Method and apparatus for detecting malicious access to information

By acquiring the status and association information of server components to generate system operation information, the problem of low accuracy in detecting malicious access information in existing technologies is solved, and more accurate malicious access information detection is achieved.

CN120880779BActive Publication Date: 2025-12-12LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511362190.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-23
Publication Date
2025-12-12
Estimated Expiration
2045-09-23

AI Technical Summary

Technical Problem

Existing technologies have low accuracy in detecting malicious access information to servers and are easily affected by malicious programs tampering with system logs, leading to false positives or false negatives.

Method used

By acquiring the target status information of multiple server components deployed in the server, detecting the correlation information between components, and generating system operation information to reflect the real operating status of the business system, malicious access information can be detected.

Benefits of technology

It improves the accuracy of detecting malicious access information on servers, avoids the impact of system log tampering on detection results, and achieves more accurate identification of malicious access information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880779B_ABST
    Figure CN120880779B_ABST
Patent Text Reader

Abstract

The application discloses a malicious access information detection method and device, and relates to the technical field of server security. The method comprises the following steps: obtaining target state information of a plurality of server components deployed in a server; detecting target correlation information of the plurality of server components according to the target state information; generating system running information of a business system according to the target correlation information and the target state information; and detecting malicious access information of the server according to the system running information. The malicious access information is used for indicating malicious access conditions of the server in a business handling process. The method can solve the technical problem of low detection accuracy of the malicious access information of the server in related technologies, and achieves the technical effect of improving the detection accuracy of the malicious access information of the server.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of server security, and particularly relates to a malicious access information detection method and device. BACKGROUND

[0002] Under the background of current digital transformation and the vigorous development of cloud computing, servers, as the key infrastructure for data processing and storage, are facing unprecedented security challenges. In order to ensure the safe operation of the server and the safe and reliable business handling environment, it is necessary to perform security detection on the server to avoid malicious access to the server. The current commonly used method is malicious access detection based on single business handling data (such as cache access time, memory timing, access process quantity, etc.) recorded in the system log of the server business system, that is, whether there is a malicious access operation in the current business system is detected according to the mutation of a certain business handling data of the server business system. However, this method has great limitations. On the one hand, the data in the business system of the server is at risk of being tampered with, and related malicious programs can avoid the discovery of malicious access events by tampering with the system log. In addition, the fault detection based on single business data has contingency, and redundant false positives or false negatives may occur. In summary, the detection accuracy of malicious access information of the server in the related art is low. SUMMARY

[0003] The present application provides a malicious access information detection method and device to at least solve the problem of low detection accuracy of malicious access information of the server in the related art.

[0004] The present application provides a malicious access information detection method, comprising:

[0005] Obtaining target state information of a plurality of server components deployed in a server, wherein the server components are components used by the server in a business handling process, and the target state information is used to indicate the component running state of the corresponding server component; detecting target association information of a plurality of server components according to the target state information, wherein the target association information is used to indicate the association relationship between the running states of a plurality of server components in a business handling process of a business system running on the server; generating system running information of the business system according to the target association information and the target state information, wherein the system running information is used to indicate the running condition of the business system in a business handling process; and detecting malicious access information of the server according to the system running information, wherein the malicious access information is used to indicate the malicious access condition of the server in a business handling process.

[0006] The present application also provides a malicious access information detection device, comprising:

[0007] obtaining a target state information of a plurality of server components deployed in a server, wherein the server components are components used by the server in a service handling process, and the target state information is used to indicate a component running state of the corresponding server component;

[0008] detecting a target association information between the plurality of server components according to the target state information, wherein the target association information is used to indicate an association relationship between the running states of the plurality of server components in the service handling process of a service system running on the server;

[0009] generating system running information of the service system according to the target association information and the target state information, wherein the system running information is used to indicate a running condition of the service system in the service handling process;

[0010] detecting malicious access information of the server according to the system running information, wherein the malicious access information is used to indicate a malicious access condition of the server in the service handling process.

[0011] The application further provides an electronic device, comprising a memory for storing a computer program and a processor for executing the computer program to implement the steps of the malicious access information detection method.

[0012] The application further provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the malicious access information detection method.

[0013] The application further provides a computer program product, comprising a computer program, and the computer program is executed by a processor to implement the steps of the malicious access information detection method.

[0014] According to the application, the target state information reflecting the component running state of the server components is obtained, and the target association information between the component running states of the server components in the service handling process is detected according to the target state information, and then the system running information of the service system is generated according to the target state information and the target association information, so that the real running state of the server service system in the current service handling process is reflected based on the collected component running state of the server components, thereby avoiding the influence of the tampering of the system running information of the system log record by the malicious program in the service system on the detection result, and thus the technical problem of low detection accuracy of the malicious access information of the server in the related art is solved, and the technical effect of improving the detection accuracy of the malicious access information of the server is achieved. Attached Figure Description

[0015] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0016] Figure 1 This is a hardware structure block diagram of the malicious access information detection method according to an embodiment of this application;

[0017] Figure 2 This is a flowchart of a method for detecting malicious access information according to an embodiment of this application;

[0018] Figure 3 This is an optional attack detection flowchart according to an embodiment of this application;

[0019] Figure 4 This is a schematic diagram of an optional attack detection system according to an embodiment of this application;

[0020] Figure 5 This is a structural block diagram of a malicious access information detection device according to an embodiment of this application. Detailed Implementation

[0021] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0022] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0023] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0024] In combination with a specific application environment architecture or a specific hardware architecture on which the detection method of malicious access information is executed, the specific application environment architecture or the specific hardware architecture is described herein.

[0025] The method embodiments provided in the embodiments of the present application can be executed in a server device or similar computing device. Taking the case of running on a server device, Figure 1 is a hardware structure block diagram of the detection method of malicious access information in the embodiments of the present application. As shown in Figure 1 , the server device can include one or more (only one is shown in Figure 1 ) processor 102 (the processor 102 can include but not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the above-mentioned server device can further include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that Figure 1 the structure shown is only schematic, which does not limit the structure of the above-mentioned server device. For example, the server device can further include more or less components than those shown in Figure 1 , or have a different configuration from Figure 1 .

[0026] The memory 104 can be used to store computer programs, such as software programs of application software and modules, such as the computer program corresponding to the detection method of malicious access information in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above-mentioned method. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, which can be connected to the server device through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0027] The transmission device 106 is used to receive or send data via a network. The specific examples of the above-mentioned network can include a wireless network provided by a communication provider of the server device. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC) which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, RF) module which is used to communicate with the Internet in a wireless manner.

[0028] Embodiments of the present application provide a method for detecting malicious access information. The method is described in detail in combination with an execution flow of the method for detecting malicious access information.

[0029] In the present embodiment, a method for detecting malicious access information is provided, Figure 2 is a flowchart of the method for detecting malicious access information according to an embodiment of the present application, as shown in the figure, the method comprises the following steps: Figure 2

[0030] In step S202, target state information of a plurality of server components deployed in a server is acquired, wherein the server components are components used by the server in a business handling process, and the target state information is used to indicate a component running state of the corresponding server component;

[0031] In step S204, target association information of a plurality of server components is detected according to the target state information, wherein the target association information is used to indicate an association relationship between running states of a plurality of server components in a business handling process of a business system running on the server;

[0032] In step S206, system running information of the business system is generated according to the target association information and the target state information, wherein the system running information is used to indicate a running condition of the business system in the business handling process;

[0033] In step S208, malicious access information of the server is detected according to the system running information, wherein the malicious access information is used to indicate a malicious access condition of the server in the business handling process.

[0034] Through the above steps, by acquiring the target state information representing the component running state of the server component, and by detecting the target association information between the component running states of the server components in the business handling process according to the target state information, and then generating the system running information of the business system according to the target state information and the target association information, the real running state of the business system in the current business handling process is reflected based on the collected component running state of the server component, so as to avoid the influence of the tampering of the system running information of the business system by the malicious program in the business system on the detection result, and thus the technical problem of low detection accuracy of the malicious access information of the server in the related art can be solved, and the technical effect of improving the detection accuracy of the malicious access information of the server is achieved.

[0035] ​The detection method of the malicious access information can be applied to, but is not limited to, a control component having a management control function for the running state of the server. The control component can be, but is not limited to, a baseboard management controller or other component having a server component running state control function deployed in the server for controlling the running state of the server component. The control component directly collects the target state information of the server component during the running of the server. Specifically, a sensor for collecting the running state of the component can be deployed on the server component, and the sensor is directly connected to the control component for executing the detection method of the malicious access information in the embodiment, so as to avoid the target state information of the server component being maliciously tampered with by a malicious program implanted in the business system.

[0036] In the embodiment provided in step S202, the server component is a component used by the business system in the server to handle business. The server component provides hardware support for the business handling of the business system. For example, the server component can include, but is not limited to, a central processing unit, a memory, a power supply, and the like deployed in the server. The present solution is not limited thereto.

[0037] Optionally, in the embodiment of the present application, the running state of the server component can reflect the current business carrying condition of the business system of the server, that is, when the business running on the business system of the server changes, the component of the server will change accordingly. For example, when the data computation thread of the business system decreases but the memory access thread increases, the running power of the central processing unit will decrease accordingly, and the surface temperature of the central processing unit will also decrease accordingly. At the same time, the running power of the memory will increase, and the surface temperature of the memory will increase accordingly.

[0038] Optionally, in the embodiment of the present application, the target state information is a physical state exhibited by the server component during the running process. The target state information can include, but is not limited to, power consumption, electromagnetic radiation, time delay, sound, temperature, and the like. For example, taking the central processing unit as the server component, the target state information can be the surface temperature of the central processing unit, the electromagnetic radiation of the area where the central processing unit is located, the power consumption of the central processing unit, and the like. The present solution is not limited thereto.

[0039] Optionally, in the embodiment of the present application, the target state information of the server component can be, but is not limited to, the information representing the current physical state of the server component collected by the signal collector deployed in the server, which is directly connected to the control component for running the detection method of malicious access information, so as to avoid the tampering of information by the malicious program implanted in the business system of the server. In the embodiment, the method for obtaining the target state information can be as follows: obtaining the initial state information of the first component in the server at a plurality of time points included in a first time period before the current time period, wherein the first component is a component for satisfying the basic running function of the server, and the initial state information is used to indicate the physical running state of the first component at the corresponding time point; calculating the information change amount between the initial state information of adjacent time points in the first time period; in the case where the information change amount is greater than or equal to a target threshold, constructing an information change curve of the initial state information of the first component in the first time period in chronological order, predicting a second time period for collecting the running information of the server component according to the running state transformation feature of the first component indicated in the information change curve, and predicting a target collection accuracy of the running information of the server component according to the running state transformation feature of the first component indicated in the information change curve; and controlling the signal collector on the server component to collect the target state information in the second time period according to the target collection accuracy. Through the above embodiment, the running state of the basic component required by the server is detected, so as to preliminarily determine whether the malicious access operation is likely to occur in the server according to the running state of the basic component, and then the burst time of the malicious access operation is predicted according to the running state transformation feature of the first component in the first time period, and then the information collection time and the collection accuracy of the plurality of server components are predicted, so as to avoid the huge load pressure caused by the real-time information detection and information processing operation with relatively heavy load, and improve the detection efficiency. The way of predicting the second time period for collecting the running information of the server component according to the running state transformation feature of the first component indicated in the information change curve can be, but is not limited to, inputting the running state transformation feature of the first component into a first prediction model to obtain the second time period for collecting the running feature of the server component output by the first prediction model, wherein the first prediction model records the conversion relationship between the running state transformation feature and the state information collection time period. The way of predicting the target collection accuracy of the running information of the server component according to the running state transformation feature of the first component indicated in the information change curve can be: inputting the running state transformation feature into a second prediction model to obtain the target collection accuracy output by the second prediction model, wherein the second prediction model records the conversion relationship between the running state transformation feature and the collection accuracy.

[0040] In the embodiment provided in step S204, the purpose of detecting the target correlation information according to the target state information is to determine the component running state of the server component that is most relevant and most real to the current real running state of the server business system in the current plurality of server components, that is, to avoid the influence of the component running state being tampered or using the component state information irrelevant to the running state of the server business system on the construction of the system running information, and therefore in this embodiment, the target correlation information can reflect the correlation between the running state of each server component and the current real business state of the server business system.

[0041] Optionally, in the embodiment of the present application, the manner of detecting the target correlation information of the plurality of server components according to the target state information can be: performing feature extraction on the target state information to obtain a target running feature of each server component, wherein the target state information is used to record the component running state of the server component at a plurality of time points in a target time period before the current time point, and the target running feature is used to indicate the change of the component running state of the server component in the target time period; selecting a target business corresponding to the current server component from a plurality of preset businesses according to the matching relationship between the target running feature of each server component and a reference running feature of the corresponding server component in the plurality of preset businesses, wherein the target business is a business with the highest matching degree between the reference running feature and the target running feature in the plurality of preset businesses, and the reference running feature is the change of the running state of the current server component when the corresponding preset business is running; calculating the business similarity of the plurality of server components corresponding to the target business; and converting the business similarity into a running state correlation parameter of the corresponding server component, wherein the target correlation information includes the running state correlation parameter, and the running state correlation parameter is used to indicate the correlation degree between the running state of the server component and the current real business state of the server business system. In this embodiment, the business currently handled by the server business system is first predicted according to the component running state change feature of each server component, the business handling information of the business system is predicted according to the running state of a single component, and then the relationship between the running features of the server components is predicted through the similarity relationship between the target businesses handled by the business system predicted using the running state of each component, so as to improve the accuracy of the generated target correlation information.

[0042] In the embodiment provided in step S206, the manner of generating the system running information according to the target correlation information and the target state information can be: inputting the target correlation information and the target state information into a target prediction model to obtain the system running information output by the target prediction model, wherein the target prediction model records the conversion relationship between the correlation information, the state information and the system running information.

[0043] Optionally, in the embodiments of the present application, the manner of generating the system running information according to the target correlation information and the target state information can also be: assigning a corresponding state weight to the target state information of each server component according to the correlation degree between the running states indicated by the target correlation information, wherein the higher the correlation degree between the running state of the current server component and the running states of other server components in the plurality of server components indicated by the target correlation information, the greater the state weight assigned to the target state information; and weighting and merging the target state information using the state weight to obtain the system running information.

[0044] In the embodiment provided in step S208, the manner of detecting the malicious access information according to the system running information can be: inputting the system running information into an information prediction model to obtain the malicious access information output by the information prediction model, wherein the information prediction model records the conversion relationship between the system running information and the malicious access information.

[0045] As an optional implementation, the detecting the target correlation information of the plurality of server components according to the target state information comprises:

[0046] constructing a target running data sequence of the server component according to the time sequence of a plurality of running data of the server component within a target time period before the current time, wherein the running data is used to indicate the running state of the server component at a corresponding time, and the target state information comprises the running data of the server component within the target time period;

[0047] performing feature extraction on each target running data sequence to obtain a state transformation feature of each server component within the target time period, wherein the state transformation feature is used to indicate the time sequence variation of the running state of the server component within the target time period;

[0048] detecting the feature correlation degree between the state transformation features of the plurality of server components to obtain a correlation parameter of the target state information of each server component, wherein the correlation parameter is used to indicate the correlation relationship between the running state of the current server component and the running states of other server components in the plurality of server components except the current server component in the business handling process of the business system, and the target correlation information comprises the correlation parameter.

[0049] Optionally, in the embodiments of the present application, the feature correlation degree detection manner of the plurality of state transition features can be: in the feature space of each of the plurality of preset services, the feature similarity between any current target state transition feature and a reference state transition feature in the plurality of state transition features except the target state transition feature is calculated, to obtain the initial similarity between the target state transition feature and the reference state transition feature in the feature space of each of the plurality of preset services; and the initial similarities of the target state transition feature in the feature spaces of the plurality of preset services are fused to obtain a target similarity between the target state transition feature and the reference transition feature, wherein the correlation parameter includes the target similarity.

[0050] Through the above, the target operation data sequence is formed by recording the operation data of the server component in a period of time. By using time series analysis technology, the change rule of the hardware resource usage pattern over time can be observed. In terms of effects, the construction of such operation data sequence helps to analyze the long-term behavior of the server component and identify possible abnormal trends.

[0051] As an optional implementation, the target operation data sequence of the server component is constructed according to the time sequence of the plurality of operation data of the server component in the target time period before the current time, and includes:

[0052] Each of the plurality of operation data of the server component in the target time period before the current time is sorted in time sequence to obtain an initial operation data sequence of the corresponding server component;

[0053] The data mutation quantity of each of the operation data in the initial operation data sequence is determined, wherein the data mutation quantity is used to indicate the difference between the current operation data and the operation data at the adjacent time;

[0054] The target operation data in the initial operation data sequence whose data mutation quantity is greater than or equal to a target threshold is extracted.

[0055] The data value of the target operation data in the initial operation data sequence is adjusted according to the data difference between the reference operation data in the initial operation data sequence to obtain the target operation data sequence, wherein the reference operation data is the operation data at the adjacent time of the target operation data in the initial operation data sequence.

[0056] Optionally, in the embodiments of the present application, the data mutation quantity can be but is not limited to the signal entropy of each operation data in the initial operation data sequence, which reflects the data mutation quantity of the operation data at the current time relative to other operation data through the information entropy, and the information entropy calculation formula can be P(Xi) represents the probability of the Xi-th data in the sequence appearing in the initial running sequence, the higher the entropy value H(X) is, the greater the randomness or uncertainty of the sequence is; the lower the entropy value is, the greater the regularity or abnormal concentration in the sequence is. The information entropy of the initial running data sequence is calculated in this way, so as to objectively and accurately reflect the mutation of the running data at each time in the initial running data sequence, so as to filter out the abnormal noise signal in the initial running data sequence and ensure the reliability of the data in the running data sequence.

[0057] Through the above content, the running data of the recording server component in a period of time is recorded to form a target running data sequence. By using time series analysis technology, the change rule of the hardware resource usage mode over time can be observed. The construction of such a running data sequence helps to analyze the long-term behavior of the server component, and the accuracy and reliability of the target running data sequence are ensured by eliminating abnormal data in the initial running data sequence and compensating the eliminated abnormal data by giving data transformation time behavior.

[0058] As an optional implementation, the generating the system running information of the business system according to the target correlation information and the target state information comprises:

[0059] performing feature extraction on the target state information to obtain a target running feature of each server component;

[0060] allocating a weight parameter to each target running feature according to a correlation parameter of the target state information, wherein the correlation parameter is used to indicate the correlation between the running state of a current server component and the running state of other server components except the current server component in the business handling process of the business system, the target correlation information comprises the correlation parameter, and the weight parameter is used to indicate the influence degree of the corresponding target running feature on representing the execution state of the business system to the business;

[0061] performing weighted summation calculation on the target running features of the plurality of server components using the weight parameter to obtain a system running feature of the business system, wherein the system running information comprises the system running feature.

[0062] Optionally, in the embodiment of the present application, the weight parameter and the correlation parameter of the target state information have a positive proportional relationship, the greater the correlation degree indicated by the correlation parameter is, the greater the weight parameter allocated is, and the weight parameter represents the importance degree of the target running feature of the corresponding server component, that is, the greater the weight parameter is, the higher the proportion of the corresponding running feature in the system running information is.

[0063] By the above, the interdependence between the states of different hardware components is quantified, so as to reflect the real business processing state of the server business system under the operation state of each server component, and then the weight parameter is assigned to the operation feature of the server component according to the correlation parameter, so as to realize the construction of the system operation feature of the server business system according to the dependence of the operation state of the component on the business state of the business system, and improve the accuracy and reliability of the system operation feature.

[0064] As an optional implementation, the detecting the malicious access information of the server according to the system operation information comprises:

[0065] matching the system operation information with target operation information, wherein the target operation information is used to indicate the system operation state of the server under malicious access;

[0066] in the case that the system operation information and the target operation information match, it is determined that the server is currently in a malicious access state.

[0067] Optionally, in the embodiment of the application, the target operation information is the system operation state under the attack of the known malicious access state, by matching the system operation information with multiple target operation information, the target operation information that completely matches the system operation state is filtered out from the multiple target operation information, and the malicious access state corresponding to the target operation information is determined as the malicious access state currently in the system.

[0068] By the above, by comparing the similarity between the current system operation information and the preset malicious access mode, it can be judged whether there is malicious access. This matching process helps to quickly identify malicious access behavior and provide timely warning for taking defensive measures.

[0069] As an optional implementation, after the detecting the malicious access information of the server according to the system operation information, the method further comprises:

[0070] filtering out a target server component from the multiple server components according to the target state information, wherein the influence degree of the component operation state of the target server component on the malicious access state of the server is greater than or equal to a preset threshold;

[0071] generating target control information of the server according to the current reference state information of the target server component, wherein the target control information is used to adjust the operation state of the multiple server components deployed in the server;

[0072] adjusting the operation state of the multiple server components deployed in the server according to the state adjustment mode indicated by the target control information.

[0073] Optionally, in the embodiments of the present application, the manner of screening the target server components according to the target state information can be: constructing a target running data sequence of the server component according to the time sequence of a plurality of running data of the server component within a target time period before the current time, wherein the running data is used to indicate the running state of the server component at the corresponding time, and the target state information includes the running data of the server component within the target time period; performing feature extraction on each target running data sequence to obtain a state transition feature of each server component within the target time period, wherein the state transition feature is used to indicate the time sequence variation of the running state of the server component within the target time period; performing feature correlation degree detection between the state transition features of a plurality of server components to obtain a correlation parameter of the target state information of each server component, wherein the correlation parameter is used to indicate the correlation between the running state of the current server component and the running state of other server components except the current server component in the business handling process of the business system, and the target correlation information includes the correlation parameter; determining the server component corresponding to the correlation parameter greater than or equal to a target parameter threshold value in a plurality of server components as a target server component.

[0074] Optionally, in the embodiments of the present application, the target control information and the current reference state information of the target server component have a corresponding relationship, that is, different reference state information corresponds to different target control information, and then the running state of the target server component is adjusted according to the target control information, so as to avoid that the malicious attack object attacks the server according to the running state of the target server component, thereby realizing the dynamic generation of the defense strategy against the side channel attack according to the running state of the server component, and better resisting the attack of the malicious access user to the server system.

[0075] Through the above, the threshold screening technology is used to select the target component which has a significant impact on the malicious access state from a plurality of server components, and the screening of the target server component helps to focus on the monitoring of the key hardware resources, improves the detection efficiency, and reduces the resource consumption. The generation of the target control information helps to take action immediately when the malicious access is detected, adjust the running state of the server, suppress the attack behavior, and can quickly respond when the malicious access is detected, change the running parameters of the server hardware, and destroy the side channel utilization chain of the attacker.

[0076] As an optional implementation, the screening of the target server component from the plurality of server components according to the target state information includes:

[0077] Correlation degree calculation is performed on the plurality of target state information, to obtain a state correlation degree corresponding to each target state information, wherein the state correlation degree is used to indicate an association degree between a component running state of a server component indicated by the target state information and component running states of other server components in the plurality of server components, except for a current server component, in a business handling process of the business system;

[0078] The server component corresponding to the target state information with a state correlation degree greater than or equal to a target correlation degree threshold is determined as the target server component.

[0079] Through the above, by quantifying the mutual relationship between different hardware component states, a collaborative mode in hardware resource use can be revealed, and the calculation of the state correlation degree helps to identify abnormal collaboration between hardware states, provides additional clues for malicious access detection, and helps to focus on monitoring and adjusting these key components in subsequent defense strategies, improving the pertinence and efficiency of defense measures.

[0080] As an optional implementation, the generating of the target control information of the server according to the current reference state information of the target server component comprises:

[0081] The target control information corresponding to the reference state information is determined from the state information and the control information with the corresponding relationship.

[0082] As an optional implementation, the obtaining of the target state information of the plurality of server components deployed in the server comprises:

[0083] The processor power consumption of the central processing unit is collected by a power consumption sensor deployed in the server according to a first signal collection accuracy, wherein the power consumption sensor is used to collect the running power consumption of the central processing unit;

[0084] In a case where a difference between the processor power consumptions collected at adjacent time points is greater than or equal to a target power consumption threshold, the current target running power consumption of the central processing unit is collected by the power consumption sensor according to a second signal collection accuracy, the power supply amount of the memory is collected by an electric energy detector deployed in the server according to a third signal collection accuracy, and the electromagnetic radiation amount in the server is collected by an electromagnetic sensor deployed in the server according to a fourth signal collection accuracy, wherein the second signal collection accuracy is higher than the first signal collection accuracy, the second signal collection accuracy, the third signal collection accuracy, and the fourth signal collection accuracy all satisfy a signal collection accuracy condition, the target state information comprises the target running power consumption, the power supply amount, and the electromagnetic radiation amount, and the server component comprises the central processing unit and the memory.

[0085] Through the above, using the dynamic signal acquisition technology, when the CPU power consumption changes more than the preset threshold, it is automatically switched to a higher precision acquisition mode, and through dynamic adjustment of the signal acquisition precision, more detailed data can be obtained when the power consumption is abnormal, which helps to more accurately analyze the attack behavior, and the dynamic signal acquisition mechanism can ensure that high-quality data is obtained at the critical moment, and the accuracy and timeliness of malicious access detection are improved.

[0086] The embodiment of the application provides a side channel attack detection and defense method based on BMC, which utilizes the hardware control capability of BMC to perform multi-physical signal collaborative analysis by taking BMC as a detection platform, and the scheme mainly solves the following problems in the prior art:

[0087] 1. Software layer signal tampering defect: the traditional scheme (such as based on operating system performance counter) has the risk of kernel level data forgery. Attackers can tamper with software layer signals such as CPU cache hit rate and branch prediction error rate by loading malicious drivers, resulting in failure of the detection system.

[0088] The application uses server hardware level interface for data acquisition and communication through BMC, establishes a BMC hardware exclusive signal source, and establishes an unforgeable data source. Attackers are prevented from interfering with the data source acquisition. At the same time, the analysis of data is carried out in BMC, without interfering with the operating system.

[0089] 2. Unable to actively block attacks: the prior art only implements the "detection-alarm" process, and cannot prevent attacks during the attack window, so that critical information may still be stolen.

[0090] The application realizes fan control, power consumption control, voltage glitch control and other hardware level control to confuse the server running condition through BMC, interferes with the side channel attack signal source, and suppresses the side channel attack.

[0091] 3. High false alarm rate of single signal source: relying on a single signal, it is easy to be disturbed by the environment.

[0092] The application adopts multiple data sources to easily obtain hardware level side channel evaluation data such as power consumption, voltage and temperature through BMC in-band collaboration, and more accurately identifies side channel attack features through multi-data collaborative analysis.

[0093] 4. Unable to monitor during the startup phase: traditional security schemes rely on OS for verification and cannot detect attacks before the OS starts.

[0094] The embodiment of the application can realize 24*7 attack detection through BMC management, and is independent of the system. The traditional system-based data acquisition and analysis method cannot identify side channel attacks (such as the bios boot phase) before the system starts. The BMC-based method is independent of the system start, and data acquisition and analysis can be performed before the start.

[0095] Figure 3 An optional attack detection flowchart according to the embodiment of the application is as shown in FIG. 1. Figure 3 As shown in FIG. 1, the BMC-based side channel attack detection and defense method uses the hardware control capability of the BMC to perform multi-physical signal collaborative analysis by taking the BMC as a detection platform. The main work flow is as follows.

[0096] The application mainly relates to the fusion and innovation practice of four key steps of data acquisition, signal preprocessing and feature processing, attack detection analysis, and dynamic defense strategy execution.

[0097] 1. In the data acquisition stage, the embodiment of the application proposes a BMC-based multi-physical quantity space-time collaborative acquisition method. The signal tamperability problem is solved through the following innovative design:

[0098] A hardware signal fusion architecture is designed. Hardware-level protocol interfaces are used to obtain signals that are not easily obtained at the software layer. Hardware signals can be obtained without expansion through the BMC and server built-in interfaces. Physical quantity data is obtained through different hardware-level protocols. The CPU microcode level power consumption gradient sequence of the PECI interface, the memory VRM (Voltage Regulator Module) transient response waveform of the PMBus interface, and the electromagnetic sensor spectrum data connected through the SMBus are synchronized in the hardware clock domain. The time of the three signals is aligned in the time domain through the built-in time domain of the BMC. The acquisition of multiple signals and the synchronization mechanism across protocols are realized (compared with the existing single data source).

[0099] A dynamic acquisition control technology is designed. When the PECI acquisition power gradient mutates (defined as a change in power consumption > 5%), the high-precision sampling mode of the VRM / electromagnetic is activated through the BMC in-band. The default frequency is usually 1khz. Through the dynamic acquisition control mode, the VMR / electromagnetic acquisition frequency can be increased to 10Mhz when the abnormal power mutation occurs, greatly improving the detection sensitivity.

[0100] 2. Signal preprocessing and feature processing:

[0101] The signal preprocessing part is the processing of the data of the multiple signal sources obtained in the previous step. In order to provide standardized data formats for subsequent physical signal analysis and improve the efficiency of data analysis:

[0102] Multi-hardware data source synchronizer, the time intervals of multiple signal sources are often different and need to be uniformly processed. The collection methods of power consumption, voltage, and electromagnetic signals are different, and the time difference is large, such as ms level for power consumption and ns level for electromagnetic signals. A unified timestamp is generated through the internal clock of BMC to mark the sampling points, and the time alignment of multiple signal sources is realized.

[0103] Data processing module, through entropy calculation and peak detection technology, abnormal noise data is removed. At the same time, data fusion and dimension reduction method is used, and industry common multi-source data fusion and dimension reduction method-principal component analysis (PCA) is used for data dimension reduction, integration and summary of data. Here, the industry common method is used, which is not within the protection scope of the application and is not described in detail.

[0104] Attack detection analysis:

[0105] Attack detection analysis module based on multi-source signals collected by physical hardware layer (such as CPU power consumption, voltage glitch, and electromagnetic characteristics), through BMC firmware layer for real-time synchronization, denoising and feature extraction, for the processed data, using double-mode analysis engine: comparing the preprocessed data with 20 kinds of known attack characteristics (such as voltage glitch waveform template, electromagnetic spectrum fingerprint) and hardware acceleration, matching successfully immediately transferred to dynamic defense strategy execution module; At the same time, through the probabilistic evaluation model based on hardware behavior, the spatio-temporal correlation characteristics of multiple signals are analyzed, and the dynamic defense strategy execution is called based on the analysis and matching results.

[0106] Lightweight LSTM model is used to analyze the threat, and the attack feature library is continuously optimized.

[0107] Through parallel rule library matching and evaluation model evaluation, the defense execution strategy is dynamically adjusted to prevent false positives of single judgment logic and effectively improve the defense accuracy.

[0108] Dynamic defense strategy execution:

[0109] Dynamic defense strategy execution module based on attack detection analysis results, through the hardware level control ability of BMC, directly manipulates the server bottom layer hardware components, realizes multi-dimensional collaborative interference for side channel attack. Through the hardware control ability of BMC, the module directly operates the server bottom layer hardware (such as CPU voltage regulator, memory controller, clock generator), realizes accurate response.

[0110] The core defense means are voltage glitch injection, fake memory refresh and clock jitter control. The application innovatively targets the scene of side channel attacks, can synchronously execute interference of different dimensions in combination with multiple signal sources, directly controls through the BMC without OS intervention, effectively reduces the delay, and proposes a combination execution strategy of dynamically selecting voltage glitch, fake memory refresh and clock jitter control according to the attack type, and proposes a dynamic defense strategy through BMC hardware direct control. The core of the application lies in the hardware control link without OS intervention and the dynamic defense strategy adaptive to attack characteristics, which can adjust the defense strength according to the system state.

[0111] Figure 4 An optional attack detection system schematic diagram according to an embodiment of the application is shown in FIG. 1. Figure 4 As shown in FIG. 1, the attack detection system mainly includes the following modules: a multi-source signal acquisition module, a signal preprocessing module, a security analysis engine and a dynamic confusion control module.

[0112] The multi-source signal acquisition module: through a BMC special signal routing circuit, multiple data are cooperatively collected, for example as follows:

[0113] A bus interface (which can include a PECI interface or a PMBus interface), the PECI interface directly connects the CPU microcode unit to collect the core power consumption gradient sequence (precision ±1mV) at a period of 1ms; the PMBus controller monitors the voltage regulator module (VRM, Voltage Regulator Module) phase current ripple (bandwidth 100MHz) to capture the transient response waveform; the SMBus extension channel accesses the on-board electromagnetic sensor array to collect spectrum data (0.1-1GHz) to support a dynamic acquisition and control technology, and uses an event-triggered multi-stage sampling: the normal data acquisition mode is 1kHz polling (power consumption <2W), when a power consumption mutation is detected, the attack detection mode is used, the ADC clock divider electromagnetic sampling rate is reconfigured to 10MHz, and the data sampling capture efficiency is improved.

[0114] The signal preprocessing module: uses compensation technology to solve the problem of inconsistent signal time, applies delay to the signal with high frequency, uses analog interpolation processing to the signal with low frequency, and outputs a multi-signal source matrix with time alignment. And the PCA analysis is performed on the multi-signal source matrix to realize data preprocessing.

[0115] For a running data sequence composed of running data of each server component at multiple moments within a target time period before the current moment, an entropy filter is used to avoid abnormal data sources, and the signal entropy within a millisecond is calculated: through the signal entropy of each running data in the running data sequence, the data mutation of the running data at the current moment relative to other running data is reflected through the information entropy, and the information entropy calculation formula can be where P(X i ) represents the probability of the X i th data in the sequence appearing in the running sequence, the higher the entropy value H(X), the greater the randomness or uncertainty of the sequence; the lower the entropy value, the greater the regularity or abnormal concentration in the sequence. By calculating the information entropy of the running data sequence in this way, the mutation of the running data at each time in the running data sequence is objectively and accurately reflected, thereby filtering out abnormal noise signals in the initial running data sequence and ensuring the reliability of the data in the running data sequence.

[0116] Security analysis engine: for side channel attack analysis, a dual-mode analysis engine is used: the preprocessed data and known attack features (such as voltage glitch waveform templates, electromagnetic spectrum fingerprints) are compared with hardware acceleration, and if a match is found, it is immediately transferred to the dynamic defense strategy execution module; at the same time, through the probabilistic evaluation model based on hardware behavior, the spatiotemporal correlation characteristics of multiple signals are analyzed, and based on the analysis and matching results, the dynamic defense strategy execution is called. While performing analysis, AI-assisted analysis is used to run a lightweight LSTM to assist in optimizing the feature library and evaluation model, and to optimize the accuracy of the system.

[0117] Dynamic confusion control module: this module adaptively adjusts system running parameters for different signal sources corresponding to side channel attacks to interfere with side channel attacks. Its core is a multi-dimensional cooperative interference mechanism that applies differential interference to power consumption, timing, electromagnetic, and other different signal sources, and dynamically adjusts the defense strength according to the detected attack type and the current system environment load. In particular, this defense method bypasses the operating system and controls the underlying hardware through the BMC, effectively improving the anti-interference ability and reducing the delay. The specific implementation method is as follows:

[0118] Using attack-adaptive defense combinations, according to the attack type identified by the security analysis engine, dynamically selecting differential combination strategies for voltage glitches, pseudo-memory refresh, and clock jitter, a three-dimensional cooperative interference is achieved. For example, increase the 15mV voltage glitch injection and +5% clock jitter offset. Using a dynamic scheduling algorithm, according to the current system state, system load, and environmental noise, adaptively adjust the parameters of different confusion, and optimize the defense strength in real time to achieve the best effect of confusion.

[0119] At the same time, through the exclusive interface and data bus of the BMC, the confusion instructions are directly operated, bypassing the operating system, reducing the response delay; using the offset amount within the safe range that meets the safety specifications (such as mV level voltage and ms level clock offset), which will not affect the system, and the defense action cannot be evaded by the software layer.

[0120] The embodiment of the application realizes multi-source signal cooperative collection and dynamic confusion control through a BMC hardware exclusive interface, constructs a full-cycle side channel defense system from signal tamper prevention, attack real-time suppression to start-up stage monitoring, first realizes hardware-level active security protection without OS intervention in the field of servers, improves the accuracy of attack detection, and provides a method for interfering attacks and suppressing side channel attacks for the server.

[0121] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and the necessary general hardware platform, and of course, it can also be realized by hardware, but in many cases, the former is a better embodiment.

[0122] The embodiment of the application further provides a malicious access information detection device, Figure 5 is a structural block diagram of a malicious access information detection device according to the embodiment of the application, as shown in Figure 5 The device comprises:

[0123] An acquisition module is configured to acquire target state information of a plurality of server components deployed in a server, wherein the server components are components used by the server in a business handling process, and the target state information is used to indicate a component running state of the corresponding server component.

[0124] A first detection module is configured to detect target association information of the plurality of server components according to the target state information, wherein the target association information is used to indicate an association relationship of running states between the plurality of server components in a business handling process of a business system running on the server.

[0125] A first generation module is configured to generate system running information of the business system according to the target association information and the target state information, wherein the system running information is used to indicate a running condition of the business system in the business handling process.

[0126] A second detection module is configured to detect malicious access information of the server according to the system running information, wherein the malicious access information is used to indicate a malicious access condition of the server in the business handling process.

[0127] By means of the above device, by acquiring target state information representing the component running state of the server component, and by detecting target association information between the component running states of the server component in the service handling process according to the target state information, and further generating system running information of the service system according to the target state information and the target association information, the real running state of the server service system in the current service handling process is reflected based on the collected component running state of the server component, so as to avoid the influence of the tampering of the system running information of the service system by the malicious program in the service system on the detection result, and thus the technical problem of low detection accuracy of malicious access information of the server in the related art can be solved, and the technical effect of improving the low detection accuracy of malicious access information of the server is achieved.

[0128] Optionally, the first detection module comprises:

[0129] The construction unit is configured to construct a target running data sequence of the server component according to the time sequence of a plurality of running data of the server component within a target time period before the current time, wherein the running data is used to indicate the running state of the server component at a corresponding time, and the target state information comprises the running data of the server component within the target time period.

[0130] The first extraction unit is configured to perform feature extraction on each target running data sequence to obtain a state transformation feature of each server component within the target time period, wherein the state transformation feature is used to indicate the time sequence variation of the running state of the server component within the target time period.

[0131] The detection unit is configured to perform feature correlation degree detection between the state transformation features of a plurality of server components to obtain an association parameter of the target state information of each server component, wherein the association parameter is used to indicate the association relationship between the running state of a current server component and the running state of other server components except the current server component in the plurality of server components in the service handling process of the service system, and the target association information comprises the association parameter.

[0132] Optionally, the construction unit is configured to:

[0133] sort a plurality of running data of each server component within a target time period before the current time in time sequence to obtain an initial running data sequence of the corresponding server component;

[0134] determine a data mutation variable of each of the operation data in the initial operation data sequence, wherein the data mutation variable is used to indicate a difference between the current operation data and the operation data at an adjacent time point;

[0135] extract target operation data in the initial operation data sequence, wherein the data mutation variable of the target operation data is greater than or equal to a target threshold value;

[0136] adjust a data value of the target operation data in the initial operation data sequence according to a data difference between reference operation data in the initial operation data sequence, to obtain a target operation data sequence, wherein the reference operation data are operation data at adjacent time points of the target operation data in the initial operation data sequence.

[0137] Optionally, the first generating module comprises:

[0138] a second extracting unit configured to perform feature extraction on the target state information to obtain target operation features of each of the server components;

[0139] a distribution unit configured to distribute a weight parameter of each of the target operation features according to an association parameter of the target state information, wherein the association parameter is used to indicate an association relationship between an operation state of a current server component and operation states of other server components except the current server component in the business system during a business handling process of the business system, the target association information comprises the association parameter, and the weight parameter is used to indicate an influence degree of the corresponding target operation feature on representing an execution state of the business system on the business.

[0140] a first calculating unit configured to perform weighted summation calculation on the target operation features of the plurality of server components using the weight parameter to obtain a system operation feature of the business system, wherein the system operation information comprises the system operation feature.

[0141] Optionally, the second detecting module comprises:

[0142] a matching unit configured to match the system operation information and target operation information, wherein the target operation information is used to indicate a system operation state of the server under malicious access;

[0143] a first determining unit configured to determine that the server is currently in a malicious access state when the system operation information and the target operation information are matched and consistent.

[0144] Optionally, the apparatus further comprises:

[0145] The screening module is configured to screen a target server component from the plurality of server components according to the target state information after detecting the malicious access information of the server according to the system operation information, where a degree of influence of a component operation state of the target server component on the malicious access state of the server is greater than or equal to a preset threshold value;

[0146] The second generation module is configured to generate target control information of the server according to the reference state information of the target server component, where the target control information is used to adjust the operation states of the plurality of server components deployed in the server.

[0147] The adjustment module is configured to adjust the operation states of the plurality of server components deployed in the server according to a state adjustment mode indicated by the target control information.

[0148] Optionally, the screening module comprises:

[0149] The second calculation unit is configured to perform correlation degree calculation on the plurality of target state information to obtain a state correlation degree corresponding to each target state information, where the state correlation degree is used to indicate a correlation degree between a component operation state of a server component indicated by the target state information and component operation states of other server components except for a current server component in the plurality of server components in a business handling process of the business system.

[0150] The second determination unit is configured to determine the server component corresponding to the target state information with the state correlation degree greater than or equal to a target correlation degree threshold value as the target server component.

[0151] Optionally, the second generation module comprises:

[0152] The third determination unit is configured to determine the target control information corresponding to the reference state information from the state information and the control information with the corresponding relationship.

[0153] Optionally, the acquisition module comprises:

[0154] The acquisition unit is configured to acquire a processor power consumption of a central processing unit collected by a power consumption sensor deployed in the server according to a first signal collection precision, where the power consumption sensor is used to collect an operation power consumption of the central processing unit.

[0155] The control unit is configured to control the power consumption sensor to collect the target running power consumption of the central processing unit at a second signal collection precision, control the power detector arranged in the server to collect the power supply amount of the memory at a third signal collection precision, and control the electromagnetic sensor arranged in the server to collect the electromagnetic radiation amount in the server at a fourth signal collection precision, when a difference between the power consumptions of the central processing unit collected at adjacent time points is greater than or equal to a target power consumption threshold, the second signal collection precision is higher than the first signal collection precision, the second signal collection precision, the third signal collection precision, and the fourth signal collection precision all satisfy a signal collection precision condition, the target state information includes the target running power consumption, the power supply amount, and the electromagnetic radiation amount, and the server component includes the central processing unit and the memory.

[0156] The features of the embodiments of the detection apparatus for malicious access information can be understood by referring to the related descriptions of the embodiments of the detection method for malicious access information, which will not be repeated here.

[0157] The embodiments of the present application also provide an electronic device including a memory and a processor, the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any of the above-mentioned detection method embodiments for malicious access information.

[0158] The embodiments of the present application also provide a computer readable storage medium, which stores a computer program, and the computer program is configured to perform the steps in any of the above-mentioned detection method embodiments for malicious access information when running.

[0159] In an example embodiment, the above-mentioned computer readable storage medium can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.

[0160] The embodiments of the present application also provide a computer program product, which includes a computer program, and the computer program is executed by a processor to implement the steps in any of the above-mentioned detection method embodiments for malicious access information.

[0161] The embodiments of the present application also provide another computer program product, which includes a non-volatile computer readable storage medium, and the non-volatile computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps in any of the above-mentioned detection method embodiments for malicious access information.

[0162] Those skilled in the art will further realize that the mere concepts, teachings, and embodiments described herein are merely meant to provide an enabling description of the claimed application. Accordingly, modifications and / or additions, other than those explicitly described herein, can be obvious to those skilled in the art in the light of this disclosure. The claimed application is intended to embrace all such modifications and / or additions.

[0163] The above has carried out the detailed introduction to the method and device for detecting malicious access information provided by the application. The principle and implementation mode of the application are described by applying specific examples in this paper. The above description of the embodiments is only applicable to help understand the method and its core idea of the application. It should be pointed out that for ordinary skilled in the art, some improvements and modifications can be made to the application without departing from the principle of the application. These improvements and modifications also fall within the protection scope of the claims of the application.

Claims

1. A method of detecting malicious access information, characterized by, The method comprises the following steps: obtaining target state information of a plurality of server components deployed in a server, wherein the server components are components used by the server in a business handling process, and the target state information is used to indicate the component running state of the corresponding server component; detecting target association information of a plurality of the server components according to the target state information, wherein the target association information is used to indicate the association relationship between the running states of a plurality of the server components in a business handling process of a business system running on the server; generating system running information of the business system according to the target association information and the target state information, wherein the system running information is used to indicate the running condition of the business system in a business handling process; detecting malicious access information of the server according to the system running information, wherein the malicious access information is used to indicate the malicious access condition of the server in a business handling process; The method further comprises the following steps: extracting features from the target state information to obtain target running features of each of the server components; allocating a weight parameter to each of the target running features according to an association parameter of the target state information, wherein the association parameter is used to indicate the association relationship between the running state of a current server component and the running states of other server components except the current server component in a business handling process of the business system, the target association information comprises the association parameter, and the weight parameter is used to indicate the influence degree of the corresponding target running feature on the execution state of the business system on the business; performing weighted summation calculation on the target running features of a plurality of the server components using the weight parameter to obtain system running features of the business system, wherein the system running information comprises the system running features.

2. The method of claim 1, wherein The method further comprises the following steps: constructing a target running data sequence of each of the server components according to the time sequence of a plurality of running data of the server component within a target time period before the current time, wherein the running data is used to indicate the running state of the server component at the corresponding time, and the target state information comprises the running data of the server component within the target time period; extracting features from each of the target running data sequences to obtain state transformation features of each of the server components within the target time period, wherein the state transformation features are used to indicate the time sequence variation of the running state of the server component within the target time period. The feature correlation degree detection is performed between the state transition features of the plurality of server components, to obtain a correlation parameter of the target state information of each server component, where the correlation parameter is used to indicate an association relationship between a running state of a current server component and running states of other server components except the current server component in a service handling process of the service system, and the target correlation information includes the correlation parameter.

3. The method of claim 2, wherein, the target running data sequence of the server component is constructed according to a time sequence of a plurality of running data of the server component within a target time period before a current time, including: sorting the plurality of running data of each server component within the target time period before the current time according to a time sequence, to obtain an initial running data sequence of the corresponding server component; determining a data mutation variable of each running data in the initial running data sequence, where the data mutation variable is used to indicate a difference between the current running data and the running data at an adjacent time; extracting a target running data in the initial running data sequence, where a data mutation variable of the target running data is greater than or equal to a target threshold value; adjusting a data value of the target running data in the initial running data sequence according to a data difference between reference running data in the initial running data sequence, to obtain the target running data sequence, where the reference running data are running data at adjacent times of the target running data in the initial running data sequence.

4. The method of claim 1, wherein, the malicious access information of the server is detected according to the system running information, including: matching the system running information with target running information, where the target running information is used to indicate a system running state of the server when the server is under malicious access; in a case where the system running information and the target running information match, it is determined that the server is currently in a malicious access state.

5. The method of claim 1, wherein, after the malicious access information of the server is detected according to the system running information, the method further includes: filtering out a target server component from the plurality of server components according to the target state information, where an influence degree of a component running state of the target server component on the malicious access state of the server is greater than or equal to a preset threshold value; generating target control information of the server according to a reference state information of the target server component, where the target control information is used to adjust running states of the plurality of server components deployed in the server; adjusting the running states of the plurality of server components deployed in the server according to a state adjustment mode indicated by the target control information.

6. The method of claim 5, wherein, the target server component is filtered out from the plurality of server components according to the target state information, including: Correlation degree calculation is performed on the plurality of target state information, to obtain a state correlation degree corresponding to each target state information, wherein the state correlation degree is used to indicate an association degree between a component running state of a current server component indicated by the target state information and component running states of other server components in the plurality of server components except the current server component in a business handling process of the business system; The server component corresponding to the target state information with the state correlation degree greater than or equal to a target correlation degree threshold is determined as the target server component.

7. The method of claim 6, wherein The target control information of the server is generated according to the current reference state information of the target server component, including: The target control information corresponding to the reference state information is determined from the state information and the control information with the corresponding relationship.

8. The method of claim 1, wherein The target state information of the plurality of server components deployed in the server is obtained, including: A processor power consumption of a central processing unit is collected by a power consumption sensor deployed in the server according to a first signal collection accuracy, wherein the power consumption sensor is used to collect a running power consumption of the central processing unit; In a case where a difference between the processor power consumptions collected at adjacent time instants is greater than or equal to a target power consumption threshold, the current target running power consumption of the central processing unit is collected by the power consumption sensor according to a second signal collection accuracy, the power supply amount of a memory is collected by an electric energy detector deployed in the server according to a third signal collection accuracy, and the electromagnetic radiation amount in the server is collected by an electromagnetic sensor deployed in the server according to a fourth signal collection accuracy, wherein the second signal collection accuracy is higher than the first signal collection accuracy, the second signal collection accuracy, the third signal collection accuracy and the fourth signal collection accuracy all satisfy a signal collection accuracy condition, the target state information includes the target running power consumption, the power supply amount and the electromagnetic radiation amount, and the server components include the central processing unit and the memory.

9. A device for detecting malicious access to information, characterized by including: An obtaining module is configured to obtain target state information of a plurality of server components deployed in a server, wherein the server components are components used by the server in a business handling process, and the target state information is used to indicate a component running state of a corresponding server component; A first detection module is configured to detect target association information of the plurality of server components according to the target state information, wherein the target association information is used to indicate an association relationship between running states of the plurality of server components in a business handling process of a business system running on the server; A first generation module is configured to generate system running information of the business system according to the target association information and the target state information, wherein the system running information is used to indicate a running condition of the business system in the business handling process. A second detection module is configured to detect malicious access information of the server according to the system operation information, wherein the malicious access information is used to indicate malicious access conditions of the server in the business handling process. The first generation module comprises: a second extraction unit configured to perform feature extraction on the target state information to obtain target operation features of each server component; an allocation unit configured to allocate a weight parameter of each target operation feature according to an association parameter of the target state information, wherein the association parameter is used to indicate an association relationship between an operation state of a current server component and operation states of other server components except the current server component in the business handling process of the business system, the target association information comprises the association parameter, and the weight parameter is used to indicate an influence degree of the corresponding target operation feature on representing an execution state of the business system on the business; and a first calculation unit configured to perform weighted summation calculation on the target operation features of the plurality of server components using the weight parameter to obtain a system operation feature of the business system, wherein the system operation information comprises the system operation feature.

Citation Information

Patent Citations

  • Calculation Internet traffic processing method and system

    CN118740518A

  • Method and device for testing temperature control performance of server

    CN119690764A