Website operation method and device for suppressing zero-day attack, computer equipment and storage medium
Through multi-version deployment architecture and automated processing, the zero-day vulnerability attack problem of WordPress websites is solved, rapid recovery and stability during attacks are achieved, and the security of the website and user experience are ensured.
Patent Information
- Application Number
- CN202511142952.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-08-15
AI Technical Summary
Existing technologies are unable to effectively defend against zero-day vulnerability attacks, especially APT attacks against WordPress websites, which can lead to significant losses such as content tampering.
A multi-version deployment architecture is adopted, including internal version, intermediate version and public version. Data is synchronized between the internal version and the intermediate version through automated devices, and production environment adaptation processing is performed, including database optimization, domain name search and replacement, and security reinforcement. Finally, the data of the intermediate version is synchronized to two public versions that are not used by users at the same time, realizing the transformation from a dynamic writable system to a static read-only system.
The attack surface of the public version is greatly reduced, and it has strong rapid recovery capabilities, which can quickly recover when attacked. It can contain zero-day attacks, prevent write-type attacks, and ensure the stability of the website and user experience.
Smart Images

Figure CN120729620A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a website operation method, apparatus, computer equipment, and storage medium for curbing zero-day attacks. Background Art
[0002] WordPress is a content management system based on the PHP (Hypertext Preprocessor) language and the MySQL database. Its open source nature and rich plug-in ecosystem have attracted a large number of developers, but this has also led to uneven quality of third-party plug-in code and frequent security vulnerabilities.
[0003] The main security protection measures currently used by WordPress include: (1) "post-event remediation" for publicly disclosed vulnerabilities (such as 1-day vulnerabilities and n-day vulnerabilities), such as collecting, analyzing, and reporting publicly disclosed vulnerabilities, and then patching newly disclosed vulnerabilities; (2) using some intrusion prevention systems (IPS) for defense, such as Web Application Firewall (WAF). These intrusion prevention systems can use powerful threat intelligence, rule systems, or AI-enabled detection models to detect and intercept malicious traffic in real time.
[0004] However, these methods still have some shortcomings. Method (1) can effectively defend against attacks from later attackers, but if the attacker exploits the "protection vacuum" between vulnerability disclosure and patch release to launch an attack, this method will not be effective. In addition, this method is difficult to defend against APT (Advanced Persistent Threat) attacks. Some targeted APT organizations will specifically study the corresponding version of the target WordPress and third-party plug-ins to discover undisclosed zero-day vulnerabilities. Using zero-day vulnerabilities to launch attacks can circumvent existing detection methods and pose a persistent threat. Method (2) relies on threat intelligence, rules or AI models, and its defense effect is limited when facing carefully designed customized APT attacks. Once bypassed, the attacker may cause significant losses such as content tampering. The consequences are difficult to estimate, especially for large commercial websites that rely on WordPress. Summary of the Invention
[0005] In response to the above-mentioned deficiencies or shortcomings, the present application provides a website operation method, apparatus, computer equipment, and storage medium for curbing zero-day attacks. The embodiments of the present application can curb zero-day attacks against WordPress (i.e., attacks based on zero-day vulnerabilities) and minimize losses when security protection measures fail.
[0006] According to a first aspect, the present application provides a website operation method for curbing zero-day attacks. In some embodiments, a website content management system has multiple versions, including an internal version and an intermediate version deployed on an intranet server, and two public versions deployed on a public network server for users to use at different times. The internal version is used by website operators to edit and publish website content, and the public version is used by users to browse website content. The method includes: After the operator releases new website content, synchronize the internal version of the website data to the intermediate version; Performing production environment adaptation processing on the website data synchronized to the intermediate version. Production environment adaptation processing includes one or more of database optimization processing, domain name search and replacement processing, and security reinforcement processing; Synchronize the intermediate version of the website data that has completed the production environment adaptation process to the public version that is not currently available to users, and update the user access entrance to make the public version available to users.
[0007] In some embodiments, before synchronizing the internal version of the website data to the intermediate version, the method further includes: detecting whether the new website content meets the expected effect; if it meets the expected effect, determining to execute the step of synchronizing the internal version of the website data to the intermediate version.
[0008] In some embodiments, before updating the user access portal, the method further includes: detecting whether the new website content meets the expected effect; if it meets the expected effect, determining to execute the step of updating the user access portal.
[0009] In some embodiments, the database optimization process includes deleting revision files and junk files; the security hardening process includes deleting wp-login.php, disabling access to the wp-admin folder through htaccess, disabling xmlrpc and wp-json, disabling wp-cron.php, deleting temporary cache data of wordpress, and restricting one or more of php functions.
[0010] In some embodiments, synchronizing the intermediate version of the website data that has completed the production environment adaptation processing to the public version that is not currently in use by users includes: synchronizing the intermediate version of the website data that has completed the production environment adaptation processing to a temporary folder of the public network server; after determining the public version that is not currently in use by users, synchronizing the website data in the temporary folder to the public version that is not currently in use by users.
[0011] In some embodiments, each of the internal version, intermediate version and public version includes a database and a file system; the website data synchronized from the internal version to the intermediate version and the website data synchronized from the intermediate version to the public version both include database data and file system data; when synchronizing database data, a full synchronization method is adopted; when synchronizing file system data, an incremental synchronization method is adopted.
[0012] In some embodiments, the public version of the file system is deployed on a public network server in a read-only deployment mode, and the public version of the database controls user access to the public version of the website data through a combination of read-only accounts and triggers.
[0013] According to a second aspect, the present application provides a website operation device for curbing zero-day attacks. In some embodiments, a website content management system has multiple versions, including an internal version and an intermediate version deployed on an intranet server, and two public versions deployed on a public network server for users to use at different times. The internal version is used by website operators to edit and publish website content, and the public version is used by users to browse website content. The device includes: The first synchronization module is used to synchronize the internal version of the website data to the intermediate version after the operator releases new website content; A production environment adaptation processing module is used to perform production environment adaptation processing on the website data synchronized to the intermediate version. The production environment adaptation processing includes one or more of database optimization processing, domain name search and replacement processing, and security reinforcement processing; The second synchronization module is used to synchronize the intermediate version of the website data that has completed the production environment adaptation process to the public version that is not currently available to users, and to update the user access entrance so that the public version can be used by users.
[0014] According to a third aspect, the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the website operation method for curbing zero-day attacks provided in any of the above embodiments are implemented.
[0015] According to a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the website operation method for curbing zero-day attacks provided in any of the above embodiments are implemented.
[0016] In the above embodiment of the present application, multiple versions are set for the content management system of the website, which include internal versions, intermediate versions and public versions. The deployment method of the three major versions of the internal version, intermediate version and public version is: the internal version and intermediate version are deployed on the intranet server, while the public version is deployed on the public network server. The website operator can edit and publish the website content in the internal version. After the operator publishes the new website content, the website data of the internal version is synchronized to the intermediate version through the automation device. After the website data of the internal version is synchronized to the intermediate version, the automation device will perform production environment adaptation processing on the website data in the intermediate version to meet specified requirements such as website performance and data security. There are two public versions, and these two public versions are not used by users at the same time. Based on this, after the website data of the intermediate version is adapted to the production environment, the website data of the intermediate version is first synchronized to the public version that is not currently used by users, and then the public version is made available to users by updating the user access portal. The embodiments of the present application can convert a dynamically writable content management system into a static, read-only public service, greatly reducing the attack surface exposed by WordPress (i.e., the public version) used in an online production environment, and blocking write-type attacks at the source; moreover, even if the public version is attacked, it can be quickly restored through the update process of internal version → intermediate version → public version, thereby achieving the goal of containing zero-day attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 A schematic diagram illustrating deployment of multiple versions of a website content management system and synchronization of website data of each version according to one or more embodiments of the present application; Figure 2 A flowchart of a website operation method for curbing zero-day attacks provided by the present application according to one or more embodiments; Figure 3 This is a structural block diagram of a website operation device for curbing zero-day attacks provided by the present application according to one or more embodiments; Figure 4 This is a diagram of the internal structure of a computer device provided in accordance with one or more embodiments of the present application. DETAILED DESCRIPTION
[0018] To make the purpose, technical solutions, and advantages of this application more clear, the embodiments of this application will be further described in detail below with reference to the accompanying drawings. It should be understood that the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0019] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are merely examples of devices and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0020] In the description of this application, it should be understood that the terms "first", "second", "third", etc. are only used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence, nor can they be understood as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to the specific circumstances. In addition, in the description of this application, unless otherwise specified, "multiple" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship.
[0021] To address the shortcomings or deficiencies of related technologies, this application provides a website operation method for curbing zero-day attacks. This method can curb zero-day attacks against WordPress (i.e., attacks based on zero-day vulnerabilities) and minimize losses when security measures fail. This method is described in detail below through several examples.
[0022] In some embodiments, a website's content management system (CMS) is a software platform or application that greatly simplifies the process of creating and maintaining a website by separating content from design and providing an intuitive user interface. It allows users to create, edit, organize, publish, and manage website content, enabling users to effectively manage and publish website content without requiring specialized programming knowledge. The CMS may be WordPress.
[0023] This application sets up multiple versions for the website's content management system, including internal versions, intermediate versions, and public versions. Figure 1As shown in the figure, the three major versions—internal, middle, and public—are deployed as follows: internal and middle versions are deployed on intranet servers, while public versions are deployed on public servers. An intranet server is a server deployed within an enterprise or organization's internal network, typically in its internal data center, isolated from the external network by firewalls and routers. Administrators configure access control lists to restrict access to the intranet server to internal users only. Internal users can connect to the intranet server through an internal network (such as a virtual private network or a company intranet). Access typically requires authentication (such as a username and password) to ensure security. A public server is a server deployed on the internet (such as the Internet) and can be accessed by users anywhere in the world.
[0024] Each of the three versions, internal version, intermediate version and public version, has a corresponding database and file system. The database and file system of the internal version are Figure 1 mysql_internal, wordpress_internal; the database and file system of the intermediate version are Figure 1 There are two public versions, namely the first public version and the second public version. The database and file system of the first public version are Figure 1 The database and file system of the second public version are mysql_public_1 and wordpress_ public_1 respectively. Figure 1 mysql_public_2 and wordpress_ public_2 in.
[0025] The internal version is the "master copy" of the intermediate version and the public version. It is for direct use by website operators. Website operators can edit and publish website content in the internal version. They have read and write permissions for the internal version database. The internal version is not open to users (mainly people who use the website). Users cannot access the internal version and cannot browse the website content in the internal version.
[0026] The website data in the intermediate version is synchronized from the internal version, but the website data in the internal and intermediate versions is not exactly the same. After the website data from the internal version is synchronized to the intermediate version, automated devices will perform a series of processing on the intermediate version (the relevant processing will be explained in detail below) to meet specific requirements such as website performance and data security. The intermediate version is "transparent" to website operators, and users cannot access the intermediate version and browse the website content therein.
[0027] The public version is accessible to users, allowing them to browse the website's content. Users have read access to the public version's database, but not write access. The website data in the public version is synchronized from the intermediate version. Having two public versions allows for seamless switching, preventing users from noticing updates during actual use and improving the user experience.
[0028] The website operation method for curbing zero-day attacks provided in this embodiment adopts Figure 1 The website deployment method shown in FIG. 1 includes the following steps: Figure 2 As shown below, we will combine Figure 1 Each step is explained in detail.
[0029] S110: After the operator releases new website content, the internal version of the website data is synchronized to the intermediate version.
[0030] Website content refers to the information that users can directly view and interact with in a browser, such as articles. Website content typically consists of text, images, video, audio, layout, style, and more. Website data refers to the underlying information that drives website functionality, stores key information, and defines the website's structure and configuration. This data can be stored in a database (specifically, a MySQL database) or file system.
[0031] Operations personnel can edit new website content in the internal version and publish it after editing. For example, they can modify an old article or write a new one. Both the modified and new articles are considered new website content. After the operation personnel publish the new website content, they can use automated devices to synchronize the internal version of the website data with the intermediate version.
[0032] S120: Perform production environment adaptation processing on the website data synchronized to the intermediate version.
[0033] After the internal version of the website data is synchronized with the intermediate version, the automated system will adapt the intermediate version of the website data to the production environment to meet specific requirements such as website performance and data security. The production environment adaptation process includes one or more of the following: database optimization, domain name search and replacement, and security hardening.
[0034] Database optimization refers to the process of adjusting and maintaining one or more of the database's structure, configuration, and content. The goal is to improve database performance (query speed, response time), reduce resource consumption (storage space, memory, CPU), enhance data integrity, and lay a good foundation for future expansion.
[0035] Database optimization may include, but is not limited to, deleting revision files, deleting junk files, and cleaning up unused metadata or transient data.
[0036] When the content management system is WordPress, deleting revision files can include deleting revision articles. Revision articles are historical versions of articles, which are saved by WordPress through the revision function. If revision articles are not deleted, their number will increase, which will significantly increase the size of the database, thereby slowing down the query speed. Deleting revision articles can help improve the query speed. Deleting junk files can include deleting trash files. Trash files are similar to recycle bins. Data such as posts, pages, and media files deleted by users are not actually deleted by WordPress, but are moved to trash files. These will occupy database space for a long time. Deleting trash files can empty the recycle bin, which can immediately free up the storage space occupied by these data. Cleaning up unused metadata or transient data can include deleting expired or no longer used options, temporary cached data, and orphaned metadata records in data tables such as wp_options, wp_postmeta, and wp_usermeta.
[0037] wp_options is a data table used to store global settings and options for a website. These settings or options can be various parameters configured by operators through the WordPress backend settings interface, or they can be specific settings added by themes and plugins. The data stored in wp_options includes basic site information (such as the site title, site description, WordPress address and site address), user-configured settings (such as the number of articles displayed per page, date and time format, default time zone setting, etc.), theme and plugin settings (such as the theme's color scheme and layout options), and system-related options (such as whether to enable article comments and whether to allow new user registration).
[0038] wp_postmeta is a table used to store metadata related to posts. Operators can use wp_postmeta to add custom fields to posts, beyond basic fields like title, content, and publication date. Data stored in wp_postmeta includes custom post fields (for example, when writing a product introduction, you can add custom fields like price, weight, and dimensions) and featured image information (such as image IDs and other related data).
[0039] wp_usermeta is a table used to store user metadata. The data stored in wp_usermeta includes user settings (such as nickname display, user description, and user language preference in the WordPress backend).
[0040] By performing database optimization on intermediate versions of your website data, you can improve database performance, which in turn improves website performance.
[0041] Regarding domain name search and replace, you may need to change the website's domain name during website operation, such as changing the current domain name "old-example.com" to "new-example.com." Since all URLs in WordPress articles (such as image attachments) are hard-coded URLs (Uniform Resource Locator) and do not change with settings, a global search and replace is required to replace the old domain name in the articles with the new one. Specifically, this process involves traversing all content in the intermediate version of the database and replacing text strings associated with the old domain name with those associated with the new domain name. By performing a domain name search and replace on the intermediate version of the website data, you can ensure that links in the website content are correct and resources are available.
[0042] Security hardening involves proactively improving system or application security by modifying configurations, restricting access, removing unnecessary features, and / or updating software. This reduces the risk and potential attack surface of attacks (such as unauthorized access, data leakage, malware injection, and denial of service). By performing security hardening on intermediate versions of website data, website security can be improved (e.g., reducing risk and increasing resilience).
[0043] Security hardening includes, but is not limited to, deleting wp-login.php, disabling access to the wp-admin folder via htaccess, disabling xmlrpc and wp-json, disabling wp-cron.php, deleting WordPress's temporary cached data, and restricting PHP functions.
[0044] wp-login.php is the default login page for WordPress. Deleting wp-login.php prevents malicious attackers from brute-forcing administrators' login credentials by repeatedly trying different username and password combinations, thereby protecting website login security. Furthermore, the default login page is easily discovered and targeted by attackers. Deleting it can hide the login page through other means (such as using a plugin to redirect login requests to a custom login page), making it more difficult for attackers to find and attack the login page.
[0045] The wp-admin folder is where the WordPress admin panel is located. Disabling access to the wp-admin folder limits user access rights, preventing them from accessing the admin panel. This protects website configuration, content editing, and other functions from malicious tampering or corruption. Furthermore, even without direct access to the admin panel, attackers could potentially access files in the wp-admin folder to obtain sensitive website information (such as database connection information). Disabling access to the wp-admin folder can prevent this from happening and prevent information leaks.
[0046] XMLRPC (or XML-RPC) is a protocol that allows software applications to communicate with each other over the internet. WordPress implements XML-RPC functionality through the xmlrpc.php file. Attackers can exploit xmlrpc.php to perform brute force attacks, attempting to guess usernames and passwords. Disabling xmlrpc.php can reduce the risk of such attacks.
[0047] The REST API (Representational State Transfer Application Programming Interface) is a network application programming interface based on HTTP (Hypertext Transfer Protocol). It allows different applications to communicate over a network. In WordPress, the REST API provides a standard interface that allows developers to manipulate WordPress website data through simple HTTP requests. For example, developers can use it to retrieve the latest posts on a WordPress website from a mobile app or update page content on the website from an external script. wp-json is the default entry point for the REST API in WordPress, used to output website data in JSON (JavaScript Object Notation) format. It provides a wealth of website information, including posts, pages, users, and other data. Disabling wp-json can prevent attackers from obtaining this information through the API (Application Programming Interface), reducing the risk of information leakage.
[0048] wp-cron.php is WordPress's built-in scheduled task system. It checks for and executes scheduled tasks on every page load. In some cases, this can lead to a waste of server resources, especially on high-traffic websites. Disabling wp-cron.php can help optimize website performance and improve resource utilization. Furthermore, attackers could maliciously trigger wp-cron.php to perform unintended tasks, such as sending large amounts of spam. Disabling wp-cron.php can reduce this risk.
[0049] WordPress's temporary cache data may contain sensitive information, such as user session data and form submission data. Deleting this data prevents attackers from accessing cached files and obtaining this information, thereby protecting the security of your website and users. Furthermore, excessive temporary cache data can consume server storage space and affect website loading speeds. Therefore, deleting temporary cache data (such as clearing the wp-content / cache / directory) can free up storage space and improve website performance.
[0050] Attackers may exploit PHP functions (such as eval, exec, and system) by uploading malicious scripts or exploiting code injection vulnerabilities to execute dangerous PHP code (such as system commands or server control). This can lead to website intrusion or damage. Restricting the use of PHP functions can reduce this risk. Furthermore, restricting PHP functions encourages developers to write safer and more reliable code, avoiding security vulnerabilities caused by the use of unsafe functions, thereby improving the security of the entire website.
[0051] Some related technologies deploy a site in both the intranet and public network environments. The data on the intranet site is synchronized with the public network site, preventing users from accessing the intranet site and only the public network site. This approach prevents website data from being tampered with. However, these related technologies also have some shortcomings. For example, the intranet site needs to give operators full operational permissions. If security reinforcement is performed directly on the intranet site, the operators will not be able to operate normally (for example, after deleting wp-login.php and disabling wp-admin, the operators will not be able to log in). For another example, the security reinforcement process may involve sensitive operations (such as executing cleanup scripts). If executed directly on the intranet site, any script anomalies may damage the editing environment.
[0052] This embodiment adopts a three-version isolation architecture. Figure 1As shown, the intranet version is for operators to freely edit, publish and preview website content, the public network version is for users to browse website content in read-only mode, and the intermediate version is equivalent to the preparation area and buffer zone. It inherits the website data of the internal version and completely strips away the high-risk functions that are not needed in the production environment through production environment adaptation processing. Even if the operation fails completely or produces unexpected consequences during the processing process, it will not immediately affect the operators or real users. Therefore, it can play an important role in decoupling, isolating risk operations, and ensuring the stability and security of the production environment.
[0053] S130: Synchronize the website data of the intermediate version that has completed the production environment adaptation process to the public version that is not currently available to users, and update the user access portal to make the public version available to users.
[0054] After the intermediate version of the website data is adapted for the production environment, it is synchronized with the public version. In related art, there is usually only one public version, but in this embodiment, there are two public versions, and these two versions are not available to users at the same time. If only one public version is used, when the website content needs to be updated, it is necessary to shut down and switch (for example, shut down the service → overwrite the file → restart), which will cause user access interruption. Moreover, if an attacker injects malicious code at the moment of synchronization, it may also contaminate the only public version, and then it will be impossible to provide services to users. However, if two public versions are used that are not available to users at the same time, when the website content is updated, the public version that is not currently available to users can be updated first. After the update is complete, the public version can be made available to users. This provides a smoother user experience, and the user will basically not be aware that the website content has been updated. Moreover, if a public version is attacked, it can be directly switched back to the other public version to continue providing services to users.
[0055] The two public versions can be used to serve users separately and seamlessly through iptables rules. For example, two public versions of WordPress can be deployed on a public network server. These two public versions can be distinguished by different ports (or different IP addresses). For example, the first public version (referred to as version 1) uses port 80, while the second public version (referred to as version 2) uses port 8080. The public version used by users can be switched by changing the port.
[0056] The embodiments of the present application can convert a dynamically writable content management system into a static, read-only public service, greatly reducing the attack surface exposed by WordPress (i.e., the public version) used in an online production environment, and blocking write-type attacks at the source; moreover, even if the public version is attacked, it can be quickly restored through the update process of internal version → intermediate version → public version, thereby achieving the goal of containing zero-day attacks.
[0057] In some embodiments, in addition to being accessible to users, the public version may also reserve ports for use by internal personnel of an enterprise or organization, such as operations staff and developers, for purposes such as review and whitelist control. For example, the public version reserves at least two ports, such as the iptables_port_forward port 443 (open to the public) and the nginx_review port (open to internal personnel), as shown in Figure 1.
[0058] In some embodiments, before synchronizing the internal version of the website data to the intermediate version, the method further includes: detecting whether the new website content meets the expected effect; if it meets the expected effect, determining to execute the step of synchronizing the internal version of the website data to the intermediate version.
[0059] After the operations staff releases new website content, they can check whether the new website content meets the expected results. If so, they synchronize the internal version of the website data with the intermediate version. If the new website content does not meet the expected results, the operations staff will return to the process of editing and releasing the new website content in the internal version.
[0060] When website content needs to be updated frequently, automated devices can be used to perform expected effect detection operations to increase the speed of expected effect detection, reduce the error rate, and thus improve the overall update efficiency of website content.
[0061] In some embodiments, before updating the user access portal, the method further includes: detecting whether the new website content meets the expected effect; if it meets the expected effect, determining to execute the step of updating the user access portal.
[0062] After synchronizing the intermediate version of the website data to the public version not yet available to users, the new website content can be tested again to see if it meets the expected performance. If so, the user access portal can be updated. If the new website content does not meet the predicted performance, the operations staff will return to editing and publishing the new website content in the internal version. This dual validation of expected performance ensures that the new website content meets the expected requirements to the greatest extent possible.
[0063] Furthermore, after synchronizing the intermediate version of the website data that has completed the production environment adaptation process to the public version that is not currently used by users, first check whether the synchronization is successful. If the synchronization is successful, execute the step of detecting whether the new website content meets the expected effect; if the synchronization is unsuccessful, return to the step of synchronizing the internal version of the website data to the intermediate version.
[0064] In some embodiments, synchronizing the intermediate version of the website data that has completed the production environment adaptation processing to the public version that is not currently in use by users includes: synchronizing the intermediate version of the website data that has completed the production environment adaptation processing to a temporary folder of the public network server; after determining the public version that is not currently in use by users, synchronizing the website data in the temporary folder to the public version that is not currently in use by users.
[0065] When synchronizing website data in the intermediate version to a public version that is not currently available to users, the website data in the intermediate version can be synchronized directly to the public version. However, this synchronization method has some shortcomings. For example, the synchronization operation between the intermediate version and the public version is transmitted via the Internet. When synchronizing directly to the public version, if some uncontrollable network failures occur in the middle, the public version will be unpredictably damaged. At the same time, this damage also destroys the original intention of the "double backup" of the public version. If there is a problem with the public version facing users at this time, it is impossible to quickly fall back to the public version that is not available to users. In response to the above shortcomings, this application sets up a temporary folder on the public network server (such as Figure 1 The temporary folder acts as a data transfer station. After the intermediate version of the website data has been adapted for the production environment, it is synchronized to the temporary folder on the public network server. The data can be uploaded first. After the intermediate version of the website data has been transferred to the temporary folder, the website data in the temporary folder is verified. If the verification is successful, the public version currently not available to users is detected. The entire website data in the temporary folder is then synchronized to the public version not currently available to users. Because the temporary folder and the public version are in the same file system and are not transferred over the network, the risk of subsequent synchronization failures due to uncontrollable reasons is reduced. In addition, once the website data in the temporary folder has been fully synchronized to the public version not currently available to users, the public version can be made available to users for access, thus eliminating the risk of business interruption.
[0066] In some embodiments, the two public versions are deployed using Docker containers. Regarding the file systems and databases of each public version, the file systems can be deployed in read-only mode. Read-only deployment places the system or data in read-only mode. In this mode, users can only view the data and cannot modify, delete, or add new data. Using read-only deployment for the file system can be used to protect important data, historical records, or shared resources. In some scenarios, it is necessary to protect certain fields in the database from accidental modification, while at the same time allowing other fields to be updated. Therefore, a combination of read-only accounts and triggers can be used to achieve field-specific read-only control. A read-only account in the database is a user account that only has query permissions but no modify, delete, or add permissions. By limiting a user's database operation permissions, the risk of malicious data tampering can be reduced. A trigger is a special stored procedure that automatically executes when a specific database operation (such as add, update, or delete) occurs. Triggers can be used to protect specific fields, blocking any attempts to modify those fields. By combining read-only accounts and triggers, you can precisely control which fields in the database can be modified and which fields cannot be modified, thereby protecting important data from accidental modifications. At the same time, you can also allow certain fields to be updated normally while other fields remain read-only, thereby meeting complex business needs.
[0067] In some embodiments, website data that needs to be synchronized between versions, such as website data synchronized from an internal version to an intermediate version, and website data synchronized from an intermediate version to a public version, all include database data and file system data. Database data refers to structured data stored in a MySQL database. These data are usually organized in a table format and contain various fields and records. File system data refers to unstructured data stored in a server file system. These data are usually organized in the form of files and directories. When synchronizing database data, a full synchronization method is used; when synchronizing file system data, an incremental synchronization method is used. Full synchronization means that during the synchronization process, the entire content of the source data is copied to the target location. During full synchronization, whether the data has changed is not considered, and the complete data set is transmitted each time. Incremental synchronization means that during the synchronization process, only the data that has changed is synchronized. The incremental synchronization method determines which data needs to be synchronized by comparing the hash value, timestamp or other identifiers of the data.
[0068] Given that database data is typically structured and interrelated (e.g., complex dependencies between database tables), full synchronization ensures the consistency and integrity of all data, avoiding association errors caused by partial data synchronization. Furthermore, database data may change more frequently than file system data, so full synchronization ensures that all database data changes are captured to avoid omissions. File system data (such as media files and log files) is typically large, requiring a full synchronization that consumes significant time and bandwidth. Furthermore, file system data typically changes infrequently, so incremental synchronization can reduce unnecessary data transfer, minimize server resource usage, and improve synchronization efficiency.
[0069] When fully synchronizing database data, you can use mysqldump and the mysql command. mysqldump is a command-line tool that exports the contents of a source MySQL database to a SQL file, making it easier to store and restore database data. This SQL file can then be used to restore the database data in the target database, achieving full database synchronization. When synchronizing website data from an internal version to an intermediate version, the internal version is the source version, and the intermediate version is the target version. When synchronizing website data from an intermediate version to the public version, the intermediate version is the source version, and the public version is the target version.
[0070] When incrementally synchronizing file system data, you can use one-way hash lists such as sha256 to determine changes in the file systems of both parties, and only transfer or delete the modified files.
[0071] It should be noted that, with respect to the various steps included in the website operation method for curbing zero-day attacks provided in any of the above embodiments, unless otherwise explicitly stated herein, there is no strict order restriction on the execution of these steps, and these steps may be executed in other orders. Furthermore, at least a portion of these steps may include multiple sub-steps or multiple stages, and these sub-steps or stages do not necessarily need to be completed at the same time, but may be executed at different times. These sub-steps or stages do not necessarily need to be executed sequentially, but may be executed in rotation or alternation with other steps or at least a portion of their sub-steps or stages.
[0072] Based on the same inventive concept, the present application also provides a website operation device for curbing zero-day attacks. In some embodiments, the website's content management system has multiple versions, including an internal version and an intermediate version deployed on an intranet server, and two public versions deployed on a public network server for users to use at different times; the internal version is used by website operators to edit and publish website content, and the public version is used by users to browse website content; Figure 3 As shown, the device includes: The first synchronization module 110 is used to synchronize the internal version of the website data to the intermediate version after the operator releases new website content; The production environment adaptation processing module 120 is used to perform production environment adaptation processing on the website data synchronized to the intermediate version. The production environment adaptation processing includes one or more of database optimization processing, domain name search and replacement processing, and security reinforcement processing; The second synchronization module 130 is used to synchronize the intermediate version of the website data that has completed the production environment adaptation process to the public version that is not currently available to users, and to update the user access portal to make the public version available to users.
[0073] In some embodiments, the device further includes an expected effect detection module. The expected effect detection module is configured to detect whether the new website content meets the expected effect before the first synchronization module 110 synchronizes the internal version of the website data to the intermediate version; if so, determine to execute the step of synchronizing the internal version of the website data to the intermediate version.
[0074] In some embodiments, the expected effect detection module is also used to detect whether the new website content meets the expected effect before the second synchronization module 130 updates the user access portal; if it meets the expected effect, it is determined to execute the step of updating the user access portal.
[0075] In some embodiments, the database optimization process includes deleting revision files and junk files; the security hardening process includes deleting wp-login.php, disabling access to the wp-admin folder through htaccess, disabling xmlrpc and wp-json, disabling wp-cron.php, deleting temporary cache data of wordpress, and restricting one or more of php functions.
[0076] In some embodiments, the production environment adaptation processing module 120 is specifically used to synchronize the intermediate version of the website data that has completed the production environment adaptation processing to a temporary folder of the public network server; after determining the public version that is not currently used by users, the website data in the temporary folder is synchronized to the public version that is not currently used by users.
[0077] In some embodiments, each of the internal version, intermediate version and public version includes a database and a file system; the website data synchronized from the internal version to the intermediate version and the website data synchronized from the intermediate version to the public version both include database data and file system data; when synchronizing database data, a full synchronization method is adopted; when synchronizing file system data, an incremental synchronization method is adopted.
[0078] In some embodiments, the public version of the file system is deployed on a public network server in a read-only deployment mode, and the public version of the database controls user access to the public version of the website data through a combination of read-only accounts and triggers.
[0079] The specific definition of the website operation device for curbing zero-day attacks can be found in the definition of the website operation method for curbing zero-day attacks described above and will not be repeated here. Each module in the aforementioned website operation device for curbing zero-day attacks can be implemented in whole or in part through software, hardware, or a combination thereof. Each of these modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.
[0080] The present application also provides a computer device. In some embodiments, the computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the website operation method for curbing zero-day attacks provided in any of the above embodiments can be implemented.
[0081] In some embodiments, the internal structure diagram of the computer device can be as follows: Figure 4 As shown. The computer device includes a processor, a memory and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as website content. The specific stored data can also be found in the definitions in the above method embodiments. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a website operation method for curbing zero-day attacks is implemented.
[0082] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0083] The present application also provides a computer-readable storage medium. In some embodiments, a computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps of the website operation method for curbing zero-day attacks provided in any of the above embodiments are implemented.
[0084] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0085] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the above-described method embodiments. Any reference to memory, storage, database, or other media used in the embodiments provided herein may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink), DRAM (SLDRAM), RAMbus, direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM).
[0086] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0087] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.
Claims
1. A website operation method for curbing zero-day attacks, characterized in that: The website's content management system has multiple versions, including an internal version and an intermediate version deployed on an intranet server, and two public versions deployed on a public network server that are not used by users at the same time; The internal version is used by website operators to edit and publish website content, and the public version is used by users to browse website content. The method includes: After the operator releases new website content, the website data of the internal version is synchronized to the intermediate version; Performing production environment adaptation processing on the website data synchronized to the intermediate version, wherein the production environment adaptation processing includes one or more of database optimization processing, domain name search and replacement processing, and security reinforcement processing; The website data of the intermediate version that has completed the production environment adaptation process is synchronized to the public version that is not currently available to users, and the user access portal is updated to make the public version available to users.
2. The method according to claim 1, wherein Before synchronizing the website data of the internal version to the intermediate version, the method further includes: Check whether the new website content meets the expected results; If the expected effect is met, it is determined to execute the step of synchronizing the website data of the internal version to the intermediate version.
3. The method according to claim 1 or 2, wherein: Before updating the user access portal, the method further includes: Check whether the new website content meets the expected results; If the expected effect is met, it is determined to execute the step of updating the user access portal.
4. The method according to claim 1, wherein The database optimization process includes deleting revision files and junk files; the security reinforcement process includes deleting wp-login.php, disabling access to the wp-admin folder through htaccess, disabling xmlrpc and wp-json, disabling wp-cron.php, deleting temporary cache data of WordPress and restricting one or more of php functions.
5. The method according to claim 1, wherein Synchronizing the website data of the intermediate version that has completed the production environment adaptation process to the public version that is not currently available to users, including: Synchronize the intermediate version of the website data that has completed the production environment adaptation process to a temporary folder of the public network server; After determining the public version that is not currently used by the user, the website data in the temporary folder is synchronized to the public version that is not currently used by the user.
6. The method according to claim 1, wherein Each of the internal version, the intermediate version and the public version includes a database and a file system; the website data synchronized from the internal version to the intermediate version and the website data synchronized from the intermediate version to the public version both include database data and file system data; when synchronizing the database data, a full synchronization method is adopted; when synchronizing the file system data, an incremental synchronization method is adopted.
7. The method according to claim 6, wherein The public version of the file system is deployed on the public network server in a read-only deployment mode, and the public version of the database controls the user's access to the public version of the website data by combining a read-only account and a trigger.
8. A website operation device for curbing zero-day attacks, characterized in that: The website's content management system has multiple versions, including an internal version and an intermediate version deployed on an intranet server, and two public versions deployed on a public network server that are not used by users at the same time; The internal version is used by website operators to edit and publish website content, and the public version is used by users to browse website content; the device includes: A first synchronization module is used to synchronize the website data of the internal version to the intermediate version after the operator releases new website content; A production environment adaptation processing module, configured to perform production environment adaptation processing on the website data synchronized to the intermediate version, wherein the production environment adaptation processing includes one or more of database optimization processing, domain name search and replacement processing, and security reinforcement processing; The second synchronization module is used to synchronize the website data of the intermediate version that has completed the production environment adaptation process to the public version that is not currently available to users, and to update the user access portal to make the public version available to users.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Autonomous controllable website safety defensive system based on hardware processing board
CN102801711A
Web site content management system and program
JP2004157883A
Version management and releases of a software application
US20250004757A1