Industrial host protection method and system based on trusted chain

By introducing dynamic trusted chains in industrial host protection and establishing static and dynamic trusted file libraries, the problem of high operation and maintenance costs of traditional whitelist mechanisms is solved, and the security protection and operation and maintenance efficiency of industrial hosts is improved.

CN120180512APending Publication Date: 2025-06-20CHINA NUCLEAR POWER OPERATION TECH CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311756825.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-20
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The traditional whitelisting mechanism has high operation and maintenance costs in the security protection of industrial hosts and industrial software, especially when business changes frequently and operating systems and industrial software upgrades, the whitelist needs to be frequently rescanned, which increases the burden of operation and maintenance work.

Method used

By introducing the concept of dynamic trusted chain, a static trusted file library and a dynamic trusted file library are established. The static trusted file list is used as the trusted root. The created and modified files are automatically added to the dynamic trusted file list to realize the management of dynamic whitelists.

Benefits of technology

This not only ensures the safety of industrial hosts, but also avoids the operation and maintenance costs brought by the traditional whitelisting mechanism and improves the operation and maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180512A_ABST
    Figure CN120180512A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of information security, and particularly relates to an industrial host protection method and system based on a trusted chain. Establishing a static credible file library for storing static credible files; a dynamic trusted file library is established based on the static trusted file library and used for storing dynamic trusted files, and the dynamic trusted files are established based on the static trusted files or the dynamic trusted files stored in the dynamic trusted file library; and obtaining a to-be-executed file, and performing release judgment on the to-be-executed file based on the static trusted file library and the dynamic trusted file library. According to the method, the dynamic trusted chain is introduced, the static trusted file list is used as the trusted root, and the file created and modified by the trusted root can be automatically added into the dynamic trusted file list, so that the safety of the industrial host is ensured, and the operation and maintenance cost caused by a traditional white list mechanism is also avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to an industrial host protection method and system based on a trusted chain. Background Art

[0002] Industrial hosts and industrial software are the keys connecting the physical world and the digital world. Once the security of industrial hosts and industrial software is threatened, the entire industrial production will be affected. Due to mechanism problems, traditional antivirus software cannot well solve industrial control security problems. For example, in old hosts, the virus database cannot be updated in time, and there are problems such as false positives affecting production. In the field of industrial security, lightweight whitelist solutions are usually adopted. The specific solutions are as follows: A full - disk scan is performed on a clean and secure environment to form a whitelist list. After the whitelist is solidified, only trusted programs in the whitelist can run, and the running of all other programs will be intercepted. The whitelist mechanism greatly protects the security of industrial hosts and industrial production. However, the use of the whitelist mechanism requires a prerequisite: the business is fixed, and the program whitelist does not need to be frequently changed. Otherwise, it will increase the burden of operation and maintenance work. Common operation and maintenance problems include: After the operating system is upgraded, the whitelist needs to be scanned again; after industrial software is upgraded, the whitelist needs to be scanned again; files dynamically generated by industrial software will be intercepted. Summary of the Invention

[0003] The purpose of the present invention is to provide an industrial host protection method and system based on a trusted chain. By introducing a dynamic trusted chain and using a static trusted file list as the trusted root, files created and modified by the trusted root can be automatically added to the dynamic trusted file list (dynamic whitelist), which not only ensures the security of industrial hosts but also avoids the operation and maintenance costs brought by the traditional whitelist mechanism.

[0004] To achieve the above - mentioned purpose, the technical solutions adopted by the present invention are as follows:

[0005] An industrial host protection method based on a trusted chain includes establishing a static trusted file library for storing static trusted files; establishing a dynamic trusted file library based on the static trusted file library for storing dynamic trusted files, and the dynamic trusted files are established based on static trusted files or dynamic trusted files already stored in the dynamic trusted file library; obtaining a file to be executed, and making a judgment on whether to release the file to be executed based on the static trusted file library and the dynamic trusted file library.

[0006] Establishing the static trusted file library includes: obtaining a set of original executable files, and establishing a static trusted file library based on the set of original executable files, where the original executable files are any executable files, including executable script files.

[0007] The static trusted files are stored in the static trusted database in a hash - index manner.

[0008] Building a dynamic trusted file library based on a static trusted file library includes: obtaining a created or modified file, determining whether the parent file of the file is a static trusted file, and if so, adding the created or modified file to the dynamic trusted file library; when the created or modified file is not a static trusted file, determining whether the parent file of the created or modified file is a dynamic trusted file, and if so, adding the created or modified file to the dynamic trusted file library, otherwise, intercepting the parent file of the created or modified file.

[0009] A dynamic trusted file is a file created or modified during the execution of a static trusted file or other dynamic trusted files.

[0010] It also includes associating a dynamic trusted file with its corresponding parent file to generate a dynamic trusted propagation chain.

[0011] Making a release judgment on a file to be executed includes: determining whether the file to be executed is a static trusted file, and if so, releasing the file to be executed.

[0012] Making a release judgment on a file to be executed includes: when it is determined that the file to be executed is not a static trusted file, determining whether the file to be executed is a dynamic trusted file, and if so, releasing the file to be executed, otherwise, intercepting the file to be executed.

[0013] An industrial host protection system based on a trusted chain includes:

[0014] A static trusted file library building module for building a static trusted file library, which is used to store static trusted files;

[0015] A dynamic trusted file library building module for building a dynamic trusted file library based on the static trusted file library, which is used to store dynamic trusted files;

[0016] An execution module for obtaining a file to be executed and making a release judgment on the file to be executed based on the static trusted file library and the dynamic trusted file library.

[0017] A dynamic trusted file is established based on a static trusted file or a dynamic trusted file already stored in the dynamic trusted file library.

[0018] The beneficial effects obtained by the present invention are:

[0019] The present invention first establishes a static trusted file library and a dynamic trusted file library, and then obtains the file to be executed. Based on the static trusted file library and the dynamic trusted file library, a release judgment of the file to be executed is made. By introducing the concept of a dynamic trusted chain, using the static trusted file list (static whitelist) as the trusted root, the files created and modified by the trusted root are automatically added to the dynamic trusted file list (dynamic whitelist), which not only ensures the security of the industrial host but also avoids the operation and maintenance costs brought by the traditional whitelist mechanism. Description of the Drawings

[0020] Figure 1 It is a schematic diagram for the maintenance of the dynamic trusted file library;

[0021] Figure 2 It is a schematic diagram for the use of the dynamic trusted file library. Detailed Embodiment

[0022] The present invention will be described in detail below with reference to the drawings and specific embodiments.

[0023] The present invention provides an industrial host protection method based on a trusted chain, including the following steps:

[0024] Establish a static trusted file library, where the static trusted file library is used to store static trusted files;

[0025] Based on the static trusted file library, establish a dynamic trusted file library, where the dynamic trusted file library is used to store dynamic trusted files, and the dynamic trusted files are established based on the static trusted files or the dynamic trusted files already stored in the dynamic trusted file library;

[0026] Obtain the file to be executed, and based on the static trusted file library and the dynamic trusted file library, make a release judgment on the file to be executed.

[0027] Preferably, the establishment of the static trusted file library includes:

[0028] Obtain the set of original executable files, and establish the static trusted file library based on the set of original executable files, where the original executable files are any executable files including executable script files.

[0029] Preferably, the static trusted files are stored in the static trusted database in a hash index manner.

[0030] Preferably, the establishment of the dynamic trusted file library based on the static trusted file library includes:

[0031] Obtain the created or modified file, and determine whether the parent file of the file is a static trusted file. If so, add the created or modified file to the dynamic trusted file library;

[0032] When the created or modified file is not a static trusted file, determine whether the parent file of the created or modified file is a dynamic trusted file. If so, add the created or modified file to the dynamic trusted file library; otherwise, intercept the parent file of the created or modified file.

[0033] Further, the dynamic trusted file is a file created or modified during the execution of the static trusted file or other dynamic trusted files.

[0034] Preferably, the method further includes:

[0035] Associate the dynamic trusted file with its corresponding parent file to generate a dynamic trusted propagation chain.

[0036] Preferably, the obtaining of the file to be executed and the determination of whether to release the file to be executed based on the static trusted file library and the dynamic trusted file library include:

[0037] Obtain the file to be executed, and determine whether the file to be executed is a static trusted file. If so, release the file to be executed;

[0038] When it is determined that the file to be executed is not a static trusted file, determine whether the file to be executed is a dynamic trusted file. If so, release the file to be executed; otherwise, intercept the file to be executed.

[0039] An industrial host protection system based on a trusted chain, comprising:

[0040] A static trusted file library establishment module, configured to establish a static trusted file library, wherein the static trusted file library is used to store static trusted files;

[0041] A dynamic trusted file library establishment module, based on the static trusted file library, establishes a dynamic trusted file library, wherein the dynamic trusted file library is used to store dynamic trusted files, and the dynamic trusted files are established based on the static trusted files or the dynamic trusted files already stored in the dynamic trusted file library;

[0042] An execution module, configured to obtain the file to be executed, and based on the static trusted file library and the dynamic trusted file library, perform a determination on whether to release the file to be executed.

[0043] The present invention provides an industrial host protection method based on a trusted chain, comprising the following steps:

[0044] S100. Establish a static trusted file library, where the static trusted file library is used to store static trusted files;

[0045] S200. Based on the static trusted file library, establish a dynamic trusted file library, where the dynamic trusted file library is used to store dynamic trusted files, and the dynamic trusted files are established based on the static trusted files or the dynamic trusted files already stored in the dynamic trusted file library;

[0046] S300. Obtain the file to be executed, and based on the static trusted file library and the dynamic trusted file library, perform a release judgment on the file to be executed.

[0047] In this embodiment, first, a static trusted file library storing static trusted files is established. Then, a dynamic trusted file library storing dynamic trusted files is established, and the dynamic trusted files are established based on the static trusted files or the dynamic trusted files already stored in the dynamic trusted file library. Finally, the file to be executed is obtained, and based on the static trusted file library and the dynamic trusted file library, a release judgment on the file to be executed is performed. By introducing the concept of a dynamic trusted chain, using the static trusted file list (static whitelist) as the trusted root, the files created and modified by the trusted root are automatically added to the dynamic trusted file list (dynamic whitelist), which not only ensures the security of the industrial host but also avoids the operation and maintenance costs brought by the traditional whitelist mechanism.

[0048] In some embodiments, the step S100 is used to establish a static trusted file library, and the static trusted files are safe and clean files that can be executed. Optionally, the step S100 specifically includes:

[0049] Obtain a set of original executable files, and establish the static trusted file library based on the set of original executable files, where the original executable files are any executable files including executable script files.

[0050] In this embodiment, the static trusted file library is a lightweight database, and the set of original executable files is the set of all safe and clean files when the system leaves the factory. Therefore, the static trusted file library is the basic whitelist library, and all files in the static trusted file library can be executed. Among them, the file type of the static trusted files in this application embodiment is not limited. Preferably, the static trusted files can be of any file type. Exemplarily, the static trusted files can be EXE files, DLL files, COM files, OCX files, BAT files, Office documents, PDF files, JS files, MSI files, VBScript files, Python files, Powershell files, etc.

[0051] Further, when obtaining the set of original executable files, the industrial host can be scanned comprehensively at the time of factory shipment, and all the scanned files are regarded as original executable files, and then the static trusted file library is established based on the set of such files.

[0052] In some embodiments, the static trusted files are stored in the static trusted database in a hash index manner.

[0053] In this embodiment, in order to facilitate the rapid search for static trusted files, the static trusted files are stored in the form of hash values. The file name, file path, and hash value of each file are stored in a hash list. The file can be quickly located by searching for the hash value or file path. Exemplarily, when searching for the file path, the corresponding hash value is calculated from the file name, and then the corresponding file path is found through the hash value, so as to quickly determine whether the file to be executed is a static trusted file, and then the file can be quickly released or blocked.

[0054] In some embodiments, the step S200 is used to establish a dynamic trusted file library. The files in the dynamic trusted file library are not the original executable files at the time of factory shipment, but are generated based on the original executable files or derivative files of the original executable files. Therefore, a trusted propagation chain can be formed, which can ensure the security of the industrial host while avoiding the operation and maintenance costs brought by the traditional whitelist mechanism.

[0055] Optionally, the step S200 specifically includes:

[0056] S210. Obtain the created or modified file, and determine whether the parent file of the file is a static trusted file. If so, add the created or modified file to the dynamic trusted file library;

[0057] S220. When the created or modified file is not a static trusted file, determine whether the parent file of the created or modified file is a dynamic trusted file. If so, add the created or modified file to the dynamic trusted file library; otherwise, intercept the parent file of the created or modified file.

[0058] In this embodiment, after a file is created or modified, the parent process of the file is judged, and based on the parent process of the process, it is judged whether the file can be added to the dynamic trusted file library. Exemplarily, after the file is created or modified, first judge whether the parent file of the file is a static trusted file. If so, the file can be directly added to the dynamic trusted file library. If not, it is necessary to judge whether the parent file of the file is a dynamic trusted file. If so, the file is added to the dynamic trusted file library. Otherwise, the parent file of the file will be intercepted.

[0059] In some embodiments, the dynamic trusted file is a file created or modified during the execution of the static trusted file or other dynamic trusted files.

[0060] In this embodiment, the dynamic trusted file is, in principle, a file created or modified during the execution of the static trusted file. Therefore, in order to ensure that the created or modified file is also trusted, the modification basis of the dynamic trusted file must be trusted. Therefore, after the dynamic trusted file is created, its parent file must be located in the dynamic trusted file library or the static trusted file library, so as to ensure that when the dynamic trusted file is executed, it will not affect the security of the industrial host and ensure the continuous progress of industrial production.

[0061] In some embodiments, the method further includes:

[0062] Associating the dynamic trusted file with its corresponding parent file to generate a dynamic trusted propagation chain.

[0063] In this embodiment, in order to prevent the created or modified file from being mistakenly added to the dynamic trusted file library, when the dynamic trusted file is generated, it is associated with its corresponding parent file to generate a dynamic trusted propagation chain for convenient subsequent traceability. Exemplarily, file A is a static trusted file, and file B is created through file A. Then file B will be added to the dynamic trusted file library and associated with file A, thus forming an initial trusted propagation chain A - B. After that, file C is created based on file B. Then file C is also dynamically trusted. Therefore, file C will also be added to the dynamic trusted file library and added to the trusted propagation chain to form the trusted propagation chain A - B - C, and so on, thus forming a trusted propagation chain that is convenient for traceability. When maintaining, if any node on the trusted propagation chain is found to be untrusted, all processes after that node are terminated.

[0064] In some embodiments, step S300 is used to perform an execution judgment on the file to be executed. If the judgment passes, it can be released. Otherwise, it will be intercepted. Optionally, the step S300 specifically includes:

[0065] Obtain the file to be executed, and determine whether the file to be executed is a static trusted file. If so, release the file to be executed;

[0066] When it is determined that the file to be executed is not a static trusted file, determine whether the file to be executed is a dynamic trusted file. If so, release the file to be executed; otherwise, intercept the file to be executed.

[0067] In this embodiment, after obtaining the file to be executed, it will be successively determined whether the file to be executed is a static trusted file or a dynamic trusted file, and based on the judgment result, it is determined whether the file is executable. Exemplarily, after a file is created or modified, first determine whether the file to be executed is a static trusted file. If so, release the file to be executed. If not, it is necessary to determine whether the file to be executed is a dynamic trusted file. If so, release it; otherwise, the file will be intercepted.

[0068] To better understand the present invention, the following gives a specific embodiment to detail the technical solution of the present invention:

[0069] Step 1: Obtain all the safe and clean file sets in the system when the system leaves the factory, and store the file sets in the static trusted file library to complete the establishment of the static trusted file library;

[0070] Step 2: Establish a dynamic trusted file library;

[0071] Step 3: Obtain the created or modified file, and determine whether the parent file of the created or modified file is a static trusted file or a dynamic trusted file. If so, add the created or modified file to the dynamic trusted file library; otherwise, intercept the parent file of the created or modified file;

[0072] Step 4: Obtain the file to be executed, and determine whether the file to be executed is a static trusted file. If not, execute Step 5; otherwise, execute Step 6;

[0073] Step 5: Determine whether the file to be executed is a dynamic trusted file. If not, execute Step 7; otherwise, execute Step 6;

[0074] Step 6: Release the file to be executed;

[0075] Step 7: Intercept the file to be executed.

[0076] In summary, the present application first establishes a static trusted file library storing static trusted files, then establishes a dynamic trusted file library storing dynamic trusted files, and the dynamic trusted files are established based on the static trusted files or the dynamic trusted files already stored in the dynamic trusted file library. Finally, the file to be executed is obtained, and based on the static trusted file library and the dynamic trusted file library, the release judgment of the file to be executed is performed. By introducing the concept of a dynamic trusted chain, using the static trusted file list (static whitelist) as the trusted root, the files created and modified by the trusted root are automatically added to the dynamic trusted file list (dynamic whitelist), which not only ensures the security of the industrial host but also avoids the operation and maintenance costs brought by the traditional whitelist mechanism.

Claims

1. An industrial host protection method based on a trusted chain, characterized in that: Establish a static trusted file library for storing static trusted files; Based on the static trusted file library, establish a dynamic trusted file library for storing dynamic trusted files. The dynamic trusted files are established based on the static trusted files or the dynamic trusted files already stored in the dynamic trusted file library; Obtain the file to be executed, and based on the static trusted file library and the dynamic trusted file library, perform a release judgment on the file to be executed.

2. The industrial host protection method based on a trusted chain according to claim 1, characterized in that: Establishing a static trusted file library includes: obtaining a set of original executable files, and establishing a static trusted file library based on the set of original executable files. The original executable files are any executable files, including executable script files.

3. The industrial host protection method based on a trusted chain according to claim 1, characterized in that: The static trusted files are stored in the static trusted database in the form of hash indexes.

4. The industrial host protection method based on a trusted chain according to claim 1, characterized in that: Establishing a dynamic trusted file library based on the static trusted file library includes: obtaining the created or modified file, determining whether the parent file of the file is a static trusted file. If so, add the created or modified file to the dynamic trusted file library; when the created or modified file is not a static trusted file, determine whether the parent file of the created or modified file is a dynamic trusted file. If so, add the created or modified file to the dynamic trusted file library, otherwise, intercept the parent file of the created or modified file.

5. The industrial host protection method based on a trusted chain according to claim 1, characterized in that: The dynamic trusted files are files created or modified during the execution of static trusted files or other dynamic trusted files.

6. The industrial host protection method based on a trusted chain according to claim 1, characterized in that: It also includes associating the dynamic trusted files with their corresponding parent files to generate a dynamic trusted propagation chain.

7. The industrial host protection method based on a trusted chain according to claim 1, characterized in that: Performing a release judgment on the file to be executed includes: determining whether the file to be executed is a static trusted file. If so, release the file to be executed.

8. The industrial host protection method based on a trusted chain according to claim 1, characterized in that: Performing a release judgment on the file to be executed includes: when it is determined that the file to be executed is not a static trusted file, determine whether the file to be executed is a dynamic trusted file. If so, release the file to be executed, otherwise intercept the file to be executed.

9. An industrial host protection system based on a trusted chain, characterized in that: Includes: A static trusted file library establishment module for establishing a static trusted file library, which is used to store static trusted files; A dynamic trusted file library establishment module that establishes a dynamic trusted file library based on the static trusted file library. The dynamic trusted file library is used to store dynamic trusted files; An execution module for obtaining the file to be executed and performing a release judgment on the file to be executed based on the static trusted file library and the dynamic trusted file library.

10. The industrial host protection system based on a trusted chain according to claim 9, characterized in that: The dynamic trusted files are established based on the static trusted files or the dynamic trusted files already stored in the dynamic trusted file library.