A resource-isolated ubiquitous operating system hardening method and system
By acquiring ubiquitous operating system information and user command information, dynamically classifying processes and isolating resources, the shortcomings of existing ubiquitous operating system hardening methods are addressed, enabling accurate assessment of user login anomalies and improving system stability and reliability.
Patent Information
- Application Number
- CN202510660670.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2045-05-22
AI Technical Summary
Existing ubiquitous operating system hardening methods cannot dynamically adjust system hardening based on user login status, cannot accurately assess the threat level of processes, and cannot detect abnormal processes in a timely manner, resulting in insufficient system security.
By acquiring ubiquitous operating system information and user command information, and based on lightweight hardware-assisted virtualization technology, the system obtains the execution environment and user operation risk coefficients, dynamically classifies processes and isolates resources, and constructs dynamic classification standards to ensure the accuracy and stability of system hardening.
It enables accurate assessment of abnormal user logins, ensuring the stability and reliability of system hardening, and classifies processes based on user operation risk coefficients to ensure system security and reliability.
Smart Images

Figure CN120579178B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer security technology, specifically to a method and system for hardening a ubiquitous operating system with resource isolation. Background Technology
[0002] With the rapid development of computer and network technologies and applications, the security situation of computer systems is more severe than ever before. We hear about numerous hacker incidents and virus threats almost daily. Once a computer system is compromised, it can cause significant economic losses to the user organization and severely disrupt normal operations. Therefore, strengthening computer system security is a crucial aspect of information technology development. Ubiquitous Operating Systems (UOS) are a new type of operating system designed for ubiquitous computing that integrates humans, machines, and things. Their core objective is to shield heterogeneous resources downwards and aggregate common application features upwards, achieving unified management and dynamic scheduling of ubiquitous computing resources. For UOS, attacks can lead to delays in critical control instructions and further damage through lateral movement. Therefore, hardening UOS is a critical step.
[0003] Currently, the hardening of ubiquitous operating systems still suffers from the inability to dynamically adjust system hardening based on user login status. It often relies on preset fixed standards for system hardening. For example, different execution environments are set according to the different access targets involved in the process, and permissions for the process are set according to the access targets. It is impossible to accurately assess the threat level of different processes based on the risk situation, to detect abnormal processes in a timely manner, or to accurately classify processes. Summary of the Invention
[0004] To address the aforementioned technical problems, this paper provides a method and system for hardening a ubiquitous operating system with resource isolation. This technical solution solves the problems mentioned in the background art, such as the inability to dynamically adjust system hardening based on user login status, the tendency to harden the system simply by using preset fixed standards, such as setting different execution environments based on different access targets of processes, setting process permissions based on access targets, the inability to accurately assess the threat level of different processes based on risk conditions, the inability to detect abnormal processes in a timely manner, and the inability to accurately classify processes.
[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:
[0006] A method for hardening a ubiquitous operating system with resource isolation includes:
[0007] Obtain ubiquitous operating system information, which includes operating system functional module information and operating system architecture information;
[0008] Based on ubiquitous operating system information and lightweight hardware-assisted virtualization technology, execution environment information is obtained, including a secure execution environment and a normal environment.
[0009] Acquire user instruction information, which includes user instruction content information and user behavior environment information;
[0010] Based on user instruction information, obtain the user operation risk coefficient and user instruction process information;
[0011] Based on the user operation risk coefficient, the user command process information is classified to obtain process classification information;
[0012] Based on process classification information and resource isolation, obtain the virtual machine corresponding to each type of process;
[0013] Based on the execution environment information, obtain the execution environment corresponding to each process in the virtual machine;
[0014] The processes are executed according to their respective execution environments.
[0015] Preferably, obtaining the user operation risk coefficient based on user instruction information specifically includes:
[0016] Based on user instruction information, obtain user behavior environment information, which includes user account information;
[0017] Based on user account information, obtain account historical login information, which includes account historical login time information and account historical login location information;
[0018] Based on the account's historical login time information, the account's historical login information is sorted according to the timestamp to obtain the account's historical login order information;
[0019] Based on the account's historical login location information and account's historical login time information, and based on the account's historical login order information, obtain the displacement information and time information of the account's historical login information with adjacent timestamps;
[0020] The ratio of the displacement to the time of the historical login information of accounts with adjacent timestamps is used as the displacement coefficient of the login position corresponding to the historical login information of accounts with adjacent timestamps.
[0021] Based on the account's historical login sequence information, the average value of the login location displacement coefficient is used as the login behavior difference coefficient, and the maximum and minimum values of the displacement of the account's historical login information are used as the login location difference threshold.
[0022] Based on user behavior environment information, obtain user login location information and user login time information;
[0023] The user operation risk coefficient is obtained based on the user login location information, user login time information, login location displacement coefficient, and login location difference threshold.
[0024] Preferably, obtaining the user operation risk coefficient based on user login location information, user login time information, login location displacement coefficient, and login location difference threshold specifically includes:
[0025] Based on the user's login time information and the account's historical login information, the account's historical login information most recently associated with the user's login time information is obtained as the account's historical login feature information.
[0026] Based on account historical login characteristics, user login location information, and user login time information, obtain user login interval time information and user login displacement information;
[0027] The product of the user login interval time information and the login position displacement coefficient is used as the user login reference displacement;
[0028] Based on user account information, user account verification information is obtained based on user login time information and account historical login feature information. The user account verification information represents account login verification failure information during the time period corresponding to the account historical login time of the user login time and account historical login feature information.
[0029] Based on the user account verification information, obtain the user account behavior anomaly coefficient;
[0030] The abnormal coefficient of user login location is obtained based on the user login baseline displacement, user login displacement information, and login location difference threshold.
[0031] The user operation risk coefficient is obtained based on the user account behavior anomaly coefficient and the user login location anomaly coefficient.
[0032] If the user login displacement does not exceed the user login baseline displacement, the user login position anomaly coefficient is 1.
[0033] If the user login displacement exceeds the user login baseline displacement but does not exceed the login location difference threshold, then the user login location anomaly coefficient is: Where d is the user login displacement, d0 is the user login baseline displacement, (d2, d1) is the login position difference threshold, and β is the displacement difference correction coefficient with β = 0.6;
[0034] If a user's login displacement exceeds the login location difference threshold, the user's identity is verified based on the user account security verification procedure. If the verification fails, the user's login is rejected. If the verification is successful, the user's login location anomaly coefficient is (1-β), and the login location displacement coefficient and login location difference threshold are updated according to the user's account information.
[0035] Preferably, obtaining the user operation risk coefficient based on the user account behavior anomaly coefficient and the user login location anomaly coefficient specifically includes:
[0036] Based on the user account verification information, obtain the number of times the user account has been verified and the verification time for each user account verification.
[0037] Obtain user account verification restriction information, which includes the user account verification restriction time and the maximum number of user account verifications allowed within the user account verification restriction time.
[0038] Using the user account verification restriction time as a time window, obtain the maximum number of user account verifications within the time window based on the user account verification information;
[0039] Obtain historical risk information of system accounts, including historical abnormal information of system accounts;
[0040] Based on the historical risk information of system accounts, obtain the historical verification risk information of system accounts. The historical verification risk information of system accounts refers to the system accounts that have reached the maximum number of user account verifications within the user account verification restriction period.
[0041] Based on the historical verification risk information of system accounts, the ratio of the number of historical system accounts that reached the maximum number of verification attempts within the user account verification restriction period to the total number of abnormal historical system accounts is used as the verification login correction coefficient.
[0042] The abnormal user account behavior coefficient is obtained based on the login verification correction coefficient and the maximum number of user account verifications within the time window.
[0043] The product of the abnormal coefficient of user account behavior and the abnormal coefficient of user login location is used as the user operation risk coefficient.
[0044] Specifically, the user account behavior anomaly coefficient is as follows:
[0045]
[0046] In the formula, k is the abnormal user account behavior coefficient, μ is the login verification correction coefficient, f is the maximum number of user account verifications within the time window, and F is the maximum number of user account verifications allowed within the user account verification restriction time.
[0047] Preferably, the step of classifying user instruction process information based on user operation risk coefficient to obtain process classification information specifically includes:
[0048] Based on the user command process information, obtain the target access information and target interaction interface information corresponding to each user command process;
[0049] Based on ubiquitous operating system information and user instruction process information, the maximum amount of data accessed and the maximum number of interaction interfaces corresponding to each user instruction process are obtained.
[0050] The product of the user operation risk coefficient and the maximum amount of data accessed for each user instruction process is used as the threshold for the amount of data accessed for that user instruction process.
[0051] The product of the user operation risk coefficient and the maximum number of interaction interfaces corresponding to each user command process is used as the threshold for the number of interaction interfaces corresponding to that user command process.
[0052] Based on the access data volume threshold and the interaction interface number threshold, user command process information is classified to obtain process classification information;
[0053] If the target access data volume corresponding to the user instruction process exceeds the access data volume threshold or the target interaction interface number exceeds the interaction interface number threshold, then the user instruction process is the first process.
[0054] If the target access data volume corresponding to the user instruction process does not exceed the access data volume threshold and the target interaction interface number does not exceed the interaction interface number threshold, then the user instruction process is the second process.
[0055] Preferably, obtaining the execution environment corresponding to each process in the virtual machine based on the execution environment information specifically includes:
[0056] Based on the process classification information, obtain the information of the first process and the second process.
[0057] Based on process resource requirements, the system resources required to obtain the first process information are called the first system resources, and the system resources required to obtain the second process information are called the second system resources.
[0058] Based on the resources of the first system and the second system, and using ubiquitous operating system resource isolation, a first virtual machine and a second virtual machine are formed. The first virtual machine is used to execute the first process, and the second virtual machine is used to execute the second process.
[0059] Based on the first process information, obtain the target access information corresponding to each first process;
[0060] To obtain sensitive data information based on the data security requirements of ubiquitous operating systems;
[0061] Based on the target access information corresponding to each first process, determine whether sensitive data is stored in the target access information corresponding to the first process. If so, the first process is regarded as the first environment requirement process; otherwise, the first process is regarded as the first ordinary process.
[0062] Based on the first virtual machine, according to the execution environment information, a secure execution environment is assigned to the first environment-required process, and a normal environment is assigned to the first ordinary process;
[0063] Based on the target access information corresponding to each second process, determine whether sensitive data is stored in the target access information corresponding to the second process. If so, the second process is used as the second environment requirement process; otherwise, the second process is used as the second ordinary process.
[0064] Based on the second virtual machine, and according to the execution environment information, a secure execution environment is assigned to the second environment-required process, and a normal environment is assigned to the second ordinary process.
[0065] Furthermore, a resource-isolated ubiquitous operating system hardening system is proposed to implement the hardening method described above, including:
[0066] The main control module is used to determine whether sensitive data is stored in the target access information corresponding to each first process based on the target access information corresponding to each first process, and to determine whether sensitive data is stored in the target access information corresponding to each second process based on the target access information corresponding to each second process. It sorts the account historical login information to obtain the account historical login order information, obtains the user account verification information, classifies the user instruction process information based on the access data volume threshold and the interaction interface number threshold to obtain the process classification information, and obtains the execution environment corresponding to each process in the virtual machine based on the execution environment information.
[0067] The information acquisition module is used to acquire ubiquitous operating system information, operating system functional module information, and operating system architecture information. Based on the ubiquitous operating system information and using lightweight hardware-assisted virtualization technology, it acquires execution environment information, secure execution environment, and normal environment. It also acquires user instruction information, user instruction content information, and user behavior environment information. Based on user account information, it acquires account historical login information, account historical login time information, and account historical login location information.
[0068] The user login evaluation module is used to take the ratio of the displacement to the time of the historical login information of accounts with adjacent timestamps as the login position displacement coefficient corresponding to the historical login information of accounts with adjacent timestamps. Based on the user login baseline displacement, user login displacement information and login position difference threshold, the module obtains the user login position abnormality coefficient. The module takes the ratio of the number of system historical accounts that reached the maximum number of user account verifications within the user account verification limit time to the total number of abnormal system historical accounts as the verification login correction coefficient. Based on the verification login correction coefficient and the maximum number of user account verifications within the time window, the module obtains the user account behavior abnormality coefficient. The product of the user account behavior abnormality coefficient and the user login position abnormality coefficient is used as the user operation risk coefficient.
[0069] The display module interacts with the main control module and is used to output and display execution environment information, user instruction information, process classification information, virtual machine, and the execution environment corresponding to each process.
[0070] Optionally, the main control module specifically includes:
[0071] The control unit is used to sort the historical login information of the account, obtain the historical login order information of the account, obtain the user account verification information, classify the user instruction process information based on the access data volume threshold and the number of interaction interfaces threshold, obtain the process classification information, and obtain the execution environment corresponding to each process in the virtual machine according to the execution environment information.
[0072] An information receiving unit interacts with an information acquisition module and a user login evaluation module to receive data and transmit it to a judgment unit.
[0073] The judgment unit is used to determine whether sensitive data is stored in the target access information corresponding to each first process based on the target access information corresponding to each first process, and to determine whether sensitive data is stored in the target access information corresponding to each second process based on the target access information corresponding to each second process.
[0074] Optionally, the information acquisition module specifically includes:
[0075] The first acquisition unit is used to acquire ubiquitous operating system information, operating system functional module information and operating system architecture information. Based on the ubiquitous operating system information and lightweight hardware-assisted virtualization technology, it acquires execution environment information, secure execution environment and normal environment.
[0076] The second acquisition unit is used to acquire user instruction information, user instruction content information, and user behavior environment information, and based on user account information, acquire account historical login information, account historical login time information, and account historical login location information.
[0077] Optionally, the user login evaluation module specifically includes:
[0078] The first evaluation module is used to take the ratio of the displacement to the time of the account historical login information of adjacent timestamps as the login position displacement coefficient corresponding to the account historical login information of the group of adjacent timestamps, and to obtain the user login position anomaly coefficient based on the user login baseline displacement, user login displacement information and login position difference threshold.
[0079] The second evaluation module is used to take the ratio of the number of historical accounts that have reached the maximum number of user account verifications within the user account verification limit time to the total number of abnormal historical accounts as the verification login correction coefficient. Based on the verification login correction coefficient and the maximum number of user account verifications within the time window, the user account behavior abnormality coefficient is obtained. The product of the user account behavior abnormality coefficient and the user login location abnormality coefficient is taken as the user operation risk coefficient.
[0080] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0081] This invention proposes a ubiquitous operating system hardening method and system with resource isolation. It accurately assesses user login anomalies through user operation risk coefficients, providing a foundation for subsequent system hardening. By using user account behavior anomaly coefficients and user login location anomaly coefficients, it analyzes user login status from two dimensions: login time and login location, ensuring the accuracy and reliability of the analysis. A dynamic classification standard is established using user operation risk coefficients to categorize user command process information, ensuring the stability of the classification. Resource isolation is applied to each type of process, ensuring the stability and reliability of the system. Attached Figure Description
[0082] Figure 1 This is a flowchart of a ubiquitous operating system hardening method with resource isolation proposed in this invention;
[0083] Figure 2 This is a flowchart of the process for obtaining the user operation risk coefficient in this invention;
[0084] Figure 3 This is a flowchart of the process for obtaining the anomaly coefficient of user login location in this invention;
[0085] Figure 4 This is a flowchart of the process for obtaining the abnormal coefficient of user account behavior in this invention;
[0086] Figure 5 This is a block diagram of a resource-isolated, ubiquitous operating system hardening system proposed in this invention. Detailed Implementation
[0087] The following description is intended to disclose the invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art.
[0088] Reference Figure 1 - Figure 4 As shown, a method for hardening a ubiquitous operating system with resource isolation in an embodiment of the present invention includes:
[0089] Obtain ubiquitous operating system information, which includes operating system functional module information and operating system architecture information;
[0090] Based on ubiquitous operating system information and lightweight hardware-assisted virtualization technology, execution environment information is obtained, including a secure execution environment and a normal environment.
[0091] Acquire user instruction information, which includes user instruction content information and user behavior environment information;
[0092] Based on user instruction information, obtain the user operation risk coefficient and user instruction process information;
[0093] Specifically, based on user instruction information, the user operation risk coefficient is obtained, including:
[0094] Based on user instruction information, obtain user behavior environment information, which includes user account information;
[0095] Based on user account information, obtain account historical login information, which includes account historical login time information and account historical login location information;
[0096] Based on the account's historical login time information, the account's historical login information is sorted according to the timestamp to obtain the account's historical login order information;
[0097] Based on the account's historical login location information and account's historical login time information, and based on the account's historical login order information, obtain the displacement information and time information of the account's historical login information with adjacent timestamps;
[0098] The ratio of the displacement to the time of the historical login information of accounts with adjacent timestamps is used as the displacement coefficient of the login position corresponding to the historical login information of accounts with adjacent timestamps.
[0099] Based on the account's historical login sequence information, the average value of the login location displacement coefficient is used as the login behavior difference coefficient, and the maximum and minimum values of the displacement of the account's historical login information are used as the login location difference threshold.
[0100] Based on user behavior environment information, obtain user login location information and user login time information;
[0101] The user operation risk coefficient is obtained based on the user login location information, user login time information, login location displacement coefficient, and login location difference threshold.
[0102] Specifically, based on user login location information, user login time information, login location displacement coefficient, and login location difference threshold, a user operation risk coefficient is obtained, which includes:
[0103] Based on the user's login time information and the account's historical login information, the account's historical login information most recently associated with the user's login time information is obtained as the account's historical login feature information.
[0104] Based on account historical login characteristics, user login location information, and user login time information, obtain user login interval time information and user login displacement information;
[0105] The product of the user login interval time information and the login position displacement coefficient is used as the user login reference displacement;
[0106] Based on user account information, user account verification information is obtained based on user login time information and account historical login feature information. The user account verification information represents account login verification failure information during the time period corresponding to the account historical login time of the user login time and account historical login feature information.
[0107] Based on the user account verification information, obtain the user account behavior anomaly coefficient;
[0108] The abnormal coefficient of user login location is obtained based on the user login baseline displacement, user login displacement information, and login location difference threshold.
[0109] The user operation risk coefficient is obtained based on the user account behavior anomaly coefficient and the user login location anomaly coefficient.
[0110] If the user login displacement does not exceed the user login baseline displacement, the user login position anomaly coefficient is 1.
[0111] If the user login displacement exceeds the user login baseline displacement but does not exceed the login location difference threshold, then the user login location anomaly coefficient is: Where d is the user login displacement, d0 is the user login baseline displacement, (d2, d1) is the login position difference threshold, and β is the displacement difference correction coefficient with β = 0.6;
[0112] If a user's login displacement exceeds the login location difference threshold, the user's identity is verified based on the user account security verification procedure. If the verification fails, the user's login is rejected. If the verification is successful, the user's login location anomaly coefficient is (1-β), and the login location displacement coefficient and login location difference threshold are updated according to the user's account information.
[0113] This solution analyzes the time and location information of historical account logins to calculate the login location displacement coefficient (displacement / time) and the login location difference threshold (historical displacement extreme value), thus constructing a dynamic baseline for user login behavior. For example, if a user's historical logins are concentrated in a fixed city, with an average displacement coefficient of 50km / h (within the commuting range) and a difference threshold of 300km (crossing city boundaries), when a login displacement reaches 500km with a time interval of 2 hours (displacement coefficient 250km / h, far exceeding the baseline), the system can quickly identify it as an anomaly. Combining the login interval time × displacement coefficient (baseline displacement), the deviation between the actual displacement and the base / threshold, and historical verification failure records (behavioral anomaly coefficient), a three-dimensional risk assessment system is formed, avoiding misjudgments caused by a single dimension (such as only location or time). Unlike traditional static blacklists and whitelists, this method continuously learns user behavior patterns (such as weekday vs. weekend login patterns and changes in frequently used devices), allowing the risk assessment model to dynamically evolve with user habits. It is particularly suitable for scenarios with diverse user terminals (mobile phones, tablets, IoT devices) in ubiquitous operating systems.
[0114] It is understandable that even in daily work, users' login locations vary at different times, and some abnormal situations can cause the differences in login locations between different login times to be even greater. Therefore, a fixed location standard cannot be directly used to evaluate a user's login status.
[0115] Specifically, a user operation risk coefficient is obtained based on the user account behavior anomaly coefficient and the user login location anomaly coefficient, which includes:
[0116] Based on the user account verification information, obtain the number of times the user account has been verified and the verification time for each user account verification.
[0117] Obtain user account verification restriction information, which includes the user account verification restriction time and the maximum number of user account verifications allowed within the user account verification restriction time.
[0118] Using the user account verification restriction time as a time window, obtain the maximum number of user account verifications within the time window based on the user account verification information;
[0119] Obtain historical risk information of system accounts, including historical abnormal information of system accounts;
[0120] Based on the historical risk information of system accounts, obtain the historical verification risk information of system accounts. The historical verification risk information of system accounts refers to the system accounts that have reached the maximum number of user account verifications within the user account verification restriction period.
[0121] Based on the historical verification risk information of system accounts, the ratio of the number of historical system accounts that reached the maximum number of verification attempts within the user account verification restriction period to the total number of abnormal historical system accounts is used as the verification login correction coefficient.
[0122] The abnormal user account behavior coefficient is obtained based on the login verification correction coefficient and the maximum number of user account verifications within the time window.
[0123] The product of the abnormal coefficient of user account behavior and the abnormal coefficient of user login location is used as the user operation risk coefficient.
[0124] Specifically, the user account behavior anomaly coefficient is as follows:
[0125]
[0126] In the formula, k is the abnormal user account behavior coefficient, μ is the login verification correction coefficient, f is the maximum number of user account verifications within the time window, and F is the maximum number of user account verifications allowed within the user account verification restriction time.
[0127] In this solution, based on the historical verification risk information of system accounts, the ratio of the number of historical accounts that reached the maximum number of verifications within the user account verification restriction period to the total number of abnormal historical accounts is used as the verification login correction coefficient. Based on the verification login correction coefficient and the maximum number of user account verifications within the time window, the user account behavior anomaly coefficient is obtained. The product of the user account behavior anomaly coefficient and the user login location anomaly coefficient is used as the user operation risk coefficient. Through the verification login correction coefficient μ, the system-level historical risk is transformed into a personalized assessment factor for the current account, solving the problem of "disconnect between general rules and specific scenarios" and ensuring the stability and accuracy of user login status assessment.
[0128] Understandably, traditional methods (such as judging anomalies by the number of verifications exceeding a threshold) do not take into account the risk differences of different system account types, and cannot accurately identify the anomalies of system accounts that have verified multiple times but whose verification time intervals have not exceeded the threshold. Therefore, we analyze the abnormal verification status of accounts by the maximum number of user account verifications within a time window, and accurately assess the impact of verification anomalies on account security by using the verification login correction coefficient.
[0129] Based on the user operation risk coefficient, the user command process information is classified to obtain process classification information;
[0130] Specifically, based on the user operation risk coefficient, user command process information is classified to obtain process classification information, which includes:
[0131] Based on the user command process information, obtain the target access information and target interaction interface information corresponding to each user command process;
[0132] Based on ubiquitous operating system information and user instruction process information, the maximum amount of data accessed and the maximum number of interaction interfaces corresponding to each user instruction process are obtained.
[0133] The product of the user operation risk coefficient and the maximum amount of data accessed for each user instruction process is used as the threshold for the amount of data accessed for that user instruction process.
[0134] The product of the user operation risk coefficient and the maximum number of interaction interfaces corresponding to each user command process is used as the threshold for the number of interaction interfaces corresponding to that user command process.
[0135] Based on the access data volume threshold and the interaction interface number threshold, user command process information is classified to obtain process classification information;
[0136] If the target access data volume corresponding to the user instruction process exceeds the access data volume threshold or the target interaction interface number exceeds the interaction interface number threshold, then the user instruction process is the first process.
[0137] If the target access data volume corresponding to the user instruction process does not exceed the access data volume threshold and the target interaction interface number does not exceed the interaction interface number threshold, then the user instruction process is the second process.
[0138] In this solution, a dynamic threshold is formed by multiplying the user operation risk coefficient by the maximum data access volume and the maximum number of interaction interfaces of the process (e.g., when the risk coefficient = 0.2, the data access volume threshold = maximum data volume × 0.2). The data access volume threshold for high-risk users (e.g., login from a different location + multiple failed authentications) is significantly reduced. For example, ordinary users are allowed to access 10MB of data, while high-risk users are only allowed 2MB. This effectively curbs malicious processes from stealing sensitive information through large data transfers. The risk coefficient directly affects the resource access boundary of the process, avoiding the drawbacks of traditional static strategies. For example, normal large data transfers (e.g., file backups) by low-risk users are unrestricted, while similar operations by high-risk users are blocked in advance, achieving dynamic binding of risk and permissions.
[0139] Based on process classification information and resource isolation, obtain the virtual machine corresponding to each type of process;
[0140] Based on the execution environment information, obtain the execution environment corresponding to each process in the virtual machine;
[0141] Specifically, based on the execution environment information, the execution environment corresponding to each process in the virtual machine is obtained, including:
[0142] Based on the process classification information, obtain the information of the first process and the second process.
[0143] Based on process resource requirements, the system resources required to obtain the first process information are called the first system resources, and the system resources required to obtain the second process information are called the second system resources.
[0144] Based on the resources of the first system and the second system, and using ubiquitous operating system resource isolation, a first virtual machine and a second virtual machine are formed. The first virtual machine is used to execute the first process, and the second virtual machine is used to execute the second process.
[0145] Based on the first process information, obtain the target access information corresponding to each first process;
[0146] To obtain sensitive data information based on the data security requirements of ubiquitous operating systems;
[0147] Based on the target access information corresponding to each first process, determine whether sensitive data is stored in the target access information corresponding to the first process. If so, the first process is regarded as the first environment requirement process; otherwise, the first process is regarded as the first ordinary process.
[0148] Based on the first virtual machine, according to the execution environment information, a secure execution environment is assigned to the first environment-required process, and a normal environment is assigned to the first ordinary process;
[0149] Based on the target access information corresponding to each second process, determine whether sensitive data is stored in the target access information corresponding to the second process. If so, the second process is used as the second environment requirement process; otherwise, the second process is used as the second ordinary process.
[0150] Based on the second virtual machine, and according to the execution environment information, a secure execution environment is assigned to the second environment-required process, and a normal environment is assigned to the second ordinary process.
[0151] In this solution, based on the resource requirements of the first and second processes, the first and second system resources are obtained. Based on the resource isolation of the ubiquitous operating system, the first virtual machine and the second virtual machine are formed. Based on the target access information and sensitive data information corresponding to each first process, the first process is divided into a first environment requirement process and a first normal process. Based on the target access information and sensitive data information corresponding to each second process, the second process is divided into a second environment requirement process and a second normal process. Different execution environments are determined, ensuring the stability and reliability of the system and realizing system hardening.
[0152] It is understandable that the abnormal situation of the first process is much greater than that of the second process. Therefore, two independent virtual machines are built to execute the two types of processes independently. For the first process, in this embodiment, the amount of data accessed by the process is limited by the access data volume threshold corresponding to each first environment requirement process, and the number of interaction interfaces is limited by the number of interaction interfaces corresponding to each first environment requirement process. At the same time, the product of the maximum standard frequency of interaction between the first environment requirement process and each interaction interface and the user operation risk coefficient is used as the interaction frequency threshold.
[0153] For the first normal process, if the target access data volume corresponding to the first normal process exceeds the access data volume threshold, the product of the maximum standard interaction frequency between the first normal process and each interaction interface and the user operation risk coefficient is used as the interaction frequency threshold, and the interaction frequency is limited by the interaction frequency threshold.
[0154] If the number of target interaction interfaces corresponding to the first ordinary process exceeds the threshold for the number of interaction interfaces, then the number of interaction interfaces will be limited by the threshold for the number of interaction interfaces.
[0155] If the target access data volume corresponding to the first normal process exceeds the access data volume threshold and the target interaction interface number exceeds the interaction interface number threshold, then the interaction frequency is limited by the interaction frequency threshold and the interaction interface number is limited by the interaction interface number threshold.
[0156] For the second environment requirement process, the interaction frequency threshold is the product of the maximum standard interaction frequency between the second environment requirement process and each interaction interface and the user operation risk coefficient. The interaction frequency is limited by the interaction frequency threshold, but no limit is imposed on the second normal process.
[0157] The processes are executed according to their respective execution environments.
[0158] Reference Figure 5 As shown, further, combining the above-mentioned resource isolation ubiquitous operating system hardening method, a resource isolation ubiquitous operating system hardening system is proposed, including:
[0159] The main control module is used to determine whether sensitive data is stored in the target access information corresponding to each first process based on the target access information corresponding to each first process, and to determine whether sensitive data is stored in the target access information corresponding to each second process based on the target access information corresponding to each second process. It sorts the account historical login information to obtain the account historical login order information, obtains the user account verification information, classifies the user instruction process information based on the access data volume threshold and the interaction interface number threshold to obtain the process classification information, and obtains the execution environment corresponding to each process in the virtual machine based on the execution environment information.
[0160] The information acquisition module is used to acquire ubiquitous operating system information, operating system functional module information, and operating system architecture information. Based on the ubiquitous operating system information and using lightweight hardware-assisted virtualization technology, it acquires execution environment information, secure execution environment, and normal environment. It also acquires user instruction information, user instruction content information, and user behavior environment information. Based on user account information, it acquires account historical login information, account historical login time information, and account historical login location information.
[0161] The user login evaluation module is used to take the ratio of the displacement to the time of the historical login information of accounts with adjacent timestamps as the login position displacement coefficient corresponding to the historical login information of accounts with adjacent timestamps. Based on the user login baseline displacement, user login displacement information and login position difference threshold, the module obtains the user login position abnormality coefficient. The module takes the ratio of the number of system historical accounts that reached the maximum number of user account verifications within the user account verification limit time to the total number of abnormal system historical accounts as the verification login correction coefficient. Based on the verification login correction coefficient and the maximum number of user account verifications within the time window, the module obtains the user account behavior abnormality coefficient. The product of the user account behavior abnormality coefficient and the user login position abnormality coefficient is used as the user operation risk coefficient.
[0162] The display module interacts with the main control module and is used to output and display execution environment information, user instruction information, process classification information, virtual machine, and the execution environment corresponding to each process.
[0163] The main control module specifically includes:
[0164] The control unit is used to sort the historical login information of the account, obtain the historical login order information of the account, obtain the user account verification information, classify the user instruction process information based on the access data volume threshold and the number of interaction interfaces threshold, obtain the process classification information, and obtain the execution environment corresponding to each process in the virtual machine according to the execution environment information.
[0165] An information receiving unit interacts with an information acquisition module and a user login evaluation module to receive data and transmit it to a judgment unit.
[0166] The judgment unit is used to determine whether sensitive data is stored in the target access information corresponding to each first process based on the target access information corresponding to each first process, and to determine whether sensitive data is stored in the target access information corresponding to each second process based on the target access information corresponding to each second process.
[0167] The information acquisition module specifically includes:
[0168] The first acquisition unit is used to acquire ubiquitous operating system information, operating system functional module information and operating system architecture information. Based on the ubiquitous operating system information and lightweight hardware-assisted virtualization technology, it acquires execution environment information, secure execution environment and normal environment.
[0169] The second acquisition unit is used to acquire user instruction information, user instruction content information, and user behavior environment information, and based on user account information, acquire account historical login information, account historical login time information, and account historical login location information.
[0170] The user login evaluation module specifically includes:
[0171] The first evaluation module is used to take the ratio of the displacement to the time of the account historical login information of adjacent timestamps as the login position displacement coefficient corresponding to the account historical login information of the group of adjacent timestamps, and to obtain the user login position anomaly coefficient based on the user login baseline displacement, user login displacement information and login position difference threshold.
[0172] The second evaluation module is used to take the ratio of the number of historical accounts that have reached the maximum number of user account verifications within the user account verification limit time to the total number of abnormal historical accounts as the verification login correction coefficient. Based on the verification login correction coefficient and the maximum number of user account verifications within the time window, the user account behavior abnormality coefficient is obtained. The product of the user account behavior abnormality coefficient and the user login location abnormality coefficient is taken as the user operation risk coefficient.
[0173] In summary, the advantages of this invention are as follows: It obtains a user operation risk coefficient by using user login location information, user login time information, login location displacement coefficient, and login location difference threshold; it accurately assesses user login anomalies using this coefficient, providing a foundation for subsequent system hardening; it obtains a user account behavior anomaly coefficient using user account verification information; it obtains a user login location anomaly coefficient using user login baseline displacement, user login displacement information, and login location difference threshold; it analyzes user login status from two dimensions—login time and login location—using both the user account behavior anomaly coefficient and the user login location anomaly coefficient, ensuring the accuracy and reliability of the analysis; it establishes a dynamic classification standard using the user operation risk coefficient to classify user instruction process information, ensuring the stability of the classification; and it ensures system stability and reliability by isolating resources for each type of process.
[0174] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.
Claims
1. A method for hardening a ubiquitous operating system with resource isolation, characterized in that, include: Obtain ubiquitous operating system information, which includes operating system functional module information and operating system architecture information; Based on ubiquitous operating system information and lightweight hardware-assisted virtualization technology, execution environment information is obtained, including a secure execution environment and a normal environment. Acquire user instruction information, which includes user instruction content information and user behavior environment information; Based on user instruction information, obtain the user operation risk coefficient and user instruction process information; Based on the user operation risk coefficient, the user command process information is classified to obtain process classification information; Based on process classification information and resource isolation, obtain the virtual machine corresponding to each type of process; Based on the execution environment information, obtain the execution environment corresponding to each process in the virtual machine; The processes are executed according to their respective execution environments; The step of obtaining the user operation risk coefficient based on user instruction information specifically includes: Based on user instruction information, obtain user behavior environment information, which includes user account information; Based on user account information, obtain account historical login information, which includes account historical login time information and account historical login location information; Based on the account's historical login time information, the account's historical login information is sorted according to the timestamp to obtain the account's historical login order information; Based on the account's historical login location information and account's historical login time information, and based on the account's historical login order information, obtain the displacement information and time information of the account's historical login information with adjacent timestamps; The ratio of the displacement to the time of the historical login information of accounts with adjacent timestamps is used as the displacement coefficient of the login position corresponding to the historical login information of accounts with adjacent timestamps. Based on the account's historical login sequence information, the average value of the login location displacement coefficient is used as the login behavior difference coefficient, and the maximum and minimum values of the displacement of the account's historical login information are used as the login location difference threshold. Based on user behavior environment information, obtain user login location information and user login time information; Based on user login location information, user login time information, login location displacement coefficient, and login location difference threshold, obtain the user operation risk coefficient; The step of obtaining the user operation risk coefficient based on user login location information, user login time information, login location displacement coefficient, and login location difference threshold specifically includes: Based on the user's login time information and the account's historical login information, the account's historical login information most recently associated with the user's login time information is obtained as the account's historical login feature information. Based on account historical login characteristics, user login location information, and user login time information, obtain user login interval time information and user login displacement information; The product of the user login interval time information and the login position displacement coefficient is used as the user login reference displacement; Based on user account information, user account verification information is obtained based on user login time information and account historical login feature information. The user account verification information represents account login verification failure information during the time period corresponding to the account historical login time of the user login time and account historical login feature information. Based on the user account verification information, obtain the user account behavior anomaly coefficient; The abnormal coefficient of user login location is obtained based on the user login baseline displacement, user login displacement information, and login location difference threshold. The user operation risk coefficient is obtained based on the user account behavior anomaly coefficient and the user login location anomaly coefficient. If the user login displacement does not exceed the user login baseline displacement, the user login position anomaly coefficient is 1. If the user login displacement exceeds the user login baseline displacement but does not exceed the login location difference threshold, then the user login location anomaly coefficient is: ,in For user login displacement, For user login, the reference displacement, The threshold for login location difference. For displacement difference correction coefficient and ; If a user's login location exceeds the login location difference threshold, the user's identity will be verified based on the user account security verification procedure. If verification fails, the user's login will be denied; if verification succeeds, the user's login location anomaly coefficient will be [value missing]. And based on the user account information, update the login location displacement coefficient and login location difference threshold; The process of obtaining a user operation risk coefficient based on user account behavior anomaly coefficient and user login location anomaly coefficient specifically includes: Based on the user account verification information, obtain the number of times the user account has been verified and the verification time for each user account verification. Obtain user account verification restriction information, which includes the user account verification restriction time and the maximum number of user account verifications allowed within the user account verification restriction time. Using the user account verification restriction time as a time window, obtain the maximum number of user account verifications within the time window based on the user account verification information; Obtain historical risk information of system accounts, including historical abnormal information of system accounts; Based on the historical risk information of system accounts, obtain the historical verification risk information of system accounts. The historical verification risk information of system accounts refers to the system accounts that have reached the maximum number of user account verifications within the user account verification restriction period. Based on the historical verification risk information of system accounts, the ratio of the number of historical system accounts that reached the maximum number of verification attempts within the user account verification restriction period to the total number of abnormal historical system accounts is used as the verification login correction coefficient. The abnormal user account behavior coefficient is obtained based on the login verification correction coefficient and the maximum number of user account verifications within the time window. The product of the abnormal coefficient of user account behavior and the abnormal coefficient of user login location is used as the user operation risk coefficient. Specifically, the abnormal user account behavior coefficient is as follows: In the formula, The abnormal behavior coefficient of user accounts. To verify the login correction coefficient, This represents the maximum number of user account verifications within the time window. The maximum number of times a user account can be verified within a specified time period; The process of classifying user command process information based on user operation risk coefficients and obtaining process classification information specifically includes: Based on the user command process information, obtain the target access information and target interaction interface information corresponding to each user command process; Based on ubiquitous operating system information and user instruction process information, the maximum amount of data accessed and the maximum number of interaction interfaces corresponding to each user instruction process are obtained. The product of the user operation risk coefficient and the maximum amount of data accessed for each user instruction process is used as the threshold for the amount of data accessed for that user instruction process. The product of the user operation risk coefficient and the maximum number of interaction interfaces corresponding to each user command process is used as the threshold for the number of interaction interfaces corresponding to that user command process. Based on the access data volume threshold and the interaction interface number threshold, user command process information is classified to obtain process classification information; If the target access data volume corresponding to the user instruction process exceeds the access data volume threshold or the target interaction interface number exceeds the interaction interface number threshold, then the user instruction process is the first process. If the target access data volume corresponding to the user instruction process does not exceed the access data volume threshold and the target interaction interface number does not exceed the interaction interface number threshold, then the user instruction process is the second process.
2. The ubiquitous operating system hardening method with resource isolation according to claim 1, characterized in that, The step of obtaining the execution environment corresponding to each process in the virtual machine based on the execution environment information specifically includes: Based on the process classification information, obtain the information of the first process and the second process. Based on process resource requirements, the system resources required to obtain the first process information are called the first system resources, and the system resources required to obtain the second process information are called the second system resources. Based on the resources of the first system and the second system, and using ubiquitous operating system resource isolation, a first virtual machine and a second virtual machine are formed. The first virtual machine is used to execute the first process, and the second virtual machine is used to execute the second process. Based on the first process information, obtain the target access information corresponding to each first process; To obtain sensitive data information based on the data security requirements of ubiquitous operating systems; Based on the target access information corresponding to each first process, determine whether sensitive data is stored in the target access information corresponding to the first process. If so, the first process is regarded as the first environment requirement process; otherwise, the first process is regarded as the first ordinary process. Based on the first virtual machine, according to the execution environment information, a secure execution environment is assigned to the first environment-required process, and a normal environment is assigned to the first ordinary process; Based on the target access information corresponding to each second process, determine whether sensitive data is stored in the target access information corresponding to the second process. If so, the second process is used as the second environment requirement process; otherwise, the second process is used as the second ordinary process. Based on the second virtual machine, and according to the execution environment information, a secure execution environment is assigned to the second environment-required process, and a normal environment is assigned to the second ordinary process.
3. A resource-isolated ubiquitous operating system hardening system, used to implement the hardening method as described in any one of claims 1-2, characterized in that, include: The main control module is used to determine whether sensitive data is stored in the target access information corresponding to each first process based on the target access information corresponding to each first process, and to determine whether sensitive data is stored in the target access information corresponding to each second process based on the target access information corresponding to each second process. It sorts the account historical login information to obtain the account historical login order information, obtains the user account verification information, classifies the user instruction process information based on the access data volume threshold and the interaction interface number threshold to obtain the process classification information, and obtains the execution environment corresponding to each process in the virtual machine based on the execution environment information. The information acquisition module is used to acquire ubiquitous operating system information, operating system functional module information, and operating system architecture information. Based on the ubiquitous operating system information and using lightweight hardware-assisted virtualization technology, it acquires execution environment information, secure execution environment, and normal environment. It also acquires user instruction information, user instruction content information, and user behavior environment information. Based on user account information, it acquires account historical login information, account historical login time information, and account historical login location information. The user login evaluation module is used to take the ratio of the displacement to the time of the historical login information of accounts with adjacent timestamps as the login position displacement coefficient corresponding to the historical login information of accounts with adjacent timestamps. Based on the user login baseline displacement, user login displacement information and login position difference threshold, the module obtains the user login position abnormality coefficient. The module takes the ratio of the number of system historical accounts that reached the maximum number of user account verifications within the user account verification limit time to the total number of abnormal system historical accounts as the verification login correction coefficient. Based on the verification login correction coefficient and the maximum number of user account verifications within the time window, the module obtains the user account behavior abnormality coefficient. The product of the user account behavior abnormality coefficient and the user login position abnormality coefficient is used as the user operation risk coefficient. The display module interacts with the main control module and is used to output and display execution environment information, user instruction information, process classification information, virtual machine, and the execution environment corresponding to each process.
4. The ubiquitous operating system hardening system with resource isolation according to claim 3, characterized in that, The main control module specifically includes: The control unit is used to sort the historical login information of the account, obtain the historical login order information of the account, obtain the user account verification information, classify the user instruction process information based on the access data volume threshold and the number of interaction interfaces threshold, obtain the process classification information, and obtain the execution environment corresponding to each process in the virtual machine according to the execution environment information. An information receiving unit interacts with an information acquisition module and a user login evaluation module to receive data and transmit it to a judgment unit. The judgment unit is used to determine whether sensitive data is stored in the target access information corresponding to each first process based on the target access information corresponding to each first process, and to determine whether sensitive data is stored in the target access information corresponding to each second process based on the target access information corresponding to each second process.
5. A resource-isolated ubiquitous operating system hardening system according to claim 3, characterized in that, The information acquisition module specifically includes: The first acquisition unit is used to acquire ubiquitous operating system information, operating system functional module information and operating system architecture information. Based on the ubiquitous operating system information and lightweight hardware-assisted virtualization technology, it acquires execution environment information, secure execution environment and normal environment. The second acquisition unit is used to acquire user instruction information, user instruction content information, and user behavior environment information, and based on user account information, acquire account historical login information, account historical login time information, and account historical login location information.
6. The ubiquitous operating system hardening system with resource isolation according to claim 3, characterized in that, The user login evaluation module specifically includes: The first evaluation module is used to take the ratio of the displacement to the time of the account historical login information of adjacent timestamps as the login position displacement coefficient corresponding to the account historical login information of the group of adjacent timestamps, and to obtain the user login position anomaly coefficient based on the user login baseline displacement, user login displacement information and login position difference threshold. The second evaluation module is used to take the ratio of the number of historical accounts that have reached the maximum number of user account verifications within the user account verification limit time to the total number of abnormal historical accounts as the verification login correction coefficient. Based on the verification login correction coefficient and the maximum number of user account verifications within the time window, the user account behavior abnormality coefficient is obtained. The product of the user account behavior abnormality coefficient and the user login location abnormality coefficient is taken as the user operation risk coefficient.
Citation Information
Patent Citations
Virtual machine security isolation system and method oriented to multi-security-level virtual desktop system
CN103902885A
Container engine of computing node and container arrangement method
CN119806728A