A method, device and readable storage medium for detecting deserialization attacks
By analyzing the format of Java deserialization data and refining the detection strategy, the problem of low detection accuracy of Java deserialization attacks is solved, and higher detection accuracy and flexibility are achieved.
Patent Information
- Application Number
- CN202210128338.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-11
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-02-11
AI Technical Summary
In the prior art, Java deserialization attack detection accuracy is low, mainly due to untimely blacklist updates and degraded matching performance.
By determining the data format of the serialized data, analyzing the data and determining the corresponding detection strategy according to different formats, deserialization attack detection is performed on the classes in the parsed data, and the detection strategy is refined to improve detection accuracy.
Improve the accuracy of Java deserialization attack detection, avoid misjudgment, and enhance the flexibility and targeted detection.
Smart Images

Figure CN114547609B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a method, device and readable storage medium for detecting a deserialization attack. Background Art
[0002] To facilitate the transmission of complex data by technicians, Java provides an "object serialization" mechanism for serializing data. Usually, when Java objects are serialized to persistent storage (local hard disk) or transmitted over the network, they are serialized into binary byte sequences for storage and transmission. This behavior of converting Java objects into binary is called serialization.
[0003] Deserialization is the reverse process of serialization, which is used to restore the binary byte sequence to the Java object before serialization. As for the key problem in Java applications: For Java deserialization attacks, the most common method is to use blacklists for matching, which is used to find the data content in Java data that performs deserialization attacks, so as to block deserialization attacks. However, this method has problems such as untimely blacklist updates, or updating the matching rule library at the same time as the blacklist is updated, which causes the matching performance to decline, resulting in low accuracy, and further leads to low accuracy in Java deserialization attack detection. Summary of the invention
[0004] The present application provides a method, device and readable storage medium for detecting a deserialization attack, so as to solve the problem of low accuracy in detecting Java deserialization attacks.
[0005] In a first aspect, the present application provides a method for detecting a deserialization attack, the method comprising:
[0006] Determine the data format of the serialized data; wherein the data format includes one of the following formats: native byte stream, object notation Json format, and extensible markup language XML format;
[0007] Based on the data format, parsing the serialized data to obtain parsed data corresponding to the data format; wherein the parsed data includes a class, and the class indicates a strategy for creating a Java entity;
[0008] Based on the data format, a detection strategy for the serialized data is determined, and a deserialization attack detection is performed on the class in the parsed data using the detection strategy to determine whether a deserialization attack exists in the serialized data.
[0009] The above method determines the corresponding detection strategy for parsed data of different data formats; that is, according to the data format of serialized data, the detection strategy of deserialization attack is refined, so that the detection of deserialization attack is more targeted, thereby improving the accuracy of detecting deserialization attack.
[0010] In a possible implementation manner, the step of parsing the serialized data based on the data format to obtain parsed data corresponding to the data format includes:
[0011] When the data format is a native byte stream format, the parsed data includes an array and an object; wherein the array is a collection of fields of the same type, the object indicates a Java entity, and the field includes a field name and a field value;
[0012] When the data format is in Json format, the parsed data includes a specified field, and the specified field and the field value of the specified field form a key-value pair;
[0013] When the data format is XML format, determine whether the serialized data is in XML Encoder format; if so, the parsed data includes Object nodes and Void nodes, and the Object node includes a class field, and the Void node includes a method field; if not, the parsed data is in X Stream format, and the parsed data includes a class node or a class field; wherein the node is a start identifier of the serialized data in XML format.
[0014] In a possible implementation manner, determining the detection strategy of the serialized data based on the data format includes:
[0015] When the data format is a native byte stream, the detection strategy is to detect the number of serialized objects contained in the parsed data; and / or
[0016] Contains the number of serialized arrays; and / or
[0017] Contains the number of class names in the first blacklist; and / or
[0018] When the nesting depth of the reference object exceeds a set depth, the nesting depth of the reference object; and / or
[0019] Whether there is a parsing anomaly caused by a protocol format error;
[0020] The first blacklist indicates that the serialized data in the native byte stream format includes records of deserialization attacks, the records include classes that carry deserialization attacks, and the nesting depth of the referenced object indicates the number of times the object is referenced.
[0021] In a possible implementation manner, determining the detection strategy of the serialized data based on the data format includes:
[0022] When the data format is Json format, the detection strategy is to detect the number of field values of the specified field in the key-value pair that conform to the naming characteristics of the Java class; and / or
[0023] The Java class name is the number of class names in the second blacklist;
[0024] The second blacklist is Json format serialized data including records of deserialization attacks, and the records include classes that carry deserialization attacks.
[0025] In a possible implementation manner, determining the detection strategy of the serialized data based on the data format includes:
[0026] When the data format is the XML Encoder format, the detection strategy is to detect the number of nodes whose field value of the class field in the Object node is the class name; and / or
[0027] The field value of the method field in the Void node is the number of nodes of the field value of the method field in the third blacklist; wherein the third blacklist indicates that the serialized data in the XML Encoder format includes records during deserialization attacks;
[0028] When the data format is an X Stream format, the detection strategy is to detect that the parsed data includes the number of nodes in the fourth blacklist or the number of nodes with the same class name; and / or
[0029] The field value of the class node is the number of class names in the fourth blacklist; wherein the fourth blacklist indicates that the serialized data in the X Stream format includes a record of a deserialization attack, and the record includes a class that carries the deserialization attack.
[0030] In a possible implementation manner, the using the detection strategy to perform deserialization attack detection on the parsed data to determine whether a deserialization attack exists in the serialized data includes:
[0031] Determine the score and set the weight of each item in the detection strategy corresponding to the data format;
[0032] Determine the score of each item of content based on the score of each item of content and the set weight;
[0033] Accumulating the scores of each of the contents to obtain a confidence value of the serialized data; wherein the confidence value indicates the probability that the serialized data includes a deserialization attack;
[0034] The confidence value is compared with an alarm value, and when the confidence value is greater than the alarm value, it is determined that a deserialization attack exists in the serialized data; wherein the alarm value is set according to a usage scenario of the serialized data.
[0035] The above method flexibly sets the alarm value through different deserialization scenarios, making the detection of deserialization attacks more flexible, avoiding misjudgment, and further improving the accuracy of detecting deserialization attacks.
[0036] In a second aspect, the present application provides a deserialization attack detection device, the device comprising:
[0037] Determining unit: used to determine the data format of serialized data; wherein the data format includes one of native byte stream, object notation Json format, and extensible markup language XML format;
[0038] A parsing unit: used for parsing the serialized data based on the data format to obtain parsed data corresponding to the data format; wherein the parsed data includes a class, and the class indicates a strategy for creating a Java entity;
[0039] A detection unit is used to determine a detection strategy for the serialized data based on the data format, and use the detection strategy to perform deserialization attack detection on the class in the parsed data to determine whether a deserialization attack exists in the serialized data.
[0040] In a possible implementation manner, the parsing unit is specifically configured to: when the data format is a native byte stream format, the parsed data includes an array and an object; wherein the array is a collection of fields of the same type, the object indicates a Java entity, and the field includes a field name and a field value; when the data format is a Json format, the parsed data includes a specified field, and the specified field and the field value of the specified field form a key-value pair; when the data format is an XML format, determine whether the serialized data is in an XML Encoder format; if so, the parsed data includes an Object node and a Void node, and the Object node includes a class field, and the Void node includes a method field; if not, the parsed data is in an X Stream format, and the parsed data includes a class node or a class field; wherein the node is a start identifier of the serialized data in the XML format.
[0041] In a possible implementation manner, the detection unit is specifically used to determine the score and set weight of each content in the detection strategy corresponding to the data format; based on the score and set weight of each content, determine the score of each content; accumulate the scores of each content to obtain a confidence value of the serialized data; wherein the confidence value indicates the probability that the serialized data includes a deserialization attack; compare the confidence value with an alarm value, and when the confidence value is greater than the alarm value, determine that a deserialization attack exists in the serialized data; wherein the alarm value is set according to the usage scenario of the serialized data.
[0042] In a possible implementation manner, when the data format is a native byte stream, the detection strategy is to detect the number of serialized objects contained in the parsed data; and / or
[0043] Contains the number of serialized arrays; and / or
[0044] Contains the number of class names in the first blacklist; and / or
[0045] When the nesting depth of the reference object exceeds a set depth, the nesting depth of the reference object; and / or
[0046] Whether there is a parsing anomaly caused by a protocol format error;
[0047] The first blacklist indicates that the serialized data in the native byte stream format includes records of deserialization attacks, the records include classes that carry deserialization attacks, and the nesting depth of the referenced object indicates the number of times the object is referenced.
[0048] In a possible implementation manner, determining the detection strategy of the serialized data based on the data format includes:
[0049] When the data format is Json format, the detection strategy is to detect the number of field values of the specified field in the key-value pair that conform to the naming characteristics of the Java class; and / or
[0050] The Java class name is the number of class names in the second blacklist;
[0051] The second blacklist is Json format serialized data including records of deserialization attacks, and the records include classes that carry deserialization attacks.
[0052] In a possible implementation manner, determining the detection strategy of the serialized data based on the data format includes:
[0053] When the data format is the XML Encoder format, the detection strategy is to detect the number of nodes whose field value of the class field in the Object node is the class name; and / or
[0054] The field value of the method field in the Void node is the number of nodes of the field value of the method field in the third blacklist; wherein the third blacklist indicates that the serialized data in the XML Encoder format includes records during deserialization attacks;
[0055] When the data format is an X Stream format, the detection strategy is to detect that the parsed data includes the number of nodes in the fourth blacklist or the number of nodes with the same class name; and / or
[0056] The field value of the class node is the number of class names in the fourth blacklist; wherein the fourth blacklist indicates that the serialized data in the X Stream format includes a record of a deserialization attack, and the record includes a class that carries the deserialization attack.
[0057] In a third aspect, the present application provides a readable storage medium, comprising:
[0058] Memory,
[0059] The memory is used to store instructions. When the instructions are executed by the processor, the device including the readable storage medium performs the method described in the first aspect and any possible implementation manner. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 A flowchart of a deserialization attack detection method provided by this application;
[0061] Figure 2 A schematic diagram of deserialization attack detection for serialized data provided by this application;
[0062] Figure 3 A schematic diagram of the structure of a Java deserialization attack detection device provided by the present application. DETAILED DESCRIPTION
[0063] In view of the problem of low accuracy in detecting deserialization attacks in the prior art, the present application proposes a method for detecting deserialization attacks: first, serialized data in different formats are parsed, and corresponding deserialization attack detection is performed based on the parsed results of serialized data in different formats. By refining the judgment method of deserialization attacks in different formats, the purpose of improving the accuracy of detecting deserialization attacks is achieved.
[0064] The following is an explanation of the technical terms used in the embodiments of the present application:
[0065] Serialization: refers to the process of converting an object into a format that can be easily transmitted.
[0066] Deserialization attack: The attacker serializes the malicious object (code) through the serialization function and sends it to the deserialization interface of the target server pretending to be normal data. If the server does not perform security verification on the serialized data and directly deserializes the serialized data of the malicious object, the server will execute the code in the malicious object, causing an attack on the server.
[0067] Java native byte stream: refers to a type of data that serializes an object into a binary byte stream through the writeObject method in a Java program.
[0068] Fast json: A Json parser and generator developed based on Java; it can be used to convert Java objects into their Json representations, and can also convert Json strings into corresponding Java objects.
[0069] XML Encoder (Extensible Markup Language Encoder): refers to a serialization class in the Java.bean package that converts Java objects and XML format data; serialization can only be achieved if the class implements the Serializable interface; it includes<java version="1.8.0_131"class="java.beans.XMLDecoder"> .
[0070] X Stream: refers to a Java library (a serialization class) that converts Java objects and XML format data.
[0071] Confidence value: used to indicate the credibility of a data deserialization attack. This value is obtained through the final scoring calculation. Its range is 0 to 10. The larger the value, the higher the credibility, which is equivalent to the threat score.
[0072] DoS deserialization attack: refers to an attack method in which the attacker constructs N layers of object references in serialized data, so that when the target server receives the serialized data and performs deserialization parsing, the server must consume a large amount of CPU resources, resulting in an inability to process normal business.
[0073] In order to better understand the above technical scheme, the technical scheme of the present application is described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present application and the specific features in the embodiments are detailed descriptions of the technical scheme of the present application, rather than limitations on the technical scheme of the present application. In the absence of conflict, the embodiments of the present application and the technical features in the embodiments can be combined with each other.
[0074] Please refer to Figure 1 The embodiment of the present application provides a method for detecting a deserialization attack, which is used to solve the problem of low accuracy of Java deserialization attack detection in the prior art. The method specifically includes the following implementation steps:
[0075] Step 101: Determine the data format of serialized data.
[0076] The data format includes one of the following formats: native byte stream, object notation Json format, and extensible markup language XML format.
[0077] Specifically, the data header of the serialized data is identified. If the data header includes "aced0005", the format of the serialized data is a native byte stream; if the data header starts with "{" or "[", the format of the serialized data is a Json format; if the data header starts with "<", the format of the serialized data is an XML format.
[0078] The serialized data can be at least one of URL, Querystring, Cookie, Body, etc. Among them, URL is a uniform resource locator, indicating an address; Querystring is a query string in a URL; Cookie is a Cookie field in an http header; Body refers to the request body in an http request. For example, in Java data: POST / 1.php? q=123HTTP / 1.1
[0079] Host:1.1.1.1
[0080] Cookie:aaa=bbb
[0081] Yyyyyyyyy.
[0082] Among them, Querystring is q=123; Cookie is aaa=bbb; Body is yyyyyyyy. Parse one of Querystring, Cookie, and Body to determine the data format of the corresponding serialized data.
[0083] Step 102: Based on the data format, parse the serialized data to obtain parsed data corresponding to the data format.
[0084] The parsed data includes a class, and the class indicates a strategy for creating a Java entity.
[0085] Specifically, the serialized data in the Java native byte stream format can be parsed according to the Java standard serialization protocol format, wherein the serialization protocol is the standard definition of the data carrier, so that the loaded data can be effectively and losslessly converted with specific data using different languages on different platforms, and the protocol itself is independent of the platform and language. Therefore, when the data format is the native byte stream format, the parsed data includes arrays and objects; wherein the array is a collection of fields of the same type, the object indicates a Java entity, the field includes a field name and a field value, and the array can also be a collection of objects. In other words, a class is an abstraction and generalization of an object and an array, and an object is a Java entity.
[0086] When the data format is in Json format, the parsed data includes a specified field, and the specified field and the field value of the specified field form a key-value pair. The key-value pair is composed of a key and a value pair. Among them, Key is the field name, and value is the field value. Deserialization attacks in Json format data only exist in the fast json framework. In Fast json serialized data, the specified field can be a @type field, and the field value of the @type field is a java class name; otherwise, the serialized data in the Json format is not used for deserialization processing, that is, there is no threat of deserialization attacks.
[0087] Parsing the serialized data in XML format may include: node name, field name and field value. The node is the start identifier of the serialized data in XML format.<java version="1.8.0_131"class="java.beans.XML Decoder"> The parsing results include a node named "java", field names "version" and "class", and field values "1.8.0_131" and "java.beans.XML Decoder" respectively.
[0088] When the data format is XML format, determine whether the serialized data is in XML Encoder format; if so, the parsed data includes Object nodes and Void nodes, and the Object node includes a class field, and the Void node includes a method field; if not, the parsed data is in X Stream format, and the parsed data includes a class node or a class field. Among them, when class is used as a node, it corresponds to the situation that the serialized data does not include member variables, and class as a node directly represents the class; and when class is used as a field, it corresponds to the situation that the serialized data includes member variables, and the class field represents the class as one of the member variables. It is worth noting that in the serialized data, class as an attribute represents the characteristics of the class, and method as a function method represents the behavior of the class.
[0089] In particular, if an error occurs during the parsing process and normal parsed data cannot be obtained; for serialized data in Json format and serialized data in XML format, it can be determined that there is no threat of deserialization attack. However, since the Java standard serialization protocol format is used for parsing the serialized data in Java native byte stream format, there is a possibility of parsing errors caused by differences in protocol formats. In other words, for serialized data in native byte stream format, when a parsing error occurs, it cannot be directly determined as serialized data that does not contain deserialization attacks; if the data with the parsing error does not contain an object, it can be determined that the parsing error is not caused by differences in protocol formats, and it can be determined that the serialized data in the native byte stream format does not contain deserialization attacks. In other words, if the data with the parsing error contains an object, there is still a possibility of deserialization attacks in the serialized data in the native byte stream format, so it is necessary to continue to use the corresponding parsing strategy for parsing.
[0090] Step 103: Based on the data format, determine a detection strategy for the serialized data, and use the detection strategy to perform deserialization attack detection on the class in the parsed data to determine whether a deserialization attack exists in the serialized data.
[0091] Specifically, when the data format is a native byte stream, the detection strategy is: detect the number of serialized objects contained in the parsed data; and / or the number of serialized arrays contained; and / or the number of class names contained in the first blacklist; and / or when the nesting depth of the referenced object exceeds the set depth, the nesting depth of the referenced object; and / or whether there is a parsing anomaly caused by a protocol format error. Among them, the first blacklist indicates that the serialized data in the native byte stream format includes a record of a deserialization attack, and the record includes a class that carries a deserialization attack, and the nesting depth of the referenced object indicates the number of times the object is referenced.
[0092] It can be seen that for serialized data in native byte stream format, deserialization attack detection can be performed based on at least one of the number of objects, the number of arrays, the number of overlaps with the class names in the first blacklist, and the nesting depth of referenced objects included in the parsing results; that is, by refining the detection strategy, the detection of deserialization attacks is made more targeted, thereby improving the accuracy of deserialization attack detection.
[0093] When the data format is Json format, the detection strategy is: detect the number of field values of the specified field in the key-value pair in the parsed data that conform to the naming characteristics of the Java class; and / or the number of class names in the second blacklist of the Java class name; it is also possible to determine whether the field value of the specified field is the number of package names defined in the blacklist, and the package name is the name of the data packet formed by combining multiple class names. Among them, the second blacklist is a Json format serialized data including a record of a deserialization attack, and the record includes a class that carries the deserialization attack. In the parsed data corresponding to the Json format, the aforementioned specified field can be the @type field.
[0094] It can be seen that for serialized data in Json format, deserialization attacks can be detected by detecting the number of fields in the @type field in the parsed data that are classes and conform to the naming characteristics of the Java class, as well as the number of overlaps with the class names in the second blacklist; that is, by refining the detection strategy, the detection of deserialization attacks is made more targeted, thereby improving the accuracy of deserialization attack detection.
[0095] When the data format is XML Encoder format, the number of nodes whose field value of the class field in the Object node is the class name is detected; and / or the number of nodes whose field value of the method field in the Void node is the field value of the method field in the third blacklist is detected. The third blacklist indicates that the serialized data in XML Encoder format includes records of deserialization attacks.
[0096] When the data format is an X Stream format, the detection strategy is to detect that the parsed data includes the number of nodes in the fourth blacklist or the number of nodes with the same class name; and / or the field value of the class node is the number of class names in the fourth blacklist; wherein the fourth blacklist indicates that the serialized data in the X Stream format includes a record during a deserialization attack, and the record includes a class that carries the deserialization attack.
[0097] It can be seen that the serialized data in XML format can be further refined into XML Encoder format and XStream format, and deserialization attack detection can be performed according to the characteristics of parsed data in different formats. Similarly, by refining the detection strategy, the detection of deserialization attacks can be made more targeted, thereby improving the accuracy of deserialization attack detection.
[0098] Furthermore, based on the corresponding deserialization attack detection methods under the above different formats, the serialized data can be scored according to the attack detection results, and the corresponding alarm thresholds can be set according to different deserialization scenarios, so as to achieve the purpose of accurately intercepting deserialization attacks. The following is a specific description of the setting of the scoring method.
[0099] In the scoring stage, the score calculation method for each project is the same, and each project includes at least one label, and each label corresponds to a set weight value. The scoring method can be expressed as:<I,T,Score,Weight> . Wherein, I indicates the project; T indicates the label of the project; Score indicates the score corresponding to the label; Weight indicates the set weight value corresponding to the label; then the score of any label (project) is: f(T) = min(Score×Weight,Max Score). Wherein, Max Score represents the maximum score that the label can give. If the project includes multiple labels, the final score is f(T1)+f(T2); finally, the scores of all projects are accumulated to obtain the confidence value of the corresponding serialized data. That is, first determine the score and set weight of each content in the detection strategy corresponding to the data format. Then, based on the score and set weight of each content, determine the score of each content. Then, accumulate the scores of each content to obtain the confidence value of the serialized data. Wherein, the confidence value indicates the probability that the serialized data includes a deserialization attack. Finally, the confidence value is compared with the alarm value. When the confidence value is greater than the alarm value, it can be determined that there is a deserialization attack in the serialized data. Wherein, the alarm value can be set according to the usage scenario of the serialized data.
[0100] The first item of the detection strategy for serialized data in native byte stream format: the number of serialized objects contained in the parsed data. Since there is no deserialization attack, the number of serialized objects in normal serialized data is small, usually only one. Therefore, two labels can be set for the first item, namely: the number of serialized objects is 1; the number of serialized objects exceeds 1. For the first type of label, the score can be set to 1 or 0, and the weight value can be set to 2; for the second type of label, the score is the number of specific serialized objects minus 1, and the weight value is set to 0.5. It should be noted that the number of serialized objects is obtained by traversing all classes in the parsing results, and in order to prevent a single feature score from being too high, resulting in a high final score, so that a comprehensive and comprehensive judgment on deserialization attacks cannot be made through the final score, the maximum score for the first item is set to 4. For example, if the number of serialized objects included in the parsing result of the serialized data is determined to be 4, the score of this item is: 1×2+3×0.5=3.5.
[0101] Similarly, for the second item of the native byte stream format serialized data detection strategy: the number of serialized arrays contained in the parsed data; since there is no deserialization attack, the number of serialized arrays in normal serialized data is small, usually only one. Therefore, two tags can also be set, namely: the number of serialized arrays is 1; the number of serialized arrays exceeds 1. The corresponding scoring method is the same as the scoring method of the first item above, and will not be repeated here.
[0102] For the third item of the native byte stream format serialized data detection project: the number of class names in the first blacklist. You can set the label to "classes in the first blacklist", and the score corresponding to this label is the number of classes in the serialized blacklist, and the weight value is set to 1.5. It should be noted that the feature strength of this detection content is higher than the first and second items, so the maximum score can be set to 10.
[0103] For the fourth item of the detection strategy for serialized data in native byte stream format: when the nesting depth of the referenced object exceeds the set depth, the nesting depth of the referenced object; because there is a "DOS (Denial Of Service) deserialization attack" that consumes CPU, which is characterized by inserting normal data in a deep nested manner, the label can be set to "whether the nesting depth of the referenced object exceeds the set depth". The set depth can be set to 5, then if the nesting depth of the referenced object does not exceed the set depth, the score of this item is 0. If the nesting depth of the referenced object exceeds the set depth, the corresponding score of the label is determined as follows: the nesting depth minus 5, and the corresponding set weight value is 0; similarly, to avoid unreasonable influence of a single item on serialized data, the maximum score of this item can be set to 2.5.
[0104] For the fifth item of the native byte stream format serialized data detection project: whether there is a parsing anomaly caused by a protocol format error; it is necessary to determine whether the parsing error is caused by a protocol format difference (non-standard data or incompatibility caused by protocol upgrade). It can be determined whether the serialized object is parsed. If not, it is determined that the parsing error is not caused by a protocol format difference, then the score of this project is 0, and the corresponding serialized data can be determined to be free of the threat of deserialization attack. If so, it is scored, the corresponding score of this label is 1, and the weight value is set to -2. The reason for setting the weight value to a negative number in this project is that when the serialized data is deserialized, even if it includes a deserialization attack, the deserialization attack is less harmful due to the parsing anomaly.
[0105] After scoring the detection items of the above native byte stream format serialized data respectively, the scores can be accumulated to obtain a total score, which can be used as the confidence value of the Java native byte stream format serialized data. And the alarm value can be set to 2.
[0106] The first item of the Json format serialized data detection strategy: the number of field values of the specified field that conform to the naming characteristics of the class in Java. In the embodiment of the present application, the specified field is set to @type, so the number of field values of the @type field included in the corresponding parsed data that conform to the naming characteristics of the class in Java can be determined, and the number is used as the project score value and multiplied by the corresponding set weight value to obtain the corresponding score.
[0107] For the second item of the Json format serialized data detection strategy: the class name detected in the first item of the detection content is the number of class names (or package names) defined in the second blacklist; this number is used as the project score value and multiplied by the corresponding set weight value to obtain the corresponding score. Furthermore, the first and second item scores can be added together to obtain the total score of the Json format serialized data.
[0108] For XML format serialized data, the score of the corresponding serialized data can also be obtained by multiplying the detection items with the corresponding set weight values. Specifically. For the XML Encoder format, the first item in the detection strategy can be: the number of nodes whose field value of the class field in the Object node is the class name. And the second item: the number of nodes whose field value of the method field in the Void node is the field value of the method field in the third blacklist; that is, whether the field value of the method field in the Void node is the field value of the method field in the third blacklist. Determine the number of Object nodes that meet the first requirement and the number of Void nodes that meet the second requirement as the score values of the corresponding items, and set the corresponding weights to 0.5 respectively. Similarly, the maximum value is set for the score of each detection item. For the two detection contents in the XML Encoder format, the scores can be set to no more than 2. The score values of each content in the detection strategy are accumulated to obtain the total score of the serialized data in the XML Encoder format, which is the corresponding confidence value.
[0109] Similarly, for the two detection contents in X Stream, the number of features can be set as the score, and the corresponding weight number can be set to 1. The maximum score of each item does not exceed 2. The score value of each content in the detection strategy is accumulated to obtain the total score of the serialized data in XStream format, which is the corresponding confidence value.
[0110] It is worth noting that the confidence value interval corresponding to all the above-mentioned serialized data formats must be within the set interval, which can be [0,10]. That is, when the total score of the project scores under each format of serialized data exceeds 10, the corresponding confidence value is 10. Since the serialized data corresponding to the implementation of the deserialization attack includes at least one deserialization class after parsing, the corresponding score is greater than 2. Therefore, the setting of the alarm value can be appropriately adjusted according to the usage scenario of the sequence or the deserialization scenario.
[0111] The above method determines the corresponding detection strategy for parsed data of different data formats; that is, according to the data format of serialized data, the detection strategy of deserialization attack is refined, so that the detection of deserialization attack is more targeted, thereby improving the accuracy of detecting deserialization attack.
[0112] Based on the above steps 101 to 103, the following is a complete description of the detection of whether a serialized data contains a deserialization attack. Please refer to Figure 2 .
[0113] First, data pre-identification can be performed, that is, the format of serialized data can be determined through the data header. After the data format is determined, the corresponding parsing method can be used to parse it to obtain parsed data. If the parsing is unsuccessful, it is determined that the serialized data does not contain a deserialization attack, and the data can be released for subsequent processing. In particular, for serialized data in native byte stream format, if the result data of the parsing error includes an object, it cannot be directly determined that it does not contain a deserialization attack, and subsequent detection is still required. Further, for the successfully parsed parsed data, the corresponding detection strategy is used for detection and scoring; and the scoring result is compared with the current alarm value. If the scoring result is higher than the alarm value, it can be determined that there is a deserialization attack in the serialized data, and the data is blocked. If the scoring result is not higher than the alarm value, it can be determined that there is no deserialization attack in the serialized data, and the data is released. According to the above method, the detection of whether any serialized data contains a deserialization attack can be completed. The technical solution provided in the embodiments of the present application can be used by security protection devices such as WAF to analyze serialized data using a Java deserialization protection device after receiving a request sent by a user.
[0114] Through the above operations, it is possible to determine whether any serialized data contains a deserialization attack; and the method of flexibly adjusting the alarm value according to the usage scenario to detect the deserialization attack can further improve the accuracy of the deserialization attack detection.
[0115] Based on the same inventive concept, a deserialization attack detection device is provided in an embodiment of the present application. Figure 1 The detection method of the deserialization attack shown in the figure corresponds to the specific implementation method of the device. The specific implementation method of the device can refer to the description of the aforementioned method embodiment part, and the repeated parts will not be repeated. Figure 3 , the device comprises:
[0116] Determining unit 301: used to determine the data format of serialized data.
[0117] The data format includes one of the following formats: native byte stream, object notation Json format, and extensible markup language XML format.
[0118] Specifically, the data header of the serialized data is identified. If the data header includes "aced0005", the format of the serialized data is a native byte stream; if the data header starts with "{" or "[", the format of the serialized data is a Json format; if the data header starts with "<", the format of the serialized data is an XML format.
[0119] Parsing unit 302: used for parsing the serialized data based on the data format to obtain parsed data corresponding to the data format.
[0120] The parsed data includes a class, and the class indicates a strategy for creating a Java entity.
[0121] When the data format is a native byte stream format, the parsed data includes an array and an object; wherein the array is a collection of fields of the same type, the object indicates a Java entity, and the field includes a field name and a field value;
[0122] When the data format is in Json format, the parsed data includes a specified field, and the specified field and the field value of the specified field form a key-value pair;
[0123] When the data format is XML format, determine whether the serialized data is in XML Encoder format; if so, the parsed data includes Object nodes and Void nodes, and the Object node includes a class field, and the Void node includes a method field; if not, the parsed data is in X Stream format, and the parsed data includes a class node or a class field; wherein the node is a start identifier of the serialized data in XML format.
[0124] Detection unit 303: used to determine a detection strategy for the serialized data based on the data format, and use the detection strategy to perform deserialization attack detection on the class in the parsed data to determine whether a deserialization attack exists in the serialized data.
[0125] Specifically used when the data format is a native byte stream, the detection strategy is to detect the number of serialized objects contained in the parsed data; and / or the number of serialized arrays contained; and / or the number of class names contained in the first blacklist; and / or when the nesting depth of the referenced object exceeds the set depth, the nesting depth of the referenced object; and / or whether there is a parsing exception caused by a protocol format error; wherein the first blacklist indicates that the serialized data in the native byte stream format includes records of deserialization attacks, the records include classes that carry deserialization attacks, and the nesting depth of the referenced object indicates the number of times the object is referenced.
[0126] The detection unit 303 can also be used for, when the data format is Json format, the detection strategy is to detect the number of field values of the specified field in the key-value pair that conform to the Java naming characteristics; and / or the number of class names in the second blacklist whose Java class names are; wherein the second blacklist is Json format serialized data including records of deserialization attacks, and the records include classes that carry deserialization attacks.
[0127] The detection unit 303 may also be used for, when the data format is the XML Encoder format, the detection strategy is to detect the number of nodes whose field value of the class field in the Object node is the class name; and / or the number of nodes whose field value of the method field in the Void node is the field value of the method field in the third blacklist; wherein the third blacklist indicates that the serialized data in the XML Encoder format includes records during deserialization attacks; when the data format is the X Stream format, the detection strategy is to detect that the parsed data includes the number of nodes in the fourth blacklist or the number of nodes with the same class name; and / or the field value of the class node is the number of class names in the fourth blacklist; wherein the fourth blacklist indicates that the serialized data in the X Stream format includes records during deserialization attacks, and the records include classes carrying deserialization attacks.
[0128] The detection unit 303 can also be used to determine the score and set weight of each content in the detection strategy corresponding to the data format; determine the score of each content based on the score and set weight of each content; add up the scores of each content to obtain the confidence value of the serialized data; wherein the confidence value indicates the probability that the serialized data includes a deserialization attack; compare the confidence value with the alarm value, and when the confidence value is greater than the alarm value, determine that a deserialization attack exists in the serialized data; wherein the alarm value is set according to the usage scenario of the serialized data.
[0129] Based on the same inventive concept, the embodiment of the present application further provides a readable storage medium, including:
[0130] Memory,
[0131] The memory is used to store instructions. When the instructions are executed by the processor, the device including the readable storage medium completes the above-mentioned deserialization attack detection method.
[0132] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and unit described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0133] In the several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0134] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0135] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0136] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (processor) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: a universal serial bus flash disk (Universal Serial Bus flash disk), a mobile hard disk, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a disk or an optical disk, and other media that can store program codes.
[0137] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A method for detecting a deserialization attack, characterized in that: The method comprises: Determine the data format of the serialized data; wherein the data format includes one of the following formats: native byte stream, object notation Json format, and extensible markup language XML format; Based on the data format, parsing the serialized data to obtain parsed data corresponding to the data format; wherein the parsed data includes a class, and the class indicates a strategy for creating a Java entity; Based on the data format, determining a detection strategy for the serialized data, and using the detection strategy to perform deserialization attack detection on the class in the parsed data to determine whether a deserialization attack exists in the serialized data; Wherein, determining the detection strategy of the serialized data based on the data format includes: When the data format is a native byte stream, the detection strategy is to detect the number of serialized objects contained in the parsed data; and / or the number of serialized arrays contained in the parsed data; and / or the number of class names contained in the first blacklist; and / or the nesting depth of the referenced object when the nesting depth of the referenced object exceeds the set depth; and / or whether there is a parsing exception caused by a protocol format error; When the data format is Json format, the parsed data includes a specified field, and the specified field and the field value of the specified field form a key-value pair, and the detection strategy is to detect the number of field values of the specified field in the key-value pair that conform to the naming characteristics of the Java class; and / or the number of class names whose Java class names are in the second blacklist; When the data format is the XML Encoder format, the detection strategy is to detect the number of nodes whose field value of the class field in the Object node is the class name; and / or the number of nodes whose field value of the method field in the Void node is the field value of the method field in the third blacklist; When the data format is X Stream format, the detection strategy is to detect that the parsed data includes the number of nodes in the fourth blacklist or the number of nodes with the same class name; and / or the field value of the class node is the number of class names in the fourth blacklist.
2. The method according to claim 1, characterized in that The step of parsing the serialized data based on the data format to obtain parsed data corresponding to the data format includes: When the data format is a native byte stream format, the parsed data includes an array and an object; wherein the array is a collection of fields of the same type, the object indicates a Java entity, and the field includes a field name and a field value; When the data format is XML format, determine whether the serialized data is in XML Encoder format; if so, the parsed data includes the Object node and the Void node, and the Object node includes the class field, and the Void node includes the method field; if not, the parsed data is in X Stream format, and the parsed data includes the class node or the class field; wherein the node is the start identifier of the serialized data in XML format.
3. The method according to claim 1, characterized in that The first blacklist indicates that the serialized data in the native byte stream format includes records of deserialization attacks, the records include classes that carry deserialization attacks, and the nesting depth of the referenced object indicates the number of times the object is referenced.
4. The method according to claim 1, characterized in that The second blacklist is Json format serialized data including records of deserialization attacks, and the records include classes that carry deserialization attacks.
5. The method according to claim 1, characterized in that The third blacklist indicates that the serialized data in XML Encoder format includes records of deserialization attacks; The fourth blacklist indicates that the serialized data in the X Stream format includes a record of a deserialization attack, and the record includes a class that carries the deserialization attack.
6. The method according to any one of claims 1 to 5, characterized in that The using the detection strategy to perform deserialization attack detection on the parsed data to determine whether there is a deserialization attack in the serialized data includes: Determine the score and set the weight of each item in the detection strategy corresponding to the data format; Determine the score of each item of content based on the score of each item of content and the set weight; Accumulating the scores of each of the contents to obtain a confidence value of the serialized data; wherein the confidence value indicates the probability that the serialized data includes a deserialization attack; The confidence value is compared with an alarm value, and when the confidence value is greater than the alarm value, it is determined that a deserialization attack exists in the serialized data; wherein the alarm value is set according to a usage scenario of the serialized data.
7. A deserialization attack detection device, characterized in that: The device comprises: Determining unit: used to determine the data format of serialized data; wherein the data format includes one of native byte stream, object notation Json format, and extensible markup language XML format; A parsing unit: used for parsing the serialized data based on the data format to obtain parsed data corresponding to the data format; wherein the parsed data includes a class, and the class indicates a strategy for creating a Java entity; A detection unit: used to determine a detection strategy for the serialized data based on the data format, and use the detection strategy to perform deserialization attack detection on the class in the parsed data to determine whether there is a deserialization attack in the serialized data; When the data format is a native byte stream, the detection strategy is to detect the number of serialized objects contained in the parsed data; and / or the number of serialized arrays contained in the parsed data; and / or the number of class names contained in the first blacklist; and / or the nesting depth of the referenced object when the nesting depth of the referenced object exceeds the set depth; and / or whether there is a parsing exception caused by a protocol format error; When the data format is Json format, the parsed data includes a specified field, and the specified field and the field value of the specified field form a key-value pair, and the detection strategy is to detect the number of field values of the specified field in the key-value pair that conform to the naming characteristics of the Java class; and / or the number of class names whose Java class names are in the second blacklist; When the data format is the XML Encoder format, the detection strategy is to detect the number of nodes whose field value of the class field in the Object node is the class name; and / or the number of nodes whose field value of the method field in the Void node is the field value of the method field in the third blacklist; When the data format is X Stream format, the detection strategy is to detect that the parsed data includes the number of nodes in the fourth blacklist or the number of nodes with the same class name; and / or the field value of the class node is the number of class names in the fourth blacklist.
8. The device according to claim 7, characterized in that The parsing unit is specifically used for, when the data format is a native byte stream format, the parsed data includes an array and an object; wherein the array is a collection of fields of the same type, the object indicates a Java entity, and the field includes a field name and a field value; when the data format is an XML format, determining whether the serialized data is in an XML Encoder format; if so, the parsed data includes the Object node and the Void node, and the Object node includes the class field, and the Void node includes the method field; if not, the parsed data is in an X Stream format, and the parsed data includes the class node or the class field; wherein the node is a start identifier of the serialized data in the XML format.
9. The device according to claim 7 or 8, characterized in that The detection unit is specifically used to determine the score and set weight of each content in the detection strategy corresponding to the data format; determine the score of each content based on the score and set weight of each content; accumulate the scores of each content to obtain the confidence value of the serialized data; wherein the confidence value indicates the probability that the serialized data includes a deserialization attack; compare the confidence value with the alarm value, and when the confidence value is greater than the alarm value, determine that a deserialization attack exists in the serialized data; wherein the alarm value is set according to the usage scenario of the serialized data.
10. A readable storage medium, characterized in that: include, Memory, The memory is used to store instructions. When the instructions are executed by the processor, the device including the readable storage medium performs the method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Network attack detection method and device, terminal equipment, and computer storage medium
CN107395599A
Serialization method and device, deserialization method and device and electronic equipment
CN113905093A