Kernel protection method and device, electronic equipment and readable storage medium
By detecting write operations in the kernel space and obtaining the target expected data of the target node for writing, the problem of insufficient protection of permission division in the prior art is solved, and strong protection of the kernel space is achieved.
Patent Information
- Application Number
- CN202311700055.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-11
- Publication Date
- 2025-06-13
AI Technical Summary
The prior art protects security-type nodes in the kernel space by dividing different levels of permissions, but the degree of protection is weak. Malicious programs can illegally obtain higher-level permissions for writing operations.
When a write operation to a secure type target node in the kernel space is detected, the first identification information of the target node is obtained, the target expected data of the target node is determined based on the information, and written to the target node to ensure that the node maintains its expected state.
By actively obtaining and writing target expected data, malicious programs prevent them from modifying secure target nodes in the kernel space, achieving strong protection against the kernel.
Smart Images

Figure CN120145369A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of kernel security technology, and more particularly, to a kernel protection method, device, electronic device, and readable storage medium. Background Art
[0002] Currently, with the development of electronic information technology, it is possible to protect nodes related to security in the kernel space of an electronic device. Higher-level permissions can be set by dividing different levels of permissions to restrict the write operations of nodes related to security in the kernel space. However, the method of protecting nodes related to security in the kernel space by dividing different levels of permissions has a weak protection level. Summary of the Invention
[0003] This application provides a kernel protection method, device, electronic device, and readable storage medium.
[0004] In a first aspect, an embodiment of this application provides a kernel protection method applied to an electronic device. The method includes: when a write operation to a target node of a security type in the kernel space of the electronic device is detected, obtaining first identification information of the target node; determining target expected data of the target node based on the first identification information; and writing the target expected data to the target node.
[0005] In a second aspect, an embodiment of this application further provides a kernel protection device applied to an electronic device. The device includes: a detection unit, a determination unit, and a writing unit. The detection unit is configured to obtain first identification information of the target node when a write operation to a target node of a security type in the kernel space of the electronic device is detected; the determination unit is configured to determine target expected data of the target node based on the first identification information; and the writing unit is configured to write the target expected data to the target node.
[0006] In a third aspect, an embodiment of this application further provides an electronic device, including: one or more processors; a memory; one or more application programs, where the one or more application programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method described in the first aspect.
[0007] In a fourth aspect, an embodiment of this application further provides a computer-readable storage medium, in which program code is stored, and the program code can be called by a processor to execute the method described in the first aspect.
[0008] The kernel protection method, device, electronic device, and readable storage medium provided by this application, when detecting a write operation on a target node of a secure type in the kernel space of the electronic device, obtain the first identification information of the target node; then determine the target expected data of the target node based on the first identification information; and then write the target expected data to the target node. If only by dividing different levels of user permissions to restrict the operations of lower-level user permissions on nodes of the secure type in the kernel space, without restricting the writes of higher-level user permissions to nodes of the secure type in the kernel space, malicious programs may illegally obtain higher-level permissions, and thus can write to nodes of the secure type. In this application, when detecting a write operation on a target node of a secure type in the kernel space, it will actively obtain the target expected data corresponding to the target node and write the target expected data to the target node, so as to ensure that the target node is the target expected data and will not be modified by malicious programs into other data, preventing malicious programs from modifying the target nodes of the secure type in the kernel space and achieving a relatively strong degree of protection for the kernel.
[0009] Other features and advantages of the embodiments of this application will be described in the subsequent description. Moreover, some will become obvious from the description, or be understood by implementing the embodiments of this application. The objectives and other advantages of the embodiments of this application can be achieved and obtained through the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] To more clearly illustrate the technical solutions in the embodiments of this application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of this application. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0011] Figure 1 Shows the method flow chart of the kernel protection method provided by the embodiments of this application;
[0012] Figure 2 Shows the method flow chart of the kernel protection method provided by another embodiment of this application;
[0013] Figure 3 Shows the schematic diagram of the kernel entry corresponding to the kernel space node provided by the embodiments of this application;
[0014] Figure 4 Shows the method flow chart of the kernel protection method provided by yet another embodiment of this application;
[0015] Figure 5The structural block diagram of the kernel protection device provided by the embodiment of the present application is shown;
[0016] Figure 6 The schematic diagram of the kernel method provided by the embodiment of the present application applied to an electronic device is shown;
[0017] Figure 7 The structural block diagram of the electronic device provided by the embodiment of the present application is shown;
[0018] Figure 8 The structural block diagram of the computer-readable storage medium provided by the embodiment of the present application is shown. Detailed implementation manners
[0019] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Usually, the components of the embodiments of the present application described and shown in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application to be protected, but only represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0020] It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for differential description and cannot be understood as indicating or implying relative importance.
[0021] Currently, with the development of electronic information technology, it is possible to protect the security-related nodes in the kernel space of an electronic device. Higher-level permissions can be set by dividing different levels of permissions to restrict the write operations of the security-related nodes in the kernel space. However, the method of protecting the security-related nodes in the kernel space by dividing different levels of permissions has a weak protection level. How to improve the protection ability of the security nodes in the kernel space is an urgent problem to be solved.
[0022] Among them, the kernel space of the electronic device can be accessed and operated through sysctl. Specifically, sysctl allows users to view and modify the running parameters (Kernel tunables) and settings (Kernel settings) of the nodes in the kernel space through specific interfaces. It can be accessed and operated through the files in the / proc / sys / directory.
[0023] Exemplarily, the / proc / sys / directory may include sysfs or procfs. Among them, sysfs is a special file system provided by the kernel space for accessing devices, drivers, and other kernel objects. Some sysctl-related files are included in sysfs, so that the relevant nodes in the kernel space can be modified by reading and writing these files, such as modifying the running parameters or settings of the nodes.
[0024] procfs is a special type of file system that provides access to running processes and system information. In procfs, each process is represented as a folder and named after its process ID. Information about the process, such as status information and command-line arguments, can be found in it. Some sysctl-related files are included in procfs, so that the relevant nodes in the kernel space can be modified by reading and writing these files, such as modifying the running parameters or settings of the nodes.
[0025] That is to say, sysctl is a mechanism for modifying running parameters in the kernel space, while procfs and sysfs are two special file systems that provide access to sysctl-related information. The settings and running parameters of the relevant nodes in the kernel space can be accessed and modified by reading and writing the corresponding files.
[0026] Sysctl may include multiple types of nodes. Some nodes are non-security type nodes, and some are security type nodes. Currently, by dividing different user permission levels, the access rights of users with lower levels are restricted to read and write security type nodes, while the access rights of users with higher levels are not restricted to read and write security type nodes, so as to achieve the protection of security type nodes in the kernel space.
[0027] However, the inventor found in the research that malicious programs can obtain higher-level user permissions through the vulnerabilities of the electronic device, so as to achieve the read and write of security type nodes in the kernel space, and then modify the running parameters or settings of security type nodes. For example, the vulnerabilities related to sysctl can be used to obtain higher-level user permissions. That is to say, the method of protecting the security-related nodes in the kernel space by setting higher-level user permissions has a weak protection degree.
[0028] Therefore, in order to overcome or partially overcome the above defects, the present application provides a kernel protection method, apparatus, electronic device and readable storage medium.
[0029] Please refer to Figure 1 , Figure 1 which shows a flowchart of a kernel protection method provided by an embodiment of the present application. The kernel protection method can be applied to an electronic device, specifically to the processor of the electronic device. The kernel protection method specifically includes steps S110 to S130.
[0030] Among them, the electronic device can be an electronic device based on the Linux system, such as a personal computer, server, in-vehicle system, etc. based on the Linux system, or an electronic device based on the Android system, such as a smart phone, smart tablet, smart watch, smart TV, etc. based on the Linux system.
[0031] Step S110: When a write operation on a target node of a security type in the kernel space of the electronic device is detected, obtain first identification information of the target node.
[0032] An electronic device may include a kernel space, and the kernel space may include multiple nodes. Some of these nodes may be nodes of a security type, and the other part may be nodes of a non-security type. It can be understood that operating on a non-security type node, such as writing or reading, will not affect the security of the kernel space of the electronic device; while operating on a security type node, such as a write operation, may have a negative impact on the security of the kernel space of the electronic device. Therefore, it is necessary to protect the security type nodes in the kernel space.
[0033] Exemplarily, security-type nodes may include ftrace_dump_on_oops, kptr_restrict, randomize_va_space, unprivileged_bpf_disabled, perf_event_paranoid, modules_disabled, protected_fifos, protected_hardlinks, protected_symlinks, or unprivileged_userfaultfd, etc. Among them, ftrace_dump_on_oops can be used to set how to print the stack in the Ftrace buffer to the console when the kernel has an oops crash; kptr_restrict is used to set how to hide the addresses in the kernel symbol table; randomize_va_space is used to set how to randomize user-space virtual addresses to prevent layout attacks against a specific kernel; unprivileged_bpf_disabled is used to set to run or prohibit unprivileged users from using the eBPF function; perf_event_paranoid is used to set the access level of unprivileged users to performance events; modules_disabled is used to set to allow or prohibit loading kernel modules; protected_fifos is used to set the protection level of FIFOS files; protected_hardlinks is used to set the protection level of hard links; protected_symlinks is used to set the protection level of soft links; unprivileged_userfaultfd is used to set to allow or prohibit unprivileged users from creating and using userfault file descriptors.
[0034] It should be noted that the above introduction to security-type nodes is only an example and does not constitute a specific limitation on the embodiments of the present application.
[0035] Optionally, the system default non-security-type nodes can also be artificially set as security-type nodes to improve the protection ability of the kernel space of the electronic device. For example, the node type of the node under the path sys / fs / selinux / enforce or some important self-developed nodes can be set as the security type.
[0036] It can be understood that since the kernel space includes nodes of non-secure types, and operating on nodes of non-secure types will not affect the security of the kernel space of the electronic device, it is not necessary to detect or restrict the read and write operations of nodes of non-secure types. However, operating on nodes of secure types, such as performing a write operation, may have a negative impact on the security of the kernel space of the electronic device. Therefore, it is possible to detect or restrict the write operations of nodes of secure types.
[0037] For some embodiments, when a write operation on a target node of a secure type in the kernel space of the electronic device is detected, the first identification information of the target node can be obtained. Herein, the target node is the target object of this write operation. The first identification information can be used to uniquely determine the target object, that is, the first identification information can be used to characterize the identity of the target object. Exemplarily, the first identification information can include a name, such as "ftrace_dump_on_oops", "kptr_restrict", "randomize_va_space", or "unprivileged_bpf_disabled", etc. Another exemplarily, the first identification information can include a name and a path, such as the name is "ftrace_dump_on_oops" and the path is " / proc / sys / kernel"; the name is "kptr_restrict" and the path is " / proc / sys / kernel"; the name is "protected_fifos" and the path is " / proc / sys / fs" or the name is "unprivileged_userfaultfd" and the path is " / proc / sys / vm".
[0038] Furthermore, the target expected data corresponding to the target node can be determined through the first identification information in the subsequent steps. For a detailed introduction, please refer to the subsequent steps.
[0039] Among them, the first identification information of the target node is included in the parameters of the write operation, so the first identification information can be determined by reading the parameters of the write operation. The write operation can be created by a process in the electronic device.
[0040] Step S120: Determine the target expected data of the target node based on the first identification information.
[0041] Among them, the target expected data is used to characterize the correct value corresponding to the configuration or running state of the target node. The target node written with the target expected data can run in a normal configuration or running state; if the target node is written with non-target expected data, it may cause the configuration or running state of the target node to be abnormal, thus causing the electronic device to be abnormal.
[0042] It can be understood that different target nodes may correspond to different target expected data. Exemplarily, the target expected data corresponding to the target node ftrace_dump_on_oops may be 0, indicating that when the kernel crashes due to an oops, printing the stack in the Ftrace buffer to the console is prohibited; for another example, the target expected data corresponding to the target node kptr_restrict may be 2, indicating that the address is hidden as 0; for yet another example, the target expected data corresponding to the target node randomize_va_space may be 2, indicating that the user space virtual address is randomized each time, and the randomization of the system-wide and address space is increased.
[0043] Therefore, after obtaining the first identification information, the target expected data of the target node can be determined based on the first identification information. For some embodiments, the target expected data of the target node can be determined based on a pre-established node table. Wherein, the node table may include at least one standard node of a security type, and the standard identification information corresponding to each standard node. The node table may also include the standard expected data corresponding to each standard node, so that the target expected data of the target node can be determined based on the node table through the first identification information. For a detailed introduction, reference can be made to the subsequent embodiments.
[0044] Step S130: Write the target expected data to the target node.
[0045] In some embodiments, after obtaining the target expected data, the target expected data can be directly written to the target node, thereby completing the writing operation of the target node of the security type in the kernel space of the electronic device.
[0046] Optionally, it can also be first determined whether the target expected data is the same as the data to be written corresponding to the writing operation. If they are not the same, the target expected data can be written to the target node; if they are the same, the data to be written can be directly written to the target node. For a detailed introduction, reference can be made to the subsequent embodiments.
[0047] The kernel protection method provided by this application, in the case of detecting a write operation on a target node of a secure type in the kernel space of the electronic device, obtains the first identification information of the target node; then determines the target expected data of the target node based on the first identification information; and then writes the target expected data to the target node. If only different levels of user permissions are divided to restrict the operations of lower-level user permissions on nodes of the secure type in the kernel space, without restricting the writes of higher-level user permissions to nodes of the secure type in the kernel space, malicious programs may illegally obtain higher-level permissions, and thus can write to nodes of the secure type. In this application, however, in the case of detecting a write operation on a target node of a secure type in the kernel space, the target expected data corresponding to the target node is actively obtained and written to the target node, so as to ensure that the target node is the target expected data and will not be modified by malicious programs into other data, preventing malicious programs from modifying the target nodes of the secure type in the kernel space and achieving a relatively strong degree of protection for the kernel.
[0048] Please refer to Figure 2 , Figure 2 which shows a flowchart of a kernel protection method provided by an embodiment of this application. This kernel protection method can be applied to an electronic device, specifically to the processor of the electronic device. This kernel protection method specifically includes steps S210 to S290.
[0049] Step S210: Obtain the operation type of the operation to be executed and the node type of the node to be operated corresponding to the operation to be executed. The operation to be executed includes an operation on the kernel space. The operation type includes a read operation or a write operation, and the node type includes a secure type and a non-secure type.
[0050] In some embodiments, different nodes included in the kernel space may correspond to different kernel entries. Please refer to Figure 3 , Figure 3 which shows a schematic diagram of the kernel entries corresponding to the kernel space nodes provided by an embodiment of this application. Figure 3 The kernel space in [reference] includes a first kernel entry 310, a second kernel entry 320, and a third kernel entry 330.
[0051] Among them, after the parameters corresponding to the operations to be executed for different nodes enter the kernel space through the kernel entry, they will all pass through the specified function 340, and the specified function 340 can be a function that the data output through each kernel entry passes through. Thus, in the embodiment provided in the present application, the kprobe function 350 can be mounted at the specified function 340. Specifically, a Hook point 341 can be set at the specified function 340. When the parameters corresponding to different operations to be executed enter the kernel space through the kernel entry and reach this Hook point 341 during execution, they can jump to execute the mounted kprobe function 350, and then return to the Hook point 341 to execute the subsequent process after the execution is completed. Exemplarily, the specified function 340 can be the proc_dointvec_minmax function. Among them, Hook points are usually used to extend the functions of functions or perform custom processing during the function running process. Hook points can be set at various levels or links of function execution to achieve different functions.
[0052] Exemplarily, for Hook points and different nodes, please refer to Table 1 below.
[0053] Table 1
[0054]
[0055]
[0056] As can be seen from Table 1, the Hook points corresponding to each different node are all the proc_dointvec_minmax function.
[0057] From the foregoing introduction, it can be known that the protection of the target node can be performed only when a write operation on the target node of the security type in the kernel space of the electronic device is detected. Therefore, the operation type of the operation to be executed and the node type of the node to be operated corresponding to the operation to be executed can be obtained based on the pre-configured kprobe function. Among them, the kprobe function is a dynamic probing tool that can provide a debugging mechanism and can flexibly track the execution of functions in the kernel space without modifying the existing code. The Kprobe function can register a probe point, and when the execution reaches this probe point, it will call and execute the user-defined function to monitor, modify, or process some functions in the kernel space. In the embodiment provided in the present application, the probe point of the kprobe function is Figure 3 the Hook point 341 shown in
[0058] Among them, the to-be-executed operation includes an operation on the kernel space, the operation type includes a read operation or a write operation, and the node type includes a security type and a non-security type. The to-be-operated node is the node to be operated in the kernel space corresponding to the to-be-executed operation. Exemplarily, the to-be-executed operation may be an operation on sysctl. Similar to the write operation in the foregoing embodiment, the to-be-executed operation may be created by a process in the electronic device.
[0059] The implementation manner provided by this application realizes the protection of the target node in the kernel space by setting a Hook point to switch to the kprobe function, and does not damage the Kernel Module Integrity (KMI). Therefore, the implementation manner provided by this application meets the requirements of The Generic Kernel Image (GKI), and can be compatible with many Linux versions, and can be conveniently deployed to devices that support the Generic Kernel Image 2.0 standard, and has good compatibility.
[0060] Among them, step S210 may further include steps S211 to S213.
[0061] Step S211: When detecting the to-be-executed operation, determine the operation type of the to-be-executed operation based on the specified parameter corresponding to the to-be-executed operation.
[0062] Step S212: Obtain the second identification information of the to-be-operated node.
[0063] Step S213: Based on the second identification information and the pre-obtained node table, determine the node type, where the node table includes at least one standard node of the security type and the standard identification information corresponding to each standard node.
[0064] For some implementation manners, when detecting the to-be-executed operation, the operation type of the to-be-executed operation may be determined based on the specified parameter corresponding to the to-be-executed operation. For example, the mapping relationship between the value and the operation type may be preset. For example, the operation type of the read operation is represented by 0, and the operation type of the write operation is represented by 1. Thus, the operation type of the to-be-executed operation can be determined by the specified parameter corresponding to the to-be-executed operation. For example, when the specified parameter is 0, it indicates that the operation type of the to-be-executed operation is a read operation; when the specified parameter is 1, it indicates that the operation type of the to-be-executed operation is a write operation.
[0065] Exemplarily, when the operation to be executed reaches the Hook point, it is necessary to jump to execute the kprobe function corresponding to the Hook point. Specifically, the parameters corresponding to the operation to be executed can be first stored in the pt_regs register, and during the execution of the kprobe function, the parameters corresponding to the operation to be executed can be obtained from the kprobe function. In some embodiments, the parameters corresponding to the operation to be executed can be stored in the pt_regs register in sequence.
[0066] Thus, the parameter stored in pt_regs[1] can be used as the specified parameter. Among them, the parameter stored in pt_regs[1] can be used to characterize whether the type of the operation to be executed is a read operation or a write operation. Specifically, it can be represented by 0 that the operation type of the operation to be executed is a read operation, and it can be represented by 1 that the operation type of the operation to be executed is a write operation. Therefore, the operation type of the operation to be executed can be determined by the parameter stored in pt_regs[1].
[0067] Furthermore, the second identification information of the node to be operated can also be obtained; thus, based on the second identification information and the pre-obtained node table, the node type can be determined. The node table includes at least one standard node of a security type and the corresponding standard identification information of each standard node. Among them, the second identification information can be used to represent the identity of the node to be operated.
[0068] Exemplarily, the parameter stored in pt_regs[0] in the pt_regs register can be used to represent the identity of the node to be operated, that is, the second identification information. For some embodiments, the ctl_table structure can be restored from pt_regs[0], and the proname member in the ctl_table structure can record the second identification information. Then, based on the second identification information and the node table, the node type can be determined.
[0069] Specifically, when executing step S213, steps S2131 to S2133 can also be included.
[0070] Step S2131: Determine whether the standard identification information identical to the second identification information is included in the node table.
[0071] Step S2132: If it is included, determine that the node type is a secure node.
[0072] Step S2133: If it is not included, determine that the node type is a non-secure node.
[0073] From the foregoing introduction, it can be seen that the node table includes at least one standard node of a security type and the corresponding standard identification information of each standard node. Exemplarily, please refer to Table 2 below.
[0074] Table 2
[0075]
[0076]
[0077] As can be seen from Table 2, Table 2 includes 10 standard nodes of security types and standard identification information corresponding to each of the standard nodes. Among them, each standard identification information includes a name and a path.
[0078] Further, after obtaining the second identification information, it can be determined whether the node table includes standard identification information identical to the second identification information. If it includes, it can be determined that the node type is a security node; if it does not include, it can be determined that the node type is a non-security node.
[0079] Exemplarily, if the second identification information includes the name unprivileged_userfaultfd and the path / proc / sys / vm, it can be determined that the node type is a security node.
[0080] Step S220: Determine whether the operation type is a write operation and whether the node type is a security type.
[0081] Further, it can be determined whether the operation type is a write operation and whether the node type is a security type. If so, it can jump to execute Step S230; if not, it can jump to execute Step S240.
[0082] It should be noted that if not, it can include that the operation type is a write operation and the node type is a non-security type; the operation type is a read operation and the node type is a security type; the operation type is a read operation and the node type is a non-security type.
[0083] Step S230: If the operation type is a write operation and the node type is a security type, it is determined that a write operation to the target node of the security type in the kernel space of the electronic device is detected.
[0084] If the operation type is a write operation and the node type is a security type, it is determined that a write operation to the target node of the security type in the kernel space of the electronic device is detected. At this time, it can jump to execute Step S250 to protect the target node in the kernel space.
[0085] Step S240: If not, it is determined that a write operation to the target node of the security type in the kernel space of the electronic device is not detected.
[0086] In the case where the result determined in step S220 is negative, it can be determined that a write operation to the target node of the security type in the kernel space of the electronic device has not been detected. Subsequently, the pending operation node corresponding to the pending operation may not be protected.
[0087] Step S250: In the case where a write operation to the target node of the security type in the kernel space of the electronic device is detected, obtain the first identification information of the target node.
[0088] In the case where a write operation to the target node of the security type in the kernel space of the electronic device is detected, the aforementioned pending operation node is the target node, so that the second identification information corresponding to the aforementioned pending operation node can be used as the first identification information of the target node.
[0089] Step S260: Determine the target expected data of the target node based on the first identification information.
[0090] In some embodiments, each standard node in the node table may also correspond to standard expected data. Please continue to refer to Table 2 above. For example, the standard expected data corresponding to the standard node ftrace_dump_on_oops is 0; the standard expected data corresponding to the standard node unprivileged_bpf_disabled is 1, etc.
[0091] Thus, after obtaining the first identification information, the target expected data of the target node can be determined based on the node table and the first identification information. Specifically, step S260 may further include steps S261 and S262.
[0092] Step S261: Determine the standard identification information identical to the first identification information in the node table as the target standard identification information.
[0093] Step S262: Obtain the standard expected data corresponding to the target standard identification information as the target expected data.
[0094] The standard identification information identical to the first identification information can be found in the node table as the target standard identification information.
[0095] Exemplarily, taking Table 2 above as the node table for further illustration, if the name of the first identification information is ftrace_dump_on_oops and the path is / proc / sys / kernel, it can be determined by looking up the node table that the standard node with the serial number 1 in Table 2 is the same as the first identification information, so that the standard identification information corresponding to the standard node with the serial number 1 can be determined as the target standard identification information.
[0096] Further, obtain the standard expected data corresponding to the target standard identification information through the node table as the target expected data. That is to say, the standard expected data 0 corresponding to the standard node with the serial number 1 can be used as the target expected data.
[0097] Step S270: Obtain the data to be written corresponding to the write operation.
[0098] In some embodiments, the data to be written corresponding to the write operation can be obtained.
[0099] Step S271: Determine whether the data to be written is the same as the target expected data.
[0100] If they are the same, step S290 can be jumped to and executed; if they are different, step S280 can be jumped to and executed.
[0101] As can be seen from the foregoing introduction, the parameters of the write operation to be performed can be stored in the pt_regs register shown above. Thus, the data to be written can be stored in pt_regs[2]. Subsequently, during the execution of the kprobe function, the data to be written corresponding to the write operation can be retrieved from pt_regs[2].
[0102] Step S280: If the data to be written is different from the target expected data, write the target expected data to the target node.
[0103] If the data to be written is different from the target expected data, it indicates that there may be a malicious program writing to the target node. At this time, pt_regs[2] can be modified and the target expected data can be assigned to pt_regs[2]. Subsequently, the target expected data can be written to the target node through the data stored in pt_regs[2].
[0104] Optionally, since it indicates that there may be a malicious program writing to the target node when the data to be written is different from the target expected data, the process that initiated the write operation can also be traced at this time. That is, the identity of the process that initiated the write operation can be determined.
[0105] Optionally, in combination with a Host-based Intrusion Detection System (HIDS), when the data to be written is different from the target expected data, the process that initiated the write operation can be collected in the form of data logging, providing possibilities for subsequent big data analysis.
[0106] Step S290: If the data to be written is the same as the target expected data, write the data to be written to the target node.
[0107] If the data to be written is the same as the target expected data, the target expected data does not need to be assigned to pt_regs[2], and the data stored in pt_regs[2] can be directly written to the target node.
[0108] In the embodiment of the present application, the corresponding kprobe function is jumped to and executed by inserting a Hook point, so as to realize the protection of the target node, and the additional consumed system resources are less, and the impact on the performance of the electronic device is almost negligible.
[0109] Optionally, the electronic device may also be configured with a device lock. When the device lock is in the locked state, the kernel protection method provided in the embodiment of the present application can be executed; when the device lock is in the unlocked state, the kernel protection method provided in the embodiment of the present application may not be executed. Thus, specific test requirements or special requirements of users can be met.
[0110] The kernel protection method provided by the present application first obtains the operation type of the operation to be executed and the node type of the node to be operated corresponding to the operation to be executed; determines whether the operation type is a write operation and whether the node type is a security type; if the operation type is a write operation and the node type is a security type, it is determined that a write operation on the target node of the security type in the kernel space of the electronic device is detected; when a write operation on the target node of the security type in the kernel space of the electronic device is detected, the first identification information of the target node is obtained; the target expected data of the target node is determined based on the first identification information; the data to be written corresponding to the write operation is obtained; if the data to be written is different from the target expected data, the target expected data is written to the target node; if the data to be written is the same as the target expected data, the data to be written is written to the target node. The embodiment of the present application only needs to additionally consume less system resources to be able to protect the write operation on the target node, and can also trace the process that initiates the write operation.
[0111] Please refer to Figure 4 , Figure 4 shows a method flow chart of a kernel protection method provided by an embodiment of the present application. The kernel protection method can be applied to an electronic device, specifically, it can be applied to the processor of the electronic device. The kernel protection method specifically includes steps S310 to S3110.
[0112] Step S310: The user space executes the operation to be executed on the node to be operated in the kernel space through sysctl.
[0113] Among them, the operation to be executed can be created by a process of the electronic device. For some embodiments, the electronic device may include a user space, a kernel space, and a hardware space, where the kernel space is respectively connected to the user space and the hardware space. The nodes in the kernel space can be operated through sysctl, so as to create an operation to be executed in the user space through a process to operate on the nodes to be operated in the kernel space. For a detailed introduction, reference can be made to the foregoing embodiments, which will not be elaborated here.
[0114] Step S320: Enter the kernel space.
[0115] The operation to be executed can enter the kernel space through the kernel entry.
[0116] Step S330: Execute to the proc_dointvec_minmax function and detect the Hook point.
[0117] A Hook point is pre-set at the proc_dointvec_minmax function, so that when the operation to be executed reaches the proc_dointvec_minmax function, the Hook point can be detected. Among them, the Hook point can be used to make the operation to be executed jump to the kprobe function.
[0118] Step S340: Store the parameters corresponding to the operation to be executed in the pt_regs register, and then jump to the kprobe function.
[0119] After detecting the Hook point, the parameters corresponding to the operation to be executed can be first stored in the pt_regs register, and then jump to the kprobe function. Thus, in the subsequent process of executing the kprobe function, the parameters corresponding to the operation to be executed can be directly retrieved from the pt_regs register.
[0120] Step S350: Obtain the parameters stored in pt_regs[0], pt_regs[1], and pt_regs[2] from the pt_regs register respectively.
[0121] In the process of executing the kprobe function, the parameters corresponding to the operation to be executed can be retrieved from the pt_regs register. Specifically, the parameters stored in pt_regs[0], pt_regs[1], and pt_regs[2] can be obtained from the pt_regs register respectively.
[0122] Step S360: Determine whether the operation type of the operation to be executed is a write operation according to the parameter stored in pt_regs[1].
[0123] Among them, the parameter stored in pt_regs[1] can be used to characterize whether the type of the to-be-executed operation is a read operation or a write operation. Therefore, it is possible to determine whether the type of the to-be-executed operation is a write operation according to the parameter stored in pt_regs[1]. When it is determined that the operation type is a write operation, step S370 can be jumped to for execution; when it is determined that the operation type is a read operation, step S3110 can be jumped to for execution.
[0124] Step S370: Determine whether the node type corresponding to the to-be-executed operation is a security type according to the parameter stored in pt_regs[0].
[0125] Among them, the parameter stored in pt_regs[0] can be used to characterize the identity of the to-be-operated node, that is, the second identification information in the foregoing embodiment. Thus, based on the second identification information and the node table, it is possible to determine whether the node type is a security type. When it is determined that the node type is a security type, step S380 can be jumped to for execution; when it is determined that the node type is a non-security type, step S3110 can be jumped to for execution.
[0126] Step S380: Determine whether the to-be-executed data corresponding to the to-be-executed operation is the same as the target expected data corresponding to the to-be-operated node according to pt_regs[2].
[0127] Furthermore, pt_regs[2] can be used to store the to-be-written data corresponding to the to-be-executed operation. Thus, it is possible to determine whether the to-be-executed data corresponding to the to-be-executed operation is the same as the target expected data corresponding to the to-be-operated node according to pt_regs[2]. When they are the same, step S3110 can be jumped to for execution; when they are different, step S390 can be jumped to for execution. Among them, the target expected data can be determined in advance based on the node table. For a detailed introduction, reference can be made to the introduction in the foregoing embodiment, which will not be elaborated here.
[0128] Step S390: Write the target expected data into pt_regs[2].
[0129] When the to-be-executed data is different from the target expected data corresponding to the to-be-operated node, the target expected data can be written into pt_regs[2].
[0130] Step S3100: After the kprobe function is executed, take out the parameter stored in pt_regs and return to continue executing the proc_dointvec_minmax function.
[0131] Step S3110: Write the parameter stored in pt_regs[2] to the target node.
[0132] Subsequently, the parameters stored in pt_regs can be retrieved, and the target expected data stored in t_regs[2] is written to the node to be operated. When the target expected data is written to pt_regs[2] in the foregoing steps, the parameter stored in pt_regs[2] at this time is the target expected parameter; when the target expected data is not written to pt_regs[2] in the foregoing steps, the parameter stored in pt_regs[2] at this time is the data to be executed corresponding to the operation to be executed.
[0133] It should be noted that when it is determined that the operation type is a write operation and the node type corresponding to the operation to be executed is a security type, the node to be operated is the target node in the foregoing embodiments. Therefore, writing the target expected data to the node to be operated is essentially writing the target expected data to the target node. For a detailed introduction, reference can be made to the foregoing embodiments, which will not be elaborated here.
[0134] Please refer to Figure 5 , Figure 5 FIG. shows a structural block diagram of a kernel protection device 500 provided by an embodiment of the present application, which is applied to an electronic device. The kernel protection device 500 includes: a detection unit 510, a determination unit 520, and a writing unit 530.
[0135] The detection unit 510 is configured to obtain the first identification information of the target node when detecting a write operation on the target node of the security type in the kernel space of the electronic device.
[0136] Optionally, the detection unit 510 may also be configured to obtain the operation type of the operation to be executed and the node type of the node to be operated corresponding to the operation to be executed. The operation to be executed includes an operation on the kernel space. The operation type includes a read operation or a write operation, and the node type includes a security type and a non-security type; determine whether the operation type is a write operation and whether the node type is a security type; if the operation type is a write operation and the node type is a security type, it is determined that a write operation on the target node of the security type in the kernel space of the electronic device is detected.
[0137] Optionally, the detection unit 510 may also be configured to, when detecting an operation to be executed, determine the operation type of the operation to be executed based on the specified parameters corresponding to the operation to be executed; obtain the second identification information of the node to be operated; and determine the node type based on the second identification information and a pre-obtained node table. The node table includes at least one standard node of the security type and the standard identification information corresponding to each standard node.
[0138] Optionally, the detection unit 510 can also be used to determine whether the node table includes standard identification information that is the same as the second identification information; if it does, it is determined that the node type is a secure node; if it does not, it is determined that the node type is a non-secure node.
[0139] Optionally, the detection unit 510 can also be used to determine the standard identification information in the node table that is the same as the first identification information as the target standard identification information; and obtain the standard expected data corresponding to the target standard identification information as the target expected data.
[0140] The determination unit 520 is configured to determine the target expected data of the target node based on the first identification information.
[0141] Optionally, the determination unit 520 can also be used to obtain the operation type of the operation to be performed and the node type of the node to be operated corresponding to the operation to be performed based on a pre-configured kprobe function.
[0142] The writing unit 530 is configured to write the target expected data to the target node.
[0143] Optionally, the writing unit 530 can also be used to obtain the data to be written corresponding to the write operation; if the data to be written is different from the target expected data, then write the target expected data to the target node.
[0144] Optionally, the writing unit 530 can also be used to write the data to be written to the target node if the data to be written is the same as the target expected data.
[0145] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described devices and units can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0146] In several embodiments provided in the present application, the coupling between units can be electrical, mechanical, or other forms of coupling. Additionally, in each embodiment of the present application, the various functional units can be integrated in one processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0147] Please refer to Figure 6 , Figure 6 which shows a schematic diagram of applying the kernel method provided in the embodiments of the present application to an electronic device. Figure 6An electronic device 600 is shown, where the electronic device 600 includes a user space 610, a kernel space 620, and a hardware space 630. The kernel space 620 is respectively connected to the user space 610 and the hardware space 630.
[0148] Among them, the user space 610 can achieve communication with the kernel space 620 through system calls. The kernel protection method proposed in this application can be executed on the system calls sent from the user space 610 to the kernel space 620. Among them, the system calls can be triggered by the to-be-executed operations in the foregoing embodiments. The kernel space 620 may further include sysctl 621. Sysctl 621 may include multiple types of nodes, a part of the nodes are non-secure type nodes, and the other part are secure type nodes.
[0149] Thus, for the system calls executed by sysctl 621 in the kernel space 620, the execution can be transferred to the kprobe function 650 by setting a Hook point, and then steps S691 to S693 are executed in the kprobe function 650.
[0150] Step S691: Determine whether the operation type is a write operation and whether the node type is a secure type.
[0151] Step S692: If the operation type is a write operation and the node type is a secure type, it is determined that a write operation to the target node of the secure type in the kernel space of the electronic device is detected.
[0152] Step S693: If the data to be written is different from the target expected data, assign the target expected data to pt_regs[2].
[0153] Among them, the relevant introductions of steps S691 to S693 can refer to the foregoing embodiments and will not be elaborated here.
[0154] Please refer to Figure 7 , Figure 7 , which shows a structural block diagram of an electronic device 700 provided by an embodiment of the present application. The electronic device 700 may be a smart phone, a laptop computer, a desktop computer, a tablet computer, etc. The electronic device 700 in the present application may include one or more of the following components: a processor 711, a memory 712, and one or more application programs, where the processor 711 is electrically connected to the memory 712, and the one or more programs are configured to execute the methods described in the foregoing embodiments of the kernel protection method.
[0155] Among them, the processor 711 may include one or more processing cores. The processor 711 connects various parts within the entire electronic device 700 through various interfaces and lines. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 712, and by invoking the data stored in the memory 712, it executes various functions of the electronic device 700 and processes data. Optionally, the processor 711 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 711 may integrate a combination of one or several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, computer programs, etc.; the GPU is responsible for the rendering and drawing of display content; the modem is used to process wireless communication. It can be understood that the above-mentioned modem may not be integrated into the processor 711 and may be implemented separately through a communication chip. Specifically, the above-described method may be executed by one or more processors 711.
[0156] For some embodiments, the memory 712 may include random access memory (RAM) and may also include read-only memory. The memory 712 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 712 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for implementing at least one function, instructions for implementing the following various method embodiments, etc. The data storage area may also store data created during the use of the electronic device 700.
[0157] Please refer to Figure 8 , which shows a structural block diagram of a computer-readable storage medium provided by an embodiment of the present application. Program code is stored in the computer-readable medium 800, and the program code can be called by a processor to execute the method described in the above method embodiments.
[0158] The computer-readable storage medium 800 can be an electronic memory such as a flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, a hard disk, or a ROM. Optionally, the computer-readable storage medium 800 includes a non-transitory computer-readable storage medium. The computer-readable storage medium 800 has a storage space for program code 810 that executes any of the method steps in the above-described methods. These program codes can be read from or written to one or more computer program products. The program code 810 can be compressed in a suitable form, for example.
[0159] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A kernel protection method, characterized in that, applied to an electronic device, the method includes: When detecting a write operation on a target node of a security type in the kernel space of the electronic device, obtaining first identification information of the target node; Determining target expected data of the target node based on the first identification information; Writing the target expected data to the target node.
2. The method according to claim 1, characterized in that, Before the step of obtaining the first identification information of the target node when detecting a write operation on a target node of a security type in the kernel space of the electronic device, the method further includes: Obtaining an operation type of an operation to be executed and a node type of a node to be operated corresponding to the operation to be executed, the operation to be executed includes an operation on the kernel space, the operation type includes a read operation or a write operation, and the node type includes a security type and a non - security type; Judging whether the operation type is a write operation and whether the node type is a security type; If the operation type is a write operation and the node type is a security type, it is determined that a write operation on a target node of a security type in the kernel space of the electronic device is detected.
3. The method according to claim 2, characterized in that, The step of obtaining the operation type of the operation to be executed and the node type of the node to be operated corresponding to the operation to be executed includes: When detecting an operation to be executed, determining the operation type of the operation to be executed based on a specified parameter corresponding to the operation to be executed; Obtaining second identification information of the node to be operated; Based on the second identification information and a pre - obtained node table, determining the node type, where the node table includes at least one standard node of a security type and standard identification information corresponding to each standard node.
4. The method according to claim 3, characterized in that, The step of determining the node type based on the second identification information and the pre - obtained node table includes: Determining whether the node table includes standard identification information identical to the second identification information; If it includes, determining that the node type is a security node; If it does not include, determining that the node type is a non - security node.
5. The method according to claim 3, characterized in that, The node table further includes standard expected data corresponding to the standard node, and the step of determining the target expected data of the target node based on the first identification information includes: Determining the standard identification information identical to the first identification information in the node table as target standard identification information; Obtaining the standard expected data corresponding to the target standard identification information as the target expected data.
6. The method according to claim 2, characterized in that, The step of obtaining the operation type of the operation to be executed and the node type of the node to be operated corresponding to the operation to be executed includes: Obtaining the operation type of the operation to be executed and the node type of the node to be operated corresponding to the operation to be executed based on a pre - configured kprobe function.
7. The method according to claim 1, characterized in that, Writing the target expected data to the target node includes: Obtaining the data to be written corresponding to the write operation; If the data to be written is different from the target expected data, writing the target expected data to the target node.
8. The method according to claim 7, wherein, the method further includes: If the data to be written is the same as the target expected data, writing the data to be written to the target node.
9. A kernel protection device, wherein, applied to an electronic device, the device includes: A detection unit, configured to obtain first identification information of the target node when detecting a write operation on a target node of a secure type in the kernel space of the electronic device; A determination unit, configured to determine the target expected data of the target node based on the first identification information; A writing unit, configured to write the target expected data to the target node.
10. An electronic device, wherein, includes: One or more processors; A memory; One or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1-8.
11. A computer-readable storage medium, wherein, program code is stored in the computer-readable storage medium, and the program code can be called by a processor to execute the method according to any one of claims 1-8.