Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

99 results about "Os kernel" patented technology

Linux access control system based on attributes

The invention provides a Linux access control system based on attributes, and relates to the technical field of data access control. The system comprises a system monitor module, a data interaction module and a decision unit. The system monitor module collects attributes from a kernel and a user space and writes the attributes into the data interaction module; the access decision unit compiles the access control strategy into an eBPF program and mounts the eBPF program to a corresponding hook; executing the kernel to the hook, and triggering an eBPF program; an eBPF program queries a Flow rule; matching the attribute with the Flow rule, and if the matching is successful, executing a corresponding action; if all the Flow rules fail to match, executing a default action; the system can be expanded during operation, and can be loaded or unloaded based on dynamic loading characteristics and strategies of the eBPF program and the eBPF program during operation of the system, so that the problem that a kernel needs to be compiled in a traditional LSM scheme is solved; the method does not intrude the kernel, is completely based on an eBPF program, does not modify a kernel source code, and can guarantee the stability and compatibility.
Owner:SICHUAN UNIV

Deep learning reasoning service performance analysis method based on kernel function trajectory

The invention provides a kernel function trajectory-based deep learning inference service performance analysis method, which comprises the following steps of: based on service indexes and hardware theoretical computing power acquired from a production cluster, defining floating point operation times per request (FPR) index to quantify service resource efficiency, and identifying high FPR hotspot services; positioning a reasoning iteration candidate boundary based on a GPU kernel function trajectory, verifying iteration integrity through fingerprint matching and chi-square test, and calculating a second reasoning iteration number IIPS and a model reasoning efficiency MIE; aiming at calculation-intensive operators on the key path, combining a dynamic Roofline model to estimate an operator theoretical performance upper limit, and based on actual execution time, calculating efficiency and a BottleScore index to identify a key bottleneck operator; and outputting targeted optimization suggestions according to analysis results of service efficiency analysis, model efficiency analysis and operator efficiency analysis. According to the method, the inference behavior pattern can be automatically identified from massive kernel trajectories, and the efficiency loss of each level is quantified.
Owner:UNIV OF SHANGHAI FOR SCI & TECH +1

Kernel probe generation method and device, computer equipment and storage medium

The invention discloses a kernel probe generation method and device, computer equipment and a storage medium, and relates to the technical field of operating system kernel monitoring, and the kernel probe generation method comprises the steps of obtaining a target metadata file corresponding to a current operating system kernel in response to a kernel probe generation request; determining a target declarative strategy file; and determining a target program logic file corresponding to the target declarative strategy file, and generating a probe code according to the target program logic file and the target metadata file to obtain a kernel probe program. The probe program source code adaptive to the current kernel version can be dynamically generated in combination with the target metadata file and the target declarative strategy file, kernel probe development logic and underlying kernel knowledge can be decoupled through the source code generation function, and developers do not need to deeply understand kernel internal data structures and version differences; the development threshold is lower, a specific operating system or probe type is supported, and a universal Linux kernel and multiple probe types are also supported.
Owner:BEIJING LINX SOFTWARE CORP

Unified programming model compiling and runtime system oriented to Shenwei supercomputing platform

The invention discloses a unified programming model compiling and runtime system oriented to a Shenwei supercomputing platform, which comprises a compiling module used for compiling SYCL programming model codes and detecting kernel functions to generate equipment end intermediate representation; processing the equipment end intermediate representation to obtain a kernel function dynamic link library and an executable code of a host end; and the public runtime module is used for calling the kernel function dynamic link library when the executable code at the host side runs. Based on a compiling module and a public runtime module, a vertical optimization system from a compiler to runtime is constructed, efficient operation of SYCL in a domestic supercomputing system is realized, a semantic gap between a domestic many-core architecture and a universal programming model is overcome, and the development of the system is facilitated. The SYCL programming model is processed by a host end and an equipment end respectively after being extracted by a kernel during compiling, and is dynamically called by a common runtime module, so that the cooperative computing capability of the host end and the equipment end is fully exerted.
Owner:XI AN JIAOTONG UNIV

Systems and methods for testing sandboxed in-kernel programs

Systems and methods for testing sandboxed in-kernel programs are provided. A method of testing a program includes: obtaining a Berkeley Packet Filter (BPF) program to test; obtaining a test to run on the BPF program; performing the test on the BPF program for a plurality of Linux kernels and reporting a result of performing the test on the BPF program for a plurality of Linux kernels. This enables a generic testing solution for black box testing of BPF programs. The embodiments can integrate with existing testing suites and frameworks and can integrate into CI / CD pipelines. Some embodiments allow testing using any kernel from user space. Host kernel testing of BPF programs is enabled by a developer using the developer's own workstation and version of the Linux kernel. Guest kernel testing of BPF programs is enabled using specific kernel versions by providing the framework a specification of the target kernel environment.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Linux operating system drive fuzzy test system based on kernel device model

The invention provides an improved scheme of a fuzzy testing system of a Linux operating system. According to the scheme, fuzzy testing is guided by integrating device attributes, driving attributes and topological relations among devices. Specifically, a new syzlang description is generated by deeply analyzing a Linux kernel source code, so that a test case can introduce modification operation of equipment and drive attributes. Meanwhile, according to the scheme, the depth and the breadth of the fuzzy test are improved based on the corresponding relation between the equipment attribute file and the equipment file, so that the behavior of the kernel driver is more effectively explored. In addition, according to the scheme, concurrent testing is guided through the topological relation between the devices, testing cases related to device attributes and drive attributes are increased, the testing efficiency is further improved, the coverage rate of fuzzy testing is increased, and finally the testing process can reveal vulnerabilities caused by memory errors of a kernel of the Linux operating system in different states.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Generation scheduling method for kernel fuzzy test configuration related seeds

The invention discloses a generation scheduling method for kernel fuzzy test configuration related seeds. The generation scheduling method comprises the following steps: 1, calling, classifying and generating a configuration system based on a large language model; 2, test execution scheduling and generation based on behavior association; and 3, test efficiency optimization based on configuration code association driving. Compared with the prior art, the method has the advantages that in the theoretical aspect, a configuration-sensitive fuzzy test theory in a kernel test scene is explored, a kernel fuzzy test framework based on configuration sensitivity is constructed, and kernel defect detection capacity and efficiency are improved; in the technical aspect, a large language model, relation learning and a dynamic analysis technology are deeply fused, and technical features and innovativeness are achieved; in the application aspect, a kernel configuration code detection tool is realized, a code related configuration detection service oriented to a Linux main line kernel and a domestic open source operating system kernel is planned to be constructed, and the kernel defect detection capability and the automation level are improved.
Owner:CENT SOUTH UNIV

Operating system IO processing method supporting random IO merging, operating system and storage system

The invention discloses an operating system IO processing method supporting random IO merging, an operating system and a storage system, and belongs to the field of computer operating systems. The method comprises the steps that in a user mode, only one parameter copy is reserved for the same parameters of a plurality of random IO requests and recorded in a shared structure A, respectively recording different parameters of each random IO request into the shared structure body B to obtain a pseudo sequence request; the pseudo-sequence requests are issued to a system kernel, corresponding operations are executed on the pseudo-sequence requests in all layers of the system kernel in sequence, the batch operations are only executed once, and the non-batch operations are executed once for all the random IO requests respectively; the batch operation and the non-batch operation are operations executed for parameters in the shared structure body A and the shared structure body B respectively; and splitting the pseudo sequence request into random IO requests in an equipment driving layer of the kernel system, generating a corresponding equipment command, and submitting the equipment command to storage equipment. According to the invention, kernel overhead under the condition of high throughput can be relieved, so that the throughput is improved.
Owner:HUAZHONG UNIV OF SCI & TECH

Work graph-based sparse linear algebra operations for parallel processors

A processor includes a plurality of processing elements. The processor is configured to execute a work graph including a plurality of nodes representing kernels executable by one or more processing elements of the plurality of processing elements. A first processing element of the one or more of the processing elements associated with a first node of the plurality of nodes is configured to assign each logical division of a sparse input matrix to a bin of a plurality of bins. Responsive to a dispatch condition associated with a bin of the plurality of bins, the processor is configured to dispatch a workgroup to at least a second processing element associated with at least a second node of the plurality of nodes corresponding to the bin. The workgroup includes a plurality of work items based on one or more logical divisions of the sparse input matrix assigned to the bin.
Owner:ADVANCED MICRO DEVICES INC

Kernel selection method and device during general matrix multiplication operation, equipment and storage medium

PendingCN122044838AResource allocationBiological modelsGeneral matrixAlgorithm
The embodiment of the invention provides a kernel selection method and device during general matrix multiplication operation, equipment and a storage medium, and belongs to the technical field of computers. The method comprises the following steps: acquiring general matrix multiplication problem size data; preprocessing the general matrix multiplication problem size data to obtain general matrix multiplication problem size features; based on a pre-trained problem size encoder, mapping the general matrix multiplication problem size feature into a problem size embedded vector of a preset dimension; taking the problem size embedded vector as a query vector, and performing nearest neighbor vector search in a pre-configured vector database to obtain a kernel configuration feature with the highest similarity; and outputting the kernel configuration feature as a selection result. The method is used for improving the kernel selection efficiency and precision during the operation of the general matrix multiplication.
Owner:DAWNING INT INFORMATION IND CO LTD +1

Automatic generation of computation kernels for approximating elementary functions

An apparatus for computing functions using polynomial-based approximation, comprising one or more processing circuitries configured for computing a polynomial-based approximant approximating a function by executing one or more iterations. Each iteration comprising computing the polynomial-based approximant using scaled fixed-point unit(s) according to a constructed set of coefficients, minimizing an approximation error of the computed polynomial-based approximant compared to the function while complying with one or more constraints selected from a group comprising at least: an accuracy, a compute graph size, a computation complexity, and a hardware utilization of the processing circuitry(s), adjusting one or more of the coefficients in case the approximation error is incompliant with the constraint(s) and initiating another iteration. The polynomial-based approximant and its adjusted set of coefficients for which the computed polynomial-based approximant complies with the constraint(s) may be output to one or more processing circuitries configured to approximate the function by computing the polynomial-based approximant.
Owner:NEXTSILICON LTD

A linux kernel module cross-version binary compatibility method

PendingCN122363701ANo additional overheadGuaranteed accuracyLoad timeLinux kernel
This invention relates to a method for cross-version binary compatibility of Linux kernel modules, belonging to the field of computer operating system kernels. It includes the following steps: During the compilation phase, the compiler identifies specific keywords (__kabi_reloc_member, __kabi_check_member, __kabi_sizeof) and records instruction offsets, type identifiers, member variable name offsets, and relocation types, generating a .kabi_relocs segment. During the loading phase, the loader parses the .kabi_relocs segment, combines it with module BTF and kernel BTF information, and dynamically repairs instructions based on the relocation type. This invention achieves "compile once, run anywhere" binary compatibility for kernel modules, with the repair operation completed at load time, having no impact on runtime performance.
Owner:KYLIN CORP

Model Inference Optimization Method, Apparatus, Device, Medium, and Program Product

The present application discloses a method, device, equipment, medium and program product for optimizing model inference, relating to the field of computer technology, including: obtaining the network characteristics of at least one network layer included in the target model; generating kernel code adapted to the at least one network layer according to the network characteristics; the kernel code represents the calculation method of the network layer in the current inference process of the target model; configuring kernel parameters based on the hardware resources of the target device to be used for inferring the target model; the kernel parameters refer to the relevant parameters for the execution of the kernel code on the target device; compiling the kernel code to generate an executable kernel file; and invoking the kernel file to perform inference on the target model. By generating kernel code adapted to each network layer based on the network characteristics and flexibly setting the kernel parameters according to the hardware resources, the technical problems of poor flexibility of fixed code and low utilization rate of hardware resources are solved, and the technical effects of improving the model inference efficiency and resource utilization rate are achieved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Static Ftrace adaptation method and dynamic Ftrace adaptation method based on SW processor

The invention discloses a static Ftrace adaptation method and a dynamic Ftrace adaptation method based on a SW processor, and belongs to the technical field of computer system structures.In the process that a first kernel function calls a second kernel function, the static Ftrace adaptation method comprises the step that a static jump pile is inserted in front of an entry address of the second kernel function. The dynamic Ftrace adaptation method comprises the steps that a dynamic jump pile is inserted in front of an entry address of a second kernel function, an ftracemakecalall function is called to modify the dynamic jump pile into a null instruction, the null instruction is dynamically processed in response to user configuration processing, and if the second function is set as a tracking target, the null instruction is modified into the dynamic jump pile and executed; and if the second function is not set as the tracking target, executing the null instruction. The problem that an existing SW processor cannot track a kernel function and perform kernel debugging analysis is solved.
Owner:WUXI ADVANCED TECH RES INST

Industrial control network flow intrusion detection method combining deep learning and multi-kernel learning

The invention belongs to the field of industrial network security, and particularly relates to an industrial control network traffic intrusion detection method combining deep learning and multi-kernel learning, which comprises the following steps of: firstly, acquiring an industrial control traffic data sample and performing feature cleaning, and then establishing a multilayer deep neural network DNN model; and the optimal parameter configuration of the model is obtained through iterative training. Then extracting a middle layer representation result of the DNN as a kernel matrix of mapping; the kernel matrixes obtain respective weights through a multi-kernel learning MKL process, and linear combination is carried out. And finally, the combined kernel matrix replaces the original shallow kernel function of the kernel extreme learning machine KELM, and a multi-depth kernel extreme learning machine MDKELM model for detecting the traffic sample type is formed. The model is deployed at the edge of a device and a network, external access traffic is detected, whether the external access traffic belongs to normal traffic is judged, and if not, early warning is given out in time.
Owner:SHENYANG AEROSPACE UNIVERSITY

Automatic reconstruction kernel code generation method

The invention relates to the technical field of kernel code generation, and discloses an automatic reconstruction kernel code generation method, which comprises the following steps: collecting example code data of a kernel part, and carrying out structured processing on example codes to obtain a logic transfer diagram of the example codes; constructing an example code feature extraction model to perform embedded representation on the logic transfer diagram of the example code, and converting an embedded representation result into structural features of the example code; semantic features of the function description text are extracted; and receiving the kernel demand description text by using the automatic reconstruction model of the depth kernel code obtained by optimization solution, and reconstructing the kernel code to generate the kernel code meeting the kernel demand description text. According to the method, feature extraction is carried out on structural features representing a logic sequence and a logic structure of an example code and semantic features representing semantic information of a function description text, and the example code similar to semantic of a kernel demand description text is selected to carry out code structure reconstruction and kernel code generation.
Owner:WUXI INSTITUTE OF TECHNOLOGY

Accelerating linear algebra kernels for any processor architecture

Systems and methods for obtaining a set of instructions for executing a computer program and generating executable code for the computer program based, at least in part, on scheduling operations associated with the executable code according to a polyhedral representation of a directed acyclic graph. The set of instructions may be represented as a domain-specific language. The executable code may be executable code for a specific processor architecture.
Owner:NVIDIA CORP

Vulnerability risk level determination method, related system and computer storage medium

The invention discloses a kernel vulnerability detection method, a related system and a computer storage medium. The method can comprise the steps of obtaining to-be-detected information of a target kernel layer; inputting the to-be-tested information of the target kernel layer into a vulnerability risk model to obtain a compiling vulnerability and a running vulnerability of the target kernel layer; and determining a vulnerability risk level of the target kernel layer based on the compiling vulnerability of the target kernel layer and the operation vulnerability of the target kernel layer. Therefore, the method adopts a mode of inputting the to-be-tested information of the target kernel layer into the vulnerability risk model to firstly determine the compiling vulnerability and the running vulnerability of the target kernel layer, and then determines the vulnerability risk level of the target kernel layer through the compiling vulnerability of the target kernel layer and the running vulnerability of the target kernel layer. Vulnerabilities generated during compiling and vulnerabilities generated during running are fully considered, so that the two methods can mutually compensate for the limitation of self detection, and the false alarm rate is reduced.
Owner:WUHAN ANTIY MOBILE SECURITY

Automatic system call specification generation method and system for kernel fuzz testing

The invention relates to the technical field of software testing, and provides an automatic system call specification generation method and system for kernel fuzz testing. The method comprises the following steps: a static analysis stage: compiling a Linux kernel source code to be tested into an LLVM byte code, and performing deep static analysis on the LLVM byte code to identify and reconstruct an interface and a parameter type called by a system; a symbol execution and specification generation stage: adopting a constraint extraction and solution algorithm to extract constraints under different paths, carrying out constraint solution, and generating an initialized calling specification template in combination with an interface called by the system, the parameter type and the constraints; a standard test and verification stage: constructing an evaluation system of a multi-dimensional index to verify the initialized calling standard template and generate corresponding error information; in the large language model auxiliary correction stage, the initialized calling standard template and the error information serve as input, and a high-quality calling standard template is obtained after a large model iteration repair algorithm is conducted.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Docker-based linux kernel compiling method and system

The invention discloses a docker-based linux kernel compiling method and a docker-based linux kernel compiling system, which are characterized in that standardized kernel compiling environment docker mirror images are respectively constructed for server operating systems and desktop operating systems of different target architectures, uploading environment docker mirror images are constructed for different target kernel architectures, two types of compiling environment mirror images and uploading mirror images of corresponding architectures are pre-deployed by compiling nodes, and the docker-based linux kernel compiling method comprises the following steps of: constructing standard kernel compiling environment docker mirror images and uploading mirror images of corresponding architectures; the first compiling node is selected according to the compiling node scheduling rule, and the first compiling node calls the adaptive compiling environment mirror image according to the task type to perform kernel compiling, so that the consistency of the task environments with the same framework and the same type is ensured, the result certainty can be improved, and the resource reuse rate is increased; the kernel file selects the second compiling node according to the preset publishing node screening rule to start the kernel uploading environment mirror image to automatically publish the kernel file, so that the global consistency of a GPG signature algorithm and key configuration is ensured, and the stability and efficiency of a kernel delivery link are ensured.
Owner:KYLIN CORP

Linux kernel vulnerability mining method based on diversity guidance

The invention belongs to the technical field of computer software testing, and particularly relates to a Linux kernel vulnerability mining method based on diversity guidance. According to the method, firstly, collected PoCs are expressed by using a customized abstract syntax tree, clustering is carried out on the PoCs based on a Louvain community discovery algorithm, an initial diversity seed bank is constructed, and seeds are divided into a plurality of communities with different functions; in order to quantify seed diversity, a community prevalence rate index (CPR) is introduced; designing a double-layer multi-arm tiger machine scheduling framework based on the CPR, wherein the framework is used for efficiently allocating variable resources between communities and in the communities; a CPR-guided seed variation strategy is adopted to preferentially carry out rapid variation and expansion on high-diversity seeds, so that the coverage speed and efficiency of vulnerability triggering are improved. Experimental results show that compared with a current most advanced kernel fuzzy test tool, the method has the advantages that the code coverage rate is averagely increased by 17.4%, and the vulnerability discovery number is averagely increased by 9.1 times.
Owner:FUDAN UNIVERSITY

Code generation method and electronic equipment

The invention discloses a code generation method and electronic equipment, and relates to the technical field of artificial intelligence. The method comprises the following steps: generating a knowledge base according to an operation form of performing data operation on task data by an operator and an implementation demand; according to the hardware architecture data of the operator running target hardware and the knowledge base, generating a cue word of a kernel code supporting execution of a corresponding task on the target hardware; inputting the kernel code generation cue word into a code generation language model, and obtaining a kernel code generation result output by the language model; and if the kernel code generation result does not pass the test verification, adding error information in the test verification process to a kernel code generation prompt word, and re-inputting the kernel code generation prompt word to the language model until the kernel code generation result passes the test verification. According to the method and the device, the problem that hardware adaptation is difficult in the kernel code optimization process in the prior art can be solved, the kernel codes are automatically generated in the whole process, and the kernel code generation quality and the kernel code generation efficiency are improved.
Owner:INSPUR (BEIJING) ELECTRONICS INFORMATION IND CO LTD

Model compilation security evaluation method and system based on structure detection and differential analysis

The present disclosure provides a model compilation security evaluation method and system based on structural detection and differential analysis, relating to the technical field of compilation security evaluation, comprising: calling a compiler for compilation to generate intermediate representations and compilation products in each stage; performing single-file static detection on the intermediate representation graph file to identify neural network backdoor patterns embedded in the form of mathematical calculation structures in the graph; reading the intermediate representation graph file before and after operator fusion, performing differential analysis on the intermediate representation graph file before and after fusion, and identifying abnormal operators or data streams injected in the fusion stage; performing differential analysis on the kernel source code file and the machine code disassembly file to identify malicious tampering injected in the code generation or binary compilation stage; and synthesizing the detection results of multiple identification processes to perform final security evaluation on the model compilation process and generate a structured evaluation report. The present disclosure improves the identification capability of abnormal structures or potential backdoor logic hidden in the model compilation stage.
Owner:SHANDONG UNIV

Source code encryption and decryption method and device

The invention provides a source code encryption and decryption method and device, and solves the problem that a source code is easy to crack due to the defects of the existing source code encryption and decryption technology. According to the method, the relationship with the kernel of the Linux operating system is close, separation protection is carried out on the self-protection source code and the third-party open source code, and the safety of the system is improved while the system performance is guaranteed.
Owner:ROCK AI

Kernel probe generation method, apparatus, computer equipment and storage medium

This application discloses a kernel probe generation method, apparatus, computer device, and storage medium, relating to the field of operating system kernel monitoring technology. The method includes: responding to a kernel probe generation request, obtaining a target metadata file corresponding to the current operating system kernel; determining a target declarative policy file; determining a target program logic file corresponding to the target declarative policy file; and generating probe code based on the target program logic file and the target metadata file to obtain a kernel probe program. This application, by combining the target metadata file and the target declarative policy file, can dynamically generate probe program source code adapted to the current kernel version. This source code generation function decouples the kernel probe development logic from underlying kernel knowledge, eliminating the need for developers to deeply understand the kernel's internal data structures and version differences, thus lowering the development threshold. It supports not only specific operating systems or probe types but also the general Linux kernel and various probe types.
Owner:BEIJING LINX SOFTWARE CORP

A Fuzzing Test Input Generation Method and Related Devices Based on Feature Unification

The present application relates to the technical field of kernel fuzz testing, and provides a method for generating fuzz testing inputs based on unified features and related devices. The method includes: generating a function call graph and multiple control flow graphs of a target system, and integrating the function call graph and all control flow graphs to obtain an inter-procedural control flow graph; constructing a kernel code call chain based on the inter-procedural control flow graph; performing unified feature characterization modeling based on the kernel configuration file of the target system and the kernel code call chain to generate a configuration code relationship mapping table; extracting relevant information of feature-related interface functions according to the kernel code call chain, and performing syntax conversion based on the relevant information to generate a system call test specification template for feature-related interface functions; generating fuzz testing inputs for the target system based on the system call test specification template and the configuration code relationship mapping table. The method of the present application can improve the correlation between kernel feature configuration and fuzz testing inputs.
Owner:CENT SOUTH UNIV

Server network monitoring method and device

The invention discloses a server network monitoring method and device, and relates to the technical field of server monitoring, and the method comprises the steps: obtaining the function index information of a plurality of target kernel network functions in a BTF type function database; the BTF type function database comprises a plurality of kernel network functions and the function index information of each kernel network function; the target kernel network function is a kernel network function comprising a target parameter in the BTF type function database; for each target kernel network function, determining a position sequence number of a target parameter in the target kernel network function in a parameter list according to the function index information; according to the position serial number, matching a corresponding kernel probe program from a plurality of preset kernel probe programs, and mounting the kernel probe program to a corresponding target kernel network function; and when the target kernel network function is called, collecting kernel network event data through a kernel probe program. According to the method and the device, the monitoring efficiency of the Linux kernel network can be improved.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Security verification method for kernel driver, terminal device and storage medium

The present invention discloses a security verification method, a terminal device and a storage medium for kernel drivers, which analyze the Linux kernel driver source code, extract the parameters of the ioctl() system call; according to the extracted kernel driver parameters, use the kernel driver parameters to extract driver feature information; according to the extracted feature information of various kernel drivers, use the feature information of different driver programs to construct a vector matrix; construct a driver program feature information data set, use the parallel Bagging algorithm for learning, and construct a kernel driver security verifier; at any time, hook the system call ioctl(), intercept the data stream and extract the parameter values of ioctl() at this moment; according to the parameter values, extract the feature information of the kernel driver at this moment and use it as the input of the kernel driver security verifier, and perform a static comparison with the training result to determine whether the kernel driver parameters have been maliciously modified at this moment. The present invention can continuously evaluate the security status of the system in a more comprehensive way.
Owner:HUNAN UNIV

A Linux system fault diagnosis method and system based on kernel event driving

The application discloses a kind of based on kernel event-driven Linux system fault diagnosis method and system;Its operation steps: real-time capture hard exception, soft exception and resource exception event;Dynamic monitoring is carried out to CPU, memory, storage I / O and network resource use trend and mutation behavior;Complete call stack, execution parameter, lock contention state and connection metadata are formed structured fault context information when abnormal moment is comprehensively collected, CPU register state is urgently frozen to firmware reserved memory in interrupt context respectively, task structure body and kernel stack information are collected in software interrupt context, cross-CPU core state snapshot is completed in high-priority kernel thread coordination;According to system load, direct memory access transmission, atomic log addition or bare device block write mode is selected adaptively, and collected diagnostic data is written and saved;System recovery agent automatically reorganizes diagnostic data, and generates standardized diagnostic package.The application realizes the deep observability of Linux system while ensuring very low running overhead, and significantly improves fault positioning efficiency.
Owner:NARI INFORMATION & COMM TECH