Method for secure operation of an operating system

By dividing the operating system into multiple isolated subdomains and deploying Hfish honeypots and attack defense modules, the problem of secure operation of the operating system is solved, achieving high isolation and proactive defense, and improving security performance and defense efficiency.

CN119299186BActive Publication Date: 2026-04-28CHINA MOBILE INTERNET CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE INTERNET CO LTD
Filing Date
2024-10-14
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing operating systems are vulnerable to malicious attacks. Attackers can masquerade as normal communications to infiltrate servers, leading to data leaks and losses. There is a lack of effective security measures for operation.

Method used

The operating system is divided into multiple isolated subdomains. Hfish honeypots and attack defense modules are deployed in each subdomain. High-risk subdomains are identified through the network attack detection module, and defense strategies based on the HGSBAB model are executed.

Benefits of technology

It achieves high-level isolation and proactive defense of the operating system, effectively capturing and analyzing attack behaviors, improving security performance, reducing the scope of attack impact, and enhancing the effectiveness and speed of defense strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119299186B_ABST
    Figure CN119299186B_ABST
Patent Text Reader

Abstract

The application discloses a safe operation method of an operating system, comprising the following steps: collecting access traffic data of an Hfish honeypot in a sub-domain operating system, and sending the access traffic data to a network attack detection module; wherein the operating system comprises a plurality of mutually isolated sub-domain operating systems, and each of the sub-domain operating systems comprises the Hfish honeypot; the network attack detection module is used for detecting network attacks on the access traffic data; in the case that it is determined based on the network attack detection module that the access traffic data contains attack data, the sub-domain operating system is determined as a high-risk sub-domain operating system; and a defense action is performed based on a defense strategy in an attack defense module in the high-risk sub-domain operating system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method for secure operation of an operating system. Background Technology

[0002] With the rapid development of computer technology, the security of operating systems, as the core of computer systems, has received increasing attention. Servers with deployed operating systems often face malicious attacks from networks, and this trend is increasing year by year. As network attack and defense systems have evolved, more and more malicious attacks can disguise themselves as normal communication, access data or commands, bypass the firewalls set up by the operating system itself, infiltrate servers, disrupt server communication and functions, and leak important and private data of users and enterprises, causing irreparable losses to users and enterprises. Therefore, how to achieve the secure operation of operating systems is a technical problem that urgently needs to be solved in related technologies. Summary of the Invention

[0003] The purpose of this application is to provide a method for the secure operation of an operating system, thereby solving the technical problem of the inability to achieve secure operation of an operating system.

[0004] Firstly, a secure operation method for an operating system is provided, comprising: collecting access traffic data of an Hfish honeypot within a subdomain operating system and sending the access traffic data to a network attack detection module; wherein the operating system includes multiple mutually isolated subdomain operating systems, each subdomain operating system including the Hfish honeypot; the network attack detection module is used to perform network attack detection on the access traffic data; if the network attack detection module determines that the access traffic data contains attack data, the subdomain operating system is identified as a high-risk subdomain operating system; and defense actions are executed based on the defense strategy in the attack defense module within the high-risk subdomain operating system.

[0005] Secondly, an electronic device is provided, comprising: a data processing module for collecting access traffic data of an Hfish honeypot within a subdomain operating system and sending the access traffic data to a network attack detection module; wherein the operating system includes multiple mutually isolated subdomain operating systems, each subdomain operating system including the Hfish honeypot; the network attack detection module for performing network attack detection on the access traffic data; a processing module for identifying the subdomain operating system as a high-risk subdomain operating system if the network attack detection module determines that the access traffic data contains attack data; and a defense module for executing defense actions based on the defense strategy in the attack defense module within the high-risk subdomain operating system.

[0006] Thirdly, an electronic device is provided, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the method of the first aspect.

[0007] Fourthly, a computer-readable storage medium is provided on which a computer program is stored, which, when executed by a processor, implements the steps of the method of the first aspect.

[0008] Fifthly, a computer program product is provided, comprising a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps of the method of the first aspect.

[0009] In this embodiment, by dividing the operating system into multiple isolated subdomain operating systems, a high degree of file system isolation is achieved, which is beneficial to improving the security performance of the operating system. At the same time, by deploying an Hfish honeypot and an attack defense module in each subdomain operating system, the attack defense module is equipped with a defense strategy. The Hfish honeypot can capture and analyze attack behaviors, which is beneficial to the attack defense module to execute effective defense actions based on the defense strategy, thereby improving the security performance of the operating system. Attached Figure Description

[0010] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0011] Figure 1 This invention provides a flowchart illustrating a secure operation method for an operating system according to an embodiment of the present application.

[0012] Figure 2 This invention provides a flowchart illustrating a secure operation method for an operating system according to an embodiment of the present application.

[0013] Figure 3 This invention provides a flowchart illustrating a secure operation method for an operating system according to an embodiment of the present application.

[0014] Figure 4 This invention provides a flowchart illustrating a secure operation method for an operating system according to an embodiment of the present application.

[0015] Figure 5 This invention provides a flowchart illustrating a secure operation method for an operating system according to an embodiment of the present application.

[0016] Figure 6This invention provides a flowchart illustrating a secure operation method for an operating system according to an embodiment of the present application.

[0017] Figure 7 This invention provides a schematic diagram of the structure of an electronic device according to an embodiment of the present application.

[0018] Figure 8 A schematic diagram of the hardware structure of an electronic device for executing the secure operation method of the operating system provided in the embodiments of this application. Detailed Implementation

[0019] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. The drawing numbers in this application are only used to distinguish the various steps in the solution and are not used to limit the execution order of the various steps. The specific execution order is subject to the description in the specification.

[0020] Figure 1 This illustration shows a flowchart of a secure operation method for an operating system provided in an embodiment of this application. This method can be executed by an electronic device, such as a terminal device or a server device. In other words, the method can be executed by software or hardware installed on the terminal device or server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. Figure 1 As shown, the method may include the following steps.

[0021] S102: Collect access traffic data of Hfish honeypot within the subdomain operating system and send the access traffic data to the network attack detection module.

[0022] The operating system comprises multiple isolated subdomain operating systems, each containing the Hfish honeypot; the network attack detection module is used to perform network attack detection on the access traffic data. This embodiment can execute steps S102 to S106 for each subdomain operating system.

[0023] The aforementioned multiple subdomain operating systems can be obtained by dividing the server's (original) operating system. These multiple subdomain operating systems are isolated from each other, which helps to improve the security of the operating system.

[0024] This embodiment can deploy Hfish honeypots within each subdomain operating system. Hfish honeypots are a proactive defense technology that can actively expose vulnerabilities and set up decoys to lure attackers into launching attacks, thereby capturing and analyzing attack behavior and improving the security of the operating system.

[0025] In one embodiment, before collecting access traffic data of the Hfish honeypot within the subdomain operating system, the method further includes: setting the server's single-level file structure to a multi-level file structure; wherein the multi-level file structure includes a primary domain file system and multiple subdomain file systems; and based on the primary domain file system and multiple subdomain file systems, dividing the operating system into a primary domain operating system and multiple subdomain operating systems.

[0026] This embodiment can divide the operating system into a main domain operating system and multiple subdomain operating systems. These multiple subdomain operating systems are isolated from each other, but they can share memory space. By controlling the access of the subdomain operating systems to the shared memory space, a high degree of isolation of the file system can be achieved, thereby improving the security of the operating system.

[0027] The network attack detection module can be located within the main domain operating system. This module is used to detect the presence of attack behavior, specifically, to detect the presence of attack data within access traffic data. The network attack detection module includes a network attack detection model, which can be pre-trained.

[0028] S104: If the network attack detection module determines that the access traffic data contains attack data, the subdomain operating system is identified as a high-risk subdomain operating system.

[0029] As mentioned earlier, the server's operating system can include multiple subdomain operating systems. S102 can collect access traffic data of the Hfish honeypot within each subdomain operating system. This step can identify subdomain operating systems containing attack data as high-risk subdomain operating systems.

[0030] S106: Execute defense actions based on the defense strategy in the attack defense module within the high-risk subdomain operating system.

[0031] The defense strategy can be obtained based on the HGSBAB (Honeypot Game Strategy Based on Attack Beliefs) model, which is generated by attacking and defending the Hfish honeypot.

[0032] Before executing this embodiment, the HGSBAB algorithm can be used in advance to conduct an attack and defense game on the Hfish honeypot to generate an HGSBAB model. This HGSBAB model is used to generate a defense strategy for the Hfish honeypot. The core of the defense strategy is to use game theory to optimize the operation of the Hfish honeypot, for example, to gain an advantage in network confrontation by confusing and deceiving attackers.

[0033] Before executing this embodiment, the optimal defense strategy for Hfish honeypots can be obtained based on the HGSBAB model.

[0034] This embodiment can also disable the virtual security access permissions of the high-risk subdomain operating system, thereby isolating the high-risk subdomain operating system from the shared memory space and improving the security of the operating system.

[0035] The secure operation method for the operating system provided in this application divides the operating system into multiple isolated subdomain operating systems, achieving a high degree of file system isolation, which is beneficial to improving the security performance of the operating system. At the same time, by deploying an Hfish honeypot and an attack defense module in each subdomain operating system, the attack defense module deploys defense strategies. The Hfish honeypot can capture and analyze attack behaviors, which is beneficial to the attack defense module to execute effective defense actions based on the defense strategies, thereby improving the security performance of the operating system.

[0036] Meanwhile, the defense strategy in the attack defense module can be obtained based on the HGSBAB model, which is generated by attack and defense game of the Hfish honeypot. This helps to obtain the optimal defense strategy and further improve the security performance of the operating system.

[0037] In one embodiment, sending the access traffic data to the network attack detection module includes: sending the access traffic data to the network attack detection module by attacking and trapping an Hfish honeypot chain; wherein, the attacking and trapping Hfish honeypot chain includes: an Hfish management module set in the main domain operating system and an Hfish honeypot set in each of the subdomain operating systems, the Hfish management module being connected to each of the Hfish honeypots, and the Hfish management module being used to manage each of the Hfish honeypots.

[0038] This embodiment, through the set-up attack-luring Hfish honeypot chain network, can utilize the active defense technology of Hfish honeypots to proactively expose some vulnerabilities and set some baits to lure attackers to launch attacks. This allows for the capture and analysis of attack behaviors, which is beneficial for the attack defense module to execute effective defense actions based on the defense strategy, thereby improving the security performance of the operating system.

[0039] In one embodiment, after the defense action is performed, the method further includes: returning defense action execution information to the Hfish management module; wherein each subdomain operating system includes the attack defense module, each attack defense module is connected to the Hfish management module to form a network attack defense chain, and the attack defense module in each subdomain operating system is connected to the Hfish honeypot.

[0040] This embodiment improves the security performance of the operating system by setting up a network attack defense chain and an attack-trapping Hfish honeypot chain.

[0041] In one embodiment, the method further includes: repeatedly performing the following steps to generate the HGSBAB model by playing an attack-defense game on the Hfish honeypot: 1) setting an initial attack belief value for the attacker participating in the attack-defense game; 2) obtaining the expected reward of each attack action performed by the attacker based on the initial attack belief value; 3) generating attack action execution information based on the expected reward of each attack action; 4) obtaining the expected reward of the defender's defense action based on the attack action execution information and generating corresponding defense action execution information; 5) if the defense action execution information includes blocking actions, updating the attacker's attack belief value according to Bayes' theorem.

[0042] This embodiment can preset a threshold number of iterations. When the number of iterations in the above five steps is greater than or equal to the preset threshold number, the attack and defense game of the Hfish honeypot can be stopped, and the HGSBAB model is obtained.

[0043] In one embodiment, the method further includes: based on the HGSBAB model and at least one of the following information, using the IUCT (Imporved Upper Confidence Bound Apply to Tce) algorithm to solve the pure policy equilibrium of the NSE (N Successes are Enough) honeypot game, to obtain the defense strategy corresponding to the Hfish honeypot: the loss caused by the attacker being captured by the Hfish honeypot when executing each attack action; the gain of the attacker successfully executing each attack action; the cost of the attacker re-executing the attack; and the cost of maintenance by the defender.

[0044] IUCT can be used in the selection phase of solving pure strategy equilibrium in NSE honeypot games. The pure strategy equilibrium solution in NSE honeypot games can include multiple phases, such as the selection phase, expansion phase, simulation phase, and backtracking update phase.

[0045] This embodiment helps to obtain the optimal defense strategy and improve the security performance of the operating system.

[0046] In one embodiment, after obtaining the defense policy corresponding to the Hfish honeypot, the method further includes: using the virtual security access verification module in the primary domain operating system to verify the virtual security access requests sent by each of the subdomain operating systems; and sharing the defense policy with the successfully verified subdomain operating systems.

[0047] This embodiment can share the generated defense strategy to the successfully verified subdomain operating system. By performing security verification operations on the subdomain operating system, the security performance of the operating system can be improved.

[0048] In one embodiment, sharing the defense strategy to the successfully verified subdomain operating system includes: sharing the defense strategy to the successfully verified subdomain operating system via a shared memory space; wherein multiple subdomain operating systems share the memory space.

[0049] In one embodiment, before collecting access traffic data of the Hfish honeypot within the subdomain operating system, the method further includes: performing model training to obtain the network attack detection module.

[0050] In one embodiment, the process of training the network attack detection module by executing the model includes: 1) collecting historical access traffic data, which includes attack data carrying attack tags; 2) dividing the historical access traffic data into a model training sample set and a model test sample set; 3) optimizing the training using the DBN-IFWA (Deep Belief Network, Iterative Forward Weighted Averaging) algorithm based on the model training sample set to construct an initial network attack detection model; 4) determining the accuracy of the initial network attack detection model based on the model test sample set; and 5) if the accuracy is greater than a preset accuracy threshold, deploying the initial network attack detection model within the network attack detection module.

[0051] This embodiment uses the DBN-IFWA algorithm to build an initial network attack detection model. By mining the deep data features of traffic data, it can automatically and accurately identify and detect malicious network attack traffic data. DBN-IFWA is an iterative weighted average algorithm that can be used to perform operations such as filtering, sorting and sorting of data.

[0052] To illustrate in detail the secure operation method of the operating system provided in the embodiments of this application, the following will describe it in conjunction with several specific embodiments.

[0053] This embodiment provides a secure operation method for an operating system based on honeypot technology, such as... Figure 2 As shown, it includes the following steps:

[0054] S1: Initialize the multi-domain isolated operating system of the current server based on the primary domain file system and several subdomain file systems with a federated multi-level file structure.

[0055] like Figure 3 As shown, S1 may include the following steps:

[0056] S1-1: Set the current single-level file structure of the server to a combined multi-level file structure.

[0057] The federated multi-level file structure includes a primary domain file system at the bottom and several subdomain file systems at the federated multilevel, wherein the primary domain file system and the several subdomain file systems are independent of each other.

[0058] S1-2: Based on a federated multi-level file system, a primary domain file system and several subdomain file systems are set up, with a corresponding primary domain operating system partition and several subdomain operating system partitions.

[0059] A domain operating system refers to setting up multiple independent operating systems on the same server. Each domain operating system can operate in front of users, and the operation of different domain operating systems is isolated from each other.

[0060] S1-3: Set up a shared memory space, which is connected to the primary domain-level file system and several subdomain-level file systems respectively.

[0061] S1-4: Configure the corresponding primary domain operating system image file and subdomain operating system image file according to the system attribute information of the primary domain operating system and several subdomain operating systems as required.

[0062] S1-5: Store the primary domain operating system image file and the subdomain operating system image file to the corresponding primary domain hierarchical file system and several subdomain hierarchical file systems.

[0063] S1-6: Load and boot the kernel, pull the primary domain operating system image file and the subdomain operating system image file at once in kernel mode, and start the corresponding primary domain operating system and several subdomain operating system partitions.

[0064] S1-7: Integrate the primary domain operating system and several subdomain operating systems to obtain the current server's multi-domain isolated operating system.

[0065] S2: In the current multi-domain isolated operating system of the server, the main domain operating system deploys the Hfish management module and the network attack detection module, and each subdomain operating system deploys Hfish honeypots and connects to the main domain Hfish management module to form an Hfish honeypot chain network.

[0066] The network attack detection module can be obtained based on the following process: the initial network parameters of the DBN (Deep Belief Network) are used as the optimization target of the IFWA (Improved Fireworks Algorithm) optimization algorithm. Based on the optimization target, the IFWA optimization algorithm is used to optimize and obtain the optimal initial network parameters of the DBN network. The model training sample set is then input into the DBN network for optimization training to obtain the optimized network attack detection model.

[0067] like Figure 4 As shown, S2 may include the following steps:

[0068] S2-1: Based on a multi-domain isolated operating system, deploy the Hfish management module, virtual security access verification module, and network attack detection module on the main domain operating system.

[0069] The virtual security access verification module connects to all subdomain operating systems and is used to receive virtual security access requests sent by the subdomain operating systems.

[0070] The training method for the network attack detection model is as follows:

[0071] (1) Collect historical access traffic data containing several network attacks, and preprocess and add tags to several historical access traffic data to obtain several preprocessed historical access traffic data with preset network attack tags.

[0072] The preprocessing process includes, in sequence, standardizing data formats, cleaning up duplicate data, deleting erroneous data, and desensitizing sensitive data.

[0073] (2) Divide several preprocessed historical access traffic data into a model training sample set and a model test sample set in a ratio of 7:3.

[0074] (3) Based on the model training sample set, use the DBN-IFWA algorithm to perform optimization training and build the initial network attack detection model, including the following steps:

[0075] ① The initial network parameters of the DBN network are used as the optimization target of the IFWA optimization algorithm. Based on the optimization target, the IFWA optimization algorithm is used to optimize and obtain the optimal initial network parameters of the DBN network. This includes the following steps:

[0076] a: Use the initial network parameters of the DBN network as the optimization target of the IFWA optimization algorithm.

[0077] b: Set the IFWA population parameters, maximum number of iterations, and fitness function for the IFWA optimization algorithm, and use the optimization target as the position of the IFWA individual in the IFWA population.

[0078] c: Based on the IFWA population parameters, the IFWA population is initialized using the Circle chaotic mapping sequence to obtain the initialized IFWA population, as shown in the formula:

[0079]

[0080] In the formula, For the initial IFWA individuals of the Circle chaotic map; The initial IFWA individuals are randomly generated; For IFWA individual indicators.

[0081] d: Calculate the fitness value of IFWA individuals in the initialized IFWA population according to the fitness function. The formula is:

[0082]

[0083] In the formula, For the initial IFWA individuals fitness value; MSE The mean square error function for prediction; For predicted values ​​and actual values; L This represents the total number of IFWA individuals.

[0084] e: Obtain the explosion radius and spark count of IFWA individuals in the IFWA population, using the following formula:

[0085]

[0086] In the formula, For the initial IFWA individuals The number of sparks; It is a constant; The maximum fitness value in the initialized IFWA population; For the initial IFWA individuals fitness value; It is an infinitesimal constant.

[0087]

[0088] In the formula, For the initial IFWA individuals Explosion radius; This is a constant used to adjust the explosion radius. The minimum fitness value in the initialized IFWA population.

[0089] f: Based on the explosion radius and spark count of each initial IFWA individual in the initial IFWA population, fireworks are detonated to obtain an updated IFWA population, using the following formula:

[0090]

[0091] In the formula, For updated IFWA individuals; A random number between -1 and 1; This refers to the initial IFWA individual.

[0092] g: Use the Gaussian mutation algorithm to perform Gaussian mutation on the initialized IFWA population to generate a Gaussian-mutated IFWA population. The formula is:

[0093]

[0094] In the formula, An IFWA individual with Gaussian mutation; These are random numbers distributed according to a Gaussian distribution with a mean and variance of 1. This refers to the initial IFWA individual.

[0095] h: Using a dynamic back-learning algorithm, the initialized IFWA population is dynamically back-learned to generate a dynamically back-learned IFWA population. The formula is:

[0096]

[0097] In the formula, For dynamically reversed IFWA individuals; For the initial IFWA individual; γ is the decreasing inertia coefficient, γ=0.9-0.5t / T; These are the maximum and minimum values ​​in the vector space, respectively. t For iteration indication; T This is the threshold for the number of iterations.

[0098] i: Calculate the fitness value of all IFWA individuals in the updated IFWA population, the Gaussian-mutated IFWA population, and the dynamically reversed IFWA population, and select the IFWA individual with the lowest fitness value as the optimal individual.

[0099] j: If the number of iterations reaches the iteration threshold or the fitness value of the best individual meets the requirements, then the optimal solution corresponding to the current best individual is output to obtain the optimal initial network parameters of the DBN network.

[0100] ② Construct the network structure of the DBN network based on the optimal initial network parameters of the DBN network.

[0101] ③ Input the model training sample set into the DBN network for optimization training to build the initial network attack detection model.

[0102] (4) Input the model test sample set into the initial network attack detection model, perform model testing, and obtain several corresponding network attack prediction labels.

[0103] (5) Based on several network attack prediction labels and corresponding network attack preset labels, the model test accuracy is obtained.

[0104] (6) If the model test accuracy is greater than the preset accuracy threshold, the optimal network attack detection model is output; otherwise, the optimization training continues.

[0105] S2-2: Generate corresponding Hfish honeypot elements based on the system attribute information of each subdomain operating system and the application attribute information of the applications provided by the subdomain operating system.

[0106] S2-3: Based on the Hfish honeypot features, set up the Hfish honeypot at all applications in the subdomain operating system and set up network traffic probes at the Hfish honeypot.

[0107] The Hfish honeypot elements include the service framework protocol for building the virtual server corresponding to the Hfish honeypot, the virtual server attribute information, the applicable application attribute information, and the applicable system attribute information.

[0108] S2-4: Connect all Hfish honeypots deployed on all subdomain operating systems to the Hfish management module of the main domain operating system, and connect all network traffic probes to the network attack detection model of the main domain operating system to form an attack-trapping Hfish honeypot chain network.

[0109] S3: In the main domain operating system of the multi-domain isolated operating system, the Hfish honeypot is subjected to attack and defense game to generate the HGSBAB model. The optimal defense strategy is obtained and shared to each subdomain file system to form a network attack defense chain.

[0110] like Figure 5 As shown, S3 may include the following steps:

[0111] S3-1: A primary domain operating system based on a multi-domain isolated operating system, using the HGSBAB algorithm to conduct attack and defense game against Hfish honeypots and generate the HGSBAB model.

[0112] The attack and defense game against Hfish honeypots includes the following steps:

[0113] (1) Set an initial attack belief value for the attacker participating in the attack and defense game, and pre-set three types of attack actions for the attacker: including low-frequency attack actions, high-frequency attack actions and attack withdrawal actions, and two types of defense actions for the defender: including blocking actions and release actions.

[0114] (2) Based on the initial attack belief value, obtain the expected benefits of the attacker performing three types of attack actions, including: expected benefits of low-frequency attack actions, expected benefits of high-frequency attack actions, and expected benefits of attack exit actions.

[0115] (3) Based on the attacker's expected gain, execute the attack action with the highest expected gain and send the corresponding attack action execution information to the defender.

[0116] (4) Based on the defender, the expected benefits of executing three types of attack actions are obtained according to the attack action execution information, including: the expected benefits of blocking actions and the expected benefits of releasing actions.

[0117] (5) Based on the defender's expected benefit, execute the defense action with the highest expected benefit and generate the corresponding defense action execution information.

[0118] (6) If the defensive action execution information contains a blocking action of the defender, according to Bayes' theorem, update the attacker's attack belief value to obtain the updated attack belief value, and repeat the above steps according to the updated attack belief value to carry out the next Hfish honeypot attack and defense game.

[0119] (7) If the number of iterations of the Hfish honeypot attack and defense game exceeds the preset threshold, then stop the Hfish honeypot attack and defense game.

[0120] The relevant formulas for the HGSBAB model are shown below:

[0121] The formula for threshold attack belief value is:

[0122]

[0123] In the formula, The threshold attack belief value for the attacker to execute an attack action; The attack belief value for the attacker to execute the attack exit action; The probability that the defender will execute the release action; The benefit to the attacker in successfully executing low-frequency attack actions; The benefits for the attacker to successfully execute high-frequency attack actions; The loss was caused by the attacker's information being leaked when the attacker was captured by the Hfish honeypot while performing low-frequency attack actions; The loss was caused by the Hfish honeypot capturing the attacker's information when the attacker was executing high-frequency attack actions; This represents the number of iterations in the Hfish honeypot attack and defense game.

[0124] The formula for updating attack belief value is:

[0125]

[0126] In the formula, The attack belief value updated for the attacker when the defender's defensive action is a blocking action; The probability of the defending side performing a blocking action. much smaller ; This represents the attacker's initial belief value.

[0127] The formula for equilibrium return is:

[0128]

[0129] In the formula, For the first The balanced gains of the attacker in the next iteration; After the attack belief value is updated, the th The balanced gains of the attacker in the next iteration; The cost for the attacker to re-execute the attack; The cost of maintenance for the defending side; This is to allow the attacker to re-execute the attack and gain benefits.

[0130] like The defending side executes the release operation;

[0131] The formula for expected return is:

[0132]

[0133] In the formula, For the first The expected gain of the attacker when the defender's defensive action in the next iteration is a release action and the attacker's attack action is a low-frequency attack action. For the first The expected return of the attacker when the defender's defensive action is a release action and the attacker's attack action is a high-frequency attack action in the next iteration. The loss was caused by the attacker's information being leaked when the attacker was captured by the Hfish honeypot while performing low-frequency attack actions; The loss was caused by the Hfish honeypot capturing the attacker's information when the attacker was executing high-frequency attack actions; The number of iterations in the Hfish honeypot attack and defense game; For the first The attacker's updated attack belief value in the next iteration; The benefit to the attacker in successfully executing low-frequency attack actions; The benefits for the attacker to successfully execute high-frequency attack actions; For the first The balanced gains of the attacker in the next iteration; The probability that the defender will execute the release action; The probability of the defending side performing a blocking action.

[0134] like The attacker performs low-frequency attack actions.

[0135]

[0136] In the formula, For the first The expected gain of the attacker when the defender's defensive action is a blocking action and the attacker's attack action is a low-frequency attack action in the next iteration. For the first The expected gain of the attacker when the defender's defensive action is a blocking action and the attacker's attack action is a high-frequency attack action in the next iteration.

[0137] like The attacker performs low-frequency attack actions.

[0138] S3-2: Based on the HGSBAB model, the IUCT algorithm is used to solve the pure strategy equilibrium of the NSE honeypot game, where N is a preset threshold number of iterations. The optimal defense strategy of the Hfish honeypot is obtained and stored in the main domain file system. The steps include the following:

[0139] (1) Set the preset number of times threshold N in the HGSBAB model, and the initial states of the attacker and defender. The loss occurred when the attacker's low-frequency attack actions were captured by the Hfish honeypot, resulting in the leakage of the attacker's information. The loss caused by the attacker's information being leaked when the attacker was capturing the high-frequency attack actions by the Hfish honeypot. The benefits of the attacker successfully executing low-frequency attack actions The benefits of the attacker successfully executing high-frequency attack actions The cost for the attacker to re-execute the attack The cost of maintenance by the defender Input the IUCT algorithm.

[0140] (2) Initial state of the attacker and defender Construct the root node of the search tree .

[0141] (3) Based on the root node The search is performed, resulting in several child nodes, and the current search depth is less than a preset search depth threshold. .

[0142] (4) Obtain the node evaluation values ​​of several child nodes, using the following formula:

[0143]

[0144] In the formula, For the first The node's evaluation value; For the first The average revenue of a node; Total number of explorations; For the first The number of times a node has been explored; This is the balance coefficient; The greedy coefficient is used; the average profit value is based on the node. corresponding , , , , as well as Obtain.

[0145] (5) Add the node with the highest evaluation value to the search tree.

[0146] (6) If the current number of explorations is greater than or equal to the preset number of explorations threshold N, then search all the corresponding root nodes in the search tree. The optimal defense strategy for the Hfish honeypot is obtained by outputting the defense action strategies of the child nodes.

[0147] S3-3: Use the virtual security access verification module to verify the virtual security access requests sent by all subdomain operating systems. If the verification is successful, the optimal defense strategy of the Hfish honeypot is shared to several subdomain file systems through shared memory space.

[0148] S3-4: Configure attack defense modules at the Hfish honeypots on all subdomain operating systems, and connect all attack defense modules to the Hfish management module deployed on the main domain operating system.

[0149] S3-5: Use the Hfish management module to write the optimal defense strategy into the attack defense module to form a network attack defense chain.

[0150] The attack defense module is connected to both the Hfish honeypot and the Hfish management module. It controls the Hfish honeypot, executes defense actions against network attacks from attackers based on the optimal defense strategy, and returns the corresponding defense action execution information to the Hfish management module.

[0151] S4: Based on a multi-domain isolated operating system, the Hfish honeypot chain network for attack trapping and the network attack defense chain network are used to trap and defend against malicious network attacks on the current server.

[0152] like Figure 6 As shown, S4 may include the following steps:

[0153] S4-1: Based on any subdomain operating system, use a network traffic probe to collect access traffic data of Hfish honeypots, and send the access traffic data to the network attack detection module by attacking and trapping the Hfish honeypot chain network.

[0154] S4-2: The network attack detection model deployed using the network attack detection module performs network attack detection on access traffic data. If the network attack detection result indicates the presence of a malicious network attack, the access traffic data is treated as attack traffic data to achieve the malicious network attack trapping function.

[0155] S4-3: Based on the transmission path of the attack traffic data in the attack-trapping Hfish honeypot chain network and the network traffic probe information, trace the attack traffic data to obtain the corresponding high-risk subdomain operating system.

[0156] S4-4: Based on the virtual security access verification module, the virtual security access permissions of the high-risk subdomain operating system are turned off, thereby isolating the high-risk subdomain operating system from the shared memory space.

[0157] S4-5: Use the attack defense module corresponding to the high-risk subdomain operating system in the network attack defense chain to execute defense actions according to the optimal defense strategy, and return the corresponding defense action execution information to the Hfish management module to realize the malicious network attack defense function.

[0158] In this embodiment, based on the multi-domain isolated operating system, the Hfish honeypot chain network for attack trapping and the network attack defense chain network are used to trap and defend against malicious network attacks on the current server. This enables 24-hour uninterrupted monitoring of the operating system's operation and can accurately and efficiently identify and promptly intercept malicious network attacks, thereby improving the security of operating system files and data.

[0159] In this embodiment, a multi-domain isolated operating system is deployed on the server. By controlling the access of the subdomain operating system to the shared memory space, a high degree of file system isolation is achieved, which improves the data security and reliability of the main domain operating system's file system, avoids malicious network attacks from invading the main domain operating system's file system and causing losses, and limits the impact of malicious network attacks to the subdomain operating system, thereby reducing the degree of damage caused by malicious network attacks.

[0160] In this embodiment, an attack-trapping Hfish honeypot network is constructed, which can trap malicious network attacks while ensuring the security of the operating system. This facilitates subsequent analysis of attack behavior, improves the functionality of operating system security monitoring, and is applicable to constantly updated malicious network attack technologies.

[0161] In this embodiment, the HGSBAB algorithm is used to conduct an attack and defense game on the Hfish honeypot. The Hfish honeypot is trained to execute the optimal defense strategy to the maximum extent. It can fully weigh the risk of taking the attack against the attacker's strategy and reduce the attacker's suspicion in order to obtain more information about the attacker and select the best response. This improves the speed of Hfish honeypot's response to malicious network attacks and the effectiveness of its defense strategy, and speeds up the efficiency and speed of defense actions.

[0162] In this embodiment, the DBN-IFWA algorithm is used to construct an initial network attack detection model. By mining the deep data features of traffic data, malicious network attack traffic data is automatically and accurately identified and detected. Through network traffic data collected by Hfish honeypot, real-time and dynamic malicious network attack detection is performed, which improves the intelligence and accuracy of operating system operation security monitoring and ensures the stability and security of operating system operation.

[0163] Figure 7 The diagram shows the structure of an electronic device 700 provided in an embodiment of this application. The electronic device 700 includes the following modules.

[0164] The data processing module 702 is used to collect access traffic data of the Hfish honeypot within the subdomain operating system and send the access traffic data to the network attack detection module; wherein, the operating system includes multiple mutually isolated subdomain operating systems, and each subdomain operating system includes the Hfish honeypot; the network attack detection module is used to perform network attack detection on the access traffic data.

[0165] The processing module 704 is used to identify the subdomain operating system as a high-risk subdomain operating system when the network attack detection module determines that the access traffic data contains attack data.

[0166] Defense module 706 is used to perform defense actions based on the defense strategy in the attack defense module within the high-risk subdomain operating system.

[0167] The defense strategy can be based on the HGSBAB model, which is generated by attacking and defending the Hfish honeypot.

[0168] In this embodiment, by dividing the operating system into multiple isolated subdomain operating systems, a high degree of file system isolation is achieved, which is beneficial to improving the security performance of the operating system. At the same time, by deploying an Hfish honeypot and an attack defense module in each subdomain operating system, the attack defense module is equipped with a defense strategy. The Hfish honeypot can capture and analyze attack behaviors, which is beneficial to the attack defense module to execute effective defense actions based on the defense strategy, thereby improving the security performance of the operating system.

[0169] The electronic device 700 provided in this application embodiment can execute any of the embodiments described in the foregoing method embodiments and achieve the functions and beneficial effects of any of the embodiments described in the foregoing method embodiments, which will not be repeated here.

[0170] In this application, the electronic device provided with the above-mentioned modules can also implement the method steps provided in the above-mentioned method embodiments. Alternatively, the electronic device provided with this application may further include other modules besides the above-mentioned modules to implement the method steps provided in the above-mentioned method embodiments. Furthermore, the electronic device provided with this application can achieve the technical effects achievable by the above-mentioned method embodiments.

[0171] This application also provides an electronic device, including a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described operating system secure operation method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here.

[0172] Figure 8 The diagram illustrates the hardware structure of an electronic device implementing the embodiments of this application. Referring to the diagram, at the hardware level, the electronic device includes a processor, and may also include an internal bus, a network interface, and a memory. The memory may include RAM, such as high-speed random-access memory (RAM), and may also include non-volatile memory, such as at least one disk storage device. Of course, the electronic device may also include other hardware required for other services.

[0173] The processor, network interface, and memory can be interconnected via an internal bus, which can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be categorized as an address bus, data bus, control bus, etc. For ease of illustration, only a single bidirectional arrow is used in this diagram, but this does not imply that there is only one bus or one type of bus.

[0174] Memory is used to store programs. Specifically, programs may include program code, which includes computer operation instructions. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0175] The processor reads the corresponding computer program from non-volatile memory into main memory and then runs it. The processor executes the program stored in memory and specifically performs the following tasks: Figure 1-6 The methods disclosed in the embodiments shown achieve the functions and beneficial effects of the methods described in the preceding method embodiments, and will not be repeated here.

[0176] The above is as stated in this application. Figure 1-6The methods disclosed in the illustrated embodiments can be applied to or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above methods can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0177] The electronic device can also execute any of the embodiments described in the foregoing method embodiments and achieve the functions and beneficial effects of any of the embodiments described in the foregoing method embodiments, which will not be repeated here.

[0178] Of course, in addition to software implementation, the electronic device of this application does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0179] This application also provides a computer-readable storage medium storing a computer program. When executed by a processor, this computer program implements the various processes of the above-described embodiments of the secure operation method of the operating system, and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.

[0180] This application also provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program. The computer program is operable to cause a computer to perform some or all of the steps of the above-described embodiments of the secure operation method of the operating system, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0181] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0182] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0183] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0184] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0185] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0186] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0187] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0188] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0189] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0190] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of this application should be included within the scope of the claims of this application.

Claims

1. A method for secure operation of an operating system, characterized in that, include: Access traffic data of the Hfish honeypot within the subdomain operating system is collected and sent to the network attack detection module; wherein, the operating system includes multiple mutually isolated subdomain operating systems, and each subdomain operating system includes the Hfish honeypot; the network attack detection module is used to perform network attack detection on the access traffic data; If the network attack detection module determines that the access traffic data contains attack data, the subdomain operating system is identified as a high-risk subdomain operating system. Based on the defense strategy in the attack defense module within the high-risk subdomain operating system, execute defense actions; The method further includes: repeatedly performing the following steps to generate an HGSBAB model through an attack-defense game on the Hfish honeypot: Set an initial attack belief value for the attacking side participating in the attack and defense game; Based on the initial attack belief value, the expected benefit of each attack action performed by the attacker is obtained; Based on the expected benefits of each attack action, attack action execution information is generated; Based on the attack action execution information, the expected benefit of the defender's defense action is obtained, and corresponding defense action execution information is generated; If the defensive action execution information includes blocking actions, then the attacker's attack belief value is updated according to Bayes' theorem. The method further includes: The HGSBAB model is generated by performing an attack-defense game on the Hfish honeypot; Based on the HGSBAB model and the following information, the improved tree upper bound confidence interval (IUCT) algorithm is used to solve the pure policy equilibrium of the successful honeypot game with N moves, thus obtaining the defense strategy corresponding to the Hfish honeypot: The losses incurred by the attacker when being captured by the Hfish honeypot while executing each attack action; the gains of the attacker when successfully executing each attack action; the cost of the attacker re-executing the attack; the maintenance cost of the defender; Wherein, N is the preset number of times threshold in the HGSBAB model.

2. The method according to claim 1, characterized in that, The step of sending the access traffic data to the network attack detection module includes: By attacking and trapping the Hfish honeypot chain network, the access traffic data is sent to the network attack detection module; The attack-luring Hfish honeypot chain network includes: an Hfish management module located in the main domain operating system and an Hfish honeypot located in each of the subdomain operating systems, wherein the Hfish management module is connected to each of the Hfish honeypots.

3. The method according to claim 2, characterized in that, After performing the defensive action, the method further includes: Return defense action execution information to the Hfish management module; Each of the subdomain operating systems includes an attack defense module, and each attack defense module is connected to the Hfish management module to form a network attack defense chain. The attack defense module in each subdomain operating system is also connected to the Hfish honeypot.

4. The method according to claim 1, characterized in that, After obtaining the defense strategy corresponding to the Hfish honeypot, the method further includes: The virtual security access verification module in the primary domain operating system is used to verify the virtual security access requests sent by each of the subdomain operating systems. The defense strategy is shared to the successfully verified subdomain operating system.

5. The method according to claim 4, characterized in that, The step of sharing the defense strategy to the successfully verified subdomain operating system includes: The defense strategy is shared to the successfully verified subdomain operating system through a shared memory space; wherein, multiple subdomain operating systems share the memory space.

6. The method according to claim 1, characterized in that, Before collecting access traffic data of the Hfish honeypot within the subdomain operating system, the method further includes: The server's single-level file structure is set to a multi-level file structure; wherein, the multi-level file structure includes a primary domain file system and multiple subdomain file systems; Based on the primary domain file system and multiple subdomain file systems, the operating system is divided into a primary domain operating system and multiple subdomain operating systems.

7. The method according to claim 1, characterized in that, Before collecting access traffic data of the Hfish honeypot within the subdomain operating system, the method further includes: The network attack detection module is obtained by performing model training.

8. The method according to claim 7, characterized in that, The network attack detection module obtained by training the execution model includes: Collect historical access traffic data, which includes attack data carrying attack tags; The historical access traffic data is divided into a model training sample set and a model test sample set; Based on the training sample set of the model, the DBN-IFWA algorithm is used for optimization training to build an initial network attack detection model. The accuracy of the initial network attack detection model is determined based on the model test sample set. If the accuracy rate is greater than a preset accuracy rate threshold, then the initial network attack detection model is deployed within the network attack detection module.

9. An electronic device, characterized in that, include: The data processing module is used to collect access traffic data of the Hfish honeypot within the subdomain operating system and send the access traffic data to the network attack detection module; wherein, the operating system includes multiple mutually isolated subdomain operating systems, and each subdomain operating system includes the Hfish honeypot; the network attack detection module is used to perform network attack detection on the access traffic data; The processing module is used to identify the subdomain operating system as a high-risk subdomain operating system when the network attack detection module determines that the access traffic data contains attack data. The defense module is used to execute defense actions based on the defense strategy in the attack defense module within the high-risk subdomain operating system; The electronic device is also used to: repeatedly perform the following steps to generate an HGSBAB model through an attack-defense game on the Hfish honeypot: Set an initial attack belief value for the attacking side participating in the attack and defense game; Based on the initial attack belief value, the expected benefit of each attack action performed by the attacker is obtained; Based on the expected benefits of each attack action, attack action execution information is generated; Based on the attack action execution information, the expected benefit of the defender's defense action is obtained, and corresponding defense action execution information is generated; If the defensive action execution information includes blocking actions, then the attacker's attack belief value is updated according to Bayes' theorem. The electronic device is also used for: The HGSBAB model is generated by performing an attack-defense game on the Hfish honeypot; Based on the HGSBAB model and the following information, the improved tree upper bound confidence interval (IUCT) algorithm is used to solve the pure policy equilibrium of the successful honeypot game with N moves, thus obtaining the defense strategy corresponding to the Hfish honeypot: The losses incurred by the attacker when being captured by the Hfish honeypot while executing each attack action; the gains of the attacker when successfully executing each attack action; the cost of the attacker re-executing the attack; the maintenance cost of the defender; Wherein, N is the preset number of times threshold in the HGSBAB model.

10. An electronic device, comprising: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the method as described in any one of claims 1-8.

11. A computer-readable storage medium storing a computer program thereon, the computer program, when executed by a processor, implementing the steps of the method as claimed in any one of claims 1-8.

Citation Information

Patent Citations

  • Multi-system shared memory management method and device

    CN108064377A

  • Network security protection method and system

    CN114268452A

  • Network security protection method, device and system and electronic equipment

    CN114944961A

  • Network security protection method based on signal game

    CN118764267A