BMC intrusion prevention methods and devices, BMC and computer equipment
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2026-08-14
AI Technical Summary
[0029] Fifthly, a computer-readable storage medium is provided, comprising: computer software instructions; when the computer software instructions are executed in a processor, causing the processor to perform operational steps of the method as described in the first aspect or any possible implementation thereof.
Smart Images

Figure CN120017290B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computers, and more particularly to a BMC intrusion prevention method, apparatus, BMC, and computer equipment. Background Technology
[0002] Currently, attacks on computer devices are gradually shifting from decentralized attacks to organized and targeted advanced persistent threats (APTs). The Baseboard Management Controller (BMC) in a computer device serves as the security center, performing trusted authentication of components to prevent counterfeiting, tampering, or replacement, thus ensuring component security and reliability. Therefore, improving the BMC's ability to resist APT attacks and ensuring its security and trustworthiness is a pressing issue that needs to be addressed. Summary of the Invention
[0003] This application provides a BMC intrusion protection method, device, BMC, and computer equipment, thereby effectively improving the BMC's ability to resist APT attacks and ensuring the security and reliability of the BMC.
[0004] Firstly, a BMC intrusion prevention method is provided, applied to a BMC in a computer device. The BMC includes a service module and a security detection module. The service module provides management functions for components within the computer device, while the security detection module performs security detection on the BMC. The service module and the security detection module are isolated in communication and access to different storage media. The method includes: the security detection module acquiring data stored on the storage media associated with the service module, analyzing the data to perceive the security posture of the service module, and obtaining security detection results. If the security detection results indicate that the BMC has been subjected to an APT attack, the BMC is restarted in a downgraded boot mode.
[0005] Compared to BMC's defense strategy, which relies solely on perimeter defense, allowing APT attacks to breach these defenses and compromise the BMC, thus diminishing its value as a trusted hub, this application provides a defense-in-depth solution. Building upon traditional defenses, it adds intrusion detection capabilities to the BMC. By isolating business modules and security detection modules, it prevents the security detection module from being affected when business modules are under APT attacks. Furthermore, the security detection module analyzes data from the BMC's business modules to understand their security posture. When the BMC is potentially under APT attack, it can restart the BMC while ensuring basic business operations and the BMC's recoverability. This forms a dynamic defense chain of defense -> detection -> degradation -> recovery, effectively enhancing the BMC's ability to resist APT attacks and ensuring its security and trustworthiness.
[0006] In one possible implementation, obtaining a security detection result based on data stored in a storage medium associated with the business module includes: detecting the operational security of the business module based on data stored in a first storage medium associated with the business module, and obtaining a security detection result. The first storage medium is used to store data required for the operation of the business module.
[0007] Therefore, by analyzing data from the operation of business modules, the operational security of these modules can be detected; that is, the security of the operating environment when the BMC manages components in computer equipment can be assessed. For example, by analyzing data stored in memory associated with business modules and detecting memory security, the BMC can be identified as potentially vulnerable to APT attacks, thereby enhancing its ability to defend against APT attacks.
[0008] In another possible implementation, the security detection result is obtained based on the data stored in the storage medium associated with the business module, including: detecting the data security of the business module based on the data stored in the second storage medium associated with the business module, and obtaining the security detection result, wherein the second storage medium is used to store the persistent data of the business module.
[0009] Therefore, by analyzing the persistent data of business modules, the data security of these modules can be detected. For example, by analyzing the data stored in the non-volatile memory associated with business modules, and by detecting data security, the BMC can be identified as potentially vulnerable to APT attacks, thereby improving the BMC's ability to resist APT attacks.
[0010] In another possible implementation, security detection results are obtained based on data stored in the storage medium associated with the business module, including obtaining security detection results based on the trusted root verification data of the BMC.
[0011] Since the root of trust serves as the basis of trust in a trusted computer system, the BMC's root of trust is used to perform integrity verification on the data of the business modules. That is, it checks whether the database is in a consistent state and whether the data has been modified based on integrity constraints. This reduces the possibility that the root of trust may be tampered with, enhances the BMC's ability to resist APT attacks, and ensures the security and trustworthiness of the BMC.
[0012] In another possible implementation, security detection results are obtained based on data stored on storage media associated with the business module, including: obtaining security detection results based on data analysis by an advanced threat analysis system.
[0013] The remote system provides intrusion detection capabilities that require high computing power, addressing the issue of insufficient computing power in the BMC embedded processor. The BMC and the remote system work together to detect potential APT attacks on the BMC, enhancing the BMC's ability to defend against APT attacks.
[0014] In another possible implementation, the BMC is restarted in a downgraded boot mode, including: restarting the security detection module and mounting the storage medium associated with the security detection module.
[0015] In another possible implementation, after restarting the security detection module and mounting the storage medium associated with the security detection module, the method further includes: restarting the security detection module and mounting the storage medium associated with the security detection module according to the restart command, and restarting the business module and mounting the storage medium associated with the business module.
[0016] In some embodiments, the storage medium associated with the security detection module stores the initial data for restarting the service module, the security detection module configures the initial data to the storage medium associated with the security detection module, and the service module restarts based on the initial data.
[0017] With secure boot protecting the BMC firmware, memory security is ensured through reset, and data security is guaranteed only by mounting the storage medium associated with the security detection module. This can erase existing APT attack data and block APT attacks. After blocking the attack, the operation of the security detection module maintains the core business operation capabilities of the operating system, providing basic remotely manageable functions, and preventing it from becoming unmanaged.
[0018] Secondly, a security detection device is provided, comprising modules for performing the BMC intrusion prevention method of the first aspect or any possible design of the first aspect. For example, the security detection device includes a communication module, a detection module, and a control module.
[0019] The detection module is used to obtain security detection results based on the data stored in the storage medium associated with the business module. The data is used to perceive the security status of the business module, and the security detection results are used to indicate the possibility that the BMC is subjected to advanced long-term threat (APT) attacks.
[0020] The control module is used to determine if the BMC has been subjected to an APT attack based on the security detection results, and to restart the BMC in a downgraded boot mode.
[0021] In one possible implementation, when the detection module obtains the security detection result based on the data stored in the storage medium associated with the business module, it is specifically used to: detect the operational security of the business module based on the data stored in the first storage medium associated with the business module, and obtain the security detection result. The first storage medium is used to store the data required for the operation of the business module.
[0022] In another possible implementation, when the detection module obtains the security detection result based on the data stored in the storage medium associated with the business module, it is specifically used to: detect the data security of the business module based on the data stored in the second storage medium associated with the business module, and obtain the security detection result. The second storage medium is used to store the persistent data of the business module.
[0023] In another possible implementation, when the detection module obtains the security detection result based on the data stored in the storage medium associated with the business module, it is specifically used to: obtain the security detection result based on the trusted root verification data of the BMC.
[0024] In another possible implementation, when the detection module obtains security detection results based on data stored in the storage medium associated with the business module, it is specifically used to: obtain security detection results based on data analysis by an advanced threat analysis system.
[0025] In another possible implementation, when the control module restarts the BMC in a downgraded boot mode, it is specifically used to: restart the security detection module and mount the storage medium associated with the security detection module.
[0026] In another possible implementation, after the control module restarts the security detection module and mounts the storage medium associated with the security detection module, it is also used to: restart the security detection module and mount the storage medium associated with the security detection module according to the restart command, and restart the business module and mount the storage medium associated with the business module.
[0027] Thirdly, a BMC is provided, which includes a service module and a security detection module. The service module is used to provide management functions for components in a computer device, and the security detection module is used to perform security detection on the BMC. The service module and the security detection module are isolated in communication and the storage media accessed by the service module and the security detection module are isolated. The security detection module is used to execute the operation steps of the method in the first aspect or any possible implementation of the first aspect.
[0028] Fourthly, a computer device is provided, comprising a processor, a memory, and a BMC as described in the third aspect, the BMC being used to perform operational steps of the method in the first aspect or any possible implementation thereof.
[0029] Fifthly, a computer-readable storage medium is provided, comprising: computer software instructions; when the computer software instructions are executed in a processor, causing the processor to perform operational steps of the method as described in the first aspect or any possible implementation thereof.
[0030] In a sixth aspect, a computer program product is provided that, when run on a computer, causes the computer to perform the operational steps of the method as described in the first aspect or any possible implementation thereof.
[0031] The technical effects of any of the design methods in aspects two through six can be found in aspect one or in different design methods in aspect one, and will not be repeated here.
[0032] Based on the implementation methods provided in the above aspects, this application can be further combined to provide more implementation methods. Attached Figure Description
[0033] Figure 1 A schematic diagram of the structure of a baseboard management controller provided in this application;
[0034] Figure 2 A schematic diagram of another substrate management controller provided in this application;
[0035] Figure 3 A flowchart illustrating a BMC intrusion prevention method provided in this application;
[0036] Figure 4 A schematic diagram of the structure of a safety detection device provided in this application;
[0037] Figure 5 This is a schematic diagram of the structure of a computer device provided in this application. Detailed Implementation
[0038] To facilitate understanding, the main terms used in this application will be explained first.
[0039] Baseboard Management Controller (BMC): A dedicated controller for managing servers, either integrated on the motherboard or plugged into it via Peripheral Component Interconnect Express (PCIe). Its functions include device information management, server status management, remote server control management, and maintenance management.
[0040] Root of Trust (ROT): Also known as the root of trust, it serves as the basis of trust in a trusted computer system. The root of trust includes the root of trust measurement, the root of trust storage, and the root of trust reporting.
[0041] Advanced Persistent Threat (APT): Also known as advanced persistent threat, it is a complex and persistent cyberattack. APTs comprise three elements: advanced, persistent, and threatening. "Advanced" means that executing an APT attack requires a higher degree of customization and complexity than traditional attacks, demanding significant time and resources to research and identify vulnerabilities in the target. "Persistent" means that to achieve a specific objective, it requires continuous monitoring of the target and maintaining long-term access to it. "Threat" emphasizes that the target is a high-value organization; once a successful attack is achieved, it often causes substantial economic losses, even devastating damage, to the target.
[0042] The attack phases of advanced long-term threats include information gathering, external penetration, command and control, internal proliferation, and data breach. From targeting to successful attack, multiple stages are involved; in the security field, this process can be called the attack chain.
[0043] APT attackers are typically an organization. After selecting a target, they collect all information related to that target. This information includes the target's organizational structure, office location, products and services, address book, email addresses, meeting schedules, portal directory structure, internal network architecture, deployed network security devices, exposed ports, the office operating systems and email systems used by employees, and the operating system and version of the company's World Wide Web (WWW) server, among other things.
[0044] After information gathering is complete, malware is developed and deployed on the target. Malware is typically a small remote control tool, also known as a Remote Administration Tool or Remote Access Trojan (RAT), used to establish command and control channels (C&C) with the control server.
[0045] When a user opens a file containing malware using a vulnerable client program or browser, the malware exploits the vulnerability, downloads and installs the malware, and allows the target to be successfully attacked. Malicious programs often also escalate privileges or add administrator users. For example, they may start the malicious program on system boot or even quietly disable or modify host firewall settings in the background to make the malicious program as undetectable as possible.
[0046] Because hosts within the same organization often use the same operating systems and similar application software environments, they largely share the same vulnerabilities. After compromising one internal network host, malware can spread laterally to other hosts within the subnet or vertically to internal enterprise servers. Since remote management tools have keylogging and screen recording capabilities, it is easy to obtain users' domain passwords, email passwords, and various server passwords.
[0047] The attack also employs self-protection measures such as anonymous networks, encrypted communication, and trace erasure. During the transmission of confidential information, various technical means are used to avoid detection by network security devices. On the one hand, confidential information is broken down, encrypted, or obfuscated to prevent data leakage prevention (DLP) devices from detecting leaks through keyword scanning; on the other hand, the transmission rate is limited to avoid exceeding the detection thresholds of various security devices.
[0048] To address the vulnerability of BMCs to APT attacks, this application provides a BMC intrusion prevention method. This method involves establishing a communication-isolated service module and a security detection module within the BMC. The storage media accessed by the service module and the security detection module are also isolated. The service module provides management functions for components within the computer device, while the security detection module performs security checks on the BMC. The security detection module acquires data stored on the storage media associated with the service module, analyzes the data to assess the security posture of the service module, and obtains security detection results. If the security detection results indicate that the BMC has been subjected to an APT attack, the BMC is restarted in a downgraded boot mode.
[0049] Compared to BMC's defense strategy, which relies solely on perimeter defense (firewalls, interface encapsulation, restrictions on operating system logins, and Identity and Access Management (IAM) technologies to limit attacker behavior), it lacks awareness of actions during the attack process. As BMC exposes more and more interfaces, it becomes vulnerable to command injection, database injection, buffer overflows, and other vulnerabilities, allowing APT attacks to breach the defense perimeter and ultimately compromise the BMC, reducing its value as a trusted hub. This application provides a defense-in-depth solution. Building upon traditional defenses, it adds intrusion detection capabilities to the BMC. By isolating business modules and security detection modules, it prevents the security detection module from being affected when business modules are attacked by APTs. Furthermore, the security detection module analyzes data from the BMC's business modules to perceive their security posture. When a potential APT attack is predicted, it can restart the BMC while ensuring basic business operations and the BMC's recoverability. This forms a dynamic defense chain of defense -> detection -> degradation -> recovery, effectively enhancing the BMC's ability to resist APT attacks and ensuring its security and trustworthiness.
[0050] The method provided in this application can be applied to computer devices that include a BMC (Browser Control Center). Examples include inference servers, training servers, inference cards, training cards, rack-mount servers, blade servers, or platform servers.
[0051] The BMC intrusion protection method provided in this application is described in detail below with reference to the accompanying drawings. Figure 1 This is a schematic diagram of a baseboard management controller provided in this application. Figure 1 As shown, the baseboard management controller 100 includes a processor 110, a bus 120, a memory 130, a communication interface 140, and a main memory unit 150. The processor 110, memory 130, main memory unit 150, and communication interface 140 are connected via the bus 120.
[0052] Processor 110 is the control center of the baseboard management controller 100. Processor 110 can be a central processing unit (CPU). Processor 110 can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), system-on-chip (SoCs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. General-purpose processors can be microprocessors or any conventional processors. For ease of description, the following embodiments use processor 110 as a CPU as an example.
[0053] Figure 1 The baseboard management controller 100 may include one or more processors. The processor may be a multi-core processor, meaning it includes one or more processor cores. For example, Figure 1 The processor 110 shown contains N processor cores. Here, a processor can refer to one or more devices, circuits, and / or computing units used to process data (e.g., computer program instructions).
[0054] In some embodiments, processor 110 runs service module 111 and security detection module 112. Service module 111 provides management functions for components in a computer device including baseboard management controller 100. Security detection module 112 performs security detection on baseboard management controller 100, i.e., detects the security of the operating environment and data integrity of service module 111. For example, security detection module 112 acquires data stored on storage media associated with service module 111, analyzes the data to perceive the security posture of service module 111, and obtains security detection results. If the security detection results indicate that baseboard management controller 100 has been subjected to an APT attack, baseboard management controller 100 is restarted in a downgraded boot mode. This enhances the BMC's ability to resist APT attacks and ensures the security and trustworthiness of the BMC.
[0055] The service module 111 and the security detection module 112 can be processes or threads running on the same processor 110. Communication between the service module 111 and the security detection module 112 is isolated. Alternatively, the service module 111 and the security module 112 can also be processes or threads running on different processors.
[0056] For example, business module 111 is prohibited from obtaining user information and user group information from security detection module 112. Similarly, business module 111 is prohibited from obtaining process information from security detection module 112. Furthermore, business module 111 is prohibited from sharing the bus with security detection module 112, with the exception of the business whitelist message bus. Also, business module 111 is prohibited from system calls other than those on the whitelist. The whitelist can include the security detection interface, upgrade function interface, configuration function interface, and security management interface. The security detection interface allows security detection module 112 to detect data from business module 111 required for APT attacks. The upgrade function interface allows security detection module 112 to upgrade the data from business module 111. The configuration function interface allows security detection module 112 to configure the data from business module 111. The security management interface allows security detection module 112 to manage the data from business module 111. The storage media accessed by business module 111 and security detection module 112 are isolated. For example, the memory accessed by business module 111 and the memory accessed by security detection module 112 are isolated. For example, the flash memory accessed by business module 111 and the flash memory accessed by security detection module 112 are isolated. For example, business module 111 is prohibited from rewriting file information in the storage medium accessible to security detection module 112. For example, security detection module 112 is prohibited from reading file information in the storage medium accessible to business module 111, but security detection module 112 can read data in the storage medium accessible to business module 111 required for intrusion detection.
[0057] It should be noted that if the business module 111 and the security detection module 112 access different areas within the same storage medium, then these different areas within the same storage medium are isolated. For example, access can be restricted by limiting permissions to different areas within the same storage medium, thus isolating them. By using access control lists, role permissions, and other methods, authorized users or roles can be allowed to access specific areas, preventing unauthorized users from obtaining sensitive information.
[0058] For example, service module 111 can access a first area in memory 130, which is used to store persistent data of service module 111. Security detection module 112 can access a second area in memory 130, which is used to store persistent data of security detection module 112. The first and second areas in memory 130 are isolated from each other.
[0059] The business module 111 can access the first area in memory 150, which is used to store data for the business module 111 during runtime. The security detection module 112 can access the second area in memory 150, which is used to store data for the security detection module 112 during runtime. The first and second areas in memory 150 are isolated from each other.
[0060] Optionally, inter-process isolation can be used to achieve communication isolation between the business module 111 and the security detection module 112 and isolation of the accessed storage media. For example, Linux namespace technology can be used to achieve communication isolation between the business module 111 and the security detection module 112 and isolation of the accessed storage media.
[0061] Therefore, within the same operating system of BMC, system security isolation is achieved through user (e.g., username isolation, privileged user and ordinary user isolation), file (e.g., storage isolation), inter-process communication isolation, and inter-component communication isolation. This isolates BMC's business modules from its security detection module, and the storage media used by the two modules are also isolated. Business modules are only allowed to access the security detection module through whitelisted business interfaces / systems, minimizing the exposure surface and preventing the security detection module from being affected when business modules are attacked by APTs. This enhances the security of the security detection module. Furthermore, by analyzing the data from BMC's business modules through the security detection module, the security posture of the business modules is perceived, improving BMC's ability to resist APT attacks and ensuring BMC's security and trustworthiness.
[0062] Memory 150 may be a pool of volatile memory. Volatile memory may be random access memory (RAM), which serves as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). Memory 150 is used to store data required for the operation of service module 111. For example, BMC firmware, service data, and network configuration data.
[0063] Memory 130 may be a non-volatile memory pool. Non-volatile memory may be read-only memory (ROM), disk, or flash memory. Memory 130 is used to store persistent data of service module 111, such as user information, alarm data, fault diagnosis data, BMC event subscription scope, and alarm reporting level.
[0064] The communication interface 140 is used to enable communication between the baseboard management controller 100 and external devices or components. For example, the baseboard management controller 100 communicates with processors, memory, storage devices, and peripherals in a computer device. In this application, the communication interface 140 can transmit data from the service module 111 to an advanced threat analysis system, which then analyzes the data to obtain security detection results.
[0065] Bus 120 may include a pathway for transmitting information between the aforementioned components (such as processor 110, memory 150, and storage 130). In addition to a data bus, bus 120 may also include a power bus, control bus, and status signal bus. However, for clarity, all buses are labeled as bus 120 in the figure. Bus 120 may be a Peripheral Component Interconnect Express (PCIe) bus, or an Extended Industry Standard Architecture (EISA) bus, a Unified Bus (Ubus or UB), a Compute Express Link (CXL), a Cache Coherent Interconnect for Accelerators (CCIX), DDR, or an Embedded Multi Media Card (EMMC) control protocol, etc. Bus 120 can be divided into address bus, data bus, control bus, etc.
[0066] It is worth noting that, Figure 1 Taking the baseboard management controller 100 as an example, which includes one processor 110 and one memory 130, the processor 110 and the memory 130 are used to indicate a type of device or equipment. In a specific embodiment, the number of each type of device or equipment can be determined according to business needs.
[0067] In some embodiments, the baseboard management controller 100 may include multiple processors, and the service module 111 and the security detection module 112 may run on different processors. The baseboard management controller 100 may include multiple memories and multiple memory blocks, enabling the service module 111 and the security detection module 112 to access different memories and memory blocks, thereby achieving communication isolation between the service module 111 and the security detection module 112, as well as isolation of the storage media accessed by the service module 111 and the security detection module 112.
[0068] For example, such as Figure 2As shown, the baseboard management controller 100 may include a processor 110 and a processor 160. Processor 110 runs a service module 111. Processor 160 runs a security detection module 112. The baseboard management controller 100 includes a memory 130 and a memory 170. Service module 111 can access memory 130, which is used to store persistent data of service module 111. Security detection module 112 can access memory 170, which is used to store persistent data of security detection module 112. Memory 130 and memory 170 are isolated from each other.
[0069] The baseboard management controller 100 includes memory 150 and memory 180. Service module 111 can access memory 150. Memory 150 is used to store data generated during the operation of service module 111. Security detection module 112 can access memory 180, and memory 180 is used to store data generated during the operation of security detection module 112. Memory 150 and memory 180 are isolated from each other.
[0070] In other embodiments, the storage medium associated with the security detection module 112 may also store the root of trust of the baseboard management controller 100. For example, the root of trust of the baseboard management controller 100 and the persistent data of the security detection module 112 may be stored on the same storage medium, with memory 130 or memory 170 in the baseboard management controller 100 storing both the root of trust of the baseboard management controller 100 and the persistent data of the security detection module 112. Alternatively, the root of trust of the baseboard management controller 100 and the persistent data of the security detection module 112 may be stored on different storage media. Integrity verification of the data in the service module 111 is performed using the root of trust of the baseboard management controller 100.
[0071] As one possible implementation, the business module 111 and the security module 112 can also be implemented in hardware. Accordingly, the business module 111 and the security module 112 can be implemented by one logic circuit, or the functions of the business module 111 and the security module 112 can be implemented by two logic circuits respectively.
[0072] Next, the BMC intrusion prevention method flow provided in this application will be described in conjunction with the accompanying drawings, such as... Figure 3 As shown. Here it is. Figure 1 The following example illustrates how the service module 111 and security detection module 112 of the baseboard management controller 100 detect APT attacks on the baseboard management controller 100.
[0073] Step 310: The security detection module obtains the data stored in the storage medium associated with the business module.
[0074] The system retrieves data from the memory storage accessed by the business modules. This memory storage includes data required by the BMC to manage components. For example, the security detection module retrieves data such as the software programs running on the BMC, business data, and network configurations from the memory accessed by the business modules.
[0075] The system retrieves data from flash storage accessed by the business modules. This flash storage data includes persistent data from the BMC. For example, persistent data includes data required during the operation of the BMC software program, such as alarm data and fault diagnosis data. Persistent data may also include customer-managed configuration data for the BMC's business modules, such as the BMC event subscription scope and alarm reporting levels.
[0076] In some embodiments, the security detection module can periodically acquire data stored in the storage medium associated with the business module, analyze the data, and determine whether the BMC is under APT attack, so as to block the APT attack on the BMC in a timely manner.
[0077] Step 320: The security detection module obtains the security detection result based on the data stored in the storage medium associated with the business module.
[0078] The security detection module analyzes data to perceive the security posture of business modules and obtains security detection results. These results indicate the likelihood of the BMC being subjected to an APT attack. For example, a security detection result can indicate that the BMC has been subjected to an APT attack. Alternatively, a security detection result can indicate that the BMC may be subjected to an APT attack. Finally, a security detection result can indicate that the BMC has not been subjected to an APT attack.
[0079] In some embodiments, the security detection module detects the operational security of the business module based on the data stored in memory accessed by the business module, and obtains the security detection result. Operational security can also be referred to as memory security.
[0080] For example, the security detection module analyzes the programs running on the BMC to determine if they contain malicious code. If malicious code is injected into the programs running on the BMC, it controls program redirection, causing the BMC program's pointer to jump to the attacking program, thus attacking the BMC. If malicious code is found in the programs running on the BMC, it is determined that the BMC is under an APT attack.
[0081] For example, the security detection module analyzes the BMC's basic data to determine if it has been tampered with. If an APT attacker tampers with the BMC's basic data, such as modifying user information and configuration items, the attacker can create users arbitrarily and control the BMC as a legitimate user, thus launching an attack. Therefore, tampering with the BMC's basic data determines whether the BMC has been subjected to an APT attack.
[0082] For example, the security detection module analyzes the network status to determine if there is any abnormal traffic accessing the BMC. Abnormal traffic may be generated during an attack on the BMC. If abnormal traffic accessing the BMC is detected, it determines whether the BMC is under an APT attack.
[0083] In other embodiments, the security detection module detects the data security of the business module based on the data stored in the flash memory associated with the business module, and obtains the security detection result.
[0084] For example, the security detection module analyzes the BMC's basic data to determine if it has been tampered with. An APT attacker might tamper with the BMC's basic data in the flash memory, allowing them to create arbitrary users. The attacker, acting as a legitimate user, could then control the BMC, thus launching an attack. The tampering with the BMC's basic data confirms that the BMC has been subjected to an APT attack.
[0085] For example, the security detection module can analyze security logs to determine if there is any abnormal data within them. During an attack on the BMC, the security logs may contain abnormal data. If abnormal data is found in the security logs, it confirms that the BMC has been subjected to an APT attack.
[0086] The above-mentioned security detection module is used as an example to illustrate the security detection of BMC. The detection content of the security detection module described in this application includes, but is not limited to, data related to the BMC's execution management operation process, such as programs, basic data, network status, etc., and may also include integrity verification.
[0087] For example, the security detection module can perform integrity checks on the data stored in memory that is associated with the business module.
[0088] For example, integrity checks are performed on code segments in memory. During initial loading, a hash calculation is performed on the code segment to obtain a trusted root, which is stored in a storage medium associated with the security detection module. During the execution of the code segment by the BMC, the hash value of the code segment is obtained and compared with the trusted root for integrity checks. If the hash value is the same as the trusted root, it indicates that the program running by the BMC does not contain malicious programs, and the BMC is determined not to be under an APT attack. If the hash value is different from the trusted root, it indicates that the program running by the BMC contains malicious programs, and the BMC is determined to be under an APT attack.
[0089] For example, the security detection module can perform integrity checks on the data stored in flash memory associated with the business module. The security detection module can perform integrity checks on the initial data of the BMC. The initial data includes program files, configuration files, and data files stored in the flash memory associated with the business module.
[0090] The security detection module can perform hash calculations on the data in the flash memory to obtain a hash value, and compare the hash value with the BMC's root of trust. If the hash value is the same as the BMC's root of trust, it means that the data in the flash memory has not been tampered with and the BMC has not been subjected to an APT attack; if the hash value is different from the BMC's root of trust, it means that the data in the flash memory may have been tampered with and the BMC has been subjected to an APT attack.
[0091] For example, the configuration file undergoes integrity verification. A hash calculation is performed on the configuration file to obtain a trusted root, which is then stored in the storage medium associated with the security detection module. If the configuration file is modified, a new trusted root is immediately generated, updating the trusted root stored in the storage medium associated with the security detection module. During the execution of the BMC code segment, the configuration file can be inspected; for example, by comparing the hash value of the configuration file with the trusted root to determine whether the BMC is under APT attack.
[0092] Furthermore, due to potential vulnerabilities in the BMC program, APT attackers have long studied these vulnerabilities, gradually penetrating the system to launch attacks. Recovery is possible in downgrade boot mode, and program security can be ensured by upgrading the BMC program (e.g., upgrading the BMC firmware). For example, downloading the BMC program upgrade from the official website provides patches. Traditional secure boot ensures program integrity.
[0093] Optionally, if the computing power of the processor in the BMC is insufficient to support the analysis of data obtained from the storage media associated with the business module, the data obtained can be analyzed with the help of a remote system, thereby enabling the BMC to detect potential APT attacks and improve its ability to resist APT attacks.
[0094] For example, this embodiment may also include step 321, obtaining security detection results based on data analyzed by the advanced threat analysis system. The BMC can send data to the advanced threat analysis system, obtain security detection results from the data of the advanced threat analysis system, and receive the security detection results fed back by the advanced threat analysis system.
[0095] Step 330: The security detection module determines that the BMC has been subjected to an APT attack based on the security detection results, and restarts the BMC in a downgraded boot mode.
[0096] When the security detection module detects that the BMC is under APT attack, it controls the BMC to restart in a downgraded boot mode, or the BMC receives a restart command and restarts in a downgraded boot mode.
[0097] Downgraded startup mode can refer to resetting the memory associated with the business module, restarting the security detection module, mounting the storage medium associated with the security detection module, not starting the business module, not mounting the storage medium associated with the business module, ensuring a high-security operating environment for the BMC, blocking APT attack paths, ensuring the core business of the BMC, and providing remote recovery and configuration capabilities.
[0098] After the BMC's operating environment is secure, the BMC receives a restart command to restart the BMC, which means restarting the security detection module, mounting the storage medium associated with the security detection module, restarting the service module, and mounting the storage medium associated with the service module.
[0099] In some embodiments, the security detection result indicates that the data security of the business module has been subjected to an APT attack, specifically, the data in the flash memory storage associated with the business module has been attacked by an APT. The security detection module configures the backed-up initial data to the flash memory associated with the business module. Based on the initial data, the business module restarts itself and the storage medium associated with it. The initial data can be stored in the flash memory associated with the security detection module.
[0100] The BMC intrusion prevention method provided in this application, based on boundary defense, adds intrusion detection capabilities to the BMC. Under the premise of secure boot protecting firmware security, it comprehensively analyzes memory and data security, ensuring memory security through reset and ensuring data security by only mounting the storage media associated with the security detection module. This can block all existing APT attacks. After blocking an APT attack, the operating system's core business capabilities are maintained due to the normal operation of the security detection module, providing remotely manageable basic functions such as upgrades and configuration management. After ensuring the BMC's memory and data security, the BMC is restarted, i.e., the business modules and the security detection module are restarted. This forms a dynamic defense chain of defense -> detection -> degradation -> recovery, creating a defense-in-depth solution for the BMC, effectively improving its ability to resist APT attacks and ensuring the BMC's security and trustworthiness.
[0101] Optionally, the BMC can also send security test results back to the display terminal, so that the system administrator can know the security status of the BMC in a timely manner, and restart the BMC in a downgraded boot mode to block APT attacks.
[0102] It is understood that, in order to achieve the functions in the above embodiments, the BMC includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the units and method steps described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0103] The above text combines Figures 1 to 3 This application provides a detailed description of the BMC intrusion prevention method. The following section will combine... Figure 4 This application describes the safety detection device provided in accordance with this application.
[0104] Figure 4 This is a schematic diagram of a possible authentication device provided in this application. These authentication devices can be used to implement the functions of remote devices or computer devices in the above method embodiments, and therefore can also achieve the beneficial effects of the above method embodiments. In this embodiment, the authentication device can be as follows: Figure 1 The device shown can also be a module (such as a chip) used in servers.
[0105] like Figure 4 As shown, the security detection device 400 includes a communication module 410, a detection module 420, a control module 430, and a storage module 440. The security detection device 400 is used to implement the above-mentioned... Figure 3 The method embodiment shown illustrates the function of the security detection module.
[0106] Communication module 410 is used to acquire data stored in the storage medium associated with the service module. For example, communication module 410 is used to execute... Figure 3 Step 310.
[0107] The detection module 420 is used to analyze the data stored on the storage medium associated with the business module to obtain security detection results. For example, the detection module 420 is used to perform... Figure 3 Step 320.
[0108] Control module 430 is used to determine that the BMC has been subjected to an APT attack based on security detection results, and to restart the BMC in a downgraded boot mode. For example, control module 430 is used to execute... Figure 3 Step 330.
[0109] Optionally, the detection module 420 is used to detect the operational security of the business module based on data stored in a first storage medium associated with the business module, and obtain a security detection result. The first storage medium is used to store data required for the operation of the business module.
[0110] Optionally, the detection module 420 is used to detect the data security of the business module based on the data stored in the second storage medium associated with the business module, and obtain a security detection result. The second storage medium is used to store the persistent data of the business module.
[0111] Storage module 440 is used to store the data required for security testing, the security testing program, and the initial data of the backup business module.
[0112] It should be understood that the security detection device 400 in this application embodiment can be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD can be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), a data processing unit (DPU), an accelerator card, an offload card, or any combination thereof. It can also be implemented using software. Figure 3 The BMC intrusion prevention method shown can also be a software module, as can the security detection device 400 and its modules.
[0113] The security detection device 400 according to the embodiments of this application can correspond to the execution of the methods described in the embodiments of this application, and the above and other operations and / or functions of each unit in the security detection device 400 are respectively for implementing Figure 3 For the sake of brevity, the corresponding processes of each method in the code will not be elaborated here.
[0114] Figure 5 This is a schematic diagram of the structure of a computer device provided in this application. Figure 5 As shown, computer device 500 includes processor 510, memory 520, storage 530, PCIe card 540, BMC 550, and communication interface 560. Processor 510, memory 520, storage 530, PCIe card 540, BMC 550, and communication interface 560 are connected via bus 570.
[0115] Processor 510 is the control center of computer device 500. Processor 510 can be a high-powered computing unit with computing capabilities, such as a central processing unit (CPU), graphics processing unit (GPU), data processing unit (DPU), neural processing unit (NPU), or embedded neural-network processing unit (NPU). Processor 510 includes one or more processor cores.
[0116] In some embodiments, the processor 510 includes registers and a cache memory.
[0117] The cache memory is used to store instructions or data that the processor core in processor 510 may access multiple times. This improves the speed at which the processor processes data and avoids frequent accesses to memory 520 by the processor.
[0118] Registers are used to store instructions or data that the processor core in processor 510 may access multiple times. Since registers are faster than cache memory, instructions or data that the processor core may access multiple times can be stored in registers first, which can further improve the processor's data processing speed.
[0119] Alternatively, the processor 510 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0120] Memory 520 (also known as main memory unit) can be a pool of volatile memory or a pool of non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0121] The memory 530 can be a persistent storage medium, such as a disk, like a hard disk drive (HDD) or a solid-state drive (SSD). The PCIe card 540 can refer to a peripheral device. For example, a PCIe card 540 includes a network interface card (NIC). The communication interface 560 is used to enable communication between the computer device 500 and external devices or components.
[0122] The BMC550 is used to manage other devices in the computer device 500, such as the processor 510, memory 520, storage 530, PCIe card 540, and communication interface 560.
[0123] In this application, the BMC550 includes a service module 551 and a security detection module 552. The functions of the service module 551 and the security detection module 552 can be found in the descriptions of the service module and security detection module in the above embodiments.
[0124] Bus 570 may include a pathway for transmitting information between the aforementioned components (such as processor 510, memory 520, storage 530, PCIe card 540, and communication interface 560). In addition to a data bus, bus 570 may also include a power bus, control bus, and status signal bus. However, for clarity, all buses are labeled as bus 570 in the diagram. Bus 570 may be a Peripheral Component Interconnect Express (PCIe) bus, or an Extended Industry Standard Architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. Bus 570 can be divided into address bus, data bus, control bus, etc.
[0125] Figure 5 The device structure shown does not constitute a limitation on the computer device and may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. For example, a computer device may also include artificial intelligence cards, read cards, GPUs, DPUs, and NPUs.
[0126] The components described in this application may include processors, memory, RAM, registers, cache memory, network interface cards (NICs), and circuit boards, etc., in computer equipment. The BMC (Browser Control Center) included in the computer equipment can perform APT attack detection and defend against APT attacks using the BMC intrusion prevention method provided in this application, ensuring the security and trustworthiness of the BMC.
[0127] It should be understood that the BMC550 in the computer device 500 according to this embodiment can correspond to the security detection device 400 in this embodiment, and can correspond to the execution of the system according to this embodiment. Figure 3 The corresponding subject in any of the methods, and the above and other operations and / or functions of each module in the security detection device 400 are respectively for the purpose of implementing Figure 3 For the sake of brevity, the corresponding processes of each method in the code will not be elaborated here.
[0128] This application provides a cluster that may include multiple computer devices. Each computer device includes multiple components and a Base Management Console (BMC). The BMC can perform APT attack detection and defense against APT attacks using the BMC intrusion prevention method provided in this application, ensuring the security and trustworthiness of the BMC. This allows the BMC to perform trusted authentication of components within the computer devices, preventing components from being counterfeited, tampered with, or replaced, and guaranteeing the security and reliability of the components.
[0129] This application also provides a chip capable of implementing the above. Figures 1 to 5 The chip can function as a standalone chip or be integrated into the BMC, and can also function as a business module and a security detection module.
[0130] The method steps in this embodiment can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a computing device. Of course, the processor and storage medium can also exist as discrete components in the computing device.
[0131] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); or it can be a semiconductor medium, such as a solid-state drive (SSD). The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for intrusion protection of a baseboard management controller (BMC), characterized in that, The method is applied to a BMC (Browser Control Center) in a computer device. The BMC includes a service module and a security detection module. The service module provides management functions for components in the computer device, and the security detection module performs security detection on the BMC. The service module and the security detection module are communicatively isolated, and the storage media accessed by the service module and the security detection module are isolated. The method is executed by the security detection module, and the method includes: Security detection results are obtained based on data stored in the storage medium associated with the business module. The data is used to perceive the security status of the business module, and the security detection results are used to indicate the possibility that the BMC is subjected to an advanced long-term threat (APT) attack. Based on the security detection results, it was determined that the BMC had been subjected to the APT attack, and the BMC was restarted in a downgraded boot mode. The security detection results are obtained based on the data stored in the storage medium associated with the business module, including: Based on the data stored in the first storage medium associated with the business module, the operational security of the business module is detected, and the security detection result is obtained. The first storage medium is used to store the data required for the operation of the business module; or... Based on the data stored in the second storage medium associated with the business module, the data security of the business module is detected, and the security detection result is obtained. The second storage medium is used to store the persistent data of the business module, and the persistent data includes the persistent data required during the operation of the BMC software program.
2. The method according to claim 1, characterized in that, Obtaining the security test results includes: The security detection result is obtained by verifying the data using the trusted root of the BMC.
3. The method according to claim 1, characterized in that, Obtaining the security test results includes: The security detection results are obtained by analyzing the data using an advanced threat analysis system.
4. The method according to claim 1, characterized in that, Rebooting the BMC in a downgraded boot mode includes: Restart the security detection module and mount the storage medium associated with the security detection module.
5. The method according to claim 4, characterized in that, After restarting the security detection module and mounting the storage medium associated with the security detection module, the method further includes: According to the restart command, the security detection module is restarted, the storage medium associated with the security detection module is mounted, and the service module is restarted, and the storage medium associated with the service module is mounted.
6. A safety detection device, characterized in that, The security detection device is used to implement the functions of the security detection module included in the baseboard management controller (BMC) of the computer equipment; the BMC also includes a service module, which is used to provide management functions for the components in the computer equipment, and the security detection module is used to perform security detection on the BMC. The service module and the security detection module are communicatively isolated, and the storage media accessed by the service module and the security detection module are isolated. The safety detection device includes: The detection module is specifically used to detect the operational security of the business module based on data stored in a first storage medium associated with the business module, and obtain the security detection result. The first storage medium is used to store data required for the operation of the business module. Alternatively, it can detect the data security of the business module based on data stored in a second storage medium associated with the business module, and obtain the security detection result. The second storage medium is used to store persistent data of the business module, including persistent data required during the operation of the BMC software program. The data is used to perceive the security posture of the business module, and the security detection result is used to indicate the possibility that the BMC is subjected to an Advanced Persistent Threat (APT) attack. The control module is used to determine, based on the security detection results, that the BMC has been subjected to the APT attack, and to restart the BMC in a downgraded boot mode.
7. A baseboard management controller (BMC), characterized in that, The BMC includes a service module and a security detection module. The service module is used to provide management functions for components in the computer device. The security detection module is used to perform security detection on the BMC. The service module and the security detection module are communicatively isolated. The storage media accessed by the service module and the security detection module are isolated. The security detection module is used to execute the operation steps of the method according to any one of claims 1 to 5.
8. A computer device, characterized in that, The computer device includes a processor, a memory, and a baseboard management controller (BMC) as described in claim 7, the BMC being used to perform the operational steps of the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method, device and server for managing firmware of basic input and output system
CN109446815A
Firmware starting method, chip and computing equipment
CN115935335A
Chip, method for generating private key, and method for trusted verification
WO2020073206A1