File access control method and device for Linux kernel based on black and white lists

By introducing a black and white list mechanism in the Linux kernel, automatically identifying sensitive files and dynamically adjusting strategies, the problems of insufficient flexibility and malicious program protection in the existing technology are solved, and precise control and security improvement of sensitive files are achieved.

CN120337290APending Publication Date: 2025-07-18KYLIN CORP
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510468310.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The file access control mechanism of the existing Linux operating system lacks flexibility, cannot refine the behavior of the program, cannot effectively protect malicious programs, and there is a contradiction between security and ease of use, and administrators have high technical requirements.

Method used

Implement a black and white listing mechanism in the Linux kernel. By automatically identifying sensitive files and adding hierarchical markers, intercepting program access, judging whether access is allowed based on static permission markers and management policy modes, and supporting dynamic policy adjustments and precise audits.

Benefits of technology

It realizes dynamic protection of sensitive files, prevents malicious programs from accessing, accurately controls access permissions, supports multi-mode policies, reduces administrator technical requirements, and provides detailed audit support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337290A_ABST
    Figure CN120337290A_ABST
Patent Text Reader

Abstract

The invention provides a Linux kernel file access management and control method and device based on black and white lists, and the method comprises the steps: automatically recognizing a sensitive file, and adding a grading mark for the sensitive file according to a management and control strategy mode; the Linux kernel intercepts and checks whether a program accessing the sensitive file allocates a static permission mark or not; judging whether access is allowed or not according to the static permission mark of the program and the hierarchical mark of the sensitive file; extracting program information according to the management and control strategy mode, and matching black and white list features; judging whether access is allowed or not according to a matching result and a grading mark of the sensitive file; and switching a management and control strategy mode according to requirements in system operation, and modifying the grading marks of the sensitive files. According to the method, a blacklist and whitelist mechanism is realized in a Linux kernel, and operations such as access, modification and deletion of a program to a sensitive file are monitored and controlled in real time in combination with a configuration strategy, so that the security of a system is effectively improved, and risks caused by malicious programs or improper operations are prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer information technology, and particularly relates to a method and device for controlling file access based on black and white lists in the Linux kernel. Background Art

[0002] In modern operating systems, data protection and security issues are becoming increasingly severe. Especially in open-source operating systems such as Linux, the running permissions of programs and the access control of files are particularly important. For some key system files, user data files, and files containing sensitive information (such as password files, configuration files, etc.), their security requirements are very high. Preventing unauthorized programs from accessing, modifying, or deleting these files is the basis for ensuring the normal operation of the system and data security.

[0003] Currently, the Linux operating system provides multiple mechanisms to implement access control between programs and files. Common file access control mechanisms include user permission-based control, access control lists (ACLs), and the security attributes of the file system, etc. Most of these methods rely on predefined rules, such as the read, write, and execute permissions of files or permission settings based on user identities, to control program access to files. However, the deficiencies of the existing technologies are mainly reflected in the following aspects:

[0004] 1) Permission management is too static:

[0005] Existing permission controls are mostly set based on static user and group identities, which means that the permission control of the system often lacks flexibility. For some scenarios that require dynamic management according to the characteristics of programs (such as the type and behavior of programs), the existing permission mechanisms cannot adapt well.

[0006] 2) Unable to control program behavior in a refined manner:

[0007] Existing file access control mechanisms mainly rely on the permissions of users or programs, but cannot control the behavior of programs in a fine-grained manner. For example, a program may have sufficient permissions to access a file, but it does not mean that its access behavior is legal or meets security requirements.

[0008] 3) Insufficient protection against malicious programs:

[0009] Traditional signature-based malicious program detection methods often rely on known virus libraries or behavior analysis. These methods have weak recognition capabilities for new malicious programs or variant programs and are prone to false negatives. Even in some cases where malicious programs can be recognized, they may still be able to access sensitive files due to improper permissions or configurations.

[0010] 4) The contradiction between security and usability:

[0011] When implementing strict security protection, existing file access control mechanisms often require configuring complex permissions and rules, which impose relatively high technical requirements on system administrators and increase the management burden of the system.

[0012] Therefore, in the face of malicious programs and complex access requirements, existing technologies often fail to provide sufficient flexibility and effective protection. Summary of the Invention

[0013] The purpose of the present invention is to provide a method and device for file access control based on black and white lists in the Linux kernel. By implementing the black and white list mechanism in the Linux kernel and combining configuration policies, it can monitor and control operations such as access, modification, and deletion of sensitive files by programs in real time, thereby effectively enhancing the security of the system and preventing risks brought by malicious programs or improper operations.

[0014] To achieve the above purpose, the technical solution of the present invention is as follows:

[0015] A method for file access control based on black and white lists in the Linux kernel, including:

[0016] S1. Automatically identify sensitive files and add a classification mark to the sensitive files according to the control policy mode; the classification mark includes black and white list marks;

[0017] S2. The Linux kernel intercepts and checks whether the program accessing the sensitive file is assigned a static permission mark. If it exists, execute step S3; if not, execute step S4; the static permission mark includes black and white list permission marks;

[0018] S3. Judge whether to allow access according to the static permission mark of the program and the classification mark of the sensitive file;

[0019] S4. Extract program information according to the control policy mode, match the black and white list features; then judge whether to allow access according to the matching result and the classification mark of the sensitive file;

[0020] S5. Switch the control policy mode according to the demand during the system operation and modify the classification mark of the sensitive file.

[0021] Further, the control policy mode in step S1 includes a blacklist mechanism in the loose policy mode and a whitelist mechanism in the strict policy mode; the blacklist mechanism only prohibits programs in the blacklist from accessing sensitive files, and the whitelist mechanism only allows authorized programs in the whitelist to access sensitive files.

[0022] Further, the method for extracting program information according to the control policy mode in step S4 includes: the blacklist mechanism extracts the program file path, program name, program content hash value, and word frequency feature value as program information, and the whitelist mechanism only extracts the program content hash value as program information.

[0023] Still further, the method for matching blacklist features through a feature matching algorithm in step S4 includes:

[0024] Use a lightweight difference detection method to quickly calculate the similarity between the extracted program information and the blacklist features: First, obtain the blacklist features. Under the blacklist mechanism, extract the program information content in bytecode format, count the number of occurrences of each word (00-FF) separately as the word frequency feature of the blacklist features, and configure a similarity threshold; after the kernel intercepts and executes the program, when extracting program information, obtain the word frequency of the program information in the same way, compare it with the word frequency of the blacklist features, calculate the difference in the word frequency of each word (00-FF), calculate the total difference, and if it is within the similarity threshold range, determine that the current program and the program in the blacklist features are the same program or similar programs.

[0025] Further, the classification mark of sensitive files in step S1 also includes a sensitivity level mark, and the static permission mark of the program in step S2 correspondingly includes a sensitivity level permission mark.

[0026] The present invention also proposes a Linux kernel file access control device based on black and white lists, including:

[0027] Sensitive file module: Automatically identify sensitive files and add classification marks to sensitive files according to the control policy mode; the classification marks include black and white list marks;

[0028] Program permission module: The Linux kernel intercepts and checks whether the program accessing the sensitive file is assigned a static permission mark. If it exists, it transfers to the judgment module; if it does not exist, it transfers to the matching judgment module; the static permission mark includes black and white list permission marks;

[0029] Judgment module: Judge whether access is allowed according to the static permission mark of the program and the classification mark of the sensitive file;

[0030] Matching judgment module: Extract program information according to the control policy mode, match black and white list features; then judge whether access is allowed according to the matching result and the classification mark of the sensitive file;

[0031] Mode switching module: Switch the control policy mode according to the demand during system operation and modify the classification mark of the sensitive file.

[0032] Further, the control policy mode in the sensitive file module includes a blacklist mechanism for the loose policy mode and a whitelist mechanism for the strict policy mode; the blacklist mechanism only prohibits programs in the blacklist from accessing sensitive files, and the whitelist mechanism only allows authorized programs in the whitelist to access sensitive files.

[0033] Furthermore, an extraction unit is set in the matching and judging module to extract program information according to the control policy mode. The blacklist mechanism extracts the program file path, program name, program content hash value, and word frequency feature value as program information, and the whitelist mechanism only extracts the program content hash value as program information.

[0034] Still further, a matching unit is set in the matching and judging module to match the blacklist features through a feature matching algorithm, and use a lightweight difference detection method to quickly calculate the similarity between the extracted program information and the blacklist features: First, obtain the blacklist features. Under the blacklist mechanism, extract the program information content in bytecode format, count the number of occurrences of each word (00-FF) separately as the word frequency feature of the blacklist features, and configure a similarity threshold; after the kernel intercepts and executes the program, when extracting the program information, obtain the word frequency of the program information in the same way and compare it with the word frequency of the blacklist features, calculate the difference in the word frequency of each word (00-FF), calculate the total difference, and if it is within the similarity threshold range, it is determined that the current program and the program in the blacklist features are the same program or similar programs.

[0035] Further, the classification mark of sensitive files in the sensitive file module also includes a sensitive level mark, and the static permission mark of programs in the program permission module correspondingly includes a sensitive level permission mark.

[0036] Compared with the prior art, the present invention has the following beneficial effects:

[0037] 1. Achieve dynamic protection: Through the black and white list and sensitive level matching mechanism, the present invention realizes dynamic protection of access to sensitive files and ensures data security.

[0038] 2. Achieve precise control of access permissions:

[0039] Through the blacklist mechanism, absolutely shield programs or files clearly marked as prohibited from accessing, and no matter how the program tries, it cannot obtain the content of sensitive files, thus eliminating the risk of intrusion by malicious programs from the source;

[0040] Through the whitelist mechanism, only authorized programs are allowed to access sensitive files, and the remaining programs cannot perform any operations on sensitive files even if they pass other permission checks.

[0041] 3. Prevent unauthorized access:

[0042] Sensitivity level matching: By comparing the program permission tags and sensitive file tags, it prevents low-privilege programs from illegally reading highly sensitive files. Even if the program itself has obtained user authorization, it cannot bypass the strict checks at the kernel layer.

[0043] 4. Effectively deal with malicious programs:

[0044] The black and white list mechanism has a higher defense ability against malicious programs that are camouflaged, deformed, or dynamically generated. Even if a malicious program is not recognized by traditional signature detection methods, the system can still reject its access to sensitive files through kernel marking.

[0045] 5. Dynamic policy adjustment:

[0046] The present invention supports dynamically adjusting the black and white list policies during operation without restarting the system. Administrators can quickly add blacklisted programs or adjust white list authorizations according to the real-time security situation to timely respond to new threats.

[0047] 6. Support for multiple modes:

[0048] Loose policy mode: In an environment with a low security threat, the blacklist policy is used to block explicit malicious programs, and the access behavior of the remaining programs is more relaxed, effectively balancing security and system performance.

[0049] Strict policy mode: In scenarios with high security requirements, access permissions are strictly controlled through the white list, and only programs with explicit authorization are allowed to access sensitive files, thereby achieving a higher security level.

[0050] 7. Compatible with multi-scenario requirements:

[0051] The system supports classifying and marking various types of sensitive files (such as personal privacy, business secrets, system configuration files, etc.), and flexibly formulating personalized access policies in combination with the functional characteristics of the programs to meet the complex enterprise-level and individual user requirements.

[0052] 8. Precise auditing:

[0053] Based on kernel control, the present invention provides precise auditing support for the access behavior of the system through the log recording mechanism at the kernel layer, which helps in problem troubleshooting and security policy optimization.

[0054] Comprehensively record access behavior: For each access request of a program to a sensitive file (including success and failure), the system automatically generates detailed logs. The recorded content includes: access time and program path, the file path accessed and its marked attributes (such as sensitivity level), whether it matches the black and white list or sensitivity level requirements, and the specific reasons for denying access (such as the program not being listed in the white list or insufficient permissions).

[0055] Convenient Log Management: Audit logs are centrally stored in a secure directory, and administrators can quickly query, classify, or analyze log data through user-space tools. The system supports feedback of potential threat behaviors to administrators through methods such as regular summarization and anomaly detection, facilitating the adoption of preventive measures.

[0056] Support for Problem Tracing: When data leakage or unauthorized access occurs, detailed audit logs can help administrators quickly identify the problematic program, access path, and time period, providing strong technical support for the investigation and handling of security incidents. Brief Description of the Drawings

[0057] Figure 1 It is a schematic diagram of the overall control solution of Embodiment 1 of the present invention.

[0058] Figure 2 It is a schematic diagram of the sensitive file access process of Embodiment 1 of the present invention.

[0059] Figure 3 It is a schematic diagram of the process of the kernel interception program accessing sensitive files in Embodiment 1 of the present invention. Detailed Implementation Modes

[0060] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0061] The design concept of the present invention is to propose a file access control method based on black and white lists, specifically designed for the Linux kernel. Through mechanisms such as policy switching, sensitive file identification, dynamic policy distribution, and audit log generation, a flexible and reliable file access protection system is constructed. This method combines a loose policy mode and a strict policy mode to achieve precise control over the behavior of programs accessing sensitive files, effectively improving system security and management efficiency.

[0062] The present invention will be specifically described below in conjunction with specific embodiments and drawings:

[0063] Embodiment 1:

[0064] I. Overall Control Solution:

[0065] The overall control solution for file access based on black and white lists proposed in this embodiment is as Figure 1 shown and is specifically described as follows:

[0066] 1. Loose Policy Mode (Blacklist Mechanism).

[0067] Basic Principle:

[0068] Only programs in the blacklist are prohibited from accessing sensitive files.

[0069] Implementation Method:

[0070] Collect and analyze the program information of malicious programs or potentially high-risk programs, and add it as a blacklist feature to the kernel blacklist. The program information of the blacklist feature can support the program file path, program name, and program content hash value.

[0071] At the stage when the program requests file access, the kernel checks the blacklist. If the program is on the blacklist, access is denied.

[0072] Typical application scenario: Environments with high requirements for system performance and the goal of protecting against known threats.

[0073] 2. Strict policy mode (whitelist mechanism).

[0074] Basic principle: Only authorized programs in the whitelist are allowed to access sensitive files, and access by other programs is prohibited.

[0075] Implementation method: For trusted programs, extract their program information in advance and add it as a whitelist feature to the kernel whitelist. The program information of the whitelist feature only supports the program content hash value.

[0076] When a program triggers a file access request, the kernel first checks the whitelist. If the program is not in the whitelist, access is directly denied.

[0077] Typical application scenario: Environments with high security requirements, such as critical business servers or important data storage systems.

[0078] 3. Discovery and identification of sensitive files.

[0079] Automatic identification mechanism:

[0080] The system automatically marks the targets that may be sensitive files by analyzing file meta-information, access frequency, and location paths (such as / etc / , / var / lib / , etc.).

[0081] The sensitive file discovery and identification system can be an automated expert system. It can either set the files that need to be protected in the system as sensitive files through configuration, add file extension attributes to mark such files, or automatically scan the files in the system according to preset sensitive rules to check whether the files contain sensitive content. After hitting the sensitive rules, extension attribute marks will be added to the files to facilitate the kernel's control program to intercept and process the behavior of accessing sensitive files. The monitoring module in the sensitive file discovery and identification system will monitor the changes of files in the system in real time. Once a file changes, it will trigger the scanning mechanism to detect whether there is sensitive information in the file content, so as to realize the dynamic update of file marking.

[0082] Sensitivity classification:

[0083] File marking supports two implementation methods:

[0084] One way is to classify sensitive files into multiple levels (such as high, medium, and low sensitivity) according to the file security level, and apply differentiated protection policies to files at different levels. For the method of kernel control, access control policies need to be configured for different levels of markings.

[0085] File marking: security.sensitive = high, indicating that the file has the highest security level, and unauthorized access is not allowed by default policy.

[0086] File marking: security.sensitive = medium, indicating a medium security level, and whether access is allowed can be customized according to the policy.

[0087] File marking: security.sensitive = low, indicating that the file has a low security level, and unauthorized access is allowed.

[0088] Another way is to classify sensitive files into two levels (whitelist level and blacklist level) according to the file importance, and apply differentiated protection policies to files at different levels.

[0089] Blacklist: security.blacklist = true, indicating that the file is prohibited from being accessed by blacklisted programs.

[0090] Whitelist: security.whitelist = true, indicating that only whitelisted programs are allowed to access.

[0091] 4. Issuing control policies.

[0092] Dynamic update:

[0093] It supports the administrator to dynamically issue the whitelist, blacklist, and file sensitivity configurations to the kernel through user-space tools, and use the Netlink communication mechanism to synchronously update the kernel policy table.

[0094] It supports the administrator to issue the whitelist and blacklist policies to the kernel security virtual subsystem ( / sys / kernel / security / dlp / whitelist_blacklist) through the policy configuration tool, and update the kernel policy table through the LSM dynamic loading mechanism.

[0095] Automatic synchronization:

[0096] Regularly synchronize policies from the remote policy server or the centralized management platform to cope with changes in the malicious program signature library and the definition of sensitive files.

[0097] The policy configuration tool can be used to collect the policy configurations of remote policy servers and centralized management platforms and automatically synchronize them to the kernel policy table. It can not only distribute secure and reliable applications as whitelist features but also distribute malicious programs, virus software, mining programs, etc. as blacklist features.

[0098] The kernel control program can authenticate the identity of programs accessing sensitive files when the programs do not set static permission marks. Different methods are adopted for blacklists and whitelists. For blacklists, it supports program file paths, program names, program content hash values, and word frequency feature values as policy configuration items for blacklist features, enabling more convenient and rapid configuration; for whitelist policies, it only supports program content hash values as policy configuration items for whitelist features. The whitelist policy configuration items do not use program file paths and program names. On the one hand, it is to prevent programs from being impersonated, and on the other hand, it is to prevent whitelist programs from being tampered with or injected with malicious code.

[0099] Consistency check:

[0100] Each time the policy is updated, the kernel will verify whether the formats of program file paths, program names, and program content hash values in the blacklist and whitelist policy configuration items are correct and whether the paths exist to ensure the integrity and effectiveness of the policy data. The kernel will perform the verification to ensure the integrity and effectiveness of the policy data. Abnormal data will be rejected from being loaded and logged for administrators to review.

[0101] 5. Policy switching.

[0102] Real-time switching mechanism:

[0103] During system operation, administrators can switch the policy mode (blacklist or whitelist) according to requirements. For example, when a potential threat is detected, the policy is automatically distributed to the kernel security virtual subsystem / sys / kernel / security / dlp / switch to modify the current policy type from blacklist mode to whitelist mode, configuring that only authorized programs can access sensitive files, achieving a switch from a loose mode to a strict mode to comprehensively intercept unauthorized programs. When the system load is high, switch from the strict mode to the loose mode to reduce detection overhead.

[0104] Automated switching mechanism:

[0105] The system supports an automated switching mechanism based on security events. For example, when multiple illegal access attempts are detected, the policy can be triggered to switch from the loose mode to the strict mode.

[0106] 6. Kernel control mechanism.

[0107] File access interception:

[0108] Intercept all access requests to sensitive files through the VFS (Virtual File System) layer or file system hook functions in the kernel.

[0109] The hook function will extract the program information of the current access process and match the policy (blacklist feature or whitelist feature).

[0110] The control program in the hook function will extract the process information of the program accessing the sensitive file according to the current configured policy mode (blacklist / whitelist). In the blacklist mode, it will extract the program file path, program name, program content hash value, and word frequency feature value. In the whitelist mode, it will extract the program content hash value, and perform a matching check with the blacklist feature or whitelist feature of the policy configuration item based on the extracted content.

[0111] Feature matching algorithm:

[0112] Use a lightweight difference detection method to quickly calculate the similarity between program information and blacklist features. The difference method reads program information in bytecode format, counts the number of occurrences of each word (00-FF) separately, and uses it as the word frequency feature of the program in the blacklist feature. And configure a similarity threshold. After the kernel intercepts and executes the program, obtain the program information word frequency in the same way, compare it with the word frequency of the feature value in the policy table, calculate the difference of the word frequency of each word (00-FF), and calculate the total difference. If it is within the threshold setting range, it is determined that the currently running program is the same program or a similar program as the program in the blacklist feature, and its execution is rejected.

[0113] Behavior rejection and feedback:

[0114] For unauthorized access requests, the kernel will immediately block them and feedback the detailed information to the audit log system.

[0115] 7. Audit log generation.

[0116] Log content:

[0117] Record all requests to access sensitive files, including successful and rejected cases. Include detailed information such as process identifier (PID), program path, access time, target file path, similarity matching value, and interception reason.

[0118] Storage and analysis:

[0119] The audit log is stored in the user-specified directory and supports synchronization through a remote server. Provide user-mode tools for log analysis, such as generating security reports, tracing the source of illegal access, etc.

[0120] Real-time alarm:

[0121] The system supports real-time pushing of high-risk log events (such as programs with multiple access denials) to administrators for quick response.

[0122] II. Sensitive File Access Process:

[0123] Based on the above control scheme, the process of accessing sensitive files using the black and white list mechanism is as Figure 2 shown, including:

[0124] 1. Sensitive File Identification and Marking:

[0125] 1) Scan the system directory.

[0126] When the system starts or scans the specified directory according to the scheduled task. Extract the file content through the parsing tool, supporting multiple encoding formats and compression structures.

[0127] 2) Sensitive Information Identification.

[0128] Use the rule matching algorithm or machine learning model to identify sensitive information (such as personal privacy, business secrets, etc.). The extracted sensitive information includes keywords, structural features or format patterns (such as ID numbers, credit card numbers, etc.).

[0129] 3) Sensitive File Marking.

[0130] For the identified sensitive files, use the Linux kernel extended attribute (setxattr command) to set the mark.

[0131] Blacklist: security.blacklist = true, indicating that the file is prohibited from being accessed by blacklisted programs.

[0132] Whitelist: security.whitelist = true, indicating that only whitelisted programs are allowed to access.

[0133] Sensitivity Level: Set the security.sensitive field to mark sensitivity levels such as high, medium, low, etc.

[0134] 2. Program Permission Configuration and Marking:

[0135] 1) Static Permission Marking.

[0136] Administrators can predefine and allocate static permission marks for programs through the policy configuration interface:

[0137] Blacklisted Programs: Marked as security.blacklist = true, prohibited from accessing any sensitive files.

[0138] Whitelist program: Marked as security.whitelist = true, allowing access to specific sensitive files.

[0139] Access permission level: Such as security.sensitive = high / medium / low, used to match the sensitivity level of files.

[0140] 2) Dynamic adjustment.

[0141] When the program starts, it automatically loads and applies predefined static permission marks.

[0142] When the administrator updates the policy, the system supports dynamic adjustment of program permissions without restarting the service.

[0143] 3. Kernel-mode control mechanism:

[0144] 1) Access request interception.

[0145] As Figure 3 The kernel interception program accesses sensitive file process shown: The kernel monitors the program's access requests to files through system call interception (such as open, read, write, etc.).

[0146] The intercepted requests include the program path, file path, and their marking information.

[0147] 2) Program marking and black / white list policy matching check.

[0148] The black / white list check mainly includes two methods. First, the kernel control program loads static permission marks for the program. When intercepting, it checks the current program's static permission marks and performs control based on the marks. Second, if the black / white list mark of the program file is false or not set, the control program continues to execute and uses the blacklist features and whitelist features of the kernel black / white list as the control basis to decide whether to allow the program to access sensitive files or continue to execute.

[0149] Blacklist rules:

[0150] If the program is marked as blacklist (security.blacklist = true) or is matched as a blacklist feature, it is prohibited from accessing all sensitive files (regardless of whether the sensitive file belongs to the blacklist level or the whitelist level).

[0151] Whitelist rules:

[0152] If the file is marked as whitelist (security.whitelist = true), only programs marked as whitelist or matched as whitelist features are allowed to access. Access requests from other programs are rejected.

[0153] Sensitivity level matching:

[0154] The privilege level (security.sensitive) of the program label must be equal to or higher than the sensitivity level (security.sensitive) of the file. Otherwise, the kernel rejects the access request.

[0155] 3) Rejection handling and logging:

[0156] If the access request is rejected, the kernel returns an error code (such as EACCES or EPERM). At the same time, a detailed audit log is generated, including information such as the access program, file path, label value, and reason for the mismatch.

[0157] 4. Policy management and dynamic switching:

[0158] 1) Policy distribution.

[0159] The administrator submits the updated black and white list or sensitivity level policy through the user-space interface.

[0160] The system transfers the new policy to the kernel module and it takes effect immediately without restarting the system.

[0161] 2) Mode switching.

[0162] Two operating modes are supported:

[0163] Loose policy mode: Based on the blacklist mechanism, programs not on the blacklist can attempt to access sensitive files.

[0164] Strict policy mode: Based on the whitelist policy, only programs on the whitelist are allowed to access sensitive files, and all other programs are denied access.

[0165] 3) Real-time adjustment.

[0166] The administrator can flexibly switch the policy mode or update specific rules according to system load, program requirements, and security situation.

[0167] 5. Audit log generation and analysis:

[0168] 1) Log record content.

[0169] For each access request (successful or failed) to a sensitive file, the system generates an audit log: access time, access program path and label, file path and label, and reason for denying access (such as blacklist match, insufficient sensitivity level, etc.).

[0170] 2) Log storage and analysis.

[0171] The audit logs are stored in a secure directory for administrators to review regularly. By analyzing the logs, administrators can identify abnormal access behaviors, adjust the black and white lists and access permission policies, and optimize system security.

[0172] In this embodiment, by implementing a black and white list mechanism in the Linux kernel and combining configuration policies, operations such as access, modification, and deletion of sensitive files by programs are monitored and controlled in real time, thereby effectively enhancing system security and preventing risks brought by malicious programs or improper operations.

[0173] Embodiment 2:

[0174] This embodiment proposes a file access control device based on black and white lists in the Linux kernel, including:

[0175] Sensitive file module: Automatically identify sensitive files and add classification marks to sensitive files according to the control policy mode; the classification marks include black and white list marks;

[0176] Program permission module: The Linux kernel intercepts and checks whether the program accessing the sensitive file is assigned a static permission mark. If it exists, it transfers to the judgment module; if not, it transfers to the matching judgment module; the static permission marks include black and white list permission marks;

[0177] Judgment module: Judge whether access is allowed according to the static permission mark of the program and the classification mark of the sensitive file;

[0178] Matching judgment module: Extract program information according to the control policy mode and match the black and white list features; then judge whether access is allowed according to the matching result and the classification mark of the sensitive file;

[0179] Mode switching module: Switch the control policy mode according to the demand during system operation and modify the classification mark of the sensitive file.

[0180] Among them, the control policy mode in the sensitive file module includes a blacklist mechanism in the loose policy mode and a whitelist mechanism in the strict policy mode; the blacklist mechanism only prohibits programs in the blacklist from accessing sensitive files, and the whitelist mechanism only allows authorized programs in the whitelist to access sensitive files.

[0181] An extraction unit is set in the matching judgment module to extract program information according to the control policy mode. The blacklist mechanism extracts the program file path, program name, program content hash value, and word frequency feature value as program information, and the whitelist mechanism only extracts the program content hash value as program information.

[0182] A matching unit is set in the matching judgment module to match blacklist features through a feature matching algorithm, and a lightweight difference detection method is used to quickly calculate the similarity between the extracted program information and the blacklist features: First, obtain the blacklist features. Under the blacklist mechanism, extract the program information content in bytecode format, count the number of occurrences of each word (00-FF) separately as the word frequency feature of the blacklist features, and configure a similarity threshold. After the kernel intercepts and executes the program, when extracting the program information, obtain the word frequency of the program information in the same way, compare it with the word frequency of the blacklist features, calculate the difference in the word frequency of each word (00-FF), calculate the total difference, and if it is within the similarity threshold range, determine that the current program and the program in the blacklist features are the same program or similar programs.

[0183] The grading mark of sensitive files in the sensitive file module also includes a sensitivity level mark, and the static permission mark of the program in the program permission module correspondingly includes a sensitivity level permission mark.

[0184] The Linux kernel-based file access control device based on black and white lists proposed in this embodiment can implement the Linux kernel-based file access control method described in Embodiment 1 and has the same technical effects.

[0185] The above embodiments are only the preferred embodiments of the present invention and are only used to help understand the method and its core idea of the present application. The protection scope of the present invention is not limited to the above embodiments. Any technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A file access control method based on black and white lists for the Linux kernel, characterized in that, Including: S1. Automatically identify sensitive files and add a classification mark to the sensitive files according to the control policy mode; the classification mark includes black and white list marks; S2. The Linux kernel intercepts and checks whether the program accessing the sensitive file is assigned a static permission mark. If it exists, step S3 is executed; if it does not exist, step S4 is executed; the static permission mark includes black and white list permission marks; S3. Judge whether to allow access according to the static permission mark of the program and the classification mark of the sensitive file; S4. Extract program information according to the control policy mode and match black and white list features; Then judge whether to allow access according to the matching result and the classification mark of the sensitive file; S5. Switch the control policy mode according to the demand during the system operation and modify the classification mark of the sensitive file.

2. The Linux kernel-based file access control method based on black and white lists according to claim 1, characterized in that, The control policy mode in step S1 includes a blacklist mechanism in the loose policy mode and a whitelist mechanism in the strict policy mode; the blacklist mechanism only prohibits programs in the blacklist from accessing sensitive files, and the whitelist mechanism only allows authorized programs in the whitelist to access sensitive files.

3. The method for controlling file access based on black and white lists in the Linux kernel according to claim 2, wherein The method for extracting program information according to the control policy mode in step S4 includes: the blacklist mechanism extracts the program file path, program name, program content hash value, and word frequency feature value as program information, and the whitelist mechanism only extracts the program content hash value as program information.

4. The method for controlling file access based on black and white lists in the Linux kernel according to claim 3, wherein, In step S4, the blacklist features are matched through a feature matching algorithm. The method includes: Using a lightweight difference detection method to quickly calculate the similarity between the extracted program information and the blacklist features: first obtain the blacklist features, extract the program information content in bytecode format under the blacklist mechanism, count the number of occurrences of each word separately as the word frequency feature of the blacklist features, and configure a similarity threshold; after the kernel intercepts and executes the program, when extracting the program information, obtain the word frequency of the program information in the same way and compare it with the word frequency of the blacklist features, calculate the difference of each word's word frequency, calculate the total difference, and if it is within the similarity threshold range, it is determined that the current program and the program in the blacklist features are the same program or similar programs.

5. The Linux kernel-based file access control method based on black and white lists according to claim 1, characterized in that, The classification mark of the sensitive file in step S1 further includes a sensitivity level mark, and the static permission mark of the program in step S2 correspondingly includes a sensitivity level permission mark.

6. A file access control device based on black and white lists for the Linux kernel, characterized in that, Including: Sensitive file module: Automatically identify sensitive files and add a classification mark to the sensitive files according to the control policy mode; the classification mark includes black and white list marks; Program permission module: The Linux kernel intercepts and checks whether the program accessing the sensitive file is assigned a static permission mark. If it exists, it transfers to the judgment module; if it does not exist, it transfers to the matching judgment module; The static permission mark includes black and white list permission marks; Judgment module: Judge whether to allow access according to the static permission mark of the program and the classification mark of the sensitive file; Matching judgment module: Extract program information according to the control policy mode and match black and white list features; Then judge whether to allow access according to the matching result and the classification mark of the sensitive file; Mode switching module: Switch the control policy mode according to the demand during the system operation and modify the classification mark of the sensitive file.

7. The Linux kernel-based file access control device according to claim 6, characterized in that, The control policy modes described in the sensitive file module include the blacklist mechanism of the loose policy mode and the whitelist mechanism of the strict policy mode; the blacklist mechanism only prohibits the programs in the blacklist from accessing sensitive files, and the whitelist mechanism only allows the authorized programs in the whitelist to access sensitive files.

8. The Linux kernel-based file access control device according to claim 7, wherein, An extraction unit is set in the matching judgment module to extract program information according to the control policy mode. The blacklist mechanism extracts the program file path, program name, program content hash value, and word frequency feature value as program information, and the whitelist mechanism only extracts the program content hash value as program information.

9. The Linux kernel-based file access control device based on black and white lists according to claim 8, characterized in that, A matching unit is set in the matching judgment module to match the blacklist features through a feature matching algorithm, and use a lightweight difference detection method to quickly calculate the similarity between the extracted program information and the blacklist features: First, obtain the blacklist features. Under the blacklist mechanism, extract the program information content in bytecode format, count the number of times each word appears separately as the word frequency feature of the blacklist features, and configure a similarity threshold; after the kernel intercepts and executes the program, when extracting the program information, obtain the word frequency of the program information in the same way and compare it with the word frequency of the blacklist features, calculate the difference in the word frequency of each word, calculate the total difference. If it is within the similarity threshold range, it is determined that the current program and the program in the blacklist features are the same program or similar programs.

10. The Linux kernel-based file access control device according to claim 6, wherein The classification mark of sensitive files in the sensitive file module also includes a sensitivity level mark, and the static permission mark of programs in the program permission module correspondingly includes a sensitivity level permission mark.

Citation Information

Cited By

  • Lightweight security protection method for file permission access in localized scene

    CN121808766A