Host memory security detection method, sensing card, device, equipment and medium

Through the intelligent perception card, memory mapping of host memory and operating system behavior is carried out, and correlation detection is carried out in combination with the system security mechanism, which solves the problems of inefficiency and virus attacks in the existing technology, and achieves efficient and accurate security detection.

CN120449151APending Publication Date: 2025-08-08BEIJING TONGCHUANG SECURITY TRUST TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510394687.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The prior art is not efficient in host memory security detection, and security software is vulnerable to virus attacks, occupying computing resources, and affecting system performance.

Method used

Through the intelligent perception card, the host memory data and operating system behavior is surveyed and mapped, the system security mechanism is used to obtain behavioral data, and the associated comprehensive security detection is performed to avoid relying on operating system software. The PCIe DMA mechanism is used to directly obtain data from the physical memory bus.

Benefits of technology

Improve the efficiency and accuracy of host memory security detection, avoid virus interference, reduce the occupation of host resources, and achieve real-time and interference-free security detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120449151A_ABST
    Figure CN120449151A_ABST
Patent Text Reader

Abstract

The invention provides a security detection method and device for a host memory, a sensing card, equipment and a medium, and the method comprises the steps: obtaining a target detection mode which is used for indicating the security detection of the memory data of a host and / or the behavior of a target operating system on the host; when the target detection mode indicates that security detection is performed on the memory data of the host, performing memory surveying and mapping on the target operating system to obtain the memory data, and performing security detection on the memory data; when the target detection mode indicates that security detection is carried out on memory data of the host and behaviors of a target operating system on the host, memory mapping is carried out on the target operating system to obtain memory data, and behavior data is obtained through a system security mechanism on the target operating system; and associated comprehensive security detection is carried out on the memory data and the behavior data. Therefore, the security detection efficiency and accuracy of the host memory are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of security detection technology, and in particular, to a security detection method, sensing card, device, equipment, and medium applicable to host memory. Background Art

[0002] In today's information age, the battle between cyberattacks and cyberdefense is intensifying. Attackers are constantly developing new attack methods, while defenders are also continuously strengthening their countermeasures. In this offensive and defensive confrontation, timely on-site perception and identification are the core of security. Perception and identification means being able to quickly detect abnormal behavior and potential threats in the system, accurately and quickly identify and analyze them, and promptly preserve evidence to prevent attackers from destroying traces of the crime scene. It also prevents attackers from detecting and interfering with it, thus enabling effective defensive measures.

[0003] In related technologies, host memory security testing is primarily based on installed software. Specifically, designated security software is installed at the operating system level, and the software is used to perform real-time attack detection on the operating system. This installed security software and operating system structure are vulnerable to virus attacks, rendering security ineffective or inaccurate, preventing effective detection. Furthermore, the running of security software consumes host resources, and the complex calculations consumed by the software consume significant computing resources, slowing down service response times.

[0004] However, using existing technologies, the efficiency of security detection is not high. Summary of the Invention

[0005] The embodiments described herein provide a host memory security detection method, sensing card, apparatus, device, and medium to overcome the above-mentioned problems.

[0006] In a first aspect, according to the present disclosure, a host memory security detection method is provided, comprising:

[0007] Acquire a target detection mode, where the target detection mode is used to instruct to perform security detection on memory data of a host and / or behavior of a target operating system on the host;

[0008] When the target detection mode indicates to perform security detection on the memory data of the host, obtaining the memory data by performing memory mapping on the target operating system, and performing security detection on the memory data;

[0009] When the target detection mode indicates that a security check is to be performed on the memory data of the host and the behavior of the target operating system on the host, the memory data is obtained by performing memory mapping on the target operating system, the behavior data is obtained through the system security mechanism on the target operating system, and the memory data and the behavior data are correlated and comprehensively security checked.

[0010] In a second aspect, according to the present disclosure, a smart perception card is provided, characterized in that the smart perception card includes:

[0011] Policy parsing engine, used to obtain and parse the host memory's security detection mode and security detection policy;

[0012] a memory analysis engine, configured to perform memory mapping on the target operating system of the host according to the security detection mode and the security detection policy to obtain memory data of the host;

[0013] A behavior analysis engine, configured to obtain behavior data of the target operating system through a system security mechanism on the target operating system in accordance with the security detection mode and the security detection policy;

[0014] The policy parsing engine is further configured to perform security detection on the memory data and / or the behavior data according to the security detection policy.

[0015] In a third aspect, a host memory security detection device is provided, comprising:

[0016] an acquiring unit, configured to acquire a target detection mode, wherein the target detection mode is used to instruct to perform security detection on memory data of a host and / or behavior of a target operating system on the host;

[0017] a first detection unit, configured to obtain the memory data by performing memory mapping on the target operating system and perform security detection on the memory data when the target detection mode indicates to perform security detection on the memory data of the host;

[0018] The second detection unit is used to obtain the memory data by performing memory mapping on the target operating system when the target detection mode indicates that a security detection is to be performed on the memory data of the host and the behavior of the target operating system on the host, obtain the behavior data through the system security mechanism on the target operating system, and perform a correlated comprehensive security detection on the memory data and the behavior data.

[0019] In a fourth aspect, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the steps of the host memory security detection method in any of the above embodiments are implemented.

[0020] In a fifth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the host memory security detection method in any of the above embodiments are implemented.

[0021] The host memory security detection method provided by the embodiment of the present application includes: obtaining a target detection mode, the target detection mode is used to indicate a security detection of the host's memory data and / or the behavior of the target operating system on the host; when the target detection mode indicates a security detection of the host's memory data, memory data is obtained by performing memory mapping on the target operating system, and a security detection is performed on the memory data; when the target detection mode indicates a security detection of the host's memory data and the behavior of the target operating system on the host, memory data is obtained by performing memory mapping on the target operating system, behavior data is obtained through the system security mechanism on the target operating system, and a comprehensive security detection is performed on the memory data and the behavior data. In this way, the host's memory data and / or the behavior of the target operating system on the host are security detected by the smart perception card, and memory data is obtained by performing memory mapping on the target operating system by the smart perception card, so as to effectively improve the efficiency and accuracy of the host memory security detection.

[0022] The above description is only an overview of the technical solutions of the embodiments of the present application. In order to more clearly understand the technical means of the embodiments of the present application, they can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the embodiments of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings of the embodiments will be briefly described below. It should be noted that the drawings described below only relate to some embodiments of the present disclosure and are not intended to limit the present disclosure.

[0024] Figure 1 This is a flowchart of a host memory security detection method provided by the present disclosure.

[0025] Figure 2 This is a memory data detection flow chart provided by the present disclosure.

[0026] Figure 3 This is a flowchart of association detection of memory data and behavior data provided by the present disclosure.

[0027] Figure 4 This is a memory mapping flow chart provided by the present disclosure.

[0028] Figure 5This is a data communication diagram of a smart perception card provided by the present disclosure.

[0029] Figure 6 This is a schematic diagram of the structure of a host memory security detection device provided by the present disclosure.

[0030] Figure 7 It is a structural diagram of a computer device provided by the present disclosure.

[0031] It should be noted that the elements in the drawings are schematic and not drawn to scale. DETAILED DESCRIPTION

[0032] In order to make the purpose, technical solutions and advantages of the embodiments of the present disclosure more clear, the technical solutions of the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the described embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative work also fall within the scope of protection of the present disclosure.

[0033] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present disclosure belongs. It will be further understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the specification and the relevant art, and will not be interpreted in an idealized or overly formal manner unless otherwise explicitly defined herein. As used herein, a statement that two or more parts are "connected" or "coupled" together shall mean that the parts are joined together either directly or through one or more intermediate components.

[0034] References to "embodiments" herein mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase "embodiment" in various places in the specification does not necessarily refer to the same embodiment, nor does it necessarily refer to independent or alternative embodiments that are mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0035] The term "and / or" in this document simply describes an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists, A and B exist simultaneously, and B exists. Additionally, the character " / " in this document generally indicates that the related objects are in an "or" relationship. Terms such as "first" and "second" are used solely to distinguish one component (or portion of a component) from another component (or portion of a component).

[0036] In the description of this application, unless otherwise specified, "plurality" means more than two (including two), and similarly, "multiple groups" means more than two (including two).

[0037] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.

[0038] Figure 1 This is a flow chart of a host memory security detection method provided by an embodiment of the present disclosure. The operating system referred to in this embodiment has corresponding mode differences. For example, the security mechanism cannot add security software to the operating system, or it is not in the offensive and defensive security requirements. The user needs to detect the operation of the business program and no other checks are performed.

[0039] like Figure 1 As shown in FIG, the specific process of the host memory security detection method includes:

[0040] S110: Acquire target detection mode.

[0041] The target detection mode is used to instruct a security check to be performed on the host's memory data and / or the behavior of the target operating system on the host. It is understood that the target detection mode can be used to instruct an independent security check to be performed on the host's memory data, or to instruct an independent security check to be performed on the behavior of the target operating system on the host, or to instruct an associated security check to be performed on the host's memory data and the behavior of the target operating system on the host.

[0042] S120 : When the target detection mode indicates to perform security detection on the host's memory data, obtain the memory data by performing memory mapping on the target operating system, and perform security detection on the memory data.

[0043] Memory mapping can analyze kernel objects, mapping the layout of kernel objects within the operating system and deriving the location addresses of different memory data objects. Based on prior knowledge of the operating system kernel, for example, a target analysis file can be generated based on security check logic and requirements expressed in a programming language within the target operating system and sent to the smart perception card. The policy parsing engine converts the target analysis file into specific operations to establish memory data objects. The target analysis file includes the address information and storage structure of the target kernel. Memory scanning and searching is performed using the PCIe protocol's DMA mechanism, identifying key information to map and extract kernel object structure address information within the system. Related storage and indexing are then established for use during detection.

[0044] In some embodiments, memory data is obtained by performing memory mapping on the target operating system, and security detection of the memory data is performed, including:

[0045] Obtain and parse the first security detection policy file; when it is detected that the conditions for periodic security detection are met, obtain memory data by performing memory mapping on the target operating system, and perform security detection on the memory data according to the first security detection policy file.

[0046] The first security detection policy file is used to instruct periodic security checks on memory data. The first security detection policy file consists of detection rules written by security personnel and distributed to the smart sensing card. The smart sensing card's policy parsing engine then loads the policy file into memory, obtaining the result. This file is used to detect specific data objects in memory. Based on the sub-policies within the first security detection policy file, each sub-policy establishes a thread or process that periodically queries and detects relevant memory data objects based on the sub-policy's contents, facilitating parallel and independent detection of multiple sub-policies.

[0047] like Figure 2 As shown in the figure, the memory data security detection process includes:

[0048] S210: Writing a detection policy file based on a policy language, sending the policy file to the smart perception card, and loading all policy files into memory through a policy parsing engine on the smart perception card.

[0049] S220 , determining whether the policy file is a periodic measurement; if so, executing step S230 ; if not, not processing.

[0050] S230: Add the policy file to the periodic measurement list, and add the number of threads corresponding to the number in the measurement list.

[0051] S240, each thread determines whether the cycle condition of the policy is met; if so, execute S250; if not, repeat the determination in a loop.

[0052] S250: Check each item according to the policy content.

[0053] Among them, each detection item needs to query the memory analysis engine in the smart perception card to obtain corresponding data (such as memory data, such as data in a shared memory segment, or data in a process stack, data in the process symbol table, etc.) to complete the detection.

[0054] S260: The memory analysis engine queries whether the data exists locally based on the request. If so, the data is sent to the thread for detection. If not, the bus address of the data object is located based on the memory mapping result.

[0055] S270: The memory analysis engine drives the DMA to obtain the data according to the bus address and returns it to the thread for detection.

[0056] After the thread completes all detections and obtains the detection results, the detection results will be logged according to the strategy, the detection content data will be recorded and stored locally to form the corresponding memory evidence, and the detection results and data will be sent to the intelligent digital immunity platform through the network for display and storage.

[0057] S130. When the target detection mode indicates that a security detection is to be performed on the host's memory data and the behavior of the target operating system on the host, memory data is obtained by performing memory mapping on the target operating system, behavior data is obtained through the system security mechanism on the target operating system, and a comprehensive security detection is performed on the memory data and the behavior data.

[0058] System security mechanisms utilize the operating system's built-in security checkpoints for security monitoring and program debugging to capture system behavior, such as ftrace (which targets files only) and tracepoints. They also include other debugging and tracing mechanisms within the operating system kernel, such as kprobes, which utilize breakpoint instructions to perform security checks and capture system behavior.

[0059] In some embodiments, memory data is obtained by performing memory mapping on the target operating system, behavioral data is obtained through the system security mechanism of the target operating system, and the memory data and behavioral data are correlated and integrated security detection is performed, including:

[0060] Obtain and parse the second security detection policy file, and determine whether the second security detection policy file contains a behavior and memory comprehensive measurement strategy; if the second security detection policy file contains a behavior and memory comprehensive measurement strategy, retrieve the target behavior that meets the behavior detection conditions; obtain behavior data related to the target behavior, and obtain memory data by performing memory mapping on the target operating system; perform correlated comprehensive security detection on the memory data and the behavior data related to the target behavior.

[0061] Among them, the comprehensive behavior and memory measurement strategy is used to describe sensitive behavior information related to behavior, which may include but is not limited to: operating key files, for example, modifying the operating system password record file passwd, modifying the operating system firewall configuration, modifying the startup configuration, creating and modifying binary executable files in key directories, and setting executable behavior of applications on memory.

[0062] like Figure 3 As shown in the figure, the integrated security detection process of memory data and behavioral data includes:

[0063] S310: Write a detection policy file based on the policy language, send the policy file to the smart perception card, and load all the policy files into the memory by the policy parsing engine.

[0064] S320: The policy analysis engine sends the behavior-related sensitive behavior information to the behavior engine, and the behavior engine forwards the behavior described in the policy to the policy analysis engine for retrieval based on the policy.

[0065] Among them, if the amount of behavior is large, the behavior engine will filter it in the behavior perception module in the operating system to optimize processing efficiency.

[0066] S330: The behavior perception module in the operating system sends the system behavior to the behavior analysis engine. If there is an optimization strategy, the behavior that meets the conditions is sent to the behavior analysis engine.

[0067] S340 , the behavior engine determines whether the behavior is a sensitive behavior marked in the policy. If not, no processing is performed; if so, S350 is executed.

[0068] S350: Find the corresponding policy in the policy analysis engine and perform detection.

[0069] Among them, after the policy analysis engine discovers the behavior, it starts a thread to perform detection based on the policy content. The thread accesses the memory analysis engine to obtain the corresponding data. The memory analysis engine queries whether the data is available locally based on the request. If so, the data is given to the thread for detection. If not, the bus address of the data object is located based on the memory mapping results. The memory analysis engine drives DMA to obtain the data based on the bus address and returns it to the thread for detection.

[0070] This thread accesses the behavior analysis engine to obtain the corresponding behavior data, performs correlation detection based on the policy-based integrated memory data and behavior data, and obtains the detection results; records the detection results in a log according to the policy, records the detection content data and stores it locally to form the corresponding memory evidence, and sends the detection results and data via the network to the intelligent digital immunity platform for display and storage.

[0071] In addition, when the target detection mode indicates that a security check is to be performed on the behavior of the target operating system on the host, the behavior data is obtained through the system security mechanism on the target operating system, and the behavior data is subjected to a security check. It should be noted that the security check on the behavior data may include: writing a detection policy file based on a policy language, sending the policy file to the smart perception card, the policy parsing engine loading all policy files into the memory, the policy parsing engine sending the sensitive behavior information related to the behavior to the behavior engine, and the behavior engine forwarding the behavior described by the policy to the policy parsing engine for retrieval based on the policy. The behavior perception module in the operating system sends the system behavior to the behavior analysis engine, and the behavior engine determines whether the behavior is a sensitive behavior marked in the policy. If not, it will not be processed; if it is, the corresponding policy will be found in the policy analysis engine for detection. After the policy analysis engine discovers the behavior, it starts a thread to perform a security check based on the policy content.

[0072] In some embodiments, memory data is obtained by performing memory mapping on the target operating system, including:

[0073] Obtain a target analysis file corresponding to the target operating system; the target analysis file includes: address information and data storage structure information; determine the address and parsing method of the kernel object based on the address information and data storage structure information; parse the kernel object according to the address and parsing method of the kernel object to determine the address of each data object, the storage structure and description information of the data object; establish an index table of the address and storage structure of the data object, and obtain memory data according to the index table.

[0074] The address information describes the distribution addresses of kernel objects in the target operating system. The data storage structure information describes the storage structure and description of each data object within the kernel object, such as a DWARF file. Each data object within the kernel object may include kernel object data and application object data. The index table stores the addresses of data objects and retrieves memory data based on the addresses.

[0075] A DWARF format file is a symbol file used in conjunction with "symbolic information." Symbol files are used to locate the definition of a particular symbol in a program, first in the current scope, then in successively enclosing scopes until the symbol is found. The same name may have multiple definitions in different scopes. DWARF format files follow this model, where each descriptive entity in DWARF (except for the top-level entry describing the source file) is contained within a parent entry and may contain child entities. If a node contains multiple entities, they are all related siblings. The DWARF description of a program is a tree structure, similar to a compiler's internal tree, where each node can have children or siblings. These nodes may represent types, variables, or functions, providing the information needed to describe a particular aspect of a program.

[0076] One operating system (uniquely identified by the kernel version number, such as 4.15.0-72-generic) corresponds to one target analysis file (including storage structure and symbol files). The surveying and mapping can support the measurement of multiple operating systems because it stores the storage structures and symbol files of multiple operating systems. The corresponding files can be found to facilitate support for multiple systems.

[0077] like Figure 4 As shown, the memory mapping process includes:

[0078] S410: Obtain target operating system kernel version information and establish a similar environment.

[0079] S420: Obtain a symbol file on a corresponding environment platform (CPU instruction set) and operating system, and execute a collection module on the corresponding platform and operating system to obtain a data structure file (used to save and store data structures).

[0080] S430: Import the symbol file and the data structure file into the smart perception card, and insert the smart perception card into the protected device.

[0081] Among them, the protected device, such as a computer, the protection device and the smart perception card are powered on and started, and the loading work can be driven by the smart perception card.

[0082] S440: The smart perception card driver transmits the kernel version information and platform information of the target operating system to the smart perception card.

[0083] S450. The smart perception card uses the DMA mechanism of the PCIe bus to locate the flag information in the memory, and uses the operating system information to select the corresponding symbol file and related data.

[0084] Among them, the smart perception card uses operating system information to select corresponding symbol files and related data to support the use of multiple platforms and operating systems. The operating system information may include but is not limited to: kernel version number, hardware architecture, processor type, kernel name, kernel version, etc.

[0085] S460. The smart perception card analyzes and locates the objects in the symbol file based on the address of the flag information, obtains the definition and corresponding address of the key object, and creates an index in the memory for the obtained definition and corresponding address of the object for quick query.

[0086] In some embodiments, obtaining a target analysis file corresponding to a target operating system includes:

[0087] Obtain kernel version information of the target operating system; determine a target analysis file corresponding to the kernel version information of the target operating system according to a pre-established mapping relationship, wherein the mapping relationship is used to indicate the correspondence between the kernel version information of the operating system and the analysis file.

[0088] The kernel version information may include the kernel version number, such as 4.15.0-72-generic, which is a unique identifier of an operating system kernel. It includes the names of various functions, variable names, variable definitions, corresponding address information, symbol types, etc. in the kernel.

[0089] The mapping relationship can represent a one-to-one correspondence between the kernel version information of the operating system and the analysis file, making it easy to quickly search for the target analysis file corresponding to the kernel version information of the target operating system through the mapping relationship.

[0090] In some embodiments, determining the address of the kernel object based on the address information and the data storage structure information includes:

[0091] The DMA mechanism of the PCIe bus is used to locate the address of the target identification information in the host memory; based on the address and address information of the target identification information, the address of the key kernel object is relocated; based on the address of the relocated key kernel object and data storage structure information, the addresses of other kernel objects are determined.

[0092] The identification information is a specific string of content that needs to be searched bit by bit in the memory. The target identification information is a special character identifier that is used to relocate the location of the bus address.

[0093] Specifically, the offset may be calculated according to the physical bus position of the target identification information, and the address of the target identification information may be located according to the offset.

[0094] In the process of relocating the address of the key kernel object, the address information of the target identification information and the offset can be used to perform calculation and transformation to obtain the address of the relocated key kernel object.

[0095] The host memory security detection method provided in this embodiment includes: obtaining a target detection mode, the target detection mode is used to indicate a security detection of the host's memory data and / or the behavior of the target operating system on the host; when the target detection mode indicates a security detection of the host's memory data, memory data is obtained by performing memory mapping on the target operating system, and a security detection is performed on the memory data; when the target detection mode indicates a security detection of the host's memory data and the behavior of the target operating system on the host, memory data is obtained by performing memory mapping on the target operating system, behavior data is obtained through the system security mechanism on the target operating system, and a comprehensive security detection is performed on the memory data and the behavior data. In this way, the host's memory data and / or the behavior of the target operating system on the host are security detected through the smart perception card, and memory data is obtained through memory mapping on the target operating system through the smart perception card, so as to effectively improve the efficiency and accuracy of the host memory security detection.

[0096] Figure 5 This is a data communication diagram of a smart perception card provided in this embodiment. The smart perception card 50 includes: a policy parsing engine 501, a memory analysis engine 502 and a memory analysis engine 503.

[0097] Smart Perception Card 50 interacts with the target operating system via a network connection. It uses a PCIE (Peripheral Component Interconnect Express) interface card that acquires data using the PCIE bus's DMA (Direct Memory Access) mechanism. It then performs on-card data analysis, analyzing memory objects in real time and intelligently sensing changes in memory objects within the system. This allows it to determine the security status of the system and record memory security data evidence. It also has an independent network port that transmits monitored data to an analysis platform for analysis and display.

[0098] The smart perception card 50 uses the PCIe DMA mechanism to actively retrieve memory data from the bus to the smart perception card's memory analysis engine 502. The memory analysis engine 502 restores the memory object structure based on the structure and symbol information of the operating system kernel version and the acquired data, mapping the host memory address layout. The behavior perception module 511 is deployed on the computer 51 operating system. If the behavior perception module 511 is deployed, the system call behavior in the operating system will be transmitted to the smart perception card 50 via the PCIe driver. The smart perception card 50 performs correlation analysis based on the behavior data. The policy parsing engine 501 parses the security detection policy written in the policy language to obtain the specific execution operation and detection object for step-by-step detection, and finally obtains the detection result. According to the policy, the detection result is stored on the card or transmitted to the intelligent digital immunity platform 52 via the network. The smart perception card 50 has an independent network port.

[0099] The smart perception card 50 uses its own resources to establish a secure operating resource with independent resource isolation. It can be constructed using a dedicated chip, a reconfigurable chip, or a general-purpose chip (where the dedicated chip is optimized and designed based on the policy parsing engine 501 and the memory analysis engine 502 algorithm and has high computing efficiency). It has a large amount of storage space and network ports, and can use the DMA function to collect data in parallel for analysis, while maintaining the original general operating system functional process unchanged, implementing monitoring and operating status security analysis.

[0100] The policy parsing engine 501 is used to obtain and parse the security detection mode and security detection policy of the host memory.

[0101] The memory analysis engine 502 is used to perform memory mapping on the target operating system of the host according to the security detection mode and security detection policy to obtain the memory data of the host.

[0102] The behavior analysis engine 503 obtains the behavior data of the target operating system through the system security mechanism of the target operating system according to the security detection mode and security detection policy.

[0103] The policy analysis engine 501 is also used to perform security detection on memory data and / or behavior data according to the security detection policy.

[0104] Specifically, a policy file is written based on a policy language and sent to the intelligent perception 50; the policy parsing engine 501 loads all policy files into the memory to obtain a security detection policy; the policy parsing engine 501 sends the sensitive behavior information related to the behavior to the behavior analysis engine 503, and the behavior analysis engine 503 forwards the behavior described by the policy to the policy parsing engine 501 for retrieval. If the amount of behavior is large, the behavior analysis engine 503 will filter it in the behavior perception module 511 to optimize processing efficiency; the behavior perception module 511 sends the system behavior (if there is an optimization policy, it is a qualified behavior) to the behavior analysis engine 503; the behavior analysis engine 503 determines whether the behavior is a sensitive behavior marked in the security detection policy. If not, it will not be processed. If so, the corresponding policy will be found in the behavior analysis engine 503 for detection.

[0105] After the behavior analysis engine 503 discovers the behavior, it starts a thread to perform detection based on the policy content. This thread accesses the memory analysis engine 502 to obtain the corresponding data. The memory analysis engine 502 queries whether the data exists locally based on the request. If so, the data is passed to the thread for detection. If not, the bus address of the data object is located based on the memory mapping results. The memory analysis engine 502 drives the DMA to obtain the data based on the bus address and returns it to the thread for detection. The thread accesses the behavior analysis engine 503 to obtain the corresponding behavior data. Based on the security detection policy, the thread performs a correlation detection on the memory data and behavior data to obtain the detection results. The detection results are logged according to the policy. The detection content data is recorded and stored locally according to the policy to form corresponding memory evidence. According to the policy, the detection results and data are sent to the intelligent digital immune platform 52 via the network for display and storage.

[0106] This embodiment addresses existing technical shortcomings by using the PCIe DMA mechanism to obtain basic data directly from the physical memory bus, making it imperceptible and uninterruptable to operating system-level software. Furthermore, the intelligent perception card incorporates an independent computing chip capable of analyzing and restoring memory objects based on data, performing memory mapping and restoring various data structures within the operating system. This independent operation system-independent memory detection prevents malware from interfering with the detected object, significantly improving the accuracy and non-bypassability of security analysis.

[0107] Smart sensing cards use independent PCIe cards for analysis, eliminating the need for host CPU resources. They also eliminate the need for traditional endpoint acquisition methods to deeply penetrate the operating system, leading to poor compatibility and instability. Traditional endpoint detection technologies, in order to obtain various operating system data structures, require continuous adaptation to the operating system kernel, deploying hooks at various key points. This severely fragments the operating system, leading to poor stability and compatibility. Hardware-based smart sensing cards can avoid this issue. The PCIe bus has become the real-time standard for various CPU external buses, and its mature and stable technology is effectively applicable to various hardware platforms.

[0108] Smart Perception Cards utilize independent computing resources to directly retrieve data from the bus using the DMA mechanism via the PCIe protocol. This non-intrusive detection method is also invisible to the operating system. Data collected by DMA can be used to directly restore memory object structures for timely and accurate security detection. Existing attacks often target and manipulate operating system data structures to conceal their presence. Checking based on the OS's provided structures can easily allow attackers to bypass security mechanisms. Smart Perception Card detection eliminates the need for malware to hide. Smart Perception Cards perform security metric detection by analyzing and restoring memory objects, eliminating the need for embedded host code. Traditional data collection methods require hooks into various operating system components to obtain relevant data, which is highly invasive and requires compatibility with various operating system kernel versions to achieve stable results. With thousands of operating system versions, the severe kernel fragmentation significantly limits the applicability of traditional methods. Furthermore, computing the security model requires significant CPU resources on the host, similar to antivirus scanning, significantly slowing the system. Attackers in security incidents often clean up their tracks after an attack, killing processes and deleting logs. Smart perception cards can instantly acquire and analyze memory data. Smart trusted cards are the closest security mechanism to the scene, capable of proactively acquiring physical memory data without interference from malicious programs. Traditional defenses require sending behavior data to a remote cloud-based analysis center. By the time an attack is identified and evidence is collected on the terminal, the malicious process on the local terminal has already been shut down, making it impossible to obtain the current memory state. This capability is only possible with smart perception cards, which provide local, real-time forensic computing.

[0109] Figure 6 This is a schematic structural diagram of a host memory security detection device provided in this embodiment. The host memory security detection device may include: an acquisition unit 610, a first detection unit 620 and a second detection unit 630.

[0110] The acquisition unit 610 is configured to acquire a target detection mode, where the target detection mode is used to indicate a security detection to be performed on the memory data of the host and / or the behavior of the target operating system on the host.

[0111] The first detection unit 620 is configured to obtain memory data by performing memory mapping on the target operating system and perform security detection on the memory data when the target detection mode indicates to perform security detection on the memory data of the host.

[0112] The second detection unit 630 is used to obtain memory data by performing memory mapping on the target operating system when the target detection mode indicates that a security detection is to be performed on the host's memory data and the behavior of the target operating system on the host, obtain behavior data through the system security mechanism on the target operating system, and perform a correlated comprehensive security detection on the memory data and the behavior data.

[0113] In this embodiment, optionally, the first detection unit 620 includes: a first acquisition component, a surveying and mapping component, and a first detection component.

[0114] The first acquisition component is used to acquire and parse a first security detection policy file, where the first security detection policy file is used to instruct to perform periodic security detection on memory data.

[0115] The mapping component is used to obtain memory data by performing memory mapping on the target operating system when it is detected that the conditions for periodic security detection are met.

[0116] The first detection component is used to perform security detection on memory data according to a first security detection policy file.

[0117] In this embodiment, optionally, the second detection unit 630 includes: a second acquisition component, a retrieval component, a third acquisition component and a second detection component.

[0118] The second acquisition component is used to acquire and parse the second security detection strategy file, and determine whether the second security detection strategy file contains a behavior and memory comprehensive measurement strategy.

[0119] The detection component is used to retrieve target behaviors that meet the behavior detection conditions if the second security detection strategy file contains a behavior and memory comprehensive measurement strategy.

[0120] The third acquisition component is used to acquire behavior data related to the target behavior.

[0121] The mapping component is used to obtain memory data by performing memory mapping on the target operating system.

[0122] The second detection component is used to perform associated comprehensive security detection on memory data and behavioral data related to the target behavior.

[0123] In this embodiment, the optional surveying and mapping component is specifically used to:

[0124] Obtain a target analysis file corresponding to the target operating system, wherein the target analysis file includes: address information and data storage structure information, the address information is used to describe the distribution address of the kernel object of the target operating system, and the data storage structure information is used to describe the storage structure and description information of each data object in the kernel object; determine the address and parsing method of the kernel object based on the address information and data storage structure information; parse the kernel object according to the address and parsing method of the kernel object to determine the address of each data object, the storage structure and description information of the data object; establish an index table of the address and storage structure of the data object, and obtain memory data according to the index table.

[0125] In this embodiment, the optional surveying and mapping component is specifically used to:

[0126] Obtain kernel version information of the target operating system; determine a target analysis file corresponding to the kernel version information of the target operating system according to a pre-established mapping relationship, wherein the mapping relationship is used to indicate the correspondence between the kernel version information of the operating system and the analysis file.

[0127] In this embodiment, the optional surveying and mapping component is specifically used to:

[0128] The DMA mechanism of the PCIe bus is used to locate the address of the target identification information in the host memory; based on the address and address information of the target identification information, the address of the key kernel object is relocated; based on the address of the relocated key kernel object and data storage structure information, the addresses of other kernel objects are determined.

[0129] The host memory security detection device provided by the present disclosure can execute the above method embodiments. Its specific implementation principles and technical effects can be found in the above method embodiments, and the present disclosure will not repeat them here.

[0130] The present application also provides a computer device. Figure 7 , Figure 7 This is a basic structural block diagram of the computer device in this embodiment.

[0131] The computer device includes a memory 710 and a processor 720 that are interconnected and communicate with each other via a system bus. It should be noted that the figure only shows a computer device with a memory 710 and a processor 720, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to a microprocessor, an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a digital signal processor (DSP), an embedded device, etc.

[0132] Computer devices can be desktop computers, laptops, PDAs, cloud servers, etc. Computer devices can interact with users through keyboards, mice, remote controls, touchpads, or voice-activated devices.

[0133] The memory 710 includes at least one type of readable storage medium, including non-volatile memory or volatile memory, such as flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic storage, magnetic disk, optical disk, etc. The RAM may include static RAM or dynamic RAM. In some embodiments, the memory 710 may be an internal storage unit of a computer device, such as a hard disk or memory of the computer device. In other embodiments, the memory 710 may also be an external storage device of the computer device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, or a Flash Card equipped on the computer device. Of course, the memory 710 may also include both the internal storage unit of the computer device and its external storage device. In this embodiment, the memory 710 is generally used to store the operating system and various application software installed on the computer device, such as the program code of the above-mentioned method. In addition, the memory 710 may also be used to temporarily store various types of data that have been output or are about to be output.

[0134] The processor 720 is generally used to perform the overall operation of the computer device. In this embodiment, the memory 710 is used to store program code or instructions, which include computer operating instructions. The processor 720 is used to execute the program code or instructions stored in the memory 710 or process data, such as the program code for running the above method.

[0135] In this document, a bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. This bus system can be divided into address buses, data buses, and control buses. For ease of illustration, the figure uses only one thick line, but this does not mean that there is only one bus or only one type of bus.

[0136] Another embodiment of the present application further provides a computer-readable medium, which may be a computer-readable signal medium or a computer-readable medium. A processor in a computer reads the computer-readable program code stored in the computer-readable medium, enabling the processor to execute the functional actions specified in each step or combination of steps in the above method, and to generate a device that implements the functional actions specified in each block or combination of blocks in the block diagram.

[0137] Computer-readable media include but are not limited to electronic, magnetic, optical, electromagnetic, infrared memory or semiconductor systems, devices or apparatuses, or any appropriate combination of the foregoing, the memory is used to store program codes or instructions, the program codes include computer operating instructions, and the processor is used to execute the program codes or instructions of the above-mentioned methods stored in the memory.

[0138] For the definitions of memory and processor, please refer to the description of the aforementioned computer device embodiment and will not be repeated here.

[0139] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0140] Each functional unit or module in each embodiment of the present application may be integrated into a processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The above-mentioned integrated units may be implemented in the form of hardware or software functional units.

[0141] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) or a processor (processor) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program code.

[0142] In the claims, any reference signs placed between brackets shall not be construed as limiting the claims. The word "comprising" described in the present application does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present application can be implemented with the aid of hardware comprising several different elements and with the aid of a suitably programmed computer. In a unit claim that lists several means, several units of these means may be embodied by the same hardware item. The use of first, second, and third etc. does not indicate any order and these words may be interpreted as names. The steps in the above embodiments should not be understood as limiting the order of execution unless otherwise specified.

[0143] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A host memory security detection method, characterized in that: include: Acquire a target detection mode, where the target detection mode is used to instruct to perform security detection on memory data of a host and / or behavior of a target operating system on the host; When the target detection mode indicates to perform security detection on the memory data of the host, obtaining the memory data by performing memory mapping on the target operating system, and performing security detection on the memory data; When the target detection mode indicates that a security check is to be performed on the memory data of the host and the behavior of the target operating system on the host, the memory data is obtained by performing memory mapping on the target operating system, the behavior data is obtained through the system security mechanism on the target operating system, and the memory data and the behavior data are correlated and comprehensively security checked.

2. The method according to claim 1, characterized in that The obtaining of the memory data by performing memory mapping on the target operating system and performing security detection on the memory data includes: Obtaining and parsing a first security detection policy file, where the first security detection policy file is used to instruct to perform periodic security detection on the memory data; When it is detected that the periodic security detection condition is met, the memory data is obtained by performing memory mapping on the target operating system, and a security detection is performed on the memory data according to the first security detection policy file.

3. The method according to claim 1, characterized in that The memory data is obtained by performing memory mapping on the target operating system, the behavior data is obtained through a system security mechanism on the target operating system, and a correlation comprehensive security detection is performed on the memory data and the behavior data, including: Obtaining and parsing a second security detection strategy file, and determining whether the second security detection strategy file includes a behavior and memory comprehensive measurement strategy; If the second security detection strategy file includes a behavior and memory comprehensive measurement strategy, then retrieving a target behavior that meets the behavior detection conditions; Obtaining behavior data related to the target behavior, and obtaining the memory data by performing memory mapping on the target operating system; Performing an associated comprehensive security check on the memory data and the behavior data related to the target behavior.

4. The method according to claim 2 or 3, characterized in that The obtaining of the memory data by performing memory mapping on the target operating system includes: Obtaining a target analysis file corresponding to the target operating system, wherein the target analysis file includes: address information and data storage structure information, the address information being used to describe the distribution address of kernel objects of the target operating system, and the data storage structure information being used to describe the storage structure and description information of each data object in the kernel object; Determining the address and parsing method of the kernel object according to the address information and the data storage structure information; Parsing the kernel object according to the address of the kernel object and the parsing method to determine the address of each data object, the storage structure and description information of the data object; An index table of the address and storage structure of the data object is established, and the memory data is obtained according to the index table.

5. The method according to claim 4, characterized in that The obtaining of a target analysis file corresponding to the target operating system includes: Obtaining kernel version information of the target operating system; According to a pre-established mapping relationship, a target analysis file corresponding to the kernel version information of the target operating system is determined, wherein the mapping relationship is used to indicate a corresponding relationship between the kernel version information of the operating system and the analysis file.

6. The method according to claim 4, characterized in that Determining the address of the kernel object according to the address information and the data storage structure information includes: Utilizing the DMA mechanism of the PCIe bus, locating the address of the target identification information in the host memory; relocating the address of the key kernel object based on the address of the target identification information and the address information; Based on the relocated address of the key kernel object and the data storage structure information, addresses of other kernel objects are determined.

7. A smart perception card, characterized in that: The smart perception card is used to execute the method according to any one of claims 1 to 6, and the smart perception card includes: Policy parsing engine, used to obtain and parse the host memory's security detection mode and security detection policy; a memory analysis engine, configured to perform memory mapping on the target operating system of the host according to the security detection mode and the security detection policy to obtain memory data of the host; A behavior analysis engine, configured to obtain behavior data of the target operating system through a system security mechanism on the target operating system in accordance with the security detection mode and the security detection policy; The policy parsing engine is further configured to perform security detection on the memory data and / or the behavior data according to the security detection policy.

8. A host memory security detection device, characterized in that: include: an acquiring unit, configured to acquire a target detection mode, wherein the target detection mode is used to instruct to perform security detection on memory data of a host and / or behavior of a target operating system on the host; a first detection unit, configured to obtain the memory data by performing memory mapping on the target operating system and perform security detection on the memory data when the target detection mode indicates to perform security detection on the memory data of the host; The second detection unit is used to obtain the memory data by performing memory mapping on the target operating system when the target detection mode indicates that a security detection is to be performed on the memory data of the host and the behavior of the target operating system on the host, obtain the behavior data through the system security mechanism on the target operating system, and perform a correlated comprehensive security detection on the memory data and the behavior data.

9. A computer device, characterized in that: The method comprises a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the host memory security detection method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the host memory security detection method according to any one of claims 1 to 7 is implemented.