Process monitoring improvement method and device for dynamic measurement function of system
By building the kernel dynamic dynamic metric functional components, decoupling the policy library and the benchmark library, the process is fully measured, and the problem of omissions in the dynamic metric scheme is solved, ensuring the trustworthiness of the process and the security of the system.
Patent Information
- Application Number
- CN202510883822.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-06-30
AI Technical Summary
The existing dynamic metric scheme cannot effectively monitor the tampering of newly added dynamic library code segments and read-only data segments in the process, resulting in missed measurements and unable to prove the actual credibility of the monitored process.
Build the kernel dynamic metrics functional components, including the policy library and the benchmark library. By traversing the system process list, check whether the vma of each process saves the benchmark value in the benchmark library, calculates the hash value and compares it, ensuring the complete measurement of the process, the policy library is decoupled from the benchmark library, and the measurement strategy is independently maintained.
The process is fully measured, avoids omissions of measurement segments, ensures the actual credibility of the monitored process, and improves the security and stability of the system.
Smart Images

Figure CN120371656A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of computer information technology, and in particular relates to a process monitoring improvement method and device for a system dynamic measurement function. Background Art
[0002] With the rapid development of science and technology, hacker technology is also constantly evolving and upgrading. Nowadays, more and more hackers no longer rely on traditional file replacement methods to carry out attacks, but focus on digging system vulnerabilities and invading the system by directly modifying the data in the memory. This attack method is more covert and efficient, and poses an unprecedented challenge to the security protection of the system. In order to cope with this new threat, host protection technology must be continuously improved to effectively deal with complex and changeable attack methods and ensure the security and stability of the system. With the rapid development of science and technology, hacker technology is also constantly evolving and upgrading. Nowadays, more and more hackers no longer rely on traditional file replacement methods to carry out attacks, but focus on digging system vulnerabilities and invading the system by directly modifying the data in the memory. This attack method is more covert and efficient, and poses an unprecedented challenge to the security protection of the system. In order to cope with this new threat, host protection technology must be continuously improved to effectively deal with complex and changeable attack methods and ensure the security and stability of the system.
[0003] Dynamic measurement is a method of periodic hash checking of read-only data and code segments of running processes. In another dimension, it strengthens the monitoring of key software processes in the system and can shut down processes that have been maliciously tampered with according to policy configuration, thereby improving the overall security of the system and reducing the threat of hacker attacks.
[0004] At present, dynamic measurement mainly checks the code segment corresponding to the elf file in the policy configuration and the memory vma (virtual memory address) mapping related to the read-only data segment to confirm whether the process has been maliciously attacked. When the corresponding mapped memory segment detects a change in the measurement value, an alarm record is issued or actions such as killing the abnormal process are executed.
[0005] However, the existing dynamic measurement schemes have logical contradictions that need to be resolved: Since the process operation depends on executable files and dynamic libraries, the corresponding segments of each dynamic library and executable file are maintained separately in the process, and the dynamic libraries used by the program are not all loaded at once, which results in the absence of an exact node to guarantee that no new dynamic library code segments or read-only data segments will be added to the process later. In some existing dynamic measurement designs, all measurement benchmark values are calculated at a specific time node at one time and used as the measurement benchmark for the subsequent process. This method has a logical fallacy in time, which makes it impossible for the dynamic measurement task to monitor the tampering of the dynamic library code segment and read-only data segment after the process baseline value is captured, resulting in measurement omissions.
[0006] In the existing design, to solve the above problems, a method of measuring the elf segment is adopted. In this method, only the vma of the dynamic library or the executable file added to the measurement policy is measured, rather than measuring and checking all the key segments of the entire process. There is still a hidden danger of undetected inspection. For example, when the vma of the X dynamic library in process A is tampered with, due to the copy-on-write mechanism between processes, the vma of the X dynamic library in process B will not be changed. It can be concluded that the tampering of the vma of the X dynamic library in process A is not equivalent to the modification of all the vmas corresponding to the X dynamic library.
[0007] In summary, in the existing dynamic measurement design state, the failure to detect tampering anomalies does not prove that the monitored object has not actually undergone memory state tampering, that is, it cannot prove the actual credibility of the monitored process. Summary of the Invention
[0008] The purpose of the present invention is to provide an improved method and device for process monitoring with system dynamic measurement functions, which issues policies for the process main body and takes the entire process as the measurement target, solving the problems of measurement omission and the inability to prove the actual credibility of the monitored process existing in the existing dynamic measurement functions.
[0009] To achieve the above purpose, the technical solution of the present invention is as follows: An improved method for process monitoring with system dynamic measurement functions includes: S1. Construct a kernel-state dynamic measurement function component, which includes a policy library and a reference library; the reference library is used to store the reference values of the memory vma mappings related to the code segments of the executable program files and dynamic libraries; the policy library is used to store measurement policies, and the measurement policy contains the unique identification information of the main executable file of the process; S2. When the measurement task is started, traverse the entire process list in the system through the kernel-state dynamic measurement function component, and detect whether the main executable file corresponding to the current process is in the measurement policy list. If it is, execute step S3; if not, execute step S4; S3. Traverse the vma list of the current process, check whether each vma has a reference value stored in the reference library. If not, calculate the vma hash value and save it as the reference value in the reference library; if there is a saved value, measure the vma hash value and compare it with the reference value. If they match, continue to traverse the next vma; if they do not match, decide whether to kill the process to which the vma belongs according to the measurement policy; S4. Traverse the next process in the process list until the process list is traversed.
[0010] Further, the method for constructing the kernel-state dynamic measurement function component in step S1 includes: Build a file system interface for the user layer to write configuration information and measurement policy information to the kernel layer; Build an initialization component responsible for initializing the policy library, benchmark library, and starting a timing task maintenance thread; Build a timing task maintenance thread: used to schedule measurement tasks at a specific measurement period according to the cycle policy configuration in the measurement policy; Build a process measurement component: As the core component of the dynamic measurement function, when called, it scans all processes in the kernel and compares the policies. When the policies match, measurement actions are performed; when it is found that the vma information is tampered with during measurement, logs are generated through the standard syslog interface and passed to the upper-layer auditd service, and it decides whether to kill the process to which the vma belongs according to the measurement policy.
[0011] Furthermore, the collection of benchmark values in the benchmark library described in steps S1 and S3 includes: S101. Local loading: After the kernel-mode dynamic measurement function component is started for the first time, read the localized benchmark database and write it to the benchmark library through the file system interface; S102. Collect benchmark values through the dynamic measurement benchmark library collection function mounted on the lsm hook when loading the elf file and write them to the benchmark library; S103. Complete the missing benchmark values during the measurement action.
[0012] Even further, the dynamic measurement benchmark library collection function includes: Confirm whether it is an executable mapping. If so, check whether there is already a benchmark value for the current mapping object. If not, calculate the benchmark value and write it to the kernel-mode benchmark library.
[0013] Furthermore, the start of the measurement task in step S2 includes: measurement event trigger and measurement policy update.
[0014] On the other hand, the present invention also proposes an improved device for process monitoring of the system dynamic measurement function, including: Kernel-mode dynamic measurement function component: The kernel-mode dynamic measurement function component includes a policy library and a benchmark library; the benchmark library is used to save the code segment benchmark values of the execution program file and the dynamic library; the policy library is used to save the measurement policy, and the measurement policy contains the unique identification information of the main execution file of the process; Process detection module: Traverse all process lists in the system through the kernel-mode dynamic measurement function component, and detect whether the main execution file corresponding to the current process is in the measurement policy list. If so, jump to the Vma traversal module; if not, jump to the process traversal module; Vma Traversal Module: Traverse the vma list of the current process, check whether each vma has a reference value saved in the reference library. If not, calculate the vma hash value and save it as the reference value in the reference library. If it has been saved, measure the vma hash value and compare it with the reference value. If they match, continue to traverse the next vma. If they don't match, decide whether to kill the process to which the vma belongs according to the measurement policy; Process Traversal Module: Traverse the next process in the process list until the process list traversal is completed.
[0015] Furthermore, the kernel-mode dynamic measurement function component includes: File system interface, used for the user layer to write configuration information and measurement policy information to the kernel layer; Initialization component, responsible for initializing the policy library, reference library, and starting the timing task maintenance thread; Timing task maintenance thread: Used to schedule measurement tasks at a specific measurement period according to the period policy configuration in the measurement policy; Process measurement component: As the core component of the dynamic measurement function, when called, it scans all processes in the kernel and compares policies. When the policies match, measurement actions are performed. When it is found that the vma information has been tampered with during measurement, a log is generated through the standard syslog interface and passed to the upper-layer auditd service, and it decides whether to kill the process to which the vma belongs according to the measurement policy.
[0016] Furthermore, the collection of reference values in the reference library in the kernel-mode dynamic measurement function component and the Vma traversal module includes: Local loading unit: After the kernel-mode dynamic measurement function component is started for the first time, read the localized reference database and write it to the reference library through the file system interface; File loading unit: When loading an elf file, collect reference values through the dynamic measurement reference library collection function mounted on the lsm hook and write them to the reference library; Missing value completion unit: Complete missing reference values during measurement actions.
[0017] Even further, the dynamic measurement reference library collection function of the file loading unit includes: Confirm whether it is an executable mapping. If so, check whether the current mapping object already has a reference value. If not, calculate the reference value and write it to the kernel-mode reference library.
[0018] Furthermore, the start of the measurement task in the process detection module includes: measurement event trigger, measurement policy update.
[0019] Compared with the prior art, the present invention has the following beneficial effects: (1) In the present invention, the policy library for dynamic measurement is separated from the benchmark library. The benchmark library is responsible for collecting and maintaining the benchmark values of each segment, while the policy library is responsible for the supervision logic of the measurement policy, without the need to pay attention to the specific number of measurement segments and specific objects. Logically, the benchmark library and the policy library are decoupled. The measurement policy focuses on specific measurement objects, ensuring that each dynamic measurement can perform a full measurement on the process, avoiding the problem of missing measurement segments in other existing solutions.
[0020] (2) The measurement policy of the present invention takes the complete execution program or process as the main body, rather than a single elf as the main body, ensuring that there is no contradiction in the logical correspondence between the policy and the measured entity program or process.
[0021] (3) The dynamic measurement range of the present invention always remains the entire code segment of the complete process, rather than the corresponding segment of a specific file or a part of the corresponding segment locked at a specific moment. Brief Description of the Drawings
[0022] Figure 1 Schematic diagram of the kernel-mode dynamic measurement function component in Embodiment 1 of the present invention; Figure 2 Functional schematic diagram of the process measurement component in the kernel-mode dynamic measurement function component in Embodiment 1 of the present invention; Figure 3 Schematic diagram of the dynamic measurement process in Embodiment 1 of the present invention; Figure 4 Schematic diagram of the benchmark value collection process of the benchmark library in Embodiment 1 of the present invention. Detailed Embodiments
[0023] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0024] The design idea of the present invention is no longer to use a single elf file as the policy configuration target, but to issue policies for the process main body (executable file) and take the entire process as the measurement target, and ensure that the monitored object is all code segments and read-only data segments of the current process through the independence of the policy library and the benchmark library, solving the problems of missing measurement segments in the existing dynamic measurement function and unclear monitored and protected objects.
[0025] The present invention will be further described below in conjunction with the drawings and specific embodiments.
[0026] Embodiment 1: In this embodiment, first, a kernel-mode dynamic measurement function component is constructed.
[0027] As Figure 1 shown, the kernel-mode dynamic measurement function component includes: 1. File System Interface: The securityfs file system interface for the user layer to write configuration information and measurement policy information to the kernel layer. Users can perform policy configuration and related function configuration through standard file operations.
[0028] 2. Initialization Component: Responsible for initializing the policy library and the baseline library; The baseline library saves the baseline values of the memory vma mappings related to the execution program file and the dynamic library code segment through the baseline value cache structure; The policy library saves the measurement policy through the policy cache structure. The measurement policy contains the unique identification information of the main execution file of the process. The unique identification information can be the real path of the main execution file of the process, or it can be a unique information such as "partition information + iNode number". In this embodiment, the real path of the main execution file of the process is used as its unique identification information and is included in the measurement policy; The initialization component initializes the policy library and the baseline library so that it can normally receive the configuration and measurement policies issued by the user layer. After initialization, it starts a timed task maintenance thread.
[0029] 3. Timed Task Maintenance Thread: Used to schedule measurement tasks at a specific measurement period according to the periodic policy configuration in the measurement policy.
[0030] 4. Process Measurement Component: The core component of the entire kernel measurement function. When called, it will scan all processes on the kernel side and compare the measurement policy. When the policy matches, a measurement action will be performed. When it is found that the key segment information has been tampered with during the measurement, a log can be generated through the standard syslog interface and passed to the upper-layer auditd service, and it will decide whether to kill the process to which the vma belongs according to the measurement policy.
[0031] Among them, the basic algorithm flow of the process measurement component as the core component is as Figure 2 shown, including: (1) Traverse all processes of the system kernel: In the system kernel, the system global task linked list can be obtained through the current process task. Traversing each node of the system global task linked list one by one can achieve the traversal of all processes.
[0032] (2) When traversing a process task structure, first obtain the real path of the main execution file of the process as the key to index the policy library (policy cache).
[0033] If there is a measurement policy for this path in the policy library, further obtain the vma list of this process task. If there is no measurement policy for this path in the policy library, continue to traverse the next task node.
[0034] The description of the vma list is as follows: Each process has an independent read-only and executable vma list to maintain all the executed files mapped in the current process, including the main executed file and dynamic library files.
[0035] (3) After obtaining the vma list, sequentially traverse the vma nodes of the currently inspected process and obtain the mapped file information of the vma nodes.
[0036] If the file information exists, it is possible that the current vma node contains a code segment or a data segment, and further verification and matching are performed. Otherwise, traverse the next vma.
[0037] Check the vma segment flag. If the segment flag is read-only, it is determined that there is a read-only data existence area; perform the measurement calculation of the read-only data segment. If the flag is executable but not writable, it is determined that there is an executable segment existence area.
[0038] Perform hash calculation for the corresponding area.
[0039] (4) Query the reference library with the mapped file path of the vma segment as the key. If there is a match, match the current hash calculation value with the reference value saved in the reference library. Otherwise, save the current hash value as the reference value to the reference library and start traversing the next vma.
[0040] If the current hash value is the same as that in the reference cache, the check passes. Otherwise, generate a log and send it to the log system to record the information that the process has been tampered with, and decide whether to kill the process to which the vma belongs according to the measurement policy.
[0041] In the above process, the measurement policy is always only related to the real path of the main executed file of the process and has nothing to do with the dynamic library.
[0042] During the running of each process, there will be multiple vma mappings for multiple files (including the executed program and dynamic library). Specifically, the reference values of the code segments of each executed program file and dynamic library are maintained in the reference library.
[0043] At the same time, the reference value library can be persistently saved and configured by upper-layer software components through the file system interface.
[0044] After building the kernel-mode dynamic measurement function component, the dynamic measurement process can be executed.
[0045] The execution of the dynamic measurement process is as Figure 3 shown, including: a. Send the measurement policy to the kernel through the file system interface of the kernel-mode dynamic measurement function component. The measurement policy has a policy list, and the policy contains the real path of the main executed file of the process as the only identification information, as well as the auxiliary policy for the main executed file of the process.
[0046] b. The kernel-mode dynamic measurement function component saves the issued measurement strategy to the strategy library.
[0047] c. When the system encounters measurement event triggering, measurement strategy update and other states, the process measurement component is started to perform the measurement task.
[0048] d. The process measurement component traverses all process lists in the system and detects whether the current process is in the policy list of the policy library. If so, it executes the next step; otherwise, it executes step j to traverse the next process.
[0049] e. Expand and traverse the vma list of the currently traversed process (that is, the independent read-only executable vma list that exists in each process).
[0050] f. Check whether the currently traversed vma already has a benchmark value in the benchmark library. If so, execute step g; otherwise, execute step h.
[0051] g. Measure the current vma hash value and compare it with the benchmark value stored in the benchmark library. If the benchmark value does not match, an alarm log is issued (generated through the standard syslog interface and passed to the upper-level auditd service), and decide whether to kill the process to which vma belongs based on the measurement strategy. Then execute step i.
[0052] h. Calculate the current vma hash value and save it as the benchmark value in the benchmark library. Then execute step i.
[0053] i. If the vma list of the current process is traversed, execute step j, otherwise traverse the next vma in the vma list and execute step f.
[0054] j. If the process list is traversed, end this round of measurement; otherwise, traverse the next process in the process list and execute step e.
[0055] The difference between the above process and traditional dynamic measurement is that the measured process segment will not be solidified at the first time. Instead, the measurement value is compared with the benchmark value through the vma list when any measurement event is triggered (manual trigger, periodic task trigger, etc.), and all key segment information of the current process is fully scanned, thereby ensuring that dynamic measurement always measures the current complete state of the process, avoiding omission of measurement segments, and thus ensuring the availability of the current dynamic measurement results.
[0056] The acquisition and update of benchmark values in the benchmark library come from three scenarios.
[0057] like Figure 4As shown, the three scenarios include local persistent baseline configuration, the loading of elf files caused by the running of any program, and the triggering of non-existent baseline values during the dynamic measurement process.
[0058] 1. Local persistent baseline value configuration: The configuration file loading process is as follows: a. When the dynamic measurement service is first started after booting, the initialization component of the dynamic measurement function component in the kernel state initializes the baseline library of the system kernel; b. Read the local baseline library; c. Write the baseline value of the local baseline library into the baseline library of the system kernel through the file system interface.
[0059] 2. Program running to load elf files: a. Any program starts; b. Trigger the elf loading system call (including program loading and dynamic library loading); c. Trigger the lsm hook; the lsm hook is the core mechanism in the Linux Security Module (lsm) framework, and realizes access control of system resources by inserting hook functions in the kernel critical path; d. Trigger the dynamic measurement baseline library collection function mounted on the lsm hook; e. The dynamic measurement baseline library collection function confirms whether the loaded elf is an executable vma mapping. If so, proceed to the next step; otherwise, return; f. Check whether the current vma mapping object already has a baseline value. If not, proceed to the next step; otherwise, return; g. Calculate the current vma baseline value; h. Write it into the kernel state baseline library.
[0060] 3. Trigger non-existent baseline values during the dynamic measurement process: a. Trigger the measurement action on a certain vma of a process; b. Check whether the baseline value exists. If it exists, perform the measurement; otherwise, proceed to the next step; c. Calculate the vma baseline value and save it into the kernel baseline library.
[0061] Since the measurement segment baseline value and the policy are separated in the present invention, the policy is used to maintain which programs or processes are measured, without the need to pay attention to the specific number of measurement segments and specific objects, ensuring that each dynamic measurement can perform a full measurement on the process and avoiding the problem of missing measurement segments in existing other solutions.
[0062] In actual project requirements, the actual demand of the user side for dynamic measurement is to monitor the overall business software of itself. When any tampering is detected in the business software, the program is terminated or a warning is issued according to the measurement policy.
[0063] Logically, the benchmark library and the policy library are independent of each other, so the benchmark value and the policy are decoupled. The measurement policy focuses on specific measurement objects, avoiding the problem that the measurement policy does not match the actual needs of users in existing other dynamic measurement schemes.
[0064] Embodiment 2: The present invention proposes an improved device for process monitoring of the system dynamic measurement function, including: Kernel-mode dynamic measurement function component: The kernel-mode dynamic measurement function component includes a policy library and a benchmark library; the benchmark library is used to store the code segment benchmark values of the execution program file and the dynamic library; the policy library is used to store the measurement policy, and the measurement policy includes the unique identification information of the main execution file of the process. Process detection module: Traverse all process lists in the system through the kernel-mode dynamic measurement function component, and detect whether the main execution file corresponding to the current process is in the list of measurement policies. If it is, jump to the Vma traversal module; if not, jump to the process traversal module. Vma traversal module: Traverse the vma list of the current process, check whether each vma has a benchmark value saved in the benchmark library. If not, calculate the vma hash value and save it as the benchmark value in the benchmark library; if there is a saved value, measure the vma hash value and compare it with the benchmark value. If they match, continue to traverse the next vma; if they do not match, decide whether to kill the process to which the vma belongs according to the measurement policy. Process traversal module: Traverse the next process in the process list until the process list traversal is completed.
[0065] Among them, the kernel-mode dynamic measurement function component includes: File system interface, used for the user layer to write configuration information and measurement policy information to the kernel layer. Initialization component, responsible for initializing the policy library, the benchmark library, and starting the timing task maintenance thread. Timing task maintenance thread: Used to schedule measurement tasks at a specific measurement period according to the period policy configuration in the measurement policy. Process measurement component: As the core component of the dynamic measurement function, when called, it scans all processes in the kernel and compares the policies, and performs measurement actions when the policies match; when it is found that the vma information is tampered with during the measurement, a log is generated through the standard syslog interface and passed to the upper-layer auditd service, and it is decided whether to kill the process to which the vma belongs according to the measurement policy.
[0066] The collection of reference values in the reference library in the kernel-mode dynamic measurement function component and the Vma traversal module includes: Local loading unit: After the kernel-mode dynamic measurement function component is started for the first time, it reads the localized reference database and writes it to the reference library through the file system interface; File loading unit: When loading an elf file, it collects reference values through the dynamic measurement reference library collection function mounted on the lsm hook and writes them to the reference library; Missing value completion unit: Completes missing reference values during the measurement operation.
[0067] The dynamic measurement reference library collection function of the file loading unit includes: Confirms whether it is an executable mapping. If so, checks whether there is already a reference value for the current mapping object. If not, calculates the reference value and writes it to the kernel-mode reference library.
[0068] The start of the measurement task in the process detection module includes: measurement event trigger, measurement policy update.
[0069] The process monitoring improvement device for the system dynamic measurement function proposed in this embodiment can implement the process monitoring improvement method for the system dynamic measurement function proposed in Embodiment 1 and has the same technical effects as the method described in Embodiment 1.
[0070] The above-described embodiments are only the preferred embodiments of the present invention and are only used to help understand the method and its core idea of the present application. The protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. An improved method for process monitoring of the system dynamic measurement function, characterized in that, including: S1. Construct a kernel-mode dynamic measurement function component, which includes a policy library and a reference library; The reference library is used to store the reference values of the memory vma mappings related to the code segments of the execution program files and dynamic libraries; The policy library is used to store measurement policies, and the measurement policies contain the unique identification information of the main execution file of the process; S2. When the measurement task is started, traverse the entire process list in the system through the kernel-mode dynamic measurement function component, and detect whether the main execution file corresponding to the current process is in the measurement policy list. If it is, execute step S3; if not, execute step S4; S3. Traverse the vma list of the current process, check whether each vma has a reference value stored in the reference library. If not, calculate the vma hash value and save it as the reference value in the reference library; if there is a saved value, measure the vma hash value and compare it with the reference value. If they match, continue to traverse the next vma; if they do not match, decide whether to kill the process to which the vma belongs according to the measurement policy; S4. Traverse the next process in the process list until the process list is traversed.
2. The method for improving process monitoring of the system dynamic measurement function according to claim 1, characterized in that, The method for constructing the kernel-mode dynamic measurement function component described in step S1 includes: Construct a file system interface for the user layer to write configuration information and measurement policy information to the kernel layer; Construct an initialization component responsible for initializing the policy library, the reference library, and starting a timing task maintenance thread; Construct a timing task maintenance thread: used to schedule measurement tasks at a specific measurement period according to the cycle policy configuration in the measurement policy; Construct a process measurement component: as the core component of the dynamic measurement function, when called, it scans all processes in the kernel and compares policies, and performs measurement actions when the policies match; when it is found that the vma information is tampered with during the measurement, generate a log through the standard syslog interface and pass it to the upper-layer auditd service, and decide whether to kill the process to which the vma belongs according to the measurement policy.
3. The method for improving process monitoring of the system dynamic measurement function according to claim 1, characterized in that, The collection of the reference values in the reference library described in steps S1 and S3 includes: S101. Local loading. After the kernel-mode dynamic measurement function component is started for the first time, read the localized reference database and write it to the reference library through the file system interface; S102. Collect reference values through the dynamic measurement reference library collection function mounted on the lsm hook when loading the elf file and write them to the reference library; S103. Complete the missing reference values during the measurement action.
4. The method for improving process monitoring of the system dynamic measurement function according to claim 3, characterized in that, The dynamic measurement reference library collection function includes: Confirm whether it is an executable mapping. If so, check whether there is already a reference value for the current mapping object. If not, calculate the reference value and write it to the kernel-mode reference library.
5. The method for improving process monitoring of the system dynamic measurement function according to claim 1, characterized in that, The start of the measurement task in step S2 includes: measurement event trigger, measurement policy update.
6. An improved device for process monitoring of the system dynamic measurement function, characterized in that, including: Kernel-mode dynamic measurement function component: The kernel-mode dynamic measurement function component includes a policy library and a reference library; The reference library is used to store the code segment reference values of the execution program files and dynamic libraries; The policy library is used to store measurement policies, and the measurement policies contain the unique identification information of the main execution file of the process; Process Detection Module: Through the kernel-mode dynamic measurement function component, traverse the entire process list in the system, and detect whether the main execution file corresponding to the current process is in the measurement policy list. If it is, jump to the Vma Traversal Module; if not, jump to the Process Traversal Module; Vma Traversal Module: Traverse the vma list of the current process, check whether each vma has a baseline value saved in the baseline library. If not, calculate the vma hash value and save it as the baseline value in the baseline library; if it is saved, measure the vma hash value and compare it with the baseline value. If they match, continue to traverse the next vma; if they do not match, decide whether to kill the process to which the vma belongs according to the measurement policy; Process Traversal Module: Traverse the next process in the process list until the process list traversal is complete.
7. The process monitoring improvement device for the system dynamic measurement function according to claim 6, characterized in that The kernel-mode dynamic measurement function component includes: File System Interface, which is used for the user layer to write configuration information and measurement policy information to the kernel layer; Initialization Component, which is responsible for initializing the policy library, baseline library, and starting the timing task maintenance thread; Timing Task Maintenance Thread: It is used to schedule measurement tasks at a specific measurement period according to the cycle policy configuration in the measurement policy; Process Measurement Component: As the core component of the dynamic measurement function, when called, it scans all kernel processes and compares policies, and performs measurement actions when the policies match; when it is found that the vma information is tampered with during measurement, it generates a log through the standard syslog interface and passes it to the upper-layer auditd service, and decides whether to kill the process to which the vma belongs according to the measurement policy.
8. The process monitoring improvement device for the system dynamic measurement function according to claim 6, characterized in that The collection of baseline values in the baseline library in the kernel-mode dynamic measurement function component and the Vma Traversal Module includes: Local Loading Unit: After the kernel-mode dynamic measurement function component is started for the first time, read the localized baseline database and write it to the baseline library through the file system interface; File Loading Unit: When loading the elf file, collect the baseline value through the dynamic measurement baseline library collection function mounted on the lsm hook and write it to the baseline library; Missing Completion Unit: Complete the missing baseline value during the measurement action.
9. The process monitoring improvement device for the system dynamic measurement function according to claim 8, characterized in that The dynamic measurement baseline library collection function of the File Loading Unit includes: Confirm whether it is an executable mapping. If so, check whether the current mapping object already has a baseline value. If not, calculate the baseline value and write it to the kernel-mode baseline library.
10. The process monitoring improvement device for the system dynamic measurement function according to claim 6, characterized in that, The start of the measurement task in the Process Detection Module includes: measurement event trigger, measurement policy update.
Citation Information
Patent Citations
Process dynamic trusted measurement method, device and system, and terminal
CN113626772A
Method for dynamically monitoring integrity of process code segment in Docker container
CN114048485A
Code segment dynamic measurement method and device and electronic equipment
CN116737526A
Linux process code segment measurement enhancement method based on dual-system architecture
CN119808095A
Cited By
Method and device for measuring process in docker container with high kernel mode speed
CN120872506A
Kernel-level high-speed docker container internal process quantity measuring method and device
CN120872506B
File integrity detection method and device, electronic equipment and storage medium
CN121881416A