Method and device for blocking control instruction to be executed, medium, equipment and product

By determining the security level in the terminal device and determining whether the device is an abnormal device, the problem that the prior art cannot effectively identify malicious network traffic data not stored in the preset attack feature library is solved, and the security of the terminal device is improved.

CN120045918APending Publication Date: 2025-05-27CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510180034.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

When the prior art performs security detection of the network traffic data of the terminal device, it is impossible to effectively identify malicious network traffic data not stored in the preset attack feature library, resulting in poor security of the terminal device.

Method used

By determining its security level in the terminal device, and determining whether the terminal device is an abnormal device based on the security level or security level and the control instructions to be executed, thereby blocking the control instructions to be executed.

Benefits of technology

It is necessary to determine whether the terminal device is abnormal without matching the preset attack feature library, thereby blocking potential malicious instructions, improving the security of the terminal device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120045918A_ABST
    Figure CN120045918A_ABST
Patent Text Reader

Abstract

The invention discloses a to-be-executed control instruction blocking method and device, a medium, equipment and a product, relates to the technical field of communication, and is used for improving the safety of terminal equipment. The method comprises the following steps: determining the security level of the terminal equipment; the security level is used for indicating the security degree of the terminal equipment; according to the security level, or according to the security level and a to-be-executed control instruction received by the terminal device, determining whether the terminal device is an abnormal terminal device; and blocking the to-be-executed control instruction under the condition that the terminal equipment is the abnormal terminal equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communication technologies, and in particular, to a method, apparatus, medium, device, and product for blocking a to-be-executed control instruction. Background Art

[0002] With the rapid development of Internet technologies, in order to facilitate office work and improve work efficiency, many important data are stored in specific terminal devices in the form of electronic information.

[0003] To prevent malicious attacks on terminal devices by malicious personnel, security detection can usually be performed on the network traffic data received by the terminal devices. The principle of security detection is to compare the data features in the network traffic data with a preset attack feature library. However, for the data features of malicious network traffic data that are not stored in the preset attack feature library, it may not be possible to effectively identify the malicious network traffic data, thus resulting in poor security of the terminal devices. Summary of the Invention

[0004] The present application provides a method, apparatus, medium, device, and product for blocking a to-be-executed control instruction, which is used to improve the security of terminal devices.

[0005] To achieve the above object, the present application adopts the following technical solutions:

[0006] In a first aspect, a method for blocking a to-be-executed control instruction is provided. The method includes: when a terminal device receives a to-be-executed control instruction, determining the security level of the terminal device; the security level is used to indicate the security degree of the terminal device; according to the security level, or according to the security level and the to-be-executed control instruction received by the terminal device, determining whether the terminal device is an abnormal terminal device; and when the terminal device is an abnormal terminal device, blocking the to-be-executed control instruction.

[0007] Optionally, determining whether the terminal device is an abnormal terminal device according to the security level, or according to the security level and the to-be-executed control instruction received by the terminal device includes: when the security level of the terminal device is less than or equal to a first level, or greater than a second level, determining whether the terminal device is an abnormal terminal device according to the security level; when the security level of the terminal device is the second level, determining whether the terminal device is an abnormal terminal device according to the security level and the to-be-executed control instruction received by the terminal device; the second level is greater than the first level.

[0008] Optionally, determining whether the terminal device is an abnormal terminal device according to the security level and the control instruction to be executed received by the terminal device includes: determining a target control instruction; the target control instruction is determined according to the output of a prediction model for the control instruction to be executed; the prediction model for the control instruction to be executed is used to predict the target control instruction; in the case where the control instruction to be executed is different from the target control instruction, determining that the terminal device is an abnormal terminal device; in the case where the control instruction to be executed is the same as the target control instruction, determining that the terminal device is not an abnormal terminal device.

[0009] Optionally, in the case where the control instruction to be executed is different from the target control instruction, determining that the terminal device is an abnormal terminal device includes: in the case where the control instruction to be executed is different from the target control instruction and the cumulative number of times that the control instruction to be executed is different from the target control instruction is greater than a threshold number of times, determining that the terminal device is an abnormal terminal device.

[0010] Optionally, the method further includes: obtaining a first historical observation state set of the terminal device; the first historical observation state set includes a plurality of control instructions to be executed executed by the terminal device and the execution times of the plurality of control instructions to be executed during a first historical time period; based on the first historical observation state set, training a neural network model to obtain a prediction model for the control instruction to be executed.

[0011] Optionally, determining the security level of the terminal device includes: obtaining a current observation state set of the terminal device; the current observation state set includes a plurality of control instructions to be executed executed by the terminal device and the execution times of the plurality of control instructions to be executed during a third historical time period; inputting the current observation state set into a security level prediction model, and using the output of the security level prediction model as the security level of the terminal device.

[0012] Optionally, the method further includes: obtaining a second historical observation state set and a historical security level set of the terminal device; the second historical observation state set includes a plurality of control instructions to be executed executed by the terminal device during a second historical time period; the historical security level set includes the security levels of the terminal device at different times during the second historical time period; based on the second historical observation state set and the historical security level set, training a preset statistical model to obtain a security level prediction model.

[0013] Based on the technical solution provided in this application, whether the terminal device is an abnormal terminal device is determined by the security level of the terminal device or according to the security level and the control instruction to be executed received by the terminal device. In this way, it is not necessary to match the data characteristics of the network traffic data in the terminal device with a preset attack feature library to determine whether the terminal device is abnormal. Further, in the case that the terminal device is an abnormal terminal device, the control instruction to be executed is blocked. In this way, it is possible to avoid executing the instructions of the malicious attacker on the terminal device and improve the security of the terminal device.

[0014] In a second aspect, a control instruction to be executed blocking device is provided. The device includes: a determination unit and a processing unit;

[0015] The determination unit is configured to determine the security level of the terminal device when the terminal device receives a control instruction to be executed; the security level is used to indicate the security degree of the terminal device; the determination unit is further configured to determine whether the terminal device is an abnormal terminal device according to the security level or according to the security level and the control instruction to be executed received by the terminal device; the processing unit is configured to block the control instruction to be executed when the terminal device is an abnormal terminal device.

[0016] Optionally, the determination unit is specifically configured to: determine whether the terminal device is an abnormal terminal device according to the security level when the security level of the terminal device is less than or equal to the first level or greater than the second level; determine whether the terminal device is an abnormal terminal device according to the security level and the control instruction to be executed received by the terminal device when the security level of the terminal device is the second level; the second level is greater than the first level.

[0017] Optionally, the determination unit is further specifically configured to: determine a target control instruction; the target control instruction is determined according to the output of a prediction model of the control instruction to be executed; the prediction model of the control instruction to be executed is used to predict the target control instruction; determine that the terminal device is an abnormal terminal device when the control instruction to be executed is different from the target control instruction; determine that the terminal device is not an abnormal terminal device when the control instruction to be executed is the same as the target control instruction.

[0018] Optionally, when the control instruction to be executed is different from the target control instruction, the determination unit is further specifically configured to: determine that the terminal device is an abnormal terminal device when the control instruction to be executed is different from the target control instruction and the cumulative number of times that the control instruction to be executed is different from the target control instruction is greater than a threshold number of times.

[0019] Optionally, the apparatus further includes an obtaining unit configured to obtain a first historical observation state set of the terminal device; the first historical observation state set includes a plurality of to-be-executed control instructions executed by the terminal device within a first historical time period and the execution times of the plurality of to-be-executed control instructions; the processing unit is further configured to train the neural network model based on the first historical observation state set to obtain a to-be-executed control instruction prediction model.

[0020] Optionally, the determining unit is specifically configured to: obtain a current observation state set of the terminal device; the current observation state set includes a plurality of to-be-executed control instructions executed by the terminal device within a third historical time period and the execution times of the plurality of to-be-executed control instructions; input the current observation state set into the security level prediction model, and use the output of the security level prediction model as the security level of the terminal device.

[0021] Optionally, the obtaining unit is further configured to obtain a second historical observation state set and a historical security level set of the terminal device; the second historical observation state set includes a plurality of to-be-executed control instructions executed by the terminal device arranged in time sequence within a second historical time period; the historical security level set includes the security levels of the terminal device at different times within the second historical time period; the processing unit is further configured to train the preset statistical model based on the second historical observation state set and the historical security level set to obtain a security level prediction model.

[0022] In a third aspect, a to-be-executed control instruction blocking apparatus is provided. The to-be-executed control instruction blocking apparatus can implement the functions performed by the to-be-executed control instruction blocking apparatus in the above aspects or various possible designs. The functions can be implemented by hardware. For example, in a possible design, the to-be-executed control instruction blocking apparatus may include: a processor and a communication interface. The processor can be used to support the to-be-executed control instruction blocking apparatus to implement the functions involved in the above first aspect or any possible design of the first aspect.

[0023] In another possible design, the to-be-executed control instruction blocking apparatus may further include a memory for storing necessary computer execution instructions and data of the to-be-executed control instruction blocking apparatus. When the to-be-executed control instruction blocking apparatus runs, the processor executes the computer execution instructions stored in the memory so that the to-be-executed control instruction blocking apparatus executes the to-be-executed control instruction blocking method in the above first aspect or any possible one of the first aspect.

[0024] Fourthly, a computer-readable storage medium is provided. The computer-readable storage medium can be a readable non-volatile storage medium. The computer-readable storage medium stores computer instructions or programs. When the computer-readable storage medium runs on a computer, the computer can execute any possible to-be-executed control instruction blocking method in the first aspect or the above aspects.

[0025] Fifthly, a computer program product containing instructions is provided. When the computer program product runs on a computer, the computer can execute any possible to-be-executed control instruction blocking method designed in the first aspect or the above aspects.

[0026] Sixthly, an electronic device is provided. The electronic device includes one or more processors and one or more memories. One or more memories are coupled to one or more processors. One or more memories are used to store computer program code. The computer program code includes computer instructions. When one or more processors execute the computer instructions, the electronic device executes the to-be-executed control instruction blocking method in the first aspect or any possible design in the first aspect.

[0027] Seventhly, a chip system is provided. The chip system includes a processor and a communication interface. The chip system can be used to implement the functions executed by the to-be-executed control instruction blocking device in the first aspect or any possible design in the first aspect. In a possible design, the chip system further includes a memory for storing program instructions and / or data. The chip system can be composed of chips or can include chips and other discrete devices, without limitation. Description of the Drawings

[0028] Figure 1 It is a schematic structural diagram of a to-be-executed control instruction blocking system provided by an embodiment of the present application;

[0029] Figure 2 It is a schematic structural diagram of a to-be-executed control instruction blocking device provided by an embodiment of the present application;

[0030] Figure 3 It is a schematic flowchart of a to-be-executed control instruction blocking method provided by an embodiment of the present application;

[0031] Figure 4 It is a schematic structural diagram of a hidden Markov model provided by an embodiment of the present application;

[0032] Figure 5 It is a schematic flowchart of another to-be-executed control instruction blocking method provided by an embodiment of the present application;

[0033] Figure 6This is a schematic structural diagram of another to-be-executed control instruction blocking device provided by an embodiment of the present application. Detailed implementation manners

[0034] In order to enable those of ordinary skill in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0035] It should be noted that the terms "first", "second", etc. in the description and claims of the present application and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the embodiments of the present application as detailed in the appended claims.

[0036] It should also be understood that the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, and / or components.

[0037] With the rapid development of Internet technology, in order to facilitate office work and improve work efficiency, various software, network systems, Internet of Things systems, etc. are more and more widely used in daily work and life. Many important data are stored in specific terminal devices in the form of electronic information.

[0038] In order to prevent malicious personnel from maliciously attacking terminal devices, usually, security detection can be performed on the network traffic data received by the terminal devices. The principle of security detection is to compare the data features in the network traffic data with a preset attack feature library. However, for the data features of malicious network traffic data that are not stored in the preset attack feature library, it may not be possible to effectively identify the malicious network traffic data, thus resulting in poor security of the terminal devices.

[0039] For example, a terminal device can use security devices such as a security detection firewall, an intrusion detection system (IDS), an intrusion prevention system (IPS), a web application firewall (WAF), etc. to perform security detection on the network traffic data received by the terminal device.

[0040] In view of this, an embodiment of the present application provides a method for blocking a to-be-executed control instruction, including: determining the security level of a terminal device, where the security level is used to indicate the security degree of the terminal device; determining whether the terminal device is an abnormal terminal device according to the security level, or according to the security level and the to-be-executed control instruction received by the terminal device; and blocking the to-be-executed control instruction when the terminal device is an abnormal terminal device.

[0041] The method provided by the embodiment of the present application will be described in detail below with reference to the accompanying drawings of the specification.

[0042] It should be noted that the network system described in the embodiment of the present application is for more clearly explaining the technical solution of the embodiment of the present application, and does not constitute a limitation on the technical solution provided by the embodiment of the present application. Those of ordinary skill in the art know that with the evolution of the network system and the emergence of other network systems, the technical solution provided by the embodiment of the present application is equally applicable to similar technical problems.

[0043] Figure 1 The following shows a schematic structural diagram of a to-be-executed control instruction blocking system 10 provided by an embodiment of the present application. As Figure 1 shown, the to-be-executed control instruction blocking system 10 may include a terminal device 11 and a to-be-executed control instruction blocking device 12.

[0044] Among them, the terminal device 11 can be used to store file data. It can also be called a terminal, a mobile station (MS), a mobile terminal (MT), etc., and is a device that provides voice and / or data connectivity to users. For example, the terminal device 11 can be a handheld device with a wireless connection function, a vehicle-mounted device, etc. Specifically, it can be: a smart phone, a pocket personal computer (PPC), a palm computer, a personal digital assistant (PDA), a notebook computer, a tablet computer, a wearable device, or a vehicle-mounted device, etc. The embodiment of the present application does not limit the specific technology, specific quantity, and specific device form adopted by the terminal device 11.

[0045] Among them, the to-be-executed control instruction blocking device 12 involved in the embodiments of the present application is used to perform security detection on a terminal device to determine whether the terminal device is an abnormal terminal device, and block the to-be-executed control instruction of the user when the terminal device is an abnormal terminal device. For example, it can be an electronic device with processing functions such as a computer or a server. For example, the to-be-executed control instruction blocking device 12 can be a computer, a server, etc. Among them, the server can be a single server, or it can also be a server cluster composed of multiple servers. In some embodiments, the server cluster can also be a distributed cluster. The embodiments of the present application do not limit the specific technology, specific quantity, and specific device form of the to-be-executed control instruction blocking device 12.

[0046] When specifically implemented, Figure 1 each device in Figure 2 can adopt the Figure 2 shown composition structure, or include Figure 2 FIG. is a schematic structural diagram of a to-be-executed control instruction blocking device 200 provided by an embodiment of the present application. The to-be-executed control instruction blocking device 200 can be a network device, or the to-be-executed control instruction blocking device 200 can be a chip or a system-on-chip in a network device. As Figure 2 shown, the to-be-executed control instruction blocking device 200 includes a processor 201, a communication interface 202, and a communication line 203.

[0047] Furthermore, the to-be-executed control instruction blocking device 200 may further include a memory 204. Among them, the processor 201, the memory 204, and the communication interface 202 can be connected through the communication line 203.

[0048] Among them, the processor 201 is a CPU, a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 201 can also be other devices with processing functions, such as circuits, devices, or software modules, without limitation.

[0049] The communication interface 202 is used to communicate with other devices or other communication networks. The communication interface 202 can be a module, a circuit, a communication interface, or any device capable of realizing communication.

[0050] The communication line 203 is used to transmit information between the components included in the to-be-executed control instruction blocking device 200.

[0051] A memory 204 for storing instructions. The instructions can be a computer program.

[0052] Among them, the memory 204 can be a read-only memory (ROM) or other types of static storage devices that can store static information and / or instructions, or a random access memory (RAM) or other types of dynamic storage devices that can store information and / or instructions. It can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, without limitation.

[0053] It should be noted that the memory 204 can exist independently of the processor 201 or be integrated with the processor 201. The memory 204 can be used to store instructions, program codes, or some data, etc. The memory 204 can be located inside or outside the to-be-executed control instruction blocking device 200, without limitation. The processor 201 is configured to execute the instructions stored in the memory 204 to implement the to-be-executed control instruction blocking method provided in the following embodiments of the present application.

[0054] In one example, the processor 201 can include one or more CPUs. For example, Figure 2 CPU0 and CPU1 in

[0055] As an alternative implementation, the to-be-executed control instruction blocking device 200 includes multiple processors. For example, in addition to Figure 2 the processor 201 in

[0056] It should be noted that Figure 2 the shown component structure does not constitute a limitation on each device in the Figure 1 . Except for Figure 2 the components shown in Figure 1 , each device in the Figure 2 can include more or fewer components than those shown, or combine certain components, or have different component arrangements.

[0057] In the embodiments of the present application, the chip system can be composed of chips or can include chips and other discrete devices.

[0058] In addition, the actions, terms, etc. involved in the various embodiments of the present application can refer to each other without limitation. The message name or parameter name in the message exchanged between the various devices in the embodiments of the present application is only an example, and other names can also be used in the specific implementation without limitation.

[0059] In order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish the same or similar items with substantially the same functions and effects. Those skilled in the art can understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit the difference.

[0060] It should be noted that, in this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in this application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0061] In the present application, "at least one" means one or more, and "plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0062] Combine the following Figure 1 The pending control instruction blocking system shown describes the pending control instruction blocking method provided in the embodiment of the present application.

[0063] Figure 3 A flowchart of a method for blocking a pending control instruction provided in an embodiment of the present application is shown in FIG. Figure 3 As shown, the method includes the following S301-S303:

[0064] S301. When a terminal device receives a control instruction to be executed, determine a security level of the terminal device.

[0065] The security level is used to indicate the security level of the terminal device.

[0066] In one example, the security levels may include a first level, a second level, a third level, and a fourth level. The first level may be used to indicate that the security level of the terminal device is high risk. The second level may be used to indicate that the security level of the terminal device is medium risk. The third level may be used to indicate that the security level of the terminal device is low risk. The fourth level may be used to indicate that the security level of the terminal device is secure. The security level of the terminal device may also be set in other ways, which are not limited herein.

[0067] Among them, the fourth level is greater than the third level, the third level is greater than the second level, and the second level is greater than the first level.

[0068] As a possible implementation, the to-be-executed control instruction blocking device may obtain the current observation state set of the terminal device. Further, the current observation state set is input into the security level prediction model, and the output of the security level prediction model is used as the security level of the terminal device.

[0069] It should be noted that the current observation state set of the terminal device may include multiple to-be-executed control instructions. The current observation state set may be obtained from the log data of the terminal device. The current observation state set includes multiple to-be-executed control instructions executed by the terminal device within the third historical time period and the execution times of the multiple to-be-executed control instructions; the third historical time period may be set as needed. For example, the previous 1 minute, the previous 2 minutes, etc. of the current moment.

[0070] For example, the preset quantity and the preset duration may be set as needed. For example, the preset quantity may be 1, 3, 5, etc., and the preset duration may be 20 seconds, 30 seconds, 1 minute, 2 minutes, etc.

[0071] It should be noted that the to-be-executed control instruction may refer to an instruction generated in response to an operator's control operation. For example, the to-be-executed control instruction may be an instruction input by the operator through the input device (such as a keyboard) of the to-be-executed control instruction blocking device, or may be a to-be-executed control instruction input by the operator through the physical button set by the to-be-executed control instruction blocking device.

[0072] For example, the to-be-executed control instruction may be login, password modification, viewing file content, modifying files, uploading files, backing up files, executing files, deleting files, switching user permissions, etc.

[0073] As another possible implementation, the terminal device is pre-installed with an application program for determining the security level. The control instruction blocking device to be executed can send a request message for requesting the security level of the terminal device to the application program. Correspondingly, the application program receives the request message and, after receiving the request message, sends the security level of the terminal device to the control instruction blocking device to be executed, so that the control instruction blocking device to be executed determines the security level of the terminal device.

[0074] S302. Determine whether the terminal device is an abnormal terminal device according to the security level or according to the security level and the control instruction to be executed received by the terminal device.

[0075] Among them, the abnormal terminal device is a terminal device with a virus intrusion, or can also be a terminal with a system vulnerability, etc.

[0076] As a possible implementation, the control instruction blocking device to be executed can determine whether the terminal device is an abnormal terminal device according to the security level when the security level of the terminal device is less than or equal to the first level or greater than the second level.

[0077] In one example, the control instruction blocking device to be executed can determine that the terminal device is an abnormal terminal device when the security level of the terminal device is less than or equal to the first level.

[0078] For example, the security level of the terminal device can be represented by Si. When Si is at the first level (i.e., high risk), the terminal device is in a high-risk state, and the control instruction blocking device to be executed can directly determine that the terminal device is an abnormal terminal device.

[0079] In one example, when the security level of the terminal device is greater than the second level (i.e., low risk, safe), the control instruction blocking device to be executed can determine that the terminal device is a non-abnormal terminal device.

[0080] For example, the security level of the terminal device can be represented by S i When S i is at the third level (i.e., low risk), the terminal device is in a low-risk state, and the control instruction blocking device to be executed can directly determine that the terminal device is a non-abnormal terminal device.

[0081] For another example, the security level of the terminal device can be represented by S i When S i is at the fourth level (i.e., safe), the terminal device is in a safe state, and the control instruction blocking device to be executed can directly determine that the terminal device is a non-abnormal terminal device.

[0082] As another possible implementation, when the security level of the terminal device is less than or equal to the second level and greater than the first level, the control instruction to be executed blocking device may determine whether the terminal device is an abnormal terminal device according to the security level and the control instruction to be executed received by the terminal device.

[0083] For example, the security level of the terminal device can be represented by S i In the case where S i is at the second level (i.e., medium risk), the terminal device is in a medium-risk state. The control instruction to be executed blocking device may determine whether the terminal device is an abnormal terminal device according to the security level and the control instruction to be executed received by the terminal device.

[0084] It should be noted that the specific implementation of determining whether the terminal device is an abnormal terminal device according to the security level can refer to the description in the subsequent part, and will not be elaborated here.

[0085] S303. When the terminal device is an abnormal terminal device, block the control instruction to be executed.

[0086] As a possible implementation, the control instruction to be executed blocking device may set an interrupt mask register to prohibit or allow specific types of interrupts. When it is necessary to block a certain control instruction to be executed, the control instruction to be executed blocking device may set the interrupt mask bit related to the control instruction to be executed to the prohibited state, thereby blocking the control instruction to be executed.

[0087] As another possible implementation, the control instruction to be executed blocking device may block the control instruction to be executed by setting up a firewall.

[0088] In some embodiments, after blocking the control instruction to be executed, the control instruction to be executed blocking device may also send an alarm message to the network-related personnel. The alarm message is used to indicate that the terminal device is in an abnormal state.

[0089] The following uses the following example to illustrate the blocking process of the control instruction to be executed blocking device. The security level of the terminal device can be represented by S i as shown.

[0090] 1. When Si is at the first level (i.e., high risk), the terminal device is in a high-risk state. The control instruction to be executed blocking device may directly determine that the terminal device is an abnormal terminal device. The control instruction to be executed blocking device regards the terminal device as an invaded state, directly blocks the control instruction to be executed (including the user's operation), and at the same time sends an alarm message to the user and the network administrator.

[0091] 2. When Si is at the second level (i.e., medium risk), the terminal device is in a medium-risk state. The to-be-executed control instruction blocking device can determine that the terminal device is in a potential intrusion state and send alarm information to the user and the network administrator simultaneously.

[0092] The to-be-executed control instruction blocking device inputs the current observed state set into the to-be-executed control instruction prediction model to predict the user's next to-be-executed control instruction (i.e., the target control instruction). Meanwhile, it initializes the counter count = 0 and sets max_count.

[0093] When the predicted to-be-executed control instruction is the same as the received next to-be-executed control instruction (and the user's next operation), reset the counter count = 0;

[0094] When the predicted to-be-executed control instruction is different from the received next to-be-executed control instruction (and the user's next operation), count = count + 1. At this time, if count ≥ max_count, block the to-be-executed control instruction.

[0095] Among them, max_count represents the number threshold. max_count can be set as needed. For example, it can be 3, etc.

[0096] 3. When Si is at the third level (i.e., low risk), the terminal device is in a low-risk state. The to-be-executed control instruction blocking device can send alarm information to the user and the network administrator.

[0097] For another example, the security level of the terminal device can be represented by S i When S i is at the fourth level (i.e., secure), the terminal device is in a secure state. The to-be-executed control instruction blocking device can directly determine that the terminal device is a non-abnormal terminal device.

[0098] 4. When Si is at the fourth level (i.e., secure), the terminal device is in a secure state. The to-be-executed control instruction blocking device executes all received to-be-executed control instructions.

[0099] Based on the technical solution provided by this application, whether the terminal device is an abnormal terminal device is determined through the security level of the terminal device or according to the security level and the to-be-executed control instructions received by the terminal device. In this way, it is not necessary to match the data characteristics of the network traffic data in the terminal device with a preset attack feature library to determine whether the terminal device is abnormal. Further, when the terminal device is an abnormal terminal device, block the to-be-executed control instruction. In this way, it is possible to avoid executing the instructions of the malicious attacker on the terminal device and improve the security of the terminal device.

[0100] A possible embodiment. In order to determine whether a terminal device is an abnormal terminal device according to the security level and the control instruction to be executed received by the terminal device, the present application may further include the following S401 - S403.

[0101] S401. Determine the target control instruction.

[0102] Among them, the target control instruction is determined according to the output of the control instruction prediction model to be executed. The control instruction prediction model to be executed is used to predict the target control instruction.

[0103] As a possible implementation manner, the control instruction blocking device to be executed may obtain the current observation state set of the terminal device. Further, input the current observation state set into the control instruction prediction model to be executed, and use the output of the control instruction prediction model to be executed as the target control instruction.

[0104] S402. When the control instruction to be executed is different from the target control instruction, determine that the terminal device is an abnormal terminal device.

[0105] As a possible implementation manner, the control instruction blocking device to be executed may determine that the terminal device is an abnormal terminal device when there is a difference between the control instruction to be executed and the target control instruction once.

[0106] As another possible implementation manner, the control instruction blocking device to be executed may determine that the terminal device is an abnormal terminal device when the control instruction to be executed is different from the target control instruction and the number of differences is greater than the number threshold.

[0107] It should be noted that the number threshold can be set as needed. For example, it can be 3.

[0108] In an example, when a low - privilege user executes the privilege - escalation instruction "sudo root", the security - level prediction model determines that the security level of the terminal device is the second level (i.e., medium - risk), and count = 0.

[0109] Next, the next control instruction to be executed received by the terminal device is the file - viewing instruction "sudo cat

[0110] / etc / shadow" to view relevant security information such as the passwords of system users, which is different from the next control instruction to be executed predicted by the control instruction prediction model to be executed, and count = 1.

[0111] Next, another control instruction to be executed received by the terminal device is the line "sudo find / - name "*.bak"" to view all historical backup files in the system root directory, which is different from another control instruction to be executed predicted by the control instruction prediction model to be executed, and count = 2.

[0112] Next, another control instruction to be executed received by the terminal device is to execute the "history-c" command to clear the executed historical command records, which is different from another control instruction to be executed predicted by the control instruction prediction model to be executed, and count = 3. Triggering the threshold max_count, the control instruction blocking device to be executed can directly block the control instruction to be executed.

[0113] S403. When the control instruction to be executed is the same as the target control instruction, it is determined that the terminal device is not an abnormal terminal device.

[0114] The control instruction blocking device to be executed can execute the received control instruction to be executed when it is determined that the terminal device is not an abnormal terminal device.

[0115] In a possible embodiment, in order to obtain the control instruction prediction model to be executed, the present application may further include the following S501-S502.

[0116] S501. Obtain the first historical observation state set of the terminal device.

[0117] Among them, the first historical observation state set includes a plurality of control instructions to be executed executed by the terminal device arranged in time sequence within the first historical time period and the execution times of the plurality of control instructions to be executed.

[0118] Among them, the first historical time period can be set as needed. For example, it can be the previous month, the previous 2 months, etc. of the current moment.

[0119] As a possible implementation manner, the control instruction blocking device to be executed can obtain network log data from the log server and filter the first historical observation state set of the terminal device from the network log data based on time conditions.

[0120] In an example, the first historical observation state set can be expressed as O = {O 1 , O 2 ,..., O M}. O represents the first historical observation state set. O 1 , O 2 ,..., O M can represent different control instructions to be executed arranged in time series.

[0121] For example, O 1 can represent the login instruction received by the terminal device at time t1. O 2 can represent the password modification instruction at time t2. O M can represent the instruction to view the file content received by the terminal device at time t M time.

[0122] S502. Train a neural network model based on the first historical observation state set to obtain a to-be-executed control instruction prediction model.

[0123] Among them, the neural network model can be set as needed. For example, it can be a long short-term memory network model.

[0124] As a possible implementation, the to-be-executed control instruction blocking device can divide the first historical observation state set into a training set and a test set according to a preset ratio; and input the first historical observation state set as the training set into a long short-term memory network model (Long Short-Term Memory, LSTM) for training, adjust the model parameters in the long short-term memory network model until convergence, and obtain an initial to-be-executed control instruction prediction model. Further, input the first historical observation state set of the test set into the initial to-be-executed control instruction prediction model, and when the accuracy of the output result is greater than the accuracy threshold, determine the initial to-be-executed control instruction prediction model as the to-be-executed control instruction prediction model.

[0125] In a possible embodiment, this application may further include the following S601 - S602.

[0126] S601. Obtain the second historical observation state set and the historical security level set of the terminal device.

[0127] Among them, the second historical observation state set includes multiple to-be-executed control instructions executed by the terminal device arranged in time sequence within the second historical time period; the historical security level set includes the security levels of the terminal device at different times within the second historical time period.

[0128] Among them, the second historical time period can be the same historical time period as the first historical time period, or a different historical time period from the first historical time period, which is not limited here.

[0129] As a possible implementation, the to-be-executed control instruction blocking device can obtain network log data, and extract the second historical observation state set and the historical security level set from the log data according to time sequence.

[0130] It should be noted that extracting the second historical observation state set and the historical security level set according to time sequence may mean: extracting multiple to-be-executed control instructions executed by the terminal device and the security levels at different times in the order from early to late, to obtain the second historical observation state set and the historical security level set.

[0131] S602. Train a preset statistical model based on the second historical observation state set and the historical security level set to obtain a security level prediction model.

[0132] Among them, the preset statistical model can be set as needed. For example, it can be a Hidden Markov Model.

[0133] As a possible implementation, the to-be-executed control instruction blocking device can use the Baum-Welch algorithm to train a Hidden Markov Model (HMM), and update the model parameters in the Hidden Markov Model to obtain a security level prediction model.

[0134] Among them, the model parameters can be λ = [A, B, Π]. A is the transition probability matrix of the security level S, B is the generation probability matrix of the observation state O, and Π is the probability distribution of the initial state S1 of the terminal device.

[0135] In one example, Figure 4 shows a schematic structural diagram of a Hidden Markov Model, as Figure 4 shown, a plurality of to-be-executed control instructions O = {O t1 , O t2 , O t3 ,..., O tn} executed by the terminal device at preset times t1, t2, t3... tn, and the Hidden Markov Model can predict that the security levels of the preset times t1, t2, t3... tn of the terminal device are S = {S t1 , S t2 , S t3 ,..., S tn}.

[0136] Figure 5 FIG. is a schematic flowchart of another to-be-executed control instruction blocking method provided by an embodiment of the present application, as Figure 5 shown, the method includes the following S1-S9:

[0137] S1. Obtain the current observation state set of the terminal device.

[0138] Among them, the specific implementation manner of this step can refer to S301 and will not be elaborated here.

[0139] In some embodiments, the current observation state set can be a set after data cleaning. The process of data cleaning can refer to the prior art and will not be elaborated here.

[0140] S2. Input the current observation state set into the security level prediction model, and use the output of the security level prediction model as the security level of the terminal device.

[0141] Among them, the specific implementation manner of this step can refer to S301 and will not be elaborated here.

[0142] S3. Determine whether the security level of the terminal device is the second level.

[0143] S4. When the security level of the terminal device is the second level, input the current observation state set into the security level prediction model to obtain a target control instruction.

[0144] Among them, the specific implementation of this step can refer to S401 and will not be elaborated here.

[0145] In some embodiments, when the security level of the terminal device is not the second level, execute S10.

[0146] S5. Determine whether the control instruction to be executed by the current terminal device is the same as the target control instruction.

[0147] S6. When the control instruction to be executed is the same as the target control instruction, reset the cumulative number of times that the control instruction to be executed is different from the target control instruction.

[0148] S7. When the control instruction to be executed is different from the target control instruction, increase the cumulative number of times that the control instruction to be executed is different from the target control instruction.

[0149] The cumulative number of times can be count, and increasing the cumulative number of times that the control instruction to be executed is different from the target control instruction can be expressed as count = count + 1.

[0150] S8. Determine whether the cumulative number of times is greater than or equal to the number threshold.

[0151] When the cumulative number of times is greater than or equal to the number threshold, execute S9.

[0152] When the cumulative number of times is less than the number threshold, execute S10.

[0153] S9. When the cumulative number of times is greater than or equal to the number threshold, block the control instruction to be executed.

[0154] S10. Execute the control instruction to be executed.

[0155] The embodiments of the present application can divide the control instruction blocking device to be executed into functional modules or functional units according to the above method examples. For example, each functional module or functional unit can be corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules or functional units. Among them, the division of modules or units in the embodiments of the present application is illustrative, and is only a logical function division. There may be other division methods in actual implementation.

[0156] In the case of dividing each functional module according to each function, Figure 6 FIG. 1 shows a schematic structural diagram of a to-be-executed control instruction blocking device 800. The to-be-executed control instruction blocking device may be a to-be-executed control instruction blocking device, or may be a chip, a processor, etc. applied to the to-be-executed control instruction blocking device. The to-be-executed control instruction blocking device 800 may be used to execute the functions of the to-be-executed control instruction blocking device involved in the above embodiments. Figure 6 The shown to-be-executed control instruction blocking device 800 may include: a determination unit 801 and a processing unit 802; the determination unit 801 is configured to determine the security level of the terminal device when the terminal device receives a to-be-executed control instruction; the security level is used to indicate the security degree of the terminal device; the determination unit 801 is further configured to determine whether the terminal device is an abnormal terminal device according to the security level, or according to the security level and the to-be-executed control instruction received by the terminal device; the processing unit 802 is configured to block the to-be-executed control instruction when the terminal device is an abnormal terminal device.

[0157] Optionally, the determination unit 801 is specifically configured to: determine whether the terminal device is an abnormal terminal device according to the security level when the security level of the terminal device is less than or equal to the first level or greater than the second level; determine whether the terminal device is an abnormal terminal device according to the security level and the to-be-executed control instruction received by the terminal device when the security level of the terminal device is the second level; the second level is greater than the first level.

[0158] Optionally, the determination unit 801 is further specifically configured to: determine a target control instruction; the target control instruction is determined according to the output of a to-be-executed control instruction prediction model; the to-be-executed control instruction prediction model is used to predict the target control instruction; determine that the terminal device is an abnormal terminal device when the to-be-executed control instruction is different from the target control instruction; determine that the terminal device is not an abnormal terminal device when the to-be-executed control instruction is the same as the target control instruction.

[0159] Optionally, when the to-be-executed control instruction is different from the target control instruction, the determination unit 801 is further specifically configured to: determine that the terminal device is an abnormal terminal device when the to-be-executed control instruction is different from the target control instruction and the cumulative number of times that the to-be-executed control instruction is different from the target control instruction is greater than a number threshold.

[0160] Optionally, the device further includes an obtaining unit 803 configured to obtain a first historical observation state set of the terminal device; the first historical observation state set includes a plurality of to-be-executed control instructions executed by the terminal device within a first historical time period and the execution times of the plurality of to-be-executed control instructions; the processing unit 802 is further configured to train a neural network model based on the first historical observation state set to obtain a to-be-executed control instruction prediction model.

[0161] Optionally, the determining unit 801 is specifically configured to: obtain a current observation state set of the terminal device; the current observation state set includes a plurality of to-be-executed control instructions executed by the terminal device within a third historical time period and the execution times of the plurality of to-be-executed control instructions; input the current observation state set into a security level prediction model, and use the output of the security level prediction model as the security level of the terminal device.

[0162] Optionally, the obtaining unit 803 is further configured to obtain a second historical observation state set and a historical security level set of the terminal device; the second historical observation state set includes a plurality of to-be-executed control instructions executed by the terminal device arranged in time sequence within a second historical time period; the historical security level set includes the security levels of the terminal device at different times within the second historical time period; the processing unit 802 is further configured to train a preset statistical model based on the second historical observation state set and the historical security level set to obtain a security level prediction model.

[0163] The embodiments of the present application further provide a computer-readable storage medium. All or part of the processes in the above method embodiments may be completed by a computer program instructing relevant hardware. This program may be stored in the above computer-readable storage medium. When the program is executed, it may include the processes of the above method embodiments. The computer-readable storage medium may be an internal storage unit of the to-be-executed control instruction blocking device (including a data sending end and / or a data receiving end) in any of the foregoing embodiments, such as a hard disk or memory of the to-be-executed control instruction blocking device. The above computer-readable storage medium may also be an external storage device of the above terminal device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the above terminal device. Further, the above computer-readable storage medium may also include both the internal storage unit of the above to-be-executed control instruction blocking device and the external storage device. The above computer-readable storage medium is used to store the above computer program and other programs and data required by the above to-be-executed control instruction blocking device. The above computer-readable storage medium may also be used to temporarily store data that has been output or is to be output.

[0164] It should be noted that in the description of the present application, terms such as "first" and "second" in the specification, claims and drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices.

[0165] It should be understood that in the present application, "at least one (item)" means one or more, "a plurality" means two or more, "at least two (items)" means two or three or more, and "and / or" is used to describe the association relationship of associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expressions refer to any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0166] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and brevity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0167] In several embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.

[0168] The unit described as a separating component may or may not be physically separated. The component displayed as a unit may be a physical unit or multiple physical units, that is, it may be located in one place or distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0169] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0170] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on such an understanding, the technical solution of the embodiment of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0171] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for blocking a pending control instruction, characterized in that: The method comprises: In the case where the terminal device receives a control instruction to be executed, determining a security level of the terminal device; the security level is used to indicate the security level of the terminal device; Determining whether the terminal device is an abnormal terminal device according to the security level, or according to the security level and the control instruction to be executed received by the terminal device; In a case where the terminal device is the abnormal terminal device, the control instruction to be executed is blocked.

2. The method according to claim 1, characterized in that: The determining whether the terminal device is an abnormal terminal device according to the security level, or according to the security level and the control instruction to be executed received by the terminal device, includes: In the case where the security level of the terminal device is less than or equal to the first level, or greater than the second level, determining whether the terminal device is an abnormal terminal device according to the security level; the second level is greater than the first level; When the security level of the terminal device is the second level, it is determined whether the terminal device is an abnormal terminal device according to the security level and the control instruction to be executed received by the terminal device.

3. The method according to claim 2, characterized in that The determining, according to the security level and the to-be-executed control instruction received by the terminal device, whether the terminal device is an abnormal terminal device comprises: Determine a target control instruction; the target control instruction is determined according to the output of the prediction model of the control instruction to be executed; In a case where the control instruction to be executed is different from the target control instruction, determining that the terminal device is the abnormal terminal device; When the control instruction to be executed is the same as the target control instruction, it is determined that the terminal device is not the abnormal terminal device.

4. The method according to claim 3, characterized in that When the control instruction to be executed is different from the target control instruction, determining that the terminal device is the abnormal terminal device includes: When the control instruction to be executed is different from the target control instruction, and the accumulated number of times that the control instruction to be executed is different from the target control instruction is greater than a number threshold, the terminal device is determined to be the abnormal terminal device.

5. The method according to claim 3, characterized in that: The method further comprises: Acquire a first historical observation state set of the terminal device; the first historical observation state set includes a plurality of control instructions to be executed by the terminal device within a first historical time period and the execution time of the plurality of control instructions to be executed; Based on the first historical observation state set, the neural network model is trained to obtain the prediction model of the control instruction to be executed.

6. The method according to any one of claims 1 to 5, characterized in that Determining the security level of the terminal device includes: Acquire a current observation state set of the terminal device; the current observation state set includes a plurality of control instructions to be executed by the terminal device within a third historical time period and execution times of the plurality of control instructions to be executed; The current observation state set is input into a security level prediction model, and the output of the security level prediction model is used as the security level of the terminal device.

7. The method according to claim 6, characterized in that The method further comprises: Acquire a second historical observation state set and a historical security level set of the terminal device; the second historical observation state set includes a plurality of pending control instructions executed by the terminal device in a second historical time period; the historical security level set includes the security levels of the plurality of pending control instructions executed by the terminal device in the second historical time period; Based on the second historical observation state set and the historical security level set, a preset statistical model is trained to obtain the security level prediction model.

8. A device for blocking pending control instructions, characterized in that: The device comprises: a determination unit and a processing unit; The determining unit is used to determine the security level of the terminal device when the terminal device receives the control instruction to be executed; the security level is used to indicate the security level of the terminal device; The determining unit is further configured to determine whether the terminal device is an abnormal terminal device according to the security level, or according to the security level and the control instruction to be executed received by the terminal device; The processing unit is used to block the control instruction to be executed when the terminal device is the abnormal terminal device.

9. A computer-readable storage medium, characterized in that: The readable storage medium stores instructions, and when the instructions are executed, the method according to any one of claims 1 to 7 is implemented.

10. An electronic device, characterized in that: include: A processor, a memory and a communication interface; wherein the communication interface is used for the electronic device to communicate with other devices or networks; The memory is used to store one or more programs, which include computer-executable instructions. When the electronic device is running, the processor executes the computer-executable instructions stored in the memory to enable the electronic device to perform the method described in any one of claims 1-7.

11. A computer program product, comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.