WO2016082501A1 - 一种云计算系统中云应用攻击行为处理方法、装置及系统 - Google Patents
一种云计算系统中云应用攻击行为处理方法、装置及系统 Download PDFInfo
- Publication number
- WO2016082501A1 WO2016082501A1 PCT/CN2015/079897 CN2015079897W WO2016082501A1 WO 2016082501 A1 WO2016082501 A1 WO 2016082501A1 CN 2015079897 W CN2015079897 W CN 2015079897W WO 2016082501 A1 WO2016082501 A1 WO 2016082501A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- cloud
- application
- behavior
- security
- rule
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/566—Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/30—Definitions, standards or architectural aspects of layered protocol stacks
- H04L69/32—Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
- H04L69/322—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
- H04L69/329—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the application layer [OSI layer 7]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/121—Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
- H04W12/122—Counter-measures against attacks; Protection against rogue devices
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/128—Anti-malware arrangements, e.g. protection against SMS fraud or mobile malware
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45587—Isolation or security of virtual machine instances
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1466—Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/10—Protocols in which an application is distributed across nodes in the network
Definitions
- the present invention relates to the field of computer technologies, and in particular, to a method, device and system for processing a cloud application attack behavior in a cloud computing system.
- cloud computing has three service models: SaaS (software as a service) and PaaS (platform as a service platform). Service) and IaaS (infrastructure as a service).
- PaaS is a business model that provides a server platform as a service.
- PaaS mainly provides hardware resources such as CPU and memory for cloud applications, as well as software resources such as operating system and program dependency library. Developers of cloud applications do not have to care about the software and hardware environment in which the application runs, and concentrate on developing the application itself.
- the emergence of PaaS has accelerated the development and deployment of cloud applications, so in the Internet era, more and more cloud applications will be deployed to cloud computing systems.
- a cloud computing system In order to increase the utilization of system hardware resources, multiple cloud applications are usually run in the same cloud host (hardware host or virtual host, different cloud computing systems have different Implementation), the cloud computing system provides the necessary system resource isolation for the cloud application, and ensures that the cloud applications running in the same cloud host do not interfere with each other. At the same time, the cloud computing system also provides a virtual network within the cloud host for communication between cloud applications.
- a new traffic detection device is added to the cloud computing system through the switch.
- the cloud host connection of the cloud computing system is used to detect the data flow injected into the cloud host in the cloud computing system, including the data flow of the user outside the cloud computing system accessing the cloud application, and the data exchanged between the cloud hosts in the cloud computing system. flow.
- the flow detection device counts the amount of data flow injected into a cloud host within a predetermined period of time. When the statistically obtained traffic value exceeds a predetermined threshold, the traffic injected into the cloud host is considered abnormal. After detecting the abnormality of the traffic, the traffic detection device notifies the traffic cleaning device to start.
- the traffic cleaning device cleans the data traffic injected into the cloud host, filters the attack packets, and sends the cleaned data stream to the cloud host. .
- the prior art solution can only prevent attacks between cloud hosts within the cloud computing system, or external attacks to cloud hosts within the cloud computing system, but cannot prevent mutual attacks between different cloud applications within the same cloud host, or clouds. Attacks on the cloud host itself inside the host.
- the prior art solution performs traffic monitoring and cleaning on a cloud host unit, which affects all cloud applications in the target cloud host.
- Embodiments of the present invention provide a method, a device, and a system for processing a cloud application attack behavior in a cloud computing system, which are used for application level security protection of a cloud computing system, and minimize normal cloud applications in the cloud computer system. influences.
- an embodiment of the present invention provides a processing device for a cloud application attack behavior in a cloud computing system, including:
- the policy manager is used to store security judgment rules and malicious application processing rules
- the security analyzer is configured to receive application behavior data sent by a security detector on at least one of the plurality of cloud hosts in the cloud computing system, and determine the cloud according to the application behavior data and a security judgment rule stored in the policy manager. Whether the cloud application running on the host has an attack behavior, and when determining that the cloud application running on the cloud host has an attack behavior, sending the application behavior data to the security processor; wherein the application behavior data is on the cloud host.
- the security detector obtains the cloud application according to the behavior detection rule, and the application behavior data is used to indicate the running state of the cloud application.
- a security processor configured to process a cloud application that has an attack behavior by using an interface provided by a cloud controller in the cloud computing system according to a malicious application processing rule stored in the policy manager, the cloud control
- the device is communicatively coupled to the cloud host in the cloud computing system or integrated on a cloud host for controlling the cloud application running on the cloud host in the cloud computing system.
- the apparatus further includes: an information notifier; and the policy manager is further configured to store an information notification rule;
- the security analyzer is further configured to: when determining that the cloud application has an attack behavior, obtain initial information of the cloud application and send the initial information to the security processor, where the initial information is used to uniquely identify the cloud application;
- the security processor is further configured to: query the user information to which the cloud application belongs according to the initial information of the cloud application, and send the user information and the application behavior data of the cloud application to the information notifier;
- the information notifier is configured to store the received application behavior data and user information and perform attack information notification processing according to the information notification rule stored in the policy manager.
- the policy manager is configured to convert the security judgment rule into a behavior detection rule and deliver the behavior detection rule to the security detector of each cloud host.
- the malicious application is a cloud application that has an attack behavior; a processor, specifically configured to perform corresponding processing on the cloud application according to a type of an attack behavior of the cloud application, and a processing manner of the type application indicated by the malicious application processing rule; or the security processor Specifically, the cloud application is processed according to a risk level of the attack behavior of the cloud application, and a processing manner of the application of the risk level indicated by the malicious application processing rule.
- the attack information notification processing specifically includes one or any combination of the following: generating alarm information and displaying an attack behavior
- the cloud application and the user information to which the cloud application belongs, and the user information to which the cloud application having the attack behavior belongs are notified to the network police center.
- the cloud application attack behavior processing apparatus is integrated in the cloud controller.
- the configuration interface of the policy manager includes: at least one of a configuration interface and an application program interface.
- the behavior detection rule includes: a process detection rule or a thread detection rule;
- the data is obtained by the security detector detecting the process or thread of the cloud application according to the behavior detection rule.
- the security analyzer is further configured to discard the behavior data of the cloud application when determining that the cloud application does not have an attack behavior.
- the cloud host can be a physical machine or a virtual machine running on the physical machine.
- the application running on the cloud host is a cloud application, and one cloud application is running on the cloud host, Each cloud application is used to implement the corresponding business function.
- a security detector is configured on each cloud host, and the security detector is configured to use the behavior detection rule on the cloud host.
- the behavior of the running cloud application is collected, and the application behavior data generated by the collected result is reported to the security analyzer.
- the security detector reports the application behavior data to the security analyzer periodically, or based on the request, or according to the pre-configured reporting policy.
- the security judgment rule is used to define what behavior of the cloud application is an attack behavior
- the malicious application processing rule is used to define an attack for the presence. What kind of processing is applied to the cloud application of the behavior; the behavior detection rule is used to indicate the detection indicator for detecting the cloud application.
- the cloud application with the attack behavior is defined as a malicious application.
- the security analyzer or the security processor is configured to query the pre-invention according to the behavior data of the cloud application.
- the configured application signature database is used to determine the type of application attack behavior, wherein the application signature database is used to describe the mapping relationship between the application's behavior characteristics and the application's attack behavior type.
- the application feature database is an independent data set in the cloud computing system or a subset of security judgment rules; After the security analyzer determines that a cloud application is a malicious application according to the security judgment rule, the security analyzer further determines the attack behavior type of the malicious application according to the application feature database included in the security judgment rule.
- the degree of danger of the cloud application is used to characterize the degree of harm of the cloud application to the cloud computing system.
- the security analyzer or the security processor is configured to determine the risk of the attack behavior of the application by querying the mapping table according to the type of the attack behavior according to the application, wherein the mapping table is used to represent the type of the attack behavior and the corresponding degree of the risk. relationship.
- the user information of the cloud application includes, but is not limited to, one of a username, a user mailbox, or a user ID number. Multiple.
- the initial information of the cloud application includes, but is not limited to, one or more of a process ID and a process name.
- the calling the cloud controller to process the malicious includes one or any combination of the following: shutting down the malicious application, or applying the malicious application Migrate to quarantined cloud hosts and ban user accounts for malicious applications.
- the cloud application attack behavior processing device is a cloud host in the cloud computing system, where the cloud host is running in the physical An on-board virtual machine; the physical machine includes a hardware layer, a virtual machine monitor running on the hardware layer, and a host machine and a plurality of virtual machines running on the virtual machine monitor, wherein the hardware layer includes a processor and a memory
- the cloud host runs an executable program, and the executable program includes: a policy manager module, a security analyzer module, a security processor module, and an information notifier module, wherein the policy manager module is used to implement any of the above possible
- the security analyzer module is used to implement the function of the security analyzer in any of the above possible implementation manners
- the security processor module is used to implement the security processing in any of the above possible implementation manners.
- the information notifier module is used to implement the function of the information notifier in any of the above possible
- the cloud application attack behavior processing apparatus includes: at least one processor, Memory, at least one communication bus.
- the communication bus is used to implement connection communication between these components.
- the memory stores the following elements, executable modules or data structures, or a subset of them, or their extension set:
- An operating system that contains various system programs for implementing various basic services and handling hardware-based tasks
- An application module that contains various cloud applications for implementing various application services.
- the application module includes modules that implement the functions of a policy manager, a security analyzer, a security processor, and an information notifier.
- an embodiment of the present invention provides a cloud application attack behavior processing method, which is used in a cloud computing system including multiple cloud hosts, and the method includes:
- the cloud application that is in the cloud computing system is invoked to process the cloud application that has the attack behavior according to the malicious application processing rule, where the cloud controller is connected to the cloud controller.
- the cloud host is integrated or integrated with the cloud host to control the cloud application running on the cloud host.
- the method further includes:
- the user information of the cloud application is queried according to the initial information of the cloud application that has the attack behavior, where the initial information is used to identify the cloud application;
- the application behavior data of the cloud application with the attack behavior and the queried user information are stored, and the attack information notification processing is performed according to the information notification rule.
- the method further includes:
- the received application behavior data is discarded.
- the malicious application is a cloud application that has an attack behavior;
- the interface processes the cloud application with attack behavior, including: according to the cloud application.
- the type of attack behavior, and the manner in which the application is processed by the malicious application processing rule, and the cloud application is processed accordingly; or according to the degree of danger of the attack behavior of the cloud application, and the malicious application processing rule
- the cloud application is processed accordingly by the way the application of the risk level is handled.
- the attack information notification processing according to the information notification rule includes the following One or any combination:
- the alarm information is generated, the cloud application that displays the attack behavior, the user information to which the cloud application belongs, and the user information to which the cloud application having the attack behavior belongs are notified to the network police center.
- the method further includes: converting the security judgment rule into a behavior detection rule, and This behavior detection rule is sent to the security detector.
- one of a security judgment rule, a malicious application processing rule, and an information notification rule or The plurality of configurations are configured by configuring an interface, where the configuration interface includes at least one of a configuration interface and an application interface.
- the cloud host can be a physical machine or a virtual machine running on the physical machine.
- the application running on the cloud host is a cloud application, and one cloud application is running on the cloud host, where Each cloud application is used to implement the corresponding business functions.
- a security detector is configured on each cloud host, and the security detector is configured to run the cloud on the cloud host according to the behavior detection rule.
- the behavior of the application is collected, and the application behavior data is reported according to the collected result.
- the security detector periodically reports the application behavior data, or reports the report based on the request, or reports according to the pre-configured reporting policy.
- the security judgment rule is used to define what behavior of the cloud application is an attack behavior
- the malicious application processing rule is used for Define the processing method for the cloud application that has the attack behavior
- the behavior detection rule is used to indicate the detection indicator for detecting the cloud application.
- the cloud application with the attack behavior is defined as a malicious application.
- the pre-configured application feature database is queried according to the behavior data of the cloud application to determine the type of the application attack behavior.
- the application feature library is used to describe the mapping relationship between the application's behavior characteristics and the application's attack behavior type.
- the application feature database is a separate data set in the cloud computing system or a subset of security judgment rules; After determining that the cloud application is a malicious application, the determining rule further determines the attack behavior type of the malicious application according to the application feature database included in the security judgment rule.
- the degree of danger of the cloud application is used to characterize the degree of harm of the cloud application to the cloud computing system.
- the degree of danger of the applied attack behavior is determined by querying the mapping table, wherein the mapping table is used to represent the correspondence between the type of the attack behavior and the degree of danger.
- the user information of the cloud application includes, but is not limited to, one or more of a user name, a user mailbox, or a user ID number. .
- the initial information of the cloud application includes, but is not limited to, one or more of a process ID and a process name.
- the calling the cloud controller to process the malicious includes one or any combination of the following: shutting down the malicious application, or migrating the malicious application to Isolated cloud hosts, as well as user accounts that block malicious applications.
- an embodiment of the present invention provides a cloud application security protection system, including: a cloud application attack behavior processing device, a cloud controller, and a plurality of security detectors; wherein multiple security detectors are respectively deployed in multiple On the cloud host, each cloud host corresponds to a security detector; the cloud controller is connected to multiple cloud hosts for managing and controlling multiple cloud hosts, and each cloud host runs one or more cloud applications. ; cloud application attack behavior processing device stores security judgment rules and malicious application places Rule of law;
- the security detector is configured to detect one or more cloud applications according to the behavior detection rule, to obtain application behavior data, and report the application behavior data to the cloud application attack behavior processing device; wherein the one or more cloud applications Running on the cloud host corresponding to the security detector;
- the cloud application attack behavior processing device is configured to receive application behavior data reported by the security detector on the at least one cloud host of the plurality of cloud hosts, and determine the cloud application running on the cloud host according to the application behavior data and the security judgment rule. If there is an attack behavior, if the cloud application running on the cloud host is attacked, the cloud application provided by the cloud controller is processed according to the malicious application processing rule.
- the cloud application attack behavior processing apparatus is further configured to: convert the security judgment rule into a behavior detection rule, and send the behavior detection rule to the security detector of each cloud host. .
- the cloud application attack behavior processing apparatus is further configured to: if it is determined that the cloud application running on the cloud host does not have an attack Behavior, the received application behavior data is discarded.
- the cloud application attack behavior processing apparatus is further configured to: if it is determined that the cloud application running on the cloud host has an attack behavior The cloud application that has the attack behavior and the user information to which the cloud application belongs, or the user information to which the cloud application with the attack behavior belongs is notified to the network police center.
- the application of the attack behavior processing device to the cloud controller, or the cloud application attack behavior is integrated on the cloud controller.
- the malicious application is a cloud application with an attack behavior
- the cloud application attack behavior processing device is specific Used to: process the cloud application according to the type of the attack behavior of the cloud application and the processing manner of the application indicated by the malicious application processing rule; or according to the risk degree of the attack behavior of the cloud application, and the malicious application processing
- the cloud application is processed accordingly by the way the rule indicates the application of the risk level.
- one of a security judgment rule, a malicious application processing rule, and an information notification rule or Multiples are configured through the configuration interface;
- the configuration interface described in the method includes: at least one of a configuration interface and an application program interface.
- the behavior detection rule includes: a process detection rule or a thread detection rule; the application behavior data is The security detector obtains the process or thread of the cloud application according to the behavior detection rule.
- the security judgment rule is used to define what behavior of the cloud application is an attack behavior, malicious
- the application processing rule is used to define the processing method for the cloud application that has the attack behavior;
- the behavior detection rule is used to indicate the detection indicator for detecting the cloud application.
- the attack behavior processing apparatus is configured to query the pre-configuration according to the behavior data of the cloud application.
- the application feature library is used to determine the type of application attack behavior, wherein the application feature library is used to describe the mapping relationship between the application's behavior characteristics and the applied attack behavior type.
- the application feature database is an independent data set in the cloud computing system or a subset of the security judgment rule; the application attack behavior processing device After determining that a cloud application is a malicious application according to the security judgment rule, the attack behavior type of the malicious application is further determined according to the application feature database included in the security judgment rule.
- the degree of danger of the cloud application is used to characterize the degree of harm of the cloud application to the cloud computing system;
- the application attack behavior processing apparatus is configured to determine, according to the type of the application attack behavior, the degree of danger of the attack behavior of the application by querying the mapping table, where the mapping table is used to represent the correspondence between the type of the attack behavior and the degree of danger.
- the policy manager issues a detection rule to a security detector distributed to each cloud host, and the security detector detects and reports the behavior of the application according to the behavior detection rule.
- the security analyzer determines the application of the attack behavior by analyzing the behavior data of the application, and invokes the cloud controller to perform corresponding processing.
- the embodiment of the present invention performs the cloud computing application level. Security protection can meet the deployment scenarios of cloud computing system applications, prevent mutual attacks between different applications within the same host, or attack the host itself within the host, and reduce the impact on normal applications.
- FIG. 1 is a schematic diagram of a principle of a cloud computing system attack processing method in the prior art
- FIG. 2 is a structural diagram of a cloud computing system according to an embodiment of the present invention.
- FIG. 3 is a schematic diagram of a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
- FIG. 4 is a schematic diagram of a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
- FIG. 5 is a schematic structural diagram of a policy manager according to an embodiment of the present invention.
- FIG. 6 is a working flow chart of a security analyzer according to an embodiment of the present invention.
- FIG. 7 is a schematic structural diagram of a security processor according to an embodiment of the present invention.
- FIG. 8 is a schematic structural diagram of an information notifier according to an embodiment of the present invention.
- FIG. 9 is a flowchart of a method for processing a cloud application attack behavior according to an embodiment of the present invention.
- FIG. 10 is a flowchart of a method for processing a cloud application attack behavior according to an embodiment of the present invention.
- FIG. 11 is a schematic diagram of a cloud application security protection system according to an embodiment of the present invention.
- FIG. 12 is a schematic diagram of a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
- FIG. 13 is a schematic diagram of a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
- FIG. 1 depicts the physical architecture of a cloud computing system.
- a cloud computing system typically includes multiple physical computers (referred to simply as physical machines) interconnected by switches, and these physical machines can pass through the sink.
- the physical switch can be a physical entity such as a computer or a server.
- a physical machine of the cloud computing system can be called a cloud host.
- one or more virtual machines can be simulated on a single physical computer through virtual machine software, and these virtual machines can work like real computers, and can be installed on virtual machines.
- System install applications, access network resources, and more.
- a cloud computing system may include thousands of virtual machines, and each virtual machine can run applications independently. Therefore, in other more general networking scenarios, virtual machines in cloud computing systems usually It is called a cloud host or a virtual cloud host, and an application running on a cloud host is called a cloud application. Therefore, the cloud host described in all embodiments of the present invention is not limited to a virtual machine or a physical machine, and needs to be determined according to a specific networking scenario.
- the cloud computing system further includes a cloud controller for controlling and managing the cloud host in the cloud computing system, and the cloud controller may be one of several virtual machines included in the cloud computing system, and in some cases, the cloud The controller can also be an independent physical machine.
- the cloud controller can have one or more; the cloud controller is connected to the cloud host in the cloud computing system or integrated on a cloud host for control.
- the solution of the embodiment of the present invention may be specifically implemented by a cloud host in a cloud computing system, and in some cases, may also be implemented by a cloud controller.
- the cloud computing system is generally divided into an infrastructure and a virtualization layer (IaaS layer), a platform layer (PaaS layer), and an application layer (SaaS layer).
- IaaS layer virtualization layer
- PaaS layer platform layer
- SaaS layer application layer
- the solution of the embodiment of the present invention may be implemented by a cloud computing system.
- the platform layer is implemented, and may be implemented by a cloud controller of the platform layer or another separate functional unit.
- FIG. 3 is a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
- the processing device can be a cloud host of the cloud computing system or integrated as a functional unit in the cloud controller.
- the cloud computing system includes a cloud application attack behavior processing device 20, a cloud controller 206, and a plurality of cloud hosts (such as cloud hosts 10, 11, and 12 in FIG.
- the cloud application attack behavior processing apparatus 20 includes a policy manager 201, a security analyzer 202, and a security processor 203.
- the policy manager 201 is mainly used for storing, converting, and delivering rules.
- the policy manager 201 may store a security judgment rule and a malicious application processing rule; the security judgment rule is used to define what behavior of the cloud application is an attack behavior, and the malicious application processing rule is used to define a cloud application for the presence of the attack behavior. What kind of treatment?
- the policy manager 201 can convert the security judgment rule into a behavior detection rule, and the behavior detection rule is used to define which behavior of the cloud application is detected, that is, the behavior detection rule indicates that the cloud application is detected. Test indicators. Usually behavior detection rules and security judgment rules are closely related, so they can be transformed into each other.
- the security judgment rule is: the number of TCP ports requested by the cloud application exceeds 100, the cloud application is determined to have port sniffing behavior; then the corresponding behavior detection rule is: collecting cloud application requests for different TCP ports. number.
- the security detector on the cloud host should detect the number of different TCP ports requested by the cloud application and report the detection result to the security analyzer 202.
- the security analyzer 202 can determine whether the cloud application has port sniffing behavior.
- the security analyzer 202 is configured to receive the application behavior data reported by the security detector on the at least one of the plurality of cloud hosts in the cloud computing system, and then determine the cloud according to the security judgment rule stored in the policy manager 201. Whether the cloud application on the host has an attack behavior. If it is determined that the cloud application has an attack behavior, the initial information of the cloud application with the attack behavior is sent to the security processor 203; wherein the initial information of the cloud application is used to uniquely identify the cloud application, for example, in a specific embodiment. The initial information can be either a process ID or a process name, or both.
- the application behavior data of the cloud application reported by the security detector may be reported periodically, or may be reported based on the request, or may be reported according to the pre-configured reporting policy, which is not limited in the embodiment of the present invention.
- the security processor 203 is mainly configured to: after receiving the initial information of the cloud application that has the attack behavior sent by the security analyzer 202, invoke the interface provided by the cloud controller 206 according to the malicious application processing rule stored in the policy manager 201.
- a cloud application in which an attack behavior exists (in the embodiment of the present invention, a cloud application having an attack behavior is collectively referred to as a malicious application) is processed.
- the security processor 203 may employ a unified approach to all malicious applications, such as shutting down malicious applications, or migrating malicious applications to isolated cloud hosts, or disabling user accounts for malicious applications.
- secure processing The 203 may also perform different levels or different types of processing on the malicious application according to the type of the malicious application attack behavior or the risk of the attack behavior.
- the migration may be performed by means of migration or isolation.
- the user account of the malicious application can be banned and so on. It can be understood that, in this case, in order to determine the type or degree of danger of malicious application attack behavior, the security analyzer 202 needs to report the application behavior data of the malicious application together with the initial information to the security processor 203 for secure processing.
- the device 203 determines the type or the degree of danger of the attack behavior of the malicious application according to the behavior data of the malicious application; of course, the security analyzer 202 can also determine the type or degree of danger of the applied attack behavior according to the behavior data of the application, and then The analysis result is fed back to the security processor 203, which is not specifically limited in the embodiment of the present invention.
- the security analyzer 202 can distinguish the malicious application from the normal application according to the behavior data of the cloud application and the security judgment rule, and then the security analyzer 202 or the security processor can further query the pre-configured application feature database to determine the malicious application.
- the type of attack behavior such as a denial of service attack, a Trojan attack or a worm attack.
- the security analyzer 202 determines the malicious application that has the attack behavior according to the behavior data of the cloud application and the security judgment rule
- the security analyzer 202 or the security processor 203 can query the pre-configured according to the behavior data of the cloud application.
- the signature database is applied to determine the type of attack behavior applied, and then the degree of danger of applying the attack behavior is further determined according to the type of attack behavior applied.
- the application feature library is used to describe the mapping relationship between the behavior characteristics of the application and the attack behavior type of the application; optionally, the application feature database may be an independent data set in the cloud computing system, and the security analyzer 202 is based on the cloud application.
- the application signature database may be further queried to determine the type of the attack behavior of the malicious application; of course, the application signature database may also be a subset of the security judgment rule.
- the attack behavior type of the malicious application may be further determined according to the application feature database included in the security judgment rule. It can be understood that the degree of danger of different types of attacks is different, and it is determined according to the degree of harm to the system by the attack behavior, and the greater the harm to the cloud computing system, the higher the degree of danger.
- a mapping table can be configured to represent the correspondence between the type of attack behavior and the degree of danger of the application, so that the risk of the applied attack behavior can be determined by looking up the table according to the type of the attack behavior.
- the security processor 203 may also process the malicious application according to the security level of the cloud computing system, and different security levels correspond to different processing manners.
- the security level of a cloud computing system can be set to "High”, “Medium”, and “Low”. When the security level of the cloud computing system is "High”, the security processor 203 can close the malicious application and prohibit the user account of the malicious application; when the cloud computing system When the security level is "low”, the security processor 203 can migrate the malicious application to a specific cloud host for isolation.
- the three processing modes of the malicious processor 203 for the malicious application that is, the unified processing manner described above, the processing method according to the type of attack behavior or the degree of danger, and the processing method according to the security level of the cloud computing system may be adopted.
- the malicious application processing rule indicates that different processing modes correspond to different malicious application processing rules, and the malicious application processing rules can be configured by the administrator through the configuration interface of the policy manager 201.
- malicious application processing rules can be used to indicate how different types of malicious applications are handled, or how malicious applications of different degrees of risk are handled, or how malicious applications are handled at different levels of security of the cloud computing system;
- the processor 203 may specifically process the malicious application according to the type of the attack behavior of the application and the processing manner of the application indicated by the malicious application processing rule; or the security processor 203 may specifically according to the risk of the applied attack behavior.
- the degree, and the manner in which the malicious application processing rule indicates the application of the dangerous degree, the malicious application is processed correspondingly; or the security processor 203 may be specifically according to the current security level of the cloud computing system and the malicious application processing rule The malicious application is processed at this security level, and the malicious application is processed accordingly.
- the cloud application attack behavior processing device provided by the embodiment of the present invention is issued by the policy manager as a detection rule to a security detector distributed to each cloud host, and the security detector detects and reports the behavior data of the cloud application according to the behavior detection rule, and the security analysis is performed.
- the cloud application of the attack behavior is determined, and the cloud controller is invoked to perform corresponding processing.
- the embodiment of the present invention performs security protection based on the cloud computing application level. It can meet the deployment scenarios of cloud computing system applications, prevent mutual attacks between different cloud applications within the same host, or attack the host itself within the host, and reduce the impact on normal cloud applications.
- the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
- the cloud application attack behavior processing apparatus 20 may further include: an information notifier 204; the information manager 201 further stores an information notification rule;
- the security processor 203 is further configured to: query the user information to which the cloud application belongs according to the initial information of the cloud application that has the attack behavior, and send the queried user information and the behavior data of the cloud application to the information.
- the notifier 204 wherein the user information of the cloud application includes but is not limited to: a username, a user mailbox, or a user ID number.
- the information notifier 204 is configured to back up the received application behavior data and the user information to which the cloud application belongs, and perform attack information notification processing according to the information notification rule stored in the policy manager.
- the application behavior data and the user information to which the cloud application belongs are backed up, and may be stored in a reliable storage medium in a data format such as a form, a log, or a document for the administrator to view.
- the information notifier 204 performs attack information notification processing including but not limited to one or more of the following operations: generating alarm information, displaying a cloud application in which an attack behavior exists, and a user to which the cloud application belongs.
- the information, as well as the user information to which the cloud application that has the attack behavior belongs, is notified to the network police center.
- the application behavior data may be discarded.
- the policy manager 201 includes a configuration interface through which an administrator can configure one or more of a security judgment rule, a malicious application processing rule, and an information notification rule.
- the configuration interface may be one or more of a graphical user interface (GUI), a webpage configuration interface, or an application program interface (API).
- GUI graphical user interface
- API application program interface
- different processing rules may be configured according to the attack type or the degree of danger of the malicious application, so as to implement the difference processing, thereby implementing the flexibility and scalability of the security protection.
- one or more of the three rules can also be configured by the cloud computing system according to the default rules.
- the behavior detection rule sent by the policy manager to the security detector may include: a process detection rule or a thread detection rule.
- the security detector can detect the cloud application at the process or thread level, and the security analyzer can determine the process or thread with the attack behavior based on the detection result of the security detector, and then the security processor can process the attack behavior.
- thread processing in order to achieve security protection of the process or thread sector.
- the cloud application attack behavior processing device provided by the embodiment of the present invention is further described in detail below with reference to a specific example.
- the cloud application attack behavior processing device is a cloud host 30.
- Cloud master The main workflow of machine 30 is as follows:
- the security judgment rule for determining the attack behavior of the application is configured through the configuration interface of the policy manager 201, wherein the configuration action can be completed by an administrator or by a configuration program running on the cloud computing system.
- the security judgment rule is: require different tcp port>100, that is, the number of requested TCP ports exceeds 100.
- the judgment rule indicates that when the number of TCP ports requested by the cloud application exceeds 100, the judgment is performed.
- Cloud applications have port sniffing behavior;
- the policy manager 201 converts the security judgment rule into a behavior detection rule: detecting the number of the TCP port requested by the cloud application, and sending the behavior detection rule to the security detector 205 deployed on the cloud host 10;
- the security detector 205 detects the behavior of the App A and the App B, for example, the number of the TCP port requested by the App A and the AppB is reported, and the application behavior data is generated and reported to the security analyzer 202;
- the security analyzer 202 determines that the number of TCP ports requested by the App B exceeds 100 according to the collected application behavior data and the security judgment rule, and therefore determines that the App B has an attack behavior;
- the security analyzer 202 sends the initial information of the App B, such as the process ID, or the process name, to the security processor 203;
- the security processor 203 queries the user information of the AppB from the cloud computing system application library according to the initial information of the App B;
- the security processor 203 invokes the cloud controller to close the App B, or migrates the App B to the isolated cloud host, or prohibits the user account of the App B;
- the security analyzer notifies the information notification device 204 of the user information of the App B, and the information notifier 204 reports it to the network police center for filing.
- the cloud application attack behavior processing device successfully detects and processes the port sniffing behavior of App B, and does not seriously affect App A. Further, after discovering that App B has an attack behavior, the security analyzer may further adopt different processing manners for the App according to the type of attack behavior of the App B or the degree of danger.
- the processing manner of the malicious application may be indicated by a malicious application processing rule, and the malicious application processing rule may be configured by an administrator through a configuration interface of the policy manager 201.
- the configuration interface may be a WEB interface or an API or the like.
- the Policy Manager 201 provides a configuration interface to the administrator or the automatic configuration program, and is mainly responsible for the operation of the rule storage, the rule conversion, and the rule delivery. As shown in FIG. 5, the policy manager 201 includes: a configuration interface 2011, a rule conversion unit 2012, a rule delivery unit 2013, and a rule storage unit 2014; wherein the configuration interface 2011 includes but is not limited to: a graphical user interface (GUI), a webpage A form of configuration interface or one or more of an application programming interface (API).
- GUI graphical user interface
- API application programming interface
- the configurable rules through the configuration interface 2011 include: security judgment rules, malicious application processing rules, and information notification rules.
- the rule storage unit 2014 stores the various rules configured by the administrator through the configuration interface 2011 into the corresponding rule base; the rule conversion unit 2012 can convert the security judgment rule configured by the administrator into a behavior detection rule, and the rule delivery unit 2013 is responsible for The behavior detection rule is sent to the security detector on the cloud host.
- Security analyzer 202 As shown in FIG. 6, the security analyzer is mainly responsible for receiving application behavior data sent by the security detector, and then determining whether the cloud application has an attack behavior according to the security judgment rule stored in the policy manager. If it is determined that there is an attack behavior, the initial information of the cloud application (including the process ID, the process name, and the like) is sent to the security processor. If it is determined that there is no attack behavior, the application behavior data can be discarded.
- the security processor is responsible for processing with malicious applications. Specifically, as shown in FIG. 7, the security processor 203 mainly includes an application information receiving unit 2031, a user information query unit 2032, an application processing unit 2033, and an information reporting unit 2034.
- the application information receiving unit 2031 receives the initial information of the malicious application reported by the security analyzer, and the user information querying unit 2032 queries the cloud computing system application information database for the user information to which the cloud application belongs, including but not limited to the user name, the user mailbox, and the user identity. Certificate and other information.
- the user information query unit 2032 then reports the user information and the behavior information of the malicious application to the information notifier through the information reporting unit 2034, so that the information notifier performs the attack information notification process according to the information notification rule stored in the policy manager.
- the application processing unit 2033 calls the interface provided by the cloud controller to process the malicious application according to the malicious application processing rule stored in the policy manager. Processing methods include, but are not limited to, closing applications, migrating applications to quarantined cloud hosts, disabling user accounts, and the like.
- the information notifier 204 includes: an application information receiving unit 2041, and an information notification policy determining unit 2042; wherein the application information receiving unit 2041 is responsible for receiving The application behavior information and the user information to which the cloud application belongs are received; then the information notification policy determination unit 2042 performs the attack information notification process according to the information notification rule stored in the policy manager. Specifically, the information notification policy determining unit 2042 may invoke or trigger the alarm generating unit 2043 to generate alarm information, such as generating an alarm interface. Optionally, the information notification policy determining unit 2042 may invoke or trigger the information presentation unit 2044 to form the table in the WEB page. The information of the malicious application is presented.
- the information notification policy determining unit 2042 may also invoke or trigger the information notification unit to report the information of the malicious application to the network alarm center.
- the information notifier may include any one of the alarm generating unit 2043, the information presenting unit 2044, and the information notifying unit 2045, and may also include any two of the three, or may include three of them.
- the specific application scenario needs to be determined, and the embodiment of the present invention is not particularly limited.
- the cloud application attack behavior processing device provided by the embodiment of the present invention can meet the application scenario of the cloud computing system application, implement security protection based on the cloud computing application level, prevent mutual attacks between different cloud applications within the same host, or host to the host internally. Attacks by itself while reducing the impact on normal cloud applications. Further, the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
- the cloud application attack behavior processing device may be a cloud host in a cloud computing system, and the cloud host may be a virtual machine running on a physical machine.
- the physical machine 1200 includes a hardware layer 100, a VMM (Virtual Machine Monitor) 110 running on the hardware layer 100, and a host Host 1201 and several virtual machines running on the VMM 110.
- VM Virtual Machine
- the cloud application attack behavior processing apparatus provided by the embodiment of the present invention may be specifically a virtual machine in the physical machine 1200, such as VM 1202.
- One or more cloud applications are run on the VM 1202, where each cloud application is used.
- the VM 1202 is also configured to execute a program, and the VM 1202 calls the executable program, and calls the hardware resource of the hardware layer 100 through the host Host 1201 during the running of the program to implement the policy management of the cloud application attack behavior processing device.
- the executable program may include: a policy manager module, a security analyzer module, a security processor module, and an information notifier module, and the VM 1202 runs the executable program by calling resources such as CPU and Memory in the hardware layer 100.
- resources such as CPU and Memory in the hardware layer 100.
- the cloud application attack behavior processing apparatus provided by the embodiment of the present invention may also be a physical machine in the cloud computing system. As shown in FIG. 13, the physical machine 1300 includes: at least one processing.
- the device 1301, such as a CPU has at least one network interface 1304, a memory 1305, and at least one communication bus 1302. Communication bus 1302 is used to implement connection communication between these components.
- the physical machine 1300 optionally includes an input/output device 1303 including a display, a keyboard or a pointing device (eg, a mouse, a trackball, a touchpad, or a tactile display).
- the memory 1305 may include a high speed RAM memory and may also include a non-volatile memory such as at least one disk memory.
- the memory 1305 can optionally include at least one storage device located remotely from the aforementioned processor 1301.
- the memory 1305 stores the following elements, executable modules or data structures, or a subset of them, or their extension set:
- An operating system 13051 including various system programs for implementing various basic services and processing hardware-based tasks;
- the application module 13052 includes various cloud applications for implementing various application services, such as a database application, a map application, and the like.
- the application module 13052 includes, but is not limited to, a module that implements the functions of the policy manager, the security analyzer, the security processor, and the information notifier of the cloud application attack behavior processing device.
- each module in the application module 13052 refers to the device and method embodiments of the present invention, and details are not described herein.
- the security detector provided by the embodiment of the present invention may be a functional module on the cloud host in the cloud computing system.
- the security detector may be independently operated on the virtual machine.
- An application that, when executed by the virtual machine, can detect the behavior of other cloud applications running on the virtual machine.
- the security detector may be an application stored in the memory of the physical machine, and the CPU of the physical machine can implement other clouds running on the physical machine by reading and executing the application. The function of the application's behavior detection.
- the embodiment of the present invention further provides a cloud application attack behavior processing method applied to a cloud computing system, where the cloud computing system includes multiple cloud hosts, and the cloud host may be a physical machine, or A virtual machine; at least one of the plurality of cloud hosts of the cloud computing system is a cloud controller, and the cloud controller is connected to or integrated with each cloud host in the cloud computing system to control the cloud computing system.
- the cloud application attack behavior processing method provided by the embodiment of the present invention may be executed by a cloud host in the cloud computing system, or may be executed by the cloud controller. As shown in FIG. 9, the method includes:
- S901 Receive application behavior data reported by at least one of the plurality of cloud hosts in the cloud computing system; the application behavior data is a cloud that is executed by the security detector deployed on the cloud host according to the behavior detection rule. The application is obtained after the detection, and the application behavior data is used to indicate the running status of the cloud application running on the cloud host;
- S902 Determine, according to the application behavior data and the security judgment rule, whether the cloud application running on the cloud host has an attack behavior
- the interface provided by the cloud controller is used to perform corresponding processing on the cloud application that has the attack behavior, including: invoking the cloud controller: shutting down the cloud application, migrating the cloud application to the isolated cloud host, or prohibiting the User account for the cloud application.
- the user information of the cloud application may be queried according to the initial information of the cloud application in which the attack behavior exists, and then the attack behavior is performed.
- the application behavior data of the cloud application and the queried user information are backed up, and the attack information notification process is performed according to the information notification rule.
- the initial information of the cloud application is used to uniquely identify the cloud application, and the initial information may be a process ID or a process name. Or both: the user information of the cloud application includes but is not limited to: user name, user mailbox or user ID number.
- the application behavior data and the user information to which the cloud application belongs are backed up, and may be stored in a reliable storage medium in a data format such as a form, a log, or a document for the administrator to view.
- the attack information notification process includes, but is not limited to, one of the following operations or any combination thereof: generating the alarm information, displaying the cloud application in which the attack behavior exists, and the user information to which the cloud application belongs, or the cloud application to which the attack behavior exists User information informs the network police center.
- step S903 if it is determined that the cloud application running on the cloud host does not have an attack behavior, the received application behavior data of the cloud application is discarded.
- the security judgment rule is used to define what behavior of the cloud application is an attack behavior
- the malicious application processing rule is used to define a processing manner for the cloud application that has the attack behavior
- the behavior detection rule is used to define the cloud application. What kind of behavior is detected, that is, the behavior detection rule indicates the detection index for detecting the cloud application.
- the behavior detection rule and the security judgment rule are closely related and can be converted into each other. Therefore, in a preferred embodiment, the security judgment rule can be converted into a behavior detection rule and then sent to the security detector.
- the security judgment rule is: the number of TCP ports requested by the cloud application exceeds 100, the cloud application is determined to have port sniffing behavior; then the corresponding behavior detection rule is: collecting cloud application requests for different TCP ports. number. In this way, the security detector on the cloud host should detect the number of different TCP ports requested by the cloud application and the detection result.
- a unified processing manner may be adopted for all cloud applications (malicious applications) in which the attack behavior exists, such as shutting down the malicious application, or migrating the malicious application to the isolated cloud host, or prohibiting the user account of the malicious application.
- the malicious application may be processed to different degrees or different types according to the type of the malicious application attack behavior or the risk of the attack behavior. For example, for a malicious application with a lower degree of danger, migration or isolation may be adopted. Processing, for high-risk malicious applications, you can disable the user account of the application and so on.
- the malicious application and the normal application can be distinguished, and then the pre-configured application signature database can be further queried to determine the type of the attack behavior of the malicious application, for example, a denial of service attack, the Trojan Attack or worm attack and so on.
- the pre-configured application feature database may be queried according to the behavior data of the cloud application to determine the type of the application attack behavior.
- the application feature library is used to describe the mapping relationship between the behavior characteristics of the application and the type of attack behavior of the application; optionally, the application feature
- the levy database may be an independent data set in the cloud computing system. After determining the malicious application having the attack behavior according to the behavior data of the cloud application and the security judgment rule, the application feature database may be further queried to determine the malicious application.
- the type of attack behavior of course, the application signature database may also be a subset of the security judgment rules. After determining that a cloud application is a malicious application according to the security judgment rule, the application signature database may be further determined according to the application signature database included in the security judgment rule.
- the type of attack behavior of a malicious application It can be understood that the degree of danger of different types of attacks is different, and it is determined according to the degree of harm to the system by the attack behavior, and the greater the harm to the cloud computing system, the higher the degree of danger.
- a mapping table can be configured to represent the correspondence between the type of attack behavior and the degree of danger of the application, so that the risk of the applied attack behavior can be determined by looking up the table according to the type of the attack behavior.
- the malicious application may also be processed according to the security level of the cloud computing system, and different security levels correspond to different processing modes.
- the security level of the cloud computing system can be set to three levels: “high”, “medium”, and “low”.
- the security level of the cloud computing system When the security level of the cloud computing system is “high”, the malicious application is closed and the user account of the malicious application is prohibited. When the security level of the cloud computing system is “low”, the malicious application is migrated to a specific cloud host for isolation.
- the three processing modes for malicious applications that is, the unified processing method described above, the processing method according to the type of attack behavior or the degree of danger, and the processing method according to the security level of the cloud computing system, can be processed by malicious applications. To indicate that different processing modes correspond to different malicious application processing rules.
- the administrator may configure one or more of the security judgment rules, the malicious application processing rules, and the information notification rules through the configuration interface.
- the configuration interface may be a WEB interface or an API or the like.
- different processing rules may be configured according to the attack type or the degree of danger of the malicious application, so as to implement the difference processing, thereby implementing the flexibility and scalability of the security protection.
- one or more of the three rules can also be configured by the cloud computing system according to the default rules.
- the behavior detection rule may include: a process detection rule or a thread detection rule.
- the application can be detected at the process or thread level, and then the process or thread having the attack behavior is determined based on the detection result, and the process or thread having the attack behavior is processed, thereby implementing the security protection of the process or the thread boundary.
- the cloud application attack behavior processing method provided by the embodiment of the present invention can meet the application scenario of the cloud computing system application, implement security protection based on the cloud computing application level, prevent mutual attacks between different applications within the same host, or internal to the host itself. Attacks while reducing the impact on normal applications.
- the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
- the cloud application attack behavior processing method includes the following main workflows:
- the security detector detects the cloud application behavior according to the behavior detection rule and reports the application behavior data
- 5A invokes the cloud controller to close the malicious application, or migrate the malicious application to the isolated cloud host, or prohibit the user account of the malicious application;
- the cloud application attack behavior processing device successfully detects and processes the malicious application without seriously affecting the normal application. Further, after the application is found to have an attack behavior, the malicious application may be further processed according to the type or degree of risk of the malicious application.
- the processing manner of the malicious application may be indicated by a malicious application processing rule, and the malicious application processing rule may be configured by an administrator through a configuration interface.
- the configuration interface may be a graphical user interface (GUI), a webpage configuration interface, an application program interface (API), or the like.
- the cloud application attack behavior processing method provided by the embodiment of the present invention can meet the cloud application system application deployment scenario, and performs security protection based on the cloud computing application level to prevent different internal hosts from being the same. Use mutual attacks, or internal attacks on the host itself, while reducing the impact on normal applications. Further, the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
- the embodiment of the present invention further provides a cloud application security protection system, which is applied to a cloud computing system, and is used to implement the cloud application attack behavior processing method, where the cloud application security protection system includes: a cloud application attack The behavior processing device 20, the cloud controller 206, and the plurality of security detectors (exemplified by 205 in FIG. 11); wherein the plurality of security detectors are respectively deployed on the plurality of cloud hosts (10, 11 in FIG.
- each cloud host corresponds to a security detector
- the cloud controller 206 is communicatively connected to a plurality of cloud hosts, or integrated into one of the plurality of cloud hosts for management and control
- the plurality of cloud hosts each of which runs one or more cloud applications
- the cloud application attack behavior processing device 20 stores security judgment rules and malicious application processing rules
- the security detector 205 is configured to detect one or more cloud applications according to the behavior detection rule, to obtain application behavior data, and report the application behavior data to the cloud application attack behavior processing apparatus 20; wherein the one or more clouds The application runs on the cloud host 10 corresponding to the security detector 205;
- the cloud application attack behavior processing device 20 is configured to receive application behavior data reported by the security detector 205 on the at least one cloud host of the plurality of cloud hosts, and determine the cloud running on the cloud host 10 according to the application behavior data and the security judgment rule. Whether the application has an attack behavior; if it is determined that there is an attack behavior, the cloud controller 206 is invoked to process the cloud application that will have the attack behavior according to the malicious application processing rule.
- the foregoing behavior detection rule may be obtained by the cloud application attack behavior processing device after the security judgment rule is converted and sent to the security detector.
- the cloud application attack behavior processing device 20 determines that the cloud application running on the cloud host has an attack behavior
- the user information of the cloud application that belongs to the attack behavior may be queried according to the initial information of the cloud application, and then the existence The application behavior data of the cloud application of the attack behavior and the queried user information are backed up, and the attack information notification processing is performed according to the information notification rule; wherein the initial information of the cloud application is used to uniquely identify the cloud application, and the initial information may be a process ID or The process, or both, includes; user information of the cloud application includes but is not limited to: user name, user mailbox, or user ID number.
- the application behavior data and the user information to which the cloud application belongs are backed up, specifically It is stored on a reliable storage medium in a data format such as a form, log, or document for administrators to view.
- the attack information notification process includes, but is not limited to, generating the alarm information, displaying the cloud application in which the attack behavior exists, and the user information to which the cloud application belongs, or notifying the network police center of the user information to which the cloud application having the attack behavior belongs.
- the cloud application attack behavior processing device 20 is communicatively coupled to the cloud controller 206, or the cloud application attack behavior processing device 20 is integrated on the cloud controller 206.
- the cloud application attack behavior processing apparatus 20 includes a configuration interface through which an administrator or a configuration program can configure one of a security judgment rule, a malicious application processing rule, and an information notification rule.
- the configuration interface may be a graphical user interface (GUI), a webpage configuration interface, an application program interface (API), or the like.
- GUI graphical user interface
- API application program interface
- different processing rules may be configured according to the attack type or the degree of danger of the malicious application, so as to implement the difference processing, thereby implementing the flexibility and scalability of the security protection.
- one or more of the three rules can also be configured by the cloud computing system according to the default rules.
- the behavior detection rule sent by the cloud application attack behavior processing device 20 to the security detector may include: a process detection rule or a thread detection rule.
- the security detector can perform process or thread level detection on the cloud application, and the cloud application attack behavior processing device 20 can determine the process or thread in which the attack behavior exists based on the detection result of the security detector, and then the process in which the attack behavior exists.
- thread processing in order to achieve security protection of the process or thread sector.
- the cloud application attack behavior processing device 20 included in the cloud application security protection system of the embodiment of the present invention may be the cloud application attack behavior processing device described in any of the foregoing device embodiments, and specific implementation details may be referred to.
- the foregoing apparatus and method embodiments are not described herein again.
- the cloud application attack behavior detection system can meet the application scenario of the cloud computing system application, implement security protection based on the cloud application application level, prevent mutual attacks between different applications within the same host, or internal to the host itself. Attacks while reducing the impact on normal applications.
- the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
- the storage medium may include: a ROM, a RAM, a magnetic disk, or an optical disk.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims (22)
- 一种云计算系统中云应用攻击行为的处理装置,其特征在于,包括:安全分析器,安全处理器和策略管理器,其中:所述策略管理器用于存储安全判断规则和恶意应用处理规则;所述安全分析器用于接收云计算系统中的多个云主机中的至少一个云主机上的安全检测器发送的应用行为数据,根据所述应用行为数据以及所述策略管理器中存储的安全判断规则,确定所述至少一个云主机上运行的云应用是否存在攻击行为,并在确定所述至少一个云主机上运行的云应用存在攻击行为时,将所述应用行为数据发送给所述安全处理器;其中,所述应用行为数据是所述安全检测器根据行为检测规则对所述云应用进行检测后得到的,且所述应用行为数据用于表示所述云应用的运行状态;所述安全处理器,用于根据所述策略管理器中存储的恶意应用处理规则,调用所述云计算系统中的云控制器提供的接口对所述云应用进行处理,所述云控制器与所述至少一个云主机通信连接或集成于所述至少一个云主机,用于控制所述至少一个云主机上运行的云应用。
- 根据权利要求1所述的装置,其特征在于,还包括:信息通知器;所述策略管理器中还存储有信息通知规则;所述安全分析器还用于,当确定所述云应用存在攻击行为时,获取所述云应用的初始信息并发送给所述安全处理器,其中,所述初始信息用于标识所述云应用;所述安全处理器还用于,根据所述云应用的初始信息查询所述云应用所属的用户信息,将所述用户信息和所述应用行为数据发送给所述信息通知器;所述信息通知器用于,将接收到的应用行为数据和云应用所属的用户信息存储并按照所述策略管理器中存储的信息通知规则进行攻击信息通知处理。
- 根据权利要求1或2所述的装置,其特征在于,所述策略管理器用于,将所述安全判断规则转化为所述行为检测规则,并将所述行为检测规则下发给所述至少一个云主机的安全检测器。
- 根据权利要求1至3任一项所述的装置,其特征在于,所述恶意应用处理规则用于指示对不同类型恶意应用的处理方式,或者对不同危险程度的恶意应用的处理方式,其中,所述恶意应用为存在攻击行为的云应用;所述安全处理器,具体用于根据所述云应用的攻击行为的类型,以及所述恶意应用处理规则所指示的对该类型应用的处理方式,对所述云应用进行相应处理;或者所述安全处理器,具体用于根据所述云应用的攻击行为的危险程度,以及所述恶意应用处理规则所指示的对该危险程度的应用的处理方式,对所述云应用进行相应处理。
- 根据权利要求2至4任一项所述的装置,其特征在于,所述攻击信息通知处理具体包括以下之一或其任意组合:产生告警信息、显示存在攻击行为的云应用以及该云应用所属的用户信息、以及将存在攻击行为的云应用所属的用户信息通知网警中心。
- 根据权利要求1至5任一项所述的装置,其特征在于,所述云应用攻击行为处理装置集成于所述云控制器。
- 根据权利要求2至6任一项所述的装置,其特征在于,所述安全判断规则、恶意应用处理规则和信息通知规则中的一项或多项是通过所述策略管理器的配置接口配置的,其中所述策略管理器的配置接口包括:配置界面和应用程序接口API中的至少一种。
- 根据权利要求1至6任一项所述的装置,其特征在于,所述行为检测规则包括:进程检测规则或线程检测规则;所述应用行为数据是所述安全检测器根据所述行为检测规则对所述云应用的进程或线程进行检测后得到的。
- 根据权利要求8所述的装置,其特征在于,所述安全分析器还用于在确 定所述云应用不存在攻击行为时,丢弃所述应用行为数据。
- 一种云应用攻击行为处理方法,用于包括多个云主机的云计算系统,其特征在于,包括:接收所述多个云主机中的至少一个云主机上报的应用行为数据,其中,所述应用行为数据是所述至少一个云主机上的安全检测器根据行为检测规则对所述至少一个云主机上运行的云应用进行检测后得到的,且所述应用行为数据用于表示所述至少一个云主机上运行的云应用的运行状态;根据所述应用行为数据以及安全判断规则,判断所述至少一个云主机上运行的云应用是否存在攻击行为;如果判断所述至少一个云主机上运行的云应用存在攻击行为,则根据恶意应用处理规则,调用所述云计算系统中的云控制器提供的接口对存在攻击行为的云应用进行处理,其中所述云控制器与所述至少一个云主机通信连接或集成于所述至少一个云主机,用于控制所述至少一个云主机上运行的云应用。
- 根据权利要求10所述的方法,其特征在于,还包括:如果判断所述至少一个云主机上运行的云应用存在攻击行为,则根据所述存在攻击行为的云应用的初始信息查询所述云应用所属的用户信息,其中,所述初始信息用于标识所述云应用;将所述存在攻击行为的云应用的应用行为数据和查询到的用户信息存储,并按照信息通知规则进行攻击信息通知处理。
- 根据权利要求10或11所述的方法,其特征在于,还包括:如果判断所述至少一个云主机上运行的云应用不存在攻击行为,则丢弃接收到的所述应用行为数据。
- 根据权利要求10至12任一项所述的方法,其特征在于,所述恶意应用处理规则用于指示对不同类型恶意应用的处理方式,或者对不同危险程度的恶意应用的处理方式,其中,所述恶意应用为存在攻击行为的云应用;所述调用云控制器提供的接口对将存在攻击行为的云应用进行相应处理,包括:根据所述云应用的攻击行为的类型,以及所述恶意应用处理规则所指示的对该类型应 用的处理方式,对所述云应用进行相应处理;或者根据所述云应用的攻击行为的危险程度,以及所述恶意应用处理规则所指示的对该危险程度的应用的处理方式,对所述云应用进行相应处理。
- 根据权利要求11至13任一项所述的方法,其特征在于,所述按照信息通知规则进行攻击信息通知处理包括以下之一或其任意组合:产生告警信息、显示存在攻击行为的云应用以及该云应用所属的用户信息、以及将存在攻击行为的云应用所属的用户信息通知网警中心。
- 根据权利要求10至14任一项所述的方法,其特征在于,还包括:将所述安全判断规则转化为所述行为检测规则,并将所述行为检测规则发送给所述安全检测器。
- 根据权利要求10至15任一项所述的方法,其特征在于,所述安全判断规则、恶意应用处理规则和信息通知规则中的一项或多项是通过配置接口配置的;其中所述配置接口包括:配置界面和应用程序接口API中的至少一种。
- 一种云应用安全防护系统,其特征在于,包括:云应用攻击行为处理装置、云控制器,以及多个安全检测器;其中,所述多个安全检测器分别部署于多个云主机上,且每一云主机对应于一个安全检测器;所述云控制器与所述多个云主机通信连接,用于管理和控制所述多个云主机,每一云主机上运行有一个或多个云应用;所述云应用攻击行为处理装置中存储有安全判断规则和恶意应用处理规则;所述安全检测器用于,根据行为检测规则对一个或多个云应用进行检测,以得到应用行为数据,并将所述应用行为数据上报给所述云应用攻击行为处理装置;其中,所述一个或多个云应用运行于所述安全检测器对应的云主机上;所述云应用攻击行为处理装置用于,接收所述多个云主机的至少一个云主机上的安全检测器上报的应用行为数据,根据所述应用行为数据以及所述安全判断规则,判断所述至少一个云主机上运行的云应用是否存在攻击行为;如果判断所述至少一个云主机上运行的云应用存在攻击行为,则根据所述恶意应用处理规则,调用云控制器提供的接口对存在攻击行为的云应用进行相应处理。
- 根据权利要求17所述的系统,其特征在于,所述云应用攻击行为处理 装置还用于,将所述安全判断规则转化为所述行为检测规则,并将所述行为检测规则下发给各个云主机的安全检测器。
- 根据权利要求17或18所述的系统,其特征在于,所述云应用攻击行为处理装置还用于,如果判断所述至少一个云主机上运行的云应用不存在攻击行为,则丢弃接收到的所述应用行为数据。
- 根据权利要求17或18所述的系统,其特征在于,所述云应用攻击行为处理装置还用于,如果判断所述至少一个云主机上运行的云应用存在攻击行为,则显示存在攻击行为的云应用以及该云应用所属的用户信息、或者将存在攻击行为的云应用所属的用户信息通知网警中心。
- 根据权利要求17至20任一项所述的系统,其特征在于,所述云应用攻击行为处理装置与所述云控制器通信连接,或者所述云应用攻击行为处理装置集成于所述云控制器上。
- 根据权利要求17至21任一项所述的系统,其特征在于,所述恶意应用处理规则用于指示对不同类型恶意应用的处理方式,或者对不同危险程度的恶意应用的处理方式,其中,所述恶意应用为存在攻击行为的云应用;所述云应用攻击行为处理装置具体用于:根据所述云应用的攻击行为的类型,以及所述恶意应用处理规则所指示的对该类型应用的处理方式,对所述云应用进行相应处理;或者根据所述云应用的攻击行为的危险程度,以及所述恶意应用处理规则所指示的对该危险程度的应用的处理方式,对所述云应用进行相应处理。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP15862949.3A EP3214568B1 (en) | 2014-11-26 | 2015-05-27 | Method, apparatus and system for processing cloud application attack behaviours in cloud computing system |
| EP22192092.9A EP4160456A1 (en) | 2014-11-26 | 2015-05-27 | Method, apparatus and system for processing attack behavior of cloud application in cloud computing system |
| BR112017011074-1A BR112017011074B1 (pt) | 2014-11-26 | 2015-05-27 | Aparelho e método para processar um comportamento de ataque em um sistema de computação em nuvem |
| US15/606,855 US10567422B2 (en) | 2014-11-26 | 2017-05-26 | Method, apparatus and system for processing attack behavior of cloud application in cloud computing system |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201410709018.9A CN104392175B (zh) | 2014-11-26 | 2014-11-26 | 一种云计算系统中云应用攻击行为处理方法、装置及系统 |
| CN201410709018.9 | 2014-11-26 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US15/606,855 Continuation US10567422B2 (en) | 2014-11-26 | 2017-05-26 | Method, apparatus and system for processing attack behavior of cloud application in cloud computing system |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016082501A1 true WO2016082501A1 (zh) | 2016-06-02 |
Family
ID=52610077
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2015/079897 Ceased WO2016082501A1 (zh) | 2014-11-26 | 2015-05-27 | 一种云计算系统中云应用攻击行为处理方法、装置及系统 |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US10567422B2 (zh) |
| EP (2) | EP4160456A1 (zh) |
| CN (1) | CN104392175B (zh) |
| BR (1) | BR112017011074B1 (zh) |
| WO (1) | WO2016082501A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113965405A (zh) * | 2021-11-04 | 2022-01-21 | 杭州安恒信息技术股份有限公司 | 一种web攻击的监测方法、装置、设备及可读存储介质 |
Families Citing this family (30)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104392175B (zh) * | 2014-11-26 | 2018-05-29 | 华为技术有限公司 | 一种云计算系统中云应用攻击行为处理方法、装置及系统 |
| US20160359720A1 (en) * | 2015-06-02 | 2016-12-08 | Futurewei Technologies, Inc. | Distribution of Internal Routes For Virtual Networking |
| CN106713216B (zh) * | 2015-07-16 | 2021-02-19 | 中兴通讯股份有限公司 | 流量的处理方法、装置及系统 |
| CN105262768A (zh) * | 2015-11-04 | 2016-01-20 | 上海科技网络通信有限公司 | 一种云计算平台中基于混合模型的行为检测系统与方法 |
| US10116767B2 (en) * | 2015-11-13 | 2018-10-30 | Furturewei Technologies, Inc. | Scaling cloud rendezvous points in a hierarchical and distributed manner |
| CN105468980B (zh) * | 2015-11-16 | 2018-07-03 | 华为技术有限公司 | 一种安全管控的方法、装置及系统 |
| CN105404816B (zh) * | 2015-12-24 | 2018-11-06 | 北京奇虎科技有限公司 | 基于内容的漏洞检测方法及装置 |
| CN107179957B (zh) * | 2016-03-10 | 2020-08-25 | 阿里巴巴集团控股有限公司 | 物理机故障分类处理方法、装置和虚拟机恢复方法、系统 |
| CN107545178B (zh) * | 2016-06-23 | 2021-01-15 | 华为技术有限公司 | 一种云应用的检测方法及云应用检测装置 |
| CN107819727B (zh) * | 2016-09-13 | 2020-11-17 | 腾讯科技(深圳)有限公司 | 一种基于ip地址安全信誉度的网络安全防护方法及系统 |
| CN106570400B (zh) * | 2016-10-11 | 2019-03-15 | 杭州安恒信息技术股份有限公司 | 一种云环境下通过自学习防攻击的系统及方法 |
| US10505954B2 (en) * | 2017-06-14 | 2019-12-10 | Microsoft Technology Licensing, Llc | Detecting malicious lateral movement across a computer network |
| CN107295021B (zh) * | 2017-08-16 | 2021-06-04 | 深信服科技股份有限公司 | 一种基于集中管理的主机的安全检测方法及系统 |
| US11228616B2 (en) * | 2017-12-06 | 2022-01-18 | Qatar Foundation | Methods and systems for monitoring network security |
| CN108282489B (zh) | 2018-02-07 | 2020-01-31 | 网宿科技股份有限公司 | 一种漏洞扫描方法、服务端及系统 |
| CN108595333B (zh) * | 2018-04-26 | 2021-08-03 | Oppo广东移动通信有限公司 | PaaS平台中应用进程的健康检查方法及装置 |
| CN108769124B (zh) * | 2018-04-28 | 2021-04-27 | Oppo广东移动通信有限公司 | PaaS平台的应用部署方法、装置、服务器及存储介质 |
| CN109194623A (zh) * | 2018-08-02 | 2019-01-11 | 谢聪敏 | 基于云计算的安全服务器 |
| CN109218315B (zh) * | 2018-09-20 | 2021-06-01 | 华为技术有限公司 | 一种安全管理方法和安全管理装置 |
| CN109857726B (zh) * | 2019-02-27 | 2023-05-12 | 深信服科技股份有限公司 | 一种应用特征库维护方法、装置、电子设备及存储介质 |
| CN110099044A (zh) * | 2019-03-28 | 2019-08-06 | 江苏通付盾信息安全技术有限公司 | 云主机安全检测系统及方法 |
| CN110336784A (zh) * | 2019-05-22 | 2019-10-15 | 北京瀚海思创科技有限公司 | 基于大数据的网络攻击识别预测系统、方法以及存储介质 |
| US11368496B2 (en) * | 2019-06-11 | 2022-06-21 | Zscaler, Inc. | Automatic network application security policy expansion |
| CN111343009B (zh) * | 2020-02-14 | 2021-06-04 | 腾讯科技(深圳)有限公司 | 服务告警通知方法及装置、存储介质、电子设备 |
| CN111031077B (zh) * | 2020-03-10 | 2020-06-09 | 杭州圆石网络安全技术有限公司 | 一种流量清洗方法、流量清洗系统和设备 |
| CN111984966B (zh) * | 2020-08-31 | 2024-06-18 | 深圳平安医疗健康科技服务有限公司 | 基于Linux云平台的口令检测方法、装置、设备及存储介质 |
| CN112910895B (zh) * | 2021-02-02 | 2022-11-15 | 杭州安恒信息技术股份有限公司 | 网络攻击行为检测方法、装置、计算机设备和系统 |
| CN113504971B (zh) * | 2021-07-20 | 2024-02-13 | 华云数据控股集团有限公司 | 基于容器的安全拦截方法及系统 |
| CN115904605A (zh) * | 2021-09-30 | 2023-04-04 | 腾讯科技(深圳)有限公司 | 软件防御方法以及相关设备 |
| CN114266047B (zh) * | 2021-12-14 | 2025-02-14 | 北京天融信网络安全技术有限公司 | 一种恶意程序防御方法、装置、电子设备及存储介质 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103036745A (zh) * | 2012-12-21 | 2013-04-10 | 北京邮电大学 | 云计算中一种基于神经网络的异常检测系统 |
| CN103034807A (zh) * | 2011-10-08 | 2013-04-10 | 腾讯科技(深圳)有限公司 | 恶意程序检测方法和装置 |
| US8613089B1 (en) * | 2012-08-07 | 2013-12-17 | Cloudflare, Inc. | Identifying a denial-of-service attack in a cloud-based proxy service |
| CN104038466A (zh) * | 2013-03-05 | 2014-09-10 | 中国银联股份有限公司 | 用于云计算环境的入侵检测系统、方法及设备 |
| CN104113521A (zh) * | 2014-02-20 | 2014-10-22 | 西安未来国际信息股份有限公司 | 一种分布组件化入侵检测系统的设计 |
| CN104392175A (zh) * | 2014-11-26 | 2015-03-04 | 华为技术有限公司 | 一种云计算系统中云应用攻击行为处理方法、装置及系统 |
Family Cites Families (17)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP4379223B2 (ja) * | 2004-06-18 | 2009-12-09 | 日本電気株式会社 | 動作モデル作成システム、動作モデル作成方法および動作モデル作成プログラム |
| US7725934B2 (en) | 2004-12-07 | 2010-05-25 | Cisco Technology, Inc. | Network and application attack protection based on application layer message inspection |
| US9152789B2 (en) * | 2008-05-28 | 2015-10-06 | Zscaler, Inc. | Systems and methods for dynamic cloud-based malware behavior analysis |
| US20110083179A1 (en) | 2009-10-07 | 2011-04-07 | Jeffrey Lawson | System and method for mitigating a denial of service attack using cloud computing |
| CN102043917B (zh) | 2010-12-07 | 2012-10-17 | 成都市华为赛门铁克科技有限公司 | 云系统分布式拒绝服务攻击防护方法以及装置和系统 |
| US8539556B1 (en) * | 2010-12-20 | 2013-09-17 | Amazon Technologies, Inc. | Disabling administrative access to computing resources |
| CN102075535B (zh) | 2011-01-12 | 2013-01-30 | 中国科学院计算技术研究所 | 一种应用层分布式拒绝服务攻击过滤方法及系统 |
| CN102291390B (zh) | 2011-07-14 | 2014-06-04 | 南京邮电大学 | 一种基于云计算平台的防御拒绝服务攻击的方法 |
| CN102685180B (zh) | 2011-10-18 | 2015-07-08 | 国网电力科学研究院 | 一种面向云计算的网络安全预警方法 |
| CN102693388B (zh) | 2012-06-07 | 2014-03-19 | 腾讯科技(深圳)有限公司 | 数据安全防护处理系统及方法及存储介质 |
| CN102843385B (zh) | 2012-09-24 | 2015-04-15 | 东南大学 | 一种用于云计算环境中防范旁路攻击虚拟机的方法 |
| CN103051707A (zh) | 2012-12-20 | 2013-04-17 | 浪潮集团有限公司 | 一种基于动态用户行为的云取证方法及系统 |
| CN103902892B (zh) | 2012-12-24 | 2017-08-04 | 珠海市君天电子科技有限公司 | 基于行为的病毒防御方法及系统 |
| CN103023912A (zh) | 2012-12-26 | 2013-04-03 | 蓝盾信息安全技术股份有限公司 | 一种防止基于虚拟机进行网络攻击的方法 |
| US9361455B2 (en) * | 2013-01-02 | 2016-06-07 | International Business Machines Corporation | Security management in a networked computing environment |
| TWI474213B (zh) * | 2013-01-09 | 2015-02-21 | Hope Bay Technologies Inc | 具攻擊防護機制的雲端系統及其防護方法 |
| CN103746991B (zh) | 2014-01-02 | 2017-03-15 | 曙光云计算技术有限公司 | 云计算网络中的安全事件分析方法及系统 |
-
2014
- 2014-11-26 CN CN201410709018.9A patent/CN104392175B/zh active Active
-
2015
- 2015-05-27 WO PCT/CN2015/079897 patent/WO2016082501A1/zh not_active Ceased
- 2015-05-27 EP EP22192092.9A patent/EP4160456A1/en active Pending
- 2015-05-27 EP EP15862949.3A patent/EP3214568B1/en active Active
- 2015-05-27 BR BR112017011074-1A patent/BR112017011074B1/pt active IP Right Grant
-
2017
- 2017-05-26 US US15/606,855 patent/US10567422B2/en active Active
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103034807A (zh) * | 2011-10-08 | 2013-04-10 | 腾讯科技(深圳)有限公司 | 恶意程序检测方法和装置 |
| US8613089B1 (en) * | 2012-08-07 | 2013-12-17 | Cloudflare, Inc. | Identifying a denial-of-service attack in a cloud-based proxy service |
| CN103036745A (zh) * | 2012-12-21 | 2013-04-10 | 北京邮电大学 | 云计算中一种基于神经网络的异常检测系统 |
| CN104038466A (zh) * | 2013-03-05 | 2014-09-10 | 中国银联股份有限公司 | 用于云计算环境的入侵检测系统、方法及设备 |
| CN104113521A (zh) * | 2014-02-20 | 2014-10-22 | 西安未来国际信息股份有限公司 | 一种分布组件化入侵检测系统的设计 |
| CN104392175A (zh) * | 2014-11-26 | 2015-03-04 | 华为技术有限公司 | 一种云计算系统中云应用攻击行为处理方法、装置及系统 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP3214568A4 * |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113965405A (zh) * | 2021-11-04 | 2022-01-21 | 杭州安恒信息技术股份有限公司 | 一种web攻击的监测方法、装置、设备及可读存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| US10567422B2 (en) | 2020-02-18 |
| BR112017011074A2 (zh) | 2018-07-10 |
| CN104392175B (zh) | 2018-05-29 |
| EP3214568A1 (en) | 2017-09-06 |
| EP3214568B1 (en) | 2022-11-16 |
| EP3214568A4 (en) | 2017-10-25 |
| BR112017011074B1 (pt) | 2023-02-23 |
| EP4160456A1 (en) | 2023-04-05 |
| CN104392175A (zh) | 2015-03-04 |
| US20170264637A1 (en) | 2017-09-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN104392175B (zh) | 一种云计算系统中云应用攻击行为处理方法、装置及系统 | |
| KR101535502B1 (ko) | 보안 내재형 가상 네트워크 제어 시스템 및 방법 | |
| US10320833B2 (en) | System and method for detecting creation of malicious new user accounts by an attacker | |
| US10375101B2 (en) | Computer implemented techniques for detecting, investigating and remediating security violations to IT infrastructure | |
| US10630643B2 (en) | Dual memory introspection for securing multiple network endpoints | |
| US9639693B2 (en) | Techniques for detecting a security vulnerability | |
| US9027125B2 (en) | Systems and methods for network flow remediation based on risk correlation | |
| JP6419787B2 (ja) | マルウェアコンテンツ検出システム内の仮想マシンへの最適化されたリソース割当て | |
| US9594881B2 (en) | System and method for passive threat detection using virtual memory inspection | |
| US8973147B2 (en) | Geo-mapping system security events | |
| US11113086B1 (en) | Virtual system and method for securing external network connectivity | |
| CN104956376B (zh) | 虚拟化环境中应用和设备控制的方法和技术 | |
| US10951646B2 (en) | Biology based techniques for handling information security and privacy | |
| US12563083B2 (en) | Event-driven collection and monitoring of resources in a cloud computing environment | |
| US20200045079A1 (en) | Network monitoring based on distribution of false account credentials | |
| CN111400720A (zh) | 一种终端信息处理方法、系统及装置和一种可读存储介质 | |
| Wang et al. | A novel covert channel detection method in cloud based on XSRM and improved event association algorithm |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15862949 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| REEP | Request for entry into the european phase |
Ref document number: 2015862949 Country of ref document: EP |
|
| REG | Reference to national code |
Ref country code: BR Ref legal event code: B01A Ref document number: 112017011074 Country of ref document: BR |
|
| ENP | Entry into the national phase |
Ref document number: 112017011074 Country of ref document: BR Kind code of ref document: A2 Effective date: 20170525 |