly use http and https protocols. For https encryption, data decryption must be completed first to facilitate information extraction.

[0056] Second, it is status information. It includes status information such as user login, network connection, KRON (Command Scheduler) scheduled tasks, EEM (Embedded Event Manager) events, login time, open ports, and image security. Combining with the administrator's operation habits can assist in judging attack behaviors. The prerequisite for obtaining status information is to solve the detection problem of configuration hiding attacks to prevent the status information obtained from being filtered and replaced by attackers.

[0057] Third, it is log information. It includes the commands input by users and the logs generated by the system. After obtaining the router permissions, router attackers usually perform operations such as network detection, jump connection, backdoor user addition, and data diversion on the router. The present invention records all the information input by users at the CLI interface by using the router archive and EEM functions in combination with the log server deployed in the container.

[0058] By collecting various types of information of the router, it can assist in judging common attack means such as password guessing, CLI command injection, firmware backdoor, and Web vulnerability exploitation.

[0059] Since the present invention is mainly positioned for the self-protection of Cisco devices, the data with the destination IP being the router address is mainly mirrored into the container. IOS-XE does not support mirroring data to the container in the way of mirroring data through the local port. Therefore, the present invention uses the ERSPAN method to mirror data to the container, and the problem brought is that the mirror packets are encapsulated in the GRE format.

[0060] Therefore, after the data enters the container, it is necessary to process the data to strip the GRE protocol header added to the data packet by the ERSPAN function. After the GRE header is stripped, the original data format is obtained for subsequent information extraction.

[0061] Embodiment 3: The https protocol is a commonly used protocol for Web management of Cisco routers. There is a certificate signed by Cisco installed by default in the Cisco system for https encrypted transmission, and this certificate does not support export. In order to decrypt the https encrypted data of the Cisco router, the method of certificate replacement is adopted to force the Web service to use the self-signed certificate for data encryption and decryption. At the same time, configure https to use the RSA_WITH_AES_128_CBC_SHA256 encryption algorithm to ensure the decryption efficiency of the decryption program.

[0062] The https decryption module receives the pre - processed https encrypted data in real - time and decrypts the encrypted data through the following two steps: ① Extract the random value of the interaction between the client and the server, and use the private key to decrypt the pre - master key in the Client Key Exchange; ② Calculate the MasterSecret using the random and pre - master values of the interaction between the server and the client, and finally obtain the AES encryption keys at both ends of the server and the client. Finally, use the AES encryption key to decrypt the data and extract the Web request parameter information sent by the user.

[0063] In addition to http and https traffic, the data with the destination IP being the router address also includes cdp, bgp, ospf, etc. For the attack detection of the above - mentioned protocols, the present invention deploys the Snort intrusion detection program in a self - built container to help detect and capture the corresponding attacks.

[0064] Example 4: The CLI command line provided by the IOS - XE router supports the acquisition of router status information, including running configuration, user information, login information, etc. However, the CLI is often subject to configuration hiding attacks. Attackers use configuration hiding techniques to filter the configuration query results to achieve the hiding of specified information, deceiving router administrators and detection personnel. The router_command_execute interface developed for real - time acquisition of router status ultimately calls the commands in the CLI and is also unable to block the current configuration hiding attacks. Using this method cannot guarantee that the information obtained is not tampered with. Whether the configuration hiding attack behavior can be correctly detected is related to whether the obtained router status information is accurate.

[0065] (1)Configuration hiding attack detection method based on information comparison

[0066] Configuration hiding attacks match the commands input by users and filter or modify the information to be hidden. Figure 2 Five public methods for obtaining the router running configuration are listed. Methods 1, 2, 3, and 4 are easily attacked by the current configuration hiding methods; Method 5 is a common method for attackers to obtain the router configuration. It uses the community string with RW permissions of the snmp service to remotely obtain the running configuration, and is not affected by the current known configuration hiding attack methods and can obtain the real router configuration. However, if the data back - transmission does not use a security protocol, or uses a security protocol but the encryption key is obtained by the attacker in advance, the back - transmitted data is at risk of being tampered with.

[0067] To resist the current known configuration hiding attacks, a configuration hiding attack detection method is proposed, which has not been mentioned in the publicly available materials.

[0068] Algorithm 1: Obtaining Real Configuration Based on TCL Script

[0069] Input: config_filepath / * Running configuration path * /

[0070] Output: encrypted_data / * Encrypted configuration * /

[0071] 1. fp ← open(config_filepath)

[0072] 2. file_data ← read(fp)

[0073] 3. close(fp)

[0074] 4. encrypted_data ← RC4(file_data)

[0075] 5. return encrypted_data

[0076] For the specific process, see Algorithm 1. The TCL script reads the running-config file in the virtual directory system on the router, then encrypts the file content using the RC4 encryption algorithm, and finally returns the encrypted result. The reason why this method of obtaining the configuration file can resist the current configuration hiding attack is that the execution of the TCL script depends on the TCL script interpreter, and the file reading and writing functions in TCL cannot be intercepted and filtered by the current configuration hiding attack.

[0077] For the configuration hiding detection process, see Algorithm 2. First, execute the real configuration acquisition script corresponding to Algorithm 1 by calling router_command_execute to obtain the real running configuration of the router; second, simulate logging in to the router and execute the configuration viewing command to obtain the suspicious configuration information; finally, compare the configurations obtained by the two methods to determine whether the router has been attacked by configuration hiding.

[0078] Algorithm 2: Configuration Hiding Attack Determination Algorithm

[0079] Input: tcl / * Code in Algorithm 1 * /

[0080] Output: TRUE or FALSE

[0081] 1. encryped_config ← router_command_execute (tcl)

[0082] 2. decrypted_config ← RC4(encryped_config)

[0083] 3. tn ← TelnetRoute(route_ip)

[0084] 4. result ← router_command_execute(tn,'show run')

[0085] 5. compare ← Compare(decrypted_config, result)

[0086] 6. if isTrue(compare) then

[0087] 7. return TRUE / * there is no config_hide attack * /

[0088] 8. else

[0089] 9. return FALSE / * there exist config_hide attack * /

[0090] 10. end if

[0091] The detection effect of configuration hiding is shown in Figure 3 . The left box is the result of calling the IOS-XE router CLI command to view the running configuration, and the right box is the real running configuration result obtained by executing Algorithm 1. By calling Algorithm 2 to compare the two results, the determination of configuration hiding attack can be realized.

[0092] So far, based on the solution to the problem of whether the router is suffering from configuration hiding attack, the authenticity of the result of the router_command_execute function for querying the router status can be fully trusted.

[0093] (2)Real-time extraction of TCL script based on keyword matching

[0094] When obtaining router status information, the extraction of TCL scripts is also an important part. TCL scripts are commonly used methods in the router control process. Attackers often use TCL scripts on Cisco routers to implement reverse proxy, channel construction, backdoor presetting, etc., and control and utilize the router by executing TCL scripts in memory. The extraction of TCL scripts running in the memory of Cisco routers can assist detection personnel in determining attack behaviors. Currently, the extraction of TCL scripts from the memory of Cisco devices mainly relies on obtaining core dump files and performing offline analysis and extraction.

[0095] TCL supports two running modes: plaintext running and ciphertext running. Among them, encrypted running means compiling the plaintext TCL script into a tbc file that the router can recognize and load, which can effectively improve the confidentiality of the script. The tbc file has obvious characteristics. There is a string "tbcload::bceval{}" in its code. Just extract the content within the curly braces completely and implement the decoding of the tbc file; for files with the suffix tcl, select the feature string "proc{}" to match and extract the script content in memory. For TCL files with standardized writing, the accuracy of this extraction method is relatively high. Otherwise, manual analysis is required.

[0096] Algorithm 3 TCL Script Extraction Algorithm

[0097] Input: command / * copy system:memory / heap * /

[0098] Output: null

[0099] 1. tftp←tftpserver()

[0100] 2.router_command_execute (command)

[0101] 3. while (TURE)

[0102] 4. buffer←tftp.recvfrom(4096)

[0103] 5. if isHas(buffer,keystring) then / *Keyword matching* /

[0104] 6. tcl_script←extract_tcl(buffer) / *Script extraction* /

[0105] 7. writeTosql(tcl_script) / *Write the result to the database* /

[0106] 8. if buffer.len < 4096 then

[0107] 9. exit()

[0108] 10.return

[0109] By analyzing the mechanism of running TCL scripts on IOS-XE, it can be determined that the running TCL scripts are stored in the router heap area. There are mainly two methods to extract the TCL scripts running in memory. One is to determine the starting address of the heap area through the "show region" command and then use the "show memory" command to read the memory space data. The disadvantage of this method is that it is slow. The other is to download the heap file in the virtual file system through the copy command. This file is consistent with the content of the heap space. The size of this file is generally between 1G and 3G. After the download is completed, a binary reading tool can be used to quickly locate the TCL script, with relatively high efficiency.

[0110] Algorithm 3 describes the real-time extraction process of TCL scripts. Remotely upload the heap file in the router system directory through router_command_execute and receive the heap file in a loop. Combining the keywords of the tbc file and the characteristics of the TCL script, realize the automatic location and extraction analysis of the TCL script executed in the memory of the IOS-XE router.

[0111] (3)System integrity check

[0112] The system integrity check mainly detects whether the system running on the IOS-XE router has been tampered with by attackers.

[0113] During the execution of the IOSd process in the IOS-XE system, more than 500 dynamic link libraries are loaded. Attackers may inject malicious code into the loaded dynamic link libraries and execute the malicious code when the dynamic link libraries are loaded.

[0114] The present invention checks the integrity of the router image. The security of the router image needs to consider two aspects. One is the integrity of the startup image file, to see if it is consistent with the information provided by Cisco official. The other is whether the executable code of the running image is complete and whether there may be malicious modification of the running code. The present invention collects 432 firmware of the Cisco IOS-XE system, including 121 firmware of the ASR series, 211 firmware of the CSR series, and 100 firmware of the ISR series. Calculate the hash values of the firmware, the hash values of the IOSd files, and the hash values of the loaded dynamic link libraries offline and establish an initial index file.

[0115] Meanwhile, in the container, the hash values of the IOSd process and all the code segments of the dynamically linked libraries it loads are queried in real time and compared with the hash values in the index file to determine whether the system image is complete.

[0116] Embodiment 5: After obtaining the router permission, a router attacker usually performs operations such as network probing, jump connection, backdoor user addition, and data diversion on the router. The router log information contains rich user operation behavior information, including user commands, configuration modifications, user logins, etc. The present invention records all the information input by the user at the CLI interface by using the router archive and EEM functions in combination with the log server deployed in the container.

[0117] The specific process is as follows: First, the router logging function is enabled, and the remote log server is set up, and the log server in the container receives the log information in real time; second, command monitoring is configured, including user commands and configuration modifications, to obtain all the command information input by the user in the CLI in real time; third, the limit on the number of failed logins is set, and a failed login log is generated to prevent password guessing attacks.

Claims

1. An intrusion detection method for the IOS-XE system based on containers, characterized in that, a self-built container is deployed on the router, and the intrusion detection system is carried by the self-built container. The self-built container and the IOSd process of the router establish network communication through the VPG virtual interface; wherein the intrusion detection system includes an information extraction module and an intrusion behavior determination module. The information extraction module includes extracting the network data of the router, querying the status information of the router, and extracting the log information of the router; the extracted network data, status information, and log information are stored in the database deployed by the self-built container; the intrusion judgment module reads the network data, status information, and log information from the database to determine the intrusion behavior, and outputs the detection result to the Web server for display, the intrusion behavior determination uses a hybrid detection method that combines misuse detection and anomaly detection to achieve the determination of intrusion behavior; misuse detection refers to establishing a feature rule for known attack behaviors. When the monitored information matches the feature rule, it is determined as an intrusion behavior; anomaly detection analyzes the features of normal operations. When the difference between the monitored information and the features of normal operations exceeds the threshold, an intrusion warning message is generated.

2. The intrusion detection method for the IOS-XE system based on containers according to claim 1, characterized in that, the self-built container is based on LXC.

3. The intrusion detection method for the IOS-XE system based on containers according to claim 1, characterized in that, extracting the network data of the router includes the following steps: Step 1: Mirror the data into the container in the way of ERSPAN; Step 2: After the data enters the container, strip the GRE protocol header added by the ERSPAN function to the data packet to obtain the original data format; Step 3: Decrypt the https encrypted data traffic; Step 4: After decrypting the https encrypted data traffic, extract the Web request sent by the user; Step 5: Capture and detect the data traffic of non-http and https protocols.

4. The intrusion detection method for the IOS-XE system based on containers according to claim 1, characterized in that, the router obtains the router status information through the CLI command line, and the status information includes the running configuration, user information, and login information.

5. The intrusion detection method for the IOS-XE system based on containers according to claim 4, characterized in that, extracting the status information further includes detecting the configuration hiding attack behavior, and the configuration hiding attack behavior detection includes: (1) Configuration hiding attack detection based on information comparison. Use the TCL script to read the running-config file in the virtual directory system on the router, then use the RC4 encryption algorithm to encrypt the file content, and finally return the encrypted result to obtain the real configuration information; use the simulated login router to execute the configuration viewing command to obtain the suspicious configuration information, and compare the real configuration information and the suspicious configuration information to determine whether the router is suffering from a configuration hiding attack; (2)Real-time extraction of TCL scripts based on keyword matching, remotely transmit the heap file in the router's system directory through router_command_execute, and receive the heap file in a loop. Combine the keywords of the tbc file and the characteristics of the TCL script to achieve automatic positioning, extraction and analysis of the TCL scripts executed in the memory of the IOS-XE router; (3)System integrity verification. Calculate the hash values of the firmware, IOSd file, and loaded dynamic link libraries offline and establish an initial index file. At the same time, query the hash values of the IOSd process and the code segments of all loaded dynamic link libraries in the container in real time, and compare them with the hash values in the index file to determine whether the system image is complete.

6. An intrusion detection method for an IOS-XE system based on a container according to claim 1, characterized in that The router log information contains rich user operation behavior information, including user commands, configuration modifications, and user logins. Utilize the router archive and EEM functions, combined with the log server deployed in the container, to record all information input by the user at the CLI interface, thereby obtaining complete log information.

Citation Information

Patent Citations

  • Intrusion detect system and electronic device

    CN105978904A

  • Intrusion prevention method and device in container environment, electronic equipment and storage medium

    CN113992428A