Method for process inheriting mandatory access control security level
The intimacy value of the parent-child process is judged through the intimacy algorithm, and the child process inherits the security level of the parent process is realized, which solves the problem that the child process is difficult to inherit the security level of the parent process, and improves the accuracy and flexibility of forced access control.
Patent Information
- Application Number
- CN202510169441.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-30
AI Technical Summary
In a forced access control system, it is difficult for the child process to inherit the security level of the parent process, resulting in the inability to dynamically adjust the security level, affecting the accuracy of the system's access control.
Through the intimacy algorithm, the intimacy value between the parent process and the child process is calculated. If the intimacy value is greater than or equal to the preset value, the child process inherits the forced access permissions of the parent process and synchronizes the forced access permission information of the child process.
It realizes the security inheritance of the child process's security access rights to the parent process, dynamically adjusts the security level, and improves the accuracy and flexibility of forced access control.
Smart Images

Figure CN120068035A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information security, and in particular to a method for a process to inherit a mandatory access control security level. Background Art
[0002] Mandatory access control, abbreviated as mandatory access, is an access control mechanism enforced by the operating system. According to security standards such as GB17859-1999, security systems with security levels of three or above must use mandatory access control.
[0003] The core goal of mandatory access control is to limit the access rights of subjects (such as users, processes, etc.) to objects (such as files, data, etc.). In this model, each subject and object is assigned certain security attributes, usually security levels and categories. For example, a specific process has a specific security level. Under this strategy, the system will decide whether to allow specific access behaviors based on the security attributes of the subject and object. However, in actual use, during the operation of a process or program, a corresponding sub-process will be started to complete some temporary tasks, such as deleting invalid files.
[0004] The started child process may be a system-internal program or a temporary script. These programs are widely started and called by many parent processes. Due to the special working requirements of these programs, these programs cannot have the same security level as the parent process.
[0005] However, usually a child process must not only have the same subject security level as the parent directory, but also the same security level as the parent process to complete the corresponding task. How to determine whether the child process needs to inherit the permissions of the parent process and dynamically adjust the security level is a technical problem that needs to be solved urgently in this field. Summary of the invention
[0006] In order to alleviate or partially alleviate the above technical problems, the solution of the present invention is as follows:
[0007] In a certain embodiment, the present invention relates to a method for inheriting mandatory access rights, which determines whether a child process in a process tree inherits the mandatory access rights of a parent process through an intimacy algorithm; wherein the intimacy calculation formula between the parent process and the child process is:
[0008]
[0009] S represents the intimacy value, M represents the number of intimacy conditions, i represents the sequence number of intimacy conditions, and a i represents the score of the i-th intimacy condition;
[0010] If the intimacy value is greater than or equal to the preset value, the child process inherits the permissions of the parent process, and synchronously updates the mandatory access permission information of the child process.
[0011] Optionally, a process tracking module is used to establish and maintain a process tree in real time.
[0012] Optionally, the process tracking module establishes and maintains a process tree in real time through the following steps:
[0013] Step S001: The process tracking module monitors the startup, execution, and termination of all processes in the system;
[0014] Step S002: The process tracking module forms a process tree through the parent-child relationship to display the relationship between processes.
[0015] Optionally, the mandatory access permissions of the parent process are accessed through the process tree, and the mandatory access permissions of the parent process are adopted.
[0016] Optionally, when the intimacy value is greater than or equal to 6, the mandatory access permission information of the child process is synchronously updated.
[0017] In another type of embodiment, the method for inheriting mandatory access permissions of the present invention includes the following steps:
[0018] Step S102: Determine whether the child process has its own mandatory access permissions. If so, proceed to step S103; if not, jump to step S104;
[0019] Step S103: Determine whether the mandatory access permissions of the child process itself can access the expected file. If so, directly access the expected file; if not, jump to step S104.
[0020] Step S104: Use the mandatory access permission module to access the expected file;
[0021] Among them, the mandatory access permission module determines whether the child process can inherit the mandatory access permissions of the parent process to access the expected file through an intimacy algorithm.
[0022] Optionally, the accessing of the expected file using the mandatory access permission module includes the following steps:
[0023] Step S201: Collect child process information and calculate the intimacy between the child process and the parent process;
[0024] Step S202: Determine whether the intimacy value between the parent process and the child process is greater than or equal to the preset value. If so, inherit the mandatory access permissions of the parent process.
[0025] Optionally, step S202 further includes:
[0026] If the intimacy value between the parent process and the child process is greater than or equal to a preset value, the strong access permission module accesses the strong access permission of the parent process by means of the process tree;
[0027] Adopt the mandatory access permission of the parent process to inherit the security level of the parent process.
[0028] Optionally, calculate the intimacy between the parent process and the child process through the following formula:
[0029]
[0030] S represents the intimacy value, M represents the number of items of intimacy conditions, i represents the serial number of intimacy conditions, and a i represents the score of the i-th item of intimacy conditions.
[0031] The present invention also relates to a method for providing a temporary security level, including the following steps:
[0032] Parent processes with different security levels call the same program, and the child processes created by the same program respectively inherit the security levels of their respective parent processes through the method of inheriting mandatory access permissions as described in any one of claims 1 to 9.
[0033] The technical solution of the present invention has one or more of the following beneficial technical effects:
[0034] (1) Through the intimacy algorithm, the present invention determines whether the child process inherits the parent process permission, and realizes the dynamic adjustment of the security level by providing a temporary security level for the process tree. The intimacy algorithm of the present invention is simple and easy to implement in engineering.
[0035] (2) The present invention realizes the dynamic adjustment of the security level by providing a temporary security level for the process tree.
[0036] (3) When the child process inherits the parent process permission in the present invention, the original permission is not lost. At the same time, the mandatory access permissions of each child process are updated synchronously in a timely manner to ensure that the actual running behavior of the program is consistent with the mandatory access configuration permission expected by the user, increasing the accuracy of mandatory access.
[0037] In addition, other beneficial effects of the present invention will be mentioned in specific embodiments. Description of the Drawings
[0038] Figure 1 It is an example diagram of intimacy conditions of a preferred embodiment of the present invention;
[0039] Figure 2 It is a flowchart of the method for inheriting mandatory access permissions of a preferred embodiment of the present invention;
[0040] Figure 3Schematic diagram of providing a dynamic security level through a process tree according to a preferred embodiment of the present invention. Detailed implementation manners
[0041] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts shall fall within the protection scope of the present invention.
[0042] The present invention provides a method for providing a dynamic security level for a process tree. In an existing mandatory access control module, a process tracking module is added. The process tracking module is used to establish and maintain a process tree in real time, and specifically includes the following steps:
[0043] Step S001: The process tracking module monitors the start, execution and termination of all processes in the system, and records the relevant information of each process, such as process ID, corresponding parent process ID, start time, termination time, etc.;
[0044] Step S002: The process tracking module organizes the process information into a process tree through the parent-child relationship to display the relationship between processes.
[0045] Step S003: Through an affinity algorithm, it is judged whether the child process inherits the mandatory access permission of the parent process.
[0046] The present invention designs an interface in the process tracking module for passing permission information to a newly created process, which can also be called a child process. To complete the corresponding work, if the child process does not have its own mandatory access permission while the parent process has the corresponding mandatory access permission, the child process needs to adopt the permission of the parent process, or if the child process has its own mandatory access permission but this permission does not support accessing a specific file, the child process needs to adopt the permission of the parent process. Specifically, the present invention judges whether the child process inherits the mandatory access permission of the parent process through an affinity algorithm.
[0047] The affinity calculation formula between the parent process and the child process is:
[0048]
[0049] where S represents the affinity value, M represents the number of items of affinity conditions, i represents the serial number of the affinity condition, and a i represents the score of the i-th item of affinity condition.
[0050] If the affinity value is greater than or equal to a preset value, the child process inherits the permission of the parent process and synchronously updates the mandatory access permission information of the child process.
[0051] Figure 1 This is an example diagram of the intimacy condition for a preferred embodiment of the present invention, which shows multiple dimensions of the relationship between the parent process and the child process, and configures corresponding weight scores according to importance. For example, if the digital signature manufacturers of the two program files of the parent and child processes are the same, the weight score is the largest; if the publishers of the two program files of the parent and child processes are the same, the corresponding weight score is the second.
[0052] Optionally, when the intimacy value is greater than or equal to 6, the mandatory access permission information of the child process is synchronously updated.
[0053] Figure 2 This is a flowchart of the method for inheriting the mandatory access permission for a preferred embodiment of the present invention, including the following steps:
[0054] Step S101: The parent process calls the child process;
[0055] Step S102: Determine whether the child process has its own mandatory access permission. If so, proceed to step S103; otherwise, use the mandatory access permission module to access the expected file.
[0056] Step S103: Determine whether the mandatory access permission of the child process itself can access the expected file. If so, directly access the expected file; otherwise, use the mandatory access permission module to access the expected file.
[0057] Among them, using the mandatory access permission module to access the expected file includes the following steps:
[0058] Step S201: Collect child process information and calculate the intimacy between the child process and the parent process. Specifically, calculate the intimacy value between the parent process and the child process through weighted calculation of intimacy in multiple dimensions.
[0059] Step S202: Determine whether the intimacy value between the parent process and the child process is greater than or equal to the preset value. If so, proceed to step S203; otherwise, terminate.
[0060] Step S203: The mandatory access permission module accesses the mandatory access permission of the parent process through the process tree.
[0061] Step S204: Adopt the mandatory access permission of the parent process to synchronously update the mandatory access permission of the child process.
[0062] In an embodiment, the D:\demon directory is configured as a subject and an object in the subject security level A of mandatory access control. The C:\user\administrator\temp directory is configured as a subject and an object in the security level B. Among them, the subject with security level A can read and write the object in security level B, and the subject in security level B can only read the object in security level A only. The program D:\demon\demon.exe regularly writes a clearCache_xxxx.ps1 script to the file C:\user\administrator\temp to clean the content in the D:\demon\cache\ directory. If C:\user\administrator\temp\clearCache_xxxx.ps1 is used as a subject, it will have the security level of security level B. According to the existing security level rules, there is no way to clean the content in the D:\demon\cache\ directory.
[0063] According to the method of the present invention, after the clearCache_xxxx.ps1 script fails to use its own mandatory access permission, it obtains the security level A of the parent process through the intimacy algorithm, so as to have the permission to clean the content in the D:\demon\cache\ directory.
[0064] Figure 3 It is a schematic diagram of providing a dynamic security level through a process tree in a preferred embodiment of the present invention. The mandatory access control security level of the parent process 1 is configured as security level 1, and the mandatory access control security level of the parent process 2 is configured as security level 2. The two will call or start the same program during the running process. In order to ensure the smooth completion of the task, the two child processes of the called or started program must not only have the same security level of the subject as their respective parent directories, but also have the same security level as their respective parent processes. The present invention enables the child process to inherit the security level of the corresponding parent process by providing a temporary security level.
[0065] The present invention tracks and records the child processes started by the parent process and the security levels of mandatory access control to which each process belongs through a process tracking module, and judges the intimacy value between the parent process and the child process through the intimacy algorithm, so as to realize the secure inheritance of the secure access permission of the child process to the parent process.
[0066] To better illustrate the present invention, numerous specific details are given in the above specific implementation manners. Those skilled in the art should understand that the present invention can also be implemented without some specific details. In some instances, methods, means, elements, and circuits well known to those skilled in the art are not described in detail to highlight the gist of the present invention.
[0067] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claimed rights.
Claims
1. A method for inheriting mandatory access rights, characterized in that: Through the affinity algorithm, it is determined whether the child process in the process tree inherits the mandatory access rights of the parent process. The affinity calculation formula between the parent process and the child process is: S represents the intimacy value, M represents the number of intimacy conditions, i represents the sequence number of intimacy conditions, and a i represents the score of the i-th intimacy condition; If the intimacy value is greater than or equal to the preset value, the child process inherits the permissions of the parent process and synchronously updates the mandatory access permission information of the child process.
2. The method for inheriting mandatory access rights according to claim 1, characterized in that: Use the process tracking module to establish and maintain the process tree in real time.
3. The method for inheriting mandatory access rights according to claim 2, characterized in that: The process tracking module establishes and maintains the process tree in real time through the following steps: Step S001, the process tracking module monitors the startup, execution and termination of all processes in the system; Step S002: The process tracking module constructs a process tree through the parent-child relationship to display the relationship between processes.
4. The method for inheriting mandatory access rights according to any one of claims 1 to 3, characterized in that: Use the process tree to access the parent process's strong access permissions and adopt the parent process's mandatory access permissions.
5. The method for inheriting mandatory access rights according to any one of claims 1 to 3, characterized in that: When the intimacy value is greater than or equal to 6, the mandatory access permission information of the child process is updated synchronously.
6. A method for inheriting mandatory access rights, characterized in that: The steps include: Step S102, determine whether the child process has its own mandatory access rights, if yes, proceed to step S103, if no, jump to step S104; Step S103, determine whether the subprocess's own mandatory access rights can access the expected file, if so, directly access the expected file, if not, jump to step S104. Step S104, using the strong access permission module to access the expected file; The mandatory access permission module determines whether the child process can inherit the mandatory access permission of the parent process to access the expected file through an intimacy algorithm.
7. The method for inheriting mandatory access rights according to claim 6, characterized in that: The method of using the strong access permission module to access the expected file includes the following steps: Step S201, collect child process information, and calculate the intimacy between the child process and the parent process; Step S202: Determine whether the intimacy value between the parent process and the child process is greater than or equal to a preset value. If so, the child process inherits the mandatory access rights of the parent process.
8. The method for inheriting mandatory access rights according to claim 6, characterized in that: The step S202 further includes: If the intimacy value between the parent process and the child process is greater than or equal to the preset value, the strong access permission module uses the process tree to access the strong access permission of the parent process; Adopts the mandatory access permissions of the parent process to inherit the security level of the parent process.
9. The method for inheriting mandatory access rights according to any one of claims 6 to 8, characterized in that: The intimacy between the parent process and the child process is calculated by the following formula: S represents the intimacy value, M represents the number of intimacy conditions, i represents the sequence number of intimacy conditions, and a i Represents the score of the i-th intimacy condition.
10. A method for providing a temporary security level, characterized in that The steps include: Parent processes with different security levels call the same program, and child processes created by the same program inherit the security levels of their respective parent processes through the method for inheriting mandatory access rights as described in any one of claims 1 to 9.