Real-time Blocking Method for High-risk Operations of RDP Graphics Rendering Instruction Stream under LoongArch

By intercepting the graphic rendering instruction flow of the RDP protocol in real time, generating structured features and combining static rule base matching and dynamic behavior analysis, the problem of not being able to protect against non-image attacks in the existing technology is solved, and accurate identification and interception of system-level high-risk operations is achieved, and protection capabilities are improved.

CN120085958BActive Publication Date: 2025-07-25XINAN (TIANJIN) NETWORK SECURITY TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510572530.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-07-25
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

The existing RDP graphics rendering protection technology cannot effectively protect against non-image attacks, and the static rule base is prone to missed judgments, resulting in insufficient protection capabilities for high-risk operations at the system level.

Method used

The graphical rendering instruction flow of the RDP protocol is intercepted in real time, structured features are generated, combined with static rule base matching and dynamic behavior analysis, and high-risk operations are identified through single-instruction features and context-level features. The dynamic deviation model determines abnormalities and triggers blocking.

Benefits of technology

It realizes accurate identification and interception of system-level high-risk operations, improves the detection ability of complex attack paths, reduces the risk of missed judgment, and enhances the adaptability to new attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120085958B_ABST
    Figure CN120085958B_ABST
Patent Text Reader

Abstract

The present application provides a method for real-time blocking of high-risk operations in the RDP graphics rendering instruction stream under the LoongArch architecture, which relates to the field of computer technology. The method includes the following steps: intercepting the graphics rendering instruction stream transmitted by the RDP protocol in real time, parsing each graphics rendering instruction in the graphics rendering instruction stream one by one to generate structured features, including single-instruction features and context-level features, retrieving and traversing the static rule library, matching the single-instruction features of each graphics rendering instruction with the static rule library. If at least one single-instruction feature matches successfully, it is determined as a high-risk operation and blocking is triggered; if the match is unsuccessful, dynamic behavior analysis is performed on the graphics rendering instruction stream based on the context-level features. If the determination result of the dynamic behavior analysis is abnormal, blocking is triggered. This solution uses the static rule library and dynamic analysis to work together, which not only reduces the risk of missed judgment but also avoids over-reliance on static rules, improving the protection ability against system-level high-risk operations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and particularly to a method for real-time blocking of high-risk operations in the RDP graphics rendering instruction stream under the LoongArch architecture. Background Art

[0002] The current security protection technology for the Remote Desktop Protocol (RDP) mainly focuses on image content protection. For example, the invention patent with the publication number CN117349890A discloses a technical solution that parses the image information in the RDP communication data packet, identifies the coordinates of sensitive areas and performs blurring processing, and triggers a control strategy when the user clicks or operates on the sensitive areas.

[0003] This solution relies on image feature matching (such as three-dimensional feature point extraction and sensitive area bounding) and a static rule library (such as preset operations bound to sensitive levels). Although it can effectively prevent the leakage of sensitive image data, its protection mechanism is completely based on the static feature matching of image content (such as the extraction and blurring of sensitive area coordinates), and can only target the explicit risk of image information leakage, unable to cover non-image attack behaviors (such as underlying memory out-of-bounds access, covert instruction injection, etc.). Moreover, the preset static rule library used in the matching is prone to missed judgments when facing unknown attack means or disguised attack paths, all of which lead to insufficient protection capabilities for system-level high-risk operations. Summary of the Invention

[0004] In view of the above-mentioned defects or deficiencies in the prior art, this application aims to provide a method for real-time blocking of high-risk operations in the RDP graphics rendering instruction stream under the LoongArch architecture to enhance the protection capabilities for system-level high-risk operations; the method includes the following steps:

[0005] Real-time intercept the graphics rendering instruction stream transmitted by the RDP protocol, and the graphics rendering instruction stream includes multiple graphics rendering instructions;

[0006] Parse each graphics rendering instruction in the graphics rendering instruction stream one by one to generate the structured features of the graphics rendering instruction stream; the structured features include single-instruction features and context-level features. The single-instruction features include the operation type, target address, and permission range of each graphics rendering instruction, and the context-level features include the timing correlation index, operation logic continuity result, and sensitive operation density within a preset time window among multiple graphics rendering instructions;

[0007] Retrieve and traverse the static rule library, and match the single-instruction features of each graphics rendering instruction with the static rule library. The static rule library includes multiple known attack patterns and the pattern features corresponding to each known attack pattern;

[0008] If at least one of the single-instruction features matches successfully, it is determined as a high-risk operation and blocking is triggered; if all of the single-instruction features do not match successfully, dynamic behavior analysis is performed on the graphics rendering instruction stream based on the context-level features, and if the determination result of the dynamic behavior analysis is abnormal, blocking is triggered.

[0009] According to the technical solution provided by the present application, parsing each of the graphics rendering instructions in the graphics rendering instruction stream one by one to generate the structured features of the graphics rendering instruction stream includes the following steps:

[0010] Based on the window size and sliding step of a preset time window, the graphics rendering instruction stream is divided into multiple consecutive instruction windows;

[0011] For multiple graphics rendering instructions within each instruction window, analyze the execution order and time interval between instructions to generate a timing correlation index;

[0012] Verify whether the operations within the instruction window meet the preset logic rules to obtain the result of operation logic continuity; the preset logic rules include that the video memory allocation instruction is executed before the drawing instruction, and permission verification is required after the system call instruction;

[0013] Count the number of sensitive operations within each instruction window to obtain the sensitive operation density within the preset time window; the sensitive operations include out-of-bounds access to video memory, system memory writing, and modification of non-standard protocol fields;

[0014] The timing correlation index, the result of operation logic continuity, and the sensitive operation density constitute the context-level features.

[0015] According to the technical solution provided by the present application, the dynamic behavior analysis of the graphics rendering instruction stream based on the context-level features includes the following steps:

[0016] Based on the timing correlation index, the result of operation logic continuity, and the sensitive operation density, obtain an abnormal score;

[0017] If at least one of the following conditions is met, the determination result is abnormal:

[0018] The abnormal score is greater than the preset risk threshold;

[0019] The result of operation logic continuity does not meet the preset logic rules;

[0020] The sensitive operation density is greater than or equal to the dynamic density threshold.

[0021] According to the technical solution provided by the present application, the anomaly score is obtained by calculating through a dynamic deviation model, and the dynamic deviation model is an autoencoder. Its construction and training include the following steps:

[0022] Extract context-level features from historical normal RDP sessions to generate a training dataset, and the training dataset only includes instruction stream features without attack behaviors.

[0023] Construct an autoencoder, which includes an encoder and a decoder. The encoder compresses the context-level features into a low-dimensional vector, and the decoder reconstructs the original features from the low-dimensional vector.

[0024] Train the autoencoder with the goal of minimizing the reconstruction error so that the context-level features of the normal instruction stream can be reconstructed with high precision.

[0025] Obtaining the anomaly score based on the temporal correlation index, the result of the operation logic continuity, and the sensitive operation density includes the following steps:

[0026] Input the context-level features of the real-time intercepted graphics rendering instruction stream into the trained autoencoder to calculate the reconstruction error.

[0027] Use the reconstruction error as the deviation index and set a deviation threshold.

[0028] Use the ratio of the deviation index to the deviation threshold as the anomaly score.

[0029] According to the technical solution provided by the present application, the window size of the preset time window is 5-20 consecutive graphics rendering instructions, the sliding step size is 1-5 instructions, and the window size and the sliding step size are dynamically adjusted according to the real-time load of the Loongson processor.

[0030] According to the technical solution provided by the present application, the structures of the encoder and decoder of the autoencoder are such that the number of neurons in the input layer is equal to the dimension of the context-level features, the number of neurons in the encoding layer is 20%-30% of the input layer, the number of neurons in the decoding layer is equal to the input layer, and the activation function uses a combination of ReLU and Sigmoid.

[0031] According to the technical solution provided by the present application, if the determination result of the dynamic behavior analysis is abnormal, triggering blocking includes the following steps:

[0032] If the anomaly score is in the first interval, discard the high-risk instructions and record the log; if the anomaly score is in the second interval, additionally isolate the current RDP session; if the anomaly score is greater than the upper limit of the second interval, permanently freeze the access permission of the attacking source IP; where the upper limit of the first interval is the lower limit of the second interval.

[0033] According to the technical solution provided by the present application, after extracting the context-level features from the historical normal RDP sessions and before generating the training dataset, the following steps are further included:

[0034] Perform normalization processing on the context-level features of the historical normal RDP sessions to make each dimension of the features conform to the normal distribution;

[0035] Perform moving average filtering processing on the time series correlation index, and the window size of the filtering window maintains a 1:1 mapping relationship with the window size of the preset time window.

[0036] According to the technical solution provided by the present application, verifying whether the operations within the verification instruction window meet the preset logical rules to obtain the operation logic continuity result includes the following steps:

[0037] If at least one of the following conditions is met, the operation logic continuity result is that the preset logical rules are not met:

[0038] Perform address range validity verification on the video memory allocation instruction, and the allocated base address exceeds the range of the virtual address mapping table of the current process;

[0039] Perform a permission check mark scan on multiple instructions after the system call instruction, and no permission check instruction is found.

[0040] According to the technical solution provided by the present application, the method is deployed in the GPU driver layer of Loongson 3A5000 and above processors.

[0041] Compared with the prior art, the beneficial effects of the present application are as follows: By intercepting the RDP graphics rendering instruction stream in real time and parsing it one by one, the present application directly obtains the operation type, target address, and permission range (single-instruction features) of the underlying instructions, breaking through the limitations of traditional image content protection, covering non-image attacks (such as malicious memory writing, privilege escalation instruction injection, etc.) at the instruction level, and achieving precise identification and interception of system-level high-risk operations. By extracting context-level features and combining dynamic behavior analysis technology, the present application captures the attack logic hidden in the instruction stream, effectively identifies the camouflage behavior or unknown variant attacks of the attack chain, and significantly improves the detection ability for complex attack paths. Therefore, this solution adopts a dual determination mechanism of static rule library matching and dynamic behavior analysis. The static rule library quickly intercepts known attack patterns, and the dynamic analysis module identifies abnormal behaviors through context feature modeling. The two work together to reduce the risk of missed judgments and avoid over-reliance on static rules, enhancing the adaptability to new attacks, thereby improving the protection ability for system-level high-risk operations. Description of the Drawings

[0042] Figure 1This is a flowchart of the steps of the method for real-time blocking of high-risk operations of RDP graphics rendering instruction stream under the Loongson architecture provided in this application. DETAILED DESCRIPTION

[0043] The present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention. It is also necessary to explain that, for ease of description, only the parts related to the invention are shown in the accompanying drawings.

[0044] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0045] Example 1

[0046] As mentioned in the background technology, in response to the problems in the prior art, this application proposes a real-time blocking method for high-risk operations of RDP graphics rendering instruction streams under the Loongson architecture. The professional vocabulary mentioned in this application is now explained: the Loongson architecture is an instruction system architecture independently developed and designed by Loongson Zhongke. From the top-level planning of the architecture to the details of the instructions, it is independently designed, with autonomy, advancement and compatibility. It integrates the main functional characteristics of the international mainstream instruction system, is easy to design high-performance and low-power hardware, and software compilation optimization and development, and can also achieve efficient binary translation of multiple mainstream instruction systems. All newly developed CPUs from 2020 support this architecture. The RDP protocol, namely the Remote Desktop Protocol, is a multi-channel protocol designed and implemented by Microsoft for remote connection to the Windows system desktop environment, allowing the client to perform graphical interaction, audio playback, file operations, etc. as if it were local. The protocol is located above the application layer, uses port 3389 for network transmission, and adopts a multi-channel design to allocate different types of data to their respective logical channels.

[0047] like Figure 1 As shown, the method comprises the following steps:

[0048] S1. intercepting a graphics rendering instruction stream transmitted by an RDP protocol in real time, wherein the graphics rendering instruction stream includes a plurality of graphics rendering instructions;

[0049] Specifically, the graphics rendering instruction stream is a set of instructions used to describe how to render the changes of the server desktop graphics on the client during the RDP protocol transmission process. It includes multiple graphics rendering instructions, which control operations such as graphics drawing and image display. The method for real-time capturing the graphics rendering instruction stream: In a system based on the LoongArch architecture, a data capture point is set on the RDP protocol data transmission path. By writing a corresponding data capture program and using the network interface or low-level driver interface provided by the operating system, the RDP protocol data flowing through this point is obtained in real-time, and the graphics rendering instruction stream is extracted from it.

[0050] S2. Analyze each graphics rendering instruction in the graphics rendering instruction stream one by one to generate the structured features of the graphics rendering instruction stream; the structured features include single-instruction features and context-level features. The single-instruction features include the operation type, target address, and permission range of each graphics rendering instruction. The context-level features include the timing correlation index between multiple graphics rendering instructions, the result of operation logic continuity, and the sensitive operation density within a preset time window.

[0051] Specifically, the structured features are the feature representations obtained after parsing the graphics rendering instruction stream. The single-instruction features describe the attributes of a single graphics rendering instruction, referring to the operation type (such as operation categories like drawing graphics and setting colors), target address (the target location such as the memory address targeted by the instruction operation), and permission range (the size and limit range of the permissions possessed by the instruction operation) and other characteristics of each graphics rendering instruction; the context-level features reflect the association characteristics between multiple graphics rendering instructions, covering the timing correlation index between multiple graphics rendering instructions (time-related characteristics such as instruction execution order and time interval), the result of operation logic continuity (the judgment result of whether the instruction execution conforms to the preset logic rules), and the sensitive operation density within a preset time window (the frequency of occurrence of sensitive operations within a specific time window).

[0052] S3. Retrieve and traverse the static rule library, and match the single-instruction features of each graphics rendering instruction with the static rule library. The static rule library includes multiple known attack patterns and the pattern features corresponding to each known attack pattern.

[0053] Specifically, the pre-established static rule library stores a variety of known attack patterns and the pattern features corresponding to each known attack pattern. These pattern features are obtained based on the analysis and summary of past attack behaviors and are used to match with single-instruction features to determine whether there is a high-risk operation risk in the current instruction. The static rule library can be pre-stored in a specific file system on the local disk or stored in a database management system. When matching is required, the static rule library is loaded into memory through a file reading function or a database query interface for subsequent matching operations with single-instruction features.

[0054] S4. If at least one of the single-instruction features matches successfully, it is determined as a high-risk operation and blocking is triggered; if all the single-instruction features do not match successfully, dynamic behavior analysis is performed on the graphics rendering instruction stream based on the context-level features, and if the determination result of the dynamic behavior analysis is abnormal, blocking is triggered.

[0055] Describe the usage process and technical principle of this embodiment: First, the graphics rendering instruction stream transmitted by the RDP protocol is intercepted in real time. Since the RDP protocol transmits desktop graphics change information, the graphics rendering instruction stream carries key drawing instructions and so on. Only by intercepting it can subsequent instructions be analyzed. Then, each instruction in the instruction stream is parsed one by one to generate structured features, which can convert the original instruction stream into a form with clear feature representations, facilitating subsequent analysis and judgment. Single-instruction features describe its attributes from the dimension of a single instruction, and context-level features are characterized from the dimensions of the relationship between instructions and the overall behavior. Then, the static rule library is retrieved and traversed, and the single-instruction features are matched with it. This is a feature match based on known attack patterns. If the match is successful, it indicates that there may be a high-risk operation in this instruction. If all the single-instruction features do not match successfully, dynamic behavior analysis is performed based on the context-level features because some attack behaviors may not be judged by a single instruction and need to identify anomalies from the relationship between instructions and the overall behavior pattern. If the analysis determination result is abnormal, blocking is triggered, thus realizing real-time blocking of high-risk operations.

[0056] This embodiment can monitor high-risk operations in the graphics rendering instruction stream transmitted by the RDP protocol in real time. Through the parsing and feature extraction of the instruction stream, combined with static rule library matching and dynamic behavior analysis, known attack patterns and some abnormal attack behaviors manifested through the instruction context relationship and overall behavior are effectively identified and blocked in a timely manner. This improves the security of the system under the LoongArch architecture in the remote desktop application scenario, prevents security problems such as system attacks, data leakage, or system crashes caused by malicious graphics rendering instructions, and ensures the safe and reliable operation of remote desktop operations.

[0057] In a preferred embodiment, parsing each of the graphics rendering instructions in the graphics rendering instruction stream one by one to generate the structural features of the graphics rendering instruction stream includes the following steps:

[0058] Based on the window size and sliding step of a preset time window, divide the graphics rendering instruction stream into multiple consecutive instruction windows;

[0059] Specifically, starting from the beginning position of the instruction stream, select instructions according to the window size to form the first instruction window, and then move backward at intervals of the sliding step to sequentially select new instruction windows until the entire instruction stream is traversed.

[0060] For multiple graphics rendering instructions within each instruction window, analyze the execution order and time interval between the instructions to generate a timing correlation index;

[0061] Verify whether the operations within the instruction window meet the preset logic rules to obtain the operation logic continuity result; the preset logic rules include that the video memory allocation instruction is executed before the drawing instruction, and the system call instruction needs to be followed by a permission check;

[0062] Further, verifying whether the operations within the instruction window meet the preset logic rules to obtain the operation logic continuity result includes the following steps:

[0063] If at least one of the following conditions is met, the operation logic continuity result is that the preset logic rules are not met:

[0064] Perform an address range validity verification on the video memory allocation instruction, and the allocated base address exceeds the range of the virtual address mapping table of the current process;

[0065] Perform a permission check mark scan on multiple instructions after the system call instruction, and no permission check instruction is found.

[0066] Specifically, perform an address range validity verification on the video memory allocation instruction, and the allocated base address exceeds the range of the virtual address mapping table of the current process. This is because normal video memory allocation operations should be within the legal address range of the current process. If the allocated base address exceeds this range, it is likely a malicious attack or a program error, which will pose a threat to the stability and security of the system. Perform a permission check mark scan on multiple instructions after the system call instruction, and no permission check instruction is found. This is to ensure the legality of the system call operation. System calls usually have higher privileges. If no permission check is performed after the call, it may be exploited by attackers to perform illegal operations, thus compromising the security of the system.

[0067] Count the number of sensitive operations in each of the instruction windows to obtain the sensitive operation density within a preset time window; the sensitive operations include out-of-bounds access to video memory, system memory writing, and modification of non-standard protocol fields;

[0068] The temporal correlation index, the operation logic continuity result, and the sensitive operation density constitute the context-level features.

[0069] Specifically, dividing the graphics rendering instruction stream into instruction windows based on a preset time window is to process the continuous instruction stream in segments, facilitating the analysis of the relationships and behaviors between instructions within a local scope. Generating the temporal correlation index by analyzing the execution order and time interval of instructions within the instruction window can reflect the rules and correlations of instruction execution from the time dimension. Verifying the operation logic continuity result and judging whether the instruction execution logic is correct according to the preset logic rules, because reasonable instruction execution logic is the basis for the normal operation of the system, and violating the logic rules may mean abnormal or attack behaviors. Counting the sensitive operation density and measuring the security risk level of the instruction stream by paying attention to the occurrence frequency of sensitive operations within the instruction window. These context-level features combined can more comprehensively describe the behavior pattern of the graphics rendering instruction stream over a period of time, providing data support for subsequent dynamic behavior analysis.

[0070] Further, the window size of the preset time window is 5 - 20 consecutive graphics rendering instructions, the sliding step is 1 - 5 instructions, and the window size and the sliding step are dynamically adjusted according to the real-time load of the Loongson processor.

[0071] Exemplarily, the complete instruction stream is as follows: The 1st instruction: video memory allocation; The 2nd instruction: color setting; The 3rd instruction: rectangle drawing; The 4th instruction: font loading; The 5th instruction: text rendering; The 6th instruction: video memory locking; The 7th instruction: image decoding; The 8th instruction: video memory writing; The 9th instruction: video memory release; The 10th instruction: palette modification; The 11th instruction: protocol tampering; The 12th instruction: drawing instruction; The 13th instruction: video memory allocation; The 14th instruction: system call; The 15th instruction: kernel writing. Among them, the 8th, 9th, 11th, 14th, and 15th instructions are sensitive marked. The system presets the time window size to be 10 consecutive instructions, and the sliding step is 5 instructions. When the attacker launches an attack, the instruction stream is divided into multiple windows (for example: the 1st - 10th instructions are window 1, the 6th - 15th instructions are window 2, and so on). The system detects the following anomalies for window 1: Number of sensitive operations: 2 times (instructions 8, 9), Sensitive operation density: 2 / 10 = 0.2 (equal to the threshold, not greater than), Temporal feature: Interval between instructions 8 - 9: normal value 15ms (meeting the requirement of > 10ms), Instruction order: Video memory allocation (1) → Operation (8) → Release (9) conforms to logic, Logic continuity: The video memory operation chain is complete: Allocation → Use → Release. Finally, the context - level features of window 1 include: Temporal correlation index: normal; Result of operation logic continuity: normal; Sensitive operation density: 0.2 (not exceeding the threshold); Window 1 is normal. The system detects the following anomalies for window 2: Anomaly features of window 2 (instructions 6 - 15): Number of sensitive operations: 5 (instructions 8, 9, 11, 14, 15), Sensitive operation 5 times → 5 / 10 = 0.5 (exceeding the threshold 0.2), Temporal anomaly: Interval between instructions 8 → 9 compressed to 2ms (recalculated due to window overlap), Instruction 12 (drawing) precedes 13 (video memory allocation), violating the rule that "video memory allocation must precede drawing", Logic break: Violation of rule 1: Drawing instruction 12 lacks a pre - video memory allocation (13th comes later); Violation of rule 2: There is no permission check instruction after system call 14; Finally, the context - level features of window 2 include: Temporal correlation index: high - frequency operation, order anomaly; Result of operation logic continuity: incorrect video memory allocation order, lack of permission check; Sensitive operation density: 0.5 (exceeding the threshold), Window 2 is abnormal. Based on these features, combined with subsequent steps, it is determined whether to trigger a blocking operation.

[0072] In a preferred embodiment, the dynamic behavior analysis of the graphics rendering instruction stream based on the context - level features includes the following steps:

[0073] Based on the temporal correlation index, the result of operation logic continuity, and the sensitive operation density, an anomaly score is obtained;

[0074] Further, the anomaly score is obtained by calculating through a dynamic deviation model, and the dynamic deviation model is an autoencoder. Its construction and training include the following steps:

[0075] Extract context-level features from historical normal RDP sessions to generate a training dataset, and the training dataset only includes the instruction stream features without attack behavior.

[0076] Construct an autoencoder, which includes an encoder and a decoder. The encoder compresses the context-level features into a low-dimensional vector, and the decoder reconstructs the original features from the low-dimensional vector.

[0077] Train the autoencoder with the goal of minimizing the reconstruction error so that the context-level features of the normal instruction stream can be reconstructed with high precision.

[0078] Obtaining the anomaly score based on the temporal correlation index, the operation logic continuity result, and the sensitive operation density includes the following steps:

[0079] Input the context-level features of the real-time intercepted graphics rendering instruction stream into the trained autoencoder to calculate the reconstruction error.

[0080] Specifically, the reconstruction error is the degree of difference between the features reconstructed by the autoencoder after reconstructing the input context-level features and the original input features, and is calculated through a certain distance metric (such as mean square error, etc.). The larger the reconstruction error, the greater the difference between the input instruction stream features and the normal mode learned by the autoencoder, that is, the more abnormal the instruction stream behavior.

[0081] Exemplarily, from 100,000 historical normal RDP sessions, extract the context-level features (including temporal correlation index, logical continuity result, sensitive operation density) of all instruction windows to form a training dataset. For example, the typical features of a normal instruction stream are: uniform temporal interval (10 - 20 ms), fully satisfying logical rules, and sensitive operation density ≤ 0.1. Model construction: The autoencoder is designed with an input layer (3 nodes corresponding to 3 types of features), an encoder (compressed into a 1-dimensional low-dimensional vector), and a decoder (reconstructing 3-dimensional features); Model training: Using the mean square error (MSE) as the loss function, the reconstruction error of the trained autoencoder for normal features is stabilized below 0.05 (the threshold is set to 0.1).

[0082] Take the reconstruction error as the deviation index and set a deviation threshold.

[0083] Take the ratio of the deviation index to the deviation threshold as the anomaly score.

[0084] Exemplarily, numericalize the context-level features of window 2: Temporal correlation index: [High-frequency marker = 1, Sequential anomaly marker = 1] → Encoded as 2 (1 + 1, anomaly count). Logical continuity result: [Video memory allocation error = 1, Permission verification missing = 1] → Encoded as 2. Sensitive operation density: 0.3. It should be noted that the actual features need to be normalized, and this is simplified as an example here. The input vector is x = [2, 2, 0.3], the encoder weights = [0.3, 0.3, 0.1], the encoder bias = [0.3, 0.3, 0.1], then the encoder output is: = (0.3 × 2) + (0.3 × 2) + (0.1 × 0.3) + 0.2 = 1.43; z activation = σ(1.43) = ≈ 0.81, so the encoder output is [0.8], the decoder weights are = [0.5, 0.4, 0.1], = [0.1, 0.2, 0.05], the decoder decodes to = [0.5 × 0.8 + 0.1, 0.4 × 0.8 + 0.2, 0.1 × 0.8 + 0.05] = [0.5, 0.52, 0.13]. Using the mean squared error (MSE) to calculate the difference between the original input and the reconstructed output is 1.4834. Based on historical normal data, the threshold is set to 0.1 (average MSE of normal instruction stream ≤ 0.1), and the anomaly score = reconstruction error / deviation threshold = 14.834.

[0085] If at least one of the following conditions is met, the determination result is abnormal:

[0086] The anomaly score is greater than the preset risk threshold;

[0087] The operation logical continuity result does not meet the preset logical rules;

[0088] The sensitive operation density is greater than or equal to the dynamic density threshold.

[0089] Specifically, by analyzing and statistically calculating the context-level features of a large number of historical normal RDP sessions, the distribution range of abnormal scores under normal conditions can be calculated. Based on this distribution, considering factors such as system security requirements and acceptable false alarm rates, a suitable value is determined as the preset risk threshold. For example, the 95th percentile of the abnormal scores in the historical normal data is selected as the preset risk threshold. The dynamic density threshold is dynamically calculated according to factors such as the current real-time load of the system, historical sensitive operation density data, and adjustment of security policies. For example, when the system load is low, the dynamic density threshold can be appropriately reduced to improve detection sensitivity; according to historical data statistics, if the average sensitive operation density is 5% within a certain period of time, then a certain percentage (such as ±2%) can be fluctuated up and down based on the strictness of the security policy to determine the dynamic density threshold.

[0090] Exemplarily, the abnormal score (14.834) > the preset risk threshold (for example, threshold = 2.0). The sensitive operation density (0.3) > the dynamic density threshold (for example, threshold = 0.2). The logical continuity result is not satisfied (video memory allocation error + permission verification missing), so all three conditions are satisfied, and the determination result is abnormal.

[0091] This embodiment can accurately determine whether there is an abnormal behavior in the graphics rendering instruction stream, and then trigger a blocking operation in a timely manner. By comparing the abnormal score with the preset risk threshold, the deviation of the overall behavior of the instruction stream from the normal mode is considered; the operation logic continuity result directly reflects the correctness of the instruction execution logic; the sensitive operation density judges the abnormality from the perspective of the occurrence frequency of sensitive operations. The combination of multiple determination conditions avoids the limitations of single-condition judgment, improves the accuracy and reliability of abnormal behavior detection, effectively prevents high-risk operations from harming the system, and ensures the safe operation of the system under the LoongArch architecture. Through the compression-reconstruction mechanism, the normal mode is encoded into a low-dimensional distribution, and abnormal behaviors generate high reconstruction errors because they cannot be restored. Combining multi-dimensional determination conditions, precise real-time blocking of the RDP graphics rendering instruction stream under the LoongArch architecture is achieved.

[0092] In a preferred embodiment, the encoder and decoder structures of the autoencoder are such that the number of neurons in the input layer is equal to the dimension of the context-level features, the number of neurons in the encoding layer is 20%-30% of the input layer, the number of neurons in the decoding layer is equal to the input layer, and the activation functions use a combination of ReLU and Sigmoid.

[0093] Specifically, the number of neurons in the input layer is equal to the dimension of the context-level features, ensuring that the autoencoder can directly process the original context-level feature data, enabling all information in the input data to be utilized and avoiding information loss. The number of neurons in the encoding layer is set to 20% - 30% of the input layer. This is a dimensionality reduction operation. By compressing the high-dimensional context-level features into a low-dimensional space, the autoencoder can learn the essential features and latent structure of the data, removing noise and redundant information. This allows for better discrimination between normal and abnormal patterns during subsequent reconstruction. The number of neurons in the decoding layer is equal to the input layer to be able to reconstruct the encoded low-dimensional vector into features of the same dimension as the original input for calculating the reconstruction error. The activation function uses a combination of ReLU and Sigmoid. The ReLU function has good performance in dealing with non-linear problems, can effectively solve the vanishing gradient problem, and accelerate the training speed of the model. The Sigmoid function can map the output to the interval [0, 1], which is suitable for dealing with probability-related problems and can help the model better learn the distribution of the data in the autoencoder. Exemplarily, ReLU is used in the encoding layer: to solve the vanishing gradient problem and enhance non-linear expression ability. Sigmoid is used in the decoding layer: to limit the output to the range [0, 1] and adapt to the numerical distribution after feature normalization.

[0094] In a preferred embodiment, the triggering of blocking when the determination result of the dynamic behavior analysis is abnormal includes the following steps:

[0095] If the anomaly score is within the first interval, discard the high-risk instruction and record a log; if the anomaly score is within the second interval, additionally isolate the current RDP session; if the anomaly score is greater than the upper limit of the second interval, permanently freeze the access permission of the attack source IP; where the upper limit of the first interval is the lower limit of the second interval.

[0096] Specifically, based on historical data statistics, for example, the 95th percentile of the normal score is 1.5, then the upper limit of the first interval = 1.5 × 1.3 ≈ 2.0 (leaving 30% buffer); First interval (1.0 ≤ score < 2.0): low risk, only record the log to avoid interfering with normal operations. Second interval (2.0 ≤ score < 5.0): medium risk, isolate the session to prevent lateral penetration. Third interval (score ≥ 5.0): high risk, permanently freeze the IP to prevent continuous attacks.

[0097] In a preferred embodiment, after extracting the context-level features from the historical normal RDP sessions and before generating the training dataset, the following steps are further included:

[0098] Perform normalization processing on the context-level features of the historical normal RDP sessions to make each dimension of the features conform to a normal distribution;

[0099] Perform a moving average filtering process on the temporal correlation index, and the window size of the filtering window maintains a 1:1 mapping relationship with the window size of the preset time window.

[0100] Specifically, the standardization process can adopt Z-score normalization to eliminate the difference in feature dimensions. For example, the numerical scales of temporal correlation (0 - 100 ms) and sensitive operation density (0 - 1) are different. The moving average filtering is to smooth the instantaneous fluctuations of the temporal index (such as abnormal instruction intervals caused by network jitter) and reduce misjudgments.

[0101] In a preferred embodiment, the method is deployed in the GPU driver layer of LoongArch 3A5000 and above processors.

[0102] Specifically, deploying the method in the GPU driver layer of LoongArch 3A5000 and above processors is because the GPU driver layer can directly access and process the graphics rendering instruction stream, with high real-time performance and efficiency. LoongArch 3A5000 and above processors have strong computing capabilities and performance, which can meet the requirements of real-time monitoring and analysis of the graphics rendering instruction stream. Deploying this method in the GPU driver layer can intercept and analyze at the source of the graphics rendering instruction stream, discover and block high-risk operations in a timely manner, and effectively protect the security of the system.

[0103] The specific implementation is to build a program module for the GPU driver layer of LoongArch 3A5000 and above processors (the strategy is consistent with the process of this method). This module realizes functions such as real-time intercepting the graphics rendering instruction stream transmitted by the RDP protocol, parsing the instruction stream, generating structured features, matching the static rule library, performing dynamic behavior analysis, and triggering blocking operations. In the initialization stage of the GPU driver layer, load this program module and register it into the corresponding event handling mechanism to ensure that this module can be called in a timely manner for processing when the graphics rendering instruction stream is transmitted. Conduct strict testing and optimization on this program module to ensure that it can run stably in the GPU driver layer of LoongArch 3A5000 and above processors and will not have an obvious impact on the normal performance of the system.

[0104] In this article, specific examples are used to elaborate on the principle and implementation method of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. The above are only the preferred implementation methods of this application. It should be noted that due to the limited nature of text expression and objectively existing infinite specific structures, for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements, refinements or changes can be made, or the above technical features can be combined in an appropriate manner; these improvements, refinements, changes or combinations, or directly applying the concept and technical solution of the invention to other occasions without improvement, should all be regarded as the protection scope of this application.

Claims

1. A real-time blocking method for high-risk operations of RDP graphics rendering instruction streams under the LoongArch architecture, characterized in that, Including the following steps: Intercepting in real time the graphics rendering instruction stream transmitted by the RDP protocol, where the graphics rendering instruction stream includes multiple graphics rendering instructions; Parsing each graphics rendering instruction in the graphics rendering instruction stream one by one to generate the structured features of the graphics rendering instruction stream; The structured features include single-instruction features and context-level features. The single-instruction features include the operation type, target address, and permission range of each graphics rendering instruction. The context-level features include the timing correlation index between multiple graphics rendering instructions, the result of operation logic continuity, and the sensitive operation density within a preset time window; Retrieving and traversing the static rule library, and matching the single-instruction features of each graphics rendering instruction with the static rule library. The static rule library includes multiple known attack patterns and the pattern features corresponding to each known attack pattern; If at least one of the single-instruction features matches successfully, it is determined as a high-risk operation and blocking is triggered; if all the single-instruction features do not match successfully, dynamic behavior analysis is performed on the graphics rendering instruction stream based on the context-level features. If the determination result of the dynamic behavior analysis is abnormal, blocking is triggered.

2. The real-time blocking method for high-risk operations of RDP graphics rendering instruction streams under the LoongArch architecture according to claim 1, wherein: The step of parsing each graphics rendering instruction in the graphics rendering instruction stream one by one to generate the structured features of the graphics rendering instruction stream includes the following steps: Dividing the graphics rendering instruction stream into multiple consecutive instruction windows based on the window size and sliding step of the preset time window; Analyzing the execution order and time interval between instructions for multiple graphics rendering instructions in each instruction window to generate a timing correlation index; Verifying whether the operations within the instruction window meet the preset logic rules to obtain the result of operation logic continuity. The preset logic rules include that the video memory allocation instruction is executed before the drawing instruction, and permission verification is required after the system call instruction; Counting the number of sensitive operations in each instruction window to obtain the sensitive operation density within the preset time window. The sensitive operations include out-of-bounds access to video memory, system memory writing, and modification of non-standard protocol fields; The timing correlation index, the result of operation logic continuity, and the sensitive operation density constitute the context-level features.

3. The real-time blocking method for high-risk operations of RDP graphics rendering instruction stream under the LoongArch architecture according to claim 1, characterized in that: The step of performing dynamic behavior analysis on the graphics rendering instruction stream based on the context-level features includes the following steps: Obtaining an anomaly score based on the timing correlation index, the result of operation logic continuity, and the sensitive operation density; If at least one of the following conditions is met, the determination result is abnormal: The anomaly score is greater than the preset risk threshold; The result of operation logic continuity does not meet the preset logic rules; The sensitive operation density is greater than or equal to the dynamic density threshold.

4. The method for real-time blocking of high-risk operations of the RDP graphics rendering instruction stream under the LoongArch architecture according to claim 3, wherein: The anomaly score is obtained through calculation by a dynamic deviation model. The dynamic deviation model is an autoencoder, and its construction and training include the following steps: Extracting context-level features from historical normal RDP sessions to generate a training dataset, where the training dataset only includes the instruction stream features without attack behavior; Construct an autoencoder, which includes an encoder and a decoder. The encoder compresses the context-level features into a low-dimensional vector, and the decoder reconstructs the original features from the low-dimensional vector; Train the autoencoder with the goal of minimizing the reconstruction error, so that the context-level features of the normal instruction stream can be reconstructed with high precision; Based on the temporal correlation index, the operation logic continuity result, and the sensitive operation density, obtain an anomaly score, including the following steps: Input the context-level features of the real-time intercepted graphics rendering instruction stream into the trained autoencoder, and calculate the reconstruction error; Use the reconstruction error as the deviation index, and set a deviation threshold; Use the ratio of the deviation index to the deviation threshold as the anomaly score.

5. The method for real-time blocking of high-risk operations of RDP graphics rendering instruction stream under LoongArch architecture according to claim 2, wherein: The window size of the preset time window is 5-20 consecutive graphics rendering instructions, and the sliding step size is 1-5 instructions. The window size and the sliding step size are dynamically adjusted according to the real-time load of the Loongson processor.

6. The real-time blocking method for high-risk operations of the RDP graphics rendering instruction stream under the LoongArch architecture according to claim 4, characterized in that: The encoder and decoder structures of the autoencoder are such that the number of neurons in the input layer is equal to the dimension of the context-level features, the number of neurons in the encoding layer is 20%-30% of the input layer, the number of neurons in the decoding layer is equal to the input layer, and the activation function uses a combination of ReLU and Sigmoid.

7. The method for real-time blocking of high-risk operations of the RDP graphics rendering instruction stream under the LoongArch architecture according to claim 3, characterized in that: If the determination result of the dynamic behavior analysis is abnormal, trigger blocking, including the following steps: If the anomaly score is within the first interval, discard the high-risk instructions and record the log; if the anomaly score is within the second interval, additionally isolate the current RDP session; if the anomaly score is greater than the upper limit of the second interval, permanently freeze the access permission of the attacking source IP; where the upper limit of the first interval is the lower limit of the second interval.

8. The real-time blocking method for high-risk operations of RDP graphics rendering instruction streams under the LoongArch architecture according to claim 4, characterized in that: Before generating the training dataset after extracting the context-level features from the historical normal RDP sessions, the following steps are also included: Perform standardization processing on the context-level features of the historical normal RDP sessions to make each dimension of the features conform to the normal distribution; Perform a moving average filtering process on the temporal correlation index, and the window size of the filtering window maintains a 1:1 mapping relationship with the window size of the preset time window.

9. The real-time blocking method for high-risk operations of the RDP graphics rendering instruction stream under the Godson architecture according to claim 2, characterized in that: Verify whether the operations within the verification instruction window meet the preset logic rules to obtain the operation logic continuity result, including the following steps: If at least one of the following conditions is met, the operation logic continuity result is that the preset logic rules are not met: Verify the validity of the address range of the video memory allocation instruction, and the allocated base address exceeds the virtual address mapping table range of the current process; Scan the permission verification marks of multiple instructions after the system call instruction, and no permission verification instruction is found.

10. The method for real-time blocking of high-risk operations of RDP graphics rendering instruction stream under the LoongArch architecture according to claim 1, characterized in that: The method is deployed in the GPU driver layer of Loongson 3A5000 and above processors.

Citation Information

Patent Citations

  • RDP-based sensitive data processing method and system, and electronic equipment

    CN117349890A

  • Remote desktop configuration method and device and electronic equipment

    CN119557028A

  • Remote office network security protection method and system based on big data

    CN119728311A