Network card access control method and device, storage medium and electronic equipment

By loading an extensible packet filter program in the Linux kernel and associating it with control packets, responding to packet events and controlling network card access based on return values, the problem of process access to all network cards in the Linux operating system is solved, and process-level security restrictions and system stability are achieved.

CN120614142APending Publication Date: 2025-09-09ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510510048.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

In the Linux operating system, processes can access all network cards, which threatens the confidentiality, integrity, and availability of the system. How can we limit the network capabilities of processes to improve security?

Method used

A specific type of extensible packet filter program is loaded into the kernel through the management process, and an association with the target control packet is established. The system responds to the packet sending and receiving events of the business process and performs corresponding operations according to the return value of the filter program to restrict network card access.

Benefits of technology

It implements process-level network card access control, avoids system crashes, has good compatibility and flexibility, and can limit network card access without creating a new network namespace.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614142A_ABST
    Figure CN120614142A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network card access control method and device, a storage medium and electronic equipment, and the method comprises the steps: loading a specific type of extensible data packet filter program into a kernel through a management process, and building the association between the extensible data packet filter program and a target control group, and executing the extensible data packet filter program in response to a receiving and transmitting event of a target data packet of a target network card in a target service process in the at least one service process, and executing corresponding operation on the target data packet according to a return value of the extensible data packet filter program. Therefore, whether the access of the correspondingly used network card is limited or not can be checked in the outgoing direction and the incoming direction of the data packet, so that process-level network card access control is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to computer technology, and in particular to a method, device, storage medium and electronic equipment for network card access control. Background Art

[0002] Linux, an open-source operating system, is widely used on servers. Linux operating systems may have multiple network cards connecting to different networks. Some of these cards can access external networks, some can only access the local area network, and some can only be used locally. By default, processes in the Linux operating system can access all network cards, meaning all processes can access external networks. If an attacker successfully exploits a vulnerability in the operating system, they can connect to external attack tools, control the system from external networks, and transmit internal data to external devices over the network. This can seriously undermine the confidentiality, integrity, and availability of computer systems. Restricting the network capabilities of systems and processes has always been a key issue in computer security. Summary of the Invention

[0003] The purpose of the embodiments of this specification is to provide a method, device, storage medium and electronic device for network card access control.

[0004] The embodiments of this specification provide a method for network card access control, including:

[0005] Loading a specific type of extensible packet filter program into the kernel through the management process, and establishing an association between the extensible packet filter program and a target control group, wherein the target control group includes at least one service process placed by the management process;

[0006] executing the extensible data packet filter program in response to a target data packet receiving and sending event of a target service process in the at least one service process with respect to a target network card;

[0007] A corresponding operation is performed on the target data packet according to a return value of the extensible data packet filter program, wherein the return value is used to indicate whether to restrict access to the target network card.

[0008] Furthermore, the method further comprises:

[0009] The at least one business process is placed into the target control group through the management process.

[0010] Furthermore, the method further comprises:

[0011] The management process is deployed in the target control group, so that the new business process started by the management process is deployed in the target control group.

[0012] Furthermore, establishing an association between the extensible packet filter program and the target control packet includes:

[0013] The extensible packet filter program is associated with identification information of the target control packet.

[0014] Furthermore, the method further comprises:

[0015] Storing identification information of at least one network card in a shared data unit corresponding to the extensible packet filter program;

[0016] Wherein, executing the extensible packet filter program includes:

[0017] The extensible packet filter program is executed so that the extensible packet filter program determines a corresponding return value by querying whether the at least one network card in the shared data unit includes the target network card.

[0018] Furthermore, the method further comprises:

[0019] The at least one network card is determined from a plurality of network cards according to the characteristic information of the service process.

[0020] Furthermore, performing corresponding operations on the target data packet according to the return value of the extensible data packet filter program includes:

[0021] If the return value of the extensible packet filter program indicates that the at least one network card includes the target network card, the target data packet is discarded; otherwise, the target data packet is sent and received normally.

[0022] The embodiment of this specification also provides a device for network card access control, including:

[0023] a program loading module, configured to load a specific type of extensible packet filter program into the kernel through the management process, and establish an association between the extensible packet filter program and a target control group, wherein the target control group includes at least one service process placed by the management process;

[0024] a first execution module, configured to execute the extensible data packet filter program in response to a sending / receiving event of a target data packet of a target network card by a target business process in the at least one business process;

[0025] The second execution module is configured to execute a corresponding operation on the target data packet according to a return value of the extensible data packet filter program, wherein the return value is used to indicate whether to restrict access to the target network card.

[0026] An embodiment of this specification further provides a storage medium, wherein the storage medium stores a computer program, and the computer program is suitable for being loaded by a processor and executing the steps of the above method.

[0027] An embodiment of this specification further provides an electronic device, comprising: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the above method.

[0028] An embodiment of this specification also provides a computer program product having at least one instruction stored thereon, wherein the at least one instruction implements the steps of the above method when executed by a processor.

[0029] According to the solution of the embodiments of this specification, a specific type of extensible packet filter program is loaded into the kernel through a management process, and an association is established between the extensible packet filter program and a target control packet. Then, in response to a sending and receiving event of a target data packet of a target network card by a target business process in at least one business process, the extensible packet filter program is executed, and corresponding operations are performed on the target data packet according to a return value of the extensible packet filter program. This enables checking in the outgoing and incoming directions of the data packet whether the corresponding network card used is restricted from access, thereby realizing process-level network card access control. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 A flowchart of a method for network card access control provided in an embodiment of this specification;

[0031] Figure 2 This is a flowchart of an example of network card access control provided in an embodiment of this specification;

[0032] Figure 3 A schematic diagram of the structure of a device for network card access control provided in an embodiment of this specification;

[0033] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this specification. DETAILED DESCRIPTION

[0034] To make the objectives, technical solutions, and advantages of this specification more clear, the following will clearly and completely describe the technical solutions of this specification in conjunction with the specific embodiments of this specification and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this specification.

[0035] See Figure 1 , is a flow chart of a method for network card access control provided in an embodiment of this specification. In an embodiment of this specification, the method for network card access control is applied to a device for network card access control (hereinafter referred to as "access control device") or an electronic device equipped with an access control device. Figure 1 The process shown in FIG. 1 is described in detail. The method for network card access control may specifically include the following steps:

[0036] S102, loading a specific type of extensible packet filter program into the kernel through the management process, and establishing an association between the extensible packet filter program and a target control group, wherein the target control group includes at least one business process placed by the management process.

[0037] In some embodiments, the extensible packet filter program is an eBPF (Extended Berkeley Packet Filter) program. eBPF is an instrumentation technology that can dynamically add code to the Linux operating system kernel, thereby modifying the Linux kernel's behavior at runtime. After the management process loads the eBPF program into the kernel, the checker in the Linux kernel will check the loaded eBPF program to ensure that the loaded eBPF bytecode does not damage the kernel. In some embodiments, the service process is a process that can load the extensible packet filter program. Taking the eBPF program as an example, it can be recorded in various service processes in the kernel, such as system calls, socket layers, TCP / IP protocol stacks, etc. In some embodiments, a specific type of extensible packet filter program can be executed when a process in a specific cgroup (control groups, a method used in Linux systems to control process access to system resources) sends and receives packets. For example, BPF_PROG_TYPE_CGROUP_SKB is an eBPF program type that can be executed when a process in a specific cgroup sends and receives packets.

[0038] In some embodiments, the target control group, also known as the aforementioned cgroup, loads a specific type of extensible packet filter program into the kernel and establishes an association between the extensible packet filter program and the target control group into which it is loaded. In some embodiments, multiple extensible packet filter programs can be loaded into a target control group, and a single extensible packet filter program can be loaded into multiple target control groups. In some embodiments, before the management process loads the specific type of extensible packet filter program into a target control group in the kernel, the management process has already loaded at least one business process into the target control group. In some embodiments, after the management process loads the specific type of extensible packet filter program into a target control group in the kernel, the management process may also load a newly launched business process into the target control group. In some embodiments, the management process and the at least one business process are both deployed in the target control group, so that any new business processes subsequently launched by the management process can be placed in the target control group, thereby facilitating management of future processes. In some embodiments, the management process is not deployed in the target control group. When launching a new business process, the management process may place the business process in the corresponding target control group based on the characteristics of the business process. By establishing an association between the extensible packet filter program and the target control group, the cgroup can be bound to the extensible packet filter program, which is equivalent to binding each business process in the cgroup to the extensible packet filter program.

[0039] S104 , executing the extensible data packet filter program in response to a target data packet receiving and sending event of a target service process in the at least one service process with respect to a target network card.

[0040] In some embodiments, the transceiver events include packet reception events and packet sending events. The extensible packet filter program may be executed only when a packet sending event occurs, or may be executed when both a packet sending event and a packet receiving event occur. Furthermore, the extensible packet filter program may be executed only for a transceiver event when the target packet meets a preset condition. For example, a server includes network cards eth0 and eth1. A target service process in a target control packet initiates an access to network card eth0. After the target packet corresponding to the access enters the network protocol stack, the eBPF program associated with the target control packet is executed when the packet is about to be sent.

[0041] S106 , performing corresponding operations on the target data packet according to a return value of the extensible data packet filter program, wherein the return value is used to indicate whether to restrict access to the target network card.

[0042] In some embodiments, the return value indicates whether access to the target network card is prohibited. For example, a return value of 0 indicates that access is prohibited, and a return value of 1 indicates that access is allowed. In some embodiments, the extensible packet filter program determines the return value by querying whether the identification information of the target network card exists in an associated map (a data structure that can store identification information of the network card to be prohibited). For example, if the identification information exists, the return value is confirmed to indicate that access is prohibited, and if not, the return value is confirmed to indicate that access is allowed. In some embodiments, if the return value indicates that access to the target network card is prohibited, a discard operation is performed on the target data packet. If the return value indicates that access to the target network card is allowed, a corresponding receive or send operation is performed on the target data packet.

[0043] According to the solution of the embodiments of this specification, a specific type of extensible packet filter program is loaded into the kernel through a management process, and an association is established between the extensible packet filter program and a target control packet. Then, in response to a sending and receiving event of a target data packet of a target network card by a target business process in at least one business process, the extensible packet filter program is executed, and corresponding operations are performed on the target data packet according to a return value of the extensible packet filter program. This enables checking in the outgoing and incoming directions of the data packet whether the corresponding network card used is restricted from access, thereby realizing process-level network card access control.

[0044] In the prior art, two methods are usually used to implement process access control: one is process network access restriction based on network namespace, which creates an independent network namespace for the process and restricts the process's network access in this namespace; the other is process network control based on the netfilter (packet filtering framework in the Linux kernel) kernel module, which compiles a netfilter module and restricts the access of a specified process to certain network cards according to the policy in the netfilter module. Compared with the above-mentioned existing process network access restriction scheme based on network namespace, the scheme of the embodiment of this specification can use various network cards on the host machine without being affected because it does not need to create a new network namespace. Compared with the above-mentioned existing process network control scheme based on the netfilter module, the scheme of the embodiment of this specification has very good stability because the extensible packet filter program has been strictly checked by the kernel, so it will not cause system crashes, and the extensible packet filter program can be loaded in different kernel versions without recompilation, so it has good compatibility. In addition, for processes with restricted network card access, this scheme can easily add or delete them to the corresponding cgroup, making management more convenient and flexible.

[0045] In some embodiments, the method further includes: placing, by the management process, the at least one business process into the target control group. In some embodiments, each target control group corresponds to a different access control policy, and the management process places at least one business process corresponding to the same access control policy into the same target control group. For example, the management process places multiple business processes prohibited from accessing network card eth0 into the same target control group, and places multiple business processes prohibited from accessing network card eth1 into another target control group.

[0046] In some embodiments, the method further includes: deploying the management process in the target control group, such that new business processes initiated by the management process are deployed in the target control group. In some embodiments, the management process and the at least one business process are both deployed in the target control group, such that new business processes subsequently initiated by the management process are all placed in the target control group. In other words, all processes initiated by the management process are placed in the target control group, thereby facilitating that all processes initiated by the management process directly adopt the access control policy corresponding to the target control group.

[0047] In some embodiments, establishing an association between the extensible packet filter program and the target control packet includes associating the extensible packet filter program with identification information of the target control packet. As an example, the management process loads an eBPF program of type BPF_PROG_TYPE_CGROUP_SKB into the kernel and associates the packet identification (ID) of the loaded target control packet c1 with the eBPF program. The eBPF program then filters all packets destined for the corresponding network card based on the identification information of the network card specified in the eBPF policy map.

[0048] In some embodiments, the method further includes: storing identification information of at least one network card in a shared data unit corresponding to the extensible packet filter program; wherein executing the extensible packet filter program includes: executing the extensible packet filter program so that the extensible packet filter program determines a corresponding return value by querying whether the at least one network card in the shared data unit includes the target network card. In some embodiments, the shared data unit is the aforementioned map, and the at least one network card is the network card that is prohibited from access by the target control packet. In some embodiments, the identification information of the network card is used to uniquely identify the network card, such as the network card's index or MAC (Media Access Control) address. In some embodiments, the at least one network card to be prohibited from access can be determined based on historical network card access records, and the identification information of the at least one network card can then be stored in the shared data unit. In some embodiments, the at least one network card to be stored in the shared data unit can be pre-set. In some embodiments, if the identification information corresponding to the target network card is present in the shared data unit, it is determined that the at least one network card includes the target network card, and the return value can be determined accordingly.

[0049] In some embodiments, the method further includes: determining the at least one network card among a plurality of network cards based on the characteristic information of the business process. In some embodiments, the characteristic information includes any information used to characterize the characteristics of the network card access behavior of the business process, for example, the characteristic information is used to characterize whether the website currently to be accessed is a malicious website, the degree of danger and suspicion of the current network card access behavior, whether the current network card access behavior is untrustworthy, etc. In some embodiments, based on the characteristic information of each business process, the network cards that need to be prohibited from access by different business processes can be determined, thereby enabling at least one business process that is prohibited from accessing the same network card to be placed in the same control group, and the corresponding associated map stores the identification information of the network card that is prohibited from access by the at least one business process.

[0050] In some embodiments, the step of performing a corresponding operation on the target data packet based on the return value of the extensible packet filter program includes: if the return value of the extensible packet filter program indicates that the at least one network card includes the target network card, discarding the target data packet; otherwise, transmitting and receiving the target data packet normally. The return value indicating that the at least one network card includes the target network card indicates that access to the target network card needs to be restricted. For example, when a corresponding eBPF program is executed when sending a target data packet, if the identification information of the target network card is not stored in the map (i.e., the at least one network card does not include the target network card), the return value of the eBPF program is 1, indicating that access to the target network card does not need to be restricted, and the target data packet is transmitted normally; if the identification information of the target network card is stored in the map (i.e., the at least one network card does not include the target network card), the return value of the eBPF program is 0, indicating that access to the target network card needs to be restricted, and the target data packet is discarded, i.e., the sending operation is not performed.

[0051] Figure 2 This is a flowchart of an example of network card access control provided in the embodiments of this specification. Figure 2 Taking the eBPF program as an example, the process for network card access control is as follows: 1) The management process puts the business process into a specific control group cgroup. In order to manage the processes started in the future, the management process itself is also put into the cgroup; 2) The management process loads the eBPF program of type BPF_PROG_TYPE_CGROUP_SKB into the kernel and associates the ID corresponding to the cgroup with the eBPF program. The eBPF program will filter out all the data packets of the corresponding network card according to the network card index specified in the eBPF policy map; 3) According to the characteristics of the business process, its access to the network card is restricted, such as Figure 2As shown in the figure, for the business process in the cgroup, access to the network card eth0 is prohibited, and access to the network card eth1 is allowed. The management process obtains the network card index of eth0 and writes the index into the eBPF policy map; 4) The business program initiates access to the network card eth0; 5) After the data packet enters the network protocol stack, when it is about to be sent out, the eBPF program recorded in 2 will be executed; 6) After the eBPF program queries the eBPF policy map, it finds that the index of the network card eth0 of the data packet is in the map, and returns the value 0 indicating that sending is prohibited; 7) The network protocol stack checks the return value of the eBPF program and discards the packet after finding that the return value is 0; 8) The business program initiates access to the network card eth1; 9) After the data packet enters the network protocol stack, when it is about to be sent out, the eBPF program loaded in 2 will be executed; 10) After the eBPF program queries the map, it finds that the index of the network card eth1 of the data packet is not in the map, and returns the value 1 indicating that sending is allowed; 11) The network protocol stack checks the return value of the eBPF program and sends the data packet normally after finding that the return value is 1. It should be noted that Figure 2 The operations 1-11 identified in the figure are only for explaining the principle of network card access control and do not represent the actual execution order.

[0052] Figure 3 This is a schematic diagram of the structure of a device for network card access control provided in an embodiment of this specification. This device for network card access control (hereinafter referred to as "access control device 100") can be implemented as all or part of an electronic device through software, hardware, or a combination of both. According to some embodiments, access control device 100 includes a program loading module 101, a first execution module 102, and a second execution module 103.

[0053] The program loading module 101 is used to load a specific type of extensible packet filter program into the kernel through the management process, and establish an association between the extensible packet filter program and a target control group, wherein the target control group includes at least one business process placed by the management process.

[0054] The first execution module 102 is configured to execute the extensible data packet filter program in response to a target data packet receiving and sending event of a target service process in the at least one service process with respect to a target network card.

[0055] The second execution module 103 is configured to execute a corresponding operation on the target data packet according to a return value of the extensible data packet filter program, wherein the return value is used to indicate whether to restrict access to the target network card.

[0056] In some embodiments, the access control apparatus 100 is further configured to: place the at least one business process into the target control group through the management process.

[0057] In some embodiments, the access control apparatus 100 is further configured to: deploy the management process in the target control group, so that the new service process started by the management process is deployed in the target control group.

[0058] In some embodiments, said establishing an association between the extensible packet filter program and the target control packet includes: associating the extensible packet filter program with identification information of the target control packet.

[0059] In some embodiments, the access control device 100 is further used to: store identification information of at least one network card in a shared data unit corresponding to the extensible packet filter program; wherein, executing the extensible packet filter program includes: executing the extensible packet filter program so that the extensible packet filter program determines a corresponding return value by querying whether the at least one network card in the shared data unit includes the target network card.

[0060] In some embodiments, the access control device 100 is further configured to: determine the at least one network card from a plurality of network cards according to characteristic information of the service process.

[0061] In some embodiments, the second execution module 103 is configured to: if the return value of the extensible packet filter program indicates that access to the target network card is restricted, discard the target data packet; otherwise, send and receive the target data packet normally.

[0062] The above-mentioned device embodiments correspond to the method embodiments. For detailed descriptions, please refer to the description of the method embodiments, which will not be repeated here. The device embodiments are obtained based on the corresponding method embodiments and have the same technical effects as the corresponding method embodiments. For detailed descriptions, please refer to the corresponding method embodiments.

[0063] The embodiments of this specification also provide a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded by a processor and executing the method of the embodiments of this specification.

[0064] An embodiment of the present specification further provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded by the processor to execute the method of the embodiment of the present specification.

[0065] The embodiments of this specification also provide Figure 4 The structural diagram of the electronic device shown in FIG. Figure 4 At the hardware level, the electronic device includes a processor, an internal bus, a network interface, memory, and non-volatile storage, and may also include other hardware required for its operations. The processor reads the corresponding computer program from the non-volatile storage into the memory and then runs it to implement the above method.

[0066] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0067] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0068] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0069] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0070] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0071] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0072] This specification may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media, including storage devices.

[0073] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.

[0074] The foregoing is merely an example of the present invention and is not intended to limit the present invention. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be included within the scope of the claims of the present invention.

Claims

1. A method for network card access control, comprising: Loading a specific type of extensible packet filter program into the kernel through the management process, and establishing an association between the extensible packet filter program and a target control group, wherein the target control group includes at least one service process placed by the management process; executing the extensible data packet filter program in response to a target data packet receiving and sending event of a target service process in the at least one service process with respect to a target network card; A corresponding operation is performed on the target data packet according to a return value of the extensible data packet filter program, wherein the return value is used to indicate whether to restrict access to the target network card.

2. The method according to claim 1, further comprising: The at least one business process is placed into the target control group through the management process.

3. The method according to claim 2, further comprising: The management process is deployed in the target control group, so that the new business process started by the management process is deployed in the target control group.

4. The method of claim 1 , wherein establishing an association between the extensible packet filter program and a target control packet comprises: The extensible packet filter program is associated with identification information of the target control packet.

5. The method according to claim 1, further comprising: Storing identification information of at least one network card in a shared data unit corresponding to the extensible packet filter program; Wherein, executing the extensible packet filter program includes: The extensible packet filter program is executed so that the extensible packet filter program determines a corresponding return value by querying whether the at least one network card in the shared data unit includes the target network card.

6. The method according to claim 5, further comprising: The at least one network card is determined from a plurality of network cards according to the characteristic information of the service process.

7. The method according to claim 5, wherein performing corresponding operations on the target data packet according to a return value of the extensible data packet filter program comprises: If the return value of the extensible packet filter program indicates that the at least one network card includes the target network card, discarding the target data packet; Otherwise, the target data packet is sent and received normally.

8. A device for network card access control, comprising: a program loading module, configured to load a specific type of extensible packet filter program into the kernel through the management process, and establish an association between the extensible packet filter program and a target control group, wherein the target control group includes at least one service process placed by the management process; a first execution module, configured to execute the extensible data packet filter program in response to a sending / receiving event of a target data packet of a target network card by a target business process in the at least one business process; The second execution module is configured to execute a corresponding operation on the target data packet according to a return value of the extensible data packet filter program, wherein the return value is used to indicate whether to restrict access to the target network card.

9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

10. An electronic device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the method according to any one of claims 1 to 7.

11. A computer program product having at least one instruction stored thereon, characterized in that: When the at least one instruction is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.