File operation tracking method and device, equipment, medium and program product

By creating two tracking points in the system call layer and the virtual file system layer, parsing the parameters of the virtual file system opening function to determine the absolute path of the file, and feeding the file descriptor to the user layer, the problem of inaccurately tracking file operations and obtaining the complete absolute path in the prior art is solved, and efficient and accurate file operation tracking is achieved.

CN120104590AInactive Publication Date: 2025-06-06北京长擎量子技术有限公司
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510164548.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-06-06
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art cannot accurately track any operation of files and obtain complete absolute paths, resulting in high system overhead and inaccurate paths.

Method used

By creating two trace points at the system call layer and the virtual file system layer, in response to the open function call of the file operation, parsing the parameters of the virtual file system opening function to determine the absolute path of the file, and feeding the file descriptor to the user layer.

Benefits of technology

It realizes accurate tracking of arbitrary files operations and obtains complete absolute paths, improving the tracking efficiency of file operations and the accuracy of paths.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120104590A_ABST
    Figure CN120104590A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of operating systems, and discloses a file operation tracking method and device, equipment, a medium and a program product.The method comprises the steps that for multiple file operations of a user layer, a first tracking point and a second tracking point are created in response to execution of any file operation; responding to the situation that an opening function corresponding to any file operation is called to trigger a first tracking point, executing a virtual file system opening function corresponding to the opening function, triggering a second tracking point, and analyzing to obtain an absolute path of the operated file; and in response to the return of the first tracking point, obtaining a file descriptor of the operated file, and tracking by taking the file descriptor as a parameter of other file operation functions. According to the method, the file descriptor of the operated file is determined by utilizing the two tracking points, and the file descriptor is used as a parameter of other file operation functions for tracking, so that any operation and a complete absolute path of the file are accurately tracked, and the tracking efficiency of file operation is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of operating systems, and in particular to a file operation tracking method, device, equipment, medium and program product. Background Art

[0002] Real-time tracking of specific file operations is mainly used to solve the problem of locating file operations in the operating system. For example, for a known configuration file, if you don't know when the configuration file was modified, you can track the file to locate which processes and users have operated on the file, or you can track which files have been operated by a specified user or process.

[0003] Traditional file operation tracking methods, such as auditd and inotify, require frequent context switching between user mode and kernel mode, resulting in high system overhead. In the Virtual File System (VFS) layer, only vfs_open can obtain the absolute path. In other vfs functions, the complete absolute path cannot be obtained, and there will be a problem that the mount point cannot be obtained; it is difficult to obtain the complete absolute path using only the system call tracking point, which will increase the tasks to be processed in the user mode, and the absolute path may be inaccurate. The existing technology cannot accurately track any operation on the file and the complete and accurate absolute path. Summary of the invention

[0004] In view of this, the present invention provides a file operation tracking method, device, equipment, medium and program product to solve the problem of being unable to accurately track any operation on a file and the complete absolute path.

[0005] In a first aspect, the present invention provides a method for tracking file operations, the method comprising:

[0006] For a plurality of file operations at the user layer, in response to any file operation being executed, a first tracking point corresponding to the file operation is created at the system call layer, and a second tracking point corresponding to the file operation is created at the virtual file system layer;

[0007] In response to an open function corresponding to any file operation being called, a first tracking point corresponding to the file operation is triggered;

[0008] Based on the first tracking point, the virtual file system open function corresponding to the open function is executed to trigger the second tracking point of the file operation, and the absolute path of the operated file is obtained by parsing;

[0009] In response to the first tracking point returning, a file descriptor of the operated file is obtained, and the file descriptor is fed back to the user layer;

[0010] Track the file descriptor as an argument to other file operation functions.

[0011] The file operation tracking method provided by the present invention utilizes two tracking points to determine the file descriptor of the operated file, and uses the file descriptor as a parameter of other file operation functions for tracking, accurately tracking any operation on the file and the complete absolute path, thereby improving the tracking efficiency of the file operation.

[0012] In an optional implementation, in response to an open function corresponding to any file operation being called, triggering a first tracking point corresponding to the file operation includes:

[0013] Determine whether any file operation being performed meets the preset filtering conditions of the user layer;

[0014] If the preset filtering condition of the user layer is met, the first tracking point corresponding to the file operation is triggered.

[0015] The file operation tracking method provided by the present invention realizes the purpose of tracking the target file operation type or the target file by setting preset filtering conditions in the user layer. During operation, the user layer directly receives and displays the information transmitted by the kernel layer, and the logical operations are all in the kernel layer, which reduces the interaction between the user layer and the kernel layer and improves the performance.

[0016] In an optional implementation, based on the first tracking point, executing the virtual file system open function corresponding to the open function, triggering the second tracking point of the file operation, parsing to obtain the absolute path of the operated file, including:

[0017] Based on the second tracking point of the file operation, the file directory parameter of the virtual file system open function is parsed to obtain the file directory of the operated file, and the mount point parameter of the virtual file system open function is parsed to obtain the mount point directory of the operated file;

[0018] Based on the file directory and the mount point directory, determine the absolute path of the file being operated.

[0019] The file operation tracking method provided by the present invention determines the file directory and the mount point directory by parsing the parameters of the virtual file system open function, and then determines the absolute path of the operated file. The paths in the transmission process are all absolute paths, which ensures the uniqueness and accuracy of the operated file and avoids path confusion or errors caused by relative paths.

[0020] In an optional implementation, parsing the file directory parameter of the virtual file system open function to obtain the file directory of the operated file includes:

[0021] Parse the file directory parameters of the virtual file system open function to obtain the file directory structure;

[0022] For the last level directory entry of the file directory structure, determine whether the directory entry is equal to the parent directory of the directory entry;

[0023] If the directory entry is not equal to the parent directory of the directory entry, record the name of the directory entry;

[0024] The parent directory of the directory entry is used as the directory entry for the next loop, and the process returns to the step of determining whether the directory entry is equal to the parent directory of the directory entry, until the directory entry is consistent with the parent directory of the directory entry, and the names of all recorded directory entries are sequentially concatenated as the file directory.

[0025] The file operation tracking method provided by the present invention can quickly and accurately obtain the complete file directory of the operated file by traversing the directory items level by level, avoiding repeated traversal or redundant operations, thereby ensuring that the finally generated file directory is accurate.

[0026] In an optional implementation, if the called file operation function is not an open function, the file path associated with the file descriptor when the operated file is opened is used as the absolute path.

[0027] The file operation tracking method provided by the present invention uses the file descriptor as a transmission parameter for other types of file operation functions except the open function, which can increase security to a certain extent, eliminate the need to directly transmit the absolute path, reduce the complexity of transmitting parameters, and improve the accuracy of path transmission.

[0028] In an optional implementation, in response to the first tracking point returning, obtaining the file descriptor of the operated file includes:

[0029] In response to the first tracking point return of the file operation, the absolute path of the operated file and the file descriptor of the operated file are stored as a key-value pair;

[0030] Determine the file descriptor of the file being operated based on the key-value pair.

[0031] The file operation tracking method provided by the present invention uses the file descriptor as a key and the absolute path as a value, so that the file path can be quickly found according to the file descriptor, so that the absolute path can be accurately obtained according to the file structure and the mount point only when the file is opened. When other file operations only pass the file descriptor and cannot obtain the mount point, the real absolute path obtained when the file is opened can be directly used.

[0032] In a second aspect, the present invention provides a file operation tracking device, the device comprising:

[0033] A tracking point creation module, for creating a first tracking point corresponding to a plurality of file operations at a user layer in response to any file operation being executed, at a system call layer, and creating a second tracking point corresponding to the file operation at a virtual file system layer;

[0034] A tracking point triggering module, configured to trigger a first tracking point corresponding to a file operation in response to an open function corresponding to any file operation being called;

[0035] An absolute path determination module, used to execute a virtual file system open function corresponding to the open function based on the first tracking point, trigger a second tracking point of the file operation, and resolve and obtain the absolute path of the operated file;

[0036] An operation function return module, used for obtaining a file descriptor of the operated file in response to the return of the first tracking point, and feeding the file descriptor back to the user layer;

[0037] The file operation tracking module is used to track file descriptors as parameters of other file operation functions.

[0038] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0039] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to cause a computer to execute the method of the first aspect or any corresponding embodiment thereof.

[0040] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions for causing a computer to execute the method of the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0042] Figure 1 is a flowchart of a method for tracking file operations according to an embodiment of the present invention;

[0043] Figure 2is a schematic diagram of a process of dynamic tracking in a method for tracking file operations according to an embodiment of the present invention;

[0044] Figure 3 is a flowchart of another file operation tracking method according to an embodiment of the present invention;

[0045] Figure 4 It is a schematic diagram of a process of cyclically obtaining a complete directory in a file operation tracking method according to an embodiment of the present invention;

[0046] Figure 5 is a structural block diagram of a device for tracking file operations according to an embodiment of the present invention;

[0047] Figure 6 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0048] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0049] An embodiment of the present invention provides a method for tracking file operations. By utilizing two tracking points of an open function, the file descriptor of the operated file is determined, and the file descriptor is used as a parameter of other file operation functions for tracking, so as to achieve the effect of accurately tracking any operation on the file and the complete absolute path.

[0050] According to an embodiment of the present invention, an embodiment of a method for tracking file operations is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0051] In this embodiment, a file operation tracking method is provided, which can be used in the above-mentioned computer system. Figure 1 is a flow chart of a method for tracking file operations according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:

[0052] Step S101, for multiple file operations at the user layer, in response to any file operation being executed, a first tracking point corresponding to the file operation is created at the system call layer, and a second tracking point corresponding to the file operation is created at the virtual file system layer.

[0053] Specifically, when the user layer executes any file operation, a first tracking point corresponding to the file operation is created in the system call layer of the kernel, and a second tracking point corresponding to the file operation is created in the virtual file system layer of the kernel. For example, if the file operation executed in the user layer is open (" / root"), the first tracking point can be sys_enter_open, sys_exit_open, and the second tracking point can be kprobe_vfs_open, kretprobe_vfs_open, and the real file opening operation is performed through kprobe_vfs_open, and kretprobe_vfs_open is used as the return of the file opening operation. After kretprobe_vfs_open returns, sys_exit_open of the system call layer returns. The user-defined extended Berkeley Packet Filter (eBPF) program can be directly executed in the kernel state, reducing the number of context switches, thereby reducing the CPU load and memory usage, and realizing efficient real-time monitoring.

[0054] Tracepoints are markers in kernel code, usually embedded in the kernel's critical code paths. When the kernel runs to a tracepoint, it can trigger the corresponding handler to record or analyze events. Tracepoints are defined when the kernel is compiled and can be dynamically enabled or disabled at runtime without restarting the system or recompiling the kernel. Static tracepoints: manually inserted by kernel developers at key code locations, such as process scheduling, I / O operations, memory management, etc. Dynamic tracepoints: users can dynamically add or delete dynamic tracepoints without modifying the kernel code. Commonly used tools such as kprobe and uprobe can achieve this function.

[0055] Step S102: In response to an open function corresponding to any file operation being called, a first tracking point corresponding to the file operation is triggered.

[0056] Specifically, after the user layer executes the file operation, the corresponding open function will be called in the kernel layer. When the open function is called, the first tracking point corresponding to the file operation will be triggered. For example, after open(" / root") is executed, sys_enter_open and sys_exit_open will be triggered. This is just an example, but not limited to this.

[0057] Step S103: Based on the first tracking point, the virtual file system open function corresponding to the open function is executed to trigger the second tracking point of the file operation, and the absolute path of the operated file is obtained by parsing.

[0058] Specifically, based on the first tracking point sys_enter_open, the corresponding virtual file system opening function kprobe_vfs_open is executed to perform the file opening action, and then the absolute path of the operated file is obtained and passed to sys_exit_open. When sys_exit_open is executed, the absolute path and the corresponding file descriptor are stored as a key-value pair hash_map. The file descriptor and the corresponding key-value pair are used in other file operation functions to find the corresponding absolute path and obtain the absolute path of the operated file.

[0059] Usually when the system calls open, the actual file opening operation is performed through vfs_open. After vfs_open returns, the open system call returns. Figure 2 As shown, this embodiment uses two tools, kprobe and tracepoint, to realize dynamic tracing. The left column is the tracking points of kprobe / tracepoint. These tracking points have no absolute order. There is no particular order in which the functions of the entire operating system are executed. For a program, it is guaranteed that sys_enter_open / openat will be called first, then the vfs_open function will be executed, and finally the file descriptor will be obtained at sys_exit_open / openat. Subsequent operations on files by other file operation functions will use this file descriptor.

[0060] It should be noted that Figure 2 "kstack" is the call stack in the kernel, which is only needed for vfs stubs. vfs_* functions are kernel functions, and kstack will record how to call here; "ustack" is the user state call stack, which shows how the user layer calls here; "syscall" is a way for user state and kernel state to communicate. After the user state syscall, it enters the kernel state.

[0061] In some optional implementations, if the called file operation function is not an open function, the file path associated with the file descriptor when the operated file is opened is used as the absolute path.

[0062] Specifically, if the called file operation function is not an open function, such as read, write, or lseek, the file path associated with the file descriptor when the operated file is opened is directly used as the absolute path. It should be noted that the path parameters of other file operation functions include file descriptors, but do not include the absolute path of the file. Other vfs layer functions do not include the mount point information of the file.

[0063] The file operation tracking method provided in this embodiment uses the file descriptor as a transmission parameter for other types of file operation functions except the open function, which can increase security to a certain extent, eliminate the need to directly transmit the absolute path, reduce the complexity of transmitting parameters, and improve the accuracy of path transmission.

[0064] Step S104, in response to the return of the first tracking point, triggering the second tracking point of the file operation, parsing the absolute path of the operated file, obtaining the file descriptor of the operated file, and feeding back the file descriptor to the user layer.

[0065] Specifically, in response to the return of sys_exit_open from the first tracking point, the second tracking points kprobe_vfs_open and kretprobe_vfs_open of the file operation are triggered, the absolute path of the operated file is parsed, the file descriptor corresponding to the absolute path is obtained, and the file descriptor is fed back to the user layer for display at the user layer. For example, the user state program uses the user state function open("b") to operate the file in the working directory a, and executes to open the file b in the directory a. At this time, a is a mounted file system, and only the relative path b is passed during open. The user state function open will execute the system call open. The system call open will first parse the path string in the kernel state to find the real file location, create the corresponding file path structure, find the mount point information in the file path, and execute the two parameters of the file path structure and mount point passed when the vfs_open function is executed. The second tracking point is triggered during vfs_open, and the path "b" is obtained by parsing the passed file path structure, and the complete absolute path " / a / b" is obtained according to the mount point information. After waiting for vfs_open to return, it continues to run until the system call open returns, triggering the first tracking point sys_exit_open, which is the time when the system call open exits. At this time, the return value of the system call open, that is, the file descriptor, is obtained. Assume that the file descriptor is "3". At this moment, it sends information to the user layer that the application has opened this file, and creates a key-value pair to store the absolute path corresponding to the file descriptor in the hashmap. In other file operations, the system call layer uses the file descriptor to represent the absolute path of the file. At this time, the corresponding path found in the hashmap according to the file descriptor is the real absolute path.

[0066] Step S105: Track the file descriptor as a parameter of other file operation functions.

[0067] Specifically, the file descriptor is used as a parameter of other file operation functions so that other operation functions can accurately find the operated file, avoiding tracking errors that cannot be properly handled when the system call layer does not pass the file path and other vfs functions do not pass the mount point.

[0068] The file operation tracking method provided in this embodiment uses two tracking points of the open function to determine the file descriptor of the operated file, and uses the file descriptor as a parameter of other file operation functions for tracking, accurately tracking any operation on the file and the complete absolute path, thereby improving the tracking efficiency of file operations.

[0069] In this embodiment, a file operation tracking method is provided, which can be used in the above-mentioned mobile terminals, such as mobile phones, tablet computers, etc. Figure 3 is a flow chart of a method for tracking file operations according to an embodiment of the present invention. Figure 3 As shown, the process includes the following steps:

[0070] Step S201: For multiple file operations at the user layer, in response to any file operation being executed, a first tracking point corresponding to the file operation is created at the system call layer, and a second tracking point corresponding to the file operation is created at the virtual file system layer. Figure 1 Step S101 of the illustrated embodiment will not be described in detail here.

[0071] Step S202: In response to an open function corresponding to any file operation being called, a first tracking point corresponding to the file operation is triggered.

[0072] Specifically, the above step S202 includes:

[0073] Step S2021, determining whether any file operation being executed meets the preset filtering condition of the user layer.

[0074] Specifically, the user layer does not require any other complex processing and is only responsible for setting filtering conditions at startup. The filtering conditions can be specific files or specified operation types. This is just an example, but not limited to this. During runtime, the messages passed from the kernel state can be directly displayed, and all logic is in the instrumented kernel state.

[0075] Step S2022: If the preset filtering condition of the user layer is met, the first tracking point corresponding to the file operation is triggered.

[0076] Specifically, only the file operation that meets the preset filtering condition of the user layer will trigger the first tracking point corresponding to the file operation to achieve tracking of a specific file or a specified operation type.

[0077] The file operation tracking method provided in this embodiment achieves the purpose of tracking the target file operation type or target file by setting preset filtering conditions in the user layer. During runtime, the user layer directly receives and displays the information transmitted by the kernel layer, and all logical operations are in the kernel layer, thereby reducing the interaction between the user layer and the kernel layer and improving performance.

[0078] Step S203: Based on the first tracking point, the virtual file system open function corresponding to the open function is executed to trigger the second tracking point of the file operation, and the absolute path of the operated file is obtained by parsing.

[0079] Specifically, the above step S203 includes:

[0080] Step S2031, based on the second tracking point of the file operation, parse the file directory parameter of the virtual file system open function to obtain the file directory of the operated file, parse the mount point parameter of the virtual file system open function to obtain the mount point directory of the operated file.

[0081] In some optional implementations, parsing the file directory parameter of the virtual file system open function in the above step S2031 includes:

[0082] Step a1, parsing the file directory parameter of the virtual file system open function to obtain the file directory structure.

[0083] Specifically, since all file operation functions have a file directory parameter (dentry), the file directory parameter can be parsed to obtain a file directory structure (struct dentry). Figure 4 As shown, it is a schematic diagram of the complete process of parsing the file directory parameter of the virtual file system open function, and the complete directory is determined by loop acquisition and directory comparison.

[0084] Step a2: for the directory entry at the last level of the file directory structure, determine whether the directory entry is equal to the parent directory of the directory entry.

[0085] Specifically, check whether the current directory entry (dentry) is equal to its parent directory (parent dentry) to determine whether the root directory has been reached, so as to determine whether it is necessary to continue traversing upwards, or whether the root directory or mount point has been reached, so as to terminate the loop.

[0086] Step a3: If the directory entry is not equal to the parent directory of the directory entry, record the name of the directory entry.

[0087] Specifically, if the current directory entry is not equal to its parent directory, the name (d_name) of the current directory entry is recorded.

[0088] Step a4, taking the parent directory of the directory entry as the directory entry for the next loop, and returning to the step of determining whether the directory entry is equal to the parent directory of the directory entry, until the directory entry is consistent with the parent directory of the directory entry, and sequentially concatenating the names of all recorded directory entries as the file directory.

[0089] Specifically, the current directory entry is updated to the parent directory, and the above-mentioned checking and name collection operations are repeated until the current directory entry is equal to its parent directory, at which point it is considered that the root directory has been reached. Finally, all recorded directory entry names are concatenated in order to form a complete file path. By looping through, the complete file path is gradually constructed.

[0090] The complete directory is an absolute path. Check whether the absolute path meets the preset filtering conditions of the user layer. If it does, obtain other additional information at the current time, including but not limited to: process name, process id, user stack, user name id, kernel stack, etc. This information can be used in sys_exit_open / openat and displayed in the user layer. The process name, process id, and user name id can locate which process and which user triggered the current file operation. The kernel stack and user stack are used to accurately locate the path through which the user's program is executed to this point.

[0091] It should be noted that the mount point is also a structure. The parameters of the mount point include: the mount point directory, the directory above the mount point, and the need to continue looping this mount point directory. Mount points also have levels, that is, a mount point may also be on a mount point. Figure 4 The branch "The mount point is equal to the mount point of the previous layer (handling the problem of multiple mount points)" can be interpreted as: whether the current directory entry is equal to the mount point directory, if not, set the mount point directory as the current directory for the next loop, and use the mount point of the mount point as the next mount point, and continue the loop.

[0092] The file operation tracking method provided in this embodiment can quickly and accurately obtain the complete file directory of the operated file by traversing the directory entries level by level, avoiding repeated traversal or redundant operations, thereby ensuring that the finally generated file directory is accurate.

[0093] Specifically, all files operated by file operation functions may be mounted, but only the mount point parameter of the vfs_open function can be parsed to obtain the situation of mounting to other file systems. When the file path contains the mount point parameter, that is, it contains the mount point, the file directory structure will reflect the new file system structure after the mount point, and the mount point directory can record the mount point information. The vfs_open function can parse the complete path, including the mount point, when opening a file, so as to obtain the correct file path and mount information. This design enables VFS to flexibly manage and access multiple file systems.

[0094] Step S2032: Determine the absolute path of the operated file based on the file directory and the mount point directory.

[0095] Specifically, assuming that there is a file c in the mount device, and the mount point directory is / mnt / data, that is, mounted at / mnt / data, if the file directory obtained in step S2031 is c, considering the mount point and the mount point directory, the actual file path can be obtained as / mnt / data / c.

[0096] The file operation tracking method provided in this embodiment determines the file directory and the mount point directory by parsing the parameters of the virtual file system open function, and then determines the absolute path of the operated file. The paths in the transmission process are all absolute paths, which ensures the uniqueness and accuracy of the operated file and avoids path confusion or errors caused by relative paths.

[0097] Step S204, in response to the return of the first tracking point, obtain the file descriptor of the operated file, and feed the file descriptor back to the user layer.

[0098] Specifically, the step S204 of obtaining the file descriptor of the operated file includes:

[0099] Step S2041, in response to the first tracking point return of the file operation, the absolute path of the operated file and the file descriptor of the operated file are stored as a key-value pair.

[0100] Specifically, for example, if the absolute path of the operated file is: / home / user / documents / report.txt, the absolute path can be used as the value and the file descriptor (such as "3") can be used as the key. The constructed key-value pair can be: {3:" / home / user / documents / report.txt"}). This is only an example, but not limited to this.

[0101] Step S2042, determining the absolute path of the operated file according to the key-value pair.

[0102] Specifically, by using the key-value pairs of the operated files, the mapping relationship between the file descriptor and the absolute path can be directly determined, and the corresponding file descriptor can be found according to the path of the operated file, or the absolute path of the operated file can be determined according to the file descriptor, without traversing the entire file system or maintaining complex mapping relationships.

[0103] The file operation tracking method provided in this embodiment uses an absolute path as a value and a file descriptor as a key, and can quickly find the corresponding absolute path of the file according to the file descriptor without traversing the entire file system or maintaining complex mapping relationships, thereby improving the efficiency of file operations. In some dynamic environments, the relative path of a file may change due to various reasons (such as remounting the file system), but the absolute path remains unchanged. Using an absolute path to identify a file can ensure that the file can still be accurately located even when the environment changes.

[0104] Step S205: Track the file descriptor as a parameter of other file operation functions. Figure 1 Step S105 of the illustrated embodiment will not be described in detail here.

[0105] In a specific embodiment, the fdsnoop program at the user level opens the " / proc / 1218 / root / usr / lib64 / libXext.so.6.4.0" file through openat, and the return value is 41, indicating that the file descriptor of the successfully opened file is 41, the program id is 21598, the user id is 0, and the code executes here by calling the openat system call through libc-1.28.so.

[0106] The path " / proc / 1218 / root / usr / lib64 / libXext.so.6.4.0" passed by openat may be a relative path, a path with a mount point, etc. It is impossible to determine whether the path passed by open / openat is an accurate path, so the absolute complete path " / usr / lib64 / libXext.so.6.4.0" is obtained indirectly through vfs_open. In the path passed by openat, " / proc / 1218 / root" is a soft link pointing to the root directory " / ".

[0107] After the path transmission and conversion through openat and vfs_open, other file operation functions, such as syscall_close and read, can use the file descriptor "41". At the same time, "vfs: / usr / lib64 / libXext.so.6.4.0" is used to determine that the file descriptor "41" is the path stored in the path_hash saved during the previous open / openat.

[0108] It should be noted that only vfs_open can obtain the complete path, and there is no correlation between vfs functions. The path obtained by open cannot be used in other vfs_* functions. In the embodiment, other file operations are tracked by syscall, and read / write / close all use file descriptors. The key-value pair composed of the path and file descriptor during vfs_open can be used to ensure that the absolute path of the corresponding file can be displayed during other file operations.

[0109] In this embodiment, a file operation tracking device is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and will not be repeated hereafter. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0110] This embodiment provides a file operation tracking device, such as Figure 5 As shown, including:

[0111] The tracking point creation module 501 is used to create a first tracking point corresponding to the file operation at the system call layer and a second tracking point corresponding to the file operation at the virtual file system layer in response to any file operation being executed for multiple file operations at the user layer.

[0112] The tracking point triggering module 502 is used to trigger the first tracking point corresponding to any file operation in response to the opening function corresponding to any file operation being called.

[0113] The absolute path determination module 503 is used to execute the virtual file system open function corresponding to the open function based on the first tracking point, trigger the second tracking point of the file operation, and parse to obtain the absolute path of the operated file.

[0114] The operation function return module 504 is used to obtain the file descriptor of the operated file in response to the first tracking point return, and feed the file descriptor back to the user layer.

[0115] The file operation tracking module 505 is used to track the file descriptor as a parameter of other file operation functions.

[0116] In some optional implementations, the tracking point triggering module 502 includes:

[0117] The condition filtering unit is used to determine whether any file operation being executed meets the preset filtering conditions of the user layer.

[0118] The first tracking point triggering unit is used to trigger the first tracking point corresponding to the file operation if the preset filtering condition of the user layer is met.

[0119] In some optional implementations, the absolute path determination module 503 includes:

[0120] The parameter parsing unit is used to parse the file directory parameter of the virtual file system open function based on the second tracking point of the file operation to obtain the file directory of the operated file, and parse the mount point parameter of the virtual file system open function to obtain the mount point directory of the operated file.

[0121] The path determination unit is used to determine the absolute path of the operated file based on the file directory and the mount point directory.

[0122] In some optional implementations, the parameter parsing unit includes:

[0123] The structure determines the subunit, which is used to parse the file directory parameter of the virtual file system open function to obtain the file directory structure.

[0124] The directory entry judgment subunit is used to judge whether the directory entry of the last level of the file directory structure is equal to the parent directory of the directory entry.

[0125] The directory entry record subunit is used to record the name of the directory entry if the directory entry is not equal to the parent directory of the directory entry.

[0126] The loop judgment subunit is used to use the parent directory of the directory entry as the directory entry in the next loop, and return to the step of judging whether the directory entry is equal to the parent directory of the directory entry, until the directory entry is consistent with the parent directory of the directory entry, and the names of all recorded directory entries are sequentially spliced ​​as the file directory.

[0127] In some optional implementations, the operation function return module 504 includes:

[0128] The key-value pair construction unit is used to store the absolute path of the operated file and the file descriptor of the operated file as a key-value pair in response to the return of the first tracking point of the file operation.

[0129] The file descriptor determination unit is used to determine the file descriptor of the operated file according to the key-value pair.

[0130] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0131] In this embodiment, the file operation tracking device is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0132] The embodiment of the present invention also provides a computer device having the above Figure 5 The file operation tracer shown.

[0133] See also Figure 6 , Figure 6 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 6 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 6 A processor 10 is taken as an example.

[0134] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0135] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.

[0136] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0137] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0138] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0139] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0140] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.

[0141] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A file operation tracking method, characterized in that: The method comprises: For a plurality of file operations at the user layer, in response to any file operation being executed, a first tracking point corresponding to the file operation is created at the system call layer, and a second tracking point corresponding to the file operation is created at the virtual file system layer; In response to an open function corresponding to any file operation being called, triggering a first tracking point corresponding to the file operation; Based on the first tracking point, executing the virtual file system open function corresponding to the open function, triggering the second tracking point of the file operation, and parsing to obtain the absolute path of the operated file; In response to the first tracking point returning, obtaining a file descriptor of the operated file, and feeding the file descriptor back to the user layer; The file descriptor is tracked as a parameter to other file operation functions.

2. The method according to claim 1, characterized in that In response to an open function corresponding to any file operation being called, triggering a first tracking point corresponding to the file operation includes: Determine whether any file operation being performed meets the preset filtering conditions of the user layer; If the preset filtering condition of the user layer is met, the first tracking point corresponding to the file operation is triggered.

3. The method according to claim 1, characterized in that Based on the first tracking point, executing the virtual file system open function corresponding to the open function, triggering the second tracking point of the file operation, and parsing to obtain the absolute path of the operated file, including: Based on the second tracking point of the file operation, parsing the file directory parameter of the virtual file system open function to obtain the file directory of the operated file, parsing the mount point parameter of the virtual file system open function to obtain the mount point directory of the operated file; Based on the file directory and the mount point directory, the absolute path of the operated file is determined.

4. The method according to claim 3, characterized in that Parsing the file directory parameter of the virtual file system open function to obtain the file directory of the operated file includes: Parsing the file directory parameter of the virtual file system open function to obtain a file directory structure; For the directory entry at the last level of the file directory structure, determining whether the directory entry is equal to the parent directory of the directory entry; If the directory entry is not equal to the parent directory of the directory entry, record the name of the directory entry; The parent directory of the directory entry is used as the directory entry for the next loop, and the process returns to the step of determining whether the directory entry is equal to the parent directory of the directory entry, until the directory entry is consistent with the parent directory of the directory entry, and the names of all recorded directory entries are sequentially concatenated as the file directory.

5. The method according to claim 1, characterized in that If the called file operation function is not an open function, the file path associated with the file descriptor when the operated file is opened will be taken as the absolute path.

6. The method according to claim 1, characterized in that Parse the absolute path of the operated file to obtain the file descriptor of the operated file, including: In response to the first tracking point return of the file operation, the absolute path of the operated file and the file descriptor of the operated file are stored as a key-value pair; The file descriptor of the operated file is determined according to the key-value pair.

7. A file operation tracking device, characterized in that: The device comprises: A tracking point creation module, for creating, in response to any file operation being executed, a first tracking point corresponding to the file operation at the system call layer and a second tracking point corresponding to the file operation at the virtual file system layer for multiple file operations at the user layer; A tracking point triggering module, configured to trigger a first tracking point corresponding to any file operation in response to an open function corresponding to the file operation being called; an absolute path determination module, configured to execute, based on the first tracking point, a virtual file system open function corresponding to the open function, trigger a second tracking point of the file operation, and resolve and obtain an absolute path of the operated file; An operation function return module, used for obtaining a file descriptor of the operated file in response to the return of the first tracking point, and feeding back the file descriptor to the user layer; The file operation tracking module is used to track the file descriptor as a parameter of other file operation functions.

8. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 6 by executing the computer instructions.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 6.

10. A computer program product, characterized in that The method comprises computer instructions for causing a computer to execute the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method for detecting program internal storage layout information leakage behavior

    CN107220537A

  • File access control method and device, equipment and medium

    CN115758420A

  • Container escape determination method and device

    CN117056030A

  • Hidden process detection method and device based on eBPF, equipment and medium

    CN117473501A

  • Method and apparatus for obtaining the absolute path name of an open file system object from its file descriptor

    US20080294703A1