Method and related device for identifying a development framework
By building a directory tree and extracting feature string recognition website development framework, the problem of identification difficulties in the existing technology is solved, and the efficiency and accuracy of vulnerability scanning are improved.
Patent Information
- Application Number
- CN202010540068.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-12
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2040-06-12
AI Technical Summary
The prior art does not provide an effective method to identify the development framework utilized by the website, resulting in long scan time and low efficiency of vulnerability.
By obtaining the directory tree of the target website, extracting feature strings, using feature strings to identify the development framework, building configuration files to match the feature string collection, and determining the development framework.
A rapid identification development framework is implemented, which improves the pertinence and efficiency of vulnerability scanning and shortens scanning time.
Smart Images

Figure CN113806647B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a method for identifying a development framework and related devices. Background Art
[0002] Website vulnerability scanning generally needs to use vulnerability scanning tools corresponding to different development frameworks for scanning according to different development frameworks. If the development framework used to develop the website is not identified and determined before scanning the website for vulnerabilities, it may lead to a long time for vulnerability scanning and low efficiency. In the related art, no solution for identifying the development framework is provided. Summary of the Invention
[0003] Embodiments of this application provide a method for identifying a development framework and related devices, which can thus at least to some extent achieve rapid identification of the development framework.
[0004] Other features and advantages of this application will become apparent through the following detailed description, or be learned in part through the practice of this application.
[0005] According to one aspect of the embodiments of this application, a method for identifying a development framework is provided, including: obtaining a directory tree of a target website, where the directory tree is constructed according to a hierarchical string of the target website, and the hierarchical string is obtained by splitting the URL of a page under the target website; extracting a feature string corresponding to the target website from the directory tree; and identifying the development framework used to develop the target website according to the feature string.
[0006] According to one aspect of the embodiments of this application, a device for identifying a development framework is provided. The device includes: a directory tree obtaining module, configured to obtain a directory tree of a target website, where the directory tree is constructed according to a hierarchical string of the target website, and the hierarchical string is obtained by splitting the URL of a page under the target website; a feature extraction module, configured to extract a feature string corresponding to the target website from the directory tree; and an identification module, configured to identify the development framework used to develop the target website according to the feature string.
[0007] In some embodiments of this application, based on the foregoing solution, the identification module includes: a matching unit, configured to perform string matching in a configuration file according to the feature string to determine a set of feature strings corresponding to the feature string; and a determining unit, configured to determine the development framework indicated by the framework identifier associated with the set of feature strings as the development framework used to develop the target website.
[0008] In some embodiments of the present application, based on the foregoing solution, the device for identifying a development framework further includes: a first directory tree obtaining module, configured to obtain the first directory trees respectively corresponding to multiple sample websites, and the framework identifiers of the development frameworks corresponding to each sample website; a first feature string determining module, configured to, for each sample website, determine a first feature string corresponding to the sample website according to the first directory tree; a feature string set determining module, configured to determine a feature string set corresponding to each development framework according to the first feature string corresponding to the sample website and the framework identifier corresponding to the sample website; and an association module, configured to associate the feature string set with the framework identifier of the corresponding development framework to obtain the configuration file.
[0009] In some embodiments of the present application, based on the foregoing solution, the first feature string determining module includes: a statistics unit, configured to count the occurrence times of each hierarchical string in the first directory tree corresponding to the sample website; a first hierarchical string determining unit, configured to determine a first hierarchical string whose occurrence times in the first directory tree exceed a first threshold according to the counted occurrence times; a general string filtering unit, configured to filter out the general strings in the first hierarchical string to obtain a difference string corresponding to the sample website; and a first feature string determining unit, configured to determine a first feature string corresponding to the sample website according to the difference string.
[0010] In some embodiments of the present application, based on the foregoing solution, the first feature string determining unit is configured to use the difference string as the first feature string corresponding to the sample website.
[0011] In some embodiments of the present application, based on the foregoing solution, there are at least two of the difference strings, and the first feature string determining unit is configured to: combine at least two of the difference strings to obtain a combined string; count the combined occurrence times of the difference strings included in the combined string in the first directory tree corresponding to the sample website; and use the combined string whose combined occurrence times meet the set number requirement as the first feature string corresponding to the sample website.
[0012] In some embodiments of the present application, based on the foregoing solution, the feature string set determination module includes: a classification unit configured to classify the first feature strings according to the framework identifier to obtain an initial feature string set corresponding to each development framework; a sorting unit configured to sort the first feature strings in the initial feature string set in descending order according to the number of sample websites associated with the first feature strings in the initial feature string set; an acquisition unit configured to acquire the first feature strings ranked among the top set number in the initial feature set; and a feature string set determination unit configured to use the acquired first feature strings as elements in the feature string set corresponding to the development framework.
[0013] In some embodiments of the present application, based on the foregoing solution, the apparatus for identifying a development framework further includes: an access data acquisition module configured to acquire access data for the target website, where the access data includes a plurality of access records, and the access record includes the URL of the page accessed under the target website; a path splitting module configured to split the identification character segment in the URL according to the delimiter in the URL to obtain a plurality of hierarchical strings; and a directory tree construction module configured to construct a directory tree of the target website according to the hierarchical strings in the URL.
[0014] In some embodiments of the present application, based on the foregoing solution, the directory tree construction module includes: a sub-path determination unit configured to determine a sub-path in the URL according to the splitting of the identification character segment in the URL, where the starting point of the sub-path is the first-level path in the URL; an occurrence frequency statistics unit configured to count the occurrence frequency of each sub-path in the access data to determine a first sub-path whose occurrence frequency is greater than a second threshold; and a writing unit configured to write the hierarchical strings in the first path into the corresponding tree nodes in the directory tree corresponding to the target website according to the positions of the hierarchical strings in the first sub-path.
[0015] In some embodiments of the present application, based on the foregoing solution, the apparatus for identifying a development framework further includes: a new access data acquisition module configured to acquire new access data collected for the target website; a second directory tree construction module configured to construct a second directory tree for the target website according to the new access data; and a merging module configured to merge the second directory tree into the directory tree to update the directory tree.
[0016] According to one aspect of the embodiments of the present application, there is provided an electronic device, including: a processor; and a memory storing computer-readable instructions thereon, where when the computer-readable instructions are executed by the processor, the method for identifying a development framework as described above is implemented.
[0017] According to one aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which computer-readable instructions are stored. When the computer-readable instructions are executed by a processor, the method for identifying the development framework described above is implemented.
[0018] In the technical solution provided by the present application, based on the correlation between the URL of the target website and the development framework, a directory tree of the target website is constructed according to the hierarchical string in the URL under the target website. Then, a feature string corresponding to the target website is extracted from the directory tree of the target website, and further, the development framework used to develop the target website is identified and determined according to the feature string, realizing the rapid identification of the development framework.
[0019] Moreover, after identifying and determining the development framework used to develop the target website, a scanning tool adapted to the development framework can be correspondingly determined to perform vulnerability scanning on the target website. Since it is not necessary to try multiple scanning tools to determine the scanning tool adapted to the target website before performing vulnerability scanning, thus, the time spent on vulnerability scanning is significantly shortened, and the efficiency of vulnerability scanning is effectively improved.
[0020] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. In the drawings:
[0022] Figure 1 A schematic diagram showing an exemplary system architecture to which the technical solution of the embodiments of the present application can be applied;
[0023] Figure 2 is a flowchart of a method for identifying a development framework shown according to an embodiment;
[0024] Figure 3 is Figure 2 a flowchart of step 250 in the corresponding embodiment in one embodiment;
[0025] Figure 4 is a flowchart of the steps before step 310 shown according to an embodiment in one embodiment;
[0026] Figure 5 is Figure 4 a flowchart of step 430 in the corresponding embodiment in one embodiment;
[0027] Figure 6 is Figure 4 The flowchart of step 450 of the corresponding embodiment in one embodiment;
[0028] Figure 7 is Figure 2 The flowchart of the steps before step 210 of the corresponding embodiment in one embodiment;
[0029] Figure 8 is Figure 7 The flowchart of step 750 of the corresponding embodiment in one embodiment;
[0030] Figure 9 is Figure 7 The flowchart of the steps after step 750 of the corresponding embodiment in one embodiment;
[0031] Figure 10 The flowchart of the method for identifying a development framework shown according to a specific embodiment;
[0032] Figure 11 The schematic diagram of the directory tree constructed for a domain name in a specific embodiment;
[0033] Figure 12 The flowchart of the vulnerability scanning method shown according to an embodiment;
[0034] Figure 13 The block diagram of the device for identifying a development framework shown according to an embodiment;
[0035] Figure 14 is The block diagram of the vulnerability scanning device shown according to an embodiment;
[0036] Figure 15 The schematic diagram of the structure of the computer system of the electronic device suitable for implementing the embodiments of the present application is shown. Detailed implementation manners
[0037] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.
[0038] In addition, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application may be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be employed. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.
[0039] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.
[0040] The flowcharts shown in the drawings are only illustrative and do not necessarily include all the content and operations / steps, nor are they necessarily executed in the described order. For example, some operations / steps may be decomposed, while some operations / steps may be combined or partially combined, so the actual execution order may change according to the actual situation.
[0041] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solutions of the embodiments of the present application can be applied is shown.
[0042] As Figure 1 shown, the system architecture may include terminal devices (such as one or more of the smart phone 101, tablet computer 102, and portable computer 103 shown in Figure 1 , and of course it may also be a desktop computer, etc.), a network 104, and a server 105. The network 104 is used to provide a medium for the communication link between the terminal device and the server 105. The network 104 may include various connection types, such as wired communication links, wireless communication links, etc.
[0043] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in
[0044] are only illustrative. According to the implementation requirements, there may be any number of terminal devices, networks, and servers. For example, the server 105 may be a server cluster composed of multiple servers, etc. In an embodiment of the present application, the server 105 may collect access data of the target website according to the access to the pages of the target website triggered by each terminal device, and thus construct a directory tree of the target website based on the access data of the target website, and then identify the development framework used to develop the target website according to the directory tree of the target website by the method of identifying the development framework of the present application.
[0045] In an embodiment of the present application, after the server 105 identifies and determines the development framework used for developing the target website, it can further determine a vulnerability scanning tool adapted to the development framework used for developing the target website, and perform vulnerability scanning on the target website through the vulnerability scanning tool adapted to the development framework.
[0046] In an embodiment of the present application, after the server 105 identifies and determines the development framework used for developing the target website, it can generate indication information and send the indication information to the terminal device where the user is located, where the indication information is used to indicate the development framework identified and determined by the server 105 for developing the target website. Then, the user selects a vulnerability scanning tool in the terminal device according to the development framework indicated by the indication information. Furthermore, the server-side performs vulnerability scanning on the target website according to the vulnerability scanning tool selected by the user.
[0047] It should be noted that the method for identifying the development framework and the vulnerability scanning method provided in the present application are generally executed by the server 105. Correspondingly, the device for identifying the development framework and the vulnerability scanning device are generally set in the server 105. However, in other embodiments of the present application, the terminal device can also have a similar function as the server, so as to implement the method for identifying the development framework or the vulnerability scanning method provided in the present application.
[0048] The implementation details of the technical solutions of the embodiments of the present application are elaborated in detail below:
[0049] Figure 2 is a flowchart of a method for identifying a development framework shown according to an embodiment. The method for identifying the development framework can be executed by a device with computing and processing capabilities, such as Figure 1 the server 105 shown in Figure 2 As shown, the method for identifying the development framework includes at least steps 210 to 250, which are introduced in detail as follows:
[0050] Step 210, obtain the directory tree of the target website. The directory tree is constructed according to the hierarchical string of the target website, and the hierarchical string is obtained by splitting the URL of the page under the target website.
[0051] The websites involved in the present application, such as the above-mentioned target website and the sample website in the following text, refer to the websites developed based on the development framework. Among them, the target website does not specifically refer to a certain website, but generally refers to the website for which the corresponding development framework is to be identified and determined.
[0052] A development framework is a reusable design component that defines the architecture of an application, clarifies the overall design, the dependencies between collaborating components, the responsibility assignment, and the control flow. It is manifested as a set of abstract classes and the methods of collaboration between their instances (i.e., a set of abstract components and the methods of interaction between component instances), and it provides the context for component reuse.
[0053] The development framework implements the underlying services of general and complete functions (excluding the parts for special applications). Developers using the development framework can start specific application development based on the realization of general functions. The development framework provides a set of classes that represent the default behaviors expected by the application. The specific application supports application-specific behaviors by overriding subclasses (which belong to the default behaviors of the development framework) or assembling objects. This set of classes includes multiple comprehensive object-oriented reusable classes, such as interfaces, abstract classes, and concrete classes, etc. Given the class library provided by the development framework to implement basic functions, using the development framework for website development can improve development efficiency and ensure website quality.
[0054] For a website, it includes multiple pages, and each page has its corresponding URL. The URL (Uniform Resource Locator) of a page, also known as the web address of the page, is composed of a string of simple characters, and the URL of the page indicates the location of the page on the Internet.
[0055] Among them, the URLs of the pages under the target website are determined during the development of the target website using the development framework. Specifically, the development framework provides a URL generation tool, and during the development process, this URL generation tool is used to generate the URLs of the pages.
[0056] For example, in the Yii2 development framework, there is a built-in URL manager, namely urlManager, to generate URLs for pages. Another example is that the Laravel development framework provides a URL helper function to generate URLs for pages. The urlManager in the Yii2 development framework and the URL helper function in the Laravel development framework listed above are regarded as the URL generation tools provided by the development framework.
[0057] It can be understood that since the URLs of the pages are generated using the URL generation tool in the development framework during the website development process, the URLs generated by the development framework can reflect the characteristics of the development framework. There is a correlation between the URLs generated by the development framework and the development framework. Thus, to a certain extent, the generated URLs can reflect the development framework that generates them. Correspondingly, the URLs of the pages under the target website can reflect the development framework used to develop the target website.
[0058] Based on the correlation between the URL of the target website and the development framework, a solution is proposed to identify the development framework used to develop the target website based on the URL of each page of the target website.
[0059] The format of the URL is: schema: / / host:port / path?query#fragment. Specifically, the schema part is a protocol character segment, which is used to indicate the transmission protocol used to obtain the corresponding page, such as HTTP (Hypertext transfer protocol), HTTPS (Hypertext Transfer Protocol over Secure Socket Layer) and the like.
[0060] The host part is a domain name character segment, which is used to indicate the address of the server corresponding to the page. Specifically, the domain name character segment can be a domain name or an IP address (Internet Protocol Address).
[0061] The port part is a port character segment, which is used to indicate the network logical port. Different network protocols have their specific port numbers, for example, the port number of the http protocol is 80. Generally, the port part can be omitted in the URL.
[0062] The path part is a path character segment, which is used to indicate the complete path of the storage location of the page in the network. The string indicating the path may include more than two levels of paths, and each level of path is graded by " / ", and the path character segment also starts with " / ". In the path character segment, the last level of the path is a file name string, which is at least used to indicate the file name of the file where the page is located. Furthermore, the file name string may further include a file suffix.
[0063] The query part is a parameter segment, which is used to indicate the parameters transmitted to the server, for example, the search terms input by the user. A parameter segment in a URL can include multiple parameters, and the parameters are separated by "&". In a URL, the parameter segment starts with "?".
[0064] The fragment part is a fragment character segment, which is used to indicate the anchor point of the page. In the URL, the fragment character segment starts with "#". In the process of requesting a page, the fragment character segment does not need to be transmitted to the server. In the process of page browsing, the fragment character segment in the URL may change as the position on the page changes. Therefore, the anchor point is generally used to locate the page on the front end.
[0065] For example, if the URL of a page is: http: / / www.aspxfans.com:8080 / news / index.asp?boardID=5&ID=24618&page=1#name. For this URL, "http" is the protocol segment, www.aspxfans.com is the domain name segment, "8080" is the port segment, "boardID=5&ID=24618&page=1" is the parameter segment, and "name" is the fragment segment. "news / index.asp" is the path segment, where "news" is the first-level path and "index.asp" is the second-level path. In this second-level path, "index" is the file name and ".asp" is the file extension.
[0066] It is worth mentioning that not every page's URL includes all the components shown above. For example, the URL of the homepage of Tencent is: https: / / www.qq.com, which only includes the protocol segment and the domain name segment; for another example, the URL of a page is: http: / / www.infzm.com / contents / 183166. It can be seen that the URL of this page includes the protocol segment "http", the domain name segment "www.infzm.com" and the path segment "contents / 183166", but does not include the port segment, the parameter segment and the fragment segment. For a page, the necessary components in its URL include the protocol segment and the domain name segment.
[0067] As described above, the URL generated by the development framework can reflect the characteristics of the development framework, and the characteristics of the page's URL itself are reflected by the strings included in the URL. Therefore, it can also be understood that: the URL generated by the development framework reflects the characteristics of the development framework through the strings in the URL.
[0068] On this basis, in order to improve the efficiency and effectiveness of identifying the development framework, the URL of the page under the target framework is segmented to obtain hierarchical strings, so as to determine the string that can represent the development framework corresponding to the target website among multiple hierarchical strings under the target website.
[0069] As described above, the protocol character segment and the domain name character segment are separated by " / / ", the domain name character segment and the port character segment are separated by ":", the parameter character segment starts with "?", the fragment character segment starts with "#", and the path character segment starts with " / ". Moreover, the levels of the path are separated by " / ". Therefore, the above-listed " / / ", ":", "?", "#", and " / " can be used as delimiters to split the URL and obtain the hierarchical strings in the URL.
[0070] In this application, after splitting the URL of the page under the target website to obtain the hierarchical strings, a directory tree is further constructed for the target website, so as to reflect the situation of the hierarchical strings in the target website through the directory tree of the target website.
[0071] For a target website, the transport protocol required to obtain a page is an industry standard, the domain name and IP address of the target website are obtained through application and registration, and the port for requesting a page under the target website depends on the selected transport protocol. Therefore, the protocol character segment and the domain name character segment included in the URLs of each page under the same target website correspond identically. Of course, if the port character segment is not omitted, the port character segments in the URLs of each page are also the same. From this, it can also be seen that the protocol string, server address string, and port string in the URL of a page cannot reflect the relevance between the development frameworks used to develop the target website.
[0072] Then, the differences between the URLs of the pages under the target website are reflected by the path character segment and the subsequent character segments in the URL. Moreover, it is precisely the path character segment and the subsequent character segments in the URL that reflect the relevance between the URL and the development framework. Therefore, to create the directory tree of the target website, after establishing the root node, the hierarchical strings extracted from the path character segment and the subsequent character segments in each URL can be used as the content corresponding to each tree node under the root node, so as to construct the directory tree corresponding to the target website.
[0073] In a URL, the positions of the hierarchical strings have corresponding front-to-back orders. Therefore, to construct the directory tree of the target website, the corresponding relationship between the positions of the strings in the URL and the tree nodes in the directory tree is preset in advance, and then, according to the front-to-back order of the positions of the hierarchical strings in the URL, the hierarchical strings are sequentially written into the corresponding tree nodes.
[0074] Step 230, extract the characteristic string corresponding to the target website from the directory tree.
[0075] The characteristic string corresponding to the target website refers to the hierarchical string used in the target website to characterize the development framework utilized for developing the target website. It can be understood that the characteristic string corresponding to the target website can reflect the common characteristics of each URL under the target website. Thus, it indicates that this characteristic string is universal among the URLs under this target website. Among them, the number of characteristic strings extracted for the target website is not limited and can be one or multiple.
[0076] In an embodiment of the present application, the characteristic string can be determined according to the number of occurrences of the hierarchical string in the directory tree. Generally, the higher the number of occurrences of a hierarchical string in the directory tree, the more tree nodes occupied by this hierarchical string in the directory tree, further indicating a higher correlation between this hierarchical string and the development framework utilized for developing the target website, and thus indicating that this hierarchical string can better reflect the development framework corresponding to this target website.
[0077] In view of this, the hierarchical strings whose number of occurrences meets the set requirements can be correspondingly used as the characteristic strings corresponding to the target website according to the number of occurrences of each hierarchical string in the directory tree. For example, count the number of occurrences of each hierarchical string in the directory tree, then sort them in descending order of the number of occurrences, and use the hierarchical strings in the top set number of the sorting as the characteristic strings corresponding to the target website.
[0078] It is worth mentioning that among the URLs of the pages in the websites developed by each development framework, there may be some common strings, such as image, plugin, default. These common strings have a relatively high frequency of occurrence in the URLs of the pages in the websites developed by each development framework. Correspondingly, the occurrence times of this part of the common strings in the directory tree corresponding to the target website may also be relatively high. Therefore, in order to avoid the influence of this part of the common strings on the accuracy of identifying the development framework, based on determining the hierarchical strings whose number of occurrences meets the set requirements in the directory tree, filter out the common strings included in the hierarchical strings whose number of occurrences meets the set requirements, and use the remaining hierarchical strings after filtering as the characteristic strings corresponding to the target website.
[0079] In another embodiment of the present application, the characteristic string can also be determined according to the number of occurrences of the hierarchical string in the development framework and the weights configured for each level of tree nodes in the directory tree. Specifically, according to the probability that the characteristic string may appear at each position in the URL, based on the correspondence between the positions in the URL and the tree nodes in the directory tree, weights are pre-configured for each level of tree nodes. On this basis, for a hierarchical string, count the number of occurrences of this hierarchical string in each level of tree nodes, weight the number of occurrences of this hierarchical string in each level of tree nodes and the weight of this level of tree nodes to obtain the weighted number of times of this hierarchical string. Then determine the characteristic string corresponding to the target website according to the weighted number of times. For example, sort the weighted number of times corresponding to each hierarchical string from largest to smallest, and use the hierarchical strings in the top set number in the sorting as the characteristic strings corresponding to the target website.
[0080] In another embodiment of the present application, after determining the hierarchical strings in the directory tree whose number of occurrences meets the set requirements and filtering out the common strings included therein, the remaining hierarchical strings after filtering can also be combined, and the combined string obtained by combination is used as the characteristic string corresponding to the target website.
[0081] Step 250, identify the development framework used by the development target website according to the characteristic string.
[0082] Since the extracted characteristic string characterizes the development framework used by the development target website, this characteristic string can be used as an identification feature of the development framework to correspondingly identify the development framework used for developing this target website.
[0083] In the solution of the present application, based on the relevance between the URL of the target website and the development framework, a directory tree of the target website is constructed according to the hierarchical strings in the URL under the target website, and then the characteristic string corresponding to the target website can be extracted from the directory tree of the target website, and then the development framework used for developing this target website is identified and determined according to the characteristic string, realizing the rapid identification of the development framework. Thus, if subsequent vulnerability scanning needs to be performed on this target website, a vulnerability scanning tool adapted to this development framework can be correspondingly selected, so that the vulnerability scanning is more targeted and the efficiency of vulnerability scanning is improved.
[0084] In an embodiment of the present application, as Figure 3 shown, step 250 includes:
[0085] Step 310, perform string matching according to the characteristic string in the configuration file to determine a set of characteristic strings corresponding to the characteristic string.
[0086] The strings in the set of feature strings serve as the feature identifiers for recognizing the development framework associated with the set of feature strings. The configuration file includes a set of feature strings corresponding to each development framework, and based on this, the development framework is recognized.
[0087] The string matching performed refers to matching the feature string with the strings in the set of feature strings in the configuration file.
[0088] Determining the set of feature strings corresponding to the feature string is carried out according to the set corresponding rules. The corresponding rules can be: (1) If there is a string in the set of feature strings that is the same as the feature string, then the feature string is regarded as the set of feature strings corresponding to the feature string.
[0089] As described above, there can be multiple feature strings for the same target website. Therefore, the following situations may exist:
[0090] Situation I: In a set of feature strings, there are at least two strings that are the same as the feature string.
[0091] Situation II: There are at least two sets of feature strings, and in each set of feature strings, there is a string that is the same as the feature string.
[0092] In the above Situations I and II, the corresponding rules can also be: If the number of strings in a set of feature strings that are the same as the feature string meets the first set requirement, then the set of feature strings is regarded as the set of feature strings corresponding to the feature string. For Situation I above, the first set requirement can be that the number of strings the same as the feature string ≥ N (N is a positive integer). In Situation II above, the first set requirement can also be that the number of strings the same as the feature string is among the top M (M is a positive integer ≥ 1) in the sorting, where the sorting is in descending order according to the number of strings the same as the feature string.
[0093] Since there may be multiple feature strings for the target website, the set of feature strings determined to correspond to the feature string in step 310 may also be multiple. For example, the feature strings of the target website include feature string A and feature string B. By performing string matching in the configuration file, it is determined that there is a string in the set of feature strings P that is the same as feature string A, and there is a string in the set of feature strings Q that is the same as feature string B. If the set corresponding rule is the rule in (1) above, then the set of feature strings P is the set of feature strings corresponding to feature string A, and the set of feature strings Q is the set of feature strings corresponding to feature string B.
[0094] In summary, it can be seen that in the above step 310, the number of sets of feature strings determined for the target website and corresponding to the feature strings of the target website can be one or multiple, which varies depending on the number of feature strings of the target website and / or the set corresponding rules.
[0095] Step 330: Determine the development framework indicated by the framework identifier associated with the set of feature strings as the development framework used for developing the target website.
[0096] Through the above process, based on the correspondence between the set of feature strings and the development framework in the configuration file and the feature strings of the target website, the development framework used by the development target framework is quickly identified.
[0097] In an embodiment of the present application, as Figure 4 shown, before step 310, the method for identifying the development framework further includes:
[0098] Step 410: Obtain the first directory tree corresponding to each of a plurality of sample websites, and the framework identifier of the development framework corresponding to each sample website.
[0099] A sample website refers to a website used to generate the configuration file and whose corresponding development framework is known. The first directory tree refers to the directory tree corresponding to the sample website. The development framework corresponding to the sample website refers to the development framework used for developing the sample website.
[0100] Among them, the construction of the first directory tree is the same as the construction process of the directory tree of the target website, that is: first collect the URLs of the pages under the sample website; then split the URLs to obtain hierarchical strings; finally, construct the first directory tree of the sample website according to the hierarchical strings.
[0101] Step 430: For each sample website, determine the first feature string corresponding to the sample website according to the first directory tree.
[0102] The first feature string corresponding to the sample website refers to the hierarchical string in the sample website used to characterize the development framework used for developing the sample website.
[0103] In an embodiment of the present application, as Figure 5 shown, step 430 includes:
[0104] Step 510: Count the occurrence times of each hierarchical string in the first directory tree corresponding to the sample website.
[0105] Step 530: According to the counted occurrence times, determine the first hierarchical string whose occurrence times in the first directory tree exceed the first threshold.
[0106] The first hierarchical string refers to the hierarchical string that appears more than the first threshold in the corresponding directory tree. It can be understood that the hierarchical string that appears more than the first threshold in the first directory tree corresponding to the sample website may be one or more.
[0107] As described above, if the number of occurrences of a hierarchical string in the directory tree is higher, it indicates that the relevance between the hierarchical string and the development framework used for developing the target website may be higher, and further indicates that the probability that the hierarchical string can reflect the development framework corresponding to the target website is higher. Thus, through step 530, the hierarchical string with a relatively high relevance to the development framework used for developing the sample website is determined from the first directory tree corresponding to the sample website, that is, the first hierarchical string.
[0108] Step 550, filter the common strings in the first hierarchical string to obtain the distinguishing string corresponding to the sample website.
[0109] As described above, the common string refers to the string that is common in the URLs of the pages in the websites developed by each development framework. This common string is the common string in the URLs generated by each development framework, and this common string cannot reflect the relevance between the URL and the development framework. Thus, the common strings in the first hierarchical string are filtered out first.
[0110] The distinguishing string corresponding to the sample website refers to the remaining first hierarchical string after filtering out the common strings in the first hierarchical string corresponding to the sample website.
[0111] It can be understood that before step 550, it is further necessary to construct a common string set, and thus, based on this common string set, the filtering of the common strings in the first hierarchical string corresponding to the sample website is realized.
[0112] Specifically, for multiple development frameworks, collect the URLs of the pages in the websites developed by each development framework, then split the collected URLs to obtain hierarchical strings, and correspondingly obtain the string set corresponding to each development framework. The elements in the string set corresponding to the development framework are the hierarchical strings in the websites developed by the development framework. On this basis, analyze the strings in each string set. If the number of occurrences and / or the occurrence frequency of a string in multiple string sets exceed a set threshold, then determine the string as a common string and put it into the common string set. The occurrence frequency of a string (assumed to be string C) in multiple string sets can be equal to the number of string sets including string C / the total number of string sets.
[0113] Step 570, determine the first feature string corresponding to the sample website according to the distinguishing string.
[0114] Since the difference string can reflect the association with the development framework corresponding to the sample website, accordingly, the first feature string corresponding to the sample website is determined according to the difference string.
[0115] In an embodiment of the present application, the difference string can be directly used as the first feature string corresponding to the sample website. On the one hand, the difference string appears a relatively high number of times in the first directory tree corresponding to the sample website. On the other hand, the difference string is not a common string, and the difference string reflects the commonality of the URLs in the sample website where it is located. Therefore, the difference string can be used as the first feature string corresponding to the sample website to represent the feature string of the development framework used to develop the sample website.
[0116] In another embodiment of the present application, there are at least two difference strings corresponding to the sample website, and step 570 above may include: combining at least two difference strings to obtain a combined string; using the combined string as the first feature string corresponding to the sample website.
[0117] Since both difference strings in the combined string have a relatively high association with the development framework corresponding to the developed sample website, compared with a single difference string, the combined string can better represent the development framework used for the developed sample website.
[0118] Correspondingly, if in the configuration file, the combined string is used as an element in the set of feature strings corresponding to a development framework in the configuration file, and the combined string is used as the matching target, it is equivalent to enhancing the string matching constraint, thereby improving the accuracy of development framework recognition.
[0119] Among them, the combination performed can be to connect at least two difference strings according to a set connector. For example, if the difference strings corresponding to the sample website include: wp-content and themes, then “ / ” can be used as the connector to combine the two difference strings into a combined string: wp-content / themes. Another example is that if the difference strings corresponding to the sample website include: wp-content, themes, and uploads, then the following two combined strings can be obtained: wp-content / themes and wp-content / uploads.
[0120] In another embodiment of the present application, there are at least two difference strings corresponding to the sample website, and step 570 includes: combining at least two difference strings to obtain a combined string; counting the combined occurrence times of the difference strings included in the combined string in the first directory tree corresponding to the sample website; and taking the combined string whose combined occurrence times meet the set number requirement as the first feature string corresponding to the sample website.
[0121] Among them, the combined occurrence times of the difference strings included in the combined string in the first directory tree corresponding to the sample website can be determined by counting the number of tree branches. Specifically, in the first directory tree corresponding to the sample website, count the number of tree branches where all the difference strings included in the combined string exist at the same time, and the counted number of tree branches is equal to the combined occurrence times corresponding to the combined string.
[0122] Compared with the above embodiments in which a single difference string or directly the combined string is used as the first feature string corresponding to the sample website, in this embodiment, the combined string whose combined occurrence times meet the set number requirement is used as the first feature string corresponding to the sample website. As the determined first feature string, it can better represent the development framework used to develop the sample website. Correspondingly, if in the configuration file, this combined string whose combined occurrence times meet the set number requirement is used as an element in the feature string set corresponding to a development framework in the configuration file, the accuracy of development framework recognition can be further improved.
[0123] The above process of determining the first feature string according to the sample website is equally applicable to the process of determining the corresponding feature string according to the directory tree of the target website.
[0124] Step 450, determine the feature string set corresponding to each development framework according to the first feature string corresponding to the sample website and the framework identifier corresponding to the sample website.
[0125] Since there is a corresponding relationship between the first feature string and the sample website, and there is a corresponding relationship between the sample website and the framework identifier (which can also be understood as the development framework), therefore, taking the sample website as a medium, the framework identifier corresponding to the first feature string can be used as an attribute of the first feature string to determine the corresponding relationship between the first feature string and the development framework, and then determine the feature string set corresponding to each development framework.
[0126] Step 470, associate the feature string set with the framework identifier of the corresponding development framework to obtain a configuration file.
[0127] Thus, the configuration file includes a set of feature strings respectively constructed for each development framework. Furthermore, it is convenient to use this configuration file as the basis for identifying the development framework to accurately identify the development framework.
[0128] In an embodiment of the present application, as Figure 6 shown, step 450 includes:
[0129] Step 610, classify the first feature strings according to the framework identifier to obtain an initial set of feature strings corresponding to each development framework.
[0130] Since the first feature strings correspond to sample websites, and the sample websites correspond to development frameworks, thus, taking the sample websites as a medium, a correspondence relationship between the first feature strings and the development frameworks is constructed. On this basis, several first feature strings having a mapping relationship with the same development framework are grouped into the same set, and this set is the initial set of feature strings corresponding to this development framework.
[0131] Step 630, sort the first feature strings in the initial set of feature strings in descending order according to the number of sample websites associated with the first feature strings in the initial set of feature strings.
[0132] The initial set of feature strings may include multiple first feature strings, and the relevance of each first feature string in the initial set of feature strings to the development framework associated with this initial set of feature strings is different. Therefore, in order to ensure the accuracy and recognition efficiency of identifying the development framework based on the configuration file, it is further necessary to determine the first feature strings in the initial set of feature strings that have a high relevance to the associated development framework.
[0133] In the initial set of feature strings corresponding to a development framework, the more the number of sample websites associated with a first feature string, the higher the relevance between this first feature string and the development framework associated with the initial set of feature strings where it is located. Correspondingly, this first feature string can better represent the associated development framework.
[0134] Therefore, sort the first feature strings in the initial set of feature strings according to the number of sample websites associated with the first feature strings, so as to correspondingly determine the sorting of the relevance levels between each first feature string in this initial set of feature strings and the development framework associated with this initial set of feature strings.
[0135] Step 650, obtain the first feature strings ranked in the top set number in the initial feature set.
[0136] Generally speaking, in the initial set of feature strings, the larger the number of sample websites associated with the first feature string, the higher the relevance of the first feature string to the development framework corresponding to the sample websites. Based on this, the first feature strings ranked in the top set number obtained from the initial feature set are the feature strings with a higher relevance to the corresponding development framework. Among them, the set number can be set according to actual needs and will not be specifically limited here.
[0137] Step 670, use the obtained first feature string as an element in the set of feature strings of the corresponding development framework.
[0138] By sorting the first feature strings in the initial set of feature strings according to the number of sample websites associated with the first feature strings as described above, and then obtaining the first feature strings from the obtained sorting, it is possible to determine the first feature strings in the initial set of feature strings that have a high relevance to the development framework corresponding to the initial set of feature strings, that is, the first feature strings ranked in the top set number obtained.
[0139] When using the obtained first feature string as an element in the set of feature strings of the corresponding development framework, it can ensure that the identification of the development framework based on this set of feature strings is more targeted. Moreover, compared with using the initial set of feature strings as the set of feature strings of the corresponding development framework to identify the development framework, the relevance between each string in the set of feature strings determined in this embodiment and the development framework is higher. Therefore, the efficiency of identifying the development framework and the efficiency of performing the development framework identification can be improved.
[0140] In an embodiment of the present application, as Figure 7 shown, before step 210, the method for identifying the development framework further includes:
[0141] Step 710, obtain access data for the target website. The access data includes multiple access records, and each access record includes the URL of the page under the accessed target website.
[0142] Step 730, split the identification character segment in the URL according to the delimiter in the URL to obtain a number of hierarchical strings.
[0143] The identification character segment in the URL refers to the character segment that can be used to distinguish different URLs under the target website. As described above, in the URLs of each page under the same target website, the protocol character segment and the domain name character segment are the same. Of course, if the port character segment is not omitted, the port character segments in the URLs of each page are also the same. Therefore, specifically, the identification character segment in the URL refers to the other character segments in the URL except the protocol character segment, the domain name character segment, and the port character segment.
[0144] As described above, in a URL, the parameter field starts with "?", parameters in the parameter field are separated by "&", the fragment field starts with "#", the path field starts with " / ", and levels of paths are separated by " / ". Therefore, the "?", "#", " / ", and "&" in the above can be used as delimiters to split the identifier fields in the URL, obtaining the hierarchical strings in the URL.
[0145] Of course, in addition to using the symbols listed above as delimiters, splitting can also be performed according to the structure of the character fields. For example, the last-level path in the path field may be a file name field, which may include a file name and a file extension, and the file extension generally starts with ".", so based on the composition structure of the file name field, "." can be used as a delimiter to split the file name field into two strings, namely the file name and the file extension.
[0146] Step 750, construct a directory tree of the target website according to the hierarchical strings in the URL.
[0147] After obtaining the hierarchical strings in each URL of the target website, write the hierarchical strings into the corresponding tree nodes in the directory tree of the target website according to the positions of the hierarchical strings in the URL, thereby realizing the construction of the directory tree of the target website.
[0148] In an embodiment of the present application, as Figure 8 shown, step 750 includes:
[0149] Step 810, determine the sub-path in the URL according to the splitting of the identifier fields in the URL, and the path starting point of the sub-path is the first-level path in the URL.
[0150] In the splitting performed in step 730, the positions of the delimiters are used as splitting positions. Thus, the strings between adjacent splitting positions are used as hierarchical strings. Of course, for the first splitting position, the string before the first splitting position in the identifier field is also a hierarchical string, and for the last splitting position, the string after the last splitting position is also a hierarchical string. Further, in this embodiment, the splitting position can also be used as the hierarchical symbol for path grading, thereby realizing path grading and determining the sub-path in the URL.
[0151] Wherein, the path starting point of each sub-path is the first-level path in the URL, and the end point of the path is the string before the corresponding hierarchical symbol.
[0152] For example, if the URL of a page is: http: / / www.aspxfans.com:8080 / news / index.asp. As described above, the identification character segment in the URL is the other character segments except the protocol character segment, the domain name character segment, and the port character segment, that is: / news / index.asp. If it is split using " / ", "?", and "#" as delimiters, then the following sub-paths can be obtained: Sub-path I: / news; Sub-path II: / news / index.asp.
[0153] Step 830, count the number of occurrences of each sub-path in the access data to determine the first sub-path whose number of occurrences is greater than the second threshold.
[0154] The first sub-path refers to the sub-path under the target website whose number of occurrences in the access data exceeds the second threshold. The second threshold can be set according to actual needs and will not be specifically limited here.
[0155] If a sub-path appears in different URLs, it means that this sub-path under the target website is universal and can represent the general composition structure of the URLs under the target website, and the general composition structure of the URLs under the target website can reflect the development framework corresponding to the target website to a certain extent.
[0156] On this basis, count the number of occurrences of each sub-path in the access data, and then determine the first sub-path whose number of occurrences is greater than the second threshold. Then, the determined first sub-path can represent the general composition structure of the URLs under the target website.
[0157] Step 850, write the hierarchical strings in the first sub-path into the corresponding tree nodes in the directory tree corresponding to the target website according to the positions of the hierarchical strings in the first sub-path.
[0158] Since the determined first sub-path can represent the general composition structure of the URLs under the target website, thus, writing the hierarchical strings in the first sub-path into the corresponding tree nodes in the directory tree of the target website can correspondingly ensure that the hierarchical strings in the directory tree can represent the general composition structure of the URLs under the target website, and thus, it is convenient to extract the characteristic strings of the target website from this directory tree.
[0159] In an embodiment of the present application, as Figure 9 shown, after step 750, the method for identifying the development framework further includes:
[0160] Step 910, obtain the new access data collected for the target website.
[0161] Step 930, construct a second directory tree for the target website according to the new access data.
[0162] For the construction of the directory tree of the target website, since it involves the collection of URLs under the target website, therefore, the collection of URLs may be carried out in time periods. In this case, the directory tree of the target website can be updated in time periods.
[0163] Specifically, after collecting the access data of the target website for a time period, first initially construct the directory tree corresponding to the target website according to the collected access data in the above process. Then, in the subsequent process, construct the second directory tree of the target website according to the newly collected access data for the target website.
[0164] The process of constructing the second directory tree for the target website according to the newly collected access data is the same as the above process of constructing the directory tree, which will not be elaborated here. It is worth mentioning that the root node of the constructed second directory tree is the same as that of the initially constructed directory tree.
[0165] Step 950, merge the second directory tree into the directory tree to update the directory tree.
[0166] By merging the second directory tree of the target website into the directory tree of the target website, the update of the directory tree of the target website is realized.
[0167] The following specifically describes the method for identifying the development framework of the present application in combination with a specific embodiment:
[0168] Figure 10 is a flowchart of identifying the development framework shown in a specific embodiment. As Figure 10 shown, it specifically includes steps 1010-1090, which are introduced in detail as follows:
[0169] Step 1010, obtain user access data including the URLs of the accessed pages every hour.
[0170] In a specific embodiment, since the amount of user access data obtained every hour is large, more than several billion per hour, correspondingly, the data processing volume is also large. To ensure the speed of data processing, the method of this embodiment is implemented in the Spark system, and the original user access data is stored in a distributed hive table.
[0171] Step 1020, classify the URLs according to the same domain name.
[0172] The user access data obtained in the above step 1010 may be data under multiple domain names (websites). Therefore, classify the URLs according to the domain name to obtain the URLs corresponding to each domain name.
[0173] Step 1030, create a dictionary for each domain name to store the directory tree of the domain name.
[0174] Store the directory tree corresponding to the domain name through a dictionary, so that all branch relationships in the directory tree can be completely saved. Since there are multiple parent nodes and child nodes in the directory tree, and there are also multiple corresponding branches, it is difficult for ordinary structured data to store all the parent-child branch relationships.
[0175] Step 1040: Split the URL.
[0176] The splitting can refer to the Figure 7 URL splitting process involved in the corresponding embodiment above. By splitting the URL, several hierarchical strings are correspondingly obtained.
[0177] Step 1050: Count the occurrence times of each sub-path in all URLs under the same domain name.
[0178] The path location of each sub-path is the first-level path in the URL where it is located, and the path end point is the hierarchical string before the separator. In the process of counting the occurrence times of sub-paths, it is required not only that the path end points in two sub-paths are the same, but also that each level of path before the path end point is the same.
[0179] Step 1060: If the occurrence times of the sub-path are greater than a certain threshold, then incorporate the hierarchical string in the sub-path into the directory tree of the domain name.
[0180] The threshold can be set according to actual needs. For example, the threshold is 20.
[0181] Step 1070: Merge the newly added directory tree corresponding to the domain name and the previous directory tree.
[0182] Since there is a large amount of newly added access data every hour, therefore, the newly added directory tree constructed by the newly added access data for the domain name is merged with the previously constructed directory tree for the domain name to realize the update of the directory tree. In the merging process, it is necessary to compare the hierarchical strings and all the previous paths one by one to ensure the accuracy of the directory tree merging and avoid deviations.
[0183] Figure 11 It is a schematic diagram of the directory tree constructed for the domain name. As Figure 11 shown, on the left is the domain name, which is used to identify the website, and on the right is the directory tree constructed corresponding to the domain name.
[0184] Through the above steps 1010 - 1070, the construction of the directory tree of the website identified by the domain name is realized.
[0185] After constructing the directory tree corresponding to the domain name, the feature string representing the development framework can be extracted from the directory tree through the following steps 1081-1083 or 1082-1084, that is, feature extraction is performed.
[0186] Step 1081, count the occurrence times of each hierarchical string in the directory tree.
[0187] Step 1083, determine the hierarchical strings that can represent the development framework.
[0188] In steps 1081-1083, by counting the occurrence times of each hierarchical string in the directory tree, the hierarchical strings in the directory tree with occurrence times higher than the times threshold can be determined. Since the occurrence times of this part of hierarchical strings are relatively high, the higher the probability that the hierarchical string can represent the development framework. It is worth mentioning that the occurrence times of some general strings are also relatively high. General strings such as image, plugin, default. Therefore, after determining the hierarchical strings with occurrence times higher than the times threshold, filter out the general strings among them, and then use the filtered hierarchical strings as the hierarchical strings that can represent the development framework, that is, the feature strings.
[0189] In the above steps 1081-1083, only single-layer hierarchical strings are extracted, and the context relationship of the hierarchical strings is not considered. The determination process of the feature strings is simple and fast. In practice, it is found that single-layer hierarchical strings can already represent the development framework adopted by the website in many scenarios.
[0190] Step 1082, count the occurrence times of combinations of multiple hierarchical strings.
[0191] Step 1084, combine multiple hierarchical strings to obtain a combined string.
[0192] In the process of the above steps 1082-1084, after determining the hierarchical strings in the directory tree with occurrence times higher than the times threshold and filtering out the general strings among them, count the occurrence times of combinations of multiple hierarchical strings in the directory tree to correspondingly determine the combined strings that can represent the development framework. For example, combine multiple hierarchical strings with combined occurrence times exceeding the first times threshold, and use the combined string as the combined string that can represent the development framework.
[0193] Through the above steps 1082-1084, it is equivalent to mining the relationships between multiple hierarchical strings. Thus, using the determined combined strings to represent the development framework can ensure accurate matching and positioning, and ensure the accuracy of development framework recognition.
[0194] In the process of completing the above feature extraction, the development framework is identified through step 1090. In step 1090, the development framework is identified according to the hierarchical string or combined string that can characterize the development framework.
[0195] In one embodiment, in order to identify the development framework according to the hierarchical string or combined string that characterizes the development framework, a configuration file is generated in advance according to the hierarchical string in the URL of the sample website and the framework identifier of the development framework corresponding to the sample website. The configuration file configures a set of feature strings for each development framework, and the strings in the set of feature strings can be used as strings to identify the development framework. Then, in step 1090, if the feature string of a domain name (the hierarchical string determined through steps 1081 - 1083 or the combined string determined through steps 1082 - 1084) matches (for example, is the same as) the string in a certain set of feature strings, then the development framework corresponding to the set of feature strings is the development framework for developing the website corresponding to the feature string.
[0196] Table 1 is a correspondence table showing the correspondence between development frameworks and strings identifying development frameworks according to one embodiment.
[0197] Development framework String identifying the development framework php _upload.php wordpress wp-content, wp-includes ASP.NET .aspx jsp .jsp avatar avatar jquery jquery javascript javascript vendor vendor ueditor ueditor frontend frontend banner banner lottery lottery workflow workflow
[0198] Table 1
[0199] After constructing the correspondence in Table 1, the identification of the development framework corresponding to the website can be realized by corresponding the feature strings extracted from the directory tree of the website with the correspondence in Table 1.
[0200] It should be noted that Table 1 only exemplarily shows some development frameworks and strings identifying development frameworks. Further, according to the method in the above embodiments of the present application, more strings identifying development frameworks can be further discovered.
[0201] Figure 12 is a flowchart of a vulnerability scanning method shown according to one embodiment. The vulnerability scanning method can be executed by a device with computing and processing capabilities, such as Figure 1 the server 105 shown in Figure 12 As shown, the vulnerability scanning method at least includes steps 1210 to 1250, which are introduced in detail as follows:
[0202] Step 1210, identify the development framework used by the target website to be developed according to the method of identifying the development framework in any of the above embodiments.
[0203] Step 1230, determine the scanning tool adapted to the development framework in the set of scanning tools.
[0204] Step 1250: Perform vulnerability scanning on the target website using the determined scanning tool.
[0205] Vulnerability scanning of a website requires selecting a scanning tool adapted to the development framework used for developing the website to perform targeted vulnerability scanning on the website. In the related art, since there is no effective method to identify the development framework used for developing the website, before performing vulnerability scanning on the target website, it is necessary to try scanning tools corresponding to multiple development frameworks to determine the development framework applicable to the target website. In this method, since it is necessary to try scanning tools corresponding to multiple development frameworks, the vulnerability scanning is time-consuming and, moreover, the vulnerability scanning speed is slow.
[0206] In the vulnerability scanning method of this embodiment, before performing vulnerability scanning, the development framework used for developing the target website is identified and determined according to the feature string extracted from the directory tree of the target website. On this basis, the target website is scanned for vulnerabilities using a scanning tool adapted to the development framework. Since it is not necessary to try multiple scanning tools before performing vulnerability scanning to determine the scanning tool adapted to the target website, the time spent on vulnerability scanning is significantly shortened, and the efficiency of vulnerability scanning is effectively improved.
[0207] The following introduces the device embodiment of the present application, which can be used to execute the method in the above embodiments of the present application. For details not disclosed in the device embodiment of the present application, please refer to the above method embodiment of the present application.
[0208] Figure 13 is a block diagram of a device for identifying a development framework shown according to an embodiment, as Figure 13 shown, the device for identifying a development framework includes:
[0209] A directory tree acquisition module 1310, configured to acquire the directory tree of the target website, where the directory tree is constructed according to the hierarchical string of the target website, and the hierarchical string is obtained by splitting the URL of the page under the target website.
[0210] A feature extraction module 1330, configured to extract the feature string corresponding to the target website from the directory tree.
[0211] An identification module 1350, configured to identify the development framework used for developing the target website according to the feature string.
[0212] In an embodiment of the present application, the identification module 1350 includes: a matching unit, configured to perform string matching in the configuration file according to the feature string to determine the feature string set corresponding to the feature string; a determination unit, configured to determine the development framework indicated by the framework identifier associated with the feature string set as the development framework used for developing the target website.
[0213] In one embodiment of the present application, the device for identifying a development framework further includes: a first directory tree obtaining module, configured to obtain the first directory trees respectively corresponding to a plurality of sample websites, and the framework identifiers of the development frameworks corresponding to each sample website; a first feature string determining module, configured to, for each sample website, determine a first feature string corresponding to the sample website according to the first directory tree; a feature string set determining module, configured to determine a feature string set corresponding to each development framework according to the first feature string corresponding to the sample website and the framework identifier corresponding to the sample website; and an association module, configured to associate the feature string set with the framework identifier of the corresponding development framework to obtain a configuration file.
[0214] In one embodiment of the present application, the first feature string determining module includes: a statistics unit, configured to count the occurrence times of each hierarchical string in the first directory tree corresponding to the sample website; a first hierarchical string determining unit, configured to determine a first hierarchical string whose occurrence times in the first directory tree exceed a first threshold according to the counted occurrence times; a filtering unit, configured to filter out the common strings in the first hierarchical string to obtain a difference string corresponding to the sample website; and a first feature string determining unit, configured to determine a first feature string corresponding to the sample website according to the difference string.
[0215] In one embodiment of the present application, the first feature string determining unit is configured to use the difference string as the first feature string corresponding to the sample website.
[0216] In one embodiment of the present application, there are at least two difference strings, and the first feature string determining unit is configured to: combine at least two difference strings to obtain a combined string; count the combined occurrence times of the difference strings included in the combined string in the first directory tree corresponding to the sample website; and use the combined string whose combined occurrence times meet the set number requirement as the first feature string corresponding to the sample website.
[0217] In one embodiment of the present application, the feature string set determining module includes: a classification unit, configured to classify the first feature strings according to the framework identifiers to obtain an initial feature string set corresponding to each development framework; a sorting unit, configured to sort the first feature strings in the initial feature string set in descending order according to the number of sample websites associated with the first feature strings in the first feature string set; an obtaining unit, configured to obtain the first feature strings whose sorting positions in the initial feature set are among the top set number; and a feature string set determining unit, configured to use the obtained first feature strings as elements in the feature string set corresponding to the corresponding development framework.
[0218] In one embodiment of the present application, the device for identifying a development framework further includes: an access data acquisition module, configured to acquire access data for a target website, where the access data includes a plurality of access records, and the access record includes the URL of the page under the accessed target website; a path segmentation module, configured to segment the identification character segment in the URL according to the delimiter in the URL to obtain a plurality of hierarchical strings; and a directory tree construction module, configured to construct a directory tree of the target website according to the hierarchical strings in the URL.
[0219] In one embodiment of the present application, the directory tree construction module includes: a sub-path determination unit, configured to determine the sub-path in the URL according to the segmentation of the identification character segment in the URL, where the starting point of the sub-path is the first-level path in the URL; an occurrence frequency statistics unit, configured to count the occurrence frequency of each sub-path in the access data to determine the first sub-path whose occurrence frequency is greater than a second threshold; and a writing unit, configured to write the hierarchical strings in the first path into the corresponding tree nodes in the directory tree corresponding to the target website according to the positions of the hierarchical strings in the first sub-path.
[0220] In one embodiment of the present application, the device for identifying a development framework further includes: a new access data acquisition module, configured to acquire new access data collected for the target website; a second directory tree construction module, configured to construct a second directory tree for the target website according to the new access data; and a merging module, configured to merge the second directory tree into the directory tree to update the directory tree.
[0221] Figure 14 is a block diagram of a vulnerability scanning device shown according to an embodiment, as Figure 14 shown, the vulnerability scanning device includes:
[0222] A development framework identification module 1410, configured to identify the development framework used for developing the target website according to the method for identifying a development framework in any of the above embodiments.
[0223] A scanning tool determination module 1430, configured to determine a scanning tool adapted to the development framework from a set of scanning tools.
[0224] A vulnerability scanning module 1450, configured to perform a vulnerability scan on the target website through the determined scanning tool.
[0225] The implementation processes of the functions and roles of each module / unit in the above device are specifically described in detail in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.
[0226] It is understood that these modules can be implemented by hardware, software, or a combination of both. When implemented in hardware, these modules can be implemented as one or more hardware modules, such as one or more application-specific integrated circuits. When implemented in software, these modules can be implemented as one or more computer programs executed on one or more processors.
[0227] Figure 15 FIG. shows a schematic structural diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application.
[0228] It should be noted that Figure 15 the computer system 1500 of the illustrated electronic device is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.
[0229] As Figure 15 shown, the computer system 1500 includes a central processing unit (CPU) 1501, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1502 or the program loaded from the storage section 1508 into the random access memory (RAM) 1503, such as executing the methods in the above embodiments. In the RAM 1503, various programs and data required for system operation are also stored. The CPU 1501, ROM 1502, and RAM 1503 are connected to each other via a bus 1504. An input / output (I / O) interface 1505 is also connected to the bus 1504.
[0230] The following components are connected to the I / O interface 1505: an input section 1506 including a keyboard, a mouse, etc.; an output section 1507 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1508 including a hard disk, etc.; and a communication section 1509 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 1509 performs communication processing via a network such as the Internet. A drive 1510 is also connected to the I / O interface 1505 as needed. A removable medium 1511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1510 as needed so that a computer program read from it can be installed into the storage section 1508 as needed.
[0231] In particular, according to an embodiment of the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present application includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication section 1509 and / or installed from the removable medium 1511. When the computer program is executed by the central processing unit (CPU) 1501, various functions defined in the system of the present application are performed.
[0232] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0233] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0234] The units involved in the embodiments described in the present application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not, in some cases, constitute a limitation on the units themselves.
[0235] On the other hand, the present application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiments; or may exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device is caused to implement the method for identifying a development framework or the vulnerability scanning method in the above embodiments.
[0236] It should be noted that although several modules or units of devices for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0237] From the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.
[0238] After considering the specification and practicing the disclosed embodiments herein, those skilled in the art will readily conceive of other embodiments of the present application. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include common general knowledge or conventional technical means in the technical field not disclosed in the present application.
[0239] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A method for identifying a development framework, characterized in that, Including: Obtain the directory tree of the target website, where the directory tree is constructed according to the hierarchical string of the target website, and the hierarchical string is obtained by splitting the URL of the page under the target website; Extract the feature string corresponding to the target website from the directory tree; Perform string matching in the configuration file according to the feature string to determine the set of feature strings corresponding to the feature string; Determine the development framework used to develop the target website as the development framework indicated by the framework identifier associated with the set of feature strings; Wherein, there are multiple feature strings; the performing string matching in the configuration file according to the feature string to determine the set of feature strings corresponding to the feature string includes: If it is detected that the number of strings identical to the feature string in the set of feature strings included in the configuration file is greater than the preset number threshold, then use the detected set of feature strings as the set of feature strings corresponding to the feature string; Wherein, before performing string matching in the configuration file according to the feature string to determine the set of feature strings corresponding to the feature string, the method further includes: Obtain the first directory tree corresponding to each of multiple sample websites, and the framework identifier of the development framework corresponding to each sample website; For each sample website, determine the first feature string corresponding to the sample website according to the first directory tree; According to the first feature string corresponding to the sample website and the framework identifier corresponding to the sample website, determine the set of feature strings corresponding to each development framework; Associate the set of feature strings with the framework identifier of the corresponding development framework to obtain the configuration file.
2. The method according to claim 1, characterized in that, The determining the first feature string corresponding to the sample website according to the first directory tree includes: Count the occurrence times of each hierarchical string in the first directory tree corresponding to the sample website; According to the counted occurrence times, determine the first hierarchical string whose occurrence times in the first directory tree exceed the first threshold; Filter out the common strings in the first hierarchical string to obtain the difference string corresponding to the sample website; Determine the first feature string corresponding to the sample website according to the difference string.
3. The method according to claim 2, wherein The determining the first feature string corresponding to the sample website according to the difference string includes: Use the difference string as the first feature string corresponding to the sample website.
4. The method according to claim 2, wherein There are at least two difference strings, and the determining the first feature string corresponding to the sample website according to the difference string includes: Combine at least two of the difference strings to obtain a combined string; Count the combined occurrence times of the difference strings included in the combined string in the first directory tree corresponding to the sample website; Use the combined string whose combined occurrence times meet the set number requirement as the first feature string corresponding to the sample website.
5. The method according to claim 1, characterized in that, Determining a set of feature strings corresponding to each development framework according to the first feature string corresponding to the sample website and the framework identifier corresponding to the sample website includes: Classifying the first feature string according to the framework identifier to obtain an initial set of feature strings corresponding to each development framework; Sorting the first feature strings in the initial set of feature strings in descending order according to the number of sample websites associated with the first feature strings in the initial set of feature strings; Obtaining the first feature strings ranked among the top set number in the initial feature set; Taking the obtained first feature strings as elements in the set of feature strings corresponding to the corresponding development framework.
6. The method according to claim 1, characterized in that, Before obtaining the directory tree of the target website, the method further includes: Obtaining access data for the target website, where the access data includes a plurality of access records, and the access records include the URLs of the pages accessed under the target website; Splitting the identification character segments in the URL according to the delimiter in the URL to obtain a number of hierarchical strings; Constructing the directory tree of the target website according to the hierarchical strings in the URL.
7. The method according to claim 6, characterized in that, Constructing the directory tree of the target website according to the hierarchical strings in the URL includes: Determining a sub-path in the URL according to the splitting of the identification character segments in the URL, where the starting point of the sub-path is the first-level path in the URL; Counting the number of occurrences of each sub-path in the access data to determine a first sub-path with the number of occurrences greater than a second threshold; Writing the hierarchical strings in the first sub-path into the corresponding tree nodes in the directory tree corresponding to the target website according to the positions of the hierarchical strings in the first sub-path.
8. The method according to claim 6, characterized in that, After constructing the directory tree of the target website according to the hierarchical strings in the URL, the method further includes: Obtaining new access data collected for the target website; Constructing a second directory tree for the target website according to the new access data; Merging the second directory tree into the directory tree to update the directory tree.
9. An apparatus for identifying a development framework, characterized in that, The device includes: A directory tree acquisition module for acquiring a directory tree of a target website, where the directory tree is constructed according to hierarchical strings of the target website, and the hierarchical strings are obtained by splitting the URLs of the pages under the target website; A feature extraction module for extracting a feature string corresponding to the target website from the directory tree; An identification module for performing string matching in a configuration file according to the feature string to determine a set of feature strings corresponding to the feature string; and determining the development framework indicated by the framework identifier associated with the set of feature strings as the development framework used to develop the target website. Among them, there are multiple described feature strings; the determining of the feature string set corresponding to the feature string by performing string matching in the configuration file according to the feature string includes: if it is detected that the number of strings identical to the feature string in the feature string set included in the configuration file is greater than a preset number threshold, then the detected feature string set is used as the feature string set corresponding to the feature string; Among them, before the determining of the feature string set corresponding to the feature string by performing string matching in the configuration file according to the feature string, it further includes: obtaining the first directory tree corresponding to each of multiple sample websites, and the framework identifier of the development framework corresponding to each sample website; for each sample website, determining the first feature string corresponding to the sample website according to the first directory tree; determining the feature string set corresponding to each development framework according to the first feature string corresponding to the sample website and the framework identifier corresponding to the sample website; associating the feature string set with the framework identifier of the corresponding development framework to obtain the configuration file.
10. An electronic device, characterized in that, Including: A processor; And A memory, on which computer-readable instructions are stored, and when the computer-readable instructions are executed by the processor, the method according to any one of claims 1 to 8 is implemented.
11. A computer-readable storage medium, characterized in that, On which computer-readable instructions are stored, and when the computer-readable instructions are executed by the processor, the method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Website clustering and vulnerability scanning method and device, electronic equipment and storage medium
CN109583211A