A Method and Device for Detecting Linux System Port Reuse Attacks

The method addresses the inefficiencies of current port reuse attack detection by using kernel and application layer collaboration to identify and differentiate between legitimate and malicious port sharing in Linux systems, enhancing security and reducing manual effort.

CN119577753BActive Publication Date: 2025-07-15BEIJING BIG DATA CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411600766.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-11
Publication Date
2025-07-15
Estimated Expiration
2044-11-11

AI Technical Summary

Technical Problem

The existing technology lacks effective real-time detection methods to identify port multiplexing attacks in Linux systems, making it difficult to detect attacks in time, increasing the system security risks and the possibility of information leakage.

Method used

Through the kernel and application layer linkage, the setsockopt system call process information is detected, the socket inode number is obtained, the socket data table is traversed, the process data is judging whether the process has port reuse attacks, and the socket inode number, process pid and path are used for in-depth analysis.

Benefits of technology

Real-time automatic detection of port multiplexing attacks is realized, the accuracy and efficiency of detection is improved, potential security threats can be identified in a timely manner, and the security and stability of system network communications are guaranteed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119577753B_ABST
    Figure CN119577753B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for detecting Linux system port multiplexing attacks. The method includes: detecting the first process of the setsockopt system call, obtaining the corresponding process information and sending it to the application layer; obtaining the first socket inode number in the first process information of the setsockopt system call through the application layer; obtaining the first socket corresponding to the first socket inode number in the socket socket data table, traversing the socket socket data table, and obtaining the second socket sharing the port with the first socket according to the port sharing detection rule; based on the first socket and the second socket, determining whether there is a corresponding port multiplexing attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call. Through the linkage detection between the system kernel and the application layer, the real-time automatic detection of port multiplexing attack behavior is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Linux attack detection, and in particular to a Linux system port multiplexing attack detection method and device. Background Art

[0002] Port multiplexing is a practical network programming technology. It is widely used in malicious attacks because it allows multiple processes to communicate through the open ports of the Linux system without affecting normal services. Attackers usually use this technology to bypass the server's port protection rules, process auditing, etc., to hide and disguise their malicious behavior.

[0003] Currently, there is no good automatic detection method for port reuse. Basically, auditing and screening process information and network information is done after the system is suspected of being invaded or on a regular basis to determine whether the system has port reuse risks. For example, netstat or ss is used to review the status of the process listening port to determine whether there are multiple processes listening to the same port. This method has great limitations and is not time-effective. For example, in a certain penetration attack, the attacker used port reuse technology to bypass network protection, hide their actual connection, and actively disconnect the malicious connection after uploading malicious files in the system. If the port reuse behavior is not discovered in time during this process, it is almost impossible to discover it by post-event tracing and auditing; moreover, it is impossible to collect various information at the first scene at this time, which is of no help for subsequent disposal links such as tracing the source and strengthening protection. In addition, active audit screening requires manual review or improvement of the network log audit system, which is also very complex and greatly increases the labor cost. Summary of the invention

[0004] The purpose of the embodiments of the present invention is to provide a Linux system port reuse attack detection method and device, which realizes real-time automatic detection of port reuse attack behavior through the linkage detection of the kernel and application layer of the Linux system, thereby effectively detecting potential security risks, ensuring the security and stability of the Linux system network communication, and avoiding information leakage, system abnormality and other problems caused by port reuse attacks.

[0005] To solve the above technical problems, a first aspect of an embodiment of the present invention provides a Linux system port reuse attack detection method, wherein the Linux system application layer includes a socket socket data table in a listening state, and the detection method includes the following steps:

[0006] Detect the first process of the setsockopt system call, obtain the first process information of the setsockopt system call and send it to the application layer;

[0007] Obtain the first socket inode number in the first process information of the setsockopt system call through the application layer;

[0008] Obtain the first socket corresponding to the first socket inode number in the socket socket data table, traverse the socket socket data table, and obtain the second socket sharing the port with the first socket according to the port sharing detection rule;

[0009] Based on the first socket and the second socket, determine whether there is a corresponding port multiplexing attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call corresponding to the second socket.

[0010] Further, the first process information of the setsockopt system call includes: the first setsockopt parameter;

[0011] After obtaining the first process information of the setsockopt system call, it further includes:

[0012] Judge whether the type of the first setsockopt parameter is the SO_REUSEADDR parameter or the SO_REUSEPORT parameter;

[0013] If so, execute the step of obtaining the first socket inode number in the first process information of the setsockopt system call through the application layer;

[0014] If not, discard the first process of the setsockopt system call.

[0015] Further, the first process information of the setsockopt system call includes: the first socket descriptor;

[0016] After obtaining the first process information of the setsockopt system call, it further includes:

[0017] Judge whether the first socket descriptor conforms to the Linux description rule;

[0018] If so, execute the step of obtaining the first socket inode number in the first process information of the setsockopt system call through the application layer;

[0019] If not, discard the first process of the setsockopt system call.

[0020] Further, the first information of the setsockopt system call process includes: the first socket descriptor and the first process pid;

[0021] Obtaining a second socket sharing a port with the first socket according to the port sharing detection rule includes:

[0022] Obtaining the inode number of the first socket of the first process information of the setsockopt system call based on the first socket descriptor and the first process pid;

[0023] Obtaining the first socket corresponding to the inode number of the first socket in the socket data table;

[0024] Traversing the socket data table, and obtaining at least one second socket sharing a port with the first socket in the socket data table according to the port sharing detection rule.

[0025] Furthermore, the socket data table includes: socket inode number, port information, protocol information, and local address information;

[0026] The port sharing detection rule includes: the port information of the first socket and the second socket is the same, the protocol information is the same, the local address information is the same, and the inode numbers are different.

[0027] Furthermore, determining whether there is a corresponding port multiplexing attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call corresponding to the second socket includes:

[0028] Obtaining the first process pid and the first process path of the first process of the setsockopt system call;

[0029] Obtaining the second process pid and the second process path of the second process of the setsockopt system call;

[0030] If the first process pid and the second process pid have no parent-child relationship and the first process path and the second process path are different, it is determined that there is a port multiplexing risk between the first process of the setsockopt system call and the second process of the setsockopt system call.

[0031] Furthermore, the socket data table is a non-unix domain socket.

[0032] Correspondingly, a second aspect of the embodiments of the present invention provides a Linux system port multiplexing attack detection device. The application layer of the Linux system includes a socket data table in a listening state. The detection device includes:

[0033] A process information acquisition module, which is used to detect the first process of the setsockopt system call, acquire the information of the first process of the setsockopt system call and send it to the application layer;

[0034] An inode number acquisition module, which is used to acquire the first socket inode number in the information of the first process of the setsockopt system call through the application layer;

[0035] A data table traversal module, which is used to acquire the first socket corresponding to the first socket inode number in the socket data table, traverse the socket data table, and acquire the second socket sharing the port with the first socket according to the port sharing detection rule;

[0036] A port multiplexing judgment module, which is used to judge whether there is a corresponding port multiplexing attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call corresponding to the second socket based on the first socket and the second socket.

[0037] Correspondingly, a third aspect of the embodiments of the present invention provides an electronic device, including: at least one processor; and a memory connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the above-mentioned Linux system port multiplexing attack detection method.

[0038] Correspondingly, a fourth aspect of the embodiments of the present invention provides a computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the above-mentioned Linux system port multiplexing attack detection method is implemented.

[0039] The above technical solutions of the embodiments of the present invention have the following beneficial technical effects:

[0040] 1. By detecting the first process of the setsockopt system call through the kernel and collecting its related information, including parameters, socket descriptors, process pids, process paths, etc., and accurately transmitting it to the application layer, it ensures that the starting data source for detection is reliable and closely related to the target detection content (port multiplexing situation), provides a comprehensive basis for subsequent analysis, avoids interference from irrelevant information, and enables the detection process to focus on processes and sockets that may involve port multiplexing;

[0041] 2. At the application layer, based on the information obtained from the kernel, by obtaining the inode number of the first socket, and then associating it with the first socket in the socket data table, and traversing the table to find the second socket according to the port sharing detection rules, using the inode number as a bridge, the socket information association and analysis method in the data table efficiently discovers socket pairs that may share ports. By utilizing the data table maintained by the application layer, it fully exploits the functions of the application layer in data processing and analysis, and can accurately and quickly locate potential sockets related to port multiplexing;

[0042] 3. By determining that two processes have no parent-child relationship and different process paths to identify whether there is a port multiplexing attack behavior, in-depth analysis from the process level accurately identifies abnormal port multiplexing situations, effectively differentiates normal port sharing (such as sharing between parent and child processes or different instances of the same application) and possible attack behaviors, thus providing strong support for ensuring system security, promptly detecting and responding to port multiplexing attacks. Description of the Drawings

[0043] Figure 1 is a flowchart of the method for detecting port multiplexing attacks in the Linux system provided by an embodiment of the present invention;

[0044] Figure 2 is a schematic diagram of the logic for detecting port multiplexing attacks in the Linux system provided by an embodiment of the present invention;

[0045] Figure 3 is a block diagram of the device for detecting port multiplexing attacks in the Linux system provided by an embodiment of the present invention.

[0046] Reference Numerals:

[0047] 1. Process Information Acquisition Module, 2. Inode Number Acquisition Module, 3. Data Table Traversal Module, 4. Port Multiplexing Judgment Module. Detailed Embodiments

[0048] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in conjunction with the specific embodiments and with reference to the accompanying drawings. It should be understood that these descriptions are exemplary and are not intended to limit the scope of the present invention. In addition, in the following descriptions, the descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present invention.

[0049] Under the Linux system, for port reuse technology, whether using iptables or other self-developed application-layer programs, fundamentally, it lies in utilizing the setsockopt system call. Through the SO_REUSEADDR or SO_REUSEPORT parameter of this system call, the purpose of multiple sockets using the same port is achieved. The present invention monitors the setsockopt system call in the kernel in real time, regards it as a potential port reuse event, sends its context information to the application layer, and in the application layer, by judging the SO_REUSEADDR / SO_REUSEPORT parameter, querying current system processes, network and other information to compare whether there is duplicate socket information, further screening and review are carried out to filter false alarms.

[0050] Please refer to Figure 1 and Figure 2 , the first aspect of the embodiment of the present invention provides a method for detecting port reuse attacks in the Linux system. The application layer of the Linux system includes a socket socket data table in the listening state. The detection method includes the following steps:

[0051] Step S100, detect the first process of the setsockopt system call, obtain the first process information of the setsockopt system call and send it to the application layer.

[0052] Step S200, obtain the first socket inode number in the first process information of the setsockopt system call through the application layer.

[0053] Step S300, obtain the first socket corresponding to the first socket inode number in the socket socket data table, traverse the socket socket data table, and obtain the second socket sharing the port with the first socket according to the port sharing detection rule.

[0054] Step S400, based on the first socket and the second socket, judge whether there is a corresponding port reuse attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call corresponding to the second socket.

[0055] First of all, the above detection method detects the setsockopt system call process at the system kernel level, indicating that the kernel plays a role at the starting stage of the entire detection process, responsible for real-time monitoring of this key event of the system call and collecting initial information; secondly, at the system application layer level, information reception and processing, data query and comparison, and attack behavior judgment are carried out, and finally the judgment of port reuse attack behavior is completed, clearly reflecting the characteristics of combining the Linux system kernel and application layer to achieve port reuse attack detection.

[0056] In an implementation manner of an embodiment of the present invention, the first process information of the setsockopt system call includes: the first setsockopt parameter.

[0057] After obtaining the first process information of the setsockopt system call in step S100, it further includes:

[0058] Step S111, determining whether the type of the first setsockopt parameter is the SO_REUSEADDR parameter or the SO_REUSEPORT parameter.

[0059] Step S112, if so, execute the step of obtaining the inode number of the first socket in the first process information of the setsockopt system call through the application layer;

[0060] Step S113, if not, discard the first process of the setsockopt system call.

[0061] After obtaining the first process information of the setsockopt system call in step S100, it is very important to judge the type of the first setsockopt parameter. Because only when the parameter type is the SO_REUSEADDR parameter or the SO_REUSEPORT parameter, the subsequent step of obtaining the inode number of the first socket through the application layer is executed. If it is not these two types of parameters, the first process of the setsockopt system call is directly discarded. This kind of judgment can screen out the process information of specific parameter types related to port reuse, avoid the ineffective processing of irrelevant process information, and thus improve the efficiency and accuracy of detecting port reuse attack behaviors.

[0062] In another implementation manner of an embodiment of the present invention, the first process information of the setsockopt system call includes: the first socket descriptor.

[0063] After obtaining the first process information of the setsockopt system call in step S100, it further includes:

[0064] Step S121, determining whether the first socket descriptor conforms to the Linux description rule.

[0065] Step S122, if so, execute the step of obtaining the inode number of the first socket in the first process information of the setsockopt system call through the application layer.

[0066] Step S123, if not, discard the first process of the setsockopt system call.

[0067] Only when the first socket descriptor meets the Linux description rules, will the step of obtaining the inode number of the first socket in the first process information of the setsockopt system call through the application layer continue to be executed. If it is illegal, the process will be directly discarded. This judgment process can effectively filter out invalid information caused by illegal socket descriptors, avoid interfering with subsequent processes, ensure that the detection process focuses on processing legal and meaningful process information, and thus improve the detection efficiency and accuracy.

[0068] In addition, the first information of the setsockopt system call process includes: the first socket descriptor and the first process pid.

[0069] Obtaining the second socket sharing the port with the first socket according to the port sharing detection rules in step 300 includes:

[0070] Step 310, obtaining the inode number of the first socket of the first process information of the setsockopt system call based on the first socket descriptor and the first process pid.

[0071] As one of the identifiers of the socket in the system, the socket descriptor combined with the process pid can accurately locate the relevant information of the target socket in the system, thus providing a basis for obtaining the inode number.

[0072] Step 320 obtains the first socket corresponding to the inode number of the first socket in the socket data table.

[0073] Based on the obtained inode number of the first socket, search in the socket data table to determine the corresponding first socket. The socket data table is a collection containing rich socket information. By accurately matching with the inode number, the first socket of interest can be found.

[0074] Step 330, traverse the socket data table, and obtain at least one second socket sharing the port with the first socket in the socket data table according to the port sharing detection rules.

[0075] Conduct a comprehensive traversal of the entire socket data table. During the traversal process, strictly filter according to the port sharing detection rules. These rules clarify the conditions for judging whether two sockets share the port. By comparing each socket in the data table one by one, find at least one second socket that meets these conditions and shares the port with the first socket.

[0076] The above traversal process can perform the port multiplexing judgment process every time a process is detected, or a time period can be set to perform the port multiplexing judgment on several detected and stored processes together.

[0077] Specifically, the socket data table includes: socket inode number, port information, protocol information, and local address information. The port sharing detection rules include: the port information, protocol information, and local address information of the first socket and the second socket are the same, and the inode numbers are different.

[0078] Ports are important identifiers used to distinguish different services or application processes in network communication. In network communication, a port usually corresponds to a specific service or application. When the port information of the first socket and the second socket is the same, it means that they may compete for the same communication resources at the network level or be maliciously exploited to interfere with normal port communication. For example, a normal Web service uses port 80 for HTTP communication. If another socket also uses port 80, it may cause service conflicts or be exploited by attackers to intercept traffic originally destined for the normal service.

[0079] The protocol determines the way, format, and rules for data transmission in the network. If the protocol information of the first socket and the second socket is the same, it means that they are consistent in the basic rules of data transmission. For example, when two sockets both use the TCP protocol, they follow the same rules in aspects such as establishing connections and ensuring the reliability of data transmission (such as the three-way handshake, data confirmation, and retransmission mechanisms, etc.). The existence of this rule is to ensure that the detected sockets that may share ports are in the same communication mode, so as to more accurately judge whether there is abnormal port multiplexing. Because the communication behaviors and potential risks of sockets with different protocols are very different even if their ports are the same. For example, TCP sockets focus on reliable data transmission, while UDP sockets focus more on fast data transmission and have a certain tolerance for data loss.

[0080] The local address information specifies the network location of the socket on the local machine. When the local address information of the first socket and the second socket is the same, it means that their positions in the local network environment are the same. This helps to narrow the detection scope and focus on the possible port multiplexing situations at the same local network endpoint. For example, on a server with multiple network interfaces, only sockets with the same local address may have port multiplexing conflicts or security risks locally. If the local addresses are different, they are in different physical or logical network connections, and the risks and impact ranges of port multiplexing will also be different.

[0081] An inode number is a number used in a file system to uniquely identify a file or resource (including sockets). Requiring different inode numbers for the first socket and the second socket is to ensure that two different socket entities are detected. If the inode numbers are the same, then they are actually the same socket, and there is no such thing as "sharing a port". This rule is an important supplement to the entire detection rule, which can accurately screen out different socket combinations that may actually have the risk of port multiplexing and avoid misjudgment.

[0082] Furthermore, determining whether there is a corresponding port multiplexing attack behavior in the setsockopt system call of the first process and the setsockopt system call of the second process corresponding to the second socket in step S400 includes:

[0083] Step S410, obtain the first process pid and the first process path of the setsockopt system call of the first process.

[0084] Step S420, obtain the second process pid and the second process path of the setsockopt system call of the second process.

[0085] The process pid (process identifier) is a number used by the system to uniquely identify each process. During the entire system operation, different processes can be accurately located and distinguished through the pid. The process path records the location of the process in the file system and can reflect the application or service to which the process belongs. For example, in the Linux system, a Web server process may be located at a path like " / usr / local / apache / bin / httpd", and through the process path, the source and software components to which the process belongs can be understood.

[0086] Obtaining these two pieces of information provides an effective basis for subsequent determination of port multiplexing attack behavior. If different processes communicate through a shared port or interfere with the normal use of the port, then their identities (pids) and sources (process paths) are important factors for determining whether such sharing is reasonable.

[0087] Step S430, if the first process pid and the second process pid have no parent-child relationship and the first process path and the second process path are different, then it is determined that there is a port multiplexing risk in the setsockopt system call of the first process and the setsockopt system call of the second process.

[0088] When the first process PID and the second process PID have no parent-child relationship and the first process path is different from the second process path, it is determined that there is a risk of port reuse. In normal system operations, some resources, including ports, may be shared between parent and child processes. For example, a main process may spawn multiple child processes to handle different tasks, and these child processes may legally share some ports for communication under the management of the parent process. Therefore, if two processes have a parent-child relationship, their sharing of ports may be allowed for the normal operation of the system.

[0089] Similarly, even if two processes have no parent-child relationship, but if their process paths are the same, this may mean that they belong to different instances of the same application or service. In some cases, it is normal design for different instances of the same application to share ports. For example, some load-balanced application servers may have multiple instances of the same service, and share ports through reasonable configuration to improve the performance and availability of the system.

[0090] However, when two processes have neither a parent-child relationship nor come from different process paths, this situation of port sharing is rather suspicious and is very likely an abnormal port reuse. It may be that malware is trying to hide its communication by sharing the ports of legitimate services, or an attacker is trying to interfere with normal network services by occupying legitimate ports. Determining the risk of port reuse in this case can help users detect and handle potential security threats in a timely manner, and ensure the normal order and security of system network communication.

[0091] In addition, the socket socket data table is for non-Unix domain sockets. The socket socket data table is for non-Unix domain sockets. Non-Unix domain sockets are mainly used for network communication, involving process communication between different hosts or between the same host and an external network, and data transmission is achieved according to network protocols (such as TCP / IP, UDP / IP, etc.). Different from Unix domain sockets, the data of non-Unix domain sockets needs to go through the complete network protocol stack for processing, including the network layer, transport layer, etc. Since the socket socket data table is related to non-Unix domain sockets, it means that the socket information recorded in the table mainly revolves around network communication sockets. For example, the port information therein is crucial for network communication because different ports are used to distinguish different network services. For example, port 80 is commonly used for HTTP services, and port 443 is commonly used for HTTPS services. These port information are used in the data table of non-Unix domain sockets to identify and manage the service types of network communication.

[0092] Accordingly, please refer to Figure 3, in the second aspect of the embodiments of the present invention, a Linux system port multiplexing attack detection device is provided. The application layer of the Linux system includes a socket socket data table in a listening state. The detection device includes:

[0093] A process information acquisition module 1, which is used to detect the first process of the setsockopt system call, acquire the first process information of the setsockopt system call and send it to the application layer;

[0094] An inode number acquisition module 2, which is used to acquire the first socket inode number in the first process information of the setsockopt system call through the application layer;

[0095] A data table traversal module 3, which is used to acquire the first socket corresponding to the first socket inode number in the socket socket data table, traverse the socket socket data table, and acquire the second socket sharing the port with the first socket according to the port sharing detection rule;

[0096] A port multiplexing judgment module 4, which is used to judge whether there is a corresponding port multiplexing attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call corresponding to the second socket based on the first socket and the second socket.

[0097] Correspondingly, in the third aspect of the embodiments of the present invention, an electronic device is provided, including: at least one processor; and a memory connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the above-mentioned Linux system port multiplexing attack detection method.

[0098] Correspondingly, in the fourth aspect of the embodiments of the present invention, a computer-readable storage medium is provided, on which computer instructions are stored, and when the instructions are executed by a processor, the above-mentioned Linux system port multiplexing attack detection method is implemented.

[0099] An embodiment of the present invention aims to protect a method and device for detecting Linux system port multiplexing attacks. The application layer of the Linux system includes a socket socket data table in a listening state. The detection method includes the following steps: detecting the first process of the setsockopt system call, obtaining the information of the first process of the setsockopt system call and sending it to the application layer; obtaining the first socket inode number in the information of the first process of the setsockopt system call through the application layer; obtaining the first socket corresponding to the first socket inode number in the socket socket data table, traversing the socket socket data table, and obtaining the second socket sharing the port with the first socket according to the port sharing detection rule; based on the first socket and the second socket, determining whether there is a corresponding port multiplexing attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call corresponding to the second socket. The above technical solution has the following effects:

[0100] 1. By detecting the first process of the setsockopt system call in the kernel and collecting its relevant information, including parameters, socket descriptors, process pids, process paths, etc., and accurately transmitting it to the application layer, it ensures that the initial data source for detection is reliable and closely related to the target detection content (port multiplexing situation), provides a comprehensive basis for subsequent analysis, avoids interference from irrelevant information, and enables the detection process to focus on processes and sockets that may be involved in port multiplexing;

[0101] 2. In the application layer, based on the information obtained from the kernel, by obtaining the first socket inode number, and then associating it with the first socket in the socket socket data table, and traversing the table to find the second socket according to the port sharing detection rule, the way of socket information association and analysis in the data table with the inode number as the bridge efficiently mines the socket pairs that may have the situation of sharing ports, utilizes the data table maintained by the application layer, gives full play to the functions of the application layer in data processing and analysis, and can accurately and quickly locate the potential sockets related to port multiplexing;

[0102] 3. By determining whether there is a port multiplexing attack behavior by judging that the two processes have no parent-child relationship and different process paths, analyzing deeply from the process level, accurately identifying abnormal port multiplexing situations, effectively distinguishing normal port sharing (such as sharing between parent and child processes or different instances of the same application program) and possible attack behaviors, thus providing strong support for ensuring system security, timely discovering and dealing with port multiplexing attacks.

[0103] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.

[0104] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.

[0105] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.

[0106] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.

[0107] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: the specific implementation manners of the present invention can still be modified or equivalently replaced, and any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.

Claims

1. A method for detecting Linux system port multiplexing attacks, characterized in that, The application layer of the Linux system includes a socket socket data table in a listening state, and the detection method includes the following steps: Detect the first process of the setsockopt system call, obtain the information of the first process of the setsockopt system call, and send it to the application layer; Obtain the first socket inode number in the information of the first process of the setsockopt system call through the application layer; Obtain the first socket corresponding to the first socket inode number in the socket socket data table, traverse the socket socket data table, and obtain the second socket sharing the port with the first socket according to the port sharing detection rule; Based on the first socket and the second socket, determine whether there is a corresponding port reuse attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call corresponding to the second socket.

2. The Linux system port multiplexing attack detection method according to claim 1, characterized in that The information of the first process of the setsockopt system call includes: the first setsockopt parameter; After obtaining the information of the first process of the setsockopt system call, it further includes: Judge whether the type of the first setsockopt parameter is the SO_REUSEADDR parameter or the SO_REUSEPORT parameter; If so, execute the step of obtaining the first socket inode number in the information of the first process of the setsockopt system call through the application layer; If not, discard the first process of the setsockopt system call.

3. The Linux system port multiplexing attack detection method according to claim 1, characterized in that The information of the first process of the setsockopt system call includes: the first socket descriptor; After obtaining the information of the first process of the setsockopt system call, it further includes: Judge whether the first socket descriptor conforms to the Linux description rule; If so, execute the step of obtaining the first socket inode number in the information of the first process of the setsockopt system call through the application layer; If not, discard the first process of the setsockopt system call.

4. The method for detecting Linux system port multiplexing attacks according to claim 1, wherein The first information of the setsockopt system call process includes: the first socket descriptor and the first process pid; The step of obtaining the second socket sharing the port with the first socket according to the port sharing detection rule includes: Obtain the first socket inode number of the information of the first process of the setsockopt system call according to the first socket descriptor and the first process pid; Obtain the first socket corresponding to the first socket inode number in the socket socket data table; Traverse the socket socket data table, and obtain at least one second socket sharing the port with the first socket in the socket socket data table according to the port sharing detection rule.

5. The method for detecting port reuse attack in a Linux system according to claim 4, wherein The socket data table includes: socket inode number, port information, protocol information, and local address information; The port sharing detection rule includes: the port information, protocol information, and local address information of the first socket and the second socket are the same, and the inode numbers are different.

6. The method for detecting Linux system port multiplexing attacks according to claim 1, characterized in that Judging whether there is a corresponding port reuse attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call corresponding to the second socket includes: Obtaining the first process pid and the first process path of the first process of the setsockopt system call; Obtaining the second process pid and the second process path of the second process of the setsockopt system call; If there is no parent-child relationship between the first process pid and the second process pid and the first process path and the second process path are different, it is determined that there is a port reuse risk between the first process of the setsockopt system call and the second process of the setsockopt system call.

7. The Linux system port reuse attack detection method according to any one of claims 1-6, characterized in that The socket data table is a non-unix domain socket.

8. A Linux system port multiplexing attack detection device, characterized in that, The application layer of the Linux system includes a socket data table in a listening state, and the detection device includes: A process information acquisition module, which is used to detect the first process of the setsockopt system call, acquire the first process information of the setsockopt system call and send it to the application layer; An inode number acquisition module, which is used to acquire the first socket inode number in the first process information of the setsockopt system call through the application layer; A data table traversal module, which is used to acquire the first socket corresponding to the first socket inode number in the socket data table, traverse the socket data table, and acquire the second socket sharing the port with the first socket according to the port sharing detection rule; A port reuse judgment module, which is used to judge whether there is a corresponding port reuse attack behavior between the first process of the setsockopt system call and the second process of the setsockopt system call corresponding to the second socket based on the first socket and the second socket.

9. An electronic device, characterized in that, Includes: At least one processor; And a memory connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the Linux system port reuse attack detection method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, Stored thereon are computer instructions, which when executed by a processor implement the Linux system port reuse attack detection method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Advanced persistent threat detection method based on aggressive behavior analysis

    CN105871883A

  • Mobile terminal to detect network attack and method thereof

    US20130227687A1