Automatic memory protection method and device, computer equipment and storage medium
Through real-time tag verification of memory operations, dynamically partitioning and managing memory areas is solved, and the problem of data-oriented attacks is improved, memory security and system operation efficiency are improved.
Patent Information
- Application Number
- CN202510210671.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-07-04
AI Technical Summary
The existing technology cannot effectively prevent data-oriented attacks, resulting in non-controlled data facing risks such as data leakage, increased permissions, and arbitrary code execution.
By responding to real-time memory read and write instructions, the pre-memory mark value and actual mark value of the target memory address are determined, and memory operations are blocked when mismatch, dynamically divide the mark area and memory pool, generate unique mark value, embed the memory block metadata area, and monitor and verify the legitimacy of memory access in real time.
It has effectively prevented data-oriented attacks, improved memory security and system operation efficiency, and ensured the legality and security of memory access.
Smart Images

Figure CN120256337A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technologies, and in particular, to an automated memory protection method, apparatus, computer device, and storage medium. Background Art
[0002] Current memory security protection technologies mainly focus on preventing control flow attacks such as buffer overflow attacks and return-oriented programming, and cannot effectively prevent data-oriented attacks. In a data-oriented attack, an attacker usually constructs data carefully and uses the data processing logic in a program to carry out an attack, resulting in risks such as data leakage, privilege escalation, and arbitrary code execution for non-control data.
[0003] Regarding the problem that data-oriented attacks cannot be effectively prevented in related technologies, no effective solution has been proposed yet. Summary of the Invention
[0004] In this embodiment, an automated memory protection method, apparatus, computer device, and storage medium are provided to solve the problem that data-oriented attacks cannot be effectively prevented in related technologies.
[0005] In a first aspect, in this embodiment, an automated memory protection method is provided. The method includes:
[0006] In response to a real-time memory read / write instruction, determine a target memory address corresponding to the memory read / write instruction;
[0007] Determine a pre-stored marker value corresponding to the target memory address, and an actual marker value currently embedded in the memory block pointed to by the target memory address;
[0008] When it is detected that the pre-stored marker value does not match the actual marker value, block the memory operation associated with the memory read / write instruction.
[0009] In some of the embodiments, before the step of in response to a real-time memory read / write instruction, determine a target memory address corresponding to the memory read / write instruction, the method further includes:
[0010] Dynamically divide a plurality of marker regions according to the memory requirements of an application program; wherein each of the marker regions includes a plurality of memory pools, and each of the memory pools includes at least one memory block;
[0011] Generate a unique marker value corresponding to each of the memory pools;
[0012] Embed the unique marker value into the metadata area of each memory block in the memory pool.
[0013] In some of these embodiments, after dynamically partitioning multiple marked regions according to the memory requirements of the application program, the method further includes:
[0014] In response to a real-time memory application, selecting the marked region that is adapted to the memory application;
[0015] In the marked region that is adapted to the memory application, creating the memory pool corresponding to the memory application.
[0016] In some of these embodiments, after blocking the memory operation associated with the memory read / write instruction, the method further includes:
[0017] Determining all memory blocks with unreleased memory within each marked region;
[0018] Clearing the marked data of each memory block with unreleased memory, and releasing the corresponding records of each memory block in the memory control register.
[0019] In some of these embodiments, after blocking the memory operation associated with the memory read / write instruction, the method further includes:
[0020] Controlling the system for running the application program to enter a recovery mode; the recovery mode is used to instruct the system to reallocate memory or reset each marked region according to a preset policy.
[0021] In some of these embodiments, the determining the pre-stored marked value corresponding to the target memory address includes:
[0022] Retrieving the mapping relationship associated with the target memory address;
[0023] According to the mapping relationship, determining the pre-stored marked value corresponding to the target memory address.
[0024] In some of these embodiments, after determining the pre-stored marked value corresponding to the target memory address and the actual marked value currently embedded in the memory block pointed to by the target memory address, it further includes:
[0025] When it is detected that the pre-stored marked value matches the actual marked value, performing the memory operation associated with the memory read / write instruction.
[0026] In a second aspect, in this embodiment, an automated memory protection device is provided, and the device includes:
[0027] An extraction module, configured to determine a target memory address corresponding to the memory read / write instruction in response to a real-time memory read / write instruction;
[0028] A reading module, configured to determine a pre-stored tag value corresponding to the target memory address, and an actual tag value currently embedded in the memory block pointed to by the target memory address;
[0029] A matching module, configured to prevent a memory operation associated with the memory read / write instruction when it is detected that the pre-stored tag value does not match the actual tag value.
[0030] In a third aspect, in the present embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the automated memory protection method described in the first aspect above is implemented.
[0031] In a fourth aspect, in the present embodiment, a storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the automated memory protection method described in the first aspect above is implemented.
[0032] Compared with the related art, the automated memory protection method, device, computer device, and storage medium provided in the present embodiment determine a target memory address corresponding to a memory read / write instruction in response to a real-time memory read / write instruction; determine a pre-stored tag value corresponding to the target memory address and an actual tag value currently embedded in the memory block pointed to by the target memory address; and prevent a memory operation associated with the memory read / write instruction when it is detected that the pre-stored tag value does not match the actual tag value, thereby solving the problem of being unable to effectively prevent data-oriented attacks, achieving effective prevention of data-oriented attacks, and improving memory security and system operation efficiency.
[0033] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0035] Figure 1 is a hardware structure block diagram of a terminal device of the automated memory protection method provided in an embodiment of the present application;
[0036] Figure 2 is a flowchart of the automated memory protection method provided in an embodiment of the present application;
[0037] Figure 3 is a flowchart of a memory allocation method provided in an embodiment of the present application;
[0038] Figure 4 It is a flowchart of a method for reading pre - stored marker values provided by an embodiment of the present application;
[0039] Figure 5 It is a flowchart of an automated memory protection method provided by a preferred embodiment of the present application;
[0040] Figure 6 It is a structural block diagram of an automated memory protection device provided by an embodiment of the present application.
[0041] In the figure: 102, processor; 104, memory; 106, transmission device; 108, input / output device; 10, extraction module; 20, reading module; 30, matching module. Detailed implementation manners
[0042] For a clearer understanding of the purpose, technical solutions, and advantages of the present application, the present application will be described and explained below with reference to the accompanying drawings and embodiments.
[0043] Unless otherwise defined, the technical terms or scientific terms involved in the present application shall have the general meaning understood by those with ordinary skills in the technical field to which the present application belongs. In the present application, words such as "a", "one", "a kind of", "the", "these", etc. do not indicate a limitation in quantity, and they can be singular or plural. The terms "including", "comprising", "having" and any variants thereof involved in the present application are intended to cover non - exclusive inclusion; for example, a process, method, system, product, or device including a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products, or devices. The terms "connected", "coupled", etc. involved in the present application do not limit to physical or mechanical connections, but may include electrical connections, whether directly or indirectly. The term "plurality" involved in the present application refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" may represent: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " indicates that the objects before and after are in an "or" relationship. The terms "first", "second", "third", etc. involved in the present application only distinguish similar objects and do not represent a specific sorting of the objects.
[0044] The method embodiments provided in this embodiment can be executed on a terminal, a computer, or a similar computing device. For example, running on a terminal, Figure 1 It is a hardware structural block diagram of the terminal of the automated memory protection method in this embodiment. As Figure 1As shown, the terminal may include one or more ( Figure 1 only one is shown in the figure) processors 102 and a memory 104 for storing data. Among them, the processor 102 may include, but is not limited to, processing devices such as a microprocessor MCU or a field programmable gate array FPGA. The above terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above terminal. For example, the terminal may further include more or fewer components than Figure 1 shown in the figure, or have a different configuration from Figure 1 shown in the figure.
[0045] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the automated memory protection method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0046] The transmission device 106 is used to receive or send data via a network. The above network includes a wireless network provided by the communication provider of the terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0047] In this embodiment, an automated memory protection method is provided. Figure 2 is a flowchart of the automated memory protection method of this embodiment. As Figure 2 shown, the process includes the following steps:
[0048] Step S210, in response to a real-time memory read / write instruction, determine the target memory address corresponding to the memory read / write instruction;
[0049] Step S220: Determine the pre-stored tag value corresponding to the target memory address and the actual tag value currently embedded in the memory block pointed to by the target memory address;
[0050] Step S230: When it is detected that the pre-stored tag value does not match the actual tag value, block the memory operation associated with the memory read / write instruction.
[0051] Specifically, when the application starts, the system loads the memory management module, registers the memory tag protection function, initializes the tag register, and defines the memory tag table structure of the memory pool. The memory tag table structure includes the tag value field, memory address range field, and lifecycle field of the memory pool. In addition, the memory management module activates tag protection through the system configuration file or predefined policy at startup, and loads the configuration into the memory control register, which is used to manage the allocation and recycling status of tag values.
[0052] Furthermore, according to the memory requirements during the operation of the application, dynamically divide multiple tag regions, create corresponding multiple memory pools within each tag region, and each memory pool contains at least one memory block. Generate a unique tag value corresponding to each memory pool, embed the unique tag value into the metadata area at the head of each memory block in the memory pool, implement fully automatic analysis of stack memory allocation, and record the mapping relationship between the corresponding memory address of the memory block and the tag value in a preset memory management table or register.
[0053] During the operation of the application, monitor memory operations in real time. The memory management module intercepts the memory read / write instruction before the memory operation is executed, extracts the target memory address corresponding to the memory read / write instruction. Read the pre-stored tag value corresponding to the target memory address from the preset memory management table or register, determine the memory block pointed to by the target memory address, obtain the actual tag value currently embedded in the memory block, and compare the pre-stored tag value with the actual tag value to detect whether the pre-stored tag value matches the actual tag value. If the pre-stored tag value does not match the actual tag value, block the memory operation associated with the memory read / write instruction; otherwise, normally execute the memory operation associated with the memory read / write instruction.
[0054] Among them, after blocking the memory operation associated with the memory read / write instruction, trigger a memory protection exception and generate a detailed log file to record the access time when the exception occurs, the target address where the exception appears, and the current tag status. At the same time, control the system for running the application to enter the recovery mode. In the recovery mode, the system reallocates memory or resets each tag region according to the preset policy to restore the normal operation of the application.
[0055] It should be noted that in this embodiment, based on the ARM Memory Tag Extension (MTE), the use of memory tags and tag verification mechanisms is implemented to detect and prevent illegal memory access. It can accelerate tag verification through hardware, resulting in a relatively small performance overhead for the tagging and monitoring processes, reducing the deployment cost. At the same time, it does not rely on static analysis and can well adapt to dynamic program behaviors. Among them, the stack memory allocation can be automatically tagged through a Low Level Virtual Machine (LLVM) compiler plugin, achieving automatic adaptation to the existing program structure, supporting multiple program environments, and eliminating the need for manual intervention.
[0056] Current memory security protection technologies mainly focus on preventing control flow attacks such as buffer overflow attacks and return-oriented programming, and are unable to effectively prevent data-oriented attacks. In data-oriented attacks, attackers usually carefully construct data and use the data processing logic in the program to carry out attacks, resulting in risks such as data leakage, privilege escalation, and arbitrary code execution for non-control data.
[0057] Compared with the prior art, in this application, in response to a real-time memory read / write instruction, the target memory address corresponding to the memory read / write instruction is determined; the pre-stored tag value corresponding to the target memory address and the actual tag value currently embedded in the memory block pointed to by the target memory address are determined; when it is detected that the pre-stored tag value does not match the actual tag value, the memory operation associated with the memory read / write instruction is blocked. Based on this, by real-time monitoring of memory operations, memory tag verification is performed on the target memory address before the memory operation is executed to ensure the legality of each memory access, so as to be able to timely block illegal operations, prevent memory corruption and potential attacks, solve the problem of being unable to effectively prevent data-oriented attacks, achieve full-stack memory protection, effectively prevent data-oriented attacks, and improve memory security and system operation efficiency.
[0058] In some of these embodiments, as Figure 3 shown, before determining the target memory address corresponding to the real-time memory read / write instruction, the following steps are further included:
[0059] Step S201, dynamically divide multiple tag regions according to the memory requirements of the application program; wherein, each tag region contains multiple memory pools, and each memory pool contains at least one memory block;
[0060] Step S202, generate a unique tag value for each memory pool;
[0061] Step S203, embed the unique tag value into the metadata area of each memory block in the memory pool.
[0062] Specifically, according to the memory requirements during the operation of the application program, multiple marked areas are dynamically divided. The sizes and uses of the marked areas are different. For example, the marked areas are respectively used to store information in different running stages of the application program. A corresponding number of memory pools are created within each marked area. Each memory pool contains at least one memory block. Each memory block is aligned according to a predefined granularity. For example, the memory block is aligned by 16 bytes to ensure boundary alignment and prevent cross-boundary access and out-of-bounds operations. Among them, the number of memory blocks required for different memory requirements may be the same or different.
[0063] Furthermore, a random marking generation algorithm is adopted to generate a unique marking value corresponding to each memory pool, and the unique marking value is embedded in the metadata area of each memory block in the memory pool, so that the system can quickly obtain the marking value for verification when accessing the memory block, and record the mapping relationship between the corresponding memory address of the memory block and the marking value in a preset memory management table or register. For example, a random number generator (RNG) and a hash function are used to generate a random unique marking value, or an encryption operation is performed based on a timestamp and a process identifier to obtain a unique marking value. The specific method is not limited here, ensuring that the marking is difficult to predict. In this embodiment, a cyclic allocation strategy is adopted for marking value allocation, so that the marking values are cyclically allocated within a specified range to avoid conflicts caused by duplicate markings.
[0064] It should be noted that during the program compilation stage, the compiler will automatically insert marking generation and marking detection instructions into the code. The marking generation instruction is used to generate a random marking value during memory allocation and embed it into the memory block, while the marking detection instruction is used to check whether the marking value matches during memory access, ensuring that the memory management mechanism is transparent to developers, reducing the possibility of human errors, and improving the security and reliability of the program.
[0065] Through this embodiment, according to the memory requirements of the application program, multiple marked areas are dynamically divided. Each marked area contains multiple memory pools, and each memory pool contains at least one memory block. A unique marking value corresponding to each memory pool is generated, and the unique marking value is embedded in the metadata area of each memory block in the memory pool. In this way, the memory protection range is dynamically adjusted through an adaptive memory allocation strategy to ensure the safe and efficient operation of the program. And during the memory allocation stage, a memory marking is generated according to a preset allocation strategy and memory security requirements, and the marking data is written into the memory control metadata area through a marking embedding mechanism to achieve multi-layer security protection.
[0066] In some of these embodiments, after dynamically dividing multiple marked areas according to the memory requirements of the application program, the above-mentioned automated memory protection method further includes the following steps:
[0067] In response to a real-time memory application, select a marked area that is adapted to the memory application;
[0068] Create a memory pool corresponding to the memory application in the marked area adapted to the memory application.
[0069] Specifically, when the application program initiates a real-time memory application, select the marked area adapted to the memory application, and create a memory pool corresponding to the memory application in the marked area adapted to the memory application. Among them, the appropriate marked area can be selected according to the size and type of the memory block required by the memory application, so as to avoid resource waste caused by using too large a memory area to meet small memory requirements or using a memory area of an unmatched type.
[0070] It should be noted that if it is detected that the remaining space in the currently selected marked area is insufficient, a new marked area will be automatically expanded to provide additional memory space for the application program, or through the memory pool reorganization mechanism, the unused memory blocks in the current marked area will be sorted out, and the scattered free memory blocks will be merged into continuous memory blocks to improve memory utilization.
[0071] Through this embodiment, in response to a real-time memory application, select the marked area adapted to the memory application, and create a memory pool corresponding to the memory application in the marked area adapted to the memory application, so as to accurately adapt to the memory requirements during memory allocation, dynamically respond to changes in memory requirements, help improve memory utilization, and ensure the safe and stable operation of the program at the same time.
[0072] In some of these embodiments, after blocking the memory operation associated with the memory read / write instruction, the above-mentioned automated memory protection method further includes the following steps:
[0073] Determine all the memory blocks of the unreleased memory in each marked area;
[0074] Clear the marked data of each memory block of the unreleased memory, and release the corresponding records of each memory block in the memory control register.
[0075] Specifically, after blocking the memory operation associated with the memory read / write instruction, if a program crash or illegal exit event is detected, start emergency memory cleaning to control the system to scan each marked area in the memory address space, determine all the memory blocks of the unreleased memory in each marked area, clear the marked data of each memory block of the unreleased memory, and release the corresponding records of each memory block in the memory control register, and restore the available state of the memory pool, so that the memory resources can be reallocated and used subsequently.
[0076] Exemplarily, in the case where the marked value verification does not match, if the system cannot solve the corresponding problem through the recovery mechanism and the program falls into a state where it cannot work properly due to frequent blocking of memory operations, causing a program crash, then start the abnormal recovery mechanism to trigger emergency memory cleaning.
[0077] Through this embodiment, all memory blocks with unreleased memory in each marked area are determined, the marking data of each memory block with unreleased memory is cleared, and the corresponding records of each memory block in the memory control register are released, so as to perform a memory marking cleaning operation in the case of abnormal program operation, ensure the safe and stable release of memory resources, and prevent marking leakage.
[0078] In some of these embodiments, after blocking the memory operation associated with the memory read / write instruction, the above-mentioned automated memory protection method further includes the following steps:
[0079] Control the system for running the application program to enter the recovery mode; the recovery mode is used to instruct the system to reallocate memory or reset each marked area according to a preset policy.
[0080] Specifically, when it is detected that the pre-stored mark value does not match the actual mark value, the memory operation associated with the memory read / write instruction is blocked, a memory protection exception is triggered, and a detailed log file is generated to record the access time when the exception occurs, the target address where the exception occurs, and the current mark status.
[0081] After that, control the system for running the application program to enter the recovery mode. In the recovery mode, the system reallocates memory or resets each marked area according to a preset policy based on the current requirements of the application program, so as to try to resume the normal operation of the application program. It should be noted that if the recovery fails, the control system enters the safe mode to block further memory operations to protect the core data of the system.
[0082] Through this embodiment, control the system for running the application program to enter the recovery mode. The recovery mode is used to instruct the system to reallocate memory or reset each marked area according to a preset policy, so as to solve the program operation problem caused by abnormal conditions and improve the system fault tolerance.
[0083] In some of these embodiments, as Figure 4 shown, determining the pre-stored mark value corresponding to the target memory address in step S220 includes the following steps:
[0084] Step S221, retrieve the mapping relationship associated with the target memory address;
[0085] Step S222, determine the pre-stored mark value corresponding to the target memory address according to the mapping relationship.
[0086] It should be noted that in the memory allocation stage, a unique mark value corresponding to each memory pool is generated. While embedding the unique mark value into the metadata area of each memory block in the memory pool, a mapping relationship between the corresponding memory address of the memory block and the mark value is constructed, and the mapping relationship between the memory address and the mark value is recorded in a preset memory management table or register.
[0087] During memory tag verification, a pre-stored tag value corresponding to the target memory address is read from a preset memory management table or register, so as to compare the pre-stored tag value with the actual tag value currently embedded in the corresponding memory block, and detect whether the pre-stored tag value matches the actual tag value.
[0088] Through this embodiment, the mapping relationship associated with the target memory address is retrieved, so that the pre-stored tag value corresponding to the target memory address can be accurately obtained according to the mapping relationship, and memory tag verification is realized.
[0089] In some of these embodiments, after determining the pre-stored tag value corresponding to the target memory address and the actual tag value currently embedded in the memory block pointed to by the target memory address, the following steps are further included:
[0090] When it is detected that the pre-stored tag value matches the actual tag value, a memory operation associated with the memory read / write instruction is executed.
[0091] Specifically, the pre-stored tag value is compared with the actual tag value to detect whether the pre-stored tag value matches the actual tag value. If the pre-stored tag value matches the actual tag value, the memory operation associated with the memory read / write instruction is normally executed.
[0092] It should be further noted that if the application program is executed normally, when the application program terminates normally or a function returns, the system will automatically detect unused memory blocks and clean the corresponding tag data. In addition, the memory recycling mechanism depends on the tag lifecycle management table, which is used to record the lifecycle information of each memory block tag, so as to uniformly recycle the tags with the end of the lifecycle according to the tag lifecycle management table, improving the memory management efficiency.
[0093] Through this embodiment, when it is detected that the pre-stored tag value matches the actual tag value, a memory operation associated with the memory read / write instruction is executed to ensure the normal operation of the program after memory tag verification. At the same time, the system enables a normal recycling mechanism to improve the utilization rate of the system memory, and combines the above abnormal recycling mechanism to ensure the safe and stable release of memory resources through active and passive memory management strategies.
[0094] The following describes and illustrates this embodiment through preferred embodiments.
[0095] Figure 5 is the flowchart of the automated memory protection method of this preferred embodiment, as Figure 5 shown, the automated memory protection method includes the following steps:
[0096] Step S510: Dynamically divide multiple tagged regions according to the memory requirements of the application program. Each tagged region contains multiple memory pools, and each memory pool contains at least one memory block.
[0097] Step S520: Generate a unique tag value for each memory pool, embed the unique tag value into the metadata area of each memory block in the memory pool, and record the mapping relationship between the corresponding memory address of the memory block and the tag value in a preset memory management table.
[0098] Step S530: In response to a real-time memory read / write instruction, determine the target memory address corresponding to the memory read / write instruction.
[0099] Step S540: Retrieve the mapping relationship associated with the target memory address, determine the pre-stored tag value corresponding to the target memory address according to the mapping relationship, and obtain the actual tag value currently embedded in the memory block pointed to by the target memory address.
[0100] Step S550: When it is detected that the pre-stored tag value matches the actual tag value, normally execute the memory operation associated with the memory read / write instruction.
[0101] Step S560: When it is detected that the pre-stored tag value does not match the actual tag value, block the memory operation associated with the memory read / write instruction, and control the system for running the application program to enter the recovery mode. The recovery mode is used to instruct the system to reallocate memory or reset each tagged region according to a preset policy.
[0102] Through this embodiment, multiple tagged regions are dynamically divided according to the memory requirements of the application program. Each tagged region contains multiple memory pools, and each memory pool contains at least one memory block. A unique tag value is generated for each memory pool, the unique tag value is embedded into the metadata area of each memory block in the memory pool, and the mapping relationship between the corresponding memory address of the memory block and the tag value is recorded in a preset memory management table.
[0103] In response to a real-time memory read / write instruction, the target memory address corresponding to the memory read / write instruction is determined, the mapping relationship associated with the target memory address is retrieved, the pre-stored tag value corresponding to the target memory address is determined according to the mapping relationship, and the actual tag value currently embedded in the memory block pointed to by the target memory address is obtained. When it is detected that the pre-stored tag value matches the actual tag value, the memory operation associated with the memory read / write instruction is normally executed, while when it is detected that the pre-stored tag value does not match the actual tag value, the memory operation associated with the memory read / write instruction is blocked, and the system for running the application program is controlled to enter the recovery mode. The recovery mode is used to instruct the system to reallocate memory or reset each tagged region according to a preset policy, solving the problem of being unable to effectively prevent data-oriented attacks, achieving effective prevention of data-oriented attacks, and improving memory security and system operation efficiency.
[0104] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0105] In this embodiment, an automated memory protection device is also provided. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated here. The following terms such as "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0106] Figure 6 is the structural block diagram of the automated memory protection device of this embodiment, as Figure 6 shown, this device includes:
[0107] An extraction module 10, configured to determine a target memory address corresponding to a real-time memory read / write instruction in response to the instruction.
[0108] A reading module 20, configured to determine a pre-stored marker value corresponding to the target memory address, and an actual marker value currently embedded in the memory block pointed to by the target memory address.
[0109] A matching module 30, configured to prevent a memory operation associated with the memory read / write instruction when it detects that the pre-stored marker value does not match the actual marker value.
[0110] Through the device provided in this embodiment, in response to a real-time memory read / write instruction, a target memory address corresponding to the memory read / write instruction is determined; a pre-stored marker value corresponding to the target memory address, and an actual marker value currently embedded in the memory block pointed to by the target memory address are determined; when it is detected that the pre-stored marker value does not match the actual marker value, a memory operation associated with the memory read / write instruction is prevented, solving the problem of being unable to effectively prevent data-oriented attacks, achieving effective prevention of data-oriented attacks, and improving memory security and system operation efficiency.
[0111] In some of these embodiments, on the basis of Figure 6 this, the device further includes a dynamic allocation module, configured to dynamically divide a plurality of marker regions according to the memory requirements of the application program; wherein each marker region contains a plurality of memory pools, each memory pool contains at least one memory block; generate a unique marker value corresponding to each memory pool; and embed the unique marker value into the metadata area of each memory block in the memory pool.
[0112] In some of these embodiments, the dynamic allocation module is further configured to select a marked area adapted to the memory application in response to a real-time memory application; and create a memory pool corresponding to the memory application in the marked area adapted to the memory application.
[0113] In some of these embodiments, based on Figure 6 the above, the device further includes a recycling module, configured to determine memory blocks of all unreleased memory in each marked area; clean the marking data of the memory blocks of all unreleased memory, and release the corresponding records of each memory block in the memory control register.
[0114] In some of these embodiments, based on Figure 6 the above, the device further includes a recovery module, configured to control the system for running the application program to enter the recovery mode; the recovery mode is used to instruct the system to reallocate memory or reset each marked area according to a preset policy.
[0115] In some of these embodiments, the reading module 20 is further configured to retrieve a mapping relationship associated with the target memory address; and determine a pre-stored marking value corresponding to the target memory address according to the mapping relationship.
[0116] In some of these embodiments, the matching module 30 is further configured to perform a memory operation associated with the memory read / write instruction when it detects that the pre-stored marking value matches the actual marking value.
[0117] It should be noted that the above-mentioned various modules can be functional modules or program modules, and can be implemented either by software or by hardware. For the modules implemented by hardware, the above-mentioned various modules can be located in the same processor; or the above-mentioned various modules can also be located in different processors in any combined form.
[0118] In this embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0119] Optionally, the above computer device may further include a transmission device and an input / output device, wherein the transmission device is connected to the above processor, and the input / output device is connected to the above processor.
[0120] Optionally, in this embodiment, the above processor may be configured to execute the following steps through the computer program:
[0121] S1, in response to a real-time memory read / write instruction, determine a target memory address corresponding to the memory read / write instruction;
[0122] S2. Determine the pre-stored tag value corresponding to the target memory address and the actual tag value currently embedded in the memory block pointed to by the target memory address;
[0123] S3. When it is detected that the pre-stored tag value does not match the actual tag value, block the memory operation associated with the memory read / write instruction.
[0124] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, and will not be elaborated herein.
[0125] In addition, in combination with the automated memory protection method provided in the above embodiments, a storage medium can also be provided in this embodiment to implement it. A computer program is stored on the storage medium; when the computer program is executed by a processor, any one of the automated memory protection methods in the above embodiments is implemented.
[0126] It should be understood that the specific embodiments described here are only used to explain this application, rather than to limit it. According to the embodiments provided in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0127] Obviously, the drawings are only some examples or embodiments of the present application. For those of ordinary skill in the art, the present application can also be applied to other similar situations based on these drawings without creative work. In addition, it can be understood that although the work done during the development process here may be complex and time-consuming, for those of ordinary skill in the art, certain design, manufacturing, or production changes based on the technical content disclosed in the present application are only conventional technical means and should not be regarded as insufficient disclosure of the present application.
[0128] The term "embodiment" in the present application means that the specific features, structures, or characteristics described in combination with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various positions in the specification does not necessarily mean the same embodiment, nor does it mean being independent or alternative to other embodiments and mutually exclusive. Those of ordinary skill in the art can clearly or implicitly understand that the embodiments described in the present application can be combined with other embodiments without conflict.
[0129] The above-described embodiments only represent several implementation manners of the present application, and their descriptions are relatively specific and detailed, but should not be construed as a limitation on the scope of patent protection. It should be pointed out that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. An automated memory protection method, characterized in that, The method includes: In response to a real-time memory read / write instruction, determining a target memory address corresponding to the memory read / write instruction; Determining a pre-stored tag value corresponding to the target memory address, and an actual tag value currently embedded in the memory block pointed to by the target memory address; When it is detected that the pre-stored tag value does not match the actual tag value, blocking the memory operation associated with the memory read / write instruction.
2. The automated memory protection method according to claim 1, wherein Before the step of, in response to a real-time memory read / write instruction, determining a target memory address corresponding to the memory read / write instruction, the method further includes: Dynamically dividing a plurality of tag regions according to the memory requirements of the application program; wherein each of the tag regions includes a plurality of memory pools, and each of the memory pools includes at least one memory block; Generating a unique tag value corresponding to each of the memory pools; Embedding the unique tag value into the metadata area of each memory block in the memory pool.
3. The automated memory protection method according to claim 2, wherein After the step of dynamically dividing a plurality of tag regions according to the memory requirements of the application program, the method further includes: In response to a real-time memory application, selecting a tag region suitable for the memory application; In the tag region suitable for the memory application, creating the memory pool corresponding to the memory application.
4. The automated memory protection method according to claim 2, wherein After the step of blocking the memory operation associated with the memory read / write instruction, the method further includes: Determining the memory blocks with unreleased memory in each of the tag regions; Clearing the tag data of the memory blocks with unreleased memory, and releasing the corresponding records of the memory blocks in the memory control register.
5. The automated memory protection method according to claim 2, wherein After the step of blocking the memory operation associated with the memory read / write instruction, the method further includes: Controlling the system for running the application program to enter a recovery mode; the recovery mode is used to instruct the system to reallocate memory or reset each of the tag regions according to a preset policy.
6. The automated memory protection method according to claim 1, characterized in that The step of determining the pre-stored tag value corresponding to the target memory address includes: Retrieving a mapping relationship associated with the target memory address; According to the mapping relationship, determining the pre-stored tag value corresponding to the target memory address.
7. The automated memory protection method according to claim 1, wherein After the step of determining the pre-stored tag value corresponding to the target memory address, and the actual tag value currently embedded in the memory block pointed to by the target memory address, the method further includes: When it is detected that the pre-stored tag value matches the actual tag value, performing the memory operation associated with the memory read / write instruction.
8. An automated memory protection device, characterized in that, The apparatus includes: An extraction module, configured to determine a target memory address corresponding to the memory read / write instruction in response to a real-time memory read / write instruction; A reading module, configured to determine a pre-stored tag value corresponding to the target memory address, and an actual tag value currently embedded in the memory block pointed to by the target memory address; A matching module, configured to block the memory operation associated with the memory read / write instruction when it is detected that the pre-stored tag value does not match the actual tag value.
9. A computer device, comprising a memory and a processor, characterized in that, A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps of the automated memory protection method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the automated memory protection method according to any one of claims 1 to 7.
Citation Information
Cited By
Method and system for synchronously hiding multiple parameters in memory address
CN120723679A
Method and system for multi-parameter synchronization concealment in memory address
CN120723679B
GPU memory security detection method and device, electronic equipment and readable storage medium
CN122044894A