A business line-based security protection method, system, device and storage medium

By deploying monitoring points and control register traceability access lines on terminal devices, the problem that traditional network security protection methods are unable to cope with complex threats is solved, achieving more efficient protection and data security.

CN119109627BActive Publication Date: 2025-11-18CHINA NAT OFFSHORE OIL CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411132649.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-19
Publication Date
2025-11-18
Estimated Expiration
2044-08-19

AI Technical Summary

Technical Problem

Traditional cybersecurity protection methods are insufficient to effectively deal with complex and diverse cyber threats, especially camouflage and bypass attacks, resulting in inadequate protection capabilities.

Method used

By deploying monitoring points on terminal devices, access information is obtained, the basic risks of access behavior are analyzed, and control registers are used to trace the access lines and generate protection commands to intercept the risk sources.

Benefits of technology

It has improved the protection capabilities of terminal devices, enhanced the identification and response to complex network threats, and ensured the security of sensitive information and business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119109627B_ABST
    Figure CN119109627B_ABST
Patent Text Reader

Abstract

The application relates to a business line-based security protection method, system, device and storage medium, and belongs to the technical field of network security. The method comprises the following steps: acquiring access information at a monitoring point, wherein the access information represents information required for accessing a monitored device; analyzing an access behavior corresponding to the access information, and determining a basic risk of the access behavior; tracing the access behavior according to the basic risk and the access information, determining an access line of the access behavior, and the access line comprises a relationship between processes and threads generated in the process of the access behavior, wherein the relationship between the processes and the threads is determined by a control register deployed on the monitored device; and determining a risk source of the access information and a protection instruction corresponding to the risk source according to the access line of the access behavior. The application has the effect of improving the network security protection capability of a terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of network security, and in particular to a security protection method, system, device and storage medium based on business lines. Background Technology

[0002] Cybersecurity has become increasingly important in today's society. With the continuous evolution of cyberattack methods, traditional manual cybersecurity protection faces a contradiction between "dynamic" security risks and "static" defense systems. Relying on traditional security products (such as WAF and IPS) for session interception cannot fundamentally and effectively control the source of risk, while relying on manual IP blocking methods struggles to guarantee security protection capabilities and blocking efficiency against automated attack scripts and unpredictable, continuous attacks.

[0003] As cybersecurity threats become increasingly complex and diverse, traditional protection methods are insufficient to meet cybersecurity needs. For example, current cyber threats utilize proxies to masquerade as legitimate visits. Therefore, improving cybersecurity protection capabilities is a pressing issue that needs to be addressed. Summary of the Invention

[0004] To improve network security protection capabilities, this application provides a security protection method, system, device, and storage medium based on business lines.

[0005] In a first aspect of this application, a security protection method based on business lines is provided. The method includes:

[0006] Access information is obtained at the monitoring point; the access information represents the information required to access the monitored device.

[0007] Analyze the access behavior corresponding to the access information to determine the underlying risks of the access behavior;

[0008] Based on the basic risks and access information, the access behavior is traced to determine the access path of the access behavior. The access path includes the relationship between processes and threads generated during the access behavior. The relationship between processes and threads is determined by the control registers deployed on the monitored device.

[0009] Based on the access path of the access behavior, identify the risk source of the access information and the corresponding protection instructions.

[0010] As can be seen from the above technical solution, by deploying monitoring points on the terminal device to obtain access information, the basic risks of the access behavior are determined based on the access behavior corresponding to the access information, the access behavior is traced back to obtain the access line based on the basic risks, and each node in the access line is obtained from the control register. The data has high authenticity, which lays the foundation for judging the risk source. Then, the risk source in the access line is obtained, and the corresponding protection command is generated to achieve protection of the terminal device and improve the protection capability.

[0011] In one possible implementation, the access behavior corresponding to the access information is analyzed to determine the underlying risks of the access behavior, including:

[0012] Obtain the access targets and access risk table for access behavior. The access risk table is used to reflect the risk of different access targets.

[0013] Based on the access target and access risk table, determine the basic risks of the access behavior. The basic risks are used to reflect the importance of the access target.

[0014] In one possible implementation, before tracing the access behavior based on the underlying risks and access information to determine the access route, the method further includes:

[0015] When the underlying risk is low, execute the access action;

[0016] When the underlying risk is medium or high, the access behavior is traced to determine the access route.

[0017] In one possible implementation, access behavior is traced based on underlying risks and access information to determine the access path, including:

[0018] Retrieve the initiating object and the historical behavior of the initiating object level by level. The initiating object represents a process or thread.

[0019] Determine if there is any access behavior in the history of the initiating object;

[0020] If not, then mark the initiating object as a risk;

[0021] The access route is determined based on the correspondence between the initiating object and the access behavior, as well as the risk marker.

[0022] In one possible implementation, based on the access path of the access behavior, the risk source of the access information and the corresponding protection instructions for the risk source are determined, including:

[0023] When a risk marker exists in the access line, the initiating object corresponding to the risk marker is regarded as the risk source;

[0024] Generate protection commands corresponding to the risk source. These commands are used to block access attempts and / or output alarm information.

[0025] In one possible implementation, the monitoring point is deployed in the EBPF program on the monitored device.

[0026] In one possible implementation, the control register is the CR3 register.

[0027] In a second aspect of this application, a business line-based security protection system is provided. The system includes:

[0028] The data acquisition module is used to acquire access information at the monitoring point. The access information represents the information required to access the monitored device.

[0029] The risk assessment module is used to analyze the access behavior corresponding to the access information and determine the basic risks of the access behavior.

[0030] The access route tracing module is used to trace access behavior based on basic risks and access information, determine the access route of the access behavior, and include the relationship between processes and threads generated during the access behavior. The relationship between processes and threads is determined by the control registers deployed on the monitored device.

[0031] The risk determination module is used to determine the risk source of the access information and the corresponding protection instructions based on the access path of the access behavior.

[0032] In a third aspect of this application, an electronic device is provided. The electronic device includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the program to implement the method described above.

[0033] In a fourth aspect of this application, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the method according to the first aspect of this application.

[0034] In summary, this application includes at least one beneficial technical effect:

[0035] Access information is obtained by deploying monitoring points on terminal devices. Based on the access behavior corresponding to the access information, the basic risks of the access behavior are determined. The access behavior is traced back to the source based on the basic risks to obtain the access line. Each node in the access line is obtained from the control register. The data has high authenticity, which lays the foundation for judging the risk source. Then, the risk source in the access line is obtained, and the corresponding protection command is generated to protect the terminal device and improve the protection capability. Attached Figure Description

[0036] Figure 1 This is a schematic diagram of the operating environment of the security protection method based on business lines provided in this application.

[0037] Figure 2 This is a flowchart illustrating the security protection method based on business lines provided in this application.

[0038] Figure 3 This is a schematic diagram of the security protection system based on business lines provided in this application.

[0039] Figure 4 This is a schematic diagram of the structure of the electronic device provided in this application.

[0040] In the diagram, 100 is the operating environment; 110 is the monitoring equipment; 120 is the monitored equipment; 201 is the data acquisition module; 202 is the risk assessment module; 203 is the access route tracing module; 204 is the risk determination module; 301 is the CPU; 302 is the ROM; 303 is the RAM; 304 is the I / O interface; 305 is the input section; 306 is the output section; 307 is the storage section; 308 is the communication section; 309 is the driver; and 310 is the removable media. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0042] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article, unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.

[0043] With the escalating threat of cybersecurity, advanced attack groups often employ camouflage, blinding, and bypass techniques to breach enterprise system defenses. These techniques include low-frequency brute-force attacks, white-program exploitation, encrypted communication, rootkits, low-level function calls, and embedded assembly language, which traditional single-point tools struggle to counter. Low-frequency brute-force attacks refer to attackers using low-frequency methods to penetrate and damage target systems, evading detection and defenses. Compared to traditional high-frequency attacks, low-frequency attacks are often more covert, time-consuming, and cause more severe damage to the victim. White-program exploitation refers to the attack technique where a Trojan horse uses a legitimate program to load itself. For example, importing fake certificates makes it unblockable by security software. A rootkit is a special type of malware that hides itself and specified files, processes, and network connections on its target. Rootkits achieve this by loading special drivers and modifying the system kernel. Protecting computers and computer networks from malware is a pressing issue that needs to be addressed.

[0044] The embodiments of this application will now be described in further detail with reference to the accompanying drawings.

[0045] Figure 1 This is a schematic diagram of the operating environment provided in this application. The operating environment 100 includes multiple terminal devices, which transmit data to each other via wireless or wired communication. To monitor abnormal behavior on the terminal devices and improve their protection capabilities against such behavior, a service-line-based security protection method is configured in any one of the terminal devices. The terminal device configured with this method is called the monitoring device 110, and the other devices are called the monitored devices 120. It should be understood that the monitoring device 110 can monitor not only the monitored devices 120 but also itself. To further illustrate the operation process of the service-line-based security protection method, this application provides an embodiment of a service-line-based security protection method. The main flow of the above method is described below.

[0046] like Figure 2 As shown:

[0047] Step S101: Obtain access information at the monitoring point.

[0048] Specifically, the aforementioned monitoring points are deployed in the eBPF program on any of the aforementioned terminal devices. These monitoring points are used to acquire access information for various accesses on the terminal devices. This access information represents the information required to access the monitored device 120, such as user ID, user password, user permissions, access object, and initiating object.

[0049] eBPF (extended Berkeley Packet Filter) is a technology that allows user-written programs to run within the Linux kernel without modifying kernel code or loading kernel modules. eBPF programs are written in C and compiled into object files, i.e., eBPF bytecode files, using Clang. Clang is a compiler that compiles eBPF programs. Then, an application needs to load the compiled eBPF bytecode into the kernel by calling Linux kernel system calls. During the loading process, the kernel verifies the eBPF program to ensure its safety.

[0050] By using eBPF, deep monitoring of terminal devices can be achieved. At the same time, eBPF is closer to the bottom layer, making it less susceptible to tampering and preventing malware from bypassing monitoring points, thus providing a foundation for the protection of terminal devices.

[0051] Step S102: Analyze the access behavior corresponding to the access information and determine the basic risks of the access behavior.

[0052] Specifically, the access targets and access risk tables for the aforementioned access behaviors are obtained, and the access risk tables are used to reflect the risk of different access targets; based on the access targets and the access risk tables, the basic risks of the aforementioned access behaviors are determined, and the basic risks are used to reflect the importance of the access targets.

[0053] The access risk table above includes the access object and its importance. The more important the access object, the higher the risk; conversely, the less important the access object, the lower the risk. This access risk table is set based on the actual value of the data on the terminal device. For example, if the access behavior is reading data A, then the access object is data A. However, if data A contains important information and can only be viewed by senior administrators, then the basic risk of this access behavior is high, because if data A is leaked or tampered with, the resulting losses would be significant. As another example, if the access behavior is modifying data B, then the access object is data B. However, if data B contains generally important information and can be modified by any company employee, then the basic risk of this access behavior is medium, because the losses caused by data B being leaked or tampered with are relatively controllable. For example, if the access behavior is to read C data, then the access object of the access behavior is C data. However, the content of C data is not important and anyone can view it. When a terminal device accesses or modifies C data, the basic risk of this access behavior is low risk because the loss caused by the leakage or tampering of C data is small or non-existent.

[0054] Step S103: Based on the basic risks and access information, trace the access behavior to determine the access route of the access behavior.

[0055] Specifically, the aforementioned access path includes the relationships between processes and threads generated during the aforementioned access behavior. These relationships are determined through control registers deployed on the monitored device 120. In the embodiments provided in this application, the control register is the CR3 register. Using the CR3 register has two advantages: firstly, the CR3 register contains the physical memory base address of the page directory table, allowing the determination of the creation relationship between processes and threads; secondly, the CR3 register is a low-level code, making it difficult to tamper with, resulting in higher data authenticity and providing a basis for tracing the source of access behavior.

[0056] When the basic risk is low, the access behavior will not be traced to its source to avoid excessive waste of computing resources due to risk monitoring. When the basic risk is medium or high, the initiating object and its historical behavior will be retrieved level by level. The initiating object represents the process or thread mentioned above. It is determined whether the access behavior exists in the historical behavior of the initiating object. If it does, the next higher-level initiating object is retrieved and the process continues. If no previous-level initiating object is found, it indicates that there is no risk source in the access path. If, during the process, an initiating object in the access path has not generated the access behavior, it indicates that the initiating object may be risky, and it is marked as risky. If it is impossible to determine whether the initiating object has generated the access behavior, the next higher-level initiating object is retrieved and the process continues. If it is determined that the initiating object has not generated the access behavior, it is marked as risky, forming an access path.

[0057] In the embodiments provided in this application, once a certain initiating object is marked as risky, it is not necessary to continue to judge the initiating object of the previous level. In other embodiments, the complete access path of the access behavior can be judged, which is not limited here.

[0058] In a specific example, terminal device A generates processes a1 and b1 to execute tasks. Process a1 then generates threads a11 and a12 to execute tasks, and process b1 generates threads b11 and b12 to execute tasks. Thread a11 accesses a first database, and thread b12 accesses a second database. When the accessed object is the first database, the basic risk is medium risk. It is necessary to determine whether thread a11, the initiating object of thread a11, has accessed the first database. If it has, then it is further determined whether process a1, the initiating object of thread a11, has accessed the first database. If not, process a1 is marked as risky, and the resulting access path is process a1 → thread a11 → first database, where process a1 includes the risk mark. When the accessed object is the second database, the basic risk is low risk, and it is not necessary to obtain the initiating object of the second database. In another implementation, after risk marking is performed on process a1, it can be further determined whether the initiating object terminal device A of process a1 has accessed the first database. If it has, the initiating object of terminal device A is determined. However, if the initiating object of terminal device A does not exist, the determination ends and the obtained access route is terminal device A → process a1 → thread a11 → first database.

[0059] Step S104: Based on the access path of the access behavior, determine the risk source of the access information and the corresponding protection instructions.

[0060] Specifically, when the aforementioned risk marker exists in the access line, the initiating object corresponding to the aforementioned risk marker is taken as the risk source; a protection instruction corresponding to the aforementioned risk source is generated, and the protection instruction is used to intercept the aforementioned access behavior and / or output alarm information.

[0061] This application establishes monitoring points in the underlying code to trace and assess access behavior, preventing malicious software from circumventing terminal device defense mechanisms through white-label exploits or low-frequency brute-force attacks. This enhances both the protection capabilities and data security of terminal devices. By monitoring and responding to network threats in real time, it reduces potential risks, maintains business continuity, and ensures the proper protection of sensitive information.

[0062] This application provides a security protection system based on business lines, referring to... Figure 3 The business line-based security protection system includes:

[0063] The data acquisition module 201 is used to acquire access information at the monitoring point. The access information represents the information required to access the monitored device 120.

[0064] Risk assessment module 202 is used to analyze access behavior corresponding to access information and determine the basic risks of access behavior;

[0065] Access route tracing module 203 is used to trace access behavior based on basic risks and access information, determine the access route of the access behavior, and include the relationship between processes and threads generated during the access behavior in the access route. The relationship between processes and threads is determined by the control register deployed on the monitored device 120.

[0066] The risk determination module 204 is used to determine the risk source of the access information and the corresponding protection instructions based on the access path of the access behavior.

[0067] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the described module can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0068] This application discloses an electronic device. (Refer to...) Figure 4 The electronic device includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 302 or programs loaded from storage section 307 into random access memory (RAM) 303. RAM 303 also stores various programs and data required for system operation. The CPU 301, ROM 302, and RAM 303 are interconnected via a bus. An input / output (I / O) interface 304 is also connected to the bus.

[0069] The following components are connected to I / O interface 304: an input section 305 including a keyboard, mouse, etc.; an output section 306 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 307 including a hard disk, etc.; and a communication section 308 including a network interface card such as a local area network (LAN) card, modem, etc. The communication section 308 performs communication processing via a network such as the Internet. A drive 309 is also connected to I / O interface 304 as needed. A removable medium 310, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 309 as needed so that computer programs read from it can be installed into storage section 307 as needed.

[0070] Specifically, according to embodiments of this application, the flowchart above refers to... Figure 2 The described process can be implemented as a computer software program. For example, embodiments of this application include a computer program product comprising a computer program carried on a machine-readable medium, the computer program containing program code for performing the methods shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network via communication section 308, and / or installed from removable medium 310. When the computer program is executed by central processing unit (CPU) 301, it performs the functions defined in the apparatus of this application.

[0071] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, radio frequency (RF), etc., or any suitable combination thereof.

[0072] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the foregoing application concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions claimed in this application.

Claims

1. A security protection method based on business lines, characterized in that, include: Access information is obtained at the monitoring point, and the access information represents the information required to access the monitored device. Analyze the access behavior corresponding to the access information to determine the underlying risks of the access behavior; The access action is performed when the underlying risk is low. When the underlying risk is medium or high risk, the access behavior is traced to determine the access route of the access behavior; Based on the underlying risks and access information, the access behavior is traced to determine the access path. The access path includes the relationship between processes and threads generated during the access behavior. The relationship between processes and threads is determined by a control register deployed on the monitored device, specifically the CR3 register. The process includes: acquiring the initiating object of the access behavior and the historical behavior of the initiating object step by step, where the initiating object represents the process or the thread; determining whether the access behavior exists in the historical behavior of the initiating object; if not, marking the initiating object with a risk; and determining the access path based on the correspondence between the initiating object and the access behavior, as well as the risk mark. When the risk marker exists in the access line, the initiating object corresponding to the risk marker is regarded as the risk source; Generate a protection instruction corresponding to the risk source, the protection instruction being used to intercept the access behavior and / or output alarm information.

2. The security protection method based on business lines according to claim 1, characterized in that, The analysis of the access information and the determination of the underlying risks of the access behavior include: Obtain the access object and access risk table of the access behavior, wherein the access risk table is used to reflect the risk of different access objects; Based on the access object and the access risk table, the basic risk of the access behavior is determined, and the basic risk is used to reflect the importance of the access object.

3. The security protection method based on business lines according to claim 1, characterized in that, The monitoring points are deployed in the EBPF program on the monitored device.

4. A security protection system based on business lines, characterized in that, include: The data acquisition module is used to acquire access information at the monitoring point, wherein the access information represents the information required to access the monitored device; The risk assessment module is used to analyze the access behavior corresponding to the access information and determine the basic risk of the access behavior. The access action is performed when the underlying risk is low. When the underlying risk is medium or high risk, the access behavior is traced to determine the access route of the access behavior; The access route tracing module is used to trace the access behavior based on the basic risk and the access information, and determine the access route of the access behavior. The access route includes the relationship between processes and threads generated during the access behavior. The relationship between processes and threads is determined by a control register deployed on the monitored device. The control register is the CR3 register. The module includes: acquiring the initiating object of the access behavior and the historical behavior of the initiating object step by step. The initiating object represents the process or the thread. It determines whether the access behavior exists in the historical behavior of the initiating object. If not, it marks the initiating object with a risk. It determines the access route based on the correspondence between the initiating object and the access behavior and the risk mark. The risk determination module is used to identify the initiating object corresponding to the risk mark as a risk source when the risk mark exists in the access line; generate a protection instruction corresponding to the risk source, and the protection instruction is used to intercept the access behavior and / or output alarm information.

5. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and executed as described in any one of claims 1 to 3.

6. A computer-readable storage medium, characterized in that, The computer program is stored that can be loaded by a processor and executed as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • RISCV memory access violation detection method and device based on hardware virtualization

    CN116340081A

  • Network attack tracing method and system based on flow monitoring

    CN116846659A

  • Network security risk prediction method and system based on user behavior analysis

    CN117675387A