EBPF-based protocol stack cross-layer interaction security vulnerability automatic defense method and system
By adopting an automatic defense method based on eBPF in the network protocol stack, the security vulnerabilities during cross-layer interaction of the protocol stack are solved, effective mitigation and defense of multiple security vulnerabilities are achieved, and the security and robustness of the protocol stack are improved.
Patent Information
- Application Number
- CN202510133881.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-06
- Publication Date
- 2025-07-01
AI Technical Summary
The network protocol stack has security vulnerabilities during cross-layer interactions, especially due to the isolation between layers, the information maintained by other layers cannot be accurately grasped, resulting in a weak verification mechanism that may be adopted, which gives attackers an opportunity to take advantage of.
The protocol stack cross-layer interactive security vulnerability automatic defense method is adopted, and hash key values are generated through the monitoring program module and sent to the BPF Map. The stateless ICMP Error message filter and ICMP input rate limiter are run. The program is compiled into BPF bytecode in combination with the llvm/clang tool chain, and the eBPF module in the kernel is verified and executed to achieve automated defense.
Effectively mitigate and defend against four types of security vulnerabilities during cross-layer interaction of protocol stacks, including IP shard pollution vulnerabilities, IPID counter side channel vulnerabilities, ICMP Redirect semantics missing vulnerabilities, and ICMP Error port inference vulnerabilities, improving the robustness of the protocol stack.
Smart Images

Figure CN120238334A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network protocol stack security, and in particular, to an automatic defense method, system, device and storage medium for cross-layer interaction security vulnerabilities of a protocol stack based on eBPF. Background Art
[0002] As the fundamental support for network communication, the network protocol stack is designed with a hierarchical structure. Each layer has formed corresponding specifications and independently completes its respective functions. At the same time, the lower layer provides support for the transparent transmission of the upper-layer protocol. Taking the OSI seven-layer model as an example, it defines the physical layer, data link layer, network layer, transport layer, session layer, presentation layer, and application layer from bottom to top. The physical layer specifies the specific transmission medium. The data link layer abstracts the physical signal into a bit stream and sets frame delimitation. The network layer provides the routing function of packets. The transport layer provides reliable transmission guarantee. The session layer and the presentation layer serve the application layer. The session layer maintains the corresponding session and exchange order. The presentation layer is responsible for data format conversion. Finally, the application layer protocol defined by the application layer directly serves users. After decades of development and improvement, the implementations of each layer in the protocol stack are now robust enough to effectively respond to and mitigate various security threats.
[0003] In order to be improved and updated more quickly, each layer of the protocol stack adopts a modular-like design for separate maintenance, but at the same time keeps the interfaces provided to adjacent layers unchanged, aiming to provide transparent transmission. However, such a design does not consider the security issues caused by cross-layer interaction of the protocol stack. During the process of a data packet being processed by the protocol stack, it will pass through multiple different layers, and the information therein will be recorded and modified. The problem brought by this mechanism is that there may be multiple data packet processing paths passing through the same layer and modifying the same variable. If one of these paths can be observed by an attacker, then a side-channel vulnerability that can be exploited is generated, bringing security risks. At the same time, due to the isolation design between layers, each layer cannot accurately master the information maintained by other layers, or some stateless protocols themselves cannot maintain complete connection information, thus may adopt a weak verification mechanism, giving attackers an opportunity.
[0004] The TCP / IP hierarchical network protocol stack was required to be independently maintained for each layer at the beginning of its design, while ensuring that the lower layer supports the transparent transmission of the upper layer. However, this design concept ignores the security issues caused by cross-layer interaction of the protocol stack. Summary of the Invention
[0005] The present invention aims to at least solve one of the technical problems in the related art to some extent.
[0006] To this end, the first object of the present invention is to propose an automatic defense method for security vulnerabilities in cross-layer interaction of the protocol stack based on eBPF, aiming to automatically mitigate and defend against security vulnerabilities generated during the cross-layer interaction of the network protocol stack.
[0007] The second object of the present invention is to propose an automatic defense system for security vulnerabilities in cross-layer interaction of the protocol stack based on eBPF.
[0008] The third object of the present invention is to propose a computer device.
[0009] The fourth object of the present invention is to propose a non-transitory computer-readable storage medium.
[0010] To achieve the above object, an embodiment of the first aspect of the present invention proposes an automatic defense method for security vulnerabilities in cross-layer interaction of the protocol stack based on eBPF, including:
[0011] Randomly generate a hash key value through the monitoring program module and send it to the BPF Map.
[0012] In the BPF program module, run a stateless ICMP Error message filter and an ICMP input rate limiter to process the current ICMP message respectively, combine these two components, and compile the combined program into BPF bytecode through the llvm / clang tool chain and load it into the kernel.
[0013] The eBPF module in the kernel verifies the legality of the BPF bytecode, and based on the verification result, translates the BPF bytecode into machine language and executes it through the JIT just-in-time compiler. During the operation of the automatic defense mechanism, interact with the BPF Map for reading and writing.
[0014] Use the monitoring program module to read the BPF Map to obtain the log information generated during the operation of the stateless ICMP Error message filter and the ICMP input rate limiter, and write it into the log file.
[0015] The automatic defense method for security vulnerabilities in cross-layer interaction of the protocol stack according to the embodiment of the present invention may also have the following additional technical features:
[0016] In an embodiment of the present invention, running the stateless ICMP Error message filter to process the current ICMP message includes:
[0017] S101, determine whether the current ICMP message is an ICMP Redirect message. If so, jump to S102; otherwise, jump to S103.
[0018] S102, Determine whether the embedded message of the current message is a stateless protocol. If so, jump to S105; otherwise, jump to S106;
[0019] S103, Determine whether the current message is an ICMP Fragment Needed message. If so, jump to S104; otherwise, jump to S106;
[0020] S104, Determine whether the embedded message of the current message is a passively generated ICMP message. If so, jump to S105; otherwise, jump to S106;
[0021] S105, Filter the current message and end the judgment logic;
[0022] S106, Receive the current message and end the judgment logic.
[0023] In an embodiment of the present invention, a 32-bit hash key value is generated when the ICMP input rate limiter is loaded; running the ICMP input rate limiter to process the current ICMP message includes:
[0024] S11, Extract the 24-bit prefix of the source IP address of the ICMP message and calculate the hash value as a parameter in combination with the hash key value generated during initialization;
[0025] S12, Take out the time stamp and credit value stored in the corresponding table entry from the BPF Map with the calculated hash value as the key, restore the credit according to the difference between the current time and the time stamp, and update the time stamp to the current time;
[0026] S13, Randomly generate the credit consumption value consume of the current ICMP message, compare the size of consume and credit. If credit is greater than or equal to consume, jump to S14; otherwise, jump to S15;
[0027] S14, Subtract the value of consume from credit and update it back to the original table entry in the BPF Map, receive the current ICMP message, and end the judgment logic;
[0028] S15, Filter the current ICMP message and end the judgment logic.
[0029] In one embodiment of the present invention, the stateless ICMP Error packet filter only filters ICMP Fragment Needed packets that embed passively generated ICMP packets. The passively generated ICMP packets include ICMP EchoReply, ICMP Destination Unreachable, and ICMP Redirect.
[0030] In one embodiment of the present invention, the ICMP input rate limiter is designed with 2048 hash-based LRU entries. The source IP address is mapped to one of the entries for calculation. The hash value is calculated using a 24-bit prefix of the source IP address. The credit consumed by each ICMP packet is randomized to be 1 or 2, and finally, it is ensured that each hash table entry receives at most 500 to 1000 of the earliest-arriving ICMP packets per second.
[0031] To achieve the above object, a second aspect embodiment of the present invention proposes an automatic defense system for cross-layer interaction security vulnerabilities of a protocol stack based on eBPF, including:
[0032] A hash key value distribution module, configured to randomly generate hash key values through a monitoring program module and distribute them to the BPF Map;
[0033] A defense compilation module, configured to respectively run a stateless ICMP Error packet filter and an ICMP input rate limiter in the BPF program module to process the current ICMP packet, combine these two components, and compile the combined program into BPF bytecode through the llvm / clang toolchain and load it into the kernel;
[0034] A verification translation module, configured to verify the legality of the BPF bytecode by the eBPF module in the kernel, and translate the BPF bytecode into machine language and execute it based on the verification result through a JIT just-in-time compiler, and interact with the BPF Map for reading and writing during the operation of the automatic defense mechanism;
[0035] A log acquisition module, configured to use the monitoring program module to read the BPF Map to obtain the log information generated during the operation of the stateless ICMP Error packet filter and the ICMP input rate limiter and write it into a log file.
[0036] The automatic defense method and system for cross-layer interaction security vulnerabilities of the protocol stack based on eBPF according to the embodiments of the present invention are directed to four types of cross-layer security vulnerabilities, including IP fragmentation pollution vulnerability, IPID counter side-channel vulnerability, ICMP Redirect semantic absence vulnerability, and ICMP Error port inference vulnerability. Two automatic defense modules are designed, namely the stateless protocol ICMP Error message filter and the ICMP input rate limiter. By using eBPF to mount BPF bytecode to the kernel, the above vulnerabilities can be mitigated and defended to the maximum extent. This solution first analyzes the above four types of security vulnerabilities from the principles and causes, and combines the characteristics of eBPF to introduce the design of two automatic defense modules, and combines the two to obtain the automatic defense mechanism for cross-layer interaction security vulnerabilities of the protocol stack based on eBPF proposed by the present invention. At the same time, this solution is not limited to defending the above four vulnerabilities. Since the root causes of these types of vulnerabilities are grasped, theoretically, the same defense effect can also be achieved for other vulnerabilities with similar principles.
[0037] To achieve the above object, an embodiment of the third aspect of the present invention provides a computer device, including: a processor and a memory; wherein, the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the automatic defense method for cross-layer interaction security vulnerabilities of the protocol stack based on eBPF as described in the embodiment of the first aspect.
[0038] To achieve the above object, an embodiment of the fourth aspect of the present invention provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the automatic defense method for cross-layer interaction security vulnerabilities of the protocol stack based on eBPF as described in the embodiment of the first aspect.
[0039] The additional aspects and advantages of the present invention will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present invention. Description of the Drawings
[0040] The above and / or additional aspects and advantages of the present invention will become obvious and easy to understand from the following description of the embodiments in conjunction with the drawings, where:
[0041] Figure 1 It is a flowchart of an automatic defense method for cross-layer interaction security vulnerabilities of the protocol stack based on eBPF according to an embodiment of the present invention;
[0042] Figure 2 It is a schematic diagram of a stateless ICMP Error message filter according to an embodiment of the present invention;
[0043] Figure 3Schematic diagram of an ICMP input rate limiter according to an embodiment of the present invention;
[0044] Figure 4 Schematic diagram of the overall architecture of the automatically defensive mechanism for cross-layer interaction security vulnerabilities of the finally formed protocol stack according to an embodiment of the present invention;
[0045] Figure 5 Structural diagram of an automatically defensive system for cross-layer interaction security vulnerabilities of the protocol stack based on eBPF according to an embodiment of the present invention;
[0046] Figure 6 Schematic diagram of the structure of a computer device according to an embodiment of the present invention. Detailed implementation manners
[0047] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other. The present invention will be described in detail below with reference to the drawings and in conjunction with the embodiments.
[0048] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.
[0049] The automatically defensive method, system, computer device and storage medium for cross-layer interaction security vulnerabilities of the protocol stack based on eBPF according to an embodiment of the present invention will be described below with reference to the drawings.
[0050] Figure 1 It is a flowchart of an automatically defensive method for cross-layer interaction security vulnerabilities of the protocol stack based on eBPF according to an embodiment of the present invention.
[0051] As Figure 1 shown, the method includes but is not limited to the following steps:
[0052] S1, randomly generate a hash key value through the monitoring program module and send it to the BPF Map;
[0053] S2, in the BPF program module, respectively run a stateless ICMP Error packet filter and an ICMP input rate limiter to process the current ICMP packet, combine these two components, and compile the combined program into BPF bytecode through the llvm / clang tool chain and load it into the kernel;
[0054] S3. The eBPF module in the kernel verifies the legality of the BPF bytecode, and based on the verification result, uses the JIT just-in-time compiler to translate the BPF bytecode into machine language and execute it. During the operation of the automated defense mechanism, it interacts with the BPF Map for reading and writing.
[0055] S4. The monitor module reads the BPF Map to obtain the log information generated during the runtime of the stateless ICMP Error packet filter and the ICMP input rate limiter, and writes it into the log file.
[0056] It can be understood that, in order to better understand the causes of these security issues, the present invention introduces four existing vulnerability exploitation methods, namely IP fragmentation pollution attack, IPID counter side-channel attack, ICMP Redirect semantic missing attack, and ICMP Error port inference attack.
[0057] (1) IP fragmentation pollution attack
[0058] In this attack, the bypass attacker triggers the reduction of the IP layer's PMTU by sending an ICMP FragmentNeeded packet embedded with an ICMP Echo Reply. However, at this time, the IP layer does not promptly notify the TCP layer to reduce the MSS, resulting in the TCP packet being fragmented. At this time, the attacker only needs to know the content of the original packet and construct the checksum to pollute the fragments and inject malicious payloads without having to guess the TCP seq and ack numbers.
[0059] (2) IPID counter side-channel attack
[0060] In this attack, similar to (1), the bypass attacker also triggers the reduction of the IP layer's PMTU by sending an ICMP Fragment Needed packet embedded with an ICMP Echo Reply. At this time, the DF of the IP packet to the destination is set to 0, resulting in the per-socket IPID counter being downgraded to 2048 hash-based IPID counters. The attacker can infer the TCP sequence number by constructing hash collisions using this side-channel vulnerability. The specific method is to periodically send ICMP Echo Request packets to capture the IPID changes.
[0061] (3) ICMP Redirect semantic missing attack
[0062] In this attack, the side-channel attacker sends an ICMP Redirect packet embedded with UDP. The source port number of the embedded UDP packet is open on the victim server. Since UDP is connectionless, only the source port number can be verified, which results in semantic loss, causing the ICMP Redirect packet to pass the authenticity verification and routing subsequent packets to the destination to a black hole or a gateway controlled by the attacker.
[0063] (4) ICMP Error Port Inference Attack
[0064] In this attack, similar to (3), the side-channel attacker sends an ICMP Fragment Needed / Redirect packet embedded with UDP. If an open port is successfully hit, the fnhe cache (next hop exception cache) maintained internally by the kernel will be modified, and the attacker can then use the length side channel of the fnhe cache to infer the open port.
[0065] eBPF is an improvement on BPF (Berkeley Packet Filter). Its essence is a virtual machine that executes BPF bytecode to perform specific functions in the kernel. Today's eBPF provides a powerful user-space interface. Users can freely write C programs, compile them into BPF bytecode using clang / llvm, and then load them into the kernel through a system call. After passing security verification, they are translated into machine language using JIT and linked to a specified attachment point to achieve specific functions. eBPF supports a rich set of kernel attachment points, including kprobes / tracepoints (performance tracing), socket / xdp / tc / netfilter (networking), cgroup (containers), and so on.
[0066] eBPF also supports and provides the BPF Map system to help exchange data between BPF processes or between the kernel and user space. There are two ways to operate on the data in BPF Maps. One is to operate on it in a BPF program, and the other is to operate on it in user space through a system call. By using BPF Maps, users can store the state information maintained by BPF programs and read and monitor it in user space.
[0067] In the present invention, eBPF is used to complete the writing of the defense mechanism, which is compiled into BPF bytecode through the llvm tool chain and loaded into the kernel through the BPF loader written in the user space, so as to achieve automatic filtering and defense. Compared with writing kernel modules, using the eBPF subsystem is more simple and robust, and even if the program crashes, it will not have too much impact on the kernel. Therefore, it is the first choice for implementing the defense strategy of the customized protocol stack.
[0068] The present invention aims to introduce an automated defense mechanism to effectively defend against or mitigate the above four attacks and derivative attacks with the same principle.
[0069] To this end, the present invention first analyzes the essential problems of the four attacks as follows:
[0070] (1) IP fragmentation pollution attack
[0071] Although this attack is caused by the IP layer not timely transmitting the PMTU tampered by the attacker to the TCP layer, resulting in ambiguity, fundamentally speaking, the attacker takes advantage of the problem that the stateless protocol cannot detect authenticity, that is, it cannot verify whether the ICMP Echo Reply packet embedded in the ICMP Fragment Needed packet is sent by the attacker before. At this time, the protocol stack adopts an aggressive approach of accepting all these packets.
[0072] (2) IPID counter side-channel attack
[0073] The essential reason for this attack to occur is the same as (1), that is, the protocol stack cannot judge the authenticity of the embedded stateless ICMP Echo Reply packet and adopts an aggressive acceptance strategy. At the same time, the attacker needs to detect the IPID change by sending an ICMP Echo Request packet every time using the side channel. Therefore, a large number of ICMP Echo Request packets with the source IP address of the attacker should be sent to the victim server, and the victim server should be able to detect such abnormal changes.
[0074] (3) ICMP Redirect semantic missing attack
[0075] The reason for the successful implementation of this attack is due to the weak verification mechanism for UDP packets. UDP is a connectionless protocol. Different from TCP, it does not have sequence numbers (seq) and acknowledgment numbers (ack) to perform more accurate verification on authenticity. In the protocol stack, the verification of UDP packets embedded in ICMP Redirect packets only checks whether the source port number is an open port of the server. Once the attacker knows one of the open ports of the server, this ICMP Redirect packet will be accepted by the victim server, resulting in the contamination of the fnhe cache.
[0076] (4) ICMP Error Port Inference Attack
[0077] The essential reason for the occurrence of this attack is the same as that in (1), which is also caused by the weak verification mechanism adopted by the protocol stack for UDP packets embedded in ICMP Error packets. At the same time, in order to utilize the length side channel of the fnhe cache, the attacker also needs to frequently send ICMP Echo Request packets to determine the change in the PMTU from the victim server to the attacker. The victim should be able to detect such abnormal changes.
[0078] From the analysis of the above four attacks, the fundamental reasons for the successful execution of the attacks are as follows: First, the protocol stack adopts an aggressive acceptance strategy or a weak verification mechanism for stateless ICMP and UDP protocols. Second, the protocol stack does not filter the abnormal ICMP traffic received. Accordingly, the present invention proposes two automated defense modules, the stateless protocol ICMP Error packet filter and the ICMP input rate limiter, which are specifically introduced as follows:
[0079] (1) Stateless Protocol ICMP Error Packet Filter
[0080] In this module, ICMP Error packets (such as ICMP Fragment Needed, ICMP Redirect) embedded with stateless protocols (such as ICMP, UDP) are filtered to a certain extent. Specifically, compared with the aggressive acceptance strategy or weak verification mechanism adopted in the protocol stack, this module adopts a more conservative strategy.
[0081] For ICMP Redirect messages, since a server usually has only one gateway, in this case, ICMP Redirect itself does not exist. Even if there are multiple gateways, the situation of ICMP Redirect caused by destination unreachable is extremely rare. Once an attacker-forged ICMP Redirect message is received, the consequences are extremely serious. At the very least, it will cause a denial-of-service attack, and at worst, traffic hijacking will occur. Therefore, due to the inability to accurately verify the authenticity of stateless protocols, all ICMP Redirect messages embedded with stateless protocols are conservatively filtered in this module.
[0082] For ICMP Fragment Needed messages, compared with ICMP Redirect messages, they are much more likely to occur, and even if forged, they are relatively less harmful. Therefore, a slightly conservative strategy is adopted in this module, that is, filter ICMP Fragment Needed messages embedded with passively generated stateless protocol messages and ICMP Redirect messages embedded with any stateless protocol messages. Passively generated ICMP messages include ICMP Echo Reply, ICMP Destination Unreachable, and ICMP Redirect. In this case, even if a non-forged message is wrongly filtered, since it is not actively triggered by the server, it will not affect the original functions of the server, and at the same time, it also poses a greater challenge to attackers forging messages.
[0083] (2) ICMP Input Rate Limiter
[0084] In the existing protocol stack implementations, usually only the output rate of ICMP is limited, but the input rate of ICMP is not limited. From the analysis of the four types of attacks above, it can be seen that attackers can use ICMP to scan some sensitive information of the victim server or utilize side channels, indicating that it is necessary to filter the ICMP message bursts from the same or similar IPs. In this module, when processing ICMP messages, the credit corresponding to the source address is dynamically updated, and the credit is periodically restored through the maintained timestamp. If the credit is empty, it can be judged that there is suspected scanning traffic, and these messages are conservatively discarded. Since the number of entries that can be maintained in eBPF is limited, 2048 hash-based LRU entries are designed in this module, and the source IP address is mapped to one of the entries for calculation. At the same time, considering that attackers may manipulate all IPs in a network segment, resulting in credit reuse, the prefix with a source IP address length of 24 is used for hash value calculation (normally, the subnet size allocated is larger than 2 8) Meanwhile, when the module is loaded, a 32-bit random hash key value is generated to prevent hash collisions. In addition, to prevent side-channel vulnerabilities caused by fixed rate limits, the amount of credit consumed by each ICMP packet is randomized to 1 or 2, ultimately ensuring that each hash table entry receives at most 500 to 1000 of the earliest-arriving ICMP packets per second, and the rest will be conservatively filtered.
[0085] The present invention combines the above two automated defense modules and implements and loads them through eBPF, forming an automated defense mechanism for protocol stack cross-layer interaction security vulnerabilities based on eBPF, aiming to help user terminals automatically mitigate and defend common protocol stack cross-layer interaction security vulnerabilities, thereby improving the robustness of the protocol stack implementation.
[0086] In an embodiment of the present invention, Figure 2 The following is a description of the operating principle of the stateless ICMP Error packet filter. When processing an ICMP packet, the specific workflow is as follows:
[0087] S101, Determine whether the current ICMP packet is an ICMP Redirect packet. If so, jump to S102; otherwise, jump to S103.
[0088] S102, Determine whether the embedded packet of the current packet is a stateless protocol, such as ICMP or UDP. If so, jump to S105; otherwise, jump to S106.
[0089] S103, Determine whether the current packet is an ICMP Fragment Needed packet. If so, jump to S104; otherwise, jump to S106.
[0090] S104, Determine whether the embedded packet of the current packet is a passively generated ICMP packet, such as Echo Reply / Destination Unreachable / Redirect. If so, jump to S105; otherwise, jump to S106.
[0091] S105, Filter the current packet and end the judgment logic.
[0092] S106, Receive the current packet and end the judgment logic.
[0093] In an embodiment of the present invention, Figure 3 The following is a description of the operating principle of the ICMP input rate limiter. When the module is loaded, a 32-bit hash key value is generated for subsequent hash value calculation. The specific workflow when processing ICMP packets is as follows:
[0094] S11. Extract the 24-bit prefix of the source IP address of the ICMP packet, and use it as a parameter to calculate the hash value in combination with the hash key value generated during initialization;
[0095] S12. Using the calculated hash value as the key in the BPF Map, retrieve the time stamp and credit value stored in the corresponding table entry. Restore the credit based on the difference between the current time and the time stamp, and update the time stamp to the current time;
[0096] S13. Randomly generate the credit consumption value consume of the current ICMP packet, compare the size of consume and credit. If credit is greater than or equal to consume, jump to S14; otherwise, jump to S15;
[0097] S14. Subtract the value of consume from credit, and update it back to the original table entry in the BPF Map, receive the current ICMP packet, and end the judgment logic;
[0098] S15. Filter the current ICMP packet and end the judgment logic.
[0099] It can be understood that since the table entries need to be read and written in this module, there is a data race. To speed up the processing speed, the present invention does not use the traditional method of completely locking the table entries during a single execution of the logic, but uses a combination of atomic operations provided by the compiler to reduce the head resistance phenomenon caused by locking.
[0100] In an embodiment of the present invention, Figure 4 is the overall architecture schematic diagram of the final formed cross-layer interaction security vulnerability automatic defense mechanism. Among them, this solution mainly includes two modules written in C language, the BPF program module and the monitoring program module, and the eBPF module in the kernel. The following will introduce the specific principle:
[0101] 1. The logic of the above two defense sub-modules is fully implemented in the BPF program and combined. Subsequently, it is compiled into BPF bytecode through the llvm / clang tool chain and loaded into the kernel.
[0102] 2. The eBPF module in the kernel verifies the legality of the BPF bytecode, and then translates it into machine language and executes it through the JIT (Just-In-Time compiler). During the operation of the automatic defense mechanism, it interacts with the BPF Map for reading and writing to implement the sub-module function and the logging function.
[0103] 3. Before the bytecode is loaded into the kernel, the BPF monitor randomly generates a 32-bit hash key value and sends it to the BPF Map for the core implementation of this design to read. At the same time, it periodically reads the BPF Map to obtain the log information generated during the operation of the defense module and writes it into the specified log file for users to conduct security audits.
[0104] The automatic defense method for protocol stack cross-layer interaction security vulnerabilities based on eBPF in the embodiments of the present invention combines two automatic defense modules and is implemented and loaded through eBPF, forming an automatic defense mechanism for protocol stack cross-layer interaction security vulnerabilities based on eBPF, aiming to help user terminals automatically mitigate and defend common protocol stack cross-layer interaction security vulnerabilities, thereby improving the robustness of the protocol stack implementation.
[0105] To implement the above embodiments, as Figure 5 shown, an automatic defense system 10 for protocol stack cross-layer interaction security vulnerabilities based on eBPF is further provided in this embodiment. The system 10 includes:
[0106] A hash key value distribution module 100, which is used to randomly generate a hash key value through the monitor program module and send it to the BPF Map;
[0107] A defense compilation module 200, which is used to respectively run a stateless ICMP Error message filter and an ICMP input rate limiter in the BPF program module to process the current ICMP message, combine these two components, and compile the combined program into BPF bytecode through the llvm / clang tool chain and load it into the kernel;
[0108] A verification and translation module 300, which is used for the eBPF module in the kernel to verify the legality of the BPF bytecode, and based on the verification result, translate the BPF bytecode into machine language and execute it through the JIT just-in-time compiler, and interact with the BPF Map for reading and writing during the operation of the automatic defense mechanism;
[0109] A log acquisition module 400, which is used to use the monitor program module to read the BPF Map to obtain the log information generated during the operation of the stateless ICMP Error message filter and the ICMP input rate limiter and write it into the log file.
[0110] The automatic defense system for protocol stack cross-layer interaction security vulnerabilities based on eBPF in the embodiments of the present invention combines two automatic defense modules and is implemented and loaded through eBPF, forming an automatic defense mechanism for protocol stack cross-layer interaction security vulnerabilities based on eBPF, aiming to help user terminals automatically mitigate and defend common protocol stack cross-layer interaction security vulnerabilities, thereby improving the robustness of the protocol stack implementation.
[0111] To implement the method of the above embodiments, the present invention also provides a computer device, as Figure 6 shown. The computer device 600 includes a memory 601 and a processor 602. Among them, the processor 602 runs a program corresponding to the executable program code by reading the executable program code stored in the memory 601, so as to implement each step of the method described above.
[0112] To implement the above embodiments, the present invention also proposes a non-transitory computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the method described in the foregoing embodiments is implemented.
[0113] In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0114] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of the present invention, "a plurality" means at least two, such as two, three, etc., unless otherwise specifically and clearly defined.
Claims
1. A method for automatic defense of cross-layer interactive security vulnerabilities in a protocol stack based on eBPF, characterized in that: include: The monitoring program module randomly generates a hash key value and sends it to the BPF Map; In the BPF program module, the stateless ICMP Error message filter and the ICMP input rate limiter are run separately to process the current ICMP message, and these two components are combined. The combined program is compiled into BPF bytecode through the llvm / clang tool chain and loaded into the kernel; The eBPF module in the kernel verifies the legitimacy of the BPF bytecode, and based on the verification result, translates the BPF bytecode into machine language through the JIT compiler and executes it. During the operation of the automated defense mechanism, it interacts with the BPF Map for reading and writing. The monitoring program module is used to read the BPF Map to obtain the log information generated by the stateless ICMP Error message filter and the ICMP input rate limiter during operation, and write them into the log file.
2. The method according to claim 1, characterized in that Run the stateless ICMP Error message filter to process the current ICMP message, including: S101, determine whether the current ICMP message is an ICMP Redirect message, if so, jump to S102, otherwise jump to S103; S102, determine whether the embedded message of the current message is a stateless protocol, if so, jump to S105, otherwise jump to S106; S103, determine whether the current message is an ICMP Fragment Needed message, if so, jump to S104, otherwise jump to S106; S104, determine whether the embedded message of the current message is a passively generated ICMP message, if so, jump to S105, otherwise jump to S106; S105, filter the current message and end the judgment logic; S106, receiving the current message and ending the judgment logic.
3. The method according to claim 1, characterized in that Generate a 32-bit hash key value when the ICMP input rate limiter is loaded; run the ICMP input rate limiter to process the current ICMP message, including: S11, extract the 24-bit prefix of the source IP address of the ICMP message and use it as a parameter to calculate the hash value in conjunction with the hash key value generated during initialization; S12, using the calculated hash value as the key from the BPF Map, retrieve the time stamp and credit value stored in the corresponding entry, restore the credit based on the difference between the current time and the time stamp, and update the time stamp to the current time; S13, randomly generate the credit consumption value of the current ICMP message, compare the value of consume with the value of credit, if credit is greater than or equal to consume, jump to S14, otherwise jump to S15; S14, subtract the value of consume from credit, and update it back to the original entry in the BPF Map, receive the current ICMP message, and end the judgment logic; S15, filter the current ICMP message and end the judgment logic.
4. The method according to claim 1, characterized in that: The stateless ICMP Error message filter only filters ICMP Fragment Needed messages embedded with passively generated ICMP messages, where the passively generated ICMP messages include ICMPEcho Reply, ICMP Destination Unreachable, and ICMP Redirect.
5. The method according to claim 1, characterized in that The ICMP input rate limiter is designed with 2048 hash-based LRU entries. The source IP address is mapped to one of the entries for calculation. The hash value is calculated using a prefix of the source IP address with a length of 24. The credit amount consumed by each ICMP message is randomized to 1 or 2, ultimately ensuring that each hash table entry receives at most the earliest 500 to 1000 ICMP messages arriving per second.
6. An automatic defense system for cross-layer interactive security vulnerabilities of protocol stack based on eBPF, characterized in that: include: The hash key value sending module is used to randomly generate hash key values through the monitoring program module and send them to the BPF Map; The defense compilation module is used to run the stateless ICMP Error message filter and ICMP input rate limiter in the BPF program module to process the current ICMP message, combine the two components, and compile the combined program into BPF bytecode through the llvm / clang tool chain and load it into the kernel; Verification and translation module, used by the eBPF module in the kernel to verify the legitimacy of the BPF bytecode, and based on the verification result, translate the BPF bytecode into machine language through the JIT compiler and execute it. During the operation of the automated defense mechanism, it interacts with the BPF Map for reading and writing; The log acquisition module is used to use the monitoring program module to read the BPF Map to obtain the log information generated when the stateless ICMP Error message filter and the ICMP input rate limiter are running, and write them into the log file.
7. The system according to claim 6, characterized in that The stateless ICMP Error message filter filters ICMP Fragment Needed messages embedded with passively generated stateless protocol messages and ICMP Redirect messages embedded with any stateless protocol messages; passively generated ICMP messages include ICMP Echo Reply, ICMP Destination Unreachable and ICMP Redirect.
8. The system according to claim 6, characterized in that The ICMP input rate limiter is designed with 2048 hash-based LRU entries. The source IP address is mapped to one of the entries for calculation. The hash value is calculated using a prefix of the source IP address with a length of 24. The credit amount consumed by each ICMP message is randomized to 1 or 2, ultimately ensuring that each hash table entry receives at most the earliest 500 to 1000 ICMP messages arriving per second.
9. A computer device, characterized in that: including a processor and a memory; The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the automatic defense method for cross-layer interactive security vulnerabilities of the protocol stack based on eBPF as described in any one of claims 1-5.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method for automatically defending against cross-layer interactive security vulnerabilities of the protocol stack based on eBPF as described in any one of claims 1 to 5 is implemented.