Embedded integrity measurement method and system combining coarse and fine granularities

By adopting the integrity measurement method of coarse and fine-grained combination in embedded devices, the problem of large overhead in IMA architecture in embedded devices is solved, the defense effectiveness is enhanced, and the resistance to TOCTOU attacks is improved, and efficient integrity measurement is achieved.

CN120012105APending Publication Date: 2025-05-16HUNAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510090889.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing IMA architecture in embedded devices has a large overhead due to poor hashing algorithm performance; the lack of runtime periodic measurements reduces defense effectiveness; and its resistance to TOCTOU attacks is limited.

Method used

The embedded integrity measurement method combined with coarse and fine granularity is adopted. By extracting the metric objects from the kernel physical memory for hash hash encryption, a hash benchmark library is constructed, and the TOCTOU attack detection rate is obtained using the computer simulation modeling method, the functional relationship between CPU load and metric period is fitted, the best metric period sequence is generated, and the coarse and fine granularity measurement method is dynamically switched.

Benefits of technology

It significantly reduces system performance overhead, enhances defense effectiveness, improves resistance to TOCTOU attacks, and achieves efficient integrity measurements under limited CPU resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012105A_ABST
    Figure CN120012105A_ABST
Patent Text Reader

Abstract

The invention discloses an efficient integrity measurement method for embedded equipment. The method comprises the following steps: firstly, extracting all measurement objects; the first stage involves performing a hash operation on the objects to derive a plurality of hash values; a hash table is adopted as a data structure to store the objects, keys are selected according to the types of the objects, and hash values of the objects serve as key values; storing the hash table as a reference library; then, modeling to obtain a TOCTOU attack detection rate, fitting a function relationship between a measurement period and a CPU load, and generating a randomized period sequence according to the relationship so as to realize maximum utilization of resources; and finally, randomly selecting a measurement period in the randomized period sequence, comparing the CPU load of the current embedded equipment with a CPU load threshold value of the embedded equipment, selecting a coarse-grained or fine-grained measurement scheme, starting measurement, and judging whether the integrity of a measurement object is damaged or not.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of embedded real-time operating system kernels, and more specifically, relates to a coarse-grained and fine-grained embedded integrity measurement method and system. Background Art

[0002] Today, the Linux kernel is widely used in embedded systems, especially in the fields of intelligence and connectivity, which is inseparable from its large open source community, high stability and high reliability. As technology continues to develop, the demand for security is becoming increasingly prominent, because any damage to the integrity of the kernel may lead to serious consequences, such as modifying unauthorized kernel code or data structures may cause system failures, vulnerabilities or complete crashes. Therefore, maintaining the integrity of the Linux kernel at runtime is crucial to the security and stability of the entire embedded system.

[0003] In order to enhance the integrity of the Linux kernel, researchers developed the Linux security module (LSM). The Integrity Measurement Architecture (IMA) is an important component of the LSM, which is used to ensure the integrity of system files and applications, prevent them from being tampered with, and strictly comply with the Trusted Computing Group (TCG) standards. The IMA architecture includes two major modes: measurement and evaluation. The measurement mode records the integrity status of the file, while the evaluation mode verifies the integrity of the file and denies access to tampered files. In addition, the IMA architecture also provides flexibly configurable security policies to define measurement and evaluation rules to meet different security needs.

[0004] However, the above IMA architecture still has some non-negligible defects:

[0005] First, due to the poor performance of the hash algorithm of the IMA architecture, the IMA architecture will bring significant overhead, which is unacceptable for most embedded devices with limited computing resources and strict timing requirements;

[0006] Second, the IMA architecture itself is not periodic and requires configuring scheduled tasks to implement periodic measurements, which weakens the effectiveness of defense;

[0007] Third, the IMA architecture has limited resistance to time-of-check-to-time-of-use (TOCTOU) attacks and cannot prevent runtime attacks. Summary of the invention

[0008] In view of the above defects or improvement needs of the prior art, the present invention provides a coarse-grained and fine-grained embedded integrity measurement method and system, which aims to solve the technical problems of high overhead of the existing enhanced Linux kernel integrity policy, the technical problem of weakening the effectiveness of defense due to the lack of runtime periodic measurement, and the technical problem of limited resistance to TOCTOU attacks.

[0009] To achieve the above object, according to one aspect of the present invention, there is provided an efficient integrity measurement method for an embedded device, comprising the following steps:

[0010] (1) Extract multiple measurement objects of the embedded device from the kernel physical memory of the embedded device, perform hash encryption processing on all the measurement objects, store the processed results in a hash table, and store the hash table storing the results in a trusted platform module TPM to build a hash benchmark library.

[0011] (2) Using a computer simulation modeling method, the hash benchmark library obtained in step (1) is simulated and modeled to obtain the TOCTOU attack detection rate, the CPU load and measurement cycle of the embedded device, and fit the functional relationship between the CPU load and the measurement cycle of the embedded device to obtain the optimal measurement cycle sequence.

[0012] (3) Randomly select a measurement period from the measurement period sequence obtained in step (2), and obtain the CPU load of the embedded device based on the measurement period.

[0013] (4) According to the CPU load of the current embedded device obtained from step (3), determine whether the CPU load of the current embedded device is greater than the CPU load threshold of the embedded device. If so, proceed to step (5); otherwise, proceed to step (8).

[0014] (5) Obtain multiple measurement objects from the embedded device; set the counter k=0, and obtain the hash table from the hash reference library of the trusted platform module.

[0015] (6) Set k=k+1, obtain the hash value of the kth measurement object among the multiple measurement objects obtained in step (5), and determine whether the hash value is the same as the hash value of the kth measurement object in the hash table obtained in step (5). If so, proceed to step (7). Otherwise, it indicates that the kth measurement object among the multiple measurement objects has been attacked, and the type of the kth measurement object in the hash table is sent to the embedded device.

[0016] (7) Determine whether k is equal to the size of the hash table obtained in step (5). If so, the process ends; otherwise, return to step (6).

[0017] (8) Set counter l=0.

[0018] (9) Determine whether there is a security value file in the memory of the embedded device, and whether the difference between the current time and the creation time of the security value file exceeds the timeout threshold of the security value file, otherwise proceed to step (10);

[0019] (10) Use the touch security number.txt command in the Linux operating system to create a file, write the creation time and timeout threshold of the file, the security value of each measurement object in the hash table of the hash benchmark library obtained in step (1) (whose initial value is 50), and the measurement flag of the measurement object (whose initial value is 0) into the file, thereby obtaining a created security value file, and then proceed to step (11);

[0020] (11) Obtain the security value file from the memory of the embedded device; obtain the hash table from the hash reference library of the trusted platform module; set the counter m=0.

[0021] (12) Set m=m+1, use a random seed to generate a random value, and determine whether the random value is greater than or equal to the security value of the mth measurement object in the security value file obtained from step (11). If so, proceed to step (13), otherwise proceed to step (14).

[0022] (13) Setting the metric flag of the mth metric object in the security value file obtained from step (11) to 1, increasing the security value of the metric object, and setting the counter l=l+1, and then proceeding to step (15);

[0023] (14) reducing the safety value of the mth measurement object in the safety value file obtained in step (11), and then proceeding to step (15);

[0024] (15) Determine whether m is equal to the size of the hash table obtained in step (11). If so, proceed to step (16); otherwise, return to step (12).

[0025] (16) Set counter n=0.

[0026] (17) Set the counter n=n+1, and determine whether the measurement flag of the nth measurement object in the security value file obtained from step (11) is 1. If so, proceed to step (18); otherwise, proceed to step (17).

[0027] (18) Set the measurement flag of the nth measurement object in the security value file to 0, set the counter l=l-1, obtain the hash value of the nth measurement object from the hash table, and determine whether the hash value is the same as the hash value of the nth measurement object in the hash table obtained in step (11). If so, proceed to step (19). Otherwise, it indicates that the nth measurement object has been attacked. Send the type of the nth measurement object in the hash table to the embedded device, and then proceed to step (19).

[0028] (19) Determine whether l is equal to 0. If so, update the creation time of the security value file obtained from step (11) to the current time, and store the file in the memory of the embedded device. The process ends. Otherwise, return to step (17).

[0029] Preferably, step (1) specifically includes the following sub-steps:

[0030] (1-1) Acquire multiple measurement objects in the kernel physical memory of the embedded device, and extract all the acquired measurement objects into the memory.

[0031] (1-2) Perform hash encryption processing on all measurement objects obtained in step (1-1), use a hash table to store all hash-encrypted measurement objects, and store the hash table in a trusted platform module to build a hash benchmark library.

[0032] Preferably, the acquired measurement objects include the following types: kernel code segment, kernel data segment, system call table, global symbol table, interrupt symbol table, file system, kernel module, and user-mode process space.

[0033] Step (1-1) is as follows: first, use the kernel function kallsyms_lookup_name to obtain the first address and offset of the measurement object from the kernel physical memory, then allocate the corresponding space in the memory according to the offset size, then select the array as the data structure, and finally, according to the first address and offset of the measurement object, use the array to cyclically transfer the measurement object to the memory.

[0034] Step (1-2) is specifically as follows: first, SHA256 hash encryption is performed on each extracted measurement object to obtain the hash value corresponding to the measurement object, and then a hash table is selected as a data structure to store all hashed and encrypted objects, wherein the kernel code segment, kernel data segment, system call table, global symbol table, and interrupt symbol table are keyed by their first addresses in the kernel, the file system is keyed by the attributes and inode number of its corresponding file, the kernel module is keyed by its corresponding module name, the user-state process is keyed by its corresponding process PID, and the hash values ​​corresponding to the kernel code segment, kernel data segment, system call table, global symbol table, interrupt symbol table, kernel module, and user-state process are used as values ​​to form key-value pairs, and all key-value pairs form a hash table. Finally, the entire hash table is stored in the trusted platform module to build a hash benchmark library.

[0035] Preferably, step (2) specifically includes the following sub-steps:

[0036] (2-1) Use a computer simulation modeling method to perform simulation cycle measurement on the hash benchmark library obtained in step (1) to obtain the TOCTOU attack detection rate.

[0037] (2-2) Using a nonlinear least squares fitting algorithm, the TOCTOU attack detection rate obtained in step (2-1) is fitted to obtain a fitting function;

[0038] (2-3) Determine the measurement period range parameters based on the TOCTOU attack detection rate obtained in step (2-1) and the fitting function obtained in step (2-2), and obtain the measurement period sequence based on the measurement period range parameters.

[0039] Preferably, step (2-1) comprises the following sub-steps:

[0040] (2-1-1) Create empty sets attack_regions and random_points;

[0041] (2-1-2) Generate simulated attack events through the hash benchmark library established in step (1-2). For each simulated attack event, extract the start and end points of the attack region where it is located. Store the extracted start and end points as a tuple (start, end) and add it to the set attack_regions.

[0042] (2-1-3) Generate multiple measurement points and store all the measurement points in the set random_points in sequence.

[0043] (2-1-4) Create a variable detected_attacks with an initial value of 0.

[0044] (2-1-5) Set counter i=0. ,

[0045] (2-1-6) Set counter j=0.

[0046] (2-1-7) Set i=i+1, and determine whether i is equal to the total amount of data attack_regions_size in the set attack_regions. If so, go to step (2-1-11), otherwise go to step (2-1-8).

[0047] (2-1-8) Get the i-th attack region from the set attack_regions as the current attack region current_region.

[0048] (2-1-9) Determine whether the j+1th measurement point in the set random_points is within the range of the current attack region current_region. If so, set the variable detected_attacks = detected_attacks + 1, and then go to step (2-1-10), otherwise go to step (2-1-10).

[0049] (2-1-10) Set j=j+1, and determine whether j is equal to the total amount of data random_points_size in the set random_points. If so, return to step (2-1-6), otherwise return to step (2-1-9).

[0050] (2-1-11) The value of the variable detected_attacks is taken as the total number of detected attack events, and is divided by the total number of attack events in all attack areas in the hash benchmark library. The result is the TOCTOU attack detection rate.

[0051] Preferably, the fitting formula obtained in step (2-2) is:

[0052] ln(cpu load )=2.6446×e ―0.00023×period -0.3952

[0053] Where cpu load Indicates the CPU load of the embedded device, and period indicates the measurement period of the embedded device.

[0054] Preferably, step (2-3) comprises the following sub-steps:

[0055] (2-3-1) Set the TOCTOU attack detection rate obtained in step (2-1) as parameter σ 2, substitute the CPU load of the embedded device into the fitting formula obtained in step (2-2) to obtain the measurement period of the embedded device, and set the measurement period as parameter μ to obtain the measurement period range parameter (μ±σ).

[0056] (2-3-2) generating a measurement period sequence according to the measurement period range parameters obtained in step (2-3-1) and using a random number generation algorithm;

[0057] Specifically, this step is as follows: first, initialize the size of the measurement period sequence to 10, and then substitute the measurement period range parameter and the size of the measurement period sequence obtained in step (2-3-1) into the machine number generation algorithm Xorshift algorithm to obtain the measurement period sequence.

[0058] According to another aspect of the present invention, there is provided an efficient integrity measurement system for an embedded device, comprising:

[0059] The first module is used to extract multiple measurement objects of the embedded device from the kernel physical memory of the embedded device, perform hash encryption processing on all measurement objects, store the processed results in a hash table, and store the hash table storing the results in a trusted platform module TPM to build a hash benchmark library.

[0060] The second module is used to perform simulation modeling processing on the hash benchmark library obtained in the first module using a simulation modeling method of computer simulation to obtain the TOCTOU attack detection rate, the CPU load and measurement cycle of the embedded device, and fit the functional relationship between the CPU load and measurement cycle of the embedded device to obtain the optimal measurement cycle sequence.

[0061] The third module is used to randomly select a measurement period from the measurement period sequence obtained by the second module, and obtain the CPU load of the embedded device according to the measurement period.

[0062] The fourth module is used to determine whether the CPU load of the current embedded device is greater than the CPU load threshold of the embedded device according to the CPU load of the current embedded device obtained from the third module, and if so, enter the fifth module, otherwise enter the eighth module.

[0063] The fifth module is used to obtain multiple measurement objects from the embedded device, set the counter k=0, and obtain the hash table from the hash reference library of the trusted platform module.

[0064] The sixth module is used to set k=k+1, obtain the hash value of the kth measurement object among the multiple measurement objects obtained by the fifth module, and determine whether the hash value is the same as the hash value of the kth measurement object in the hash table obtained by the fifth module. If so, enter the seventh module; otherwise, it indicates that the kth measurement object among the multiple measurement objects has been attacked, and the type of the kth measurement object in the hash table is sent to the embedded device.

[0065] The seventh module is used to determine whether k is equal to the size of the hash table obtained by the sixth module. If so, the process ends, otherwise it returns to the sixth module.

[0066] The eighth module is used to set the counter l=0.

[0067] The ninth module is used to determine whether there is a security value file in the memory of the embedded device, and whether the difference between the current time and the creation time of the security value file exceeds the timeout threshold of the security value file, otherwise, it goes to the tenth module;

[0068] The tenth module is used to create a file using the touch security number.txt command in the Linux operating system, write the creation time and timeout threshold of the file, the security value of each measurement object in the hash table in the hash benchmark library obtained in the first module (whose initial value is 50), and the measurement flag bit of the measurement object (whose initial value is 0) into the file, thereby obtaining the created security value file, and then proceeding to the eleventh module;

[0069] The eleventh module is used to obtain the security value file from the memory of the embedded device, obtain the hash table from the hash reference library of the trusted platform module, and set the counter m=0.

[0070] The twelfth module is used to set m=m+1, use a random seed to generate a random value, and determine whether the random value is greater than or equal to the security value of the mth measurement object in the security value file obtained from the twelfth module. If so, enter the thirteenth module, otherwise enter the fourteenth module.

[0071] The thirteenth module is used to set the measurement flag bit of the mth measurement object in the security value file obtained from the eleventh module to 1, increase the security value of the measurement object, and set the counter l=l+1, and then transfer to the fifteenth module;

[0072] The fourteenth module is used to reduce the security value of the mth measurement object in the security value file obtained by the eleventh module, and then enter the fifteenth module;

[0073] In the fifteenth module, the user determines whether m is equal to the size of the hash table obtained in the eleventh module. If so, the user enters the sixteenth module, otherwise, the user returns to the twelfth module.

[0074] The sixteenth module is used to set the counter n=0.

[0075] The seventeenth module is used to set the counter n=n+1 and determine whether the measurement flag bit of the nth measurement object in the security value file obtained from the eleventh module is 1, if so, enter the eighteenth module, otherwise enter the seventeenth module.

[0076] The eighteenth module is used to set the measurement flag of the nth measurement object in the security value file to 0, set the counter l=l-1, obtain the hash value of the nth measurement object from the hash table, and determine whether the hash value is the same as the hash value of the nth measurement object in the hash table obtained by the eleventh module. If so, enter the nineteenth module, otherwise it means that the nth measurement object has been attacked, send the type of the nth measurement object in the hash table to the embedded device, and then enter the nineteenth module.

[0077] The nineteenth module is used to determine whether l is equal to 0. If so, the creation time of the security value file obtained from the eleventh module is updated to the current time, and the file is stored in the memory of the embedded device. The process ends, otherwise it returns to the seventeenth module.

[0078] In general, the above technical solutions conceived by the present invention can achieve the following beneficial effects compared with the prior art:

[0079] (1) Due to the adoption of step (1), the present invention adopts a hash table to store hash values. In the hash table, the measurement object type and the calculated hash value of the measurement object form a key-value pair. Based on the characteristics of the hash table itself that it can add, delete, modify, and search quickly, the search and comparison speed is greatly accelerated, and the performance overhead of the system is reduced;

[0080] (2) Due to the adoption of step (2), the present invention uses a TOCTOU attack detection method, fits the functional relationship between the CPU load of the embedded device and the measurement cycle interval, and generates a measurement cycle sequence, thereby obtaining a TOCTOU attack detection rate under limited CPU overhead of the embedded device, thereby enhancing the effectiveness of defense;

[0081] (3) The present invention adopts steps (3) to (19), so the selection of random measurement period can not only effectively defend against TOCTOU attack, but also control the measurement period interval within a reasonable range; at the same time, the coarse-grained and fine-grained measurement methods are reasonably selected according to the CPU load of the embedded device, which can not only effectively monitor whether the system is attacked during operation, but also effectively control the CPU overhead of the embedded device. The coarse-grained method can reduce the overhead when the system load is high, and the fine-grained method can provide stronger and more refined security protection when the load is light through the security value file. These two methods together ensure a powerful and efficient monitoring system. BRIEF DESCRIPTION OF THE DRAWINGS

[0082] Figure 1 It is a schematic diagram of the overall framework of the embedded integrity measurement method based on the combination of coarse and fine granularity of the present invention;

[0083] Figure 2 It is a flow chart of the embedded integrity measurement method based on the combination of coarse and fine granularity of the present invention. DETAILED DESCRIPTION

[0084] In order to make the purpose, technical scheme and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0085] The basic idea of ​​the present invention is to first extract all measurement objects, such as kernel code segments, kernel data segments, system call tables, global symbol tables, interrupt symbol tables, file systems, kernel modules, and user-mode process spaces. The first stage involves performing hash operations on these objects to derive multiple hash values; using a hash table as a data structure to store these objects, selecting a key based on the object type, and its hash value as the key value; and storing the hash table as a benchmark library. Then, a model is built to obtain the TOCTOU attack detection rate, fit the functional relationship between the measurement cycle and the CPU load, and generate a randomized cycle sequence based on the relationship to maximize resource utilization. Finally, a measurement cycle is randomly selected in the randomized cycle sequence, and the CPU load of the current embedded device is compared with the CPU load threshold of the embedded device, a coarse-grained or fine-grained measurement scheme is selected and measurement is started to determine whether the integrity of the measurement object is damaged.

[0086] like Figure 1 and Figure 2 As shown, the present invention provides an efficient integrity measurement method for embedded devices, comprising the following steps:

[0087] (1) Extract multiple measurement objects of the embedded device from the kernel physical memory of the embedded device, perform hash encryption processing on all the measurement objects, store the processed results in a hash table, and store the hash table containing the results in a trusted platform module (Trusted Platform Module, TPM) to build a hash benchmark library.

[0088] Specifically, this step includes the following sub-steps:

[0089] (1-1) Acquire multiple measurement objects in the kernel physical memory of the embedded device, and extract all the acquired measurement objects into the memory.

[0090] Specifically, the acquired measurement objects include the following types: kernel code segment, kernel data segment, system call table, global symbol table, interrupt symbol table, file system, kernel module, and user-mode process space.

[0091] Specifically, this step is as follows: first, use the kernel function kallsyms_lookup_name to obtain the first address and offset of the measurement object from the kernel physical memory, then allocate the corresponding space in the memory according to the offset size, then select the array as the data structure, and finally, according to the first address and offset of the measurement object, use the array to cyclically transfer the measurement object to the memory.

[0092] (1-2) Perform hash encryption processing on all measurement objects obtained in step (1-1), use a hash table to store all hash-encrypted measurement objects, and store the hash table in a trusted platform module to build a hash benchmark library.

[0093] Specifically, this step first performs SHA256 hash encryption processing on each extracted measurement object to obtain the hash value corresponding to the measurement object, and then selects a hash table as a data structure to store all hashed and encrypted objects, wherein the kernel code segment, kernel data segment, system call table, global symbol table, and interrupt symbol table are keyed by their first addresses in the kernel, the file system is keyed by the attributes and inode number of its corresponding file, the kernel module is keyed by its corresponding module name, the user-state process is keyed by its corresponding process PID, and the hash values ​​corresponding to the kernel code segment, kernel data segment, system call table, global symbol table, interrupt symbol table, kernel module, and user-state process are used as values ​​to form key-value pairs, and all key-value pairs form a hash table. Finally, the entire hash table is stored in the trusted platform module to build a hash benchmark library.

[0094] The advantage of the above sub-steps (1-1) to (1-2) is that a hash table is used for storage. The hash table is an efficient data structure that can be used to implement fast insertion, deletion and search operations. It has an extremely low average time complexity and can greatly reduce the performance overhead of the system, thereby meeting the limited computing resources and strict timing requirements of embedded applications.

[0095] (2) Using a computer simulation modeling method, the hash benchmark library obtained in step (1) is simulated and modeled to obtain the TOCTOU attack detection rate, the CPU load and measurement cycle of the embedded device, and fit the functional relationship between the CPU load and the measurement cycle of the embedded device to obtain the optimal measurement cycle sequence.

[0096] Specifically, this step includes the following sub-steps:

[0097] (2-1) Use a computer simulation modeling method to perform simulation cycle measurement on the hash benchmark library obtained in step (1) to obtain the TOCTOU attack detection rate.

[0098] This step includes the following sub-steps:

[0099] (2-1-1) Create empty sets attack_regions and random_points;

[0100] (2-1-2) Generate simulated attack events through the hash benchmark library established in step (1-2). For each simulated attack event, extract the start and end points of the attack region where it is located. Store the extracted start and end points as a tuple (start, end) and add it to the set attack_regions.

[0101] (2-1-3) Generate multiple measurement points and store all the measurement points in the set random_points in sequence.

[0102] (2-1-4) Create a variable detected_attacks with an initial value of 0.

[0103] (2-1-5) Set counter i=0. ,

[0104] (2-1-6) Set counter j=0.

[0105] (2-1-7) Set i=i+1, and determine whether i is equal to the total amount of data attack_regions_size in the set attack_regions. If so, go to step (2-1-11), otherwise go to step (2-1-8).

[0106] (2-1-8) Get the i-th attack region from the set attack_regions as the current attack region current_region.

[0107] (2-1-9) Determine whether the j+1th measurement point in the set random_points is within the range of the current attack region current_region. If so, set the variable detected_attacks = detected_attacks + 1, and then go to step (2-1-10), otherwise go to step (2-1-10).

[0108] (2-1-10) Set j=j+1, and determine whether j is equal to the total amount of data random_points_size in the set random_points. If so, return to step (2-1-6), otherwise return to step (2-1-9).

[0109] (2-1-11) The value of the variable detected_attacks is taken as the total number of detected attack events, and is divided by the total number of attack events in all attack areas in the hash benchmark library. The result is the TOCTOU attack detection rate.

[0110] (2-2) Use a nonlinear least squares fitting algorithm to fit the TOCTOU attack detection rate obtained in step (2-1) to obtain a fitting function (the fitting function is related to the CPU load and measurement cycle of the embedded device).

[0111] The fitting formula obtained in this step is:

[0112] ln(cpu load )=2.6446×e ―0.00023×period -0.3952

[0113] Where cpu load Indicates the CPU load of the embedded device, and period indicates the measurement period of the embedded device.

[0114] (2-3) Determine the measurement period range parameters based on the TOCTOU attack detection rate obtained in step (2-1) and the fitting function obtained in step (2-2), and obtain the measurement period sequence based on the measurement period range parameters.

[0115] This step includes the following sub-steps:

[0116] (2-3-1) Set the TOCTOU attack detection rate obtained in step (2-1) as parameter σ 2, substitute the CPU load of the embedded device into the fitting formula obtained in step (2-2) to obtain the measurement period of the embedded device, and set the measurement period as parameter μ to obtain the measurement period range parameter (μ±σ).

[0117] (2-3-2) Generate a measurement period sequence based on the measurement period range parameters obtained in step (2-3-1) and using a random number generation algorithm.

[0118] Specifically, this step is as follows: first, initialize the size of the measurement period sequence to 10, and then substitute the measurement period range parameter and the size of the measurement period sequence obtained in step (2-3-1) into the machine number generation algorithm Xorshift algorithm (this algorithm is a pseudo-random number generation algorithm based on XOR and shift operations, with the characteristics of fast generation speed and low memory consumption, and is suitable for embedded application environments) to obtain the measurement period sequence.

[0119] The advantages of the above sub-steps (2-1) to (2-3) are that a TOCTOU attack detection method is adopted to generate a measurement cycle sequence in combination with the functional relationship between the CPU load of the embedded device and the measurement cycle interval. This method effectively obtains the TOCTOU attack detection rate under limited embedded device CPU overhead, thereby enhancing the defense mechanism.

[0120] (3) Randomly select a measurement period from the measurement period sequence obtained in step (2), and obtain the CPU load of the embedded device based on the measurement period.

[0121] Specifically, a measurement cycle is randomly selected from the measurement cycle sequence obtained in step (2) as a measurement cycle, and a timer is started. After the measurement cycle starts, the CPU load of the embedded device is obtained through the eBPF technology, and then the timer is stopped.

[0122] (4) According to the CPU load of the current embedded device obtained from step (3), determine whether the CPU load of the current embedded device is greater than the CPU load threshold of the embedded device. If so, proceed to step (5); otherwise, proceed to step (8).

[0123] (5) Obtain multiple measurement objects from the embedded device; set the counter k=0, and obtain the hash table from the hash reference library of the trusted platform module.

[0124] (6) Set k=k+1, obtain the hash value of the kth measurement object among the multiple measurement objects obtained in step (5), and determine whether the hash value is the same as the hash value of the kth measurement object in the hash table obtained in step (5). If so, proceed to step (7). Otherwise, it indicates that the kth measurement object among the multiple measurement objects has been attacked, and the type of the kth measurement object in the hash table is sent to the embedded device.

[0125] (7) Determine whether k is equal to the size of the hash table obtained in step (5). If so, the process ends; otherwise, return to step (6).

[0126] (8) Set counter l=0.

[0127] (9) Determine whether there is a security value file in the memory of the embedded device, and whether the difference between the current time and the creation time of the security value file exceeds the timeout threshold of the security value file, otherwise proceed to step (10);

[0128] (10) Use the touch security number.txt command in the Linux operating system to create a file, write the creation time and timeout threshold of the file, the security value of each measurement object in the hash table of the hash benchmark library obtained in step (1) (whose initial value is 50), and the measurement flag of the measurement object (whose initial value is 0) into the file, thereby obtaining a created security value file, and then proceed to step (11);

[0129] (11) Obtain the security value file from the memory of the embedded device; obtain the hash table from the hash reference library of the trusted platform module; set the counter m=0.

[0130] (12) Set m=m+1, use a random seed to generate a random value, and determine whether the random value is greater than or equal to the security value of the mth measurement object in the security value file obtained from step (11). If so, proceed to step (13), otherwise proceed to step (14).

[0131] (13) Setting the metric flag of the mth metric object in the security value file obtained from step (11) to 1, increasing the security value of the metric object, and setting the counter l=l+1, and then proceeding to step (15);

[0132] (14) reducing the safety value of the mth measurement object in the safety value file obtained in step (11), and then proceeding to step (15);

[0133] (15) Determine whether m is equal to the size of the hash table obtained in step (11). If so, proceed to step (16); otherwise, return to step (12).

[0134] (16) Set counter n=0.

[0135] (17) Set the counter n=n+1, and determine whether the measurement flag of the nth measurement object in the security value file obtained from step (11) is 1. If so, proceed to step (18); otherwise, proceed to step (17).

[0136] (18) Set the measurement flag of the nth measurement object in the security value file to 0, set the counter l=l-1, obtain the hash value of the nth measurement object from the hash table, and determine whether the hash value is the same as the hash value of the nth measurement object in the hash table obtained in step (11). If so, proceed to step (19). Otherwise, it indicates that the nth measurement object has been attacked. Send the type of the nth measurement object in the hash table to the embedded device, and then proceed to step (19).

[0137] (19) Determine whether l is equal to 0. If so, update the creation time of the security value file obtained from step (11) to the current time, and store the file in the memory of the embedded device. The process ends. Otherwise, return to step (17).

[0138] The advantages of the above steps (3) to (19) are that the use of random measurement cycle sequences can not only effectively defend against TOCTOU attacks, but also control the measurement cycle interval within a reasonable range. In addition, by dynamically switching between coarse-grained and fine-grained methods according to the CPU load of the embedded device, the CPU overhead of the embedded device can be reasonably controlled. Specifically, the coarse-grained method can reduce the overhead when the system load is high, while the fine-grained method can provide stronger security protection when the load is light, thereby ensuring that the monitoring system is both powerful and efficient.

[0139] Test Results

[0140] The test environment of the present invention is carried out on the hardware device OK1028A-C_Ubuntu, whose Ubuntu version is 18.04.1, kernel version is 5.4.3, dual-core ARMCortex-A72 processor, onboard 2GB DDR4 RAM, 8GB ROM.

[0141] In order to evaluate the performance of the system of the present invention, the performance testing tool LMBench is used to compare the performance differences brought by the IMA architecture and the IMA architecture combined with the present invention to the operating system. Common system call operations, including read, write, and open / close operations, as well as context switch delays under 2, 4, 8, and 16 process parallel configurations are evaluated. A standardized workload size of 1024KB is used, and each test is repeated 100 times to calculate the average delay value. In order to ensure consistency and minimize fluctuations, a 10-second warm-up phase is applied before each test to stabilize system resources, especially the use of cache.

[0142] The system call latency results are shown in Table 1. The present invention introduces an average overhead of 8.7% compared to only enabling the IMA architecture. The biggest impact is on the open and close operations, which have a maximum additional latency of 0.113 milliseconds due to the measurement process of the present invention (involving file operations). Nevertheless, the overall overhead is still small and acceptable for actual deployment.

[0143] Table 1 System call delay results (unit: ms)

[0144]

[0145] The context switch delay results are shown in Table 2. The average overhead is 2.3%, and the maximum increase is 0.91 milliseconds under a single process configuration. As the number of parallel processes increases, the impact gradually decreases, proving that the performance overhead brought by the present invention is almost negligible and suitable for resource-constrained environments.

[0146] Table 2 Context switch delay results (unit: ms)

[0147]

[0148] It will be easily understood by those skilled in the art that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. An efficient integrity measurement method for embedded devices, characterized in that: The following steps are involved: (1) Extract multiple measurement objects of the embedded device from the kernel physical memory of the embedded device, perform hash encryption processing on all the measurement objects, store the processed results in a hash table, and store the hash table storing the results in a trusted platform module TPM to build a hash benchmark library. (2) Using a computer simulation modeling method, the hash benchmark library obtained in step (1) is simulated and modeled to obtain the TOCTOU attack detection rate, the CPU load and measurement cycle of the embedded device, and fit the functional relationship between the CPU load and the measurement cycle of the embedded device to obtain the optimal measurement cycle sequence. (3) Randomly select a measurement period from the measurement period sequence obtained in step (2), and obtain the CPU load of the embedded device based on the measurement period. (4) According to the CPU load of the current embedded device obtained from step (3), determine whether the CPU load of the current embedded device is greater than the CPU load threshold of the embedded device. If so, proceed to step (5); otherwise, proceed to step (8). (5) Obtain multiple measurement objects from the embedded device; set the counter k=0, and obtain the hash table from the hash reference library of the trusted platform module. (6) Set k=k+1, obtain the hash value of the kth measurement object among the multiple measurement objects obtained in step (5), and determine whether the hash value is the same as the hash value of the kth measurement object in the hash table obtained in step (5). If so, proceed to step (7). Otherwise, it indicates that the kth measurement object among the multiple measurement objects has been attacked, and the type of the kth measurement object in the hash table is sent to the embedded device. (7) Determine whether k is equal to the size of the hash table obtained in step (5). If so, the process ends; otherwise, return to step (6). (8) Set counter l=0. (9) Determine whether there is a security value file in the memory of the embedded device, and whether the difference between the current time and the creation time of the security value file exceeds the timeout threshold of the security value file, otherwise proceed to step (10); (10) Use the touch security number.txt command in the Linux operating system to create a file, write the creation time and timeout threshold of the file, the security value of each measurement object in the hash table of the hash benchmark library obtained in step (1) (whose initial value is 50), and the measurement flag of the measurement object (whose initial value is 0) into the file, thereby obtaining a created security value file, and then proceed to step (11); (11) Obtain the security value file from the memory of the embedded device; obtain the hash table from the hash reference library of the trusted platform module; set the counter m=0. (12) Set m=m+1, use a random seed to generate a random value, and determine whether the random value is greater than or equal to the security value of the mth measurement object in the security value file obtained from step (11). If so, proceed to step (13), otherwise proceed to step (14). (13) Setting the metric flag of the mth metric object in the security value file obtained from step (11) to 1, increasing the security value of the metric object, and setting the counter l=l+1, and then proceeding to step (15); (14) reducing the safety value of the mth measurement object in the safety value file obtained in step (11), and then proceeding to step (15); (15) Determine whether m is equal to the size of the hash table obtained in step (11). If so, proceed to step (16); otherwise, return to step (12). (16) Set counter n=0. (17) Set the counter n=n+1, and determine whether the measurement flag of the nth measurement object in the security value file obtained from step (11) is 1. If so, proceed to step (18); otherwise, proceed to step (17). (18) Set the measurement flag of the nth measurement object in the security value file to 0, set the counter l=l-1, obtain the hash value of the nth measurement object from the hash table, and determine whether the hash value is the same as the hash value of the nth measurement object in the hash table obtained in step (11). If so, proceed to step (19). Otherwise, it indicates that the nth measurement object has been attacked. Send the type of the nth measurement object in the hash table to the embedded device, and then proceed to step (19). (19) Determine whether l is equal to 0. If so, update the creation time of the security value file obtained from step (11) to the current time, and store the file in the memory of the embedded device. The process ends. Otherwise, return to step (17).

2. The efficient integrity measurement method for embedded devices according to claim 1, characterized in that: Step (1) specifically includes the following sub-steps: (1-1) Acquire multiple measurement objects in the kernel physical memory of the embedded device, and extract all the acquired measurement objects into the memory. (1-2) Perform hash encryption processing on all measurement objects obtained in step (1-1), use a hash table to store all hash-encrypted measurement objects, and store the hash table in a trusted platform module to build a hash benchmark library.

3. The efficient integrity measurement method for embedded devices according to claim 1 or 2, characterized in that: The acquired measurement objects include the following types: kernel code segment, kernel data segment, system call table, global symbol table, interrupt symbol table, file system, kernel module, and user-mode process space. Step (1-1) is as follows: first, use the kernel function kallsyms_lookup_name to obtain the first address and offset of the measurement object from the kernel physical memory, then allocate the corresponding space in the memory according to the offset size, then select the array as the data structure, and finally, according to the first address and offset of the measurement object, use the array to cyclically transfer the measurement object to the memory. Step (1-2) is specifically as follows: first, SHA256 hash encryption is performed on each extracted measurement object to obtain the hash value corresponding to the measurement object, and then a hash table is selected as a data structure to store all hashed and encrypted objects, wherein the kernel code segment, kernel data segment, system call table, global symbol table, and interrupt symbol table are keyed by their first addresses in the kernel, the file system is keyed by the attributes and inode number of its corresponding file, the kernel module is keyed by its corresponding module name, the user-state process is keyed by its corresponding process PID, and the hash values ​​corresponding to the kernel code segment, kernel data segment, system call table, global symbol table, interrupt symbol table, kernel module, and user-state process are used as values ​​to form key-value pairs, and all key-value pairs form a hash table. Finally, the entire hash table is stored in the trusted platform module to build a hash benchmark library.

4. The efficient integrity measurement method for embedded devices according to any one of claims 1 to 3, characterized in that: Step (2) specifically includes the following sub-steps: (2-1) Use a computer simulation modeling method to perform simulation cycle measurement on the hash benchmark library obtained in step (1) to obtain the TOCTOU attack detection rate. (2-2) Using a nonlinear least squares fitting algorithm, the TOCTOU attack detection rate obtained in step (2-1) is fitted to obtain a fitting function; (2-3) Determine the measurement period range parameters based on the TOCTOU attack detection rate obtained in step (2-1) and the fitting function obtained in step (2-2), and obtain the measurement period sequence based on the measurement period range parameters.

5. The efficient integrity measurement method for embedded devices according to claim 4, characterized in that: Step (2-1) includes the following sub-steps: (2-1-1) Create empty sets attack_regions and random_points; (2-1-2) Generate simulated attack events through the hash benchmark library established in step (1-2). For each simulated attack event, extract the start and end points of the attack region where it is located. Store the extracted start and end points as a tuple (start, end) and add it to the set attack_regions. (2-1-3) Generate multiple measurement points and store all the measurement points in the set random_points in sequence. (2-1-4) Create a variable detected_attacks with an initial value of 0. (2-1-5) Set counter i=0. , (2-1-6) Set counter j=0. (2-1-7) Set i=i+1, and determine whether i is equal to the total amount of data attack_regions_size in the set attack_regions. If so, go to step (2-1-11), otherwise go to step (2-1-8). (2-1-8) Get the i-th attack region from the set attack_regions as the current attack region current_region. (2-1-9) Determine whether the j+1th measurement point in the set random_points is within the range of the current attack region current_region. If so, set the variable detected_attacks = detected_attacks + 1, and then go to step (2-1-10), otherwise go to step (2-1-10). (2-1-10) Set j=j+1, and determine whether j is equal to the total amount of data random_points_size in the set random_points. If so, return to step (2-1-6), otherwise return to step (2-1-9). (2-1-11) The value of the variable detected_attacks is taken as the total number of detected attack events, and is divided by the total number of attack events in all attack areas in the hash benchmark library. The result is the TOCTOU attack detection rate.

6. The efficient integrity measurement method for embedded devices according to claim 5, characterized in that: The fitting formula obtained in step (2-2) is: ln(cpu load )=2.6446×e ―0.00023×period ―0.3952 Where cpu load Indicates the CPU load of the embedded device, and period indicates the measurement period of the embedded device.

7. The efficient integrity measurement method for embedded devices according to claim 6, characterized in that: Step (2-3) includes the following sub-steps: (2-3-1) Set the TOCTOU attack detection rate obtained in step (2-1) as parameter σ 2 , substitute the CPU load of the embedded device into the fitting formula obtained in step (2-2) to obtain the measurement period of the embedded device, and set the measurement period as parameter μ to obtain the measurement period range parameter (μ±σ). (2-3-2) generating a measurement period sequence according to the measurement period range parameters obtained in step (2-3-1) and using a random number generation algorithm; Specifically, this step is as follows: first, initialize the size of the measurement period sequence to 10, and then substitute the measurement period range parameter and the size of the measurement period sequence obtained in step (2-3-1) into the machine number generation algorithm Xorshift algorithm to obtain the measurement period sequence.

8. An efficient integrity measurement system for embedded devices, characterized in that: include: The first module is used to extract multiple measurement objects of the embedded device from the kernel physical memory of the embedded device, perform hash encryption processing on all measurement objects, store the processed results in a hash table, and store the hash table storing the results in a trusted platform module TPM to build a hash benchmark library. The second module is used to perform simulation modeling processing on the hash benchmark library obtained in the first module using a simulation modeling method of computer simulation to obtain the TOCTOU attack detection rate, the CPU load and measurement cycle of the embedded device, and fit the functional relationship between the CPU load and measurement cycle of the embedded device to obtain the optimal measurement cycle sequence. The third module is used to randomly select a measurement period from the measurement period sequence obtained by the second module, and obtain the CPU load of the embedded device according to the measurement period. The fourth module is used to determine whether the CPU load of the current embedded device is greater than the CPU load threshold of the embedded device according to the CPU load of the current embedded device obtained from the third module, and if so, enter the fifth module, otherwise enter the eighth module. The fifth module is used to obtain multiple measurement objects from the embedded device, set the counter k=0, and obtain the hash table from the hash reference library of the trusted platform module. The sixth module is used to set k=k+1, obtain the hash value of the kth measurement object among the multiple measurement objects obtained by the fifth module, and determine whether the hash value is the same as the hash value of the kth measurement object in the hash table obtained by the fifth module. If so, enter the seventh module; otherwise, it indicates that the kth measurement object among the multiple measurement objects has been attacked, and the type of the kth measurement object in the hash table is sent to the embedded device. The seventh module is used to determine whether k is equal to the size of the hash table obtained by the sixth module. If so, the process ends, otherwise it returns to the sixth module. The eighth module is used to set the counter l=0. The ninth module is used to determine whether there is a security value file in the memory of the embedded device, and whether the difference between the current time and the creation time of the security value file exceeds the timeout threshold of the security value file, otherwise, it goes to the tenth module; The tenth module is used to create a file using the touch security number.txt command in the Linux operating system, write the creation time and timeout threshold of the file, the security value of each measurement object in the hash table in the hash benchmark library obtained in the first module (whose initial value is 50), and the measurement flag bit of the measurement object (whose initial value is 0) into the file, thereby obtaining the created security value file, and then proceeding to the eleventh module; The eleventh module is used to obtain the security value file from the memory of the embedded device, obtain the hash table from the hash reference library of the trusted platform module, and set the counter m=0. The twelfth module is used to set m=m+1, use a random seed to generate a random value, and determine whether the random value is greater than or equal to the security value of the mth measurement object in the security value file obtained from the twelfth module. If so, enter the thirteenth module, otherwise enter the fourteenth module. The thirteenth module is used to set the measurement flag bit of the mth measurement object in the security value file obtained from the eleventh module to 1, increase the security value of the measurement object, and set the counter l=l+1, and then transfer to the fifteenth module; The fourteenth module is used to reduce the security value of the mth measurement object in the security value file obtained by the eleventh module, and then enter the fifteenth module; In the fifteenth module, the user determines whether m is equal to the size of the hash table obtained in the eleventh module. If so, the user enters the sixteenth module, otherwise, the user returns to the twelfth module. The sixteenth module is used to set the counter n=0. The seventeenth module is used to set the counter n=n+1 and determine whether the measurement flag bit of the nth measurement object in the security value file obtained from the eleventh module is 1, if so, enter the eighteenth module, otherwise enter the seventeenth module. The eighteenth module is used to set the measurement flag of the nth measurement object in the security value file to 0, set the counter l=l-1, obtain the hash value of the nth measurement object from the hash table, and determine whether the hash value is the same as the hash value of the nth measurement object in the hash table obtained by the eleventh module. If so, enter the nineteenth module, otherwise it means that the nth measurement object has been attacked, send the type of the nth measurement object in the hash table to the embedded device, and then enter the nineteenth module. The nineteenth module is used to determine whether l is equal to 0. If so, the creation time of the security value file obtained from the eleventh module is updated to the current time, and the file is stored in the memory of the embedded device. The process ends, otherwise it returns to the seventeenth module.