Detection Method, Device, Storage Medium and Electronic Device for Subdomain Brute Force Attack

By extracting feature data from HTTP traffic data, combining preset dictionary library and weight calculation, the problem of poor detection of sub-domain name brute force cracking in the existing technology is solved, and high accuracy detection and timely protection of the server are achieved.

CN115834181BActive Publication Date: 2025-07-18HILLSTONE NETWORKS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211447829.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-18
Publication Date
2025-07-18
Estimated Expiration
2042-11-18

AI Technical Summary

Technical Problem

In the prior art, an isolated forest algorithm is used to calculate abnormal scores based on the target IP port feature value to detect whether the server is subject to brute-force cracking of the subdomain name. The detection effect is poor and it is difficult to effectively detect the collection of asset information at the application layer.

Method used

By obtaining the HTTP traffic data of the target server, extracting the target feature data, including HTTP request and response traffic data, analyzing the abnormal response code frequency and domain name configuration data, using the preset dictionary library and weight calculation, we determine whether the server is in the subdomain name brute force cracking state.

Benefits of technology

The accuracy of brute-force detection of subdomain names is improved, and the problem of low detection accuracy caused by only IP and IP port statistics is avoided, and effective identification and timely protection of application-level data is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834181B_ABST
    Figure CN115834181B_ABST
Patent Text Reader

Abstract

The present invention discloses a detection method, device, storage medium and electronic device for subdomain brute force cracking. Among them, the method includes: responding to a detection request, obtaining target traffic data and domain name configuration data of a target server, wherein the detection request is used to request to detect whether the target server is in a state of subdomain brute force cracking, the target traffic data is HTTP traffic data of the Hypertext Transfer Protocol generated when the target server accepts access during a target time period, and the domain name configuration data is domain name data for the target server to provide domain name services externally; extracting target feature data from the target traffic data based on the domain name configuration data; and determining whether the target server is in a state of subdomain brute force cracking based on the target feature data. The present invention solves the technical problem that the method of detecting whether a server is suffering from subdomain brute force cracking by using an isolation forest algorithm to calculate an anomaly score according to the destination IP port feature value has a poor detection effect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular, to a method, device, storage medium, and electronic device for detecting subdomain brute force cracking. Background Art

[0002] In the related art, the destination IP (Internet Protocol address) and the corresponding destination IP port feature values are extracted from each packet data; the isolation forest algorithm is used to calculate the anomaly score of the corresponding destination IP according to the destination IP port feature values of each packet data; the anomaly score threshold is calculated for the anomaly scores of all destination IPs through the quartile algorithm, and the destination IP corresponding to the anomaly score greater than the anomaly score threshold is marked as the destination IP suffering from network scanning. The anomaly scores of each destination IP are obtained by integrating various port features, and the destination IPs suffering from network scanning are determined by integrating all the scores. However, the statistics, calculations, and scoring of IPs and ports cannot effectively detect the collection of asset information at the application layer.

[0003] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention

[0004] Embodiments of the present invention provide a method, device, storage medium, and electronic device for detecting subdomain brute force cracking, so as to at least solve the technical problem of poor detection effect in the method of detecting whether a server is suffering from subdomain brute force cracking by calculating the anomaly score according to the destination IP port feature values using the isolation forest algorithm.

[0005] According to one aspect of the embodiments of the present invention, a method for detecting subdomain brute force cracking is provided, including: responding to a detection request, obtaining target traffic data and domain name configuration data of a target server, where the detection request is used to request to detect whether the target server is in a state of subdomain brute force cracking, the target traffic data is hypertext transfer protocol (HTTP) traffic data generated when the target server accepts access during a target time period, and the domain name configuration data is domain name data for which the target server provides domain name services externally; extracting target feature data from the target traffic data based on the domain name configuration data; and determining whether the target server is in a state of subdomain brute force cracking based on the target feature data.

[0006] Further, the target traffic data at least includes: a plurality of HTTP request traffic data and a plurality of HTTP response traffic data. Based on the domain name configuration data, target feature data is extracted from the target traffic data, including: based on the domain name configuration data and the target fields of each HTTP request traffic data, first HTTP request traffic data that hits the domain name configuration data is extracted from the plurality of HTTP request traffic data; in the plurality of HTTP response traffic data, first HTTP response traffic data corresponding to an abnormal response code is extracted, where the response code is used to judge the response status of the HTTP response traffic data, and the abnormal response code indicates that the target server does not provide access services for the corresponding domain name; based on the first HTTP request traffic data and the first HTTP response traffic data, the target feature data is determined.

[0007] Further, based on the first HTTP request traffic data and the first HTTP response traffic data, determining the target feature data includes: in the first HTTP request traffic data and the first HTTP response traffic data, target domain name data whose target fields hit the domain name configuration data and whose response code is an abnormal response code is extracted; the target domain name data is preprocessed to filter the target domain name data to obtain target domain name keywords; based on the target domain name keywords and the first HTTP response traffic data, the target feature data is determined.

[0008] Further, based on the target domain name keywords and the first HTTP response traffic data, determining the target feature data includes: performing a deduplication process on the target domain name keywords, and calculating the number of the target domain name keywords after the deduplication process to obtain the target domain name quantity; based on the first HTTP response traffic data, calculating the frequency of the abnormal response code in the target time period to obtain the frequency of the abnormal response code; based on the target domain name quantity, the frequency of the abnormal response code, and the target domain name keywords, the target feature data is determined.

[0009] Further, based on the target domain name quantity, the frequency of the abnormal response code, and the target domain name keywords, determining the target feature data includes: obtaining a preset dictionary library, where the preset dictionary library at least includes domain name keywords used by a preset sub - domain brute - force cracking tool; counting the number of times the target domain name keywords hit the domain name keywords in the preset dictionary library to obtain the target hit times; based on the target domain name quantity, the target hit times, and the frequency of the abnormal response code, the target feature data is obtained.

[0010] Further, based on the target feature data, determining whether the target server is in a state of sub - domain brute - force cracking includes: calculating a weighted sum of the number of target domains, the number of target hits, and the frequency of abnormal response codes through a preset weight to obtain the target probability that the target server is in a state of sub - domain brute - force cracking; comparing the size of the target probability with a preset threshold; when the target probability is greater than the preset threshold, determining that the target server is in a state of sub - domain brute - force cracking; when the target probability is less than or equal to the preset threshold, determining that the target server is not in a state of sub - domain brute - force cracking.

[0011] Further, obtaining the target traffic data of the target server includes: obtaining the traffic data of the target server within a target time period; performing application identification on each piece of traffic data in the traffic data, and extracting the HTTP traffic data in the traffic data to obtain the target traffic data.

[0012] According to another aspect of the embodiments of the present invention, there is also provided a detection device for sub - domain brute - force cracking, including: an acquisition module, configured to respond to a detection request and obtain target traffic data and domain name configuration data of a target server, where the detection request is used to request to detect whether the target server is in a state of sub - domain brute - force cracking, the target traffic data is hyper - text transfer protocol (HTTP) traffic data generated when the target server accepts access within a target time period, and the domain name configuration data is domain name data for which the target server provides domain name services externally; an extraction module, configured to extract target feature data from the target traffic data based on the domain name configuration data; a determination module, configured to determine whether the target server is in a state of sub - domain brute - force cracking based on the target feature data.

[0013] Further, the target traffic data at least includes: a plurality of HTTP request traffic data and a plurality of HTTP response traffic data, and the extraction module includes: a first extraction unit, configured to extract first HTTP request traffic data that hits the domain name configuration data from the plurality of HTTP request traffic data based on the domain name configuration data and a target field of each HTTP request traffic data; a second extraction unit, configured to extract first HTTP response traffic data corresponding to an abnormal response code from the plurality of HTTP response traffic data, where the response code is used to judge the response status of the HTTP response traffic data, and the abnormal response code indicates that the target server does not provide access services for the corresponding domain name; a determination unit, configured to determine the target feature data based on the first HTTP request traffic data and the first HTTP response traffic data.

[0014] Further, the determination unit includes: a first extraction sub-module, configured to extract, from the first HTTP request traffic data and the first HTTP response traffic data, target domain name data where the target field hits the domain name configuration data and the response code is an abnormal response code; a filtering sub-module, configured to preprocess the target domain name data and filter the target domain name data to obtain a target domain name keyword; a determination sub-module, configured to determine the target feature data based on the target domain name keyword and the first HTTP response traffic data.

[0015] Further, the determination sub-module includes: a processing sub-unit, configured to perform duplicate removal processing on the target domain name keyword and calculate the number of the target domain name keywords after the duplicate removal processing to obtain a target domain name quantity; a calculation sub-unit, configured to calculate the frequency of the abnormal response code within the target time period based on the first HTTP response traffic data to obtain the frequency of the abnormal response code; a determination sub-unit, configured to determine the target feature data based on the target domain name quantity, the frequency of the abnormal response code, and the target domain name keyword.

[0016] Further, the determination sub-unit includes: a first-level acquisition sub-unit, configured to acquire a preset dictionary library, where the preset dictionary library at least includes domain name keywords used by a preset sub-domain brute-force cracking tool; a first-level statistics sub-unit, configured to count the number of times the target domain name keyword hits the domain name keyword in the preset dictionary library to obtain a target hit count; a first-level processing sub-unit, configured to obtain the target feature data based on the target domain name quantity, the target hit count, and the frequency of the abnormal response code.

[0017] Further, the first-level processing sub-unit includes: a second-level calculation sub-unit, configured to perform weighted calculation on the target domain name quantity, the target hit count, and the frequency of the abnormal response code through a preset weight to obtain a target probability that the target server is in a sub-domain brute-force cracking state; a second-level comparison sub-unit, configured to compare the size of the target probability with a preset threshold; a first determination sub-unit, configured to determine that the target server is in a sub-domain brute-force cracking state when the target probability is greater than the preset threshold; a second-level determination sub-unit, configured to determine that the target server is not in a sub-domain brute-force cracking state when the target probability is less than or equal to the preset threshold.

[0018] Further, the acquisition module includes: a traffic acquisition unit, configured to acquire traffic data of the target server within a target time period; a data extraction unit, configured to perform application identification on each piece of traffic data in the traffic data and extract the HTTP traffic data in the traffic data to obtain the target traffic data.

[0019] According to another aspect of the embodiments of the present invention, an electronic device is further provided, including: a processor; and a memory for storing executable instructions of the processor; wherein, the processor is configured to execute the detection method for subdomain brute force cracking of any one of the above via executing the executable instructions.

[0020] According to another aspect of the embodiments of the present invention, a computer-readable storage medium is further provided. The computer-readable storage medium stores a computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the detection method for subdomain brute force cracking of any one of the above.

[0021] In the present invention, in response to a detection request, target traffic data and domain name configuration data of a target server are obtained, wherein the detection request is used to request to detect whether the target server is in a state of subdomain brute force cracking, the target traffic data is HTTP traffic data of the Hypertext Transfer Protocol generated when the target server accepts access during a target time period, and the domain name configuration data is domain name data for which the target server provides domain name services externally; based on the domain name configuration data, target feature data is extracted from the target traffic data; based on the target feature data, it is determined whether the target server is in a state of subdomain brute force cracking. Furthermore, the technical problem that the detection effect is not good in the method of detecting whether a server is suffering from subdomain brute force cracking by using the isolation forest algorithm to calculate the anomaly score according to the destination IP port feature value is solved. In the present invention, by extracting target feature data from the HTTP traffic data of the target server and determining whether the target server is in a state of subdomain brute force cracking based on the target feature data, it is avoided that in the related art, by means of IP and IP port statistics to detect whether the server is in a state of subdomain brute force cracking, it is difficult to identify application layer data, resulting in a low detection accuracy, thereby achieving the technical effect of improving the detection accuracy of detecting whether the server is suffering from subdomain brute force cracking. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:

[0023] Figure 1 is a flowchart of an optional detection method for subdomain brute force cracking according to an embodiment of the present invention Figure 1 ;

[0024] Figure 2 is a flowchart of an optional detection method for subdomain brute force cracking according to an embodiment of the present invention Figure 2 ;

[0025] Figure 3The flowchart of a method for detecting sub - domain brute - force cracking according to an embodiment of the present invention Figure 3 ;

[0026] Figure 4 The application schematic diagram of a firewall for sub - domain brute - force cracking according to an embodiment of the present invention;

[0027] Figure 5 The schematic diagram of a detection device for sub - domain brute - force cracking according to an embodiment of the present invention. Detailed implementation manners

[0028] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0029] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above - mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non - exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily limit to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0030] For the convenience of description, some terms or nouns related to this embodiment are illustrated below.

[0031] A sub - domain is the next - level domain name of a domain name. For example, map.abc.com and image.abc.com are two sub - domains of abc.com.

[0032] DNS, Domain Name System, abbreviated as DNS, is a system for resolving machine naming on the Internet.

[0033] Subdomain brute force cracking enumerates all possible subdomains to crack them. It uses tools to brute force the website server. There are conventional dictionary brute force cracking, custom fuzzing modes, batch brute force cracking, and recursive brute force cracking. The specific implementation of such tools usually tries different parameters in the HOST field of HTTP requests (usually GET (request to return specified page information), POST (submit data to specified resources for processing requests), HEAD (used to obtain headers)).

[0034] The HOST field can be a domain name or an IP address. After the domain name / IP, a port number can be followed, such as host: www.xxx.com:80.

[0035] Embodiment 1

[0036] According to an embodiment of the present invention, an optional method embodiment for detecting subdomain brute force cracking is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0037] Figure 1 It is a flowchart of an optional method for detecting subdomain brute force cracking according to an embodiment of the present invention. As Figure 1 shown, the method includes the following steps:

[0038] Step S101, in response to a detection request, obtain target traffic data and domain name configuration data of the target server. Among them, the detection request is used to request to detect whether the target server is in a state of subdomain brute force cracking. The target traffic data is the HTTP traffic data of the Hypertext Transfer Protocol generated when the target server accepts access during the target time period, and the domain name configuration data is the domain name data for which the target server provides domain name services externally.

[0039] Subdomains are an important part of domain name information collection. Collecting subdomain information can, on the one hand, discover more targets and increase the possibility of penetration testing; on the other hand, it can explore more hidden or forgotten application services, and among these applications, there are often some relatively serious vulnerabilities or quality problems.

[0040] The above-mentioned target server can be a web server (web page server). The above-mentioned detection request can be used to determine whether the target server is in a state of subdomain brute force cracking, that is, whether there is an attacker performing subdomain brute force cracking on the target server. The above-mentioned HTTP traffic data can be the hypertext transfer protocol HTTP traffic data generated during the access process of the target service, and can include HTTPS and HTTP traffic data during the request and response processes.

[0041] In order to avoid the situation in the related art where only IP and ports are statistically calculated and scored to determine whether the target server is in a state of subdomain brute force cracking, and it is difficult to collect information at the application layer. In this embodiment, by obtaining the target traffic data of the target server, the accuracy of detecting whether the target server is in a state of subdomain brute force cracking is improved.

[0042] Step S102: Extract target feature data from the target traffic data based on the domain name configuration data.

[0043] The above-mentioned target feature data can be extracted and analyzed from the target traffic data based on the domain name configuration data on the target server to obtain the target feature data. The above-mentioned extraction and analysis process can include, but is not limited to, the extraction and analysis of response codes in the HTTP traffic data, the statistics of target domain name data extracted from the HTTP traffic data, the frequency statistics of abnormal response codes, etc. Among them, the target domain name can be a subdomain of a preset domain name.

[0044] The above-mentioned domain name configuration data can be domain name configuration data that a user can configure on a network security device for a network server that provides domain name services externally. For example, configure the second-level domain name information of a certain company as xxx.com.

[0045] Step S103: Determine whether the target server is in a state of subdomain brute force cracking based on the target feature data.

[0046] In this embodiment, statistical analysis can be performed on the above-mentioned target feature data, which can include, but is not limited to, weighted calculation of multiple data in the target feature data, comparing the data after weighted calculation with a preset threshold to determine whether the target server is in a state of subdomain brute force cracking. In the case of determining that the target server is in a state of subdomain brute force cracking, a warning message can also be sent to timely strengthen the security protection function of the target server.

[0047] Through the above steps, by extracting target feature data from the HTTP traffic data of the target server and determining whether the target server is in the state of subdomain brute force cracking based on the target feature data, it avoids the situation in the related art where it is difficult to identify application layer data and the detection accuracy is low by detecting whether the server is in the state of subdomain brute force cracking through the method of IP and IP port statistics. Thus, the technical effect of improving the detection accuracy of whether the server is suffering from subdomain brute force cracking is achieved. And it solves the technical problem that the detection effect is not good by using the isolation forest algorithm to detect whether the server is suffering from subdomain brute force cracking by calculating the anomaly score according to the destination IP port feature value.

[0048] Optionally, the target traffic data at least includes: a plurality of HTTP request traffic data and a plurality of HTTP response traffic data. Extracting target feature data from the target traffic data based on the domain name configuration data includes: extracting the first HTTP request traffic data that hits the domain name configuration data from the plurality of HTTP request traffic data based on the domain name configuration data and the target field of each HTTP request traffic data; in the plurality of HTTP response traffic data, extracting the first HTTP response traffic data corresponding to the abnormal response code, where the response code is used to judge the response status of the HTTP response traffic data, and the abnormal response code indicates that the target server does not provide access services for the corresponding domain name; determining the target feature data based on the first HTTP request traffic data and the first HTTP response traffic data.

[0049] The above-mentioned target traffic data may include a plurality of HTTP request traffic data and a plurality of HTTP response traffic data.

[0050] In this embodiment, since the subdomain brute force cracking tool usually sends a large number of HTTP requests (usually GET (requests to return the specified page information), POST (submits data to the specified resource for processing requests), HEAD (used to obtain headers)) to the server within a short period of time, and the Host field in the request line is different. The user can configure on the network security device for the network server that provides domain name services externally (corresponding to the above-mentioned target server). For example, configure the second-level domain name information of a certain company as xxx.com, and in the Host of the request line of the brute force cracking tool, it may be filled with domain names such as aaa.xxx.com and bbb.xxx.com. For the request information or HTTP request traffic data in the above-mentioned HTTP request traffic data that hits the configured domain name information (corresponding to the above-mentioned domain name configuration data), that is, taking this HTTP request traffic data as one of the above-mentioned first HTTP request traffic data, and this HTTP request traffic data can also be marked and recorded in the storage medium.

[0051] In this embodiment, it is also possible to extract the first HTTP response traffic data corresponding to the abnormal response code from multiple HTTP response traffic data. Specifically, to distinguish from normal business request traffic, since there is actually no corresponding domain name for access in the subdomain brute force cracking request traffic, the response code of the HTTP response traffic data returned by the http request is usually an abnormal response code such as 20X - 30X and 404. That is, the above response code is used to judge the response status of the HTTP response traffic data, and the abnormal response code can be used to indicate that the target server does not provide access services for the corresponding domain name. In this embodiment, when the status code in the HTTP response traffic data is parsed as an abnormal response code, the HTTP response traffic data can be used as one of the above first HTTP response traffic data.

[0052] In this embodiment, it is also possible to determine the target feature data based on the above first HTTP request traffic data and first HTTP response traffic data, achieving the technical effect of improving the extraction efficiency of the target feature data.

[0053] Optionally, determining the target feature data based on the first HTTP request traffic data and the first HTTP response traffic data includes: extracting target domain name data in which the target field hits the domain name configuration data and the response code is an abnormal response code from the first HTTP request traffic data and the first HTTP response traffic data; preprocessing the target domain name data to filter the target domain name data to obtain target domain name keywords; and determining the target feature data based on the target domain name keywords and the first HTTP response traffic data.

[0054] The above target field can be the HOST field. Based on the HOST field, it can be judged whether the target traffic data hits the domain name configuration data, that is, whether the HOST field exists in the domain name configuration data.

[0055] In this embodiment, it is also possible to extract target domain name data in which the target field hits the domain name configuration data and the response code is an abnormal response code from the first HTTP request traffic data and the first HTTP response traffic data. That is, the domain name in the above target domain name data is in the first HTTP request traffic data, and the target domain name is the target domain name data in which the target traffic data hits the domain name configuration data and there is an abnormal response status.

[0056] Specifically, if the response code of the HTTP response traffic data is an abnormal response code, it can be judged whether the HOST field of the current target traffic data has hit the configured domain name of the domain name configuration data in the HTTP request traffic data. In this way, in the target traffic data, target domain name data in which the target field hits the domain name configuration data and the response code is an abnormal response code can be extracted.

[0057] The target domain name data can also be pre - processed to further filter out redundant colons, port numbers, and configured domain names, and extract the secondary domain name keywords of the configured domain names. Based on the target domain name keywords and the first HTTP response traffic data, the target feature data is determined, which improves the extraction efficiency of the target feature data.

[0058] Optionally, determining the target feature data based on the target domain name keywords and the first HTTP response traffic data includes: de - duplicating the target domain name keywords, calculating the number of the de - duplicated target domain name keywords to obtain the target domain name quantity; based on the first HTTP response traffic data, calculating the frequency of abnormal response codes within the target time period to obtain the frequency of abnormal response codes; based on the target domain name quantity, the frequency of abnormal response codes, and the target domain name keywords, determining the target feature data.

[0059] In this embodiment, the target domain name keywords can also be de - duplicated to remove duplicate domain name keywords, and the number of the de - duplicated target domain name keywords is calculated to obtain the target domain name quantity. Since the response code of the first HTTP response traffic data is an abnormal response code, the frequency of abnormal response codes within the target time period can also be calculated based on the first HTTP response traffic data to obtain the frequency of abnormal response codes; in this embodiment, the target feature data can be determined based on the target domain name quantity, the frequency of abnormal response codes, and the target domain name keywords, achieving the technical effect of improving the extraction efficiency of the target feature data.

[0060] Optionally, determining the target feature data based on the target domain name quantity, the frequency of abnormal response codes, and the target domain name keywords includes: obtaining a preset dictionary library, where the preset dictionary library at least includes the domain name keywords used by the preset sub - domain brute - force cracking tool; counting the number of times the target domain name keywords hit the domain name keywords in the preset dictionary library to obtain the target hit times; based on the target domain name quantity, the target hit times, and the frequency of abnormal response codes, obtaining the target feature data.

[0061] The above - mentioned preset dictionary library may include the common domain name keywords for sub - domain brute - force cracking, and the above - mentioned preset sub - domain brute - force cracking tool may be the common sub - domain brute - force cracking tool in the related art.

[0062] In this embodiment, the number of times the secondary domain names (corresponding to the above-mentioned target domain name keywords) extracted within a period of time (corresponding to the above-mentioned target time period) hit a preset dictionary library can be counted. The preset dictionary library can be a pre-loaded keyword library. By generating a state machine, multi-mode matching can be performed during the process of determining whether the domain name keyword in the HTTP traffic data hits the preset dictionary library. If the matching is successful, the hit count is incremented by one. In this way, by determining whether each target domain name keyword hits the preset dictionary library, the above-mentioned target hit count can be statistically obtained. The above-mentioned target feature data can be composed of the above-mentioned target domain name quantity, target hit count, and the frequency of abnormal response codes, achieving the technical effect of improving the determination efficiency of the target feature data.

[0063] Optionally, based on the target feature data, determining whether the target server is in the state of subdomain brute force cracking includes: performing weighted calculation on the target domain name quantity, target hit count, and the frequency of abnormal response codes through a preset weight to obtain the target probability that the target server is in the state of subdomain brute force cracking; comparing the size of the target probability with a preset threshold; in the case where the target probability is greater than the preset threshold, determining that the target server is in the state of subdomain brute force cracking; in the case where the target probability is less than or equal to the preset threshold, determining that the target server is not in the state of subdomain brute force cracking.

[0064] In this embodiment, through a preset weight, weighted calculation can be performed on the target domain name quantity, target hit count, and the frequency of abnormal response codes to obtain the target probability that the target server is in the state of subdomain brute force cracking; comparing the size of the target probability with a preset threshold; in the case where the target probability is greater than the preset threshold, determining that the target server is in the state of subdomain brute force cracking; in the case where the target probability is less than or equal to the preset threshold, determining that the target server is not in the state of subdomain brute force cracking, achieving the technical effect of improving the accuracy of detecting whether the server is in the state of subdomain brute force cracking.

[0065] Optionally, obtaining the target traffic data of the target server includes: obtaining the traffic data of the target server within the target time period; performing application identification on each piece of traffic data in the traffic data, and extracting the HTTP traffic data in the traffic data to obtain the target traffic data.

[0066] In this embodiment, the HTTP traffic (corresponding to the above-mentioned target traffic data) can be obtained through application recognition. Since subdomain brute force cracking usually uses HTTP requests, if the traffic application is recognized as HTTPS or HTTP, it is parsed; if it is a non-HTTP traffic application, it is non-target traffic and does not enter the current parsing. Through application recognition, the HTTP traffic data in the traffic data can be extracted to obtain the target traffic data, avoiding the situation that it is difficult to detect whether the target server is in the state of subdomain brute force cracking due to too much traffic data of the target server and the low detection efficiency, and achieving the technical effect of improving the detection efficiency of whether the target server is in the state of subdomain brute force cracking.

[0067] Figure 2 It is the flow of an optional method for detecting subdomain brute force cracking according to an embodiment of the present invention Figure 2 , such as Figure 2 shown. In this embodiment, the HTTP traffic to be detected and user configuration (corresponding to the above-mentioned domain name configuration data) can be obtained first; then, according to certain status codes of the HTTP response (corresponding to the above-mentioned HTTP response traffic data) (corresponding to the above-mentioned response codes), record the corresponding Host field in the request and the frequency of the request; then, according to whether the Host field hits a preset dictionary or the number of Host fields and whether the request frequency is greater than the configured threshold; in the case where the Host field hits a preset dictionary or the number of Host fields and the request frequency is greater than the corresponding configured threshold, it can be determined that the traffic to be detected is attack traffic, and the data connection corresponding to the traffic to be detected is an attack connection.

[0068] Figure 3 It is the flow of an optional method for detecting subdomain brute force cracking according to an embodiment of the present invention Figure 3 ; the user traffic on the web server (corresponding to the above-mentioned target server) can be obtained, and the application traffic is recognized to determine whether it is an HTTP request message (or HTTP request traffic data) and whether it is an HTTP response message (HTTP response traffic data); in the case of an HTTP request message, it is judged whether the traffic matches the user configuration, and in the case of a match, the host field can be parsed and recorded; in the case of an HTTP response message, it is judged whether the response code is abnormal, and in the case of an abnormal response code, the host field of the corresponding request can be obtained, the frequency can be calculated, and a subdomain brute force attack determination is performed. In the case where the judgment result is attack traffic, an alarm can be issued.

[0069] Figure 4 It is an application schematic diagram of a firewall for an optional subdomain brute force cracking according to an embodiment of the present invention, such as Figure 4As shown in the figure, when a firewall is deployed on a Web server (corresponding to the target server mentioned above), an attacker conducts brute force subdomain name cracking on the Web server through an HTTP request to collect information about the subdomains related to the Web server. At this time, if the user enables the detection function for brute force subdomain name cracking in the firewall, it will detect that the attacker is conducting brute force subdomain name cracking on the Web server, and can notify the user in a timely manner and generate an alarm message for the user.

[0070] There are many methods to collect subdomain information, such as: collecting subdomains using certificate transparency, collecting subdomains through regular checks (zone transfer, site configuration files, checking content security policies, collecting using DNS queries), collecting subdomains using DNS data sets, collecting subdomains using threat intelligence platform data, discovering subdomains using search engines, collecting domain name filings, and collecting through domain name brute force cracking.

[0071] Before conducting a web penetration, an attacker will first collect information. The depth of information collection is directly related to the success or failure of penetration testing. Information collection usually includes the collection of subdomain information. The embodiment mainly focuses on the detection and protection of the subdomain information collection link in web penetration.

[0072] In this embodiment, the number of times the secondary domain names extracted within a certain period of time (corresponding to the target time period mentioned above) hit the preset dictionary can be used. The preset dictionary (corresponding to the preset dictionary library mentioned above) is a pre-loaded keyword library, which generates a state machine and performs multi-pattern matching in the determination stage. If the matching is successful, the hit count is incremented by one to obtain the target hit count. The number of distinct secondary domain names extracted within a certain period of time can also be counted to obtain the target domain name quantity. Since the dictionary magnitudes and common keywords of different brute force cracking tools are different, and in addition, an attacker may use custom content to fill the message content, the preset dictionary often has limitations. Therefore, the number of distinct secondary domain names is also used as one of the determination conditions to improve the accuracy of detection. The number of requests with abnormal response codes within a certain period of time is used to obtain the frequency of abnormal response codes, and a large number of abnormal requests within a short period of time are also used as one of the determination conditions.

[0073] Based on different weights, the above three data are used to calculate the probability that the current attack is being suffered, obtaining the target probability. If it exceeds the preset threshold, it is considered that the web server (corresponding to the target server mentioned above) is being subjected to brute force subdomain name cracking.

[0074] Embodiment 2

[0075] This embodiment provides an optional detection device for brute force subdomain name cracking. Each implementation step in this detection device corresponds to each implementation step in Embodiment 1.

[0076] Figure 5Schematic diagram of an optional sub - domain brute - force cracking detection device according to an embodiment of the present invention, as Figure 5 shown, the detection device includes: an acquisition module 51, an extraction module 52, and a determination module 53.

[0077] Specifically, the acquisition module 51 is configured to respond to a detection request and acquire target traffic data and domain name configuration data of a target server. Among them, the detection request is used to request to detect whether the target server is in a state of sub - domain brute - force cracking. The target traffic data is HTTP traffic data of the hypertext transfer protocol generated when the target server accepts access within a target time period, and the domain name configuration data is domain name data for which the target server provides domain name services externally;

[0078] The extraction module 52 is configured to extract target feature data from the target traffic data based on the domain name configuration data;

[0079] The determination module 53 is configured to determine whether the target server is in a state of sub - domain brute - force cracking based on the target feature data.

[0080] In the sub - domain brute - force cracking detection device provided in the second embodiment of the present application, it includes: an acquisition module 51, configured to respond to a detection request and acquire target traffic data and domain name configuration data of a target server. Among them, the detection request is used to request to detect whether the target server is in a state of sub - domain brute - force cracking. The target traffic data is HTTP traffic data of the hypertext transfer protocol generated when the target server accepts access within a target time period, and the domain name configuration data is domain name data for which the target server provides domain name services externally; an extraction module 52, configured to extract target feature data from the target traffic data based on the domain name configuration data; a determination module 53, configured to determine whether the target server is in a state of sub - domain brute - force cracking based on the target feature data. Furthermore, it solves the technical problem of poor detection effect of the method for detecting whether a server is suffering from sub - domain brute - force cracking by using the isolation forest algorithm to calculate the anomaly score according to the destination IP port eigenvalue. In the present invention, by extracting target feature data from the HTTP traffic data of the target server and determining whether the target server is in a state of sub - domain brute - force cracking based on the target feature data, it avoids the situation in the related art where it is difficult to identify application - layer data by detecting whether the server is in a state of sub - domain brute - force cracking through IP and IP port statistics, resulting in low detection accuracy, thereby achieving the technical effect of improving the detection accuracy of detecting whether the server is suffering from sub - domain brute - force cracking.

[0081] Optionally, in the sub - domain brute - force cracking detection device provided in the second embodiment of the present application, the target traffic data at least includes: a plurality of HTTP request traffic data and a plurality of HTTP response traffic data. The extraction module includes: a first extraction unit, configured to extract, from the plurality of HTTP request traffic data, the first HTTP request traffic data that hits the domain name configuration data based on the domain name configuration data and the target field of each HTTP request traffic data; a second extraction unit, configured to extract, from the plurality of HTTP response traffic data, the first HTTP response traffic data corresponding to an abnormal response code, where the response code is used to determine the response status of the HTTP response traffic data, and the abnormal response code indicates that the target server does not provide access services for the corresponding domain name; a determination unit, configured to determine the target feature data based on the first HTTP request traffic data and the first HTTP response traffic data.

[0082] The above - mentioned target traffic data may include a plurality of HTTP request traffic data and a plurality of HTTP response traffic data.

[0083] In this embodiment, since the sub - domain brute - force cracking tool usually sends a large number of HTTP requests (usually GET, POST, HEAD) to the server within a short period of time, and the Host field in the request line is different. The user can configure the network security device for the network server that provides domain name services externally (corresponding to the above - mentioned target server). For example, configure the second - level domain name information of a certain company as xxx.com. In the Host of the request line of the brute - force cracking tool, it may be filled with domain names such as aaa.xxx.com, bbb.xxx.com. The request information or HTTP request traffic data in the above - mentioned HTTP request traffic data that hits the configured domain name information (corresponding to the above - mentioned domain name configuration data) is taken as one of the above - mentioned first HTTP request traffic data, and the HTTP request traffic data can also be marked and recorded in the storage medium.

[0084] In this embodiment, it is also possible to extract the first HTTP response traffic data corresponding to the abnormal response code from multiple HTTP response traffic data. Specifically, to distinguish from normal business request traffic, since the subdomain brute force cracking request traffic actually has no corresponding domain name for access, the response code of the HTTP response traffic data returned by the http request is usually an abnormal response code such as 20X - 30X and 404. That is, the above response code is used to judge the response status of the HTTP response traffic data, and the abnormal response code can be used to indicate that the target server does not provide access services for the corresponding domain name. In this embodiment, when the status code in the HTTP response traffic data is parsed as an abnormal response code, this HTTP response traffic data can be used as one of the above first HTTP response traffic data.

[0085] In this embodiment, it is also possible to determine the target feature data based on the above first HTTP request traffic data and first HTTP response traffic data, achieving the technical effect of improving the extraction efficiency of the target feature data.

[0086] Optionally, in the subdomain brute force cracking detection device provided in the second embodiment of this application, the determination unit includes: a first extraction sub-module, configured to extract target domain name data in which the target field hits the domain name configuration data and the response code is an abnormal response code from the first HTTP request traffic data and the first HTTP response traffic data; a filtering sub-module, configured to preprocess the target domain name data and filter the target domain name data to obtain target domain name keywords; a determination sub-module, configured to determine the target feature data based on the target domain name keywords and the first HTTP response traffic data.

[0087] The above target field can be the HOST field. Based on the HOST field, it can be judged whether the target traffic data hits the domain name configuration data, that is, whether the HOST field exists in the domain name configuration data.

[0088] In this embodiment, it is also possible to extract target domain name data in which the target field hits the domain name configuration data and the response code is an abnormal response code from the first HTTP request traffic data and the first HTTP response traffic data. That is, the domain name in the above target domain name data is in the first HTTP request traffic data, and the domain name in the target domain name data is also in the first HTTP response traffic data. That is, the target domain name is the target traffic data in which the target traffic data hits the domain name configuration data and there is an abnormal response status.

[0089] Specifically, if the response code of the HTTP response traffic data is an abnormal response code, it can be determined whether the HOST field of the current target traffic data has hit the configured domain name of the domain name configuration data in the HTTP request traffic data. Based on this, in the target traffic data, the target domain name data with the target field hitting the domain name configuration data and the response code being an abnormal response code can be extracted.

[0090] Preprocessing can also be performed on the target domain name data to further filter out redundant colons, port numbers, and filter the configured domain names, and extract the secondary domain name keywords of the configured domain names. Based on the target domain name keywords and the first HTTP response traffic data, the target feature data is determined, which improves the extraction efficiency of the target feature data.

[0091] Optionally, in the subdomain brute-force cracking detection device provided in the second embodiment of the present application, the determination sub-module includes: a processing sub-unit for de-duplicating the target domain name keywords and calculating the number of the de-duplicated target domain name keywords to obtain the target domain name quantity; a calculation sub-unit for calculating the frequency of the abnormal response code within the target time period based on the first HTTP response traffic data to obtain the frequency of the abnormal response code; a determination sub-unit for determining the target feature data based on the target domain name quantity, the frequency of the abnormal response code, and the target domain name keywords.

[0092] In this embodiment, the target domain name keywords can also be de-duplicated to remove duplicate domain name keywords, and the number of the de-duplicated target domain name keywords is calculated to obtain the target domain name quantity. Since the response code of the first HTTP response traffic data is an abnormal response code, the frequency of the abnormal response code within the target time period can also be calculated based on the first HTTP response traffic data to obtain the frequency of the abnormal response code; in this embodiment, the target feature data can be determined based on the target domain name quantity, the frequency of the abnormal response code, and the target domain name keywords, achieving the technical effect of improving the extraction efficiency of the target feature data.

[0093] Optionally, in the subdomain brute-force cracking detection device provided in the second embodiment of the present application, the determination sub-unit includes: a first-level acquisition sub-unit for acquiring a preset dictionary library, where the preset dictionary library at least includes the domain name keywords used by the preset subdomain brute-force cracking tool; a first-level statistics sub-unit for counting the number of times the target domain name keywords hit the domain name keywords in the preset dictionary library to obtain the target hit times; a first-level processing sub-unit for obtaining the target feature data based on the target domain name quantity, the target hit times, and the frequency of the abnormal response code.

[0094] The above-mentioned preset dictionary library may include common domain name keywords for subdomain brute-force cracking, and the above-mentioned preset subdomain brute-force cracking tool may be a commonly used subdomain brute-force cracking tool in the related art.

[0095] In this embodiment, the number of times the secondary domain names (corresponding to the above-mentioned target domain name keywords) extracted within a period of time (corresponding to the above-mentioned target time period) hit the preset dictionary library can be counted. The preset dictionary library can be a pre-loaded keyword library. By generating a state machine, multi-mode matching can be performed during the process of determining whether the domain name keyword of the HTTP traffic data hits the preset dictionary library. If the matching is successful, the hit count is incremented by one. In this way, by determining whether each target domain name keyword hits the preset dictionary library, the above-mentioned target hit count can be statistically obtained. The above-mentioned target feature data can be composed of the above-mentioned target domain name quantity, target hit count, and the frequency of abnormal response codes, achieving the technical effect of improving the determination efficiency of the target feature data.

[0096] Optionally, in the subdomain brute-force cracking detection device provided in the second embodiment of the present application, the first primary processing sub-unit includes: a first secondary calculation sub-unit, which has the ability to perform weighted calculation on the target domain name quantity, target hit count, and the frequency of abnormal response codes through preset weights to obtain the target probability that the target server is in the state of subdomain brute-force cracking; a first secondary comparison sub-unit, which is used to compare the size of the target probability with a preset threshold; a first determination sub-unit, which is used to determine that the target server is in the state of subdomain brute-force cracking when the target probability is greater than the preset threshold; a first secondary determination sub-unit, which is used to determine that the target server is not in the state of subdomain brute-force cracking when the target probability is less than or equal to the preset threshold.

[0097] In this embodiment, the target probability that the target server is in the state of subdomain brute-force cracking can be obtained by performing weighted calculation on the target domain name quantity, target hit count, and the frequency of abnormal response codes through preset weights; the size of the target probability is compared with a preset threshold; when the target probability is greater than the preset threshold, it is determined that the target server is in the state of subdomain brute-force cracking; when the target probability is less than or equal to the preset threshold, it is determined that the target server is not in the state of subdomain brute-force cracking, achieving the technical effect of improving the accuracy of detecting whether the server is in the state of subdomain brute-force cracking.

[0098] Optionally, in the subdomain brute-force cracking detection device provided in the second embodiment of the present application, the acquisition module includes: a traffic acquisition unit, which is used to acquire the traffic data of the target server within the target time period; a data extraction unit, which is used to perform application identification on each piece of traffic data in the traffic data, extract the HTTP traffic data in the traffic data, and obtain the target traffic data.

[0099] In this embodiment, HTTP traffic (corresponding to the above-mentioned target traffic data) can be obtained through application recognition. Since subdomain brute force attacks usually use HTTP requests, if the traffic application is recognized as HTTPS or HTTP, it is parsed; if it is a non-HTTP traffic application, it is non-target traffic and does not enter the current parsing. Through application recognition, the HTTP traffic data in the traffic data can be extracted to obtain the target traffic data, avoiding the situation that it is difficult to detect whether the target server is in the state of subdomain brute force attack due to too much traffic data of the target server and the low detection efficiency, and achieving the technical effect of improving the detection efficiency of whether the target server is in the state of subdomain brute force attack.

[0100] The above-mentioned detection device for subdomain brute force attack may further include a processor and a memory. The above-mentioned acquisition module 51, extraction module 52, determination module 53, etc. are all stored in the memory as program units, and the corresponding functions are realized by the processor executing the above program units stored in the memory.

[0101] The above-mentioned processor includes a kernel, and the kernel retrieves the corresponding program units from the memory. One or more kernels can be set, and by adjusting the kernel parameters, the technical problem of poor detection effect in the method of detecting whether the server is suffering from subdomain brute force attack by calculating the anomaly score according to the destination IP port eigenvalue using the isolation forest algorithm is solved. In the present invention, by extracting target feature data from the HTTP traffic data of the target server and determining whether the target server is in the state of subdomain brute force attack based on the target feature data, the situation that it is difficult to identify the application layer data and the low detection accuracy in the related art by detecting whether the server is in the state of subdomain brute force attack through the IP and IP port statistics method is avoided, thereby achieving the technical effect of improving the detection accuracy of whether the server is suffering from subdomain brute force attack.

[0102] The above-mentioned memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.

[0103] According to another aspect of the embodiments of the present invention, an electronic device is further provided, including: a processor; and a memory for storing executable instructions of the processor; wherein, the processor is configured to execute the detection method for subdomain brute force attack according to any one of the above through executing the executable instructions.

[0104] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium storing a computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the detection method for subdomain brute force cracking of any one of the above.

[0105] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0106] In the above embodiments of the present invention, the descriptions of the respective embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0107] In the several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in electrical or other forms.

[0108] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0109] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0110] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs.

[0111] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A detection method for brute-force cracking of subdomains, characterized in that, Including: In response to a detection request, obtain target traffic data and domain name configuration data of a target server, where the detection request is used to request detection of whether the target server is in a state of subdomain brute force cracking, the target traffic data is HTTP traffic data of the Hypertext Transfer Protocol generated when the target server accepts access during a target time period, and the domain name configuration data is domain name data for which the target server provides domain name services externally; Based on the domain name configuration data, extract target feature data from the target traffic data; Based on the target feature data, determine whether the target server is in a state of subdomain brute force cracking; Extracting target feature data from the target traffic data includes: extracting and analyzing response codes in the HTTP traffic data, counting target domain name data extracted from the HTTP traffic data, and counting the frequency of abnormal response codes to obtain the target feature data.

2. The detection method according to claim 1, wherein, The target traffic data at least includes: a plurality of HTTP request traffic data and a plurality of HTTP response traffic data. Based on the domain name configuration data, extracting target feature data from the target traffic data includes: Based on the domain name configuration data and the target fields of each HTTP request traffic data, extract the first HTTP request traffic data that hits the domain name configuration data from the plurality of HTTP request traffic data; Among the plurality of HTTP response traffic data, extract the first HTTP response traffic data corresponding to an abnormal response code, where the response code is used to judge the response status of the HTTP response traffic data, and the abnormal response code indicates that the target server does not provide access services for the corresponding domain name; Based on the first HTTP request traffic data and the first HTTP response traffic data, determine the target feature data.

3. The detection method according to claim 2, wherein, Based on the first HTTP request traffic data and the first HTTP response traffic data, determining the target feature data includes: In the first HTTP request traffic data and the first HTTP response traffic data, extract target domain name data whose target fields hit the domain name configuration data and whose response code is an abnormal response code; Perform preprocessing on the target domain name data, filter the target domain name data, and obtain target domain name keywords; Based on the target domain name keywords and the first HTTP response traffic data, determine the target feature data.

4. The detection method according to claim 3, characterized in that Based on the target domain name keywords and the first HTTP response traffic data, determining the target feature data includes: Perform deduplication processing on the target domain name keywords, and calculate the number of the target domain name keywords after deduplication processing to obtain the target domain name quantity; Based on the first HTTP response traffic data, calculate the frequency of abnormal response codes during the target time period to obtain the frequency of abnormal response codes; Based on the target domain name quantity, the frequency of abnormal response codes, and the target domain name keywords, determine the target feature data.

5. The detection method according to claim 4, characterized in that Based on the target domain name quantity, the frequency of abnormal response codes, and the target domain name keywords, determining the target feature data includes: Obtain a preset dictionary library, where the preset dictionary library at least includes domain name keywords used by a preset sub - domain brute - force cracking tool; Count the number of times the target domain name keywords hit the domain name keywords in the preset dictionary library to obtain the target hit count; Based on the target domain name quantity, the target hit count, and the frequency of abnormal response codes, obtain the target feature data.

6. The detection method according to claim 5, wherein Based on the target feature data, determine whether the target server is in a state of sub - domain brute - force cracking, including: Through a preset weight, perform weighted calculation on the target domain name quantity, the target hit count, and the frequency of the abnormal response codes to obtain the target probability that the target server is in a state of sub - domain brute - force cracking; Compare the size of the target probability with a preset threshold; In the case where the target probability is greater than the preset threshold, determine that the target server is in a state of sub - domain brute - force cracking; In the case where the target probability is less than or equal to the preset threshold, determine that the target server is not in a state of sub - domain brute - force cracking.

7. The detection method according to claim 1, wherein Obtain the target traffic data of the target server, including: Obtain the traffic data of the target server within a target time period; Perform application identification on each piece of traffic data in the traffic data, and extract the HTTP traffic data in the traffic data to obtain the target traffic data.

8. A detection device for brute-force cracking of subdomains, characterized in that, Include: An acquisition module, configured to respond to a detection request, and obtain the target traffic data and domain name configuration data of the target server, where the detection request is used to request detection of whether the target server is in a state of sub - domain brute - force cracking, the target traffic data is the HTTP traffic data of the Hypertext Transfer Protocol generated when the target server accepts access within a target time period, and the domain name configuration data is the domain name data for which the target server provides domain name services externally; An extraction module, configured to extract target feature data from the target traffic data based on the domain name configuration data; A determination module, configured to determine whether the target server is in a state of sub - domain brute - force cracking based on the target feature data; Wherein, the device is further configured to: extract and analyze the response codes in the HTTP traffic data, count the target domain name data extracted from the HTTP traffic data, and count the frequency of abnormal response codes to obtain the target feature data.

9. A computer-readable storage medium, characterized in that, A computer - readable storage medium stores a computer program, wherein when the computer program runs, it controls the device where the computer - readable storage medium is located to execute the sub - domain brute - force cracking detection method according to any one of claims 1 to 7.

10. An electronic device, characterized in that, Include one or more processors and a memory, where the memory is used to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the sub - domain brute - force cracking detection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Malicious traffic detection method and device

    CN114531271A

  • Abnormal traffic interception method and device, abnormal domain name identification method and device, equipment and medium

    CN115037537A