Method and system for detecting Web attack based on ClickHouse
By storing and analyzing network card traffic logs in real time in the ClickHouse database, combining regular matching and baseline model detection methods, the delay and resource consumption problems of non-real-time monitoring of web attack detection are solved, and efficient web attack detection is achieved.
Patent Information
- Application Number
- CN202510537248.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-08-22
AI Technical Summary
The existing non-real-time monitoring Web attack detection methods have problems such as long delay in detection results and high hardware resource consumption.
The ClickHouse database is used for standardized analysis and real-time storage of network card traffic logs, and the ClickHouse SQL statement is executed through the timing task program for web attack detection. Combined with regular matching and baseline model detection methods, it reduces data handling and calculation framework, and uses ClickHouse's columnar storage and high-performance regular expression engine for query analysis.
It significantly reduces the latency of detection results, reduces the consumption of hardware resources, and improves the efficiency of Web attack detection.
Smart Images

Figure CN120528630A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of Web attack detection, and in particular, relates to a method and system for detecting Web attacks based on ClickHouse. Background Art
[0002] There are two common methods for detecting web attacks: (1) Methods based on real-time monitoring, such as ModSecurity, which analyzes whether there is attack behavior by real-time unpacking and matching rules; (2) Non-real-time monitoring methods generally identify potential security threats by analyzing log files and historical data. The usual approach is to first store the data to be analyzed, such as in a distributed file storage system like ElasticSearch, Splunk, or HDFS, and then write a monitoring program to analyze abnormal information in the logs. There are various analysis methods, including rule-based matching, machine learning, and large AI models.
[0003] Non-real-time monitoring methods have become a trend. Compared to real-time detection and analysis, they can analyze data over a longer period of time, making them particularly suitable for identifying APTs and hidden insider attacks. However, non-real-time monitoring methods require data to be read from storage and then analyzed in memory, which, combined with the time it takes for the detection program to analyze data, results in significant latency. Furthermore, when log volumes are large, storage and computational overhead can be significant. Therefore, it is necessary to research non-real-time web attack detection methods that can reduce latency and resource usage.
[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of this disclosure. Summary of the Invention
[0005] In order to overcome the shortcomings and deficiencies of the prior art, the purpose of the present invention is to provide a method and system for detecting Web attacks based on ClickHouse, so as to improve the efficiency of Web attack detection and significantly reduce the consumption of hardware resources while reducing the delay in returning detection results.
[0006] The purpose of the present invention is achieved through the following technical solutions: According to one aspect of the present invention, a method for detecting Web attacks based on ClickHouse is provided, the method comprising: S1. Standardize and parse the network card traffic log and store the parsed data in the ClickHouse database in real time. S2. Write a scheduled task program connected to the ClickHouse database, regularly read data from ClickHouse and execute ClickHouse SQL statements to detect web attacks.
[0007] Based on the above solution, S1 specifically includes: S11. Standardize and parse network card traffic, Nginx logs, and API gateway logs into various field types. S12: Send the parsed data to the Kafka message queue, monitor the Kafka data stream through Flink, and perform field matching and parsing. S13. Logs of different types are stored in different tables of the ClickHouse database.
[0008] Based on the above solution, the field types include request source IP, request method, request body content, UserAgent, time, domain name, and URL.
[0009] Based on the above solution, S2 specifically includes: S21. Write different ClickHouse SQL statements for different attack types. S22. Use Python or Flink to write a scheduled task program that connects to the ClickHouse database; S23. The task program periodically reads data from ClickHouse and executes ClickHouse SQL statements to detect Web attacks.
[0010] Based on the above solution, the attack detection adopts a detection method based on regular expression matching and a detection method based on baseline model. The two detection methods are used simultaneously to deal with different types of attacks.
[0011] Based on the above solution, the method further includes: S3. Analyze the results returned after executing ClickHouse SQL statements and apply them to attack blocking and alarm by calling API interfaces.
[0012] Based on the above scheme, the attack blocking includes: when the analysis result is a suspicious attack IP, further judging the IP attribute, if it is an intranet IP or a whitelist IP, it will not be blocked, otherwise the attack IP will be blocked.
[0013] Based on the above solution, the alarm includes: when the analysis result is a suspicious attack IP, an alarm email is sent to the security operation department to remind that a suspicious attack is occurring, and the alarm details are sent to the security event management platform for front-end display.
[0014] According to another aspect of the present invention, a system for detecting Web attacks based on ClickHouse is provided, which is applicable to the above-mentioned method for detecting Web attacks based on ClickHouse. The system includes: The log collection module is used to perform standardized analysis on network card traffic logs and store the parsed data in the ClickHouse database in real time; The attack detection module is used to write a scheduled task program connected to the ClickHouse database, regularly read data from ClickHouse and execute ClickHouse SQL statements for Web attack detection.
[0015] Furthermore, the system further comprises: The attack blocking and alarm module is used to analyze the results returned after executing ClickHouse SQL statements and apply them to attack blocking and alarm by calling API interfaces.
[0016] The present invention has the following advantages and effects compared to the prior art: (1) The present invention's method for detecting web attacks based on ClickHouse directly uses ClickHouse's SQL engine for query analysis after storing data in ClickHouse. ClickHouse uses columnar storage, storing data by column rather than by row. This means it only needs to scan relevant columns (such as message columns) rather than the entire data set, thereby reducing I / O and memory usage and speeding up data retrieval. Compared with existing non-real-time detection methods, the present invention does not require additional data handling and complex computing frameworks, and can significantly reduce the delay in returning detection results.
[0017] (2) ClickHouse's multiMatchAny function uses the Vectorscan library, a high-performance regular expression engine particularly well-suited for handling multiple pattern matches. Vectorscan compiles multiple regular expressions into an efficient state machine, reducing computational overhead. Baseline model-based analysis often involves subqueries, grouping, and counting, which are typical analytical queries, and this is precisely ClickHouse's strength. Therefore, the web attack detection method of the present invention is highly efficient.
[0018] (3) Python's Pandas library requires all data to be loaded into memory. For large data scenarios such as log analysis (e.g., millions or billions of records), performance may degrade due to insufficient memory. In addition, Pandas operations (such as grouping and counting) require row-by-row processing, which is less efficient than ClickHouse's batch processing. In contrast, ClickHouse can execute queries directly in the database without loading data into memory, reducing memory processing steps and further reducing query latency. Moreover, ClickHouse's compression technology and storage optimization can significantly reduce hardware resource consumption under the same log data volume, making up for the low efficiency and high resource investment of non-real-time monitoring methods.
[0019] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort. In the drawings: Figure 1 This is a schematic diagram of the steps of the method for detecting Web attacks based on ClickHouse in Example 1.
[0021] Figure 2 This is a schematic diagram of the specific steps of step S1 of the method for detecting Web attacks based on ClickHouse in Example 1.
[0022] Figure 3 This is a schematic diagram of the specific steps of step S2 of the method for detecting Web attacks based on ClickHouse in Example 1.
[0023] Figure 4 This is a schematic diagram of the steps of the method for detecting Web attacks based on ClickHouse in Example 3.
[0024] Figure 5 This is a schematic diagram of the relationship between system modules for detecting Web attacks based on ClickHouse in Example 5. DETAILED DESCRIPTION
[0025] The embodiments of the present invention will be clearly and completely described below with reference to the examples. The examples described are only some of the embodiments of the present invention, rather than all of them. The following description of at least one exemplary embodiment is actually only illustrative and is in no way intended to limit the present invention and its application or use. All other embodiments obtained by ordinary technicians in this field based on the examples in the present invention without making any creative work are within the scope of protection of the present invention.
[0026] The flowcharts shown in the accompanying drawings are for illustrative purposes only and do not necessarily include all contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may be decomposed, while others may be combined or partially combined. Therefore, the actual execution order may vary depending on the actual situation.
[0027] Example 1 This embodiment provides a method for detecting Web attacks based on ClickHouse, the method comprising the following steps: S1. Standardize and parse the network card traffic logs and store the parsed data in the ClickHouse database in real time.
[0028] In this embodiment, step S1 specifically includes: S11. Standardize and parse network card traffic, Nginx logs, and API gateway logs into various field types; field types include request source IP, request method, request body content, UserAgent, time, domain name, and URL; S12: Send the parsed data to the Kafka message queue, monitor the Kafka data stream through Flink, and perform field matching and parsing. S13. Logs of different types are stored in different tables of the ClickHouse database.
[0029] S2. Write a scheduled task program connected to the ClickHouse database, regularly read data from ClickHouse and execute ClickHouse SQL statements to detect web attacks.
[0030] In this embodiment, step S2 specifically includes: S21. Write different ClickHouse SQL statements for different attack types. S22. Use Flink to write a scheduled task program that connects to the ClickHouse database; S23. The task program periodically reads data from ClickHouse and executes ClickHouse SQL statements to detect Web attacks.
[0031] Attack detection uses both regular expression matching and baseline model-based detection methods, and these two methods are used simultaneously to address different types of attacks. 1. Regular expression matching detection: Web attacks with obvious attack signatures, such as SQL injection attacks, XSS attacks, and JAVA deserialization vulnerability exploitation attacks, can be accurately matched using regular expressions. For example, the following SQL injection attack contains keywords such as select, from, and sleep: "id=1'+AND+(SELECT+9687+FROM+(SELECT(SLEEP(6)))pnac)+AND+'ARHJ'='ARHJ".
[0032] 2. Baseline model-based detection: For example, directory traversal typically uses different URIs to detect the same subdomain, and the response code returned is used to determine whether the page exists. Alternatively, a possible web attack can be determined by the number of visits to a website subdomain by an IP address exceeding a threshold within a unit time.
[0033] This embodiment uses SQL injection attacks as an example to illustrate how to implement Web attack detection based on a regular expression matching detection method.
[0034] The following is a ClickHouse SQL query to detect SQL injection attacks: “SELECT source_ip_distinct, arrayElement(groupArray(Req_ID), 1) AS Req_ID, arrayElement(groupArray(Req_URL), 1) AS Req_URL, arrayElement(groupArray(Req_Method), 1) AS Req_Method, arrayElement(groupArray(Req_Body), 1) AS Req_Body, arrayElement(groupArray(User_Agent), 1) AS User_Agent, arrayElement(groupArray(Host), 1) AS Host, arrayElement(groupArray(logtime), 1) AS logtime, arrayElement(groupArray(timestamp), 1) AS timestamp, arrayElement(groupArray(reg_match_result), 1) AS reg_match_result, arrayElement(groupArray(rule_name), 1) AS rule_name FROM ( select DISTINCT X_Real_Ip as source_ip_distinct,Req_ID, Req_URL, Req_Method, Req_Body, User_Agent, Host, logtime, timestamp,reg_match_result,rule_name from ( select Req_ID, Req_URL, Req_Method, Req_Body, User_Agent, Host, X_Real_Ip, logtime, timestamp, multiMatchAny( Req_Body, '(?i:sleep\(\s*?\d*?\s*?\)|benchmark\(.*?\,.*?\))', '(?i)union.*?select.*?from', 'base64_decode', '(?:from\W+information_schema\W)' ) as reg_match_result, 'SQL injection' as rule_name from table1 where timestamp >= (toInt32(now()) - 10) AND reg_match_result = 1 ) ) GROUP BY source_ip_distinct” The specific analysis and matching steps are as follows, which are carried out in three stages: 1) Raw data filtering stage: Retrieve the data of the last 10 seconds from table1 and use the ClickHouse regular set matching function multiMatchAny(Req_Body, [...]). There are 4 rules written here. If any rule is matched, the result of reg_match_result will be 1. The request information that hits the rule set is extracted, and the name of this type of attack rule is marked as 'SQL injection' and returned as the rule_name field.
[0035] 2) Result deduplication stage: Select all fields from the filtered results and use DISTINCT to remove possible duplicate records; rename X_Real_Ip to source_ip_distinct to ensure subsequent grouping by source IP address.
[0036] 3) Grouping and selection phase: Group the records for each IP address into a group based on the source IP address. Use groupArray to collect all the values of the group for each field to form an array. Use arrayElement(groupArray(column), 1) to select the first value in each array, which is equivalent to selecting a representative record for each IP address.
[0037] Through these three stages, we can ensure that every attack source IP address in a SQL injection attack is extracted, and only one record is included, thus extracting valid information while reducing the output of redundant data. ClickHouse's multiMatchAny function uses the Vectorscan library, a high-performance regular expression engine that is particularly suitable for handling multiple pattern matches. Vectorscan compiles multiple regular expressions into an efficient state machine, reducing computational overhead.
[0038] The present invention's method for detecting web attacks based on ClickHouse directly uses ClickHouse's SQL engine for query analysis after storing data in ClickHouse. ClickHouse uses columnar storage, storing data by column rather than by row. This means it only needs to scan relevant columns (such as message columns) rather than the entire data set, thereby reducing I / O and memory usage and speeding up data retrieval. Compared with existing non-real-time detection methods, the present invention does not require additional data handling and complex computing frameworks, and can significantly reduce the delay in returning detection results.
[0039] Example 2 This embodiment provides a method for detecting Web attacks based on ClickHouse, the method comprising the following steps: S1. Standardize and parse the network card traffic logs and store the parsed data in the ClickHouse database in real time.
[0040] In this embodiment, step S1 specifically includes: S11. Standardize and parse network card traffic, Nginx logs, and API gateway logs into various field types; field types include request source IP, request method, request body content, UserAgent, time, domain name, and URL; S12: Send the parsed data to the Kafka message queue, monitor the Kafka data stream through Flink, and perform field matching and parsing. S13. Logs of different types are stored in different tables of the ClickHouse database.
[0041] S2. Write a scheduled task program connected to the ClickHouse database, regularly read data from ClickHouse and execute ClickHouse SQL statements to detect web attacks.
[0042] In this embodiment, step S2 specifically includes: S21. Write different ClickHouse SQL statements for different attack types. S22. Use Python to write a scheduled task program that connects to the ClickHouse database; S23. The task program periodically reads data from ClickHouse and executes ClickHouse SQL statements to detect Web attacks.
[0043] Attack detection adopts a detection method based on regular matching and a detection method based on baseline model. The two detection methods are used simultaneously to deal with different types of attacks.
[0044] The most common detection method based on the baseline model is directory traversal attacks. Directory traversal attacks are characterized by attackers frequently probing the URIs of a domain name, sending various URIs, such as requests for / login.php and / index.php, and sending a large number of request packets in a short period of time. This example uses directory traversal attacks as an example to illustrate how to implement web attack detection based on the baseline model.
[0045] The following is a ClickHouse SQL query to detect directory traversal attacks and SQL injection attacks: “SELECT source_ip as source_ip_distinct, nginxlogtime, request, http_user_agent, upstream_addr, source, beat_ipaddr, uuid, status, 'Directory traversal' AS rule_name from nginx_log_data where source_ip in ( select source_ip from nginx_log_data where timestamp (toInt32(now()) - 60) group by source_ip having count(distinct request) > 20 ) limit 1” The specific analysis and matching steps are as follows, which are carried out in three stages: 1) Raw data filtering stage: Filter the data of the last 60 seconds from the nginx_log_data table for analysis.
[0046] 2) Grouping and statistics stage: Group by source_ip (source IP), count the number of different request contents exceeding 20, and query the source IP.
[0047] 3) Grouping and selection phase: Query nginx_log_data, select data related to the source IP address, and extract the first data item for output.
[0048] In the baseline model-based analysis, subqueries, grouping, and counting are often involved, which are typical analytical queries, and this is exactly the strength of ClickHouse. Therefore, the web attack detection efficiency of the present invention is high.
[0049] Example 3 This embodiment provides a method for detecting Web attacks based on ClickHouse, the method comprising the following steps: S1. Standardize and parse the network card traffic logs and store the parsed data in the ClickHouse database in real time.
[0050] In this embodiment, step S1 specifically includes: S11. Standardize and parse network card traffic, Nginx logs, and API gateway logs into various field types; field types include request source IP, request method, request body content, UserAgent, time, domain name, and URL; S12: Send the parsed data to the Kafka message queue, monitor the Kafka data stream through Flink, and perform field matching and parsing. S13. Logs of different types are stored in different tables of the ClickHouse database.
[0051] S2. Write a scheduled task program connected to the ClickHouse database, regularly read data from ClickHouse and execute ClickHouse SQL statements to detect web attacks.
[0052] In this embodiment, step S2 specifically includes: S21. Write different ClickHouse SQL statements for different attack types. S22. Use Python or Flink to write a scheduled task program that connects to the ClickHouse database; S23. The task program periodically reads data from ClickHouse and executes ClickHouse SQL statements to detect Web attacks.
[0053] S3. Analyze the results returned after executing ClickHouse SQL statements and apply them to attack blocking and alarm by calling API interfaces.
[0054] When the analysis result indicates a suspicious attack IP address, attack blocking and alarming are performed in the following steps: Step 1: Block the attacking IP. After receiving a suspicious attacking IP, further judgment is made. If it is an intranet IP, it will not be blocked. If it is a whitelist IP (such as CDN), it will not be blocked. Finally, the attacking IP that needs to be blocked is submitted to the Nginx gateway blocking list or submitted to the firewall to achieve attack blocking; Step 2: Regardless of the situation, an alert email will be sent to the security operations staff to alert them of the suspected attack. Step 3: Regardless of the situation, the alarm details will be sent to the security event management platform, and the detailed information of various events can be displayed on the front end of the platform, such as a web page.
[0055] Example 4 This embodiment provides a system for detecting web attacks based on ClickHouse, including the following modules: The log collection module is used to perform standardized analysis on network card traffic logs and store the parsed data in the ClickHouse database in real time.
[0056] The log collection module parses network card traffic, Nginx logs, and API gateway logs into standardized fields, including request source IP, request method, request body, UserAgent, time, domain name, and URL. The parsed data is then sent to the Kafka message queue. Flink monitors the Kafka data stream and performs field matching and parsing. Logs are then stored in different tables in the ClickHouse database based on the log type.
[0057] The attack detection module is used to write a scheduled task program connected to the ClickHouse database, regularly read data from ClickHouse and execute ClickHouse SQL statements for Web attack detection.
[0058] The attack detection module writes different ClickHouse SQL statements for different attack types; Then use Python or Flink to write a scheduled task program connected to the ClickHouse database; the task program regularly reads data from ClickHouse and executes ClickHouse SQL statements to detect web attacks.
[0059] Furthermore, the system further comprises: The attack blocking and alerting module is used to analyze the results returned after executing ClickHouse SQL statements and apply them to attack blocking and alerting by calling API interfaces. Among them, attack blocking includes: when the analysis result is a suspicious attack IP, further judging the IP attributes. If it is an intranet IP or a whitelist IP, it will not be blocked; otherwise, the attack IP will be blocked. Alerts include: when the analysis result is a suspicious attack IP, an alert email is sent to the security operations department to remind them that a suspicious attack is occurring, and the alert details are sent to the security event management platform for front-end display.
[0060] In this embodiment, the log collection module collects and processes data and stores it in a database, providing an analysis data source for the attack detection module, interacting via the SQL protocol. The attack detection module then calls the attack blocking and alerting modules via a RESTful API. This system can efficiently analyze massive amounts of log data and detect attacks, while significantly reducing storage and computing resource requirements, thus addressing the inefficiency and resource-intensive nature of non-real-time monitoring systems.
[0061] Example 5 This embodiment provides the performance test results of the method for detecting Web attacks based on ClickHouse in Example 1 of the present invention.
[0062] Obtain 10,000 identical data items to be tested, mixed with 100 SQL injection attack statements. Execute 10 regular SQL injection detection rule sets simultaneously according to the three schemes in Table 1, test the return time, and compare the results.
[0063] Table 1. Three detection schemes and their corresponding detection performance
[0064] From the comparison of the three solutions in Table 1, it can be seen that the solution of the present invention using the ClickHouse SQL engine returns the fastest results and has the highest attack detection performance in the same analysis scenario with the least resource investment.
[0065] From the perspective of storage cost comparison, assuming that 1TB of original data is to be retained, the hardware storage space configuration comparison of the above three solutions is shown in Table 2: Table 2. Three detection schemes and their corresponding storage costs
[0066] From the comparison of the three solutions in Table 2, it can be seen that for the Web attack detection scenario, under the same original data, the storage cost of the solution using the ClickHouse SQL engine of the present invention is much lower than that of the traditional solution.
[0067] In summary, the method for detecting web attacks based on ClickHouse of the present invention directly uses ClickHouse's SQL engine for query analysis after storing data in ClickHouse. ClickHouse uses columnar storage, and data is stored by column rather than by row, which means that it only needs to scan relevant columns (such as message columns) rather than the entire data set, thereby reducing I / O and memory usage and speeding up data retrieval. Compared with existing non-real-time detection methods, the present invention does not require additional data handling and complex computing frameworks, and can significantly reduce the delay in returning detection results.
[0068] ClickHouse's multiMatchAny function uses the Vectorscan library, a high-performance regular expression engine particularly well-suited for handling multiple pattern matches. Vectorscan compiles multiple regular expressions into an efficient state machine, reducing computational overhead. Baseline model-based analysis often involves subqueries, grouping, and counting, typical analytical queries—the very strengths of ClickHouse. Therefore, the present invention achieves high efficiency in web attack detection.
[0069] Python's Pandas library requires all data to be loaded into memory. For big data scenarios like log analysis (e.g., millions or billions of records), performance may degrade due to insufficient memory. In addition, Pandas operations (such as grouping and counting) require row-by-row processing, which is less efficient than ClickHouse's batch processing. In contrast, ClickHouse can execute queries directly in the database without loading data into memory, reducing memory processing steps and further reducing query latency. Furthermore, ClickHouse's compression technology and storage optimization can significantly reduce hardware resource consumption for the same amount of log data, making up for the low efficiency and high resource investment of non-real-time monitoring methods.
[0070] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow from the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.
[0071] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A method for detecting Web attacks based on ClickHouse, characterized in that: The method comprises: S1. Standardize and parse the network card traffic log and store the parsed data in the ClickHouse database in real time. S2. Write a scheduled task program connected to the ClickHouse database, regularly read data from ClickHouse and execute ClickHouse SQL statements to detect web attacks.
2. The method for detecting Web attacks based on ClickHouse according to claim 1, characterized in that: Said S1 specifically includes: S11. Standardize and parse network card traffic, Nginx logs, and API gateway logs into various field types; S12. Send the parsed data to the Kafka message queue, monitor the Kafka data stream through Flink, and perform field matching and parsing. S13. Logs of different types are stored in different tables of the ClickHouse database.
3. The method for detecting Web attacks based on ClickHouse according to claim 2, characterized in that: The field types include request source IP, request method, request body content, UserAgent, time, domain name, and URL.
4. The method for detecting Web attacks based on ClickHouse according to claim 1, characterized in that: The S2 specifically includes: S21. Write different ClickHouse SQL statements for different attack types. S22. Use Python or Flink to write a scheduled task program that connects to the ClickHouse database; S23. The task program periodically reads data from ClickHouse and executes ClickHouse SQL statements to detect Web attacks.
5. The method for detecting Web attacks based on ClickHouse according to claim 1, characterized in that: The attack detection adopts a detection method based on regular matching and a detection method based on a baseline model.
6. The method for detecting Web attacks based on ClickHouse according to claim 1, characterized in that: The method further comprises: S3. Analyze the results returned after executing ClickHouse SQL statements and apply them to attack blocking and alarm by calling API interfaces.
7. The method for detecting Web attacks based on ClickHouse according to claim 6, characterized in that: The attack blocking includes: when the analysis result is a suspicious attack IP, further judging the IP attribute, if it is an intranet IP or a whitelist IP, it will not be blocked, otherwise the attack IP will be blocked.
8. The method for detecting Web attacks based on ClickHouse according to claim 6, characterized in that: The alarm includes: when the analysis result is a suspicious attack IP, an alarm email is sent to the security operation department to remind that a suspicious attack is occurring, and the alarm details are sent to the security event management platform for front-end display.
9. A system for detecting Web attacks based on ClickHouse, applicable to the method for detecting Web attacks based on ClickHouse according to any one of claims 1 to 8, characterized in that: The system comprises: The log collection module is used to perform standardized analysis on network card traffic logs and store the parsed data in the ClickHouse database in real time; The attack detection module is used to write a scheduled task program connected to the ClickHouse database, regularly read data from ClickHouse and execute ClickHouse SQL statements for Web attack detection.
10. The system for detecting Web attacks based on ClickHouse according to claim 9, characterized in that: The system further comprises: The attack blocking and alarm module is used to analyze the results returned after executing ClickHouse SQL statements and apply them to attack blocking and alarm by calling API interfaces.
Citation Information
Patent Citations
Click-home-based gambling website detection method
CN113285957A
Security detection method and system, electronic equipment and storage medium
CN118972149A