Resource-isolated ubiquitous operating system reinforcing method and system

By calculating user operation risk coefficients in the ubiquitous operating system, dynamically classifying processes and isolation of resources, the problem of strengthening standards in the existing technology is solved, and accurate evaluation of user login exceptions and stable classification of processes is achieved to ensure the stability and reliability of the system.

CN120579178AActive Publication Date: 2025-09-02BEIJING JIAOTONG UNIV
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510660670.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-09-02
Estimated Expiration
2045-05-22

AI Technical Summary

Technical Problem

The existing ubiquitous operating system reinforcement methods cannot be dynamically adjusted according to the user's login status, and the reinforcement standards are fixed. It is impossible to accurately evaluate the threat level of the process, and it is impossible to detect abnormal conditions of the process in a timely manner, resulting in insufficient system security.

Method used

By obtaining ubiquitous operating system information and user instruction information, based on lightweight hardware-assisted virtualization technology, users' operation risk coefficients are calculated, dynamic classification processes are dynamically classified, and resource isolation is carried out to build a dynamic execution environment.

Benefits of technology

Accurate evaluation of user login exceptions and stable classification of processes is realized to ensure the stability and reliability of the system and prevent potential threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120579178A_ABST
    Figure CN120579178A_ABST
Patent Text Reader

Abstract

The invention discloses a resource-isolated ubiquitous operating system reinforcement method and system, and relates to the technical field of computer security, and the method comprises the steps: obtaining ubiquitous operating system information, obtaining execution environment information based on a lightweight hardware-assisted virtualization technology according to the ubiquitous operating system information, and obtaining execution environment information based on user instruction information; and obtaining a user operation risk coefficient and user instruction process information. According to the method, the user login abnormity is accurately evaluated through the user operation risk coefficient, a basis is provided for subsequent system reinforcement, the user login condition is analyzed from two dimensions of login time and login position through the user account behavior abnormity coefficient and the user login position abnormity coefficient, the accuracy and reliability of analysis are ensured, and the user login safety is improved. According to the method, the user instruction process information is classified through the user operation risk coefficient, the classification stability is ensured, and the stability and reliability of the system are ensured by performing resource isolation on each type of process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer security technology, and in particular to a resource-isolated ubiquitous operating system reinforcement method and system. Background Art

[0002] With the rapid development of computer and network technology and applications, the computer system security situation is more severe than ever before. Almost every day, we hear about numerous hacking incidents and virus threats. Once a computer system is damaged, it can cause significant economic losses to the user and seriously affect normal work. Strengthening computer system security is a key task in information construction. The Ubiquitous Operating System (UOS) is a new operating system for ubiquitous computing that integrates human, machine, and objects. Its core goal is to shield heterogeneous resources downward and consolidate application commonalities upward, achieving unified management and dynamic scheduling of ubiquitous computing resources. For a ubiquitous operating system, once the system is attacked, it may cause delays in critical control instructions and cause further damage through lateral penetration. Therefore, strengthening the UOS is a crucial step.

[0003] Currently, there is still a problem with the reinforcement of ubiquitous operating systems, which is that they cannot dynamically adjust the system reinforcement according to the user's login status. Often, the system reinforcement is only carried out according to preset fixed standards. For example, different execution environments are set according to the different access targets involved in the process, and the permissions of the process are set according to the access targets. It is impossible to accurately assess the threat level of different processes based on the risk status, unable to timely discover the abnormal status of the process, and unable to accurately divide the processes. Summary of the Invention

[0004] In order to solve the above technical problems, a resource-isolated ubiquitous operating system reinforcement method and system are provided. This technical solution solves the problem raised in the above background technology that the system reinforcement cannot be dynamically adjusted according to the user's login status, and the system reinforcement is often only performed through preset fixed standards. For example, different execution environments are set according to the different access targets involved in the process, and the permissions of the process are set according to the access targets. It is impossible to accurately assess the threat level of different processes according to the risk status, it is impossible to timely discover the abnormal status of the process, and it is impossible to accurately divide the processes.

[0005] In order to achieve the above purpose, the technical solution adopted by the present invention is:

[0006] A resource-isolated ubiquitous operating system hardening method includes:

[0007] Acquire ubiquitous operating system information, wherein the ubiquitous operating system information includes operating system function module information and operating system architecture information;

[0008] According to the ubiquitous operating system information, based on lightweight hardware-assisted virtualization technology, the execution environment information is obtained, where the execution environment includes a secure execution environment and a normal environment;

[0009] Acquiring user instruction information, wherein the user instruction information includes user instruction content information and user behavior environment information;

[0010] According to the user instruction information, obtain the user operation risk factor and user instruction process information;

[0011] Based on the user operation risk coefficient, the user instruction process information is classified and the process classification information is obtained;

[0012] Based on process classification information and resource isolation, obtain the virtual machine corresponding to each type of process;

[0013] According to the execution environment information, obtain the execution environment corresponding to each process in the virtual machine;

[0014] Execute the process according to the execution environment corresponding to each process.

[0015] Preferably, obtaining the user operation risk coefficient according to the user instruction information specifically includes:

[0016] Acquire user behavior environment information according to user instruction information, wherein the user behavior environment information includes user account information;

[0017] Based on the user account information, obtain the account's historical login information, the account's historical login information including the account's historical login time information and the account's historical login location information;

[0018] According to the account's historical login time information, the account's historical login information is sorted based on the timestamp to obtain the account's historical login order information;

[0019] According to the account's historical login location information and account's historical login time information, based on the account's historical login sequence information, obtain the displacement information and time information of the account's historical login information with adjacent timestamps;

[0020] The ratio of the displacement of the historical login information of the account with adjacent timestamps to the time is used as the login position displacement coefficient corresponding to the historical login information of the account with adjacent timestamps;

[0021] Based on the account's historical login sequence information, the average value of the login position displacement coefficient is used as the login behavior difference coefficient, and the maximum and minimum values ​​of the displacement of the account's historical login information are used as the login position difference threshold;

[0022] Based on the user's behavior environment information, obtain the user's login location information and user login time information;

[0023] The user operation risk coefficient is obtained based on the user login location information, user login time information, login location displacement coefficient and login location difference threshold.

[0024] Preferably, obtaining the user operation risk coefficient according to the user login location information, the user login time information, the login location displacement coefficient and the login location difference threshold specifically includes:

[0025] According to the user login time information, based on the account history login information, obtain the account history login information most recent to the user login time information as the account history login feature information;

[0026] Obtain user login interval information and user login displacement information based on account history login feature information, user login location information, and user login time information;

[0027] The product of the user login interval information and the login position displacement coefficient is used as the user login reference displacement;

[0028] Based on the user account information, the user login time information and the account history login feature information are used to obtain user account verification information, wherein the user account verification information indicates account login verification failure information during the time period of the account history login time corresponding to the user login time and the account history login feature information;

[0029] Obtain the user account behavior abnormality coefficient based on the user account verification information;

[0030] Obtaining a user login location anomaly coefficient based on the user login baseline displacement, the user login displacement information, and the login location difference threshold;

[0031] Obtain the user operation risk coefficient based on the user account behavior abnormality coefficient and the user login location abnormality coefficient;

[0032] Among them, if the user login displacement does not exceed the user login reference displacement, the user login position abnormality coefficient is 1;

[0033] If the user login displacement exceeds the user login benchmark displacement and does not exceed the login position difference threshold, the user login position anomaly coefficient is Where d is the user login displacement, d0 is the user login reference displacement, (d2, d1) is the login position difference threshold, β is the displacement difference correction coefficient and β = 0.6;

[0034] If the user login displacement exceeds the login position difference threshold, the user is authenticated based on the user account security verification procedure. If the verification fails, the user login is denied. If the verification succeeds, the user login position anomaly coefficient is (1-β), and the login position displacement coefficient and login position difference threshold are updated based on the user account information.

[0035] Preferably, obtaining the user operation risk coefficient based on the user account behavior abnormality coefficient and the user login location abnormality coefficient specifically includes:

[0036] According to the user account verification information, obtain the number of user account verifications and the verification time information corresponding to each user account verification;

[0037] Obtain user account verification restriction information, wherein the user account verification restriction information includes the user account verification restriction time and the maximum number of user account verifications allowed within the user account verification restriction time;

[0038] Take the user account verification limit time as the time window, and obtain the maximum number of user account verification times within the time window based on the user account verification information;

[0039] Obtaining historical risk information of system accounts, wherein the historical risk information of system accounts includes historical abnormal information of system accounts;

[0040] Obtaining system account historical verification risk information based on system account historical risk information, wherein the system account historical verification risk information indicates system historical accounts that have reached a maximum number of user account verifications within a user account verification limit;

[0041] Based on the historical verification risk information of system accounts, the ratio of the number of historical system accounts that have reached the maximum number of user account verifications within the user account verification limit to the total number of abnormal historical system accounts is used as the verification login correction coefficient;

[0042] Obtain the user account behavior abnormality coefficient based on the verification login correction coefficient and the maximum number of user account verifications within the time window;

[0043] The product of the user account behavior abnormality coefficient and the user login location abnormality coefficient is used as the user operation risk coefficient;

[0044] The user account behavior abnormality coefficient is specifically:

[0045]

[0046] Where k is the user account behavior abnormality coefficient, μ is the verification login correction coefficient, f is the maximum number of user account verifications within the time window, and F is the maximum number of user account verifications allowed within the user account verification limit time.

[0047] Preferably, the step of classifying the user instruction process information based on the user operation risk coefficient and obtaining the process classification information specifically includes:

[0048] According to the user instruction process information, obtain the target access information and target interaction interface information corresponding to each user instruction process;

[0049] Based on the ubiquitous operating system information and the user instruction process information, the maximum amount of access data and the maximum number of interactive interfaces corresponding to each user instruction process are obtained;

[0050] The product of the user operation risk coefficient and the maximum access data volume corresponding to each user instruction process is used as the access data volume threshold corresponding to the user instruction process;

[0051] The product of the user operation risk coefficient and the maximum number of interactive interfaces corresponding to each user instruction process is used as the threshold value of the number of interactive interfaces corresponding to the user instruction process;

[0052] Based on the access data volume threshold and the interactive interface number threshold, the user instruction process information is classified to obtain process classification information;

[0053] If the target access data volume corresponding to the user instruction process exceeds the access data volume threshold or the target interactive interface number exceeds the interactive interface number threshold, the user instruction process is the first process;

[0054] If the target access data volume corresponding to the user instruction process does not exceed the access data volume threshold and the target interactive interface number does not exceed the interactive interface number threshold, then the user instruction process is the second process.

[0055] Preferably, obtaining the execution environment corresponding to each process in the virtual machine according to the execution environment information specifically includes:

[0056] Obtaining first process information and second process information according to the process classification information;

[0057] Based on the process resource requirements, the system resources required for the first process information, i.e., the first system resources, are obtained, and the system resources required for the second process information, i.e., the second system resources, are obtained;

[0058] According to the first system resources and the second system resources, based on the ubiquitous operating system resource isolation, a first virtual machine and a second virtual machine are formed, wherein the first virtual machine is used to execute the first process and the second virtual machine is used to execute the second process;

[0059] According to the first process information, obtaining target access information corresponding to each first process;

[0060] Obtain sensitive data information based on the data security requirements of the ubiquitous operating system;

[0061] Based on the target access information corresponding to each first process, determining whether sensitive data is stored in the target access information corresponding to the first process; if so, treating the first process as a first environment requirement process; if not, treating the first process as a first ordinary process;

[0062] Based on the first virtual machine, according to the execution environment information, assigning a secure execution environment to the first environment-required process and assigning a normal environment to the first normal process;

[0063] Based on the target access information corresponding to each second process, determine whether sensitive data is stored in the target access information corresponding to the second process; if so, treat the second process as a second environment requirement process; if not, treat the second process as a second ordinary process;

[0064] Based on the second virtual machine and according to the execution environment information, a secure execution environment is assigned to the second environment-required process, and a normal environment is assigned to the second normal process.

[0065] Furthermore, a resource-isolated ubiquitous operating system hardening system is proposed to implement the above-mentioned hardening method, including:

[0066] a main control module, the main control module being configured to determine, based on target access information corresponding to each first process, whether sensitive data is stored in the target access information corresponding to the first process; determine, based on the target access information corresponding to each second process, whether sensitive data is stored in the target access information corresponding to the second process; sort historical account login information, obtain historical account login sequence information, obtain user account verification information; classify user instruction process information based on an access data volume threshold and an interactive interface number threshold, obtain process classification information; and obtain an execution environment corresponding to each process in the virtual machine based on the execution environment information;

[0067] An information acquisition module, the information acquisition module is used to obtain ubiquitous operating system information, operating system functional module information, and operating system architecture information; based on the ubiquitous operating system information and based on lightweight hardware-assisted virtualization technology, obtain execution environment information, secure execution environment, and normal environment; obtain user instruction information, user instruction content information, and user behavior environment information; based on user account information, obtain account history login information, account history login time information, and account history login location information;

[0068] A user login assessment module, which is configured to use the ratio of the displacement of the historical login information of the account at adjacent timestamps to the time as the login position displacement coefficient corresponding to the historical login information of the account at the same group of adjacent timestamps, obtain the user login position anomaly coefficient based on the user login baseline displacement, the user login displacement information, and the login position difference threshold, use the ratio of the number of system historical accounts that have reached the maximum number of user account verifications within the user account verification limit time to the total number of abnormal system historical accounts as the verification login correction coefficient, obtain the user account behavior anomaly coefficient based on the verification login correction coefficient and the maximum number of user account verifications within the time window, and use the product of the user account behavior anomaly coefficient and the user login position anomaly coefficient as the user operation risk coefficient;

[0069] The display module interacts with the main control module and is used to output and display execution environment information, user instruction information, process classification information, virtual machines and the execution environment corresponding to each process.

[0070] Optionally, the main control module specifically includes:

[0071] a control unit configured to sort historical account login information, obtain historical account login sequence information, obtain user account verification information, classify user instruction process information based on an access data volume threshold and an interactive interface number threshold, obtain process classification information, and obtain an execution environment corresponding to each process in the virtual machine based on the execution environment information;

[0072] An information receiving unit, which interacts with the information acquisition module and the user login evaluation module to receive data and transmit it to the judgment unit;

[0073] A judgment unit, wherein the judgment unit is used to judge whether sensitive data is stored in the target access information corresponding to each first process based on the target access information corresponding to the first process, and to judge whether sensitive data is stored in the target access information corresponding to the second process based on the target access information corresponding to each second process.

[0074] Optionally, the information acquisition module specifically includes:

[0075] a first acquisition unit, configured to acquire ubiquitous operating system information, operating system functional module information, and operating system architecture information, and acquire execution environment information, a secure execution environment, and a normal environment based on the ubiquitous operating system information and lightweight hardware-assisted virtualization technology;

[0076] The second acquisition unit is used to obtain user instruction information, user instruction content information and user behavior environment information, and based on user account information, obtain account history login information, account history login time information and account history login location information.

[0077] Optionally, the user login evaluation module specifically includes:

[0078] A first evaluation module, configured to use a ratio of a displacement of historical account login information of adjacent timestamps to time as a login position displacement coefficient corresponding to the historical account login information of the group of adjacent timestamps, and to obtain a user login position anomaly coefficient based on a user login baseline displacement, user login displacement information, and a login position difference threshold;

[0079] The second evaluation module is used to use the ratio of the number of system historical accounts that have reached the maximum number of user account verification times within the user account verification limit time to the total number of system historical account anomalies as the verification login correction coefficient, and obtain the user account behavior anomaly coefficient based on the verification login correction coefficient and the maximum number of user account verification times within the time window, and use the product of the user account behavior anomaly coefficient and the user login location anomaly coefficient as the user operation risk coefficient.

[0080] Compared with the prior art, the present invention has the following beneficial effects:

[0081] The present invention proposes a resource-isolated ubiquitous operating system reinforcement method and system, which accurately evaluates user login anomalies through user operation risk coefficients, providing a basis for subsequent system reinforcement. Through the user account behavior anomaly coefficient and the user login location anomaly coefficient, the user login status is analyzed from the two dimensions of login time and login location, ensuring the accuracy and reliability of the analysis. Dynamic classification standards are established through the user operation risk coefficient to classify user instruction process information, ensuring the stability of the classification. By isolating resources for each type of process, the stability and reliability of the system are ensured. BRIEF DESCRIPTION OF THE DRAWINGS

[0082] Figure 1 This is a flow chart of a resource-isolated ubiquitous operating system reinforcement method proposed by the present invention;

[0083] Figure 2 A flowchart for obtaining the user operation risk coefficient in the present invention;

[0084] Figure 3 This is a flow chart for obtaining the abnormal coefficient of the user login location in the present invention;

[0085] Figure 4 This is a flowchart for obtaining the abnormal behavior coefficient of a user account in the present invention;

[0086] Figure 5 This is a structural block diagram of a resource-isolated ubiquitous operating system reinforcement system proposed by the present invention. DETAILED DESCRIPTION

[0087] The following description is intended to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are merely examples, and those skilled in the art may conceive of other obvious variations.

[0088] Reference Figure 1 - Figure 4 As shown, a resource-isolated ubiquitous operating system reinforcement method according to an embodiment of the present invention includes:

[0089] Acquire ubiquitous operating system information, wherein the ubiquitous operating system information includes operating system function module information and operating system architecture information;

[0090] According to the ubiquitous operating system information, based on lightweight hardware-assisted virtualization technology, the execution environment information is obtained, where the execution environment includes a secure execution environment and a normal environment;

[0091] Acquiring user instruction information, wherein the user instruction information includes user instruction content information and user behavior environment information;

[0092] According to the user instruction information, obtain the user operation risk factor and user instruction process information;

[0093] Specifically, based on the user instruction information, the user operation risk coefficient is obtained, including:

[0094] Acquire user behavior environment information according to user instruction information, wherein the user behavior environment information includes user account information;

[0095] Based on the user account information, obtain the account's historical login information, the account's historical login information including the account's historical login time information and the account's historical login location information;

[0096] According to the account's historical login time information, the account's historical login information is sorted based on the timestamp to obtain the account's historical login order information;

[0097] According to the account's historical login location information and account's historical login time information, based on the account's historical login sequence information, obtain the displacement information and time information of the account's historical login information with adjacent timestamps;

[0098] The ratio of the displacement of the historical login information of the account with adjacent timestamps to the time is used as the login position displacement coefficient corresponding to the historical login information of the account with adjacent timestamps;

[0099] Based on the account's historical login sequence information, the average value of the login position displacement coefficient is used as the login behavior difference coefficient, and the maximum and minimum values ​​of the displacement of the account's historical login information are used as the login position difference threshold;

[0100] Based on the user's behavior environment information, obtain the user's login location information and user login time information;

[0101] The user operation risk coefficient is obtained based on the user login location information, user login time information, login location displacement coefficient and login location difference threshold.

[0102] Specifically, the user operation risk coefficient is obtained based on the user login location information, user login time information, login location displacement coefficient, and login location difference threshold, including:

[0103] According to the user login time information, based on the account history login information, obtain the account history login information most recent to the user login time information as the account history login feature information;

[0104] Obtain user login interval information and user login displacement information based on account history login feature information, user login location information, and user login time information;

[0105] The product of the user login interval information and the login position displacement coefficient is used as the user login reference displacement;

[0106] Based on the user account information, the user login time information and the account history login feature information are used to obtain user account verification information, wherein the user account verification information indicates account login verification failure information during the time period of the account history login time corresponding to the user login time and the account history login feature information;

[0107] Obtain the user account behavior abnormality coefficient based on the user account verification information;

[0108] Obtaining a user login location anomaly coefficient based on the user login baseline displacement, the user login displacement information, and the login location difference threshold;

[0109] Obtain the user operation risk coefficient based on the user account behavior abnormality coefficient and the user login location abnormality coefficient;

[0110] Among them, if the user login displacement does not exceed the user login reference displacement, the user login position abnormality coefficient is 1;

[0111] If the user login displacement exceeds the user login benchmark displacement and does not exceed the login position difference threshold, the user login position anomaly coefficient is Where d is the user login displacement, d0 is the user login reference displacement, (d2, d1) is the login position difference threshold, β is the displacement difference correction coefficient and β = 0.6;

[0112] If the user login displacement exceeds the login position difference threshold, the user is authenticated based on the user account security verification procedure. If the verification fails, the user login is denied. If the verification succeeds, the user login position anomaly coefficient is (1-β), and the login position displacement coefficient and login position difference threshold are updated based on the user account information.

[0113] This solution analyzes the time and location of historical account logins, calculates the login location displacement coefficient (displacement / time), and the login location difference threshold (historical displacement extremes), to construct a dynamic baseline for user login behavior. For example, a user's historical logins are concentrated in a specific city, with an average displacement coefficient of 50 km / h (consistent with commuting distance) and a difference threshold of 300 km (crossing city boundaries). If a login displacement reaches 500 km with a two-hour interval (a displacement coefficient of 250 km / h, far exceeding the baseline), the system can quickly identify it as an anomaly. Combining the login interval time multiplied by the displacement coefficient (baseline displacement), the deviation between the actual displacement and the baseline / threshold, and historical verification failure records (behavior anomaly coefficient), a three-dimensional risk assessment system is formed, avoiding misjudgments caused by a single dimension (such as location or time alone). Unlike traditional static blacklists and whitelists, this method continuously learns user behavior patterns (such as weekday vs. weekend login patterns and changes in commonly used devices), allowing the risk assessment model to dynamically evolve with user habits. This approach is particularly suitable for scenarios with diverse user terminals (mobile phones, tablets, IoT devices) in ubiquitous operating systems.

[0114] It is understandable that even in daily work, there are certain differences in the login locations of users at different times, and some abnormal situations will cause the differences in login locations between different login times to become larger. Therefore, it is not possible to directly use a fixed location standard to evaluate the user's login status.

[0115] Specifically, the user operation risk coefficient is obtained based on the user account behavior abnormality coefficient and the user login location abnormality coefficient, including:

[0116] According to the user account verification information, obtain the number of user account verifications and the verification time information corresponding to each user account verification;

[0117] Obtain user account verification restriction information, wherein the user account verification restriction information includes the user account verification restriction time and the maximum number of user account verifications allowed within the user account verification restriction time;

[0118] Take the user account verification limit time as the time window, and obtain the maximum number of user account verification times within the time window based on the user account verification information;

[0119] Obtaining historical risk information of system accounts, wherein the historical risk information of system accounts includes historical abnormal information of system accounts;

[0120] Obtaining system account historical verification risk information based on system account historical risk information, wherein the system account historical verification risk information indicates system historical accounts that have reached a maximum number of user account verifications within a user account verification limit;

[0121] Based on the historical verification risk information of system accounts, the ratio of the number of historical system accounts that have reached the maximum number of user account verifications within the user account verification limit to the total number of abnormal historical system accounts is used as the verification login correction coefficient;

[0122] Obtain the user account behavior abnormality coefficient based on the verification login correction coefficient and the maximum number of user account verifications within the time window;

[0123] The product of the user account behavior abnormality coefficient and the user login location abnormality coefficient is used as the user operation risk coefficient;

[0124] The user account behavior abnormality coefficient is specifically:

[0125]

[0126] Where k is the user account behavior abnormality coefficient, μ is the verification login correction coefficient, f is the maximum number of user account verifications within the time window, and F is the maximum number of user account verifications allowed within the user account verification limit time.

[0127] In this solution, based on the system account historical verification risk information, the ratio of the number of system historical accounts that have reached the maximum number of user account verification times within the user account verification limit time to the total number of system historical account anomalies is used as the verification login correction coefficient. According to the verification login correction coefficient and the maximum number of user account verification times within the time window, the user account behavior anomaly coefficient is obtained. The product of the user account behavior anomaly coefficient and the user login location anomaly coefficient is used as the user operation risk coefficient. Through the verification login correction coefficient μ, the system-level historical risk is converted into a personalized assessment factor for the current account, solving the problem of "disconnection between general rules and specific scenarios" and ensuring the stability and accuracy of user login status assessment.

[0128] It is understandable that traditional methods (such as determining an anomaly when the number of verifications exceeds a threshold) do not take into account the risk differences between different system account types, and cannot accurately identify the abnormal conditions of system accounts that have been verified multiple times but the verification time interval does not exceed the threshold. Therefore, the abnormal account verification status is analyzed by the maximum number of user account verifications within the time window, and the impact of verification anomalies on account security is accurately evaluated by verifying the login correction coefficient.

[0129] Based on the user operation risk coefficient, the user instruction process information is classified and the process classification information is obtained;

[0130] Specifically, based on the user operation risk factor, the user instruction process information is classified to obtain process classification information, including:

[0131] According to the user instruction process information, obtain the target access information and target interaction interface information corresponding to each user instruction process;

[0132] Based on the ubiquitous operating system information and the user instruction process information, the maximum amount of access data and the maximum number of interactive interfaces corresponding to each user instruction process are obtained;

[0133] The product of the user operation risk coefficient and the maximum access data volume corresponding to each user instruction process is used as the access data volume threshold corresponding to the user instruction process;

[0134] The product of the user operation risk coefficient and the maximum number of interactive interfaces corresponding to each user instruction process is used as the threshold value of the number of interactive interfaces corresponding to the user instruction process;

[0135] Based on the access data volume threshold and the interactive interface number threshold, the user instruction process information is classified to obtain process classification information;

[0136] If the target access data volume corresponding to the user instruction process exceeds the access data volume threshold or the target interactive interface number exceeds the interactive interface number threshold, the user instruction process is the first process;

[0137] If the target access data volume corresponding to the user instruction process does not exceed the access data volume threshold and the target interactive interface number does not exceed the interactive interface number threshold, then the user instruction process is the second process.

[0138] In this solution, a dynamic threshold is formed by multiplying the user operation risk coefficient with the maximum amount of data accessed by the process and the maximum number of interactive interfaces (e.g., when the risk coefficient is 0.2, the access data volume threshold = maximum data volume × 0.2). The process access data volume threshold for high-risk users (e.g., remote login + multiple verification failures) is significantly lowered. For example, ordinary users are allowed to access 10MB of data, while high-risk users are only allowed 2MB. This effectively curbs malicious processes from stealing sensitive information through large-scale data transmission. The risk coefficient directly affects the resource access boundary of the process, avoiding the drawbacks of traditional static policies. For example, normal large-scale data transmission (such as file backup) for low-risk users is not restricted, while similar operations for high-risk users will be blocked in advance, realizing dynamic binding of risks and permissions.

[0139] Based on process classification information and resource isolation, obtain the virtual machine corresponding to each type of process;

[0140] According to the execution environment information, obtain the execution environment corresponding to each process in the virtual machine;

[0141] Specifically, according to the execution environment information, the execution environment corresponding to each process in the virtual machine is obtained, which specifically includes:

[0142] Obtaining first process information and second process information according to the process classification information;

[0143] Based on the process resource requirements, the system resources required for the first process information, i.e., the first system resources, are obtained, and the system resources required for the second process information, i.e., the second system resources, are obtained;

[0144] According to the first system resources and the second system resources, based on the ubiquitous operating system resource isolation, a first virtual machine and a second virtual machine are formed, wherein the first virtual machine is used to execute the first process and the second virtual machine is used to execute the second process;

[0145] According to the first process information, obtaining target access information corresponding to each first process;

[0146] Obtain sensitive data information based on the data security requirements of the ubiquitous operating system;

[0147] Based on the target access information corresponding to each first process, determining whether sensitive data is stored in the target access information corresponding to the first process; if so, treating the first process as a first environment requirement process; if not, treating the first process as a first ordinary process;

[0148] Based on the first virtual machine, according to the execution environment information, assigning a secure execution environment to the first environment-required process and assigning a normal environment to the first normal process;

[0149] Based on the target access information corresponding to each second process, determine whether sensitive data is stored in the target access information corresponding to the second process; if so, treat the second process as a second environment requirement process; if not, treat the second process as a second ordinary process;

[0150] Based on the second virtual machine and according to the execution environment information, a secure execution environment is assigned to the second environment-required process, and a normal environment is assigned to the second normal process.

[0151] In this solution, the first system resources and the second system resources are obtained based on the process resource requirements through the first process information and the second process information, and the first virtual machine and the second virtual machine are formed based on the ubiquitous operating system resource isolation. Based on the target access information and sensitive data information corresponding to each first process, the first process is divided into a first environment requirement process and a first ordinary process. Based on the target access information and sensitive data information corresponding to each second process, the second process is divided into a second environment requirement process and a second ordinary process, and different execution environments are determined to ensure the stability and reliability of the system and achieve system reinforcement.

[0152] It is understandable that, for the first process and the second process, the abnormal conditions of the first process are far greater than those of the second process. Therefore, two independent virtual machines are constructed to independently execute the two types of processes. For the first process, in this embodiment, the access data volume threshold corresponding to each first environment requirement process is used to limit the process access data volume, and the interaction interface threshold corresponding to each first environment requirement process is used to limit the interaction interface. At the same time, the product of the maximum standard interaction frequency between the first environment requirement process and each interaction interface and the user operation risk coefficient is used as the interaction frequency threshold;

[0153] For the first common process, if only the target access data volume corresponding to the first common process exceeds the access data volume threshold, the product of the maximum standard interaction frequency between the first common process and each interaction interface and the user operation risk coefficient is used as the interaction frequency threshold, and the interaction frequency is limited based on the interaction frequency threshold;

[0154] If the number of target interactive interfaces corresponding to the first common process exceeds the interactive interface number threshold, the number of interactive interfaces is limited according to the interactive interface number threshold;

[0155] If the target access data volume corresponding to the first common process exceeds the access data volume threshold and the target interactive interface number exceeds the interactive interface number threshold, the interactive frequency is limited by the interactive frequency threshold and the interactive interface number threshold is used to limit the interactive interface number;

[0156] For the second environment requirement process, the product of the maximum standard interaction frequency between the second environment requirement process and each interaction interface and the user operation risk coefficient is used as the interaction frequency threshold. The interaction frequency is limited by the interaction frequency threshold, while no limit is imposed on the second ordinary process.

[0157] Execute the process according to the execution environment corresponding to each process.

[0158] Reference Figure 5 As shown, further, in combination with the above-mentioned resource-isolated ubiquitous operating system reinforcement method, a resource-isolated ubiquitous operating system reinforcement system is proposed, including:

[0159] a main control module, the main control module being configured to determine, based on target access information corresponding to each first process, whether sensitive data is stored in the target access information corresponding to the first process; determine, based on the target access information corresponding to each second process, whether sensitive data is stored in the target access information corresponding to the second process; sort historical account login information, obtain historical account login sequence information, obtain user account verification information; classify user instruction process information based on an access data volume threshold and an interactive interface number threshold, obtain process classification information; and obtain an execution environment corresponding to each process in the virtual machine based on the execution environment information;

[0160] An information acquisition module, the information acquisition module is used to obtain ubiquitous operating system information, operating system functional module information, and operating system architecture information; based on the ubiquitous operating system information and based on lightweight hardware-assisted virtualization technology, obtain execution environment information, secure execution environment, and normal environment; obtain user instruction information, user instruction content information, and user behavior environment information; based on user account information, obtain account history login information, account history login time information, and account history login location information;

[0161] A user login assessment module, which is configured to use the ratio of the displacement of the historical login information of the account at adjacent timestamps to the time as the login position displacement coefficient corresponding to the historical login information of the account at the same group of adjacent timestamps, obtain the user login position anomaly coefficient based on the user login baseline displacement, the user login displacement information, and the login position difference threshold, use the ratio of the number of system historical accounts that have reached the maximum number of user account verifications within the user account verification limit time to the total number of abnormal system historical accounts as the verification login correction coefficient, obtain the user account behavior anomaly coefficient based on the verification login correction coefficient and the maximum number of user account verifications within the time window, and use the product of the user account behavior anomaly coefficient and the user login position anomaly coefficient as the user operation risk coefficient;

[0162] The display module interacts with the main control module and is used to output and display execution environment information, user instruction information, process classification information, virtual machines and the execution environment corresponding to each process.

[0163] Main control module, specifically including:

[0164] a control unit configured to sort historical account login information, obtain historical account login sequence information, obtain user account verification information, classify user instruction process information based on an access data volume threshold and an interactive interface number threshold, obtain process classification information, and obtain an execution environment corresponding to each process in the virtual machine based on the execution environment information;

[0165] An information receiving unit, which interacts with the information acquisition module and the user login evaluation module to receive data and transmit it to the judgment unit;

[0166] A judgment unit, wherein the judgment unit is used to judge whether sensitive data is stored in the target access information corresponding to each first process based on the target access information corresponding to the first process, and to judge whether sensitive data is stored in the target access information corresponding to the second process based on the target access information corresponding to each second process.

[0167] Information acquisition module, specifically including:

[0168] a first acquisition unit, configured to acquire ubiquitous operating system information, operating system functional module information, and operating system architecture information, and acquire execution environment information, a secure execution environment, and a normal environment based on the ubiquitous operating system information and lightweight hardware-assisted virtualization technology;

[0169] The second acquisition unit is used to obtain user instruction information, user instruction content information and user behavior environment information, and based on user account information, obtain account history login information, account history login time information and account history login location information.

[0170] User login assessment module, including:

[0171] A first evaluation module, configured to use a ratio of a displacement of historical account login information of adjacent timestamps to time as a login position displacement coefficient corresponding to the historical account login information of the group of adjacent timestamps, and to obtain a user login position anomaly coefficient based on a user login baseline displacement, user login displacement information, and a login position difference threshold;

[0172] The second evaluation module is used to use the ratio of the number of system historical accounts that have reached the maximum number of user account verification times within the user account verification limit time to the total number of system historical account anomalies as the verification login correction coefficient, and obtain the user account behavior anomaly coefficient based on the verification login correction coefficient and the maximum number of user account verification times within the time window, and use the product of the user account behavior anomaly coefficient and the user login location anomaly coefficient as the user operation risk coefficient.

[0173] To sum up, the advantages of the present invention are: obtaining the user operation risk coefficient through user login location information, user login time information, login location displacement coefficient and login location difference threshold, accurately evaluating user login anomalies through the user operation risk coefficient, providing a basis for subsequent system reinforcement, obtaining the user account behavior anomaly coefficient through user account verification information, obtaining the user login location anomaly coefficient through user login benchmark displacement, user login displacement information and login location difference threshold, analyzing the user login status from two dimensions of login time and login location through the user account behavior anomaly coefficient and the user login location anomaly coefficient, ensuring the accuracy and reliability of the analysis, establishing a dynamic classification standard through the user operation risk coefficient, classifying user instruction process information, ensuring the stability of the classification, and ensuring the stability and reliability of the system by isolating resources for each type of process.

[0174] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions merely illustrate the principles of the present invention. Various changes and modifications may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and modifications are intended to fall within the scope of the present invention. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.

Claims

1. A resource-isolated ubiquitous operating system reinforcement method, characterized in that: include: Acquire ubiquitous operating system information, wherein the ubiquitous operating system information includes operating system function module information and operating system architecture information; According to the ubiquitous operating system information, based on lightweight hardware-assisted virtualization technology, the execution environment information is obtained, where the execution environment includes a secure execution environment and a normal environment; Acquiring user instruction information, wherein the user instruction information includes user instruction content information and user behavior environment information; According to the user instruction information, obtain the user operation risk factor and user instruction process information; Based on the user operation risk coefficient, the user instruction process information is classified and the process classification information is obtained; Based on process classification information and resource isolation, obtain the virtual machine corresponding to each type of process; According to the execution environment information, obtain the execution environment corresponding to each process in the virtual machine; Execute the process according to the execution environment corresponding to each process.

2. The resource-isolated ubiquitous operating system reinforcement method according to claim 1, characterized in that: The step of obtaining the user operation risk coefficient according to the user instruction information specifically includes: Acquire user behavior environment information according to user instruction information, wherein the user behavior environment information includes user account information; Based on the user account information, obtain the account's historical login information, the account's historical login information including the account's historical login time information and the account's historical login location information; According to the account's historical login time information, the account's historical login information is sorted based on the timestamp to obtain the account's historical login order information; According to the account's historical login location information and account's historical login time information, based on the account's historical login sequence information, obtain the displacement information and time information of the account's historical login information with adjacent timestamps; The ratio of the displacement of the historical login information of the account with adjacent timestamps to the time is used as the login position displacement coefficient corresponding to the historical login information of the account with adjacent timestamps; Based on the account's historical login sequence information, the average value of the login position displacement coefficient is used as the login behavior difference coefficient, and the maximum and minimum values ​​of the displacement of the account's historical login information are used as the login position difference threshold; Based on the user's behavior environment information, obtain the user's login location information and user login time information; The user operation risk coefficient is obtained based on the user login location information, user login time information, login location displacement coefficient and login location difference threshold.

3. The resource-isolated ubiquitous operating system reinforcement method according to claim 2, characterized in that: The step of obtaining the user operation risk coefficient based on the user login location information, the user login time information, the login location displacement coefficient, and the login location difference threshold specifically includes: According to the user login time information, based on the account history login information, obtain the account history login information most recent to the user login time information as the account history login feature information; Obtain user login interval information and user login displacement information based on account history login feature information, user login location information, and user login time information; The product of the user login interval information and the login position displacement coefficient is used as the user login reference displacement; Based on the user account information, the user login time information and the account history login feature information are used to obtain user account verification information, wherein the user account verification information indicates account login verification failure information during the time period of the account history login time corresponding to the user login time and the account history login feature information; Obtain the user account behavior abnormality coefficient based on the user account verification information; Obtaining a user login location anomaly coefficient based on the user login baseline displacement, the user login displacement information, and the login location difference threshold; Obtain the user operation risk coefficient based on the user account behavior abnormality coefficient and the user login location abnormality coefficient; Among them, if the user login displacement does not exceed the user login reference displacement, the user login position abnormality coefficient is 1; If the user login displacement exceeds the user login benchmark displacement and does not exceed the login position difference threshold, the user login position anomaly coefficient is Where d is the user login displacement, d0 is the user login reference displacement, (d2, d1) is the login position difference threshold, β is the displacement difference correction coefficient and β = 0.6; If the user login displacement exceeds the login position difference threshold, the user is authenticated based on the user account security verification procedure. If the verification fails, the user login is denied. If the verification succeeds, the user login position anomaly coefficient is (1-β), and the login position displacement coefficient and login position difference threshold are updated based on the user account information.

4. The resource-isolated ubiquitous operating system reinforcement method according to claim 3, characterized in that: The user operation risk coefficient is obtained based on the user account behavior abnormality coefficient and the user login location abnormality coefficient, specifically including: According to the user account verification information, obtain the number of user account verifications and the verification time information corresponding to each user account verification; Obtain user account verification restriction information, wherein the user account verification restriction information includes the user account verification restriction time and the maximum number of user account verifications allowed within the user account verification restriction time; Take the user account verification limit time as the time window, and obtain the maximum number of user account verification times within the time window based on the user account verification information; Obtaining historical risk information of system accounts, wherein the historical risk information of system accounts includes abnormal information of historical system accounts; Obtaining system account historical verification risk information based on system account historical risk information, wherein the system account historical verification risk information indicates system historical accounts that have reached a maximum number of user account verifications within a user account verification limit; Based on the historical verification risk information of system accounts, the ratio of the number of historical system accounts that have reached the maximum number of user account verifications within the user account verification limit to the total number of abnormal historical system accounts is used as the verification login correction coefficient; Obtain the user account behavior abnormality coefficient based on the verification login correction coefficient and the maximum number of user account verifications within the time window; The product of the user account behavior abnormality coefficient and the user login location abnormality coefficient is used as the user operation risk coefficient; The user account behavior abnormality coefficient is specifically: Where k is the user account behavior abnormality coefficient, μ is the verification login correction coefficient, f is the maximum number of user account verifications within the time window, and F is the maximum number of user account verifications allowed within the user account verification limit time.

5. The resource-isolated ubiquitous operating system reinforcement method according to claim 4, characterized in that: The process of classifying the user instruction process information based on the user operation risk coefficient and obtaining the process classification information specifically includes: According to the user instruction process information, obtain the target access information and target interaction interface information corresponding to each user instruction process; Based on the ubiquitous operating system information and the user instruction process information, the maximum amount of access data and the maximum number of interactive interfaces corresponding to each user instruction process are obtained; The product of the user operation risk coefficient and the maximum access data volume corresponding to each user instruction process is used as the access data volume threshold corresponding to the user instruction process; The product of the user operation risk coefficient and the maximum number of interactive interfaces corresponding to each user instruction process is used as the threshold value of the number of interactive interfaces corresponding to the user instruction process; Based on the access data volume threshold and the interactive interface number threshold, the user instruction process information is classified to obtain process classification information; If the target access data volume corresponding to the user instruction process exceeds the access data volume threshold or the target interactive interface number exceeds the interactive interface number threshold, the user instruction process is the first process; If the target access data volume corresponding to the user instruction process does not exceed the access data volume threshold and the target interactive interface number does not exceed the interactive interface number threshold, then the user instruction process is the second process.

6. The resource-isolated ubiquitous operating system reinforcement method according to claim 1, characterized in that: The step of obtaining the execution environment corresponding to each process in the virtual machine according to the execution environment information specifically includes: Obtaining first process information and second process information according to the process classification information; Based on the process resource requirements, the system resources required for the first process information, i.e., the first system resources, are obtained, and the system resources required for the second process information, i.e., the second system resources, are obtained; According to the first system resources and the second system resources, based on the ubiquitous operating system resource isolation, a first virtual machine and a second virtual machine are formed, wherein the first virtual machine is used to execute the first process and the second virtual machine is used to execute the second process; According to the first process information, obtaining target access information corresponding to each first process; Obtain sensitive data information based on the data security requirements of the ubiquitous operating system; Based on the target access information corresponding to each first process, determining whether sensitive data is stored in the target access information corresponding to the first process; if so, treating the first process as a first environment requirement process; if not, treating the first process as a first ordinary process; Based on the first virtual machine, according to the execution environment information, assigning a secure execution environment to the first environment-required process and assigning a normal environment to the first normal process; Based on the target access information corresponding to each second process, determine whether sensitive data is stored in the target access information corresponding to the second process; if so, treat the second process as a second environment requirement process; if not, treat the second process as a second ordinary process; Based on the second virtual machine and according to the execution environment information, a secure execution environment is assigned to the second environment-required process, and a normal environment is assigned to the second normal process.

7. A resource-isolated ubiquitous operating system reinforcement system, used to implement the reinforcement method according to any one of claims 1 to 6, characterized in that: include: a main control module, the main control module being configured to determine, based on target access information corresponding to each first process, whether sensitive data is stored in the target access information corresponding to the first process; determine, based on the target access information corresponding to each second process, whether sensitive data is stored in the target access information corresponding to the second process; sort historical account login information, obtain historical account login sequence information, obtain user account verification information; classify user instruction process information based on an access data volume threshold and an interactive interface number threshold, obtain process classification information; and obtain an execution environment corresponding to each process in the virtual machine based on the execution environment information; An information acquisition module, the information acquisition module is used to obtain ubiquitous operating system information, operating system functional module information, and operating system architecture information; based on the ubiquitous operating system information and based on lightweight hardware-assisted virtualization technology, obtain execution environment information, secure execution environment, and normal environment; obtain user instruction information, user instruction content information, and user behavior environment information; based on user account information, obtain account history login information, account history login time information, and account history login location information; A user login assessment module, which is configured to use the ratio of the displacement of the historical login information of the account at adjacent timestamps to the time as the login position displacement coefficient corresponding to the historical login information of the account at the same group of adjacent timestamps, obtain the user login position anomaly coefficient based on the user login baseline displacement, the user login displacement information, and the login position difference threshold, use the ratio of the number of system historical accounts that have reached the maximum number of user account verifications within the user account verification limit time to the total number of abnormal system historical accounts as the verification login correction coefficient, obtain the user account behavior anomaly coefficient based on the verification login correction coefficient and the maximum number of user account verifications within the time window, and use the product of the user account behavior anomaly coefficient and the user login position anomaly coefficient as the user operation risk coefficient; The display module interacts with the main control module and is used to output and display execution environment information, user instruction information, process classification information, virtual machines and the execution environment corresponding to each process.

8. The resource-isolated ubiquitous operating system reinforcement system according to claim 7, characterized in that: The main control module specifically includes: a control unit configured to sort historical account login information, obtain historical account login sequence information, obtain user account verification information, classify user instruction process information based on an access data volume threshold and an interactive interface number threshold, obtain process classification information, and obtain an execution environment corresponding to each process in the virtual machine based on the execution environment information; An information receiving unit, which interacts with the information acquisition module and the user login evaluation module to receive data and transmit it to the judgment unit; A judgment unit, wherein the judgment unit is used to judge whether sensitive data is stored in the target access information corresponding to each first process based on the target access information corresponding to the first process, and to judge whether sensitive data is stored in the target access information corresponding to the second process based on the target access information corresponding to each second process.

9. The resource-isolated ubiquitous operating system reinforcement system according to claim 7, characterized in that: The information acquisition module specifically includes: a first acquisition unit, configured to acquire ubiquitous operating system information, operating system functional module information, and operating system architecture information, and acquire execution environment information, a secure execution environment, and a normal environment based on the ubiquitous operating system information and lightweight hardware-assisted virtualization technology; The second acquisition unit is used to obtain user instruction information, user instruction content information and user behavior environment information, and based on user account information, obtain account history login information, account history login time information and account history login location information.

10. The resource-isolated ubiquitous operating system reinforcement system according to claim 7, characterized in that: The user login evaluation module specifically includes: A first evaluation module, configured to use a ratio of a displacement of historical account login information of adjacent timestamps to time as a login position displacement coefficient corresponding to the historical account login information of the group of adjacent timestamps, and to obtain a user login position anomaly coefficient based on a user login baseline displacement, user login displacement information, and a login position difference threshold; The second evaluation module is used to use the ratio of the number of system historical accounts that have reached the maximum number of user account verification times within the user account verification limit time to the total number of system historical account anomalies as the verification login correction coefficient, and obtain the user account behavior anomaly coefficient based on the verification login correction coefficient and the maximum number of user account verification times within the time window, and use the product of the user account behavior anomaly coefficient and the user login location anomaly coefficient as the user operation risk coefficient.

Citation Information

Patent Citations

  • Virtual machine security isolation system and method oriented to multi-security-level virtual desktop system

    CN103902885A

  • Method and device for concurrent login of same account, computer equipment and storage medium

    CN119051898A

  • Container engine of computing node and container arrangement method

    CN119806728A

  • Methods And Apparatus Supporting Access To Physical And Virtual Trusted Platform Modules

    US20090165117A1

  • Login performance

    US20170264708A1