Abnormal behavior detection method, electronic equipment, medium and product

By comparing the virtual machine's disk information with the baseline information in the virtualization management platform, abnormal behavior of the operating system can be identified, which solves the accuracy and security problems of virtual machine detection in the existing technology and realizes efficient abnormal behavior detection and processing.

CN120653368APending Publication Date: 2025-09-16ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510804333.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing technologies have difficulty accurately identifying abnormal behavior of operating systems in virtual machines, which affects the service quality of the cloud platform and the stability of the physical host. Traditional detection methods can be easily circumvented or forged by attackers.

Method used

Obtain virtual machine disk information through the virtualization management platform and compare it with pre-recorded benchmark disk information to identify abnormal behavior at the operating system level, avoid intrusion into virtual machine detection, and improve detection accuracy and performance.

Benefits of technology

It realizes abnormal behavior detection at the operating system level, improves the accuracy and performance of detection, ensures data security, reduces virtual machine resource usage, and improves the bottom-level nature and anti-circumvention capabilities of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120653368A_ABST
    Figure CN120653368A_ABST
Patent Text Reader

Abstract

The invention provides an abnormal behavior detection method, an electronic device, a medium and a product, the method is applied to a virtualization management platform, the virtualization management platform is correspondingly deployed with a virtual machine, and the method comprises the steps that under the condition that a preset detection condition is met, current first disk information of the virtual machine is acquired, the first disk information is associated with an operating system type; second disk information of the virtual machine is obtained from a data reporting center, and the second disk information represents reference disk information configured when the virtual machine is created and is recorded in the data reporting center in advance; comparing the first disk information with the second disk information; and under the condition of determining that the first disk information is inconsistent with the second disk information, determining that the virtual machine has an abnormal behavior aiming at an operating system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of virtualization management, and in particular to an abnormal behavior detection method, electronic equipment, medium, and product. Background Art

[0002] With the development of virtualization technology, cloud service providers can provide users with elastic computing resources through virtualization management platforms. Users can use computing resources based on virtual machines to perform tasks. However, users may use computing resources for other abnormal behaviors, affecting the service quality of the cloud platform and the stability of the physical host. Therefore, it is very important to accurately identify such abnormal behaviors. Summary of the Invention

[0003] The present disclosure provides an abnormal behavior detection method, electronic equipment, medium, and product.

[0004] In a first aspect, an embodiment of the present disclosure provides an abnormal behavior detection method, which is applied to a virtualization management platform, wherein a virtual machine is deployed on the virtualization management platform, and includes:

[0005] When a preset detection condition is met, obtaining current first disk information of the virtual machine, wherein the first disk information is associated with an operating system type;

[0006] Acquire second disk information of the virtual machine from a data reporting center, wherein the second disk information represents baseline disk information configured when the virtual machine is created and is pre-recorded in the data reporting center;

[0007] comparing the first disk information and the second disk information;

[0008] When it is determined that the first disk information and the second disk information are inconsistent, it is determined that the virtual machine has abnormal behavior with respect to the operating system.

[0009] In a second aspect, an embodiment of the present disclosure provides an electronic device comprising a memory and a processor; the memory stores a computer program that can be executed by the processor, and the computer program implements the above-mentioned abnormal behavior detection method when executed by the processor.

[0010] In a third aspect, an embodiment of the present disclosure provides a computer-readable medium having a computer program stored thereon, which implements the above-mentioned abnormal behavior detection method when executed by a processor.

[0011] In a fourth aspect, an embodiment of the present disclosure provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the above-mentioned abnormal behavior detection method.

[0012] In the embodiment of the present disclosure, when the preset detection conditions are met, the current first disk information of the virtual machine is obtained, and the first disk information is compared with the second disk information pre-recorded by the data reporting center. In the case of inconsistency in the comparison, it is determined that the virtual machine has abnormal behavior with respect to the operating system. In this way, by comparing the disk information for abnormal behavior detection, it is possible to effectively identify whether the operating system has been tampered with abnormal behavior, and the second disk information serving as the benchmark disk information is stored in the data reporting center, which can improve data security and credibility, thereby improving the accuracy of abnormal behavior detection, and does not require intrusion into the virtual machine detection, does not require occupation of virtual machine resources, and improves detection performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In the accompanying drawings of the embodiments of the present disclosure:

[0014] Figure 1 An application scenario architecture diagram provided for an embodiment of the present disclosure;

[0015] Figure 2 A flowchart of an abnormal behavior detection method provided in an embodiment of the present disclosure;

[0016] Figure 3 An interactive flow chart of abnormal behavior detection and processing provided by an embodiment of the present disclosure;

[0017] Figure 4 A block diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0018] In order to enable those skilled in the art to better understand the technical solutions of the present disclosure, the embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0019] The present disclosure will be described more fully hereinafter with reference to the accompanying drawings, but the illustrated embodiments may be embodied in different forms, and the present disclosure should not be construed as limited to the embodiments set forth below. Rather, these embodiments are provided so that the present disclosure will be thorough and complete and will fully understand the scope of the present disclosure to those skilled in the art.

[0020] The accompanying drawings of the embodiments of the present disclosure are used to provide a further understanding of the embodiments of the present disclosure and constitute a part of the specification. Together with the detailed embodiments, they are used to explain the present disclosure and do not constitute a limitation of the present disclosure. The above and other features and advantages will become more apparent to those skilled in the art by describing the detailed embodiments with reference to the accompanying drawings.

[0021] The present disclosure may be described with reference to plan views and / or cross-sectional views by way of ideal schematic views of the present disclosure. Therefore, the exemplary illustrations may be modified according to manufacturing techniques and / or tolerances.

[0022] In the absence of conflict, the various embodiments of the present disclosure and the various features therein may be combined with each other.

[0023] The terms used in this disclosure are only used to describe specific embodiments and are not intended to limit the disclosure. As used in this disclosure, the term "and / or" includes any and all combinations of one or more related enumerated items. As used in this disclosure, the singular forms "a" and "the" are also intended to include plural forms, unless the context clearly indicates otherwise. As used in this disclosure, the terms "comprising" and "made of" specify the presence of the features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups thereof.

[0024] Unless otherwise defined, all terms (including technical and scientific terms) used in this disclosure have the same meanings as those commonly understood by those skilled in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly defined in this disclosure.

[0025] The present disclosure is not limited to the embodiments shown in the drawings, but includes modifications of the configurations formed based on the manufacturing process. Therefore, the regions illustrated in the drawings have schematic properties, and the shapes of the regions shown in the drawings illustrate the specific shapes of the regions of the elements, but are not intended to be limiting.

[0026] Based on the development of virtualization technology, computing resources can be provided to users through the virtualization management platform. However, users may use computing resources for other abnormal behaviors, affecting the service quality of the cloud platform and the stability of the physical host.

[0027] In some related technologies, abnormal behavior is usually identified by detecting the central processing unit (CPU) and memory usage of the virtual machine. This method only considers the dynamic behavior of the CPU or memory usage when the virtual machine is running. However, an attacker may tamper with the operating system image of the virtual machine and implant an abnormal program. In this case, the initial state of the virtual machine when it is started is illegal, and the runtime resource usage may evade detection through some means. For example, the attacker can lower the process priority of the abnormal program to hide the CPU abnormality, resulting in the failure of the anomaly detection based on resource thresholds in the related technology. In addition, anomaly detection based on runtime resource usage is overly dependent on the exposure of the attacker's behavior, which may lead to delayed anomaly detection and defense.

[0028] In addition, related technologies can also determine whether a virtual machine is being used maliciously by detecting the hardware fingerprint corresponding to the virtual machine (such as the Media Access Control Address (MAC), motherboard serial number, etc.) or operating environment characteristics (such as specific process detection, registry entries). This method is easy to forge or modify. For example, an attacker may manually modify the MAC address of the virtual machine or delete the virtualization component-related processes, causing the detection to fail.

[0029] In some related technologies, a monitoring agent can be deployed in a virtual machine to perform anomaly detection. However, this intrusive detection method will occupy the computing resources of the virtual machine and may be terminated and become ineffective due to being controlled by an abnormal program.

[0030] An anomaly detection method is provided in an embodiment of the present disclosure. A virtual machine is deployed corresponding to a virtualization management platform. The first disk information of the virtual machine is obtained through the virtualization management platform, and the first disk information is compared with the pre-recorded second disk information of the virtual machine. When the comparison is determined to be inconsistent, it is determined that the virtual machine has abnormal behavior against the operating system. In this way, since the disk information of different operating system types is different, abnormal behavior that implements illegal or attack activities by tampering with the operating system can be detected by verifying the consistency of the current first disk information of the virtual machine and the pre-recorded second disk information, thereby realizing abnormal behavior detection at the operating system level. In addition, the pre-recorded second disk information is obtained and detected by the virtualization management platform, and there is no need to build an additional detection program into the virtual machine. The second disk information is also pre-recorded in the data reporting center corresponding to the virtualization management platform, which can ensure data security, thereby improving the accuracy and performance of detection, and improving the bottom-level and anti-circumvention capabilities of detection.

[0031] For ease of understanding, the following first describes the application scenarios of the embodiments of the present disclosure. Figure 1 , which is a schematic diagram of an application scenario in an embodiment of the present disclosure.

[0032] The application scenarios of the embodiments of the present disclosure are mainly oriented to cloud computing platforms and distributed network architectures built based on virtualization technology. They can also support enterprise data centers, hybrid clouds, and edge computing scenarios, etc., without limitation. Figure 1 As shown, the distributed network architecture in the embodiment of the present disclosure may include a physical host, a virtual machine, a virtualization management platform, and a data reporting center. Based on the distributed virtualization cluster, multiple physical hosts may be interconnected through a network to form a unified resource pool. Specifically:

[0033] 1) The physical host is a physical server that can serve as a computing node in the virtualization management platform and is mainly responsible for computing functions.

[0034] 2) The virtualization management platform is a system used to manage and monitor the virtualized environment, mainly providing support for virtual machine lifecycle management, computing virtualization, storage virtualization, and network virtualization.

[0035] Furthermore, in the embodiments of the present disclosure, the virtualization management platform can customize a universal interface to adapt to different application scenarios and improve compatibility. In one possible embodiment, the virtualization management platform and the physical host communicate through a set application programming interface (API). For example, the virtualization management platform communicates with the physical host through the API to request the disk information of the virtual machine, and can receive the disk information returned by the physical host. Then, through comparison, if it is determined that abnormal behavior exists, the corresponding processing strategy can be implemented for the virtual machine with abnormal behavior through the virtualization layer interface. Among them, in the embodiments of the present disclosure, the ability to parse virtual disk information is supported, and the disk format, file system type, etc. can be parsed from the disk information to compare with the pre-recorded disk information to determine whether abnormal behavior occurs. The disk parsing process can be executed in an independent thread of the physical host, without perception inside the virtual machine, and non-invasive virtual machine detection also improves detection performance.

[0036] In one possible embodiment, a customized interface can also be established between the virtualization management platform and the data reporting center, and the two can communicate based on the interface, and can be compatible with different virtualization management platforms and application scenarios. For example, in the embodiment of the present disclosure, the disk information configured when the virtual machine is created can be pre-stored in the data reporting center as baseline information. When performing abnormal behavior detection, the virtualization management platform can obtain the pre-recorded baseline disk information from the data reporting center and perform a consistency comparison. In this way, the pre-recorded virtual machine disk information can be obtained directly from the bottom layer of the virtualization management platform, rather than relying on the virtual machine's internal agent or memory introspection technology to obtain it from the virtual machine, thereby ensuring the security, reliability and tamper-proofness of the disk information used as baseline information.

[0037] The virtualization management platform can also integrate a security operation and maintenance system. When abnormal behavior is detected in a virtual machine, it can trigger an automated processing process for the abnormal virtual machine and display abnormal prompt information on the interface. For example, the abnormal prompt information includes a prompt message that the virtual machine's disk format is inconsistent with expectations, processing operation log information for the abnormal virtual machine, etc. There are no restrictions on this.

[0038] 3) A virtual machine represents the desktop used by the user. The creation, migration, and monitoring of virtual machines can be achieved through a virtualization management platform, and the virtual machine can be sent to the user's device through a physical host for use.

[0039] 4) The data reporting center represents a platform for collecting data information of physical hosts and virtual machines and for visually displaying it. For example, in the embodiment of the present disclosure, the operating system type, disk information, etc. configured by the virtual machine can be pre-recorded in the data reporting center.

[0040] In the embodiment of the present disclosure, for a virtualized environment, for example, an attacker may tamper with the Windows operating system into a Linux operating system by replacing the operating system image, so as to achieve abnormal behavior executed in the Linux operating system. The disk file system type of the Windows operating system is usually the New Technology File System (NTFS) format, and the disk file system type of the Linux operating system is usually the XFS format. The attacker tampered with the operating system type to cause the NTFS format to be converted to the XFS format. In this way, in the embodiment of the present disclosure, by comparing the current disk information of the virtual machine with the pre-recorded benchmark disk information, the detection of abnormal behavior of tampering with the operating system layer is achieved, providing a more accurate and effective abnormality detection method.

[0041] See Figure 2 As shown, an embodiment of the present disclosure provides a flowchart of a method for detecting abnormal behavior, the method comprising:

[0042] Step S201: When a preset detection condition is met, obtain the current first disk information of the virtual machine, wherein the first disk information is associated with the operating system type.

[0043] In the embodiment of the present disclosure, disk information may include information such as disk format, file system type, file system identifier, etc., and there is no limitation on this. The disk information of different operating system types is usually different. Among them, the disk format usually refers to the initialization process of the storage medium so that data can be stored thereon. The process includes selecting a file system and other possible settings, and focuses more on how the virtual hard disk as a file is managed and stored by the virtualization management platform. The file system represents the way data is organized and managed on the virtual disk.

[0044] Taking the file system type in the disk information as an example, when creating a virtual machine, it is necessary to configure the operating system of the virtual machine. Usually, the file system types of different operating system types are different. For example, the file system types of the Windows operating system include NTFS, and the file system types of the Linux operating system include XFS. Of course, an operating system type can support multiple file system types. Usually, after the operating system type of the virtual machine is configured, its default file system type can be automatically selected and set, or it can be configured according to needs. However, after the file system type of the operating system is configured, the file system type cannot usually be directly changed without reinstalling the operating system. For example, some attack behaviors can only be executed in a specific operating system environment, and the original operating system when the virtual machine is created does not support it. At this time, the attacker may carry out the attack by tampering with the operating system of the virtual machine. Tampering with the operating system will cause the file system type to change. Therefore, in the embodiment of the present disclosure, abnormal behavior detection of the virtual machine operating system layer can be achieved by detecting the file system type in the disk information.

[0045] Step S202: obtaining the second disk information of the virtual machine from the data reporting center, wherein the second disk information represents the reference disk information configured when the virtual machine is created and is pre-recorded in the data reporting center.

[0046] In some possible embodiments, in the embodiments of the present disclosure, when a virtual machine is created, relevant information of the virtual machine can be configured and stored in a data reporting center. Storing it in the data reporting center can improve information security and tamper-proofing. Taking the configuration of disk information when a virtual machine is created as an example, when the virtual machine is initialized, registered and created, the second disk information of the virtual machine is obtained, and the second disk information is uploaded to the data reporting center for storage through a preset interface between the virtualization management platform and the data reporting center. The second disk information may include operating system type, file system type, file system identifier, creation time, etc.

[0047] Step S203: Compare the first disk information and the second disk information.

[0048] Step S204: When it is determined that the first disk information and the second disk information are inconsistent, it is determined that the virtual machine has abnormal behavior with respect to the operating system.

[0049] In the embodiment of the present disclosure, the virtualization management platform obtains the pre-recorded second disk information as the benchmark disk information from the data reporting center to ensure the accuracy of the benchmark disk information, thereby comparing the current first disk information of the virtual machine with the second disk information. When there is inconsistency, it is determined that there is abnormal behavior against the operating system in the virtual machine, thereby realizing abnormal detection of tampering of the operating system image in the virtual machine, improving the underlying performance and performance of the detection, and eliminating the need to invade the detection program inside the virtual machine. Instead, the virtualization management platform performs abnormal detection, and the benchmark disk information is also obtained from the data reporting center, thereby improving anti-interference and accuracy.

[0050] In some possible embodiments, several possible preset detection conditions are provided when performing abnormality detection. Specifically, for satisfying the preset detection condition in step S201 above, the following possible implementations are included:

[0051] 1) When a preset time interval is reached, it is determined that a preset detection condition is met.

[0052] For example, the preset time interval is thirty minutes, and the virtual management platform can obtain the first disk information of the virtual machine through the physical host every thirty minutes and perform abnormality detection.

[0053] In the embodiments of the present disclosure, relevant personnel can be supported to modify the preset time interval according to needs, and dynamic modification of the preset time interval can also be supported. For example, when a virtual machine is detected to have other possible abnormal behaviors, the time interval for abnormal detection of the virtual machine can be shortened. For example, after abnormal behavior of the virtual machine is detected and processed, abnormal behavior detection can continue to be performed on the virtual machine, and the time interval for abnormal detection of the virtual machine can be shortened.

[0054] In this way, in the embodiments of the present disclosure, the accuracy and performance of anomaly detection can be improved by periodically performing anomaly detection.

[0055] 2) When it is determined that the CPU usage of the virtual machine is greater than the preset threshold within the preset time period, it is determined that the preset detection condition is met.

[0056] For example, if the CPU usage of a virtual machine exceeds 20% within 10 seconds, it indicates a sudden increase in CPU usage and a possible attack risk. In this case, the detection condition is determined to be met.

[0057] In this way, in the embodiment of the present disclosure, real-time detection can be triggered when the CPU usage suddenly increases, which can improve the timeliness of detection and provide better security.

[0058] Of course, when any one or all of the above implementation modes are met, it is determined that the preset detection conditions are met, and other possible detection conditions can also be set according to needs. For example, if it is detected that the memory usage of the virtual machine is abnormal, there may also be an attack risk, and it is determined that the detection conditions are met. This is not limited in the embodiments of the present disclosure.

[0059] In the embodiment of the present disclosure, after determining that the virtual machine has abnormal behavior against the operating system, several possible exception handling methods are provided, specifically:

[0060] In some possible embodiments, the virtualization management platform performs exception processing on the virtual machine by calling a preset first interface based on any of the following operations: reducing the operating frequency of the CPU of the virtual machine; controlling the virtual machine to be unavailable; reducing the network traffic or network speed of the virtual machine.

[0061] For example, the CPU operating frequency of the virtual machine can be reduced to a set frequency value. In this way, by reducing the CPU operating frequency, the speed and workload of the virtual machine's task processing can be reduced, and its resource usage can be reduced, thereby limiting attacks from abnormal behavior.

[0062] In this way, in the embodiment of the present disclosure, when it is determined that abnormal behavior exists, abnormal processing can be performed based on the set processing operation to limit the abnormal behavior and improve security.

[0063] In some possible embodiments, resource usage information of a virtual machine is obtained; a processing strategy for the virtual machine is determined based on the resource usage information; and exception processing is performed on the virtual machine based on the processing strategy.

[0064] The resource usage information may include, for example, CPU usage, graphics processing unit (GPU) usage, traffic usage, memory resource usage, etc., and is not limited thereto.

[0065] Regarding determining a processing strategy for the virtual machine based on resource usage information in this step, a possible implementation is:

[0066] Based on resource usage information, determine the target risk level of abnormal behavior; based on the mapping relationship between preset risk levels and processing strategies, determine the processing strategy corresponding to the target risk level.

[0067] For example, risk levels can be divided into high risk, medium risk, and low risk. Different risk levels correspond to different processing strategies. For example, the processing strategy for high risk is to control the virtual machine to shut down or become unavailable, the processing strategy for medium risk is to reduce the CPU operating frequency and reduce the network speed, and the processing strategy for low risk is to reduce the network speed.

[0068] Furthermore, the target risk level may be determined, for example, by resource usage information and a correspondingly set judgment threshold. For another example, a model may be pre-trained, which is used to make predictions based on the input resource usage information to determine the target risk level.

[0069] Regarding determining the processing strategy for the virtual machine based on the resource usage information in this step, another possible embodiment is: the resource usage information is CPU usage, and determining the processing strategy for the virtual machine based on the resource usage information includes:

[0070] 1) When the CPU usage is greater than a first threshold, determining a processing strategy for the virtual machine: controlling the virtual machine to be forcibly shut down and switching the disk of the virtual machine to a read-only mount state.

[0071] Among them, the CPU usage rate is greater than the first threshold, which may indicate that the abnormal behavior has a greater impact on resource usage. In the embodiment of the present disclosure, in this case, the virtual machine can be shut down immediately and the disk can be switched to a read-only mount state to quickly and effectively handle the abnormal behavior. Among them, the read-only mount state of the disk means that the storage device (such as a hard disk, USB drive, partition, etc.) is mounted in read-only mode to a mount point of the file system, which means that users or system processes can access the data on the storage device, but cannot modify, delete or write new data to it, which can protect the data from being deliberately tampered with.

[0072] 2) When the CPU usage is less than or equal to the first threshold and greater than the second threshold, the processing strategy for the virtual machine is determined as: controlling the network traffic speed of the virtual machine to be less than the speed threshold and controlling the CPU resource allocation to be reduced to a third threshold.

[0073] 3) When the CPU usage is less than or equal to the second threshold and greater than the fourth threshold, the processing strategy for the virtual machine is determined as: after waiting for a set period of time, the CPU resource allocation of the control virtual machine is reduced to the fifth threshold, wherein the fifth threshold is less than or equal to the fourth threshold, and the third threshold is less than the fourth threshold.

[0074] For example, the first threshold is 80%, the second threshold is 70%, the third threshold is 30%, the fourth threshold is 50%, and the fifth threshold is 50%. The preset duration is 5 minutes. The sliding window method can be used to calculate the CPU usage to avoid false triggering caused by instantaneous peaks, thereby determining the corresponding processing strategy based on the judgment of the corresponding threshold interval of the CPU usage.

[0075] Furthermore, in the embodiment of the present disclosure, the virtualization management platform can send the processing policy to the physical host, and the physical host performs corresponding exception processing on the virtual machine by calling the virtualization command. Specifically, different virtualization commands can be used to implement it according to different virtualization environments, and there is no restriction on this. For example, for VMware environment, it is implemented through the govc tool: #CPU frequency reduction command (limited to 50% quota) govc vm.change-vm$vm_uuid-cpus.shares=5000; #Forced shutdown command govc vm.power-off-force$vm_uuid; for another example, for KVM / QEMU environment, it is implemented through the virsh command: #CPU frequency reduction command virsh schedinfo$vm_uuid--set vcpu_quota=50%; #Forced shutdown command virsh destroy$vm_uuid; for another example, for Hyper-V environment, it is implemented through PowerShell command: #CPU frequency reduction command Set-VMProcessor-VMName$vm_uuid-MaximumPercent 50;#Force shutdown command Stop-VM-Name$vm_uuid–Force.

[0076] In this way, in the embodiment of the present disclosure, whether there is abnormal behavior is determined by comparing static disk information. When it is determined that there is abnormal behavior, the processing strategy for the abnormal behavior can be determined in combination with the resource usage information. The corresponding hierarchical processing strategy can be determined by risk level judgment or based on CPU usage, thereby achieving accurate detection of abnormal behavior at the operating system layer of the virtual machine and resource-level restriction of abnormal behavior. The execution of abnormal behavior can be restricted from the resource scheduling level, effectively reducing the occupation of illegal resource computing power, and improving the rationality of resource utilization of the virtualization management platform.

[0077] It should be noted that the embodiments of the present disclosure do not limit the exception handling strategy, which can be set according to needs. In addition, in the embodiments of the present disclosure, the handling strategy can also be determined based on resource usage information and combined with other behavior information.

[0078] In addition, in the embodiments of the present disclosure, a whitelist mechanism may be provided to reduce mishandling. In one possible embodiment, when it is determined that a virtual machine does not belong to the whitelist according to a preset whitelist, exception handling is performed on the virtual machine.

[0079] For example, a whitelist of virtual machines can be pre-configured and saved in the physical host. For example, the universally unique identifier (UUID) of the whitelisted virtual machines can be configured in the whitelistvm.txt file in the shared directory of the physical host. This allows the virtual machines in the whitelist to be skipped without performing exception processing on them.

[0080] In some possible embodiments, after exception handling is performed on a virtual machine, the handling result may be reported to a data reporting center. For example, the handling result may include whether the exception handling is successful, time information, abnormal behavior related information, and the like.

[0081] In some possible embodiments, specific examples are used for illustration below. Figure 3 As shown, the embodiment of the present disclosure provides an interactive flow chart of abnormal behavior detection and processing, including:

[0082] (1) Virtual machine initialization registration phase:

[0083] Step S301: Register virtual machine information.

[0084] In the embodiment of the present disclosure, when the virtual machine starts, the physical host can read the disk information of the virtual machine through the host agent, for example, calling the blkid command to view the partition information of the virtual machine, the file system type on the partition, identification information, etc.

[0085] Step S302: The virtualization management platform stores the baseline disk information of the virtual machine to the data reporting center.

[0086] For example, the host agent can record information such as the operating system type, file system type, creation time, and file system identifier by calling a preset interface, and can transmit data in JSON format. In one possible embodiment, the data fields of the reference disk information include:

[0087] {"vm_uuid":"Virtual machine unique identifier", / / Virtual machine identifier

[0088] "os_type":"Windows / Linux", / / Operating system type

[0089] "disk_format":"NTFS / XFS / ext4", / / File system type / disk file format

[0090] "fs_id":"File system UUID", / / File system identifier

[0091] "partition_table":"MBR / GPT", / / Partition table type

[0092] "create_time": "ISO8601 timestamp" / / creation time}

[0093] (2) Abnormal behavior detection stage:

[0094] Step S303: When a preset detection condition is met, the virtualization management platform requests the physical host to obtain the current first disk information of the virtual machine.

[0095] For example, detection may be performed periodically at preset time intervals. For another example, detection may be performed when it is determined that the CPU usage of the virtual machine is greater than a preset threshold within a preset time period.

[0096] Step S304: The physical host returns the first disk information to the virtualization management platform.

[0097] Step S305: The virtualization management platform obtains the benchmark disk information from the data reporting center.

[0098] Step S306: The virtualization management platform determines a comparison result between the first disk information and the reference disk information.

[0099] In addition, in the embodiment of the present disclosure, the virtualization management platform can also send the first disk information to the data reporting center, and the data reporting center can compare the first disk information with the benchmark disk information and return the comparison result to the virtualization management platform. There is no restriction on this.

[0100] (3) Abnormal behavior handling stage

[0101] Step S307: When it is determined that the virtual machine has abnormal behavior against the operating system, the virtualization management platform sends a processing strategy to the physical host.

[0102] In the embodiment of the present disclosure, the processing strategy may also be pre-stored in the data reporting center, and then the virtualization management platform may obtain it from the data reporting center and send it to the physical host.

[0103] For example, taking the determination of the target risk level of abnormal behavior and performing exception handling as an example, the data format of the handling strategy may include:

[0104] {"vm_uuid":"Virtual machine unique identifier", / / Virtual machine identifier

[0105] "detection_time": "Detection timestamp", / / detection time

[0106] "risk_level":"Risk level (high risk / medium risk / low risk)", / / risk level

[0107] "recommended_action": "Recommended action (frequency reduction / shutdown / current limiting)", / / Processing strategy

[0108] "policy_id":"Association policy ID" / / Processing policy identifier}

[0109] Step S308: The physical host performs exception processing on the virtual machine according to the processing policy.

[0110] Step S309: The physical host returns the processing result to the virtualization management platform.

[0111] Step S310: The virtualization management platform reports the abnormal behavior event log to the data reporting center.

[0112] For example, the abnormal behavior event log may include the virtual machine identifier, the reason for determining the abnormal behavior, the processing result, etc., so that relevant personnel can be aware of the abnormal situation of the virtual machine based on the log.

[0113] Step S311: The data reporting center returns log reception confirmation response information to the virtualization management platform.

[0114] The abnormal behavior detection method in the embodiment of the present disclosure is not limited to the application field and scenario. For example, it can be applied to the security protection of cloud computing platforms, such as detecting users who maliciously tamper with virtual machine images (such as replacing them with mining-specific systems) in public cloud / private cloud environments to prevent the abuse of computing resources. For another example, it can be applied to compliance audits of enterprise virtualization data centers, such as monitoring virtual machine images developed by internal employees or third parties to ensure that they are consistent with the reported configuration (such as prohibiting unauthorized replacement of operating systems). For another example, it can be applied to the security reinforcement of edge computing nodes, such as preventing malicious virtual machines from occupying local computing power by tampering with images in edge servers.

[0115] In the embodiment of the present disclosure, the consistency comparison between the first disk information of the virtual machine and the reference disk information can be used to detect whether the virtual machine has abnormal behavior, and abnormal behavior at the operating system level can be effectively identified. The processing strategy can be determined in combination with resource usage information, and the virtual machine can be handled abnormally. This can limit the resource usage of abnormal behavior and achieve more accurate resource management and control.

[0116] Figure 4 A block diagram of an electronic device provided in an embodiment of the present disclosure.

[0117] Reference Figure 4An embodiment of the present disclosure provides an electronic device, which includes: at least one processor 401; at least one memory 402, and one or more I / O interfaces 403, connected between the processor 401 and the memory 402; wherein the memory 402 stores one or more computer programs that can be executed by the at least one processor 401, and the one or more computer programs are executed by the at least one processor 401 so that the at least one processor 401 can perform the above-mentioned abnormal behavior detection method.

[0118] Each module in the above-mentioned electronic device can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each of the above modules.

[0119] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the above-mentioned abnormal behavior detection method. The computer-readable storage medium may be a volatile or non-volatile computer-readable storage medium.

[0120] An embodiment of the present disclosure also provides a computer program product, including computer-readable code, or a non-volatile computer-readable storage medium carrying computer-readable code. When the computer-readable code runs in a processor of an electronic device, the processor in the electronic device executes the above-mentioned abnormal behavior detection method.

[0121] Among them, the processor is a device with data processing capabilities, including but not limited to the central processing unit (CPU); the memory is a device with data storage capabilities, including but not limited to random access memory (RAM, more specifically such as SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), and flash memory (FLASH); the I / O interface (read-write interface) is connected between the processor and the memory, which can realize information exchange between the memory and the processor, including but not limited to the data bus (Bus), etc.

[0122] Those skilled in the art will appreciate that all or some of the steps, systems, and functional modules / units in the apparatus disclosed above may be implemented as software, firmware, hardware, or a suitable combination thereof.

[0123] In hardware implementations, the division between functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component may have multiple functions, or one function or step may be performed by several physical components in cooperation.

[0124] Some or all of the physical components may be implemented as software executed by a processor, such as a central processing unit (CPU), a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory (FLASH) or other disk storage; compact disc (CD-ROM), digital versatile disc (DVD) or other optical disc storage; magnetic cassettes, tapes, disk storage or other magnetic storage; any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0125] The present disclosure has disclosed example embodiments, and although specific terms are employed, they are used and should be interpreted only in a general illustrative sense and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly indicated, features, characteristics, and / or elements described in conjunction with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in conjunction with other embodiments. Therefore, it will be understood by those skilled in the art that various changes in form and detail may be made without departing from the scope of the present disclosure as set forth in the appended claims.

Claims

1. A method for detecting abnormal behavior, applied to a virtualization management platform, wherein a virtual machine is deployed on the virtualization management platform, comprising: When a preset detection condition is met, obtaining current first disk information of the virtual machine, wherein the first disk information is associated with an operating system type; Acquire second disk information of the virtual machine from a data reporting center, wherein the second disk information represents baseline disk information configured when the virtual machine is created and is pre-recorded in the data reporting center; comparing the first disk information and the second disk information; When it is determined that the first disk information and the second disk information are inconsistent, it is determined that the virtual machine has abnormal behavior with respect to the operating system.

2. The method according to claim 1, wherein The predetermined detection conditions are met, including any of the following: When a preset time interval is reached, determining that a preset detection condition is satisfied; When it is determined that the CPU usage of the virtual machine is greater than a preset threshold within a preset time period, it is determined that the preset detection condition is met.

3. The method according to claim 1, wherein After determining that the virtual machine has abnormal behavior with respect to the operating system, the method further includes: The virtualization management platform performs exception handling on the virtual machine based on any of the following operations by calling a preset first interface: Reducing the operating frequency of the CPU of the virtual machine; controlling the virtual machine to be unavailable; Reduce the network traffic or speed of the virtual machine.

4. The method according to claim 1, wherein After determining that the virtual machine has abnormal behavior with respect to the operating system, the method further includes: Obtaining resource usage information of the virtual machine; determining a processing strategy for the virtual machine based on the resource usage information; According to the processing strategy, the virtual machine is subjected to exception processing.

5. The method according to claim 4, wherein Determining a processing strategy for the virtual machine based on the resource usage information includes: determining a target risk level of the abnormal behavior based on the resource usage information; According to the preset mapping relationship between risk levels and processing strategies, the processing strategy corresponding to the target risk level is determined.

6. The method according to claim 4, wherein: The resource usage information is a CPU usage rate, and determining a processing strategy for the virtual machine based on the resource usage information includes: When the CPU usage is greater than a first threshold, determining a processing strategy for the virtual machine: controlling the virtual machine to be forcibly shut down and switching the disk of the virtual machine to a read-only mount state; When the CPU usage is less than or equal to the first threshold and greater than the second threshold, determining a processing strategy for the virtual machine as follows: controlling the network traffic speed of the virtual machine to be less than the speed threshold and controlling the CPU resource allocation to be reduced to a third threshold; When the CPU usage is less than or equal to the second threshold and greater than the fourth threshold, the processing strategy for the virtual machine is determined as: after waiting for a set period of time, the CPU resource allocation of the control virtual machine is reduced to a fifth threshold, wherein the fifth threshold is less than or equal to the fourth threshold, and the third threshold is less than the fourth threshold.

7. The method according to any one of claims 3 to 6, wherein: Before performing exception handling on the virtual machine, the method further includes: According to a preset whitelist, it is determined that the virtual machine does not belong to the whitelist.

8. An electronic device comprising a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements the abnormal behavior detection method according to any one of claims 1 to 7.

9. A computer-readable medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the abnormal behavior detection method according to any one of claims 1 to 7 is implemented.

10. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the abnormal behavior detection method according to any one of claims 1 to 7 is implemented.