Data integrity protection method and device, electronic equipment and storage medium
By obtaining the address and content of the specified data structure of the operating system kernel, hashing operations and storing it in a storage area that does not support modification, the problem of insufficient integrity protection methods for the existing Linux system kernel is solved, and effective protection of the kernel data structure is achieved.
Patent Information
- Application Number
- CN202311615105.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-28
- Publication Date
- 2025-05-30
AI Technical Summary
The kernel integrity protection method of existing Linux systems is flawed, especially on Android smart devices after the implementation of GKI. OEM manufacturers can no longer change the kernel code, resulting in incomplete protection methods.
By obtaining the target pointer function, obtaining the address of the specified data structure of the operating system kernel, obtaining its contents and hashing, obtaining the hash value, and storing it in a specified storage area that does not support modification, to protect the integrity of the data structure.
It realizes the integrity protection of the specified data structures in the operating system kernel, prevents malicious processes from raising power by modifying sensitive data, and enhances the security and stability of the system.
Smart Images

Figure CN120068160A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and more specifically, to a data integrity protection method, apparatus, electronic device, and storage medium. Background Art
[0002] As an open-source operating system, Linux is widely loved and trusted by users. As the most popular operating system for servers, Linux has extremely high requirements for data security. The kernel integrity protection mechanism of Linux aims to protect important data structures in the kernel from being maliciously tampered with, thereby ensuring kernel security and preventing malicious vulnerability exploitation and privilege escalation behaviors. However, the current kernel integrity protection methods still need to be improved. Summary of the Invention
[0003] This application proposes a data integrity protection method, apparatus, electronic device, and storage medium to improve the above problems.
[0004] In a first aspect, an embodiment of this application provides a data integrity protection method, the method includes: obtaining a target pointer function; obtaining the address of a specified data structure of the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address; performing a hash operation on the content of the specified data structure to obtain a specified hash value; storing the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area is not supported to be modified.
[0005] In a second aspect, an embodiment of this application provides a data integrity protection apparatus, the apparatus includes: a pointer function obtaining module, configured to obtain a target pointer function; a content obtaining module, configured to obtain the address of a specified data structure of the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address; a calculation module, configured to perform a hash operation on the content of the specified data structure to obtain a specified hash value; a data protection module, configured to store the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area is not supported to be modified.
[0006] In a third aspect, this application provides an electronic device, including one or more processors and a memory; one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method in the first aspect above.
[0007] In a fourth aspect, this application provides a computer-readable storage medium, in which program code is stored, and wherein the method in the first aspect above is executed when the program code runs.
[0008] A data integrity protection method, apparatus, electronic device, and storage medium provided by this application obtain a target pointer function; obtain the address of a specified data structure in the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address; perform a hash operation on the content of the specified data structure to obtain a specified hash value; store the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area does not support modification. Thus, through the above method, the specified data structure in the operating system kernel is obtained through the target pointer function, and the hash value obtained by performing a hash operation on the content of the specified data structure is stored in a specified storage area that does not support data modification, so as to prevent malicious processes from escalating privileges by modifying sensitive data, and the integrity protection of the specified data structure in the operating system kernel is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] In order to more clearly illustrate the technical solutions in the embodiments of this application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of this application. For those skilled in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0010] Figure 1 The flowchart of a data integrity protection method provided by an embodiment of this application is shown.
[0011] Figure 2 The flowchart of a data integrity protection method provided by another embodiment of this application is shown.
[0012] Figure 3 The flowchart of a data integrity protection method provided by still another embodiment of this application is shown.
[0013] Figure 4 The flowchart of a data integrity protection method provided by yet another embodiment of this application is shown.
[0014] Figure 5 The structural block diagram of a data integrity protection apparatus provided by an embodiment of this application is shown.
[0015] Figure 6 The structural block diagram of an electronic device provided by an embodiment of this application is shown.
[0016] Figure 7 The storage unit for storing or carrying the program code for implementing the data integrity protection method according to the embodiments of this application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application.
[0018] Kernel protection refers to implementing a series of technical means in an operating system to protect the security and stability of the operating system kernel. The operating system kernel is the core component of the entire system, responsible for managing hardware resources, processing requests from application programs, providing system services, and other functions. Therefore, the security and stability of the kernel are of crucial significance for the normal operation of the entire system.
[0019] The primary goal of kernel protection is to ensure that the system is not attacked and damaged by malware, so as to safeguard the integrity of sensitive data and security functions in the system. Kernel protection requires access control over various resources in the system to ensure that only authorized processes can access sensitive resources and prevent unauthorized tampering or access. However, the inventors found that the data integrity protection scheme introduced in the current Linux system mainly modifies the kernel code directly. For Android smart devices after the implementation of GKI (Generic Kernel Image), OEM (Original Equipment Manufacturer) manufacturers can no longer modify the kernel code. Therefore, the current kernel integrity protection method still needs to be improved.
[0020] To optimize the above problems, the inventors found through long-term research that it is possible to obtain a target pointer function; obtain the address of a specified data structure of the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address; perform a hash operation on the content of the specified data structure to obtain a specified hash value; store the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area does not support modification. Thus, through the above method, the specified data structure of the operating system kernel is obtained through the target pointer function, and the hash value obtained by performing a hash operation on the content of the specified data structure is stored in a specified storage area that does not support data modification, thereby preventing malicious processes from escalating privileges by modifying sensitive data and achieving integrity protection for the specified data structure of the operating system kernel.
[0021] Therefore, to improve the above problems, the inventors proposed a data integrity protection method, device, electronic device, and computer-readable storage medium provided in this application, which can prevent malicious processes from escalating privileges by modifying sensitive data and achieve integrity protection for the specified data structure of the operating system kernel.
[0022] To facilitate a better understanding of the solution described in the embodiments of the present application, the following briefly explains the terms involved in the description process of the embodiments of the present application:
[0023] PAN (Privileged Access Never): Represents the prohibition of privileged access.
[0024] SMAP (Supervisor Mode Access Prevention): Represents supervisor mode access protection.
[0025] KO (Kernel Object): Represents a kernel module.
[0026] In the embodiments of the present application, the operating system is taken as the linux system as an example for illustration. In actual implementation, the operating system can also be other systems. If the operating system is other systems, a similar method can also be used to implement data integrity protection for sensitive data in the operating system kernel.
[0027] The following will specifically describe the embodiments of the present application with reference to the accompanying drawings.
[0028] Please refer to Figure 1 , which shows a flowchart of a data integrity protection method provided by an embodiment of the present application. This embodiment provides a data integrity protection method, which can be applied to a server or a terminal device. Specifically, it can be not limited, and the specific type of the server or the terminal device can be not limited. The method includes:
[0029] Step S110: Obtain a target pointer function.
[0030] In this embodiment, the target pointer function represents a pointer function that can obtain the pointer of the core data structure or sensitive data structure of the operating system kernel. The specific type of the target pointer function can be not limited. For example, the target pointer function can be the kallsyms_lookup_name function (kernel symbol lookup pointer function).
[0031] As an implementation method, the address of the target pointer function can be obtained by calling the kernel tracing framework, and then the address of the target pointer function can be converted into a function pointer for use. Among them, the kernel tracing framework can be the kprobe function. Specifically, the address of the target pointer function can be obtained by calling the kernel tracing framework in the initialization function of the kernel module, and then the address of the target pointer function can be converted into a function pointer for use. The initialization function of the kernel module can be the __init function.
[0032] As a specific implementation, for the Linux system, in the __init function of the Linux kernel module (KO), the kprobe can be used to hook the function named "kallsyms_lookup_name (kernel symbol lookup pointer function)". The kallsyms_lookup_name function is not exported in the Linux system (it is a Bash command used to set or display environment variables. When used without any arguments, the export command will display a list of all exported variables in the environment), so it cannot be directly used in the kernel module. However, through the kprobe mechanism, the address of the kallsyms_lookup_name function can be obtained and explicitly converted into a function pointer for use. The code implementation for obtaining the kallsyms_lookup_name function is as follows:
[0033]
[0034] Step S120: Obtain the address of a specified data structure in the operating system kernel through the target pointer function, and obtain the content of the specified data structure through the address.
[0035] In this embodiment, the specified data structure represents a sensitive data structure or a vulnerable data structure. The specific type of the specified data structure may not be limited, and the number of specified data structures is at least one.
[0036] Exemplarily, the specified data structure may include at least one of a system call table, a code segment in.txt format, and a read-only data segment in.rodata format.
[0037] As an implementation, the address of a specified data structure in the operating system kernel can be obtained through the target pointer function, and the content of the specified data structure can be obtained through the address. For example, if the specified data structure is a system call table, the kallsyms_lookup_name function can be used to obtain the address of the system call table to obtain the specific content of the system call table through the address; if the specified data structure is a code segment in.txt format, the kallsyms_lookup_name function can be used to obtain the start address and end address of the.txt code segment to obtain the specific content of the.txt code segment through the address; if the specified data structure is a read-only data segment in.rodata format, the kallsyms_lookup_name function can be used to obtain the address of the read-only data segment.rodata to obtain the specific content of the read-only data segment.rodata through the address.
[0038] Optionally, if the specified data structure includes a system call table and a code segment in.txt format, the kallsyms_lookup_name function can be used to obtain the address of the system call table to retrieve the specific content of the system call table through this address, and the kallsyms_lookup_name function can also be used to obtain the start address and end address of the.txt code segment to retrieve the specific content of the.txt code segment through this address.
[0039] Step S130: Perform a hash operation on the content of the specified data structure to obtain a specified hash value.
[0040] After obtaining the address of the specified data structure of the operating system kernel through the target pointer function, the address can be accessed to obtain the content of the specified data structure. As a way, for subsequent data integrity verification, a hash operation can be performed on the content of the specified data structure to obtain a specified hash value. Optionally, if the content of the specified data structure is different, the way of performing the hash operation can also be different.
[0041] Among them, if the specified data structure is a system call table, then a hash operation can be performed on the content of the system call table to obtain a specified hash value corresponding to the system call table. The code implementation for obtaining the system call table through the target pointer function and performing a hash operation on the system call table is as follows:
[0042] / *find syscall_table and do hash* /
[0043] sys_call_table = (syscall_fn_t *)kallsyms_lookup_name(SYSCALL_TBL);
[0044] printk(TAG "find syscall_table, first func and 225func: %lx, %lx", sys_call_table[0], sys_call_table
[225] );
[0045] memcpy(syscall_func_addr, sys_call_table, sizeof(syscall_func_addr));
[0046] printk(TAG "memcpy Succees: first func and 225func: %lx, %lx", syscall_func_addr[0], syscall_func_addr
[225] );
[0047] ret = do_hash(syscall_func_addr, sizeof(syscall_func_addr), hash_syscall_table);
[0048] If the specified data structure is a code segment in.txt format, then the content of the code segment in.txt format can be hashed to obtain a specified hash value corresponding to the code segment in.txt format. The code for obtaining the code segment in.txt format through the target pointer function and hashing the content of the code segment in.txt format is as follows:
[0049]
[0050] If the specified data structure is a read-only data segment in.rodata format, then the content of the read-only data segment in.rodata format can be hashed to obtain a specified hash value corresponding to the read-only data segment in.rodata format. The code for obtaining the read-only data segment in.rodata format through the target pointer function and hashing the content of the read-only data segment in.rodata format is as follows:
[0051]
[0052] Optionally, if the content of the specified data structure is different, the corresponding specified hash value can be different. If the number of specified data structures is one, then one specified hash value can be obtained; if the number of specified data structures is multiple, then multiple corresponding specified hash values can be obtained. For example, if the specified data structure includes a system call table, then a specified hash value corresponding to the system call table can be obtained. If the specified data structure includes a system call table, a code segment in.txt format, and a read-only data segment in.rodata format, then a specified hash value corresponding to the system call table, a specified hash value corresponding to the code segment in.txt format, and a specified hash value corresponding to the read-only data segment in.rodata format can be obtained respectively.
[0053] Step S140: Store the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area does not support modification.
[0054] In this embodiment, the data in the specified storage area does not support modification (i.e., modification is prohibited). Exemplarily, the specified storage area can be read-only memory, or other storage areas that do not support modification, or a storage area encrypted by a specific encryption algorithm.
[0055] As an implementation manner, a specified hash value obtained by performing a hash operation on a specified data structure may be stored in a specified storage area to strengthen kernel security, prevent malicious processes from elevating privileges by modifying sensitive data, and further implement integrity protection for sensitive data in the operating system kernel.
[0056] The data integrity protection method provided in this embodiment includes obtaining a target pointer function; obtaining the address of a specified data structure in the operating system kernel through the target pointer function to obtain the content of the specified data structure through the address; performing a hash operation on the content of the specified data structure to obtain a specified hash value; and storing the specified hash value in a specified storage area to protect the integrity of the specified data structure, where the data in the specified storage area does not support modification. Thus, through the above method, the specified data structure in the operating system kernel is obtained through the target pointer function, and the hash value obtained by performing a hash operation on the content of the specified data structure is stored in the specified storage area that does not support data modification, thereby preventing malicious processes from elevating privileges by modifying sensitive data and implementing integrity protection for the specified data structure in the operating system kernel.
[0057] Please refer to Figure 2 , which shows a flowchart of a data integrity protection method provided in another embodiment of the present application. This embodiment provides a data integrity protection method that can be applied to a server or a terminal device, and specific applications are not limited, nor are the types of the server or the terminal device. Based on the content described in the foregoing embodiment, this implementation manner mainly describes the implementation process of performing a hash operation on the content of a specified data structure. The method includes:
[0058] Step S210: Obtain a target pointer function.
[0059] Specifically, the implementation of step S210 may refer to the relevant description of step S110 in the foregoing embodiment and will not be elaborated here.
[0060] Step S220: Obtain the address of a specified data structure in the operating system kernel through the target pointer function to obtain the content of the specified data structure through the address.
[0061] Specifically, the implementation of step S220 may refer to the relevant description of step S120 in the foregoing embodiment and will not be elaborated here.
[0062] Step S230: Copy the content of the specified data structure to temporary memory.
[0063] In this embodiment, in order to reduce the occupation of system memory, the content of the specified data structure obtained can be copied to the temporary memory, which can be understood as a temporary storage area. The specific type of the temporary memory may not be limited. For example, the temporary memory can be a local array.
[0064] Step S240: Perform a hash operation on the content of the specified data structure in the temporary memory to obtain a specified hash value.
[0065] As an implementation, a hash operation can be performed on the content of the specified data structure in the temporary memory to obtain a specified hash value. The specified hash value can be temporarily stored in the temporary memory, and the temporary memory can be automatically released after the hash operation is completed.
[0066] Step S250: Store the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area does not support modification.
[0067] As an implementation, after storing the specified hash value temporarily stored in the temporary memory in the specified storage area, the temporary memory can be automatically released.
[0068] Among them, for other specific implementations of step S250, reference can be made to the relevant description of step S140 in the foregoing embodiments, which will not be elaborated here.
[0069] The data integrity protection method provided in this embodiment obtains the target pointer function; obtains the address of the specified data structure of the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address; copies the content of the specified data structure to the temporary memory; performs a hash operation on the content of the specified data structure in the temporary memory to obtain a specified hash value; stores the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area does not support modification. Thus, through the above method, the specified data structure of the operating system kernel is obtained through the target pointer function, and the hash value obtained by performing a hash operation on the content of the specified data structure is stored in the specified storage area that does not support data modification, so as to prevent malicious processes from escalating privileges by modifying sensitive data, and the integrity protection of the specified data structure of the operating system kernel is realized.
[0070] At the same time, by first temporarily storing the content of the specified data structure in the temporary memory and performing a hash operation on the content of the specified data structure in the temporary memory, the occupation of system memory resources can be reduced, and the system operation efficiency can be ensured.
[0071] Please refer to Figure 3, which shows a flowchart of a data integrity protection method provided by another embodiment of the present application. This embodiment provides a data integrity protection method, which can be applied to a server or a terminal device, and specifically can be not limited. Moreover, the type of the server or the terminal device can be not limited. On the basis of the content described in the foregoing embodiment, this embodiment mainly describes other implementation processes of obtaining the content of a specified data structure of the operating system kernel. The method includes:
[0072] Step S310: Obtain the starting address of the exception vector table through a first register.
[0073] In this embodiment, the specified data structure may further include an exception vector table. The length of the exception vector table is fixed.
[0074] As an implementation manner, the starting address of the exception vector table can be obtained by reading the first register to determine the starting address for starting to fetch the exception vector table. The first register is the register of the exception vector table, and the first register can be a hardware register. Optionally, the first register can be VBAR_EL1. The code implementation for obtaining the starting address of the exception vector table through the first register is as follows:
[0075]
[0076] Step S320: Obtain the content of the exception vector table based on the starting address.
[0077] In the case where the starting address of the exception vector table is obtained, the length of the exception vector table is known, so the content of the exception vector table can be obtained based on the starting address and the length.
[0078] Step S330: Perform a hash operation on the content of the exception vector table to obtain a specified hash value.
[0079] As an implementation manner, a hash operation can be performed on the content of the exception vector table according to the length of the exception vector table to obtain a specified value. Specifically, the code implementation for performing a hash operation on the content of the exception vector table is as follows:
[0080] evt_addr = get_evt_addr();
[0081] printk(TAG "get_evt_addr succeed: %lx", evt_addr);
[0082] ret = do_hash((uint64_t*)evt_addr, EXCEPTION_TBL_LENGTH, hash_evt_table);
[0083] In this embodiment, the specified data structure may further include a kernel access mechanism (such as the PAN mechanism). In this case, the value of the kernel access mechanism can be obtained through the second register, and then a hash operation is performed on the value of the kernel access mechanism.
[0084] Among them, the value of the kernel access mechanism is used to represent the open / closed state of the kernel access mechanism. The second register and the first register are different registers. Optionally, the second register can be SCTLR_EL1. In this embodiment, the code implementation for obtaining the value of the kernel access mechanism through the second register is as follows:
[0085]
[0086] The code implementation for performing a hash operation on the value of the kernel access mechanism is represented as follows:
[0087]
[0088] Step S340: Store the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area does not support modification.
[0089] Among them, for the specific implementation of step S340, reference can be made to the relevant descriptions of step S140 and step S250 in the foregoing embodiments, which will not be elaborated here.
[0090] The data integrity protection method provided in this embodiment obtains the starting address of the exception vector table through the first register; obtains the content of the exception vector table based on the starting address; performs a hash operation on the content of the exception vector table to obtain a specified hash value; and stores the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area does not support modification. Thus, through the above method, the specified data structure of the operating system kernel is obtained through the register, and the hash value obtained by performing a hash operation on the content of the specified data structure is stored in the specified storage area that does not support data modification, thereby preventing malicious processes from escalating privileges by modifying sensitive data, and realizing the integrity protection of the specified data structure of the operating system kernel.
[0091] Please refer to Figure 4 , which shows a flowchart of a data integrity protection method provided in another embodiment of the present application. This embodiment provides a data integrity protection method that can be applied to a server or a terminal device, and specifically can be not limited, and the type of the server or the terminal device can be not limited. On the basis of the content described in the foregoing embodiments, this embodiment mainly describes the implementation process of storing the specified hash value in the specified storage area. The method includes:
[0092] Step S410: Obtain the target pointer function.
[0093] Among them, for the specific implementation of step S410, reference can be made to the relevant description of step S110 in the foregoing embodiments, which will not be elaborated herein.
[0094] Step S420: Obtain the address of the specified data structure of the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address.
[0095] Among them, for the specific implementation of step S420, reference can be made to the relevant description of step S120 in the foregoing embodiments, which will not be elaborated herein.
[0096] Step S430: Perform a hash operation on the content of the specified data structure to obtain a specified hash value.
[0097] Among them, for the specific implementation of step S430, reference can be made to the relevant descriptions of step S130, step S230, step S240, and step S330 in the foregoing embodiments, which will not be elaborated herein.
[0098] Step S440: Obtain the type of the specified data structure.
[0099] In this embodiment, the specified data structure may include multiple types. As an implementation manner, the type to which it belongs can be determined according to the sensitivity of the specified data structure. For example, for the system call table, code segment in.txt format, read-only data segment in.rodata format, exception vector table, and kernel access mechanism described in the foregoing embodiments, they can be used as the specified data structures of the first type, while the key global data structures and sensitive pointers of the operating system can be used as the specified data structures of the second type. The sensitivity of the specified data structures of the second type is greater than that of the specified data structures of the first type, and the greater the sensitivity, the greater the importance to the operating system.
[0100] Or other classification methods can also be used to classify the types of the specified data structures. For example, classification can be performed according to the functions of the specified data structures, etc.
[0101] Step S451: If the type of the specified data structure is the first type, store the specified hash value in the first storage area to protect the integrity of the specified data structure.
[0102] In this embodiment, the hash values of different types of specified data structures can be stored in storage areas with different security levels. Among them, the higher the sensitivity of the specified data structure, the higher the security level of the corresponding storage area.
[0103] As an implementation, if the type of the specified data structure is the first type, the specified hash value can be stored in the first storage area to protect the integrity of the specified data structure. Among them, the first storage area can be a readable memory.
[0104] Step S452: If the type of the specified data structure is the second type, store the specified hash value in the second storage area to protect the integrity of the specified data structure, and the security level of the second storage area is higher than that of the first storage area.
[0105] As another implementation, if the type of the specified data structure is the second type, the specified hash value can be stored in the second storage area to protect the integrity of the specified data structure. The security level of the second storage area is higher than that of the first storage area. Optionally, the second storage area can be a TEE (Trusted Execution Environment) or a security chip.
[0106] Among them, the TEE can be an independent area on the hardware, which has a dedicated TA (Trusted Application). This trusted application is specifically used to interact with the TEE. The specified hash value can be put into the TEE through the TA, or the specified hash value can be read out of the TEE through the TA. The security chip has complex encryption algorithms and specific access channels. Both the TEE and the security chip need to be accessed through an intermediate application, and no program, process, or third party can directly access the TEE and the security chip.
[0107] Optionally, the security level of the security chip can be higher than that of the TEE, and the security level of the TEE can be higher than that of the read-only memory.
[0108] It should be noted that the data in the first storage area and the second storage area in this embodiment do not support modification.
[0109] The data integrity protection method provided in this embodiment obtains a target pointer function; obtains the address of a specified data structure in the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address; performs a hash operation on the content of the specified data structure to obtain a specified hash value; obtains the type of the specified data structure; if the type of the specified data structure is the first type, stores the specified hash value in a first storage area to protect the integrity of the specified data structure; if the type of the specified data structure is the second type, stores the specified hash value in a second storage area to protect the integrity of the specified data structure, and the security level of the second storage area is higher than that of the first storage area. Thus, through the above method, the specified data structure in the operating system kernel is obtained through the target pointer function, and the hash value obtained by performing a hash operation on the content of the specified data structure is stored in a specified storage area that does not support data modification, so as to prevent malicious processes from elevating privileges by modifying sensitive data, and the integrity protection of the specified data structure in the operating system kernel is realized.
[0110] At the same time, by determining the storage area corresponding to the security level based on the type of the specified data structure, targeted reinforcement of kernel security can be achieved, and then integrity protection can be implemented for kernel sensitive data in a targeted manner.
[0111] Please refer to Figure 5 , which is the structural block diagram of a data integrity protection device provided in an embodiment of the present application. This embodiment provides a data integrity protection device 500, which can run on a server or a terminal device, and specifically can be not limited, and the type of the server or the terminal device can be not limited. The device 500 includes a pointer function acquisition module 510, a content acquisition module 520, a calculation module 530, and a data protection module 540:
[0112] The pointer function acquisition module 510 is used to acquire a target pointer function.
[0113] As an implementation manner, the pointer function acquisition module 510 can be used to call the kernel tracing framework to obtain the address of the target pointer function; convert the address of the target pointer function into a function pointer.
[0114] The content acquisition module 520 is used to obtain the address of a specified data structure in the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address.
[0115] In this implementation manner, the specified data structure includes at least one of a system call table, a code segment in.txt format, and a read-only data segment in.rodata format.
[0116] In this embodiment, the specified data structure may further include an exception vector table. As an implementation, the content acquisition module 520 may be configured to obtain the starting address of the exception vector table through a first register; and obtain the content of the exception vector table based on the starting address.
[0117] In this embodiment, the specified data structure may further include a kernel access mechanism. As an implementation, the content acquisition module 520 may be configured to obtain the value of the kernel access mechanism through a second register, where the value of the kernel access mechanism is used to represent the open / closed state of the kernel access mechanism, and the second register is different from the first register.
[0118] The calculation module 530 is configured to perform a hash operation on the content of the specified data structure to obtain a specified hash value.
[0119] Optionally, the device 500 may further include a storage module, configured to, after obtaining the address of the specified data structure of the operating system kernel through the target pointer function and obtaining the content of the specified data structure through the address, copy the content of the specified data structure to a temporary memory. In this way, the calculation module 530 may be configured to perform a hash operation on the content of the specified data structure in the temporary memory to obtain a specified hash value.
[0120] As an implementation, the calculation module 530 may be configured to perform a hash operation on the content of the exception vector table to obtain a specified hash value.
[0121] As an implementation, the calculation module 530 may be configured to perform a hash operation on the kernel access mechanism to obtain a specified hash value.
[0122] The data protection module 540 is configured to store the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area does not support modification.
[0123] Optionally, the device 500 may further include a data structure type acquisition module, configured to acquire the type of the specified data structure. As an implementation, the data protection module 540 may be configured to, if the type of the specified data structure is the first type, store the specified hash value in a first storage area to protect the integrity of the specified data structure; if the type of the specified data structure is the second type, store the specified hash value in a second storage area to protect the integrity of the specified data structure, and the security level of the second storage area is higher than that of the first storage area.
[0124] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described devices and modules can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0125] In several embodiments provided by the present application, the coupling between modules can be electrical, mechanical or other forms of coupling.
[0126] In addition, in each embodiment of the present application, each functional module can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules.
[0127] Please refer to Figure 6 , based on the above data integrity protection method and device, the embodiments of the present application further provide an electronic device 100 that can execute the foregoing data integrity protection method. Optionally, the electronic device 100 can be a server or a terminal device, and the specific type can be not limited. The electronic device 100 includes a memory 102 and one or more (only one is shown in the figure) processors 104 that are coupled to each other, and the memory 102 and the processor 104 are connected by a communication line. The memory 102 stores a program that can execute the content in the foregoing embodiments, and the processor 104 can execute the program stored in the memory 102.
[0128] Among them, the processor 104 may include one or more processing cores. The processor 104 connects various parts within the entire electronic device 100 through various interfaces and circuits. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 102, and by calling data stored in the memory 102, it performs various functions of the electronic device 100 and processes data. Optionally, the processor 104 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 104 may integrate a combination of one or more of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing display content; the modem is used to process wireless communication. It can be understood that the above-mentioned modem may not be integrated into the processor 104 and may be implemented separately through a communication chip.
[0129] The memory 102 may include random access memory (RAM) and may also include read-only memory. The memory 102 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 102 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for implementing at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the foregoing various embodiments, etc. The data storage area may also store data created during the use of the electronic device 100 (such as phone book, audio and video data, chat record data, etc.).
[0130] Please refer to Figure 7 , which shows a structural block diagram of a computer-readable storage medium provided by an embodiment of the present application. Program code is stored in the computer-readable medium 600, and the program code can be called by a processor to execute the method described in the above method embodiments.
[0131] The computer-readable storage medium 600 can be an electronic memory such as a flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, a hard disk, or a ROM. Optionally, the computer-readable storage medium 600 includes a non-transitory computer-readable storage medium. The computer-readable storage medium 600 has a storage space for the program code 610 that executes any of the method steps in the above-described method. These program codes can be read from or written to one or more computer program products. The program code 610 can be compressed in an appropriate form, for example.
[0132] In summary, the embodiments of the present application provide a data integrity protection method, apparatus, electronic device, and storage medium. The method includes obtaining a target pointer function; obtaining the address of a specified data structure in the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address; performing a hash operation on the content of the specified data structure to obtain a specified hash value; and storing the specified hash value in a specified storage area to protect the integrity of the specified data structure, where the data in the specified storage area does not support modification. Thus, through the above method, the specified data structure in the operating system kernel is obtained through the target pointer function, and the hash value obtained by performing a hash operation on the content of the specified data structure is stored in the specified storage area that does not support data modification, so that it is possible to prevent malicious processes from escalating privileges by modifying sensitive data, and the integrity protection of the specified data structure in the operating system kernel is achieved.
[0133] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for data integrity protection, characterized in that, the method includes: Obtain a target pointer function; Obtain the address of a specified data structure in the operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address; Perform a hash operation on the content of the specified data structure to obtain a specified hash value; Store the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area does not support modification.
2. The method according to claim 1, characterized in that, the obtaining of the target pointer function includes: Call the kernel tracing framework to obtain the address of the target pointer function; Convert the address of the target pointer function into a function pointer.
3. The method according to claim 1, characterized in that, after obtaining the address of the specified data structure in the operating system kernel through the target pointer function and obtaining the content of the specified data structure through the address, the method further includes: Copy the content of the specified data structure to temporary memory; the performing of the hash operation on the content of the specified data structure to obtain a specified hash value includes: Perform a hash operation on the content of the specified data structure in the temporary memory to obtain a specified hash value.
4. The method according to any one of claims 1-3, characterized in that, the specified data structure includes at least one of a system call table, a code segment in.txt format, and a read-only data segment in.rodata format.
5. The method according to claim 4, characterized in that, the specified data structure further includes an exception vector table, and the method further includes: Obtain the starting address of the exception vector table through a first register; Obtain the content of the exception vector table based on the starting address; the performing of the hash operation on the content of the specified data structure to obtain a specified hash value includes: Perform a hash operation on the content of the exception vector table to obtain a specified hash value.
6. The method according to claim 5, characterized in that, the specified data structure further includes a kernel access mechanism, and the method further includes: Obtain the value of the kernel access mechanism through a second register, and the value of the kernel access mechanism is used to represent the open / closed state of the kernel access mechanism, and the second register is different from the first register.
7. The method according to claim 1, characterized in that, the method further includes: Obtain the type of the specified data structure; the storing of the specified hash value in a specified storage area to protect the integrity of the specified data structure includes: If the type of the specified data structure is the first type, store the specified hash value in the first storage area to protect the integrity of the specified data structure; If the type of the specified data structure is the second type, store the specified hash value in the second storage area to protect the integrity of the specified data structure, and the security level of the second storage area is higher than that of the first storage area.
8. A data integrity protection device, characterized in that, the device includes: A pointer function obtaining module, configured to obtain a target pointer function; A content acquisition module, configured to obtain the address of a specified data structure of an operating system kernel through the target pointer function, so as to obtain the content of the specified data structure through the address; A calculation module, configured to perform a hash operation on the content of the specified data structure to obtain a specified hash value; A data protection module, configured to store the specified hash value in a specified storage area to protect the integrity of the specified data structure, and the data in the specified storage area is not supported to be modified.
9. An electronic device, characterized in that, it includes one or more processors and a memory; One or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, program code is stored in the computer-readable storage medium, wherein when the program code is run by a processor, the method according to any one of claims 1-7 is executed.