A business vulnerability protection method and system
By obtaining and analyzing the flow data of the business system and using behavior monitoring models to identify and classify abnormal IP addresses, the problem of poor business vulnerability detection in the existing technology is solved, and more accurate and timely vulnerability location and handling is achieved.
Patent Information
- Application Number
- CN202111442506.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-30
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-11-30
AI Technical Summary
Existing network security detection cannot effectively detect business vulnerabilities, resulting in low positioning accuracy and poor handling timeliness.
By obtaining the flow data of the business system, the IP address is monitored using a pre-built behavior monitoring model. If an IP address with abnormal behavior is found, it is guided to continuously submit identity data, determine the data distribution method and transaction success rate, classify abnormal behaviors, and perform disposal operations based on the classification results.
It realizes effective detection of business vulnerabilities that cannot be detected in the past, and improves the accuracy of business vulnerability location and timeliness of handling.
Smart Images

Figure CN114065225B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and more specifically, to a method and system for protecting business vulnerabilities. Background Art
[0002] With the continuous advancement of the digital and networked construction of economic activities, people's living efficiency has been greatly improved. Due to the rapid development of business, the version iteration of applications has been accelerating continuously. However, the levels of various R & D institutions are uneven, and the security issues existing in the business of business systems (such as credit systems, core transaction systems, report processing systems, etc.) are not deeply considered during design and development, resulting in some logical branches being unable to be processed normally or being processed incorrectly, and business vulnerabilities occurring.
[0003] As high-value targets in the eyes of hackers, business systems are also continuously threatened by network crimes. Therefore, it is necessary to conduct network security detection on business systems. The disadvantages of traditional network security detection include the following three aspects:
[0004] First, it detects whether business vulnerabilities are exploited by hackers based on whether there are malicious features in the request traffic. Usually, no request traffic with obvious malicious features is received, resulting in the existing network security devices being unable to exert their detection effectiveness; second, if hackers steal transaction data, usually, the malicious IP addresses are blocked. However, blocking the malicious IP addresses may lead to the inability to accurately determine the functional points with business logic defects; third, when hackers use the vulnerabilities of the banking business system to verify data and enrich the data dimension, and steal transaction data, when significant abnormalities occur in the detection indicators such as the server resources and transaction success rate of the business system, it will be found that there are business vulnerabilities in the business system. However, the time node from the occurrence of stealing transaction data is too long, resulting in the failure to dispose of the business vulnerabilities in time.
[0005] Therefore, the existing network security detection cannot effectively detect business vulnerabilities, and has low accuracy in locating business vulnerabilities and low timeliness in disposing of business vulnerabilities. Summary of the Invention
[0006] In view of this, the present application discloses a method and system for protecting business vulnerabilities, aiming to effectively detect business vulnerabilities that could not be detected in the past, and improve the accuracy of locating business vulnerabilities and the timeliness of disposing of business vulnerabilities.
[0007] To achieve the above object, the disclosed technical solutions are as follows:
[0008] The first aspect of the present application discloses a method for protecting business vulnerabilities, and the method includes:
[0009] Acquire transaction data of the business system; the transaction data at least includes the IP address of the request end that initiates the request to the business system;
[0010] Performing behavior monitoring on the IP address through a pre-built behavior monitoring model to obtain monitoring results;
[0011] If the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior, guiding the abnormal IP address to continuously submit identity data within a preset period of time;
[0012] Determine the data distribution mode of the identity data continuously submitted by the abnormal IP address within a preset period of time and the transaction success rate corresponding to the abnormal IP address within the preset period of time;
[0013] Classifying the abnormal behaviors of the abnormal IP addresses according to the data distribution mode and the transaction success rate to obtain classification results;
[0014] A corresponding treatment operation is performed based on the classification result.
[0015] Preferably, the obtaining of flow data of the business system includes:
[0016] The transaction data of the business system is obtained through a preset traffic restoration method and a preset log collection method; the preset traffic restoration method is used to obtain the transaction data when the business system is called through a preset external settlement channel; the preset log collection method is used to collect the transaction data of the server of the business system.
[0017] Preferably, the process of constructing the behavior monitoring model includes:
[0018] The acquired identity data is marked as sensitive information through a preset machine learning algorithm;
[0019] The neural network model is trained by using the flow data and the sensitive information to obtain an automated model; the automated model is a model for identifying abnormal IP addresses;
[0020] Based on the preset data calculation engine and the automation model, a behavior monitoring model is constructed; the preset data calculation engine is used to improve the efficiency of obtaining the abnormal IP address.
[0021] Preferably, the monitoring of the behavior of the IP address by using a pre-built behavior monitoring model to obtain a monitoring result includes:
[0022] Determining whether the access frequency of the IP address initiating access to the business system within a preset period is greater than a preset frequency through a pre-built behavior monitoring model;
[0023] If it is monitored that the access frequency of the IP address to initiate access to the service system within a preset time period is greater than a preset frequency, a monitoring result indicating that the IP address is an abnormal IP address with abnormal behavior is generated;
[0024] If it is monitored that the access frequency of the IP address to initiate access to the service system within the preset time period is less than the preset frequency, a monitoring result indicating that the IP address is a normal IP address with normal behavior is generated.
[0025] Preferably, if the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior, guiding the abnormal IP address to continuously submit identity data within a preset time period includes:
[0026] If the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior, a message indicating the success of a preset virtual transaction is sent back to the abnormal IP address through a pre-established series link, so that the abnormal IP address continuously submits identity data within a preset time period.
[0027] Preferably, determining the data distribution mode of the identity data continuously submitted by the abnormal IP address within a preset time period and the transaction success rate corresponding to the abnormal IP address within the preset time period includes:
[0028] Performing data distribution analysis on the identity data through a pre-established bypass link to obtain the data distribution mode of the identity data continuously submitted by the abnormal IP address within a preset time period; the bypass link is used to converge the data of requests initiated by the abnormal IP address to the service system for data distribution analysis and data transaction statistics;
[0029] Analyzing the transactions corresponding to the abnormal IP address through the bypass link to obtain the transaction success rate corresponding to the abnormal IP address within the preset time period.
[0030] Preferably, classifying the abnormal behavior of the abnormal IP address through the data distribution mode and the transaction success rate to obtain a classification result includes:
[0031] If the data distribution mode is a continuous distribution mode and the transaction success rate is less than the preset success rate, it is determined that the abnormal behavior corresponding to the abnormal IP address is the first type of abnormal behavior;
[0032] If the data distribution mode is the continuous distribution mode and the transaction success rate is greater than or equal to the preset success rate, it is determined that the abnormal behavior corresponding to the abnormal IP address is the second type of abnormal behavior;
[0033] If the data distribution mode is a distribution jump mode, and the transaction success rate is greater than or equal to the preset success rate, then it is determined that the abnormal behavior corresponding to the abnormal IP address is a third type of abnormal behavior;
[0034] If the data distribution method is the distribution jump method, and the transaction success rate is less than the preset success rate, it is determined that the abnormal behavior corresponding to the abnormal IP address is the fourth type of abnormal behavior.
[0035] Preferably, the performing a corresponding treatment operation based on the classification result includes:
[0036] If the abnormal behavior corresponding to the abnormal IP address is the first type of abnormal behavior, restricting the data submission operation of the abnormal IP address by means of a preset additional code;
[0037] If the abnormal behavior corresponding to the abnormal IP address is the second type of abnormal behavior, determining the payment verification function point of the abnormal IP address as a business vulnerability exploitation point, and performing a repair operation on the business vulnerability exploitation point;
[0038] If the abnormal behavior corresponding to the abnormal IP address is the third type of abnormal behavior, the data submission operation of the abnormal IP address is restricted by a preset additional code, and the flow data is queried, and the data collection point of the abnormal IP address is located based on the flow data, and the data collection point is repaired;
[0039] If the abnormal behavior corresponding to the abnormal IP address is the fourth type of abnormal behavior, the tracing operation is terminated or the data collection operation is extended.
[0040] The second aspect of the present application discloses a service vulnerability protection system, the system comprising:
[0041] An acquisition unit, used to acquire flow data of a business system; the flow data at least includes an IP address of a request end that initiates a request to the business system;
[0042] A monitoring unit, used to perform behavior monitoring on the IP address through a pre-built behavior monitoring model to obtain a monitoring result;
[0043] A guiding unit, configured to guide the abnormal IP address to continuously submit identity data within a preset period of time if the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior;
[0044] A determination unit, configured to determine a data distribution mode of the identity data continuously submitted by the abnormal IP address within a preset period of time and a transaction success rate corresponding to the abnormal IP address within the preset period of time;
[0045] A classification unit, used to classify the abnormal behavior of the abnormal IP address according to the data distribution mode and the transaction success rate, and obtain a classification result;
[0046] A processing unit is used to perform a corresponding processing operation based on the classification result.
[0047] Preferably, the acquisition unit is specifically used for:
[0048] The transaction data of the business system is obtained through a preset traffic restoration method and a preset log collection method; the preset traffic restoration method is used to obtain the transaction data when the business system is called through a preset external settlement channel; the preset log collection method is used to collect the transaction data of the server of the business system.
[0049] Through the above technical scheme, it can be known that the present application discloses a method and system for protecting business vulnerabilities, obtains the flow data of the business system, and the flow data at least includes the data of the IP address of the request end that initiates the request to the business system, monitors the behavior of the IP address through a pre-built behavior monitoring model, and obtains the monitoring result. If the monitoring result characterizes that the IP address is an abnormal IP address with abnormal behavior, then guide the abnormal IP address to continuously submit identity data within a preset period of time, determine the data distribution mode of the identity data continuously submitted by the abnormal IP address within the preset period of time and the corresponding transaction success rate of the abnormal IP address within the preset period of time, classify the abnormal behavior of the abnormal IP address through the data distribution mode and the transaction success rate, obtain the classification result, and perform the corresponding disposal operation based on the classification result. Through the above scheme, the location and characteristics of sensitive information at past time points can be traced, so as to achieve effective detection of past business vulnerabilities. In addition, the regularity of data distribution, transaction success rate and other dimensional data are analyzed. For abnormal IP addresses that are determined to have abnormal behavior, the transaction data is checked and automated analysis is performed in combination with the accounting data to accurately locate business loopholes and deal with them in a timely manner, thereby improving the accuracy of business vulnerability location and the timeliness of business vulnerability handling. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0051] Figure 1 A flowchart of a method for protecting business vulnerabilities disclosed in an embodiment of the present application;
[0052] Figure 2Schematic diagram of the data storage format of the streaming data disclosed in the embodiments of the present application;
[0053] Figure 3 Flow chart of the construction process of the behavior monitoring model disclosed in the embodiments of the present application;
[0054] Figure 4 Flow chart of monitoring the IP address through the pre - constructed behavior monitoring model to obtain the monitoring result disclosed in the embodiments of the present application;
[0055] Figure 5 Flow chart of determining the data distribution mode and transaction success rate of the identity data of the abnormal IP address disclosed in the embodiments of the present application;
[0056] Figure 6 Schematic diagram of the structure of a service vulnerability protection system disclosed in the embodiments of the present application. Detailed implementation manners
[0057] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0058] In the present application, the term "including", "comprising" or any other variant thereof is intended to cover non - exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0059] As can be seen from the background art, the existing network security detection cannot effectively detect service vulnerabilities, and has low accuracy in locating service vulnerabilities and low timeliness in disposing service vulnerabilities.
[0060] To solve the above problems, the embodiments of the present application disclose a service vulnerability protection method and system, aiming to effectively detect service vulnerabilities and improve the accuracy of service vulnerability location and the timeliness of service vulnerability disposal. The specific implementation manners are described through the following embodiments.
[0061] Refer to Figure 1 As shown, it is a flow chart of a service vulnerability protection method disclosed in the embodiments of the present application. The service vulnerability protection method mainly includes the following steps:
[0062] S101: Acquire transaction data of a business system; the transaction data at least includes an IP address of a requesting end that initiates a request to the business system.
[0063] In S101, the business system includes banking business system, credit system, core transaction system, financial system, report processing system, etc.
[0064] Transaction data includes information such as the business system name, the source IP address that initiated the transaction, the user who initiated the transaction, the card number, and the transaction duration.
[0065] The requesting end includes the application (Application, APP) end, the personal computer (Personal Computer, PC) end, etc.
[0066] The transaction data of the business system is obtained through the preset traffic restoration method and the preset log collection method; the preset traffic restoration method is used to obtain the transaction data when the business system is called through the preset external settlement channel; the preset log collection method is used to collect the transaction data of the server of the business system.
[0067] Among them, the preset external settlement channels include UnionPay, ChinaNetPay and other third-party external settlement channels.
[0068] The preset traffic restoration method is mainly aimed at collecting flow data of calls to banking business systems initiated by third-party external settlement channels such as UnionPay and China National Nets Union. The collection of such traffic data can be achieved by deploying splitters on related network switching equipment.
[0069] The preset log collection method can realize file data collection on each server by deploying an agent on the business system server.
[0070] Among them, agent software is deployed on the server, and the automatic collection of the logs of interest can be realized through the agent software.
[0071] By aggregating the two parts of data, namely the preset traffic restoration method and the preset log collection method, full coverage of the flow data can be achieved.
[0072] Traffic restoration is to save the network traffic for a period of time (in binary format). If needed, the network packet data for this period of time can be stored in text format to make it readable and processable. (All kinds of network packet opening software support this type of operation).
[0073] This application does not make any specific limitation on the setting of a specific period of time.
[0074] The data storage format of flow data is as follows Figure 2 shown.
[0075] Figure 2 In terms of the data storage format of flow data, the data collection objects of this solution are stored in the form of KEY-VALUE through traffic restoration and log aggregation, with card number, ID number, etc. as the primary key, to support the machine learning training of data service objects and the rapid search and location of business vulnerabilities (leakage source tracing) of data information.
[0076] S102: Monitor the behavior of the IP address using a pre-built behavior monitoring model to obtain monitoring results.
[0077] In S102, a pre-built behavior monitoring model is used to perform cluster analysis on the IP address of the requesting end that initiates the request to the business system using a big data-related algorithm to obtain monitoring results for abnormal IP addresses with abnormal behavior or normal IP addresses with normal behavior.
[0078] The construction process of the specific behavior monitoring model is as follows:
[0079] First, the acquired identity data is marked as sensitive information through a preset machine learning algorithm.
[0080] Among them, a preset machine learning algorithm with intervention is used to mark the customer's card number, ID number, mobile phone number and other fields as sensitive information.
[0081] Then, the neural network model is trained through flow data and sensitive information to obtain an automated model; the automated model is a model for identifying abnormal IP addresses.
[0082] Among them, based on the stored transaction data and sensitive information, automated models of IP addresses (abnormal IP addresses and normal IP addresses), frequency of data transactions initiated by IP addresses (minutes, hours, days, etc.), and frequency of sensitive information are trained.
[0083] Finally, a behavior monitoring model is constructed based on the preset data calculation engine and automation model; the preset data calculation engine is used to improve the efficiency of obtaining abnormal IP addresses.
[0084] The preset calculation engine can eliminate the manual process and automatically implement the above process. All the data to be analyzed and the calculation logic can be put into the memory, so as to achieve millisecond-level analysis; the data to be analyzed can also be loaded into the memory in batches for analysis, similar to the form of batch processing, and can also achieve minute-level processing.
[0085] The preset data calculation engine can be a real-time data calculation engine such as Apache Flink, or other data calculation engines. The determination of the preset data calculation engine is set by technicians according to the actual situation, and this application does not make specific limitations. Preferably, the preset data calculation engine of this solution is the Apache Flink data calculation engine.
[0086] By deploying a real-time data calculation engine such as Apache Flink in production and combining it with an automated model, the request IP address is automatically and quickly classified into a normal IP address and an abnormal IP address for subsequent disposal of the abnormal IP address (set).
[0087] Specifically, the process of monitoring the behavior of the IP address through a pre-constructed behavior monitoring model to obtain the monitoring result is as shown in A1 - A3.
[0088] A1: Determine whether the access frequency of the IP address to initiate access to the business system within the preset time period is greater than the preset frequency through a pre-constructed behavior monitoring model.
[0089] Among them, the historical data of the business system is statistically analyzed to calculate the frequency of the IP address to initiate access to the business system within the preset time period. If the access frequency is greater than the preset frequency within the preset time period, the IP address is determined to be an abnormal IP address.
[0090] The preset time period can be 9:00 - 9:30, or 14:15 - 15:00. The specific preset time period is set by technicians according to the actual situation, and this application does not make specific limitations.
[0091] The preset frequency can be 10 times per minute, 150 times per hour, etc. The determination of the specific preset frequency is set by technicians according to the actual situation, and this application does not make specific limitations.
[0092] A2: If it is monitored that the access frequency of the IP address to initiate access to the business system within the preset time period is greater than the preset frequency, then generate a monitoring result indicating that the IP address is an abnormal IP address with abnormal behavior.
[0093] A3: If it is monitored that the access frequency of the IP address to initiate access to the business system within the preset time period is less than the preset frequency, then generate a monitoring result indicating that the IP address is a normal IP address with normal behavior.
[0094] S103: Determine the monitoring result. If the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior, then execute S104. If the monitoring result indicates that the IP address is a normal IP address with normal behavior, then execute S108.
[0095] S104: Guide the abnormal IP address to continuously submit identity data within the preset time period.
[0096] In S104, if an abnormal IP address is detected, a message indicating that a preset virtual transaction is successful is sent back to the abnormal IP address through a pre-established tandem link, so that the abnormal IP address continuously submits identity data within a preset time period.
[0097] Based on the identity data (data set), sufficient factual data (generally in the tens of thousands) is collected and provided to the bypass link for analysis. The factual data is real data such as the customer's card number, ID number, mobile phone number, etc. The factual data can be obtained through databases and other means.
[0098] S105: Determine the data distribution method of the identity data continuously submitted by the abnormal IP address within a preset time period and the transaction success rate corresponding to the abnormal IP address within the preset time period.
[0099] The specific process of determining the data distribution method of the identity data continuously submitted by the abnormal IP address within a preset time period and the transaction success rate corresponding to the abnormal IP address within the preset time period is as follows:
[0100] First, perform data distribution analysis on the identity data through a pre-established bypass link to obtain the data distribution method of the identity data continuously submitted by the abnormal IP address within a preset time period; the bypass link is used to converge the data of requests initiated by the abnormal IP address to the business system for data distribution analysis and data transaction statistics.
[0101] Among them, the data distribution method includes a continuous distribution method and a distribution jump method.
[0102] The preset time period can be 7:10 - 7:20, or 21:13 - 21:30, etc. The specific preset time period is determined by technical personnel according to the actual situation and is not specifically limited in this application.
[0103] Then, analyze the transactions corresponding to the abnormal IP address through the bypass link to obtain the transaction success rate corresponding to the abnormal IP address within a preset time period.
[0104] Among them, the transaction success rate is the success rate of the requester performing financial transactions, etc. through the business system.
[0105] S106: Classify the abnormal behavior of the abnormal IP address based on the data distribution method and the transaction success rate to obtain a classification result.
[0106] In S106, the classification result includes the first type of abnormal behavior, the second type of abnormal behavior, the third type of abnormal behavior, and the fourth type of abnormal behavior.
[0107] Specifically, the process of classifying the abnormal behaviors of abnormal IP addresses based on the data distribution method and the transaction success rate to obtain the classification results is shown in B1 - B4.
[0108] B1: If the data distribution method is a continuous distribution method and the transaction success rate is less than the preset success rate, it is determined that the abnormal behavior corresponding to the abnormal IP address is the first type of abnormal behavior.
[0109] Among them, for the data distribution method being a continuous distribution method or a relatively continuous distribution, and the transaction success rate being less than the preset success rate, it can be determined as a kind of "blind test" by hackers on the business vulnerability rules. That is, the first type of abnormal behavior indicates that the hacker has not yet substantially mastered the logical vulnerability rules of the business, and the harm is relatively small.
[0110] The preset success rate can be 80%, 85%, etc. The specific determination of the preset success rate is set by technical personnel according to the actual situation, and this application does not make specific limitations.
[0111] B2: If the data distribution method is a continuous distribution method and the transaction success rate is greater than or equal to the preset success rate, it is determined that the abnormal behavior corresponding to the abnormal IP address is the second type of abnormal behavior.
[0112] Among them, for the data distribution method being a continuous distribution method (or relatively continuous) and the transaction success rate being greater than or equal to the preset success rate, it can be determined that the second type of abnormal behavior indicates that the hacker has discovered the business vulnerability exploitation rule and attempts to steal the data of the business system, and the harm is great.
[0113] Determine the abnormal IP address of the second type of abnormal behavior as a malicious IP address, and block the malicious IP address through methods such as security Orchestration, Automation and Response (SOAR).
[0114] B3: If the data distribution method is a distribution jump method and the transaction success rate is greater than or equal to the preset success rate, it is determined that the abnormal behavior corresponding to the abnormal IP address is the third type of abnormal behavior.
[0115] Among them, for the data distribution method being a distribution jump method and the transaction success rate being greater than or equal to the preset success rate, it can be determined that the third type of abnormal behavior indicates that the hacker purchases the data of the business system from elsewhere for data verification or enriching the data dimension, and the harm is great.
[0116] Determine the abnormal IP address of the third type of abnormal behavior as a malicious IP address, and block the malicious IP address through methods such as SOAR.
[0117] B4: If the data distribution method is the distribution jump method and the transaction success rate is less than the preset success rate, determine that the abnormal behavior corresponding to the abnormal IP address is the fourth type of abnormal behavior.
[0118] Among them, for the data distribution method being the distribution jump method and the transaction success rate being less than the preset success rate, it can be determined that the fourth type of abnormal behavior indicates that the hacker purchased fake data from elsewhere or the data efficiency is very low, and the harm is relatively small.
[0119] This solution is based on the detection of abnormal IP addresses and combines series links to continuously collect the data in the hands of hackers, and will not cause data leakage and other security risks. Subsequently, analyze the data distribution and the actual transaction success rate on the bypass link, and the four types of abnormal behaviors of the abnormal IP address behavior can be realized. Through the combination of the series link and the bypass link, the safe and stable collection of the data in the hands of hackers is realized, and based on the sufficient amount of collected data, the credible analysis of the data distribution law and the real situation of the data is realized.
[0120] The four types of abnormal behavior classification of the abnormal behavior corresponding to the abnormal IP address in this solution can quickly judge the coupling of the occurrence of the submission point and the logical vulnerability, and combined with the massive retrieval of the flow data, the data leakage source of the data trading cases can be quickly traced back. And according to the four types of abnormal behaviors, provide automated operational emergency handling suggestions and vulnerability repair methods for developers and analysts.
[0121] S107: Execute corresponding handling operations based on the classification results.
[0122] In S107, execute their respective corresponding automated handling operations based on the first type of abnormal behavior, the second type of abnormal behavior, the third type of abnormal behavior, and the fourth type of abnormal behavior.
[0123] The specific process of executing corresponding handling operations based on the classification results is shown in C1 - C4.
[0124] C1: If the abnormal behavior corresponding to the abnormal IP address is the first type of abnormal behavior, ban the abnormal IP address and restrict the data submission operation of the abnormal IP address by means of a preset additional code.
[0125] Among them, for the first type of abnormal behavior, if the hacker submits data violently, the submission point of the submitted data (such as the function point of login, the function point of payment verification, etc.) is the business vulnerability point, and the hacker has not actually discovered the business vulnerability point. This solution automatically pushes suggestions such as adding additional codes to restrict the hacker's violent submission.
[0126] When adding an additional code, when an abnormal IP address submits data, a prompt for verification will pop up with a sliding drag window or a logical verification picture, hindering the submission of data by the abnormal IP address (or automated software).
[0127] Brute-force submission means that for the clicks of ordinary users on the fixed services of China Construction Bank, the time consumption is a certain period, and the operations are all for the same account. For example, if a hacker uses automated software and other means to submit hundreds of account information (card numbers, ID cards, mobile phone numbers, etc.) within one minute, it is brute-force submission.
[0128] C2: If the abnormal behavior corresponding to the abnormal IP address is the second type of abnormal behavior, then block the abnormal IP address, determine that the function point of the payment verification of the abnormal IP address is the business vulnerability exploitation point, and perform repair operations on the business vulnerability exploitation point.
[0129] Among them, for the second type of abnormal behavior, if a hacker performs brute-force submission, the submission point is the business vulnerability point. When the hacker substantially discovers the business vulnerability exploitation point, this solution automatically pushes to urgently take the function point offline for avoidance, and improves authentication and other recommended measures for repair.
[0130] Taking the function point offline urgently means urgently configuring the Uniform Resource Locator (URL) link of the function point, and the URL link cannot be accessed on the Internet anymore.
[0131] C3: If the abnormal behavior corresponding to the abnormal IP address is the third type of abnormal behavior, then block the abnormal IP address, restrict the data submission operation of the abnormal IP address through the preset additional code method, query the transaction data, locate the data aggregation point of the abnormal IP address based on the transaction data, and perform repair operations on the data aggregation point.
[0132] Among them, for the third type of abnormal behavior, the hacker's data comes from data trading and the origin of data leakage. This solution can automatically search in the transaction data storage system and perform clustering in various dimensions for quick positioning. After positioning, the handling methods for the first type of abnormal behavior and the second type of abnormal behavior can be referred to for repair.
[0133] Performing quick positioning through clustering in various dimensions means that a hacker submits a large number of card numbers through an abnormal IP address. Analyze whether these cards are credit cards or debit cards, and each type is divided into multiple sub-categories. Query information such as sub-categories, card opening time, and card opening branch to find the data aggregation point.
[0134] C4: If the abnormal behavior corresponding to the abnormal IP address is the fourth type of abnormal behavior, then perform termination tracing operations or extend data collection operations.
[0135] Among them, for the fourth type of abnormal behavior, the hacker's data comes from data trading, but the data authenticity is relatively poor or very poor (relatively poor or very poor data authenticity indicates that the data accuracy rate is less than the preset accuracy rate). When the data accuracy rate is less than the preset accuracy rate, the tracing can be terminated. This solution can push two strategies for terminating the tracing or extending the sampling of the hacker's dataset for decision-making. If the strategy of extending data collection is selected, the third type of abnormal behavior can be followed for location analysis.
[0136] Terminating the tracing means no longer sampling the data submitted by the hacker.
[0137] The preset accuracy rate can be less than 5% or less than 6%. The specific determination of the preset accuracy rate is set by technicians according to the actual situation, and this application does not make specific limitations. This solution preferably has a preset accuracy rate less than 5%.
[0138] S108: Allow normal IP addresses to access the business system for data.
[0139] Among them, run normal IP addresses to access the business system for data. Such as querying data, data transactions, etc.
[0140] In the embodiments of this application, trace the positions and characteristics of sensitive information at past time points to effectively detect past business vulnerabilities. And analyze data in dimensions such as the regularity of the data distribution method and the transaction success rate. For abnormal IP addresses determined to have abnormal behaviors, reverse-check the transaction data and perform automated analysis in combination with the accounting data to accurately locate business vulnerabilities and promptly handle business vulnerabilities, improving the accuracy of business vulnerability location and the timeliness of business vulnerability handling.
[0141] Reference Figure 3 As shown, for the construction process of the behavior monitoring model involved in the above S102, it mainly includes the following steps:
[0142] S301: Label the obtained identity data as sensitive information through a preset machine learning algorithm.
[0143] S302: Train the neural network model through transaction data and sensitive information to obtain an automated model; the automated model is a model for identifying abnormal IP addresses.
[0144] S303: Build a behavior monitoring model based on a preset data calculation engine and the automated model; the preset data calculation engine is used to improve the efficiency of obtaining abnormal IP addresses.
[0145] The execution principles of S301 - S303 are the same as those of the construction process of the behavior monitoring model in the above S102, which can be referred to and will not be elaborated here.
[0146] By storing and learning the persistence of request response characteristics for initiating important transactions, a behavior monitoring model for transactions, identifying abnormal IP addresses, and the frequency of sensitive information interaction is constructed. Based on the behavior monitoring model, automatic and reliable detection of abnormal IP addresses for various business vulnerability detections in the production environment is realized, solving the problem of effective detection of business vulnerabilities by traditional security devices.
[0147] In the embodiment of the present application, a behavior monitoring model is constructed. Through the behavior monitoring model, normal IPs and abnormal IPs are automatically identified, the regularity and success rate of data submitted by hackers are automatically obtained, and the location and characteristics of sensitive information appearing at past time points are automatically traced, so as to effectively detect, timely dispose of, and accurately locate business logic vulnerabilities that could not be detected in the past, thereby reducing the risk of loss of customer sensitive information, enhancing the robustness of the business system, safeguarding customer rights and interests, and corporate reputation.
[0148] Reference Figure 4 As shown, it is the process of performing behavior monitoring on the IP address through the pre-constructed behavior monitoring model involved in S102 above to obtain the monitoring result, mainly including the following steps:
[0149] S401: Determine whether the access frequency of the IP address initiating access to the business system within a preset time period is greater than the preset frequency through the pre-constructed behavior monitoring model. If it is monitored that the access frequency of the IP address initiating access to the business system within the preset time period is greater than the preset frequency, then execute S402. If it is monitored that the access frequency of the IP address initiating access to the business system within the preset time period is less than the preset frequency, then execute S403.
[0150] S402: Generate a monitoring result indicating that the IP address is an abnormal IP address with abnormal behavior.
[0151] S403: Generate a monitoring result indicating that the IP address is a normal IP address with normal behavior.
[0152] The execution principle of the above S401 - S403 is the same as that of the process of performing behavior monitoring on the IP address through the pre-constructed behavior monitoring model to obtain the monitoring result in the above S103, which can be referred to and will not be elaborated here.
[0153] In the embodiment of the present application, the behavior of the IP address is judged through the pre-constructed behavior monitoring model, so as to achieve the purpose of identifying whether the IP address is an abnormal IP address or a normal IP address.
[0154] Reference Figure 5As shown, it is the process of determining the data distribution mode of the identity data continuously submitted by the abnormal IP address within the preset time period and the transaction success rate corresponding to the abnormal IP address involved in the above 105, which includes the following steps:
[0155] S501: Perform data distribution analysis on the identity data through a pre-established bypass link to obtain the data distribution mode of the identity data continuously submitted by the abnormal IP address within the preset time period; the bypass link is used to converge the data of the requests initiated by the abnormal IP address to the service system for data distribution analysis and data transaction statistics.
[0156] S502: Analyze the transactions corresponding to the abnormal IP address through the bypass link to obtain the transaction success rate corresponding to the abnormal IP address within the preset time period.
[0157] The execution principles of S501 - S502 are the same as those of S105 above, which can be referred to and will not be elaborated here.
[0158] In the embodiment of the present application, by performing data distribution analysis on the identity data through a pre-established bypass link and analyzing the transactions corresponding to the abnormal IP address, the purpose of obtaining the data distribution mode of the identity data continuously submitted by the abnormal IP address within the preset time period and the transaction success rate corresponding to the abnormal IP address within the preset time period is achieved.
[0159] Based on the above embodiment Figure 1 A business vulnerability protection method disclosed, the embodiment of the present application also correspondingly discloses a business vulnerability protection system, as Figure 6 shown, the business vulnerability protection system mainly includes:
[0160] An acquisition unit 601, configured to acquire the flow data of the service system; the flow data at least includes the IP address of the request end that initiates a request to the service system.
[0161] A monitoring unit 602, configured to perform behavior monitoring on the IP address through a pre-constructed behavior monitoring model to obtain a monitoring result.
[0162] A guiding unit 603, configured to, if the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior, guide the abnormal IP address to continuously submit identity data within the preset time period.
[0163] A determination unit 604, configured to determine the data distribution mode of the identity data continuously submitted by the abnormal IP address within the preset time period and the transaction success rate corresponding to the abnormal IP address within the preset time period.
[0164] A classification unit 605, configured to classify the abnormal behavior of the abnormal IP address through the data distribution mode and the transaction success rate to obtain a classification result.
[0165] A disposal unit 606, configured to perform corresponding disposal operations based on the classification result.
[0166] Furthermore, the acquisition unit 601 is specifically configured to acquire the transaction data of the service system through a preset traffic restoration method and a preset log collection method; the preset traffic restoration method is used to acquire the transaction data when the service system is called through a preset external settlement channel; the preset log collection method is used to collect the transaction data of the server of the service system.
[0167] Furthermore, when constructing the behavior monitoring model, the monitoring unit 602 includes:
[0168] A labeling module, configured to label the acquired identity data as sensitive information through a preset machine learning algorithm.
[0169] A training module, configured to train a neural network model with the transaction data and sensitive information to obtain an automated model; the automated model is a model for identifying abnormal IP addresses.
[0170] A construction module, configured to construct a behavior monitoring model based on a preset data calculation engine and the automated model; the preset data calculation engine is used to improve the efficiency of obtaining abnormal IP addresses.
[0171] Furthermore, the monitoring unit 602 includes:
[0172] A judgment module, configured to judge whether the access frequency of an IP address accessing the service system within a preset time period is greater than a preset frequency through a pre-constructed behavior monitoring model.
[0173] A first generation module, configured to generate a monitoring result indicating that the IP address is an abnormal IP address with abnormal behavior if it is monitored that the access frequency of the IP address accessing the service system within a preset time period is greater than the preset frequency.
[0174] A second generation module, configured to generate a monitoring result indicating that the IP address is a normal IP address with normal behavior if it is monitored that the access frequency of the IP address accessing the service system within a preset time period is less than the preset frequency.
[0175] Furthermore, the guiding unit 603 is specifically configured to, if it is monitored that the IP address is an abnormal IP address, reply a preset virtual transaction success message to the abnormal IP address through a pre-established serial link, so that the abnormal IP address continuously submits identity data within a preset time period.
[0176] Furthermore, the determination unit 604 includes:
[0177] A first analysis module, configured to perform data distribution analysis on identity data through a pre-established bypass link, and obtain a data distribution pattern of the identity data continuously submitted by an abnormal IP address within a preset period; the bypass link is used to converge data of requests initiated by the abnormal IP address to a service system for data distribution analysis and data transaction statistics.
[0178] A second analysis module, configured to analyze transactions corresponding to the abnormal IP address through the bypass link, and obtain a transaction success rate corresponding to the abnormal IP address within a preset period.
[0179] Further, the classification unit 605 includes:
[0180] A first determination module, configured to determine that the abnormal behavior corresponding to the abnormal IP address is a first type of abnormal behavior if the data distribution pattern is a continuous distribution pattern and the transaction success rate is less than a preset success rate.
[0181] A second determination module, configured to determine that the abnormal behavior corresponding to the abnormal IP address is a second type of abnormal behavior if the data distribution pattern is a continuous distribution pattern and the transaction success rate is greater than or equal to the preset success rate.
[0182] A third determination module, configured to determine that the abnormal behavior corresponding to the abnormal IP address is a third type of abnormal behavior if the data distribution pattern is a distribution jump pattern and the transaction success rate is greater than or equal to the preset success rate.
[0183] A fourth determination module, configured to determine that the abnormal behavior corresponding to the abnormal IP address is a fourth type of abnormal behavior if the data distribution pattern is a distribution jump pattern and the transaction success rate is less than the preset success rate.
[0184] Further, the handling unit 606 includes:
[0185] A restriction module, configured to restrict the data submission operation of the abnormal IP address by a preset additional code method if the abnormal behavior corresponding to the abnormal IP address is a first type of abnormal behavior.
[0186] A first repair module, configured to determine that the function point of the payment verification of the abnormal IP address is a service vulnerability exploitation point and perform a repair operation on the service vulnerability exploitation point if the abnormal behavior corresponding to the abnormal IP address is a second type of abnormal behavior.
[0187] A second repair module, configured to restrict the data submission operation of the abnormal IP address by a preset additional code method, query the transaction data, locate the data aggregation point of the abnormal IP address based on the transaction data, and perform a repair operation on the data aggregation point if the abnormal behavior corresponding to the abnormal IP address is a third type of abnormal behavior.
[0188] An execution module, configured to perform a termination tracing operation or extend a data collection operation if the abnormal behavior corresponding to the abnormal IP address is a fourth - type abnormal behavior.
[0189] In the embodiments of the present application, the positions and characteristics of sensitive information at past time points are traced to effectively detect past business vulnerabilities. Moreover, data such as the regularity of the data distribution method and the transaction success rate are analyzed. For abnormal IP addresses determined to have abnormal behaviors, the flow data is retrieved and automatically analyzed in combination with the account data, so as to accurately locate business vulnerabilities and promptly handle business vulnerabilities, improving the accuracy of business vulnerability location and the timeliness of business vulnerability handling.
[0190] For the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0191] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For system - type embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.
[0192] The steps in the methods of the embodiments of the present application can be adjusted, combined, and deleted according to actual needs.
[0193] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or sequence between these entities or operations.
[0194] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0195] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A method for protecting business vulnerabilities, characterized in that, The method comprises: Acquire the flow data of the business system; the flow data at least includes the IP address of the request end that initiates the request to the business system; Performing behavior monitoring on the IP address through a pre-built behavior monitoring model to obtain monitoring results; If the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior, guiding the abnormal IP address to continuously submit identity data within a preset period of time; Determine the data distribution mode of the identity data continuously submitted by the abnormal IP address within a preset period of time and the transaction success rate corresponding to the abnormal IP address within the preset period of time; The abnormal behavior of the abnormal IP address is classified by the data distribution mode and the transaction success rate to obtain a classification result, including: if the data distribution mode is a continuous distribution mode and the transaction success rate is less than a preset success rate, the abnormal behavior corresponding to the abnormal IP address is determined to be a first type of abnormal behavior; the first type of abnormal behavior indicates that the hacker has not substantially mastered the logical vulnerability rules of the business and the harm is relatively small; if the data distribution mode is the continuous distribution mode and the transaction success rate is greater than or equal to the preset success rate, the abnormal behavior corresponding to the abnormal IP address is determined to be a second type of abnormal behavior; the second type of abnormal behavior indicates that the hacker has discovered the business vulnerability exploitation rules, And attempt to steal the data of the business system, which is very harmful; if the data distribution method is the distribution jump method, and the transaction success rate is greater than or equal to the preset success rate, then determine that the abnormal behavior corresponding to the abnormal IP address is the third type of abnormal behavior; the third type of abnormal behavior indicates that the hacker purchased the data of the business system from elsewhere to verify the data or enrich the data dimension, which is very harmful; if the data distribution method is the distribution jump method, and the transaction success rate is less than the preset success rate, then determine that the abnormal behavior corresponding to the abnormal IP address is the fourth type of abnormal behavior; the fourth type of abnormal behavior indicates that the hacker purchased fake data from elsewhere or the data efficiency is very low, which is less harmful; Executing corresponding disposal operations based on the classification result, including: if the abnormal behavior corresponding to the abnormal IP address is the first type of abnormal behavior, limiting the data submission operation of the abnormal IP address by means of a preset additional code; if the abnormal behavior corresponding to the abnormal IP address is the second type of abnormal behavior, determining that the functional point of the payment verification of the abnormal IP address is a business vulnerability exploitation point, and performing a repair operation on the business vulnerability exploitation point; if the abnormal behavior corresponding to the abnormal IP address is the third type of abnormal behavior, limiting the data submission operation of the abnormal IP address by means of a preset additional code, querying the transaction data, locating the data collection point of the abnormal IP address based on the transaction data, and performing a repair operation on the data collection point; if the abnormal behavior corresponding to the abnormal IP address is the fourth type of abnormal behavior, executing a termination traceback operation or extending the data collection operation.
2. The method according to claim 1, characterized in that, The step of obtaining the flow data of the business system includes: Obtain the transaction data of the business system through a preset traffic restoration method and a preset log collection method; the preset traffic restoration method is used to obtain the transaction data when the business system is called through a preset external settlement channel; the preset log collection method is used to collect the transaction data of the server of the business system.
3. The method according to claim 1, characterized in that, The construction process of the behavior monitoring model includes: Label the obtained identity data as sensitive information through a preset machine learning algorithm; Train a neural network model with the transaction data and the sensitive information to obtain an automated model; the automated model is a model for identifying abnormal IP addresses; Build a behavior monitoring model based on a preset data calculation engine and the automated model; the preset data calculation engine is used to improve the efficiency of obtaining the abnormal IP address.
4. The method according to claim 1, characterized in that, The behavior monitoring of the IP address through the pre-built behavior monitoring model to obtain a monitoring result includes: Judge whether the access frequency of the IP address accessing the business system within a preset time period is greater than a preset frequency through the pre-built behavior monitoring model; If it is monitored that the access frequency of the IP address accessing the business system within the preset time period is greater than the preset frequency, generate a monitoring result indicating that the IP address is an abnormal IP address with abnormal behavior; If it is monitored that the access frequency of the IP address accessing the business system within the preset time period is less than the preset frequency, generate a monitoring result indicating that the IP address is a normal IP address with normal behavior.
5. The method according to claim 1, characterized in that, If the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior, guide the abnormal IP address to continuously submit identity data within a preset time period, including: If the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior, send a message indicating successful preset virtual transaction to the abnormal IP address through a pre-established series link, so that the abnormal IP address continuously submits identity data within a preset time period.
6. The method according to claim 1, characterized in that, Determine the data distribution method of the identity data continuously submitted by the abnormal IP address within a preset time period and the transaction success rate corresponding to the abnormal IP address within the preset time period, including: Conduct data distribution analysis on the identity data through a pre-established bypass link to obtain the data distribution method of the identity data continuously submitted by the abnormal IP address within a preset time period; the bypass link is used to converge the data of the requests initiated by the abnormal IP address to the business system for data distribution analysis and data transaction statistics; Analyze the transactions corresponding to the abnormal IP address through the bypass link to obtain the transaction success rate corresponding to the abnormal IP address within the preset time period.
7. A business vulnerability protection system, characterized in that, The system includes: An acquisition unit, used to acquire the transaction data of the business system; the transaction data at least includes the IP address of the request end that initiates a request to the business system; A monitoring unit, used to conduct behavior monitoring on the IP address through a pre-built behavior monitoring model to obtain a monitoring result; A guiding unit, configured to guide the abnormal IP address to continuously submit identity data within a preset period if the monitoring result indicates that the IP address is an abnormal IP address with abnormal behavior; A determining unit, configured to determine the data distribution mode of the identity data continuously submitted by the abnormal IP address within a preset period and the transaction success rate corresponding to the abnormal IP address within the preset period; A classification unit, configured to classify the abnormal behavior of the abnormal IP address through the data distribution mode and the transaction success rate to obtain a classification result; The classification unit includes: a first determining module, a second determining module, a third determining module, and a fourth determining module; The first determining module is configured to determine that the abnormal behavior corresponding to the abnormal IP address is a first type of abnormal behavior if the data distribution mode is a continuous distribution mode and the transaction success rate is less than a preset success rate; the first type of abnormal behavior indicates that the hacker has not substantially mastered the logical vulnerability rules of the service and the harm is relatively small; The second determining module is configured to determine that the abnormal behavior corresponding to the abnormal IP address is a second type of abnormal behavior if the data distribution mode is the continuous distribution mode and the transaction success rate is greater than or equal to the preset success rate; the second type of abnormal behavior indicates that the hacker has discovered the law of exploiting service vulnerabilities and attempts to steal the data of the service system, and the harm is very large; The third determining module is configured to determine that the abnormal behavior corresponding to the abnormal IP address is a third type of abnormal behavior if the data distribution mode is a distribution jump mode and the transaction success rate is greater than or equal to the preset success rate; the third type of abnormal behavior indicates that the hacker purchases the data of the service system from elsewhere for data verification or enriching the data dimension, and the harm is very large; The fourth determining module is configured to determine that the abnormal behavior corresponding to the abnormal IP address is a fourth type of abnormal behavior if the data distribution mode is the distribution jump mode and the transaction success rate is less than the preset success rate; the fourth type of abnormal behavior indicates that the hacker purchases fake data or the data efficiency from elsewhere is very low, and the harm is relatively small; A handling unit, configured to perform corresponding handling operations based on the classification result; The handling unit includes: a restriction module, a first repair module, a second repair module, and an execution module; The restriction module is configured to restrict the data submission operation of the abnormal IP address by a preset additional code method if the abnormal behavior corresponding to the abnormal IP address is the first type of abnormal behavior; The first repair module is configured to determine the function point of the payment verification of the abnormal IP address as the service vulnerability exploitation point and perform a repair operation on the service vulnerability exploitation point if the abnormal behavior corresponding to the abnormal IP address is the second type of abnormal behavior; The second repair module is used to, if the abnormal behavior corresponding to the abnormal IP address is the third type of abnormal behavior, restrict the data submission operation of the abnormal IP address by means of a preset additional code, query the flow data, locate the data aggregation point of the abnormal IP address based on the flow data, and perform a repair operation on the data aggregation point; The execution module is used to, if the abnormal behavior corresponding to the abnormal IP address is the fourth type of abnormal behavior, perform a termination tracing operation or extend the data collection operation.
8. The system according to claim 7, wherein, The obtaining unit is specifically used for: Obtaining the flow data of the service system through a preset flow restoration method and a preset log collection method; the preset flow restoration method is used to obtain the flow data when the service system is called through a preset external settlement channel; The preset log collection method is used to collect the flow data of the server of the service system.
Citation Information
Patent Citations
Abnormity detecting method based on service flow and system thereof
CN108616529A