Attack result determination method, device, electronic device and storage medium

By matching the response data packet features in the feature library, the attack result can be quickly determined as failure or success, which solves the problem of low efficiency in attack result determination in the existing technology, achieves efficient and accurate attack result determination, reduces the workload of manual determination, and reduces the missed detection rate.

CN114417349BActive Publication Date: 2025-09-26SANGFOR TECH INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111560476.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-20
Publication Date
2025-09-26
Estimated Expiration
2041-12-20

AI Technical Summary

Technical Problem

In the existing technology, the efficiency of attack result determination is low, and massive attack behaviors need to be manually processed, resulting in high costs and easy omission of successful attack events.

Method used

By matching the features of the response data packet in the feature library, the attack result is quickly determined to be a failure. The first feature library is used to determine that the attack failed, and the second feature library is used to determine that the attack was successful. The judgment process is optimized by combining hook hijacking technology.

Benefits of technology

It improves the efficiency of attack result determination, reduces the workload of manual determination, reduces the missed detection rate, and improves the automation and accuracy of security incident processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114417349B_ABST
    Figure CN114417349B_ABST
Patent Text Reader

Abstract

The present application discloses an attack result determination method, apparatus, electronic device, and storage medium. The attack result determination method includes: determining a first feature corresponding to a vulnerability type of a first security event in a first feature library; and determining that the attack result of the first security event is an attack failure if the corresponding first feature exists in a response packet of the first security event. The first feature library includes at least one first feature; each first feature characterizes a feature of the corresponding response packet when the attack of a security event of the corresponding vulnerability type fails. This method can quickly filter a large number of security events with failed attacks, improving the efficiency of attack result determination.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security, and in particular to a method, device, electronic device, and storage medium for determining attack results. Background Art

[0002] Aggressive behavior, in computer terms, refers to malicious actions that exploit existing vulnerabilities or high privileges to damage or gain access to a server. Related technologies require technical personnel to determine the results of a massive amount of attack behavior, which is inefficient. Summary of the Invention

[0003] In view of this, embodiments of the present application provide an attack result determination method, apparatus, electronic device, and storage medium to at least solve the problem of low efficiency in attack result determination in related technologies.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] The present invention provides a method for determining an attack result, the method comprising:

[0006] Determining, in a first feature library, a first feature corresponding to a vulnerability type of a first security event;

[0007] If the corresponding first feature exists in the response data packet of the first security event, determining that the attack result of the first security event is an attack failure; wherein,

[0008] The first feature library includes at least one first feature; each first feature represents a feature of a corresponding response data packet when a security event attack of a corresponding vulnerability type fails.

[0009] In the above solution, before determining the first feature corresponding to the vulnerability type of the first security event in the first feature library, the method further includes:

[0010] determining common characteristics of at least two response packets, each response packet being generated based on a security event of a vulnerability type;

[0011] The common feature is determined as a first feature of at least two vulnerability types; the at least two vulnerability types include vulnerability types corresponding to the at least two response data packets.

[0012] In the above solution, the method further includes:

[0013] Determining a second feature corresponding to the vulnerability type of the first security event in the second feature library;

[0014] Determining that the attack result of the first security event is an attack failure includes:

[0015] If the corresponding second feature does not exist in the response data packet of the first security event, determining that the attack result of the first security event is an attack failure; wherein,

[0016] The second feature library includes at least one second feature; each second feature represents a feature of a corresponding response data packet when a security event attack of a corresponding vulnerability type is successful.

[0017] In the above solution, the method further includes:

[0018] When the corresponding second feature exists in the response data packet of the first security event, it is determined that the attack result of the first security event is a successful attack.

[0019] In the above solution, before determining the first feature corresponding to the vulnerability type of the first security event in the first feature library, the method further includes:

[0020] Hijacking the first security event through a hook;

[0021] After determining the attack result of the first security event, the method further includes:

[0022] Release the hook of the first security event.

[0023] In the above solution, the method further includes:

[0024] Based on the corresponding vulnerability type and attack result, a risk level of the first security incident is determined.

[0025] In the above solution, the method further includes:

[0026] The attack result of the first security event is displayed on the setting page.

[0027] The embodiment of the present application further provides an attack result determination device, including:

[0028] A first processing unit is configured to determine, in a first feature library, a first feature corresponding to a vulnerability type of a first security event;

[0029] The second processing unit is configured to determine that the attack result of the first security event is an attack failure when the corresponding first feature exists in the response data packet of the first security event; wherein,

[0030] The first feature library includes at least one first feature; each first feature represents a feature of a corresponding response data packet when a security event attack of a corresponding vulnerability type fails.

[0031] An embodiment of the present application further provides an electronic device, comprising: a processor and a memory for storing a computer program that can be run on the processor,

[0032] Wherein, the processor is used to execute the steps of the above-mentioned attack result determination method when running the computer program.

[0033] An embodiment of the present application further provides a storage medium storing a computer program, which implements the steps of the above-mentioned attack result determination method when executed by a processor.

[0034] In an embodiment of the present application, a first feature corresponding to the vulnerability type of the first security event is determined in a first feature library, and if the corresponding first feature exists in the response data packet of the first security event, the attack result of the first security event is determined to be an attack failure; wherein the first feature library includes at least one first feature; each first feature represents the feature of the response data packet corresponding to the attack failure of the security event of the corresponding vulnerability type. In the above scheme, by judging whether there is a feature of a failed attack exploiting a vulnerability of the corresponding type in the response data packet, if there is a feature of a failed attack in the response data packet, the attack result of the corresponding security event is determined to be an attack failure. In this way, a large number of security events with failed attacks can be quickly filtered, thereby improving the efficiency of attack result determination. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 A schematic diagram of the implementation flow of the attack result determination method provided in an embodiment of the present application;

[0036] Figure 2 A schematic diagram of a display page provided in an embodiment of the present application;

[0037] Figure 3 A schematic diagram of the implementation flow of the attack result determination method provided in the application embodiment of this application;

[0038] Figure 4 A schematic diagram of an attack failure detection engine provided in an embodiment of the present application;

[0039] Figure 5 A schematic diagram of the structure of an attack result determination device provided in an embodiment of the present application;

[0040] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0041] Attack behavior, on a computer, refers to the act of exploiting existing vulnerabilities or high permissions to perform malicious operations in order to destroy or obtain server permissions.

[0042] There are numerous malicious servers on the Internet, which continuously scan for vulnerabilities in electronic devices on the Internet in order to launch attacks. Currently, many security products focus on improving attack detection. However, when conducting security monitoring or incident handling, technical personnel must manually determine the attack results of massive attacks, which is costly and inefficient.

[0043] Based on this, in various embodiments of the present application, a first feature corresponding to the vulnerability type of the first security event is determined in a first feature library, and if the corresponding first feature exists in the response data packet of the first security event, the attack result of the first security event is determined to be an attack failure; wherein the first feature library includes at least one first feature; each first feature represents the feature of the response data packet corresponding to the attack failure of the security event of the corresponding vulnerability type. In the above scheme, by judging whether there is a feature of a failed attack exploiting the corresponding type of vulnerability in the response data packet, if the feature of the failed attack exists in the response data packet, the attack result of the corresponding security event is determined to be an attack failure. In this way, a large number of security events with failed attacks can be quickly filtered, thereby improving the efficiency of attack result determination.

[0044] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0045] Figure 1 The following is a schematic diagram of the implementation process of the attack result determination method provided in the embodiment of the present application, wherein the execution subject of the process is an electronic device, including but not limited to mobile terminal devices such as mobile phones and tablets. Figure 1 As shown, the method includes:

[0046] Step 101: Determine a first feature corresponding to a vulnerability type of a first security event in a first feature library.

[0047] The first feature library includes at least one first feature; each first feature represents a feature of a corresponding response data packet when a security event attack of a corresponding vulnerability type fails.

[0048] Based on the vulnerability type of the first security event, a corresponding first feature is determined in the set first feature library. Each first feature refers to a common feature in the response data packets of security events that failed to exploit a vulnerability attack of the corresponding vulnerability type. In other words, for security events that failed to exploit a vulnerability attack of the same vulnerability type, the collected response data packets all have the same first feature. A security event of one vulnerability type can correspond to one first feature, or it can correspond to two or more first features. The first features corresponding to these vulnerability types are stored in the first feature library.

[0049] Here, a method for determining the vulnerability type of the vulnerability exploited by the first security event may be that the first security event carries a setting tag and the field value of the setting tag is used.

[0050] Step 102: When the corresponding first feature exists in the response data packet of the first security event, determine that the attack result of the first security event is an attack failure.

[0051] Because the security incident exploits different types of vulnerabilities, different content will be returned in the response packet. By matching the response packet with the presence of the corresponding first feature, it can be determined whether the attack result of the first security incident is a failure. If the corresponding first feature is present in the response packet of the first security incident, the attack result is determined to be a failure.

[0052] Here, the first feature is matched against the response data packet to determine whether the attack result of the first security event is a failed attack. The first feature can be a keyword and / or a regular expression rule. The specific keyword can be set as needed, while a regular expression is a logical formula that operates on character strings and special characters, forming a characteristic character string through the combination of characters.

[0053] There are a large number of malicious servers on the network, which continuously scan electronic devices on the Internet for vulnerabilities in order to launch attacks. Among the attacks launched by these malicious servers, the vast majority fail. In an embodiment of the present application, by determining whether a response data packet contains the characteristics of a failed attack exploiting a corresponding type of vulnerability, if the response data packet contains the characteristics of a failed attack, the attack result of the corresponding security event is determined to be an attack failure. In this way, the security event of an attack failure is determined from the vast number of security events whose attack results are to be determined, and the vast number of security events of failed attacks can be quickly filtered out, thereby improving the efficiency of attack result determination.

[0054] Before determining the first feature corresponding to the vulnerability type of the first security event in the first feature library, it is necessary to establish the first feature library storing the first feature. Taking into account the frequency of vulnerability exploitation, scope of application, and harm, various vulnerability types can be divided into at least two major categories. Here, different vulnerability types can be divided into two major categories: high-availability vulnerabilities and general vulnerabilities. High-availability vulnerabilities refer to vulnerabilities with high exploitation frequency, wide scope of application, and / or high harm, while general vulnerabilities refer to vulnerabilities other than high-availability vulnerabilities.

[0055] For high-availability vulnerabilities, by analyzing the specific vulnerabilities being exploited, we extract the characteristics of the response data packets when each vulnerability type fails to be exploited. We then match the response data packets based on the characteristics of each vulnerability type when the exploit fails to be exploited, and determine whether the attack result is an attack failure, such as the deserialization vulnerability of the T3 protocol of WebLogic.

[0056] For a general vulnerability, in one embodiment, before determining the first feature corresponding to the vulnerability type of the first security event in the first feature library, the method further includes:

[0057] determining common characteristics of at least two response packets, each response packet being generated based on a security event of a vulnerability type;

[0058] The common feature is determined as a first feature of at least two vulnerability types; the at least two vulnerability types include vulnerability types corresponding to the at least two response data packets.

[0059] Based on the response data packets of the security events of each of the at least two vulnerability types when the attack fails, common features of the at least two response data packets are determined, and the determined common features are used as matching features, i.e., first features, for determining whether the security events of the at least two vulnerability types have failed attacks. Furthermore, the determined common features can also be used as the first features of the vulnerability types associated with the two vulnerability types. Here, common features can be extracted from at least two of the multiple associated vulnerability types to be used for attack failure determination for security events of multiple vulnerability types.

[0060] For example, SQL injection is mostly used in dynamic page requests. SQL injection attacks on static pages such as HTML can be used as matching features of response data packets to determine whether the attack has failed.

[0061] As mentioned above, the first feature is used as an attack failure determination condition, which can quickly filter a large number of security events of attack failure. Ideally, in order to improve the detection rate of security events of attack failure, the determination condition of attack failure should cover more vulnerability types. In this embodiment, there is no need to extract attack failure features for each vulnerability type with an associated relationship, which reduces the workload required to generate the first feature library. At the same time, the first feature determined by the extracted common features can be universally applicable to security events of more vulnerability types. For example, for currently unknown vulnerability types, the first feature cannot be determined through feature extraction. In this way, the universality of the first feature as an attack failure determination condition for security events of various vulnerabilities is improved.

[0062] It's important to note that the criteria for vulnerability classification aren't absolute; they can be determined based on the application scenario. For example, in scenarios where component vulnerabilities (such as Struts and Tomcat) are of concern, vulnerabilities exploiting these components can be designated as high-availability vulnerabilities. By setting these criteria, vulnerability types can be divided and corresponding first features can be determined for each of the two main vulnerability types. This reduces the workload required to generate the first feature library while enabling accurate determination of attack failures for security incidents exploiting specific vulnerability types.

[0063] In various embodiments of the present application, whether the attack result of the first security event is an attack failure is determined by matching the first feature of the attack failure with the response data packet. In one embodiment, the method further includes:

[0064] Determining a second feature corresponding to the vulnerability type of the first security event in the second feature library;

[0065] Determining that the attack result of the first security event is an attack failure includes:

[0066] If the corresponding second feature does not exist in the response data packet of the first security event, determining that the attack result of the first security event is an attack failure; wherein,

[0067] The second feature library includes at least one second feature; each second feature represents a feature of a corresponding response data packet when a security event attack of a corresponding vulnerability type is successful.

[0068] A corresponding second feature is determined in a set second feature library based on the vulnerability type of the first security event. If the corresponding first feature is present in the response data packet of the first security event, and the corresponding second feature is not present in the response data packet of the first security event, the attack result is determined to be an attack failure.

[0069] It should be noted that for a security incident, the attack results can include three situations: attack success, attack failure, and pending. By matching the corresponding second feature in the response packet, it is possible to determine whether the attack result of the first security incident is a success. If the corresponding second feature is not present in the response packet, the attack result of the first security incident is not a success, and the attack result can be either an attack failure or undetermined. However, if the corresponding first feature is present in the response packet, the attack result can be determined to be a failure.

[0070] Among them, each second feature refers to a common feature in the response data packet of a security event in which a vulnerability attack using the corresponding vulnerability type is successful. In other words, for all security events in which a vulnerability attack using the same vulnerability type is successful, the collected response data packet has the same second feature. The second feature can be determined by extracting the first feature of the highly available vulnerability type. That is, by analyzing the specific vulnerability being exploited, the features of the response data packet when each vulnerability type is successfully exploited are extracted, and the response data packet is matched according to the features of each vulnerability type when it is successfully exploited, to determine whether the attack result is a successful attack. The second feature can be a keyword or a regular expression rule. The specific keyword can be set as needed, and the regular expression is a logical formula for operating on character strings and special characters, and a feature string is formed by combining characters. In addition, a security event of one vulnerability type can correspond to one second feature, or two or more second features.

[0071] Here, the matching of whether the first feature exists in the response data packet and whether the second feature exists in the response data packet can be performed simultaneously or sequentially.

[0072] In this way, by matching the attack success characteristics and attack failure characteristics of the response data packet respectively, the accuracy of the attack result determination can be improved.

[0073] In one embodiment, the method further comprises:

[0074] When the corresponding second feature exists in the response data packet of the first security event, it is determined that the attack result of the first security event is a successful attack.

[0075] As mentioned above, by matching the response data packet with the corresponding second feature, it is possible to determine whether the attack result of the first security event is a successful attack. If the response data packet contains the corresponding second feature, the attack result is determined to be a successful attack.

[0076] Here, the priority of a successful attack is set higher than that of a failed attack. That is, when the second signature of a successful attack and the first signature of a failed attack are matched, the attack result of the security event is determined to be a successful attack. In this embodiment, if the corresponding second signature is present in the response packet, the attack result of the security event is determined to be a successful attack, regardless of whether the corresponding first signature is present in the response packet. This improves the accuracy of attack result determination by combining the matching of the signatures of successful and failed attacks in the response packet.

[0077] In one embodiment, before determining the first feature corresponding to the vulnerability type of the first security event in the first feature library, the method further includes:

[0078] Hijacking the first security event through a hook;

[0079] After determining the attack result of the first security event, the method further includes:

[0080] Release the hook of the first security event.

[0081] Before the first security event is logged as a corresponding security log, the first security event is hijacked using a hook. After determining the attack result of the first security event, the judgment result corresponding to the first security event is modified, and the hook for the first security event is released, and the first security event is logged as a corresponding security log. Hijacking the first security event through the hooking technology facilitates the modification of the security event result in subsequent steps. In this way, the attack result of the first security event can be determined before generating the corresponding security log of the first security event.

[0082] In one embodiment, the method further comprises:

[0083] Based on the corresponding vulnerability type and attack result, a risk level of the first security incident is determined.

[0084] After the attack result of the first security event is determined, the risk score and weight parameter of the first security event are determined according to the vulnerability type and attack result corresponding to the first security event, thereby determining the risk level.

[0085] Among them, when setting the weight parameters of the attack results, corresponding weight parameters can be set for security events of each vulnerability type, or the same weight parameters can be set for security events of all vulnerability types. Here, when setting the weight parameters, the weight parameter for a successful attack result is not less than the weight parameter for a failed attack result. In the scheme of setting a weight parameter for a security event of each vulnerability type, the risk score is determined based on the vulnerability type corresponding to the first security event, and the weight parameter is determined based on the corresponding vulnerability type and the attack result. The risk level is determined based on the comparison of the calculation result of the risk score and the weight parameter with the set threshold. The risk score corresponding to each vulnerability type can be pre-set. Generally, the larger the risk score, the larger the calculation result obtained, and the higher the risk level, indicating that the corresponding first security event is more harmful. Preferably, an alarm message can be output according to the risk level.

[0086] For example, there is a security incident in which an external network server attacks an internal network server, and the attack result is a failure. According to the weight parameter corresponding to the attack result, the calculation result of the failed attack is smaller than the calculation result of the successful attack, and the determined risk level is smaller.

[0087] In this way, the risk level of the first security event is determined based on the vulnerability type and attack result corresponding to the first security event, which can realize automatic risk analysis of security events and thus improve the processing efficiency of security events.

[0088] In one embodiment, the method further comprises:

[0089] The attack result of the first security event is displayed on the setting page.

[0090] Here, the first security event and the corresponding security log are displayed on the setting page, and the attack result of the first security event is represented by the setting field. Figure 2 The display page diagram shows security events with failed attack results marked with a "failed" label, and security events with successful attack results marked with a "successful" label. Security events with different attack results can be filtered. Furthermore, the risk level and security level of security events can also be displayed on the settings page.

[0091] The settings page displays information such as attack results related to security incidents, allowing users to intuitively obtain relevant information on massive security incidents, improving the efficiency of users in handling security incidents, and improving the user's operating experience.

[0092] The present application will be described in further detail below in conjunction with application examples.

[0093] Figure 3The following is a schematic diagram of the implementation flow of the attack result determination method provided by the application embodiment of the present application. The attack result determination method includes:

[0094] Step 301: Attack event.

[0095] For security events generated by the attack engine, before the security events are logged as security logs, a hook is set up to hijack the security events, making it easier to modify the results of the security events in subsequent steps.

[0096] Here, you can use hook technology to hijack the object to control the interaction between this object and other objects.

[0097] Step 302: Type differentiation.

[0098] According to the tag value of the security event tag, the vulnerability type of the vulnerability exploited by the security event is determined, the security event type is distinguished according to the vulnerability type, and then the security event is sent to the attack failure detection engine.

[0099] For example, SQL injection, cross-site scripting attacks, etc.

[0100] Step 303: Attack failure detection.

[0101] Here, attack failure detection is performed through the set attack failure detection engine.

[0102] like Figure 4 The schematic diagram of the attack failure detection engine shown in the figure shows that, considering the frequency of vulnerability exploitation, scope of application, and harm, vulnerability types can be divided into general vulnerability detection (such as SQL injection and XSS vulnerabilities) and high-availability vulnerability detection (such as component vulnerabilities such as Struts and Tomcat).

[0103] For common vulnerabilities, we match the common features of failed exploits of this type of vulnerability. For example, SQL injection exploits mostly occur in dynamic page requests, so SQL injection attacks on static pages such as HTML can be judged as failed attacks.

[0104] For high-availability vulnerabilities, we analyze specific exploits and extract the signatures of successful and / or failed attacks for each vulnerability type. These signatures are then used to determine whether an attack is successful or unsuccessful, such as the deserialization vulnerability in WebLogic's T3 protocol. Since different exploits return different content in the response packet when they are successfully exploited, we can determine whether an attack has failed by matching the signature strings in the response packet.

[0105] Among them, attack failure means that the attack behavior does not achieve the intended purpose, for example, it fails to destroy or obtain server permissions.

[0106] Step 304: Modify the event result.

[0107] The attack failure detection engine modifies the security event judgment result of the security event judged as attack failure to attack failure based on the detected attack result, and then releases the hook of step 301, and the security event is recorded as a security log for storage.

[0108] Step 305: Display the attack results.

[0109] The security logs generated by security incidents are displayed on the platform page. Attack events with failed results are marked with the "failure" label, and the risk and threat level of the event are also adjusted and displayed based on the attack results. For example, if there is a security incident in which an external network server attacks an internal network server, the risk and threat level of the security incident can be lowered accordingly based on the "failure" label.

[0110] There are numerous malicious servers on the Internet, which continuously scan for vulnerabilities in electronic devices on the Internet in order to launch attacks. Currently, many security products focus on improving attack detection. However, when conducting security monitoring or incident handling, technical personnel must manually determine the attack results of massive attacks, which is costly and inefficient.

[0111] At the same time, manually determining the attack results of massive security incidents may also miss some security incidents where the attack was successful. In other words, the security incidents where the attack was successful may be buried in the massive security incidents, resulting in an increased underreporting rate of security incidents where the attack was successful.

[0112] In this application embodiment, a system for determining whether the attack result of a security event is a failed attack is proposed. By marking the failed attack result and displaying the corresponding security event on the platform page using a set failed attack label, the system filters out a large number of failed attack security events from a large number of security events, enabling the distinction of security events with different attack results. This reduces the workload of security event processing and monitoring, and improves the efficiency of security event processing. Furthermore, by filtering a large number of failed attack security events and automatically determining the attack result, there is no need for manual judgment of the attack results of a large number of attack behaviors, thereby reducing the underreporting rate of successful attack security events. Furthermore, even personnel without security capabilities can complete security event processing based on failure labels, lowering the threshold for use.

[0113] By marking the attack result of a security event as an attack failure with the "failure" label, the attack result can be used as a screening condition or data source for judgment, providing a data source for realizing functions such as attack behavior analysis.

[0114] It should be noted that the difference between a failed attack and a successful attack is as follows:

[0115] From the perspective of the damage level, a failed attack means that the attack is ineffective and the damage level is much lower than a successful attack.

[0116] From the perspective of solution design, attack failure, as a filtering condition, needs to be highly accurate. Once a false positive occurs, the attack incident will easily be ignored.

[0117] From the perspective of detection logic priority, to avoid repeated modification of attack results by misjudging both successful and failed attacks, attack failures are prioritized lower than successful attacks. Furthermore, in the calculation of risk scores and weight parameters, the weight parameter for attack failures is also lower than the weight parameter for successful attacks.

[0118] Display on the platform page, you can also highlight the color of the successful attack label and display the failed attack label in gray or black;

[0119] In terms of quantity, the number of security incidents of failed attacks is much higher than that of successful attacks. Therefore, filtering a large number of security incidents of failed attacks improves the efficiency of determining attack results.

[0120] There are some differences in the requirements for detecting attack failures and attack successes. Attack failures require more comprehensive data coverage, while successful attacks require more precise features for detection accuracy. For example, the features of successful attacks can be extracted for security events of each vulnerability type, specifically the vulnerability type or exploitation method, while failures can be detected through the features of general vulnerabilities.

[0121] In order to implement the method of the embodiment of the present application, the embodiment of the present application also provides an attack result determination device, such as Figure 5 As shown, the device includes:

[0122] The first processing unit 501 is configured to determine a first feature corresponding to a vulnerability type of a first security event in a first feature library;

[0123] The second processing unit 502 is configured to determine that the attack result of the first security event is an attack failure when the corresponding first feature exists in the response data packet of the first security event; wherein,

[0124] The first feature library includes at least one first feature; each first feature represents a feature of a corresponding response data packet when a security event attack of a corresponding vulnerability type fails.

[0125] In one embodiment, the device further comprises:

[0126] The third processing unit is used to determine a common feature of at least two response data packets before the first processing unit 501 determines the first feature corresponding to the vulnerability type of the first security event in the first feature library; each response data packet is generated based on a security event of one vulnerability type; the common feature is determined as the first feature of at least two vulnerability types; the at least two vulnerability types include the vulnerability types corresponding to the at least two response data packets.

[0127] In one embodiment, the apparatus further comprises:

[0128] a fourth processing unit, configured to determine, in the second feature library, a second feature corresponding to the vulnerability type of the first security event;

[0129] The second processing unit 502 is configured to:

[0130] If the corresponding second feature does not exist in the response data packet of the first security event, determining that the attack result of the first security event is an attack failure; wherein,

[0131] The second feature library includes at least one second feature; each second feature represents a feature of a corresponding response data packet when a security event attack of a corresponding vulnerability type is successful.

[0132] In one embodiment, the apparatus further comprises:

[0133] The fifth processing unit is configured to determine that the attack result of the first security event is a successful attack if the corresponding second feature exists in the response data packet of the first security event.

[0134] In one embodiment, the apparatus further comprises:

[0135] The sixth processing unit is used to hijack the first security event through a hook before the first processing unit 501 determines the first feature corresponding to the vulnerability type of the first security event in the first feature library; and is also used to release the hook of the first security event after the second processing unit 502 determines the attack result of the first security event.

[0136] In one embodiment, the apparatus further comprises:

[0137] The seventh processing unit is configured to determine a risk level of the first security event based on a corresponding vulnerability type and an attack result.

[0138] In one embodiment, the apparatus further comprises:

[0139] The display unit is configured to display the attack result of the first security event on a setting page.

[0140] In actual application, the first processing unit 501, the second processing unit 502, the third processing unit, the fourth processing unit, the fifth processing unit, the sixth processing unit, the seventh processing unit, and the display unit can be implemented by a processor in the attack result determination device, such as a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU), or a field-programmable gate array (FPGA).

[0141] It should be noted that the attack result determination device provided in the above embodiment is illustrated by the division of the aforementioned program modules when performing attack result determination. In actual applications, the aforementioned processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the aforementioned processing. In addition, the attack result determination device provided in the above embodiment and the attack result determination method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0142] Based on the hardware implementation of the above program modules, and in order to implement the attack result determination method of the embodiment of the present application, the embodiment of the present application also provides an electronic device. Figure 6 This is a schematic diagram of the hardware structure of the electronic device according to the embodiment of the present application. Figure 6 As shown, the electronic equipment includes:

[0143] Communication interface 1, capable of exchanging information with other devices such as network devices;

[0144] The processor 2 is connected to the communication interface 1 to implement information exchange with other devices and is used to execute the method provided by one or more of the above technical solutions when running a computer program. The computer program is stored in the memory 3.

[0145] Of course, in actual application, the various components in the electronic device are coupled together through the bus system 4. It can be understood that the bus system 4 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 4 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 6 Various buses are labeled as bus system 4.

[0146] The memory 3 in the embodiment of the present invention is used to store various types of data to support the operation of the electronic device. Examples of such data include: any computer program used to operate on the electronic device.

[0147] It is understood that the memory 3 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a magnetic disk memory or a magnetic tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory 2 described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memories.

[0148] The method disclosed in the above embodiment of the present invention can be applied to processor 2 or implemented by processor 2. Processor 2 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the hardware integrated logic circuit in processor 2 or by instructions in software form. The above processor 2 can be a general-purpose processor, a DSP, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. Processor 2 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiment of the present invention. A general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiment of the present invention can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in memory 3. Processor 2 reads the program in memory 3 and completes the steps of the above method in combination with its hardware.

[0149] When the processor 2 executes the program, the corresponding processes in the various methods of the embodiments of the present invention are implemented, which will not be described here for the sake of brevity.

[0150] In an exemplary embodiment, the present invention further provides a storage medium, namely, a computer storage medium, specifically, a computer-readable storage medium, such as a memory 3 storing a computer program. The computer program can be executed by a processor 2 to perform the steps of the aforementioned method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface mount storage, optical disk, or CD-ROM.

[0151] In the several embodiments provided in this application, it should be understood that the disclosed devices, electronic devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.

[0152] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0153] In addition, all functional units in the embodiments of the present application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the above-mentioned integrated units can be implemented in the form of hardware or in the form of hardware plus software functional units.

[0154] Those skilled in the art will understand that all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: mobile storage devices, ROM, RAM, disks or optical disks, etc. Various media that can store program codes.

[0155] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.

[0156] It should be noted that the technical solutions described in the embodiments of this application can be arbitrarily combined without conflict. Unless otherwise specified or limited, the term "connection" should be understood in a broad sense. For example, it can be an electrical connection or internal communication between two components. It can be a direct connection or an indirect connection through an intermediate medium. For those skilled in the art, the specific meaning of the above terms can be understood according to the specific circumstances.

[0157] Additionally, in the examples of this application, "first," "second," etc., are used to distinguish similar objects, and are not necessarily used to describe a specific order or precedence. It should be understood that the objects distinguished by "first," "second," and "third" can be interchanged where appropriate, such that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0158] The term "and / or" herein simply describes an association relationship between associated objects, indicating that three relationships can exist. For example, "A and / or B" can represent the existence of three situations: A alone, A and B simultaneously, and B alone. In addition, the term "at least one" herein refers to any combination of at least two of any one or more of a plurality. For example, "at least one of A, B, and C" can represent any one or more elements selected from the set consisting of A, B, and C.

[0159] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0160] The various specific technical features in the various embodiments described in the specific implementation methods can be combined in various ways without contradiction. For example, different implementation methods can be formed by combining different specific technical features. In order to avoid unnecessary repetition, the various possible combinations of the specific technical features in this application will not be described separately.

Claims

1. A method for determining an attack result, characterized in that: The method comprises: determining common characteristics of at least two response packets, each response packet being generated based on a security event of a vulnerability type; Determining the common feature as a first feature of at least two vulnerability types; the at least two vulnerability types include vulnerability types corresponding to the at least two response data packets; Determining, in a first feature library, a first feature corresponding to a vulnerability type of a first security event; If the corresponding first feature exists in the response data packet of the first security event, determining that the attack result of the first security event is an attack failure; The priority of a successful attack is set to be higher than the priority of a failed attack. When the corresponding first feature and the corresponding second feature exist in the response data packet, the attack result is determined to be a successful attack; wherein the first feature library includes at least one first feature; each first feature represents the feature of the corresponding response data packet when the security event attack of the corresponding vulnerability type fails, and the second feature represents the feature of the corresponding response data packet when the security event attack of the corresponding vulnerability type succeeds.

2. The method according to claim 1, characterized in that The method further comprises: Determining a second feature corresponding to the vulnerability type of the first security event in the second feature library; Determining that the attack result of the first security event is an attack failure includes: If the corresponding second feature does not exist in the response data packet of the first security event, determining that the attack result of the first security event is an attack failure; wherein, The second feature library includes at least one second feature.

3. The method according to claim 2, characterized in that The method further comprises: When the corresponding second feature exists in the response data packet of the first security event, it is determined that the attack result of the first security event is a successful attack.

4. The method according to claim 1, wherein Before determining the first feature corresponding to the vulnerability type of the first security event in the first feature library, the method further includes: Hijacking the first security event through a hook; After determining the attack result of the first security event, the method further includes: Release the hook of the first security event.

5. The method according to claim 1, wherein The method further comprises: Based on the corresponding vulnerability type and attack result, a risk level of the first security incident is determined.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: The attack result of the first security event is displayed on the setting page.

7. An attack result determination device, characterized in that: include: A first processing unit is configured to determine, in a first feature library, a first feature corresponding to a vulnerability type of a first security event; The second processing unit is configured to determine that the attack result of the first security event is an attack failure if the corresponding first feature exists in the response data packet of the first security event; set the priority of the attack success to be higher than the priority of the attack failure, and determine that the attack result is an attack success if the corresponding first feature and the corresponding second feature exist in the response data packet; wherein, The first feature library includes at least one first feature; each first feature represents a feature of a corresponding response data packet when a security event attack of a corresponding vulnerability type fails, and the second feature represents a feature of a corresponding response data packet when a security event attack of a corresponding vulnerability type succeeds; A third processing unit is used to determine a common feature of at least two response data packets; each response data packet is generated based on a security event of a vulnerability type; and determine the common feature as a first feature of at least two vulnerability types; the at least two vulnerability types include the vulnerability types corresponding to the at least two response data packets.

8. An electronic device, characterized in that: include: a processor and a memory for storing a computer program capable of being executed on the processor, Wherein, when the processor is used to run the computer program, it executes the steps of the method according to any one of claims 1 to 6.

9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Network attack result detection method and system

    CN108881263A