Method and device for loading kernel extension program, storage medium and electronic equipment

By deploying a controller in the host, sending the kernel extension to the target security container, so that it loads the user-state process in the virtual machine, it solves the problem that traditional technology cannot penetrate the virtualization layer of the rund container, realizes detection and intercepting the behavior in the rund container, and realizes precise control and unified management of the secure container in the cluster.

CN119987897AActive Publication Date: 2025-05-13ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510090475.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-13
Estimated Expiration
2045-01-20

AI Technical Summary

Technical Problem

The security capabilities of traditional kernel extensions deployed on the host cannot penetrate the virtualization layer of the rund container, cannot effectively intercept and audit malicious processes, files, network access, etc. in the rund container, and cannot perceive the risk of intrusion in the rund container.

Method used

The kernel extension is sent to the target security container through the controller deployed in the host, so that it is provided to the user-state process in the virtual machine to load. If the business program executes to the hook point of the kernel extension, the log data of the kernel extension is obtained through the tracking module, and the log data is provided to the controller through the user-state process.

Benefits of technology

It breaks through the limitations of the target security container virtualization layer, loads the kernel extension program into the user state, realizes behavior detection and interception in the target security container, and realizes precise control and unified management of the security container in the cluster through the controller.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119987897A_ABST
    Figure CN119987897A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a method and device for loading a kernel extension program, a storage medium and electronic equipment. The method comprises the steps that firstly, the kernel extension program is sent to a target security container deployed in a host machine through a controller deployed in the host machine; the method comprises the following steps: enabling a target security container to provide a kernel extension program to a user mode process in a virtual machine started by the target security container, then loading the kernel extension program through the user mode process, and if a business program is executed to a specific kernel position embedded by at least one hook point corresponding to the kernel extension program, executing the kernel extension program to the target security container. According to the method, log data generated when a kernel extension program runs are obtained through a tracking module running in a kernel space, so that the limitation of a virtualization layer of a target security container can be broken through, the kernel extension program is loaded into a user mode, behavior detection and interception in the target security container are realized, and the safety of the target security container is improved. And accurate control of the safe containers in the cluster can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a method, device, storage medium and electronic device for loading a kernel extension program. Background Art

[0002] The security aspect program deployed on the host can realize the security observation and interception of malicious files, processes, and networks in the host and runc (container runtime characterized by the Open Container Project) container. With the development of cloud native technology, considering the isolation security, more and more manufacturers choose to use rund (a secure container runtime) container, such as kata container (a secure container built through lightweight virtual machine technology), as the container deployment business environment. The rund container is implemented through virtualization technology and has an independent kernel. The security capabilities of the traditional kernel extension program deployed on the host cannot penetrate the virtualization layer of the rund container. Therefore, it is impossible to effectively intercept and audit malicious processes, files, network access, etc. in the rund container, and it is impossible to perceive the intrusion risk in the rund container. Summary of the invention

[0003] The purpose of the embodiments of this specification is to provide a method, device, storage medium and electronic device for loading a kernel extension program.

[0004] The embodiment of the present specification provides a method for loading a kernel extension program, the method comprising:

[0005] Sending the kernel extension program to a target secure container deployed in the host machine through a controller deployed in the host machine, so that the target secure container provides the kernel extension program to a user state process in a virtual machine started by the target secure container;

[0006] Loading the kernel extension program through the user state process so that the kernel extension module running in the kernel space corresponding to the virtual machine runs the loaded kernel extension program;

[0007] If the business program executes to a specific kernel location where at least one hook point corresponding to the kernel extension program is embedded, the log data generated by the kernel extension program during its operation is obtained by running a tracking module in the kernel space, so that the tracking module provides the log data to the controller through the user mode process.

[0008] Furthermore, sending the kernel extension program to a target secure container deployed in the host machine through a controller deployed in the host machine includes:

[0009] Receiving a custom rule issued by a user through a controller deployed in a host machine, and screening a target security container from a plurality of security containers deployed in the host machine according to the custom rule, wherein the custom rule includes a kernel extension program;

[0010] The kernel extension program is sent to the target secure container through the controller.

[0011] Furthermore, the custom rule also includes application name information and / or application identification information;

[0012] The step of selecting a target security container from a plurality of security containers deployed in the host machine according to the custom rule includes:

[0013] A target security container is screened out from multiple security containers deployed in the host machine according to the application name information and / or the application identification information.

[0014] Further, the sending of the kernel extension program to a target secure container deployed in the host machine by a controller deployed in the host machine, so that the target secure container provides the kernel extension program to a user state process in a virtual machine started by the target secure container, includes:

[0015] The kernel extension program is sent to a virtualization device implemented by a target secure container deployed in the host machine through a controller deployed in the host machine, so that the virtualization device provides the kernel extension program to a user-mode process in a virtual machine started by the target secure container.

[0016] Furthermore, the user state process runs in a sidecar container, and the sidecar container is an auxiliary container that runs together with the business container in the user space corresponding to the virtual machine.

[0017] Furthermore, the method further includes: obtaining a first loading status corresponding to the kernel extension program through the user mode process, and providing the first loading status to the controller.

[0018] Furthermore, the method further comprises:

[0019] Sending, by the controller, a first uninstall instruction corresponding to the kernel extension program to the target secure container, so that the target secure container provides the first uninstall instruction to the user state process;

[0020] The user state process is enabled to uninstall the kernel extension program based on the first uninstall instruction, so that the kernel extension module stops running the kernel extension program.

[0021] Furthermore, the method further comprises:

[0022] Sending the target security rule corresponding to the kernel extension program to the target security container through the controller, so that the target security container provides the target security rule to the user state process;

[0023] The target security rule is loaded into the kernel extension program through the user state process, so that the kernel extension module embeds the hook point corresponding to the target security rule into a specific kernel position.

[0024] Furthermore, the method also includes: obtaining a second loading status corresponding to the target security rule through the user state process, and providing the second loading status to the controller.

[0025] Furthermore, the method further comprises:

[0026] Sending, by the controller, a second uninstall instruction corresponding to the target security rule to the target security container, so that the target security container provides the second uninstall instruction to the user state process;

[0027] The target security rule is uninstalled in the kernel extension program through the user mode process based on the second uninstall instruction, so that the kernel extension module removes the hook point corresponding to the target security rule from the kernel space.

[0028] The embodiment of the present specification also provides a device for loading a kernel extension program, including:

[0029] A control module, configured to send a kernel extension program to a target secure container deployed in the host machine through a controller deployed in the host machine, so that the target secure container provides the kernel extension program to a user state process in a virtual machine started by the target secure container;

[0030] A loading module, used to load the kernel extension program through the user state process, so that the kernel extension module running in the kernel space corresponding to the virtual machine runs the loaded kernel extension program;

[0031] A log acquisition module is used to obtain log data generated by the kernel extension program during operation by a tracking module running in the kernel space if the business program is executed to a specific kernel location where at least one hook point corresponding to the kernel extension program is embedded, so that the tracking module provides the log data to the controller through the user mode process.

[0032] The embodiments of the present specification also provide a storage medium, wherein the storage medium stores a computer program, and the computer program is suitable for being loaded by a processor and executing the steps of the above method.

[0033] An embodiment of the present specification also provides an electronic device, comprising: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the above method.

[0034] The embodiments of the present specification also provide a computer program product having at least one instruction stored thereon, wherein the at least one instruction implements the steps of the above method when executed by a processor.

[0035] According to the technical solution of the embodiments of the present specification, a kernel extension program can be sent to a target secure container deployed in the host machine through a controller deployed in the host machine, so that the target secure container provides the kernel extension program to the user state process in the virtual machine started by the target secure container, and then the kernel extension program is loaded through the user state process, so that the kernel extension module running in the kernel space corresponding to the virtual machine runs the loaded kernel extension program. If the business program is executed to a specific kernel position embedded in at least one hook point corresponding to the kernel extension program, the log data generated by the kernel extension program during operation is obtained through a tracking module running in the kernel space, so that the tracking module provides the log data to the controller through the user state process, thereby breaking through the limitations of the virtualization layer of the target secure container, loading the kernel extension program into the user state, realizing behavior detection and interception in the target secure container, and realizing precise control and unified management of the secure containers in the cluster through the controller. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 A flowchart of a method for loading a kernel extension program provided in an embodiment of this specification.

[0037] Figure 2 A schematic diagram of an architecture for loading a kernel extension program in a host machine is provided in an embodiment of the present specification.

[0038] Figure 3 A schematic diagram of the structure of a device for loading a kernel extension program provided in an embodiment of this specification.

[0039] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of this specification. DETAILED DESCRIPTION

[0040] In order to make the purpose, technical solutions and advantages of this specification more clear, the technical solutions of this specification will be clearly and completely described below in combination with the specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this specification.

[0041] See also Figure 1 , is a flowchart of a method for loading a kernel extension program provided in an embodiment of this specification. In an embodiment of this specification, the method for loading a kernel extension program is applied to a device for loading a kernel extension program (hereinafter referred to as a "kernel extension program loading device") or an electronic device equipped with a kernel extension program loading device. Figure 1 The process shown in FIG. 1 is described in detail, and the method for loading a kernel extension program may specifically include the following steps:

[0042] S102, sending the kernel extension program to the target secure container deployed in the host machine through a controller deployed in the host machine, so that the target secure container provides the kernel extension program to the user mode process in the virtual machine started by the target secure container.

[0043] In some embodiments, the target security container is a rund container, such as a kata container. In some embodiments, the host machine may be a physical host or a virtual machine. In some embodiments, multiple security containers (such as multiple kata containers) are deployed on the host machine, and the virtual machines started on each security container include user space and kernel space. After the controller receives the kernel extension program, it selects a target security container corresponding to the kernel extension program from the multiple security containers, so that the virtualization device in the target security container provides the kernel extension program to the user state process in the kernel space of the target security container. In some embodiments, the controller selects the target security container from multiple security containers according to preset rules, or selects the target security container from multiple security containers based on custom rules issued by the user.

[0044] In some embodiments, the controller implements high-performance communication with the user-state process in the target secure container through the vsock (a virtualization technology provided by the Linux kernel, used for communication between virtual machines and hosts) protocol. For example, each kata container deployed in the host includes a virtualization device virtio-vsock implemented by the kata virtualization layer. The controller sends commands or data to the user-state process through virtio-vsock, and the user-state process feeds back messages to the controller through virtio-vsock. Since the communication between the controller and the user-state process in the secure container does not use the network protocol stack, it will not affect the network performance of the business container. In addition, through the vsock protocol, the controller can directly communicate and control the user-state process in each secure container running on the node, so as to realize the control of kernel extension programs in batch secure containers. Compared with the traditional method of writing a user-state loader in the container to load the kernel extension program, this solution can more directly and efficiently realize unified management, control and distribution of kernel extension programs.

[0045] In some embodiments, the controller is used to control the behavior of the user state process in the secure container user state and the perception of the newly added secure container. In some embodiments, the user state process is used to monitor the signal sent by the controller and to perform functions such as loading and / or unloading of kernel extension programs, loading and / or unloading of rules, and log collection. In some embodiments, the kernel extension program is an ebpf (Extended Berkeley Packet Filter) program.

[0046] S104: Load the kernel extension program through the user state process, so that the kernel extension module running in the kernel space corresponding to the virtual machine runs the loaded kernel extension program.

[0047] As an example, a user state process is deployed in the user space of the kata container, and a kernel extension module is deployed in the kernel space. The user state process is used to load the ebpf program, and the kernel extension program is used to run the ebpf program loaded by the user state process.

[0048] S106, if the business program executes to a specific kernel location where at least one hook point corresponding to the kernel extension program is embedded, the log data generated by the kernel extension program during operation is obtained by running a tracking module in the kernel space, so that the tracking module provides the log data to the controller through the user state process.

[0049] As an example, the kernel extension program is used to run the ebpf program loaded by the user-mode process, the tracking module records the log data (security detection log) submitted by the ebpf program, and the user-mode process running in the user space of the secure container reads the log data from the tracking module and sends the collected log data to the controller. In some embodiments, after the user-mode process reads the log data in the tracking module, the log data is sent to the controller via the vsock protocol. The method of sending the log data to the controller via the vsock protocol avoids sending the log information via the network protocol, which can reduce the pressure on the network channel in the secure container.

[0050] The present application finds that in the prior art, kernel extension programs are usually manually loaded in a secure container by writing a user-mode loader. This method has the following disadvantages: 1) In a cloud-native environment, security control policies cannot be issued in batches according to applications, and manual operation is required, which is inefficient; 2) The user-mode loader program runs directly in the user space of the virtual machine, and related resources are not isolated. The loader operation is easily affected by the virtual machine host or affects the virtual machine host; 3) The collected security logs need to be sent to the log server through a network protocol stack (such as TCP / IP protocol), which will affect the network fluctuations of the business container. According to the scheme of the embodiments of the present specification, a kernel extension program can be sent to a target secure container deployed in the host machine through a controller deployed in the host machine, so that the target secure container provides the kernel extension program to a user state process in a virtual machine started by the target secure container, and then the kernel extension program is loaded through the user state process, so that the kernel extension module running in the kernel space corresponding to the virtual machine runs the loaded kernel extension program. If the business program is executed to a specific kernel position embedded in at least one hook point corresponding to the kernel extension program, the log data generated by the kernel extension program during operation is obtained through a tracking module running in the kernel space, so that the tracking module provides the log data to the controller through the user state process, thereby breaking through the limitations of the virtualization layer of the target secure container, loading the kernel extension program into the user state, realizing behavior detection and interception in the target secure container, and realizing precise control and unified management of the secure containers in the cluster through the controller, and the user state process can collect log data in the tracking module deployed in the kernel space and send it to the controller. The log transmission channel can reduce the pressure on the network channel in the secure container.

[0051] In some embodiments, the sending of the kernel extension program to the target security container deployed in the host through the controller deployed in the host includes: receiving the user-issued custom rules through the controller deployed in the host, filtering out the target security container from the multiple security containers deployed in the host according to the custom rules, wherein the custom rules include the kernel extension program; sending the kernel extension program to the target security container through the controller. In some embodiments, different business containers can implement different security rules, and the custom rules include security rules based on application granularity. For example, the user can specify different security rules for different applications, and send the corresponding security rules to the controller, and the controller parses the security rules and sends the security rules to the corresponding target security container. In some embodiments, the custom rules also include application name information and / or application identification information; wherein, filtering out the target security container from the multiple security containers deployed in the host according to the custom rules includes: filtering out the target security container from the multiple security containers deployed in the host according to the application name information and / or the application identification information. In some embodiments, the controller determines the target security container that matches the application name information or the application identification information through a label selector.

[0052] In some embodiments, the sending of the kernel extension program to the target secure container deployed in the host machine by a controller deployed in the host machine, so that the target secure container provides the kernel extension program to the user state process in the virtual machine started by the target secure container, includes: sending the kernel extension program to the virtualization device implemented by the target secure container deployed in the host machine by a controller deployed in the host machine, so that the virtualization device provides the kernel extension program to the user state process in the virtual machine started by the target secure container. As an example, each kata container deployed in the host machine includes a virtualization device virtio-vsock implemented by the kata virtualization layer. After determining the target kata container (that is, the target secure container), the controller deployed in the host machine sends the kernel extension program to the virtio-vsock in the target kata container, so that the virtio-vsock sends the kernel extension program to the user state process in the virtual machine started by the target kata container (the user state process is deployed in the user space in the virtual machine).

[0053] In some embodiments, the user state process runs in a sidecar container, which is an auxiliary container that runs together with the business container in the user space corresponding to the virtual machine. The sidecar container is used to enhance or expand the functions of the business container (i.e., the main application container) by providing additional services or functions (such as logging, detection, security, or data synchronization) without directly modifying the main application code. By running the user state process in the sidecar container in the virtual machine, the user state process can be isolated from the business container and the host machine, thereby achieving better resource control.

[0054] In some embodiments, the method further includes: obtaining a first loading status corresponding to the kernel extension program through the user state process, and providing the first loading status to the controller. The first loading status is used to indicate whether the kernel extension program is successfully loaded. By providing the first loading status to the controller, the controller can understand the loading status in real time to achieve efficient management and effective control of the secure container.

[0055] In some embodiments, the method further includes: sending the first uninstall instruction corresponding to the kernel extension program to the target security container through the controller, so that the target security container provides the first uninstall instruction to the user state process; so that the user state process uninstalls the kernel extension program based on the first uninstall instruction, so that the kernel extension module stops running the kernel extension program. In some embodiments, the controller generates the first uninstall instruction based on the custom rules issued by the user. In some embodiments, the first uninstall instruction can instruct to uninstall all or part of the kernel extension program. For example, the kernel extension program includes 5 hook points (hook points), and the first uninstall instruction instructs to uninstall the programs corresponding to 3 of the hook points. The controller senses the uninstall status of the kernel extension module to avoid continuing to issue corresponding security rules for the downloaded program.

[0056] In some embodiments, the method further includes: sending the target security rule corresponding to the kernel extension program to the target security container through the controller, so that the target security container provides the target security rule to the user state process; loading the target security rule in the kernel extension program through the user state process, so that the kernel extension module embeds the hook point corresponding to the target security rule into a specific kernel position. In some embodiments, the controller generates the target security rule based on a custom rule issued by a user.

[0057] In some embodiments, the method further includes: obtaining a second loading status corresponding to the target security rule through the user state process, and providing the second loading status to the controller. The second loading status is used to indicate whether the target security rule is successfully loaded. The controller can understand in real time whether the target security rule is successfully loaded through the second loading status, so as to further achieve efficient management and effective control of the security container.

[0058] In some embodiments, the method further includes: sending a second uninstall instruction corresponding to the target security rule to the target security container through the controller, so that the target security container provides the second uninstall instruction to the user state process; uninstalling the target security rule in the kernel extension program based on the second uninstall instruction through the user state process, so that the kernel extension module removes the hook point corresponding to the target security rule from the kernel space. In some embodiments, the controller generates a second uninstall instruction based on a custom rule issued by a user, and the second uninstall instruction is used to indicate the target security rule that needs to be uninstalled.

[0059] In some embodiments, the controller reads the user-defined rules issued by the user, and controls the user-mode process through the command channel to implement the management of the kernel extension program, including loading and unloading, and program status perception (including loading success, loading failure, unloading success, unloading failure, etc.), to ensure that the current kernel extension program is consistent with the state defined by the rules. In this way, the controller can implement batch selective kernel extension program management.

[0060] Figure 2 This is a schematic diagram of an architecture for loading a kernel extension program in a host machine provided in an embodiment of this specification. It should be noted that: Figure 2 The host machine shown includes two security containers, and those skilled in the art should be able to understand that: Figure 2 The number of secure containers is only an example and is not a limitation of this specification. In actual applications, multiple secure containers can be deployed in the host machine based on needs.

[0061] like Figure 2As shown, the host machine includes a controller, a secure container K1, and a secure container K2. Each secure container includes a virtualization device and a virtual machine; the user space in the virtual machine includes a business container and a sidecar container, and a user-mode process is deployed in the sidecar container. The kernel space in the virtual machine includes a kernel extension module and a tracking module. Among them, the controller is used to control the behavior of the user-mode process in the user space and the perception of the newly added container; the virtualization device is implemented by the virtualization layer of the secure container, which is used to help the host machine communicate with the virtual machine and is a bridge for the communication between the controller and the user-mode process. In this example, the controller uses the vsock protocol to realize the communication between the user-mode process in the secure container; the user-mode process runs in the sidecar container, which is used to listen to the signals sent by the controller and perform functions such as loading / unloading of kernel extension programs, loading / unloading of rules, and log collection; the kernel extension module is implemented by the Linux (an operating system) kernel, which is used to run the kernel extension program loaded by the user-mode process; the tracking module records the log data submitted by the kernel extension program.

[0062] Figure 2 The links 1-8 shown are explained as follows: 1) Links 1 and 2 are the controller sending commands and data to the user-mode process; 2) Link 3 is the user-mode process loading / unloading kernel extensions and issuing / deleting security rules to the virtual machine kernel space; 3) Link 4 is the execution of programs, files, and network activities within the business program to the kernel extension hook point; 4) Link 5 is the log data generated when the kernel extension is running and submitted to the tracking module; 5) Link 6 is the user-mode process reading log data from the tracking module; 6) Links 7 and 8 are the links for the user-mode process to feedback messages to the controller, including feedback on security logs, rule loading status, kernel extension loading status, etc.

[0063] Figure 3 A schematic diagram of a structure of a device for loading a kernel extension program provided in an embodiment of the present specification, the device for loading a kernel extension program (hereinafter referred to as "kernel extension program loading device 1") can be implemented as all or part of an electronic device through software, hardware or a combination of both. According to some embodiments, the kernel extension program loading device 1 includes a control module 11, a loading module 12 and a log acquisition module 13.

[0064] A control module, configured to send a kernel extension program to a target secure container deployed in the host machine through a controller deployed in the host machine, so that the target secure container provides the kernel extension program to a user state process in a virtual machine started by the target secure container;

[0065] A loading module, used to load the kernel extension program through the user state process, so that the kernel extension module running in the kernel space corresponding to the virtual machine runs the loaded kernel extension program;

[0066] A log acquisition module is used to obtain log data generated by the kernel extension program during operation by a tracking module running in the kernel space if the business program is executed to a specific kernel location where at least one hook point corresponding to the kernel extension program is embedded, so that the tracking module provides the log data to the controller through the user mode process.

[0067] In some embodiments, the control module 11 is used to:

[0068] Receiving a custom rule issued by a user through a controller deployed in a host machine, and screening a target security container from a plurality of security containers deployed in the host machine according to the custom rule, wherein the custom rule includes a kernel extension program;

[0069] The kernel extension program is sent to the target secure container through the controller.

[0070] In some embodiments, the custom rule further includes application name information and / or application identification information;

[0071] The step of selecting a target security container from a plurality of security containers deployed in the host machine according to the custom rule includes:

[0072] A target security container is screened out from multiple security containers deployed in the host machine according to the application name information and / or the application identification information.

[0073] In some embodiments, the control module 11 is used to:

[0074] The kernel extension program is sent to a virtualization device implemented by a target secure container deployed in the host machine through a controller deployed in the host machine, so that the virtualization device provides the kernel extension program to a user-mode process in a virtual machine started by the target secure container.

[0075] In some embodiments, the user state process runs in a sidecar container, and the sidecar container is an auxiliary container that runs together with the business container in the user space corresponding to the virtual machine.

[0076] In some embodiments, the kernel extension program loading device 1 is further used for: obtaining a first loading status corresponding to the kernel extension program through the user mode process, and providing the first loading status to the controller.

[0077] In some embodiments, the kernel extension program loading device 1 is further used for:

[0078] Sending, by the controller, a first uninstall instruction corresponding to the kernel extension program to the target secure container, so that the target secure container provides the first uninstall instruction to the user state process;

[0079] The user state process is enabled to uninstall the kernel extension program based on the first uninstall instruction, so that the kernel extension module stops running the kernel extension program.

[0080] In some embodiments, the kernel extension program loading device 1 is further used for:

[0081] Sending the target security rule corresponding to the kernel extension program to the target security container through the controller, so that the target security container provides the target security rule to the user state process;

[0082] The target security rule is loaded into the kernel extension program through the user state process, so that the kernel extension module embeds the hook point corresponding to the target security rule into a specific kernel position.

[0083] In some embodiments, the kernel extension program loading device 1 is further used for:

[0084] A second loading status corresponding to the target security rule is obtained through the user state process, and the second loading status is provided to the controller.

[0085] In some embodiments, the kernel extension program loading device 1 is further used for:

[0086] Sending, by the controller, a second uninstall instruction corresponding to the target security rule to the target security container, so that the target security container provides the second uninstall instruction to the user state process;

[0087] The target security rule is uninstalled in the kernel extension program through the user mode process based on the second uninstall instruction, so that the kernel extension module removes the hook point corresponding to the target security rule from the kernel space.

[0088] The above device embodiments correspond to the method embodiments. For specific descriptions, please refer to the description of the method embodiments, which will not be repeated here. The device embodiments are obtained based on the corresponding method embodiments and have the same technical effects as the corresponding method embodiments. For specific descriptions, please refer to the corresponding method embodiments.

[0089] The embodiment of the present specification also provides a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded by a processor to execute the method of the embodiment of the present specification.

[0090] The embodiments of the present specification also provide a computer program product, which stores at least one instruction, and the at least one instruction is loaded by the processor to execute the method of the embodiments of the present specification.

[0091] The embodiments of this specification also provide Figure 4 The structural diagram of the electronic device shown in FIG. Figure 4 At the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include other hardware required for the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the above method.

[0092] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0093] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0094] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1A device that provides the functions specified in a block or multiple blocks.

[0095] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0096] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0097] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0098] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0099] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0100] The above description is only an embodiment of the present specification and is not intended to limit the present specification. For those skilled in the art, the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims of the present specification.

Claims

1. A method for loading a kernel extension program, comprising: Sending the kernel extension program to a target secure container deployed in the host machine through a controller deployed in the host machine, so that the target secure container provides the kernel extension program to a user state process in a virtual machine started by the target secure container; Loading the kernel extension program through the user state process so that the kernel extension module running in the kernel space corresponding to the virtual machine runs the loaded kernel extension program; If the business program executes to a specific kernel location where at least one hook point corresponding to the kernel extension program is embedded, the log data generated by the kernel extension program during its operation is obtained by running a tracking module in the kernel space, so that the tracking module provides the log data to the controller through the user mode process.

2. The method according to claim 1, wherein sending the kernel extension program to the target secure container deployed in the host machine through a controller deployed in the host machine comprises: Receiving a custom rule issued by a user through a controller deployed in a host machine, and screening a target security container from a plurality of security containers deployed in the host machine according to the custom rule, wherein the custom rule includes a kernel extension program; The kernel extension program is sent to the target secure container through the controller.

3. According to the method of claim 2, the custom rule further includes application name information and / or application identification information; in, The step of selecting a target security container from a plurality of security containers deployed in the host machine according to the custom rule includes: A target security container is screened out from multiple security containers deployed in the host machine according to the application name information and / or the application identification information.

4. The method according to claim 1, wherein the controller deployed in the host machine sends the kernel extension program to the target secure container deployed in the host machine, so that the target secure container provides the kernel extension program to the user state process in the virtual machine started by the target secure container, comprising: The kernel extension program is sent to a virtualization device implemented by a target secure container deployed in the host machine through a controller deployed in the host machine, so that the virtualization device provides the kernel extension program to a user-mode process in a virtual machine started by the target secure container.

5. According to the method of claim 4, the user state process runs in a sidecar container, and the sidecar container is an auxiliary container that runs together with the business container in the user space corresponding to the virtual machine.

6. The method according to claim 1, further comprising: A first loading status corresponding to the kernel extension program is obtained through the user state process, and the first loading status is provided to the controller.

7. The method according to claim 1, further comprising: Sending, by the controller, a first uninstall instruction corresponding to the kernel extension program to the target secure container, so that the target secure container provides the first uninstall instruction to the user state process; The user state process is enabled to uninstall the kernel extension program based on the first uninstall instruction, so that the kernel extension module stops running the kernel extension program.

8. The method according to claim 1, further comprising: Sending the target security rule corresponding to the kernel extension program to the target security container through the controller, so that the target security container provides the target security rule to the user state process; The target security rule is loaded into the kernel extension program through the user state process, so that the kernel extension module embeds the hook point corresponding to the target security rule into a specific kernel position.

9. The method according to claim 8, further comprising: A second loading status corresponding to the target security rule is obtained through the user state process, and the second loading status is provided to the controller.

10. The method according to claim 8, further comprising: Sending, by the controller, a second uninstall instruction corresponding to the target security rule to the target security container, so that the target security container provides the second uninstall instruction to the user state process; The target security rule is uninstalled in the kernel extension program through the user mode process based on the second uninstall instruction, so that the kernel extension module removes the hook point corresponding to the target security rule from the kernel space.

11. A device for loading a kernel extension program, comprising: A control module, configured to send a kernel extension program to a target secure container deployed in the host machine through a controller deployed in the host machine, so that the target secure container provides the kernel extension program to a user state process in a virtual machine started by the target secure container; A loading module, used to load the kernel extension program through the user state process, so that the kernel extension module running in the kernel space corresponding to the virtual machine runs the loaded kernel extension program; A log acquisition module is used to obtain log data generated by the kernel extension program during operation by a tracking module running in the kernel space if the business program is executed to a specific kernel location where at least one hook point corresponding to the kernel extension program is embedded, so that the tracking module provides the log data to the controller through the user mode process.

12. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.

13. An electronic device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the method as claimed in any one of claims 1 to 10.

14. A computer program product having at least one instruction stored thereon, characterized in that: When the at least one instruction is executed by the processor, the steps of the method described in any one of claims 1 to 10 are implemented.

Citation Information

Patent Citations

  • Container safety isolation method and system and medium

    CN110362382A

  • Container safety method and system based on Sidecar mode

    CN112099900A

  • Container operation safety detection method based on behavior monitoring

    CN115576649A

  • GPU-based user container processing method, apparatus and device, and medium

    CN118426912A

  • File access method and system, electronic device, and machine-readable storage medium

    WO2024230779A1