Malicious access information detection method and device

By generating system operation information by acquiring target status information and associated information of server components, the problem of low accuracy in malicious access information detection in existing technologies is solved, and more efficient malicious access detection is achieved.

CN120880779AActive Publication Date: 2025-10-31LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202511362190.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-23
Publication Date
2025-10-31
Estimated Expiration
2045-09-23

AI Technical Summary

Technical Problem

Existing technologies have low accuracy in detecting malicious access information to servers, are susceptible to malicious programs tampering with system logs, and are prone to misjudgment or missed detection based on single business data.

Method used

By acquiring target status information of server components, detecting the correlation information between components, and generating system operation information, the system can monitor the real operating status of the server business system and avoid the impact of malicious programs tampering with log records.

Benefits of technology

It improves the accuracy of detecting malicious access information on servers, avoids errors in detection results caused by system log tampering, and enhances the reliability and accuracy of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880779A_ABST
    Figure CN120880779A_ABST
Patent Text Reader

Abstract

The invention discloses a malicious access information detection method and device, and relates to the technical field of server security, and the method comprises the steps: obtaining target state information of a plurality of server components deployed in a server; detecting target associated information of the plurality of server components according to the target state information; generating system operation information of the service system according to the target associated information and the target state information; the malicious access information of the server is detected according to the system operation information, and the malicious access information is used for indicating the malicious access condition of the server in the service handling process, so that the technical problem of relatively low detection accuracy of the malicious access information of the server in the related technology can be solved; the technical effect of improving the detection accuracy of the malicious access information of the server is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of server security technology, and in particular to methods and apparatus for detecting malicious access information. Background Technology

[0002] In the context of current digital transformation and the booming development of cloud computing, servers, as critical infrastructure for data processing and storage, face unprecedented security challenges. To ensure the secure operation of servers and the security and reliability of the business environment, security testing of servers is necessary to prevent malicious access. Currently, a common approach is malicious access detection based on single business data recorded in the server's business system logs (such as cache access time, memory timings, number of accessing processes, etc.). This involves detecting malicious access operations in the current business system based on sudden changes in a specific business data point. However, this method has significant limitations. Firstly, data in the server's business system is at risk of being tampered with; malicious programs can circumvent detection by modifying system logs. Secondly, fault detection based on single business data is prone to randomness, leading to false positives or false negatives. In summary, the accuracy of malicious access detection for servers using current technologies is relatively low. Summary of the Invention

[0003] This application provides a method and apparatus for detecting malicious access information, so as to at least solve the problem of low accuracy in detecting malicious access information on servers in related technologies.

[0004] This application provides a method for detecting malicious access information, including:

[0005] The system acquires target status information of multiple server components deployed on the server, wherein the server components are those used by the server during business processing, and the target status information indicates the component operation status of the corresponding server component; detects target association information of multiple server components based on the target status information, wherein the target association information indicates the association relationship between the operation status of multiple server components in the business system running on the server during business processing; generates system operation information of the business system based on the target association information and the target status information, wherein the system operation information indicates the operation status of the business system during business processing; and detects malicious access information of the server based on the system operation information, wherein the malicious access information indicates the malicious access received by the server during business processing.

[0006] This application also provides a device for detecting malicious access information, including:

[0007] The acquisition module is used to acquire target status information of multiple server components deployed in the server, wherein the server components are the components used by the server in the business processing process, and the target status information is used to indicate the component operation status of the corresponding server component.

[0008] The first detection module is used to detect target association information between multiple server components based on the target status information, wherein the target association information is used to indicate the association relationship of the running status of multiple server components in the business system running on the server during the business processing process;

[0009] The first generation module is used to generate system operation information of the business system based on the target association information and the target status information, wherein the system operation information is used to indicate the operation status of the business system during the business processing process;

[0010] The second detection module is used to detect malicious access information of the server based on the system operation information, wherein the malicious access information is used to indicate the malicious access situation that the server has been subjected to during business processing.

[0011] This application also provides an electronic device, including: a memory for storing a computer program; and a processor for implementing the steps of any of the above-described methods for detecting malicious access to information when executing the computer program.

[0012] This application also provides a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, it implements the steps of any of the above-described methods for detecting malicious access to information.

[0013] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the above-described methods for detecting malicious access to information.

[0014] This application obtains target status information representing the operational status of server components, and detects target correlation information between the operational statuses of server components during business processing based on the target status information. Then, it generates system operation information of the business system based on the target status information and target correlation information. This achieves the realization that the collected operational status of server components reflects the true operational status of the current business process within the server business system. This avoids the impact of malicious programs in the business system tampering with the system operation information recorded in the system logs on the detection results. Therefore, it can solve the technical problem of low detection accuracy of malicious access information to servers in related technologies, achieving the technical effect of improving the detection accuracy of malicious access information to servers. Attached Figure Description

[0015] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0016] Figure 1 This is a hardware structure block diagram of the malicious access information detection method according to an embodiment of this application;

[0017] Figure 2 This is a flowchart of a method for detecting malicious access information according to an embodiment of this application;

[0018] Figure 3 This is an optional attack detection flowchart according to an embodiment of this application;

[0019] Figure 4 This is a schematic diagram of an optional attack detection system according to an embodiment of this application;

[0020] Figure 5 This is a structural block diagram of a malicious access information detection device according to an embodiment of this application. Detailed Implementation

[0021] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0022] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0023] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0024] The specific application environment architecture or specific hardware architecture on which the detection method for malicious access information depends is described here.

[0025] The methods and embodiments provided in this application can be executed on a server device or a similar computing device. Taking running on a server device as an example, Figure 1 This is a hardware structure block diagram of a malicious access information detection method according to an embodiment of this application. Figure 1 As shown, the server device may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The server device may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the server equipment described above. For example, the server equipment may also include components that are more... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0026] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the malicious access information detection method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thus implementing the above-described method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to server devices via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0027] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the server device. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0028] The embodiments of this application provide a method for detecting malicious access information, and the method is described in detail below in conjunction with the execution flow of the method for detecting malicious access information.

[0029] This embodiment provides a method for detecting malicious access information. Figure 2 This is a flowchart of a method for detecting malicious access information according to an embodiment of this application, such as... Figure 2 As shown, the method includes the following steps:

[0030] Step S202: Obtain target status information of multiple server components deployed in the server, wherein the server components are the components used by the server in the business processing process, and the target status information is used to indicate the component operation status of the corresponding server component;

[0031] Step S204: Detect target association information of multiple server components based on the target status information, wherein the target association information is used to indicate the association relationship of the operating status of multiple server components in the business system running on the server during the business processing process;

[0032] Step S206: Generate system operation information of the business system based on the target association information and the target status information, wherein the system operation information is used to indicate the operation status of the business system during the business processing process;

[0033] Step S208: Detect malicious access information of the server based on the system operation information, wherein the malicious access information is used to indicate malicious access to the server during business processing.

[0034] Through the above steps, by acquiring target status information representing the operational status of server components, and by detecting target correlation information between the operational statuses of server components during business processing based on the target status information, system operation information of the business system is generated based on the target status information and target correlation information. This achieves the realization that the collected operational status of server components reflects the true operational status of the current business process within the server business system, thereby avoiding the impact of malicious programs in the business system tampering with the system operation information recorded in the system logs on the detection results. Therefore, it can solve the technical problem of low detection accuracy of malicious access information of servers in related technologies, and achieve the technical effect of improving the low detection accuracy of malicious access information of servers.

[0035] The aforementioned method for detecting malicious access information can be applied, but is not limited to, to control components that manage and control the operating status of a server. These control components can be, but are not limited to, a baseboard management controller deployed within the server to control the operating status of server components, or other components with server component operating status control functions. This control component directly collects target status information of the server components during server operation. Specifically, this can be achieved by deploying sensors on the server components to collect component operating status data. These sensors are directly connected to the control component used to execute the malicious access information detection method of this embodiment, thereby preventing the target status information of the server components from being maliciously tampered with by malicious programs implanted in the business system.

[0036] In the embodiment provided in step S202, the server component is the component used by the business system in the server when handling business. The server component provides hardware support for the business system to handle business. For example, the server component may include, but is not limited to, the central processing unit, memory, power supply, etc. deployed in the server. This solution does not limit this.

[0037] Optionally, in this embodiment, the operating status of the server components can reflect the current business carrying capacity of the server business system. That is, when the business running on the server business system changes, the server components will change accordingly. For example, when the number of data processing threads in the business system decreases but the number of memory access threads increases, the operating power of the central processing unit will decrease accordingly, and the surface temperature of the central processing unit will also decrease accordingly. At the same time, the operating power of the memory will increase, and the surface temperature of the memory will rise accordingly.

[0038] Optionally, in this embodiment, the target state information is the physical state exhibited by the server component during operation. The target state information may include, but is not limited to, power consumption, electromagnetic radiation, time delay, sound, temperature, etc. For example, taking the central processing unit as the server component, the target state information may be the surface temperature of the central processing unit, the electromagnetic radiation of the area where the central processing unit is located, the power consumption of the central processing unit, etc. This solution does not limit this.

[0039] Optionally, in this embodiment, the target state information of the server component may be, but is not limited to, information representing the current physical state of the server component collected by a signal collector deployed in the server. The signal collector is directly connected to the control component used to run the malicious access information detection method of this embodiment via a connection link, thereby preventing malicious programs implanted in the server's business system from tampering with the information. In this embodiment, the method for obtaining target state information may involve the following steps: obtaining initial state information of a first component in the server within a first time period prior to the current time period, wherein the first component is a component used to satisfy the basic operating functions of the server, and the initial state information is used to indicate the physical operating state of the first component at the corresponding time; calculating the amount of information change between the initial state information at adjacent times within the first time period; if the amount of information change is greater than or equal to a target threshold, constructing an information change curve of the initial state information of the first component within the first time period in chronological order; predicting a second time period for collecting the operating information of the server component based on the operating state change characteristics of the first component indicated in the information change curve; and predicting a target acquisition accuracy for the operating information of the server component based on the operating state change characteristics of the first component indicated in the information change curve; and controlling a signal collector on the server component to collect the target state information within the second time period according to the target acquisition accuracy. Through the above embodiments, by detecting the operating status of the basic components required for server operation, it is possible to initially determine whether malicious access operations may occur on the server based on the operating status of the basic components. Then, based on the operating status change characteristics of the first component within a first time period, the outbreak time of malicious access operations is predicted, thereby predicting the information collection time and accuracy for multiple server components. This avoids the huge load pressure caused by real-time, relatively heavy information detection and processing operations, improving detection efficiency. Furthermore, the method of predicting the second time period for collecting the operating information of the server component based on the operating status change characteristics of the first component indicated by the information change curve can be, but is not limited to, inputting the operating status change characteristics of the first component into a first prediction model to obtain the second time period for collecting the operating characteristics of the server component output by the first prediction model. The first prediction model records the conversion relationship between the operating status change characteristics and the state information collection time period. The method of predicting the target collection accuracy of the operating information of the server component based on the operating status change characteristics of the first component indicated by the information change curve can be: inputting the operating status change characteristics into a second prediction model to obtain the target collection accuracy output by the second prediction model. The second prediction model records the conversion relationship between the operating status change characteristics and the collection accuracy.

[0040] In the embodiment provided in step S204, the purpose of detecting target association information based on target status information is to determine the component running status of the server component whose running status is most relevant to the current real running status of the server business system among multiple server components. That is, to avoid the impact of component running status being tampered with or the use of component status information that is unrelated to the running status of the server business system on the construction of system running information. Therefore, in this embodiment, target association information can reflect the correlation between the running status of each server component and the current real business status of the server business system.

[0041] Optionally, in this embodiment, the method for detecting target association information of multiple server components based on target state information can be as follows: Feature extraction is performed on the target state information to obtain target operating features for each server component. The target state information records the component operating states of the server component at multiple moments within a target time period prior to the current moment. The target operating features indicate the changes in the component operating states of the server component within the target time period. Based on the matching relationship between the target operating features of each server component and reference operating features of corresponding server components under multiple preset services, target services that match the target operating state of the current server component are selected from multiple preset services. The target service is the service with the highest matching degree between the reference operating features and the target operating features among the multiple preset services. The reference operating features are the changes in the operating state of the current server component during the operation of the corresponding preset service. The service similarity of the target services corresponding to multiple server components is calculated. The service similarity is converted into operating state association parameters for the corresponding server components. The target association information includes the operating state association parameters, which indicate the degree of association between the operating state of the server component and the current actual business state of the server business system. In this embodiment, the business currently being handled by the server's business system is first predicted based on the component operating state change characteristics of each server component. This enables the prediction of business handling information of the business system based on the operating state of a single component. Then, by calculating the similarity relationship between the target businesses handled by the business system predicted using the operating state of each component, the relationship between the operating characteristics of the server components is predicted, thereby improving the accuracy of the generated target association information.

[0042] In the embodiment provided in step S206, the method for generating system operation information based on target association information and target status information may be: inputting target association information and target status information into a target prediction model to obtain system operation information output by the target prediction model, wherein the target prediction model records the conversion relationship between association information, status information and system operation information.

[0043] Optionally, in this embodiment of the application, the method of generating system operation information based on target association information and target status information can also be as follows: assign a corresponding status weight to the target status information of each server component according to the degree of correlation between the operation status indicated by the target association information, wherein the higher the degree of correlation between the current server component's operation status indicated by the target association information and the operation status of other server components among multiple server components, the greater the assigned status weight; use the status weight to weight and merge the target status information to obtain system operation information.

[0044] In the embodiment provided in step S208, the method of detecting malicious access information based on system operation information can be to input the system operation information into an information prediction model to obtain the malicious access information output by the information prediction model, wherein the information prediction model records the conversion relationship between system operation information and malicious access information.

[0045] As an optional implementation, detecting target association information of multiple server components based on the target state information includes:

[0046] The target running data sequence of the server component is constructed according to the chronological order of multiple running data of the server component within a target time period before the current time. The running data is used to indicate the running status of the server component at the corresponding time. The target status information includes the running data of the server component within the target time period.

[0047] Feature extraction is performed on each of the target running data sequences to obtain the state transformation features of each of the server components within the target time period, wherein the state transformation features are used to indicate the temporal changes in the running state of the server components within the target time period;

[0048] Feature correlation detection is performed on the state transition features of the multiple server components to obtain the correlation parameters of the target state information of each server component. The correlation parameters are used to indicate the correlation between the current server component's operating state and the operating states of other server components among the multiple server components except the current server component during the business processing of the business system. The target correlation information includes the correlation parameters.

[0049] Optionally, in this embodiment, the method for detecting the feature correlation of multiple state transition features may be as follows: in the feature space of each of the multiple preset services, calculate the feature similarity between any current target state transition feature and a reference state transition feature other than the target state transition feature among the multiple state transition features, to obtain the initial similarity between the target state transition feature and the reference state transition feature in the feature space of each preset service; fuse the initial similarity of the target state transition feature in the feature space of the multiple preset services to obtain the target similarity between the target state transition feature and the reference transition feature, wherein the correlation parameter includes the target similarity.

[0050] By recording the operational data of server components over a period of time, a target operational data sequence is formed. Using time series analysis techniques, the changing patterns of hardware resource usage over time can be observed. In terms of effectiveness, constructing this operational data sequence helps analyze the long-term behavior of server components and identify potential anomalies.

[0051] As an optional implementation, constructing the target running data sequence of the server component based on the chronological order of multiple running data of the server component within a target time period prior to the current time includes:

[0052] Sort the multiple running data of each server component within the target time period before the current time according to the chronological order to obtain the initial running data sequence of the corresponding server component;

[0053] Determine the data mutation amount of each running data in the initial running data sequence, wherein the data mutation amount is used to indicate the difference between the current running data and the running data at adjacent time points;

[0054] Extract target running data from the initial running data sequence whose data mutation amount is greater than or equal to the target threshold;

[0055] The data values ​​of the target running data in the initial running data sequence are adjusted according to the data difference between the reference running data in the initial running data sequence to obtain the target running data sequence, wherein the reference running data is the running data in the initial running data sequence that is adjacent to the target running data.

[0056] Optionally, in this embodiment, the data mutation amount can be, but is not limited to, using the signal entropy of each running data in the initial running data sequence. This information entropy reflects the data mutation amount of the current running data relative to other running data. The formula for calculating the information entropy can be... Here, P(Xi) represents the probability that the Xi-th data point in the sequence appears in the initial running sequence. A higher entropy value H(X) indicates greater randomness or uncertainty in the sequence; a lower entropy value indicates the presence of some regularity or abnormal concentration in the sequence. By calculating the information entropy of the initial running data sequence in this way, the abrupt changes in the running data at each moment in the initial running data sequence are objectively and accurately reflected, thereby filtering out abnormal noise signals in the initial running data sequence and ensuring the reliability of the data in the running data sequence.

[0057] Based on the above, by recording the operational data of server components over a period of time, a target operational data sequence is formed. Using time series analysis techniques, the changing patterns of hardware resource usage over time can be observed. Constructing this operational data sequence helps analyze the long-term behavior of server components. By removing abnormal data from the initial operational data sequence and compensating for the removed abnormal data with the time behavior of data transformation, the accuracy and reliability of the target operational data sequence are ensured.

[0058] As an optional implementation, generating the system operation information of the business system based on the target association information and the target status information includes:

[0059] Feature extraction is performed on the target state information to obtain the target operating features of each server component;

[0060] The weight parameters of each target operating feature are assigned according to the association parameters of the target status information. The association parameters are used to indicate the relationship between the operating status of the current server component and the operating status of other server components among the plurality of server components except the current server component during the business processing of the business system. The target association information includes the association parameters. The weight parameters are used to indicate the degree of influence of the corresponding target operating feature on the business system's execution status.

[0061] The target operating characteristics of multiple server components are weighted and summed using the weight parameters to obtain the system operating characteristics of the business system, wherein the system operating information includes the system operating characteristics.

[0062] Optionally, in the embodiments of this application, there is a positive proportional relationship between the weight parameter and the correlation parameter of the target state information. The greater the correlation indicated by the correlation parameter, the greater the weight parameter is assigned. The weight parameter represents the importance of the target operating feature of the corresponding server component. That is, the greater the weight parameter, the higher the proportion of the corresponding operating feature in the system operating information.

[0063] By quantifying the interdependencies between the states of different hardware components, the actual business processing status of the server business system can be reflected by the operating status of each server component. Then, weight parameters are assigned to the operating characteristics of the server components based on the correlation parameters. This enables the construction of system operating characteristics of the server business system based on the dependency relationship between the operating status of the components and the business status of the business system, thereby improving the accuracy and reliability of the system operating characteristics.

[0064] As an optional implementation, the step of detecting malicious access information to the server based on the system operation information includes:

[0065] The system operation information and the target operation information are matched, wherein the target operation information is used to indicate the system operation status of the server when it is maliciously accessed;

[0066] If the system operation information and the target operation information match, it is determined that the server is currently in a malicious access state.

[0067] Optionally, in this embodiment of the application, the target operation information is the system operation state under a known malicious access state attack. By matching the system operation information with multiple target operation information, the target operation information that completely matches the system operation state is filtered out from the multiple target operation information, and the malicious access state corresponding to the target operation information is determined as the malicious access state of the system at present.

[0068] By comparing the current system operation information with preset malicious access patterns, it is possible to determine whether malicious access exists. This matching process helps to quickly identify malicious access behavior and provides timely warnings for taking defensive measures.

[0069] As an optional implementation, after detecting malicious access information of the server based on the system operation information, the method further includes:

[0070] Based on the target status information, a target server component is selected from the plurality of server components, wherein the degree of influence of the component operation status of the target server component on the malicious access status of the server is greater than or equal to a preset threshold.

[0071] Target control information for the server is generated based on the current reference state information of the target server component, wherein the target control information is used to adjust the operating state of the plurality of server components deployed in the server;

[0072] Adjust the operating status of the multiple server components deployed in the server according to the state adjustment method indicated by the target control information.

[0073] Optionally, in this embodiment, the method of filtering target server components based on target state information may be as follows: Construct a target running data sequence for the server component based on the chronological order of multiple running data of the server component within a target time period prior to the current time. The running data indicates the running state of the server component at a corresponding time, and the target state information includes the running data of the server component within the target time period. Perform feature extraction on each target running data sequence to obtain state transformation features of each server component within the target time period. The state transformation features indicate the temporal changes in the running state of the server component within the target time period. Perform feature correlation detection between the state transformation features of multiple server components to obtain correlation parameters for the target state information of each server component. The correlation parameters indicate the correlation relationship between the running state of the current server component and the running states of other server components (excluding the current server component) during the business processing process in the business system. The target correlation information includes the correlation parameters. Determine the server component whose corresponding correlation parameter is greater than or equal to a target parameter threshold as the target server component.

[0074] Optionally, in this embodiment, the target control information and the current reference state information of the target server component have a corresponding relationship, that is, different reference state information corresponds to different target control information. Then, the operating state of the target server component is dynamically adjusted through the target control information, thereby preventing malicious attackers from launching side-channel attacks on the server based on the operating state of the target server component. This enables the dynamic generation of defense strategies against side-channel attacks based on the operating state of the service component, thus better mitigating attacks on the server system by malicious users.

[0075] Based on the above, threshold filtering technology is used to select target components from multiple server components that significantly impact malicious access. Target server component filtering helps focus monitoring of critical hardware resources, improving detection efficiency and reducing resource consumption. The generation of target control information enables immediate action upon detecting malicious access, adjusting server operating status, suppressing attack behavior, and quickly responding to malicious access detection by altering server hardware operating parameters and disrupting the attacker's side-channel exploitation chain.

[0076] As an optional implementation, the step of filtering the target server component from the plurality of server components based on the target status information includes:

[0077] The correlation degree is calculated for multiple target state information to obtain the state correlation degree corresponding to each target state information. The state correlation degree is used to indicate the degree of correlation between the component operation state of the server component indicated by the current target state information and the component operation state of other server components among the multiple server components except the current server component during the business process.

[0078] The server component corresponding to the target state information whose state correlation degree is greater than or equal to the target correlation degree threshold is determined as the target server component.

[0079] By quantifying the relationships between the states of different hardware components, we can reveal the collaborative patterns in the use of hardware resources. The calculation of state correlation helps to identify abnormal collaborations between hardware states, providing additional clues for the detection of malicious access. This helps to focus on monitoring and adjusting these key components in subsequent defense strategies, thereby improving the targeting and efficiency of defense measures.

[0080] As an optional implementation, generating the target control information of the server based on the current reference state information of the target server component includes:

[0081] The target control information corresponding to the reference state information is determined from the state information and control information that have a corresponding relationship.

[0082] As an optional implementation, obtaining the target status information of multiple server components deployed in the server includes:

[0083] The power consumption of the central processing unit is collected by a power consumption sensor deployed in the server according to a first signal acquisition accuracy, wherein the power consumption sensor is used to collect the operating power consumption of the central processing unit;

[0084] If the difference between the processor power consumption collected at adjacent times is greater than or equal to the target power consumption threshold, the power consumption sensor is controlled to collect the current target operating power consumption of the central processing unit according to the second signal acquisition accuracy, the power detector deployed in the server is controlled to collect the power supply of the memory according to the third signal acquisition accuracy, and the electromagnetic sensor deployed in the server is controlled to collect the electromagnetic radiation in the server according to the fourth signal acquisition accuracy. The second signal acquisition accuracy is higher than the first signal acquisition accuracy, and the second, third, and fourth signal acquisition accuracies all meet the signal acquisition accuracy conditions. The target status information includes the target operating power consumption, the power supply, and the electromagnetic radiation. The server components include the central processing unit and the memory.

[0085] Based on the above, using dynamic signal acquisition technology, when the CPU power consumption changes beyond a preset threshold, it automatically switches to a higher precision acquisition mode. By dynamically adjusting the signal acquisition precision, more detailed data can be obtained when power consumption is abnormal, which helps to analyze attack behavior more accurately. This dynamic signal acquisition mechanism can ensure that high-quality data is obtained at critical moments, improving the accuracy and timeliness of malicious access detection.

[0086] This application provides a side-channel attack detection and defense method based on BMC. Utilizing the hardware control capabilities of BMC, it uses BMC as a detection platform for multi-physical signal collaborative analysis. This solution primarily addresses the following issues of existing technologies:

[0087] 1. Software-layer signal tampering vulnerability: Traditional solutions (such as those based on operating system performance counters) are susceptible to kernel-level data forgery. Attackers can load malicious drivers to tamper with software-layer signals such as CPU cache hit rate and branch prediction error rate, causing the detection system to malfunction.

[0088] This invention utilizes a server hardware-level interface via the BMC for data acquisition and communication, establishing a dedicated signal source for the BMC and creating an immutable data source. This prevents attackers from interfering with data source acquisition through the system. Simultaneously, data analysis is performed within the BMC without interfering with the operating system.

[0089] 2. Inability to proactively block attacks: Existing technologies only implement the "detection-alarm" process and cannot prevent attacks during the attack window, which means that critical information may still be stolen.

[0090] This invention uses BMC to implement hardware-level control such as fan control, power consumption control, and voltage glitches control to obfuscate server operation, interfere with side-channel attack signal sources, and suppress side-channel attacks.

[0091] 3. High misjudgment rate due to single signal source: It relies on a single signal and is easily affected by environmental interference.

[0092] This invention employs multiple data sources and BMC in-band collaboration to easily acquire hardware-level side-channel evaluation data such as power consumption, voltage, and temperature. Through multi-data collaborative analysis, it can more accurately identify side-channel attack characteristics.

[0093] 4. Undetectable during startup: Traditional security solutions rely on the OS for verification, which cannot detect attacks before the OS starts up.

[0094] This application embodiment enables 24 / 7 attack detection through BMC management, independent of the system. Furthermore, traditional system-based data acquisition and analysis methods cannot identify side-channel attacks targeting the system before startup (such as during the BIOS boot phase), while BMC-based methods do not depend on system startup and can perform data acquisition and analysis before boot.

[0095] Figure 3 This is an optional attack detection flowchart according to an embodiment of this application, such as... Figure 3 As shown, the side-channel attack detection and defense method based on BMC utilizes the hardware control capabilities of BMC, using BMC as a detection platform for multi-physical signal collaborative analysis. Its main workflow is as follows:

[0096] This invention mainly involves the innovative integration of four key steps: data acquisition, signal preprocessing and feature processing, attack detection and analysis, and dynamic defense strategy execution.

[0097] 1. In the data acquisition stage, this application proposes a spatiotemporal collaborative acquisition method for multiple physical quantities based on BMC, which solves the problem of signal tampering through the following innovative design:

[0098] A hardware signal fusion architecture is designed to acquire signals that are difficult to obtain at the software layer using hardware-level protocol interfaces. This is achieved through the BMC and server built-in interfaces, enabling the acquisition of hardware signals without expansion, and obtaining physical quantity data through different hardware-level protocols. The CPU microcode-level power gradient sequence from the PECI interface, the transient response waveform of the memory VRM (Voltage Regulator Module) from the PMBus interface, and the electromagnetic sensor spectrum data connected to SMBus are synchronized in the hardware clock domain. The time of the three signals is aligned using the BMC's built-in time domain. This implements a multi-signal acquisition and cross-protocol synchronization mechanism (compared to existing single data sources).

[0099] The design incorporates dynamic acquisition and control technology. When the power consumption gradient changes abruptly during PECI acquisition (defined as a power consumption change >5%), the high-precision sampling mode of VMR / electromagnetic input is activated within the BMC band. The default frequency is 1kHz. Through dynamic acquisition and control, the VMR / electromagnetic acquisition frequency can be increased to 10MHz during abnormal power consumption changes, significantly improving detection sensitivity.

[0100] 2. Signal preprocessing and feature processing:

[0101] The signal preprocessing section processes the multi-signal source data acquired in the previous step to provide a standardized data format for subsequent physical signal analysis, thereby improving the efficiency of data analysis.

[0102] Multi-hardware data source synchronizers are used because the time intervals of multiple signal sources often differ and require unified processing. The acquisition methods for power consumption, voltage, and electromagnetic signals vary, resulting in significant time differences (e.g., power consumption at the millisecond level, electromagnetic signals at the nanosecond level). A unified timestamp is generated using the BMC's internal clock to mark the sampling points, achieving time alignment across multiple signal sources.

[0103] The data processing module removes abnormal noise data through techniques such as entropy calculation and peak detection. Simultaneously, it employs data fusion and dimensionality reduction methods, using the industry-standard multi-source data fusion and dimensionality reduction method—Principal Component Analysis (PCA)—to reduce data dimensionality and integrate the summarized data. This is an industry-standard practice and is not within the scope of this application; therefore, it will not be described in detail.

[0104] Attack detection and analysis:

[0105] The attack detection and analysis module collects multi-source signals (such as CPU power consumption, voltage spikes, and electromagnetic features) at the physical hardware layer. It performs real-time synchronization, noise reduction, and feature extraction through the BMC firmware layer. For the processed data, a dual-mode analysis engine is used: the pre-processed data is compared with 20 types of known attack features (such as voltage spike waveform templates and electromagnetic spectrum fingerprints) using hardware acceleration. If a match is found, the data is immediately transferred to the dynamic defense strategy execution module. At the same time, the module analyzes the spatiotemporal correlation features of multiple signals through a probabilistic evaluation model based on hardware behavior. Based on the analysis and matching results, the module calls the dynamic defense strategy for execution.

[0106] We employ a lightweight LSTM model to analyze threats and continuously optimize the attack signature database.

[0107] By using parallel rule base matching and evaluation models, the defense execution strategy is dynamically adjusted to prevent false alarms from single-judgment logic and effectively improve defense accuracy.

[0108] Dynamic defense strategy execution:

[0109] The dynamic defense strategy execution module, based on attack detection and analysis results, directly manipulates the server's underlying hardware components through the BMC's hardware-level control capabilities to achieve multi-dimensional coordinated interference against side-channel attacks. This module uses the BMC's hardware control capabilities to directly operate the server's underlying hardware (such as the CPU voltage regulator, memory controller, and clock generator) to achieve precise responses.

[0110] The core defense methods are voltage spike injection, spoofed memory refresh, and clock jitter control. This invention innovatively targets side-channel attack scenarios, combining multiple signal sources to simultaneously execute interference of different dimensions. Furthermore, it achieves direct control via the BMC without OS intervention, effectively reducing latency. It proposes a combined execution strategy that dynamically selects voltage spikes, spoofed memory refresh, and clock jitter control based on the attack type, and presents a dynamic defense strategy directly controlled by the BMC hardware. The core of this invention lies in the OS-free hardware control link and the attack-feature-adaptive dynamic defense strategy, which can adjust the defense strength according to the system state.

[0111] Figure 4 This is a schematic diagram of an optional attack detection system according to an embodiment of this application, such as... Figure 4 As shown, the attack detection system mainly includes the following modules: multi-source signal acquisition module, signal preprocessing module, security analysis engine, and dynamic obfuscation control module.

[0112] Multi-source signal acquisition module: This module achieves coordinated acquisition of multiple data sources through a dedicated signal routing circuit for the BMC. An example is shown below:

[0113] Bus interfaces (such as PECI or PMBus interfaces) are included. The PECI interface directly connects to the CPU microcode unit, acquiring the core power consumption gradient sequence at a 1ms cycle (accuracy ±1mV). The PMBus controller monitors the phase current ripple (100MHz bandwidth) of the voltage regulator module (VRM) and captures transient response waveforms. The SMBus expansion channel connects to the onboard electromagnetic sensor array, acquiring spectrum data (0.1-1GHz). It supports a dynamic acquisition and control technology, employing event-triggered multi-level sampling: the normal data acquisition method is 1kHz polling (power consumption <2W). When a power consumption mutation is detected, an attack detection mode is used, reconfiguring the ADC clock divider electromagnetic sampling rate to 10MHz to improve data sampling and acquisition efficiency.

[0114] Signal preprocessing module: This module uses compensation techniques to address signal timing inconsistencies. It applies delays to high-frequency signals and uses analog interpolation for low-frequency signals, outputting a time-aligned multi-signal source matrix. PCA analysis is then performed on the multi-signal source matrix to complete the data preprocessing.

[0115] For each server component, a sequence of running data from multiple moments within a target time period prior to the current moment is used. An entropy filter is employed to avoid abnormal data sources, and the signal entropy within milliseconds is calculated. This information entropy reflects the magnitude of data mutation relative to other running data at the current moment. The formula for calculating information entropy can be... , where P(X i ) represents the Xth element in the sequence. i The probability of a data point appearing in the sequence is expressed by its entropy value H(X). A higher entropy value indicates greater randomness or uncertainty in the sequence; a lower entropy value indicates a certain regularity or abnormal concentration in the sequence. By calculating the information entropy of the running data sequence in this way, the abrupt changes of the running data at each moment in the running data sequence can be objectively and accurately reflected, thereby filtering out abnormal noise signals in the initial running data sequence and ensuring the reliability of the data in the running data sequence.

[0116] Security Analysis Engine: A dual-mode analysis engine is used for side-channel attack analysis. Preprocessed data is compared with known attack characteristics (such as voltage spike waveform templates and electromagnetic spectrum fingerprints) using hardware acceleration. If a match is found, the data is immediately transferred to the dynamic defense strategy execution module. Simultaneously, a probabilistic evaluation model based on hardware behavior analyzes the spatiotemporal correlation characteristics of multiple signals, and the dynamic defense strategy is executed based on the analysis and matching results. During analysis, AI-assisted lightweight LSTM is used to optimize the feature library and evaluation model, improving system accuracy.

[0117] Dynamic Obfuscation Control Module: This module adaptively adjusts system operating parameters to interfere with side-channel attacks from different signal sources. Its core lies in a multi-dimensional collaborative interference mechanism that simultaneously applies differentiated interference to different signal sources, including those related to power consumption, timing, and electromagnetic interference. Furthermore, it dynamically adjusts the defense strength based on the detected attack type and the current system load. Notably, this defense method bypasses the operating system, controlling the underlying hardware through the BMC, effectively improving anti-interference capabilities and reducing latency. Its specific implementation method is as follows:

[0118] Employing an attack-adaptive defense strategy, this approach dynamically selects differentiated combinations of voltage spikes, pseudo-memory refreshes, and clock jitter based on the attack types identified by the security analysis engine, achieving three-dimensional coordinated interference. For example, it increases voltage spike injection by 15mV and clock jitter offset by +5%. A dynamic scheduling algorithm adaptively adjusts different obfuscation parameters based on the current system state, system load, and environmental noise, optimizing defense strength in real time to achieve the best obfuscation effect.

[0119] Meanwhile, by directly manipulating obfuscated instructions through the BMC's exclusive interface and data bus, the operating system is bypassed, reducing response latency. Using offset injection within the safe range that conforms to security specifications (such as voltage at the mV level and clock offset at the ms level), it will not affect the system, and the defense action cannot be circumvented by the software layer.

[0120] This application embodiment realizes multi-source signal collaborative acquisition and dynamic obfuscation control through the BMC hardware exclusive interface, and constructs a full-cycle side-channel defense system from signal anti-tampering, real-time attack suppression to startup phase monitoring. For the first time in the server field, it realizes hardware-level active security protection without OS intervention, improves the accuracy of attack detection, and provides a method for servers to interfere with attacks and suppress side-channel attacks.

[0121] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0122] Embodiments of this application also provide a device for detecting malicious access to information. Figure 5 This is a structural block diagram of a malicious access information detection device according to an embodiment of this application, such as... Figure 5 As shown, the device includes:

[0123] The acquisition module is used to acquire target status information of multiple server components deployed in the server, wherein the server components are the components used by the server in the business processing process, and the target status information is used to indicate the component operation status of the corresponding server component.

[0124] The first detection module is used to detect target association information of multiple server components based on the target status information, wherein the target association information is used to indicate the association relationship between the operating status of multiple server components in the business system running on the server during the business processing process;

[0125] The first generation module is used to generate system operation information of the business system based on the target association information and the target status information, wherein the system operation information is used to indicate the operation status of the business system during the business processing process;

[0126] The second detection module is used to detect malicious access information of the server based on the system operation information, wherein the malicious access information is used to indicate the malicious access situation that the server has been subjected to during business processing.

[0127] The above device acquires target status information representing the operational status of server components, and detects target correlation information between the operational statuses of server components during business processing based on the target status information. Then, it generates system operation information of the business system based on the target status information and target correlation information. This achieves the realization that the collected operational status of server components reflects the true operational status of the current business process within the server business system. This avoids the impact of malicious programs in the business system tampering with the system operation information recorded in the system logs on the detection results. Therefore, it can solve the technical problem of low detection accuracy of malicious access information to servers in related technologies, achieving the technical effect of improving the detection accuracy of malicious access information to servers.

[0128] Optionally, the first detection module includes:

[0129] A construction unit is configured to construct a target running data sequence for the server component based on the chronological order of multiple running data of the server component within a target time period prior to the current time. The running data is used to indicate the running status of the server component at a corresponding time, and the target status information includes the running data of the server component within the target time period.

[0130] The first extraction unit is used to extract features from each of the target running data sequences to obtain the state transformation features of each of the server components within the target time period, wherein the state transformation features are used to indicate the temporal changes in the running state of the server components within the target time period.

[0131] The detection unit is used to perform feature correlation detection on the state transition features of the multiple server components to obtain the correlation parameters of the target state information of each server component. The correlation parameters are used to indicate the correlation between the current server component's operating state and the operating states of other server components among the multiple server components except the current server component during the business processing of the business system. The target correlation information includes the correlation parameters.

[0132] Optionally, the building unit is used for:

[0133] Sort the multiple running data of each server component within the target time period before the current time according to the chronological order to obtain the initial running data sequence of the corresponding server component;

[0134] Determine the data mutation amount of each running data in the initial running data sequence, wherein the data mutation amount is used to indicate the difference between the current running data and the running data at adjacent time points;

[0135] Extract target running data from the initial running data sequence whose data mutation amount is greater than or equal to the target threshold;

[0136] The data values ​​of the target running data in the initial running data sequence are adjusted according to the data difference between the reference running data in the initial running data sequence to obtain the target running data sequence, wherein the reference running data is the running data in the initial running data sequence that is adjacent to the target running data.

[0137] Optionally, the first generation module includes:

[0138] The second extraction unit is used to extract features from the target state information to obtain the target operating features of each server component;

[0139] The allocation unit is used to allocate a weight parameter for each target operating feature according to the association parameter of the target status information. The association parameter is used to indicate the association relationship between the operating status of the current server component and the operating status of other server components among the plurality of server components during the business processing of the business system. The target association information includes the association parameter. The weight parameter is used to indicate the degree of influence of the corresponding target operating feature on the characterization of the business system's execution status of the business.

[0140] The first calculation unit is used to perform a weighted summation calculation on the target operating characteristics of multiple server components using the weight parameters to obtain the system operating characteristics of the business system, wherein the system operating information includes the system operating characteristics.

[0141] Optionally, the second detection module includes:

[0142] A matching unit is used to match the system operation information with target operation information, wherein the target operation information is used to indicate the system operation status of the server when it is maliciously accessed;

[0143] The first determining unit is used to determine that the server is currently in a malicious access state when the system operation information and the target operation information match.

[0144] Optionally, the device further includes:

[0145] The filtering module is used to filter out a target server component from the plurality of server components based on the target status information after detecting malicious access information of the server based on the system operation information, wherein the degree of influence of the component operation status of the target server component on the characterization of the malicious access status of the server is greater than or equal to a preset threshold.

[0146] The second generation module is used to generate target control information for the server based on the current reference state information of the target server component, wherein the target control information is used to adjust the operating state of the plurality of server components deployed in the server;

[0147] The adjustment module is used to adjust the operating status of the plurality of server components deployed in the server according to the state adjustment method indicated by the target control information.

[0148] Optionally, the filtering module includes:

[0149] The second calculation unit is used to perform correlation calculation on multiple target state information to obtain the state correlation degree corresponding to each target state information. The state correlation degree is used to indicate the degree of correlation between the component operation state of the server component indicated by the current target state information and the component operation state of other server components among the multiple server components except the current server component during the business processing of the business system.

[0150] The second determining unit is used to determine the server component corresponding to the target state information whose state correlation degree is greater than or equal to the target correlation degree threshold as the target server component.

[0151] Optionally, the second generation module includes:

[0152] The third determining unit is used to determine the target control information corresponding to the reference state information from the state information and control information that have a corresponding relationship.

[0153] Optionally, the acquisition module includes:

[0154] The acquisition unit is used to acquire the processor power consumption of the central processing unit by a power consumption sensor deployed in the server according to a first signal acquisition accuracy, wherein the power consumption sensor is used to acquire the operating power consumption of the central processing unit.

[0155] The control unit is configured to, when the difference between the processor power consumption collected at adjacent times is greater than or equal to a target power consumption threshold, control the power consumption sensor to collect the current target operating power consumption of the central processing unit at a second signal acquisition precision, control the power detector deployed in the server to collect the power supply of the memory at a third signal acquisition precision, and control the electromagnetic sensor deployed in the server to collect the electromagnetic radiation in the server at a fourth signal acquisition precision. The second signal acquisition precision is higher than the first signal acquisition precision, and the second, third, and fourth signal acquisition precisions all meet the signal acquisition precision conditions. The target status information includes the target operating power consumption, the power supply, and the electromagnetic radiation. The server components include the central processing unit and the memory.

[0156] For a description of the features in the embodiment corresponding to the malicious access information detection device, please refer to the relevant description in the embodiment corresponding to the malicious access information detection method, which will not be repeated here.

[0157] Embodiments of this application also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any of the above embodiments of the malicious access information detection method.

[0158] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above embodiments of the malicious access information detection method when it is run.

[0159] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0160] The embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above embodiments of the malicious access information detection method.

[0161] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in any of the above embodiments of the malicious access information detection method.

[0162] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0163] The above provides a detailed description of a method and apparatus for detecting malicious access information provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only intended to help understand the method and its core ideas. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from its principles, and these improvements and modifications also fall within the protection scope of the claims of this application.

Claims

1. A method for detecting malicious access to information, characterized in that, include: Obtain target status information of multiple server components deployed in the server, wherein the server components are the components used by the server in the business processing process, and the target status information is used to indicate the component operation status of the corresponding server component; Target association information of multiple server components is detected based on the target status information, wherein the target association information is used to indicate the association relationship between the operating status of multiple server components in the business system running on the server during the business processing process; The system operation information of the business system is generated based on the target association information and the target status information, wherein the system operation information is used to indicate the operation status of the business system during the business processing process; The system operation information is used to detect malicious access information of the server, wherein the malicious access information is used to indicate the malicious access situation that the server has been subjected to during business processing.

2. The method according to claim 1, characterized in that, The step of detecting target association information of multiple server components based on the target state information includes: The target running data sequence of the server component is constructed according to the chronological order of multiple running data of the server component within a target time period before the current time. The running data is used to indicate the running status of the server component at the corresponding time. The target status information includes the running data of the server component within the target time period. Feature extraction is performed on each of the target running data sequences to obtain the state transformation features of each of the server components within the target time period, wherein the state transformation features are used to indicate the temporal changes in the running state of the server components within the target time period; Feature correlation detection is performed on the state transition features of the multiple server components to obtain the correlation parameters of the target state information of each server component. The correlation parameters are used to indicate the correlation between the current server component's operating state and the operating states of other server components among the multiple server components except the current server component during the business processing of the business system. The target correlation information includes the correlation parameters.

3. The method according to claim 2, characterized in that, The step of constructing the target running data sequence of the server component based on the chronological order of multiple running data within a target time period prior to the current time includes: Sort the multiple running data of each server component within the target time period before the current time according to the chronological order to obtain the initial running data sequence of the corresponding server component; Determine the data mutation amount of each running data in the initial running data sequence, wherein the data mutation amount is used to indicate the difference between the current running data and the running data at adjacent time points; Extract target running data from the initial running data sequence whose data mutation rate is greater than or equal to the target threshold; The data values ​​of the target running data in the initial running data sequence are adjusted according to the data difference between the reference running data in the initial running data sequence to obtain the target running data sequence, wherein the reference running data is the running data in the initial running data sequence that is adjacent to the target running data.

4. The method according to claim 1, characterized in that, The step of generating system operation information for the business system based on the target association information and the target status information includes: Feature extraction is performed on the target state information to obtain the target operating features of each server component; The weight parameters of each target operating feature are assigned according to the association parameters of the target status information. The association parameters are used to indicate the relationship between the operating status of the current server component and the operating status of other server components among the plurality of server components except the current server component during the business processing of the business system. The target association information includes the association parameters. The weight parameters are used to indicate the degree of influence of the corresponding target operating feature on the business system's execution status. The target operating characteristics of multiple server components are weighted and summed using the weight parameters to obtain the system operating characteristics of the business system, wherein the system operating information includes the system operating characteristics.

5. The method according to claim 1, characterized in that, The step of detecting malicious access information to the server based on the system operation information includes: The system operation information and the target operation information are matched, wherein the target operation information is used to indicate the system operation status of the server when it is maliciously accessed; If the system operation information and the target operation information match, it is determined that the server is currently in a malicious access state.

6. The method according to claim 1, characterized in that, After detecting malicious access information of the server based on the system operation information, the method further includes: Based on the target status information, a target server component is selected from the plurality of server components, wherein the degree of influence of the component operation status of the target server component on the malicious access status of the server is greater than or equal to a preset threshold. Target control information for the server is generated based on the current reference state information of the target server component, wherein the target control information is used to adjust the operating state of the plurality of server components deployed in the server; Adjust the operating status of the multiple server components deployed in the server according to the state adjustment method indicated by the target control information.

7. The method according to claim 6, characterized in that, The step of selecting the target server component from the plurality of server components based on the target status information includes: The correlation degree is calculated for multiple target state information to obtain the state correlation degree corresponding to each target state information. The state correlation degree is used to indicate the degree of correlation between the component operation state of the server component indicated by the current target state information and the component operation state of other server components among the multiple server components except the current server component during the business process. The server component corresponding to the target state information whose state correlation degree is greater than or equal to the target correlation degree threshold is determined as the target server component.

8. The method according to claim 7, characterized in that, The step of generating target control information for the server based on the current reference state information of the target server component includes: The target control information corresponding to the reference state information is determined from the state information and control information that have a corresponding relationship.

9. The method according to claim 1, characterized in that, The acquisition of target status information of multiple server components deployed in the server includes: The power consumption of the central processing unit is collected by a power consumption sensor deployed in the server according to a first signal acquisition accuracy, wherein the power consumption sensor is used to collect the operating power consumption of the central processing unit; If the difference between the processor power consumption collected at adjacent times is greater than or equal to the target power consumption threshold, the power consumption sensor is controlled to collect the current target operating power consumption of the central processing unit according to the second signal acquisition accuracy, the power detector deployed in the server is controlled to collect the power supply of the memory according to the third signal acquisition accuracy, and the electromagnetic sensor deployed in the server is controlled to collect the electromagnetic radiation in the server according to the fourth signal acquisition accuracy. The second signal acquisition accuracy is higher than the first signal acquisition accuracy, and the second, third, and fourth signal acquisition accuracies all meet the signal acquisition accuracy conditions. The target status information includes the target operating power consumption, the power supply, and the electromagnetic radiation. The server components include the central processing unit and the memory.

10. A device for detecting malicious access to information, characterized in that, include: The acquisition module is used to acquire target status information of multiple server components deployed in the server, wherein the server components are the components used by the server in the business processing process, and the target status information is used to indicate the component operation status of the corresponding server component. The first detection module is used to detect target association information of multiple server components based on the target status information, wherein the target association information is used to indicate the association relationship between the operating status of multiple server components in the business system running on the server during the business processing process; The first generation module is used to generate system operation information of the business system based on the target association information and the target status information, wherein the system operation information is used to indicate the operation status of the business system during the business processing process; The second detection module is used to detect malicious access information of the server based on the system operation information, wherein the malicious access information is used to indicate the malicious access situation that the server has been subjected to during business processing.

Citation Information

Patent Citations

  • Real-time monitoring system for cloud computing server room

    CN118509248A

  • Calculation Internet traffic processing method and system

    CN118740518A

  • Fault prediction method and device of server, storage medium and electronic equipment

    CN119440954A

  • Method and device for testing temperature control performance of server

    CN119690764A

  • Inter-core communication method, system and device based on heterogeneous asymmetric processor and medium

    CN120277022A