Equipment security protection method under eBPF, equipment, program product and medium

By storing and matching device security policies using hash mapping and bitmap formats in the eBPF environment, performance bottlenecks and complexity problems in traditional methods are solved, efficient policy storage and matching is achieved, and system performance is improved.

CN119939554AActive Publication Date: 2025-05-06LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Patent Information

Application Number
CN202510080940.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-06
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

In the eBPF environment, traditional device security policy storage and matching methods have performance bottlenecks and complexity problems, making it difficult to achieve efficient policy storage and matching.

Method used

The device security policies are stored using hash mapping and bitmap formats, and the hash mapping tables and bitmap tables are used to achieve efficient matching and management of policies.

Benefits of technology

It realizes efficient storage and matching of device security policies in eBPF environment, reduces memory usage and processing time, and improves system performance and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939554A_ABST
    Figure CN119939554A_ABST
Patent Text Reader

Abstract

The invention discloses an equipment security protection method under eBPF, equipment, a program product and a medium, and relates to the technical field of equipment security. The method comprises the following steps: determining a target equipment security policy, and issuing the target equipment security policy; performing policy storage on the issued target equipment security policy by adopting a hash mapping form and a bitmap form to correspondingly obtain first structural data and second structural data; capturing an operation event and determining a subject path and an object path in the operation event; performing strategy matching with the first structure data by using the subject path and the object path respectively, and performing strategy matching on the obtained first matching result and the second structure data; and determining a permission determination result by using the obtained second matching result, and processing the operation event according to the permission determination result. Through the technical scheme of the invention, efficient storage and matching of the equipment security policy can be realized, and the problems of performance bottleneck and complexity in a traditional method are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of device security technology, and in particular to a device security protection method, device, program product and medium under eBPF. Background Art

[0002] In modern device security management, the configuration and management of device security policies are important links in protecting computer systems from attacks. Traditional security policies are based on the kernel's device security model, which usually relies on complex data structures such as rule tables and access control lists (ACLs). These methods may lead to performance bottlenecks and management difficulties. eBPF (Extended Berkeley Packet Filter) is an extension mechanism of the Linux kernel that allows developers to execute custom code in kernel space. It is widely used in network traffic filtering, performance monitoring, and security analysis. With the rise of eBPF technology, the development of device security protection software based on eBPF enables developers to get rid of their dependence on the kernel, thereby avoiding various system problems. However, the mapping mechanism (Maps) provided by eBPF for storing data is not fully applicable to the storage and matching of security policies in device security protection software. Therefore, in practical applications, efficient device security policy storage and matching in the eBPF environment still faces challenges, and the implementation effect is not ideal. Summary of the invention

[0003] In view of this, the purpose of the present invention is to provide a device security protection method, device, program product and medium under eBPF, which can realize efficient storage and matching of device security policies and effectively solve the performance bottleneck and complexity problems in traditional methods. The specific scheme is as follows: In a first aspect, the present application discloses a device security protection method under eBPF, including: Determine the target device security policy and issue the target device security policy; The issued target device security policy is stored in a hash mapping form and a bitmap form respectively, so as to obtain the first structure data and the second structure data accordingly; When an operation event on a file or directory is detected, the subject path and object path in the operation event are determined; an operation event is an event in which a subject operates an object, the subject is the process of operating the file or directory, and the object is the file or directory to be protected; Performing strategy matching with the first structure data using the subject path and the object path respectively to determine a first matching result, and performing strategy matching with the first matching result and the second structure data to determine a second matching result; Determine whether the subject in the operation event has the operation authority for the object according to the second matching result to obtain a corresponding authority determination result, and process the operation event according to the authority determination result.

[0004] Optionally, before determining the target device security policy, the following steps are also included: Define the device security policy according to a preset rule format; wherein the preset rule format includes an object part, a subject part, a permission part, a rule part, and a policy priority part; Accordingly, determine the target device security policy and issue the target device security policy, including: Determine the target device security policy based on the current application scenario, and issue the target device security policy based on preset format rules.

[0005] Optionally, define the permissions section in the device security policy, including: A first flag is set for the permission to indicate that any operation behavior is prohibited; A second flag for indicating a read-only permission is set for the permission; A third identifier for indicating writable permission is set for the permission; A fourth identifier for representing executable permissions is set for the permissions.

[0006] Optionally, determine the target device security policy and issue the target device security policy, including: Determine the target device security policy and issue it to the target device through the command line or through the graphical user interface.

[0007] Optionally, the issued target device security policy is stored in a hash mapping form to obtain first structure data, including: An object hash map is constructed using the object portion and the policy priority portion in the target device security policy; Constructing a subject hash map using the subject part and the policy priority part in the target device security policy; Constructing a permission hash map using the policy priority part and the permission part in the target device security policy; The first structure data is determined according to the object hash mapping table, the subject hash mapping table and the permission hash mapping table; wherein the object hash mapping table, the subject hash mapping table and the permission hash mapping table are stored in the form of key-value pairs.

[0008] Optionally, the device security protection method under eBPF of the present application further includes: Determine a first target device security policy and a second target device security policy; wherein the second target device security policy is a device security policy stored after the first target device security policy is stored; When it is determined according to the preset rule format that there is an identical portion between the first target device security policy and the second target device security policy, determining a target key of the identical portion in the corresponding mapping table; The value corresponding to the target key is updated using the different parts between the second target device security policy and the first target device security policy.

[0009] Optionally, the target device security policy is stored in a bitmap format to obtain second structure data, including: A bitmap is constructed based on the policy priority part in the target device security policy, and each bit in the bitmap corresponds to a target device security policy to obtain second structure data; wherein the lower the bit in the second structure data, the higher the priority corresponding to the target device security policy.

[0010] Optionally, performing strategy matching with the first structure data using the subject path and the object path respectively to generate a first matching result includes: Matching the subject path with the subject hash map to determine the first priority corresponding to the subject path; Matching the object path with the object hash mapping table to determine a second priority corresponding to the object path; A bitwise AND operation is performed on the first priority level and the second priority level to determine a first matching result.

[0011] Optionally, performing strategy matching on the first matching result and the second structure data to determine a second matching result includes: A bitwise AND operation is performed on the first matching result and the complement of the first matching result, and the generated bitmap result is matched with the second structure data to determine a second matching result.

[0012] Optionally, matching the generated bitmap result with the second structure data to determine a second matching result includes: Determine the first low bit in the bitmap result that is not 0, and determine the target priority corresponding to the low bit according to the second structure data; the target priority is the priority corresponding to the permission when executing the operation behavior in the operation event; Correspondingly, determining whether the subject in the operation event has the operation authority over the object according to the second matching result to obtain the corresponding authority determination result includes: Match the target priority with the permission hash map to determine the target permission corresponding to the target priority; Determine whether the subject in the operation event has the operation authority for the object according to the target authority, so as to obtain the corresponding authority determination result.

[0013] Optionally, process the operation event based on the permission determination result, including: When the subject in the operation event has the operation authority over the object, the operation behavior in the operation event is released; When the subject in the operation event does not have the operation authority for the object, the operation behavior in the operation event is intercepted and processed.

[0014] Optionally, the device security protection method under eBPF of the present application further includes: When there is a third target device security policy that needs to be deleted in the target device security policy, the current first structure data and the current second structure data are deleted, and new first structure data and new second structure data are re-determined based on the third target device security policy.

[0015] In a second aspect, the present application discloses an electronic device, comprising: Memory for storing computer programs; A processor is used to load and execute a computer program to implement the aforementioned device security protection method under eBPF.

[0016] In a third aspect, the present application discloses a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the aforementioned device security protection method under eBPF.

[0017] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein the computer program, when executed by a processor, implements the aforementioned device security protection method under eBPF.

[0018] The present application provides a device security protection method under eBPF, including: determining a target device security policy and issuing the target device security policy; storing the issued target device security policy in a hash mapping form and a bitmap form respectively, so as to obtain first structure data and second structure data accordingly; after an operation event on a file or directory is monitored, determining a subject path and an object path in the operation event; the operation event is an event in which a subject operates an object, the subject is a process that operates a file or directory, and the object is a file or directory to be protected; performing policy matching with the first structure data using the subject path and the object path respectively, so as to determine a first matching result, and performing policy matching with the second structure data, so as to determine a second matching result; determining whether the subject in the operation event has operation authority over the object according to the second matching result, so as to obtain a corresponding authority determination result, and processing the operation event according to the authority determination result.

[0019] The beneficial technical effects of the present application are: in the eBPF environment, the mapping mechanism provided by the kernel is used to store data structures. The present invention adopts the storage form of hash mapping and bitmap to apply bitmaps to the eBPF environment. As an efficient data structure, the bitmap can process a large amount of data with a small memory footprint and a fast speed, and realize the effective storage and efficient matching of device security policies in the eBPF environment.

[0020] In addition, the device security protection device, program product and medium under eBPF provided by the present application correspond to the device security protection method under eBPF mentioned above, and the effect is the same as above. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0022] Figure 1 This is a flow chart of a device security protection method under eBPF disclosed in this application; Figure 2 This is a block diagram of a device security protection system under eBPF disclosed in this application; Figure 3 A schematic diagram of a strategy storage disclosed in this application; Figure 4 A schematic diagram of device security protection strategy storage and matching under eBPF disclosed in this application; Figure 5This is a schematic diagram of the structure of a device safety protection device under eBPF disclosed in this application; Figure 6 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0023] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0024] In the field of device security, a common function of security policies is to protect a file, that is, whether a process under a certain user has read, write, and execute permissions for this file. To achieve this function, the usual practice is to mount hooks on the kernel functions __x64_sys_open and __x64_sys_execve corresponding to the open function and the execve function; then obtain the three parameters of the subject and object absolute path and the desired operation in the hook function; match the obtained absolute path with the rules in the rule base to determine whether to allow or prohibit the subject from operating on the object. In this traditional kernel-based device security mode, the rules in the rule base are stored based on a bidirectional linked list, and it is relatively easy to implement the addition, deletion, and modification of policies, matching, and a node in the linked list as the head of another linked list. However, traditional device security protection software is developed based on kernel mode, which is very likely to cause system crashes, resulting in irreversible consequences for customer business.

[0025] With the rise of eBPF technology, the development of device security protection software based on eBPF enables developers to get rid of their dependence on the kernel, thus avoiding various system problems. eBPF uses the mapping mechanism provided by the kernel to store data structures, which can be used to store device security protection policies. Commonly used mapping types include hash tables, arrays, queues, etc. However, the shortcomings of these mapping types are also obvious. For example, in the file access control based on eBPF, due to the disorder of hash maps, after adding rules to the rule base, it is not certain which one will be matched first during matching; one disadvantage of array mapping is that the elements in the mapping cannot be deleted, and the array cannot be made smaller; that is, after adding rules, the rules cannot be deleted; for queue mapping, when initializing the mapping, the key size must be 0, and when the elements are written to the mapping, the key must be a null value, so the mapping key cannot be used for search. It can be seen that efficient device security policy storage and matching in the eBPF environment still faces challenges, especially when dealing with large-scale policy sets and real-time updates.

[0026] To this end, the present application provides a device security protection solution under eBPF, which can achieve efficient storage and matching of device security policies, and can effectively solve the problem of system crashes that are very easy to cause in traditional methods, as well as the problem of inability to effectively store policies and efficiently match in the eBPF environment.

[0027] The embodiment of the present invention discloses a device security protection method under eBPF, see Figure 1 As shown, the method includes: Step S11: Determine the target device security policy and issue the target device security policy.

[0028] Device security policy is an important measure to ensure the security of devices in computer systems and network environments. It can usually determine whether to allow or prohibit the subject from operating the object. In different application scenarios, as long as there is a judgment on the operating authority of the object, it is necessary to set the corresponding device security policy. It is widely used in fields such as network traffic filtering, performance monitoring and security analysis. For example, the device security policy can be a policy at the operating system security level, a policy at the data security level, a policy at the network security level, a policy at the application security level, and so on. For ease of understanding, the following embodiments are all explained by taking the target device security policy as an example of a policy configured by the system administrator for protection of files or directories.

[0029] In an embodiment of the present application, the composition of the policy is first defined before the policy is issued. Specifically, the device security policy is defined according to a preset rule format; wherein the preset rule format includes an object part, a subject part, a permission part, a rule part, and a policy priority part. It can be seen that each policy consists of five parts, namely object, subject, permission (mode), rule (ruleid), and priority (prior). Among them, the object represents the file or directory to be protected, the subject represents the process of operating the file or directory, the permission represents the type of operation allowed or denied, such as read, write, execute, the rule id represents the number of each policy, and the priority represents the priority of each policy, which is used to decide which policy to adopt in case of conflict.

[0030] Furthermore, after determining the target device security policy according to the current application scenario, the target device security policy is issued based on a preset format rule, that is, the required target device security policy is issued according to the components defined by the policy.

[0031] Step S12: The issued target device security policy is stored in a hash mapping format and a bitmap format respectively, so as to obtain first structure data and second structure data accordingly.

[0032] In the embodiment of the present application, after the target device security policy is issued, the issued policy is stored in the form of a hash map and a bitmap, specifically, in three hash maps and corresponding bitmaps.

[0033] In a specific implementation, a hash mapping form is used to store the policy of the issued target device security policy to obtain the first structure data, which specifically includes: constructing an object hash mapping table using the object part and the policy priority part in the target device security policy; constructing a subject hash mapping table using the subject part and the policy priority part in the target device security policy; constructing a permission hash mapping table using the policy priority part and the permission part in the target device security policy; determining the first structure data based on the object hash mapping table, the subject hash mapping table and the permission hash mapping table; wherein the object hash mapping table, the subject hash mapping table and the permission hash mapping table are stored in the form of key-value pairs.

[0034] It can be seen that, since the mapping mechanism provided by the kernel can be used to store data structures under eBPF, the target device security policy is stored in the form of a hash map. The first structure data obtained includes three hash mapping tables, namely, the object hash mapping table, the subject hash mapping table, and the permission hash mapping table. When adding a policy, the corresponding parameter values ​​are stored in the table respectively. The hash mapping table is stored in the form of a key-value pair, and the corresponding value can be queried according to the corresponding key.

[0035] In another specific implementation, the target device security policy is stored in a bitmap format to obtain second structure data, specifically including: constructing a bitmap based on the policy priority portion of the target device security policy, and making each bit in the bitmap correspond to a target device security policy to obtain the second structure data; wherein, the lower the bit in the second structure data, the higher the priority corresponding to the target device security policy.

[0036] It can be seen that the second structure data corresponds to bitmap storage. As an efficient data structure, bitmap can process large amounts of data with small memory usage and high speed. The bitmap structure has a fixed size and simple bit operations. The priority of the policy can be determined based on the bitmap, and a bit in the bitmap represents a policy. A bit of 1 indicates that there is a policy, and a bit of 0 indicates that there is no policy. Applying the bitmap in the eBPF environment can achieve efficient storage and matching of device security policies.

[0037] Step S13: after an operation event on a file or directory is detected, the subject path and the object path in the operation event are determined.

[0038] The operation event is an event in which the subject operates the object. The subject is the process of operating the file or directory, and the object is the file or directory to be protected.

[0039] Furthermore, the subject path is the location information of the subject. In the scenario of protecting files or directories, the subject may be a user process, and the location of the executable file of this process is the subject path. For example, in a certain operating system, assuming that the user operates a file through the process " / user / bin / touch", then the path of " / user / bin / touch" is the subject path, which represents the location information of the initiator of the operation. The object path is the location information of the object. In the scenario of protecting files or directories, since the object is the object of the subject operation, the object path at this time is the path of the operated file or directory (such as read, write, delete, etc.). For example, in a certain operating system, when a process wants to modify the " / root / a.txt" file, the path of " / root / a.txt" is the object path, which represents the location information of the file in the storage device.

[0040] Step S14: Performing strategy matching with the first structure data using the subject path and the object path respectively to determine a first matching result, and performing strategy matching with the first matching result and the second structure data to determine a second matching result.

[0041] In the embodiment of the present application, when the eBPF program monitors an operation event on a file, it obtains the subject path and object path of the event, and matches them with the policies stored in the first structure data and the second structure data in turn. The policy matching process is used to determine whether the subject in the operation event has the operation authority on the object. Therefore, in the scenario of protecting files or directories, the policy matching process is to determine whether a process can perform corresponding operations on files or directories.

[0042] It should be pointed out that both the first matching result and the second matching result are embodied in the form of bitmap values. When the subject and object paths are matched with the first structure data respectively, their corresponding priorities will be obtained accordingly, and the two priorities will be further used to determine the first matching result. Since the second structure data can be used to determine how many policies are currently stored and what the corresponding priorities are. Moreover, in the second structure data, the lower the bit, the higher the priority corresponding to the target device security policy. Therefore, after matching the first matching result with the second structure data, the obtained second matching result can be used to characterize the target priority corresponding to the permission when executing the operation behavior in the operation event, as well as how many target device security policies are matched.

[0043] Step S15: Determine whether the subject in the operation event has the operation authority for the object according to the second matching result, so as to obtain a corresponding authority determination result, and process the operation event according to the authority determination result.

[0044] After the policy matching is completed, since the second matching result can be used to characterize the target priority corresponding to the authority when executing the operation behavior in the operation event, the corresponding authority can be determined according to the target priority. Further, the authority determination result of whether the subject has the operation authority for the object in the current operation event is determined according to the authority. According to the authority determination result, it can be determined how to handle the operation event and decide whether to intercept or release the operation behavior therein. It can be understood that if the subject has the operation authority for the object, the operation behavior in the operation event will be released; if the subject does not have the operation authority for the object, the operation behavior in the operation event will be intercepted.

[0045] like Figure 2 The figure shows the overall system structure of a bitmap-based device security policy storage and matching system under eBPF according to the exemplary embodiment. First, define the composition of the policy, then issue the required policy, and store the issued policy in three hash mapping tables and corresponding bitmaps. When the operation event of the file is monitored, the subject and object path of the event will be obtained and matched with the policy stored in the hash mapping table and bitmap to decide whether to intercept or release.

[0046] The beneficial technical effects of the present application are: in the eBPF environment, the mapping mechanism provided by the kernel is used to store data structures. The present invention adopts the storage form of hash mapping and bitmap to apply bitmaps to the eBPF environment. As an efficient data structure, the bitmap can process a large amount of data with a small memory footprint and a fast speed, and realize the effective storage and efficient matching of device security policies in the eBPF environment.

[0047] In a specific implementation, if the current application scenario is a scenario of protecting files, when issuing policies, the policies are issued using a command line or a graphical user interface. When issuing policies using a graphical user interface, a management platform can be developed to operate on the graphical interface to issue policies. When issuing policies using a command line, the target device security policy is issued using a command line according to the preset format rules when the policy is defined.

[0048] Take the command line method as an example, such as . / config mac_file add 1 / usr / bin / touch 0 / root / a.txt 1, which is a policy issued. Among them, the id of the rule part is 1, the subject part is / usr / bin / touch, the subject's permission to the object is 0, the object part is / root / a.txt, and the priority of this rule is specified as 1.

[0049] In a feasible implementation, when defining the permissions portion in a device security policy, the following steps may be included: setting a first identifier for the permission to represent that any operation behavior is prohibited; setting a second identifier for the permission to represent read-only permission; setting a third identifier for the permission to represent writable permission; and setting a fourth identifier for the permission to represent executable permission.

[0050] For example, permission 0 indicates prohibiting any operation, 1 indicates read-only permission, 2 indicates write permission, and 4 indicates executable permission.

[0051] According to the set identifier, two policies are issued: . / config mac_file add 2 / usr / bin / touch 1 / root / a.txt 2 and . / config mac_file add 3 / usr / bin / touch 4 / root / b.txt 4.

[0052] Based on the above embodiment, when performing strategy storage, a storage strategy of 3 hash maps and 1 bitmap is adopted. When adding a strategy, the corresponding parameter values ​​are stored in the table respectively. Among them, the hash map is stored in the form of key-value pairs, and the corresponding value can be queried according to the corresponding key.

[0053] like Figure 3 As shown in the figure, since the object hash map is constructed using the object part and the policy priority part of the target device security policy, in the object hash map, the key (keyid) stores the rule id, and the value (value) stores the object path (object_path) and priority (prior). For example, when adding the first policy, the key in the object hash map is 1, and the value consists of two parts, namely the object path " / root / a.txt" and the priority 1=2^0.

[0054] Similarly, since the subject hash map is constructed using the subject part and policy priority part of the target device security policy, the key (keyid) in the subject hash map stores the rule id, and the value (value) stores the subject path (subject_path) and priority (prior). When adding the first policy, the key in the subject hash map is 1, and the value consists of two parts, namely the subject path " / usr / bin / touch" and the priority 2^0.

[0055] Since the permission hash map (mode hash map) is constructed using the policy priority part and permission part in the target device security policy, in the permission hash map, the key (keyid) corresponds to the priority (prior) and the value (value) corresponds to the permission (mode). When adding the first policy, the key in the permission hash map is 2^0 and the value is access right 0.

[0056] It should be noted that, for the policies issued in this embodiment, when storing the policies, the next policy can be stored after the previous policy is stored, so as to update the first structure data. In a specific implementation, the process of storing multiple target device security policies may include the following steps: Determine a first target device security policy and a second target device security policy; wherein the second target device security policy is a device security policy stored after the first target device security policy is stored; When it is determined according to the preset rule format that there is an identical portion between the first target device security policy and the second target device security policy, determining a target key of the identical portion in the corresponding mapping table; The value corresponding to the target key is updated using the different parts between the second target device security policy and the first target device security policy.

[0057] like Figure 3 As shown in the figure, when adding the second policy, the key in the object hash map is 2, the object path in the value is " / root / a.txt", and the priority should be 2=2^1. However, since the object path of the second policy is the same as that of the first policy, the two policies can be merged in the object hash map. That is, based on the first policy, the priority in the value is updated to 3=2^0 | 2^1. Similarly, in the subject hash map, since the subject of the second policy is the same as that of the first policy, it is only necessary to update the priority based on the first policy. The updated priority is 3=2^0 | 2^1. In the permission hash map, the priority is 2^1 and the permission is 1.

[0058] When adding the third policy, in the object hash map, since the first two policies are merged, the key is 2, the object path in the value is " / root / b.txt", and the priority is 4=2^2 in order; in the subject hash map, since the third policy has the same subject as the first two policies, it is only necessary to continue to update the priority based on the first two policies. The updated priority is 7=2^0 | 2^1 | 2^2.

[0059] Further, based on the above embodiment, this embodiment will specifically explain S14 in the above embodiment. The process of using the subject path and the object path to perform strategy matching with the first structure data to generate the first matching result may include the following steps: Matching the subject path with the subject hash map to determine the first priority corresponding to the subject path; Matching the object path with the object hash mapping table to determine a second priority corresponding to the object path; A bitwise AND operation is performed on the first priority level and the second priority level to determine a first matching result.

[0060] The current device security protection software under eBPF is developed based on kernel modules, which can cause system downtime if not handled with care. While eBPF technology can solve the problem of system downtime, the data structure it provides cannot effectively store and efficiently match device security policies. Therefore, the present invention proposes a policy storage format using bitmap+hash map under eBPF, which are the object part, the subject part, the permission part, the rule part, and the policy priority part. Each policy is stored in three hash mapping tables. When matching policies, each matching item is checked in the corresponding hash map, and the two found priorities are bitwise ANDed (intersection is taken) to obtain a bitmap value, which is the first matching result.

[0061] For example, to execute touch / root / a.txt, by traversing the subject hash mapping table, you can match / usr / bin / touch, and then get the first priority of 7=2^0 | 2^1 | 2^2; by traversing the object hash mapping table, you can match / root / a.txt, and then get the second priority of 3=2^0 | 2^1; the two priorities are bitwise ANDed to get the first matching result, that is, 0011 = 3&7, 0011 means that two policies with the same subject and object but different permissions are matched.

[0062] It should be pointed out that after obtaining the first matching result, the first matching result is strategically matched with the second structure data to determine the second matching result, specifically: the first matching result is bitwise ANDed with the complement of the first matching result, and the generated bitmap result is matched with the second structure data to determine the second matching result. Among them, the generated bitmap result is matched with the second structure data to determine the second matching result, specifically: determine the first low bit in the bitmap result that is not 0, and determine the target priority corresponding to the low bit according to the second structure data; the target priority is the priority corresponding to the permission when executing the operation behavior in the operation event.

[0063] Exemplarily, since the lower the bit, the higher the priority, and the earlier the match, the first matching result and the complement of the first matching result are bitwise ANDed. That is, a bitmap&= -bitmap operation is performed to obtain a binary number with only one bit being 1. For example, 0011&(-0011) can obtain 0001=1, that is, the lowest bit is 1. After matching the bitmap result with the second structure data, the second matching result determined corresponds to the priority of 1 corresponding to the permission when executing the current operation behavior.

[0064] Further, according to the second matching result, it is determined whether the subject in the operation event has the operation permission on the object to obtain the corresponding permission determination result, specifically: the target priority is matched with the permission hash mapping table to determine the target permission corresponding to the target priority; according to the target permission, it is determined whether the subject in the operation event has the operation permission on the object to obtain the corresponding permission determination result. If the obtained 1 is used to query the permission hash mapping table, the obtained permission value is 0, that is, all operations are prohibited, so the execution of touch / root / a.txt will be blocked, which is in line with expectations.

[0065] like Figure 4The diagram shows the storage and matching of device security policies. When storing policies, it is necessary to define the policies and issue them first. When defining policies, each policy consists of five parts, and then the required policies are issued, and finally the issued policies are stored in three hash maps and corresponding bitmaps. When matching policies, first capture the user's operation events on the file, such as read, write, execute, etc.; then obtain the object path and subject path of the operation event. By matching with the subject hash mapping table and the object hash mapping table, two priorities are obtained, and the final bitmap result is calculated using these two priorities. The value of the bitmap result can represent the priority value corresponding to the operation event. If the operation permission of the file is determined to be consistent with the actual operation permission corresponding to the operation event according to the second structure data, that is, the data stored in the bitmap, then it is in line with expectations, and the interception or release action of the operation is determined according to the relevant permissions. For example, if the permission is to prohibit any operation, then the operation will be intercepted according to the permission; if the permission is read-only permission, then the operation will be released and made read-only.

[0066] Based on the above embodiment, in a feasible implementation manner, when deleting a target device security policy, specifically, the following steps may also be included: When there is a third target device security policy that needs to be deleted in the target device security policy, the current first structure data and the current second structure data are deleted, and new first structure data and new second structure data are re-determined based on the third target device security policy.

[0067] In this embodiment, to delete a certain policy, all policies need to be deleted, and the remaining policies need to be read out from the database and reloaded. That is, the policy storage process is re-executed to determine the new first structure data and the new second structure data.

[0068] In addition, in a feasible implementation, further, since the device security policy is used to control the operation behavior of the subject of the operation object, if the relevant policy is not matched according to the first structure data and the second structure data when the current operation event is used for policy matching, for example, the subject that is the same as the subject in the current operation event is not matched in the subject hash mapping table, at this time, at least one of the following operations can be performed: releasing the subject related to the operation event, and issuing a prompt of security policy matching failure for the current operation event. The above two operations can be used alone or in combination. Exemplarily, if the subject that is the same as the subject in the current operation event is not matched in the subject hash mapping table, the subject in the current operation behavior can be directly released, which means that the operation behavior of the subject is not restricted, and the operation behavior of the subject does not need to be controlled and will not bring security threats; Exemplarily, if the object that is the same as the object in the current operation event is not matched in the object hash mapping table, it means that there is no security policy for the object at present, and a prompt of security policy matching failure can be issued to enable the management personnel to further confirm whether to specify a corresponding security policy for the object based on the prompt.

[0069] Correspondingly, the embodiment of the present application also discloses a device security protection device under eBPF, see Figure 5 As shown, the device comprises: The policy issuing module 11 is used to determine the target device security policy and issue the target device security policy; The policy storage module 12 is used to store the issued target device security policy in a hash mapping form and a bitmap form respectively, so as to obtain the first structure data and the second structure data accordingly; The subject-object path acquisition module 13 is used to determine the subject path and object path in the operation event after monitoring the operation event on the file or directory; the operation event is an event in which the subject operates the object, the subject is the process of operating the file or directory, and the object is the file or directory to be protected; A strategy matching module 14 is used to perform strategy matching with the first structure data using the subject path and the object path to determine a first matching result, and to perform strategy matching with the first matching result and the second structure data to determine a second matching result; The event processing module 15 is used to determine whether the subject in the operation event has the operation authority for the object according to the second matching result, so as to obtain a corresponding authority determination result, and process the operation event according to the authority determination result.

[0070] Among them, for more specific working processes of the above-mentioned modules, please refer to the corresponding contents disclosed in the aforementioned embodiments, which will not be repeated here.

[0071] It can be seen that the above scheme of this embodiment includes: determining the target device security policy and issuing the target device security policy; storing the issued target device security policy in the form of hash mapping and bitmap respectively, so as to obtain the first structure data and the second structure data accordingly; when an operation event on a file or directory is monitored, determining the subject path and the object path in the operation event; the operation event is an event in which the subject operates the object, the subject is the process of operating the file or directory, and the object is the file or directory to be protected; using the subject path and the object path to perform policy matching with the first structure data respectively to determine the first matching result, and performing policy matching with the first matching result and the second structure data to determine the second matching result; determining whether the subject in the operation event has the operation authority on the object according to the second matching result to obtain the corresponding authority determination result, and processing the operation event according to the authority determination result.

[0072] The beneficial technical effects of the present application are: in the eBPF environment, the mapping mechanism provided by the kernel is used to store data structures. The present invention adopts the storage form of hash mapping and bitmap to apply bitmaps to the eBPF environment. As an efficient data structure, the bitmap can process a large amount of data with a small memory footprint and a fast speed, and realize the effective storage and efficient matching of device security policies in the eBPF environment.

[0073] Furthermore, the present application also discloses an electronic device. Figure 6 This is a structural diagram of an electronic device 20 according to an exemplary embodiment, and the content in the diagram cannot be considered as any limitation on the scope of use of the present application.

[0074] Figure 6 A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the device security protection method under the eBPF disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be a computer.

[0075] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0076] In addition, the memory 22 as a carrier for resource storage may be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon may include an operating system 221, a computer program 222 and data 223, etc. The data 223 may include various data. The storage method may be temporary storage or permanent storage.

[0077] The operating system 221 is used to manage and control the hardware devices on the electronic device 20 and the computer program 222, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the device security protection method under eBPF executed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.

[0078] Furthermore, the embodiment of the present application also discloses a computer-readable storage medium, where the computer-readable storage medium includes a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a magnetic disk or an optical disk, or any other form of storage medium known in the technical field. Among them, when the computer program is executed by the processor, the aforementioned device security protection method under eBPF is implemented. For the specific steps of the method, please refer to the corresponding content disclosed in the aforementioned embodiment, which will not be repeated here.

[0079] Furthermore, an embodiment of the present application also provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements any one of the above-mentioned device security protection methods under eBPF.

[0080] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0081] The steps of the device security protection method or algorithm under eBPF described in the embodiments disclosed herein can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the technical field.

[0082] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0083] The above is a detailed introduction to the device security protection method, device, program product and medium under eBPF provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as limiting the present invention.

Claims

1. A device security protection method under eBPF, characterized in that: include: Determine the target device security policy and issue the target device security policy; The target device security policy that has been issued is stored in a hash mapping form and a bitmap form respectively, so as to obtain first structure data and second structure data accordingly; When an operation event on a file or directory is detected, determining a subject path and an object path in the operation event; The operation event is an event in which a subject operates an object, the subject is a process operating a file or directory, and the object is a file or directory to be protected; Performing strategy matching with the first structure data using the subject path and the object path respectively to determine a first matching result, and performing strategy matching with the first matching result and the second structure data to determine a second matching result; Determine whether the subject in the operation event has the operation authority for the object according to the second matching result to obtain a corresponding authority determination result, and process the operation event according to the authority determination result.

2. The device security protection method under eBPF according to claim 1 is characterized in that: Before determining the target device security policy, the method further includes: Defining a device security policy in accordance with a preset rule format; wherein the preset rule format includes an object part, a subject part, a permission part, a rule part, and a policy priority part; Accordingly, determining the target device security policy and issuing the target device security policy includes: The target device security policy is determined according to the current application scenario, and the target device security policy is issued based on the preset format rule.

3. The device security protection method under eBPF according to claim 2 is characterized in that: Defining the permission part in the device security policy includes: A first flag is set for the permission to indicate that any operation behavior is prohibited; Setting a second identifier for the permission to represent the read-only permission; Setting a third identifier for the permission to represent the writable permission; A fourth identifier for characterizing the executable permission is set for the permission.

4. The device security protection method under eBPF according to claim 1 is characterized in that: The step of determining a target device security policy and issuing the target device security policy includes: Determine the target device security policy, and issue the target device security policy through a command line or a graphical user interface.

5. The device security protection method under eBPF according to claim 2 is characterized in that: The issued target device security policy is stored in a hash mapping form to obtain first structure data, including: Constructing an object hash mapping table using the object portion and the policy priority portion in the target device security policy; Constructing a subject hash mapping table using the subject part and the policy priority part in the target device security policy; Constructing a permission hash mapping table using the policy priority portion and the permission portion in the target device security policy; The first structure data is determined according to the object hash mapping table, the subject hash mapping table and the permission hash mapping table; wherein the object hash mapping table, the subject hash mapping table and the permission hash mapping table are stored in the form of key-value pairs.

6. The device security protection method under eBPF according to claim 5 is characterized in that: Also includes: Determine a first target device security policy and a second target device security policy; wherein the second target device security policy is a device security policy stored after the first target device security policy is stored; When it is determined according to a preset rule format that there is an identical portion between the first target device security policy and the second target device security policy, determining a target key of the identical portion in a corresponding mapping table; The value corresponding to the target key is updated using the different parts between the second target device security policy and the first target device security policy.

7. The device security protection method under eBPF according to claim 2 is characterized in that: The target device security policy is stored in a bitmap format to obtain second structure data, including: A bitmap is constructed based on the policy priority part in the target device security policy, and each bit in the bitmap corresponds to a target device security policy to obtain second structure data; wherein, the lower the bit in the second structure data, the higher the priority corresponding to the target device security policy.

8. The device security protection method of eBPF according to claim 5, characterized in that: Using the subject path and the object path to perform strategy matching with the first structure data respectively to generate a first matching result includes: Matching the subject path with the subject hash mapping table to determine a first priority corresponding to the subject path; Matching the object path with the object hash mapping table to determine a second priority corresponding to the object path; A bitwise AND operation is performed on the first priority level and the second priority level to determine a first matching result.

9. The device security protection method under eBPF according to claim 5 is characterized in that: The performing strategy matching on the first matching result and the second structure data to determine a second matching result includes: A bitwise AND operation is performed on the first matching result and the complement of the first matching result, and the generated bitmap result is matched with the second structure data to determine a second matching result.

10. The device security protection method under eBPF according to claim 9 is characterized in that: The step of matching the generated bitmap result with the second structure data to determine a second matching result includes: Determine the first low bit in the bitmap result that is not 0, and determine the target priority corresponding to the low bit according to the second structure data; the target priority is the priority corresponding to the permission when executing the operation behavior in the operation event; Correspondingly, determining whether the subject in the operation event has operation authority over the object according to the second matching result to obtain a corresponding authority determination result includes: Matching the target priority with the permission hash mapping table to determine the target permission corresponding to the target priority; Determine whether the subject in the operation event has the operation authority for the object according to the target authority, so as to obtain a corresponding authority determination result.

11. The device security protection method under eBPF according to claim 1 is characterized in that: The processing of the operation event according to the authority determination result includes: When the subject in the operation event has the operation authority over the object, the operation behavior in the operation event is released; When the subject in the operation event does not have the operation authority for the object, the operation behavior in the operation event is intercepted and processed.

12. The device security protection method under eBPF according to any one of claims 1 to 11, characterized in that: Also includes: When there is a third target device security policy that needs to be deleted in the target device security policy, the current first structure data and the current second structure data are deleted, and new first structure data and new second structure data are re-determined based on the third target device security policy.

13. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, used to load and execute the computer program to implement the device security protection method under eBPF as described in any one of claims 1 to 12.

14. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by the processor, the steps of the device security protection method under eBPF described in any one of claims 1 to 12 are implemented.

15. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein the computer program, when executed by the processor, implements the device security protection method under eBPF as described in any one of claims 1 to 12.

Citation Information

Patent Citations

  • Security policy processing method and device, medium and equipment

    CN112291249A

  • Access control method and device, equipment and readable storage medium

    CN113612802A

  • File access control method and device, equipment and storage medium

    CN116775563A

  • Trusted program starting control method based on eBPF-LSM mechanism

    CN117113331A

  • System, method, equipment and medium for realizing cloud native security based on eBPF

    CN117290857A

Cited By

  • Kernel task execution method, electronic equipment, readable storage medium and program product

    CN120386587A

  • Kernel task execution method, electronic device, readable storage medium and program product

    CN120386587B