System call detection method and device and computer equipment
By obtaining and analyzing the call record data of system calls, identifying abnormal system calls, and creating a proxy process for monitoring, the problem of blind spots in the system call detection mechanism in the existing technology is solved, and efficient and accurate system call detection and monitoring is achieved.
Patent Information
- Application Number
- CN202510085105.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-13
AI Technical Summary
There are blind spots in existing system call detection mechanisms that cannot completely cover all system calls, especially those hidden or forged in specific ways.
By obtaining the call record data of the system call, performing feature extraction, identifying exception system calls that occur compared to the pre-built baseline model, and creating a proxy process for continuous monitoring.
It realizes reasonable and effective detection of system calls, can promptly and accurately identify abnormal system calls, and conduct real-time monitoring through proxy processes, significantly improving the security of the system.
Smart Images

Figure CN119988137A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a system call detection method, device and computer equipment. Background Art
[0002] Existing system call detection mechanisms usually rely on interfaces and hooks provided by the operating system to monitor and record system call events. In real-time operating systems such as QNX (a real-time operating system for embedded systems), when executing system services, system calls are usually implemented through the API (Application Programming Interface) provided by the kernel. Existing detection methods may include the use of kernel modules, system call interception, audit logging, etc.
[0003] The existing system call detection mechanism has some shortcomings. First, relying on the interfaces and hooks provided by the operating system may be limited by the security of the operating system itself. It is impossible to fully cover all system calls, especially those that are hidden or forged in a specific way, which makes the detection mechanism have blind spots. Therefore, how to reasonably and effectively detect system calls. Summary of the invention
[0004] In view of this, the present invention provides a system call detection method, apparatus and computer equipment to solve the problem of how to reasonably and effectively detect system calls.
[0005] In a first aspect, the present invention provides a system call detection method, the method comprising:
[0006] Get the call record data of the system call;
[0007] Extract features from the call record data to obtain actual feature values of multiple key feature data;
[0008] Based on a plurality of actual feature values, identifying abnormal system calls that are abnormal compared with a pre-built baseline model, where the baseline model is built based on historical call data of the system calls;
[0009] Create an agent process to continuously monitor abnormal system calls.
[0010] The system call detection method of the embodiment of the present invention obtains the call record data of the system call, and extracts the features of the call record data to obtain the actual feature values of multiple key feature data, thereby identifying the abnormal system calls that are abnormal compared with the pre-built baseline model based on the multiple actual feature values, and creating an agent process for continuously monitoring the abnormal system calls. Thus, through the pre-built baseline model, the abnormal system calls are timely and accurately identified, and when the abnormal system calls are detected, a lightweight agent process that can continuously monitor the system calls is created, and the agent process can use the time notification mechanism of the real-time operating system of the embedded system to realize real-time monitoring of the system calls at the agent level.
[0011] In some optional embodiments, the call record data includes call log data;
[0012] Get the call record data of the system call, including:
[0013] Obtain call log data through system monitoring tools and audit logs.
[0014] In some optional implementations, before extracting features from the call record data, the method further includes:
[0015] Perform data preprocessing on call record data.
[0016] In some optional implementations, the key feature data includes the type, frequency, caller identity, call time, and call duration of the system call.
[0017] In some optional implementations, based on a plurality of actual feature values, identifying abnormal system calls that are abnormal compared to a pre-built baseline model includes:
[0018] Determine the mean and standard deviation of key feature data based on the pre-built baseline model;
[0019] Identify abnormal system calls that occur abnormally compared to a pre-built baseline model based on the mean and standard deviation of multiple key feature data.
[0020] The system call detection method of the embodiment of the present invention determines the mean value and standard deviation of key feature data based on a pre-built baseline model, and identifies abnormal system calls that are abnormal compared to the pre-built baseline model based on the mean values and standard deviations of multiple key feature data. Thus, based on the pre-built baseline model, a comprehensive and effective analysis of the normal behavior pattern of the system call is performed, abnormal system call behavior is quickly and accurately identified, and an efficient, accurate and secure system call detection solution is constructed, which significantly improves the security of the system using the system call detection method of the embodiment of the present invention.
[0021] In some optional implementations, based on the average value and standard deviation of multiple key feature data, identifying abnormal system calls that are abnormal compared to a pre-built baseline model includes:
[0022] When the actual characteristic value of the key characteristic data is greater than the characteristic threshold, it is determined that the key characteristic data is abnormal, and the characteristic threshold is determined based on the mean value and the standard deviation;
[0023] When the number of abnormal key feature data among the multiple key feature data of the system call is greater than the set feature number, it is determined that the corresponding system call is abnormal.
[0024] The system call detection method of the embodiment of the present invention determines the feature threshold based on the average value that can describe the data center trend in the baseline model and the standard deviation that can describe the degree of data dispersion, and compares the actual feature value of the key feature data with the feature threshold to determine whether the system call is abnormal. Furthermore, the baseline model is constructed based on the historical call data of the system call, so the baseline model and the corresponding average value and standard deviation can be dynamically adapted and adjusted based on the historical call data of the system call. Therefore, the normal behavior pattern of the system call is learned and analyzed through the baseline model, and the abnormal behavior of the system call is quickly, accurately and efficiently identified, and the system call initiated by hiding or forging means is identified.
[0025] In some optional implementations, the baseline model is constructed using the following operations:
[0026] Obtain historical call data of system calls, where the historical call data has multiple data points;
[0027] Randomly select a set number of data points from the historical call data as the initial cluster centers;
[0028] Assign multiple data points to the initial clustering centers according to a preset rule to form multiple clusters;
[0029] Calculate the cluster centers of clusters and cluster centers based on multiple clusters;
[0030] Repeatedly assign data points to cluster centers and calculate new cluster centers until the number of calculations reaches the set number of iterations or a stable cluster center is obtained.
[0031] The system call detection method of the embodiment of the present invention identifies natural groupings and patterns in system calls through cluster analysis, quickly and accurately constructs a baseline model that can be used to characterize the normal behavior of system calls, significantly improves the reference value of the baseline model, and thus quickly and accurately identifies abnormal behavior of system calls.
[0032] In a second aspect, the present invention provides a system call detection device, the device comprising:
[0033] An acquisition module is used to obtain call record data of system calls;
[0034] An extraction module is used to extract features from call record data to obtain actual feature values of multiple key feature data;
[0035] an identification module, for identifying abnormal system calls that are abnormal compared with a pre-built baseline model based on a plurality of actual feature values, the baseline model being built based on historical call data of the system calls;
[0036] Create a module for creating an agent process for continuous monitoring of abnormal system calls.
[0037] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the system call detection method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0038] In a fourth aspect, the present invention provides a computer program product, comprising computer instructions, wherein the computer instructions are used to enable a computer to execute the system call detection method of the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0040] Figure 1 is a schematic flow chart of a system call detection method according to an embodiment of the present invention;
[0041] Figure 2 is a flow chart of another system call detection method according to an embodiment of the present invention;
[0042] Figure 3 is a schematic diagram of an implementation flow of a specific application example of a system call detection method according to an embodiment of the present invention;
[0043] Figure 4 is a structural block diagram of a system call detection device according to an embodiment of the present invention;
[0044] Figure 5 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0045] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0046] To solve some deficiencies in the system call detection mechanism in the related art. For example, the interfaces and hooks provided by the operating system in the related art may be limited by the security of the operating system itself and cannot completely cover all system calls, especially those hidden or forged in a specific way, which makes the detection mechanism have blind spots. The present invention provides a system call detection method to solve the technical problem of how to reasonably and effectively detect system calls, and the method can be implemented based on the QNX system.
[0047] According to an embodiment of the present invention, a system call detection method embodiment is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0048] In this embodiment, a system call detection method is provided, which can be used in computers, servers, etc. Figure 1 is a flow chart of a system call detection method according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:
[0049] Step S101, obtaining call record data of the system call.
[0050] In some optional implementations, the call record data may include call log data, and the call log data may be obtained through system monitoring tools and audit logs as the call record data of the system call.
[0051] Step S102: extracting features from the call record data to obtain actual feature values of a plurality of key feature data.
[0052] In some optional implementations, the key feature data may include the type, frequency, caller identity, call time, and call duration of the system call.
[0053] Here, the key feature data can be set according to the requirements. For example, the key feature data can also include the time period for initiating the call request. Multiple time periods can be set according to the actual situation. For example, each hour of a day is set as a time period, and each quarter of an hour of a day is set as a time period. Based on the setting of the key feature data, feature extraction is performed on the call record data.
[0054] Step S103, based on multiple actual feature values, identifying abnormal system calls that are abnormal compared to a pre-built baseline model, where the baseline model is built based on historical call data of the system calls.
[0055] In some optional implementations, the following operations may be used to construct a baseline model:
[0056] Step a1, obtaining historical call data of the system call, the historical call data having multiple data points.
[0057] The purpose of building a baseline model is to establish a model that can characterize normal system call behavior. Therefore, the historical call data here needs to have a certain validity, and the timestamp of the historical call data can be limited to a set time interval according to actual needs. In addition, the acquired historical call data can also be pre-processed to clean the data and remove information irrelevant to building the baseline model to ensure the quality of the historical call data used to build the baseline model. For example, obviously abnormal outliers can be deleted and missing values can be processed.
[0058] Step a2: randomly select a set number of data points from the historical call data as the initial cluster centers.
[0059] In some optional embodiments of the present invention, k data points may be randomly selected as initial cluster centers. For example, (x, y, z, ..., n) may be used to represent a set of historical call data with n data points, and the number is set to k. Furthermore, a Random function (a function used to characterize random numbers) or other applicable methods may be used to randomly select k data points from a set of historical call data with n data points, where k and n are both integers, and k < n. Thus, the initial cluster center includes k data points.
[0060] Step a3: assign multiple data points to initial cluster centers according to a preset rule to form multiple clusters.
[0061] In some optional implementations, taking any data point z among multiple data points as an example, the preset rule may be to assign the data point z to the point that is closest to the data point z among the k data points selected in step a2.
[0062] Therefore, if it is necessary to allocate multiple data points to the initial cluster centers according to a preset rule, it is necessary to determine the distances between the data points to be allocated and the k data points randomly selected in step a2.
[0063] Here, the distance between two points can be determined using the following formula (1):
[0064] d(x,y) = sqrt[∑(x_i-y_i) 2 ] (1)
[0065] Where d(x,y) represents the Euclidean distance between data point x and data point y;
[0066] x_i and y_i are the coordinates of data point x and data point y in the i-th dimension respectively.
[0067] Furthermore, based on the distance between the data point z and the k data points randomly selected in step a2, the data point closest to the data point z can be selected from the k data points. If multiple data points are assigned to the data point of the initial cluster center, k clusters can be formed.
[0068] Step a4, calculating the cluster center of the cluster, and based on the cluster centers of multiple clusters.
[0069] In some optional implementations, the cluster center of the cluster can be determined by calculating the average value of multiple data points in the cluster. Here, the data point in each cluster whose actual value is closest to the average value of multiple data points in the cluster can be used as the cluster center.
[0070] Step a5, repeatedly assigning data points to cluster centers and calculating new cluster centers until the number of calculations reaches the set number of iterations or a stable cluster center is obtained.
[0071] In some optional implementations, after determining the cluster center of each cluster, the above steps a3 and a4 may be performed again until the number of calculations reaches a set number of iterations or a stable cluster center is obtained. When the cluster center no longer changes, it is determined that a stable cluster center is obtained. For example, when the last two cluster centers are the same, it can be determined that the cluster center no longer changes.
[0072] The system call detection method of the embodiment of the present invention identifies natural groupings and patterns in system calls through cluster analysis, quickly and accurately constructs a baseline model that can be used to characterize the normal behavior of system calls, significantly improves the reference value of the baseline model, and thus quickly and accurately identifies abnormal behavior of system calls.
[0073] Step S104: creating an agent process for continuously monitoring abnormal system calls.
[0074] For example, a lightweight agent process can be created in user space. The agent process will be tightly integrated with the QNX kernel and run in user space to reduce the impact on system performance. The agent process will use QNX's event notification mechanism to monitor system call events in real time. When a system call occurs, the kernel will notify the agent process, and the agent process will then perform anomaly detection.
[0075] The system call detection method of the embodiment of the present invention obtains the call record data of the system call, and extracts the features of the call record data to obtain the actual feature values of multiple key feature data, thereby identifying the abnormal system calls that are abnormal compared with the pre-built baseline model based on the multiple actual feature values, and creating an agent process for continuously monitoring the abnormal system calls. Thus, through the pre-built baseline model, the abnormal system calls are timely and accurately identified, and when the abnormal system calls are detected, a lightweight agent process that can continuously monitor the system calls is created, and the agent process can use the time notification mechanism of the real-time operating system of the embedded system to realize real-time monitoring of the system calls at the agent level.
[0076] In this embodiment, a system call detection method is provided, which can be used in computers, servers, etc. Figure 2 is a flow chart of a system call detection method according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:
[0077] Step S201, obtaining call record data of the system call.
[0078] For details, please see Figure 1 Step S101 of the illustrated embodiment will not be described in detail here.
[0079] Step S202: preprocess the call record data.
[0080] Specifically, the call record data may be pre-processed by cleaning the data to remove obvious irrelevant information and ensure the quality of the call record data. For example, obviously abnormal outliers may be deleted and missing values may be processed.
[0081] Step S203: extracting features from the call record data to obtain actual feature values of multiple key feature data.
[0082] For details, please see Figure 1 Step S102 of the illustrated embodiment will not be described in detail here.
[0083] Step S204, based on the multiple actual feature values, identifying abnormal system calls that are abnormal compared to a pre-built baseline model, where the baseline model is built based on historical call data of the system calls.
[0084] Specifically, step S204 may include:
[0085] Step S2041, based on the pre-built baseline model, determine the mean value and standard deviation of the key feature data.
[0086] In some optional implementations, the average value of the key feature data may be determined based on a pre-built baseline model using the following formula (2):
[0087] μ= (∑x_i) / N (2)
[0088] Among them, μ represents the average value of key feature data;
[0089] x_i represents multiple actual characteristic values of key characteristic data;
[0090] N is the total number of actual eigenvalues of the key feature data.
[0091] In some optional implementations, the standard deviation of an actual characteristic value of the key characteristic data may be determined using the following formula (3):
[0092] σ=sqrt[(∑(x_i-y_i) 2 ) / N] (3)
[0093] Among them, σ represents the standard deviation of key feature data;
[0094] μ represents the average value of key characteristic data;
[0095] x_i represents multiple actual characteristic values of key characteristic data;
[0096] N is the total number of actual eigenvalues of the key feature data.
[0097] Step S2042, based on the average value and standard deviation of multiple key feature data, identify abnormal system calls that are abnormal compared with the pre-built baseline model.
[0098] In some optional implementations, step S2042 may include:
[0099] Step b1: when the actual characteristic value of the key characteristic data is greater than the characteristic threshold, it is determined that the key characteristic data is abnormal, and the characteristic threshold is determined based on the mean value and the standard deviation.
[0100] Here, the feature threshold can be determined using the following formula (4):
[0101] Ty=μ+σ*s (4)
[0102] Among them, Ty represents the feature threshold;
[0103] μ represents the average value of key characteristic data;
[0104] σ represents the standard deviation of key characteristic data;
[0105] s represents a constant and can be 2 to 3 or other appropriate values.
[0106] For example, the baseline model is used to calculate the average value μ and standard deviation σ of the key feature data of the call frequency of a certain system call. Among them, the average value μ = 100 times / hour, and the standard deviation σ = 10 times / hour. The feature threshold Ty can be set to the average value μ plus 3 times the standard deviation σ, and the feature threshold Ty = 130 times / hour.
[0107] Step b2: when the number of abnormal key feature data among the multiple key feature data of the system call is greater than the set feature number, it is determined that the corresponding system call is abnormal.
[0108] In some optional implementations, the number of features is set to 1, that is, as long as there is an abnormality in any key feature data of the system call, it is determined that the system call is abnormal.
[0109] For example, the baseline model is used to calculate the average μ and standard deviation σ of the key characteristic data of the call frequency of a certain system call. Among them, the average μ = 100 times / hour, and the standard deviation σ = 10 times / hour. The characteristic threshold Ty can be set to the average μ plus 3 times the standard deviation σ, then the characteristic threshold Ty = 130 times / hour. During the monitoring period, if the call frequency of a certain system call exceeds 130 times / hour, it can be determined that the system call is abnormal and is an abnormal system call, which requires further analysis and investigation.
[0110] In actual applications, the number of set features can also be set to other values according to actual needs, such as 2 or 3.
[0111] The system call detection method of the embodiment of the present invention determines the feature threshold based on the average value that can describe the data center trend in the baseline model and the standard deviation that can describe the degree of data dispersion, and compares the actual feature value of the key feature data with the feature threshold to determine whether the system call is abnormal. Furthermore, the baseline model is constructed based on the historical call data of the system call, so the baseline model and the corresponding average value and standard deviation can be dynamically adapted and adjusted based on the historical call data of the system call. Therefore, the normal behavior pattern of the system call is learned and analyzed through the baseline model, and the abnormal behavior of the system call is quickly, accurately and efficiently identified, and the system call initiated by hiding or forging means is identified.
[0112] The system call detection method of the embodiment of the present invention determines the mean value and standard deviation of key feature data based on a pre-built baseline model, and identifies abnormal system calls that are abnormal compared to the pre-built baseline model based on the mean values and standard deviations of multiple key feature data. Thus, based on the pre-built baseline model, a comprehensive and effective analysis of the normal behavior pattern of the system call is performed, abnormal system call behavior is quickly and accurately identified, and an efficient, accurate and secure system call detection solution is constructed, which significantly improves the security of the system using the system call detection method of the embodiment of the present invention.
[0113] Step S205: creating a proxy process for continuously monitoring abnormal system calls.
[0114] For details, please see Figure 1 Step S104 of the illustrated embodiment will not be described in detail here.
[0115] In this embodiment, a system call detection method is provided, which can be used in computers, servers, etc. Figure 3 is a flowchart of a specific application example of the system call detection method according to an embodiment of the present invention. Figure 3 As shown, the process includes the following steps:
[0116] Step S301, obtaining historical call data of system calls, where the historical call data has multiple data points.
[0117] Obtaining historical call data of system calls is the process of collecting normal behavior pattern data. Please refer to the above step a1, which will not be repeated here.
[0118] Step S302: construct a baseline model based on historical call data.
[0119] For details, please refer to the above steps a2 to a5, which will not be repeated here.
[0120] Step S303, obtaining call record data of the system call.
[0121] Here, the call record data refers to the current system call, and the current system call list can be obtained through the code interacting with the QNX system. For details, please refer to the above step S101, which will not be repeated here.
[0122] Step S304: pre-process the call record data.
[0123] For details, please refer to the above step S202, which will not be repeated here.
[0124] Step S305: extract features from the call record data to obtain actual feature values of multiple key feature data.
[0125] For details, please refer to the above steps S102 and S203, which will not be repeated here.
[0126] Step S306, based on the multiple actual feature values, identifying abnormal system calls that are abnormal compared to a pre-built baseline model, where the baseline model is built based on historical call data of the system calls.
[0127] For details, please refer to the above step S103 and step S204, which will not be repeated here.
[0128] Step S307: creating a proxy process for continuously monitoring abnormal system calls.
[0129] The above step S307 can be called an anomaly detection algorithm in code implementation. For details, please refer to the above step S104, which will not be repeated here.
[0130] The following is a simple example of the above system call detection method using Python:
[0131] import collections
[0132] import numpy as np
[0133] #Assume there is a function to get the current system call
[0134] def get_current_system_calls():
[0135] #Here is the code to interact with the QNX system and get the current system call list
[0136] #For example, we use a simulated system call list
[0137] return['read','write','open','close','read','write']
[0138] #Collect normal behavior pattern data
[0139] def collect_normal_behavior_data(num_samples):
[0140] normal_data=collections.defaultdict(lambda:collections.Counter())
[0141] for_in range(num_samples):
[0142] syscalls=get_current_system_calls()
[0143] for syscall in syscalls:
[0144] normal_data['process_id'].update([syscall])
[0145] return normal_data
[0146] #Anomaly Detection Algorithm
[0147] def detect_anomalies(current_syscalls,normal_data,threshold=2):
[0148] anomalies=[]
[0149] syscall_counts=collections.Counter(current_syscalls)
[0150] for syscall,count in syscall_counts.items():
[0151] if count>normal_data['process_id'][syscall]*threshold:
[0152] anomalies.append(syscall)
[0153] return anomalies
[0154] #Main program
[0155] def main():
[0156] #Collect normal behavior data
[0157] normal_data=collect_normal_behavior_data(1000)
[0158] #Real-time monitoring of system calls
[0159] while True:
[0160] current_syscalls=get_current_system_calls()
[0161] anomalies=detect_anomalies(current_syscalls,normal_data)
[0162] if anomalies:
[0163] print("Detected anomalies:",anomalies)
[0164] # Check every once in a while
[0165] time.sleep(1)
[0166] if__name__=="__main__":
[0167] main()
[0168] In this embodiment, preferably, the interaction between the proxy process and the kernel is performed through a standardized interface, so it is easier to add new detection functions and strategies, and the scope of application is wider.
[0169] The system call detection method of the embodiment of the present invention effectively statistically analyzes system calls and determines which system calls are normal, as well as the frequency and context of system calls, by establishing a baseline model, in which the mean and standard deviation are used to describe the central trend and dispersion of the data, and cluster analysis is used to identify natural groups or patterns in the data. These methods help establish a reference framework for normal behavior to facilitate subsequent detection of abnormal behavior. By learning and analyzing the normal behavior patterns of system calls through the baseline model, abnormal system call behavior can be identified. As a result, it is possible to dynamically adapt to changes in the system, and detect system calls that are initiated by hiding or forging means, so that a more efficient, accurate and secure system call detection system can be built to make up for the deficiencies of the prior art and improve the overall security of the QNX system.
[0170] In this embodiment, a system call detection device is also provided, which is used to implement the above embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware of a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0171] This embodiment provides a system call detection device, such as Figure 4As shown, the device comprises:
[0172] The acquisition module 401 is used to acquire the call record data of the system call;
[0173] Extraction module 402, used to extract features from call record data to obtain actual feature values of multiple key feature data;
[0174] An identification module 403, for identifying abnormal system calls that are abnormal compared to a pre-built baseline model based on a plurality of actual feature values, the baseline model being built based on historical call data of the system calls;
[0175] The creation module 404 is used to create an agent process for continuously monitoring abnormal system calls.
[0176] In some optional implementations, the call record data includes call log data; the acquisition module 401 includes: a log unit, which is used to acquire the call log data through a system monitoring tool and an audit log.
[0177] In some optional embodiments, the device further comprises:
[0178] The preprocessing module is used to perform data preprocessing on the call record data before extracting features from the call record data.
[0179] In some optional implementations, the key feature data includes the type, frequency, caller identity, call time, and call duration of the system call.
[0180] In some optional implementations, the identification module 403 includes:
[0181] Basic data unit, used to determine the mean and standard deviation of key feature data based on a pre-built baseline model;
[0182] The identification unit is used to identify abnormal system calls that are abnormal compared with a pre-built baseline model based on average values and standard deviations of multiple key feature data.
[0183] In some optional embodiments, the identification unit includes:
[0184] A first determination subunit is used to determine that the key feature data is abnormal when the actual feature value of the key feature data is greater than the feature threshold, and the feature threshold is determined based on the average value and the standard deviation;
[0185] The second determination subunit is used to determine that an abnormality occurs in the corresponding system call when the number of abnormal key feature data among the multiple key feature data of the system call is greater than a set feature number.
[0186] In some optional implementations, the baseline model is constructed using the following operations:
[0187] Obtain historical call data of system calls, where the historical call data has multiple data points;
[0188] Randomly select a set number of data points from the historical call data as the initial cluster centers;
[0189] Assign multiple data points to the initial clustering centers according to a preset rule to form multiple clusters;
[0190] Calculate the cluster centers of clusters and cluster centers based on multiple clusters;
[0191] Repeatedly assign data points to cluster centers and calculate new cluster centers until the number of calculations reaches the set number of iterations or a stable cluster center is obtained.
[0192] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0193] The system call detection device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0194] The embodiment of the present invention also provides a computer device having the above Figure 4 The system call detection device is shown.
[0195] See also Figure 5 , Figure 5 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 5 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 5A processor 10 is taken as an example.
[0196] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.
[0197] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.
[0198] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0199] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.
[0200] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.
[0201] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.
[0202] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.
[0203] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A system call detection method, characterized in that: The method comprises: Get the call record data of the system call; Extracting features from the call record data to obtain actual feature values of multiple key feature data; Based on the plurality of actual feature values, identifying abnormal system calls that are abnormal compared to a pre-built baseline model, the baseline model being built based on historical call data of system calls; An agent process is created for continuously monitoring the abnormal system call.
2. The method according to claim 1, characterized in that The call record data includes call log data; The obtaining of the call record data of the system call includes: The call log data is obtained through system monitoring tools and audit logs.
3. The method according to claim 1, characterized in that Before extracting features from the call record data, the method further includes: The call record data is preprocessed.
4. The method according to claim 1, characterized in that The key characteristic data includes the type, frequency, caller identity, call time and call duration of the system call.
5. The method according to claim 1, characterized in that The step of identifying abnormal system calls that are abnormal compared to a pre-built baseline model based on the multiple actual feature values includes: Determine the mean and standard deviation of the key feature data based on a pre-built baseline model; Based on average values and standard deviations of a plurality of the key feature data, abnormal system calls that are abnormal compared to a pre-built baseline model are identified.
6. The method according to claim 1, characterized in that The method of identifying abnormal system calls that are abnormal compared with a pre-built baseline model based on an average value and a standard deviation of the plurality of key feature data comprises: When the actual characteristic value of the key characteristic data is greater than a characteristic threshold, determining that the key characteristic data is abnormal, wherein the characteristic threshold is determined based on the average value and the standard deviation; When the number of abnormal key feature data among the multiple key feature data of the system call is greater than the set feature number, it is determined that the corresponding system call is abnormal.
7. The method according to claim 1, characterized in that The baseline model is constructed using the following operations: Acquire historical call data of the system call, wherein the historical call data has multiple data points; Randomly selecting a set number of data points from the historical call data as initial cluster centers; Allocating the multiple data points to the initial clustering centers according to a preset rule to form multiple clusters; Calculating the cluster center of the cluster based on the cluster centers of multiple clusters; Repeatedly assign data points to cluster centers and calculate new cluster centers until the number of calculations reaches the set number of iterations or a stable cluster center is obtained.
8. The method according to claim 1, characterized in that The agent process communicates with the kernel via a standardized interface; After creating the proxy process for continuously monitoring the abnormal system call, the method further includes: When the system call occurs, the kernel sends a notification to the agent process; The proxy process performs abnormality detection on the system call.
9. A system call detection device, characterized in that: The device comprises: An acquisition module is used to obtain call record data of system calls; An extraction module, used for performing feature extraction on the call record data to obtain actual feature values of multiple key feature data; an identification module, configured to identify, based on the plurality of actual feature values, abnormal system calls that are abnormal compared to a pre-built baseline model, wherein the baseline model is built based on historical call data of the system calls; A creation module is used to create an agent process for continuously monitoring the abnormal system call.
10. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the system call detection method according to any one of claims 1 to 8 by executing the computer instructions.