Equipment access control method and system based on security sandbox

By adopting a security sandbox-based method in equipment access control, monitoring and evaluating equipment behavior and dynamically adjusting access strategies, the security and management complexity of traditional equipment access control technology is solved, and efficient and flexible network security protection is achieved.

CN120050075AActive Publication Date: 2025-05-27DALIAN PUBLIC SECURITY BUREAU +1

Patent Information

Application Number
CN202510164431.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-27
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

Traditional device access control technology has problems such as fragile security, complex management, insufficient flexibility, poor scalability, poor compatibility and poor user experience, and lacks dynamic monitoring of device behavior and real-time monitoring of process.

Method used

The device access control method based on security sandbox is adopted, and the identity authentication request is initiated to the authentication server through the security sandbox management program, the initial access control policy is received and deployed, the access behavior of processes in the sandbox is monitored, and the process operation logic analysis is used to use deep packet detection, system call interception and process operation logic analysis, trust evaluation is carried out in combination with machine learning models, and the device trust level and access control policy are dynamically adjusted.

Benefits of technology

It realizes all-round and three-dimensional network security protection, improves the security during equipment data exchange, promptly detects and responds to abnormal or potential security threats, prevents the spread of security risks, and ensures the security and stability of the network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050075A_ABST
    Figure CN120050075A_ABST
Patent Text Reader

Abstract

The invention discloses an equipment access control method and system based on a security sandbox, which adopts an advanced virtualization technology, constructs a highly isolated operation environment, combines technologies such as deep packet inspection, system call interception and process operation logic analysis, comprehensively monitors access behaviors of processes in the sandbox to virtual equipment, and improves the access performance of the virtual equipment. And the security and credibility of the equipment are evaluated, and illegal processes are prevented from running on the access terminal, so that the security access control of the equipment is realized. The monitoring comprises data packet content, protocol filtering, threat detection, system call interception, process creation, execution and termination behavior monitoring and the like. In combination with a trust evaluation algorithm, behavior data features are collected and extracted, trust scoring is performed by applying a machine learning model, and the equipment trust level and the access strategy are dynamically adjusted according to the score. According to the invention, the access control strategy is managed in a unified manner and deployed quickly based on the security sandbox management program and the authentication server. After identity authentication of the equipment, real-time monitoring of process dynamic behaviors in the running process of the equipment is added, and the safety of the equipment in the data exchange process is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field, and in particular to a device access control method and system based on a security sandbox. Background Art

[0002] In the context of the rapid development of current network technology, ensuring the access security of network resources and the legitimacy of device identities has become a core issue in network security management. It is responsible for verifying whether the devices to be exchanged comply with security policies, thereby preventing unauthorized devices from accessing network resources. However, traditional device access control technologies, such as password verification, digital certificates, and MAC address filtering, although they guarantee network security to a certain extent, have their own problems.

[0003] Password authentication is weak in security and vulnerable to attacks, which increases the burden on users. In addition, there is a lack of verification of the device itself, which poses a risk of password leakage. Digital certificates face problems with certificate credibility, complex update and maintenance, and high management costs. MAC address filtering is easy to be deceived, is not suitable for dynamic networks, and cannot identify the true identity of the device. In addition, there are also problems such as the risk of privacy leakage, difficulty in identifying malicious devices, and complex management, as well as other shortcomings such as insufficient flexibility, poor scalability, poor compatibility, and poor user experience.

[0004] Traditional device access control methods rely on static rule matching and blacklist mechanisms. Most existing device access control methods lack dynamic monitoring and evaluation of device behavior and do not have real-time monitoring of processes. Summary of the invention

[0005] The purpose of the present invention is to provide a device access control method and system based on a security sandbox to solve the problems raised in the above background technology.

[0006] To achieve the above object, the present invention provides the following technical solution: a device access control method based on a security sandbox, comprising at least: S100. The security sandbox management program initiates an identity authentication request to the authentication server; S200. After successful authentication, the authentication server issues an initial access control policy to the security sandbox management program; S300. The security sandbox management program deploys an initial access control policy to the corresponding sandbox container; S400. The security sandbox management program monitors the access behavior of the processes in the sandbox to the virtual devices, specifically including: S410. Process behavior monitoring: network communication data analysis, system call interception and process operation logic analysis of the processes in the sandbox; S420. Process Trust Evaluation: Extract network communication, system call, and process running logic features and input them into a machine learning model to evaluate the device trust score, and then dynamically adjust the device trust level and access control policy; S500. Construct a process execution behavior profile based on the extracted features and known security rules; S600. The security sandbox management program compares the real-time execution behavior of the process with the pre-constructed process execution behavior profile. When an abnormal behavior of a certain process is detected, block the abnormal behavior of the process and push an alarm to the authentication management platform.

[0007] Preferably, the S410 process behavior monitoring at least includes: S411. Network communication data analysis: Involving deep packet inspection technology, analyze the data packets sent and received by the sandbox container, and identify the content, protocol, and potential threats of the data packets; S412. System call interception: Monitor the system calls in the sandbox and intercept suspicious or illegal operations; S413. Process running logic analysis: Analyze the process creation, execution, and termination behaviors in the sandbox to identify abnormal behavior patterns.

[0008] Preferably, the S420 process trust evaluation at least includes: S421. Collect network communication, system call, and process running logic data; S422. Extract network communication, system call, and process running logic features; S423. Input the extracted network communication, system call, and process running logic features into a machine learning model to obtain the trust score of the virtual device; S424. According to the trust score result, dynamically adjust the trust level of the device, and accordingly decide whether to allow the device to access the network, and dynamically adjust the access control policy.

[0009] Preferably, the machine learning model can be a decision tree model, a random forest model, or a neural network model.

[0010] A device access control system based on a security sandbox includes an authentication request module for initiating an identity authentication request to an authentication server by a security sandbox management program; A policy distribution receiving module for receiving and parsing the security policy issued by the authentication server and passing it to the local policy deployment module; A policy deployment module for applying the received security policy to the sandbox; A process behavior monitoring module for performing network communication data analysis, system call interception, and process running logic analysis on the processes in the sandbox; A process trust evaluation module, which is used to extract network communication, system call, and process operation logic features and input them into a machine learning model to evaluate the device trust score, and then dynamically adjust the device trust level and access control policy; A process execution behavior portrait construction module, which is used to construct a process execution behavior portrait according to the extracted features and known security rules; An abnormal behavior blocking and warning module, which is used to immediately take measures to block the abnormal behavior and send a warning notice when an abnormal behavior is detected.

[0011] An apparatus and system for device access control based on a security sandbox proposed by the present invention have the following beneficial effects: 1. The present application adopts advanced virtualization technology to construct a highly isolated operating environment, namely a security sandbox. This sandbox provides an independent test and verification platform for the device before it is connected, and constructs a multi-level and dynamically adjustable network device access control system. This system integrates multi-level technical modules such as identity authentication, behavior monitoring, risk assessment, and access control. The present invention relies on the security sandbox management program and the authentication server to uniformly manage and quickly deploy access control policies, aiming to create an all-round and three-dimensional network security protection system.

[0012] 2. After device identity authentication, the present invention adds real-time monitoring of the dynamic behavior of processes during the operation of the device, aiming to further improve the security during the data exchange process of the device. Any abnormal or potential security threats can be discovered and responded to in a timely manner. The operating state and behavior patterns of the device are comprehensively captured. Once an abnormal behavior is discovered, the system will immediately trigger an alarm and take corresponding security measures, such as isolating, blocking, or restricting the access rights of the device, so as to effectively prevent the spread of security risks and ensure the security and stability of the network environment.

[0013] 3. The present invention combines technologies such as deep packet inspection, system call interception, and process operation logic analysis to comprehensively monitor the access behavior of processes in the sandbox to virtual devices, evaluate the security and credibility of the device, and prevent illegal processes from running on the access terminal, thereby realizing the secure access control of the device. The monitoring includes packet content, protocol filtering, threat detection, system call interception, monitoring of process creation, execution, and termination behaviors, etc. Combining with a trust evaluation algorithm, behavior data features are collected and extracted, a machine learning model is applied for trust scoring, and the device trust level and access policy are dynamically adjusted according to the score to prevent the spread of security threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 is a flowchart of the device access control method of the present invention; Figure 2 is a block diagram of the device access control system of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0015] Next, in combination with the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0016] Please refer to Figure 1-2 , the present invention provides a technical solution: a device access control method based on a security sandbox, which at least includes: S100. The security sandbox management program sends an identity authentication request to the authentication server; As a key component in the entire security system, the security sandbox management program first needs to send an identity authentication request to a dedicated authentication server to verify its own legality and authenticity.

[0017] This process is similar to an individual entering a username and password when logging into certain security systems. However, here it is an interaction between the program and the server based on specific authentication protocols and mechanisms. The security sandbox management program uses methods such as digital certificates or pre-shared keys to send an authentication request data packet containing its own identification information to the specified port of the authentication server. Some environmental information, such as the host address where the program is located and the running status, will be attached to the authentication request so that the authentication server can perform more comprehensive identity verification.

[0018] S200. After successful identity authentication, the authentication server issues an initial access control policy to the security sandbox management program; When the authentication server receives the authentication request from the security sandbox management program, it will verify and review the information provided by it. If the authentication is successful, it means that the management program is confirmed to be legal and trustworthy. At this time, the authentication server will generate and issue corresponding initial access control policies for the security sandbox management program according to the pre-set rules and policies. These policies specify in detail the operation scope that the security sandbox management program can execute in subsequent operations, the types of resources that can be accessed, and the interaction permissions with other system components. For example, the access control policy can specify the number of sandbox containers that the security sandbox management program can manage, the specific permissions for resource allocation and monitoring operations on the processes in the sandbox, and the cooperation methods with other security-related systems (such as firewalls, intrusion detection systems), etc.

[0019] S300. The security sandbox management program deploys the initial access control policy to the corresponding sandbox container; After receiving the initial access control policies issued by the authentication server, the security sandbox management program will convert these policies into specific configuration parameters and deploy them to the corresponding sandbox containers.

[0020] The specific configuration parameters cover using hardware virtualization technology to allocate independent virtual resources for each device to be connected, including VCPUs, memory, and network interfaces; deploying a lightweight operating system and necessary services inside the sandbox to simulate a real network environment; and achieving logical isolation between the sandbox and the external network through network virtualization technology to ensure that all activities of the device in the sandbox will not leak to the external network.

[0021] The security sandbox management program will finely configure the network access rules, file system access permissions, process execution permissions, etc. of the sandbox container according to the access control policies. For example, if the access control policy stipulates that a process in a certain sandbox container can only access specific network service ports, the security sandbox management program will set the corresponding firewall rules in the network configuration of the container to only allow communication connections to these specified ports.

[0022] S400. The security sandbox management program monitors the access behavior of processes in the sandbox to virtual devices; After the control policies of the sandbox container are deployed, the security sandbox management program will start comprehensive monitoring of the processes in the sandbox, especially the call and access behavior of processes to virtual devices.

[0023] S410. Process behavior monitoring: Perform network communication data analysis, system call interception, and process running logic analysis on the processes in the sandbox.

[0024] S411. Network communication data analysis: Involves deep packet inspection technology to analyze the data packets sent and received by the sandbox container, identify the content, protocol, and potential threats of the data packets; For sandbox containers, deep packet inspection (DPI) can check whether the transmitted data contains malicious code or sensitive information. For example, check whether malicious scripts (such as JavaScript) are transmitted outside the container, or whether the container is sending out files containing company secrets. By parsing the data part in the data packet, DPI can identify common malicious code patterns, such as SQL injection, cross - site scripting (XSS) code, etc. DPI can help monitor the behavior of applications in the sandbox container. By analyzing the network traffic generated by the application, understand its normal communication pattern. For example, a normal office software may only synchronize data with the company's internal server at specific times. If DPI detects that the software frequently sends a large amount of data outside during non - working hours, this may be abnormal behavior, indicating that the application may be maliciously exploited or malfunctioning.

[0025] Deep Packet Inspection (DPI) protocol identification for the traffic in and out of the sandbox container: For example, in a secure sandbox hypervisor, DPI can determine whether a container is communicating using unauthorized protocols. If the sandbox is designed to only allow HTTP / HTTPS protocols for data interaction, DPI can detect any attempt to use other protocols (such as FTP or SMTP), and promptly discover potential violations.

[0026] Threat detection and prevention functions of Deep Packet Inspection (DPI): Intrusion detection: DPI can serve as an intrusion detection mechanism in a secure sandbox, monitoring abnormal traffic patterns. For situations such as a large number of connection requests from the same external IP address and the data containing suspicious instruction sequences, it is marked as a potential intrusion attempt. Malware communication blocking: DPI can detect the communication between the sandbox container and known malicious IP addresses or domain names. After detection, the hypervisor can block the link to prevent the spread of malware or the receipt of instructions.

[0027] S412. System call interception: Monitor the system calls of the device in the sandbox and intercept suspicious or illegal operations; In a secure sandbox hypervisor, system call interception can strictly control the access rights of processes in the sandbox container to system resources. For example, an application in a sandbox usually should not have direct access to the root directory of the host file system. By intercepting system calls, when an application attempts a system call such as "opening a sensitive configuration file in the root directory", the hypervisor can immediately block this operation, thus preventing the application from accessing sensitive resources with excessive privileges.

[0028] System call interception can help establish a baseline for the normal behavior of applications within the sandbox container. By long-term monitoring of the system call patterns of applications in the normal running state, including the function names called, parameter ranges, call frequencies, etc. For example, a text editing application may normally mainly involve system calls related to file reading and writing, and the file paths of these calls are usually within the user-specified document directory. Once abnormal system calls occur, such as frequent calls to encryption-related functions or access to other non-document-related directories, they can be regarded as deviating from normal behavior. During operation, system call interception continuously monitors the system call behavior within the sandbox container and compares it with the pre-established normal behavior baseline. If the system calls of a certain process significantly deviate from the baseline, such as calling a high-risk system function that has never appeared before (such as a function that directly operates on kernel memory) or the frequency of system calls suddenly increases significantly, the secure sandbox hypervisor can immediately take measures, such as pausing the process and conducting in-depth inspections.

[0029] S413. Process running logic analysis: Analyze the process creation, execution, and termination behaviors of the device in the sandbox to identify abnormal behavior patterns.

[0030] Process creation monitoring: The security sandbox management program can ensure that every process started in the sandbox container is legal by monitoring the process creation behavior. For example, in a sandbox dedicated to web browsing, only browser-related processes (such as the browser main process, plugin processes, etc.) are allowed to be created. If it is detected that a process related to verification software attempts to be created, this is obviously an abnormal behavior. The management program can determine the legality of process creation based on a predefined list of allowed processes (white list) or a list of prohibited processes (black list).

[0031] Process execution monitoring: During the process execution, analyze the instruction sequence it executes. Normal application programs usually have relatively fixed instruction execution patterns. For example, when a text editing software opens a file, it will execute a series of instructions related to file reading, memory allocation, and interface display. If in the sandbox container, a process executes a large number of instructions related to encryption and network transmission, and these instructions do not match the original function of the process (such as a simple calculator application), this may be an abnormal behavior, and it may be that malware is stealing user data and sending it out.

[0032] It also includes monitoring the resource usage during the process execution. Different processes have a certain range of resource usage for CPU, memory, disk I / O, and network bandwidth, etc. during normal execution. For example, an image viewer process will have relatively stable memory occupancy and CPU usage rate when normally loading and displaying pictures. If in the sandbox, this process suddenly starts to consume a large amount of CPU resources and frequently performs disk write operations, this may be an abnormal behavior, and it may be that the process has been maliciously tampered with.

[0033] Process termination monitoring: Pay attention to the abnormal termination of processes. Normally, a process will terminate normally after completing tasks according to the predefined logic, or exit in a specific way and return an error code when encountering an error. If in the sandbox container, a process suddenly terminates abnormally, for example, the process directly disappears without any error prompt, or repeatedly starts and terminates abnormally, this may be the result of an external attack or an internal error. The management program can record the information of these abnormally terminated processes, including the process ID, termination time, etc. When a process terminates abnormally, and analyze the behaviors of other processes related to it.

[0034] S420. Process trust assessment: Extract network communication, system call, and process running logic features and input them into a machine learning model to evaluate the device trust score, and then dynamically adjust the device trust level and access control policy; evaluate the security and credibility of the device; The specific implementation steps include: S421. Collect network communication, system call, and process running logic data; Network communication data collection: The security sandbox management program collects the network communication data of the sandbox container through deep packet inspection (DPI). The information includes source IP address, destination IP address, port number, protocol type, packet size, and frequency, etc.

[0035] System call data collection: Use the system call interception mechanism to record the system calls made by processes within the sandbox container. The information includes the function name, parameters, return value, etc. For example, when a process frequently calls system calls that modify critical system files, this may be a sign of malicious behavior. The management program will use this system call data as an important basis for evaluating the security of the device.

[0036] Process running logic data collection: Use process running logic analysis to monitor the creation, execution, and termination behavior of processes within the sandbox container. Record information such as the process name, start time, execution path, and resource consumption. For example, if a new process starts at an unexpected time and consumes a large amount of CPU resources, this may indicate a security problem. The management program will integrate this process running logic data into the evaluation dataset.

[0037] S422. Extract network communication, system call, and process running logic features; Network communication feature extraction: Extract features from the collected network communication data. For example, extract the periodicity feature of communication. If a device always communicates with a specific IP address at fixed time intervals, this may be a normal update operation; while irregular and frequent communication may be abnormal. It is also possible to extract features of the communication data volume, such as the average packet size and data transmission rate. For suspicious communication patterns, such as high-frequency large packet transmissions to external unknown addresses, these features can help identify potential security threats.

[0038] System call feature extraction: Extract features from the system call data. It is possible to extract the frequency feature of system calls. For example, the number of occurrences of a high-risk system call (such as a call to directly access kernel memory) within a unit of time. It is also possible to extract the combined feature of system calls. For example, a specific sequence of system calls may represent a certain attack behavior of malware (such as first obtaining system privileges and then modifying critical files). These features can reflect the security status of the device at the system level.

[0039] Process operation logic feature extraction: Extract features from process operation logic data. For example, extract process life cycle features, including process survival time, startup frequency, etc. A process that is frequently started and closed may be suspicious. You can also extract process resource usage features, such as the peak and average CPU usage, changes in memory usage, etc. These features help evaluate whether the process has abnormal behavior and thus determine the security of the device.

[0040] S423. Input the extracted network communication, system call and process operation logic features into the machine learning model to obtain the trust score of the virtual device; According to the characteristics of the collected and extracted data, the appropriate machine learning model is selected. Behavior Baseline Analysis is used here: using machine learning algorithms to model the normal behavior of the device, and identifying abnormal behavior patterns through real-time monitoring and comparative analysis.

[0041] Risk Assessment Model: Uses fuzzy logic, decision trees, neural networks and other algorithms to quantitatively assess the trustworthiness of a device to determine its access rights.

[0042] For example, if the data is highly logical and interpretable, a decision tree model may be a good choice. It can clearly show which features are used to judge the security of the device. If the data is more complex and requires higher accuracy, random forest or neural network models may be more appropriate. These models can handle a large number of feature combinations and mine the underlying patterns in the data. The extracted feature data is input into the selected machine learning model to obtain the trust score of the device. For example, in a 0-100 scoring system, 0 means completely untrustworthy and 100 means completely trustworthy. If a device's network communications have a large number of suspicious external connections, system calls contain high-risk operations, and process behavior is abnormal, it may get a lower trust score.

[0043] S424. Dynamically adjust the trust level of the device based on the trust score result, and decide whether to allow the device to access the network, and dynamically adjust the access control policy.

[0044] Based on the trust score results, multiple trust levels are set and dynamically adjusted according to the device's trust level and the current security status of the network. Here, the Dynamic Access Control Policy is utilized: according to the real-time network security situation and the device risk assessment results, the access control policy is automatically adjusted to achieve flexible and efficient access management. For example, if the trust score of a device is lower than a certain threshold (such as 30), its trust level can be adjusted from "normal" to "suspicious". If the behavior of the device improves during subsequent monitoring and the trust score increases, the trust level can also be correspondingly elevated. Whether to allow the device to access the network is determined based on its trust level. For devices with a lower trust level, their network access permissions can be restricted. For example, only access to internal security resources is allowed, or their network access is completely prohibited until their security is verified. This can effectively prevent potential security threats from spreading from the sandbox container to other network environments. Implement the automated deployment and update of the access control policy to quickly respond to new security threats and business requirements.

[0045] In a virtualized environment, processes within the sandbox may interact with the outside world through the virtual device interfaces of the virtualization layer. These virtual devices include virtual network interface cards, virtual disks, virtual memory, etc. The security sandbox manager will track and record in real time the operations of processes on these virtual devices. For example, whether a process attempts to access unauthorized virtual disk areas, whether it makes abnormal network connection attempts through the virtual network interface, etc. Through this monitoring, potential security threats can be detected in a timely manner to prevent processes from using virtual devices for illegal data theft, malware propagation, or other malicious behaviors.

[0046] S500. Construct a process execution behavior profile based on the extracted features and known security rules.

[0047] During the continuous monitoring of processes within the sandbox, the security sandbox manager will collect a large amount of data on process execution behaviors, including system call sequences, resource usage patterns, file and device access patterns, etc. Based on this rich data, the security sandbox manager will construct an execution behavior profile of the sandbox processes. This profile is like a "behavioral feature fingerprint" of a process, which can accurately describe the behavior patterns and characteristics of the process in its normal running state. For example, for a normal Web server process, its behavior profile may include features such as frequently listening on ports 80 or 443 within a specific time period, regularly reading and updating configuration files in a specific directory, and running with a relatively stable CPU and memory usage rate. By establishing such a behavior profile, it will be easier to identify abnormal changes in process behaviors in the future, thereby quickly discovering potential security issues.

[0048] The S600 security sandbox management program compares the real-time execution behavior of a process with a pre-constructed process execution behavior profile. When an abnormal behavior of a certain process is detected, it blocks the abnormal behavior of the process and pushes an alarm to the authentication management platform.

[0049] Specifically, the management program will block the abnormal behavior of the process according to the preset security rules to prevent it from further damaging the system. For example, if a process suddenly starts to heavily occupy CPU resources and attempts to connect to a suspicious external IP address, the security sandbox management program will immediately terminate the process's network connection to the outside and limit its CPU resource usage, putting it into a restricted running state. At the same time, the management program will also push an alarm to the authentication management platform with detailed information about the abnormal behavior, such as the process ID, description of the abnormal behavior, occurrence time, etc. After receiving the alarm, the authentication management platform can further analyze and process the security event. For example, it can notify the security administrator for in-depth investigation or initiate higher-level security defense measures to ensure the security and stability of the entire system.

[0050] A device access control system based on a security sandbox includes an authentication request module for initiating an identity authentication request to an authentication server by the security sandbox management program to verify the legitimacy of a user or service, ensuring that only authorized entities can access system resources; A policy distribution receiving module for receiving and parsing the security policies issued from the authentication server and passing them to the local policy deployment module; A policy deployment module for applying the received security policies to the sandbox to ensure the correct execution and update of the policies; A process behavior monitoring module for performing network communication data analysis, system call interception, and process running logic analysis on the processes within the sandbox; A process trust evaluation module for extracting network communication, system call, and process running logic features and inputting them into a machine learning model to evaluate the device trust score, and then dynamically adjusting the device trust level and access control policy; A process execution behavior profile construction module for constructing a process execution behavior profile according to the extracted features and known security rules; An abnormal behavior blocking and alarm module for immediately taking measures to block the behavior and sending an alarm notification when an abnormal behavior is detected.

[0051] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A device access control method based on a security sandbox, characterized in that: At least: S100. The security sandbox management program initiates an identity authentication request to the authentication server; S200. After successful authentication, the authentication server issues an initial access control policy to the security sandbox management program; S300. The security sandbox management program deploys an initial access control policy to the corresponding sandbox container; S400. The security sandbox management program monitors the access behavior of the processes in the sandbox to the virtual devices, specifically including: S410. Process behavior monitoring: network communication data analysis, system call interception and process operation logic analysis of the processes in the sandbox; S420. Process trust evaluation: extract network communication, system call and process operation logic features and input them into the machine learning model to evaluate the device trust score, and then dynamically adjust the device trust level and access control strategy; S500. Build a process execution behavior profile based on the extracted features and known security rules; S600. The security sandbox management program compares the real-time execution behavior of the process with the pre-built process execution behavior portrait. When abnormal behavior is detected in a process, the abnormal behavior of the process is blocked and an alarm is pushed to the authentication management platform.

2. The device access control method based on security sandbox according to claim 1, characterized in that: The process behavior monitoring of S410 includes at least: S411. Network communication data analysis: involving deep packet inspection technology, analyzing the data packets sent and received by the sandbox container, and identifying the content, protocol and potential threats of the data packets; S412. System call interception: monitor system calls in the sandbox and intercept suspicious or illegal operations; S413. Process operation logic analysis: Analyze the process creation, execution and termination behaviors in the sandbox and identify abnormal behavior patterns.

3. The device access control method based on security sandbox according to claim 1 is characterized in that: The process trust assessment in S420 at least includes: S421. collecting network communication, system call and process operation logic data; S422. Extracting network communication, system call and process operation logic features; S423. Input the extracted network communication, system call and process operation logic features into the machine learning model to obtain the trust score of the virtual device; S424. Dynamically adjust the trust level of the device based on the trust score result, and decide whether to allow the device to access the network, and dynamically adjust the access control policy.

4. The device access control method based on security sandbox according to claim 1 is characterized in that: The machine learning model can be a decision tree model, a random forest model or a neural network model.

5. The device access control system based on security sandbox according to claim 1, characterized in that: It includes an authentication request module, which is used for the security sandbox management program to initiate an identity authentication request to the authentication server; The policy delivery receiving module is used to receive and parse the security policy delivered by the authentication server and pass it to the local policy deployment module; A policy deployment module, used to apply the received security policy to the sandbox; Process behavior monitoring module, used to analyze network communication data, system call interception and process operation logic of processes in the sandbox; The process trust evaluation module is used to extract network communication, system call and process operation logic features and input them into the machine learning model to evaluate the device trust score, thereby dynamically adjusting the device trust level and access control policy; The process execution behavior profile building module is used to build a process execution behavior profile based on the extracted features and known security rules; The abnormal behavior blocking and alarm module is used to take immediate measures to block the behavior and issue an alarm notification when abnormal behavior is detected.

Citation Information

Patent Citations

  • Method and system for access safety detection and isolation of virtualized user

    CN102902920A

  • Cloud storage security access method based on sandbox technology

    CN108133153A

  • Lightweight network sandbox setting method based on container technology

    CN110311901A

  • Sandbox implementation method and device, equipment and storage medium

    CN113297566A

  • Sandbox-based malicious program behavior analysis processing method and system

    CN114491509A

Cited By

  • Network security protection method for power monitoring system

    CN120639350A

  • Data security dynamic evaluation system and protection method

    CN120934811A

  • Intelligent agent sandbox environment isolation and protection system based on operation base line

    CN122419988A

  • Baseline-based sandbox environment isolation and protection system for agents

    CN122419988B

  • Method for solving websocket hijacking problem based on security sandbox

    CN122533862A