Security verification method for kernel driver, terminal device and storage medium

By extracting the ioctl() system call parameters driven by Linux kernel, building a feature information matrix and using the Bagging algorithm to generate a security verifier, the accuracy problem of kernel-driven security verification is solved, and dynamic continuous evaluation of the system security status is achieved.

CN116305110BActive Publication Date: 2025-07-25HUNAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310002397.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-03
Publication Date
2025-07-25
Estimated Expiration
2043-01-03

AI Technical Summary

Technical Problem

The prior art is difficult to accurately verify the security of kernel drivers, and it is impossible to effectively extract common features between drivers, and lacks a comprehensive system security detection method.

Method used

By extracting the ioctl() system call parameters in the Linux kernel driver source code, building a driver feature information vector matrix, using the Bagging algorithm to generate a kernel-driven security verification device, combining parallel learning and hook technology to intercept parameter values for static comparison, and determining whether the kernel driver parameters are maliciously modified.

Benefits of technology

It realizes accurate security detection of kernel-driven, can quickly identify system security status changes, and provides a comprehensive dynamic and continuous evaluation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116305110B_ABST
    Figure CN116305110B_ABST
Patent Text Reader

Abstract

The present invention discloses a security verification method, a terminal device and a storage medium for kernel drivers, which analyze the Linux kernel driver source code, extract the parameters of the ioctl() system call; according to the extracted kernel driver parameters, use the kernel driver parameters to extract driver feature information; according to the extracted feature information of various kernel drivers, use the feature information of different driver programs to construct a vector matrix; construct a driver program feature information data set, use the parallel Bagging algorithm for learning, and construct a kernel driver security verifier; at any time, hook the system call ioctl(), intercept the data stream and extract the parameter values of ioctl() at this moment; according to the parameter values, extract the feature information of the kernel driver at this moment and use it as the input of the kernel driver security verifier, and perform a static comparison with the training result to determine whether the kernel driver parameters have been maliciously modified at this moment. The present invention can continuously evaluate the security status of the system in a more comprehensive way.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of system security, and particularly to a security verification method for kernel drivers, a terminal device, and a storage medium, which are used to evaluate the integrity and security of the kernel during operation. Background Art

[0002] For a long time, attacks based on vulnerability exploitation and malicious code have always been one of the main threats faced by computer software and operating system security. Kernel driver programs are the main components of the Linux kernel and are used to handle operations on various physical devices. With the development of technology, new hardware is constantly increasing, and the device driver programs in the system kernel are constantly proliferating. Since most of the driver programs are provided by third-party developers, they are more vulnerable to security vulnerabilities. Most of the Linux kernel vulnerabilities are kernel driver vulnerabilities. Third-party attackers are more likely to achieve the goal of attacking the target host by maliciously modifying the kernel driver parameters, resulting in privilege escalation vulnerabilities or arbitrary code execution. So far, the research on the security of driver programs is relatively less.

[0003] Due to the large number of kernel drivers and the huge amount of code, how to accurately and real-time verify the security of kernel drivers is a difficult problem. According to existing research, there are mainly the following problems in verifying the security of kernel drivers: First, the types and quantities of kernel drivers are large, and it is impossible to extract the common features between drivers well. Second, due to the large number of drivers, there is no completely fitting model to learn the differences between kernel drivers. Third, how to define the criteria for measuring the damage to system security. Fourth, how to accurately extract an effective and widely covered training set to train the model. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a security verification method for kernel drivers, a terminal device, and a storage medium in view of the deficiencies of the prior art, to solve the problem of large differences in training sets and accurately detect system security.

[0005] To solve the above technical problems, the technical solution adopted by the present invention is: A security verification method for kernel drivers, comprising the following steps:

[0006] 1) Extract the kernel driver parameters of the ioctl() system call in the Linux kernel driver source code;

[0007] 2) Extract the characteristic information of the driver program by using the kernel driver parameters;

[0008] 3) Construct a vector matrix by using the characteristic information of different driver programs;

[0009] 4) Construct a driver feature information data set using the vector matrix, and use the driver feature information data set as the input of the Bagging algorithm to obtain a kernel driver security checker and the output of the kernel driver security checker;

[0010] 5) Hook the system call ioctl(), intercept the data stream and extract the parameter values of ioctl() at this moment;

[0011] 6) According to the parameter values generated in step 5), extract the feature information of the kernel driver and use it as the input of the kernel driver security checker, and statically compare the obtained result with the output of the kernel driver security checker in step 4) to determine whether the kernel driver parameters have been maliciously modified, and further determine whether the system is in a safe state at the current moment.

[0012] The present invention tightly combines kernel driver parameters and system security status. By learning the range of changes in kernel driver parameters when the system is in a safe state, it can quickly detect and issue a warning after the parameter values are abnormal. The present invention also takes into account the differences between kernel drivers and the precise feature information of kernel drivers, can quickly judge the security status of the system, and dynamically and continuously evaluate the security status of the system more comprehensively and with a wider coverage.

[0013] The specific implementation process of step 1) includes:

[0014] 1.4) Preprocess the Linux kernel source code file to generate an LLVM IR file;

[0015] 1.5) Use the LLVM IR file to identify all top-level driver handlers and the associated driver names;

[0016] 1.6) Use the top-level driver handlers to find all driver function numbers; analyze all top-level driver handlers, find all paths to the copy_from_user, copy_to_user, get_user, and put_user functions, and identify all type information of the arg parameter.

[0017] In step 2), the feature information includes the driver name, top-level driver handler, driver function number, and arg parameter type; where the driver name is the unique identifier of the driver; the top-level driver handler is a function name; the driver function number is the specific function executed by the driver; the arg parameter type represents the data type copied during data copying between the user space and the kernel space.

[0018] In step 4), the specific implementation process of obtaining the kernel driver security checker includes:

[0019] S1. Randomly sample t times in parallel from the driver feature information dataset, collecting n samples each time to obtain a sampling set D containing n samples. t ;

[0020] S2. Construct t weak trainer models G t (x), and use the sampling set D containing n samples t as the sample training sets for the t weak trainer models respectively.

[0021] S3. Calculate the arithmetic mean of the results predicted by the t weak trainer models to obtain the final regression prediction result; this regression prediction result is the output of the kernel driver security checker.

[0022] To further improve the verification accuracy, it further includes:

[0023] S4. Determine whether the prediction result meets the accuracy requirement. If not, change the number t of weak trainers and return to step S1 to retrain the weak trainer models.

[0024] The specific implementation process of step 5) includes:

[0025] A) Modify the address of the called function in the Linux kernel system call table and save the original address;

[0026] B) Jump to the new function address. The new function is implemented to extract the parameter values of the ioctl() function at the current moment.

[0027] After the parameter extraction is completed, jump back to the original address.

[0028] As an inventive concept, the present invention also provides a terminal device, including a memory, a processor, and a computer program stored on the memory; the processor executes the computer program to implement the steps of the method of the present invention.

[0029] As an inventive concept, the present invention also provides a computer-readable storage medium, on which a computer program / instructions are stored; when the computer program / instructions are executed by a processor, the steps of the method of the present invention are implemented.

[0030] Compared with the prior art, the beneficial effects of the present invention are as follows: Based on the kernel driver and combined with the parallel learning of the Bagging algorithm, the present invention solves the problem that the system security verification is not comprehensive due to the large differences in data samples in the training set. The Bagging algorithm can weaken this difference to more comprehensively evaluate the system security status. By extracting the parameters of the ioctl() system call, the object of the system security verification is located on detecting the parameters of the ioctl() system call, and the feature information of the kernel driver is constructed through the parameters of the ioctl() system call, so as to accurately extract the common features between kernel drivers and integrate the security verification well into the model, enabling accurate system security detection and further judging the system security status. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 It is the diagram of the Bagging algorithm in the embodiment of the present invention;

[0032] Figure 2 It is the schematic diagram of the security verification of the kernel driver in the embodiment of the present invention;

[0033] Figure 3 It is the schematic diagram of the extraction of the kernel driver parameters in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0034] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0035] In this article, the terms "comprise", "include" and other similar words are intended to express a logical relationship and should not be regarded as expressing a spatial structure relationship. For example, "A includes B" is intended to mean that logically B belongs to A, rather than meaning that B is located inside A in terms of space. In addition, the meanings of the terms "comprise", "include" and other similar words should be regarded as open rather than closed. For example, "A includes B" is intended to mean that B belongs to A, but B does not necessarily constitute all of A, and A may also include other elements such as C, D, E, etc.

[0036] Embodiment 1

[0037] This embodiment provides a method for security verification of a kernel driver, including the following steps:

[0038] Step 1: Analyze the Linux kernel driver source code, extract the parameters of the ioctl() system call. The specific detailed steps are as follows:

[0039] 1.1) Preprocess the Linux kernel source code files. Specifically, use llvm to preprocess the kernel driver source code to generate LLVM IR.

[0040] 1.2) Use the IR file generated in step 1.1) to identify all top-level driver handlers and their associated driver names.

[0041] Specifically, to identify the top-level driver handler: ioctl() interacts with the driver and passes parameters to the corresponding driver handler. In the Linux built-in methods, there is a function pointer (struct type) pointing to the ioctl handler.

[0042] Identify the driver name mainly through the device file name registration functions: including character devices: alloc_chrdev_region; proc devices: proc_create, etc.

[0043] 1) Search for the store instructions in the.bc file, which store the address into a field in any structure in the Linux kernel built-in struct list.

[0044] 2) Check whether any registration function has a reference to the above struct.

[0045] 3) Analyze the parameter values of the device file name. If it is a constant, return it.

[0046] 1.3) Use the top-level driver handlers obtained in 1.2) as the entry point, and find all driver function numbers through path-sensitive analysis and data flow analysis.

[0047] 1.4) Analyze all top-level driver handlers in 1.2), find all paths to the copy_from_user, copy_to_user, get_user, and put_user functions, and identify all type information of the arg parameter.

[0048] Step 2: According to the kernel driver parameters extracted in Step 1, use the kernel driver parameters to extract the characteristic information of the driver program. The characteristic information includes: driver program name, top-level driver handler, driver function number, arg parameter. The format of the obtained characteristic information is as follows:

[0049] 1) Driver program name: cdrom, ndctl, tpm, ppp;

[0050] 2) Top-level driver processing function: ioctl_handler;

[0051] 3) Driver function numbers: 0X1001, 0X1002, 0X1003;

[0052] 4) Arg parameter types: uint32_t, uint8_t, DriverStructOne, DriverStructTwo;

[0053] Step 3: Construct the driver feature information vector matrix. Based on the feature information of various kernel drivers extracted in Step 2, use the feature information of different driver programs to construct a vector matrix; the feature information includes: driver program name (cdrom, ndctl, tpm, ppp), top-level driver handler (ioctl_handler), driver function number (0X1001, 0X1002, 0X1003), arg parameter (uint32_t, uint8_t, DriverStructOne, DriverStructTwo); among them, the driver program name is the unique identifier of the driver. There are about 50 Linux kernel drivers. Therefore, map the driver program name to an integer type according to the number of driver programs, and the range is 1-50. The top-level driver handler is bound to the driver program name one by one when registering the device. Therefore, map the top-level driver handler to an integer type, and the range is 1-50. The driver function number is a 32-bit binary number, and convert it to a decimal number. The number of common arg parameter types is fixed. Therefore, map the arg parameter type to an integer type, and the range is 1-100. During the actual kernel operation, there may be multiple driver function numbers passed by ioctl(), and there are also multiple arg parameter types passed. Therefore, take 4 different parameter values, and combine the driver program name, top-level driver handler, driver function number, and arg parameter type to extract 4 features to form a 4*4 feature vector matrix:

[0054]

[0055] Step 4: Based on the driver program feature information dataset in Steps 1-3, use the parallel Bagging algorithm for learning and construct a kernel driver security checker. The kernel driver security checker generated by learning based on the parallel Bagging algorithm is trained through the following process:

[0056] 1) The training set is the driver program feature information dataset obtained in the above Step 3. First, randomly sample t times in parallel from the dataset, and collect n samples each time to obtain a sampling set D containing n samples t ;

[0057] 2) Construct t weak trainer models Gt (x), use the sampling set D containing n samples t as the sample training set for the t-th weak trainer model respectively;

[0058] 3) Calculate the arithmetic mean of the results predicted by the t weak trainer models to obtain the final regression prediction result;

[0059] 4) Determine whether the prediction result meets the accuracy requirement. If not, change the number t of weak trainers and return to step 1) to retrain the weak trainer model;

[0060] In this embodiment, the weak trainer model uses a decision tree model, and the decision tree model uses the knn algorithm.

[0061] In this embodiment, calculate the accuracy rate of model training through the prediction result. If the accuracy rate reaches 0.90, it meets the requirement, otherwise retrain again.

[0062] Step 5: At any moment, hook the system call ioctl(), intercept the data stream and extract the parameter values of ioctl() at this moment, which specifically includes the following steps:

[0063] 1) Modify the address of the called function in the system call table and save the original address;

[0064] 2) Jump to the new function address. The new function is implemented to extract the parameter values of the ioctl() system call from the stack, mainly by tracking the change of the parameter values through the data stream and extracting the parameter values at this moment;

[0065] 3) After executing the new function, return to the original address;

[0066] Step 6: According to the parameter values generated in step 5, extract the feature information of the kernel driver at this moment and use it as the input of the kernel driver security checker in step 4. Compare the obtained result with the training result in step 4 statically to determine whether the kernel driver parameters have been maliciously modified at this moment, and further determine whether the system is in a safe state at this moment.

[0067] The method of kernel - driver - based security verification in this embodiment first analyzes the Linux kernel - driver source code, extracts the parameters of the ioctl() system call, uses the parameters to extract the characteristic information of the driver, constructs a driver - characteristic - information vector matrix based on the characteristic information of the kernel driver, and generates a data set. After processing the data set, it is input into the parallel Bagging algorithm for model training to obtain a kernel - driver security verifier. The hook technology is used to intercept the parameter values of the ioctl() system call at any moment, and after processing the parameter values, the characteristic information of the driver at this moment is obtained and input into the kernel - driver security verifier. The generated result is compared statically with the result obtained from model training, so as to judge whether the kernel - driver parameters are normal at this moment, and further judge whether the system is in a safe state.

[0068] Compared with the conventional system security detection methods, the embodiment of the present invention closely combines the kernel - driver parameters and the system security state. By learning the variation range of the kernel - driver parameters when the system is in a safe state, it can quickly detect and issue a warning after the parameter values are abnormal. The embodiment of the present invention also takes into account the differences between kernel drivers and the precise characteristic information of kernel drivers so as to quickly judge the security state of the system, and can perform a more comprehensive and wider - coverage dynamic continuous evaluation of the system security state.

[0069] Embodiment 2

[0070] Embodiment 2 of the present invention provides a terminal device corresponding to the above - mentioned Embodiment 1. The terminal device can be a processing device for a client, such as a mobile phone, a laptop computer, a tablet computer, a desktop computer, etc., to execute the method of the above - mentioned embodiment.

[0071] The terminal device in this embodiment includes a memory, a processor, and a computer program stored on the memory; the processor executes the computer program on the memory to implement the steps of the method in the above - mentioned Embodiment 1.

[0072] In some implementations, the memory can be a high - speed random - access memory (RAM: Random Access Memory), and may also include non - volatile memory, such as at least one disk memory.

[0073] In other implementations, the processor can be a central processing unit (CPU), a digital signal processor (DSP), or various types of general - purpose processors, which are not limited here.

[0074] Embodiment 3

[0075] Embodiment 3 of the present invention provides a computer-readable storage medium corresponding to Embodiment 1 above, on which computer programs / instructions are stored. When the computer programs / instructions are executed by a processor, the steps of the method in Embodiment 1 above are implemented.

[0076] A computer-readable storage medium may be a tangible device that retains and stores instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but is not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any combination of the above.

[0077] Those skilled in the art should understand that the embodiments of the present application may be provided as a method, a system, or a computer program product. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code. The solutions in the embodiments of the present application may be implemented in various computer languages. For example, object-oriented programming languages such as Java and interpreted scripting languages such as JavaScript.

[0078] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0079] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0080] Although the preferred embodiments of the present application have been described, additional changes and modifications can be made by those skilled in the art once they learn the basic creative concept. Therefore, the appended claims are intended to be interpreted to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present application.

[0081] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A kernel-driven security verification method, characterized in that, Including the following steps: 1) Extract the kernel driver parameters of the ioctl() system call in the Linux kernel driver source code; 2) Extract the characteristic information of the driver program by using the kernel driver parameters; 3) Construct a vector matrix by using the characteristic information of different driver programs; 4) Construct a driver program characteristic information data set by using the vector matrix, use the driver program characteristic information data set as the input of the Bagging algorithm, obtain a kernel driver security checker and the output of the kernel driver security checker; 5) Hook the system call ioctl(), intercept the data stream and extract the parameter values of ioctl() at this moment; 6) According to the parameter values generated in step 5), extract the characteristic information of the kernel driver and use it as the input of the kernel driver security checker, and statically compare the obtained result with the output of the kernel driver security checker in step 4) to determine whether the kernel driver parameters have been maliciously modified, and further determine whether the system is in a safe state at the current moment.

2. The security verification method for kernel driver according to claim 1, wherein The specific implementation process of step 1) includes: 1.1) Preprocess the Linux kernel source code file to generate an LLVM IR file; 1.2) Use the LLVM IR file to identify all top-level driver handlers and the associated driver names; 1.3) Use the top-level driver handlers to find all driver function numbers; analyze all top-level driver handlers to find all paths to the copy_from_user, copy_to_user, get_user, and put_user functions, and identify all type information of the arg parameter.

3. The security verification method of the kernel driver according to claim 1, characterized in that In step 2), the characteristic information includes the driver program name, the top-level driver handler, the driver function number, and the arg parameter type; Wherein the driver program name is the unique identifier of the driver; the top-level driver handler is a function name; the driver function number is the function specifically executed by the driver; the arg parameter type represents the data type copied during data copying between the user space and the kernel space.

4. The security verification method of the kernel driver according to claim 1, wherein In step 4), the specific implementation process of obtaining the kernel driver security checker includes: S1. Randomly sample t times in parallel from the driver feature information dataset, collecting n samples each time to obtain a sampling set D containing n samples t ; S2. Construct t weak trainer models G t (x), and use the sampling set D t containing n samples as the sample training sets of the t weak trainer models respectively; S3. Calculate the arithmetic mean of the results predicted by t weak trainer models to obtain the final regression prediction result; this regression prediction result is the output of the kernel driver security checker.

5. The security verification method of the kernel driver according to claim 4, wherein It further includes: S4. Determine whether the prediction result meets the accuracy requirement. If not, change the number t of weak trainers and return to step S1 to retrain the weak trainer model.

6. The security verification method of the kernel driver according to claim 1, characterized in that, The specific implementation process of step 5) includes: A) Modify the address of the calling function in the Linux kernel system call table and save the original address; B) Jump to the new function address. The new function is implemented to extract the parameter values of the ioctl() function at the current moment. After the parameter extraction is completed, jump back to the original address.

7. A terminal device, comprising a memory, a processor, and a computer program stored on the memory; characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 6.

8. A computer-readable storage medium having a computer program / instruction stored thereon; characterized in that, The computer program / instructions, when executed by the processor, implement the steps of the method according to any one of claims 1 to 6.