Information security monitoring method, system and device and storage medium

Through ebpf and LSM technology, the operating status of the kernel-state monitoring system is solved, and the existing system monitoring solution cannot achieve full coverage monitoring is achieved, efficient and flexible system monitoring is achieved, reducing resource occupation and improving system performance.

CN119939573APending Publication Date: 2025-05-06GUANGDONG ZHONGXING NEWSTART TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411826948.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-12
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing system monitoring solution cannot achieve full coverage monitoring of the system. Adding audit rules will mostly occupy resources, resulting in system lag and other problems.

Method used

Ebpf and LSM technologies are used to obtain monitoring data from the operating status of the kernel state monitoring system, and the monitoring data is obtained through the ebpf program and stored in the bpf map. The user state monitoring program reads data from the bpf map and analyzes the security policy. If preset destructive behavior occurs, preset behavior is sent to the LSM module to prohibit user operations.

Benefits of technology

It realizes all-round monitoring of the system, reduces the occupation of system resources, improves system performance, and ensures the security of system data from the root.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939573A_ABST
    Figure CN119939573A_ABST
Patent Text Reader

Abstract

The invention discloses an information security monitoring method, system and device and a storage medium. The method comprises the following steps: acquiring monitoring data; the monitoring data is obtained by monitoring the running state of the system by an ebpf program; analyzing the monitoring data based on a security policy; if the preset behavior occurs, the preset behavior is sent to an LSM module, so that the LSM module prohibits user operation; the preset behavior comprises a behavior causing damage to information security, and the user corresponds to the preset behavior. According to the embodiment of the invention, the operation state of the system is monitored from the kernel mode by using the ebpf and LSM technologies, the system can be monitored in all directions, the occupation of system resources is reduced, and the system performance is improved. The method can be widely applied to the technical field of computers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to an information security monitoring method, system, device and storage medium. Background Art

[0002] In corporate office work, user misoperation or malicious system intrusion may result in the loss of commercial confidential files, thus damaging corporate interests. In order to ensure the security of corporate data information, it is necessary to monitor system data, ensure that confidential files are not leaked, and prevent illegal system processes from accessing system files, thereby ensuring the security of corporate information data.

[0003] In related technologies, system monitoring generally uses the system audit function to monitor system files. To use the audit function to monitor system operations, it is necessary to add audit rules for system files or system calls, and use the kernel's audit function to audit and record the running status of system calls or the operation of system files. By analyzing the audit log, behaviors that may endanger the information security of the system are found and processed. However, this solution cannot monitor the entire system. If more audit rules are added, more resources will be occupied, causing system freezes and other effects. Summary of the invention

[0004] The purpose of the present invention is to solve one of the technical problems existing in the prior art to at least a certain extent.

[0005] To this end, the purpose of the present invention is to provide a comprehensive information security monitoring method, system, device and storage medium.

[0006] In order to achieve the above technical objectives, one aspect of an embodiment of the present invention provides an information security monitoring method, comprising the following steps: obtaining monitoring data; the monitoring data is obtained by the ebpf program monitoring the operating status of the system; based on the security policy, the monitoring data is analyzed; if a preset behavior occurs, the preset behavior is sent to the LSM module so that the LSM module prohibits user operations; the preset behavior includes behavior that damages information security, and the user corresponds to the preset behavior. The embodiment of the present application uses ebpf and LSM technology to monitor the operating status of the system from the kernel state, which can achieve all-round monitoring of the system, which is conducive to reducing the occupation of system resources and improving system performance.

[0007] In some embodiments, the information security monitoring method of the embodiment of the present invention further includes:

[0008] Monitor the running status of the system through the ebpf program to obtain the monitoring data;

[0009] Storing the monitoring data in a bpf map;

[0010] The monitoring data is read from the bpf map by a user-mode monitoring program.

[0011] In some embodiments, in one embodiment of the present invention, if a preset behavior occurs, sending the preset behavior to the LSM module so that the LSM module prohibits user operation includes:

[0012] If the user's operation may damage the information security of the system, the user's behavior is sent to the LSM module through netlink, so that the LSM module prohibits the user's operation;

[0013] Alternatively, if the operation of the process will damage the information security of the system, the process behavior is sent to the LSM module through netlink, so that the LSM module prohibits the operation of the process.

[0014] In some embodiments, in one embodiment of the present invention, the security policy includes a file protection policy, and if a preset behavior occurs, sending the preset behavior to the LSM module so that the LSM module prohibits user operations, includes:

[0015] Add a file path and set the file protection policy; the file protection policy is to limit the network sending permission of the corresponding process;

[0016] If it is detected through the monitoring data that the file is accessed by the first process, the first process is restricted from sending data to the network through the LSM module.

[0017] In some embodiments, in one embodiment of the present invention, the method further comprises:

[0018] If it is detected that the system resource usage rate is greater than the preset usage rate, the operation of obtaining monitoring data is reduced;

[0019] If it is detected that the system resource occupancy rate is less than or equal to the preset occupancy rate, the operation of obtaining monitoring data is resumed.

[0020] In some embodiments, in one embodiment of the present invention, the acquiring of monitoring data includes:

[0021] Write the ebpf program to determine the monitoring data to be collected;

[0022] Compile the ebpf program into bytecode through LLVM and load it into the kernel;

[0023] In the kernel, the monitoring data is obtained through the ebpf program based on the mount point.

[0024] In some embodiments, in an embodiment of the present invention, if it is detected through the monitoring data that the file is accessed by the first process, restricting the first process from sending data to the network through the LSM module includes:

[0025] Generate a hook function according to the file protection strategy, and add the hook function to the kernel hooklist;

[0026] Receive access from a user or process, and perform permission judgment by running the hook function to block access by the first process.

[0027] On the other hand, an embodiment of the present invention provides an information security monitoring system, including:

[0028] The first module is used to obtain monitoring data; the monitoring data is obtained by monitoring the operating status of the system by the ebpf program;

[0029] The second module is used to analyze the monitoring data based on the security policy;

[0030] The third module is used to send the preset behavior to the LSM module if the preset behavior occurs, so that the LSM module prohibits user operations; the preset behavior includes behavior that damages information security, and the user corresponds to the preset behavior.

[0031] On the other hand, an embodiment of the present invention provides an information security monitoring device, including:

[0032] at least one processor;

[0033] at least one memory for storing at least one program;

[0034] When the at least one program is executed by the at least one processor, the at least one processor implements the above-mentioned information security monitoring method.

[0035] On the other hand, an embodiment of the present invention provides a storage medium, in which a program executable by a processor is stored. When the program executable by the processor is executed by the processor, it is used to implement the above-mentioned information security monitoring method.

[0036] The embodiments of the present application include at least the following beneficial effects: the method provided by the embodiments of the present invention includes: obtaining monitoring data; the monitoring data is obtained by the ebpf program monitoring the operating status of the system; based on the security policy, the monitoring data is analyzed; if a preset behavior occurs, the preset behavior is sent to the LSM module so that the LSM module prohibits user operations; the preset behavior includes behavior that damages information security, and the user corresponds to the preset behavior. The embodiments of the present application use ebpf and LSM technology to monitor the operating status of the system from the kernel state, which can achieve all-round monitoring of the system, which is conducive to reducing the occupation of system resources and improving system performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the embodiments of the present invention or the drawings of related technical solutions in the prior art are introduced below. It should be understood that the drawings introduced below are only for the convenience of clearly describing some embodiments of the technical solutions of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0038] Figure 1 A schematic diagram of a flow chart of an embodiment of the information security monitoring method provided by the present invention;

[0039] Figure 2 A schematic diagram of an application scenario of the information security monitoring method provided by the present invention;

[0040] Figure 3 A flowchart of the map mechanism provided by the present invention;

[0041] Figure 4 A schematic diagram of the process flow of the system access provided by the present invention;

[0042] Figure 5 A schematic diagram of a flow chart of an embodiment of obtaining monitoring data provided by the present invention;

[0043] Figure 6 A schematic diagram of a flow chart of an embodiment of data analysis provided by the present invention;

[0044] Figure 7 A schematic diagram of a flow chart of an embodiment of data processing provided by the present invention;

[0045] Figure 8 A schematic diagram of the structure of an embodiment of the information security monitoring system provided by the present invention;

[0046] Fig. 9 A schematic structural diagram of an embodiment of the information security monitoring device provided by the present invention. DETAILED DESCRIPTION

[0047] The embodiments of the present invention are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and are not to be construed as limitations of the present invention. For the step numbers in the following embodiments, they are only provided for the convenience of explanation, and the order between the steps is not limited in any way, and the execution order of each step in the embodiment can be adaptively adjusted according to the understanding of those skilled in the art.

[0048] In corporate office work, user misoperation or malicious system intrusion may result in the loss of commercial confidential files, thus damaging corporate interests. In order to ensure the security of corporate data information, it is necessary to monitor system data, ensure that confidential files are not leaked, and prevent illegal system processes from accessing system files, thereby ensuring the security of corporate information data.

[0049] At present, system monitoring generally uses the system audit function to monitor system files. To use the audit function to monitor system operations, it is necessary to add audit rules for system files or system calls, and use the kernel audit function to audit and record the running status of system calls or the operation of system files. By analyzing the audit log, behaviors that may endanger system information security are found and handled. To use the audit solution to monitor the system, it is necessary to add audit rules, and the system cannot be fully covered. If too many audit rules are added, more resources will be occupied, causing system freezes and other effects.

[0050] In this regard, this solution uses ebpf and LSM technology to monitor the system's operating status from the kernel state, which can achieve all-round monitoring of the system. It is more flexible and efficient, occupies less system resources, and will not affect system performance.

[0051] The information security monitoring method and system proposed in the embodiments of the present invention are described in detail below with reference to the accompanying drawings. First, the information security monitoring method proposed in the embodiments of the present invention will be described with reference to the accompanying drawings.

[0052] Reference Figure 1In an embodiment of the present invention, an information security monitoring method is provided. The information security monitoring method in the embodiment of the present invention can be applied to a terminal, a server, or software running in a terminal or a server. The terminal can be a tablet computer, a laptop computer, a desktop computer, etc., but is not limited to this. The server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The information security monitoring method in the embodiment of the present invention mainly includes the following steps:

[0053] S100: Acquire monitoring data; the monitoring data is obtained by monitoring the operating status of the system through the ebpf program;

[0054] S200: Analyze the monitoring data based on the security policy;

[0055] S300: If a preset behavior occurs, the preset behavior is sent to the LSM module so that the LSM module prohibits user operations; the preset behavior includes behavior that damages information security, and the user corresponds to the preset behavior.

[0056] In some possible implementations, the monitoring data in this application is obtained through the process of monitoring the status of the system by the ebpf program, and the monitoring data may include monitoring system files, processes, networks and other data. The security policy can be set according to actual needs, and can be a setting restriction on access to files, access to data, etc. The preset behavior is a behavior set based on the security policy. The preset behavior may cause damage to information security. Of course, the preset behavior may also be other unallowed behaviors. The security policy can be a preset behavior and restrictions on the executor of the behavior, and the user is the executor of the behavior.

[0057] Optionally, in one embodiment of the present invention, the method further comprises:

[0058] Monitor the running status of the system through the ebpf program to obtain the monitoring data;

[0059] Storing the monitoring data in a bpf map;

[0060] The monitoring data is read from the bpf map by a user-mode monitoring program.

[0061] In some possible implementations, the embodiments of the present application can implement kernel-mode and user-mode data transmission through bpf map.

[0062] Optionally, in one embodiment of the present invention, if a preset behavior occurs, sending the preset behavior to the LSM module so that the LSM module prohibits user operation, includes:

[0063] If the user's operation may damage the information security of the system, the user's behavior is sent to the LSM module through netlink, so that the LSM module prohibits the user's operation;

[0064] Alternatively, if the operation of the process will damage the information security of the system, the process behavior is sent to the LSM module through netlink, so that the LSM module prohibits the operation of the process.

[0065] Optionally, in one embodiment of the present invention, the security policy includes a file protection policy, and if a preset behavior occurs, sending the preset behavior to the LSM module so that the LSM module prohibits user operations, includes:

[0066] Add a file path and set the file protection policy; the file protection policy is to limit the network sending permission of the corresponding process;

[0067] If it is detected through the monitoring data that the file is accessed by the first process, the first process is restricted from sending data to the network through the LSM module.

[0068] In some possible implementations, the file protection policy is to restrict access to the file. If the first process accesses the file, the related operations of the first process are restricted according to the file protection policy. Of course, those skilled in the art can set the specific type of restricted operation, including but not limited to restricting network transmission.

[0069] Optionally, in one embodiment of the present invention, the method further comprises:

[0070] If it is detected that the system resource usage rate is greater than the preset usage rate, the operation of obtaining monitoring data is reduced;

[0071] If it is detected that the system resource occupancy rate is less than or equal to the preset occupancy rate, the operation of obtaining monitoring data is resumed.

[0072] In some possible implementations, the value of the preset occupancy rate can be set according to actual needs, and this application does not impose any specific limitation.

[0073] Optionally, in one embodiment of the present invention, the acquiring monitoring data includes:

[0074] Write the ebpf program to determine the monitoring data to be collected;

[0075] Compile the ebpf program into bytecode through LLVM and load it into the kernel;

[0076] In the kernel, the monitoring data is obtained through the ebpf program based on the mount point.

[0077] Optionally, in one embodiment of the present invention, if it is detected through the monitoring data that the file is accessed by the first process, restricting the first process from sending data to the network through the LSM module includes:

[0078] Generate a hook function according to the file protection strategy, and add the hook function to the kernel hooklist;

[0079] Receive access from a user or process, and perform permission judgment by running the hook function to block access by the first process.

[0080] The following is a detailed description of the information security monitoring method provided by this application using a specific embodiment:

[0081] Regarding ebpf, BPF is a highly flexible and efficient virtual machine-like technology in the Linux kernel that allows bytecode to be executed at various hook points in a safe manner. It can implement network packet filtering, system call tracing, monitoring system operations, and other functions. BPF programs are compiled into BPF instructions using a compiler backend (such as LLVM), and the kernel later maps BPF instructions into native instructions (opcodes) of the processor through an in-kernel JIT Compiler to achieve the best execution performance in the kernel.

[0082] Reference Figure 2 As shown in Figure 1, eBPF needs to run in the kernel. This is usually done by a user-mode application, which loads the eBPF program through a system call. During the loading process, the kernel copies the code of the eBPF program into kernel space.

[0083] The eBPF program needs to be compiled and executed. The BPF program is completed by the LLVM compiler, and then the bytecode is formed. The user-mode bytecode is loaded into the kernel, and the general bytecode of the program is converted into a machine-specific instruction set through a JIT compilation step to optimize the execution speed of the program. The ebpf program can be used to hook kernel functions and user dynamic library functions. When the mounted event runs, the generated instruction set is executed to monitor the operation of system calls or user calls to dynamic library interfaces, and obtain parameter status information when the system or application is running.

[0084] The eBPF program also needs to be checked by the kernel security mechanism. This is to ensure that the eBPF program does not undermine the stability and security of the kernel. During the inspection process, the kernel will analyze the code of the eBPF program to ensure that it does not perform malicious operations.

[0085] Some embodiments, see Figure 3 In ebpf, we introduce the Map mechanism, and we can put data into the Map space. The Map space is shared by the user space and the kernel space, so generally we store data into the Map space in the kernel, and then retrieve the data in the user space. Figure 3 shown.

[0086] The BPF program itself only contains instructions and does not contain actual data and its status. We can create a BPFMap in the BPF program. The system can use the Map to realize the communication between the BPF program and the user program, and pass information from the kernel state to the user state.

[0087] It can be seen that the ebpf program has the following points:

[0088] Flexibility: Functions can be expanded without recompiling the kernel, and user needs can be flexibly met;

[0089] Security: When loading the BPF program, the bytecode will be checked to ensure the stability of the system operation;

[0090] High performance: It runs directly in the kernel, without any user-mode loss, and has higher operating efficiency.

[0091] Based on the above characteristics, the ebpf-based program can better monitor the usage of the system and ensure the security of user data and process calls.

[0092] About LSM, LSM is a lightweight universal access control framework of the Linux kernel. Users can implement user security access control policies in the LSM module through hook functions according to their needs, including access rights to system process access, system files, networks, etc.

[0093] Linux access judgment is as follows Figure 4 As shown. Users implement the corresponding hook function of LSM according to their needs, and add the hook function to the Linux kernel hook list through the kernel interface. When the system makes permission judgment, it runs the user's hook function to make permission judgment on the access to system processes and system files. Prevent illegal access and ensure the security of the system and user data.

[0094] In some embodiments, the present application provides monitoring data, such as Figure 5As shown in the figure, the system operation status monitoring can be realized through the ebpf program, and the system files, processes, networks and other data can be monitored. Then it is saved in the bpf map. The user state program reads the monitoring data from the bpf map through the interface, and then saves, analyzes and processes the data.

[0095] In some embodiments, the present application provides data analysis, such as Figure 6 As shown in the figure, after receiving the monitoring data returned by the kernel, the user-mode monitoring program determines whether the system or user's related operations will have system risks and endanger the information security of the enterprise according to the security policy set by the system. If it is determined that the system or enterprise's information security is endangered, the operation will be processed accordingly to ensure the security of the system or information.

[0096] In some embodiments, the present application provides data processing, such as Figure 7 As shown in the figure, if during the data analysis phase, it is determined that the operation of a user or process will damage the information security of the system or enterprise, the behavior of the user or process will be sent to the LSM module through netlink, prohibiting the user from accessing system files, processes or network data, thereby ensuring the security of system data from the source and preventing the leakage of sensitive enterprise data.

[0097] For example, regarding the policy instance, a protection policy for important data files is set, an important file path is added, and a permission policy is set to restrict the network sending permission of the process if the process reads the file. The monitoring service detects system file access through ebpf. If it detects that the set file is accessed, it sends a message to the kernel LSM module to prohibit the process from accessing the file and prohibit the network sending permission, thereby restricting the process from sending data to the network and protecting the security of important data.

[0098] In some embodiments, the present application provides lightweight operation. When the monitoring program detects that the system resource usage is too high, in order to improve the user's system usage experience, not affect the user's normal operation, and also be compatible with the security of system information, the system will automatically enter the lightweight operation mode. When the lightweight operation is turned on, the monitoring program will reduce the monitoring of system file operations and release system resources for system use. When it is detected that the system resource usage rate is reduced, the lightweight operation mode will be automatically turned off and the system files will be monitored again.

[0099] The embodiment of the present application combines the user state with the kernel state, which can not only flexibly and efficiently monitor and process the monitoring data of the system without wasting system resources, but also promptly prevent behaviors that undermine the security of system information and protect the security of enterprise information.

[0100] The embodiment of the present application provides a solution based on the combination of eBPF and LSM to achieve management and control of system information security; monitors system calls, system files and program running status based on eBPF; can customize monitoring strategies to protect key confidential files and prevent file leakage; and adapts to lightweight operation mode to reduce the impact on system operation.

[0101] It is understandable that using the system audit function, adding audit rules, and auditing the operation of the system requires adding audit rules, which will have a significant impact on system performance. This solution uses a combination of ebpf and LSM to monitor the system in kernel mode, which can comprehensively monitor the operation of the system without leaving any blind spots. It is more flexible and efficient and will not affect system performance. It monitors and manages system information security from the root, and can better ensure the security of system data.

[0102] In summary, the method provided by the embodiment of the present application includes: obtaining monitoring data; the monitoring data is obtained by the ebpf program monitoring the operating status of the system; based on the security policy, the monitoring data is analyzed; if a preset behavior occurs, the preset behavior is sent to the LSM module so that the LSM module prohibits user operations; the preset behavior includes behavior that damages information security, and the user corresponds to the preset behavior. The embodiment of the present application uses ebpf and LSM technology to monitor the operating status of the system from the kernel state, which can achieve all-round monitoring of the system, which is conducive to reducing the occupation of system resources and improving system performance.

[0103] Secondly, refer to the attached Figure 8 An information security monitoring system proposed according to an embodiment of the present invention is described.

[0104] Figure 8 1 is a schematic diagram of the structure of an information security monitoring system according to an embodiment of the present invention, wherein the system specifically comprises:

[0105] The first module 810 is used to obtain monitoring data; the monitoring data is obtained by monitoring the operating status of the system by the ebpf program;

[0106] The second module 820 is used to analyze the monitoring data based on the security policy;

[0107] The third module 830 is used to send the preset behavior to the LSM module if the preset behavior occurs, so that the LSM module prohibits user operations; the preset behavior includes behavior that damages information security, and the user corresponds to the preset behavior.

[0108] It can be seen that the contents of the above method embodiments are all applicable to the present system embodiments, the functions specifically implemented by the present system embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0109] Reference Fig. 9 , an embodiment of the present invention provides an information security monitoring device, comprising:

[0110] at least one processor 410;

[0111] At least one memory 420, used to store at least one program;

[0112] When the at least one program is executed by the at least one processor 410, the at least one processor 410 implements the information security monitoring method.

[0113] Similarly, the contents of the above method embodiments are all applicable to the present device embodiments. The functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0114] An embodiment of the present invention further provides a computer-readable storage medium, in which a program executable by a processor is stored. The program executable by the processor is used to execute the above-mentioned information security monitoring method when executed by the processor.

[0115] Similarly, the contents of the above method embodiments are all applicable to the present storage medium embodiments. The functions specifically implemented by the present storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0116] In some selectable embodiments, the function / operation mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the function / operation involved, the two boxes shown in succession can actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiment presented and described in the flow chart of the present invention is provided by way of example, for the purpose of providing a more comprehensive understanding of technology. The disclosed method is not limited to the operation and logic flow presented herein. Selectable embodiments are expected, wherein the order of various operations is changed and the sub-operation of a part for which is described as a larger operation is performed independently.

[0117] In addition, although the present invention is described in the context of functional modules, it should be understood that, unless otherwise specified, one or more of the functions and / or features can be integrated into a single physical device and / or software module, or one or more functions and / or features can be implemented in a separate physical device or software module. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding the present invention. More specifically, in view of the properties, functions and internal relationships of the various functional modules in the device disclosed herein, the actual implementation of the module will be understood within the conventional skills of the engineer. Therefore, those skilled in the art can implement the present invention set forth in the claims without excessive experimentation using ordinary techniques. It is also understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.

[0118] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several programs to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program codes.

[0119] The logic and / or steps represented in the flowchart or otherwise described herein, for example, may be considered as an ordered list of executable programs for implementing the logical functions, and may be embodied in any computer-readable medium for use by a program execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch and execute a program from a program execution system, device or apparatus), or in conjunction with such program execution systems, devices or apparatuses. For purposes of this specification, a "computer-readable medium" may be any device that can contain, store, communicate, propagate or transmit a program for use by a program execution system, device or apparatus, or in conjunction with such program execution systems, devices or apparatuses.

[0120] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.

[0121] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable program execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0122] In the above description of this specification, the description with reference to the terms "one embodiment / example", "another embodiment / example" or "certain embodiments / examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0123] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.

[0124] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the embodiments. Those skilled in the art may make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present invention.

Claims

1. An information security monitoring method, characterized in that: The following steps are involved: Obtain monitoring data; the monitoring data is obtained by monitoring the operating status of the system through the ebpf program; Analyzing the monitoring data based on security policies; If a preset behavior occurs, the preset behavior is sent to the LSM module so that the LSM module prohibits user operations; the preset behavior includes behavior that damages information security, and the user corresponds to the preset behavior.

2. The information security monitoring method according to claim 1, characterized in that: The method further comprises: Monitor the running status of the system through the ebpf program to obtain the monitoring data; Storing the monitoring data in a bpf map; The monitoring data is read from the bpf map by a user-mode monitoring program.

3. The information security monitoring method according to claim 1, characterized in that: If the preset behavior occurs, sending the preset behavior to the LSM module so that the LSM module prohibits the user from operating, including: If the user's operation may damage the information security of the system, the user's behavior is sent to the LSM module through netlink, so that the LSM module prohibits the user's operation; Alternatively, if the operation of the process will damage the information security of the system, the process behavior is sent to the LSM module through netlink, so that the LSM module prohibits the operation of the process.

4. The information security monitoring method according to claim 1, characterized in that: The security policy includes a file protection policy. If a preset behavior occurs, the preset behavior is sent to the LSM module so that the LSM module prohibits user operations, including: Add a file path and set the file protection policy; the file protection policy is to limit the network sending permission of the corresponding process; If it is detected through the monitoring data that the file is accessed by the first process, the first process is restricted from sending data to the network through the LSM module.

5. The information security monitoring method according to claim 1, characterized in that: The method further comprises: If it is detected that the system resource usage rate is greater than the preset usage rate, the operation of obtaining monitoring data is reduced; If it is detected that the system resource occupancy rate is less than or equal to the preset occupancy rate, the operation of obtaining monitoring data is resumed.

6. The information security monitoring method according to claim 1, characterized in that: The obtaining of monitoring data includes: Write the ebpf program to determine the monitoring data to be collected; Compile the ebpf program into bytecode through LLVM and load it into the kernel; In the kernel, the monitoring data is obtained through the ebpf program based on the mount point.

7. The information security monitoring method according to claim 4, characterized in that: If it is detected through the monitoring data that the file is accessed by the first process, restricting the first process from sending data to the network through the LSM module includes: Generate a hook function according to the file protection policy, and add the hook function to the kernel hook list; Receive access from a user or process, and perform permission judgment by running the hook function to block access by the first process.

8. An information security monitoring system, characterized in that: include: The first module is used to obtain monitoring data; the monitoring data is obtained by monitoring the operating status of the system by the ebpf program; The second module is used to analyze the monitoring data based on the security policy; The third module is used to send the preset behavior to the LSM module if the preset behavior occurs, so that the LSM module prohibits user operations; the preset behavior includes behavior that damages information security, and the user corresponds to the preset behavior.

9. An information security monitoring device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the information security monitoring method as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a program executable by a processor, characterized in that: The processor-executable program is used to implement the information security monitoring method according to any one of claims 1 to 7 when executed by the processor.

Citation Information

Cited By

  • Security detection method, security loading method, device, storage medium and program product

    CN121902141A