Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

39 results about "Parent process" patented technology

In computing, a parent process is a process that has created one or more child processes.

Causal relationship tracking method, device and system and electronic equipment

PendingCN121814411APlatform integrity maintainanceKnowledge representationPathPingRelationship Identifier
The embodiment of the invention discloses a causal relationship tracking method, device and system and electronic equipment. The causal relationship tracking method comprises the steps that an eBPF probe mounted on a specified path of a kernel space detects a first event triggered by a first process, wherein the first event is used for creating a second process; determining whether the first process is a parent process of the second process; under the condition that the first process is not the parent process of the second process, generating a causal relationship identifier of the second process, and establishing a corresponding relationship between the process identifier of the second process and the causal relationship identifier; and under the condition that the first process is the parent process of the second process, obtaining a causal relationship identifier of the first process, and establishing a corresponding relationship between the process identifier of the second process and the causal relationship identifier.
Owner:ALIPAY COM CO LTD

Process launch constraints

A kernel of an operating system receives a request from a parent process (e.g., an exec or spawn system call) to launch a child process that executes a binary. The kernel identifies a process-specific launch constraint, which is a precondition for launching the child process. The kernel evaluates the constraint, which can match against any type of system state or variable, including the process's location on disk, protection on disk, and how the process is to be launched. The kernel can then determine whether to launch the child process, thus permitting the child process to be scheduled for execution by the operating system. Launch constraints can be used both for a child process to impose preconditions on the parent process, and vice versa. Launch constraints can be included in the launch request, embedded in the binary, or located elsewhere, such as in a trust cache in kernel memory.
Owner:APPLE INC

Multi-process analyte monitoring and communication system

Systems and methods are provided for improved analyte processing with data that was captured by analyte monitors. Analyte data entries are processed with multiple child processes and the child processes pass results to a parent process. The parent process aggregates the children results to result in faster processing times. The analyte data is processed in a backend system that is linked to user computing devices with graphical user interfaces.
Owner:EDDII INC

A Knowledge Graph-Based Intelligent Method and System for Detecting Software Backdoors

This invention relates to the field of software detection technology, specifically disclosing a knowledge graph-based intelligent detection method and system for software backdoors. The method involves intercepting system kernel events and reading the object handle table to generate a time-series interaction log. Based on this log, a time-series knowledge graph is constructed, forming an interconnected network composed of process nodes, token nodes, and relationships such as handle holding, token replication, and memory writes. Newly added process nodes with process creation timestamps are further extracted as target process nodes, and the nominal parent process node is located based on its parent process identifier. Subsequently, a lineage consistency check is performed around the target process node, and cross-chain constraint analysis is conducted using the nominal parent process node, anonymous process nodes, token nodes, and memory write relationships. When contradictions arise in handle permissions, token inheritance, and write timing, and the lineage forgery index exceeds a preset threshold, the target process node is determined to be a parent process deceiving a backdoor process, and a threat interception command is output.
Owner:SHENZHEN HAIYUNAN NETWORK SECURITY TECH CO LTD

Method, device and equipment for process management, medium and product

The invention relates to the technical field of operating systems, and discloses a process management method, device and equipment, a medium and a product, the method comprises the following steps: if an ended first process exists, changing a parent process of a child process under the first process before changing the parent process of the child process under the first process; obtaining an orphan process recovery process of the namespace where the first process is located, an end reason identifier of the first process and a first sub-process list under the orphan process recovery process; after the parent process of the child processes under the first process is changed, a child process second list under the orphan process recovery process is obtained, and a to-be-recognized orphan process list is determined based on the first list and the second list; and based on the ending reason identifier, judging whether the first process exits normally, and if the ending reason identifier represents that the first process exits abnormally, ending the processes in the orphan process list to be identified. According to the method, the orphan process can be quickly and accurately positioned, and compared with the related technology of identifying the orphan process through polling, the method can reduce the identification overhead and improve the identification efficiency.
Owner:北京长擎量子技术有限公司

Process tree creating method and device, medium, equipment and computer program product

The invention discloses a process tree creating method and device, a medium, equipment and a computer program product. The method comprises the steps that a template process tree of a template container is obtained, and the template process tree comprises a plurality of template processes; generating a child process based on the template process, wherein the template process is used as a parent process of the child process; resources of the sub-process and the template process are isolated, and the sub-process is added to a target container; and updating the relationship of each sub-process based on the relationship between each template process in the template process tree, and taking the process tree formed by each sub-process as a target process tree. Therefore, the parallel degree of process creation in the process tree in the process tree creation process can be improved, and the process creation efficiency is effectively improved.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Data persistence processing method and device, electronic equipment and storage medium

ActiveCN116627716BData setDatabase
Embodiments of the present application provide a data persistence processing method and device, electronic equipment and computer readable storage medium, and relate to the technical field of computer servers. When a parent process creates a child process by executing a branch function operation, the central processing unit node where the child process is located is recorded, and a directly connected hard disk thereof is selected as a current persistent file data disk, and if not, it is stored by default. After generating a target persistent file in the snapshot mode, it is judged whether the target persistent file and the current persistent file are in the same hard disk, and if yes, the current persistent file is deleted, and the parent process updates statistical information. Otherwise, the current persistent file is first marked as an old file, and after updating the statistical information, the current persistent file is deleted, thereby solving the problem that when the data set is relatively large or the server needs to cross the road to write data, the time for stopping processing the client is too long, and the efficiency of server data persistence processing is improved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Data persistence method and device and electronic equipment

The embodiment of the invention discloses a data persistence method and device and electronic device.The data persistence method comprises the steps that in response to a persistence instruction, a child process corresponding to a parent process is created, memory metadata corresponding to the parent process is copied to the child process, and the data persistence instruction is obtained; and running the sub-process to copy an address mapping table corresponding to the parent process at the data persistence moment based on the memory metadata and the corresponding query table, and in response to completion of copying of the sub-process, obtaining memory data pointed by a multi-level address mapping table in the sub-process for persistence, the lookup table is used for recording original table item information of table items with table updating in the parent process address mapping table from the data persistence moment. Therefore, according to the embodiment of the invention, the child process completes the copying operation of each level of address mapping table, and the table item change caused by the data operation processed by the parent process is recorded through the lookup table, so that the persistent data integrity is ensured, the parent process data processing delay caused by data persistence is reduced, and the system performance is improved.
Owner:BEIJING DIDI INFINITY TECH & DEV CO LTD

Method and device for anomaly detection using N-gram subject tuples

An anomaly detection method incorporated with an anomaly detection device running an operating system is disclosed and includes steps of: storing a parent-child relationship upon a process creation; retrieving every upper layer parent-child relationship relating to a parent process; creating a process chain according to the parent-child relationship and every upper layer parent-child relationship relating to the parent process; dividing the process chain into M N-gram subject tuples; and examining an odd of each of the N-gram subject tuples by inquiring a prevalence model and determining whether a creation of a process is an anomaly event according to the odd.
Owner:TXONE NETWORKS INC

Model service method and device, equipment and storage medium

The invention discloses a model service method and device, equipment and a storage medium, and relates to the technical field of data processing, and the model service method comprises the steps: obtaining a model service request, and determining the type of the model service request; based on the type, determining a target module for processing the request from a started Modelet model engine; the Modelet model engine is used for performing initial processing on a request based on a target module and performing other processing on the initially processed request based on an original model service externally provided by a started local through a reverse proxy mode, and the Modelet model engine is designed by adopting father and son processes and a reverse proxy architecture and is designed by adopting the father and son processes and the reverse proxy architecture based on the father and son processes and the reverse proxy architecture. After the engine is started, the engine serves as a parent process to start a child process of the original model, so that the Modelet model engine reversely agents the original model, and corresponding original model services are provided. The method guarantees stable operation of large model services.
Owner:CHINA MERCHANTS BANK

Modeling method and device based on process construction, electronic equipment and storage medium

The invention provides a modeling method and device based on process construction, electronic equipment and a storage medium, in the method, definition and design of a process are separated, in a definition view of a parent process primitive, an external structure of the parent process primitive is defined, and in a design view of the parent process primitive, an external structure of the parent process primitive is defined; according to the method, internal logic and an execution path of a parent process primitive are designed, meanwhile, the internal logic and the execution path support layered structure design, the layered structure design reflects the idea that the process primitive can be refined layer by layer, the parent process primitive serves as a parent process and can be refined into sub-processes on the lower layer, and the execution sequence of the sub-processes is represented through dominant arrows. The sub-process can continue to refine the sub-process of the lower layer, namely modeling of the complex process can be achieved, logic expression is visual, in addition, design of process codes of the parent process primitives is supported, coexistence of code logic (namely the process codes) and internal logic design of the parent process primitives is achieved, and the method is more flexible and convenient to use.
Owner:BEIJING TONGYU ZHICHENG TECH CO LTD

A Deployment Method and System for Compute-Intensive Applications Based on Openresty

The present invention provides a method and system for deploying compute-intensive applications based on Openresty. The system is implemented based on the Openresty system. In the initialization stage, the system creates a global Lua buffer for sharing resources among child processes. The system includes a child process management module for creating child processes, managing idle child processes, recycling abnormal child processes, and protecting against overload; LuaSocket is introduced in the child processes for bidirectional communication between the parent and child processes based on the TCP protocol; an Nginx worker process is configured to be responsible for the entry and exit of the system network and serve as the parent process of the child processes; TCP communication is established between the child processes and the parent process; in the content processing stage, the child processes are responsible for processing user requests, forwarding, and outputting responses. This solution can solve the problem that compute-intensive processes block the Openresty system. Static data is loaded by the global Lua virtual machine to avoid multiple compute processes from loading a large amount of static resource data multiple times; a standard C interface module is provided and can be directly loaded without additional encapsulation and development.
Owner:北京中科通量科技有限公司

A method and system for detecting and blocking container escape in Linux operating system

This invention discloses a method and system for detecting and blocking container escape in a Linux operating system. The method includes: inserting a probe into a kernel function via the perf_event function of a user-space module, the kernel function including the fork function and the sys_execve function; obtaining the execution behavior of the kernel function through the probe and obtaining the process ID of the current process; constructing a first namespace set for the current process and establishing a mapping relationship between the process ID and the first namespace; based on the execution status of the current process, obtaining a shell process that creates a bounce due to a namespace change through the probe, obtaining the shell process through the kernel function and obtaining a second namespace set and its corresponding parent process, as well as a namespace set with PID 1; sending the corresponding parent process namespace set, the second namespace set, and the namespace set with PID 1 to an observation module for comparison and judgment, determining whether container escape exists based on the comparison result, and killing the container escape program.
Owner:HANGZHOU MORESEC TECH CO LTD

High availability method and device of zero-trust authentication server and computer equipment

The invention relates to the technical field of computers, and discloses a high-availability method and device of a zero-trust authentication server and computer equipment. The method is applied to a parent process in a zero-trust authentication server, the zero-trust authentication server further comprises a plurality of sub-processes, and the method comprises the following steps: acquiring process data of a first sub-process; the process data comprises at least one of an exit identifier, performance data, log data and heartbeat data; the exit identifier is used for indicating an exit reason of the first sub-process; the first sub-process is one of a plurality of sub-processes; and monitoring the first sub-process based on the process data. According to the invention, high availability of the zero-trust authentication server is realized.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Data acquisition method, electronic equipment, storage medium and program product

The invention provides a data acquisition method, electronic equipment, a storage medium and a program product, and relates to the technical field of cloud security, in the embodiment, a data packet filter is mounted in a pipeline writing function and a pipeline reading function in a kernel in advance, and if pipeline information corresponding to written data and pipeline information corresponding to read data are matched with parent process information, the data packet filter is loaded into the pipeline writing function and the pipeline reading function in advance; if it is possible that there is no file attack behavior, process information and write-in data related to the behavior are reported to a user space, so that recording of the no file attack behavior is achieved. Through a data packet filter mounting mode, data can be triggered and acquired in real time, an attack blind area caused by a detection window interval is avoided, moreover, key services cannot be delayed, and the performance and the stability are better. Besides, genetic relationship verification is achieved by judging whether parent process information corresponding to the write-in data and parent process information corresponding to the read data are matched or not, the association precision of the write-in data and the read data can be improved, and therefore the accuracy of no-file-attack-behavior recognition is improved.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Gateway and gateway hot upgrade method and system

The present disclosure discloses a gateway and a gateway hot upgrade method and system, related to the field of cloud computing. The method includes that: a connection between a parent process before a hot upgrade of a service request and a child process after the hot upgrade of the service request is cut off in response to receiving an exit signal, where the service request is used for establishing the connection between the child process after the hot upgrade and the parent process before the hot upgrade, and the child process is used for receiving port information and file descriptor information transferred by the parent process after the connection is established; and the parent process is exited, and the service request is processed based on the port information and the file descriptor information through the child process.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

Distributed File System Access Method, Device, Host, and Medium

The present disclosure provides a method, apparatus, host, and medium for accessing a distributed file system. The method includes: receiving a user operation code; enabling a parent process and a child process, where the child process executes the user operation code and jumps to the parent process when an access instruction for the distributed file system is executed. The parent process executes the access instruction and returns to the child process after the access instruction is executed. The parent process is a security framework process within the platform to which the distributed file system belongs. Embodiments of the present disclosure improve the security, convenience, and universality of accessing the distributed file system.
Owner:ALIBABA GROUP HOLDING LTD

Multi-stage trusted parent process chain simulation test and defense enhancement method

The invention relates to the technical field of network security, and discloses a multi-stage trusted parent process chain simulation test and defense enhancement method, which comprises the following steps of: embedding a simulated malicious behavior into a child process of a legal interpreter process in simulation operation to generate a multi-stage process chain, the legal interpreter process comprises a parent process and a child process of each process; performing context behavior simulation and analysis on the multi-stage process chain to generate a cross-level behavior graph; identifying an abnormal process chain and a legal process chain of the multi-stage process chain based on the cross-level behavior map; and modifying the defense rule based on the behavior characteristics of the abnormal process chain, and modifying the defense white list based on the behavior characteristics of the legal process chain. According to the method, cross-level hidden attacks can be effectively identified, and the network security is ensured.
Owner:CHINA YANGTZE POWER +2

Node level container mutation detection

A computer-implemented method for determining container information associated with detected container mutation events is disclosed. The computer-implemented method includes: determining that a system call event to a host operating system includes a call to join a namespace and execute a parent process inside the namespace; determining that the namespace is associated with an existing container; responsive to determining that the namespace is associated with an existing container, determining that the system call event further includes a call to execute a child process inside the namespace; and responsive to determining that the system call event further includes a call to execute a child process inside the namespace: designating the child process as a mutation event to the existing container, and determining container information associated with the mutation event to the existing container. A corresponding computer system and computer program product are also disclosed.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Method for bypassing download progress monitoring of a pipe buffer and use thereof

The application provides a download progress monitoring method bypassing pipeline buffering and application thereof, and belongs to the technical field of embedded system software upgrading. The application solves the problem that the parent process cannot acquire the download progress of the child process in real time due to the full buffering mechanism of the pipeline, and causes UI lag. The technical scheme points are as follows: a first process starts a second process to execute downloading and specifies a local storage path, so that a data stream bypasses a standard output pipeline and is directly written into a file system; the first process acquires the real-time size of the corresponding file through polling a file system interface as the downloaded amount, and the process is independent of the communication pipeline between the two processes; and the real-time progress is calculated and output in combination with the expected total size acquired in advance. The application realizes millisecond-level real-time monitoring and smooth display of the progress, significantly improves the user experience during system updating, and is mainly used in the OTA upgrading scene of embedded devices.
Owner:SHENZHEN SHENGQIANG TECH

Tracking of files required for running malware processes

Processes operating in a computing system are tracked. The tracking data includes or identified child processes, parent processes, and / or files associated with operation of the processes. When a process is determined to be a malware process, protective operations are performed. Protective operations may include removing or purging the malware process and all processes / files associated with the malware process in the tracking data. An infected snapshot may also be generated such that characteristics, operating procedures, and other aspects of the malware can be determined by recovering the infected snapshot to a sandbox environment and allowing the malware to execute therein.
Owner:DELL PROD LP

Dynamic updating method and system for network security attack and defense drilling range flag

The invention belongs to the technical field of network and information security, and discloses a method and system for dynamically updating flags in a network security attack and defense drilling range, and the method comprises the steps: capturing a reading operation on a preset flag file in a target host kernel layer through a file system monitoring mechanism, and triggering the collection of traceability information; the traceability information comprises an access process identifier, an executable file hash, a parent process chain, a call stack entry point and a memory page hash abstract, the flag generation unit combines the traceability information with a host unique identifier, an event timestamp and an incremental counter, and new flag content is generated through calculation of an HMAC or signature hash algorithm; embedding the hash value of the previous version to form a chained verification field; and the updating and auditing unit writes the new flag content into a temporary file, replaces the original file in an atomic mode after synchronous disk falling, generates an auditing record containing old version Hash, new version Hash, an event signature and a timestamp, and transmits the auditing record to the central platform through a TLS bidirectional authentication channel.
Owner:BEIJING LANGU TECHNOLOGY CO LTD

Debugging method, electronic device and storage medium

An embodiment of the present application provides a debugging method, an electronic device, and a storage medium, wherein the above-mentioned test configuration method is applied to an electronic device, including: after the first user space init process of the operating system of the electronic device completes the log redirection configuration, it jumps to create a child process, wherein the init process stagnates as a parent process after creating the child process; a temporary system environment is established through the child process, and the temporary system environment can read and write the native system environment file of the electronic device; the child process uses the temporary system environment to view or modify the native system environment file; in response to the signal of the termination of the child process, the init process is notified to end the stagnation and continue execution. The present application realizes debugging by interacting with the debugging device as soon as possible during the initial stage of the startup of the init process of the electronic device, that is, after the Linux system completes the basic system environment configuration, thereby advancing the debugging timing and improving the debugging efficiency.
Owner:SPREADTRUM COMM (TIANJIN) INC

NUMA-aware mickey concurrent access control method and system

This application provides a NUMA-aware concurrent access control method and system for key cards, including: a parent process creating shared memory partitioned by NUMA nodes and pre-parsed the global lock symbol of the key card library, storing the virtual address of the global lock in the header of the shared memory, and the shared memory being used to store the contention rate, ticket allocator, and current service ticket corresponding to each NUMA node; a child process obtaining the virtual address of its own NUMA node and the global lock, obtaining the state of the global lock through read-only memory mapping, where read-only memory mapping is a mapping method that only reads and does not modify the original memory of the key card library; the child process performing layered avoidance operations according to the state of the NUMA node and the global lock to complete the key card initialization. This application does not modify the source code of the key card library, does not add proxy processes, avoids the thundering herd problem of global lock and inefficiency of cross-node access, reduces high-concurrency initialization latency and lock conflict rate, and ensures system stability.
Owner:CHINA UNICOM INTERNET OF THINGS CO LTD +1

Progressive augmentation of threat timeline visualization

Security events are reported to a threat management facility for an enterprise network as self-contained lineages that include data concerning related processes such as a parent or child process related to the source of the event. By transmitting these to a short term data store, threat timeline visualizations can be more quickly rendered for an analyst in a user interface, after which the visualization can be augmented with other data from other sources such as a data lake or other long term data repository for the enterprise network, third party reputation sources, and so forth.
Owner:SOPHOS LTD

Parent process identification method, device, electronic device, storage medium and program

The present invention provides a method, apparatus, electronic device, storage medium and program for identifying a parent process. The method includes: after detecting that a target process is created, determining the default parent process of the target process; when the default parent process is a system process, determining whether the target thread of the target process is a remote procedure call thread; and when the target thread of the target process is a remote procedure call thread, obtaining information about the real parent process from the thread environment block of the target thread. The method, apparatus, electronic device, storage medium and program for identifying a parent process provided by the present invention can identify a target process created by any process in a DCOM manner and obtain information about the real parent process corresponding to the target process, thereby improving the security defense ability.
Owner:QI AN XIN SECURITY TECH ZHUHAI CO LTD +1

Linux important process monitoring method and device

The invention relates to the field of process monitoring, in particular to a Linux important process monitoring method and device.The method comprises the steps that a process tree system is built, and a parent process and child processes are decoupled; the parent process waits for the state change of the child process through waitpid blocking, captures an exit signal of the child process, and immediately triggers an automatic restart mechanism when it is detected that the child process is abnormally terminated; and according to the error defense system, performing resource leakage protection processing and environment isolation processing on the independent operation spaces of the parent process and the child process. The method has the advantages that the real-time performance is improved, the resource consumption is reduced, the reliability is enhanced, the deployment is simplified, and the expandability is high.
Owner:HENAN ZHONGYUAN CONSUMER FINANCE CO LTD

Method and device for anomaly detection using n-gram subject tuples

An anomaly detection method incorporated with an anomaly detection device running an operating system is disclosed and includes steps of: storing a parent-child relationship upon a process creation; retrieving every upper layer parent-child relationship relating to a parent process; creating a process chain according to the parent-child relationship and every upper layer parent-child relationship relating to the parent process; dividing the process chain into M N-gram subject tuples; and examining an odd of each of the N-gram subject tuples by inquiring a prevalence model and determining whether a creation of a process is an anomaly event according to the odd.
Owner:TXONE NETWORKS INC

Service process configuration method and related device

The present application provides a service process configuration method and a related device. The method comprises: by means of an editing operation performed on a target sub-process node, which is referenced by a current parent process, in a service process structure page, displaying a first resource attribute editing page corresponding to the target sub-process node; for each different current parent process displayed in the service process structure page, switching a corresponding target resource attribute configuration item to an editable state according to usage requirements of a corresponding scenario and by means of an unlocking operation performed on the required target resource attribute configuration item in the first resource attribute editing page; and determining a first target resource attribute by means of a configuration operation on the target resource attribute configuration item which is in the editable state, and configuring the target sub-process node in the current parent process according to the first target resource attribute.
Owner:BEIJING ZITIAO NETWORK TECH CO LTD

Data access control method and system based on microkernel power mechanism

The invention discloses a data access control method and system based on a microkernel power mechanism. The method comprises the following steps: defining an access power type in a power space architecture of a microkernel system; when a system is initialized, a root process is created by a kernel, and the root process is endowed with access capability to all files under a root directory. When the process is created, the parent process creates an independent power branch for the child process based on the own power space, and endows the own access power to the child process. And when the processes run, the first process transmits the access power of the owned file or directory to the second process through power transmission operation. And when the process requests to access the target file, performing multi-level directory power matching verification in the power space of the process based on the path information of the target file, and determining whether access is allowed or not according to a verification result. And when the process requests to cancel the access capability of the target file, positioning and modifying the corresponding capability slot in the capability space of the process based on the information of the capability to be cancelled.
Owner:SHENYANG INST OF ENG