A Trust Level Measurement Method and System Based on a Linux Kernel Host

By obtaining protection policies and monitoring mechanisms on the Linux kernel host, determining the trustworthy metric value and adjusting the trustworthiness level, the flexible measurement problem of trustworthy computing in the Linux kernel host is solved, and the system is safe and stable operation and ease of use is achieved.

CN116089960BActive Publication Date: 2025-07-25WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310097745.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-28
Publication Date
2025-07-25
Estimated Expiration
2043-01-28

AI Technical Summary

Technical Problem

When the existing technology implements trusted computing in Linux kernel hosts, the abnormal operation of system resources is not flexible and meticulous enough, which affects the ease of use and security of system operations, especially the coordinated work of heterogeneous computing resources under cloud platform deployment.

Method used

It provides a trustworthy level measurement method based on Linux kernel host. By obtaining protection policies and monitoring mechanisms, the trustworthy level of the target to be protected is determined, and the trustworthy level is adjusted based on the trustworthy metric value, the overall trust result of the system is generated, and dynamic monitoring is carried out in combination with trustworthy real-time measurement technology to reflect the operating status of the system in real time.

Benefits of technology

It realizes flexible and fine measurement of Linux kernel hosts to ensure the safe and stable operation of the system. Administrators can adjust the trust level according to the trust results, improving the security and ease of use of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116089960B_ABST
    Figure CN116089960B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for measuring the trust level of a Linux kernel host, belonging to the field of computer technology, including: obtaining the protection policy of the Linux kernel host, and determining the target to be protected based on the protection policy; determining the trust measurement value of the target to be protected according to the system resource metrics and dynamic trust metrics of the Linux kernel host; adjusting the trust level of the target to be protected based on the trust measurement value to generate an overall system trust result. By adopting the trusted real-time measurement technology on the Linux kernel host deployed locally or in the cloud, the present invention dynamically monitors the system device status, and the monitoring log reflecting the trusted status of the system operation in real time, and generates an overall system trust result based on the evaluation factor system, enabling the administrator to adopt different coping strategies according to the overall system trust result, flexibly adjust the trust level of the system, and ensure the safe and stable operation of the host system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a method and system for measuring the trust level based on a Linux kernel host. Background Art

[0002] When deploying a Linux kernel host, whether locally or in the cloud, information security issues are inevitably involved, and trusted computing technology is a crucial component technology in information security. Trusted computing technology uses a trusted computing platform based on secure hardware in computing and communication systems to enhance the security of the entire system. Secure hardware usually includes hardware such as a Trusted Platform Module (TPM), a TransFLash (TF) secure flash memory card, and a USB-key. After years of development and application, this technology has become an indispensable security component of various computing platforms.

[0003] In the actual application of trusted computing technology, due to the complexity of networking, there are many measurement resources participating in trusted computing during the operation of the complete system. Often, due to the lack of fine-grained measurement, as long as an abnormal resource is found, the entire system will be considered untrusted, thus affecting the usability and security of the entire system operation. Especially in the cloud platform deployment environment, there is a massive distributed structure of various heterogeneous computing resources. Once an entity fails to pass the measurement verification, it will greatly affect the collaborative work between security entities.

[0004] Therefore, a more flexible and higher-precision method for measuring the credibility of computing resources needs to be proposed. Summary of the Invention

[0005] The present invention provides a method and system for measuring the trust level based on a Linux kernel host to solve the defects in the prior art that when implementing trusted computing technology in a Linux kernel host, the detection and measurement of abnormal system resource operation are generally not flexible and fine enough and the accuracy is not high.

[0006] In a first aspect, the present invention provides a method for measuring the trust level based on a Linux kernel host, including:

[0007] Obtain the protection policy of the Linux kernel host, and determine the target to be protected based on the protection policy;

[0008] Determine the trust measurement value of the target to be protected according to the system resource indicators and dynamic trust indicators of the Linux kernel host;

[0009] Adjust the trust level of the target to be protected based on the trust measurement value to generate the overall trust result of the system.

[0010] A method for measuring the trust level of a Linux kernel host according to the present invention, the obtaining the protection policy of the Linux kernel host and determining the target to be protected based on the protection policy includes:

[0011] Obtain the backup mechanism of the target to be protected, and determine the target to be backed up based on the backup mechanism;

[0012] Obtain the monitoring mechanism of the target to be protected, and determine the target to be monitored based on the monitoring mechanism.

[0013] A method for measuring the trust level of a Linux kernel host according to the present invention, the obtaining the backup mechanism of the target to be protected and determining the target to be backed up based on the backup mechanism includes:

[0014] Obtain the storage path of the target to be backed up, and generate a compressed backup file and a compressed backup file digest value according to the storage path;

[0015] If it is determined that the target to be backed up mounts a trusted platform module, manage the key corresponding to the target to be backed up based on the trusted platform module, otherwise encrypt the target to be backed up based on the administrator password;

[0016] Encrypt the compressed backup file and the compressed backup file digest value to generate an encrypted file.

[0017] A method for measuring the trust level of a Linux kernel host according to the present invention, the obtaining the monitoring mechanism of the target to be protected and determining the target to be monitored based on the monitoring mechanism includes:

[0018] Obtain system monitoring parameters, register a monitoring process based on the system monitoring parameters, initialize the monitoring process, obtain the running parameters of the monitoring process, if it is determined that the number of running times of the monitoring process reaches a preset monitoring number, end the monitoring process, otherwise update the running parameters;

[0019] Determine the monitoring policy of the target to be monitored, create a process monitoring file based on the monitoring policy, obtain the running log of the process monitoring file, and read and update the running log.

[0020] A method for measuring the trust level of a Linux kernel host according to the present invention, the determining the trust measurement value of the target to be protected according to the system resource index and dynamic trust index of the Linux kernel host includes:

[0021] Monitor the system resources by using a preset identification process to obtain discrete trust element factors and continuous trust element factors in the system;

[0022] Based on the discrete trust element factors and the continuous trust element factors, obtain the system resource metrics and the dynamic trust metrics;

[0023] Integrate the system resource metrics and the dynamic trust metrics to obtain the trusted measurement value.

[0024] According to a trusted level measurement method for a Linux kernel host provided by the present invention, based on the discrete trust element factors and the continuous trust element factors, obtaining the system resource metrics includes:

[0025] Determine the number of idle system resources and the total number of system resources;

[0026] Based on the number of idle system resources and the total number of system resources, obtain a single-system-resource trust metric;

[0027] Obtain a set of resource trust metrics corresponding to each discrete trust element factor and each continuous trust element factor for a single system resource;

[0028] Perform normalization processing on the set of resource trust metrics based on a preset range of the resource trust metrics to obtain the system resource metrics.

[0029] According to a trusted level measurement method for a Linux kernel host provided by the present invention, based on the discrete trust element factors and the continuous trust element factors, obtaining the dynamic trust metrics includes:

[0030] Determine the abnormal operation score and the number of abnormal operations of the monitored file;

[0031] Based on the abnormal operation score, the number of abnormal operations, and the natural constant, obtain a single dynamic trust metric;

[0032] Obtain a set of dynamic trust metrics corresponding to each discrete trust element factor and each continuous trust element factor for a single monitored file;

[0033] Perform a difference operation on the set of resource trust metrics based on a preset range of the dynamic trust metrics to obtain the dynamic trust metrics.

[0034] According to a trusted level measurement method for a Linux kernel host provided by the present invention, adjusting the trusted level of the target to be protected based on the trusted measurement value to generate an overall system trust result includes:

[0035] Obtain a trusted evaluation system;

[0036] Compare the trusted measurement value of the target to be protected with the trusted evaluation system, adjust the trusted level of the target to be protected, and output an overall system trust value.

[0037] A method for measuring the trust level based on a Linux kernel host provided by the present invention. After adjusting the trust level of the target to be protected according to the trust measurement value and generating the overall system trust result, it further includes:

[0038] Obtain the storage path, compressed backup file, and compressed backup file digest value of the target to be backed up in the target to be protected;

[0039] Decrypt the compressed backup file to generate a decrypted backup file digest value;

[0040] Compare the compressed backup file digest value with the decrypted backup file digest value. If it is determined that the comparison values are consistent, restore the target to be backed up; otherwise, report an error to the system.

[0041] In a second aspect, the present invention also provides a trust level measurement system based on a Linux kernel host, including:

[0042] A determination module for obtaining the protection policy of the Linux kernel host and determining the target to be protected based on the protection policy;

[0043] A measurement module for determining the trust measurement value of the target to be protected according to the system resource metrics and dynamic trust metrics of the Linux kernel host;

[0044] An adjustment module for adjusting the trust level of the target to be protected based on the trust measurement value and generating the overall system trust result.

[0045] In a third aspect, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the method for measuring the trust level based on a Linux kernel host as described in any one of the above.

[0046] In a fourth aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the method for measuring the trust level based on a Linux kernel host as described in any one of the above.

[0047] The method and system for measuring the trust level based on a Linux kernel host provided by the present invention dynamically monitor the system device status by using the trusted real-time measurement technology on the Linux kernel host deployed locally or in the cloud, and generate the overall system trust result based on the evaluation factor system through the monitoring log that reflects the trusted status of the system operation in real time. This enables the administrator to adopt different response strategies according to the overall system trust result, flexibly adjust the trust level of the system, and ensure the safe and stable operation of the host system. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0049] Figure 1 It is a schematic flowchart of a trusted level measurement method for a Linux kernel-based host provided by the present invention;

[0050] Figure 2 It is a general design diagram of a trusted level measurement method for a Linux kernel-based host provided by the present invention;

[0051] Figure 3 It is a security backup flowchart provided by the present invention;

[0052] Figure 4 It is a system resource monitoring flowchart provided by the present invention;

[0053] Figure 5 It is a file monitoring flowchart provided by the present invention;

[0054] Figure 6 It is a security recovery flowchart provided by the present invention;

[0055] Figure 7 It is a schematic structural diagram of a trusted level measurement system for a Linux kernel-based host provided by the present invention;

[0056] Figure 8 It is a schematic structural diagram of an electronic device provided by the present invention. Detailed implementation manners

[0057] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the drawings in the present invention. Obviously, the described embodiments are some embodiments of the present invention, rather than all embodiments. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.

[0058] In view of the limitations existing in the deployment of the trusted security technology for Linux kernel hosts in the prior art, the present invention proposes a trusted level measurement method based on Linux kernel hosts. By an improved trust level division method, the trust level is divided according to the impact degree after the system resources are attacked and the actual situation of the current running system platform. The trust level evaluation supports runtime evaluation and offline evaluation, and provides an association model for response and recovery to obtain the overall trust result. Figure 1 is a schematic flowchart of the trusted level measurement method based on Linux kernel hosts provided by the present invention, as Figure 1 shown, including:

[0059] Step 100: Obtain the protection policy of the Linux kernel host, and determine the target to be protected based on the protection policy;

[0060] Step 200: Determine the trusted measurement value of the target to be protected according to the system resource metrics and dynamic trust metrics of the Linux kernel host;

[0061] Step 300: Adjust the trusted level of the target to be protected based on the trusted measurement value to generate the overall system trust result.

[0062] It should be noted that the Linux kernel host involved in the present invention can be deployed and run locally or in the cloud, and uses the trusted real-time measurement technology to dynamically monitor the status of system devices and reflect the current trusted status of the system in real time.

[0063] According to the actual running situation of the system, corresponding protection policies are adopted, and the actual target to be protected is obtained. The system resources and files are monitored to generate logs, and the system resource metrics and dynamic trust metrics are output in real time based on the evaluation factor system, and a trusted measurement value is comprehensively formed. The trust status of the system terminal entity is presented through the trusted measurement value, and the system administrator can set fine-grained response strategies based on the trust value, adjust the trusted level of the target to be protected, and generate the overall system trust result.

[0064] Specifically, as Figure 2 shown, in the overall design of the system, the present invention realizes trusted measurement by calling different functional modules for backup files and system files respectively. Among them, the backup module and the recovery module are called for backup files. The Dump command is used to generate the backup file system, and the Openssl library is called to encrypt the backup file securely using encryption and hash algorithms, and the Restore command is used to execute the recovery of the backup file; the file monitoring module and the process monitoring module are called for system files, and the Audit module is used to monitor the system files. Then, by integrating the information transmitted between the backup module, the recovery module, the file monitoring module and the process monitoring module, the scoring module outputs the trusted measurement value for the system administrator to perform process monitoring and processing.

[0065] The present invention dynamically monitors the status of system devices by adopting a trusted real-time measurement technology on a Linux kernel host deployed locally or in the cloud, and generates monitoring logs that reflect the trusted status of the system operation in real time. Based on an evaluation factor system, an overall system trust result is generated, enabling an administrator to adopt different response strategies according to the overall system trust result, flexibly adjust the trusted level of the system, and ensure the safe and stable operation of the host system.

[0066] Based on the above embodiments, step 100 includes:

[0067] Step 101: Obtain the backup mechanism of the target to be protected, and determine the target to be backed up based on the backup mechanism;

[0068] Step 102: Obtain the monitoring mechanism of the target to be protected, and determine the target to be monitored based on the monitoring mechanism.

[0069] Among them, step 101 includes:

[0070] Obtain the storage path of the target to be backed up, and generate a compressed backup file and a compressed backup file digest value according to the storage path;

[0071] If it is determined that the target to be backed up is mounted with a trusted platform module, manage the key corresponding to the target to be backed up based on the trusted platform module, otherwise encrypt the target to be backed up based on the administrator password;

[0072] Encrypt the compressed backup file and the compressed backup file digest value to generate an encrypted file.

[0073] Among them, step 102 includes:

[0074] Obtain system monitoring parameters, register a monitoring process based on the system monitoring parameters, initialize the monitoring process, obtain the running parameters of the monitoring process, if it is determined that the running times of the monitoring process reach a preset monitoring times, end the monitoring process, otherwise update the running parameters;

[0075] Determine the monitoring strategy of the target to be monitored, create a process monitoring file based on the monitoring strategy, obtain the running log of the process monitoring file, and read and update the running log.

[0076] Specifically, after installing the program and program dependency library files on the Linux kernel host, the system administrator needs to use the root user to set rules, including:

[0077] First, set the path of the file / folder that needs to be backed up and protected;

[0078] If files / folders that need to be backed up and protected are set, the program automatically detects whether the TPM is mounted on the system. If the TPM is mounted on the system, the TPM is used for key management. If the TPM is not mounted on the system, the administrator needs to provide a password to encrypt the backup files.

[0079] Then set the paths of the files / folders to be monitored and set the monitoring behaviors, including read operations, write operations, execution operations, and modification operations on the files.

[0080] Such as Figure 3 The security backup process proposed by the present invention as shown is executed by the backup module in Figure 2 and includes: obtaining the backup file path, generating and compressing the backup file, generating the backup file digest value, determining whether the TPM is mounted, further encrypting the backup file and the backup file digest value, and storing the encrypted file.

[0081] Such as Figure 4 The system resource monitoring process as shown is executed by the process monitoring module in Figure 2 and includes: obtaining the monitoring parameters, registering the monitoring process, initializing the process and starting to execute the monitoring, recording, reading, and outputting the corresponding monitoring parameters, counting whether the preset monitoring times have been reached. If so, the system monitoring process ends; otherwise, the data of the monitoring parameters is continuously updated.

[0082] Such as Figure 5 The file monitoring process as shown is executed by the file monitoring module in Figure 2 and includes: first configuring the monitoring rules, starting the audit service, and performing monitoring in the form of a daemon process, that is, creating a process to monitor the file. The daemon process here starts after the kernel is loaded and continuously runs to monitor the file, updates the log in real time and passes it to the scoring system until the system is shut down or forcibly shut down by the administrator with root privileges, outputs the running log of the monitoring file, and continuously reads and updates the running log.

[0083] By setting the backup and monitoring processes for system files and backup files, the present invention can obtain the system running status in real time and reasonably set the backup strategy, enabling the system to efficiently implement the calculation of trusted measurement.

[0084] Based on the above embodiments, step 200 includes:

[0085] Monitoring system resources using a preset recognition process to obtain discrete trust element factors and continuous trust element factors in the system;

[0086] Based on the discrete trust element factors and the continuous trust element factors, obtaining the system resource indicators and the dynamic trust indicators;

[0087] Based on the comprehensive system resource metrics and the dynamic trust metrics, the trusted measurement value is obtained.

[0088] Among them, based on the discrete trust element factors and the continuous trust element factors, the system resource metrics are obtained, including:

[0089] Determine the number of idle system resources and the total number of system resources;

[0090] Based on the number of idle system resources and the total number of system resources, a single system resource trust metric is obtained;

[0091] Obtain the resource trust metric set corresponding to each discrete trust element factor and each continuous trust element factor for a single system resource;

[0092] Based on the preset range of the resource trust metrics, the resource trust metric set is normalized to obtain the system resource metrics.

[0093] Among them, based on the discrete trust element factors and the continuous trust element factors, the dynamic trust metrics are obtained, including:

[0094] Determine the abnormal operation score and the number of abnormal operations of the monitored file;

[0095] Based on the abnormal operation score, the number of abnormal operations, and the natural constant, a single dynamic trust metric is obtained;

[0096] Obtain the dynamic trust metric set corresponding to each discrete trust element factor and each continuous trust element factor for a single monitored file;

[0097] Based on the preset range of the dynamic trust metrics, the difference is calculated for the resource trust metric set to obtain the dynamic trust metrics.

[0098] Specifically, on the basis of setting the backup strategy and the monitoring strategy, the trusted real-time measurement of the system resources is carried out. According to the characteristics of the system metric information types involved in the host system, the cloud system security, and the elastic fluctuations of the resource requirements, the system resources to be monitored are comprehensively selected, the basis standard suitable for the current running system platform metric selection is determined, the discrete trust element factors and the continuous trust element factors in the system are obtained. Here, the system resources are monitored in units of processes, and the usage of resources such as CPU, memory, and network IO by the monitored process can be realized by identifying the specified process PID number.

[0099] Quantify the standard into discrete and continuous trust element factors, and adopt a positive evaluation system to evaluate each system terminal security index element. Among them, the element value is a component of the overall trust value. By decomposing the overall trust value into each trust element value, the composition relationship between the overall trust value and the trust element value is constructed, and the possible internal causes of the overall trust value fluctuation are judged through the change of the trust element value. The continuous trust element factors are shown in Table 1, and the discrete trust element factors are shown in Table 2.

[0100] Table 1

[0101]

[0102] Table 2

[0103] Index Name Index Definition MemMinfltRate Frequency of minor faults occurred by the process MemMajfltRate Frequency of major faults occurred by the process CpuIndex Cup number of the currently running process

[0104] Furthermore, system resource indicators and dynamic trust indicators are adopted, which are embodied as system resource scores and dynamic trust scores. Without loss of generality, taking a full score of 100 as an example, in this embodiment, the system resource score and the dynamic trust score each account for 50 points.

[0105] For the system resource score, the program obtains the usage of system resources, including discrete and continuous trust element factors, which are incorporated into the trust score. When these indicators are low, the system resources are sufficient and the trust score is high. When some indicators are too high, the response ability of the system and the ability to cope with risks decline, and the trust score decreases. As the indicators gradually approach 100%, the rate of score decline gradually becomes faster.

[0106] Use F to represent the idle resources and T to represent the total resources. The trust score obtained for each type of resource is:

[0107] G = 7*T / (T - F) - 7, G ∈ [0, 10];

[0108] After obtaining the trust score for each type of resource, perform normalization processing on the score to obtain:

[0109] G(s) = 50*(G(CpuRatio) + G(CpuUsrRatio) + … + G(MemMajfltRate)) / 30.

[0110] For the dynamic trust score, when illegal read and write operations, modifications, additions, deletions, executions of monitored files, and access failures (such as insufficient permissions) are detected, the trust score will be reduced. The reduced score gradually increases as the number of illegal acts increases. Use D to represent the score reduced each time, and the number of occurrences is t. Introduce the natural constant e, then:

[0111] D = [5 * (e^t)] / x, where D ∈ [0, 50];

[0112] G(d) = 50 - D.

[0113] Here, x is a self - set parameter, usually taking the average value of the number of unauthorized access logs received by the system in a previous period of time.

[0114] It should be noted that when starting the recovery behavior, it is considered that the system has suffered a certain degree of damage, and a flag is passed to the scoring system, such as setting a 10 - point reduction in the trust score; if the recovery fails, it is considered that the degree of attack is relatively high, such as setting a 20 - point reduction in the trust score.

[0115] After obtaining the system resource indicators and dynamic trust indicators, determine the trust metric value for the evaluation of the system's trust level, which is used to evaluate the overall trust situation of the system's current operating state and represents the possible security risk situation within the system. The trust metric value is further refined into the composition of trust factor values, which can further refine the trust state from a micro perspective and can achieve micro - analysis and determination of risks.

[0116] The final trust metric value is the sum of two parts of scores, that is:

[0117] G = G(s) + G(d).

[0118] The present invention monitors through system resources and files, generates logs, and forms a trust metric value in real - time based on the evaluation factor system, with the characteristics of high accuracy and strong objectivity.

[0119] Based on the above - mentioned embodiments, step 300 includes:

[0120] Obtain the trust evaluation system;

[0121] Compare the trust metric value of the target to be protected and the trust evaluation system, adjust the trust level of the target to be protected, and output the overall system trust value.

[0122] Specifically, the program monitors the permission information of the system user group, password files, and the files and folders to be protected set by the administrator according to the set rules. Once an unauthorized event is monitored, a system warning will be thrown, and a corresponding log file will be generated to record details including the address of the illegal program, time, etc. in detail. And according to the severity classification of this behavior in the trust evaluation system, the micro - trust value of the corresponding trust factor is reduced, and finally reflected in the overall system trust value.

[0123] It should be noted that the rules set by the administrator here for protecting the permission information of the system user group, the password file, and the system setting related files are default written in the program, which is different from the protected files determined by the administrator according to the actual situation of the system in the foregoing embodiments.

[0124] After step 300, it further includes:

[0125] Obtain the storage path, the compressed backup file, and the compressed backup file digest value of the target to be backed up in the target to be protected;

[0126] Decrypt the compressed backup file to generate a decrypted backup file digest value;

[0127] Compare the compressed backup file digest value and the decrypted backup file digest value, and generate if it is determined that the comparison values are consistent, then restore the target to be backed up, otherwise report an error to the system.

[0128] Specifically, as Figure 6 shown in the secure recovery process, it is necessary to perform a secure recovery on the backup file. The specific implementation steps include:

[0129] Obtain the storage path, the compressed backup file, and the compressed backup file digest value of the target to be backed up in the target to be protected. According to whether the TPM is mounted, different decryption methods are judged, which correspond one by one to the foregoing encryption process. Then decrypt the compressed backup file to generate a new decrypted backup file digest value, compare the compressed backup file digest value and the decrypted backup file digest value, judge whether the two are consistent. If they are consistent, directly restore the file. If they are inconsistent, report an error to the system and stop the operation of restoring the file.

[0130] The present invention adjusts the trusted level of the system through the trusted measurement value, and provides backup and recovery of the specified files of the system, with high fault tolerance.

[0131] The trusted level measurement system based on the Linux kernel host provided by the present invention will be described below. The trusted level measurement system based on the Linux kernel host described below can be mutually corresponding and referred to the trusted level measurement method based on the Linux kernel host described above.

[0132] Figure 7 is a schematic structural diagram of the trusted level measurement system based on the Linux kernel host provided by the present invention. As Figure 7 shown, it includes a determination module 71, a measurement module 72, and an adjustment module 73, where:

[0133] The determination module 71 is configured to obtain the protection policy of the Linux kernel host and determine the target to be protected based on the protection policy; the measurement module 72 is configured to determine the trusted measurement value of the target to be protected according to the system resource metrics and dynamic trust metrics of the Linux kernel host; the adjustment module 73 is configured to adjust the trusted level of the target to be protected based on the trusted measurement value to generate an overall system trust result.

[0134] Figure 8 An example of the physical structure diagram of an electronic device is shown as Figure 8 shown. The electronic device may include: a processor 810, a communication interface 820, a memory 830, and a communication bus 840. Among them, the processor 810, the communication interface 820, and the memory 830 communicate with each other through the communication bus 840. The processor 810 can call the logical instructions in the memory 830 to execute the trusted level measurement method based on the Linux kernel host. The method includes: obtaining the protection policy of the Linux kernel host and determining the target to be protected based on the protection policy; determining the trusted measurement value of the target to be protected according to the system resource metrics and dynamic trust metrics of the Linux kernel host; adjusting the trusted level of the target to be protected based on the trusted measurement value to generate an overall system trust result.

[0135] In addition, when the logical instructions in the above-mentioned memory 830 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0136] On the other hand, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements a trusted level measurement method based on a Linux kernel host provided by the above-mentioned various methods. The method includes: obtaining a protection policy of the Linux kernel host, determining a target to be protected based on the protection policy; determining a trusted measurement value of the target to be protected according to system resource metrics and dynamic trust metrics of the Linux kernel host; adjusting the trusted level of the target to be protected based on the trusted measurement value to generate an overall system trust result.

[0137] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative effort.

[0138] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course also by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0139] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A trusted level measurement method for a Linux kernel-based host, characterized in that, Including: Obtain the protection policy of the Linux kernel host, and determine the target to be protected based on the protection policy; Determine the trusted measurement value of the target to be protected according to the system resource metrics and dynamic trust metrics of the Linux kernel host; Adjust the trusted level of the target to be protected based on the trusted measurement value to generate the overall system trust result; The step of determining the trusted measurement value of the target to be protected according to the system resource metrics and dynamic trust metrics of the Linux kernel host includes: Monitor the system resources using a preset recognition process to obtain discrete trust element factors and continuous trust element factors in the system; Based on the discrete trust element factors and the continuous trust element factors, obtain the system resource metrics and the dynamic trust metrics; Integrate the system resource metrics and the dynamic trust metrics to obtain the trusted measurement value; Based on the discrete trust element factors and the continuous trust element factors, obtaining the system resource metrics includes: Determine the number of idle system resources and the total number of system resources; Based on the number of idle system resources and the total number of system resources, obtain a single system resource trust metric; Obtain the resource trust metric set corresponding to each discrete trust element factor and each continuous trust element factor for a single system resource; Normalize the resource trust metric set based on the preset range of the resource trust metric to obtain the system resource metrics; Based on the discrete trust element factors and the continuous trust element factors, obtaining the dynamic trust metrics includes: Determine the abnormal operation score and the number of abnormal operations of the monitored file; Based on the abnormal operation score, the number of abnormal operations, and the natural constant, obtain a single dynamic trust metric; Obtain the dynamic trust metric set corresponding to each discrete trust element factor and each continuous trust element factor for a single monitored file; Take the difference of the resource trust metric set based on the preset range of the dynamic trust metric to obtain the dynamic trust metrics.

2. The trusted level measurement method based on the Linux kernel host according to claim 1, wherein The step of obtaining the protection policy of the Linux kernel host and determining the target to be protected based on the protection policy includes: Obtain the backup mechanism of the target to be protected, and determine the target to be backed up based on the backup mechanism; Obtain the monitoring mechanism of the target to be protected, and determine the target to be monitored based on the monitoring mechanism.

3. The method for measuring the trust level of a Linux kernel-based host according to claim 2, wherein The step of obtaining the backup mechanism of the target to be protected and determining the target to be backed up based on the backup mechanism includes: Obtain the storage path of the target to be backed up, and generate a compressed backup file and a compressed backup file digest value according to the storage path; If it is determined that the target to be backed up mounts a trusted platform module, manage the key corresponding to the target to be backed up based on the trusted platform module, otherwise encrypt the target to be backed up based on the administrator password; Encrypt the compressed backup file and the compressed backup file digest value to generate an encrypted file.

4. The method for measuring the trust level of a Linux kernel-based host according to claim 2, wherein The step of obtaining the monitoring mechanism of the target to be protected and determining the target to be monitored based on the monitoring mechanism includes: Obtain system monitoring parameters, register a monitoring process based on the system monitoring parameters, initialize the monitoring process, obtain the running parameters of the monitoring process, if it is determined that the running times of the monitoring process reach a preset monitoring times, then end the monitoring process, otherwise update the running parameters; Determine the monitoring strategy of the target to be monitored, create a process monitoring file based on the monitoring strategy, obtain the running log of the process monitoring file, and read and update the running log.

5. The method for measuring the trust level of a Linux kernel-based host according to claim 1, wherein Adjusting the trust level of the target to be protected based on the trusted measurement value and generating an overall system trust result includes: Obtain a trusted evaluation system; Compare the trusted measurement value of the target to be protected with the trusted evaluation system, adjust the trust level of the target to be protected, and output an overall system trust value.

6. The trusted level measurement method based on the Linux kernel host according to claim 1, wherein After adjusting the trust level of the target to be protected based on the trusted measurement value and generating an overall system trust result, it further includes: Obtain the storage path of the target to be backed up, the compressed backup file, and the compressed backup file digest value in the target to be protected; Decrypt the compressed backup file to generate a decrypted backup file digest value; Compare the compressed backup file digest value with the decrypted backup file digest value, and if it is determined that the comparison values are consistent, then restore the target to be backed up, otherwise report an error to the system.

7. A trusted level measurement system based on a Linux kernel host, characterized in that Includes: A determination module for obtaining a protection strategy of a Linux kernel host and determining a target to be protected based on the protection strategy; A measurement module for determining a trusted measurement value of the target to be protected according to the system resource indicators and dynamic trust indicators of the Linux kernel host; An adjustment module for adjusting the trust level of the target to be protected based on the trusted measurement value and generating an overall system trust result; Specifically, the measurement module is used for: Monitor system resources using a preset identification process to obtain discrete trust element factors and continuous trust element factors in the system; Based on the discrete trust element factors and the continuous trust element factors, obtain the system resource indicators and the dynamic trust indicators; Integrate the system resource indicators and the dynamic trust indicators to obtain the trusted measurement value; Based on the discrete trust element factors and the continuous trust element factors, obtaining the system resource indicators includes: Determine the number of system idle resources and the total number of system resources; Based on the number of system idle resources and the total number of system resources, obtain a single system resource trust indicator; Obtain a resource trust indicator set corresponding to each discrete trust element factor and each continuous trust element factor for a single system resource; Normalize the resource trust indicator set based on a preset range of resource trust indicators to obtain the system resource indicators; Based on the discrete trust element factors and the continuous trust element factors, obtaining the dynamic trust indicators includes: Determine the abnormal operation score and the number of abnormal operations of the monitoring file; Based on the abnormal operation score, the number of abnormal operations, and the natural constant, obtain a single dynamic trust indicator; Obtain a dynamic trust indicator set corresponding to each discrete trust element factor and each continuous trust element factor for a single monitoring file; Taking the difference of the resource trust metric set based on the preset range of the dynamic trust metric to obtain the dynamic trust metric.

Citation Information

Patent Citations

  • Active trusted computing method and active trusted computing system based on TrustZone sub-core asynchronous execution

    CN111353162A

  • Verification method and device for accessing host, access verification system and storage medium

    CN115422523A