Library hit attack behavior recognition method and device, equipment, medium and program product
By setting a pseudo password for the account and calculating similarity parameters, simulating the response delay time and identifying low-frequency and long-term library collision attack behaviors, the problem of insufficient identification accuracy in the existing technology is solved, and higher identification accuracy and lower misjudgment rate are achieved.
Patent Information
- Application Number
- CN202510741710.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2045-06-04
AI Technical Summary
It is difficult for the existing technology to accurately identify low-frequency and long-term library collision attacks. The attacker disguises himself as low-frequency and long-term normal login operations by reducing the frequency of IP addresses, resulting in a decrease in recognition accuracy.
By setting the target pseudo password for the target account, the similarity parameters of the login input password and the pseudo password are calculated, the response delay time is determined based on the similarity parameters, and the difference between the login input password and the account password is simulated, which induces attackers to constantly try to approach the pseudo password, and identify the attack behavior of the collision database through the changes in the similarity parameters of multiple login request messages.
It improves the accuracy of identification of attack behaviors in the database, reduces the missed detection rate, reduces misjudgment of normal users, extends the attack cycle, increases the attack cost, and reduces the consumption of computing resources.
Smart Images

Figure CN120498816A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security protection, and in particular to a method, device, equipment, medium and program product for identifying credential stuffing attack behavior. Background Art
[0002] A credential stuffing attack is a cyberattack in which attackers use leaked usernames and multiple password combinations to attempt bulk logins on websites or services. Specifically, attackers use automated tools to try to log in to websites one by one using the collected usernames and passwords. If a successful login attempt occurs, the attackers gain access to the user's account information on the website, potentially exposing the user's privacy.
[0003] Because credential stuffing attacks typically involve batch login attempts, they often occur frequently within a short period of time. Presetting a threshold for the number of logins or frequency can be used to identify credential stuffing attacks. However, to counter this, attackers reduce the frequency of attempts from a single Internet Protocol (IP) address, disguising the attack as low-frequency, long-term normal logins. This circumvents detection and reduces the accuracy of attack identification. Summary of the Invention
[0004] The embodiments of the present application provide a method, apparatus, device, medium, and program product for identifying credential stuffing attack behaviors, which can improve the accuracy of identifying credential stuffing attack behaviors.
[0005] In the first aspect, an embodiment of the present application provides a method for identifying database stuffing attack behavior, including: receiving a login request message requesting to log in to a target account, the login request message including a target user name and a login input password, and the target user name corresponds to the target account; when the login input password is inconsistent with the account password of the target account, calculating the similarity parameter between the login input password and a target pseudo-password pre-set for the target account, the target pseudo-password is different from the account password; based on the similarity parameter, determining the response delay time, and feeding back a login response message according to the response delay time; when the change in the similarity parameters corresponding to multiple login request messages for logging into the target account meets the preset abnormal identification conditions, determining that there is a database stuffing attack behavior for logging into the target account.
[0006] In the second aspect, an embodiment of the present application provides a device for identifying credential stuffing attack behavior, including: a receiving module, used to receive a login request message requesting to log in to a target account, the login request message including a target user name and a login input password, and the target user name corresponds to the target account; a similarity calculation module, used to calculate the similarity parameter between the login input password and a target pseudo-password pre-set for the target account when the login input password is inconsistent with the account password of the target account, and the target pseudo-password is different from the account password; a response time determination module, based on the similarity parameter, determines the response delay time, and feeds back the login response message according to the response delay time; a behavior determination module, used to determine the presence of a credential stuffing attack behavior for logging into the target account when the change in the similarity parameters corresponding to multiple login request messages for logging into the target account meets the preset abnormal identification conditions.
[0007] In a third aspect, an embodiment of the present application provides a credential stuffing attack behavior identification device, comprising: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, the credential stuffing attack behavior identification method of the first aspect is implemented.
[0008] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processor, the method for identifying credential stuffing attack behavior of the first aspect is implemented.
[0009] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the method for identifying credential stuffing attack behavior of the first aspect.
[0010] The embodiment of the present application provides a method, apparatus, device, medium and program product for identifying credential stuffing attack behavior. When the login input password in the login request message for logging into the target account is inconsistent with the real password of the target account, i.e., the account password, the similarity parameter between the login input password and the target pseudo-password of the target account can be calculated, and the response delay time of the feedback login response message can be determined based on the similarity parameter, so as to simulate the effect of the difference between the login input password and the account password on the response delay time of the feedback login response message, thereby inducing the attacker to use the target pseudo-password as the account password and continuously invest resources to try to approach the target pseudo-password. On this basis, based on the changes in the similarity parameters corresponding to the multiple login request messages for logging into the target account within a preset time period, it is determined whether the multiple login request messages conform to the behavior pattern of the attacker continuously trying to approach the target pseudo-password. If the multiple login request messages conform to the behavior pattern of the attacker continuously trying to approach the target pseudo-password, that is, if the changes in the similarity parameters meet the abnormal identification conditions, it is determined that a credential stuffing attack behavior exists. This method can identify low-frequency, long-term credential stuffing attacks, thereby reducing the missed detection rate of credential stuffing attacks, reducing misjudgments of normal users, and improving the accuracy of identifying credential stuffing attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0012] Figure 1 A flowchart of a method for identifying credential stuffing attacks provided in one embodiment of the present application;
[0013] Figure 2 A schematic diagram of an example of a visual report provided in an embodiment of the present application;
[0014] Figure 3 This is a flowchart of an example of a credential stuffing attack behavior identification process provided in an embodiment of the present application;
[0015] Figure 4 A schematic diagram of the structure of a credential stuffing attack behavior identification device provided in one embodiment of the present application;
[0016] Figure 5 A schematic diagram of the structure of a credential stuffing attack behavior identification device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0017] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating examples of the present application. It should be noted that the acquisition, storage, use, processing, etc. of information and data in the embodiments of the present application are authorized by the user or relevant agencies and comply with the relevant provisions of national laws and regulations.
[0018] A credential stuffing attack is a type of network attack where attackers use automated tools to try to log in to a website one by one using collected username and password combinations. If a successful login attempt occurs, the attacker can obtain the user's account information on the website, causing a wider range of privacy leaks. To identify credential stuffing attacks, parameter thresholds such as the number of logins or the frequency of logins can be preset. If the number of logins exceeds the threshold or the frequency of logins exceeds the threshold within a short period of time, it can be considered a credential stuffing attack. However, to counter this identification scheme, attackers will reduce the frequency of attempts from a single IP address, disguising the credential stuffing attack as a low-frequency, long-term normal login operation, thereby bypassing the identification of credential stuffing attacks and reducing the accuracy of identifying credential stuffing attacks.
[0019] The present application provides a method, apparatus, device, medium and program product for identifying credential stuffing attack behavior, which can design a pseudo-password trap mechanism. By simulating the progressive response feedback of the login system, it can induce the attacker to form a unique trial-and-correction behavior trajectory in the process of low-frequency, long-term continuous login attempts. The trial-and-correction behavior trajectory can be identified in the long-term login process, thereby identifying low-frequency, long-term credential stuffing attack behavior, improving the recognition accuracy of credential stuffing attack behavior, and strengthening the precise identification and effective control of credential stuffing attack behavior.
[0020] The following describes the method, device, equipment, medium and program product for identifying credential stuffing attack behavior provided by this application.
[0021] The present application provides a method for identifying credential stuffing attack behavior, which can be applied to scenarios where user logins are monitored. The method for identifying credential stuffing attack behavior can be executed by a user login system, and the user login system can be implemented as a credential stuffing attack behavior identification device, equipment, etc., which is not limited here. Figure 1 This is a flow chart of a method for identifying credential stuffing attacks provided in one embodiment of the present application. Figure 1 As shown, the method for identifying credential stuffing attack behavior may include steps S101 to S104.
[0022] In step S101 , a login request message for logging into a target account is received.
[0023] The target account is the account being logged in. The target account may include accounts of applications, mini-programs, etc., or payment accounts, and is not limited here. The login request message is used to request login to the target account, including the target username and login input password. Different accounts correspond to different usernames. The target username corresponds to the target account. The target username includes the username obtained based on the user's input. For example, the target username can be the username entered by the receiving user in the username input box, or the target username can be the username selected by the receiving user in the username drop-down list. The way the user enters the target username is not limited here. The login input password is the password entered by the user carried in the login request message.
[0024] In some examples, the login request message may also include, but is not limited to, one or more of the following information: the IP address sending the login request message, device identification information of the device sending the login request message, the time when the login request message was sent, etc. The device identification information is used to identify the device sending the login request message. For example, the device identification information may include, but is not limited to, a device code, device fingerprint information, etc.
[0025] In step S102 , when the login password is inconsistent with the target account's password, a similarity parameter between the login password and a target pseudo password preset for the target account is calculated.
[0026] The login password may or may not match the target account's password. First, compare the login password to see if they match. If they match, the likelihood that the logged-in user is the target account is greater. The login can be allowed directly or user identity verification can continue, with no restrictions. If the login password doesn't match the target account's password, it's possible the target account's user accidentally entered the wrong password, or an attacker may be conducting a credential stuffing attack. Further processing is required to determine which scenario is the cause.
[0027] A target pseudo-password can be set in advance for the target account, and the target pseudo-passwords for different target accounts can be different. The target pseudo-password is different from the account password. The target pseudo-password is a fake password for the target account. Using the target pseudo-password cannot log in to the target account, but using the account password can log in to the target account. The purpose of setting the target pseudo-password is to induce the attacker to input the login password in the low-frequency, long-term database stuffing attack behavior closer to the target pseudo-password, so as to subsequently identify the attacker's database stuffing attack behavior. The target pseudo-password can be randomly generated. In some examples, an encryption algorithm can be used to generate a random string as the target pseudo-password. For example, the Advanced Encryption Standard (AES) algorithm is used to randomly generate the target pseudo-password. In order to ensure the security of the account password, that is, the real password, the target pseudo-password can be encrypted and stored in an independent database that is completely isolated from the database where the account password is located to avoid leakage of the account password.
[0028] The similarity parameter between the login password and the target pseudo-password can represent the similarity between the login password and the target pseudo-password. The similarity parameter may include, but is not limited to, cosine similarity, edit distance (i.e., Levenshtein distance), Jacard similarity, Hamming distance, longest common subsequence similarity, N-Gram similarity, Jaro-Winkler similarity, or a combination of two or more parameters. Other similarity parameters that can represent similarity are also within the scope of protection of the embodiments of this application.
[0029] In step S103, based on the similarity parameter, the response delay duration is determined, and a login response message is fed back according to the response delay duration.
[0030] In the past, the user login process did not involve the target pseudo-password. Only the login password entered by the user was compared with the target account's account password. During the comparison process, the difference between the login password and the account password will affect the delay in the user login system sending the login response message back to the user. For example, if the login password and the account password are compared bit by bit, the more characters that differ between the login password and the account password are in the front, the shorter the delay. An attacker may exploit this and determine the degree of similarity between the login password and the account password based on the delay in receiving the login response message from the user, thereby updating the login password and sending the login request message again, repeating the above process until the user's account is compromised. The embodiments of the present application exploit this by setting a target pseudo-password and adjusting the response delay of the feedback login response message based on the similarity between the login password and the target pseudo-password. This simulates the impact of the difference between the login password and the account password on the response delay of the feedback login response message, so that the attacker will mistake the target pseudo-password for the account password and continuously invest resources to try to approximate the target pseudo-password. A Login Response message is a feedback message paired with a Login Request message. It may include the login result, which can be either a success or failure. A response delay time may be inserted before the Login Response message is fed back. This means that the Login Response message is fed back after waiting for the response delay time.
[0031] In some examples, the response delay duration is positively correlated with the similarity represented by the similarity parameter, that is, the higher the similarity represented by the similarity parameter, the longer the response delay duration, so as to simulate the impact of the difference between the login input password and the account password on the response delay duration of the feedback login response message.
[0032] In step S104, when the changes in the similarity parameters corresponding to the multiple login request messages for logging into the target account meet the preset abnormality identification conditions, it is determined that there is a database stuffing attack for logging into the target account.
[0033] If a credential stuffing attack is occurring to log into the target account, the changes in similarity parameters corresponding to multiple login request messages sent to the target account over a long period of time may follow a certain pattern. Anomaly identification conditions can be pre-set based on the attacker's behavior patterns, such as using a target pseudo-password as the account password and continuously investing resources in an attempt to approximate the target pseudo-password. Specifically, the anomaly identification conditions can include information describing the attacker's behavior patterns, such as using a target pseudo-password as the account password and continuously investing resources in an attempt to approximate the target pseudo-password. By analyzing the changes in similarity parameters corresponding to multiple login request messages sent to the target account over a long period of time, the long-term login behavior of the target account can be reflected. This reduces reliance on high-frequency request detection mechanisms and can reduce computing resource consumption by the user login system. If the changes in similarity parameters meet the anomaly identification conditions, it indicates that the multiple login request messages sent within a preset period of time were sent by the attacker and constitute a credential stuffing attack. Therefore, the presence of a credential stuffing attack can be determined. In response to the determination of a credential stuffing attack, appropriate security measures can be promptly implemented to protect the security of the target account. For example, security measures may include, but are not limited to, one or more of locking the target account, sending an alarm message to the real user of the target account, and sending an alarm message to the administrator of the user logging into the system.
[0034] In some examples, the login request message may also include, but is not limited to, one or more of the following information: the IP address that sends the login request message, the device identification information of the device that sends the login request message, the time point when the login request message is sent, etc. The IP address, device identification information, time point, etc. in the login request message can be used as context information for the similarity parameter to determine whether a credential stuffing attack has occurred in combination with the similarity parameter. For example, if a certain IP address sends login request messages at a higher frequency than the preset normal frequency in a short period of time, it can be considered that a credential stuffing attack has occurred; if a device fingerprint is associated with multiple different IP addresses in multiple login request messages, it can be considered that a credential stuffing attack has occurred; if login request messages sent by multiple IP addresses in a short period of time request to log in to the same target account, it can be considered that a credential stuffing attack has occurred. It is also possible to lock abnormal IP addresses and abnormal devices based on the IP address, device fingerprint, etc. in the login request message identified as a credential stuffing attack for subsequent tracing.
[0035] In an embodiment of the present application, when the login password in the login request message requesting to log in to the target account is inconsistent with the real password of the target account, that is, the account password, the similarity parameter between the login password and the target pseudo-password of the target account can be calculated, and the response delay time of the feedback login response message can be determined based on the similarity parameter, so as to simulate the impact of the difference between the login password and the account password on the response delay time of the feedback login response message, thereby inducing the attacker to use the target pseudo-password as the account password and continuously invest resources to try to approximate the target pseudo-password. On this basis, based on the changes in the similarity parameters corresponding to multiple login request messages for logging into the target account within a preset time period, it is determined whether the multiple login request messages conform to the behavior pattern of the attacker continuously trying to approximate the target pseudo-password. If the multiple login request messages conform to the behavior pattern of the attacker continuously trying to approximate the target pseudo-password, that is, if the changes in the similarity parameters meet the abnormal identification conditions, it is determined that a database collision attack has occurred. This approach can identify low-frequency, long-term credential stuffing attacks, thereby reducing the missed detection rate, reducing misjudgments of legitimate users, improving the accuracy of identifying credential stuffing attacks, extending the attack cycle, increasing the attacker's attack cost, and reducing the success rate of credential stuffing attacks. It also reduces reliance on high-frequency login request detection mechanisms, lowers the computing resource consumption of user login systems, and supports seamless integration with existing password verification systems.
[0036] In some embodiments, a similarity parameter between the login input password and the target pseudo-password can be determined by combining two similarities. Specifically, a first similarity parameter can be determined based on the operations required to convert the login input password into the target pseudo-password; a second similarity parameter can be determined based on the length of the matching prefix between the login input password and the target pseudo-password; and the first and second similarity parameters can be combined to obtain the similarity parameter.
[0037] The first similarity parameter can characterize the size of the minimum number of operations required to convert the login input password into the target pseudo-password. The smaller the minimum number of operations required to convert the login input password into the target pseudo-password, the more similar the login input password is to the target pseudo-password. The operations required to convert the login input password into the target pseudo-password may include but are not limited to editing operations such as character deletion operations, character addition operations, and character replacement operations. In some examples, the first similarity parameter can be calculated by dynamic programming, and the minimum number of operations required to convert the first i characters of the login input password into the first j characters of the target pseudo-password is obtained one by one until the minimum number of operations required to convert the login input password into the target pseudo-password is obtained, where i is any digit of the characters in the login input password, and j is any digit of the characters in the target pseudo-password. The minimum number of operations required to convert the first i characters of the login input password into the first j characters of the target pseudo-password is obtained based on the conversion between the first i-1 characters of the login input password and the first j-1 characters of the target pseudo-password. For example, the login input password is string s1, the target pseudo password is string s2, string s1 includes m characters, and string t1 includes n characters. A two-dimensional matrix can be used to represent the minimum number of operations for converting the first i characters of the login input password into the first j characters of the target pseudo password. Any element d[i][j] in the two-dimensional matrix represents the minimum number of operations for converting the first i characters of the login input password into the first j characters of the target pseudo password. It should be noted that the character numbers in string s1 and string t1 can start from 0, that is, the characters in string s1 include characters s[0] to characters s[m-1], and the characters in string t1 include characters t[0] to characters t[n-1]. The first similarity parameter can be calculated according to the following formula (1):
[0038]
[0039] Where d(i,j) is the minimum number of operations required to convert the first i characters of the login password into the first j characters of the target pseudo-password; s[i-1] is the i-1th character in the string s1, and t[i-1] is the j-1th character in the string t1; if the characters s[i-1] and t[i-1] are the same, then d(i,j) = d(i-1,j-1); if the characters s[i-1] and t[i-1] are different, then d(i,j) is the minimum of d(i-1,j)+1, d(i,j-1)+1, and d(i-1,j-1)+1. The value d(i-1,j)+1 indicates that character s[i-1] must be deleted from string s1 to convert the first i characters of the login password into the first j characters of the target pseudo-password. d(i,j-1)+1 indicates that character t[j-1] must be inserted into string s1 to convert the first i characters of the login password into the first j characters of the target pseudo-password. d(i-1,j-1)+1 indicates that character s[i-1] in string s1 must be replaced with t[j-1] to convert the first i characters of the login password into the first j characters of the target pseudo-password. Through this iterative calculation, we can ultimately calculate d(m,n), which is the minimum number of operations required to convert the login password into the target pseudo-password.
[0040] The normalization process can convert the minimum number of operations required to convert the login input password into the target pseudo-password into a value between 0 and 1, so as to facilitate the subsequent calculation of the similarity parameter. The specific method of the normalization process is not limited herein, and any normalization process that can convert the minimum number of operations into a value between 0 and 1 is within the scope of protection of the embodiments of the present application. For example, the length of the login input password and the length of the target pseudo-password, whichever is longer, can be obtained, the ratio of the minimum number of operations to the longer length can be calculated, and then the difference between 1 and the ratio can be determined as the first similarity parameter.
[0041] The second similarity parameter characterizes the degree of matching between the login input password and the target pseudo-password. The longer the matching length between the login input password and the target pseudo-password, the more similar they are considered to be. The matching prefix includes the consecutive identical characters between the login input password and the target pseudo-password starting from the first character, that is, the matching prefix includes the characters preceding the first occurrence of different characters between the login input password and the target pseudo-password in character order. The mechanism of deriving similarity based on the matching length can better promote the attacker's probing behavior. Combining the second similarity with the first similarity can consider the impact of different characters appearing at the beginning of the string on the similarity. For example, if the target pseudo-password is abcdef, one login input password is ab*def, and the other login input password is a*cdef. Both login input passwords have the same first similarity with the target pseudo-password, but considering the matching prefix, the login input password ab*def is generally considered to be closer to the target pseudo-password abcdef than the login input password a*cdef.
[0042] In some examples, the matching prefix can be determined as the number of consecutive characters that are identical between the login input password and the target pseudo password starting from the first character. The larger of the length of the login input password and the length of the target pseudo password is obtained, and the ratio of the length of the matching prefix to the larger length is determined as the second similarity parameter. The length here can specifically be the number of characters.
[0043] For example, the second similarity parameter can be calculated according to the following formula (2):
[0044]
[0045] Among them, prefix_similarity is the second similarity parameter; prelen is the length of the matching prefix; len(s) is the length of the login input password; len(target) is the length of the target pseudo-password; max() is the maximum value algorithm.
[0046] The first similarity parameter and the second similarity parameter may be combined to obtain a similarity parameter. In some examples, the product of the first similarity parameter and the second similarity parameter may be used as the similarity parameter. For example, the similarity parameter may be calculated according to the following formula (3):
[0047] Similarity=d(m,n)×Prefix_similarity (3)
[0048] Wherein, Similarity is the similarity parameter; d(m,n) is the first similarity parameter; and Prefix_similarity is the second similarity parameter. The specific contents of the first similarity parameter and the second similarity parameter can be found in the relevant descriptions in the above embodiments and will not be repeated here. The value of the first similarity parameter is between 0 and 1, and the value of the second similarity parameter is between 0 and 1. Correspondingly, the value of the similarity parameter is also between 0 and 1.
[0049] In some examples, weight coefficients may be set for the first similarity parameter and the second similarity parameter respectively, and the similarity parameters may be calculated using a weighted algorithm.
[0050] When the similarity parameter is a value between 0 and 1, a similarity parameter of 0 indicates that the login input password and the target pseudo-password do not match at all, and a similarity parameter of 1 indicates that the login input password and the target pseudo-password match completely. If the length of the matching prefix between the login input password and the target pseudo-password is long and the minimum number of operations required to convert the login input password to the target pseudo-password is short, the similarity parameter is close to 1, i.e., the login input password and the target pseudo-password are very similar and nearly match completely. If the length of the matching prefix between the login input password and the target pseudo-password is short or even 0, or the minimum number of operations required to convert the login input password to the target pseudo-password is long, the similarity parameter is close to 0, i.e., the login input password and the target pseudo-password are very low in similarity.
[0051] In some embodiments, a gradient mapping relationship between a similarity parameter and a gradient delay time can be preset. The gradient mapping relationship includes a correspondence between a similarity parameter and a delay time. In the gradient mapping relationship, the similarity represented by the similarity parameter increases by a preset similarity step, and the delay time correspondingly increases by a preset time step. The similarity step and the time step can be set according to the scenario, requirements, experience, etc., and are not limited here. For example, the similarity step is 0.1 and the time step is 100 milliseconds, that is, for every increase of 0.1 in the similarity parameter, the delay time correspondingly increases by 100 milliseconds. After determining the response delay time corresponding to the similarity parameter obtained in this calculation, the delay time corresponding to the calculated similarity parameter is searched in the preset gradient mapping relationship, and the searched delay time is determined as the response delay time. For example, if the delay time correspondingly increases by 100 milliseconds for every increase of 0.1 in the similarity parameter, the response delay time can be calculated according to the following formula (4), which can also be regarded as a model of the gradient mapping relationship:
[0052] response_time=base_response_time+(Similarity×1000) (4)
[0053] Among them, response_time is the response delay duration; base_response_time is the basic response time, which can be set according to the scenario, requirements, experience, etc. For example, the basic response time can be 0 milliseconds or other values, which are not limited here; Similarity is the similarity parameter.
[0054] The response delay duration is determined through the gradient mapping relationship, and the login response message is fed back according to the response delay duration. While ensuring login security, it can also avoid interfering with normal user operations, thereby taking into account login defense capabilities, user login system login efficiency and user experience.
[0055] In some embodiments, the abnormal identification conditions in the above embodiments may include: the similarity represented by the similarity parameter increases monotonically and gradually converges; or, the similarity represented by the similarity parameter increases monotonically until the login input password is consistent with the target pseudo-password. The feature that the similarity represented by the similarity parameter increases monotonically is consistent with the feature that the attacker gradually tries to make the login input password approach the target pseudo-password, and in the early stage of the database collision attack, the change in similarity is large, but as the induction mechanism of the target pseudo-password in the embodiment of the present application gradually takes effect, the change in similarity represented by the similarity parameter will gradually decrease, reflecting that the attacker's behavior pattern tends to be stable. Therefore, if the similarity represented by the similarity parameter increases monotonically and gradually converges, it can be determined that there is a database collision attack. The similarity represented by the similarity parameter increases monotonically until the login input password is consistent with the target pseudo-password, indicating that the attacker has tried to approach the target pseudo-password and crack the target pseudo-password many times, and it can be determined that there is a database collision attack.
[0056] The changing trend of the similarity represented by the similarity parameter can be determined by linear regression. For example, the linear regression model is as follows (5):
[0057] s i =α+βi+ε i (5)
[0058] Among them, s i is the dependent variable, which can be the similarity parameter; α is the intercept term; β is the slope parameter; i is the independent variable, which can be the position of the similarity parameter in the time series; ε i is the error term. If the slope parameter β in the linear regression model is greater than 0, it means that the similarity represented by the similarity parameter is monotonically increasing.
[0059] The similarity represented by the similarity parameter gradually converges means that the similarity gradually tends to a certain value or a stable state. Whether the similarity represented by the similarity parameter converges can be determined by calculating the rate of change between the similarity parameters obtained twice adjacently. If, within a period of time, the amplitude of the rate of change between the similarity parameters obtained twice adjacently gradually decreases to below a preset rate of change threshold, it can be determined that the similarity represented by the similarity parameter converges. The rate of change threshold can be set according to the scenario, requirements, experience, etc., and is not limited here. For example, the rate of change threshold can be 0.01. For example, the rate of change between the similarity parameters obtained twice adjacently can be calculated according to the following formula (6):
[0060] rate(i)=|(s i+1 -s i ) / s i | (6)
[0061] Among them, rate(i) is the rate of change between the similarity parameters obtained twice; s i+1 is the similarity parameter obtained the next time; s i is the similarity parameter obtained previously.
[0062] In some embodiments, a sliding time window algorithm can be used to analyze changes in similarity parameters. Specifically, for login request messages received in chronological order where the input password is inconsistent with the account password, the time window can be shifted by a preset time step. An average similarity value is calculated based on the similarity parameters corresponding to the login request messages in the time window after each time window shift. The change in similarity parameters is determined based on the average similarity values obtained after multiple time window shifts. The time window can be set based on specific scenarios, requirements, and experience, and can include a fixed number of similarity parameters. The preset time step can be the same as the interval between two consecutive login request messages received. The time window can be slid in real time. For example, for each new login request message received for the target account, the similarity parameters corresponding to the login request message are calculated, the time window is shifted once, so that the last data in the time window corresponds to the similarity parameter corresponding to the most recent login request message, and the average similarity value of the similarity parameters in the time window is calculated. Alternatively, for a series of similarity parameters acquired within a preset time period, the time window can be gradually slid so that the last data in the time window corresponds to the similarity parameter corresponding to the most recent login request message, and the average similarity value of the similarity parameters in the time window is calculated. By calculating the average similarity value of the similarity parameters in the time window, the trend of the continuous similarity parameters can be smoothed and analyzed. For example, the average similarity value of the similarity parameters in the time window can be expressed as follows (7):
[0063]
[0064] Among them, window_avg(i) is the average similarity; s k is the kth similarity parameter; w is the length of the time window, that is, the number of similarity parameters contained in the time window; w≤i≤n, n is the total number of similarity parameters.
[0065] If the average similarity value for a time window gradually increases, it indicates that the similarity represented by the similarity parameter is improving. If the average similarity value for a time window gradually decreases, it indicates that the similarity represented by the similarity parameter is decreasing. If the average similarity value for a time window still fluctuates significantly, further smoothing can be performed to smooth out the fluctuations. Smoothing methods may include, but are not limited to, weighted moving average processing and exponential smoothing.
[0066] Based on the similarity analysis in a sliding time window manner, the variation trend of the continuous similarity parameters can be smoothed and analyzed, so as to dynamically adjust the response extension time of the feedback login response message according to the similarity parameters.
[0067] In some embodiments, the severity of a credential stuffing attack can be determined based on the magnitude of the similarity represented by a similarity parameter, thereby adjusting security policies. The similarity parameter can be positively correlated with the similarity. That is, the larger the similarity parameter, the higher the similarity; the smaller the similarity parameter, the lower the similarity. If the similarity parameter is greater than a first threshold, a verification code verification process is added and executed; if the similarity parameter is greater than a second threshold, the target account is locked for a preset lock duration; if the similarity parameter is greater than a third threshold, an alarm notification message is sent, and the target account is locked until the account administrator unlocks it. The specific values of the first threshold, the second threshold, the third threshold, and the preset lock time can be set according to the scenario, requirements, scenarios, etc., and are not limited here. For example, the first threshold is 0.5, the second threshold is 0.8, and the third threshold is 0.9; that is, if the similarity parameter is greater than 0.5, a verification code verification process can be added to send a verification code to the real user of the target account to prompt the real user to enter the verification code for verification. If the login request message is sent by an attacker, the attacker cannot receive the verification code and cannot pass the verification code verification, which can protect the login security of the target account; if the similarity parameter is greater than 0.8, the target account can be locked for 1 hour; if the similarity parameter is greater than 0.9, an alarm message can be sent to the administrator and the target account can be locked. There is no time limit for locking the target account, and the target account can only be logged in again until the administrator unlocks it.
[0068] Through the above-mentioned step-by-step dynamic defense strategy, the security protection of user login can be strengthened and the security of user data can be improved.
[0069] In some embodiments, identified credential stuffing attacks can be recorded and a security report generated. Specifically, relevant information about each login associated with a credential stuffing attack can be recorded, such as the login request time, IP address, device fingerprint, and similarity parameters. Visual reports can also be generated, such as displaying the attacker's behavior trajectory and similarity parameter trends, allowing administrators and users to intuitively understand the manifestations of credential stuffing attacks. The security report can also record warning messages and implemented protective measures.
[0070] For example, Figure 2 A schematic diagram of an example of a visual report provided in an embodiment of the present application, such as Figure 2 As shown, curves of similarity parameters corresponding to the login request messages of user 1, user 2, and user 3, as well as a warning threshold line and an alarm threshold line are shown. Figure 2 The horizontal axis is time, and the vertical axis is the similarity parameter. The similarity parameter is positively correlated with the similarity. The three green dotted lines are the linear regression fitting lines of the similarity parameter curve of user 1, the similarity parameter curve of user 2, and the similarity parameter curve of user 3. Figure 2 The slope of the linear regression line for User 1's similarity parameter curve is almost zero, indicating that User 1's similarity parameter curve is converging and above the warning threshold. This suggests the possibility of a credential stuffing attack. Further observation or combining the trend of User 1's previous similarity parameter curves is necessary to determine whether a credential stuffing attack is occurring. However, warning measures should be implemented for User 1. The slope of the linear regression line for User 1's similarity parameter curve is greater than zero. User 2's similarity parameter curve increases, and later similarity parameters approach 1. Portions of User 2's similarity parameter curve are above the warning threshold, and even portions are above the alert threshold. This suggests a credential stuffing attack, and warning and alert measures should be implemented for User 2. The slope of the linear regression line for User 3's similarity parameter curve is less than zero, indicating that User 3's similarity parameter curve is decreasing and below the warning threshold. This suggests a credential stuffing attack is not occurring, and warning and alert measures are not necessary for User 3.
[0071] For ease of understanding, the following example illustrates the process of identifying credential stuffing attack behavior in an embodiment of the present application. Figure 3 This is a flowchart of an example of a credential stuffing attack behavior identification process provided in an embodiment of the present application. The credential stuffing attack behavior can be performed by a user logging into the system, such as Figure 3 As shown, the credential stuffing attack behavior identification process may include steps a1 to a10.
[0072] In step a1, a login request message is received.
[0073] In step a2, the account password verification process is performed. This process is to compare the login password in the login request message with the real password of the target account, that is, the account password.
[0074] In step a3, if the login password is consistent with the account password, a login response message is fed back normally.
[0075] In step a4, if the login password is inconsistent with the account password, the similarity between the login password and the target pseudo password is calculated. The similarity can be reflected by a similarity parameter.
[0076] In step a5, the behavior data corresponding to each login request message is recorded. The behavior data may include but is not limited to similarity parameters, IP address, device fingerprint information, login request time, login account, etc.
[0077] In step a6, a long-term behavior analysis is performed on the target login account. The long-term behavior analysis may include obtaining changes in similarity parameters.
[0078] In step a7, a check is performed to determine whether an anomaly has occurred. This can be accomplished by determining whether the change in the similarity parameter satisfies anomaly identification criteria. If the change in the similarity parameter satisfies the anomaly identification criteria, an anomaly is determined to have occurred. If the change in the similarity parameter does not meet the anomaly identification criteria, no anomaly is determined to have occurred. If no anomaly has occurred, step a3 is executed. If an anomaly has occurred, a credential stuffing attack is considered to have occurred, and step a8 is executed.
[0079] In step a8, a step response time strategy is executed. The step response time strategy includes searching for a response delay time corresponding to the similarity parameter from a step-like gradient mapping relationship based on the similarity represented by the similarity parameter, and feeding back a login response message according to the response delay time.
[0080] In step a9, the credential stuffing attack behavior is recorded and a security report is generated.
[0081] In step a10, the credential stuffing attack is monitored and an alarm is issued.
[0082] The specific contents of the above steps a1 to a10 can be found in the relevant descriptions in the above embodiments, which will not be repeated here.
[0083] This application also provides a device for identifying database stuffing attack behavior. Figure 4 This is a schematic diagram of the structure of a credential stuffing attack behavior identification device provided in one embodiment of the present application. Figure 4 As shown, the credential stuffing attack behavior identification device 200 may include a receiving module 201 , a similarity calculation module 202 , a response time determination module 203 and a behavior determination module 204 .
[0084] A receiving module is used to receive a login request message for requesting to log in to a target account, the login request message including a target user name and a login input password, and the target user name corresponds to the target account;
[0085] A similarity calculation module is used to calculate a similarity parameter between the login password and a target pseudo-password preset for the target account when the login password is inconsistent with the account password of the target account, where the target pseudo-password is different from the account password;
[0086] A response time determination module determines the response delay time based on the similarity parameter and feeds back a login response message according to the response delay time;
[0087] The behavior determination module is used to determine whether there is a database stuffing attack behavior for logging into the target account when the changes in the similarity parameters corresponding to multiple login request messages of the target account meet the preset abnormality identification conditions.
[0088] In some embodiments, the similarity calculation module 202 can be specifically used to: determine a first similarity parameter based on the operations required to convert the login input password into the target pseudo password; determine a second similarity parameter based on the length of the matching prefix between the login input password and the target pseudo password; and perform comprehensive processing on the first similarity parameter and the second similarity parameter to obtain a similarity parameter.
[0089] In some examples, the similarity calculation module 202 can be specifically used to: obtain the minimum number of operations for converting the first i characters of the login input password into the first j characters of the target pseudo-password one by one, until the minimum number of operations for converting the login input password into the target pseudo-password is obtained, and the minimum number of operations for converting the first i characters of the login input password into the first j characters of the target pseudo-password is obtained based on the conversion between the first i-1 characters of the login input password and the first j-1 characters of the target pseudo-password, i is any digit of the characters in the login input password, and j is any digit of the characters in the target pseudo-password; the minimum number of operations for converting the login input password into the target pseudo-password is normalized to obtain a first similarity parameter.
[0090] In some examples, the similarity calculation module 202 can be specifically used to: determine the consecutive identical characters starting from the first digit of the login input password and the target pseudo-password as a matching prefix; obtain the larger of the length of the login input password and the length of the target pseudo-password, and determine the ratio of the length of the matching prefix to the larger one as a second similarity parameter.
[0091] In some embodiments, the response delay duration is positively correlated with the similarity represented by the similarity parameter.
[0092] In some embodiments, the response time determination module 203 can be specifically used to: search for the delay time corresponding to the calculated similarity parameter in a preset gradient mapping relationship, and determine the found delay time as the response delay time. The gradient mapping relationship includes a correspondence between the similarity parameter and the delay time. In the gradient mapping relationship, the similarity represented by the similarity parameter increases by a preset similarity step, and the delay time correspondingly increases by a preset time step.
[0093] In some embodiments, the abnormality identification condition includes: the similarity represented by the similarity parameter monotonically increases and gradually converges; or, the similarity represented by the similarity parameter monotonically increases until the login input password is consistent with the target pseudo password.
[0094] In some embodiments, the similarity calculation module 202 can also be used to: move the time window according to a preset time step in the login request message received in chronological order in which the login input password is inconsistent with the account password; obtain the average similarity value based on the similarity parameters corresponding to the login request message in the time window after each time window movement; determine the change in the similarity parameter based on the average similarity value obtained after multiple time window movements.
[0095] In some embodiments, the similarity parameter is positively correlated with the similarity. The credential stuffing attack behavior identification device 200 may also include a security policy module. The security policy module may be used to: if the similarity parameter is greater than a first threshold, add and execute a verification code verification process; if the similarity parameter is greater than a second threshold, control the target account to be locked for a preset lock duration; if the similarity parameter is greater than a third threshold, send an alarm notification message and lock the target account until the account administrator unlocks it; wherein the first threshold is less than the second threshold, and the second threshold is less than the third threshold.
[0096] It should be noted that the device 500 for accessing a virtual reality conference is a device corresponding to the above-mentioned method for accessing a virtual reality conference. All implementation methods in the above-mentioned method embodiments are applicable to the embodiments of the device and can achieve the same technical effects.
[0097] This application also provides a device for identifying database stuffing attack behavior. Figure 5 This is a schematic diagram of the structure of a credential stuffing attack behavior identification device provided in an embodiment of the present application, as shown in FIG. Figure 5 As shown, the credential stuffing attack behavior identification device 300 includes a memory 301, a processor 302, and a computer program stored in the memory 301 and executable on the processor 302.
[0098] In some examples, the processor 302 may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0099] The memory 301 may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical or other physical / tangible memory storage device. Therefore, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method for identifying credential stuffing attack behavior in the embodiment of the present application.
[0100] The processor 302 runs a computer program corresponding to the executable program code by reading the executable program code stored in the memory 301 , so as to implement the credential stuffing attack behavior identification method in the above embodiment.
[0101] In some examples, the credential stuffing attack behavior identification device 300 may further include a communication interface 303 and a bus 304. Figure 5 As shown, the memory 301 , the processor 302 , and the communication interface 303 are connected via a bus 304 and communicate with each other.
[0102] The communication interface 303 is mainly used to implement communication between the modules, devices, units and / or equipment in the embodiment of the present application. Input devices and / or output devices can also be connected through the communication interface 303.
[0103] The bus 304 includes hardware, software, or both, and couples the components of the database attack behavior recognition device 300 to each other. For example, and not limitation, the bus 304 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-E) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable buses or a combination of two or more of these. Where appropriate, the bus 304 may include one or more buses. Although embodiments herein describe and illustrate a particular bus, this application contemplates any suitable bus or interconnect.
[0104] The present application also provides a computer-readable storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processor, the method for identifying credential stuffing attacks described in the above embodiment can be implemented, and the same technical effects can be achieved. To avoid repetition, the above-mentioned computer-readable storage medium may include a non-transitory computer-readable storage medium, such as a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc., which is not limited here.
[0105] The present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the method for identifying credential stuffing attack behavior in the above embodiment and can achieve the same technical effect. To avoid repetition, it will not be described here.
[0106] It should be understood that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. For device embodiments, equipment embodiments, computer-readable storage medium embodiments, and computer program product embodiments, the relevant parts can be referred to the description section of the method embodiment. This application is not limited to the specific steps and structures described above and shown in the figures. Those skilled in the art can make various changes, modifications and additions, or change the order of the steps after understanding the spirit of this application. In addition, for the sake of brevity, a detailed description of known method technologies is omitted here.
[0107] Aspects of the present application have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed via the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. This processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or the flowchart and the combination of the boxes in the block diagram and / or the flowchart can also be implemented by the dedicated hardware that performs the specified function or action, or can be implemented by the combination of dedicated hardware and computer instructions.
[0108] Those skilled in the art should understand that the above embodiments are illustrative rather than restrictive. Different technical features appearing in different embodiments can be combined to achieve beneficial effects. Based on a study of the drawings, the specification and the claims, those skilled in the art should be able to understand and implement other variations of the disclosed embodiments. In the claims, the term "comprising" does not exclude other devices or steps; the quantifier "one" does not exclude a plurality; the terms "first" and "second" are used to identify names rather than to indicate any specific order. Any figure marks in the claims should not be understood as limiting the scope of protection. The functions of multiple parts appearing in the claims can be implemented by a separate hardware or software module. The fact that certain technical features appear in different dependent claims does not mean that these technical features cannot be combined to achieve beneficial effects.
Claims
1. A method for identifying credential stuffing attacks, characterized in that: include: Receive a login request message for logging into a target account, the login request message including a target user name and a login input password, the target user name corresponding to the target account; If the login password is inconsistent with the target account's password, calculating a similarity parameter between the login password and a target pseudo-password preset for the target account, the target pseudo-password being different from the target account's password; Determining a response delay duration based on the similarity parameter, and feeding back a login response message according to the response delay duration; When changes in the similarity parameters corresponding to multiple login request messages for logging into the target account meet a preset abnormality identification condition, it is determined that there is a database stuffing attack for logging into the target account.
2. The method according to claim 1, characterized in that The calculating of the similarity parameter between the login input password and the target pseudo password preset for the target account includes: determining a first similarity parameter according to an operation required to convert the login input password into the target pseudo password; determining a second similarity parameter according to the length of a matching prefix between the login input password and the target pseudo password; The first similarity parameter and the second similarity parameter are comprehensively processed to obtain the similarity parameter.
3. The method according to claim 2, characterized in that The determining of the first similarity parameter according to the operation required to convert the login input password into the target pseudo password includes: Obtaining one by one the minimum number of operations for converting the first i characters of the login input password into the first j characters of the target pseudo-password until the minimum number of operations for converting the login input password into the target pseudo-password is obtained, the minimum number of operations for converting the first i characters of the login input password into the first j characters of the target pseudo-password being obtained based on the conversion between the first i-1 characters of the login input password and the first j-1 characters of the target pseudo-password, where i is any digit of the characters in the login input password, and j is any digit of the characters in the target pseudo-password; The minimum number of operations for converting the login input password into the target pseudo password is normalized to obtain the first similarity parameter.
4. The method according to claim 2, characterized in that The determining of a second similarity parameter according to the length of a matching prefix between the login input password and the target pseudo password includes: Determine the consecutive identical characters of the login input password and the target pseudo password starting from the first digit as the matching prefix; The larger of the length of the login input password and the length of the target pseudo password is obtained, and the ratio of the length of the matching prefix to the larger one is determined as the second similarity parameter.
5. The method according to claim 1, wherein The response delay duration is positively correlated with the similarity represented by the similarity parameter.
6. The method according to claim 1, characterized in that The determining of the response delay duration based on the similarity parameter includes: The delay duration corresponding to the calculated similarity parameter is searched in a preset gradient mapping relationship, and the found delay duration is determined as the response delay duration. The gradient mapping relationship includes a correspondence between the similarity parameter and the delay duration. In the gradient mapping relationship, the similarity represented by the similarity parameter is increased by a preset similarity step, and the delay duration is correspondingly increased by a preset duration step.
7. The method according to claim 1, characterized in that The abnormality identification conditions include: The similarity represented by the similarity parameter increases monotonically and converges gradually; or, The similarity represented by the similarity parameter increases monotonically until it represents that the login input password is consistent with the target pseudo password.
8. The method according to claim 1, characterized in that Also includes: In the login request messages received in chronological order and in which the login input password is inconsistent with the account password, moving the time window according to a preset time step; Obtaining an average similarity value according to the similarity parameter corresponding to the login request message in the time window after each time window moves; The change of the similarity parameter is determined according to the average similarity value obtained after multiple time window shifts.
9. The method according to claim 1, characterized in that The similarity parameter is positively correlated with the similarity; The method further comprises: If the similarity parameter is greater than a first threshold, adding and executing a verification code verification process; If the similarity parameter is greater than a second threshold, controlling the target account to lock a preset lock duration; If the similarity parameter is greater than a third threshold, an alarm notification message is sent, and the target account is locked until the account manager unlocks it; The first threshold is smaller than the second threshold, and the second threshold is smaller than the third threshold.
10. A device for identifying credential stuffing attacks, characterized in that: include: A receiving module, configured to receive a login request message for requesting to log in to a target account, wherein the login request message includes a target user name and a login input password, and the target user name corresponds to the target account; a similarity calculation module, configured to calculate a similarity parameter between the login password and a target pseudo-password preset for the target account, if the login password is inconsistent with the account password of the target account, the target pseudo-password being different from the account password; a response time determination module, which determines a response delay time based on the similarity parameter and feeds back a login response message according to the response delay time; The behavior determination module is used to determine whether there is a database collision attack behavior for logging into the target account when the changes in the similarity parameters corresponding to multiple login request messages for logging into the target account meet the preset abnormality identification conditions.
11. A device for identifying credential stuffing attacks, characterized in that: include: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the method for identifying credential stuffing attack behavior according to any one of claims 1 to 9 is implemented.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the method for identifying credential stuffing attack behavior according to any one of claims 1 to 9.
13. A computer program product, characterized in that The method comprises a computer program, which, when executed by a processor, implements the method for identifying credential stuffing attack behavior according to any one of claims 1 to 9.
Citation Information
Patent Citations
Library hit attack determination method and device, equipment and storage medium
CN113179281A
Login method and device
CN113591071A
Dynamic protection from detected to brute force attack
US20200112585A1
Authentication device and image forming apparatus
US20210250467A1
Mobile application single sign-on method and device
WO2016173199A1