A method, device, equipment and readable storage medium for detecting attack behavior
By obtaining the current operation sequence of the target system and the frequent multi-item set matching judgment, the problem of timely detecting attack behavior in the existing technology without increasing the system logic complexity is solved, and efficient and real-time attack behavior detection is achieved.
Patent Information
- Application Number
- CN202111241239.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-25
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2041-10-25
AI Technical Summary
The existing attack behavior detection technology promptly detects attack behavior without increasing the complexity of the system logic.
通过获取目标系统的当前操作序列,并与预先挖掘出的频繁多项集进行匹配判断,若存在攻击特征,则确定当前操作序列存在攻击行为。
It realizes timely detection of attack behavior without increasing the complexity of the system logic, reduces system losses, and improves real-time response capabilities to attack behavior.
Smart Images

Figure CN113971286B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of attack detection, and more specifically, to an attack behavior detection method, device, equipment and readable storage medium. Background Art
[0002] With the rapid development of mobile Internet, various faults or vulnerabilities are inevitably contained in the agile iteration process of Internet services. Therefore, while people enjoy the convenient services of various applications, they also bring various security issues, such as crawlers, drag databases and other attacks that lead to data leakage, or hackers use abnormal database queries, XSS (also called Cross-SiteScripting, cross-site scripting attack) attack scripts, unauthorized access, traversal and other penetrating detection behaviors to query website vulnerabilities.
[0003] At present, the existing attack behavior detection is divided into two categories: pre-detection and post-audit. Among them, pre-detection usually adds attack behavior detection code to the system, and uses the added attack behavior detection code to perform attack behavior detection on user operations. However, since it needs to add the above code to the system logic, it will increase the complexity of the system; post-audit is to perform attack behavior detection after a user session ends, but this will cause losses to the system because the attack behavior has already occurred.
[0004] In summary, how to detect attack behaviors in a timely manner without increasing the complexity of system logic is a technical problem that needs to be urgently solved by those skilled in the art. Summary of the invention
[0005] In view of this, the purpose of the present application is to provide an attack behavior detection method, device, equipment and readable storage medium, which are used to detect attack behaviors in a timely manner without increasing the complexity of system logic.
[0006] In order to achieve the above objectives, this application provides the following technical solutions:
[0007] An attack behavior detection method, comprising:
[0008] Get the current operation sequence in the target system;
[0009] Determine whether there is a target frequent polynomial set matching the current operation sequence in the pre-mined frequent polynomial sets; wherein the frequent polynomial set is obtained by pre-acquiring historical logs corresponding to each historical operation sequence in the target system and mining the historical logs;
[0010] If the target frequent multi-item set exists, determining whether there is an attack feature in the target frequent multi-item set;
[0011] If the target frequent multiple sets have attack features, it is determined that the current operation sequence has attack behavior, and a prompt is issued that the current operation sequence has attack behavior.
[0012] Preferably, the historical logs are mined to obtain frequent multinomial sets, including:
[0013] Preprocessing each of the historical logs, and treating each of the preprocessed historical logs as a transaction;
[0014] Determine whether there is an attack feature in each of the transactions, add a first feature item to the transaction with the attack feature, and add a second feature item to the transaction without the attack feature;
[0015] Use FP-Growth algorithm to mine each transaction and obtain frequent multi-item sets;
[0016] Accordingly, judging whether there is an attack feature in the target frequent multiple sets includes:
[0017] Obtaining a superset of the target frequent multinomial set, and determining the number of supersets including the first feature item and the number of supersets including the second feature item;
[0018] Calculating the confidence of the target frequent multinomial set by using the number of supersets including the first feature item and the number of supersets including the second feature item;
[0019] It is determined whether the confidence level is greater than a first preset value, and if so, it is determined that the target frequent multiple sets contain attack features.
[0020] Preferably, determining whether there is an attack feature in each of the transactions includes:
[0021] Determine whether at least one operation item in the transaction occurs more than a second preset value, whether the time interval between two adjacent operation items in the transaction is less than a third preset value, whether the duration of the transaction exceeds a fourth preset value, and whether there is a printing system abnormality in the transaction;
[0022] If there is at least one of the following in which the number of occurrences of at least one operation item in the transaction exceeds the second preset value, the time interval between two adjacent operation items is lower than the third preset value, the elapsed time exceeds the fourth preset value, and the printing system is abnormal, it is determined that there are attack features in the transaction.
[0023] Preferably, after determining that the current operation sequence contains attack behavior, the method further includes:
[0024] The log corresponding to the current operation sequence is obtained, and the log is used as a historical log, and the step of preprocessing each of the historical logs is returned to be executed.
[0025] Preferably, preprocessing each of the historical logs includes:
[0026] Delete the invalid operation items in each of the history logs.
[0027] Preferably, after determining that the current operation sequence contains attack behavior, the method further includes:
[0028] The target system is informed that the current operation sequence contains an attack behavior, so that the target system closes a current session corresponding to the current operation sequence.
[0029] An attack behavior detection device, comprising:
[0030] An acquisition module, used to obtain the current operation sequence in the target system;
[0031] A first judgment module is used to judge whether there is a target frequent polynomial set matching the current operation sequence in the pre-mined frequent polynomial sets; wherein the frequent polynomial set is obtained by pre-acquiring historical logs corresponding to each historical operation sequence in the target system and mining the historical logs;
[0032] A second judgment module is used to judge whether there is an attack feature in the target frequent multi-item set if the target frequent multi-item set exists;
[0033] The determination module is used to determine that the current operation sequence has an attack behavior if the target frequent multiple sets have attack characteristics, and issue a prompt that the current operation sequence has an attack behavior.
[0034] Preferably, the attack behavior detection device further comprises a mining module for mining the historical log to obtain frequent polynomials, and the mining module comprises:
[0035] A preprocessing unit, used to preprocess each of the historical logs, and treat each of the preprocessed historical logs as a transaction;
[0036] A first judgment unit, configured to judge whether there is an attack feature in each of the transactions, add a first feature item to the transaction with the attack feature, and add a second feature item to the transaction without the attack feature;
[0037] A mining unit is used to mine each transaction using the FP-Growth algorithm to obtain frequent multi-item sets;
[0038] Accordingly, the second judgment module includes:
[0039] an acquiring unit, configured to acquire a superset of the target frequent multinomial set, and determine the number of supersets including the first feature item and the number of supersets including the second feature item;
[0040] a calculation unit, configured to calculate the confidence of the target frequent multinomial set by using the number of supersets including the first feature item and the number of supersets including the second feature item;
[0041] The second judgment unit is used to judge whether the confidence level is greater than a first preset value, and if so, determine that the target frequent multiple sets contain attack features.
[0042] An attack behavior detection device, comprising:
[0043] Memory for storing computer programs;
[0044] A processor is used to implement the steps of any of the above-mentioned attack behavior detection methods when executing the computer program.
[0045] A readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of any of the above-mentioned attack behavior detection methods are implemented.
[0046] The present application provides an attack behavior detection method, apparatus, device and readable storage medium, wherein the method comprises: obtaining a current operation sequence in a target system; determining whether there is a target frequent multi-item set matching the current operation sequence in a pre-mined frequent multi-item set; wherein the frequent multi-item set is obtained by pre-acquiring historical logs corresponding to each historical operation sequence in the target system and mining the historical logs; if there is a target frequent multi-item set, determining whether there is an attack feature in the target frequent multi-item set; if there is an attack feature in the target frequent multi-item set, determining that there is an attack behavior in the current operation sequence, and issuing a prompt that there is an attack behavior in the current operation sequence.
[0047] The above-mentioned technical scheme disclosed in the present application obtains the historical logs corresponding to each historical operation sequence in the target system in advance and mines the historical logs to obtain frequent multi-items. When performing attack behavior detection, the current operation sequence existing in the target system is obtained, and it is determined whether there is a target frequent multi-item set matching the current operation sequence in the pre-mined frequent multi-item set. If so, it is determined whether there is an attack feature in the target frequent multi-item set. If the attack feature exists in the target frequent multi-item set, it is determined that there is an attack behavior in the current operation sequence. Through the above process, it can be seen that the present application only needs to use the historical logs corresponding to each historical operation sequence in the target system and obtain the current operation sequence in the target system to realize attack behavior detection. Therefore, the present application can decouple attack behavior detection from the system logic of the target system, that is, there is no need to realize attack behavior detection by adding attack behavior detection code in the system logic of the target system, thereby reducing the complexity of the system logic. In addition, since the present application detects attack behaviors by acquiring the current operation sequence of the target system, it is possible to realize in-process attack behavior detection, so as to timely discover attack behaviors during the operation of the target system, and by issuing prompts, relevant personnel can be promptly informed of the existence of attack behaviors in the current operation sequence and take countermeasures in a timely manner, so as to effectively reduce the losses caused by the attack behaviors to the target system. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0049] Figure 1 A flowchart of an attack behavior detection method provided in an embodiment of the present application;
[0050] Figure 2 A schematic diagram of the structure of an attack behavior detection device provided in an embodiment of the present application;
[0051] Figure 3 A schematic diagram of the structure of an attack behavior detection device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0052] The core of this application is to provide an attack behavior detection method, device, equipment and readable storage medium, which are used to detect attack behaviors in a timely manner without increasing the complexity of system logic.
[0053] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0054] See also Figure 1 , which shows a flow chart of an attack behavior detection method provided by an embodiment of the present application. The attack behavior detection method provided by an embodiment of the present application may include:
[0055] S11: Obtain the current operation sequence in the target system.
[0056] When it is necessary to check whether there is an attack in the current session between the user and the target system, the current operation sequence in the target system during the current session between the user and the target system can be obtained in a timely or real-time manner, that is, the current operation sequence S corresponding to the current session in the target system can be obtained. n =(O 1 ,…,O i ), where S n Represents the current operation sequence, O i Represents the i-th operation in the current operation sequence, that is, the i-th operation item contained in the current operation sequence.
[0057] S12: Determine whether there is a target frequent polynomial set that matches the current operation sequence in the pre-mined frequent polynomial sets; wherein the frequent polynomial set is obtained by pre-acquiring historical logs corresponding to each historical operation sequence in the target system and mining the historical logs; if so, execute step S13, if not, determine that there is no attack behavior in the current operation sequence.
[0058] It should be noted that before the attack behavior detection device detects whether there is an attack behavior in the current operation sequence in the target system, it can obtain the historical logs corresponding to each historical operation sequence in the target system in advance, and mine the historical logs to obtain frequent multi-items, that is, to mine frequent multi-items of attack features of many existing functions based on the historical logs corresponding to each historical operation sequence, so as to predict the attack behavior of the current operation sequence. Among them, in addition to the corresponding operation items, the historical logs can also include the operation ID, the printing of abnormal information, etc., and the historical operation sequences mentioned here need to be classified according to user sessions. Each operation within the validity period of each user's login session corresponds to an operation sequence, and an operation sequence corresponds to a historical log.
[0059] On the basis of step S11, the attack behavior detection device can determine whether there is a target frequent polynomial set that matches the current operation sequence in the pre-mined frequent polynomial set, wherein the matching mentioned here specifically means that each operation item included in the target frequent polynomial set has a matching operation item in the current operation sequence, that is, the operation items in the current operation sequence cover the operation items in the target frequent polynomial set, that is, the target frequent polynomial set can be regarded as a subset of the current operation sequence.
[0060] If there is no target frequent polynomial set matching the current operation sequence in the pre-mined frequent polynomial set, it indicates that there is no attack behavior in the current operation sequence, and the current session between the target system and the user can continue normally. If there is a target frequent polynomial set matching the current operation sequence in the pre-mined frequent polynomial set, it indicates that there may be an attack behavior in the current operation sequence, and step S13 can be executed.
[0061] S13: Determine whether there is an attack feature in the target frequent multi-item set; if so, execute step S14; if not, determine that there is no attack behavior in the current operation sequence.
[0062] S14: Determine that the current operation sequence contains an attack behavior, and issue a prompt indicating that the current operation sequence contains an attack behavior.
[0063] When it is determined that there is a target frequent multi-item set matching the current operation sequence in the pre-mined frequent multi-item set, it can be determined whether there is an attack feature in the target frequent multi-item set. If it is determined that there is no attack feature in the target frequent multi-item set, it indicates that the matching attack feature association fails, that is, it is considered that there is no attack behavior in the current operation sequence. If it is determined that there is an attack feature in the target frequent multi-item set, it indicates that the matching attack feature association is successful, that is, it is determined that there is an attack behavior in the current operation sequence. At this time, a prompt that there is an attack behavior in the current operation sequence can be issued, so that relevant personnel can promptly know that there is an attack behavior in the current operation sequence, and take countermeasures in time to timely reduce the loss caused by the attack behavior to the target system.
[0064] Through the above process, it can be known that the present application only needs to obtain the historical logs corresponding to each historical operation sequence from the target system, and obtain the current operation sequence existing in the target system to realize attack behavior detection. Therefore, the attack behavior detection can be decoupled from the system logic of the target system, that is, it is no longer necessary to use the target system itself to detect attack behaviors by adding attack behavior detection code to the system logic of the target system. Therefore, the complexity of the system logic can be reduced. In addition, the present application can realize attack behavior detection during the conversation between the user and the target system by timely obtaining the current operation sequence of the target system, so as to realize attack behavior detection in the process, so that attack behavior occurs in time, effectively preventing hacker attacks and infiltration behaviors, and effectively reducing the losses caused by attack behaviors to the target system.
[0065] It should be noted that the present application can be used in the robust iteration of agile systems, that is, it can be applied to agile iterative information systems. Of course, it can also be applied to other systems, and the present application does not limit this.
[0066] The above-mentioned technical scheme disclosed in the present application obtains the historical logs corresponding to each historical operation sequence in the target system in advance and mines the historical logs to obtain frequent multi-items. When performing attack behavior detection, the current operation sequence existing in the target system is obtained, and it is determined whether there is a target frequent multi-item set matching the current operation sequence in the pre-mined frequent multi-item set. If so, it is determined whether there is an attack feature in the target frequent multi-item set. If the attack feature exists in the target frequent multi-item set, it is determined that there is an attack behavior in the current operation sequence. Through the above process, it can be seen that the present application only needs to use the historical logs corresponding to each historical operation sequence in the target system and obtain the current operation sequence in the target system to realize attack behavior detection. Therefore, the present application can decouple attack behavior detection from the system logic of the target system, that is, there is no need to realize attack behavior detection by adding attack behavior detection code in the system logic of the target system, thereby reducing the complexity of the system logic. In addition, since the present application detects attack behaviors by acquiring the current operation sequence of the target system, it is possible to realize in-process attack behavior detection, so as to timely discover attack behaviors during the operation of the target system, and by issuing prompts, relevant personnel can be promptly informed of the existence of attack behaviors in the current operation sequence and take countermeasures in a timely manner, so as to effectively reduce the losses caused by the attack behaviors to the target system.
[0067] An attack behavior detection method provided in an embodiment of the present application mines historical logs to obtain frequent multi-item sets, which may include:
[0068] Preprocess each historical log, and treat each preprocessed historical log as a transaction;
[0069] Determine whether there is an attack feature in each transaction, add a first feature item to the transaction with the attack feature, and add a second feature item to the transaction without the attack feature;
[0070] Use FP-Growth algorithm to mine each transaction and obtain frequent multi-item sets;
[0071] Accordingly, judging whether there are attack features in the target frequent multi-item set may include:
[0072] Obtain the superset of the target frequent multinomial set, and determine the number of supersets containing the first feature item and the number of supersets containing the second feature item;
[0073] The confidence of the target frequent multinomial set is calculated using the number of supersets containing the first feature item and the number of supersets containing the second feature item;
[0074] It is determined whether the confidence is greater than a first preset value. If so, it is determined that the target frequent multiple sets contain attack features.
[0075] In this application, when mining historical logs to obtain frequent polynomials, each acquired historical log may be preprocessed to improve the efficiency and accuracy of frequent polynomial mining. Afterwards, each preprocessed historical log may be used as a transaction X=(O 1 ,O 2 ,…,O n ), then, determine whether there is an attack feature in each transaction, and add the first feature item E=1 to the transaction with the attack feature, so that the transaction of this type is from X=(O 1 ,O 2 ,…,O n ) becomes X=(O 1 ,O 2 ,…,O n , E=1), add the second feature item E=0 to the transaction without attack feature, so that this type of transaction is from X=(O 1 ,O 2 ,…,O n ) becomes X=(O 1 ,O 2 ,…,O n, E=0). Then, the FP-Growth algorithm is used to mine each transaction to obtain frequent multi-items, that is, the FP-Growth algorithm can be used to mine association rules, so as to obtain supply feature association operations with high confidence. Among them, the FP-Growth algorithm can improve the mining efficiency of frequent multi-items. The FP-Growth algorithm (also known as the FP-Tree algorithm) is an algorithm for mining frequent multi-items. FP-Growth is a tree structure that meets the following conditions: it consists of a root node, an item prefix subtree, and a frequent item header table. The idea is to construct an FP-Growth, map the data in the data set to the tree, and then find all frequent multi-items based on this FP-Growth.
[0076] Among them, the process of mining each transaction using the FP-Growth algorithm to obtain frequent multi-items is as follows:
[0077] 1) Establish the header table: Scan all operation data, count the trigger times of all user operations O (O represents operation items), obtain their count table, and delete the statistical items whose trigger times are less than 10% of the support to improve the statistical accuracy. The remaining operation items are regarded as the frequent operation set and the first-level node of the FP-Growth root node, which is called the header table;
[0078] 2) Construct an FP-Growth tree, arrange the operations in the transaction in reverse order of frequency, and insert them into the FP tree. The node in the front order is the parent node, and the node in the back order is the child node. If there is a common parent node, the frequency count is increased by 1 at the corresponding common parent node. After the insertion, if a new node appears, the node corresponding to the header table under the root node can insert the new node through the node linked list. After all the data is inserted into the FP tree, the establishment of the FP tree is completed.
[0079] 3) After building the FP-Growth tree, obtain all n frequent sets of each operation item. The steps are as follows:
[0080] 3.1) From the leaf nodes of the item header table, find the sub-FP tree (also called conditional pattern base) corresponding to the item header table in sequence. The sub-FP tree is the FP subtree that also meets the FP tree conditions.
[0081] 3.2) After obtaining this sub-FP tree, record the frequency of the nodes in the sub-tree as the frequency of the leaf nodes, and delete the nodes with frequency counts less than 10%. Recursively mine upward from the sub-FP tree to obtain the frequent multi-item sets (also called frequent n-item sets) of all item header tables.
[0082] On the basis of the above, the specific process of judging whether there is an attack feature in the target frequent polynomial set can be: obtain the parent set of the target frequent polynomial set that matches the current operation sequence in the mined frequent polynomial set, and determine the number of parent sets containing the first feature item E=1 and the number of parent sets containing the second feature item E=0 in these parent sets, and then, based on the number of parent sets containing the first feature item E=1 and the number of parent sets containing the second feature item E=0, use the confidence of the target frequent polynomial set = (the number of parent sets containing the first feature item E=1) / (the number of parent sets containing the first feature item E=1 + the number of parent sets containing the second feature item E=0) The confidence of the target frequent multinomial set is calculated by the number of supersets of the second feature item E=0, that is, the probability of containing the first feature item E=1 is calculated, that is, confidence(Sn=>E1)=P(E1|Sn)=(count(Sn∩E1)) / count(Sn), wherein confidence(Sn=>E1) is the confidence of the target frequent multinomial set, E1 is the first feature item, count(Sn∩E1) is the number of supersets containing the first feature item E=1, and count(Sn) is the number of supersets of the superset of the target frequent multinomial set. It is determined whether the calculated confidence of the target frequent polynomial set is greater than a first preset value. If the calculated confidence of the target frequent polynomial set is greater than the first preset value, it is determined that there are attack features in the target frequent polynomial set. If the calculated confidence of the target frequent polynomial set is not greater than the first preset value, it is determined that there are no attack features in the target frequent polynomial set. The first preset value may be 80% specifically. Of course, it may also be set to other values according to actual needs.
[0083] Through the above process, the FP-Growth algorithm can be used to calculate the correlation between operations and attack features, and accurately discover and determine the attack behavior of the current operation sequence. Among them, the advantage of using the FP-Growth algorithm is that it can block user operations in advance, and this method supports automatic update of rules.
[0084] An attack behavior detection method provided in an embodiment of the present application determines whether there are attack features in each transaction, which may include:
[0085] Determine whether at least one operation item in the transaction occurs more than a second preset value, whether the time interval between two adjacent operation items in the transaction is less than a third preset value, whether the duration of the transaction exceeds a fourth preset value, and whether there is a printing system abnormality in the transaction;
[0086] If there is at least one of the following in the transaction: the number of times that at least one operation item occurs exceeds the second preset value, the time interval between two adjacent operation items is lower than the third preset value, the elapsed time exceeds the fourth preset value, and the printing system is abnormal, it is determined that there are attack features in the transaction.
[0087] In the present application, when determining whether there is an attack feature in each transaction, it can be specifically determined whether at least one operation item in the transaction appears more than a second preset value. For example, if the number of single operations in the transaction exceeds 100, if at least one operation item in the transaction appears more than the second preset value, it indicates that the number of operations is too many. In this case, it is determined that there is an attack feature in the transaction; the time interval between two adjacent operations in each transaction is counted, and it is determined whether there is a time interval between two adjacent operation items in the transaction that is less than a third preset value. If there is a time interval between two adjacent operation items in the transaction that is less than the third preset value, it indicates that the operation interval is too short. For example, if the time interval between operation item 0 is less than the third preset value, it indicates that the operation interval is too short. i and operation item O i+1 If the time interval does not exceed 100ms, it indicates that the interval between the two operations is too short. In this case, it is determined that there are attack features in the transaction; the start and end time of the session corresponding to each transaction is counted, and the duration of the transaction is obtained according to the start and end time, and it is determined whether the duration of the transaction exceeds the fourth preset value. For example, if the total transaction spans the market for more than 12 hours, if the duration of the transaction exceeds the fourth preset value, it is determined that there are attack features in the transaction; it is determined whether there is a printing system anomaly in the transaction. If so, it is determined that there are attack features in the transaction.
[0088] Through the above process, it can be known that if there is at least one operation item in the transaction whose number of occurrences exceeds the second preset value, the time interval between two adjacent operation items is lower than the third preset value, the elapsed time exceeds the fourth preset value, and the printing system is abnormal, then it is determined that there is an attack feature in the transaction, and the first feature item is added to the transaction.
[0089] An attack behavior detection method provided by an embodiment of the present application may further include, after determining that an attack behavior exists in a current operation sequence:
[0090] Get the log corresponding to the current operation sequence, use the log as a history log, and return to execute the step of preprocessing each history log.
[0091] In the present application, after determining that an attack behavior exists in the current operation sequence, the log corresponding to the current operation sequence can be obtained, and the obtained log can be used as a historical log, and the step of preprocessing each historical log can be returned to realize the dynamic establishment of the FP-Growth tree and automatically update the mined frequent multinomial sets, thereby facilitating the improvement of the accuracy of subsequent attack behavior detection.
[0092] An attack behavior detection method provided in an embodiment of the present application pre-processes each historical log, which may include:
[0093] Delete invalid operation items in each history log.
[0094] In the present application, when preprocessing each historical log, invalid operation items in each historical log can be deleted to avoid the invalid operation items from affecting the mining of frequent polynomial sets, thereby improving the accuracy and efficiency of frequent polynomial set mining.
[0095] An attack behavior detection method provided by an embodiment of the present application may further include, after determining that an attack behavior exists in a current operation sequence:
[0096] The target system is informed that the current operation sequence contains attack behaviors, so that the target system closes the current session corresponding to the current operation sequence.
[0097] In the present application, after determining that an attack behavior exists in the current operation sequence, the target system can be informed that an attack behavior exists in the current operation sequence, so that the target system can promptly obtain the message and close the current session corresponding to the current operation sequence, that is, promptly block the current session corresponding to the current operation sequence to avoid causing serious damage to the target system.
[0098] The present application also provides an attack behavior detection device. Figure 2 , which shows a schematic diagram of the structure of an attack behavior detection device provided in an embodiment of the present application, which may include:
[0099] An acquisition module 21 is used to acquire the current operation sequence in the target system;
[0100] The first judgment module 22 is used to judge whether there is a target frequent polynomial set matching the current operation sequence in the pre-mined frequent polynomial set; wherein the frequent polynomial set is obtained by pre-acquiring historical logs corresponding to each historical operation sequence in the target system and mining the historical logs;
[0101] The second judgment module 23 is used to judge whether there is an attack feature in the target frequent multi-item set if there is a target frequent multi-item set;
[0102] The determination module 24 is used to determine that there is an attack behavior in the current operation sequence if there are attack features in the target frequent multiple sets, and issue a prompt that the current operation sequence has an attack behavior.
[0103] An attack behavior detection device provided in an embodiment of the present application may further include a mining module for mining historical logs to obtain frequent multinomial sets. The mining module may include:
[0104] A preprocessing unit, used to preprocess each historical log and treat each preprocessed historical log as a transaction;
[0105] A first judgment unit is used to judge whether there is an attack feature in each transaction, add a first feature item to the transaction with the attack feature, and add a second feature item to the transaction without the attack feature;
[0106] A mining unit is used to mine each transaction using the FP-Growth algorithm to obtain frequent multi-item sets;
[0107] Accordingly, the second determination module 23 may include:
[0108] An acquisition unit, used to acquire a superset of the target frequent multinomial set, and determine the number of supersets including the first feature item and the number of supersets including the second feature item;
[0109] A calculation unit, used to calculate the confidence of the target frequent multinomial set by using the number of supersets containing the first feature item and the number of supersets containing the second feature item;
[0110] The second judgment unit is used to judge whether the confidence is greater than a first preset value, and if so, it is determined that the target frequent multiple sets have attack features.
[0111] An attack behavior detection device provided in an embodiment of the present application may include a first judgment unit:
[0112] A judgment subunit, used to judge whether at least one operation item in the transaction appears more than a second preset value, whether the time interval between two adjacent operation items in the transaction is less than a third preset value, whether the duration of the transaction exceeds a fourth preset value, and whether there is a printing system abnormality in the transaction;
[0113] The determination subunit is used to determine that there are attack features in the transaction if at least one of the following occurs more than a second preset value in the transaction, the time interval between two adjacent operation items is lower than a third preset value, the elapsed time exceeds a fourth preset value, and the printing system is abnormal.
[0114] An attack behavior detection device provided in an embodiment of the present application may further include:
[0115] The return module is used to obtain the log corresponding to the current operation sequence after determining that there is an attack behavior in the current operation sequence, and use the log as a historical log, and return to execute the step of preprocessing each historical log.
[0116] An attack behavior detection device provided in an embodiment of the present application, wherein the preprocessing unit may include:
[0117] The deletion subunit is used to delete invalid operation items in each history log.
[0118] An attack behavior detection device provided in an embodiment of the present application may further include:
[0119] The notification module is used to notify the target system that the current operation sequence has an attack behavior after determining that the current operation sequence has an attack behavior, so that the target system closes the current session corresponding to the current operation sequence.
[0120] The present application also provides an attack behavior detection device. Figure 3 , which shows a schematic diagram of the structure of an attack behavior detection device provided in an embodiment of the present application, which may include:
[0121] A memory 31, used for storing computer programs;
[0122] The processor 32 can implement the following steps when executing the computer program stored in the memory 31:
[0123] Obtain the current operation sequence in the target system; determine whether there is a target frequent polynomial set that matches the current operation sequence in the pre-mined frequent polynomial set; wherein the frequent polynomial set is obtained by pre-acquiring the historical logs corresponding to each historical operation sequence in the target system and mining the historical logs; if there is a target frequent polynomial set, determine whether there is an attack feature in the target frequent polynomial set; if there is an attack feature in the target frequent polynomial set, determine that there is an attack behavior in the current operation sequence, and issue a prompt that the current operation sequence has an attack behavior.
[0124] The present application also provides a readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the following steps can be implemented:
[0125] Obtain the current operation sequence in the target system; determine whether there is a target frequent polynomial set that matches the current operation sequence in the pre-mined frequent polynomial set; wherein the frequent polynomial set is obtained by pre-acquiring the historical logs corresponding to each historical operation sequence in the target system and mining the historical logs; if there is a target frequent polynomial set, determine whether there is an attack feature in the target frequent polynomial set; if there is an attack feature in the target frequent polynomial set, determine that there is an attack behavior in the current operation sequence, and issue a prompt that the current operation sequence has an attack behavior.
[0126] The readable storage medium may include: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.
[0127] For the description of the relevant parts of an attack behavior detection device, equipment and readable storage medium provided in the present application, reference can be made to the detailed description of the corresponding parts of an attack behavior detection method provided in an embodiment of the present application, which will not be repeated here.
[0128] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Moreover, the term "include", "comprise" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, article or equipment that includes a series of elements are inherent to the elements. In the absence of more restrictions, the elements limited by the sentence "comprise one..." do not exclude the presence of other identical elements in the process, method, article or equipment that includes the elements. In addition, the above-mentioned technical solution provided in the embodiment of the present application is consistent with the corresponding technical solution in the prior art in principle, and the part is not described in detail, so as not to repeat too much.
[0129] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for detecting attack behavior, characterized in that: include: Get the current operation sequence in the target system; Determine whether there is a target frequent polynomial set matching the current operation sequence in the pre-mined frequent polynomial set; wherein the frequent polynomial set is obtained by pre-acquiring historical logs corresponding to each historical operation sequence in the target system and mining the historical logs; each operation item included in the target frequent polynomial set has a matching operation item in the current operation sequence; The process of obtaining the frequent multinomial set includes: preprocessing each of the historical logs, and treating each of the preprocessed historical logs as a transaction; judging whether there is an attack feature in each of the transactions, adding a first feature item to the transaction with the attack feature, and adding a second feature item to the transaction without the attack feature; mining each transaction using the FP-Growth algorithm to obtain a frequent multinomial set; If the target frequent multi-item set exists, determining whether there is an attack feature in the target frequent multi-item set; Wherein, the determining whether there is an attack feature in the target frequent multi-item set includes: obtaining a parent set of the target frequent multi-item set, and determining the number of parent sets containing the first feature item and the number of parent sets containing the second feature item; calculating the confidence of the target frequent multi-item set by using the number of parent sets containing the first feature item and the number of parent sets containing the second feature item; determining whether the confidence is greater than a first preset value, and if so, determining that there is an attack feature in the target frequent multi-item set; If the target frequent multiple sets have attack features, it is determined that the current operation sequence has attack behavior, and a prompt is issued that the current operation sequence has attack behavior.
2. The attack behavior detection method according to claim 1, characterized in that: Determining whether there are attack features in each of the transactions includes: Determine whether at least one operation item in the transaction occurs more than a second preset value, whether the time interval between two adjacent operation items in the transaction is less than a third preset value, whether the duration of the transaction exceeds a fourth preset value, and whether there is a printing system abnormality in the transaction; If there is at least one of the following in which the number of occurrences of at least one operation item in the transaction exceeds the second preset value, the time interval between two adjacent operation items is lower than the third preset value, the elapsed time exceeds the fourth preset value, and the printing system is abnormal, it is determined that there are attack features in the transaction.
3. The attack behavior detection method according to claim 1, characterized in that: After determining that the current operation sequence has an attack behavior, the method further includes: The log corresponding to the current operation sequence is obtained, and the log is used as a historical log, and the step of preprocessing each of the historical logs is returned to be executed.
4. The attack behavior detection method according to claim 1, characterized in that: Preprocessing each of the historical logs includes: Delete the invalid operation items in each of the history logs.
5. The attack behavior detection method according to claim 1, characterized in that: After determining that the current operation sequence has an attack behavior, the method further includes: The target system is informed that the current operation sequence contains an attack behavior, so that the target system closes a current session corresponding to the current operation sequence.
6. An attack behavior detection device, characterized in that: include: An acquisition module, used to obtain the current operation sequence in the target system; A first judgment module is used to judge whether there is a target frequent polynomial set matching the current operation sequence in the pre-mined frequent polynomial set; wherein the frequent polynomial set is obtained by pre-acquiring historical logs corresponding to each historical operation sequence in the target system and mining the historical logs; each operation item included in the target frequent polynomial set has a matching operation item in the current operation sequence; A mining module, used for mining the historical logs to obtain frequent multinomial sets, including: a preprocessing unit, used for preprocessing each of the historical logs, and treating each of the preprocessed historical logs as a transaction; a first judgment unit, used for judging whether there is an attack feature in each of the transactions, adding a first feature item to the transaction with the attack feature, and adding a second feature item to the transaction without the attack feature; a mining unit, used for mining each transaction using an FP-Growth algorithm to obtain a frequent multinomial set; A second judgment module is used to judge whether there is an attack feature in the target frequent multi-item set if the target frequent multi-item set exists; The second judgment module includes: an acquisition unit, used to acquire the parent set of the target frequent multi-item set, and determine the number of parent sets containing the first feature item and the number of parent sets containing the second feature item; a calculation unit, used to calculate the confidence of the target frequent multi-item set by using the number of parent sets containing the first feature item and the number of parent sets containing the second feature item; a second judgment unit, used to judge whether the confidence is greater than a first preset value, and if so, determine that there is an attack feature in the target frequent multi-item set; The determination module is used to determine that the current operation sequence has an attack behavior if the target frequent multiple sets have attack features, and issue a prompt that the current operation sequence has an attack behavior.
7. An attack behavior detection device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the attack behavior detection method according to any one of claims 1 to 5 when executing the computer program.
8. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the attack behavior detection method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Network event processing method and device
CN103281341A