Real-time threat monitoring and defending method and system for digital infrastructure

By performing segmented processing of WASM modules and dynamic code and generating differentiated protection strategy, combining shadow stack technology and hardware accelerated verification, dynamic code isolation and adaptive security control are realized, and the contradiction between security and performance in the existing technology is solved, and a balance between high security and low performance overhead is achieved.

CN120200849AActive Publication Date: 2025-06-24ZHEJIANG COMM SERVICES
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510663019.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-06-24
Estimated Expiration
2045-05-22

AI Technical Summary

Technical Problem

Prior arts are difficult to maintain low performance overhead while ensuring high security, especially in critical digital infrastructure environments that require high real-time performance.

Method used

By segmenting the WASM module and dynamic code, differentiated protection strategies are generated, and combined with shadow stack technology and hardware accelerated verification, a two-layer control flow protection system is built to realize dynamic code isolation and permission control, and finally, an adaptive security control system is built to dynamically adjust the verification strategy.

Benefits of technology

Mathematically proven security is achieved, the success rate of control flow hijacking attacks is reduced to nearly zero, while the verification overhead is controlled below 5%, which is significantly lower than traditional methods, and is suitable for critical digital infrastructures with strict requirements on real-timeness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200849A_ABST
    Figure CN120200849A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computer network security, and discloses a digital infrastructure real-time threat monitoring and defending method and system.The method comprises the steps that a WASM module and a dynamic code module are segmented, codes are divided into a static segment, a performance key segment and a dynamic loading segment, and differential protection strategies are generated; a double-layer control flow protection system is constructed, and the security of function calling and returning is ensured in combination with a shadow stack technology and runtime verification; a hardware acceleration verification technology is utilized, verification is executed in parallel through a special core and a main application, and verification overhead is reduced; dynamic code isolation and authority control are realized, and the dynamically loaded code is prevented from executing border crossing operation and unauthorized access; and constructing a self-adaptive security control system, and dynamically adjusting a verification strategy according to the security sensitivity and the execution frequency of the code block. According to the method, comprehensive safety guarantee is provided with extremely low performance overhead, and the method is particularly suitable for key digital infrastructures with strict requirements for performance and safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer network security, and more specifically, it relates to a method and system for real-time threat monitoring and defense of digital infrastructure. Background Art

[0002] With the wide application of Web Assembly (WASM) modules and dynamic code loading technology in key digital infrastructures such as cloud computing, edge computing, Internet of Things gateways, financial trading systems, and industrial control networks, security risks have emerged continuously. Among them, Web Assembly is a virtual instruction set architecture (virtual ISA), and its overall architecture includes the definition of the core ISA, binary encoding, the definition and execution of program semantics, and application programming interfaces (Web Assembly APIs) for different embedded environments (such as the Web);

[0003] The existing security protection technologies have the following technical problems:

[0004] The WASM hybrid execution mode (coexistence of interpretation execution and JIT compilation) and dynamic module loading characteristics result in that traditional protection measures cannot fully cover all execution scenarios;

[0005] The existing stack protection technology and Address Space Layout Randomization (ASLR) can be bypassed by specific attack methods;

[0006] The static code analysis method has a high false alarm rate when dealing with dynamically loaded code, while the pure dynamic monitoring method brings significant performance overhead;

[0007] For key digital infrastructures with high real-time requirements, the runtime latency introduced by the existing control flow protection mechanism is unacceptable;

[0008] There is a lack of real-time and efficient verification capabilities for dynamically loaded code.

[0009] Therefore, a new technical solution is needed, which can maintain low performance overhead while ensuring high security and is applicable to the key digital infrastructure environment with strict real-time requirements. Summary of the Invention

[0010] The present invention provides a method and system for real-time threat monitoring and defense of digital infrastructure, which solves the technical problem of the contradiction between security and performance when dealing with dynamically loaded code in related technologies.

[0011] The present invention provides a method for real-time threat monitoring and defense of digital infrastructure, including the following steps:

[0012] Segment the WASM module and dynamic code module, divide the code into static segments, performance-critical segments, and dynamically loaded segments, and generate differentiated protection policies;

[0013] Build a two-layer control flow protection system, combine shadow stack technology with runtime verification to ensure the security of function calls and returns;

[0014] Utilize hardware-accelerated verification technology, perform verification in parallel with a dedicated core and the main application to reduce verification overhead;

[0015] Implement dynamic code isolation and permission control to prevent out-of-bounds operations and unauthorized access by dynamically loaded code;

[0016] Build an adaptive security control system to dynamically adjust verification policies according to the security sensitivity and execution frequency of code blocks.

[0017] Furthermore, segmenting the code includes:

[0018] Divide the code module into static segments, performance-critical segments, and dynamically loaded segments;

[0019] Generate a control flow graph for the static segment and define a set of legal control transfer paths;

[0020] Analyze function call signatures and build a function call signature verification model;

[0021] Generate differentiated protection policies for different code segments according to the code segment type and security importance.

[0022] Furthermore, building a two-layer control flow protection system includes:

[0023] Maintain an independent shadow stack system at the interpreter level to store function return address information;

[0024] Implement the runtime verification logic for direct control flow transfer and indirect control flow transfer;

[0025] Perform function return address verification, compare the current return address on the stack with the expected return address stored in the shadow stack;

[0026] Build an exception handling and recovery system to handle control flow violations.

[0027] Furthermore, utilizing hardware-accelerated verification technology includes:

[0028] Identify and apply the available hardware security features of the platform to build a hardware-assisted verification system;

[0029] Implement a precomputed hash verification model, calculate the hash value for legal control flow paths, and only compare the hash values at runtime to verify the control flow legality;

[0030] Build a parallel verification execution architecture to perform verification through independent processor cores, reducing the impact on the performance of the main application;

[0031] Optimize the verification instruction scheduling and reduce the overhead by leveraging the processor's instruction-level parallelism capabilities and predictive verification.

[0032] Furthermore, implementing dynamic code isolation and permission control includes:

[0033] Create an isolated execution environment for dynamically loaded code modules, restricting the memory range they can access;

[0034] Build a dynamic code loading verification system to perform pre-loading verification and in-loading transformation on modules;

[0035] Implement fine-grained resource access control, build a resource access policy model, and define the resource access permissions of modules;

[0036] Build a real-time behavior monitoring system, define a behavior pattern library, and identify operations that deviate from the normal behavior pattern.

[0037] Furthermore, building an adaptive security control system includes:

[0038] Build a code block risk assessment model to calculate the criticality, vulnerability, and accessibility metrics of code blocks;

[0039] Implement execution statistics and hotspot analysis, record the execution frequency of code blocks, and identify the performance critical path;

[0040] Build an adaptive verification frequency control system to dynamically adjust the verification density based on the risk score and execution frequency;

[0041] Implement dynamic security policy adjustment to automatically switch different security policies according to the system threat level.

[0042] Furthermore, the pre-computed hash verification model adopts an incremental hash calculation method to update the path hash value in real time when a control flow transfer occurs, avoiding the overhead of storing the complete execution path.

[0043] Furthermore, the code block risk scoring function uses the analytic hierarchy process to determine the weight coefficients, and evaluates the criticality, vulnerability, and accessibility metrics of code blocks from multiple dimensions of resource access, code quality, and exposure level respectively.

[0044] Furthermore, the method is applicable to the computing environments of WASM modules, edge computing, and IoT gateways. Through differential protection strategies and adaptive security control, it ensures security while controlling the performance overhead.

[0045] The present invention also provides a real-time threat monitoring and defense system for digital infrastructure, which is used to execute the steps in the aforementioned real-time threat monitoring and defense method for digital infrastructure, including:

[0046] Code segmentation module: used to divide the code into static segments, performance-critical segments, and dynamically loaded segments, and generate differentiated protection policies;

[0047] Control flow protection module: used to combine the shadow stack technology and runtime verification to ensure the security of function calls and returns;

[0048] Hardware-accelerated verification module: used to perform verification in parallel with the main application through a dedicated core to reduce verification overhead;

[0049] Dynamic code isolation module: used to prevent out-of-bounds operations and unauthorized access of dynamically loaded code;

[0050] Adaptive security control module: used to dynamically adjust the verification policy according to the security sensitivity and execution frequency of code blocks.

[0051] The beneficial effects of the present invention are as follows:

[0052] Mathematically provable security guarantee: Through the segmented control flow verification algorithm and the double-layer control flow protection system, this method can provide a mathematically provable security guarantee and prevent all attack behaviors that violate the predetermined control flow specification. In actual application tests, the success rate of control flow hijacking attacks is reduced to nearly zero, and effective protection can be maintained even in the face of targeted advanced persistent threat (APT) attacks.

[0053] Extremely low performance overhead: Through hardware-accelerated verification, pre-computed hash verification model, parallel verification execution architecture, and adaptive security control system, this method controls the verification overhead below 5%, significantly lower than the 10-30% performance loss of traditional methods. This makes this method particularly suitable for critical digital infrastructure with strict real-time requirements, such as financial trading systems, industrial control networks, and edge computing nodes.

[0054] Comprehensive dynamic code protection: Through the dynamic code isolation and permission control system, this method solves the security blind spots of the existing technology in dealing with WASM modules and dynamically loaded code, realizes comprehensive and real-time verification of dynamic code, and fills an important gap in the security protection of digital infrastructure.

[0055] Static-dynamic collaborative verification: This method cleverly combines static code analysis and dynamic runtime verification, avoiding both the high false alarm rate of pure static analysis and the high overhead problem of pure dynamic monitoring, and realizing more comprehensive and efficient security protection.

[0056] Adaptive Security Protection: Through an adaptive security and performance balancing algorithm, this method can dynamically adjust the verification strategy according to the security sensitivity, execution frequency of code blocks, and system threat levels, minimizing the impact on system performance while maintaining high-intensity security protection, achieving an optimal balance between security and performance.

[0057] Wide Applicability: This method is specifically optimized for computing environments (such as WASM modules, edge computing, and IoT gateways), providing dedicated security protection solutions for these fields and addressing the deficiencies of traditional defense methods in these scenarios. Practice has shown that this method can seamlessly adapt to digital infrastructures of different scales and types, from single edge devices to complex distributed systems. Brief Description of the Drawings

[0058] Figure 1 is the overall flowchart of the embodiments of the present invention;

[0059] Figure 2 is the sub-step flowchart of Step 1, "Implement Code Segment Control Flow Verification", of the present invention;

[0060] Figure 3 is the sub-step flowchart of Step 2, "Implement a Double-Layer Control Flow Protection System", of the present invention;

[0061] Figure 4 is the sub-step flowchart of Step 3, "Apply Hardware-Accelerated Verification and Performance Optimization", of the present invention;

[0062] Figure 5 is the sub-step flowchart of Step 4, "Implement a Dynamic Code Isolation and Permission Control System", of the present invention;

[0063] Figure 6 is the sub-step flowchart of Step 5, "Achieve Adaptive Security and Performance Balance", of the present invention. Detailed Embodiments

[0064] Now, the subject matter described herein will be discussed with reference to exemplary embodiments. It should be understood that discussing these embodiments is only to enable those skilled in the art to better understand and thus implement the subject matter described herein. The functions and arrangements of the elements discussed can be changed without departing from the scope of protection of the content of this specification. Each example can omit, substitute, or add various processes or components as needed. Additionally, the features described relative to some examples can also be combined in other examples.

[0065] As Figures 1-6 shown, a method for real-time threat monitoring and defense of digital infrastructure includes the following steps:

[0066] Step 1, Implement code segmented control flow verification: In this step, the segmented control flow verification algorithm is used to classify the WASM (WebAssembly) module and dynamically loaded code, generating a differential protection strategy and a control flow verification model;

[0067] In an embodiment of the present invention, it specifically includes the following steps:

[0068] Step 1.1, Segment the code based on execution characteristics:

[0069] The code module is divided into three categories:

[0070] Static segment: The code segment that will not change after loading, suitable for comprehensive control flow protection;

[0071] Performance-critical segment: The code segment with high execution frequency and affecting system performance, which requires a balance between security and performance;

[0072] Dynamically loaded segment: The code segment dynamically loaded during runtime, which requires real-time verification of its legality.

[0073] For each code segment, a formal description model is constructed to record its entry point, exit point, and internal control flow transfer characteristics.

[0074] Step 1.2, Generate the static segment control flow graph and the set of legal paths:

[0075] For the static code segment, precise specification is carried out using a formal language, its control flow structure is analyzed, and a static control flow graph (CFG) is output, defined as follows:

[0076] ;

[0077] Among them, represents the set of basic blocks, represents the set of control flow edges, and respectively represent the entry and exit nodes, represents the static control flow graph.

[0078] Based on the CFG, the set of legal control transfer paths is defined as:

[0079] ;

[0080] where represents a valid path from the program entry Entry to the exit Exit, and a valid path refers to an execution sequence that conforms to the program control flow semantics;

[0081] Step 1.3, Analyze function call signatures and construct a verification model: Analyze all function definitions and call points in the code, extract function signature information, including parameter types, return value types, and calling conventions;

[0082] Construct a function call signature verification model:

[0083] ;

[0084] where represents a function pointer that points to a function that can be called indirectly, represents a function signature that includes a list of parameter types and a return value type, represents a function signature verification set;

[0085] This model is used to verify the legality of indirect function calls and ensure that the signature of the target function is consistent with the expectations at the call point.

[0086] Step 1.4, Generate differentiated protection strategies: Generate differentiated protection strategies for different code segments according to the code segment type and security importance:

[0087] Static segments: Apply full control flow verification to verify all control flow transfer instructions;

[0088] Performance-critical segments: Apply selective control flow verification to only verify critical control flow transfer instructions;

[0089] Dynamically loaded segments: Apply real-time verification, perform integrity checks during loading, and apply dynamic verification during runtime.

[0090] Output the protection strategy set , which includes the protection level, verification frequency, and verification method for each code segment.

[0091] Step 2, Implement a two-layer control flow protection system: In this step, combine the shadow stack technology with the runtime verification system to create a two-layer control flow protection system to ensure the security of function calls and returns;

[0092] In one embodiment of the present invention, it specifically includes the following steps:

[0093] Step 2.1, Construct a shadow stack system:

[0094] At the WASM interpreter or JIT compilation level, implement an independent shadow stack system for storing function return address information:

[0095] ;

[0096] where represents the return address, and each call context Contains call point information, the signature of the calling function, and an encrypted check value. Represents the shadow stack system, which is used to store and manage the return information of function calls.

[0097] Shadow stack operations include:

[0098] During a function call: Push the return address and the context onto the shadow stack.

[0099] During a function return: Pop the return address from the shadow stack and compare it with the actual return address.

[0100] Step 2.2, Implement the runtime verification logic:

[0101] For all control flow transfer instructions, implement the runtime verification logic:

[0102] For direct control flow transfers (such as direct function calls, fixed jumps):

[0103] ;

[0104] Where represents the target address of the control flow transfer, represents the set of legal target addresses determined by static analysis, represents the direct control flow transfer verification function, represents the membership relational operator;

[0105] For indirect control flow transfers (such as function pointer calls, indirect jumps): ;

[0106] Where, is the set of legal target addresses, is the function type corresponding to the address, is the function type expected at the call point, represents the verification function for indirect control flow transfers, represents the target address of the indirect jump, represents the logical AND operator, indicating that both conditions need to be satisfied;

[0107] Step 2.3, Function return address verification:

[0108] Before the function return instruction is executed, perform return address verification:

[0109] ;

[0110] Where, is the return address on the current stack, is the expected return address stored in the shadow stack. Represents the return address verification function, represents the comparison operation for complete equality of addresses;

[0111] Trigger the security exception handling when the verification fails.

[0112] Step 2.4, construct the exception handling and recovery system: Construct an exception handling system. When a control flow violation is detected: Record the type of violation, the location where it occurred, and the relevant context information;

[0113] According to the configured policy, execute the corresponding security response, including terminating the execution, returning an error code, or redirecting to a security handling routine;

[0114] For recoverable violations, construct a state rollback and execution path correction system.

[0115] Output the security exception handling rule set , define the handling policies corresponding to different types of violations.

[0116] Step 3, apply hardware acceleration verification and performance optimization: In this step, utilize the hardware security features and parallel verification technologies of modern processors to perform hardware acceleration and performance optimization on control flow protection;

[0117] In an embodiment of the present invention, it specifically includes the following steps:

[0118] Step 3.1, apply the hardware security features of the processor: Identify and apply the available hardware security features of the platform to construct a hardware-assisted verification system:

[0119] For Intel processors: Utilize the Intel Processor Trace (PT) technology to collect the control flow execution traces and output the compressed execution path information;

[0120] For ARM processors: Utilize the Core Sight debugging and tracing technology to obtain the branch instruction stream during the program execution;

[0121] For platforms supporting hardware memory protection: Configure the Memory Protection Unit (MPU) or Memory Management Unit (MMU) to achieve hard isolation of the code area and data area.

[0122] Step 3.2, construct a pre-computed hash verification model: To improve the verification efficiency, implement a pre-computed hash verification model:

[0123] For the set of legal control flow paths obtained from static analysis , calculate the hash value of each path:

[0124] ;

[0125] Among them, represents a path hash function that maps an execution path to a hash value of a fixed length. represents a complete control flow execution path. represents a hash calculation function, such as SHA-256, etc. means that hash calculations are performed on all legal paths;

[0126] Store the hash values of all legal paths in a fast lookup structure:

[0127] ;

[0128] Among them represents the set of hash values of all legal paths, which is used for fast verification;

[0129] Collect execution path information during runtime and calculate the hash value of the current path , and the verification formula is:

[0130] ;

[0131] Among them represents the hash value of the current execution path, represents a hash verification function;

[0132] This verification method based on hash value comparison reduces the time complexity of path verification from to .

[0133] The specific implementation of the pre-computed hash verification model adopts an incremental hash calculation method. Whenever a control flow transfer occurs, the following formula is used to update the hash value of the current path:

[0134] ;

[0135] Among them, is the target address of the control flow transfer, and respectively represent bitwise left shift and bitwise right shift operations, represents an exclusive OR operation;

[0136] This incremental hash calculation method avoids the overhead of storing the complete execution path and significantly reduces memory occupancy.

[0137] In the scenario of a financial trading system, this model is applied to the key transaction processing path of a high-frequency trading engine. Since tens of thousands of transaction requests need to be processed per second, traditional verification methods will cause significant delays. The pre-computed hash verification model achieves sub-microsecond verification speed by pre-loading the hash values of common transaction processing flows into the processor L1 cache, ensuring the real-time requirements of the trading system and effectively preventing control flow hijacking attacks on the trading engine.

[0138] Step 3.3, implement a parallel verification execution architecture: Build a parallel verification execution architecture to reduce the impact of verification on the performance of the main application:

[0139] The main thread executes the application code and records control flow events in a shared memory buffer;

[0140] The verification threads run in parallel and read control flow events from the buffer for verification;

[0141] For multi-core processors, allocate the verification threads to independent processor cores for execution;

[0142] Implement a lightweight synchronization mechanism between the main verification thread and the application thread to ensure that verification does not block the execution of the main program.

[0143] Step 3.4, optimize the verification instruction scheduling: Analyze the hot paths of the application and optimize the verification instruction scheduling strategy:

[0144] For code paths with high execution frequencies, adopt predictive verification and pre-load verification data before the execution of branch instructions;

[0145] Interleave the verification instructions and the application instructions to utilize the instruction-level parallelism of the processor;

[0146] Use SIMD instructions to accelerate key verification operations to achieve batch verification;

[0147] Implement instruction-level pipelining for verification operations to reduce the blocking delay of verification instructions.

[0148] Output the hardware-accelerated verification configuration and the optimized strategy set , significantly reducing the verification overhead.

[0149] Step 4, implement a dynamic code isolation and permission control system: This step constructs a dynamic code isolation system and a fine-grained permission control system to prevent out-of-bounds operations and unauthorized access of dynamically loaded code;

[0150] In an embodiment of the present invention, it specifically includes the following steps:

[0151] Step 4.1, establish a dynamic code isolation area: Create an isolated execution environment for dynamically loaded code modules:

[0152] Build a memory sandbox to limit the memory range accessible by dynamic code:

[0153] Allocate independent memory segments for each dynamic module;

[0154] Implement memory boundary checks to prevent cross-segment access;

[0155] Implement verification checks at the inter-module communication points.

[0156] Implement a code segment permission control system to define memory protection policies:

[0157] ;

[0158] Among them, represents the memory area, represents the corresponding access permission (read / write / execute), represents the set of memory protection policies that define the access control rules for all memory areas.

[0159] Step 4.2, build a dynamic code loading verification system: When the system dynamically loads a code module, perform multi-level verification:

[0160] Verification before loading:

[0161] Check the module signature and integrity;

[0162] Analyze the module import / export table to ensure compliance with the expected interface.

[0163] Conversion during loading:

[0164] Perform immediate conversion on the dynamic module code and insert control flow verification instructions;

[0165] Rewrite the memory access instructions to add boundary check logic;

[0166] Implement the separation of the code segment and the data segment.

[0167] Define a dynamic module verification rule set and specify the verification requirements for different types of dynamic modules.

[0168] Step 4.3, implement fine-grained resource access control: Implement fine-grained resource access control for dynamically loaded code modules:

[0169] Build a resource access policy model:

[0170] ;

[0171] Among them, represents the unique identifier of the dynamically loaded module, Represents the set of resources that the module is allowed to access, including system APIs, file systems, network interfaces, etc. Represents the set of access control policies that define the resource access permissions for all modules.

[0172] Implement permission checks at critical resource access points:

[0173] ;

[0174] Among them, is the currently executing module, is the resource requested for access, is the module is the set of resources authorized for the module to access, represents the resource access verification function.

[0175] Step 4.4, construct a real-time behavior monitoring system: Implement a real-time monitoring system for dynamic code behavior:

[0176] Define the behavior pattern library , which describes the normal execution pattern;

[0177] Collect real-time module behavior characteristics, including: system call frequency and sequence; memory access pattern; control flow transfer characteristics.

[0178] Apply anomaly detection algorithms to identify operations that deviate from the normal behavior pattern:

[0179] ;

[0180] Among them, is the currently observed behavior, The function calculates the deviation degree of the behavior from the normal pattern, represents the anomaly detection function, represents the normal behavior pattern library, represents the anomaly determination threshold.

[0181] Output the dynamic code isolation configuration and the permission control policy , which can effectively prevent the attack behavior of malicious dynamic code.

[0182] Step 5, achieve adaptive security and performance balance: This step constructs an adaptive security control system to achieve fine-grained security-performance balance adjustment according to the security sensitivity and execution frequency of code blocks;

[0183] In an embodiment of the present invention, it specifically includes the following steps:

[0184] Step 5.1, construct a code block risk assessment model: Conduct a security risk assessment on the code blocks in the system and establish a risk scoring model:

[0185] Define the risk scoring function for code blocks:

[0186] ;

[0187] Where: represents the criticality of the code block, which is related to the sensitive resources it operates on, and represents the vulnerability of the code block, which is related to its complexity and potential vulnerabilities; and represents the accessibility of the code block, which is related to its external exposure level; and , , are the weight coefficients for criticality, vulnerability, and accessibility, represents the comprehensive risk score of the code block.

[0188] Calculate the risk scores for all code blocks to generate a risk distribution map .

[0189] The specific implementation of the risk assessment model uses the Analytic Hierarchy Process (AHP) to determine the weight coefficients and determines the weights of each factor by constructing a judgment matrix: ;

[0190] At the same time, the following methods are used to calculate each index:

[0191] ;

[0192] Where is the set of resources accessed by the code block , represents the importance of the resource , represents the weight corresponding to the access type (read / write / execute);

[0193]

[0194] Where represents the code complexity index, represents the historical vulnerability index, represents the code quality index;

[0195] Comprehensively consider code complexity, historical vulnerabilities, and code quality;

[0196] ;

[0197] Where represents the code exposure level, represents the authentication strength coefficient;

[0198] Combine the code exposure level and the authentication strength.

[0199] In the industrial control system scenario, this model is used to conduct risk assessments on different functional modules of the SCADA system. For example, the highest risk score is assigned to the key control module that directly controls physical devices, while a lower risk score is assigned to auxiliary functional modules such as logging. This differential risk assessment enables the system to concentrate limited security resources on protecting the most critical components. For instance, 90% of the verification resources are used to protect high-risk code blocks that account for 20% of the total code volume, improving the overall security protection efficiency.

[0200] Step 5.2, Implement execution statistics and hotspot analysis: Monitor the runtime behavior of the system to implement execution statistics and hotspot analysis:

[0201] Record the execution frequency of code blocks and construct an execution hotspot map:

[0202] ;

[0203] Among them, is the number of executions of code block , is the total number of execution instructions of the system, represents the execution frequency of the code block.

[0204] Analyze the characteristics of the execution path and identify the performance critical path.

[0205] Construct a performance - security relationship model to evaluate the impact degree of verification operations on performance.

[0206] Step 5.3, Construct an adaptive verification frequency control system: Based on the risk score and the execution frequency, implement adaptive verification frequency control:

[0207] Define the verification frequency function:

[0208] ;

[0209] Among them, is the basic verification rate, is the risk score of the code block, is the execution frequency of the code block, represents the verification frequency of the code block.

[0210] Increase the verification density for high - risk and low - frequency code blocks, and reduce the verification density for low - risk and high - frequency code blocks. The optimization formula:

[0211] ;

[0212] Among them, and are the minimum and maximum verification rates respectively, indicating the code block of the finally optimized verification frequency.

[0213] Step 5.4, implement dynamic security policy adjustment: Dynamically adjust the security policy according to the system operation status and threat level:

[0214] Define the system threat level evaluation function:

[0215] ;

[0216] wherein, is the number of abnormal events, is the attack feature index, is the resource utilization rate, represents the system threat level.

[0217] Dynamically adjust the verification policy based on the threat level:

[0218] Low threat state: Reduce the verification intensity and optimize the performance;

[0219] Medium threat state: Balance security and performance;

[0220] High threat state: Enhance the verification intensity and give priority to ensuring security.

[0221] Build an automatic security policy switching system to achieve smooth transition between different threat levels.

[0222] Output the adaptive security control configuration to achieve the dynamic balance of system security and performance.

[0223] According to the above monitoring and defense methods and systems, the following gives a real application example of this embodiment;

[0224] Application scenario;

[0225] This embodiment has been verified in the following three typical scenarios:

[0226] Financial trading system: Deployed on the high-frequency trading platform of a certain securities exchange, which uses WASM module technology to implement a cross-platform trading algorithm execution environment and processes more than 100 million trading requests per day. The system requires a millisecond-level response time and needs to prevent control flow hijacking attacks against the trading engine.

[0227] Industrial control network: Applied to the edge computing gateway of a certain power dispatching system, which is responsible for processing real-time data from thousands of sensors and running dynamically loaded analysis modules. The system needs to ensure the security of control instructions and prevent malicious modules from interfering with the industrial production process.

[0228] IoT Device Management Platform: Deployed on the smart city IoT management platform, this platform uses dynamic code loading technology to achieve device adaptation and protocol conversion, and needs to manage tens of thousands of heterogeneous IoT devices simultaneously. The system faces complex security threats from the device access layer and needs to verify the behavior of dynamically loaded modules in real time.

[0229] Implementation process instance;

[0230] Taking the financial trading system as an example, the specific implementation process of this embodiment will be described in detail below:

[0231] Code segmentation and risk assessment;

[0232] Segment and risk assess the WASM module in the trading system. The results are shown in Table 1:

[0233] Table 1, Code module segmentation and risk scores of the financial trading system;

[0234]

[0235] Implement double-layer control flow protection;

[0236] Build a shadow stack system for the order processing core and trading algorithm engine modules. The verification results show that it effectively blocks return-oriented programming (ROP) attacks. A typical protection example is shown in Table 2:

[0237] Table 2, Shadow stack verification records of the order processing core module (partial)

[0238]

[0239] Hardware acceleration verification implementation;

[0240] The trading system uses an Intel Xeon processor and utilizes Intel PT technology to achieve control flow verification. Table 3 shows the verification performance comparison:

[0241] Table 3, Performance comparison of different verification methods;

[0242]

[0243] Dynamic code isolation implementation;

[0244] Implement dynamic code isolation for the trading algorithm engine. Table 4 shows the resource access policy:

[0245] Table 4, Resource access control policy of the trading algorithm engine;

[0246]

[0247] Adaptive security control effect;

[0248] After the system has been running for a week, the adaptive security control automatically adjusted the verification policy according to the execution statistics. Table 5 shows the comparison before and after the adjustment:

[0249] Table 5, Performance comparison of adaptive security control before and after adjustment;

[0250]

[0251] Verification of technical effects;

[0252] The deployment of this embodiment in the above application scenario verified two key technical effects: security guarantee and extremely low performance overhead.

[0253] Security verification;

[0254] To verify the security protection effect of this method, we conducted a security penetration test on the deployed system, simulating different types of control flow hijacking attacks. The test results are shown in Table 6:

[0255] Table 6, Defense effect test of different attack types;

[0256]

[0257] Comparison of performance overhead and defense effect;

[0258] The performance performance of this method in different application scenarios and its comparison with traditional methods are shown in Table 7:

[0259] Table 7, Comprehensive comparison of performance overhead and defense effect of different defense methods;

[0260]

[0261] The above test results verified that this method can provide comprehensive security guarantee with extremely low performance overhead (average 3.8%), while maintaining the real-time response ability of the system, and is particularly suitable for critical digital infrastructures with strict requirements for both performance and security.

[0262] The embodiments of the present invention have been described above, but the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms, all of which fall within the protection scope of the present invention.

Claims

1. A real-time threat monitoring and defense method for digital infrastructure, characterized in that, The steps include: Segment the WASM module and the dynamic code module, divide the code into static segments, performance-critical segments, and dynamically loaded segments, and generate differential protection policies; Build a two-layer control flow protection system, combine shadow stack technology with runtime verification to ensure the security of function calls and returns; Utilize hardware-accelerated verification technology, execute verification in parallel with the dedicated core and the main application through a dedicated core to reduce verification overhead; Implement dynamic code isolation and permission control to prevent out-of-bounds operations and unauthorized access by dynamically loaded code; Build an adaptive security control system, and dynamically adjust the verification policy according to the security sensitivity and execution frequency of code blocks.

2. The real-time threat monitoring and defense method for digital infrastructure according to claim 1, characterized in that, Segmenting the code includes: Divide the code module into static segments, performance-critical segments, and dynamically loaded segments; Generate a control flow graph for the static segment and define a set of legal control transfer paths; Analyze function call signatures and build a function call signature verification model; Generate differential protection policies for different code segments according to the code segment type and security importance.

3. A real-time threat monitoring and defense method for digital infrastructure according to claim 2, characterized in that Building a two-layer control flow protection system includes: Maintain an independent shadow stack system at the interpreter level to store function return address information; Implement the runtime verification logic for direct control flow transfer and indirect control flow transfer; Perform function return address verification, compare the return address on the current stack with the expected return address stored in the shadow stack; Build an exception handling and recovery system to handle control flow violations.

4. A real-time threat monitoring and defense method for digital infrastructure according to claim 3, characterized in that, Utilizing hardware-accelerated verification technology includes: Identify and apply the available hardware security features of the platform to build a hardware-assisted verification system; Implement a precomputed hash verification model, calculate the hash value for the legal control flow path, and only compare the hash value at runtime to verify the control flow legality; Build a parallel verification execution architecture, execute verification through an independent processor core to reduce the impact on the performance of the main application; Optimize the verification instruction scheduling, utilize the processor instruction-level parallelism ability and predictive verification to reduce overhead.

5. A real-time threat monitoring and defense method for digital infrastructure according to claim 4, characterized in that, Implementing dynamic code isolation and permission control includes: Create an isolated execution environment for the dynamically loaded code module and limit the memory range it can access; Build a dynamic code loading verification system to perform pre-loading verification and loading-time conversion on the module; Implement fine-grained resource access control, build a resource access policy model, and limit the resource access permissions of the module; Build a real-time behavior monitoring system, define a behavior pattern library, and identify operations that deviate from the normal behavior pattern.

6. A real-time threat monitoring and defense method for digital infrastructure according to claim 5, characterized in that Building an adaptive security control system includes: Build a code block risk assessment model, calculate the criticality, vulnerability, and accessibility metrics of code blocks; Implement execution statistics and hotspot analysis, record the execution frequency of code blocks, and identify performance-critical paths; Build an adaptive verification frequency control system, and dynamically adjust the verification density based on the risk score and execution frequency; Implement dynamic security policy adjustment, and automatically switch different security policies according to the system threat level.

7. A method for real-time threat monitoring and defense of digital infrastructure according to claim 6, characterized in that The precomputed hash verification model adopts an incremental hash calculation method to update the path hash value in real time when a control flow transfer occurs, avoiding the overhead of storing the complete execution path.

8. A method for real-time threat monitoring and defense of digital infrastructure according to claim 7, characterized in that The code block risk scoring function determines the weight coefficients using the analytic hierarchy process, and evaluates the criticality, vulnerability, and accessibility indicators of the code block from multiple dimensions of resource access, code quality, and exposure level respectively.

9. A method for real-time threat monitoring and defense of digital infrastructure according to claim 8, characterized in that, The method is applicable to the computing environments of WASM modules, edge computing, and IoT gateways. Through differentiated protection strategies and adaptive security controls, it ensures security while controlling performance overhead.

10. A real-time threat monitoring and defense system for digital infrastructure, characterized in that, For performing the steps in a method for real-time threat monitoring and defense of digital infrastructure as described in any one of claims 1-9, including: Code segmentation module: used to divide the code into static segments, performance-critical segments, and dynamically loaded segments, and generate differentiated protection strategies; Control flow protection module: used to combine shadow stack technology with runtime verification to ensure the security of function calls and returns; Hardware-accelerated verification module: used to execute verification in parallel with the main application through a dedicated core to reduce verification overhead; Dynamic code isolation module: used to prevent out-of-bounds operations and unauthorized access of dynamically loaded code; Adaptive security control module: used to dynamically adjust the verification strategy according to the security sensitivity and execution frequency of the code block.

Citation Information

Patent Citations

  • Intelligent contract vulnerability detection method and system based on hybrid fuzzy test

    CN117828616A

  • Web end encryption method based on WASM, medium and equipment

    CN118316595A

  • Software and hardware collaborative operating system isolation enhancement method and system

    CN119720297A

  • Protocol fuzz testing method and system based on fine-grained state division and selection

    CN119996271A

  • Shadow stack enforcement range for dynamic code

    US20210303681A1