Data Processing System, Method and Device Based on XSS Attack Detection

By implementing a three-layer data processing system based on XSS attack detection in the power system network, verify, audit and filter the data input by users, the XSS attack threat faced by the power system network is solved and the security of the network environment is ensured.

CN114254306BActive Publication Date: 2025-06-10GUANGZHOU KETENG INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111470887.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-03
Publication Date
2025-06-10
Estimated Expiration
2041-12-03

AI Technical Summary

Technical Problem

The power system network faces the threat of XSS attacks, resulting in network information leakage and system control impacts, seriously damaging the lives of the people.

Method used

Design a data processing system based on XSS attack detection, and verify, audit and filter the data input by users through the three-layer detection mechanisms of the front-end layer, the browser layer and the server layer to ensure that the data does not carry XSS attack statements during transmission.

Benefits of technology

It effectively reduces the possibility of substation servers being attacked by XSS, ensures the security of the power system network environment, and prevents large-scale network information leakage and system control impacts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114254306B_ABST
    Figure CN114254306B_ABST
Patent Text Reader

Abstract

This application relates to a data processing system, method, device, computer device, storage medium and computer program product based on XSS attack detection. The system includes: a server layer, a browser layer and a front-end layer; the server layer, the browser layer and the front-end layer are communicatively connected; the front-end layer is configured to obtain data input by a user; verify the data to obtain a verification result; if the verification result is normal, transmit the data to the browser layer; the browser layer is configured to perform XSS audit processing on the data to obtain an XSS audit result; if the XSS audit result is normal, transmit the data to the server layer; the server layer is configured to filter the data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine target data according to the matching result; This disclosure reduces the possibility of substation servers being attacked by XSS and ensures the security of the power system network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent power network security, and particularly to a data processing system, method, device, computer device, storage medium, and computer program product for XSS attack detection. Background Art

[0002] One way of XSS attack is to inject prepared malicious code into the web page that the user is browsing through a series of means, and activate the malicious code through the user's unconscious click or other operations to launch an attack, enabling the attacker to achieve their malicious purposes at will. Once the power grid system is threatened by XSS vulnerabilities, it will not only cause large-scale network information leakage, but also affect the entire system control and power distribution links, causing serious losses to people's lives.

[0003] Therefore, a data processing system for XSS attack detection is still needed to process data, so as to reduce the possibility of the substation server being attacked by XSS and ensure the security of the power system network environment. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a data processing system, method, device, computer device, computer-readable storage medium, and computer program product for XSS attack detection that can improve the security of the power system network environment.

[0005] In a first aspect, this application provides a data processing system for XSS attack detection. The system includes: a server layer, a browser layer, and a front-end layer; the server layer, the browser layer, and the front-end layer are communicatively connected;

[0006] The front-end layer is configured to obtain data input by a user; verify the data to obtain a verification result; if the verification result is normal, transmit the data to the browser layer;

[0007] The browser layer is configured to perform XSS audit processing on the data to obtain an XSS audit result; if the XSS audit result is normal, transmit the data to the server layer;

[0008] The server layer is configured to filter the data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine target data according to the matching result.

[0009] In one embodiment, the front-end layer is further configured to, in response to data input by a user, obtain event information corresponding to the data; call a pre-set hash tree rule interface to perform hash tree detection on the event information; and determine the verification result according to the hash tree detection result.

[0010] In one embodiment, the front-end layer is further configured to construct an XSS attack vector before calling the pre-set hash tree rule interface; construct a hash tree based on the constructed XSS attack vector to generate the hash tree rule interface.

[0011] In one embodiment, the front-end layer is further configured to encode a preset vector string into a 16-bit hexadecimal string; obtain the binary integer of the 16-bit hexadecimal string; obtain the decimal integer of the binary integer; and construct the hash tree according to the decimal integer.

[0012] In one embodiment, the server layer is further configured to obtain preset filtering configuration information; determine characters to be recognized according to the preset filtering configuration information; identify target characters matching the characters to be recognized from the data; and obtain the filtered data after deleting the target characters from the data.

[0013] In a second aspect, the present application provides a data processing method based on XSS attack detection, the method including:

[0014] Obtain data input by a user; verify the data to obtain a verification result;

[0015] If the verification result is normal, perform XSS audit processing on the data to obtain an XSS audit result;

[0016] If the XSS audit result is normal, filter the data; perform encoding processing on the filtered data to obtain encoded data; and match the encoded data with a preset list, and determine target data according to the matching result.

[0017] In a third aspect, the present application provides a data processing device based on XSS attack detection, the device including:

[0018] A data verification module, configured to obtain data input by a user; verify the data to obtain a verification result;

[0019] A data audit module, configured to, if the verification result is normal, perform XSS audit processing on the data to obtain an XSS audit result;

[0020] A data determination module, configured to filter the data if the XSS audit result is normal; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine target data according to the matching result.

[0021] Fourthly, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0022] Obtain the data input by the user; verify the data to obtain a verification result;

[0023] If the verification result is normal, perform XSS audit processing on the data to obtain an XSS audit result;

[0024] If the XSS audit result is normal, filter the data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine target data according to the matching result.

[0025] Fifthly, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0026] Obtain the data input by the user; verify the data to obtain a verification result;

[0027] If the verification result is normal, perform XSS audit processing on the data to obtain an XSS audit result;

[0028] If the XSS audit result is normal, filter the data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine target data according to the matching result.

[0029] Sixthly, the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0030] Obtain the data input by the user; verify the data to obtain a verification result;

[0031] If the verification result is normal, perform XSS audit processing on the data to obtain an XSS audit result;

[0032] If the XSS audit result is normal, filter the data; perform encoding processing on the filtered data to obtain the encoded data; match the encoded data with a preset list, and determine the target data according to the matching result.

[0033] The above data processing system, method, device, computer device, storage medium, and computer program product based on XSS attack detection. The system includes: a server layer, a browser layer, and a front-end layer; the server layer, the browser layer, and the front-end layer are communicatively connected; the front-end layer is used to obtain the data input by the user; verify the data to obtain a verification result; if the verification result is normal, transmit the data to the browser layer; the browser layer is used to perform XSS audit processing on the data to obtain an XSS audit result; if the XSS audit result is normal, transmit the data to the server layer; the server layer is used to filter the data; perform encoding processing on the filtered data to obtain the encoded data; match the encoded data with a preset list, and determine the target data according to the matching result; it realizes verifying the input data through the front-end layer, sending it to the browser layer for auditing after verification, and sending it to the server layer for filtering and matching processing after auditing, ensuring that the data input by the user is transmitted to the server layer for processing without any attached XSS attack statements, reducing the possibility of the substation server being attacked by XSS, and ensuring the security of the power system network environment. Description of the Drawings

[0034] Figure 1 It is a structural environment diagram of a data processing system based on XSS attack detection in an embodiment;

[0035] Figure 2 It is a schematic flowchart of the XSS attack process in an embodiment;

[0036] Figure 3 It is a schematic diagram of a three-layer detection mechanism of a data processing system based on XSS attack detection in an embodiment;

[0037] Figure 4 It is a schematic flowchart of a detection process based on hash tree matching in an embodiment;

[0038] Figure 5 It is a schematic flowchart of a data processing method based on XSS attack detection in an embodiment;

[0039] Figure 6 It is a structural block diagram of a data processing device based on XSS attack detection in an embodiment;

[0040] Figure 7 It is an internal structure diagram of a computer device in an embodiment. Detailed Embodiments

[0041] In order to make the purpose, technical solution and advantages of this application clearer, the following further details this application in combination with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.

[0042] The data processing system based on XSS attack detection provided by the embodiment of this application has a structure as Figure 1 shown. The system includes: a server layer 110, a browser layer 120, and a front-end layer 130; the server layer 110, the browser layer 120, and the front-end layer 130 are communicatively connected;

[0043] The front-end layer 130 is used to obtain the data input by the user; verify the data to obtain a verification result; if the verification result is normal, transmit the data to the browser layer 120;

[0044] The browser layer 120 is used to perform XSS audit processing on the data to obtain an XSS audit result; if the XSS audit result is normal, transmit the data to the server layer 110;

[0045] The server layer 110 is used to filter the data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine target data according to the matching result.

[0046] Among them, cross-site scripting attacks are generally abbreviated as XSS. In modern society with the rapid development of the Internet, due to the rapid development of technologies such as JavaScript and ajax, not only the social field, but also the military, medical, and power fields are filled with Web applications today. Although the existence of these Web applications enriches our lives, it also brings many network security problems, and XSS is one of them. One way of XSS attacks is to inject prepared malicious code into the web page that the user is browsing through a series of means, and activate the malicious code through the user's unconscious click or other operations to launch a malicious attack, enabling the attacker to obtain the victim's personal information or others. Before launching an XSS attack, an XSS attacker will prepare a relevant XSS malicious attack code file in advance. This code file may be hidden in another pre-prepared malicious phishing URL, or may be submitted to the server database of a website through an XSS vulnerability in advance. When the victim accidentally clicks on the phishing URL or browses the malicious code on the attacked website, it will trigger the execution of the malicious script and complete this XSS attack; the process of an XSS attack is as Figure 2As shown. Currently, XSS can be classified into: reflected cross-site scripting, persistent cross-site scripting, and DOM-based XSS according to characteristics and exploitation techniques. Reflected cross-site scripting generally hides the prepared script in the address of a malicious URL. The XSS attacker uses certain methods to induce or deceive users into clicking and accessing this malicious link. When the user initiates an access request for this link, the malicious code will be triggered, resulting in an XSS attack. Since the reflected cross-site scripting attack depends on the user's access to a specific phishing URL and only triggers the malicious script when the access request is initiated to launch an attack, it is also called a non-persistent, parameter-based cross-site scripting attack. Persistent cross-site scripting (usually also called stored cross-site scripting). Among several common types of XSS attacks, persistent XSS is more threatening due to its effective way, and because it is stored in the database of the website server, it can also threaten the security of the server itself. DOM-based XSS (also known as DOM-Base XSS), its attack principle is an attack method achieved by submitting malicious code to the DOM storage to modify elements in the interface. Since the DOM document allows the user client to submit JS code to modify DOM nodes in the web interface, there is a situation where an attack can be launched by maliciously modifying DOM nodes by submitting malicious JS code.

[0047] Specifically, the data processing system for XSS attack detection proposed in this disclosure can be an XSS attack detection model based on the Html5 standard and the ES6 standard, which can effectively help developers and researchers detect and defend against new XSS attacks and construct a secure Web environment.

[0048] Specifically, to implement the detection model for XSS attacks, it is first necessary to understand that the most fundamental reason for XSS attacks is the improper filtering or incorrect filtering of illegal user input by Web programs. Currently, most Web application programs' detection and protection methods for XSS malicious attacks are actually to use filtering means on the server side to control users' input and output, and secondly, rely on the information security awareness of the attacked themselves to reduce the success rate of being attacked by XSS.

[0049] The data processing system for XSS attack detection given in this application is a three-layer detection mechanism: the server layer, the browser layer, and the front-end layer. Among them, the relevant operations of the front-end layer and the browser layer are established on the client side. The working mechanism of the three-layer model is as Figure 3 shown.

[0050] Taking a user's post request as an example, first, the user sends such a request to the server through the local client browser. This request will pass through the self-detection and defense mechanism of the first-layer browser, that is, the verification of the locally customized relevant data verification script. After detecting no signs of XSS attack scripts, the screened data will be verified by the XSS audit system. After both layers of verification pass, the qualified data will be sent to the server side again through a new request. After the server side receives the data, it will perform legal input verification on the data, and then perform a series of data disinfection measures such as the third-layer black and white list and data filtering on the legal input to prevent JS scripts from being submitted to the server database. After all three layers of detection and verification pass, the returned data will be encoded, and the three-layer model will be executed in reverse to prevent the possible execution of JS scripts, and finally the corresponding result of the browser will be successfully displayed.

[0051] In one embodiment, the front-end layer is further configured to, in response to the data input by the user, obtain the event information corresponding to the data; call the pre-set hash tree rule interface to perform hash tree detection on the event information; and determine the verification result according to the hash tree detection result.

[0052] Further, the front-end layer is further configured to construct an XSS attack vector before calling the pre-set hash tree rule interface; construct a hash tree based on the constructed XSS attack vector to generate a hash tree rule interface.

[0053] Further, the front-end layer is further configured to encode the preset vector string into a 16-bit hexadecimal string; obtain the binary integer of the 16-bit hexadecimal string; obtain the decimal integer of the binary integer; and construct a hash tree according to the decimal integer.

[0054] Specifically, the front-end detection and defense mechanism model includes event scanning, static and dynamic script scanning, and custom data verification; among them, custom verification generally uses JS scripts for input verification to detect the legality of user input; event scanning is for whether malicious code is injected into node events such as onerror events; static scanning and dynamic scanning are respectively for statically added script and dynamically added script tags to detect whether there is malicious code in the relevant scripts.

[0055] This embodiment will implement a dynamic scanner in the event capture stage of the event stream. When the event is triggered, it directly captures the event information, calls the hash tree rule interface constructed as follows, performs hash tree detection, and identifies whether there is a malicious XSS attack. The work flow is as Figure 4 shown.

[0056] (1) Process of constructing XSS attack vectors, including: XSS attack vectors need to undergo certain mathematical processing before being stored in the hash tree. Therefore, the following process is adopted:

[0057] Step 1: Convert the vector string into a 16-bit hexadecimal string using the MD5 encoding method;

[0058] Step 2: Convert the string into a binary integer;

[0059] Step 3: Convert the binary integer into a decimal integer;

[0060] Step 4: Substitute the decimal integer into the calculation to obtain the corresponding remainder vector;

[0061] Step 5: Construct a hash tree.

[0062] (2) Detection principle based on the hash tree, including: The hash tree is a storage method. In this embodiment, the prime number resolution theorem is used as the basis for explanation: Prime number resolution theorem: Select any n distinct prime numbers, p1, p2,..., pn, (n is a positive integer), define, let m < k1 < k2 < m + M (m, k1, k2, M are all positive integers), then for any 0 < i < n + 1, k1 mod pi = k2 mod pi cannot always hold. From this theorem, it can be known that different positive integers will produce different remainder vectors for the prime number vector p. Therefore, for a specific attack vector, its corresponding remainder vector can be obtained through calculation. This design invention will construct a hash tree with h = 10, which can distinguish 2 * 3 * 5 * 7 *... * 29 numbers. Construct a hash tree and initialize the root node k_word as new, and at the same time initialize the status of the root node as true. Then store the constructed XSS attack vectors into the tree. Define the array prime = [2, 3, 5, 7, 11, 13, 17, 19, 23, 29], h is the height of the currently scanned hash tree, and h is initialized as h = 0. The process is as follows:

[0063] Step 1: Obtain the value of the node to be inserted in the hash tree, scan the root node, and scan sequentially;

[0064] Step 2: If the scan result is false, insert the value of the node to be inserted into the current node, modify the keyword of the node, and set status = true, then return;

[0065] Step 3: If the scan result is true, calculate ops = k_word % prime[h];

[0066] Step 4: If child[ops] is null, that is, there is no unscanned child node currently, create a child node, and at the same time h = h + 1, then return to Step 1;

[0067] Step 5: If child[ops] is a child node in the tree, then h = h + 1, and return to Step 1;

[0068] (3) The detection mechanism based on hash tree matching includes: constructing according to the attack vectors in the above text to convert XSS attack vectors into corresponding remainder vectors. Similarly, the remainder vectors corresponding to the data to be detected extracted above can be obtained through the above steps for subsequent hash tree detection. At the same time, to prevent attackers from deliberately confusing malicious scripts, before converting the remainder vectors, it is necessary to first perform URL decoding, Unicode decoding, and Html decoding on the data to be tested, and convert the decoded content into lowercase. At the same time, to improve the detection efficiency of the system for XSS attacks, the minimum length of the divided sequence is set to 9. After obtaining the remainder vectors of the subsequences, match them in the hash tree rule library. If the match is successful, it means that a malicious attack is found and record it; if the match fails, determine whether it is the last subsequence to decide whether to continue searching the hash tree. The search steps of the hash tree are as follows:

[0069] Step 1: If the current search node is false, that is, the current node does not store valid keywords and the search fails. Because of the order of constructing the hash tree in the previous round, when it is false, the entire tree should have been searched completely but has not reached the maximum height, so it does not contain malicious code, and return;

[0070] Step 2: If the current search node is true, then compare the information with the valid keywords in the current node. If they are equal, the search is successful and return. Otherwise, execute Step 3;

[0071] Step 3: Calculate ops = k_word % prime[h];

[0072] Step 4: If child[ops] = null, the search is completed and it does not contain malicious code, and return;

[0073] Step 5: If child[ops] is a child node in the tree, h = h + 1, and return to Step 1.

[0074] In one embodiment, the server layer is further configured to obtain preset filtering configuration information; determine the characters to be recognized according to the preset filtering configuration information; identify the target characters matching the characters to be recognized from the data; and after deleting the target characters in the data, obtain the filtered data.

[0075] Specifically, the model at the server layer focuses on data filtering, that is, detecting suspicious characters in the input and filtering and desensitizing the input. The common filtering operation is the matching principle of the black and white list database, and data filtering is performed on any data submitted by any user to reduce the possibility of being attacked by XSS.

[0076] (1) Data filtering, including: Data filtering performed on the server side is generally divided into two parts, namely input and output data filtering. The former processes the input data of users, and the latter processes the output data returned by the server to users. Input data filtering is to first verify the data length and data format after receiving the data submitted by users, and perform disinfection and desensitization operations on the data that conforms to the rules, and then perform black and white list verification. Common examples include the verification of the length and format of mobile phone numbers and usernames, and the verification of the length and format of email addresses. However, the server generally uses JS code for data verification, which enables attackers to bypass the legality detection through specific encapsulation methods. To avoid this situation, the server will filter all data that passes the input length detection and format detection. For example, sensitive characters such as "<", ">", "&", "javascript" and other common malicious scripts are set as preset filtering configuration information, and by loading the preset filtering configuration information, characters that may be involved in attack behaviors can be identified and filtered.

[0077] (2) Output encoding, including: After filtering, the possibility of XSS attacks is greatly reduced, but there may be a possibility that the data filtering is incomplete, and there are also other possible methods of hiding malicious code, which may lead to the successful injection of malicious code into the server database. Therefore, it is necessary to encode the output data of the database. Server output encoding means encoding the data that needs to be output. Literalize the originally dynamic output content and turn the dynamic data into a document to avoid the execution of the missed malicious JS code.

[0078] (3) Black and white list security policies, including: Black and white list detection is generally divided into the blacklist method and the white list method. The blacklist method means that when matching information in the blacklist appears in all the data to be detected, the data is regarded as threatening data and is encoded, modified or discarded; the white list rule is the opposite. Before no matching data in the white list is detected, the data is regarded as threatening data, and only when it matches the white list database is the data allowed to enter. Compared with blacklist detection, white list detection has a higher security level. However, due to the limited data of white list detection, many legitimate requests may not pass the detection and be discarded, and at the same time, the coding difficulty for developers is extremely high. On the contrary, the security of the blacklist is proportional to the integrity of its rule library. The blacklist has great limitations, but it can reduce the coding difficulty for developers. Therefore, it is necessary to make a careful choice according to the actual situation.

[0079] In one embodiment, as Figure 5 shown, a data processing method based on XSS attack detection is provided, including the following steps:

[0080] Step S510, obtain the data input by the user; verify the data to obtain a verification result;

[0081] Step S520, if the verification result is normal, perform XSS auditing processing on the data to obtain an XSS auditing result;

[0082] Step S530, if the XSS auditing result is normal, filter the data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine target data according to the matching result.

[0083] The above data processing method based on XSS attack detection includes: obtaining the data input by the user; verifying the data to obtain a verification result; if the verification result is normal, performing XSS auditing processing on the data to obtain an XSS auditing result; if the XSS auditing result is normal, filtering the data; performing encoding processing on the filtered data to obtain encoded data; matching the encoded data with a preset list, and determining target data according to the matching result. This disclosure realizes the verification of the input data, performs auditing after verification passes, performs filtering and matching processing after auditing passes, ensures that the data input by the user is processed without any attached XSS attack statements, reduces the possibility of the substation server being attacked by XSS, and guarantees the security of the power system network environment.

[0084] It should be understood that although the various steps in the flowcharts involved in the above embodiments are shown in sequence according to the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily have to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily have to be sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.

[0085] Based on the same inventive concept, an embodiment of the present application further provides a data processing apparatus for implementing the data processing method for XSS attack detection described above. The solution provided by this apparatus to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the data processing apparatus for XSS attack detection provided below can refer to the limitations on the data processing method for XSS attack detection in the above text, and will not be repeated here.

[0086] In one embodiment, as Figure 6 shown, a data processing apparatus for XSS attack detection is provided, including: a data verification module 610, a data auditing module 620, and a data determination module 630, where:

[0087] The data verification module 610 is configured to obtain the data input by the user; verify the data to obtain a verification result;

[0088] The data auditing module 620 is configured to, if the verification result is normal, perform XSS auditing processing on the data to obtain an XSS auditing result;

[0089] The data determination module 630 is configured to, if the XSS auditing result is normal, filter the data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine target data according to the matching result.

[0090] Each module in the above data processing apparatus for XSS attack detection can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0091] In one embodiment, a computer device is provided. This computer device can be a server, and its internal structure diagram can be as Figure 7 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data processing data for XSS attack detection. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a data processing method for XSS attack detection.

[0092] Those skilled in the art can understand that Figure 7 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.

[0093] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:

[0094] Obtain the data input by the user; verify the data to obtain a verification result;

[0095] If the verification result is normal, perform XSS audit processing on the data to obtain an XSS audit result;

[0096] If the XSS audit result is normal, filter the data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine the target data according to the matching result.

[0097] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0098] Obtain the data input by the user; verify the data to obtain a verification result;

[0099] If the verification result is normal, perform XSS audit processing on the data to obtain an XSS audit result;

[0100] If the XSS audit result is normal, filter the data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine the target data according to the matching result.

[0101] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0102] Obtain the data input by the user; verify the data to obtain a verification result;

[0103] If the verification result is normal, perform XSS audit processing on the data to obtain an XSS audit result;

[0104] If the XSS audit result is normal, filter the data; perform encoding processing on the filtered data to obtain the encoded data; match the encoded data with a preset list, and determine the target data according to the matching result.

[0105] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties.

[0106] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the various embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the various embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., and are not limited thereto. The processors involved in the various embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., and are not limited thereto.

[0107] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0108] The above embodiments only express several implementation manners of the present application, and the description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A data processing system based on XSS attack detection, characterized in that, the system includes: a server layer, a browser layer, and a front-end layer; the server layer, the browser layer, and the front-end layer are communicatively connected; the front-end layer is used to obtain the data input by the user; verify the data to obtain a verification result; if the verification result is normal, transmit the data to the browser layer; the verification result is obtained by performing a hash tree detection on the event information corresponding to the data; the browser layer is used to perform XSS audit processing on the data to obtain an XSS audit result; if the XSS audit result is normal, transmit the data to the server layer; the server layer is used to filter the data according to preset filtering configuration information to obtain filtered data; perform encoding processing on the filtered data to obtain encoded data; match the encoded data with a preset list, and determine target data according to the matching result; the preset filtering configuration information is obtained by setting sensitive characters of malicious scripts.

2. The system according to claim 1, characterized in that, the front-end layer is further used to, in response to the data input by the user, obtain the event information corresponding to the data; call a preset hash tree rule interface to perform hash tree detection on the event information; determine the verification result according to the hash tree detection result.

3. The system according to claim 2, characterized in that, the front-end layer is further used to construct an XSS attack vector before calling the preset hash tree rule interface; construct a hash tree based on the constructed XSS attack vector to generate the hash tree rule interface.

4. The system according to claim 3, characterized in that, the front-end layer is further used to encode a preset vector string into a 16-bit hexadecimal string; obtain the binary integer of the 16-bit hexadecimal string; obtain the decimal integer of the binary integer; construct the hash tree according to the decimal integer.

5. The system according to claim 1, characterized in that, the server layer is further used to obtain preset filtering configuration information; determine the characters to be identified according to the preset filtering configuration information; identify the target characters matching the characters to be identified from the data; delete the target characters in the data to obtain the filtered data.

6. A data processing method based on XSS attack detection, characterized in that, the method includes: obtaining the data input by the user; verifying the data to obtain a verification result; the verification result is obtained by performing a hash tree detection on the event information corresponding to the data; if the verification result is normal, perform XSS audit processing on the data to obtain an XSS audit result; If the XSS audit result is normal, filter the data according to the preset filtering configuration information to obtain the filtered data; perform encoding processing on the filtered data to obtain the encoded data; match the encoded data with a preset list, and determine the target data according to the matching result; the preset filtering configuration information is set through sensitive characters of malicious scripts.

7. A data processing device based on XSS attack detection, characterized in that, the device includes: A data verification module, configured to obtain the data input by the user; verify the data to obtain a verification result; the verification result is obtained by performing a hash tree detection on the event information corresponding to the data; A data audit module, configured to perform XSS audit processing on the data to obtain an XSS audit result if the verification result is normal; A data determination module, configured to filter the data according to the preset filtering configuration information to obtain the filtered data if the XSS audit result is normal; perform encoding processing on the filtered data to obtain the encoded data; match the encoded data with a preset list, and determine the target data according to the matching result; the preset filtering configuration information is set through sensitive characters of malicious scripts.

8. A computer device, including a memory and a processor, the memory stores a computer program, characterized in that, when the processor executes the computer program, the steps of the data processing method based on XSS attack detection described in claim 6 are implemented.

9. A computer-readable storage medium, on which a computer program is stored, characterized in that, when the computer program is executed by a processor, the steps of the data processing method based on XSS attack detection described in claim 6 are implemented.

10. A computer program product, including a computer program, characterized in that, when the computer program is executed by a processor, the steps of the data processing method based on XSS attack detection described in claim 6 are implemented.

Citation Information

Patent Citations

  • Cross-site scripting attack defense method, device and equipment and storage medium

    CN110417746A

  • XSS attack detection method

    CN110502899A