CN107247910A - A kind of file integrality measurement detection method, system and detection device - Google Patents

A kind of file integrality measurement detection method, system and detection device Download PDF

Info

Publication number
CN107247910A
CN107247910A CN201710687004.5A CN201710687004A CN107247910A CN 107247910 A CN107247910 A CN 107247910A CN 201710687004 A CN201710687004 A CN 201710687004A CN 107247910 A CN107247910 A CN 107247910A
Authority
CN
China
Prior art keywords
file
measurement
integrality
reference value
measurement file
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201710687004.5A
Other languages
Chinese (zh)
Other versions
CN107247910B (en
Inventor
崔士伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Suzhou Inspur Intelligent Technology Co Ltd
Original Assignee
Zhengzhou Yunhai Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zhengzhou Yunhai Information Technology Co Ltd filed Critical Zhengzhou Yunhai Information Technology Co Ltd
Priority to CN201710687004.5A priority Critical patent/CN107247910B/en
Publication of CN107247910A publication Critical patent/CN107247910A/en
Application granted granted Critical
Publication of CN107247910B publication Critical patent/CN107247910B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures

Abstract

The present invention relates to file detection technique field there is provided a kind of file integrality measurement detection method, system and detection device, method includes:According to the requirement of file integrality, the Initialize installation for measurement file measure based on file integrality;According to Initialize installation, the access action to pre-defined measurement file is intercepted, and calculates a reference value of the measurement file in real time;The a reference value of the measurement file prestored is read in inquiry, judges whether the measurement file meets the requirement of file integrality;If the measurement file meets file integrality requirement, allow the access action to the measurement file, so as to realize the control that conducted interviews to predefined file, complete file integrity measurement ensures the safety execution of access action.

Description

A kind of file integrality measurement detection method, system and detection device
Technical field
The invention belongs to file detection technique field, more particularly to a kind of file integrality measurement detection method, system and Detection device.
Background technology
The integrity measurement technology of file has very important significance to finding whether vital document is tampered, but at present The file integrality measurement technology of use belongs to static full property measurement substantially.The static full property measurement technology is every one Whether section time measure this document changes with benchmark metric value, when changing, then judges that this document integrality is present Problem, the possibility being tampered, when not changing, then file is complete.
But, if file is tampered between measuring twice, not detected measurement of distorting now is arrived, now to file Access will produce risk.
The content of the invention
Detection method is measured it is an object of the invention to provide a kind of file integrality, it is intended to if solved in the prior art File is tampered between measuring twice, and not detected measurement of distorting now is arrived, and the now access to file will produce wind Dangerous the problem of.
The present invention is achieved in that a kind of file integrality measurement detection method, and methods described comprises the steps:
According to the requirement of file integrality, the Initialize installation for measurement file measure based on file integrality;
According to Initialize installation, the access action to pre-defined measurement file is intercepted, and is calculated in real time described Measure a reference value of file;
The a reference value of the measurement file prestored is read in inquiry, judges whether the measurement file meets file complete The requirement of whole property;
If the measurement file meets file integrality requirement, allow the access action to the measurement file.
As an improvement scheme, the requirement according to file integrality, to measurement file carry out based on file it is complete The step of Initialize installation of whole property measurement, specifically includes following step:
The measurement the file whether pre-defined file of detection in real time is tampered, the quantity of the pre-defined measurement file For several;
File system carry again is carried out to pre-defined measurement file, during system again carry, is specified Iversion options;
According to the requirement of file integrality, a reference value sha1 of the pre-defined measurement file is calculated, and is preserved.
As an improvement scheme, described according to Initialize installation, the access to pre-defined measurement file is acted After the step of being intercepted, and calculate a reference value of the measurement file in real time;The measurement file is read in the inquiry Also comprise the steps before the step of a reference value:
Judge whether the measurement file is the file accessed, wherein, the file accessed is stored in In caching;
When the measurement file is the file accessed, then judge whether the measurement file is credible;
If the measurement file credible, performing allows the access action to the measurement file;
If the measurement file is the non-file accessed, the base that the measurement file is read in the inquiry is performed The step of quasi- value.
As an improvement scheme, if it is described measurement file meet file integrality requirement, allow to described Also comprise the steps after the step of access of measurement file is acted:
The measurement file for allowing to perform access action is added in the caching.
Another object of the present invention is to provide a kind of file integrality measurement detecting system, the system includes:
Initialize installation module, for the requirement according to file integrality, carries out being based on file integrality to measurement file The Initialize installation of measurement;
Access acts blocking module, for according to Initialize installation, the access of pre-defined measurement file is acted into Row is intercepted;
A reference value computing module, a reference value for calculating the measurement file in real time;
A reference value inquiry judging module, a reference value of the measurement file prestored is read for inquiring about, institute is judged State the requirement whether measurement file meets file integrality;
Allow action executing module, if judging that the measurement file meets file for a reference value inquiry judging module Integrity demands, then allow the access action to the measurement file.
As an improvement scheme, the Initialize installation module specifically includes:
Measure file and predefine module, the measurement file whether being tampered for the pre-defined file of detection in real time, in advance The quantity of the measurement file of definition is several;
System carry module, for carrying out file system carry again to pre-defined measurement file, in system again During carry, iversion options are specified;
A reference value calculates preserving module, for the requirement according to file integrality, calculates pre-defined measurement text The a reference value sha1 of part, and preserve.
As an improvement scheme, the system also includes:
Judge module is accessed, for judging whether the measurement file is the file that had accessed, wherein, this has been visited The file storage asked is in the buffer;
Credible judge module, for when the measurement file is the file accessed, then judging the measurement text Whether part is credible;
If the credible judge module judges that the measurement file, for the non-file accessed, performs the benchmark It is worth the step of inquiry judging module polls read a reference value of the measurement file;
If the measurement file credible, performing the permission action executing module allows the access to the measurement file Action.
As an improvement scheme, the system also includes:
Caching addition update module, for the measurement file for allowing to perform access action to be added in the caching.
Another object of the present invention is to provide a kind of detection device that detecting system is measured including file integrality.
In embodiments of the present invention, according to the requirement of file integrality, measurement file is carried out being based on file integrality degree The Initialize installation of amount;According to Initialize installation, the access action to pre-defined measurement file is intercepted, and is counted in real time Calculate a reference value of the measurement file;The a reference value of the measurement file prestored is read in inquiry, judges the measurement text Whether part meets the requirement of file integrality;If the measurement file meets file integrality requirement, allow to the measurement The access action of file, so as to realize the control that conducted interviews to predefined file, complete file integrity measurement is ensured and accessed The safety execution of action.
Brief description of the drawings
Fig. 1 is the implementation process figure that the file integrality that the embodiment of the present invention one is provided measures detection method;
Fig. 2 is the requirement according to file integrality that the present invention is provided, and measurement file is carried out being based on file integrality degree The implementation process figure of the Initialize installation of amount;
Fig. 3 is the implementation process figure that the file integrality that the embodiment of the present invention two is provided measures detection method;
Fig. 4 is the structured flowchart that the file integrality that the present invention is provided measures detecting system.
Embodiment
In order to make the purpose , technical scheme and advantage of the present invention be clearer, it is right below in conjunction with drawings and Examples The present invention is further elaborated.It should be appreciated that the specific embodiments described herein are merely illustrative of the present invention, and It is not used in the restriction present invention.
Fig. 1 shows that the file integrality that the embodiment of the present invention one is provided measures the implementation process figure of detection method, and it has Body comprises the steps:
In step S101, according to the requirement of file integrality, that is measured based on file integrality is carried out to measurement file Initialize installation.
In step s 102, according to Initialize installation, the access action to pre-defined measurement file is intercepted, and The a reference value of the measurement file is calculated in real time.
Wherein, the access action of this pair measurement file includes but is not limited to reading and writing, execution, deleted and renaming, and should To access act interception system kernel layer realize, can be intercepted by the way of system calls replacement, herein without To limit the present invention.
After the access action of measurement file is intercepted, a reference value of the measurement file is calculated in real time, is then performed following The step of judging in S103.
In step s 103, a reference value of the measurement file prestored is read in inquiry, judges the measurement file Whether the requirement of file integrality is met.
This judges to read to come whether that file meets the requirement of file integrality, that is, judge a reference value that calculates in real time with it is pre- Whether a reference value first stored is identical, if then meeting the requirement, if otherwise not meeting.
In step S104, if the measurement file meets file integrality requirement, allow to the measurement file Access is acted.
When measurement file does not meet this document integrity demands, then forbid performing above-mentioned access action.
In embodiments of the present invention, when detect measurement file do not meet file integrality requirement when, that is, measure file Through being tampered, then this is distorted into content and notify keeper, the advice method can use daily record form, naturally it is also possible to use it His form, herein not to limit the present invention.
Fig. 2 shows the requirement according to file integrality that the present invention is provided, and measurement file is carried out complete based on file Property measurement Initialize installation implementation process figure, it specifically includes following step:
In step s 201, the measurement file that whether detection file is tampered in real time is pre-defined, pre-defined is described The quantity for measuring file is several.
The process that this document is defined is that system file is confirmed, some vital documents are predefined, and prevents weight File is wanted to be maliciously tampered.
In step S202, file system carry again is carried out to pre-defined measurement file, in system again carry During, specify iversion options.
In this step, when to carrying out integrity detection with the file in file system, in addition it is also necessary to restarting systems.
In step S203, according to the requirement of file integrality, a reference value of the pre-defined measurement file is calculated Sha1, and preserve.
Wherein, the file and catalogue for often changing, it is not necessary to carry out file integrality measurement, such as/var/ Log catalogues.
Fig. 3 shows that the file integrality that the embodiment of the present invention two is provided measures the implementation process figure of detection method, and it has Body comprises the steps:
In step S301, according to Initialize installation, the access action to pre-defined measurement file is intercepted, and The a reference value of the measurement file is calculated in real time.
In step s 302, judge whether the measurement file is the file accessed, is then to perform step S303, Otherwise step S305 is performed.
Wherein, the file accessed is stored in the buffer.
In step S303, when it is the file accessed to measure file, then judge whether measurement file is credible, if It is then to perform step S304, otherwise performs step S306.
In this step, judge whether measurement file is credible, whether is changed realizations particularly directed to iversion, has Body is:
The access of file is very frequent under linux system, will if all carrying out a reference value sha1 calculating when accessing every time Systematic function is had a strong impact on, in order to influence systematic function less as far as possible, addition caching query is highly desirable to, and by inode Whether iversion is recorded, will be changed according to the iversion in file inode in caching when accessing this document again Determine whether file is tampered;
Inode is the data structure that file system represents a file, when file system mount is to specify iversion Option, then be that iversion in inode is counted and can be incremented by when file changes.
In step s 304, performing allows the access action to the measurement file.
In step S305, if the measurement file is the non-file accessed, the institute prestored is read in inquiry The a reference value of measurement file is stated, judges whether the measurement file meets the requirement of file integrality, is then to perform to return to perform Step S304, otherwise performs step S306.
Wherein, this judge the foundation for measuring the file requirement that whether meets file integrality be a reference value that calculates in real time with The a reference value of storage is same parameters value.
In step S306, forbid the access action to the measurement file.
The specific embodiment of the present invention is above are only, be will not be repeated here.
In this embodiment, after above-mentioned steps S305 has been performed, then the measurement file of the judgement is added in the buffer, together When mark the legitimacy that the access of the measurement file is acted, when receiving the action of the access to the measurement file next time again, then Legitimacy to the measurement file detects that detection is can be legal, if legal, continues executing with above-mentioned steps S303, no Then forbid accessing.
In embodiments of the present invention, said reference value is stored in application layer data storehouse, and the application layer opens one Netlink, when system kernel layer intercepts access action, after the inquiry is not hit, inner nuclear layer sends benchmark to application layer It is worth query messages to application layer, from application layer to inner nuclear layer feedback result.
Fig. 4 shows that the file integrality that the present invention is provided measures the structured flowchart of detecting system, for convenience of description, figure In only give the part related to the embodiment of the present invention, wherein, this document integrity measurement detecting system is built in detection and set In standby.
File integrality measurement detecting system includes:
Initialize installation module 11, for the requirement according to file integrality, is carried out complete based on file to measurement file Property measurement Initialize installation;
Access acts blocking module 12, for according to Initialize installation, the access to pre-defined measurement file to be acted Intercepted;
A reference value computing module 13, a reference value for calculating the measurement file in real time;
A reference value inquiry judging module 14, a reference value of the measurement file prestored is read for inquiring about, and is judged Whether the measurement file meets the requirement of file integrality;
Allow action executing module 15, if judging that the measurement file meets text for a reference value inquiry judging module Part integrity demands, then allow the access action to the measurement file.
Wherein, Initialize installation module 11 is specifically included:
Measure file and predefine module 16, the measurement file whether being tampered for the pre-defined file of detection in real time, in advance The quantity of the measurement file first defined is several;
System carry module 17, for carrying out file system carry again to pre-defined measurement file, in system weight During new carry, iversion options are specified;
A reference value calculates preserving module 18, for the requirement according to file integrality, calculates the pre-defined measurement The a reference value sha1 of file, and preserve.
With reference to shown in Fig. 4, this document integrity measurement detecting system also includes:
Judge module 19 is accessed, for judging whether the measurement file is the file that had accessed, wherein, this is The file storage accessed is in the buffer;
Credible judge module 20, for when the measurement file is the file accessed, then judging the measurement Whether file is credible;
If the credible judge module 20 judges that the measurement file, for the non-file accessed, performs the base The step of quasi- value inquiry judging module 14 inquires about a reference value for reading the measurement file;
If the measurement file credible, performing the permission action executing module 15 allows the visit to the measurement file Ask action.
Wherein, caching addition update module 21, it is described slow for the measurement file for performing access action will to be allowed to be added to In depositing.
Wherein, the function of above-mentioned modules will not be repeated here as described in above-mentioned embodiment of the method.
In embodiments of the present invention, according to the requirement of file integrality, measurement file is carried out being based on file integrality degree The Initialize installation of amount;According to Initialize installation, the access action to pre-defined measurement file is intercepted, and is counted in real time Calculate a reference value of the measurement file;The a reference value of the measurement file prestored is read in inquiry, judges the measurement text Whether part meets the requirement of file integrality;If the measurement file meets file integrality requirement, allow to the measurement The access action of file, so as to realize the control that conducted interviews to predefined file, complete file integrity measurement is ensured and accessed The safety execution of action.
The foregoing is merely illustrative of the preferred embodiments of the present invention, is not intended to limit the invention, all essences in the present invention Any modifications, equivalent substitutions and improvements made within refreshing and principle etc., should be included in the scope of the protection.

Claims (9)

1. a kind of file integrality measures detection method, it is characterised in that methods described comprises the steps:
According to the requirement of file integrality, the Initialize installation for measurement file measure based on file integrality;
According to Initialize installation, the access action to pre-defined measurement file is intercepted, and calculates the measurement in real time The a reference value of file;
The a reference value of the measurement file prestored is read in inquiry, judges whether the measurement file meets file integrality Requirement;
If the measurement file meets file integrality requirement, allow the access action to the measurement file.
2. file integrality according to claim 1 measures detection method, it is characterised in that described according to file integrality Requirement, to measurement file carry out based on file integrality measure Initialize installation the step of specifically include following step:
The measurement the file whether pre-defined file of detection in real time is tampered, if the quantity of the pre-defined measurement file is Dry;
File system carry again is carried out to pre-defined measurement file, during system again carry, is specified Iversion options;
According to the requirement of file integrality, a reference value sha1 of the pre-defined measurement file is calculated, and is preserved.
3. file integrality according to claim 2 measures detection method, it is characterised in that described to be set according to initialization Put, the access action to pre-defined measurement file is intercepted, and calculate the step of a reference value of the measurement file in real time After rapid;Also comprise the steps before the step of a reference value of the measurement file is read in the inquiry:
Judge whether the measurement file is the file accessed, wherein, the file accessed is stored in caching In;
When the measurement file is the file accessed, then judge whether the measurement file is credible;
If the measurement file credible, performing allows the access action to the measurement file;
If the measurement file is the non-file accessed, a reference value that the measurement file is read in the inquiry is performed The step of.
4. file integrality according to claim 3 measures detection method, it is characterised in that if the measurement file Meet file integrality requirement, then allow also to comprise the steps after the step of access to the measurement file is acted:
The measurement file for allowing to perform access action is added in the caching.
5. a kind of file integrality measures detecting system, it is characterised in that the system includes:
Initialize installation module, for the requirement according to file integrality, is carried out based on file integrality measurement to measurement file Initialize installation;
Access acts blocking module, for according to Initialize installation, the access action to pre-defined measurement file to be blocked Cut;
A reference value computing module, a reference value for calculating the measurement file in real time;
A reference value inquiry judging module, a reference value of the measurement file prestored is read for inquiring about, the degree is judged Whether amount file meets the requirement of file integrality;
Allow action executing module, if it is complete to judge that the measurement file meets file for a reference value inquiry judging module Property require, then allow to it is described measurement file access action.
6. file integrality according to claim 5 measures detecting system, it is characterised in that the Initialize installation module Specifically include:
Measure file and predefine module, the measurement file whether being tampered for the pre-defined file of detection in real time is pre-defined The measurement file quantity be several;
System carry module, for carrying out file system carry again to pre-defined measurement file, in system again carry During, specify iversion options;
A reference value calculates preserving module, for the requirement according to file integrality, calculates the pre-defined measurement file A reference value sha1, and preserve.
7. file integrality according to claim 6 measures detecting system, it is characterised in that the system also includes:
Judge module is accessed, for judging whether the measurement file is the file that had accessed, wherein, this had been accessed File storage in the buffer;
Credible judge module, for when the measurement file is the file accessed, then judging that the measurement file is It is no credible;
If the credible judge module judges that the measurement file, for the non-file accessed, performs a reference value and looked into Ask the step of a reference value of the measurement file is read in judge module inquiry;
If the measurement file credible, performing the permission action executing module allows the access to the measurement file to move Make.
8. file integrality according to claim 7 measures detecting system, it is characterised in that the system also includes:
Caching addition update module, for the measurement file for allowing to perform access action to be added in the caching.
9. a kind of file integrality including described in any one of claim 5 to 8 measures the detection device of detecting system.
CN201710687004.5A 2017-08-11 2017-08-11 File integrity measurement detection method, system and detection equipment Active CN107247910B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710687004.5A CN107247910B (en) 2017-08-11 2017-08-11 File integrity measurement detection method, system and detection equipment

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710687004.5A CN107247910B (en) 2017-08-11 2017-08-11 File integrity measurement detection method, system and detection equipment

Publications (2)

Publication Number Publication Date
CN107247910A true CN107247910A (en) 2017-10-13
CN107247910B CN107247910B (en) 2021-01-15

Family

ID=60012259

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710687004.5A Active CN107247910B (en) 2017-08-11 2017-08-11 File integrity measurement detection method, system and detection equipment

Country Status (1)

Country Link
CN (1) CN107247910B (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105069353A (en) * 2015-08-11 2015-11-18 武汉大学 Security reinforcement method for credible container based on Docker
CN105205391A (en) * 2015-10-15 2015-12-30 中南大学 Clean room real-time monitoring method based on integrity verification
CN106250760A (en) * 2016-07-26 2016-12-21 浪潮电子信息产业股份有限公司 A kind of U Boot based on TPM2.0 chip credible startup method
CN106384053A (en) * 2016-09-14 2017-02-08 江苏北弓智能科技有限公司 Trusted boot method and apparatus for mobile operation system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105069353A (en) * 2015-08-11 2015-11-18 武汉大学 Security reinforcement method for credible container based on Docker
CN105205391A (en) * 2015-10-15 2015-12-30 中南大学 Clean room real-time monitoring method based on integrity verification
CN106250760A (en) * 2016-07-26 2016-12-21 浪潮电子信息产业股份有限公司 A kind of U Boot based on TPM2.0 chip credible startup method
CN106384053A (en) * 2016-09-14 2017-02-08 江苏北弓智能科技有限公司 Trusted boot method and apparatus for mobile operation system

Also Published As

Publication number Publication date
CN107247910B (en) 2021-01-15

Similar Documents

Publication Publication Date Title
Loscocco et al. Linux kernel integrity measurement using contextual inspection
Tang et al. {CleanOS}: Limiting Mobile Data Exposure with Idle Eviction
CN101593259B (en) Method and system for verifying software completeness
US10432662B2 (en) Method and system for blocking malicious third party site tagging
CN102045319B (en) Method and device for detecting SQL (Structured Query Language) injection attack
US20100083383A1 (en) Phishing shield
CN103905461A (en) Cloud service behavior trustworthiness attestation method and system based on trusted third party
CN103455756B (en) A kind of course control method based on trust computing
RU2007143380A (en) UNIFORM AUTHORIZATION FOR HETEROGENEOUS APPLICATIONS
WO2016145993A1 (en) Method and system for user device identification
US20110219454A1 (en) Methods of identifying activex control distribution site, detecting security vulnerability in activex control and immunizing the same
CN103856471A (en) Cross-site scripting attack monitoring system and method
CN113542214B (en) Access control method, device, equipment and machine-readable storage medium
CN111159762B (en) Subject credibility verification method and system under mandatory access control
CN108205615A (en) Implementation system and implementation method for optimizing trusted basic component
US20230297676A1 (en) Systems and methods for code injection detection
US20170153986A1 (en) Cache longevity detection and refresh
US10970392B2 (en) Grouping application components for classification and malware detection
Chang et al. Numerical analysis for the approximation of optimal control problems with pointwise observations
Da et al. Detection of Android malware security on system calls
Shahriar et al. Content provider leakage vulnerability detection in Android applications
CN105631336B (en) Detect the system and method for the malicious file in mobile device
Kaczmarek et al. Operating system security by integrity checking and recovery using write‐protected storage
Fujii et al. Evaluation and design of function for tracing diffusion of classified information for file operations with KVM
CN107247910A (en) A kind of file integrality measurement detection method, system and detection device

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
TA01 Transfer of patent application right
TA01 Transfer of patent application right

Effective date of registration: 20201209

Address after: Building 9, No.1, guanpu Road, Guoxiang street, Wuzhong Economic Development Zone, Wuzhong District, Suzhou City, Jiangsu Province

Applicant after: SUZHOU LANGCHAO INTELLIGENT TECHNOLOGY Co.,Ltd.

Address before: Room 1601, floor 16, 278 Xinyi Road, Zhengdong New District, Zhengzhou City, Henan Province

Applicant before: ZHENGZHOU YUNHAI INFORMATION TECHNOLOGY Co.,Ltd.

GR01 Patent grant
GR01 Patent grant