WO2016082501A1 - 一种云计算系统中云应用攻击行为处理方法、装置及系统 - Google Patents

一种云计算系统中云应用攻击行为处理方法、装置及系统 Download PDF

Info

Publication number
WO2016082501A1
WO2016082501A1 PCT/CN2015/079897 CN2015079897W WO2016082501A1 WO 2016082501 A1 WO2016082501 A1 WO 2016082501A1 CN 2015079897 W CN2015079897 W CN 2015079897W WO 2016082501 A1 WO2016082501 A1 WO 2016082501A1
Authority
WO
WIPO (PCT)
Prior art keywords
cloud
application
behavior
security
rule
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/079897
Other languages
English (en)
French (fr)
Inventor
蒙泽超
刘赫伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to EP15862949.3A priority Critical patent/EP3214568B1/en
Priority to EP22192092.9A priority patent/EP4160456A1/en
Priority to BR112017011074-1A priority patent/BR112017011074B1/pt
Publication of WO2016082501A1 publication Critical patent/WO2016082501A1/zh
Priority to US15/606,855 priority patent/US10567422B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • G06F21/566Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/30Definitions, standards or architectural aspects of layered protocol stacks
    • H04L69/32Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
    • H04L69/322Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
    • H04L69/329Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the application layer [OSI layer 7]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/121Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
    • H04W12/122Counter-measures against attacks; Protection against rogue devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/128Anti-malware arrangements, e.g. protection against SMS fraud or mobile malware
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • G06F2009/45587Isolation or security of virtual machine instances
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1466Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network

Definitions

  • the present invention relates to the field of computer technologies, and in particular, to a method, device and system for processing a cloud application attack behavior in a cloud computing system.
  • cloud computing has three service models: SaaS (software as a service) and PaaS (platform as a service platform). Service) and IaaS (infrastructure as a service).
  • PaaS is a business model that provides a server platform as a service.
  • PaaS mainly provides hardware resources such as CPU and memory for cloud applications, as well as software resources such as operating system and program dependency library. Developers of cloud applications do not have to care about the software and hardware environment in which the application runs, and concentrate on developing the application itself.
  • the emergence of PaaS has accelerated the development and deployment of cloud applications, so in the Internet era, more and more cloud applications will be deployed to cloud computing systems.
  • a cloud computing system In order to increase the utilization of system hardware resources, multiple cloud applications are usually run in the same cloud host (hardware host or virtual host, different cloud computing systems have different Implementation), the cloud computing system provides the necessary system resource isolation for the cloud application, and ensures that the cloud applications running in the same cloud host do not interfere with each other. At the same time, the cloud computing system also provides a virtual network within the cloud host for communication between cloud applications.
  • a new traffic detection device is added to the cloud computing system through the switch.
  • the cloud host connection of the cloud computing system is used to detect the data flow injected into the cloud host in the cloud computing system, including the data flow of the user outside the cloud computing system accessing the cloud application, and the data exchanged between the cloud hosts in the cloud computing system. flow.
  • the flow detection device counts the amount of data flow injected into a cloud host within a predetermined period of time. When the statistically obtained traffic value exceeds a predetermined threshold, the traffic injected into the cloud host is considered abnormal. After detecting the abnormality of the traffic, the traffic detection device notifies the traffic cleaning device to start.
  • the traffic cleaning device cleans the data traffic injected into the cloud host, filters the attack packets, and sends the cleaned data stream to the cloud host. .
  • the prior art solution can only prevent attacks between cloud hosts within the cloud computing system, or external attacks to cloud hosts within the cloud computing system, but cannot prevent mutual attacks between different cloud applications within the same cloud host, or clouds. Attacks on the cloud host itself inside the host.
  • the prior art solution performs traffic monitoring and cleaning on a cloud host unit, which affects all cloud applications in the target cloud host.
  • Embodiments of the present invention provide a method, a device, and a system for processing a cloud application attack behavior in a cloud computing system, which are used for application level security protection of a cloud computing system, and minimize normal cloud applications in the cloud computer system. influences.
  • an embodiment of the present invention provides a processing device for a cloud application attack behavior in a cloud computing system, including:
  • the policy manager is used to store security judgment rules and malicious application processing rules
  • the security analyzer is configured to receive application behavior data sent by a security detector on at least one of the plurality of cloud hosts in the cloud computing system, and determine the cloud according to the application behavior data and a security judgment rule stored in the policy manager. Whether the cloud application running on the host has an attack behavior, and when determining that the cloud application running on the cloud host has an attack behavior, sending the application behavior data to the security processor; wherein the application behavior data is on the cloud host.
  • the security detector obtains the cloud application according to the behavior detection rule, and the application behavior data is used to indicate the running state of the cloud application.
  • a security processor configured to process a cloud application that has an attack behavior by using an interface provided by a cloud controller in the cloud computing system according to a malicious application processing rule stored in the policy manager, the cloud control
  • the device is communicatively coupled to the cloud host in the cloud computing system or integrated on a cloud host for controlling the cloud application running on the cloud host in the cloud computing system.
  • the apparatus further includes: an information notifier; and the policy manager is further configured to store an information notification rule;
  • the security analyzer is further configured to: when determining that the cloud application has an attack behavior, obtain initial information of the cloud application and send the initial information to the security processor, where the initial information is used to uniquely identify the cloud application;
  • the security processor is further configured to: query the user information to which the cloud application belongs according to the initial information of the cloud application, and send the user information and the application behavior data of the cloud application to the information notifier;
  • the information notifier is configured to store the received application behavior data and user information and perform attack information notification processing according to the information notification rule stored in the policy manager.
  • the policy manager is configured to convert the security judgment rule into a behavior detection rule and deliver the behavior detection rule to the security detector of each cloud host.
  • the malicious application is a cloud application that has an attack behavior; a processor, specifically configured to perform corresponding processing on the cloud application according to a type of an attack behavior of the cloud application, and a processing manner of the type application indicated by the malicious application processing rule; or the security processor Specifically, the cloud application is processed according to a risk level of the attack behavior of the cloud application, and a processing manner of the application of the risk level indicated by the malicious application processing rule.
  • the attack information notification processing specifically includes one or any combination of the following: generating alarm information and displaying an attack behavior
  • the cloud application and the user information to which the cloud application belongs, and the user information to which the cloud application having the attack behavior belongs are notified to the network police center.
  • the cloud application attack behavior processing apparatus is integrated in the cloud controller.
  • the configuration interface of the policy manager includes: at least one of a configuration interface and an application program interface.
  • the behavior detection rule includes: a process detection rule or a thread detection rule;
  • the data is obtained by the security detector detecting the process or thread of the cloud application according to the behavior detection rule.
  • the security analyzer is further configured to discard the behavior data of the cloud application when determining that the cloud application does not have an attack behavior.
  • the cloud host can be a physical machine or a virtual machine running on the physical machine.
  • the application running on the cloud host is a cloud application, and one cloud application is running on the cloud host, Each cloud application is used to implement the corresponding business function.
  • a security detector is configured on each cloud host, and the security detector is configured to use the behavior detection rule on the cloud host.
  • the behavior of the running cloud application is collected, and the application behavior data generated by the collected result is reported to the security analyzer.
  • the security detector reports the application behavior data to the security analyzer periodically, or based on the request, or according to the pre-configured reporting policy.
  • the security judgment rule is used to define what behavior of the cloud application is an attack behavior
  • the malicious application processing rule is used to define an attack for the presence. What kind of processing is applied to the cloud application of the behavior; the behavior detection rule is used to indicate the detection indicator for detecting the cloud application.
  • the cloud application with the attack behavior is defined as a malicious application.
  • the security analyzer or the security processor is configured to query the pre-invention according to the behavior data of the cloud application.
  • the configured application signature database is used to determine the type of application attack behavior, wherein the application signature database is used to describe the mapping relationship between the application's behavior characteristics and the application's attack behavior type.
  • the application feature database is an independent data set in the cloud computing system or a subset of security judgment rules; After the security analyzer determines that a cloud application is a malicious application according to the security judgment rule, the security analyzer further determines the attack behavior type of the malicious application according to the application feature database included in the security judgment rule.
  • the degree of danger of the cloud application is used to characterize the degree of harm of the cloud application to the cloud computing system.
  • the security analyzer or the security processor is configured to determine the risk of the attack behavior of the application by querying the mapping table according to the type of the attack behavior according to the application, wherein the mapping table is used to represent the type of the attack behavior and the corresponding degree of the risk. relationship.
  • the user information of the cloud application includes, but is not limited to, one of a username, a user mailbox, or a user ID number. Multiple.
  • the initial information of the cloud application includes, but is not limited to, one or more of a process ID and a process name.
  • the calling the cloud controller to process the malicious includes one or any combination of the following: shutting down the malicious application, or applying the malicious application Migrate to quarantined cloud hosts and ban user accounts for malicious applications.
  • the cloud application attack behavior processing device is a cloud host in the cloud computing system, where the cloud host is running in the physical An on-board virtual machine; the physical machine includes a hardware layer, a virtual machine monitor running on the hardware layer, and a host machine and a plurality of virtual machines running on the virtual machine monitor, wherein the hardware layer includes a processor and a memory
  • the cloud host runs an executable program, and the executable program includes: a policy manager module, a security analyzer module, a security processor module, and an information notifier module, wherein the policy manager module is used to implement any of the above possible
  • the security analyzer module is used to implement the function of the security analyzer in any of the above possible implementation manners
  • the security processor module is used to implement the security processing in any of the above possible implementation manners.
  • the information notifier module is used to implement the function of the information notifier in any of the above possible
  • the cloud application attack behavior processing apparatus includes: at least one processor, Memory, at least one communication bus.
  • the communication bus is used to implement connection communication between these components.
  • the memory stores the following elements, executable modules or data structures, or a subset of them, or their extension set:
  • An operating system that contains various system programs for implementing various basic services and handling hardware-based tasks
  • An application module that contains various cloud applications for implementing various application services.
  • the application module includes modules that implement the functions of a policy manager, a security analyzer, a security processor, and an information notifier.
  • an embodiment of the present invention provides a cloud application attack behavior processing method, which is used in a cloud computing system including multiple cloud hosts, and the method includes:
  • the cloud application that is in the cloud computing system is invoked to process the cloud application that has the attack behavior according to the malicious application processing rule, where the cloud controller is connected to the cloud controller.
  • the cloud host is integrated or integrated with the cloud host to control the cloud application running on the cloud host.
  • the method further includes:
  • the user information of the cloud application is queried according to the initial information of the cloud application that has the attack behavior, where the initial information is used to identify the cloud application;
  • the application behavior data of the cloud application with the attack behavior and the queried user information are stored, and the attack information notification processing is performed according to the information notification rule.
  • the method further includes:
  • the received application behavior data is discarded.
  • the malicious application is a cloud application that has an attack behavior;
  • the interface processes the cloud application with attack behavior, including: according to the cloud application.
  • the type of attack behavior, and the manner in which the application is processed by the malicious application processing rule, and the cloud application is processed accordingly; or according to the degree of danger of the attack behavior of the cloud application, and the malicious application processing rule
  • the cloud application is processed accordingly by the way the application of the risk level is handled.
  • the attack information notification processing according to the information notification rule includes the following One or any combination:
  • the alarm information is generated, the cloud application that displays the attack behavior, the user information to which the cloud application belongs, and the user information to which the cloud application having the attack behavior belongs are notified to the network police center.
  • the method further includes: converting the security judgment rule into a behavior detection rule, and This behavior detection rule is sent to the security detector.
  • one of a security judgment rule, a malicious application processing rule, and an information notification rule or The plurality of configurations are configured by configuring an interface, where the configuration interface includes at least one of a configuration interface and an application interface.
  • the cloud host can be a physical machine or a virtual machine running on the physical machine.
  • the application running on the cloud host is a cloud application, and one cloud application is running on the cloud host, where Each cloud application is used to implement the corresponding business functions.
  • a security detector is configured on each cloud host, and the security detector is configured to run the cloud on the cloud host according to the behavior detection rule.
  • the behavior of the application is collected, and the application behavior data is reported according to the collected result.
  • the security detector periodically reports the application behavior data, or reports the report based on the request, or reports according to the pre-configured reporting policy.
  • the security judgment rule is used to define what behavior of the cloud application is an attack behavior
  • the malicious application processing rule is used for Define the processing method for the cloud application that has the attack behavior
  • the behavior detection rule is used to indicate the detection indicator for detecting the cloud application.
  • the cloud application with the attack behavior is defined as a malicious application.
  • the pre-configured application feature database is queried according to the behavior data of the cloud application to determine the type of the application attack behavior.
  • the application feature library is used to describe the mapping relationship between the application's behavior characteristics and the application's attack behavior type.
  • the application feature database is a separate data set in the cloud computing system or a subset of security judgment rules; After determining that the cloud application is a malicious application, the determining rule further determines the attack behavior type of the malicious application according to the application feature database included in the security judgment rule.
  • the degree of danger of the cloud application is used to characterize the degree of harm of the cloud application to the cloud computing system.
  • the degree of danger of the applied attack behavior is determined by querying the mapping table, wherein the mapping table is used to represent the correspondence between the type of the attack behavior and the degree of danger.
  • the user information of the cloud application includes, but is not limited to, one or more of a user name, a user mailbox, or a user ID number. .
  • the initial information of the cloud application includes, but is not limited to, one or more of a process ID and a process name.
  • the calling the cloud controller to process the malicious includes one or any combination of the following: shutting down the malicious application, or migrating the malicious application to Isolated cloud hosts, as well as user accounts that block malicious applications.
  • an embodiment of the present invention provides a cloud application security protection system, including: a cloud application attack behavior processing device, a cloud controller, and a plurality of security detectors; wherein multiple security detectors are respectively deployed in multiple On the cloud host, each cloud host corresponds to a security detector; the cloud controller is connected to multiple cloud hosts for managing and controlling multiple cloud hosts, and each cloud host runs one or more cloud applications. ; cloud application attack behavior processing device stores security judgment rules and malicious application places Rule of law;
  • the security detector is configured to detect one or more cloud applications according to the behavior detection rule, to obtain application behavior data, and report the application behavior data to the cloud application attack behavior processing device; wherein the one or more cloud applications Running on the cloud host corresponding to the security detector;
  • the cloud application attack behavior processing device is configured to receive application behavior data reported by the security detector on the at least one cloud host of the plurality of cloud hosts, and determine the cloud application running on the cloud host according to the application behavior data and the security judgment rule. If there is an attack behavior, if the cloud application running on the cloud host is attacked, the cloud application provided by the cloud controller is processed according to the malicious application processing rule.
  • the cloud application attack behavior processing apparatus is further configured to: convert the security judgment rule into a behavior detection rule, and send the behavior detection rule to the security detector of each cloud host. .
  • the cloud application attack behavior processing apparatus is further configured to: if it is determined that the cloud application running on the cloud host does not have an attack Behavior, the received application behavior data is discarded.
  • the cloud application attack behavior processing apparatus is further configured to: if it is determined that the cloud application running on the cloud host has an attack behavior The cloud application that has the attack behavior and the user information to which the cloud application belongs, or the user information to which the cloud application with the attack behavior belongs is notified to the network police center.
  • the application of the attack behavior processing device to the cloud controller, or the cloud application attack behavior is integrated on the cloud controller.
  • the malicious application is a cloud application with an attack behavior
  • the cloud application attack behavior processing device is specific Used to: process the cloud application according to the type of the attack behavior of the cloud application and the processing manner of the application indicated by the malicious application processing rule; or according to the risk degree of the attack behavior of the cloud application, and the malicious application processing
  • the cloud application is processed accordingly by the way the rule indicates the application of the risk level.
  • one of a security judgment rule, a malicious application processing rule, and an information notification rule or Multiples are configured through the configuration interface;
  • the configuration interface described in the method includes: at least one of a configuration interface and an application program interface.
  • the behavior detection rule includes: a process detection rule or a thread detection rule; the application behavior data is The security detector obtains the process or thread of the cloud application according to the behavior detection rule.
  • the security judgment rule is used to define what behavior of the cloud application is an attack behavior, malicious
  • the application processing rule is used to define the processing method for the cloud application that has the attack behavior;
  • the behavior detection rule is used to indicate the detection indicator for detecting the cloud application.
  • the attack behavior processing apparatus is configured to query the pre-configuration according to the behavior data of the cloud application.
  • the application feature library is used to determine the type of application attack behavior, wherein the application feature library is used to describe the mapping relationship between the application's behavior characteristics and the applied attack behavior type.
  • the application feature database is an independent data set in the cloud computing system or a subset of the security judgment rule; the application attack behavior processing device After determining that a cloud application is a malicious application according to the security judgment rule, the attack behavior type of the malicious application is further determined according to the application feature database included in the security judgment rule.
  • the degree of danger of the cloud application is used to characterize the degree of harm of the cloud application to the cloud computing system;
  • the application attack behavior processing apparatus is configured to determine, according to the type of the application attack behavior, the degree of danger of the attack behavior of the application by querying the mapping table, where the mapping table is used to represent the correspondence between the type of the attack behavior and the degree of danger.
  • the policy manager issues a detection rule to a security detector distributed to each cloud host, and the security detector detects and reports the behavior of the application according to the behavior detection rule.
  • the security analyzer determines the application of the attack behavior by analyzing the behavior data of the application, and invokes the cloud controller to perform corresponding processing.
  • the embodiment of the present invention performs the cloud computing application level. Security protection can meet the deployment scenarios of cloud computing system applications, prevent mutual attacks between different applications within the same host, or attack the host itself within the host, and reduce the impact on normal applications.
  • FIG. 1 is a schematic diagram of a principle of a cloud computing system attack processing method in the prior art
  • FIG. 2 is a structural diagram of a cloud computing system according to an embodiment of the present invention.
  • FIG. 3 is a schematic diagram of a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
  • FIG. 4 is a schematic diagram of a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
  • FIG. 5 is a schematic structural diagram of a policy manager according to an embodiment of the present invention.
  • FIG. 6 is a working flow chart of a security analyzer according to an embodiment of the present invention.
  • FIG. 7 is a schematic structural diagram of a security processor according to an embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of an information notifier according to an embodiment of the present invention.
  • FIG. 9 is a flowchart of a method for processing a cloud application attack behavior according to an embodiment of the present invention.
  • FIG. 10 is a flowchart of a method for processing a cloud application attack behavior according to an embodiment of the present invention.
  • FIG. 11 is a schematic diagram of a cloud application security protection system according to an embodiment of the present invention.
  • FIG. 12 is a schematic diagram of a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
  • FIG. 13 is a schematic diagram of a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
  • FIG. 1 depicts the physical architecture of a cloud computing system.
  • a cloud computing system typically includes multiple physical computers (referred to simply as physical machines) interconnected by switches, and these physical machines can pass through the sink.
  • the physical switch can be a physical entity such as a computer or a server.
  • a physical machine of the cloud computing system can be called a cloud host.
  • one or more virtual machines can be simulated on a single physical computer through virtual machine software, and these virtual machines can work like real computers, and can be installed on virtual machines.
  • System install applications, access network resources, and more.
  • a cloud computing system may include thousands of virtual machines, and each virtual machine can run applications independently. Therefore, in other more general networking scenarios, virtual machines in cloud computing systems usually It is called a cloud host or a virtual cloud host, and an application running on a cloud host is called a cloud application. Therefore, the cloud host described in all embodiments of the present invention is not limited to a virtual machine or a physical machine, and needs to be determined according to a specific networking scenario.
  • the cloud computing system further includes a cloud controller for controlling and managing the cloud host in the cloud computing system, and the cloud controller may be one of several virtual machines included in the cloud computing system, and in some cases, the cloud The controller can also be an independent physical machine.
  • the cloud controller can have one or more; the cloud controller is connected to the cloud host in the cloud computing system or integrated on a cloud host for control.
  • the solution of the embodiment of the present invention may be specifically implemented by a cloud host in a cloud computing system, and in some cases, may also be implemented by a cloud controller.
  • the cloud computing system is generally divided into an infrastructure and a virtualization layer (IaaS layer), a platform layer (PaaS layer), and an application layer (SaaS layer).
  • IaaS layer virtualization layer
  • PaaS layer platform layer
  • SaaS layer application layer
  • the solution of the embodiment of the present invention may be implemented by a cloud computing system.
  • the platform layer is implemented, and may be implemented by a cloud controller of the platform layer or another separate functional unit.
  • FIG. 3 is a cloud application attack behavior processing apparatus according to an embodiment of the present invention.
  • the processing device can be a cloud host of the cloud computing system or integrated as a functional unit in the cloud controller.
  • the cloud computing system includes a cloud application attack behavior processing device 20, a cloud controller 206, and a plurality of cloud hosts (such as cloud hosts 10, 11, and 12 in FIG.
  • the cloud application attack behavior processing apparatus 20 includes a policy manager 201, a security analyzer 202, and a security processor 203.
  • the policy manager 201 is mainly used for storing, converting, and delivering rules.
  • the policy manager 201 may store a security judgment rule and a malicious application processing rule; the security judgment rule is used to define what behavior of the cloud application is an attack behavior, and the malicious application processing rule is used to define a cloud application for the presence of the attack behavior. What kind of treatment?
  • the policy manager 201 can convert the security judgment rule into a behavior detection rule, and the behavior detection rule is used to define which behavior of the cloud application is detected, that is, the behavior detection rule indicates that the cloud application is detected. Test indicators. Usually behavior detection rules and security judgment rules are closely related, so they can be transformed into each other.
  • the security judgment rule is: the number of TCP ports requested by the cloud application exceeds 100, the cloud application is determined to have port sniffing behavior; then the corresponding behavior detection rule is: collecting cloud application requests for different TCP ports. number.
  • the security detector on the cloud host should detect the number of different TCP ports requested by the cloud application and report the detection result to the security analyzer 202.
  • the security analyzer 202 can determine whether the cloud application has port sniffing behavior.
  • the security analyzer 202 is configured to receive the application behavior data reported by the security detector on the at least one of the plurality of cloud hosts in the cloud computing system, and then determine the cloud according to the security judgment rule stored in the policy manager 201. Whether the cloud application on the host has an attack behavior. If it is determined that the cloud application has an attack behavior, the initial information of the cloud application with the attack behavior is sent to the security processor 203; wherein the initial information of the cloud application is used to uniquely identify the cloud application, for example, in a specific embodiment. The initial information can be either a process ID or a process name, or both.
  • the application behavior data of the cloud application reported by the security detector may be reported periodically, or may be reported based on the request, or may be reported according to the pre-configured reporting policy, which is not limited in the embodiment of the present invention.
  • the security processor 203 is mainly configured to: after receiving the initial information of the cloud application that has the attack behavior sent by the security analyzer 202, invoke the interface provided by the cloud controller 206 according to the malicious application processing rule stored in the policy manager 201.
  • a cloud application in which an attack behavior exists (in the embodiment of the present invention, a cloud application having an attack behavior is collectively referred to as a malicious application) is processed.
  • the security processor 203 may employ a unified approach to all malicious applications, such as shutting down malicious applications, or migrating malicious applications to isolated cloud hosts, or disabling user accounts for malicious applications.
  • secure processing The 203 may also perform different levels or different types of processing on the malicious application according to the type of the malicious application attack behavior or the risk of the attack behavior.
  • the migration may be performed by means of migration or isolation.
  • the user account of the malicious application can be banned and so on. It can be understood that, in this case, in order to determine the type or degree of danger of malicious application attack behavior, the security analyzer 202 needs to report the application behavior data of the malicious application together with the initial information to the security processor 203 for secure processing.
  • the device 203 determines the type or the degree of danger of the attack behavior of the malicious application according to the behavior data of the malicious application; of course, the security analyzer 202 can also determine the type or degree of danger of the applied attack behavior according to the behavior data of the application, and then The analysis result is fed back to the security processor 203, which is not specifically limited in the embodiment of the present invention.
  • the security analyzer 202 can distinguish the malicious application from the normal application according to the behavior data of the cloud application and the security judgment rule, and then the security analyzer 202 or the security processor can further query the pre-configured application feature database to determine the malicious application.
  • the type of attack behavior such as a denial of service attack, a Trojan attack or a worm attack.
  • the security analyzer 202 determines the malicious application that has the attack behavior according to the behavior data of the cloud application and the security judgment rule
  • the security analyzer 202 or the security processor 203 can query the pre-configured according to the behavior data of the cloud application.
  • the signature database is applied to determine the type of attack behavior applied, and then the degree of danger of applying the attack behavior is further determined according to the type of attack behavior applied.
  • the application feature library is used to describe the mapping relationship between the behavior characteristics of the application and the attack behavior type of the application; optionally, the application feature database may be an independent data set in the cloud computing system, and the security analyzer 202 is based on the cloud application.
  • the application signature database may be further queried to determine the type of the attack behavior of the malicious application; of course, the application signature database may also be a subset of the security judgment rule.
  • the attack behavior type of the malicious application may be further determined according to the application feature database included in the security judgment rule. It can be understood that the degree of danger of different types of attacks is different, and it is determined according to the degree of harm to the system by the attack behavior, and the greater the harm to the cloud computing system, the higher the degree of danger.
  • a mapping table can be configured to represent the correspondence between the type of attack behavior and the degree of danger of the application, so that the risk of the applied attack behavior can be determined by looking up the table according to the type of the attack behavior.
  • the security processor 203 may also process the malicious application according to the security level of the cloud computing system, and different security levels correspond to different processing manners.
  • the security level of a cloud computing system can be set to "High”, “Medium”, and “Low”. When the security level of the cloud computing system is "High”, the security processor 203 can close the malicious application and prohibit the user account of the malicious application; when the cloud computing system When the security level is "low”, the security processor 203 can migrate the malicious application to a specific cloud host for isolation.
  • the three processing modes of the malicious processor 203 for the malicious application that is, the unified processing manner described above, the processing method according to the type of attack behavior or the degree of danger, and the processing method according to the security level of the cloud computing system may be adopted.
  • the malicious application processing rule indicates that different processing modes correspond to different malicious application processing rules, and the malicious application processing rules can be configured by the administrator through the configuration interface of the policy manager 201.
  • malicious application processing rules can be used to indicate how different types of malicious applications are handled, or how malicious applications of different degrees of risk are handled, or how malicious applications are handled at different levels of security of the cloud computing system;
  • the processor 203 may specifically process the malicious application according to the type of the attack behavior of the application and the processing manner of the application indicated by the malicious application processing rule; or the security processor 203 may specifically according to the risk of the applied attack behavior.
  • the degree, and the manner in which the malicious application processing rule indicates the application of the dangerous degree, the malicious application is processed correspondingly; or the security processor 203 may be specifically according to the current security level of the cloud computing system and the malicious application processing rule The malicious application is processed at this security level, and the malicious application is processed accordingly.
  • the cloud application attack behavior processing device provided by the embodiment of the present invention is issued by the policy manager as a detection rule to a security detector distributed to each cloud host, and the security detector detects and reports the behavior data of the cloud application according to the behavior detection rule, and the security analysis is performed.
  • the cloud application of the attack behavior is determined, and the cloud controller is invoked to perform corresponding processing.
  • the embodiment of the present invention performs security protection based on the cloud computing application level. It can meet the deployment scenarios of cloud computing system applications, prevent mutual attacks between different cloud applications within the same host, or attack the host itself within the host, and reduce the impact on normal cloud applications.
  • the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
  • the cloud application attack behavior processing apparatus 20 may further include: an information notifier 204; the information manager 201 further stores an information notification rule;
  • the security processor 203 is further configured to: query the user information to which the cloud application belongs according to the initial information of the cloud application that has the attack behavior, and send the queried user information and the behavior data of the cloud application to the information.
  • the notifier 204 wherein the user information of the cloud application includes but is not limited to: a username, a user mailbox, or a user ID number.
  • the information notifier 204 is configured to back up the received application behavior data and the user information to which the cloud application belongs, and perform attack information notification processing according to the information notification rule stored in the policy manager.
  • the application behavior data and the user information to which the cloud application belongs are backed up, and may be stored in a reliable storage medium in a data format such as a form, a log, or a document for the administrator to view.
  • the information notifier 204 performs attack information notification processing including but not limited to one or more of the following operations: generating alarm information, displaying a cloud application in which an attack behavior exists, and a user to which the cloud application belongs.
  • the information, as well as the user information to which the cloud application that has the attack behavior belongs, is notified to the network police center.
  • the application behavior data may be discarded.
  • the policy manager 201 includes a configuration interface through which an administrator can configure one or more of a security judgment rule, a malicious application processing rule, and an information notification rule.
  • the configuration interface may be one or more of a graphical user interface (GUI), a webpage configuration interface, or an application program interface (API).
  • GUI graphical user interface
  • API application program interface
  • different processing rules may be configured according to the attack type or the degree of danger of the malicious application, so as to implement the difference processing, thereby implementing the flexibility and scalability of the security protection.
  • one or more of the three rules can also be configured by the cloud computing system according to the default rules.
  • the behavior detection rule sent by the policy manager to the security detector may include: a process detection rule or a thread detection rule.
  • the security detector can detect the cloud application at the process or thread level, and the security analyzer can determine the process or thread with the attack behavior based on the detection result of the security detector, and then the security processor can process the attack behavior.
  • thread processing in order to achieve security protection of the process or thread sector.
  • the cloud application attack behavior processing device provided by the embodiment of the present invention is further described in detail below with reference to a specific example.
  • the cloud application attack behavior processing device is a cloud host 30.
  • Cloud master The main workflow of machine 30 is as follows:
  • the security judgment rule for determining the attack behavior of the application is configured through the configuration interface of the policy manager 201, wherein the configuration action can be completed by an administrator or by a configuration program running on the cloud computing system.
  • the security judgment rule is: require different tcp port>100, that is, the number of requested TCP ports exceeds 100.
  • the judgment rule indicates that when the number of TCP ports requested by the cloud application exceeds 100, the judgment is performed.
  • Cloud applications have port sniffing behavior;
  • the policy manager 201 converts the security judgment rule into a behavior detection rule: detecting the number of the TCP port requested by the cloud application, and sending the behavior detection rule to the security detector 205 deployed on the cloud host 10;
  • the security detector 205 detects the behavior of the App A and the App B, for example, the number of the TCP port requested by the App A and the AppB is reported, and the application behavior data is generated and reported to the security analyzer 202;
  • the security analyzer 202 determines that the number of TCP ports requested by the App B exceeds 100 according to the collected application behavior data and the security judgment rule, and therefore determines that the App B has an attack behavior;
  • the security analyzer 202 sends the initial information of the App B, such as the process ID, or the process name, to the security processor 203;
  • the security processor 203 queries the user information of the AppB from the cloud computing system application library according to the initial information of the App B;
  • the security processor 203 invokes the cloud controller to close the App B, or migrates the App B to the isolated cloud host, or prohibits the user account of the App B;
  • the security analyzer notifies the information notification device 204 of the user information of the App B, and the information notifier 204 reports it to the network police center for filing.
  • the cloud application attack behavior processing device successfully detects and processes the port sniffing behavior of App B, and does not seriously affect App A. Further, after discovering that App B has an attack behavior, the security analyzer may further adopt different processing manners for the App according to the type of attack behavior of the App B or the degree of danger.
  • the processing manner of the malicious application may be indicated by a malicious application processing rule, and the malicious application processing rule may be configured by an administrator through a configuration interface of the policy manager 201.
  • the configuration interface may be a WEB interface or an API or the like.
  • the Policy Manager 201 provides a configuration interface to the administrator or the automatic configuration program, and is mainly responsible for the operation of the rule storage, the rule conversion, and the rule delivery. As shown in FIG. 5, the policy manager 201 includes: a configuration interface 2011, a rule conversion unit 2012, a rule delivery unit 2013, and a rule storage unit 2014; wherein the configuration interface 2011 includes but is not limited to: a graphical user interface (GUI), a webpage A form of configuration interface or one or more of an application programming interface (API).
  • GUI graphical user interface
  • API application programming interface
  • the configurable rules through the configuration interface 2011 include: security judgment rules, malicious application processing rules, and information notification rules.
  • the rule storage unit 2014 stores the various rules configured by the administrator through the configuration interface 2011 into the corresponding rule base; the rule conversion unit 2012 can convert the security judgment rule configured by the administrator into a behavior detection rule, and the rule delivery unit 2013 is responsible for The behavior detection rule is sent to the security detector on the cloud host.
  • Security analyzer 202 As shown in FIG. 6, the security analyzer is mainly responsible for receiving application behavior data sent by the security detector, and then determining whether the cloud application has an attack behavior according to the security judgment rule stored in the policy manager. If it is determined that there is an attack behavior, the initial information of the cloud application (including the process ID, the process name, and the like) is sent to the security processor. If it is determined that there is no attack behavior, the application behavior data can be discarded.
  • the security processor is responsible for processing with malicious applications. Specifically, as shown in FIG. 7, the security processor 203 mainly includes an application information receiving unit 2031, a user information query unit 2032, an application processing unit 2033, and an information reporting unit 2034.
  • the application information receiving unit 2031 receives the initial information of the malicious application reported by the security analyzer, and the user information querying unit 2032 queries the cloud computing system application information database for the user information to which the cloud application belongs, including but not limited to the user name, the user mailbox, and the user identity. Certificate and other information.
  • the user information query unit 2032 then reports the user information and the behavior information of the malicious application to the information notifier through the information reporting unit 2034, so that the information notifier performs the attack information notification process according to the information notification rule stored in the policy manager.
  • the application processing unit 2033 calls the interface provided by the cloud controller to process the malicious application according to the malicious application processing rule stored in the policy manager. Processing methods include, but are not limited to, closing applications, migrating applications to quarantined cloud hosts, disabling user accounts, and the like.
  • the information notifier 204 includes: an application information receiving unit 2041, and an information notification policy determining unit 2042; wherein the application information receiving unit 2041 is responsible for receiving The application behavior information and the user information to which the cloud application belongs are received; then the information notification policy determination unit 2042 performs the attack information notification process according to the information notification rule stored in the policy manager. Specifically, the information notification policy determining unit 2042 may invoke or trigger the alarm generating unit 2043 to generate alarm information, such as generating an alarm interface. Optionally, the information notification policy determining unit 2042 may invoke or trigger the information presentation unit 2044 to form the table in the WEB page. The information of the malicious application is presented.
  • the information notification policy determining unit 2042 may also invoke or trigger the information notification unit to report the information of the malicious application to the network alarm center.
  • the information notifier may include any one of the alarm generating unit 2043, the information presenting unit 2044, and the information notifying unit 2045, and may also include any two of the three, or may include three of them.
  • the specific application scenario needs to be determined, and the embodiment of the present invention is not particularly limited.
  • the cloud application attack behavior processing device provided by the embodiment of the present invention can meet the application scenario of the cloud computing system application, implement security protection based on the cloud computing application level, prevent mutual attacks between different cloud applications within the same host, or host to the host internally. Attacks by itself while reducing the impact on normal cloud applications. Further, the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
  • the cloud application attack behavior processing device may be a cloud host in a cloud computing system, and the cloud host may be a virtual machine running on a physical machine.
  • the physical machine 1200 includes a hardware layer 100, a VMM (Virtual Machine Monitor) 110 running on the hardware layer 100, and a host Host 1201 and several virtual machines running on the VMM 110.
  • VM Virtual Machine
  • the cloud application attack behavior processing apparatus provided by the embodiment of the present invention may be specifically a virtual machine in the physical machine 1200, such as VM 1202.
  • One or more cloud applications are run on the VM 1202, where each cloud application is used.
  • the VM 1202 is also configured to execute a program, and the VM 1202 calls the executable program, and calls the hardware resource of the hardware layer 100 through the host Host 1201 during the running of the program to implement the policy management of the cloud application attack behavior processing device.
  • the executable program may include: a policy manager module, a security analyzer module, a security processor module, and an information notifier module, and the VM 1202 runs the executable program by calling resources such as CPU and Memory in the hardware layer 100.
  • resources such as CPU and Memory in the hardware layer 100.
  • the cloud application attack behavior processing apparatus provided by the embodiment of the present invention may also be a physical machine in the cloud computing system. As shown in FIG. 13, the physical machine 1300 includes: at least one processing.
  • the device 1301, such as a CPU has at least one network interface 1304, a memory 1305, and at least one communication bus 1302. Communication bus 1302 is used to implement connection communication between these components.
  • the physical machine 1300 optionally includes an input/output device 1303 including a display, a keyboard or a pointing device (eg, a mouse, a trackball, a touchpad, or a tactile display).
  • the memory 1305 may include a high speed RAM memory and may also include a non-volatile memory such as at least one disk memory.
  • the memory 1305 can optionally include at least one storage device located remotely from the aforementioned processor 1301.
  • the memory 1305 stores the following elements, executable modules or data structures, or a subset of them, or their extension set:
  • An operating system 13051 including various system programs for implementing various basic services and processing hardware-based tasks;
  • the application module 13052 includes various cloud applications for implementing various application services, such as a database application, a map application, and the like.
  • the application module 13052 includes, but is not limited to, a module that implements the functions of the policy manager, the security analyzer, the security processor, and the information notifier of the cloud application attack behavior processing device.
  • each module in the application module 13052 refers to the device and method embodiments of the present invention, and details are not described herein.
  • the security detector provided by the embodiment of the present invention may be a functional module on the cloud host in the cloud computing system.
  • the security detector may be independently operated on the virtual machine.
  • An application that, when executed by the virtual machine, can detect the behavior of other cloud applications running on the virtual machine.
  • the security detector may be an application stored in the memory of the physical machine, and the CPU of the physical machine can implement other clouds running on the physical machine by reading and executing the application. The function of the application's behavior detection.
  • the embodiment of the present invention further provides a cloud application attack behavior processing method applied to a cloud computing system, where the cloud computing system includes multiple cloud hosts, and the cloud host may be a physical machine, or A virtual machine; at least one of the plurality of cloud hosts of the cloud computing system is a cloud controller, and the cloud controller is connected to or integrated with each cloud host in the cloud computing system to control the cloud computing system.
  • the cloud application attack behavior processing method provided by the embodiment of the present invention may be executed by a cloud host in the cloud computing system, or may be executed by the cloud controller. As shown in FIG. 9, the method includes:
  • S901 Receive application behavior data reported by at least one of the plurality of cloud hosts in the cloud computing system; the application behavior data is a cloud that is executed by the security detector deployed on the cloud host according to the behavior detection rule. The application is obtained after the detection, and the application behavior data is used to indicate the running status of the cloud application running on the cloud host;
  • S902 Determine, according to the application behavior data and the security judgment rule, whether the cloud application running on the cloud host has an attack behavior
  • the interface provided by the cloud controller is used to perform corresponding processing on the cloud application that has the attack behavior, including: invoking the cloud controller: shutting down the cloud application, migrating the cloud application to the isolated cloud host, or prohibiting the User account for the cloud application.
  • the user information of the cloud application may be queried according to the initial information of the cloud application in which the attack behavior exists, and then the attack behavior is performed.
  • the application behavior data of the cloud application and the queried user information are backed up, and the attack information notification process is performed according to the information notification rule.
  • the initial information of the cloud application is used to uniquely identify the cloud application, and the initial information may be a process ID or a process name. Or both: the user information of the cloud application includes but is not limited to: user name, user mailbox or user ID number.
  • the application behavior data and the user information to which the cloud application belongs are backed up, and may be stored in a reliable storage medium in a data format such as a form, a log, or a document for the administrator to view.
  • the attack information notification process includes, but is not limited to, one of the following operations or any combination thereof: generating the alarm information, displaying the cloud application in which the attack behavior exists, and the user information to which the cloud application belongs, or the cloud application to which the attack behavior exists User information informs the network police center.
  • step S903 if it is determined that the cloud application running on the cloud host does not have an attack behavior, the received application behavior data of the cloud application is discarded.
  • the security judgment rule is used to define what behavior of the cloud application is an attack behavior
  • the malicious application processing rule is used to define a processing manner for the cloud application that has the attack behavior
  • the behavior detection rule is used to define the cloud application. What kind of behavior is detected, that is, the behavior detection rule indicates the detection index for detecting the cloud application.
  • the behavior detection rule and the security judgment rule are closely related and can be converted into each other. Therefore, in a preferred embodiment, the security judgment rule can be converted into a behavior detection rule and then sent to the security detector.
  • the security judgment rule is: the number of TCP ports requested by the cloud application exceeds 100, the cloud application is determined to have port sniffing behavior; then the corresponding behavior detection rule is: collecting cloud application requests for different TCP ports. number. In this way, the security detector on the cloud host should detect the number of different TCP ports requested by the cloud application and the detection result.
  • a unified processing manner may be adopted for all cloud applications (malicious applications) in which the attack behavior exists, such as shutting down the malicious application, or migrating the malicious application to the isolated cloud host, or prohibiting the user account of the malicious application.
  • the malicious application may be processed to different degrees or different types according to the type of the malicious application attack behavior or the risk of the attack behavior. For example, for a malicious application with a lower degree of danger, migration or isolation may be adopted. Processing, for high-risk malicious applications, you can disable the user account of the application and so on.
  • the malicious application and the normal application can be distinguished, and then the pre-configured application signature database can be further queried to determine the type of the attack behavior of the malicious application, for example, a denial of service attack, the Trojan Attack or worm attack and so on.
  • the pre-configured application feature database may be queried according to the behavior data of the cloud application to determine the type of the application attack behavior.
  • the application feature library is used to describe the mapping relationship between the behavior characteristics of the application and the type of attack behavior of the application; optionally, the application feature
  • the levy database may be an independent data set in the cloud computing system. After determining the malicious application having the attack behavior according to the behavior data of the cloud application and the security judgment rule, the application feature database may be further queried to determine the malicious application.
  • the type of attack behavior of course, the application signature database may also be a subset of the security judgment rules. After determining that a cloud application is a malicious application according to the security judgment rule, the application signature database may be further determined according to the application signature database included in the security judgment rule.
  • the type of attack behavior of a malicious application It can be understood that the degree of danger of different types of attacks is different, and it is determined according to the degree of harm to the system by the attack behavior, and the greater the harm to the cloud computing system, the higher the degree of danger.
  • a mapping table can be configured to represent the correspondence between the type of attack behavior and the degree of danger of the application, so that the risk of the applied attack behavior can be determined by looking up the table according to the type of the attack behavior.
  • the malicious application may also be processed according to the security level of the cloud computing system, and different security levels correspond to different processing modes.
  • the security level of the cloud computing system can be set to three levels: “high”, “medium”, and “low”.
  • the security level of the cloud computing system When the security level of the cloud computing system is “high”, the malicious application is closed and the user account of the malicious application is prohibited. When the security level of the cloud computing system is “low”, the malicious application is migrated to a specific cloud host for isolation.
  • the three processing modes for malicious applications that is, the unified processing method described above, the processing method according to the type of attack behavior or the degree of danger, and the processing method according to the security level of the cloud computing system, can be processed by malicious applications. To indicate that different processing modes correspond to different malicious application processing rules.
  • the administrator may configure one or more of the security judgment rules, the malicious application processing rules, and the information notification rules through the configuration interface.
  • the configuration interface may be a WEB interface or an API or the like.
  • different processing rules may be configured according to the attack type or the degree of danger of the malicious application, so as to implement the difference processing, thereby implementing the flexibility and scalability of the security protection.
  • one or more of the three rules can also be configured by the cloud computing system according to the default rules.
  • the behavior detection rule may include: a process detection rule or a thread detection rule.
  • the application can be detected at the process or thread level, and then the process or thread having the attack behavior is determined based on the detection result, and the process or thread having the attack behavior is processed, thereby implementing the security protection of the process or the thread boundary.
  • the cloud application attack behavior processing method provided by the embodiment of the present invention can meet the application scenario of the cloud computing system application, implement security protection based on the cloud computing application level, prevent mutual attacks between different applications within the same host, or internal to the host itself. Attacks while reducing the impact on normal applications.
  • the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
  • the cloud application attack behavior processing method includes the following main workflows:
  • the security detector detects the cloud application behavior according to the behavior detection rule and reports the application behavior data
  • 5A invokes the cloud controller to close the malicious application, or migrate the malicious application to the isolated cloud host, or prohibit the user account of the malicious application;
  • the cloud application attack behavior processing device successfully detects and processes the malicious application without seriously affecting the normal application. Further, after the application is found to have an attack behavior, the malicious application may be further processed according to the type or degree of risk of the malicious application.
  • the processing manner of the malicious application may be indicated by a malicious application processing rule, and the malicious application processing rule may be configured by an administrator through a configuration interface.
  • the configuration interface may be a graphical user interface (GUI), a webpage configuration interface, an application program interface (API), or the like.
  • the cloud application attack behavior processing method provided by the embodiment of the present invention can meet the cloud application system application deployment scenario, and performs security protection based on the cloud computing application level to prevent different internal hosts from being the same. Use mutual attacks, or internal attacks on the host itself, while reducing the impact on normal applications. Further, the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
  • the embodiment of the present invention further provides a cloud application security protection system, which is applied to a cloud computing system, and is used to implement the cloud application attack behavior processing method, where the cloud application security protection system includes: a cloud application attack The behavior processing device 20, the cloud controller 206, and the plurality of security detectors (exemplified by 205 in FIG. 11); wherein the plurality of security detectors are respectively deployed on the plurality of cloud hosts (10, 11 in FIG.
  • each cloud host corresponds to a security detector
  • the cloud controller 206 is communicatively connected to a plurality of cloud hosts, or integrated into one of the plurality of cloud hosts for management and control
  • the plurality of cloud hosts each of which runs one or more cloud applications
  • the cloud application attack behavior processing device 20 stores security judgment rules and malicious application processing rules
  • the security detector 205 is configured to detect one or more cloud applications according to the behavior detection rule, to obtain application behavior data, and report the application behavior data to the cloud application attack behavior processing apparatus 20; wherein the one or more clouds The application runs on the cloud host 10 corresponding to the security detector 205;
  • the cloud application attack behavior processing device 20 is configured to receive application behavior data reported by the security detector 205 on the at least one cloud host of the plurality of cloud hosts, and determine the cloud running on the cloud host 10 according to the application behavior data and the security judgment rule. Whether the application has an attack behavior; if it is determined that there is an attack behavior, the cloud controller 206 is invoked to process the cloud application that will have the attack behavior according to the malicious application processing rule.
  • the foregoing behavior detection rule may be obtained by the cloud application attack behavior processing device after the security judgment rule is converted and sent to the security detector.
  • the cloud application attack behavior processing device 20 determines that the cloud application running on the cloud host has an attack behavior
  • the user information of the cloud application that belongs to the attack behavior may be queried according to the initial information of the cloud application, and then the existence The application behavior data of the cloud application of the attack behavior and the queried user information are backed up, and the attack information notification processing is performed according to the information notification rule; wherein the initial information of the cloud application is used to uniquely identify the cloud application, and the initial information may be a process ID or The process, or both, includes; user information of the cloud application includes but is not limited to: user name, user mailbox, or user ID number.
  • the application behavior data and the user information to which the cloud application belongs are backed up, specifically It is stored on a reliable storage medium in a data format such as a form, log, or document for administrators to view.
  • the attack information notification process includes, but is not limited to, generating the alarm information, displaying the cloud application in which the attack behavior exists, and the user information to which the cloud application belongs, or notifying the network police center of the user information to which the cloud application having the attack behavior belongs.
  • the cloud application attack behavior processing device 20 is communicatively coupled to the cloud controller 206, or the cloud application attack behavior processing device 20 is integrated on the cloud controller 206.
  • the cloud application attack behavior processing apparatus 20 includes a configuration interface through which an administrator or a configuration program can configure one of a security judgment rule, a malicious application processing rule, and an information notification rule.
  • the configuration interface may be a graphical user interface (GUI), a webpage configuration interface, an application program interface (API), or the like.
  • GUI graphical user interface
  • API application program interface
  • different processing rules may be configured according to the attack type or the degree of danger of the malicious application, so as to implement the difference processing, thereby implementing the flexibility and scalability of the security protection.
  • one or more of the three rules can also be configured by the cloud computing system according to the default rules.
  • the behavior detection rule sent by the cloud application attack behavior processing device 20 to the security detector may include: a process detection rule or a thread detection rule.
  • the security detector can perform process or thread level detection on the cloud application, and the cloud application attack behavior processing device 20 can determine the process or thread in which the attack behavior exists based on the detection result of the security detector, and then the process in which the attack behavior exists.
  • thread processing in order to achieve security protection of the process or thread sector.
  • the cloud application attack behavior processing device 20 included in the cloud application security protection system of the embodiment of the present invention may be the cloud application attack behavior processing device described in any of the foregoing device embodiments, and specific implementation details may be referred to.
  • the foregoing apparatus and method embodiments are not described herein again.
  • the cloud application attack behavior detection system can meet the application scenario of the cloud computing system application, implement security protection based on the cloud application application level, prevent mutual attacks between different applications within the same host, or internal to the host itself. Attacks while reducing the impact on normal applications.
  • the malicious application processing policy is configurable, and the malicious application can be differentiated according to different security levels or different attack types.
  • the storage medium may include: a ROM, a RAM, a magnetic disk, or an optical disk.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Computing Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Computer And Data Communications (AREA)

Abstract

本发明公开了一种云计算系统中云应用攻击行为的处理装置,包括:安全分析器,安全处理器和策略管理器,其中:策略管理器用于存储安全判断规则和恶意应用处理规则;安全分析器用于接收安全检测器发送的应用行为数据,根据该应用行为数据以及安全判断规则,确定该云主机上运行的云应用是否存在攻击行为,并在确定该云主机上运行的云应用存在攻击行为时,将该应用行为数据发送给安全处理器;安全处理器,用于根据恶意应用处理规则,调用云计算系统中的云控制器提供的接口对存在攻击行为的云应用进行处理。本发明方案基于云计算应用级别进行安全防护,能防止同一个主机内部不同应用之间的相互攻击,同时减少对正常应用的影响。

Description

一种云计算系统中云应用攻击行为处理方法、装置及系统 技术领域
本发明涉及计算机技术领域,尤其涉及一种云计算系统中云应用攻击行为的处理方法、装置及系统。
背景技术
根据美国国家标准与技术研究院(National Institute of Standards and Technology,NIST)的定义,云计算有三大服务模式,分别是SaaS(software as a service,软件即服务)、PaaS(platform as a service平台即服务)和IaaS(infrastructure as a service,基础设施即服务)。其中PaaS是把服务器平台作为一种服务提供的商业模式。PaaS主要为云应用提供CPU、内存等硬件资源以及操作系统、程序依赖库等软件资源,云应用的开发者不必关心应用运行的软硬件环境,集中精力在开发应用程序本身。PaaS的出现,加快了云应用的开发和部署,因此在互联网时代,越来越多的云应用将会被部署到云计算系统中。
在云计算系统(可简称云系统)中,为了增加系统硬件资源的利用率,通常会将多个云应用运行在同一个云主机中(硬件主机或虚拟主机,不同的云计算系统有不同的实现),云计算系统为云应用提供必要的系统资源隔离,保证运行在同一云主机中运行的云应用之间不会相互干扰。同时云计算系统还提供云主机内的虚拟网络以供云应用之间的通信。
在另一方面的网络安全领域,黑客们向目标机器发起攻击之前,为了隐藏自己的身份,通常会在网络上寻找肉鸡(可被控制的傀儡机),然后通过肉鸡再来发起攻击。这样就算被攻击者检查到攻击,也只能查到肉鸡的地址,查不到黑客们的真实地址。在云计算系统兴起之后,网络黑客便可以不用再寻找肉鸡,而是直接将他们的攻击程序运行在云计算系统上,并且能够运行多份攻击程序的实例,形成一个大规模的攻击系统。在云计算系统中,黑客不仅能利用原有的攻击程序向目标进行攻击,并且可以利用云计算系统内部运行有大量的云应用程序这个特点,通过攻击程序攻击云计算系统内部不同云主机上的应用程序,甚至是同一云主机内部的其他应用程序。
现有技术中一般是通过流量检测与流量清洗方法解决云计算系统受到攻击的问题。如图1所示,在云计算系统内部新增流量检测装置,通过交换机与 云计算系统的云主机连接,用以检测云计算系统内注入云主机的数据流,包括云计算系统外部的用户访问云应用的数据流,以及云计算系统内部各云主机之间相互交互的数据流。通过流量检测装置统计出预定时长内注入某一云主机的数据流流量大小,当统计得到的流量数值超过了预定的阈值时,就认为注入该云主机的流量发生异常。检测到流量发生异常后,流量检测装置会通知流量清洗装置启动,流量清洗装置将对注入该云主机的数据流量进行清洗,过滤掉攻击报文,再将清洗后的数据流发送给该云主机。
现有技术的方案只能防止云计算系统内部云主机之间的攻击,或者外部向云计算系统内部云主机的攻击,但是无法防止同一个云主机内部不同云应用之间的相互攻击,或者云主机内部对云主机本身进行的攻击。另外,现有技术方案以云主机为单位进行流量监控和清洗,会影响到目标云主机中的所有云应用。
发明内容
本发明实施例提供一种云计算系统中云应用攻击行为的处理方法、装置及系统,用于对云计算系统进行应用级别的安全防护,并且尽可能减少对云计算机系统内正常的云应用的影响。
第一方面,本发明实施例提供了一种云计算系统中云应用攻击行为的处理装置,包括:
安全分析器,安全处理器和策略管理器,其中:
策略管理器用于存储安全判断规则和恶意应用处理规则;
安全分析器用于接收云计算系统中的多个云主机中的至少一个云主机上的安全检测器发送的应用行为数据,根据该应用行为数据以及策略管理器中存储的安全判断规则,确定该云主机上运行的云应用是否存在攻击行为,并在确定该云主机上运行的云应用存在攻击行为时,将该应用行为数据发送给安全处理器;其中,该应用行为数据是该云主机上的安全检测器根据行为检测规则对该云应用进行检测后得到的,且该应用行为数据用于表示该云应用的运行状态;
安全处理器,用于根据策略管理器中存储的恶意应用处理规则,调用云计算系统中的云控制器提供的接口对存在攻击行为的云应用进行处理,该云控制 器与云计算系统中的云主机通信连接或集成于一个云主机上,用于控制云计算系统中的云主机上运行的云应用。
在第一方面的第一种可能的实现方式中,该装置还包括:信息通知器;策略管理器中还用于存储信息通知规则;
安全分析器还用于,当确定云应用存在攻击行为时,获取该云应用的初始信息并发送给安全处理器,其中,初始信息用于唯一标识云应用;
安全处理器还用于,根据云应用的初始信息查询该云应用所属的用户信息,将该用户信息和该云应用的应用行为数据发送给信息通知器;
信息通知器用于,将接收到的应用行为数据和用户信息存储并按照策略管理器中存储的信息通知规则进行攻击信息通知处理。
结合第一方面,或者第一方面第一种可能的实现方式,在第二种可能的实现方式中,
策略管理器用于,将安全判断规则转化为行为检测规则,并将该行为检测规则下发给各个云主机的安全检测器。
结合第一方面,或者第一方面第一至第二种任意一种可能的实现方式,在第三种可能的实现方式中,其中,所述恶意应用为存在攻击行为的云应用;所述安全处理器,具体用于根据所述云应用的攻击行为的类型,以及所述恶意应用处理规则所指示的对该类型应用的处理方式,对所述云应用进行相应处理;或者所述安全处理器,具体用于根据所述云应用的攻击行为的危险程度,以及所述恶意应用处理规则所指示的对该危险程度的应用的处理方式,对所述云应用进行相应处理。
结合第一方面第一至第三种任意一种可能的实现方式,在第四种可能的实现方式中,攻击信息通知处理具体包括以下之一或其任意组合:产生告警信息、显示存在攻击行为的云应用以及该云应用所属的用户信息、以及将存在攻击行为的云应用所属的用户信息通知网警中心。
结合第一方面,或者第一方面第一至第四种任意一种可能的实现方式,在第五种可能的实现方式中,云应用攻击行为处理装置集成于云控制器。
结合第一方面第一到第五种中任意一种可能的实现方式,在第六种可能的实现方式中,策略管理器的配置接口包括:配置界面和应用程序接口中的至少一种。
结合第一方面,或者第一方面第一至第五种任意一种可能的实现方式,在第七种可能的实现方式中,所述行为检测规则包括:进程检测规则或线程检测规则;应用行为数据是安全检测器根据该行为检测规则对所述云应用的进程或线程进行检测后得到的。
结合第一方面第七种可能的实现方式,在第八种可能的实现方式中,安全分析器还用于在确定云应用不存在攻击行为时,丢弃该云应用的行为数据。
结合第一方面上述所有可能的实现方式,在第九种可能的实现方式中,云主机可以为物理机,或者运行于物理机之上的虚拟机。
结合第一方面上述任意一种可能的实现方式,在第十种可能的实现方式中,运行于云主机上的应用程序为云应用,且一个云主机上上运行有一个或多个云应用,其中,每一个云应用用于实现相应的业务功能。
结合第一方面上述任意一种可能的实现方式,在第十一种可能的实现方式中,每一台云主机上部署有一安全检测器,该安全检测器用于依据行为检测规则对该云主机上运行的云应用的行为进行采集,并根据采集结果生成应用行为数据上报给安全分析器。
结合第一方面第十一种可能的实现方式,在第十二种可能的实现方式中,安全检测器将应用行为数据定期,或者基于请求,或者根据预先配置的上报策略上报给安全分析器。
结合第一方面上述任意一种可能的实现方式,在第十三种可能的实现方式中,安全判断规则用于定义云应用的何种行为为攻击行为,恶意应用处理规则用于定义对于存在攻击行为的云应用采取何种处理方式;行为检测规则用于指示对云应用进行检测的检测指标。
结合第一方面上述任意一种可能的实现方式,在第十四种可能的实现方式中,将存在攻击行为的云应用定义为恶意应用。
结合第一方面第三种至第十四种可能的实现方式中的任一种,在第十五种可能的实现方式中,安全分析器或安全处理器用于根据云应用的行为数据,查询预先配置的应用特征库,以确定应用攻击行为的类型,其中,应用特征库用于描述应用的行为特征与应用的攻击行为类型的映射关系。
结合第一方面第十五种可能的实现方式,在第十六种可能的实现方式中,应用特征库是云计算系统中的一个独立的数据集或者是安全判断规则的子集; 安全分析器在根据安全判断规则判断出某一云应用为恶意应用之后,进一步根据安全判断规则中包含的应用特征库,确定恶意应用的攻击行为类型。
结合第一方面第三种至第十六种可能的实现方式中的任一种,在第十七种可能的实现方式中,云应用的危险程度用于表征云应用对云计算系统的危害程度;安全分析器或安全处理器用于根据根据应用攻击行为的类型,通过查询映射表的方式确定应用的攻击行为的危险程度,其中,该映射表用于表征应用攻击行为的类型与其危险程度的对应关系。
结合第一方面的上述任意一种可能的实现方式,在第十八种可能的实现方式中,云应用的用户信息包括但不限于:用户名、用户邮箱或用户身份证号中的一项或多项。
结合第一方面的上述任意一种可能的实现方式,在第十九种可能的实现方式中,云应用的初始信息包括但不限于:进程ID和进程名称中一项或多项。
结合第一方面的上述任意一种可能的实现方式,在第二十种可能的实现方式中,调用云控制器对恶意进行处理包括以下之一或其任意组合:关闭恶意应用,或者将恶意应用迁移到隔离的云主机,以及禁止恶意应用的用户账户。
结合第一方面的上述任意一种可能的实现方式,在第二十一种可能的实现方式中,云应用攻击行为处理装置为云计算系统中的一台云主机,该云主机为运行在物理机上的虚拟机;该物理机包括硬件层,运行在硬件层之上的虚拟机监视器,以及运行在虚拟机监视器之上的宿主机和若干虚拟机,其中,硬件层包括处理器和存储器,该云主机上运行有可执行程序,该可执行程序包括:策略管理器模块、安全分析器模块、安全处理器模块以及信息通知器模块,其中策略管理器模块用于实现上述任一可能的实现方式中的策略管理器的功能,安全分析器模块用于实现上述任一可能的实现方式中的安全分析器的功能,安全处理器模块用于实现上述任一可能的实现方式中的安全处理器的功能,信息通知器模块用于实现上述任一可能的实现方式中的信息通知器的功能。
结合第一方面,或者第一方面第一至第二十种任意一种可能的实现方式,,在第二十二种可能的实现方式中,云应用攻击行为处理装置包括:至少一个处理器,存储器,至少一个通信总线。通信总线用于实现这些组件之间的连接通信。存储器存储了如下的元素,可执行模块或者数据结构,或者他们的子集,或者他们的扩展集:
操作系统,包含各种系统程序,用于实现各种基础业务以及处理基于硬件的任务;
应用程序模块,包含各种云应用,用于实现各种应用业务等。
应用程序模块包括实现策略管理器、安全分析器、安全处理器以及信息通知器的功能的模块。
第二方面,本发明实施例提供了一种云应用攻击行为处理方法,用于包括多个云主机的云计算系统,该方法包括:
接收该多个云主机中的至少一个云主机上报的应用行为数据,其中,该应用行为数据是该云主机上的安全检测器根据行为检测规则对所述该云主机上运行的云应用进行检测后得到的,且该应用行为数据用于表示该云主机上运行的云应用的运行状态;
根据该应用行为数据以及安全判断规则,判断该云主机上运行的云应用是否存在攻击行为;
如果判断该云主机上运行的云应用存在攻击行为,则根据恶意应用处理规则,调用云计算系统中的云控制器提供的接口对存在攻击行为的云应用进行处理,其中该云控制器连接该云主机或集成于该云主机,用于控制该云主机上运行的云应用。
在第二方面的第一种可能的实现方式中,该方法还包括:
如果判断该云主机上运行的云应用存在攻击行为,则根据该存在攻击行为的云应用的初始信息查询该云应用所属的用户信息,其中,该初始信息用于标识该云应用;
将存在攻击行为的云应用的应用行为数据和查询到的用户信息存储,并按照信息通知规则进行攻击信息通知处理。
结合第二方面,或者第二方面第一种可能的实现方式,在第二种可能的实现方式中,该方法还包括:
如果判断该云主机上运行的云应用不存在攻击行为,则丢弃接收到的该应用行为数据。
结合第二方面,或者第二方面第一至第二种任意一种可能的实现方式,在第三种可能的实现方式中,其中,恶意应用为存在攻击行为的云应用;调用云控制器提供的接口对存在攻击行为的云应用进行相应处理,包括:根据云应用 的攻击行为的类型,以及恶意应用处理规则所指示的对该类型应用的处理方式,对该云应用进行相应处理;或者根据该云应用的攻击行为的危险程度,以及恶意应用处理规则所指示的对该危险程度的应用的处理方式,对该云应用进行相应处理。
结合第二方面第一种可能的实现方式以及第三种可能的实现方式中的任意一种可能的实现方式,在第四种可能的实现方式中,按照信息通知规则进行攻击信息通知处理包括以下之一或其任意组合:
产生告警信息、显示存在攻击行为的云应用以及该云应用所属的用户信息、以及将存在攻击行为的云应用所属的用户信息通知网警中心。
结合第二方面,或者第二方面第一至第四种任意一种可能的实现方式,在第五种可能的实现方式中,该方法还包括:将安全判断规则转化为行为检测规则,并将该行为检测规则发送给安全检测器。
结合第二方面,或者第二方面第一至第五种任意一种可能的实现方式,在第六种可能的实现方式中,安全判断规则、恶意应用处理规则和信息通知规则中的一项或多项是通过配置接口配置的;其中所述配置接口包括:配置界面和应用程序接口中的至少一种。
结合第二方面上述所有可能的实现方式,在第七种可能的实现方式中,云主机可以为物理机,或者运行于物理机之上的虚拟机。
结合第二方面上述所有可能的实现方式,在第八种可能的实现方式中,运行于云主机上的应用程序为云应用,且一个云主机上上运行有一个或多个云应用,其中,每一个云应用用于实现相应的业务功能。
结合第二方面上述所有可能的实现方式,在第九种可能的实现方式中,每一台云主机上部署有一安全检测器,该安全检测器用于依据行为检测规则对该云主机上运行的云应用的行为进行采集,并根据采集结果生成应用行为数据上报。
结合第二方面第九种可能的实现方式,在第十种可能的实现方式中,安全检测器将应用行为数据定期上报,或者基于请求上报,或者根据预先配置的上报策略上报。
结合第二方面上述所有可能的实现方式,在第十一种可能的实现方式中,安全判断规则用于定义云应用的何种行为为攻击行为,恶意应用处理规则用于 定义对于存在攻击行为的云应用采取何种处理方式;行为检测规则用于指示对云应用进行检测的检测指标。
结合第二方面上述所有可能的实现方式,在第十二种可能的实现方式中,将存在攻击行为的云应用定义为恶意应用。
结合第二方面第三种至第十二种可能的实现方式,在第十三种可能的实现方式中,根据云应用的行为数据,查询预先配置的应用特征库,以确定应用攻击行为的类型,其中,应用特征库用于描述应用的行为特征与应用的攻击行为类型的映射关系。
结合第二方面第十三种可能的实现方式,在第十四种可能的实现方式中,应用特征库是云计算系统中的一个独立的数据集或者是安全判断规则的子集;在根据安全判断规则判断出某一云应用为恶意应用之后,进一步根据安全判断规则中包含的应用特征库,确定恶意应用的攻击行为类型。
结合第二方面第三种至第十四种可能的实现方式中的任一种,在第十五种可能的实现方式中,云应用的危险程度用于表征云应用对云计算系统的危害程度;根据根据应用攻击行为的类型,通过查询映射表的方式确定应用的攻击行为的危险程度,其中,该映射表用于表征应用攻击行为的类型与其危险程度的对应关系。
结合第二方面的上述所有可能的实现方式,在第十六种可能的实现方式中,云应用的用户信息包括但不限于:用户名、用户邮箱或用户身份证号中的一项或多项。
结合第二方面的上述所有可能的实现方式,在第十七种可能的实现方式中,云应用的初始信息包括但不限于:进程ID和进程名称中一项或多项。
结合第二方面的上述所有可能的实现方式,在第十八种可能的实现方式中,调用云控制器对恶意进行处理包括以下之一或其任意组合:关闭恶意应用,或者将恶意应用迁移到隔离的云主机,以及禁止恶意应用的用户账户。
第三方面,本发明实施例提供了一种云应用安全防护系统,包括:云应用攻击行为处理装置、云控制器,以及多个安全检测器;其中,多个安全检测器分别部署于多个云主机上,且每一云主机对应于一个安全检测器;云控制器与多个云主机通信连接,用于管理和控制多个云主机,每一云主机上运行有一个或多个云应用;云应用攻击行为处理装置中存储有安全判断规则和恶意应用处 理规则;
安全检测器用于,根据行为检测规则对一个或多个云应用进行检测,以得到应用行为数据,并将该应用行为数据上报给云应用攻击行为处理装置;其中,所述一个或多个云应用运行于该安全检测器对应的云主机上;
云应用攻击行为处理装置用于,接收多个云主机中的至少一个云主机上的安全检测器上报的应用行为数据,根据该应用行为数据以及安全判断规则,判断该云主机上运行的云应用是否存在攻击行为;如果判断该云主机上运行的云应用存在攻击行为,则根据恶意应用处理规则,调用云控制器提供的接口对存在攻击行为的云应用进行相应处理。
在第三方面的第一种可能的实现方式中,云应用攻击行为处理装置还用于,将安全判断规则转化为行为检测规则,并将该行为检测规则下发给各个云主机的安全检测器。
结合第三方面,或者第三方面第一种可能的实现方式,在第二种可能的实现方式中,云应用攻击行为处理装置还用于,如果判断该云主机上运行的云应用不存在攻击行为,则丢弃接收到的该应用行为数据。
结合第三方面,或者第三方面第一种可能的实现方式,在第三种可能的实现方式中,云应用攻击行为处理装置还用于,如果判断该云主机上运行的云应用存在攻击行为,则显示存在攻击行为的云应用以及该云应用所属的用户信息、或者将存在攻击行为的云应用所属的用户信息通知网警中心。
结合第三方面,或者第三方面第一至第三种任意一种可能的实现方式,在第四种可能的实现方式中,应用攻击行为处理装置与云控制器通信连接,或者云应用攻击行为处理装置集成于云控制器上。
结合第三方面,或者第三方面第一至第四种任意一种可能的实现方式,在第五种可能的实现方式中,恶意应用为存在攻击行为的云应用;云应用攻击行为处理装置具体用于:根据云应用的攻击行为的类型,以及恶意应用处理规则所指示的对该类型应用的处理方式,对云应用进行相应处理;或者根据云应用的攻击行为的危险程度,以及恶意应用处理规则所指示的对该危险程度的应用的处理方式,对该云应用进行相应处理。结合第三方面,或者第三方面第一至第五种任意一种可能的实现方式,在第六种可能的实现方式中,安全判断规则、恶意应用处理规则和信息通知规则中的一项或多项是通过配置接口配置的;其 中所述配置接口包括:配置界面和应用程序接口中的至少一种。
结合第三方面,或者第三方面第一至第六种任意一种可能的实现方式,在第七种可能的实现方式中,行为检测规则包括:进程检测规则或线程检测规则;应用行为数据是安全检测器根据该行为检测规则对云应用的进程或线程进行检测后得到的。
结合第三方面,或者第三方面第一至第七种任意一种可能的实现方式,在第八种可能的实现方式中,安全判断规则用于定义云应用的何种行为为攻击行为,恶意应用处理规则用于定义对于存在攻击行为的云应用采取何种处理方式;行为检测规则用于指示对云应用进行检测的检测指标。
结合第三方面,或者第三方面第一至第八种任意一种可能的实现方式,在第九种可能的实现方式中,应用攻击行为处理装置用于根据云应用的行为数据,查询预先配置的应用特征库,以确定应用攻击行为的类型,其中,应用特征库用于描述应用的行为特征与应用的攻击行为类型的映射关系。
结合第三方面第九种可能的实现方式,在第十种可能的实现方式中,应用特征库是云计算系统中的一个独立的数据集或者是安全判断规则的子集;应用攻击行为处理装置用于根据安全判断规则判断出某一云应用为恶意应用之后,进一步根据安全判断规则中包含的应用特征库,确定恶意应用的攻击行为类型。
结合第三方面第五种至第十种可能的实现方式中的任一种,在第十一种可能的实现方式中,云应用的危险程度用于表征云应用对云计算系统的危害程度;应用攻击行为处理装置用于根据根据应用攻击行为的类型,通过查询映射表的方式确定应用的攻击行为的危险程度,其中,该映射表用于表征应用攻击行为的类型与其危险程度的对应关系。
本发明实施例提供的云应用攻击行为处理方法、装置及系统中,策略管理器下发行为检测规则给分布于各个云主机的安全检测器,安全检测器根据行为检测规则检测并上报应用的行为数据,安全分析器通过分析应用的行为数据,确定出存在攻击行为的应用,并调用云控制器进行相应处理,相比于现有技术中的安全方案,本发明实施例基于云计算应用级别进行安全防护,能满足云计算系统应用部署场景,防止同一个主机内部不同应用之间的相互攻击,或者主机内部对主机本身进行的攻击,同时减少对正常应用的影响。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是现有技术中云计算系统攻击处理方法的原理示意图;
图2是本发明实施例提供的云计算系统架构图;
图3是本发明实施例提供的云应用攻击行为处理装置示意图;
图4是本发明实施例提供的云应用攻击行为处理装置示意图;
图5是本发明实施例提供的策略管理器结构示意图;
图6是本发明实施例提供的安全分析器的工作流程图;
图7是本发明实施例提供的安全处理器结构示意图;
图8是本发明实施例提供的信息通知器结构示意图;
图9是本发明实施例提供的云应用攻击行为处理方法流程图;
图10是本发明实施例提供的云应用攻击行为处理方法流程图;
图11是本发明实施例提供的云应用安全防护系统示意图;
图12是本发明实施例提供的云应用攻击行为处理装置示意图;
图13是本发明实施例提供的云应用攻击行为处理装置示意图。
具体实施方式
为了使本技术领域的人员更好地理解本发明方案,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分的实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本发明保护的范围。
本发明实施例提供的技术方案可典型地应用于云计算系统(可简称为云系统)中,云计算系统可看成是在通用硬件上进行分布式计算、存储及管理的一种集群系统,云计算系统可提供高吞吐量的数据访问,能够应用于大规模数据计算和存储。图2描述了云计算系统的物理架构,云计算系统通常包括通过交换机互联的多个物理计算机(可简称为物理机),并且这些物理机可以通过汇 聚交换机以及核心交换机与外部网络互联;其中,物理机具体可以为计算机或服务器等物理实体,在某些组网场景下,云计算系统的一台物理机可以称为一台云主机。随着云计算技术的发展,目前通过虚拟机软件,可以在一台物理计算机上模拟出一台或多台虚拟机,而这些虚拟机可以像真正的计算机那样进行工作,虚拟机上可安装操作系统、安装应用程序、访问网络资源等等。对于在虚拟机中运行的应用程序而言,就像是在真正的计算机中进行工作。因此,一个云计算系统可能包括成千上万个虚拟机,每个虚拟机上都可以独立运行应用程序,因此,在另一些更为通用的组网场景下,云计算系统中的虚拟机通常被称为云主机或者虚拟云主机,而云主机上运行的应用程序称为云应用。故本发明所有实施例所描述的云主机,并不限制为是虚拟机或物理机,需要视具体的组网场景而定。另外,云计算系统还包括有云控制器,用于对云计算系统中的云主机进行控制和管理,云控制器可以是云计算系统包含的若干虚拟机中的一个,某些情形下,云控制器也可是一台独立的物理机,当然,云控制器可以有一个,也可以有多个;云控制器与云计算系统中的云主机通信连接或集成于一个云主机上,用于控制云计算系统中的多个云主机上运行的云应用。本发明实施例的方案具体可以由云计算系统中的云主机来实施,某些情形下,也可以有云控制器来实施。如果依据逻辑架构来划分,云计算系统通常分为基础设施与虚拟化层(IaaS层)、平台层(PaaS层)以及应用层(SaaS层),本发明实施例的方案可以由云计算系统的平台层来实施,具体可以由平台层的云控制器或者另一单独的功能单元来实施。
本发明实施例提供一种云应用攻击行为处理装置,该处理装置可以应用于云计算系统中,以对云计算系统进行安全防护,图3为本发明实施例提供的云应用攻击行为处理装置的示意图,在一个具体的实施例中,该处理装置可以为云计算系统的一台云主机,或者作为云控制器中的一个功能单元,集成于云控制器中。根据图3,云计算系统包括云应用攻击行为处理装置20、云控制器206以及多台云主机(如图3中的云主机10、11和12);其中,每一台云主机上运行有一个或多个云应用,且每一台云主机上部署有一安全检测器,负责依据云应用攻击行为处理装置20下发的行为检测规则,对该云主机上运行的云应用的行为进行采集,并将应用的应用行为数据上报给云应用攻击行为处理装置20,其中应用行为数据用于表示云应用的运行状态,比如云应用的TCP链 接信息、网络流量信息、系统调用次数等等。可选的,云应用的应用行为数据上报可以是定期的或基于请求的。具体地,云应用攻击行为处理装置20包括:策略管理器201、安全分析器202、安全处理器203。
策略管理器201主要用于规则的存储、转化以及下发。具体地,策略管理器201中可存储安全判断规则和恶意应用处理规则;安全判断规则用于定义云应用的何种行为为攻击行为,恶意应用处理规则用于定义对于存在攻击行为的云应用采取何种处理方式。在一个优选的实施例中,策略管理器201可以将安全判断规则转化为行为检测规则,行为检测规则用于定义对云应用的何种行为进行检测,即行为检测规则指示了对云应用进行检测的检测指标。通常行为检测规则和安全判断规则是密切联系的,因此可以互相转化。举例来说,如果安全判断规则为:云应用向外请求的TCP端口数量超过100则判断云应用有端口嗅探的行为;那么相应的行为检测规则就为:采集云应用请求不同TCP端口的个数。这样,云主机上的安全检测器就应该检测云应用请求不同TCP端口的个数并将检测结果上报给安全分析器202,安全分析器202就可以判断云应用是否有端口嗅探的行为。
安全分析器202主要用于接收云计算系统中的多个云主机中的至少一个云主机上的安全检测器上报的应用行为数据,然后根据策略管理器201中存储的安全判断规则,判断该云主机上的云应用是否存在攻击行为。如果确定云应用存在攻击行为,则将存在攻击行为的云应用的初始信息发送给安全处理器203;其中,云应用的初始信息用于唯一标识该云应用,比如,在一个具体的实施例中,初始信息可以为进程ID或进程名称,或者两者同时包含。可选的,安全检测器上报云应用的应用行为数据,可以是定期上报,也可以是基于请求上报,也可以是根据预先配置的上报策略来上报,本发明实施例不做特别限定。
安全处理器203主要用于在接收到安全分析器202发送的存在攻击行为的云应用的初始信息后,根据策略管理器201中存储的恶意应用处理规则,调用云控制器206提供的接口对该存在攻击行为的云应用(本发明实施例中将存在攻击行为的云应用统称为恶意应用)进行处理。在一个实施例中,安全处理器203可以对所有恶意应用采用统一处理方式,比如关闭恶意应用,或者将恶意应用迁移到隔离的云主机,或者禁止恶意应用的用户账户。可选地,安全处理 器203也可以根据恶意应用攻击行为的类型或者攻击行为的危险程度,对恶意应用进行不同程度或不同类型的处理,比如,对于危险程度较低的恶意应用,可以采取迁移或隔离等方式处理,对于高危险的恶意应用,可以禁止该恶意应用的用户账户等等。可以理解的是,在这种情形下,为了判断恶意应用攻击行为的类型或者危险程度,安全分析器202需要将恶意应用的应用行为数据和初始信息一并上报给安全处理器203,以便安全处理器203根据该恶意应用的行为数据来判断该恶意应用的攻击行为的类型或危险程度;当然,安全分析器202也可以自己根据应用的行为数据来判断应用攻击行为的类型或者危险程度,然后将分析结果反馈给安全处理器203,本发明实施例不做特别限定。比如,安全分析器202可以根据云应用的行为数据以及安全判断规则,区分出恶意应用和正常应用,然后安全分析器202或安全处理器可以进一步查询预先配置的应用特征库,以确定恶意应用的攻击行为的类型,例如为拒绝服务攻击,木马攻击或蠕虫攻击等等。又比如,在安全分析器202根据云应用的行为数据以及安全判断规则,确定出存在攻击行为的恶意应用之后,安全分析器202或安全处理器203可以根据云应用的行为数据,查询预先配置的应用特征库,以确定出应用攻击行为的类型,然后进一步根据应用攻击行为的类型,确定应用攻击行为的危险程度。其中,应用特征库用于描述应用的行为特征与应用的攻击行为类型的映射关系;可选地,应用特征库可以是云计算系统中的一个独立的数据集,在安全分析器202根据云应用的行为数据以及安全判断规则,确定出存在攻击行为的恶意应用之后,可以进一步查询该应用特征库以确定该恶意应用的攻击行为的类型;当然,应用特征库也可以是安全判断规则的子集,当安全分析器202根据安全判断规则判断出某一云应用为恶意应用之后,可以进一步根据安全判断规则中包含的应用特征库,确定恶意应用的攻击行为类型。可以理解的是,不同类型的攻击行为的危险程度是不同的,需要根据该攻击行为对系统的危害程度来确定,对云计算系统造成的危害越大的攻击行为,其危险程度也越高。通常可以配置一个映射表,用于表征应用攻击行为的类型与其危险程度的对应关系,这样根据根据应用攻击行为的类型,通过查表的方式就可以确定应用的攻击行为的危险程度。可选地,在另一个可选的实施例中,安全处理器203也可以根据云计算系统的安全级别来对恶意应用进行处理,不同的安全级别对应不同的处理方式。比如云计算系统的安全级别可以设置为 “高”、“中”、“低”三个级别,当云计算系统的安全级别为“高”时,安全处理器203可以关闭恶意应用,同时禁止该恶意应用的用户账户;当云计算系统的安全级别为“低”时,安全处理器203可以将恶意应用迁移到特定的云主机进行隔离。最后需要说明的是,安全处理器203对恶意应用的三种处理模式,即上述的统一处理方式,根据攻击行为类型或危险程度处理的方式,以及根据云计算系统安全级别的处理方式,可以通过恶意应用处理规则来指示,不同的处理模式对应有不同的恶意应用处理规则,且该恶意应用处理规则可以由管理员通过策略管理器201的配置接口来配置。例如,恶意应用处理规则可以用于指示对不同类型恶意应用的处理方式,或者对不同危险程度的恶意应用的处理方式,或者云计算系统的不同安全级别下对恶意应用的处理方式;这样,安全处理器203具体可以根据应用的攻击行为的类型,以及恶意应用处理规则所指示的对该类型应用的处理方式,对恶意应用进行相应处理;或者安全处理器203具体可以根据应用的攻击行为的危险程度,以及恶意应用处理规则所指示的对该危险程度的应用的处理方式,对恶意应用相应进行处理;或者安全处理器203具体可以根据云计算系统当前的安全级别,以及恶意应用处理规则所指示的该安全级别下对恶意应用的处理方式,对恶意应用进行相应处理。
本发明实施例提供的云应用攻击行为处理装置,策略管理器下发行为检测规则给分布于各个云主机的安全检测器,安全检测器根据行为检测规则检测并上报云应用的行为数据,安全分析器通过分析云应用的行为数据,确定出存在攻击行为的云应用,并调用云控制器进行相应处理,相比于现有技术中的安全方案,本发明实施例基于云计算应用级别进行安全防护,能满足云计算系统应用部署场景,防止同一个主机内部不同云应用之间的相互攻击,或者主机内部对主机本身进行的攻击,同时减少对正常云应用的影响。进一步地,恶意应用处理策略可配置,进而可根据不同安全级别或不同的攻击类型对恶意应用进行区别处理。
优选地,云应用攻击行为处理装置20还可以包括:信息通知器204;策略管理器201中还存储有信息通知规则;
安全处理器203还用于,根据存在攻击行为的云应用的初始信息查询该云应用所属的用户信息,将查询到的用户信息和该云应用的行为数据发送给信息 通知器204;其中,云应用的用户信息包括但不限于:用户名、用户邮箱或用户身份证号。
信息通知器204用于,将接收到的应用行为数据和云应用所属的用户信息备份,并按照策略管理器中存储的信息通知规则进行攻击信息通知处理。其中,将应用行为数据和云应用所属的用户信息备份,具体可以是以表格、日志或文档等数据格式存储在可靠存储介质中,以便管理员查看。
具体地,在一个实施例中,信息通知器204进行攻击信息通知处理包括但不限于下列操作中的一项或多项:产生告警信息、显示存在攻击行为的云应用以及该云应用所属的用户信息、以及将存在攻击行为的云应用所属的用户信息通知网警中心。
优选地,在另一个实施例中,当安全分析器接收到安全检测器上报的应用行为数据后,根据安全判断规则确定云应用不存在攻击行为时,可以丢弃改应用行为数据。
优选地,在另一个实施例中,策略管理器201包括有配置接口,管理员可以通过该配置接口配置安全判断规则、恶意应用处理规则和信息通知规则中的一项或多项。其中,该配置接口可以为图形用户界面(GUI)、网页形式的配置界面或者应用程序接口(API)中的一种或多种。进一步地,在配置恶意应用处理规则的时候,可以根据恶意应用的攻击类型或者危险程度,配置不同的处理规则,以进行区别处理,从而实现安全防护的灵活性和可扩展性。当然,可以理解的是,这三种规则中的一种和多种也可以不需要管理员配置,由云计算系统按照默认规则自定义。
进一步地,为了实现更细粒度的安全防护,策略管理器下发给安全检测器的行为检测规则可以包括:进程检测规则或线程检测规则。这样,安全检测器可以对云应用进行进程或线程级别的检测,安全分析器可以基于安全检测器的检测结果,确定出存在攻击行为的进程或线程,然后安全处理器可以对存在攻击行为的进程或线程进行处理,进而可以实现进程或线程界别的安全防护。
下面结合具体的实例,进一步详细阐述本发明实施例提供的云应用攻击行为处理装置,如图4所示,该云应用攻击行为处理装置为一云主机30。云主 机30的主要工作流程如下:
1.通过策略管理器201的配置接口配置用于判断应用攻击行为的安全判断规则,其中配置动作可以由管理员或由运行于云计算系统的配置程序完成。在一个具体的例子中,该安全判断规则为:require different tcp port>100,即请求的TCP端口数目超过100个,该判断规则表示当云应用向外请求的TCP端口数量超过100,则判定该云应用有端口嗅探的行为;
2.策略管理器201将安全判断规则转换为行为检测规则:检测云应用请求TCP端口的个数,并将行为检测规则下发给部署于云主机10上的安全检测器205;
3.安全检测器205检测App A和App B的行为,例如,统计App A和AppB请求TCP端口的数目,并生成应用行为数据上报给安全分析器202;
4.安全分析器202根据收集到的应用行为数据与安全判断规则,判断发现App B请求的TCP端口数超出了100,因此判断App B有攻击行为;
5.安全分析器202将App B的初始信息,比如进程ID,或进程名称,发送给安全处理器203;
6.安全处理器203根据App B的初始信息从云计算系统应用库查询AppB的用户信息;
7.安全处理器203调用云控制器关闭App B,或将App B迁移到隔离的云主机,或者禁止App B的用户账户;
8.安全分析器将App B的用户信息通知信息通知器204,信息通知器204上报网警中心备案。
该示例中,云应用攻击行为处理装置成功的检测并处理了App B的端口嗅探行为,并且没有对App A造成严重影响。进一步地,安全分析器在发现App B有攻击行为之后,可以进一步根据App B的攻击行为的类型或者危险程度,对App采用不同的处理方式。其中,对恶意应用的处理方式可以由恶意应用处理规则来指示,且该恶意应用处理规则可以由管理员通过策略管理器201的配置接口来配置。其中,该配置接口可以为WEB界面或者API等等。
下面对云应用攻击行为处理装置20中的各个模块进行详细介绍:
(1)策略管理器201:策略管理器向管理员或自动配置程序提供配置接口,同时主要负责规则存储,规则转化,规则下发等操作。如图5所示,策略管理器201包括有:配置接口2011,规则转化单元2012、规则下发单元2013和规则存储单元2014;其中配置接口2011包括但不限于:图形用户界面(GUI)、网页形式的配置界面或者应用程序接口(API)中的一种或多种。通过配置接口2011可配置的规则包括:安全判断规则、恶意应用处理规则、信息通知规则。规则存储单元2014将管理员通过配置接口2011配置的各种规则存储到对应的规则库中;规则转化单元2012可以将管理员配置的安全判断规则转化为行为检测规则,规则下发单元2013负责将行为检测规则下发至云主机上的安全检测器。
(2)安全分析器202:如图6所示,安全分析器主要负责接收安全检测器发送来的应用行为数据,然后根据策略管理器中存储的安全判断规则,判断云应用是否存在攻击行为。如果判断存在攻击行为,则将该云应用的初始信息(包括进程ID、进程名称等)发送给安全处理器。如果判断不存在攻击行为,则可以丢弃该应用行为数据。
(3)安全处理器203:安全处理器负责用恶意应用的处理。具体地,如图7所示,安全处理器203主要包括:应用信息接收单元2031,用户信息查询单元2032,应用处理单元2033,以及信息上报单元2034。应用信息接收单元2031接收安全分析器上报的恶意应用的初始信息,用户信息查询单元2032从云计算系统应用信息库中查询云应用所属的用户信息,包括但不限于用户名、用户邮箱、用户身份证等信息。然后用户信息查询单元2032将用户信息和恶意应用的行为信息通过信息上报单元2034上报给信息通知器,使得信息通知器按照策略管理器中存储的信息通知规则进行攻击信息通知处理。应用处理单元2033依据策略管理器中存储的恶意应用处理规则,调用云控制器提供的接口对恶意应用进行处理。处理方式包括但不限于:关闭应用、将应用迁移到隔离的云主机、禁止用户账户等。
(4)信息通知器204:如图8所示,信息通知器包括:应用信息接收单元2041,信息通知策略判断单元2042;其中,应用信息接收单元2041负责接 收应用行为信息和云应用所属的用户信息;然后信息通知策略判断单元2042根据策略管理器中存储的信息通知规则进行攻击信息通知处理。具体地,信息通知策略判断单元2042可以调用或触发告警产生单元2043产生告警信息,比如生成告警界面;可选地,信息通知策略判断单元2042可以调用或触发信息呈现单元2044在WEB页面以表格形式呈现恶意应用的信息;可选地,信息通知策略判断单元2042也可以调用或触发信息通知单元将恶意应用的信息上报网警中心。可以理解的是,信息通知器可以包括告警产生单元2043,信息呈现单元2044和信息通知单元2045中的某一个,也可以同时包含三者中的任意两个,也可以同时包含三者,需要视具体的应用场景需求来确定,本发明实施例不做特别限定。
本发明实施例提供的云应用攻击行为处理装置能够能满足云计算系统应用部署场景,基于云计算应用级别进行安全防护,防止同一个主机内部不同云应用之间的相互攻击,或者主机内部对主机本身进行的攻击,同时减少对正常云应用的影响。进一步地,恶意应用处理策略可配置,进而可根据不同安全级别或不同的攻击类型对恶意应用进行区别处理。
需要说明的是,本发明实施例提供的云应用攻击行为处理装置,具体可以为云计算系统中的一台云主机,该云主机可以为运行在物理机上的虚拟机。如图12所示,物理机1200包括硬件层100,运行在硬件层100之上的VMM(Virtual Machine Monitor,虚拟机监视器)110,以及运行在VMM 110之上的宿主机Host 1201和若干虚拟机(VM,Virtual Machine),其中,硬件层包括但不限于:I/O设备、CPU和memory。本发明实施例提供的云应用攻击行为处理装置具体可以为物理机1200中的一台虚拟机,比如VM 1202,VM 1202上运行有一个或多个云应用,其中,每一个云应用都用于实现相应的业务功能,比如数据库应用、地图应用等等,这些云应用可以由开发者开发然后部署到云计算系统中。此外VM1202还运行有可以执行程序,VM 1202通过运行该可执行程序,并在程序运行的过程中通过宿主机Host 1201来调用硬件层100的硬件资源,以实现云应用攻击行为处理装置的策略管理器、安全分析器、安全处理器以及信息通知器的功能,具体而言,策略管理器、安全分析器、安全处理器以及信息通知器可以以软件模块或函数的形式被包含在上述可执行程序 中,比如该可执行程序可以包括:策略管理器模块、安全分析器模块、安全处理器模块以及信息通知器模块,VM1202通过调用硬件层100中的CPU、Memory等资源,以运行该可执行程序,从而实现策略管理器、安全分析器、安全处理器以及信息通知器的功能。在另一种可能的场景下,本发明实施例提供的云应用攻击行为处理装置,也可以为云计算系统中的一台物理机,如图13所示,物理机1300包括:至少1个处理器1301,例如CPU,至少1个网络接口1304,存储器1305,至少一个通信总线1302。通信总线1302用于实现这些组件之间的连接通信。物理机1300可选的包含输入/输出设备1303,包括显示器,键盘或者点击设备(例如,鼠标,轨迹球(trackball),触感板或者触感显示屏)。存储器1305可能包含高速RAM存储器,也可能还包括非不稳定的存储器(non-volatile memory),例如至少一个磁盘存储器。存储器1305可选的可以包含至少一个位于远离前述处理器1301的存储装置。存储器1305存储了如下的元素,可执行模块或者数据结构,或者他们的子集,或者他们的扩展集:
操作系统13051,包含各种系统程序,用于实现各种基础业务以及处理基于硬件的任务;
应用程序模块13052,包含各种云应用,用于实现各种应用业务,比如数据库应用、地图应用等等。
应用程序模块13052中包括但不限于实现云应用攻击行为处理装置的策略管理器、安全分析器、安全处理器以及信息通知器的功能的模块。
应用程序模块13052中各模块的具体实现可参见本发明装置及方法实施例,在此不赘述。
相应地,本发明实施例提供的安全检测器,可以为云计算系统中的云主机上的一个功能模块,例如,若云主机为虚拟机时,安全检测器可以为独立运行在该虚拟机上的一个应用程序,该应用程序在被该虚拟机执行的过程中,可以检测该虚拟机上运行的其它云应用的行为。若云主机为物理机时,安全检测器可以为存储于该物理机的存储器中的一个应用程序,该物理机的CPU通过读取并执行该应用程序,可以实现对该物理机上运行的其它云应用的行为检测的功能。
基于上述装置实施例,本发明实施例还提供一种应用于云计算系统中的云应用攻击行为处理方法,其中,该云计算系统包含有多台云主机,云主机可以为物理机,也可以为虚拟机;云计算系统的多台云主机中至少有一台为云控制器,云控制器与云计算系统中的各个云主机通信连接或集成于某一云主机上,用于控制云计算系统中的多个云主机上运行的云应用;每一台云主机上运行有一个或多个云应用,且每一台云主机上部署有一安全检测器;安全检测器负责依据行为检测规则,对云主机上运行的云应用的行为进行检测。本发明实施例提供的云应用攻击行为处理方法可以由云计算系统中的一台云主机来执行,也可以由云控制器来执行,如图9所示,该方法包括:
S901:接收云计算系统中的多个云主机中的至少一个云主机上报的应用行为数据;该应用行为数据是该云主机上部署的安全检测器根据行为检测规则对该云主机上运行的云应用进行检测后得到的,且该应用行为数据用于表示该云主机上运行的云应用的运行状态;
S902:根据应用行为数据以及安全判断规则,判断该云主机上运行的云应用是否存在攻击行为;
S903:如果判断云主机上运行的云应用存在攻击行为,则根据恶意应用处理规则,调用云计算系统的云控制器提供的接口对存在攻击行为的云应用进行处理。
优选地,调用云控制器提供的接口对将存在攻击行为的云应用进行相应处理,包括:调用云控制器:关闭所述云应用、将所述云应用迁移到隔离的云主机、或者禁止所述云应用的用户账户。
优选地,在步骤S903中,如果判断云主机上运行的云应用存在攻击行为,还可以根据该存在攻击行为的云应用的初始信息查询该云应用所属的用户信息,然后将该存在攻击行为的云应用的应用行为数据和查询到的用户信息备份,并按照信息通知规则进行攻击信息通知处理;其中,云应用的初始信息用于唯一标识该云应用,初始信息可以为进程ID或进程名称,或者两者同时包含;云应用的用户信息包括但不限于:用户名、用户邮箱或用户身份证号。需要说明的是,将应用行为数据和云应用所属的用户信息备份,具体可以是以表格、日志或文档等数据格式存储在可靠存储介质中,以便管理员查看。
进一步地,进行攻击信息通知处理包括但不限于以下操作之一或其任意组合:产生告警信息、显示存在攻击行为的云应用以及该云应用所属的用户信息、或者将存在攻击行为的云应用所属的用户信息通知网警中心。
可选地,在步骤S903中,如果判断云主机上运行的云应用不存在攻击行为,则丢弃接收到的该云应用的应用行为数据。
需要说明的是,安全判断规则用于定义云应用的何种行为为攻击行为,恶意应用处理规则用于定义对于存在攻击行为的云应用采取何种处理方式,行为检测规则用于定义对云应用的何种行为进行检测,即行为检测规则指示了对云应用进行检测的检测指标。通常行为检测规则和安全判断规则是密切联系的,可以互相转化,因此在一个优选的实施例中,可以将安全判断规则转化为行为检测规则,然后下发给安全检测器。举例来说,如果安全判断规则为:云应用向外请求的TCP端口数量超过100则判断云应用有端口嗅探的行为;那么相应的行为检测规则就为:采集云应用请求不同TCP端口的个数。这样,云主机上的安全检测器就应该检测云应用请求不同TCP端口的个数并将检测结果。
可选地,在步骤S903中,可以对所有存在攻击行为的云应用(恶意应用)采用统一处理方式,比如关闭恶意应用,或者将恶意应用迁移到隔离的云主机,或者禁止恶意应用的用户账户。可选地,也可以根据恶意应用攻击行为的类型或者攻击行为的危险程度,对恶意应用进行不同程度或不同类型的处理,比如,对于危险程度较低的恶意应用,可以采取迁移或隔离等方式处理,对于高危险的恶意应用,可以禁止该应用的用户账户等等。可以理解的是,在这种情形下,为了判断恶意应用攻击行为的类型或者危险程度,需要根据恶意应用的行为数据来判断该恶意应用的攻击行为的类型或危险程度。比如,可以根据云应用的行为数据以及安全判断规则,区分出恶意应用和正常应用,然后可以进一步查询预先配置的应用特征库,以确定恶意应用的攻击行为的类型,例如为拒绝服务攻击,木马攻击或蠕虫攻击等等。又比如,在根据云应用的行为数据以及安全判断规则,确定出存在攻击行为的恶意应用之后,可以根据云应用的行为数据,查询预先配置的应用特征库,以确定出应用攻击行为的类型,然后进一步根据应用攻击行为的类型,确定应用攻击行为的危险程度。其中,应用特征库用于描述应用的行为特征与应用的攻击行为类型的映射关系;可选地,应用特 征库可以是云计算系统中的一个独立的数据集,在根据云应用的行为数据以及安全判断规则,确定出存在攻击行为的恶意应用之后,可以进一步查询该应用特征库以确定该恶意应用的攻击行为的类型;当然,应用特征库也可以是安全判断规则的子集,当根据安全判断规则判断出某一云应用为恶意应用之后,可以进一步根据安全判断规则中包含的应用特征库,确定恶意应用的攻击行为类型。可以理解的是,不同类型的攻击行为的危险程度是不同的,需要根据该攻击行为对系统的危害程度来确定,对云计算系统造成的危害越大的攻击行为,其危险程度也越高。通常可以配置一个映射表,用于表征应用攻击行为的类型与其危险程度的对应关系,这样根据根据应用攻击行为的类型,通过查表的方式就可以确定应用的攻击行为的危险程度。。可选地,也可以根据云计算系统的安全级别来对恶意应用进行处理,不同的安全级别对应不同的处理方式。比如云计算系统的安全级别可以设置为“高”、“中”、“低”三个级别,当云计算系统的安全级别为“高”时,关闭恶意应用,同时禁止该恶意应用的用户账户;当云计算系统的安全级别为“低”时,将恶意应用迁移到特定的云主机进行隔离。最后需要说明的是,对恶意应用的三种处理模式,即上述的统一处理方式,根据攻击行为类型或危险程度处理的方式,以及根据云计算系统安全级别的处理方式,可以通过恶意应用处理规则来指示,不同的处理模式对应有不同的恶意应用处理规则。
优选地,在另一个实施例中,管理员可以通过配置接口配置安全判断规则、恶意应用处理规则和信息通知规则中的一项或多项。其中,该配置接口可以为WEB界面或者API等等。进一步地,在配置恶意应用处理规则的时候,可以根据恶意应用的攻击类型或者危险程度,配置不同的处理规则,以进行区别处理,从而实现安全防护的灵活性和可扩展性。当然,可以理解的是,这三种规则中的一种和多种也可以不需要管理员配置,由云计算系统按照默认规则自定义。
可选地,为了实现更细粒度的安全防护,行为检测规则可以包括:进程检测规则或线程检测规则。这样,可以对应用进行进程或线程级别的检测,然后基于检测结果确定出存在攻击行为的进程或线程,对存在攻击行为的进程或线程进行处理,进而可以实现进程或线程界别的安全防护。
本发明实施例提供的云应用攻击行为处理方法能够能满足云计算系统应用部署场景,基于云计算应用级别进行安全防护,防止同一个主机内部不同应用之间的相互攻击,或者主机内部对主机本身进行的攻击,同时减少对正常应用的影响。进一步地,恶意应用处理策略可配置,进而可根据不同安全级别或不同的攻击类型对恶意应用进行区别处理。
下面结合具体的实例,进一步详细阐述本发明实施例的云应用攻击行为处理方法,如图10所示,该云应用攻击行为处理方法包含主要工作流程如下:
1.通过配置接口配置用于判断应用攻击行为的安全判断规则,并存储至策略库;然后将安全判断规则转化为行为检测规则下发至云主机的安全检测器;
2.安全检测器根据行为检测规则检测云应用行为并生产应用行为数据上报;
3.根据收集到的应用行为数据与安全判断规则,确定存在攻击行为的恶意应用;
4.根据恶意应用的初始信息从云计算系统应用库查询恶意应用的用户信息;
5安调用云控制器关闭恶意应用,或将恶意应用迁移到隔离的云主机,或者禁止恶意应用的用户账户;
6.将恶意应用的用户信息通知或呈现给管理员或网警中心。
该示例中,云应用攻击行为处理装置成功的检测并处理了恶意应用,并且没有对正常应用造成严重影响。进一步地,在发现应用有攻击行为之后,可以进一步根据恶意应用的攻击行为的类型或者危险程度,对恶意应用采用不同的处理方式。其中,对恶意应用的处理方式可以由恶意应用处理规则来指示,且该恶意应用处理规则可以由管理员通过配置接口来配置。其中,该配置接口可以为图形用户界面(GUI)、网页形式的配置界面或者应用程序接口(API)等等。
本发明实施例提供的云应用攻击行为处理方法能够能满足云计算系统应用部署场景,基于云计算应用级别进行安全防护,防止同一个主机内部不同应 用之间的相互攻击,或者主机内部对主机本身进行的攻击,同时减少对正常应用的影响。进一步地,恶意应用处理策略可配置,进而可根据不同安全级别或不同的攻击类型对恶意应用进行区别处理。
如图11所示,本发明实施例还提供了一种云应用安全防护系统,应用于云计算系统中,用于实现上述云应用攻击行为处理方法,该云应用安全防护系统包括:云应用攻击行为处理装置20、云控制器206,以及多个安全检测器(以图11中的205为示例);其中,多个安全检测器分别部署于多个云主机(如图11中的10、11、12和13)上,且每一云主机对应于一个安全检测器;云控制器206与多个云主机通信连接,或者集成于上述多个云主机中的一个云主机,用于管理和控制该多个云主机,每一云主机上运行有一个或多个云应用;云应用攻击行为处理装置20中存储有安全判断规则和恶意应用处理规则;
安全检测器205用于,根据行为检测规则对一个或多个云应用进行检测,以得到应用行为数据,并将应用行为数据上报给云应用攻击行为处理装置20;其中,该一个或多个云应用运行于安全检测器205对应的云主机10上;
云应用攻击行为处理装置20用于,接收多个云主机的至少一个云主机上的安全检测器205上报的应用行为数据,根据该应用行为数据以及安全判断规则,判断云主机10上运行的云应用是否存在攻击行为;如果判断存在攻击行为,则根据恶意应用处理规则,调用云控制器206对将存在攻击行为的云应用进行处理。
可选地,上述行为检测规则可以是由云应用攻击行为处理装置将安全判断规则转化后得到并下发给安全检测器的。
可选地,如果云应用攻击行为处理装置20判断云主机上运行的云应用存在攻击行为,还可以根据该存在攻击行为的云应用的初始信息查询该云应用所属的用户信息,然后将该存在攻击行为的云应用的应用行为数据和查询到的用户信息备份,并按照信息通知规则进行攻击信息通知处理;其中,云应用的初始信息用于唯一标识该云应用,初始信息可以为进程ID或进程,或者两者同时包含;云应用的用户信息包括但不限于:用户名、用户邮箱或用户身份证号。
需要说明的是,将应用行为数据和云应用所属的用户信息备份,具体可以 是以表格、日志或文档等数据格式存储在可靠存储介质中,以便管理员查看。
进一步地,进行攻击信息通知处理包括但不限于:产生告警信息、显示存在攻击行为的云应用以及该云应用所属的用户信息、或者将存在攻击行为的云应用所属的用户信息通知网警中心。
可选地,云应用攻击行为处理装置20与所述云控制器206通信连接,或者云应用攻击行为处理装置20集成于云控制器206上。
优选地,在另一个实施例中,云应用攻击行为处理装置20包括有配置接口,管理员或配置程序可以通过该配置接口配置安全判断规则、恶意应用处理规则和信息通知规则中的一项或多项。其中,该配置接口可以为图形用户界面(GUI)、网页形式的配置界面或者应用程序接口(API)等等。进一步地,在配置恶意应用处理规则的时候,可以根据恶意应用的攻击类型或者危险程度,配置不同的处理规则,以进行区别处理,从而实现安全防护的灵活性和可扩展性。当然,可以理解的是,这三种规则中的一种和多种也可以不需要管理员配置,由云计算系统按照默认规则自定义。
进一步地,为了实现更细粒度的安全防护,云应用攻击行为处理装置20下发给安全检测器的行为检测规则可以包括:进程检测规则或线程检测规则。这样,安全检测器可以对云应用进行进程或线程级别的检测,云应用攻击行为处理装置20可以基于安全检测器的检测结果,确定出存在攻击行为的进程或线程,然后对存在攻击行为的进程或线程进行处理,进而可以实现进程或线程界别的安全防护。
需要说明的是,本发明实施例的云应用安全防护系统所包含的云应用攻击行为处理装置20可以为前述任一装置实施例中所描述的云应用攻击行为处理装置,其具体实现细节可以参照前述装置及方法实施例,此处不再赘述。
本发明实施例提供的云应用攻击行为检测系统能够能满足云计算系统应用部署场景,基于云计算应用级别进行安全防护,防止同一个主机内部不同应用之间的相互攻击,或者主机内部对主机本身进行的攻击,同时减少对正常应用的影响。进一步地,恶意应用处理策略可配置,进而可根据不同安全级别或不同的攻击类型对恶意应用进行区别处理。
本领域普通技术人员可以理解上述实施例的各种方法中的全部或部分步骤是可以通过程序来指令相关的硬件(例如处理器)来完成,该程序可以存储于一计算机可读存储介质中,存储介质可以包括:ROM、RAM、磁盘或光盘等。
以上对本发明实施例所提供的云应用攻击行为处理方法、装置及系统进行了详细介绍,本文中应用了具体个例对本发明的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本发明的方法及其核心思想;同时,对于本领域的一般技术人员,依据本发明的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本发明的限制。

Claims (22)

  1. 一种云计算系统中云应用攻击行为的处理装置,其特征在于,包括:
    安全分析器,安全处理器和策略管理器,其中:
    所述策略管理器用于存储安全判断规则和恶意应用处理规则;
    所述安全分析器用于接收云计算系统中的多个云主机中的至少一个云主机上的安全检测器发送的应用行为数据,根据所述应用行为数据以及所述策略管理器中存储的安全判断规则,确定所述至少一个云主机上运行的云应用是否存在攻击行为,并在确定所述至少一个云主机上运行的云应用存在攻击行为时,将所述应用行为数据发送给所述安全处理器;其中,所述应用行为数据是所述安全检测器根据行为检测规则对所述云应用进行检测后得到的,且所述应用行为数据用于表示所述云应用的运行状态;
    所述安全处理器,用于根据所述策略管理器中存储的恶意应用处理规则,调用所述云计算系统中的云控制器提供的接口对所述云应用进行处理,所述云控制器与所述至少一个云主机通信连接或集成于所述至少一个云主机,用于控制所述至少一个云主机上运行的云应用。
  2. 根据权利要求1所述的装置,其特征在于,还包括:信息通知器;所述策略管理器中还存储有信息通知规则;
    所述安全分析器还用于,当确定所述云应用存在攻击行为时,获取所述云应用的初始信息并发送给所述安全处理器,其中,所述初始信息用于标识所述云应用;
    所述安全处理器还用于,根据所述云应用的初始信息查询所述云应用所属的用户信息,将所述用户信息和所述应用行为数据发送给所述信息通知器;
    所述信息通知器用于,将接收到的应用行为数据和云应用所属的用户信息存储并按照所述策略管理器中存储的信息通知规则进行攻击信息通知处理。
  3. 根据权利要求1或2所述的装置,其特征在于,
    所述策略管理器用于,将所述安全判断规则转化为所述行为检测规则,并将所述行为检测规则下发给所述至少一个云主机的安全检测器。
  4. 根据权利要求1至3任一项所述的装置,其特征在于,所述恶意应用处理规则用于指示对不同类型恶意应用的处理方式,或者对不同危险程度的恶意应用的处理方式,其中,所述恶意应用为存在攻击行为的云应用;所述安全处理器,具体用于根据所述云应用的攻击行为的类型,以及所述恶意应用处理规则所指示的对该类型应用的处理方式,对所述云应用进行相应处理;或者所述安全处理器,具体用于根据所述云应用的攻击行为的危险程度,以及所述恶意应用处理规则所指示的对该危险程度的应用的处理方式,对所述云应用进行相应处理。
  5. 根据权利要求2至4任一项所述的装置,其特征在于,所述攻击信息通知处理具体包括以下之一或其任意组合:产生告警信息、显示存在攻击行为的云应用以及该云应用所属的用户信息、以及将存在攻击行为的云应用所属的用户信息通知网警中心。
  6. 根据权利要求1至5任一项所述的装置,其特征在于,所述云应用攻击行为处理装置集成于所述云控制器。
  7. 根据权利要求2至6任一项所述的装置,其特征在于,所述安全判断规则、恶意应用处理规则和信息通知规则中的一项或多项是通过所述策略管理器的配置接口配置的,其中所述策略管理器的配置接口包括:配置界面和应用程序接口API中的至少一种。
  8. 根据权利要求1至6任一项所述的装置,其特征在于,所述行为检测规则包括:进程检测规则或线程检测规则;
    所述应用行为数据是所述安全检测器根据所述行为检测规则对所述云应用的进程或线程进行检测后得到的。
  9. 根据权利要求8所述的装置,其特征在于,所述安全分析器还用于在确 定所述云应用不存在攻击行为时,丢弃所述应用行为数据。
  10. 一种云应用攻击行为处理方法,用于包括多个云主机的云计算系统,其特征在于,包括:
    接收所述多个云主机中的至少一个云主机上报的应用行为数据,其中,所述应用行为数据是所述至少一个云主机上的安全检测器根据行为检测规则对所述至少一个云主机上运行的云应用进行检测后得到的,且所述应用行为数据用于表示所述至少一个云主机上运行的云应用的运行状态;
    根据所述应用行为数据以及安全判断规则,判断所述至少一个云主机上运行的云应用是否存在攻击行为;
    如果判断所述至少一个云主机上运行的云应用存在攻击行为,则根据恶意应用处理规则,调用所述云计算系统中的云控制器提供的接口对存在攻击行为的云应用进行处理,其中所述云控制器与所述至少一个云主机通信连接或集成于所述至少一个云主机,用于控制所述至少一个云主机上运行的云应用。
  11. 根据权利要求10所述的方法,其特征在于,还包括:
    如果判断所述至少一个云主机上运行的云应用存在攻击行为,则根据所述存在攻击行为的云应用的初始信息查询所述云应用所属的用户信息,其中,所述初始信息用于标识所述云应用;
    将所述存在攻击行为的云应用的应用行为数据和查询到的用户信息存储,并按照信息通知规则进行攻击信息通知处理。
  12. 根据权利要求10或11所述的方法,其特征在于,还包括:
    如果判断所述至少一个云主机上运行的云应用不存在攻击行为,则丢弃接收到的所述应用行为数据。
  13. 根据权利要求10至12任一项所述的方法,其特征在于,所述恶意应用处理规则用于指示对不同类型恶意应用的处理方式,或者对不同危险程度的恶意应用的处理方式,其中,所述恶意应用为存在攻击行为的云应用;所述调用云控制器提供的接口对将存在攻击行为的云应用进行相应处理,包括:根据所述云应用的攻击行为的类型,以及所述恶意应用处理规则所指示的对该类型应 用的处理方式,对所述云应用进行相应处理;或者根据所述云应用的攻击行为的危险程度,以及所述恶意应用处理规则所指示的对该危险程度的应用的处理方式,对所述云应用进行相应处理。
  14. 根据权利要求11至13任一项所述的方法,其特征在于,所述按照信息通知规则进行攻击信息通知处理包括以下之一或其任意组合:
    产生告警信息、显示存在攻击行为的云应用以及该云应用所属的用户信息、以及将存在攻击行为的云应用所属的用户信息通知网警中心。
  15. 根据权利要求10至14任一项所述的方法,其特征在于,还包括:将所述安全判断规则转化为所述行为检测规则,并将所述行为检测规则发送给所述安全检测器。
  16. 根据权利要求10至15任一项所述的方法,其特征在于,所述安全判断规则、恶意应用处理规则和信息通知规则中的一项或多项是通过配置接口配置的;其中所述配置接口包括:配置界面和应用程序接口API中的至少一种。
  17. 一种云应用安全防护系统,其特征在于,包括:云应用攻击行为处理装置、云控制器,以及多个安全检测器;其中,所述多个安全检测器分别部署于多个云主机上,且每一云主机对应于一个安全检测器;所述云控制器与所述多个云主机通信连接,用于管理和控制所述多个云主机,每一云主机上运行有一个或多个云应用;所述云应用攻击行为处理装置中存储有安全判断规则和恶意应用处理规则;
    所述安全检测器用于,根据行为检测规则对一个或多个云应用进行检测,以得到应用行为数据,并将所述应用行为数据上报给所述云应用攻击行为处理装置;其中,所述一个或多个云应用运行于所述安全检测器对应的云主机上;
    所述云应用攻击行为处理装置用于,接收所述多个云主机的至少一个云主机上的安全检测器上报的应用行为数据,根据所述应用行为数据以及所述安全判断规则,判断所述至少一个云主机上运行的云应用是否存在攻击行为;如果判断所述至少一个云主机上运行的云应用存在攻击行为,则根据所述恶意应用处理规则,调用云控制器提供的接口对存在攻击行为的云应用进行相应处理。
  18. 根据权利要求17所述的系统,其特征在于,所述云应用攻击行为处理 装置还用于,将所述安全判断规则转化为所述行为检测规则,并将所述行为检测规则下发给各个云主机的安全检测器。
  19. 根据权利要求17或18所述的系统,其特征在于,所述云应用攻击行为处理装置还用于,如果判断所述至少一个云主机上运行的云应用不存在攻击行为,则丢弃接收到的所述应用行为数据。
  20. 根据权利要求17或18所述的系统,其特征在于,所述云应用攻击行为处理装置还用于,如果判断所述至少一个云主机上运行的云应用存在攻击行为,则显示存在攻击行为的云应用以及该云应用所属的用户信息、或者将存在攻击行为的云应用所属的用户信息通知网警中心。
  21. 根据权利要求17至20任一项所述的系统,其特征在于,所述云应用攻击行为处理装置与所述云控制器通信连接,或者所述云应用攻击行为处理装置集成于所述云控制器上。
  22. 根据权利要求17至21任一项所述的系统,其特征在于,所述恶意应用处理规则用于指示对不同类型恶意应用的处理方式,或者对不同危险程度的恶意应用的处理方式,其中,所述恶意应用为存在攻击行为的云应用;所述云应用攻击行为处理装置具体用于:根据所述云应用的攻击行为的类型,以及所述恶意应用处理规则所指示的对该类型应用的处理方式,对所述云应用进行相应处理;或者根据所述云应用的攻击行为的危险程度,以及所述恶意应用处理规则所指示的对该危险程度的应用的处理方式,对所述云应用进行相应处理。
PCT/CN2015/079897 2014-11-26 2015-05-27 一种云计算系统中云应用攻击行为处理方法、装置及系统 Ceased WO2016082501A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
EP15862949.3A EP3214568B1 (en) 2014-11-26 2015-05-27 Method, apparatus and system for processing cloud application attack behaviours in cloud computing system
EP22192092.9A EP4160456A1 (en) 2014-11-26 2015-05-27 Method, apparatus and system for processing attack behavior of cloud application in cloud computing system
BR112017011074-1A BR112017011074B1 (pt) 2014-11-26 2015-05-27 Aparelho e método para processar um comportamento de ataque em um sistema de computação em nuvem
US15/606,855 US10567422B2 (en) 2014-11-26 2017-05-26 Method, apparatus and system for processing attack behavior of cloud application in cloud computing system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410709018.9A CN104392175B (zh) 2014-11-26 2014-11-26 一种云计算系统中云应用攻击行为处理方法、装置及系统
CN201410709018.9 2014-11-26

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/606,855 Continuation US10567422B2 (en) 2014-11-26 2017-05-26 Method, apparatus and system for processing attack behavior of cloud application in cloud computing system

Publications (1)

Publication Number Publication Date
WO2016082501A1 true WO2016082501A1 (zh) 2016-06-02

Family

ID=52610077

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/079897 Ceased WO2016082501A1 (zh) 2014-11-26 2015-05-27 一种云计算系统中云应用攻击行为处理方法、装置及系统

Country Status (5)

Country Link
US (1) US10567422B2 (zh)
EP (2) EP4160456A1 (zh)
CN (1) CN104392175B (zh)
BR (1) BR112017011074B1 (zh)
WO (1) WO2016082501A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113965405A (zh) * 2021-11-04 2022-01-21 杭州安恒信息技术股份有限公司 一种web攻击的监测方法、装置、设备及可读存储介质

Families Citing this family (30)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104392175B (zh) * 2014-11-26 2018-05-29 华为技术有限公司 一种云计算系统中云应用攻击行为处理方法、装置及系统
US20160359720A1 (en) * 2015-06-02 2016-12-08 Futurewei Technologies, Inc. Distribution of Internal Routes For Virtual Networking
CN106713216B (zh) * 2015-07-16 2021-02-19 中兴通讯股份有限公司 流量的处理方法、装置及系统
CN105262768A (zh) * 2015-11-04 2016-01-20 上海科技网络通信有限公司 一种云计算平台中基于混合模型的行为检测系统与方法
US10116767B2 (en) * 2015-11-13 2018-10-30 Furturewei Technologies, Inc. Scaling cloud rendezvous points in a hierarchical and distributed manner
CN105468980B (zh) * 2015-11-16 2018-07-03 华为技术有限公司 一种安全管控的方法、装置及系统
CN105404816B (zh) * 2015-12-24 2018-11-06 北京奇虎科技有限公司 基于内容的漏洞检测方法及装置
CN107179957B (zh) * 2016-03-10 2020-08-25 阿里巴巴集团控股有限公司 物理机故障分类处理方法、装置和虚拟机恢复方法、系统
CN107545178B (zh) * 2016-06-23 2021-01-15 华为技术有限公司 一种云应用的检测方法及云应用检测装置
CN107819727B (zh) * 2016-09-13 2020-11-17 腾讯科技(深圳)有限公司 一种基于ip地址安全信誉度的网络安全防护方法及系统
CN106570400B (zh) * 2016-10-11 2019-03-15 杭州安恒信息技术股份有限公司 一种云环境下通过自学习防攻击的系统及方法
US10505954B2 (en) * 2017-06-14 2019-12-10 Microsoft Technology Licensing, Llc Detecting malicious lateral movement across a computer network
CN107295021B (zh) * 2017-08-16 2021-06-04 深信服科技股份有限公司 一种基于集中管理的主机的安全检测方法及系统
US11228616B2 (en) * 2017-12-06 2022-01-18 Qatar Foundation Methods and systems for monitoring network security
CN108282489B (zh) 2018-02-07 2020-01-31 网宿科技股份有限公司 一种漏洞扫描方法、服务端及系统
CN108595333B (zh) * 2018-04-26 2021-08-03 Oppo广东移动通信有限公司 PaaS平台中应用进程的健康检查方法及装置
CN108769124B (zh) * 2018-04-28 2021-04-27 Oppo广东移动通信有限公司 PaaS平台的应用部署方法、装置、服务器及存储介质
CN109194623A (zh) * 2018-08-02 2019-01-11 谢聪敏 基于云计算的安全服务器
CN109218315B (zh) * 2018-09-20 2021-06-01 华为技术有限公司 一种安全管理方法和安全管理装置
CN109857726B (zh) * 2019-02-27 2023-05-12 深信服科技股份有限公司 一种应用特征库维护方法、装置、电子设备及存储介质
CN110099044A (zh) * 2019-03-28 2019-08-06 江苏通付盾信息安全技术有限公司 云主机安全检测系统及方法
CN110336784A (zh) * 2019-05-22 2019-10-15 北京瀚海思创科技有限公司 基于大数据的网络攻击识别预测系统、方法以及存储介质
US11368496B2 (en) * 2019-06-11 2022-06-21 Zscaler, Inc. Automatic network application security policy expansion
CN111343009B (zh) * 2020-02-14 2021-06-04 腾讯科技(深圳)有限公司 服务告警通知方法及装置、存储介质、电子设备
CN111031077B (zh) * 2020-03-10 2020-06-09 杭州圆石网络安全技术有限公司 一种流量清洗方法、流量清洗系统和设备
CN111984966B (zh) * 2020-08-31 2024-06-18 深圳平安医疗健康科技服务有限公司 基于Linux云平台的口令检测方法、装置、设备及存储介质
CN112910895B (zh) * 2021-02-02 2022-11-15 杭州安恒信息技术股份有限公司 网络攻击行为检测方法、装置、计算机设备和系统
CN113504971B (zh) * 2021-07-20 2024-02-13 华云数据控股集团有限公司 基于容器的安全拦截方法及系统
CN115904605A (zh) * 2021-09-30 2023-04-04 腾讯科技(深圳)有限公司 软件防御方法以及相关设备
CN114266047B (zh) * 2021-12-14 2025-02-14 北京天融信网络安全技术有限公司 一种恶意程序防御方法、装置、电子设备及存储介质

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103036745A (zh) * 2012-12-21 2013-04-10 北京邮电大学 云计算中一种基于神经网络的异常检测系统
CN103034807A (zh) * 2011-10-08 2013-04-10 腾讯科技(深圳)有限公司 恶意程序检测方法和装置
US8613089B1 (en) * 2012-08-07 2013-12-17 Cloudflare, Inc. Identifying a denial-of-service attack in a cloud-based proxy service
CN104038466A (zh) * 2013-03-05 2014-09-10 中国银联股份有限公司 用于云计算环境的入侵检测系统、方法及设备
CN104113521A (zh) * 2014-02-20 2014-10-22 西安未来国际信息股份有限公司 一种分布组件化入侵检测系统的设计
CN104392175A (zh) * 2014-11-26 2015-03-04 华为技术有限公司 一种云计算系统中云应用攻击行为处理方法、装置及系统

Family Cites Families (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP4379223B2 (ja) * 2004-06-18 2009-12-09 日本電気株式会社 動作モデル作成システム、動作モデル作成方法および動作モデル作成プログラム
US7725934B2 (en) 2004-12-07 2010-05-25 Cisco Technology, Inc. Network and application attack protection based on application layer message inspection
US9152789B2 (en) * 2008-05-28 2015-10-06 Zscaler, Inc. Systems and methods for dynamic cloud-based malware behavior analysis
US20110083179A1 (en) 2009-10-07 2011-04-07 Jeffrey Lawson System and method for mitigating a denial of service attack using cloud computing
CN102043917B (zh) 2010-12-07 2012-10-17 成都市华为赛门铁克科技有限公司 云系统分布式拒绝服务攻击防护方法以及装置和系统
US8539556B1 (en) * 2010-12-20 2013-09-17 Amazon Technologies, Inc. Disabling administrative access to computing resources
CN102075535B (zh) 2011-01-12 2013-01-30 中国科学院计算技术研究所 一种应用层分布式拒绝服务攻击过滤方法及系统
CN102291390B (zh) 2011-07-14 2014-06-04 南京邮电大学 一种基于云计算平台的防御拒绝服务攻击的方法
CN102685180B (zh) 2011-10-18 2015-07-08 国网电力科学研究院 一种面向云计算的网络安全预警方法
CN102693388B (zh) 2012-06-07 2014-03-19 腾讯科技(深圳)有限公司 数据安全防护处理系统及方法及存储介质
CN102843385B (zh) 2012-09-24 2015-04-15 东南大学 一种用于云计算环境中防范旁路攻击虚拟机的方法
CN103051707A (zh) 2012-12-20 2013-04-17 浪潮集团有限公司 一种基于动态用户行为的云取证方法及系统
CN103902892B (zh) 2012-12-24 2017-08-04 珠海市君天电子科技有限公司 基于行为的病毒防御方法及系统
CN103023912A (zh) 2012-12-26 2013-04-03 蓝盾信息安全技术股份有限公司 一种防止基于虚拟机进行网络攻击的方法
US9361455B2 (en) * 2013-01-02 2016-06-07 International Business Machines Corporation Security management in a networked computing environment
TWI474213B (zh) * 2013-01-09 2015-02-21 Hope Bay Technologies Inc 具攻擊防護機制的雲端系統及其防護方法
CN103746991B (zh) 2014-01-02 2017-03-15 曙光云计算技术有限公司 云计算网络中的安全事件分析方法及系统

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103034807A (zh) * 2011-10-08 2013-04-10 腾讯科技(深圳)有限公司 恶意程序检测方法和装置
US8613089B1 (en) * 2012-08-07 2013-12-17 Cloudflare, Inc. Identifying a denial-of-service attack in a cloud-based proxy service
CN103036745A (zh) * 2012-12-21 2013-04-10 北京邮电大学 云计算中一种基于神经网络的异常检测系统
CN104038466A (zh) * 2013-03-05 2014-09-10 中国银联股份有限公司 用于云计算环境的入侵检测系统、方法及设备
CN104113521A (zh) * 2014-02-20 2014-10-22 西安未来国际信息股份有限公司 一种分布组件化入侵检测系统的设计
CN104392175A (zh) * 2014-11-26 2015-03-04 华为技术有限公司 一种云计算系统中云应用攻击行为处理方法、装置及系统

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3214568A4 *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113965405A (zh) * 2021-11-04 2022-01-21 杭州安恒信息技术股份有限公司 一种web攻击的监测方法、装置、设备及可读存储介质

Also Published As

Publication number Publication date
US10567422B2 (en) 2020-02-18
BR112017011074A2 (zh) 2018-07-10
CN104392175B (zh) 2018-05-29
EP3214568A1 (en) 2017-09-06
EP3214568B1 (en) 2022-11-16
EP3214568A4 (en) 2017-10-25
BR112017011074B1 (pt) 2023-02-23
EP4160456A1 (en) 2023-04-05
CN104392175A (zh) 2015-03-04
US20170264637A1 (en) 2017-09-14

Similar Documents

Publication Publication Date Title
CN104392175B (zh) 一种云计算系统中云应用攻击行为处理方法、装置及系统
KR101535502B1 (ko) 보안 내재형 가상 네트워크 제어 시스템 및 방법
US10320833B2 (en) System and method for detecting creation of malicious new user accounts by an attacker
US10375101B2 (en) Computer implemented techniques for detecting, investigating and remediating security violations to IT infrastructure
US10630643B2 (en) Dual memory introspection for securing multiple network endpoints
US9639693B2 (en) Techniques for detecting a security vulnerability
US9027125B2 (en) Systems and methods for network flow remediation based on risk correlation
JP6419787B2 (ja) マルウェアコンテンツ検出システム内の仮想マシンへの最適化されたリソース割当て
US9594881B2 (en) System and method for passive threat detection using virtual memory inspection
US8973147B2 (en) Geo-mapping system security events
US11113086B1 (en) Virtual system and method for securing external network connectivity
CN104956376B (zh) 虚拟化环境中应用和设备控制的方法和技术
US10951646B2 (en) Biology based techniques for handling information security and privacy
US12563083B2 (en) Event-driven collection and monitoring of resources in a cloud computing environment
US20200045079A1 (en) Network monitoring based on distribution of false account credentials
CN111400720A (zh) 一种终端信息处理方法、系统及装置和一种可读存储介质
Wang et al. A novel covert channel detection method in cloud based on XSRM and improved event association algorithm

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15862949

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

REEP Request for entry into the european phase

Ref document number: 2015862949

Country of ref document: EP

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112017011074

Country of ref document: BR

ENP Entry into the national phase

Ref document number: 112017011074

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20170525