Verification Method and Device for Kernel Vulnerability Patches Based on Virtualization

Through the virtualization-based kernel vulnerability patch verification method, KVM virtualization technology and kernel vulnerability patch code information library are used to automatically verify patch availability and effectiveness, solving the problem of low efficiency in the operating system kernel vulnerability management and achieving efficient patch verification and iterative repair.

CN116305133BActive Publication Date: 2025-07-25NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211106239.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-09
Publication Date
2025-07-25
Estimated Expiration
2042-09-09

AI Technical Summary

Technical Problem

The operating system kernel vulnerability management is low efficiency and requires a lot of manual intervention. The existing technology has not been effectively solved.

Method used

Using a virtualization-based kernel vulnerability patch verification method, KVM virtualization technology is used to build the target operating system virtual machine environment, and through the kernel vulnerability patch code information library and vulnerability verification program, patch availability and effectiveness verification are automated, and combined with the patch iterative repair process to reduce manual intervention.

Benefits of technology

It realizes automation of operating system kernel vulnerability management, improves patch verification efficiency, reduces manual intervention process and time, and provides fast patch verification results and iterative repair methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116305133B_ABST
    Figure CN116305133B_ABST
Patent Text Reader

Abstract

This application discloses a method and apparatus for verifying kernel vulnerability patches based on virtualization. The automated operating system kernel vulnerability patch automatic repair and verification framework of this application divides the patch repair verification process into three parts: patch availability verification, patch effectiveness verification, and iterative return of patch verification results. Based on the KVM virtualization technology, it supports the repair and verification control of kernel vulnerability patches, can automatically and quickly execute the patch verification process by specifying the kernel version and patch set, and returns the effectiveness verification report of the kernel patch through the vulnerability verification program and kernel error log. The greatest feature of this method is that it is not limited to the integrity and effectiveness of kernel patches, and at the same time has a kernel patch error recovery mechanism, which can cycle through the verification of multiple kernel patch sets, avoiding the manual intervention process and improving the patch verification efficiency. This application solves the technical problem of low efficiency in operating system kernel vulnerability management in related technologies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computers, and in particular, to a method and device for verifying kernel vulnerability patches based on virtualization. Background Art

[0002] The operating system is the cornerstone of the information system, and its security is of crucial importance. In recent years, with the wide application of domestic operating systems in key domestic fields, it is urgent to further improve the security of domestic operating systems and solve the security hazards therein, including the problem of operating system kernel vulnerabilities.

[0003] The operating system kernel is the most important part of the operating system, with a high privilege level and carrying the core functions of the system. After decades of development, although the overall architecture and functions of the operating system kernel have not changed significantly, the details are cumbersome, the code volume is huge, the system scale far exceeds that of general software, and various code vulnerabilities emerge in an endless stream, almost all of which deeply affect system security and endanger the entire software ecosystem.

[0004] The threshold for repairing operating system kernel vulnerabilities is high, and improving the localization and repair efficiency of kernel defects is a current research hotspot. Some classic literature in software engineering shows that software maintenance accounts for more than 90% of software costs, and 35.6% of the activities in software maintenance are for defect repair. A report from a certain university even estimates that the cost of defect repair in modern software development reaches 50%. Software defects or vulnerabilities are inevitable in system development, and their causes can be traced back to all stages of development. Whether in the industrial or academic research fields, locating and repairing program vulnerabilities are the core issues of software engineering. With the improvement of development and debugging technologies, automated vulnerability localization technologies have been studied and developed to a certain extent, but efficient methods for repairing vulnerabilities are still in their infancy. Since kernel automatic repair and patch generation involve a huge amount of code and high complexity, although many researchers and institutions are actively involved, the achievements are not many, the available reference materials are limited, and the work available for repair is even fewer. How to develop a kernel automatic repair tool is a task of great significance but extremely challenging.

[0005] Domestic operating systems represented by the Galaxy Kylin operating system mostly use the Linux kernel as the basis and have established their own kernel code maintenance systems, including the operating system kernel CVE vulnerability library and the operating system patch library, etc., providing basic support for the automated repair of operating system kernel vulnerabilities. However, the current management of operating system kernel vulnerabilities still requires a large amount of manual intervention, resulting in low management efficiency.

[0006] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention

[0007] The embodiments of the present application provide a method and apparatus for verifying kernel vulnerability patches based on virtualization, so as to at least solve the technical problem of low efficiency in operating system kernel vulnerability management in the related art.

[0008] According to one aspect of the embodiments of the present application, a method for verifying kernel vulnerability patches based on virtualization is provided, including the following steps: S1, constructing an operating system kernel vulnerability patch code information library, collecting operating system kernel vulnerability information and its patches, including kernel version, vulnerability number, vulnerability description, vulnerability verification program, vulnerability patch set, etc., and establishing a complete kernel vulnerability patch code information library; S2, constructing an operating system kernel vulnerability patch verification environment virtual machine, based on the KVM virtualization technology of Linux, constructing a target operating system virtual machine environment according to the operating system kernel version, and providing a basic environment for the loop verification of kernel vulnerability patches; S3, verifying the availability of operating system kernel vulnerability patches, based on the Linux kernel source code tree, dynamically allocating resources for patch availability verification through vulnerability information and patch set information; S4, verifying the effectiveness of operating system kernel vulnerability patches, generating a patch effectiveness verification script according to the patch availability verification result generated in step S3 and vulnerability information, and dynamically injecting the virtualization verification environment generated in step S2 for kernel vulnerability patch effectiveness verification; S5, iteratively repairing the operating system kernel vulnerability patches based on virtualization, using the out-of-band monitoring mechanism of the virtual machine to obtain the verification result of the kernel vulnerability patch repair, and iteratively repairing the kernel vulnerability patch according to the verification result; S6, ending the operating system kernel vulnerability patch verification process, completing the repair of the operating system kernel vulnerability, and generating and outputting a repair report.

[0009] Optionally, the system framework of the present application consists of an operating system kernel vulnerability patch code information library construction module, an operating system kernel vulnerability patch availability verification module, an operating system kernel vulnerability patch effectiveness verification module, and a patch verification result iteration control module; the operating system kernel vulnerability patch code information library construction module can build a vulnerability patch library locally by collecting CVE patch information and crash patch information, and pulling the latest kernel source tree, and can generate a vulnerability patch set according to the kernel error output information, including kernel version, error type, kernel crash stack backtrace, error source code location, etc.; the operating system kernel vulnerability patch availability verification module can perform patch operations on the kernel code according to the vulnerability information, and automatically complete kernel parameter configuration and kernel compilation operations to verify whether the corresponding kernel vulnerability patch is available; the operating system kernel vulnerability patch effectiveness verification module can automatically control the patched kernel to restart, and collect relevant operating system kernel on-site information after restart. If the restart is successful, it will further automatically call the vulnerability verification program corresponding to the vulnerability to verify whether the vulnerability patch takes effect; the patch verification result iteration control module controls the iterative testing and verification process of the entire operating system kernel vulnerability patch according to the feedback results of the availability verification and effectiveness verification of the operating system kernel vulnerability patch, and can control other modules to automatically screen out available operating system kernel vulnerability patches from the vulnerability patch set.

[0010] Optionally, the detailed steps of step S1 include: S1.1, receiving the operating system kernel vulnerability patch code information library construction operation from the administrator; S1.2, the operating system kernel vulnerability patch code information library construction module pulls the latest kernel source tree according to the required operating system kernel version, and collects operating system kernel vulnerability information and its patches, including kernel version, vulnerability number, vulnerability description, CVE patch, crash patch information, etc., to form a basic kernel vulnerability patch library; S1.3, the operating system kernel vulnerability patch code information library construction module can generate a vulnerability patch set according to the kernel error output information for the vulnerabilities in the vulnerability patch library, and at the same time collect vulnerability verification programs, etc., to establish a complete kernel vulnerability patch code information library.

[0011] Optionally, the detailed steps of step S2 include: S2.1, reading the operating system kernel vulnerability information collected in step S1.2, and extracting the kernel version number; S2.2, decompressing the pure version of the Linux kernel source code, switching the kernel source code tree to the kernel version where the vulnerability is located, dynamically allocating machine resources for kernel compilation according to the default kernel source code compilation parameters, and generating a pure kernel image containing the vulnerability; S2.3, obtaining the pure kernel image containing the vulnerability generated in step S2.2, starting the Qemu client to build a target operating system virtual environment according to the initially configured virtual machine construction parameters and the default rootfs system; S2.4, injecting a kernel vulnerability verification program and a client component of an operating system kernel patch effectiveness verification module into the target operating system virtual environment.

[0012] Optionally, the detailed steps of step S3 include: S3.1, reading the kernel vulnerability patch code information library generated in step S1.3, sequentially reading the patches and applying the patches to the Linux kernel source code version in step S2.2 to generate patch application result information; S3.2, dynamically allocating machine resources for kernel compilation according to the default kernel source code compilation parameters, and generating a patched kernel image; S3.3, collecting the corresponding compilation results and kernel images, confirming that the patch is available if the compilation is successful, confirming that the patch is unavailable if the compilation fails, and collecting the compilation failure result information.

[0013] Optionally, the detailed steps of step S4 include: S4.1, controlling the client component in the target operating system virtual environment generated in step S2.4 through the control end component of the operating system kernel patch validity verification module, starting the kernel vulnerability verification program, and collecting the kernel information of the vulnerability trigger scene; S4.2, injecting the kernel image of the corresponding patch collected in step S3.2 into the target operating system virtual environment generated in step S2.3 through the control end component of the operating system kernel patch validity verification module; S4.3, controlling the client component in the target operating system virtual environment generated in step S2.4 through the control end component of the operating system kernel patch validity verification module, starting the kernel installation process, and collecting the kernel installation result and returning it to the control end component; S4.4, controlling the client component in the target operating system virtual environment generated in step S2.4 through the control end component of the operating system kernel patch validity verification module, starting the system restart process, detecting whether the virtual verification environment starts normally through the control end component, and collecting the start result; S4.5, controlling the client component in the target operating system virtual environment generated in step S2.4 through the control end component of the operating system kernel patch validity verification module, starting the kernel vulnerability verification program, collecting the verification program result and kernel information, and transmitting them to the control end component; S4.6, automatically judging whether the patch effectively repairs the vulnerability and whether it triggers a kernel crash by collecting the kernel scene information and verification program result generated in step S4.1 and step S4.5 through the control end component of the operating system kernel patch validity verification module; S4.7, if the result of step S4.6 determines that the patch is invalid, returning the patch repair result to step S5 and starting the iterative repair process; S4.8, if the result of step S4.6 determines that the patch is valid, generating a repair report of the patch repair result and returning it to step S6, ending the repair process, and entering the report generation process.

[0014] Optionally, the detailed steps of step S5 include: S5.1, receiving the operation of verifying the operating system kernel vulnerability patch by the administrator; S5.2, based on the virtualization-based operating system kernel vulnerability patch iterative repair module, reading the relevant kernel vulnerability patch set in the kernel vulnerability patch code information library according to the operating system kernel vulnerability to be patched; S5.3, based on the virtualization-based operating system kernel vulnerability patch iterative repair module, building a virtual machine for vulnerability patch verification according to the operating system kernel version; S5.4, based on the virtualization-based operating system kernel vulnerability patch iterative repair module, calling the kernel vulnerability availability verification module to complete the availability verification for a specific kernel vulnerability patch; S5.5, based on the virtualization-based operating system kernel vulnerability patch iterative repair module, calling the kernel vulnerability effectiveness verification module to complete the effectiveness verification for a specific kernel vulnerability patch in the built virtual machine; S5.6, based on the virtualization-based operating system kernel vulnerability patch iterative repair module, obtaining the result of the kernel vulnerability patch effectiveness verification through the out-of-band monitoring mechanism of the virtual machine provided by KVM, and automatically iteratively controlling steps S5.4 and S5.5 to complete the iterative repair verification for a specific kernel vulnerability patch set; S5.6, based on the virtualization-based operating system kernel vulnerability patch iterative repair module, completing the iterative verification process of the kernel vulnerability patch set for the operating system kernel vulnerability to be patched; The detailed steps of step S6 include: S6.1, collecting the patch availability and patch effectiveness verification results of steps S5.3 and S5.5; S6.2, repairing the vulnerabilities with the effective patches according to the determination result and generating and returning an effectiveness repair report; S6.3, generating corresponding error logs for the invalid repair patches and unavailable patches according to the determination result and returning the patch and vulnerability reports.

[0015] According to another aspect of the embodiments of the present application, there is also provided an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor executes the above method through the computer program.

[0016] According to one aspect of the present application, there is provided a computer program product or a computer program, the computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the steps of any one of the above methods.

[0017] Compared with the related art, the present application has the following advantages:

[0018] 1) Closely combined with the characteristics of the Linux operating system, through the open-source kernel source code tree and multi-party open vulnerability disclosure platforms, a large number of kernel vulnerability information and related vulnerability verification codes are collected. By sorting out the details information fields of kernel vulnerabilities, a complete kernel vulnerability database is established. Through this database, kernel vulnerability information can be described quickly and accurately, avoiding defects such as complex kernel vulnerability classification, scattered data, and diverse descriptions, creating a convenient and effective pre-information environment for the collection and generation of patch sets corresponding to vulnerabilities; 2) For the operating system kernel patch repair and verification process, the complex repair and verification process is disassembled into three stages: virtualization-based initial environment construction, patch availability verification, and patch effectiveness verification. Through the virtualization technology based on KVM and the control-end - client components of this system, the kernel construction and verification processes that require a large amount of manual work are automatically controlled, and parallel processing is achieved through KVM virtualization technology, greatly reducing the process and time of manual intervention. A large number of patch sets can be verified quickly and the verification results can be returned, providing a large amount of effective reference information for subsequent patch modification, and providing an effective verification method and environment for the further research of the operating system kernel patch automatic generation technology.

[0019] In addition to the purposes, features, and advantages described above, the present invention has other purposes, features, and advantages. The present invention will be further described in detail below with reference to the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The accompanying drawings forming a part of this specification are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0021] Figure 1 is a flowchart of an optional virtualization-based verification method for kernel vulnerability patches according to an embodiment of the present application;

[0022] Figure 2 is a schematic diagram of a virtualization-based automatic verification system for operating system kernel vulnerability patches according to an embodiment of the present application;

[0023] Figure 3 is a schematic diagram of the working principle of a virtualization-based automatic verification method for operating system kernel vulnerability patches according to an embodiment of the present application;

[0024] Figure 4 is a schematic diagram of an optional virtualization-based verification device for kernel vulnerability patches according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0026] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0027] According to one aspect of the embodiments of this application, this application provides a method for verifying a kernel vulnerability patch based on virtualization. The method for verifying a kernel vulnerability patch based on virtualization in the embodiments of this application can be executed by a server or a terminal. Figure 1 is a flowchart of an optional method for verifying a kernel vulnerability patch based on virtualization according to the embodiments of this application. As Figure 1 shown, the method may include the following steps:

[0028] Step S1, using the kernel vulnerability information of the operating system and the corresponding kernel vulnerability patch, construct an operating system kernel vulnerability patch code information library. The operating system kernel vulnerability patch code information library includes the operating system kernel version, vulnerability number, vulnerability description, vulnerability verification program, and vulnerability patch set (the vulnerability patch set refers to a set of patches for a specific vulnerability. In the following text, the vulnerability patch library is a database of all vulnerabilities).

[0029] Step S2, based on the KVM virtualization technology of Linux, construct a target operating system virtual machine environment according to the operating system kernel version. Among them, the target operating system virtual machine environment is used to provide a basic environment for the loop verification of the kernel vulnerability patch.

[0030] Step S3, according to the Linux kernel source code tree, through the kernel vulnerability information and the vulnerability patch set, dynamically allocate resources for kernel compilation to verify the availability of the patch, and obtain the patch availability verification result.

[0031] Step S4: According to the patch availability verification result and the kernel vulnerability information, extract the verification data set composed of the kernel available image and the vulnerability verification program, inject the verification data set into the target operating system virtual machine environment, and perform the effectiveness verification of the kernel vulnerability patch.

[0032] Step S5: Use the virtual machine out-of-band monitoring mechanism of the target operating system virtual machine environment to obtain the verification result of the kernel vulnerability patch repair, and perform iterative repair of the kernel vulnerability patch according to the verification result.

[0033] Step S6: After completing the repair of the kernel vulnerability of the operating system, generate and output a repair report.

[0034] In the technical solution of the present application, in order to improve the automation ability of the operating system kernel vulnerability management, a complete set of automated patch automatic repair and verification framework is designed, which can quickly perform the automated patch verification process through the given kernel version and patch set, reduce the manual intervention process, and can solve the technical problem of low efficiency in the operating system kernel vulnerability management in the related technology, and improve the patch verification efficiency.

[0035] In the technical solution of the present application, in order to improve the automation degree of the operating system kernel vulnerability management, the complicated repair verification process is disassembled into three main stages: virtualization-based initial environment construction, patch availability verification, and patch effectiveness verification. And through the KVM-based virtualization technology and the control end (i.e., the client component) of the system, the kernel construction and verification processes that require a large amount of manual work are automatically controlled, and parallel processing is achieved through the KVM virtualization technology, avoiding the process and time of manual intervention. The following is described in detail in combination with Figure 1 the steps shown:

[0036] In an optional implementation manner of step S1, it includes the following steps S11 to S13:

[0037] Step S11: Detect the build operation triggered by the administrator in the background management system. The administrator indicates to build the operating system kernel vulnerability patch code information library through the build operation.

[0038] Step S12: Pull the latest Linux kernel source tree according to the required operating system kernel version, and collect the kernel vulnerability information of the operating system and the corresponding kernel vulnerability patches.

[0039] Step S13: For the kernel vulnerabilities in the vulnerability patch library, generate a vulnerability patch set according to the kernel error output information, and at the same time collect the vulnerability verification program to establish a complete operating system kernel vulnerability patch code information library.

[0040] Collect the kernel vulnerability information of the operating system and its patches (i.e., the corresponding kernel vulnerability patches) to build a kernel vulnerability patch code information library for the operating system kernel. The library includes kernel vulnerability information such as kernel version, vulnerability number, and vulnerability description, as well as vulnerability verification programs, vulnerability patch sets (including several kernel vulnerability patches), etc. For the established complete kernel vulnerability patch code information library (i.e., the operating system kernel vulnerability patch code information library), the information fields of each vulnerability description can be standardized and unified.

[0041] In this solution, closely combined with the characteristics of the Linux operating system, through the open-source kernel source code tree and a multi-party open vulnerability disclosure platform, a large number of kernel vulnerability information and related vulnerability verification codes are collected. By sorting out the detailed information fields of kernel vulnerabilities, a complete kernel vulnerability database is established. Through this database, kernel vulnerability information can be quickly and accurately described, avoiding defects such as complex kernel vulnerability classification, scattered data, and diverse descriptions, creating a convenient and effective pre-information environment for the collection and generation of patch sets corresponding to vulnerabilities.

[0042] In an optional implementation manner of step S2, to implement the construction of the initial environment based on virtualization, the steps S21 to S24 included in step S2 can be executed:

[0043] KVM virtualization has two core modules: one is the KVM kernel module, mainly including the KVM virtualization core module KVM.ko, and the hardware-related KVM_intel or KVM_AMD module, which is responsible for CPU and memory virtualization, including VM creation, memory allocation and management, vCPU execution mode switching, etc.; the other is QEMU device emulation, which realizes IO virtualization and emulation of various devices (disk, network card, graphics card, sound card, etc.), and interacts with the KVM kernel through the IOCTL system call. KVM only supports hardware-assisted virtualization (such as Intel-VT and AMD-V). When the kernel is loaded, KVM first initializes its internal data structures, opens the virtualization mode switch in the CPU control register CR4, executes the VMXON instruction to set the Host OS to the root mode, and creates a special device file / dev / kvm to wait for commands from the user space. Then, the KVM kernel and QEMU cooperate with each other to manage the VM. KVM will reuse some capabilities of the Linux kernel, such as process management scheduling, device drivers, memory management, etc.

[0044] Step S21, read the collected kernel vulnerability information of the operating system and extract the kernel version of the operating system.

[0045] Step S22: Decompress the pure version of the Linux kernel source code, switch the kernel version in the kernel source tree to the operating system kernel version where the kernel vulnerability lies, and dynamically allocate machine resources for kernel compilation according to the default kernel source code compilation parameters to generate a pure kernel image containing the kernel vulnerability.

[0046] Step S23: Use the pure kernel image to construct the target operating system virtual machine environment by starting the Qemu client based on the initially configured virtual machine construction parameters and the default rootfs system.

[0047] Step S24: Inject the vulnerability verification program for the kernel vulnerability and the client component for validating the effectiveness of the operating system kernel patch into the target operating system virtual machine environment.

[0048] In this solution, the original kernel image containing vulnerabilities, the kernel images patched with various versions, and the default rootfs system generated previously can be collected. Read the default Qemu virtual machine startup parameters to construct a virtual machine startup script; read the system hardware resources, construct the virtual machine by dynamically allocating resources, and inject the vulnerability verification program, the kernel image, and the client component of the operating system kernel patch effectiveness verification module through SSH (Secure Shell, an application-layer-based security protocol designed to provide security for remote login sessions and other network services) remote commands.

[0049] In an optional implementation manner of step S3, to implement patch availability verification, steps S31 to S33 included in step S3 can be executed:

[0050] Step S31: Read the constructed operating system kernel vulnerability patch code information library, sequentially read the kernel vulnerability patches in the vulnerability patch set, and apply the kernel vulnerability patches to the operating system kernel version where the kernel vulnerability lies to generate patch application result information.

[0051] Step S32: Dynamically allocate machine resources for kernel compilation according to the default kernel source code compilation parameters to generate a patched kernel image.

[0052] Step S33: Collect the corresponding compilation results and the patched kernel image. If the compilation is successful, confirm that the corresponding kernel vulnerability patch is available; if the compilation fails, confirm that the corresponding kernel vulnerability patch is unavailable, and collect the compilation failure result information to obtain the patch availability verification result.

[0053] One of several kernel vulnerabilities can be selected as the kernel vulnerability to be verified for kernel patch availability verification: First, decompress the open-source Linux kernel source tree, and switch the kernel source tree to the corresponding kernel version according to the kernel version number corresponding to the vulnerability in the vulnerability input information (i.e., the version corresponding to the above kernel version number). Read the default kernel source code compilation parameters and the system hardware resource information; Dynamically allocate resources to compile the kernel source code with the vulnerability and monitor the compilation results; Apply the patches included in the potential patch set corresponding to the vulnerability to the kernel source tree respectively; Read the default kernel source code compilation parameters and the system hardware resource information; Dynamically allocate system resources to compile the kernel of the corresponding patch source tree and monitor the compilation results. Generally speaking, the compilation results are divided into two cases: compilation error or compilation success. If a compilation error occurs, it means that the patch is not available for the kernel source code of this version; If the compilation is successful, it means that the patch is available.

[0054] In an implementation of an optional step S4, to achieve effectiveness verification, steps S41 to S48 included in step S4 can be executed:

[0055] Step S41, start the client component in the target operating system virtual machine environment to execute the vulnerability verification program and collect the kernel information at the vulnerability trigger site.

[0056] For example, first run the client component of the operating system kernel patch effectiveness verification module through SSH remote commands, use the control end component of the operating system kernel patch effectiveness verification module to initiate a control instruction, the control end component first initiates a vulnerability site capture instruction, the client component will execute the vulnerability verification code, and collect the kernel messages at the vulnerability trigger site and return them.

[0057] Step S42, inject the patched kernel image into the target operating system virtual machine environment.

[0058] Step S43, execute the kernel installation process and return the collected kernel installation results to the control end.

[0059] Step S44, execute the system restart process, and detect whether the target operating system virtual machine environment starts normally through the control end and collect the start results.

[0060] The control - end component injects the corresponding patched kernel version image into the virtual machine, initiates the kernel image installation and restart instructions. The client - end component will execute the kernel installation and collect the installation error messages. If the installation is successful, it will return the client restart message and restart the machine. After receiving the return message, the control - end component enables the virtual machine survival detection function to detect the virtual machine restart progress in real - time. If it detects that the virtual machine has restarted successfully, it will run the client - end component of the operating system kernel patch validity verification module through SSH remote commands. If it fails to detect the successful restart of the virtual machine for a long time, it will directly delete the virtual machine and classify this patch as a failure to start after installation.

[0061] In step S45, execute the vulnerability verification program, collect the verification program results and kernel live information, and then transfer them to the control - end. The control - end component initiates a vulnerability live capture instruction. After receiving the instruction, the client executes the code of the vulnerability verification program and returns after collecting the kernel messages at the vulnerability trigger site.

[0062] In step S46, collect the kernel live information and verification program results, and automatically judge whether the kernel vulnerability patch effectively repairs the vulnerability and whether it triggers a kernel crash.

[0063] After receiving the message, the control - end stores and compares the two kernel messages, preliminarily judges whether this patch effectively repairs the vulnerability, and disk - stores all return values for manual verification.

[0064] In step S47, if the judgment result is that the kernel vulnerability patch is invalid, return the patch repair result and start the iterative repair process.

[0065] In step S48, if the judgment result is that the kernel vulnerability patch is valid, generate a repair report using the patch repair result and return it, ending the repair process so as to enter the report generation process.

[0066] In an alternative implementation of step S5, to achieve iterative verification, it can be realized through steps S51 to S57 included in step S5:

[0067] In step S51, detect the verification operation triggered by the administrator. The administrator verifies the kernel vulnerability patch of the operating system through the verification operation.

[0068] In step S52, according to the kernel vulnerability to be patched, read the relevant vulnerability patch set in the operating system kernel vulnerability patch code information library.

[0069] In step S53, build a virtual machine for vulnerability patch verification according to the operating system kernel version.

[0070] In step S54, perform the availability verification for the specified kernel vulnerability patch.

[0071] Step S55: Complete the validation of the effectiveness of the specified kernel vulnerability patch in the constructed virtual machine.

[0072] Step S56: Through the out-of-band monitoring mechanism of the virtual machine provided by KVM, obtain the validation result of the effectiveness of the kernel vulnerability patch, and automatically iterate the availability validation and effectiveness validation to complete the iterative repair validation for each kernel vulnerability patch in the vulnerability patch set.

[0073] Step S57: Complete the iterative verification process for the vulnerability patch set of the kernel vulnerability to be patched.

[0074] Execute the iterative repair process. Based on the patch repair result generated in step S4 above, return to step S1, find a new patch set according to the kernel crash information in the patch repair result, and iteratively execute step S2 to verify the availability of the new patch set. Then directly skip step S3 and execute step S4 to verify whether the kernel image generated by the new patch set in step S2 can pass the repair verification in the virtual machine verification environment in step S3. If the verification fails, continue to iterate step S5 until the system terminates or the verification result is returned.

[0075] In the technical solution of this application, for the operating system kernel patch repair verification process, the complicated repair verification process is disassembled into three stages: initial environment construction based on virtualization, patch availability verification, and patch effectiveness verification. Through the virtualization technology based on KVM and the control-end-client components of this system, the kernel construction and verification processes that require a large amount of manual work are automatically controlled, and parallel processing is achieved through the KVM virtualization technology, greatly reducing the process and time of manual intervention. It can quickly verify a large number of patch sets and return the verification results, providing a large amount of effective reference information for subsequent patch modification, and providing an effective verification method and environment for the further research of the operating system kernel patch automatic generation technology.

[0076] In an optional implementation manner of step S6, after completing the repair of the kernel vulnerability of the operating system, generate and output a repair report. If step S4 verifies that the repair is successful, output all the generated patch information, vulnerability information, and patch repair results as a more readable report; if step S4 verifies that the repair is not successful and the system is terminated manually or automatically, organize and present all the intermediate results, patch repair results, vulnerability details, etc.

[0077] After the kernel vulnerabilities of the operating system are fixed, a repair report is generated and output. If step S4 verifies that the repair is successful, all generated patch information, vulnerability information, and patch repair results are output as a report with strong readability; if step S4 verifies that the repair is not successful and the system is terminated manually or automatically, all intermediate results, patch repair results, vulnerability details, etc. are sorted out and presented.

[0078] Adopting the technical solution of this application, when an operator gives a vulnerability description file, the vulnerability information extraction module of the system control end component will extract the corresponding vulnerability information and patch set from the kernel vulnerability and patch code information library. Initialize the Linux kernel source tree through the virtual environment construction module, and compile and generate the original image as the verification environment image. Generate a virtual verification environment by injecting the vulnerability trigger program and the original image into the rootfs. Then the patch availability determination module will gradually apply each patch in the patch set to the original kernel source code, and automatically allocate system resources to compile the image. During the process, collect the compilation error information and determine whether the patch is available. Inject the generated patch image and the client component into the virtual verification environment through the communication control module, and start the client component. After the client component is started, it receives the control instructions from the control end, performs kernel upgrade installation and BootLoader setting work. If the installation fails, the error information is returned to the control end; if the installation is successful, the restart verification work will be carried out. After receiving the restart message, the control end component will detect the host liveness of the verification environment in real time. If it is found that the verification environment starts successfully, a vulnerability trigger instruction is sent to the client component. The client executes the vulnerability trigger program and collects the kernel crash message and returns it to the control end component. Finally, the patch effectiveness determination module in the control end component compares the kernel crash information and initially determines whether the patch can effectively repair the kernel vulnerability. If the patch is effective, all vulnerability information, patch information, and verification results are sorted out and reported and returned; if the patch is invalid, the patch information and kernel crash information are returned to the vulnerability information extraction module for a new round of patch set extraction and verification work, and so on, iterating in a loop until the effective patch verification passes or the system terminates.

[0079] The following will take the example of the Galaxy Kylin operating system to further elaborate in detail on the automatic verification method for the kernel vulnerability patches of the operating system based on virtualization in this application.

[0080] Such as Figure 2As shown in the figure, the operating system kernel patch automatic repair system framework is divided into three levels according to the main functions of the program: the control end component, the client component, and the kernel vulnerability and patch code information library. A complete communication control module is designed between the control end component and the client component, and information transmission and process control between components are carried out through this control module. The control end component of this system includes a vulnerability information extraction module, a virtual environment construction module, a patch availability determination module, a patch effectiveness determination module, and a communication control module. Among them, the vulnerability information extraction module interacts with the kernel vulnerability and patch code information library, and the communication control module interacts with the client component. The client component of this system includes a kernel installation and verification module, a vulnerability trigger module, a vulnerability crash information collection module, and a communication control module, where the communication control module interacts with the control end component.

[0081] In this embodiment, the kernel vulnerability and patch code information library is compiled from the publicly available kernel vulnerability information and patch code collections across the network, including a large number of known kernel vulnerabilities and patched kernel vulnerability patches. At the same time, according to the similarity of the vulnerability causes, the patch codes also have certain similar characteristics. Therefore, this library also collects a large number of variant patch codes of known patch codes, but these codes may not be available and effective. At the same time, the patch codes in this library may also come from manually modified or variant-generated codes based on multiple machine learning methods. Here, only the possible sources of the patch code sets are listed, which does not represent the availability and effectiveness of the patch set for a specific patch. This method and system focus on building an automated patch verification method and system through a hardware platform with virtualization technology, which can greatly reduce the manual operation content and improve the patch verification efficiency, providing an effective verification method and system for the research and application of the kernel vulnerability patch automatic generation technology.

[0082] As Figure 3 shown, the specific working principle process of this embodiment is as follows:

[0083] Step S1, the extraction of kernel vulnerability patch information is the starting step of this system, and its specific steps are as follows:

[0084] Step S1.1, according to the vulnerability information description template, a vulnerability description information file is given.

[0085] Step S1.2, the vulnerability information extraction module extracts valid information from this description file and selects a potential patch set from the given patch set code library.

[0086] Step S1.3, according to the kernel version number, vulnerability verification program in the vulnerability description information file, and the patch set extracted in step S1.2, a data set is generated and handed over to the virtual environment construction module.

[0087] Step S2, the virtual verification environment construction module is responsible for constructing the corresponding vulnerability verification environment. The specific steps are as follows:

[0088] Step S2.1, according to the kernel version number in the dataset given in step S1.3, switch the pure Linux kernel source code tree to the specified version code.

[0089] Step S2.2, read the system hardware resource information, and use the default kernel compilation parameters to reasonably plan the hardware resources for kernel compilation.

[0090] Step S2.3, monitor the kernel compilation result. If the compilation fails, collect and return the compilation error message and directly terminate the system; if the compilation is successful, build the generated pure kernel image, the default rootfs system, and the vulnerability verification program extracted in step S1.3 into an available verification virtual machine through the system Qemu-kvm function.

[0091] Step S3, perform the vulnerability trigger test process of the virtual verification environment through the communication control module of the control end component and the communication control module of the client component in the virtual verification environment, and perform data transmission. The specific steps are as follows:

[0092] Step S3.1, the control end issues a kernel vulnerability trigger instruction. After the client receives the instruction, execute the vulnerability trigger program through the vulnerability trigger module, and collect and process the kernel crash information through the vulnerability crash information collection module, and return it to the control end component.

[0093] Step S3.2, the control end component compares the collected and sorted kernel crash information of this vulnerability with the crash information in the given vulnerability description information file to determine whether this verification environment has this vulnerability.

[0094] Step S3.3, if the vulnerability trigger condition is not met, organize and report the kernel image, the vulnerability trigger program, and the kernel crash information to the user and terminate the program; if the vulnerability trigger condition is met, the patch availability verification process will be carried out.

[0095] Step S4, perform the patch availability verification work through the patch availability determination module of the control end component. The specific steps are as follows:

[0096] Step S4.1, extract the kernel patch set and the kernel version number in the dataset generated in step S1.3, and switch the pure Linux kernel source code tree to the specified version code.

[0097] Step S4.2, apply the patch code to the kernel source code of this version. If the patch addition fails, determine that the patch is unavailable, and at the same time collect the failure result and append it to the patch report; if the patch addition is successful, proceed to the next kernel compilation.

[0098] Step S4.3: Read the system hardware resource information, and use the default kernel compilation parameters to reasonably plan the hardware resources for compiling the patched kernel source code.

[0099] Step S4.4: Monitor the kernel compilation result. If the compilation fails, it is determined that the patch is unavailable, and the compilation error information is collected and attached to the patch report; if the compilation is successful, proceed to the next process of the patch validity verification process.

[0100] Step S5: Interact through the control end component and the client component of the virtual verification environment to perform the kernel patch validity verification process. The specific steps are as follows:

[0101] Step S5.1: The control end component transmits the kernel image successfully compiled in Step S4.4 to the virtual verification environment through the communication control module, and initiates a kernel installation and verification instruction.

[0102] Step S5.2: After receiving the instruction, the kernel installation and verification module of the client component in the virtual verification environment installs the received patched kernel image into the virtual verification system constructed in Step S2.3. After the installation is completed, modify the BootLoader settings to ensure that the system boots with the new patched kernel image after restart.

[0103] Step S5.3: The client component monitors the installation process throughout and collects and collates the results. After the installation is completed, initiate a restart instruction. At the same time, send a signal indicating that the installation is completed and the system is restarting to the control end component.

[0104] Step S5.4: After receiving the signal indicating that the installation is completed and the system is restarting sent by the client component, the control end component will enable the host liveness detection function to detect in real time whether the virtual verification environment has restarted successfully. If the virtual verification environment fails to start successfully within the timeout period, it is determined that the image generated by the patch is invalid and the startup fails, and proceed to the validity detection of the next patch; if it is detected that the virtual verification environment has started successfully, the control end component initiates a remote command to start the client component and issues a vulnerability trigger verification instruction.

[0105] Step S5.5: After receiving the vulnerability trigger verification instruction, the client component in the virtual verification environment will start the vulnerability trigger module, run the vulnerability trigger program, and at the same time collect and process the kernel crash information through the vulnerability crash information collection module, and return it to the control end component.

[0106] Step S5.6: After the control end component receives the kernel crash information, it compares the crash information with the crash information in the given vulnerability description information file to determine whether the patch effectively repairs the kernel vulnerability. If it is determined that the patch is ineffective, the effectiveness detection of the next patch is entered; if it is determined that the patch is effective, the vulnerability information, vulnerability trigger program, compilation report, and patch code are summarized to generate a final report and returned to the user for manual verification by the user.

[0107] Step S6: If all the patches in this batch are verified to be unavailable or ineffective, a repair report for all patches will be generated and returned to the user. At the same time, the kernel vulnerability description information and the patch set will be returned to the kernel vulnerability patch extraction module for it to extract a new round of patch sets for the next round of patch verification work. Such cyclic iteration is performed until the patch verification is effective or the system terminates.

[0108] In summary, this embodiment supports an automatic verification process for kernel vulnerability patches of a virtualization-based operating system. By providing the given vulnerability information and patch set, it will automatically perform tasks such as kernel patch selection, kernel compilation, virtual verification environment construction, kernel patch availability verification, and kernel patch effectiveness verification. This example can greatly reduce a large number of manual operations in traditional kernel patch verification. In theory, the patch repair and verification process is fully automated, and at the same time, a detailed repair verification report can be returned for the user to read. It provides great convenience for repairing operating system kernel vulnerabilities and also provides a reliable verification method and system for further research on kernel vulnerability patch automatic generation technology. Without a doubt, the automatic verification method and system supported by this embodiment are not limited to the Galaxy Kylin operating system and can also be applied to various other operating systems with virtualization technology, which will not be elaborated here.

[0109] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence because, according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0110] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which may be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present application.

[0111] According to another aspect of the embodiments of the present application, there is also provided a verification device for a kernel vulnerability patch based on virtualization for implementing the above verification method for a kernel vulnerability patch based on virtualization. Figure 4 It is a schematic diagram of an optional verification device for a kernel vulnerability patch based on virtualization according to an embodiment of the present application, as Figure 4 shown. The device may include:

[0112] A patch construction unit 41, configured to use the kernel vulnerability information of the operating system and the corresponding kernel vulnerability patch to construct an operating system kernel vulnerability patch code information library, where the operating system kernel vulnerability patch code information library includes an operating system kernel version, a vulnerability number, a vulnerability description, a vulnerability verification program, and a vulnerability patch set.

[0113] Optionally, the patch construction unit is further configured to: detect a construction operation triggered by an administrator, where the construction operation is used to indicate constructing the operating system kernel vulnerability patch code information library; pull the latest Linux kernel source tree according to the required operating system kernel version, collect the kernel vulnerability information of the operating system and the corresponding kernel vulnerability patch; for the kernel vulnerabilities in the vulnerability patch library, generate the vulnerability patch set according to the kernel error output information, and at the same time collect the vulnerability verification program to establish a complete operating system kernel vulnerability patch code information library.

[0114] An environment construction unit 42, configured to build a target operating system virtual machine environment based on the KVM virtualization technology of Linux according to the operating system kernel version, where the target operating system virtual machine environment is used to provide a basic environment for the loop verification of the kernel vulnerability patch.

[0115] Optionally, the environment construction unit is further configured to: read the kernel vulnerability information of the included operating system and extract the operating system kernel version; decompress the pure Linux kernel source code, switch the kernel version in the kernel source code tree to the operating system kernel version where the kernel vulnerability is located, dynamically allocate machine resources for kernel compilation according to the default kernel source code compilation parameters, and generate a pure kernel image containing the kernel vulnerability; use the pure kernel image to start the Qemu client to construct the target operating system virtual machine environment according to the initially configured virtual machine construction parameters and the default rootfs system; inject the vulnerability verification program of the kernel vulnerability and the client component for verifying the effectiveness of the operating system kernel patch into the target operating system virtual machine environment.

[0116] The availability verification unit 43 is configured to dynamically allocate resources for kernel compilation according to the Linux kernel source code tree, the kernel vulnerability information, and the vulnerability patch set to perform patch availability verification and obtain a patch availability verification result.

[0117] Optionally, the availability verification unit is further configured to: read the constructed operating system kernel vulnerability patch code information library, sequentially read the kernel vulnerability patches in the vulnerability patch set and apply the kernel vulnerability patches to the operating system kernel version where the kernel vulnerability is located to generate patch application result information; dynamically allocate machine resources for kernel compilation according to the default kernel source code compilation parameters to generate a patched kernel image; collect the corresponding compilation results and the patched kernel image, confirm that the corresponding kernel vulnerability patch is available if the compilation is successful, confirm that the corresponding kernel vulnerability patch is unavailable if the compilation fails, and collect the compilation failure result information to obtain the patch availability verification result.

[0118] The effectiveness verification unit 44 is configured to extract a verification data set composed of a kernel available image and a vulnerability verification program according to the patch availability verification result and the kernel vulnerability information, inject the verification data set into the target operating system virtual machine environment, and perform effectiveness verification of the kernel vulnerability patch.

[0119] Optionally, the validity verification unit is further configured to: start the client component in the target operating system virtual machine environment to execute the vulnerability verification program, and collect kernel information at the vulnerability trigger site; inject the patched kernel image into the target operating system virtual machine environment; execute the kernel installation process, and return the collected kernel installation result to the control end; execute the system restart process, and detect whether the target operating system virtual machine environment starts normally through the control end, and collect the startup result; execute the vulnerability verification program, and transfer the verification program result and kernel site information to the control end after collection; collect the kernel site information and the verification program result, and automatically determine whether the kernel vulnerability patch effectively repairs the vulnerability and whether it triggers a kernel crash; if the determination result is that the kernel vulnerability patch is invalid, return the patch repair result and start the iterative repair process; if the determination result is that the kernel vulnerability patch is valid, generate the repair report using the patch repair result and return it, ending the repair process so as to enter the report generation process.

[0120] The repair unit 45 is configured to obtain the verification result of the kernel vulnerability patch repair by using the out-of-band monitoring mechanism of the virtual machine in the target operating system virtual machine environment, and perform iterative repair of the kernel vulnerability patch according to the verification result.

[0121] Optionally, the repair unit is further configured to: during the process of obtaining the verification result of the kernel vulnerability patch repair by using the out-of-band monitoring mechanism of the virtual machine in the target operating system virtual machine environment and performing iterative repair of the kernel vulnerability patch according to the verification result, screen out the correct kernel vulnerability patch that can repair the kernel vulnerability from the corresponding vulnerability patch set through iterative repair testing, and provide the kernel developer with the detailed information of the kernel vulnerability and the repair report to help the kernel developer more quickly and conveniently repair the kernel vulnerability.

[0122] Optionally, the repair unit is further configured to: detect a verification operation triggered by an administrator, where the verification operation is used to verify the kernel vulnerability patch of the operating system; read the relevant vulnerability patch set in the operating system kernel vulnerability patch code information library according to the kernel vulnerability to be patched; build a virtual machine for vulnerability patch verification (i.e., the target operating system virtual machine environment) according to the operating system kernel version; perform availability verification on the specified kernel vulnerability patch; complete the validity verification of the specified kernel vulnerability patch in the built virtual machine; obtain the validity verification result of the kernel vulnerability patch through the out-of-band monitoring mechanism provided by KVM, and automatically iterate the availability verification and validity verification to complete the iterative repair verification of each kernel vulnerability patch in the vulnerability patch set; complete the iterative verification process of the vulnerability patch set for the kernel vulnerability to be patched.

[0123] A report output unit 46 is configured to generate and output a repair report after the repair of the kernel vulnerabilities of the operating system is completed.

[0124] Optionally, the report output unit is further configured to: collect the patch availability verification result and the effectiveness verification result of the kernel vulnerability patch; according to the patch availability verification result and the effectiveness verification result, use the kernel vulnerability patch with effective repair to perform vulnerability repair, and return the generated effectiveness repair report; according to the patch availability verification result and the effectiveness verification result, use the kernel vulnerability patch with ineffective repair and the unavailable kernel vulnerability patch to generate corresponding error logs, and return the patch and vulnerability report.

[0125] Using the technical solution of the present application, closely combined with the characteristics of the Linux operating system, through the open-source kernel source code tree and the multi-party open vulnerability disclosure platform, a large number of kernel vulnerability information and related vulnerability verification codes are collected. By sorting out the details of the kernel vulnerability information fields, a complete kernel vulnerability database is established. Through this database, the kernel vulnerability information can be described quickly and accurately, avoiding the defects of complex kernel vulnerability classification, scattered data, and diverse descriptions, creating a convenient and effective pre-information environment for the collection and generation of the patch set corresponding to the vulnerability; for the operating system kernel patch repair verification process, the complex repair verification process is disassembled into three stages: virtualization-based initial environment construction, patch availability verification, and patch effectiveness verification. Through the virtualization technology based on KVM and the control-end-client components of the system, the kernel construction and verification processes that require a large amount of manual work are automatically controlled, and parallel processing is achieved through the KVM virtualization technology, greatly reducing the process and time of manual intervention. A large number of patch sets can be quickly verified and the verification results can be returned, providing a large amount of effective reference information for subsequent patch modification, and providing an effective verification method and environment for the further research of the operating system kernel patch automatic generation technology.

[0126] It should be noted here that the examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules, as a part of the device, can run in the hardware environment as shown in Figure 1 and can be implemented by software or by hardware.

[0127] In the technical solution of the present application, in order to improve the automation ability of the operating system kernel vulnerability management, a complete set of automated patch automatic repair and verification framework is designed, which can quickly perform the automated patch verification process by specifying the kernel version and the patch set, reducing the manual intervention process, and can solve the technical problem of low efficiency of operating system kernel vulnerability management in the related technology, and improve the patch verification efficiency.

[0128] Optionally, the specific examples in this embodiment may refer to the examples described in the above embodiments, and will not be elaborated herein.

[0129] Optionally, in this embodiment, the above storage medium may include, but is not limited to: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.

[0130] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.

[0131] If the integrated unit in the above embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in the above computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing one or more computer devices (which may be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application.

[0132] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For the parts not elaborated in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0133] In the several embodiments provided by the present application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in electrical or other forms.

[0134] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0135] In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated units may be implemented in the form of hardware or in the form of software functional units.

[0136] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A verification method for kernel vulnerability patches based on virtualization, characterized in that, Including: Using the kernel vulnerability information of the operating system and the corresponding kernel vulnerability patches, constructing an operating system kernel vulnerability patch code information library, where the operating system kernel vulnerability patch code information library includes the operating system kernel version, vulnerability number, vulnerability description, vulnerability verification program, and a set of vulnerability patches, and the set of vulnerability patches includes multiple of the kernel vulnerability patches; Based on the KVM virtualization technology of Linux, constructing a target operating system virtual machine environment according to the operating system kernel version, where the target operating system virtual machine environment is used to provide a basic environment for the loop verification of the kernel vulnerability patches; According to the Linux kernel source tree, dynamically allocating resources for kernel compilation through the kernel vulnerability information and the set of vulnerability patches to perform patch availability verification and obtain a patch availability verification result; According to the patch availability verification result and the kernel vulnerability information, extracting a verification data set composed of a kernel available image and a vulnerability verification program, injecting the verification data set into the target operating system virtual machine environment, and performing effectiveness verification of the kernel vulnerability patches; Using the out-of-band monitoring mechanism of the virtual machine in the target operating system virtual machine environment to obtain the verification result of the repair of the kernel vulnerability patch, and performing iterative repair of the kernel vulnerability patch according to the verification result; After completing the repair of the kernel vulnerability of the operating system, generating and outputting a repair report.

2. The method according to claim 1, characterized in that, During the process of using the out-of-band monitoring mechanism of the virtual machine in the target operating system virtual machine environment to obtain the verification result of the repair of the kernel vulnerability patch and performing iterative repair of the kernel vulnerability patch according to the verification result, the method further includes: Through iterative repair testing, screening out the correct kernel vulnerability patches that can repair the kernel vulnerability from the corresponding set of vulnerability patches, and providing the kernel developer with the detailed information of the kernel vulnerability and the repair report to help the kernel developer more quickly and conveniently repair the kernel vulnerability.

3. The method according to claim 2, characterized in that The constructing of the operating system kernel vulnerability patch code information library using the kernel vulnerability information of the operating system and the corresponding kernel vulnerability patches includes: Detecting a construction operation triggered by an administrator, where the construction operation is used to indicate the construction of the operating system kernel vulnerability patch code information library; Pulling the latest Linux kernel source tree according to the required operating system kernel version, and collecting the kernel vulnerability information of the operating system and the corresponding kernel vulnerability patches; For the kernel vulnerabilities in the vulnerability patch library, generating the set of vulnerability patches according to the kernel error output information, and at the same time collecting the vulnerability verification program to establish a complete operating system kernel vulnerability patch code information library.

4. The method according to claim 3, wherein The constructing of the target operating system virtual machine environment based on the KVM virtualization technology of Linux according to the operating system kernel version includes: Reading the kernel vulnerability information of the included operating system and extracting the operating system kernel version; Unzip the pure version of the Linux kernel source code, switch the kernel version in the Linux kernel source code tree to the operating system kernel version where the kernel vulnerability is located, and dynamically allocate machine resources for kernel compilation according to the default kernel source code compilation parameters to generate a pure kernel image containing the kernel vulnerability; Use the pure kernel image to build the target operating system virtual machine environment by starting the Qemu client according to the initially configured virtual machine construction parameters and the default rootfs system; Inject the vulnerability verification program of the kernel vulnerability and the client component for validating the effectiveness of the operating system kernel patch into the target operating system virtual machine environment.

5. The method according to claim 4, wherein According to the Linux kernel source code tree, through the kernel vulnerability information and the vulnerability patch set, dynamically allocate resources for kernel compilation to perform patch availability verification, and obtain the patch availability verification result, including: Read the built operating system kernel vulnerability patch code information library, sequentially read the kernel vulnerability patches in the vulnerability patch set, and apply the kernel vulnerability patches to the operating system kernel version where the kernel vulnerability is located to generate patch application result information; Dynamically allocate machine resources for kernel compilation according to the default kernel source code compilation parameters to generate a patched kernel image; Collect the corresponding compilation results and the patched kernel image. If the compilation is successful, confirm that the corresponding kernel vulnerability patch is available. If the compilation fails, confirm that the corresponding kernel vulnerability patch is unavailable, and collect the compilation failure result information to obtain the patch availability verification result.

6. The method according to claim 5, wherein According to the patch availability verification result and the kernel vulnerability information, extract the verification data set composed of the kernel available image and the vulnerability verification program, inject the verification data set into the target operating system virtual machine environment, and perform the effectiveness verification of the kernel vulnerability patch, including: Start the client component in the target operating system virtual machine environment to execute the vulnerability verification program and collect the kernel information at the vulnerability trigger site; Inject the patched kernel image into the target operating system virtual machine environment; Execute the kernel installation process and return the collected kernel installation result to the control end; Execute the system restart process, and detect whether the target operating system virtual machine environment starts normally through the control end and record the start result; Execute the vulnerability verification program, collect the verification program result and the kernel site information, and then transfer them to the control end; Collect the kernel site information and the verification program result, and automatically judge whether the kernel vulnerability patch effectively repairs the vulnerability and whether it triggers a kernel crash; If the judgment result is that the kernel vulnerability patch is invalid, return the patch repair result and start the iterative repair process; If the judgment result is that the kernel vulnerability patch is effective, generate the repair report using the patch repair result and return it, ending the repair process so as to enter the report generation process.

7. The method according to claim 6, wherein The virtual machine out-of-band monitoring mechanism using the target operating system virtual machine environment obtains the verification result of the kernel vulnerability patch repair, and performs iterative repair of the kernel vulnerability patch according to the verification result, including: Detect a verification operation triggered by an administrator, where the verification operation is used to verify the kernel vulnerability patch of the operating system; According to the kernel vulnerability to be patched, read the relevant vulnerability patch set in the operating system kernel vulnerability patch code information library; Build a virtual machine for vulnerability patch verification according to the operating system kernel version; Perform availability verification for the specified kernel vulnerability patch; Complete the effectiveness verification for the specified kernel vulnerability patch in the built virtual machine; Through the virtual machine out-of-band monitoring mechanism provided by KVM, obtain the effectiveness verification result of the kernel vulnerability patch, and automatically iterate availability verification and effectiveness verification to complete the iterative repair verification for each kernel vulnerability patch in the vulnerability patch set; Complete the iterative verification process for the vulnerability patch set of the kernel vulnerability to be patched; After completing the repair of the kernel vulnerability of the operating system, generate and output a repair report, including: The patch availability verification result and the effectiveness verification result of the collected kernel vulnerability patches; According to the patch availability verification result and the effectiveness verification result, use the effectively repaired kernel vulnerability patch to repair the vulnerability, and return the generated effectiveness repair report; According to the patch availability verification result and the effectiveness verification result, generate corresponding error logs using the ineffectively repaired kernel vulnerability patches and the unavailable kernel vulnerability patches, and return the patch and vulnerability report.

8. A verification device for kernel vulnerability patches based on virtualization, characterized in that Including: A patch construction unit for constructing an operating system kernel vulnerability patch code information library using the kernel vulnerability information of the operating system and the corresponding kernel vulnerability patch. The operating system kernel vulnerability patch code information library includes the operating system kernel version, vulnerability number, vulnerability description, vulnerability verification program, and vulnerability patch set; An environment construction unit for building a target operating system virtual machine environment according to the operating system kernel version based on the KVM virtualization technology of Linux, where the target operating system virtual machine environment is used to provide a basic environment for the loop verification of the kernel vulnerability patch; An availability verification unit for dynamically allocating resources for kernel compilation through the kernel vulnerability information and the vulnerability patch set according to the Linux kernel source tree to perform patch availability verification and obtain a patch availability verification result; An effectiveness verification unit for extracting a verification data set composed of a kernel available image and a vulnerability verification program according to the patch availability verification result and the kernel vulnerability information, injecting the verification data set into the target operating system virtual machine environment, and performing effectiveness verification of the kernel vulnerability patch; A repair unit, configured to obtain a verification result of the kernel vulnerability patch repair by using a virtual machine out-of-band monitoring mechanism of the target operating system virtual machine environment, and perform iterative repair of the kernel vulnerability patch according to the verification result; A report output unit, configured to generate and output a repair report after completing the repair of the kernel vulnerability of the operating system.

9. A storage medium, characterized in that, The storage medium includes a stored program, wherein the program, when running, executes the method described in any one of claims 1 to 7 above.

10. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the method described in any one of claims 1 to 7 above through the computer program.

Citation Information

Patent Citations

  • Virtual machine static placement method oriented to embedded virtualization environment

    CN113282366A

  • Systems and methods for intrusion detection and prevention using software patching and honeypots

    US20210011985A1