Security protection method and device, electronic device and storage medium based on selinux module

The selinux module self-learning generates security protection conditions, which solves the problem of time-consuming and labor-intensive artificial settings, and realizes flexible and efficient security protection, adapting to the diverse needs of different servers.

CN115982717BActive Publication Date: 2025-07-25BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211675802.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-26
Publication Date
2025-07-25
Estimated Expiration
2042-12-26

AI Technical Summary

Technical Problem

In the prior art, the security protection rules of servers need to be set up manually, time-consuming and labor-intensive, unable to adapt to diverse needs, and cannot improve themselves.

Method used

Use the selinux module to perform self-learning, set its working state to access pass state, obtain the associated information of the access request, generate security protection conditions, and intercept requests that do not meet the conditions in the access detection state.

Benefits of technology

It realizes automatic generation of security protection conditions, adapts to different types and needs servers, reduces manual settings, and improves the flexibility and effectiveness of security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115982717B_ABST
    Figure CN115982717B_ABST
Patent Text Reader

Abstract

The present application provides a security protection method, device, electronic device, and storage medium based on the SELinux module. The method includes: in response to a security protection condition setting instruction, setting the current working state of the SELinux module to the access permitted state; obtaining the association information of all access requests permitted by the SELinux module in the access permitted state; generating a security protection condition based on the association information of all the access requests; after generating the security protection condition, setting the current working state of the SELinux module to the access detection state, so as to intercept access requests that do not meet the security protection condition through the SELinux module in the access detection state. The technical solution of the present application can make the generated security protection condition better meet the personalized requirements of the current server, current system, and even each access request, improve the flexibility and effectiveness of security protection condition setting, and contribute to the improvement of system security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer security technologies, and in particular, to a security protection method and device, an electronic device, and a storage medium based on the selinux module.

Background Art

[0002] In the current server market, different servers are set with security protection rules by developers. When a server detects an access request, if the access request conforms to the security protection rules, the access request can pass.

[0003] However, due to the variety of servers, corresponding manual settings are required for different types and different requirements of servers, which is time-consuming and laborious. At the same time, the manually set security protection rules are relatively rigid and cannot adapt to the diverse needs of servers, especially cannot self-improve with the changing needs of servers.

[0004] Therefore, how to automatically and efficiently set security protection rules for servers has become a technical problem to be solved urgently at present.

Summary of the Invention

[0005] Embodiments of this application provide a security protection method and device, an electronic device, and a storage medium based on the selinux module, aiming to solve the technical problems in the related art that manually setting security protection rules is time-consuming and laborious and cannot adapt to the diverse needs of servers.

[0006] In a first aspect, embodiments of this application provide a security protection method based on the selinux module, including: in response to a security protection condition setting instruction, setting the current working state of the selinux module to an access-pass state; obtaining the association information of all access requests passed by the selinux module in the access-pass state; generating a security protection condition based on the association information of all the access requests; after generating the security protection condition, setting the current working state of the selinux module to an access detection state, so as to intercept access requests that do not meet the security protection condition through the selinux module in the access detection state.

[0007] In a possible design, setting the current working state of the selinux module to the access-pass state includes: setting the selinux module to be in the access-pass state within a specified period, where the specified period is one or more.

[0008] In a possible design, setting the current working state of the SELinux module to the access - passed state includes: when it is detected that the current access request meets the specified security conditions, setting the current working state of the SELinux module when processing the current access request to the access - passed state.

[0009] In a possible design, the specified security conditions include at least one of the following: the current access request comes from a predetermined security object; the target accessed by the current access request is a predetermined security location; the running process involved in the current access request is a predetermined security process.

[0010] In a possible design, obtaining the associated information of all access requests passed by the SELinux module in the access - passed state includes: obtaining the source information, access location information, request content information, and thread information of all access requests passed by the SELinux module in the access - passed state.

[0011] In a possible design, generating security protection conditions based on the associated information of all access requests includes: converting the source information, access location information, request content information, and thread information of all access requests into a first input feature value; performing normalization processing on the first input feature value; using the normalized first input feature value of each access request as an input sample, and using the processing result of the SELinux module for each access request as an output sample to train a security protection model as the security protection conditions.

[0012] In a possible design, generating security protection conditions based on the associated information of all access requests includes: determining the request type of each access request; converting the request type, source information, access location information, request content information, and thread information of all access requests into a second input feature value; performing normalization processing on the second input feature value; using the normalized second input feature value of each access request as an input sample, and using the processing result of the SELinux module for each access request as an output sample to train a security protection model as the security protection conditions.

[0013] In a second aspect, an embodiment of the present application provides a security protection device based on the selinux module, including: an access pass status setting unit configured to set the current working state of the selinux module to the access pass status in response to a security protection condition setting instruction; an associated information acquisition unit configured to acquire the associated information of all access requests passed by the selinux module in the access pass status; a security protection condition generation unit configured to generate a security protection condition based on the associated information of all the access requests; an access detection status setting unit configured to set the current working state of the selinux module to the access detection status after generating the security protection condition; and a security protection unit configured to intercept access requests that do not meet the security protection condition through the selinux module in the access detection status.

[0014] In a possible design, the access pass status setting unit is configured to: set the selinux module to be in the access pass status within a specified period, where the specified period is one or more.

[0015] In a possible design, the access pass status setting unit is configured to: when it is detected that the current access request meets a specified security condition, set the current working state of the selinux module when processing the current access request to the access pass status.

[0016] In a possible design, the specified security condition includes at least one of the following: the current access request comes from a predetermined security object; the target accessed by the current access request is a predetermined security location; the running process involved in the current access request is a predetermined security process.

[0017] In a possible design, the associated information acquisition unit is configured to: acquire the source information, access location information, request content information, and thread information of all access requests passed by the selinux module in the access pass status.

[0018] In a possible design, the security protection condition generation unit is configured to: convert the source information, access location information, request content information, and thread information of all the access requests into a first input feature value; perform normalization processing on the first input feature value; use the normalized first input feature value of each access request as an input sample, and use the processing result of the selinux module for each access request as an output sample to train a security protection model as the security protection condition.

[0019] In a possible design, the security protection condition generation unit is configured to: determine the request type of each access request; convert the request type, source information, access location information, request content information, and thread information of all the access requests into a second input feature value; perform normalization processing on the second input feature value; use the normalized second input feature value of each access request as an input sample, and use the processing result of the selinux module for each access request as an output sample to train a security protection model as the security protection condition.

[0020] In a third aspect, an embodiment of the present application provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are configured to execute the method described in the first aspect above.

[0021] In a fourth aspect, an embodiment of the present application provides a storage medium storing computer-executable instructions for executing the method flow described in the first aspect above.

[0022] For the above technical solutions, in view of the technical problem in the related art that it is time-consuming and laborious to manually set security protection rules and cannot meet the diverse requirements of the server, first, in response to a security protection condition setting instruction, the current working state of the selinux module is set to an access-allowed state. Once the system detects a security protection condition setting instruction, the selinux module can be set to the access-allowed state to enter the steps of setting the security protection condition. In other words, the access-allowed state of the selinux module is the state for the system to set the security protection condition.

[0023] Next, obtain the association information of all the access requests passed by the selinux module in the access-allowed state. The access-allowed state of the selinux module is equivalent to a learning state, and all the access requests passed by the selinux module in the access-allowed state are the learning content of the selinux module. Further, the association information of each access request can be obtained as the specific learning content.

[0024] Then, based on the association information of all the access requests, generate a security protection condition. Thus, all the access requests passed by the selinux module in the access-allowed state are used as secure access requests for learning, and the association information of all the access requests passed by the selinux module in the access-allowed state can reflect the commonalities and regularities of the secure access requests. On this basis, according to the association information of all the access requests, a security protection condition adaptable to the access requests actually received by the system can be generated.

[0025] Finally, after generating the security protection conditions, set the current working state of the SELinux module to the access detection state, so as to intercept access requests that do not meet the security protection conditions through the SELinux module in the access detection state. Generating the security protection conditions is equivalent to the SELinux module completing the learning of all access requests passed in the access pass state. At this time, the current working state of the SELinux module can be set to the access detection state, restoring the security detection function of the SELinux module, so that the SELinux module performs security detection on the access requests received in the access detection state based on the generated security protection conditions. Once an access request does not meet the security protection conditions, the access request is intercepted.

[0026] The above technical solution can automatically generate security protection conditions by the SELinux module built in the system to self-learn the access requests received by the system. This automatic generation method of security protection conditions is compatible with servers of different types and different requirements, and does not require a cumbersome manual setting process, saving time and effort. At the same time, due to the adjustable working state of the SELinux module, the system can start the setting and update of the security protection conditions at any time according to actual needs, and the basis for the setting and update of the security protection conditions is the access requests actually received by the system. Therefore, the generated security protection conditions can better meet the personalized needs of the current server, the current system and even each access request, improving the flexibility and effectiveness of the setting of the security protection conditions and contributing to the improvement of system security.

Description of the Drawings

[0027] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0028] Figure 1 Shows a flowchart of a security protection method based on the SELinux module according to an embodiment of the present application;

[0029] Figure 2 Shows a flowchart of a security protection method based on the SELinux module according to another embodiment of the present application;

[0030] Figure 3 Shows a flowchart of a security protection method based on the SELinux module according to still another embodiment of the present application;

[0031] Figure 4A block diagram of a security protection device based on the selinux module according to an embodiment of the present application is shown;

[0032] Figure 5 A block diagram of an electronic device according to an embodiment of the present application is shown.

Specific Embodiments

[0033] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0034] Embodiment 1

[0035] Figure 1 A flowchart of a security protection method based on the selinux module according to an embodiment of the present application is shown.

[0036] As Figure 1 shown, the security protection method based on the selinux module according to an embodiment of the present application includes:

[0037] Step 102, in response to a security protection condition setting instruction, set the current working state of the selinux module to the access-through state.

[0038] The selinux module is a mandatory access control security system based on the domain-type model, which is used to perform security detection on the access requests received by the system and is equivalent to an access control tool. Setting the current working state of the selinux module to the access-through state means that when the selinux module performs security detection on the received access request, the access request is directly passed through, enabling the access request to pass the security detection. Of course, to ensure the security of the system, corresponding alarm information can be generated when passing any access request to prompt the user that the selinux module is currently in the access-through state.

[0039] The security protection condition setting instruction can be automatically generated by the system periodically or issued by the user's operation. In short, once the system detects the security protection condition setting instruction, the selinux module can be set to the access-through state to enter the steps of setting the security protection conditions. In other words, the access-through state of the selinux module is the state for setting the security protection conditions of the system.

[0040] Step 104, obtain the association information of all the access requests passed by the selinux module in the access-through state.

[0041] The access pass state of the SELinux module is equivalent to the learning state. All access requests passed by the SELinux module in the access pass state are the learning content of the SELinux module. Further, the associated information of each access request can be obtained as the specific learning content.

[0042] In a possible design, step 104 includes: obtaining the source information, access location information, request content information, and thread information of all access requests passed by the SELinux module in the access pass state. Of course, the associated information of the access request includes but is not limited to the source information, access location information, request content information, and thread information of the access request, and can also be any information that can reflect the security of the access request.

[0043] Step 106, generating security protection conditions based on the associated information of all the access requests.

[0044] Thus, all access requests passed by the SELinux module in the access pass state are used as secure access requests for learning. The associated information of all access requests passed by the SELinux module in the access pass state can reflect the commonalities and regularities of secure access requests. On this basis, according to the associated information of all access requests, security protection conditions adaptable to the access requests actually received by the system can be generated.

[0045] Step 108, after generating the security protection conditions, set the current working state of the SELinux module to the access detection state, so as to intercept access requests that do not meet the security protection conditions through the SELinux module in the access detection state.

[0046] Generating the security protection conditions is equivalent to the SELinux module completing the learning of all access requests passed in the access pass state. At this time, the current working state of the SELinux module can be set to the access detection state, restoring the security detection function of the SELinux module, so that the SELinux module performs security detection on the access requests received in the access detection state based on the generated security protection conditions. Once the access request does not meet the security protection conditions, the access request is intercepted.

[0047] In the above technical solution, the system's built-in selinux module can perform self-learning on the access requests received by the system to automatically generate security protection conditions. This automatic generation method of security protection conditions is compatible with servers of different types and different requirements, and does not require a cumbersome manual setting process, saving time and effort. At the same time, due to the adjustable working state of the selinux module, the system can start the setting and update of security protection conditions at any required time based on actual needs, and the basis for the setting and update of security protection conditions is the access requests actually received by the system. Therefore, the generated security protection conditions can better meet the personalized needs of the current server, the current system, and each access request, improving the flexibility and effectiveness of the setting of security protection conditions and contributing to the improvement of system security.

[0048] Embodiment 2

[0049] Figure 2 The flowchart of the security protection method based on the selinux module according to another embodiment of the present application is shown.

[0050] Step 202, in response to the security protection condition setting instruction, set the selinux module to be in the access-passing state within the specified time period.

[0051] Step 204, obtain the association information of all access requests passed by the selinux module in the access-passing state.

[0052] Step 206, generate security protection conditions based on the association information of all access requests.

[0053] Step 208, after generating the security protection conditions, set the current working state of the selinux module to the access detection state to intercept access requests that do not meet the security protection conditions through the selinux module in the access detection state.

[0054] Among them, the specified time period is one or more, and the durations of the multiple specified time periods are the same or different. The specified time period can be a time period set by the user, or a time period corresponding to the current cycle of a historical time period with a sufficiently high security level of access requests within the time period. For example, if all access requests detected by the selinux module during the period from 13:00 to 13:45 every day last week were security requests that could pass, then when the security protection conditions need to be updated, set the period from 13:00 to 13:45 on the current day as the specified time period. The so-called sufficiently high security level here can be that the proportion of security requests that can pass among the access requests is greater than the specified proportion.

[0055] In addition, the specified time period can also be the time period corresponding to the current cycle of the historical time period in which the proportion of security requests that can pass among the access requests within the time period is greater than the specified proportion, and the number of requests of each type in the access requests is greater than the corresponding predetermined effective reference quantity for that type. That is to say, the security of the access requests within the specified time period is high enough, the types of requests covered by the access requests are comprehensive enough, and the number of requests under each request type is large enough, which can be used as an effective reference basis.

[0056] Based on the first embodiment, it can be known that the current working state of the selinux module is set to the access-pass state, that is, when the selinux module performs security detection on the received access request, the access request is directly passed, so that the access request passes the security detection. The access-pass state of the selinux module is equivalent to the learning state, and all the access requests passed by the selinux module in the access-pass state are the learning content of the selinux module.

[0057] On this basis, in this technical solution, the selinux module is set to be in the access-pass state within the specified time period. That is to say, the selinux module passes the access requests within the specified time period, and the selinux module uses the access requests passed by itself within the specified time period as the learning content for setting the security protection conditions.

[0058] The above technical solution can improve the rationality of the basis for setting the security protection conditions by restricting the selinux module to use the access requests passed within the specified time period as the basis for setting the security protection conditions, thereby facilitating the generation of more accurate and practical security protection conditions and improving the security protection level.

[0059] Embodiment Three

[0060] Figure 3 Shows a flowchart of a security protection method based on the selinux module according to another embodiment of the present application.

[0061] Step 302, in response to a security protection condition setting instruction, when it is detected that the current access request meets the specified security condition, set the current working state of the selinux module when processing the current access request to the access-pass state.

[0062] Step 304, obtain the association information of all the access requests passed by the selinux module in the access-pass state.

[0063] Step 306, generate a security protection condition based on the association information of all the access requests.

[0064] Step 308, after generating the security protection condition, set the current working state of the selinux module to the access detection state, so as to intercept access requests that do not meet the security protection condition through the selinux module in the access detection state.

[0065] Based on the first embodiment, it can be known that setting the current working state of the selinux module to the access pass state means that when the selinux module performs security detection on the received access request, the access request is directly passed, so that the access request passes the security detection. The access pass state of the selinux module is equivalent to the learning state, and all the access requests passed by the selinux module in the access pass state are the learning content of the selinux module.

[0066] On this basis, in this technical solution, using the access requests that meet the specified security conditions as the learning content of the selinux module to generate the security protection condition is equivalent to further screening the learning content, improving the reliability of the sample data used by the selinux module for self-learning, so that the generated security protection condition is more accurate and practical, and the security protection level is improved.

[0067] Among them, the specified security condition includes at least one of the following: the current access request comes from a predetermined security object; the target requested to be accessed by the current access request is a predetermined security location; the running process involved in the current access request is a predetermined security process.

[0068] For example, taking a PHP website as an example, the website script only accesses its own ROOT directory, and the running process is php-fpm. After the selinux module learns the access requests of the PHP website in the access pass state, it can generate the corresponding security protection condition as running the php-fpm process and the file access directory ROOT_DIR. Then, once the selinux module receives an access request from the PHP website in the access detection state, it can detect whether its running process is php-fpm and whether its file access directory is ROOT_DIR. Only when its running process is php-fpm and its file access directory is ROOT_DIR, the access request is passed. Otherwise, the selinux module determines that the access request is illegal and intercepts the access request.

[0069] The above technical solution can generate personalized security protection conditions for specific objects. Further, through the learning of the SELinux module, security protection conditions adapted to their own situations and needs can be generated for a large number of specific objects. Compared with the method of manually setting security protection conditions in the related art, it effectively reduces the labor cost and time cost, and can quickly, efficiently, and automatically implement customized security protection detection for different objects, improving the scope and comprehensiveness of the system's security protection.

[0070] Based on the first to third embodiments, in a possible design, generating security protection conditions based on the association information of all access requests includes: converting the source information, access location information, request content information, and thread information of all access requests into first input feature values; normalizing the first input feature values; using the normalized first input feature values of each access request as input samples, and using the processing results of the SELinux module for each access request as output samples to train a security protection model as the security protection conditions.

[0071] That is to say, the source information, access location information, request content information, and thread information of each access request can be converted as multi-dimensional sample data into first input feature values as input samples, and the processing results of the SELinux module for each access request, that is, the access request passes, can be used as output samples to train a security protection model. Among them, the security protection model can be trained in the way of binary classification neural network or BP neural network.

[0072] Based on the first to third embodiments, in another possible design, generating security protection conditions based on the association information of all access requests includes: determining the request type of each access request; converting the request type, source information, access location information, request content information, and thread information of all access requests into second input feature values; normalizing the second input feature values; using the normalized second input feature values of each access request as input samples, and using the processing results of the SELinux module for each access request as output samples to train a security protection model as the security protection conditions.

[0073] In this technical solution, setting the request type of the access request as one of the multiple dimensions of the input sample and combining the request type of the access request with the source information, access location information, request content information, and thread information of the access request can more comprehensively reflect the actual situation of the access request.

[0074] In addition, the security protection models trained in the above two technical solutions are both used to reflect the correlation between the access request and the security detection result of the selinux module for the access request. By means of a neural network, the multi-dimensional representation content of the access request is considered as a condition affecting the security detection result of the selinux module for the access request, which can meet the personalized security detection requirements of various access requests of different types, different sources, different access purposes, different request contents, and using different threads, improve the flexibility and effectiveness of the security protection condition setting, and contribute to the improvement of system security.

[0075] Figure 4 FIG. shows a block diagram of a security protection device based on the selinux module according to an embodiment of the present application.

[0076] As Figure 4 shown, the security protection device 400 based on the selinux module according to an embodiment of the present application includes: an access pass state setting unit 402, configured to set the current working state of the selinux module to the access pass state in response to a security protection condition setting instruction; an association information acquisition unit 404, configured to acquire the association information of all access requests passed by the selinux module in the access pass state; a security protection condition generation unit 406, configured to generate a security protection condition based on the association information of all access requests; an access detection state setting unit 408, configured to set the current working state of the selinux module to the access detection state after generating the security protection condition; and a security protection unit 410, configured to intercept access requests that do not meet the security protection condition through the selinux module in the access detection state.

[0077] In a possible design, the access pass state setting unit 402 is configured to: set the selinux module to be in the access pass state within a specified period, where the specified period is one or more.

[0078] In a possible design, the access pass state setting unit 402 is configured to: when it is detected that the current access request meets a specified security condition, set the current working state of the selinux module when processing the current access request to the access pass state.

[0079] In a possible design, the specified security condition includes at least one of the following: the current access request comes from a predetermined security object; the target accessed by the current access request is a predetermined security location; the running process involved in the current access request is a predetermined security process.

[0080] In a possible design, the association information acquisition unit 404 is configured to: acquire the source information, access location information, request content information, and thread information of all access requests passed by the selinux module in the access passed state.

[0081] In a possible design, the security protection condition generation unit 406 is configured to: convert the source information, access location information, request content information, and thread information of all access requests into first input feature values; perform normalization processing on the first input feature values; use the normalized first input feature values of each access request as input samples, and use the processing results of the selinux module for each access request as output samples to train a security protection model as the security protection condition.

[0082] In a possible design, the security protection condition generation unit 406 is configured to: determine the request type of each access request; convert the request type, source information, access location information, request content information, and thread information of all access requests into second input feature values; perform normalization processing on the second input feature values; use the normalized second input feature values of each access request as input samples, and use the processing results of the selinux module for each access request as output samples to train a security protection model as the security protection condition.

[0083] The security protection device 400 based on the selinux module uses the solution described in any one of the above embodiments, and therefore has all the above technical effects, which will not be elaborated here.

[0084] Figure 5 The block diagram of an electronic device according to an embodiment of the present application is shown.

[0085] As Figure 5 shown, an electronic device 500 according to an embodiment of the present application includes at least one memory 502; and a processor 504 communicatively connected to the at least one memory 502; wherein, the memory stores instructions executable by the at least one processor 504, and the instructions are configured to execute the solution described in any one of the above embodiments. Therefore, the electronic device 500 has the same technical effects as any one of the above embodiments, which will not be elaborated here.

[0086] The electronic device in the embodiment of the present application exists in various forms, including but not limited to:

[0087] (1) Mobile communication devices: These devices are characterized by having mobile communication functions and mainly aim to provide voice and data communications. Such terminals include: smart phones (such as iPhone), multimedia phones, functional phones, and low-end phones, etc.

[0088] (2) Ultra-mobile personal computer devices: These devices belong to the category of personal computers, have computing and processing functions, and generally also have the characteristic of mobile Internet access. Such terminals include: PDA, MID, and UMPC devices, etc., such as iPad.

[0089] (3) Portable entertainment devices: These devices can display and play multimedia content. Such devices include: audio and video players (such as iPod), handheld game consoles, e-books, and smart toys and portable in-vehicle navigation devices.

[0090] (4) Servers: Devices that provide computing services. The composition of a server includes a processor, hard disk, memory, system bus, etc. Servers are similar to general computer architectures, but due to the need to provide highly reliable services, they have higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.

[0091] (5) Other electronic devices with data interaction functions.

[0092] In addition, the embodiments of the present application provide a storage medium storing computer-executable instructions, and the computer-executable instructions are used to perform the following steps: in response to a security protection condition setting instruction, set the current working state of the selinux module to the access-pass state; obtain the association information of all access requests passed by the selinux module in the access-pass state; generate a security protection condition based on the association information of all access requests; after generating the security protection condition, set the current working state of the selinux module to the access detection state to intercept access requests that do not meet the security protection condition through the selinux module in the access detection state.

[0093] It should be noted that for the functions or steps that the above storage medium or electronic device can achieve, reference can be made to the relevant descriptions in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0094] The technical solution of the present application has been described in detail above in conjunction with the accompanying drawings. Through the technical solution of the present application, the system can automatically generate security protection conditions by self-learning the access requests received by the system through the built-in selinux module. This automatic generation method of security protection conditions can be compatible with servers of different types and different requirements, and does not require a cumbersome manual setting process, saving time and effort. At the same time, due to the adjustable working state of the selinux module, the system can start the setting and updating of security protection conditions at any required time based on actual needs, and the basis for setting and updating security protection conditions is the access requests actually received by the system. Therefore, the generated security protection conditions can better meet the personalized needs of the current server, the current system and even each access request, improving the flexibility and effectiveness of setting security protection conditions and contributing to the improvement of system security.

[0095] It should be understood that although the terms first, second, etc. may be used in the embodiments of the present application to describe input characteristic values, these input characteristic values should not be limited to these terms. These terms are only used to distinguish the input characteristic values from each other. For example, without departing from the scope of the embodiments of the present application, the first input characteristic value may also be referred to as the second input characteristic value, and similarly, the second input characteristic value may also be referred to as the first input characteristic value.

[0096] Depending on the context, the word "if" as used herein can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detecting (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)".

[0097] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. The singular forms "a", "the" and "said" used in the embodiments of the present application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0098] In several embodiments provided by the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in electrical, mechanical or other forms.

[0099] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware, or in the form of a hardware plus software functional unit.

[0100] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0101] The above-described embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.

Claims

1. A security protection method based on the selinux module, characterized in that, Including: In response to a security protection condition setting instruction, set the current working state of the selinux module to the access - passed state; The setting of the current working state of the selinux module to the access - passed state includes: Set the selinux module to be in the access - passed state within a specified period, where the specified period is one or more; The setting of the current working state of the selinux module to the access - passed state includes: When it is detected that the current access request meets the specified security conditions, set the current working state of the selinux module when processing the current access request to the access - passed state; The specified security conditions include at least one of the following: The current access request comes from a predetermined security object; The target accessed by the current access request is a predetermined security location; The running process involved in the current access request is a predetermined security process; Obtain the correlation information of all access requests passed by the selinux module in the access - passed state; Generate a security protection condition based on the correlation information of all access requests; After generating the security protection condition, set the current working state of the selinux module to the access - detection state to intercept access requests that do not meet the security protection condition through the selinux module in the access - detection state.

2. The security protection method based on the selinux module according to claim 1, wherein The obtaining of the correlation information of all access requests passed by the selinux module in the access - passed state includes: Obtain the source information, access location information, request content information, and thread information of all access requests passed by the selinux module in the access - passed state.

3. The security protection method based on the selinux module according to claim 2, wherein The generating of a security protection condition based on the correlation information of all access requests includes: Convert the source information, access location information, request content information, and thread information of all access requests into a first input feature value; Perform normalization processing on the first input feature value; Use the normalized first input feature value of each access request as an input sample and the processing result of the selinux module for each access request as an output sample to train a security protection model as the security protection condition.

4. The security protection method based on the selinux module according to claim 2, characterized in that, The generating of a security protection condition based on the correlation information of all access requests includes: Determine the request type of each access request; Convert the request type, source information, access location information, request content information, and thread information of all access requests into a second input feature value; Perform normalization processing on the second input feature value; Use the normalized second input feature value of each access request as an input sample and the processing result of the selinux module for each access request as an output sample to train a security protection model as the security protection condition.

5. A security protection device based on the selinux module, characterized in that, Including: An access - passed state setting unit for setting the current working state of the selinux module to the access - passed state in response to a security protection condition setting instruction; Setting the current working state of the SELinux module to the access - permitted state includes: Setting the SELinux module to be in the access - permitted state within a specified period, where the specified period is one or more; Setting the current working state of the SELinux module to the access - permitted state includes: When it is detected that the current access request meets the specified security conditions, setting the current working state of the SELinux module when processing the current access request to the access - permitted state; The specified security conditions include at least one of the following: The current access request comes from a predetermined security object; The target accessed by the current access request is a predetermined security location; The running process involved in the current access request is a predetermined security process; An associated - information acquisition unit, configured to acquire the associated information of all access requests passed by the SELinux module in the access - permitted state; A security - protection condition generation unit, configured to generate security - protection conditions based on the associated information of all access requests; An access - detection state setting unit, configured to set the current working state of the SELinux module to the access - detection state after generating the security - protection conditions; A security - protection unit, configured to intercept access requests that do not meet the security - protection conditions through the SELinux module in the access - detection state.

6. An electronic device, characterized in that, Including: At least one processor; And a memory communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and the instructions are configured to execute the method according to any one of claims 1 to 4 above.

7. A storage medium, characterized in that, Storing computer - executable instructions for executing the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Self-learning credible strategy construction method and system based on SELinux

    CN111159713A

  • Abnormal access detection method and device, electronic equipment and readable storage medium

    CN113949527A