Communication connection channel dynamic management method and device based on aspect program

By injecting a sectional program into the native layer of the Java virtual machine, dynamically adjusting the legal connection source, the problem of difficult to defend against JDWP channel intrusion is solved, and effective defense against JDWP channels is achieved.

CN120277660APending Publication Date: 2025-07-08ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510237736.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In the prior art, JDWP and JVMTI are on the same layer and do not expose external interfaces to the JAVA layer, resulting in the JAVA layer being unable to sense JDWP channel intrusion events, making it difficult to effectively defend against intrusion by attackers through JDWP channels.

Method used

Inject a section program into the native layer of the Java virtual machine, obtain the memory address of the legal connection source of the target application through symbol hijacking, set the tangent point and inject the section program, dynamically adjust the legal connection source, and use the section program to modify the attribute information of the legal connection source to intercept the illegal connection source.

Benefits of technology

It realizes dynamic defense of JDWP channels, can effectively intercept illegal connection sources, defend against JDWP channels intrusion, and does not require host permissions, and the kernel version has no strong dependencies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277660A_ABST
    Figure CN120277660A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a communication connection channel dynamic treatment method based on a section program, and the method comprises the steps: modifying a legal connection source of a target application through injecting the section program into a native layer of a java virtual machine, and intercepting an illegal connection source in a communication channel building process. Therefore, the defense strategy of the JDWP channel can be dynamically adjusted according to requirements, and JDWP channel intrusion can be effectively defended. According to the method, only the permission of the container where the target application is located needs to be obtained, host machine permission does not need to be obtained, and strong dependence on the kernel version is avoided. The communication connection channel dynamic management device based on the aspect program, the storage medium and the electronic equipment also have the above beneficial effects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a method and device for dynamically managing a communication connection channel based on an aspect program. Background Art

[0002] JDWP (Java Debug Wire Protocol) is a communication protocol used for communication between a debugger and a debugged application. The debugger can use JDWP to send commands to the JVM and receive responses from the JVM. An attacker can connect to the application through the Java debug port JVMTI and obtain application permissions to execute instructions on the application machine, which is also called JDWP channel intrusion.

[0003] Since JDWP and JVMTI are at the same layer and no external interface is exposed to the JAVA layer, when an attacker conducts an intrusion attack through the JDWP channel, the JAVA layer cannot perceive the intrusion event, so it is difficult to effectively defend against the intrusion event. Summary of the Invention

[0004] One or more embodiments of this specification provide a method and device for dynamically managing a communication connection channel based on an aspect program, which can solve the problems existing in the related art.

[0005] In a first aspect, a method for dynamically managing a communication connection channel based on an aspect program is provided, which is applicable to a Java virtual machine, where the Java virtual machine deploys a target application, and the Java virtual machine communicates with a client using the JDWP protocol; the method includes:

[0006] Inject a pre-built aspect program into the native layer of the Java virtual machine;

[0007] Use the aspect program to modify the legal connection source of the target application;

[0008] In response to a communication connection request of the client for the target application, determine whether the client is a legal connection source, and determine whether to establish a communication connection with the client according to the judgment result.

[0009] As an optional implementation manner of the method described in the first aspect, the method further includes:

[0010] Before injecting the aspect program into the native layer of the Java virtual machine, in response to the issuance of a governance policy, construct the aspect program.

[0011] As an optional implementation manner of the method described in the first aspect, injecting the aspect program into the native layer of the Java virtual machine specifically includes:

[0012] Inject the aspect base into the native layer of the Java virtual machine through the JVMTI interface of the Java virtual machine;

[0013] Obtain the memory address of the legal connection source of the target application in the native library through symbol hijacking, and set the pointcut according to the memory address of the legal connection source of the target application;

[0014] Inject the aspect program into the pointcut through the aspect base.

[0015] Specifically, obtaining the memory address of the legal connection source of the target application in the native library through symbol hijacking specifically includes:

[0016] Obtain the address pointer of the public symbol method in the native library;

[0017] Obtain local symbol information according to the address pointer of the public symbol method;

[0018] Obtain the address offset between the legal connection source of the target application and the public symbol method according to the local symbol information;

[0019] Determine the memory address pointer of the legal connection source of the target application according to the address pointer of the public symbol method and the address offset between the legal connection source of the target application and the public symbol method.

[0020] As an optional implementation manner of the method in the first aspect, use the aspect program to modify the legal connection source of the target application, and the specific modification methods include at least one of adding a legal connection source, deleting a legal connection source, and modifying the attribute information of the current legal connection source.

[0021] Specifically, modifying the attribute information of the current legal connection source specifically includes:

[0022] Modify the IP address or network segment information of the current legal connection source.

[0023] In a second aspect, a dynamic governance device for a communication connection channel based on an aspect program is provided, which is applicable to a Java virtual machine, and the Java virtual machine deploys a target application, and the Java virtual machine communicates with a client using the JDWP protocol; the device includes:

[0024] An aspect injection module, configured to inject a pre-constructed aspect program into the native layer of the Java virtual machine, and use the aspect program to modify the legal connection source of the target application;

[0025] A connection module, configured to determine whether the client is a legitimate connection source in response to a communication connection request from the client for the target application, and determine whether to establish a communication connection with the client according to the judgment result.

[0026] As an optional implementation manner of the device described in the second aspect, the device further includes:

[0027] A cross-cutting aspect construction module, configured to construct the cross-cutting aspect program in response to the issuance of a governance policy.

[0028] As an optional implementation manner of the device described in the second aspect, the cross-cutting aspect injection module is specifically used for:

[0029] Inject a cross-cutting aspect base into the native layer of the Java virtual machine through the JVMTI interface of the Java virtual machine;

[0030] Obtain the memory address of the legitimate connection source of the target application in the native library through symbol hijacking, and set a pointcut according to the memory address of the legitimate connection source of the target application;

[0031] Inject the cross-cutting aspect program into the pointcut through the cross-cutting aspect base.

[0032] Specifically, the cross-cutting aspect injection module is further specifically used for:

[0033] Obtain the address pointer of the public symbol method in the native library;

[0034] Obtain local symbol information according to the address pointer of the public symbol method;

[0035] Obtain the address offset between the legitimate connection source of the target application and the public symbol method according to the local symbol information;

[0036] Determine the memory address pointer of the legitimate connection source of the target application according to the address pointer of the public symbol method and the address offset between the legitimate connection source of the target application and the public symbol method.

[0037] As an optional implementation manner of the device described in the second aspect, the cross-cutting aspect injection module is specifically used to modify the legitimate connection source of the target application by using at least one of the modification methods of adding a legitimate connection source, deleting a legitimate connection source, and modifying the attribute information of the current legitimate connection source.

[0038] Specifically, the specific manner for the cross-cutting aspect injection module to modify the attribute information of the current legitimate connection source includes:

[0039] Modify the IP address or network segment information of the current legitimate connection source.

[0040] In a third aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the above-described dynamic governance method for communication connection channels based on aspect programs is implemented.

[0041] In a fourth aspect, an electronic device is provided, including:

[0042] one or more processors; and a memory associated with the one or more processors, where the memory is used to store program instructions. When the program instructions are read and executed by the one or more processors, the specific steps of the above-described dynamic governance method for communication connection channels based on aspect programs are executed.

[0043] The beneficial effect of the dynamic governance method for communication connection channels based on aspect programs described in one or more embodiments of this specification is that this method modifies the legal connection sources of the target application by injecting aspect programs into the native layer of the Java virtual machine, and intercepts illegal connection sources during the establishment of the communication channel, so that the defense strategy of the JDWP channel can be dynamically adjusted according to requirements, effectively defending against JDWP channel intrusion. This method only needs to obtain the permissions of the container where the target application is located, does not need to obtain the host machine permissions, and has no strong dependence on the kernel version.

[0044] The dynamic governance device, storage medium, and electronic device for communication connection channels based on aspect programs described in the embodiments of this specification also have the above beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0046] Figure 1 Exemplarily shows a schematic diagram of the communication architecture of the JDWP protocol in the prior art.

[0047] Figure 2 Exemplarily shows a schematic flowchart of a dynamic governance method for communication connection channels based on aspect programs described in the embodiments of this specification.

[0048] Figure 3 Exemplarily shows a schematic flowchart of the injection process of a native aspect.

[0049] Figure 4The structural schematic diagram of a dynamic governance device for a communication connection channel based on an aspect program described in the embodiments of the present specification is exemplarily shown.

[0050] Figure 5 The structural schematic diagram of an electronic device described in the embodiments of the present specification is exemplarily shown. Detailed implementation manners

[0051] First of all, it should be noted that the terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms of "a", "the" and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0052] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described here without departing from the scope and spirit of the present invention. Similarly, for the sake of clarity and conciseness, the description of well-known functions and structures is omitted below.

[0053] It should be noted that: in other embodiments, the steps of the corresponding method are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.

[0054] JPDA (Java Platform Debugger Architecture) is an architecture for debugging Java platform applications. It provides a set of interfaces and tools to help developers detect, analyze and debug the running state of Java applications. In the JPDA architecture, the debugger and the application to be debugged communicate using the JDWP (Java Debug Wire Protocol) protocol. Please refer to Figure 1 , Figure 1The figure shows a schematic diagram of the communication architecture of the JDWP protocol. In this architecture, when the virtual machine JVM starts, it loads the JDWP agent module to have debugging capabilities. The debugger communicates with the virtual machine through the JDWP protocol to form a JDWP channel. The debugger can use the JDWP protocol to send commands to the JVM and receive responses from the JVM.

[0055] JVM TI (Java Virtual Machine Tool Interface): JVM TI is a standard, tool-oriented interface for inserting debugging tools and monitoring tools into the Java Virtual Machine (JVM). In the communication architecture based on the JDWP protocol, an attacker can connect to the application through the Java debugging port JVMTI and obtain application permissions to execute instructions on the application machine, which is also known as JDWP channel intrusion.

[0056] Since JDWP and JVMTI are at the same layer and do not expose external interfaces to the JAVA layer, when an attacker invades through the JDWP channel, the JAVA layer cannot perceive the data packets transmitted through the JDWP channel, nor can it perceive intrusion events based on the data packets. Therefore, it is difficult to effectively defend against intrusion events.

[0057] In view of this, this specification provides a method and device for dynamically managing communication connection channels based on aspect programs, which can dynamically adjust the governance strategy for JDWP channels using aspect programs, thereby effectively resisting JDWP channel intrusion.

[0058] To make the purpose, technical solutions, and advantages of this specification clearer, the technical solutions of this specification will be clearly and completely described below in conjunction with specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of them. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this specification.

[0059] The following details the technical solutions provided by each embodiment of this specification in conjunction with the drawings.

[0060] Please refer to Figure 2 , Figure 2 , which is a schematic flowchart of a method for dynamically managing communication connection channels based on aspect programs proposed in one or more embodiments of this specification. Figure 1 The method shown can be executed by a device for dynamically managing communication connection channels based on aspect programs, but is not limited to this device.

[0061] As Figure 2As shown, the above-mentioned dynamic governance method for communication connection channels based on aspect programs is applicable to the Java virtual machine, which deploys the target application, and the Java virtual machine communicates with the client using the JDWP protocol. This method includes steps S200 - S202.

[0062] S200: Inject a pre-built aspect program into the native layer of the Java virtual machine, and use the aspect program to modify the legitimate connection sources of the target application.

[0063] S202: In response to a communication connection request from the client to the target application, determine whether the client is a legitimate connection source, and determine whether to establish a communication connection with the client based on the judgment result.

[0064] It can be seen that the above-mentioned dynamic governance method for communication connection channels based on aspect programs dynamically modifies the legitimate connection sources of the target application through the aspect program, thereby intercepting illegal connection sources during the stage of establishing a communication connection between the client and the target application, thus ensuring the security performance of the JDWP channel and realizing effective defense against JDWP channel intrusion.

[0065] Before implementing the above method, it is necessary to first construct an aspect program according to the governance policy set by the user or the governance policy issued by the upper computer. This aspect program is used to be injected into the native layer of the Java virtual machine JVM and modify the legitimate connection sources of the target application. Therefore, in the following text, this aspect program will be simply referred to as the native aspect. The specific modification method can be set according to requirements, and this embodiment does not limit it. For example, the modification method for the legitimate connection sources of the target application can be adding legitimate connection sources, deleting legitimate connection sources, and modifying the attribute information of the current legitimate connection sources, etc. Among them, the attribute information of the legitimate connection source can specifically be the IP address or network segment information of the legitimate connection source, etc.

[0066] In addition, it is also necessary to first obtain the permissions of the container where the target application is located, that is, the permissions of this virtual machine. After obtaining the permissions, the legitimate connection sources of the target application can be dynamically adjusted through the above-mentioned native aspect.

[0067] Next, the specific implementation processes of steps S200 - S202 will be elaborated in detail.

[0068] First, for step S200, inject a pre-built aspect program into the native layer of the Java virtual machine, and use the aspect program to modify the legitimate connection sources of the target application. In some implementation manners, the injection process of the native aspect can be as Figure 3 shown, including steps S300 to S304.

[0069] S300: Inject the aspect base into the native layer of the Java virtual machine through the JVMTI interface of the Java virtual machine.

[0070] Specifically, the JVMTI Agent, that is, the JVMTI proxy module, can be injected into the native layer of the JVM through the JVMTI interface of the Java virtual machine. The JVMTI Agent can serve as the aspect base of the native aspect and is used to perform subsequent native aspect injection operations.

[0071] S302: Obtain the memory address of the legal connection source of the target application in the native library through symbol hijacking, and set the pointcut based on the memory address of the legal connection source of the target application.

[0072] The above-mentioned native library includes a dynamic link library (DLL, applicable to the Windows system) or a shared object file (.so, applicable to the Unix / Linux system) implemented by native methods. These native libraries can be loaded into the JVM at runtime through the System.loadLibrary method.

[0073] Taking the dynamic link library libdt_socket as an example, in the communication architecture based on the JDWP protocol, after the JDWPAgent loaded by the JVM is started, it will load the dynamic link library and call the jdwpTransport_OnLoad interface to implement the initialization of the transport layer. This jdwpTransport_OnLoad is the interface of the dynamic link library implemented by the transport layer. Through this interface, all public symbol methods provided by the transport layer can be accessed.

[0074] The memory addresses of these public symbol methods cannot be directly obtained externally. Based on this, in this step, after reading the dynamic link library, it can be determined whether the jdwpTransport_OnLoad interface can be accessed through symbol hijacking. If not, it means that the native aspect injection fails, and the injection process ends. If the jdwpTransport_OnLoad interface can be accessed, the local symbol information is read through the jdwpTransport_OnLoad interface. These local symbols are the public symbol methods / objects provided by the transport layer. In the read local symbol information, it is checked through symbol hijacking whether there is the _peers data used to record the legal connection source attribute information. If not, it means that the native aspect injection fails, and the injection process ends. If there is, the address offset offset between _peers and jdwpTransport_OnLoad is obtained. Finally, based on the address pointer of jdwpTransport_OnLoad and the address offset offset between _peers and jdwpTransport_OnLoad, the address pointer of _peers can be calculated. This address pointer is the memory address pointer of the legal connection source of the target application. Based on the address pointer of _peers, the attribute data of the legal connection source of the target application can be accessed.

[0075] According to the address pointer of _peers, a pointcut is implanted in the memory of the legal connection source of the target application.

[0076] S304: Inject the aspect program into the pointcut through the aspect base.

[0077] Configure the association relationship between the aspect and the pointcut in the aspect base, and then use the aspect base to inject the native aspect into the pointcut, thus completing the entire native aspect injection process.

[0078] Next, for step S202, in response to the client's communication connection request for the target application, it is determined whether the client is a legal connection source, and whether to establish a communication connection with the client is determined according to the judgment result.

[0079] Specifically, after the JVM receives a communication connection request from the client through the JDWP channel, it will call the connection initialization method to access the dynamic link library. The dynamic link library has a pre-check mechanism, which verifies whether the current client is a legitimate connection source of the target application. For example, it can verify whether the network segment or IP and other attribute data of the current client match the corresponding attribute data of the legitimate connection source of the target application. If they match, it is determined that the current client is a legitimate connection source of the target application, and the dynamic link library passes the pre-check of the current client and establishes a communication connection with the client. If they do not match, it is determined that the current client is not a legitimate connection source of the target application, and the dynamic link library refuses to establish a communication connection with the current client, and the client cannot access the target application.

[0080] By using the pre-check mechanism of the dynamic link library, it is possible to verify whether the current client is a legitimate connection source according to the current legitimate connection source whitelist of the target application, and intercept the access of illegitimate connection sources suspected of being attackers, thereby realizing the defense against JDWP channel intrusion.

[0081] Based on the same idea, this specification also provides a corresponding dynamic governance device for communication connection channels based on aspect programs, such as Figure 4 shown. Figure 4 Schematically shows a structural diagram of a dynamic governance device for communication connection channels based on aspect programs. This device is applicable to a Java virtual machine, the Java virtual machine deploys a target application, and the Java virtual machine and the client communicate using the JDWP protocol.

[0082] It should be noted that the dynamic governance method for communication connection channels based on aspect programs described in one or more embodiments of this application may rely on Figure 4 the device shown, but is not limited to this device.

[0083] As Figure 4 shown, the device includes:

[0084] An aspect injection module 401, configured to inject a pre-built aspect program into the native layer of the Java virtual machine and use the aspect program to modify the legitimate connection source of the target application.

[0085] A connection module 402, configured to determine whether the client is a legitimate connection source in response to a communication connection request from the client to the target application, and determine whether to establish a communication connection with the client according to the judgment result.

[0086] In some embodiments, the above-mentioned device may further include a section building module, which is configured to build the above-mentioned section program in response to the issuance of a governance policy. The section program is used to be injected into the native layer of the Java Virtual Machine (JVM) and modify the legitimate connection sources of the target application, which is hereinafter simply referred to as the native section. The specific modification method can be set according to requirements, and this embodiment does not limit it. For example, the modification method for the legitimate connection sources of the target application can be adding legitimate connection sources, deleting legitimate connection sources, and modifying the attribute information of the current legitimate connection sources, etc. Among them, the attribute information of the legitimate connection sources can specifically be the IP address or network segment information of the legitimate connection sources, etc.

[0087] In addition, the above-mentioned device also needs to obtain the permissions of the container where the target application is located before working, that is, the permissions of this virtual machine. After obtaining the permissions, the legitimate connection sources of the target application can be dynamically adjusted through the above-mentioned native section.

[0088] In some embodiments, for the above-mentioned section injection module 401, this module can specifically be used to inject a section base into the native layer of the Java virtual machine through the JVMTI interface of the Java virtual machine; obtain the memory address of the legitimate connection sources of the target application in the native library through symbol hijacking, and set a cut point according to the memory address of the legitimate connection sources of the target application; inject the section program into the cut point through the section base.

[0089] Specifically, the section injection module 401 can inject a JVMTI Agent, that is, a JVMTI proxy module, into the native layer of the JVM through the JVMTI interface of the Java virtual machine. The JVMTI Agent can be used as the section base of the native section and is used to perform subsequent native section injection operations.

[0090] The above-mentioned native library includes a dynamic link library (DLL, applicable to the Windows system) or a shared object file (.so, applicable to the Unix / Linux system) implemented by native methods. These native libraries can be loaded into the JVM at runtime through the System.loadLibrary method.

[0091] Taking the dynamic link library libdt_socket as an example, in a communication architecture based on the JDWP protocol, after the JDWPAgent loaded by the JVM is started, it will load the dynamic link library and call the jdwpTransport_OnLoad interface to implement the initialization of the transport layer. This jdwpTransport_OnLoad is the interface of the dynamic link library implemented by the transport layer. Through this interface, all public symbol methods provided by the transport layer can be accessed.

[0092] The memory addresses of the above-mentioned common symbol methods cannot be directly obtained externally. Based on this, after reading the dynamic link library, the aspect injection module 401 can determine whether it can access the jdwpTransport_OnLoad interface through symbol hijacking. If not, it indicates that the native aspect injection fails, and the injection process ends. If the jdwpTransport_OnLoad interface can be accessed, the aspect injection module 401 reads the local symbol information through the jdwpTransport_OnLoad interface. These local symbols are the common symbol methods / objects provided by the transport layer. The aspect injection module 401 searches for the _peers data used to record the legal connection source attribute information through symbol hijacking in the read local symbol information. If not, it indicates that the native aspect injection fails, and the injection process ends. If there is, the aspect injection module 401 obtains the address offset offset between _peers and jdwpTransport_OnLoad. Finally, the aspect injection module 401 can calculate the address pointer of _peers based on the address pointer of jdwpTransport_OnLoad and the address offset offset between _peers and jdwpTransport_OnLoad. This address pointer is the memory address pointer of the legal connection source of the target application. The aspect injection module 401 can access the attribute data of the legal connection source of the target application according to the address pointer of _peers.

[0093] The aspect injection module 401 implants a pointcut in the memory of the legal connection source of the target application according to the address pointer of _peers.

[0094] The aspect injection module 401 configures the association relationship between the aspect and the pointcut in the aspect base, and then uses the aspect base to inject the native aspect into the pointcut, thus completing the entire native aspect injection process.

[0095] In some embodiments, for the above-mentioned aspect injection module 401, the module can specifically adopt at least one modification method of adding a legal connection source, deleting a legal connection source, and modifying the attribute information of the current legal connection source to modify the legal connection source of the target application. Among them, the specific method for the aspect injection module 401 to modify the attribute information of the current legal connection source can include modifying the IP address or network segment information of the current legal connection source.

[0096] In some embodiments, for the above-mentioned connection module 402, after receiving a communication connection request from a client through the JDWP channel, the module will call a connection initialization method to access the dynamic link library. The dynamic link library has a pre-check mechanism, which verifies whether the current client is a legitimate connection source of the target application. For example, it can verify whether the network segment or IP and other attribute data of the current client match the corresponding attribute data of the legitimate connection source of the target application. If they match, it is determined that the current client is a legitimate connection source of the target application, and the dynamic link library passes the pre-check of the current client and establishes a communication connection with the client. If they do not match, it is determined that the current client is not a legitimate connection source of the target application, and the dynamic link library refuses to establish a communication connection with the current client, and the client cannot access the target application.

[0097] The connection module 402 can utilize the pre-check mechanism of the dynamic link library to verify whether the current client is a legitimate connection source according to the current legitimate connection source whitelist of the target application, and intercept the access of illegal connection sources of suspected attackers, thereby realizing the defense against JDWP channel intrusion.

[0098] For the above-mentioned communication connection channel dynamic governance device based on an aspect program, taking the module as an example of a software functional unit, the aspect injection module 401 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the aspect injection module 401 may include code running on multiple hosts / virtual machines / containers. The multiple hosts / virtual machines / containers used to run the code may be distributed in the same region, or may be distributed in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ), or may be distributed in different AZs, and each AZ includes one data center or multiple geographically close data centers. Usually, one region may include multiple AZs.

[0099] Similarly, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same virtual private cloud (VPC), or may be distributed in multiple VPCs. Usually, one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is realized through the communication gateway.

[0100] As an example of a hardware functional unit, the aspect injection module 401 may include at least one computing device, such as a server, etc. Alternatively, the aspect injection module 401 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0101] The multiple computing devices included in the aspect injection module 401 may be distributed in the same region or in different regions. The multiple computing devices included in the aspect injection module 401 may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the aspect injection module 401 may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0102] In other embodiments, the aspect injection module 401 may be used to execute any step in the above-mentioned communication connection channel dynamic governance method based on aspect programs, and the connection module 402 may be used to execute any step in the above-mentioned communication connection channel dynamic governance method based on aspect programs. The steps to be implemented by the aspect injection module 401 and the connection module 402 can be specified as needed. By implementing different steps in the above-mentioned communication connection channel dynamic governance method based on aspect programs through the aspect injection module 401 and the connection module 402 respectively, all functions of the above-mentioned communication connection channel dynamic governance device based on aspect programs can be realized.

[0103] In this implementation, the communication connection channel dynamic governance device based on aspect programs may also be applied to computing devices such as computers and servers, or to a computing device cluster including at least one computing device to implement the communication connection channel dynamic governance function based on aspect programs.

[0104] In some embodiments, an electronic device is also provided. Please refer to Figure 5, the electronic device includes: a bus 501, a processor 502, a memory 503, and a communication interface 504. The processor 502, the memory 503, and the communication interface 504 communicate with each other via the bus 501. The electronic device can be a server or a terminal device. It should be understood that the present application does not limit the number of processors and memories in the electronic device.

[0105] The bus 501 can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 5 it is represented by only one line, but it does not mean that there is only one bus or one type of bus. The bus 501 can include a path for transmitting information between various components of the electronic device (for example, the processor 502, the memory 503, and the communication interface 504).

[0106] The processor 502 can include any one or more of processors such as a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Micro Processor (MP), or a Digital Signal Processor (DSP).

[0107] The memory 503 can include a volatile memory, such as a Random Access Memory (RAM). The memory 503 can also include a non-volatile memory, such as a Read-Only Memory (ROM), a flash memory, a Hard Disk Drive (HDD), or a Solid State Drive (SSD).

[0108] The memory 503 stores executable program codes, and the processor 502 executes the executable program codes to respectively implement the functions of the foregoing aspect injection module 401 and connection module 402, that is, to implement the functions of the foregoing communication connection channel dynamic governance device based on the aspect program, so as to implement the foregoing communication connection channel dynamic governance method based on the aspect program.

[0109] The communication interface 504 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement the communication between the electronic device and other devices or a communication network.

[0110] In some embodiments, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the method for dynamically managing communication connection channels based on aspect programs is implemented.

[0111] The computer-readable storage medium may be any available medium that can be stored in the electronic device or a data storage device such as a data center that includes one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk). The computer-readable storage medium includes instructions that instruct the electronic device to execute the above-mentioned dynamic management method of the communication connection channel based on the aspect program.

[0112] It is to be understood that the structure illustrated in the embodiments of this specification does not constitute a specific limitation on the system of the embodiments of this specification. In other embodiments of the specification, the above system may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0113] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0114] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0115] It should be noted that the above examples are only specific embodiments of the present invention, and the present invention is obviously not limited to the above examples, and there are many similar variations. All variations directly derived or associated from the contents disclosed by the technicians in this field should fall within the protection scope of the present invention.

Claims

1. A method for dynamically managing a communication connection channel based on an aspect program, applicable to a Java virtual machine, where the Java virtual machine deploys a target application, and the Java virtual machine communicates with a client using the JDWP protocol; the method includes: Injecting a pre-built aspect program into the native layer of the Java virtual machine; Using the aspect program to modify the legitimate connection sources of the target application; In response to a communication connection request from the client to the target application, determining whether the client is a legitimate connection source, and determining whether to establish a communication connection with the client based on the judgment result.

2. The method according to claim 1, the method further includes: Before injecting the aspect program into the native layer of the Java virtual machine, in response to the issuance of a governance policy, constructing the aspect program.

3. The method according to claim 1, injecting the aspect program into the native layer of the Java virtual machine specifically includes: Injecting an aspect base into the native layer of the Java virtual machine through the JVMTI interface of the Java virtual machine; Obtaining the memory address of the legitimate connection source of the target application in the native library through symbol hijacking, and setting a pointcut based on the memory address of the legitimate connection source of the target application; Injecting the aspect program into the pointcut through the aspect base.

4. The method according to claim 3, obtaining the memory address of the legitimate connection source of the target application in the native library through symbol hijacking specifically includes: Obtaining the address pointer of the public symbol method in the native library; Obtaining local symbol information based on the address pointer of the public symbol method; Obtaining the address offset between the legitimate connection source of the target application and the public symbol method based on the local symbol information; Determining the memory address pointer of the legitimate connection source of the target application based on the address pointer of the public symbol method and the address offset between the legitimate connection source of the target application and the public symbol method.

5. The method according to claim 1, using the aspect program to modify the legitimate connection sources of the target application, the specific modification methods include at least one of adding a legitimate connection source, deleting a legitimate connection source, and modifying the attribute information of the current legitimate connection source.

6. The method according to claim 5, modifying the attribute information of the current legitimate connection source specifically includes: Modifying the IP address or network segment information of the current legitimate connection source.

7. A device for dynamically managing a communication connection channel based on an aspect program, applicable to a Java virtual machine, where the Java virtual machine deploys a target application, and the Java virtual machine communicates with a client using the JDWP protocol; the device includes: An aspect injection module, configured to inject a pre-built aspect program into the native layer of the Java virtual machine, and use the aspect program to modify the legitimate connection sources of the target application; A connection module, configured to determine whether the client is a legal connection source in response to a communication connection request of the client for the target application, and determine whether to establish a communication connection with the client according to the judgment result.

8. The device according to claim 7, wherein the device further comprises: A cross-cutting aspect construction module, configured to construct the cross-cutting aspect program in response to the issuance of a governance policy.

9. The device according to claim 7, wherein the cross-cutting aspect injection module is specifically configured to: Inject a cross-cutting aspect base into the native layer of the Java virtual machine through the JVMTI interface of the Java virtual machine; Obtain the memory address of the legal connection source of the target application in the native library through symbol hijacking, and set a pointcut according to the memory address of the legal connection source of the target application; Inject the cross-cutting aspect program into the pointcut through the cross-cutting aspect base.

10. The device according to claim 9, wherein the cross-cutting aspect injection module is further specifically configured to: Obtain the address pointer of the public symbol method in the native library; Obtain local symbol information according to the address pointer of the public symbol method; Obtain the address offset between the legal connection source of the target application and the public symbol method according to the local symbol information; Determine the memory address pointer of the legal connection source of the target application according to the address pointer of the public symbol method and the address offset between the legal connection source of the target application and the public symbol method.

11. The device according to claim 7, wherein the cross-cutting aspect injection module is specifically configured to modify the legal connection source of the target application by adopting at least one of the modification methods of adding a legal connection source, deleting a legal connection source, and modifying the attribute information of the current legal connection source.

12. The device according to claim 11, wherein the specific way for the cross-cutting aspect injection module to modify the attribute information of the current legal connection source includes: Modifying the IP address or network segment information of the current legal connection source.

13. A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

14. An electronic device, comprising: One or more processors; And a memory associated with the one or more processors, the memory being used to store program instructions, and when the program instructions are read and executed by the one or more processors, the specific steps of the method according to any one of claims 1 to 6 are executed.