A method, device, equipment and storage medium for detecting website intrusion and tampering

By obtaining and analyzing the various web page information of the website and selecting the appropriate detection method for intrusion and tampering detection, the accuracy of website intrusion and tampering detection is solved and efficient website security is achieved.

CN114117299BActive Publication Date: 2025-07-01EVERSEC BEIJING TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111361696.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-17
Publication Date
2025-07-01
Estimated Expiration
2041-11-17

AI Technical Summary

Technical Problem

How to accurately detect whether the website is invaded and tampered and ensure the security of the website.

Method used

By obtaining the web page information collection of the website to be detected, including the web page source code, web page domain name, web page picture and web page text information, select the web page information to be detected, determine its detection method and perform corresponding tampering detection to obtain the detection results.

Benefits of technology

Accurate detection of website intrusion and tampering is achieved, and appropriate detection methods are selected through different types of web page information to improve the accuracy of the detection results and ensure the security of the website.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114117299B_ABST
    Figure CN114117299B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention discloses a method, device, equipment and storage medium for detecting website intrusion and tampering. The method includes: obtaining a set of web page information of a website to be detected, where the set of web page information includes at least one of the following web page information: web page source code, web page domain name, web page pictures and web page text information; selecting the web page information to be detected from the set of web page information, determining the detection method corresponding to the web page information to be detected and performing corresponding tampering detection, and determining the tampering detection result. By obtaining the set of web page information and performing intrusion and tampering detection on the web page information to be detected in the set of web page information, the security of the website to be detected is ensured. According to the information type of the web page information to be detected, a suitable detection method is selected to detect the website to be detected from different angles, improving the accuracy of the detection result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of computer technologies, and in particular, to a method, apparatus, device, and storage medium for detecting website intrusion and tampering. Background Art

[0002] With the rapid development of the digital society, the Internet has had a profound impact on business, industry, banking, finance, education, government, entertainment, and people's work and life. Many traditional information is being migrated to the Internet. As an important platform for e-government and e-commerce, once a website is hacked, important information and data will be obtained, damaged, or tampered with, and at the same time, it will also cause significant economic losses and adverse social impacts. Therefore, how to detect whether a website has been invaded and tampered with has become particularly important. Summary of the Invention

[0003] The present invention provides a method, apparatus, device, and storage medium for detecting website intrusion and tampering to achieve accurate detection of website intrusion and tampering.

[0004] In a first aspect, embodiments of the present invention provide a method for detecting website intrusion and tampering, the method including:

[0005] Obtaining a set of web page information of a website to be detected, the set of web page information including at least one of the following web page information: web page source code, web page domain name, web page pictures, and web page text information;

[0006] Selecting web page information to be detected from the set of web page information, determining a detection method corresponding to the web page information to be detected, performing corresponding tampering detection, and determining a tampering detection result.

[0007] In a second aspect, embodiments of the present invention further provide a device for detecting website intrusion and tampering, the device including:

[0008] An information set obtaining module, configured to obtain a set of web page information of a website to be detected, the set of web page information including at least one of the following web page information: web page source code, web page domain name, web page pictures, and web page text information;

[0009] A detection module, configured to select web page information to be detected from the set of web page information, determine a detection method corresponding to the web page information to be detected, perform corresponding tampering detection, and determine a tampering detection result.

[0010] In a third aspect, embodiments of the present invention further provide a computer device, the device including:

[0011] One or more processors;

[0012] A memory, configured to store one or more programs,

[0013] When the one or more programs are executed by the one or more processors, the one or more processors implement a website intrusion and tampering detection method as described in any one of the embodiments of the present invention.

[0014] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements a website intrusion and tampering detection method as described in any one of the embodiments of the present invention.

[0015] An embodiment of the present invention provides a website intrusion and tampering detection method, device, equipment and storage medium. By obtaining a set of web page information of a website to be detected, the set of web page information includes at least one of the following web page information: web page source code, web page domain name, web page picture and web page text information; selecting the web page information to be detected from the set of web page information, determining the detection method corresponding to the web page information to be detected and performing corresponding tampering detection, and determining the tampering detection result. By obtaining the set of web page information and performing intrusion and tampering detection on the web page information to be detected in the set of web page information, the security of the website to be detected is ensured. Selecting a suitable detection method according to the information type of the web page information to be detected and performing detection on the website to be detected from different angles improves the accuracy of the detection result. Description of the Drawings

[0016] Figure 1 is a flowchart of a website intrusion and tampering detection method in Embodiment 1 of the present invention;

[0017] Figure 2 is a schematic structural diagram of a website intrusion and tampering detection system in Embodiment 1 of the present invention;

[0018] Figure 3 is a flowchart of a website intrusion and tampering detection method in Embodiment 2 of the present invention;

[0019] Figure 4 is an implementation example diagram of a website intrusion and tampering detection method in Embodiment 2 of the present invention;

[0020] Figure 5 is a schematic structural diagram of a website intrusion and tampering detection device in Embodiment 3 of the present invention;

[0021] Figure 6 is a schematic structural diagram of a computer device in Embodiment 4 of the present invention. Detailed Embodiments

[0022] To make the objectives, technical solutions and advantages of this application more clear, the following will further describe in detail the embodiments of this application in conjunction with the accompanying drawings. It should be clear that the described embodiments are only a part of the embodiments of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.

[0023] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. On the contrary, they are merely examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.

[0024] In the description of this application, it should be understood that the terms "first", "second", "third", etc. are only used to distinguish similar objects, and do not have to be used to describe a specific order or sequence, nor can they be understood as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances. In addition, in the description of this application, unless otherwise specified, "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0025] Embodiment 1

[0026] Figure 1 The flowchart of a website intrusion and tampering detection method provided in Embodiment 1 of this application is given. This method is applicable to detecting whether a website has been invaded and tampered with. This method can be executed by a computer device, which can be composed of two or more physical entities or one physical entity. Generally speaking, the computer device can be a notebook, a desktop computer, a smart tablet, etc.

[0027] Figure 2Schematic diagram of the architecture of a website intrusion and tampering detection system provided in this embodiment. The system includes a data source access module 11, a metadata screening module 12, a high-performance detection engine 13, a lightweight message queue 14, a RESTFUL_API interface 15, and an intrusion and tampering detection and analysis module 16. Among them, the data source access module 11 is used to obtain the data of the website to be detected 111, and the website to be detected can be a key website, a recorded website, etc. The metadata screening module 12 screens the data, and the data screening includes data format screening, data validity screening, and data format parsing. The high-performance detection engine 13 implements data detection, and the data detection includes implanted dark link detection, web page image detection, and web page text information detection to obtain the tampering detection result. The data is processed through the lightweight message queue 14, and the lightweight message queue 14 includes a message data producer Producer, message and data consumers Consumers, and a message queue Message. The detected tampering detection result is sent to the intrusion and tampering detection and analysis module 16 through the open RESTFUL_API interface 15 for detection result analysis.

[0028] As Figure 1 shown, a website intrusion and tampering detection method provided in Embodiment 1 specifically includes the following steps:

[0029] S101. Obtain the web page information set of the website to be detected. The web page information set includes at least one of the following web page information: web page source code, web page domain name, web page images, and web page text information.

[0030] In this embodiment, the website to be detected can be specifically understood as a website with the need to detect whether it has been invaded and tampered with. The website to be detected in this application can be any website. The website to be detected can be preset, and preset according to the importance of different websites. When the number of websites to be detected is more than one, the same method is used for intrusion and tampering detection for each website to be detected. The web page information set can be specifically understood as a data set composed of different types of web page information. The web page image can be specifically understood as the image displayed on the web page; the web page text information can be specifically understood as the text information on the web page, such as Chinese, English, etc. The web page information of the website to be detected is collected, and the web page information is the web page source code, web page domain name, web page image, or web page text information. The method for obtaining the web page information of the website to be detected can be through crawler collection. Among them, the web page domain name is extracted from the MD5.txt file, and the web page text information is obtained from the MD5.txt and MD5.html files.

[0031] S102. Select the web page information to be detected from the web page information set, determine the detection method corresponding to the web page information to be detected and perform corresponding tampering detection, and determine the tampering detection result.

[0032] In this embodiment, the web page information to be detected can be specifically understood as the web page information with detection requirements. Since there are various types of web page information, different web page information needs to be detected in different ways. The tampering detection result can be specifically understood as the detection result obtained after intrusion tampering detection, which can be either tampering occurred or no tampering occurred; when the tampering detection result indicates that tampering has occurred, the tampering detection result can be directly represented by the tampering type.

[0033] Specifically, select a type of web page information from the web page information set as the web page information to be detected and perform detection. When performing detection, for the web page information in the web page information set, only one item can be selected for detection, or multiple items of web page information can be selected for detection. When it is necessary to detect multiple types of web page information, one type of web page information can be first selected as the web page information to be detected. After completing the detection of this web page information to be detected, select another type of web page information from the web page information set as the new web page information to be detected and select an appropriate detection method for detection. When the web page information to be detected is web page source code or web page domain name, implant chain detection is performed. Implant chain detection includes regular expression detection, subdomain detection, and website detection. When the web page information to be detected is web page image or web page text information, content detection is performed through machine learning or neural network technology. For example, it is detected whether the web page image or web page text information contains negative information or negative words. Through tampering detection, the tampering detection result is obtained.

[0034] An embodiment of the present invention provides a method for detecting website intrusion and tampering. By obtaining a web page information set of a website to be detected, the web page information set includes at least one of the following web page information: web page source code, web page domain name, web page image, and web page text information; select the web page information to be detected from the web page information set, determine the corresponding detection method for the web page information to be detected and perform corresponding tampering detection, and determine the tampering detection result. By obtaining the web page information set and performing intrusion tampering detection on the web page information to be detected in the web page information set, the security of the website to be detected is ensured. According to the information type of the web page information to be detected, an appropriate detection method is selected to detect the website to be detected from different angles, improving the accuracy of the detection result.

[0035] Embodiment 2

[0036] Figure 3 It is a flowchart of a method for detecting website intrusion and tampering provided by Embodiment 2 of the present invention. The technical solution of this embodiment is further refined on the basis of the above technical solution, and specifically mainly includes the following steps:

[0037] S201. Obtain a web page information set of a website to be detected.

[0038] When the web page information to be detected is the web page source code, execute S202 - S203 to determine the tampering detection result.

[0039] S202. Obtain a pre - determined set of regular expressions.

[0040] In this embodiment, the set of regular expressions can be specifically understood as a data set composed of one or more regular expressions.

[0041] It should be noted that when detecting the web page source code, the principle is to analyze the web page source code to detect hidden links (i.e., hidden links, which is one of the cheating methods of black - hat SEO). In order to detect whether the web page source code structure has been maliciously modified (making the content invisible), the commonly used method of sending and receiving "hidden links" in black - hat SEO is detected to realize the detection of whether the web page source code structure has been tampered with.

[0042] There are three common types of hidden links: setting the attribute color of the label to be invisible, the position to be invisible, and the attribute not to be displayed. For different types of hidden links, corresponding regular expressions are set for detection. The regular expressions required for detecting different types of hidden links are pre - determined, and a set of regular expressions is formed and stored according to each regular expression. When performing intrusion tampering detection on the web page source code, directly obtain the set of regular expressions.

[0043] S203. Perform string matching detection on the web page source code according to the regular expressions in the set of regular expressions to determine the tampering detection result.

[0044] Perform string matching on the web page source code in turn through the regular expressions in the set of regular expressions. If the matching is successful, the web page source code has been tampered with; if all the matchings are unsuccessful, the web page source code has not been tampered with.

[0045] When the web page information to be detected is the web page domain name, execute S204 - S207 or execute S208 - S210 to determine the tampering detection result.

[0046] S204. Obtain the web page source code and analyze it to determine the set of web page hyperlinks.

[0047] In this embodiment, the set of web page hyperlinks can be specifically understood as a data set composed of all the hyperlinks of the web page, that is, all the external link sets. If the web page information to be detected is the web page domain name, the intrusion tampering detection performed at this time can be sub - domain detection or detection of whether the website domain name has been tampered with. For the two different types of detections, different methods are used for detection. For sub - domain detection, the detection is performed through steps S204 - S209; for detection of whether the website domain name has been tampered with, the detection is performed through steps S210 - S212.

[0048] Specifically, when performing a wildcard subdomain detection on a web page domain name, obtain the web page source code and analyze the web page source code to obtain one or more web page hyperlinks, which form a web page hyperlink set.

[0049] S205. Determine the target subdomain based on the web page hyperlink set and the web page domain name.

[0050] In this embodiment, the target subdomain can be specifically understood as the subdomain of a web page hyperlink that does not match the subdomain of the web page domain name.

[0051] Specifically, extract the subdomains of the web page hyperlinks in the web page hyperlink set and the web page domain name respectively, and perform a loop match on the subdomains of the web page hyperlink set and the web page domain name, and determine the target subdomain according to the matching result.

[0052] As an alternative embodiment of this embodiment, this alternative embodiment further optimizes determining the target subdomain based on the web page hyperlink set and the web page domain name to:

[0053] A1. Extract the subdomains of the web page hyperlinks in the web page hyperlink set to obtain at least one hyperlink subdomain.

[0054] In this embodiment, the hyperlink subdomain can be specifically understood as the subdomain of the web page hyperlink. Extract the subdomains of each web page hyperlink in the web page hyperlink set respectively to obtain the hyperlink subdomains.

[0055] A2. Extract the subdomain of the web page domain name to obtain the web page subdomain.

[0056] In this embodiment, the web page subdomain can be specifically understood as the subdomain corresponding to the web page domain name. Extract the subdomain of the web page domain name to obtain the web page subdomain.

[0057] A3. Compare each hyperlink subdomain with the web page subdomain respectively.

[0058] For each hyperlink subdomain, match and compare it with the remaining web page subdomains respectively to determine whether the hyperlink subdomain is the same as the web page subdomain.

[0059] A4. Determine the hyperlink subdomains with different comparison results as the target subdomains.

[0060] Determine the hyperlink subdomains with different comparison results, and determine this part of hyperlink subdomains as the target subdomains.

[0061] S206. Count the number of target subdomains.

[0062] S207. Determine whether the quantity is greater than the first preset quantity threshold. If yes, execute S208; otherwise, execute S209.

[0063] S208. Determine that the tampering detection result is a secondary domain name tampering.

[0064] S209. Determine that the tampering detection result is no tampering occurred.

[0065] In this embodiment, the first preset quantity threshold can be specifically understood as the boundary value for determining whether the quantity of the target secondary domain names is within the normal range. The first preset quantity threshold can be set according to requirements. Compare the quantity with the first preset quantity threshold. When the quantity is greater than the first preset quantity threshold, determine that the tampering detection result is a secondary domain name tampering; when the quantity is less than or equal to the first preset quantity threshold, determine that the tampering detection result is no tampering occurred.

[0066] S210. Output the web domain name to the domain name detection platform through a preset web security interface.

[0067] In this embodiment, the web security interface can be specifically understood as an interface for performing web intrusion and tampering checks to ensure web security. The domain name detection platform can specifically be a platform for detecting whether the web domain name has been tampered with. The domain name detection platform can also verify whether other functions of the website are accurate. Output the web domain name to the domain name detection platform through the web security interface so that the domain name detection platform can perform domain name detection.

[0068] S211. Receive the domain name detection result returned by the domain name detection platform.

[0069] In this embodiment, the domain name detection result can be that the domain name is normal or the domain name is abnormal. The domain name detection platform detects the web domain name and verifies whether the web domain name is normal.

[0070] S212. Analyze the domain name detection result to determine the tampering detection result.

[0071] When the domain name detection result is normal, the tampering detection result is no tampering occurred; when the domain name detection result is abnormal, the tampering detection result is that the website domain name has been tampered with.

[0072] When the to-be-detected web page information is a web page picture, execute S213 - S215 to determine the tampering detection result.

[0073] S213. Input the web page picture into a pre-determined picture detection network model, which is trained according to a detection data set and a classification data set.

[0074] In this embodiment, the image detection network model can be specifically understood as a neural network model for identifying objects existing in an image. There are many limitations in the detection datasets. The information of the classification labels is too scarce, the number of images is less than that of the classification datasets, and the cost of the detection datasets is too high, making it impossible to be used as a classification dataset. However, the classification datasets have a large number of images and very rich classification information. This application proposes a new training method - the joint training algorithm. By mixing the data of the detection datasets and the classification datasets together, classifying objects from a hierarchical perspective, and using the data of the massive classification datasets to expand the detection datasets, thus mixing the two different datasets. Train object detectors on the detection datasets and the classification datasets, learn the accurate positions of objects with the data of the detection datasets, and increase the number of classification categories and improve the robustness of the model with the data of the classification datasets. Train the image detection network model through the data in the detection datasets and the classification datasets, input the web page images into the image detection network model, and the image detection network model performs prediction processing on the web page images according to the learned experience.

[0075] As an optional embodiment of this embodiment, this optional embodiment further optimizes the training of the image detection network model. The training steps of the image detection network model include:

[0076] B1. Obtain the detection datasets and the classification datasets. The training images in the detection datasets and the classification datasets correspond to the associated standard information, and the standard information includes standard position information and standard category information.

[0077] In this embodiment, the training images can be specifically understood as the images used for model training; the standard information can be specifically understood as the information for annotating the targets in the training images. For example, if a training image includes a cat and a seal, the standard information for annotating the cat is the cat, with the horizontal coordinate being 30 - 50 pixel points and the vertical coordinate being 40 - 70 pixel points. Among them, the cat is the standard category information; the horizontal coordinate being 30 - 50 pixel points and the vertical coordinate being 40 - 70 pixel points are the standard position information. The standard position information can also be represented in other ways, such as the coordinates of the left vertex, as well as the length and width, from which the matrix box can be determined, and the position of the rectangular box is the position of the target. The training images in the detection datasets and the classification datasets are pre-annotated, and the datasets can be directly obtained during model training.

[0078] B2. Input the training images corresponding to the current iteration into the current training network model to obtain prediction information, where the prediction information includes prediction position information and prediction category information.

[0079] In this embodiment, the network model to be trained can be specifically understood as an incompletely trained neural network model based on deep learning. The prediction information can be specifically understood as the information obtained by model prediction, and the prediction information includes prediction position information and further prediction category information.

[0080] Specifically, input the training image corresponding to the current iteration into the current network model to be trained. The network model to be trained makes predictions according to the current network parameters, and obtains the prediction position information and prediction category information corresponding to each target in the training image.

[0081] B3. Adopt the given loss function expression, combine the standard information and the prediction information, and obtain the corresponding loss function.

[0082] In this embodiment, the loss function expression can be understood as the expression for calculating the loss function. When performing backpropagation on the network model to be trained, it is necessary to adjust the model parameters through the loss function. The loss function can be a GAN loss function, an L1 loss function, a focal loss function, a VGG perceptual loss function, etc.

[0083] Specifically, for each training image, calculate according to its corresponding standard information and prediction information using the loss function expression to obtain the corresponding loss function. When there are multiple targets in an image, since each target corresponds to standard information and prediction information, the loss function corresponding to each target can be calculated in sequence. After obtaining multiple loss functions, calculate according to the multiple loss functions to obtain the final loss function as the loss function for this iteration.

[0084] B4. Perform backpropagation on the network model to be trained based on the loss function to obtain the network model to be trained for the next iteration until the iteration convergence condition is met, and obtain the image detection network model.

[0085] During the training process of the neural network model, the model is continuously updated and adjusted through the backpropagation method until the output of the model converges to the target. After determining the loss function, use this loss function to perform backpropagation on the network model to be trained to obtain the image detection network model that meets the convergence condition. The embodiments of the present invention do not limit the specific backpropagation process, which can be set according to specific situations. After the model training is completed, the image detection network model can be used to predict the category and position of the objects in the image.

[0086] S214. Determine the target object according to the output result of the image detection network model.

[0087] In this embodiment, the target object can be specifically understood as an object in a web page image. After the web page image is input into the image detection network model, the image detection network model performs prediction processing on the web page image according to the network parameters to obtain the position of the target object and the category of the target object.

[0088] S215. Perform anomaly detection on the text to be detected in the target object, and determine the tampering detection result according to the anomaly detection result.

[0089] In this embodiment, the text to be detected can be specifically understood as the text included in the target object. For example, if the target object is a seal, the text in the seal is the text to be detected. The anomaly detection result can be text anomaly or text normal. There may be text to be detected in the target object, and the text to be detected may be abnormal text. For example, it contains negative information, inappropriate remarks, etc. Detect whether the text to be detected is abnormal, and determine the tampering detection result according to the anomaly detection result. For example, when the text is abnormal, the tampering detection result is that tampering has occurred; when the text is normal, the tampering detection result is that no tampering has occurred.

[0090] When the web page information to be detected is web page text information, execute S216 - S219.

[0091] S216. Obtain the web page source code and determine the text tags in the web page source code.

[0092] In this embodiment, the text tags are the text tags when designing a web page through HTML. When detecting whether the web page text information has been invaded and tampered with, it is necessary to obtain the web page source code and perform invasion and tampering detection on the web page text information according to the web page source code. Directly obtain the web page source code, analyze the web page source code, and obtain all the text tags in the web page source code.

[0093] S217. Determine the target text according to each text tag and the web page text information.

[0094] In this embodiment, the target text can be specifically understood as the text screened out from the web page text information. Determine the text in the web page text information according to the text tags, and then screen the length of the text to obtain the target text that meets the conditions.

[0095] As an alternative embodiment of this embodiment, this alternative embodiment further optimizes determining the target text according to each text tag and the web page text information to:

[0096] C1. Determine the text length of the text corresponding to each text tag in the web page text information.

[0097] In this embodiment, the text length can be specifically understood as the length of the data included in the text. Search for the text corresponding to each text tag in the web page text information, and determine the text length of each text.

[0098] C2. Determine the target text lengths that meet the preset length conditions among the text lengths.

[0099] In this embodiment, the preset length condition is a preset length range, such as 2 - 20. Determine whether each text length meets the preset length condition in turn. If so, determine this text length as the target text length.

[0100] C3. Determine the text corresponding to the target text length as the target text.

[0101] Determine the text corresponding to each target text length, and determine this part of the text as the target text.

[0102] S218. Perform anomaly detection on each target text to determine the abnormal text.

[0103] In this embodiment, the abnormal text can be specifically understood as the text containing abnormal words and information. Analyze each target text to determine whether the information in the abnormal text is abnormal. For example, whether the target text information contains too much sensitive information.

[0104] As an alternative embodiment of this embodiment, this alternative embodiment further optimizes performing anomaly detection on each target text to determine the abnormal text as follows:

[0105] D1. For each target text, determine the edit distance between the target text and a pre - determined abnormal word information library.

[0106] In this embodiment, the abnormal text information library can be specifically understood as an information library composed of abnormal words and abnormal sentences. The edit distance can be specifically understood as the minimum number of edit operations required to convert one string into another string. The permitted edit operations include replacing one character with another character, inserting a character, and deleting a character. For each target text, calculate the edit distance between each word or sentence in this target text and the abnormal word information library through methods such as sequence alignment. The method of calculating the edit distance can be calculated through machine learning modeling.

[0107] D2. Count the number of abnormal words whose edit distance meets the preset distance condition.

[0108] In this embodiment, the number of abnormal words can be specifically understood as the quantity of abnormal words. The preset distance condition can be specifically understood as a pre-set distance range condition, for example, greater than 0.75. Compare the edit distance corresponding to each word or sentence in the target text with the preset distance condition, and determine the edit distance that meets the preset distance condition. The words or sentences corresponding to this part of the edit distance are abnormal words, and count the number of abnormal words to obtain the number of abnormal words.

[0109] D3. When the number of abnormal words is greater than the third preset quantity threshold, determine that the target text is abnormal text.

[0110] In this embodiment, the third preset quantity threshold can be specifically understood as a quantity threshold for determining whether the target text is abnormal, which can be pre-set according to requirements. Compare the size of the number of abnormal words with the third preset quantity threshold. When the number of abnormal words is greater than the third preset quantity threshold, determine that the target text is abnormal text and tampering may have occurred; when the number of abnormal words is less than or equal to the third preset quantity threshold, determine that the target text is normal text and no tampering has occurred.

[0111] S219. Determine whether the number of abnormal texts is greater than the second preset quantity threshold. If so, execute S220; otherwise, execute S221.

[0112] S220. Determine that the tampering detection result is web page tampering.

[0113] S221. Determine that the tampering detection result is no tampering has occurred.

[0114] In this embodiment, the second preset quantity threshold can be specifically understood as a threshold for determining whether the number of abnormal texts meets the requirements. The values of the first preset quantity threshold, the second preset quantity threshold, and the third preset quantity threshold in this application can be the same or different, and can be set according to requirements in actual applications. Count the number of abnormal texts and compare the size of the number of abnormal texts with the second preset quantity threshold. When the number of abnormal texts is greater than the second preset quantity threshold, determine that the tampering detection result is web page tampering.

[0115] By analyzing common text tampering behaviors, extract the characteristics of the tampered text to form an abnormal text information database. Use machine learning technology to model the web page text content to automatically determine whether the text has been maliciously tampered with. And an early warning method can be set to give an early warning after the web page text information has been tampered with, and output the tampering information and the risk score. The tampering of text may occur anywhere on the page, and the forms of tampering are also diverse. The embodiments of this application can automatically detect various forms of text tampering.

[0116] As an alternative embodiment of this embodiment, this alternative embodiment is further optimized to include: generating a warning work order according to at least one tampering detection result and sending it to the corresponding user.

[0117] In this embodiment, the warning work order can be specifically understood as a work order for warning users, which is used to remind users that the website has been tampered with and to handle it in a timely manner to ensure website security. The users in the embodiments of this application can be the management personnel, maintenance personnel, etc. corresponding to the website to be detected. The users associated with the website to be detected are selected in advance. When at least one or more than a preset number of tampering detection results indicate that tampering has occurred, a warning work order is generated and sent to the corresponding user. The warning work order can include the type of tampering. For example, a second-level domain name has been tampered with, so that the user can determine the type of tampering in a timely manner and perform corresponding processing. The sending method can be set to send to an email, send to a mobile phone via text message, or send to the corresponding account through an operating system. At the same time, an operation report can also be generated according to the tampering detection result.

[0118] Furthermore, Figure 4 FIG. is a schematic implementation diagram of a website intrusion and tampering detection method provided by an embodiment of this application.

[0119] S301. Start.

[0120] S302. Collect network data for the website to be detected.

[0121] The network data can be collected by means of a crawler.

[0122] S303. Obtain the web page data file from the network data.

[0123] S304. Obtain the web page source code file from the network data.

[0124] S305. Obtain the web page screenshot file from the network data.

[0125] S306. According to the web page source code file and the web page data file, the web page URL, web page domain name, web page tags, web page keywords, web page description, web page short text, short text hyperlink, web page text set, and web page link set can be obtained, that is, it includes the web page source code, web page domain name, and web page text information.

[0126] S307. According to the web page URL, web page domain name, web page tags, web page keywords, web page description, web page short text, short text hyperlink, web page text set, and web page link set, obtain the web page URL, web page domain name, and web page link set.

[0127] S308. Determine whether the URL is valid. If not, execute S309; otherwise, execute S310.

[0128] S309. Discard the data.

[0129] S310. Perform implant chain detection. The implant chain detection includes: website detection, sub - domain detection, and regular expression detection, and then execute S322.

[0130] Among them, website detection is to detect the web page domain name through a domain name detection platform to obtain the detection result. Sub - domain detection is to determine the sub - domain for detection through the web page hyperlink set and the web page domain name to obtain the detection result. Regular expression detection is to detect the web page source code through regular expressions to obtain the detection result.

[0131] S311. Obtain the web page short text and short text hyperlinks based on the web page URL, web page domain name, web page tags, web page keywords, web page description, web page short text, short text hyperlinks, web page text set, and web page link set.

[0132] S312. Determine whether the web page short text and short text hyperlinks contain Chinese. If so, execute S313; otherwise, execute S314.

[0133] When the web page short text and short text hyperlinks contain Chinese, determine the text length of the text corresponding to the text label in the web page text information.

[0134] S313. Determine whether the text length meets the preset length condition. If not, execute S314; otherwise, execute S315.

[0135] Determine the target text length that meets the preset length condition, and determine the text corresponding to the target text length as the target text.

[0136] S314. Discard the data.

[0137] S315. Perform anomaly detection on the target text to determine the abnormal text.

[0138] S316. Compare the number of abnormal texts with the second preset quantity threshold to obtain the tampering detection result, and then execute S322.

[0139] S317. Obtain the web page images according to the web page screenshot files.

[0140] S318. Determine whether the web page images are valid. If not, execute S319; otherwise, execute S320.

[0141] S319. Discard the data.

[0142] S320. Detect the web page images.

[0143] The method of detecting the web page images can be to detect through an image detection network model.

[0144] S321. Obtain the tampering detection result and execute S322.

[0145] S322. Aggregate the tampering detection results.

[0146] S323. Output the detection result and execute S324 and S325 respectively.

[0147] S324. Generate an operation report.

[0148] S325. Generate and issue a warning work order.

[0149] S326. End.

[0150] The embodiment of the present invention provides a method for detecting website intrusion and tampering. By obtaining a set of web page information of the website to be detected, the set of web page information includes at least one of the following web page information: web page source code, web page domain name, web page pictures, and web page text information; select the web page information to be detected from the set of web page information, determine the detection method corresponding to the web page information to be detected and perform corresponding tampering detection, and determine the tampering detection result. By obtaining the set of web page information and performing intrusion and tampering detection on the web page information to be detected in the set of web page information, the security of the website to be detected is ensured. Select a suitable detection method according to the information type of the web page information to be detected, and perform detection on the website to be detected from different angles to improve the accuracy of the detection result. And during the detection process, the picture cleaning network model is trained through the detection data set classification data set, which not only ensures the accuracy of position prediction, but also can increase the number of classification categories and improve the robustness of the model, thereby improving the accuracy of intrusion and tampering detection.

[0151] Embodiment III

[0152] Figure 5 FIG. is a schematic structural diagram of a website intrusion and tampering detection device provided in Embodiment III of the present invention. The device includes: an information set acquisition module 41 and a detection module 42.

[0153] Among them, the information set acquisition module 41 is used to obtain a set of web page information of the website to be detected, and the set of web page information includes at least one of the following web page information: web page source code, web page domain name, web page pictures, and web page text information;

[0154] The detection module 42 is used to select the web page information to be detected from the set of web page information, determine the detection method corresponding to the web page information to be detected and perform corresponding tampering detection, and determine the tampering detection result.

[0155] An embodiment of the present invention provides a website intrusion and tampering detection device, which obtains a set of web page information of a website to be detected. The set of web page information includes at least one of the following web page information: web page source code, web page domain name, web page pictures, and web page text information. Select the web page information to be detected from the set of web page information, determine the detection method corresponding to the web page information to be detected, perform corresponding tampering detection, and determine the tampering detection result. By obtaining the set of web page information and performing intrusion and tampering detection on the web page information to be detected in the set of web page information, the security of the website to be detected is ensured. Select a suitable detection method according to the information type of the web page information to be detected, and perform detection on the website to be detected from different angles to improve the accuracy of the detection result.

[0156] Further, when the web page information to be detected is the web page source code, the detection module 42 includes:

[0157] An expression acquisition unit for acquiring a pre-determined set of regular expressions;

[0158] A matching detection unit for performing string matching detection on the web page source code according to the regular expressions in the set of regular expressions, and determining the tampering detection result.

[0159] Further, when the web page information to be detected is the web page domain name, the detection module 42 includes:

[0160] A hyperlink determination unit for acquiring the web page source code and analyzing it to determine a set of web page hyperlinks;

[0161] A secondary domain name determination unit for determining a target secondary domain name according to the set of web page hyperlinks and the web page domain name;

[0162] A quantity determination unit for counting the quantity of the target secondary domain names;

[0163] A secondary domain name detection unit for determining whether the quantity is greater than a first preset quantity threshold. If so, determining the tampering detection result as a secondary domain name spoofing; otherwise, determining the tampering detection result as no tampering occurred.

[0164] Further, the secondary domain name determination unit is specifically configured to extract the secondary domain name from the web page hyperlinks in the set of web page hyperlinks to obtain at least one hyperlink secondary domain name; extract the secondary domain name from the web page domain name to obtain the web page secondary domain name; compare each of the hyperlink secondary domain names with the web page secondary domain name; and determine the hyperlink secondary domain names with different comparison results as the target secondary domain names.

[0165] Further, when the web page information to be detected is the web page domain name, the detection module 42 includes:

[0166] A domain name output unit for outputting the web page domain name to a domain name detection platform through a preset web page security interface;

[0167] A detection result receiving unit for receiving the domain name detection result returned by the domain name detection platform;

[0168] A detection result analysis unit for analyzing the domain name detection result to determine the tampering detection result.

[0169] Further, when the web page information to be detected is a web page image, the detection module 42 includes:

[0170] A model input unit for inputting the web page image into a pre-determined image detection network model, and the image detection network model is trained according to a detection data set and a classification data set;

[0171] A model output unit for determining a target object according to the output result of the image detection network model;

[0172] An anomaly detection unit for performing anomaly detection on the text to be detected in the target object and determining the tampering detection result according to the anomaly detection result.

[0173] Further, the device further includes:

[0174] A data set acquisition module for acquiring a detection data set and a classification data set, and the to-be-trained images in the detection data set and the classification data set are correspondingly associated with standard information, and the standard information includes standard position information and standard category information;

[0175] A prediction information determination module for inputting the to-be-trained image corresponding to the current iteration into the current to-be-trained network model to obtain prediction information, and the prediction information includes prediction position information and prediction category information;

[0176] A loss function determination module for obtaining a corresponding loss function by using a given loss function expression in combination with the standard information and the prediction information;

[0177] A backpropagation module for performing backpropagation on the to-be-trained network model based on the loss function to obtain a to-be-trained network model for the next iteration until the iteration convergence condition is satisfied to obtain an image detection network model.

[0178] Further, when the web page information to be detected is web page text information, the detection module 42 includes:

[0179] A label determination unit for obtaining the web page source code and determining the text labels in the web page source code;

[0180] A target text determination unit, configured to determine a target text according to each of the text tags and the web page text information;

[0181] An abnormal text determination unit, configured to perform abnormal detection on each of the target texts to determine abnormal texts;

[0182] A tampering detection unit, configured to determine whether the number of the abnormal texts is greater than a second preset number threshold. If so, determine that the tampering detection result is web page tampering; otherwise, determine that the tampering detection result is no tampering.

[0183] Further, the target text determination unit is specifically configured to determine the text length of the text corresponding to each of the text tags in the web page text information; determine the target text length that meets the preset length condition among the text lengths; and determine the text corresponding to the target text length as the target text.

[0184] Further, the abnormal text determination unit is specifically configured to, for each target text, determine the edit distance between the target text and a pre-determined abnormal word information library; count the number of abnormal words whose edit distance meets the preset distance condition; and when the number of abnormal words is greater than a third preset number threshold, determine that the target text is an abnormal text.

[0185] Further, the device further includes:

[0186] A work order sending module, configured to generate a warning work order according to at least one tampering detection result and send it to the corresponding user.

[0187] The website intrusion and tampering detection device provided by the embodiments of the present invention can execute the website intrusion and tampering detection method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0188] Embodiment 4

[0189] Figure 6 FIG. is a schematic structural diagram of a computer device provided by Embodiment 4 of the present invention. As Figure 6 shown, the device includes a processor 50, a memory 51, an input device 52, and an output device 53; the number of processors 50 in the device can be one or more. Figure 6 Taking one processor 50 as an example; the processor 50, the memory 51, the input device 52, and the output device 53 in the device can be connected through a bus or other means. Figure 6 Taking the connection through a bus as an example.

[0190] The memory 51, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the website intrusion and tampering detection method in the embodiments of the present invention (for example, the information set acquisition module 41 and the detection module 42 in the website intrusion and tampering detection device). The processor 50 executes various functional applications and data processing of the device by running the software programs, instructions, and modules stored in the memory 51, that is, implements the above-mentioned website intrusion and tampering detection method.

[0191] The memory 51 mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory 51 can include high-speed random access memory, and can also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some instances, the memory 51 can further include a memory remotely set relative to the processor 50, and these remote memories can be connected to the device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0192] The input device 52 can be used to receive input digital or character information, and generate key signal inputs related to the user settings and function controls of the device. The output device 53 can include display devices such as a display screen.

[0193] Embodiment Five

[0194] Embodiment Five of the present invention further provides a storage medium containing computer-executable instructions, and the computer-executable instructions are used to execute a website intrusion and tampering detection method when executed by a computer processor. The method includes:

[0195] Obtain a web page information set of the website to be detected, and the web page information set includes at least one of the following at least one web page information: web page source code, web page domain name, web page pictures, and web page text information;

[0196] Select the web page information to be detected from the web page information set, determine the detection method corresponding to the web page information to be detected and perform corresponding tampering detection, and determine the tampering detection result.

[0197] Of course, for a storage medium containing computer-executable instructions provided by the embodiments of the present invention, the computer-executable instructions are not limited to the method operations as described above, and can also execute related operations in the website intrusion and tampering detection methods provided by any embodiment of the present invention.

[0198] From the above description of the embodiments, those skilled in the art can clearly understand that the present invention can be implemented by means of software and necessary general hardware. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as a floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk or optical disc of a computer, etc., and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention.

[0199] It should be noted that in the embodiments of the above website intrusion and tampering detection device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present invention.

[0200] Note that the above is only the preferred embodiment of the present invention and the applied technical principle. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, re-adjustments and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, more other equivalent embodiments can be included, and the scope of the present invention is determined by the scope of the appended claims.

Claims

1. A method for detecting website intrusion and tampering, characterized in that, Including: Obtain a collection of web page information of the website to be detected, where the collection of web page information includes at least one of the following web page information: web page source code, web page domain name, web page images, and web page text information; Select the web page information to be detected from the collection of web page information, determine the detection method corresponding to the web page information to be detected and perform corresponding tampering detection, and determine the tampering detection result; Among them, when the web page information to be detected is a web page domain name, determining the detection method corresponding to the web page information to be detected and performing corresponding tampering detection, and determining the tampering detection result includes: Obtain the web page source code and analyze it to determine the collection of web page hyperlinks; Determine the target secondary domain name according to the collection of web page hyperlinks and the web page domain name; Count the number of the target secondary domain names; Judge whether the number is greater than the first preset number threshold. If so, determine that the tampering detection result is a pan-secondary domain name tampering; otherwise, determine that the tampering detection result is no tampering.

2. The method according to claim 1, wherein When the web page information to be detected is the web page source code, determining the detection method corresponding to the web page information to be detected and performing corresponding tampering detection, and determining the tampering detection result includes: Obtain a pre-determined set of regular expressions; Perform string matching detection on the web page source code according to the regular expressions in the set of regular expressions to determine the tampering detection result.

3. The method according to claim 1, wherein The determining the target secondary domain name according to the collection of web page hyperlinks and the web page domain name includes: Extract the secondary domain names from the web page hyperlinks in the collection of web page hyperlinks to obtain at least one hyperlink secondary domain name; Extract the secondary domain name from the web page domain name to obtain the web page secondary domain name; Compare each of the hyperlink secondary domain names with the web page secondary domain name; Determine the hyperlink secondary domain names with different comparison results as the target secondary domain names.

4. The method according to claim 1, characterized in that, When the web page information to be detected is a web page domain name, determining the detection method corresponding to the web page information to be detected and performing corresponding tampering detection, and determining the tampering detection result includes: Output the web page domain name to the domain name detection platform through a preset web security interface; Receive the domain name detection result returned by the domain name detection platform; Analyze the domain name detection result to determine the tampering detection result.

5. The method according to claim 1, characterized in that, When the web page information to be detected is a web page image, determining the detection method corresponding to the web page information to be detected and performing corresponding tampering detection, and determining the tampering detection result includes: Input the web page image into a pre-determined image detection network model, and the image detection network model is trained according to a detection data set and a classification data set; Determine the target object according to the output result of the image detection network model; Perform anomaly detection on the text to be detected in the target object, and determine the tampering detection result according to the anomaly detection result.

6. The method according to claim 5, characterized in that, The training steps of the image detection network model include: Obtain a detection data set and a classification data set, where the to-be-trained images in the detection data set and the classification data set are correspondingly associated with standard information, and the standard information includes standard position information and standard category information; Input the to-be-trained image corresponding to the current iteration into the current to-be-trained network model to obtain prediction information, and the prediction information includes prediction position information and prediction category information; Using the given loss function expression, combining the standard information and the prediction information, to obtain the corresponding loss function; Based on the loss function, perform backpropagation on the network model to be trained to obtain the network model to be trained for the next iteration, until the iteration convergence condition is satisfied, and obtain the image detection network model.

7. The method according to claim 1, characterized in that, When the web page information to be detected is web page text information, determine the detection method corresponding to the web page information to be detected and perform corresponding tampering detection, and determine the tampering detection result, including: Obtain the web page source code and determine the text tags in the web page source code; Determine the target text according to each of the text tags and the web page text information; Perform anomaly detection on each of the target texts to determine the abnormal texts; Judge whether the number of the abnormal texts is greater than a second preset number threshold. If so, determine the tampering detection result as web page tampering; otherwise, determine the tampering detection result as no tampering occurred.

8. The method according to claim 7, wherein The determining the target text according to each of the text tags and the web page text information includes: Determine the text length of the text corresponding to each of the text tags in the web page text information; Determine the target text length that satisfies the preset length condition among the text lengths; Determine the text corresponding to the target text length as the target text.

9. The method according to claim 7, characterized in that, The performing anomaly detection on each of the target texts to determine the abnormal texts includes: For each target text, determine the edit distance between the target text and a pre-determined abnormal word information library; Count the number of abnormal words whose edit distance satisfies the preset distance condition; When the number of abnormal words is greater than a third preset number threshold, determine the target text as an abnormal text.

10. The method according to any one of claims 1-9, characterized in that It further includes: Generate a warning work order according to at least one tampering detection result and send it to the corresponding user.

11. A website intrusion and tampering detection device, characterized in that, It includes: An information set acquisition module, configured to acquire a web page information set of a website to be detected, where the web page information set includes at least one of the following web page information: web page source code, web page domain name, web page image, and web page text information; A detection module, configured to select the web page information to be detected from the web page information set, determine the detection method corresponding to the web page information to be detected and perform corresponding tampering detection, and determine the tampering detection result; Wherein, when the web page information to be detected is a web page domain name, the detection module includes: A hyperlink determination unit, configured to acquire the web page source code and perform analysis to determine a web page hyperlink set; A secondary domain name determination unit, configured to determine a target secondary domain name according to the web page hyperlink set and the web page domain name; A quantity determination unit, configured to count the quantity of the target secondary domain names; A secondary domain name detection unit, configured to judge whether the quantity is greater than a first preset number threshold. If so, determine the tampering detection result as a pan-secondary domain name tampering; otherwise, determine the tampering detection result as no tampering occurred.

12. A computer device, characterized in that, The device includes: One or more processors; A memory, configured to store one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the website intrusion and tampering detection method as described in any one of claims 1-10.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the website intrusion and tampering detection method as described in any one of claims 1-10.

Citation Information

Patent Citations

  • Method and device for detecting webpage tampering

    CN103593615A

  • Website picture tampering detection method based on deep learning

    CN111191695A

  • Webpage tampering detection method and related device

    CN111488623A