Attack chain analysis method based on RASP and related product

Through the RASP-based attack chain analysis method, the web request information of the application is obtained and analyzed, the status of key functions is monitored, and attack behavior alarms are generated. This solves the problem of low attack chain restoration efficiency in the existing technology and achieves efficient attack chain restoration and monitoring.

CN120768640APending Publication Date: 2025-10-10AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511026687.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Existing RASP technology is difficult to effectively restore the overall attack process of reconnaissance-detection-exploitation in network attack incidents, resulting in inefficient security operations and monitoring.

Method used

Through the RASP-based attack chain analysis method, the web request information of the application is obtained, the threat characteristics are analyzed using the preset vulnerability rule feature library, and the status of key functions is monitored to generate attack behavior alarms and display the reconnaissance, detection and utilization links of the attack chain.

Benefits of technology

It achieves complete restoration of the attack chain, improves the efficiency of security operations and monitoring, and can restore the entire attack process from the time or URL dimension.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768640A_ABST
    Figure CN120768640A_ABST
Patent Text Reader

Abstract

The invention discloses an attack chain analysis method based on RASP and a related product. The method comprises the following steps: acquiring web request information for accessing a target application program based on an RASP technology; according to a preset vulnerability rule feature library, analyzing each piece of web request information from the flow perspective, and determining first web request information comprising threat features; monitoring the state of a preset key function based on the RASP technology, and generating an attack behavior alarm under the condition that the key function is triggered; displaying the first web request information and the attack behavior alarm; wherein the first web information corresponds to a reconnaissance link and a detection link in an attack chain, and the attack behavior alarm corresponds to a utilization link in the attack chain. In the embodiment of the invention, the attack chain is restored by using the RASP technology, namely, the reconnaissance-detection-utilization links of the attack chain are displayed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a RASP-based attack chain analysis method and related products. Background Art

[0002] Runtime Application Self-Protection (RASP) is a security protection technology embedded within the application. It can monitor and block security threats in real time while the application is running, without relying on external devices or network layer protection.

[0003] In related technologies, RASP protection typically captures the successful exploitation of a network attack. However, in actual security operations and security monitoring, if a network attack occurs, it is necessary to track the entire attack process and restore the attack chain, that is, the entire process of reconnaissance, detection, and exploitation. Summary of the Invention

[0004] Based on the above problems, this application provides an attack chain analysis method and related products based on RASP to restore the overall process of reconnaissance-detection-exploitation.

[0005] The embodiments of this application disclose the following technical solutions:

[0006] In a first aspect, an embodiment of the present application provides an attack chain analysis method based on RASP, including:

[0007] Obtain web request information for accessing the target application based on RASP technology;

[0008] Analyze each web request information from a traffic perspective according to a preset vulnerability rule feature library, and determine the first web request information including threat features;

[0009] Based on RASP technology, the status of preset key functions is monitored and attack behavior alarms are generated when key functions are triggered.

[0010] Display the first web request information and attack behavior alarm; wherein, the first web information corresponds to the reconnaissance link and the detection link in the attack chain, and the attack behavior alarm corresponds to the utilization link in the attack chain.

[0011] In one possible implementation, the status of a preset key function is monitored based on the RASP technology. When the key function is triggered, an attack behavior alarm is generated. The method further includes:

[0012] Determine the second web request information that triggers the key function;

[0013] Displays the first web request information and attack behavior alerts, including:

[0014] The first web request information, the attack behavior alert, and the second web request information are displayed; wherein the second web request information is associated with the attack behavior alert.

[0015] In one possible implementation, displaying the first web request information, the attack behavior alert, and the second web request information includes:

[0016] Based on the time dimension or URL dimension, the first web request information, attack behavior alert and second web request information are displayed.

[0017] In one possible implementation, after obtaining web request information for accessing a target application based on RASP technology, the method further includes:

[0018] Mark each web request information; wherein the second web request information is associated with the attack behavior alarm through the corresponding marking information.

[0019] In one possible implementation, each web request information is analyzed from a traffic perspective based on a preset vulnerability rule feature library, and first web request information including threat features is determined, including:

[0020] Standardize each web request information;

[0021] Performing at least one of protocol parsing, encoding and decoding, and exception filtering on each standardized web request information to obtain vulnerability information in each web request information;

[0022] Each vulnerability information is matched with an element in a preset vulnerability rule feature library to determine first web request information including threat features.

[0023] In one possible implementation, the web request information includes at least one of a request line, a request header, a request body, and traffic metadata.

[0024] In a second aspect, an embodiment of the present application provides an attack chain analysis device based on RASP, including an acquisition module, an analysis module, a monitoring module, and a display module;

[0025] An acquisition module, used to obtain web request information for accessing the target application based on RASP technology;

[0026] An analysis module is used to analyze each web request information from a traffic perspective according to a preset vulnerability rule feature library, and determine first web request information including threat features;

[0027] The monitoring module is used to monitor the status of preset key functions based on RASP technology and generate attack behavior alarms when key functions are triggered;

[0028] The display module is used to display the first web request information and the attack behavior alarm; wherein the first web information corresponds to the reconnaissance link and the detection link in the attack chain, and the attack behavior alarm corresponds to the utilization link in the attack chain.

[0029] In one possible implementation, the monitoring module is further configured to determine second web request information that triggers the critical function;

[0030] The display module is specifically used to display the first web request information, the attack behavior alarm and the second web request information; wherein the second web request information is associated with the attack behavior alarm.

[0031] In a possible implementation, the display module is specifically configured to display the first web request information, the attack behavior alert, and the second web request information based on a time dimension or a URL dimension.

[0032] In one possible implementation, the attack chain analysis device further includes a marking module;

[0033] The marking module is used to mark each web request information; wherein the second web request information is associated with the attack behavior alarm through the corresponding marking information.

[0034] In one possible implementation, the analysis module is specifically used to perform at least one of protocol parsing, encoding and decoding, and exception filtering on each standardized web request information to obtain vulnerability information in each web request information; each vulnerability information is matched with an element in a preset vulnerability rule feature library to determine the first web request information including threat features.

[0035] In one possible implementation, the web request information includes at least one of a request line, a request header, a request body, and traffic metadata.

[0036] In a third aspect, an embodiment of the present application provides a computer device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the RASP-based attack chain analysis method as described in any embodiment of the first aspect.

[0037] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein instructions are stored in the computer-readable storage medium. When the instructions are executed on a terminal device, the terminal device executes the RASP-based attack chain analysis method as described in any embodiment of the first aspect.

[0038] To restore the attack chain, an embodiment of the present application provides a RASP-based attack chain analysis method. The method uses RASP technology to obtain web request information for accessing a target application; analyzes each web request information from a traffic perspective based on a preset vulnerability rule feature library, and determines a first web request information that includes threat characteristics; monitors the status of preset key functions based on RASP technology, and generates an attack behavior alarm when the key function is triggered; and displays the first web request information and the attack behavior alarm. The first web information corresponds to the reconnaissance and detection links in the attack chain, and the attack behavior alarm corresponds to the exploitation link in the attack chain. In the embodiment of the present application, RASP technology is used to restore the attack chain, that is, to display the reconnaissance-detection-exploitation links of the attack chain. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0040] Figure 1 A flowchart of a RASP-based attack chain analysis method provided in an embodiment of the present application;

[0041] Figure 2 A schematic diagram of an attack chain analysis device based on RASP provided in an embodiment of the present application;

[0042] Figure 3 A schematic diagram of a control device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0043] In order to help those skilled in the art better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.

[0044] The terms "first" and "second" in the specification and claims of this application are used to distinguish different objects, rather than to describe a specific order of objects. For example, "first switching device" and "second switching device" are used to distinguish different switching devices, rather than to describe a specific order of switching devices.

[0045] In the embodiments of this application, the words such as "exemplary" or "for example" are used to mean serving as an example, instance, or illustration. Any embodiment or design presented as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being more preferred or advantageous than other embodiments or design solutions. Rather, the use of the words such as "exemplary" or "for example" is intended to present relevant concepts in a particular manner.

[0046] In order to facilitate understanding of the technical solutions of the present application, the RASP-based attack chain analysis method will be explained and described below in conjunction with the embodiment drawings.

[0047] Referring to Figure 1 , the figure is a flowchart of a RASP-based attack chain analysis method provided by the embodiments of the present application.

[0048] As Figure 1 indicated, the method comprises:

[0049] S110: Obtain web request information for accessing the target application based on the RASP technology.

[0050] The core of obtaining the web request information based on the RASP technology is to utilize the deep integration characteristics of RASP and the application program, that is, to implant a hook at the key execution point of the application program, and to internally intercept, analyze and record the web request data flowing through the application program during the application running.

[0051] The dimensions of the web request information are not specifically limited in the embodiments of the application, for example, basic network layer information, HTTP protocol layer information, application layer context information, and abnormal / special request information.

[0052] Exemplarily, taking a Java Web application (based on Tomcat+Spring) as an example, the RASP obtaining process is as follows:

[0053] In the HttpServlet.service() method of Tomcat (the entry of all HTTP requests), a hook is implanted to trigger when the request arrives; basic information such as the request line, headers, body, etc. is obtained through the HttpServletRequest object, and the decoded parameters are obtained by calling the built-in parsing method of the application (such as getParameter()); the controller method corresponding to the current request and user session information are obtained through Spring's RequestContextHolder; the obtained information is converted into a structured format (such as JSON), including fields: {"method":"POST","url":"...","headers":{...},"body":"...","user":"admin",...}; the structured data is sent to the RASP console, log system or associated security platform (such as SIEM) for subsequent analysis (such as vulnerability detection, abnormal behavior identification).

[0054] S120: According to the preset vulnerability rule feature library, the web request information is analyzed from the perspective of traffic, and first web request information including threat features is determined.

[0055] For example, the preset vulnerability rule feature library can include vulnerability types, feature contents, matching methods, confidence levels, and related information such as association dimensions.

[0056] For example, the vulnerability type can correspond to OWASP Top 10 (such as SQL injection, XSS, command injection, etc.) or CVE number (such as Log4j vulnerability CVE-2021-44228).

[0057] The feature content can include the symbolic string, structure or behavior of the vulnerability exploit (such as unionselect of SQL injection, XSS <script>、路径遍历的.. / );匹配方式可以包括正则表达式、语义结构、行为模式等。

[0058] 置信度,可以包括特征的"可靠性”(如强特征:xp_cmdshell,弱特征:select)。

[0059] 关联维度,可以包括需结合的web请求部分(如仅URL参数、仅请求体、多部分联合匹配)。

[0060] 在一种可能的实现方式中,分析流程可以包括数据预处理、特征匹配、深度验证以及结果判定四个阶段,具体如下:

[0061] (1)数据预处理阶段,本申请实施例可以从协议解析、编码解码、格式统一以及异常过滤等四个步骤对web请求信息进行标准化。其中,

[0062] 协议解析方面,从流量中提取HTTP / HTTPS的请求行、headers、body,分离URL路径与查询参数(如 / api / user?id=1&name=test拆分为路径 / api / user和参数id=1、name=test);

[0063] 编码解码方面,处理各类编码(URL编码%20、Base64、Unicode\u003c等),还原原始字符串(如将%3cscript%3e解码为<script>);

[0064] 格式统一方面,统一大小写(如将SELECT与select视为同一特征)、去除无效字符(如空格、注释符 / ** / );

[0065] 异常过滤方面,排除明显无效的请求(如空请求、协议错误的数据包)。

[0066] (2)特征匹配阶段,基于预处理后的数据,从多维度匹配特征库中的规则,识别可疑请求。

[0067] 示例性的,本申请实施例中,可以通过正则匹配、关键词组合或结构匹配的方式实现特征匹配。

[0068] 正则匹配,用预定义正则(如union.*?select)匹配参数值中的SQL注入片段。

[0069] 关键词组合,同时出现select+from+where等SQL关键字(减少单一关键词的误报)。

[0070] 结构匹配,检查URL路径是否符合 / file?path=.. / etc / passwd的路径遍历结构。

[0071] (3)深度验证阶段,简单特征匹配可能存在误报(如正常业务中使用select关键词),需通过深度分析确认是否为真实漏洞利用。

[0072] 本申请实施例中可以通过以下验证手段进行验证:

[0073] 语义分析:判断特征是否处于"有意义的攻击语境”。

[0074] 示例性的,若参数值为select*from users,且该参数本应接收数字(如id=1),则语义异常,判定为可疑;若参数是搜索框(本应接收文本),包含select可能是正常内容,需结合其他特征。

[0075] 上下文关联:结合多请求行为分析。

[0076] 示例性的,单一请求包含union select可能是误报,但同一IP在1分钟内发送100次相同特征的请求,大概率是自动化攻击。

[0077] 沙箱模拟:对高可疑请求,在隔离环境中模拟执行(如将参数值传入数据库,观察是否返回异常结果),验证是否触发漏洞。

[0078] (4)结果判定阶段,根据匹配强度、验证结果,输出最终判定:

[0079] 恶意请求:多维度强特征匹配+语义 / 行为验证通过(如同时匹配union select和and 1=1,且模拟执行返回数据库信息);

[0080] 可疑请求:单一弱特征匹配或验证不明确(如仅URL包含select,但参数类型允许文本输入);

[0081] 正常请求:无任何特征匹配,或特征被验证为业务正常内容。

[0082] 应当理解的是,本申请实施例中针对恶意请求或可以请求,可以将其进行标记得到第一web请求,本申请实施例中不具体限定标记的方式。

[0083] S130:基于RASP技术监测预设关键函数的状态,在所述关键函数被触发的情况下,产生攻击行为告警。

[0084] 其中,关键函数可以是RASP植入"无侵入式钩子”的函数,钩子植入的关键是不干扰函数的正常业务逻辑,当关键函数被触发(调用)时,RASP通过钩子实时捕获以下信息:

[0085] 函数基本信息:函数名、所属类 / 模块、调用方式(同步 / 异步)。

[0086] 输入参数:函数接收的所有参数值(如cursor.execute("SELECT*FROM usersWHERE id=1")中的SQL语句参数)。

[0087] 参数来源:参数是否来自用户输入(如HTTP请求的URL参数、请求体)、是否经过业务层过滤 / 验证。

[0088] 调用上下文:应用层,当前请求的用户身份(如登录账号、角色)、请求URL、会话ID;代码层,函数调用栈(如从Controller→Service→DAO的调用链路)、当前线程ID。

[0089] 环境信息:服务器IP、应用部署路径、系统时间。

[0090] 通过捕获的上述信息,RASP结合捕获的函数调用信息与预设漏洞规则库,判断是否为攻击行为;在判定为攻击行为的情况下,RASP立即触发告警。

[0091] S140:展示所述第一web请求信息和所述攻击行为告警;其中,所述第一web信息对应攻击链中的侦察环节和探测环节,所述攻击行为告警对应所述攻击链中的利用环节。

[0092] 在一种实现方式中,基于时间维度或URL维度,展示第一web请求信息、攻击行为告警以及第二web请求信息。

[0093] 为了还原攻击链,本申请实施例中,基于RASP技术获取访问目标应用程序的web请求信息;根据预设漏洞规则特征库,从流量角度分析各所述web请求信息,并确定包括威胁特征的第一web请求信息;基于RASP技术监测预设关键函数的状态,在所述关键函数被触发的情况下,产生攻击行为告警;展示所述第一web请求信息和所述攻击行为告警;其中,所述第一web信息对应攻击链中的侦察环节和探测环节,所述攻击行为告警对应所述攻击链中的利用环节。本申请实施例中,利用RASP技术还原攻击链,即展示攻击链的侦察-探测-利用环节。

[0094] 基于前述实施例,本申请实施例在基于RASP技术获取访问目标应用程序的web请求信息之后,标记各web请求信息;基于RASP技术监测预设关键函数的状态,在所述关键函数被触发的情况下,产生攻击行为告警;确定触发关键函数的第二web请求信息,并基于web请求信息的标记,将告警与对应的web请求信息相关联;基于时间维度或URL维度,展示所述第一web请求信息、所述攻击行为告警以及所述第二web请求信息。

[0095] 本申请实施例中,增加应用程序所有web请求的提取功能,对所有的请求数据进行处理,同时对web请求设置标记,与实际漏洞利用操作关联,通过关联分析可以查看全流量信息和从时间、URL等维度还原整个攻击过程。

[0096] 基于前述方法实施例,即一种基于RASP的攻击链分析方法,本申请实施例提供一种基于RASP的攻击链分析装置,其示意图参见图2。

[0097] 如图2所示,该装置包括:获取模块210、分析模块220、监测模块230和展示模块240。

[0098] 获取模块210,用于基于RASP技术获取访问目标应用程序的web请求信息。

[0099] 分析模块220,用于根据预设漏洞规则特征库,从流量角度分析各web请求信息,并确定包括威胁特征的第一web请求信息。

[0100] 监测模块230,用于基于RASP技术监测预设关键函数的状态,在关键函数被触发的情况下,产生攻击行为告警。

[0101] 展示模块240,用于展示第一web请求信息和攻击行为告警;其中,第一web信息对应攻击链中的侦察环节和探测环节,攻击行为告警对应攻击链中的利用环节。

[0102] 本申请实施例中,增加应用程序所有web请求的提取功能,对所有的请求数据进行处理,同时对web请求设置标记,与实际漏洞利用操作关联,通过关联分析可以查看全流量信息和从时间、URL等维度还原整个攻击过程。

[0103] 一种可能的实现中,监测模块,还用于确定触发关键函数的第二web请求信息;

[0104] 展示模块,具体用于展示第一web请求信息、攻击行为告警以及第二web请求信息;其中,第二web请求信息与攻击行为告警关联。

[0105] 一种可能的实现中,展示模块,具体用于基于时间维度或URL维度,展示第一web请求信息、攻击行为告警以及第二web请求信息。

[0106] 一种可能的实现中,攻击链分析装置还包括标记模块;

[0107] 标记模块,用于标记各web请求信息;其中,第二web请求信息与攻击行为告警通过对应的标记信息关联在一起。

[0108] 一种可能的实现中,分析模块,具体用于对标准化后的各web请求信息进行协议解析、编码解码和异常过滤中的至少一种操作,得到各web请求信息中的漏洞信息;将各漏洞信息分别与预设漏洞规则特征库中的元素进行匹配,确定包括威胁特征的第一web请求信息。

[0109] 一种可能的实现中,web请求信息包括请求行、请求头、请求体和流量元数据中的至少一种。

[0110] 针对本申请实施例中的控制装置,其示意图如图3所示。

[0111] 控制装置可以包括存储器1011和处理器1012。控制装置,连接客户端、网关或应用程序中的任意一个。如图3所示,存储器可以是随机存取存储器(random access memory,RAM)、闪存、只读存储器(read only memory,ROM)、EPROM存储器、非易失性只读存储器(Electronic Programmable ROM,EPROM)、寄存器、硬盘、可移动磁盘等。

[0112] 存储器1011可以存储计算机指令,当存储器1011中存储的计算机指令被处理器1012执行时,处理器1012可以用于执行基于RASP的攻击链分析方法。存储器1011还可以存储数据,例如,上述实施例中涉及的预设范围、预设阈值等信息。

[0113] 在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行计算机程序指令时,全部或部分地产生按照本申请实施例的流程或功能。计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(digitalsubscriber line,DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包括一个或多个可用介质集成的服务器、数据中心等数据存储设备。可用介质可以是磁性介质,(例如,软盘、硬盘、磁带)、或者半导体介质(例如固态硬盘(solidstate disk,SSD))等。

[0114] 本申请实施例还提供一种可读存储介质,用于存储上述实施例提供的方法。例如,随机存取存储器(random access memory,RAM)、闪存、只读存储器(read only memory,ROM)、EPROM存储器、非易失性只读存储器(Electronic Programmable ROM,EPROM)、寄存器、硬盘、可移动磁盘或本领域中其它任意形式的存储媒介。

[0115] 需要说明的是,本说明书中各个实施例采用递进的方式描述,每个实施例重点说明的都是与其他实施例的不同之处,各个实施例之间相同相似部分互相参见即可。

[0116] 对所公开的实施例的上述说明,使本领域专业技术人员能够实现或使用本申请。对这些实施例的多种修改对本领域的专业技术人员来说将是显而易见的,本文中所定义的一般原理可以在不脱离本申请的精神或范围的情况下,在其它实施例中实现。因此,本申请将不会被限制于本文所示的这些实施例,而是要符合与本文所公开的原理和新颖特点相一致的最宽的范围。< / script>

Claims

1. A RASP-based attack chain analysis method, characterized in that: The method comprises: Obtain web request information for accessing the target application based on RASP technology; Analyzing each of the web request information from a traffic perspective according to a preset vulnerability rule feature library, and determining first web request information including threat features; Monitor the status of preset key functions based on RASP technology, and generate attack behavior alarms when the key functions are triggered; The first web request information and the attack behavior alert are displayed; wherein the first web information corresponds to the reconnaissance link and the detection link in the attack chain, and the attack behavior alert corresponds to the utilization link in the attack chain.

2. The method according to claim 1, characterized in that The method further comprises: monitoring the status of a preset key function based on the RASP technology, and generating an attack behavior alarm when the key function is triggered. Determining second web request information that triggers the key function; Displaying the first web request information and the attack behavior alert includes: The first web request information, the attack behavior alert, and the second web request information are displayed; wherein the second web request information is associated with the attack behavior alert.

3. The method according to claim 2, characterized in that The displaying of the first web request information, the attack behavior warning, and the second web request information includes: Based on the time dimension or the URL dimension, the first web request information, the attack behavior alert, and the second web request information are displayed.

4. The method according to claim 2, characterized in that After obtaining web request information for accessing the target application based on the RASP technology, the method further includes: Mark each of the web request information; wherein the second web request information is associated with the attack behavior alarm through corresponding marking information.

5. The method according to any one of claims 1 to 4, characterized in that The step of analyzing each web request information from a traffic perspective according to a preset vulnerability rule feature library and determining first web request information including threat features includes: Standardizing each of the web request information; performing at least one of protocol parsing, encoding and decoding, and exception filtering on each of the standardized web request information to obtain vulnerability information in each of the web request information; Each vulnerability information is matched with an element in the preset vulnerability rule feature library to determine first web request information including threat features.

6. The method according to claim 1, characterized in that The web request information includes at least one of a request line, a request header, a request body, and traffic metadata.

7. A RASP-based attack chain analysis device, characterized in that: include: Acquisition module, analysis module, monitoring module and display module; The acquisition module is used to obtain web request information for accessing the target application based on RASP technology; The analysis module is configured to analyze each web request information from a traffic perspective according to a preset vulnerability rule feature library, and determine first web request information including threat features; The monitoring module is used to monitor the status of preset key functions based on RASP technology, and generate an attack behavior alarm when the key function is triggered; The display module is used to display the first web request information and the attack behavior alarm; wherein the first web information corresponds to the reconnaissance link and the detection link in the attack chain, and the attack behavior alarm corresponds to the utilization link in the attack chain.

8. The device according to claim 7, characterized in that The monitoring module is further configured to determine second web request information that triggers the key function; The display module is specifically configured to display the first web request information, the attack behavior alert, and the second web request information; wherein the second web request information is associated with the attack behavior alert.

9. A computer device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the attack chain analysis method based on RASP according to any one of claims 1 to 6 is implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed on a terminal device, the terminal device executes the RASP-based attack chain analysis method according to any one of claims 1 to 6.