A data processing method and a storage medium
By obtaining and normalizing the traffic sequence in the target link, analyzing user behavior characteristics, and determining the enumeration vulnerability status, the problem of small enumeration detection coverage in the prior art is solved, and higher data security and full coverage are achieved.
Patent Information
- Application Number
- CN202011406579.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-04
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2040-12-04
AI Technical Summary
The existing technology has a small coverage in enumeration detection and cannot cover all amounts, resulting in greater safety risks.
By obtaining the traffic sequence in the target link, normalizing the target traffic, analyzing user behavior characteristics, and determining the enumeration vulnerability status, thereby improving the coverage of enumeration detection.
Full coverage of enumeration detection is achieved, data security is improved, and sensitive information is prevented from batch leakage.
Smart Images

Figure CN114611108B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet technologies, and in particular, to a data processing method and a storage medium. Background Art
[0002] Enumeration is widely used in penetration testing and APT attacks. Currently, enumeration detection is basically based on a risk control system and relies on the business itself to perform interface detection. However, for enumeration, it mainly focuses on short-term abnormal access to some interfaces, and does not cover high-threat scenarios such as massive leakage of sensitive information caused by common interface enumeration. Therefore, currently, enumeration detection can only target some interfaces or specific types of enumeration detection, with a relatively small coverage area and unable to fully cover all, thus causing huge security risks. Summary of the Invention
[0003] Embodiments of this application provide a data processing method and a storage medium, which can increase the coverage of enumeration detection and improve the security of data.
[0004] On the one hand, an embodiment of this application provides a data processing method, which may include:
[0005] Obtain a traffic sequence in a target link, and obtain target traffic for a target user according to the traffic sequence. The traffic sequence includes at least two traffics, the target traffic belongs to the traffic sequence, and the target traffic includes at least two traffics;
[0006] Perform normalization processing on each traffic in the target traffic to generate normalized target traffic;
[0007] Analyze the behavior characteristics of the target user according to the normalized target traffic, and determine the enumeration vulnerability status of the target user according to the behavior characteristics.
[0008] Wherein, the data processing method further includes:
[0009] Extract the response information of each traffic in the traffic sequence of the target link, and determine the information type of the response information;
[0010] Determine the sensitivity degree of the traffic corresponding to each user among one user or at least two users according to the information type and the number of traffics of the response information, and determine the target user from one user or at least two users according to the priority of the sensitivity degree.
[0011] Wherein, the obtaining the traffic sequence in the target link and obtaining the target traffic for the target user according to the traffic sequence includes:
[0012] Determine the time threshold corresponding to the traffic sequence, determine the target time period according to the time threshold and the current time, and obtain the traffic sequence within the target time period from the target link;
[0013] Obtain the user identifier of each traffic in the traffic sequence, and divide the traffic with the same user identifier into the traffic set corresponding to the user identifier;
[0014] Obtain the target user identifier corresponding to the target user, obtain the target traffic set corresponding to the target user identifier, and determine the traffic in the target traffic set as the target traffic of the target user.
[0015] Among them, the normalization processing of each traffic in the target traffic to generate the normalized target traffic includes:
[0016] Obtain the traffic to be processed in the target traffic, and the traffic to be processed is any traffic in the target traffic; each traffic includes cookie information and a uniform resource locator;
[0017] Obtain the cookie information in the traffic to be processed, and perform normalization processing on the cookie information to generate normalized cookie information;
[0018] Obtain the uniform resource locator in the traffic to be processed, and perform normalization processing on the uniform resource locator to generate a normalized uniform resource locator;
[0019] Determine the normalized cookie information and the normalized uniform resource locator as the normalized traffic to be processed;
[0020] When all the traffic in the target traffic is determined to be the traffic to be processed, determine all the normalized traffic to be processed as the normalized target traffic.
[0021] Among them, the obtaining of the cookie information in the traffic to be processed and the normalization processing of the cookie information to generate the normalized cookie information includes:
[0022] Determine the first parameter in the cookie of the traffic to be processed, extract the first parameter value corresponding to the first parameter, and store the first parameter and the first parameter value in the parameter list; the first parameter is used to identify the personal identity information of the target user;
[0023] Set the first parameter value in the cookie information to zero to generate normalized cookie information.
[0024] Among them, obtaining the uniform resource locator in the traffic to be processed and performing normalization processing on the uniform resource locator to generate a normalized uniform resource locator includes:
[0025] If the access method of the traffic to be processed is the GET method, determine the second parameter in the uniform resource locator of the traffic to be processed, extract the second parameter value corresponding to the second parameter, and store the second parameter and the second parameter value in the parameter list;
[0026] Set the second parameter value in the uniform resource locator to zero to generate a normalized uniform resource locator;
[0027] If the access method of the traffic to be processed is the POST method, determine the third parameter in the uniform resource locator of the traffic to be processed and the POST parameter in the traffic to be processed, extract the third parameter value corresponding to the third parameter and the POST parameter value corresponding to the POST parameter, and store the third parameter and the third parameter value, as well as the POST parameter and the POST parameter value in the parameter list;
[0028] Set the third parameter value and the POST parameter value in the uniform resource locator to zero to generate a normalized uniform resource locator and a normalized POST parameter.
[0029] Among them, analyzing the behavior characteristics of the target user according to the normalized target traffic and determining the enumerated vulnerability status of the target user according to the behavior characteristics includes:
[0030] Divide the normalized target traffic into one or at least two sets to be detected; the normalized target traffic in each set to be detected is the same;
[0031] Obtain the parameter list corresponding to the normalized target traffic in each set to be detected; the parameter list is used to store the parameters in the target traffic and the parameter values corresponding to the parameters;
[0032] Detect the number of non-repeated changes of the parameter value of each parameter in the parameter list, and use the maximum number of changes of the parameter value in the detection list as the number of changes of the set to be detected;
[0033] When the number of changes of any set to be detected is less than the number threshold, the target user does not have an enumerated vulnerability. When the number of changes of any set to be detected is greater than or equal to the number threshold, the target user has an enumerated vulnerability.
[0034] Among them, the data processing method further includes:
[0035] The enumerated vulnerability status includes having an enumerated vulnerability and not having an enumerated vulnerability;
[0036] When there is an enumeration vulnerability for the target user, an alarm message is sent to the target user to prompt the target user to intercept the enumeration vulnerability.
[0037] One aspect of the embodiments of the present application provides a data processing device, which may include:
[0038] A traffic acquisition unit, configured to acquire a traffic sequence in a target link, and acquire target traffic for a target user according to the traffic sequence. The traffic sequence includes at least two traffic flows, the target traffic belongs to the traffic sequence, and the target traffic includes at least two traffic flows;
[0039] A traffic processing unit, configured to perform normalization processing on each traffic flow in the target traffic to generate a normalized target traffic;
[0040] A behavior analysis unit, configured to analyze the behavior characteristics of the target user according to the normalized target traffic, and determine the enumeration vulnerability status of the target user according to the behavior characteristics.
[0041] Wherein, the data processing device further includes:
[0042] A priority determination unit, configured to extract response information of each traffic flow in the traffic sequence of the target link, and determine the information type of the response information;
[0043] According to the information type of the response information and the number of traffic flows, determine the sensitivity degree of the traffic corresponding to each user among one user or at least two users, and determine the target user from one user or at least two users according to the priority of the sensitivity degree.
[0044] Wherein, the traffic acquisition unit is specifically configured to:
[0045] Determine a time threshold corresponding to the traffic sequence, determine a target time period according to the time threshold and the current time, and acquire the traffic sequence within the target time period from the target link;
[0046] Acquire the user identifier of each traffic flow in the traffic sequence, and divide the traffic flows with the same user identifier into a traffic flow set corresponding to the user identifier;
[0047] Acquire a target user identifier corresponding to the target user, acquire a target traffic flow set corresponding to the target user identifier, and determine the traffic flows in the target traffic flow set as the target traffic of the target user.
[0048] Wherein, the traffic processing unit includes:
[0049] A to-be-processed traffic acquisition subunit, configured to acquire to-be-processed traffic in the target traffic, where the to-be-processed traffic is any one traffic in the target traffic; each traffic includes cookie information and a uniform resource locator;
[0050] A first normalization processing subunit, configured to acquire the cookie information in the to-be-processed traffic, and perform normalization processing on the cookie information to generate normalized cookie information;
[0051] A second normalization processing subunit, configured to acquire the uniform resource locator in the to-be-processed traffic, and perform normalization processing on the uniform resource locator to generate a normalized uniform resource locator;
[0052] Determine the normalized cookie information and the normalized uniform resource locator as the normalized to-be-processed traffic;
[0053] When all traffic in the target traffic is determined as to-be-processed traffic, determine all the normalized to-be-processed traffic as the normalized target traffic.
[0054] Wherein, the first normalization processing subunit is specifically configured to:
[0055] Determine a first parameter in the cookie of the to-be-processed traffic, extract a first parameter value corresponding to the first parameter, and store the first parameter and the first parameter value into a parameter list; the first parameter is used to identify personal identity information of the target user;
[0056] Set the first parameter value in the cookie information to zero to generate normalized cookie information.
[0057] Wherein, the second normalization processing subunit is specifically configured to:
[0058] If the access method of the to-be-processed traffic is the GET method, determine a second parameter in the uniform resource locator of the to-be-processed traffic, extract a second parameter value corresponding to the second parameter, and store the second parameter and the second parameter value into a parameter list;
[0059] Set the second parameter value in the uniform resource locator to zero to generate a normalized uniform resource locator;
[0060] If the access method of the to-be-processed traffic is the POST method, determine a third parameter in the uniform resource locator of the to-be-processed traffic, and POST parameters in the to-be-processed traffic, extract a third parameter value corresponding to the third parameter and a POST parameter value corresponding to the POST parameter, and store the third parameter and the third parameter value, and the POST parameter and the POST parameter value into a parameter list;
[0061] Set the third parameter value and the POST parameter value in the unified resource locator to zero to generate a normalized unified resource locator and a normalized POST parameter.
[0062] Wherein, the behavior analysis unit is specifically configured to:
[0063] Divide the normalized target traffic into one or at least two sets to be detected; the normalized target traffic in each set to be detected is the same;
[0064] Obtain a parameter list corresponding to the normalized target traffic in each set to be detected; the parameter list is used to store the parameters in the target traffic and the parameter values corresponding to the parameters;
[0065] Detect the number of non-repeating changes in the parameter values of each parameter in the parameter list, and use the maximum number of changes in the parameter values in the detection list as the number of changes in the set to be detected;
[0066] When the number of changes in any set to be detected is less than the number threshold, it means that the target user does not have an enumeration vulnerability. When the number of changes in any set to be detected is greater than or equal to the number threshold, it means that the target user has an enumeration vulnerability.
[0067] Wherein, the data processing device further includes:
[0068] The enumeration vulnerability status includes having an enumeration vulnerability and not having an enumeration vulnerability;
[0069] An alarm unit, configured to send an alarm message to the target user when the target user has an enumeration vulnerability, so as to prompt the target user to intercept the enumeration vulnerability.
[0070] One aspect of the embodiments of the present application provides a computer-readable storage medium, which stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the above method steps.
[0071] One aspect of the embodiments of the present application provides a computer device, including a processor and a memory; wherein, the memory stores a computer program, and the computer program is suitable for being loaded and executed by the processor to perform the above method steps.
[0072] One aspect of the embodiments of the present application provides a computer program product or a computer program, which includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device performs the above method steps.
[0073] In the embodiments of the present application, by obtaining the traffic sequence in the target link, obtaining the target traffic for the target user according to the traffic sequence, normalizing each traffic in the target traffic to generate the normalized target traffic, further analyzing the behavior characteristics of the target user according to the normalized target traffic, and finally determining the enumerated vulnerability status of the target user according to the behavior characteristics. By analyzing the traffic in the target link, it is possible to determine whether the target user has an enumerated vulnerability, prevent the batch leakage of sensitive information, and at the same time, the enumerated vulnerability detection does not target a specific enumerated type, improving the coverage rate of the enumerated vulnerability detection and enhancing the security of the data. BRIEF DESCRIPTION OF THE DRAWINGS
[0074] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0075] Figure 1 is a system architecture diagram of a data processing provided by an embodiment of the present application;
[0076] Figure 2 is a schematic flowchart of a data processing method provided by an embodiment of the present application;
[0077] Figure 3 is an example schematic diagram of a data processing method provided by an embodiment of the present application;
[0078] Figure 4 is a schematic flowchart of a data processing method provided by an embodiment of the present application;
[0079] Figure 5 is a schematic structural diagram of a data processing device provided by an embodiment of the present application;
[0080] Figure 6 is a schematic structural diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0081] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0082] Please refer to Figure 1, which is a system architecture diagram for data processing provided by an embodiment of the present invention. Server 10f establishes a connection with the user terminal cluster through switch 10e and communication bus 10d. The user terminal cluster may include: user terminal 10a, user terminal 10b,..., user terminal 10c. Server 10f obtains the traffic sequence in the target link, and obtains the target traffic for the target user according to the traffic sequence. The traffic sequence includes at least two traffic flows. The target traffic belongs to the traffic sequence, and the target traffic includes at least two traffic flows. Server 10f performs normalization processing on each traffic flow in the target traffic to generate the normalized target traffic. Server 10f analyzes the behavior characteristics of the target user according to the normalized target traffic, and determines the enumerated vulnerability status of the target user according to the behavior characteristics. Database 10g is used to store the normalized target traffic and the parameters extracted from the target traffic during the normalization process. When it is detected that the target user has an enumerated vulnerability, server 10f sends an alarm message to the corresponding user terminal.
[0083] The user terminal involved in the embodiment of the present application includes: terminal devices such as tablet computers, smart phones, personal computers (PCs), laptop computers, and palmtop computers.
[0084] Please refer to Figure 2 , which is a schematic flowchart of a data processing method provided by an embodiment of the present application. As Figure 2 shown, the method of the embodiment of the present application may include the following steps S101-step S103.
[0085] S101, obtain the traffic sequence in the target link, and obtain the target traffic for the target user according to the traffic sequence;
[0086] Specifically, the data processing device obtains the traffic sequence in the target link and obtains the target traffic for the target user according to the traffic sequence. It can be understood that the data processing device may be Figure 1In server 10f, the traffic sequence can be completed by a traffic collection component. The traffic collection component can be deployed on multiple core links. By means of optical splitting, the complete traffic flowing through the link is collected. The traffic sequence is collected by optical splitting without affecting the normal services of users. For example, the traffic collection component can be deployed on the core links of WeChat or QQ to collect the login requests of users. At the same time, the traffic collection component can periodically collect the traffic in the target link. For example, it can collect the traffic of the previous minute every minute, and the collection frequency can be preset in advance. The traffic sequence can include at least two traffic flows of one or at least two users. The traffic sequence is a series of access requests of users over time. There can be access requests of multiple users in the traffic sequence. According to the traffic sequence, the target traffic for the target user is obtained. Specifically, the traffic sequence can be classified according to the source IP address in the traffic to obtain the target traffic of the target user. The target traffic belongs to the traffic sequence, and the target traffic includes at least two traffic flows.
[0087] S102, perform normalization processing on each traffic flow in the target traffic to generate normalized target traffic;
[0088] Specifically, the data processing device performs normalization processing on each traffic flow in the target traffic to generate normalized target traffic. It can be understood that the normalization processing is to extract the parameters in the traffic and set the parameters to zero. Each traffic flow includes cookie information, a uniform resource locator (URL). If the access method in the traffic is the POST method, the traffic also includes parameter information corresponding to POSTBODY. The normalization processing of the traffic includes the normalization processing of the above cookie information, uniform resource locator, and parameter information in the POST method. Through the normalization processing, normalized target traffic is generated, and the parameter values corresponding to the parameters in the normalized target traffic are all 0.
[0089] S103, analyze the behavior characteristics of the target user according to the normalized target traffic, and determine the enumeration vulnerability status of the target user according to the behavior characteristics.
[0090] Specifically, the data processing device analyzes the behavior characteristics of the target user according to the normalized target traffic, and determines the enumeration vulnerability status of the target user according to the behavior characteristics. It can be understood that the enumeration vulnerability status includes the existence of an enumeration vulnerability and the non-existence of an enumeration vulnerability. By analyzing the normalized target traffic and the parameter values obtained from the target traffic, the behavior of the user is analyzed. Specifically, the enumeration vulnerability status of the target user can be determined by the change situation of the parameter values. Please refer to Figure 3 , which is an example schematic diagram of a data processing method provided by an embodiment of the present application. AsFigure 3 As shown, the domain name and parameters of the access request traffic of the target user are “*.qq.com / api?freeid=1&lan_ip=10.1.1.1”, that is, the parameters in the target traffic include “freeid” and “lan_ip”. Extract the parameters “freeid” and “lan_ip” from the target traffic, as well as the corresponding parameter values, normalize the target traffic to generate the normalized target traffic “*.qq.com / api?freeid=0&lan_ip=0”, obtain all the same normalized target traffic of the target user. From the extracted parameter values, it can be seen that there are 10 non-repeating values for the parameter value of “freeid”, and there is only 1 value for the parameter “lan_ip”. Finally, we can obtain that the change count of the parameter “freeid” is 10 times, and the change count of the parameter “lan_ip” is 1. If the change count of the parameter “freeid” is greater than the count threshold, it can be known that the target user has an external enumeration for the lan_ip field. When it is determined that the target user has an enumeration vulnerability, an alarm message can be sent to the target user to prompt the target user to intercept the enumeration vulnerability. The specific alarm prompt can be a voice prompt or a text pop-up prompt.
[0091] In the embodiment of the present application, by obtaining the traffic sequence in the target link, obtaining the target traffic for the target user according to the traffic sequence, normalizing each traffic in the target traffic to generate the normalized target traffic, further analyzing the behavior characteristics of the target user according to the normalized target traffic, and finally determining the enumeration vulnerability status of the target user according to the behavior characteristics. By analyzing the traffic in the target link, it can be determined whether the target user has an enumeration vulnerability, preventing the batch leakage of sensitive information. At the same time, the enumeration vulnerability detection does not target a specific enumeration type, improving the coverage rate of the enumeration vulnerability detection and improving the security of the data.
[0092] Please refer to Figure 4 , which is a schematic flowchart of a data processing method provided by the embodiment of the present application. As Figure 4 shown, the method of the embodiment of the present application may include the following steps S201-step S207.
[0093] S201, extract the response information of each traffic in the traffic sequence of the target link, and determine the information type of the response information; according to the information type of the response information and the traffic quantity, determine the sensitivity degree of the traffic corresponding to each user among one user or at least two users, and determine the target user from one user or at least two users according to the priority of the sensitivity degree.
[0094] Specifically, the data processing device extracts the response information of each traffic in the traffic sequence of the target link, determines the information type of the response information. The response information is the feedback information of the user for the request. The types of response information include username and password, personal identity data, financial data, etc. The username and password can be the password information of the account. The personal identity information can be the ID number, mobile phone number, etc. The financial data can be the bank card number. Further, according to the information type and traffic quantity of the response information, the sensitivity degree of the traffic corresponding to each user among one user or at least two users is determined. The sensitivity degree reflects the possibility of the existence of an enumeration vulnerability of the target user. The higher the sensitivity degree, the greater the possibility of the existence of an enumeration vulnerability, and the higher the priority of this user. The user with a higher priority can be preferentially detected for enumeration vulnerabilities. The traffic quantity is the quantity of the traffic belonging to the user in the traffic sequence. Specifically, the more the traffic quantity, the higher the sensitivity degree. The target user is determined from one user or at least two users according to the priority of the sensitivity degree. The specific target user can be the user with the highest sensitivity degree. It should be noted that other screening rules can also be adopted for the selection of the target user, such as in chronological order, or a specified user can be selected as the target user.
[0095] S202. Determine the time threshold corresponding to the traffic sequence. Determine the target time period according to the time threshold and the current time, and obtain the traffic sequence within the target time period from the target link; obtain the user identifier of each traffic in the traffic sequence, and divide the traffic with the same user identifier into the traffic set corresponding to the user identifier; obtain the target user identifier corresponding to the target user, obtain the target traffic set corresponding to the target user identifier, and determine the traffic in the target traffic set as the target traffic of the target user.
[0096] Specifically, the time threshold is the time length for the data processing device to collect traffic, and the target time period is the specific time period for collecting traffic. For example, the time threshold is one minute, and the target time period is the previous minute before the current time, that is, obtain the traffic sequence within the previous minute before the current time from the target link, obtain the user identifier of each traffic in the traffic sequence. The user identifier can specifically be the source IP address or the username. Different users have different user identifiers. Divide the traffic with the same user identifier into the traffic set corresponding to the user identifier, that is, each user identifier corresponds to a traffic set, and the traffic set stores one or at least two traffics of the user. Obtain the target user identifier corresponding to the target user, obtain the target traffic set corresponding to the target user identifier, and determine the traffic in the target traffic set as the target traffic of the target user.
[0097] S203. Obtain the traffic to be processed in the target traffic.
[0098] Specifically, the data processing device obtains the traffic to be processed in the target traffic. The traffic to be processed is any one of the target traffic, and each traffic includes cookie information and a uniform resource locator.
[0099] S204. Obtain the cookie information in the traffic to be processed, and perform normalization processing on the cookie information to generate normalized cookie information.
[0100] Specifically, the traffic includes cookie information and a uniform resource locator. The data processing device determines the first parameter in the cookie of the traffic to be processed, extracts the first parameter value corresponding to the first parameter, stores the first parameter and the first parameter value in a parameter list, sets the first parameter value in the cookie information to zero, and generates normalized cookie information.
[0101] The first parameter is used to identify the personal identity information of the target user. For example, the cookie information of a user logging in to a website using QQ contains a uin field, so the first parameter is "uin". If the value of the uin field is "uin = 3", then the parameter value "3" corresponding to the uin field is extracted, the first parameter and the first parameter value "uin = 3" are stored in the parameter list, and further the parameter value of the uin field in the cookie is set to zero, that is, "uin = 3" is normalized to "uin = 0". It should be noted that if the first parameter does not exist in the cookie information of the traffic to be processed, the traffic to be processed is emptied.
[0102] S205. Obtain the uniform resource locator in the traffic to be processed, and perform normalization processing on the uniform resource locator to generate a normalized uniform resource locator.
[0103] Specifically, the data processing device obtains the uniform resource locator in the traffic to be processed, and performs normalization processing on the uniform resource locator to generate a normalized uniform resource locator. It can be understood that the access methods in the traffic include the GET method and the POST method.
[0104] If the access method of the traffic to be processed is the GET method, determine the second parameter in the uniform resource locator in the traffic to be processed, extract the second parameter value corresponding to the second parameter, store the second parameter and the second parameter value in the parameter list, set the second parameter value in the uniform resource locator to zero, and generate a normalized uniform resource locator; specifically, the second parameter in the uniform resource locator can be extracted through a parameter assignment operator, and the parameter assignment operator can be an equal sign "=" or ":". When the access method of the traffic to be processed is the GET method, the parameter assignment operator is "=". For example, if the uniform resource locator in the traffic to be processed is "*.qq.com / api?freeid=1&lan_ip=10.1.1.1", the data processing device detects the "=" in the uniform resource locator. The left side of the "=" is the second parameter, and the right side of the "=" is the second parameter value corresponding to the second parameter. That is, the second parameters in the above traffic to be processed include "freeid" and "lan_ip", the parameter value of the second parameter "freeid" is 1, and the parameter value of the second parameter "lan_ip" is 10.1.1.1. Extract the second parameter value corresponding to the second parameter, store the second parameter and the second parameter value in the parameter list, and set the second parameter value in the uniform resource locator to zero, that is, keep the domain name and parameters unchanged and change all parameter values to 0. The normalized uniform resource locator is "*.qq.com / api?freeid=0&lan_ip=0".
[0105] If the access method of the traffic to be processed is the POST method, determine the third parameter in the uniform resource locator in the traffic to be processed and the POST parameter in the traffic to be processed, extract the third parameter value corresponding to the third parameter and the POST parameter value corresponding to the POST parameter, store the third parameter and the third parameter value, and the POST parameter and the POST parameter value in a parameter list, set the third parameter value and the POST parameter value in the uniform resource locator to zero, generate a normalized uniform resource locator and a normalized POST parameter. The extraction of the third parameter in the POST method is the same as the extraction of the second parameter in the GET method, both are extracted through the parameter assignment operator "=". The extraction of the POST parameter can be extracted through the parameter assignment operator ":". Specifically, when the access method of the traffic to be processed is the POST method, the parameter assignment operator is ":". For example, the specific content POSTBODY in the POST method in the traffic to be processed is {"a": 3}. The data processing device detects the ":" in POSTBODY. The left side of the ":" is the POST parameter, and the right side of the "=" is the POST parameter value corresponding to the POST parameter. That is, the POST parameter in the above traffic to be processed is "a", and the parameter value of the POST parameter "a" is 3. Set the POST parameter value to zero, that is, the normalized POSTBODY is {"a": 0}.
[0106] The data processing device traverses all the traffic in the target traffic, takes each traffic as the traffic to be processed, normalizes the cookie information and the uniform resource locator in the traffic to be processed, generates a normalized cookie information and a normalized uniform resource locator, determines the normalized cookie information and the normalized uniform resource locator corresponding to the traffic to be processed as the normalized traffic to be processed. When all the traffic in the target traffic is determined as the traffic to be processed, determine all the normalized traffic to be processed as the normalized target traffic.
[0107] S206, analyze the behavior characteristics of the target user according to the normalized target traffic, and determine the enumerated vulnerability status of the target user according to the behavior characteristics;
[0108] Specifically, the data processing device divides the normalized target traffic into one or at least two sets to be detected according to the normalized uniform resource locator, the normalized cookie, and the normalized POST parameter. Specifically, the normalized target traffic includes one or at least two normalized traffic flows. The traffic flows in the normalized target traffic with the same normalized COOKIE, the same normalized uniform resource locator, and the same normalized POST BODY are divided into the same set to be detected. The normalized uniform resource locator, the normalized cookie, and the normalized POST parameter in each set to be detected are the same. It should be noted that if the access method of the target traffic is the GET method, there is no POST parameter in the set to be detected.
[0109] Obtain the parameter list corresponding to the normalized target traffic in each set to be detected. The parameter list is used to store the parameters in the target traffic and the parameter values corresponding to the parameters. The parameters include the first parameter, the second parameter, the third parameter, and the POST parameter. Detect the number of non-repeated changes in the parameter values of each parameter in the parameter list, and take the maximum number of non-repeated changes in the parameter values in the detection list as the number of changes of the set to be detected. When the number of changes of any set to be detected is less than the number threshold, it means that the target user does not have an enumeration vulnerability. When the number of changes of any set to be detected is greater than or equal to the number threshold, it means that the target user has an enumeration vulnerability. The number threshold can be set in advance.
[0110] For example, the target traffic of the target user is “*.qq.com / api?freeid=1&lan_ip=10.1.1.1”. After normalization, the normalized target traffic is “*.qq.com / api?freeid=0&lan_ip=0”. Obtain the set to be detected corresponding to the above normalized target traffic. The set to be detected is one of the one or at least two sets to be detected. Obtain the parameters “freeid” and “lan_ip” and the corresponding parameter values from the parameter list corresponding to the target traffic, and detect the number of non-repeated changes in the parameter values of the parameters “freeid” and “lan_ip” in the parameter list. If it can be seen from the extracted parameter values that there are 10 non-repeated values for the parameter value of “freeid” and only 1 value for the parameter “lan_ip”, then the number of changes of the parameter “freeid” can be obtained as 10 times, and the number of changes of the parameter “lan_ip” is 1. If the number of changes of the parameter “freeid” is greater than the number threshold, it can be known that the target user has an external enumeration for the lan_ip field.
[0111] S207. When the target user has an enumeration vulnerability, send an alarm message to the target user to prompt the target user to intercept the enumeration vulnerability.
[0112] Specifically, the enumerated vulnerability status includes the existence of an enumerated vulnerability and the non - existence of an enumerated vulnerability. When it is detected that the target user has an enumerated vulnerability, the data processing device can send an alarm message to the target user to prompt the target user to intercept the enumerated vulnerability. The user can take measures such as blocking or access restriction. Specifically, the alarm prompt can be a voice prompt or a text pop - up prompt.
[0113] In the embodiment of the present application, by obtaining the traffic sequence in the target link, obtaining the target traffic for the target user according to the traffic sequence, normalizing each traffic in the target traffic to generate the normalized target traffic, further analyzing the behavior characteristics of the target user according to the normalized target traffic, and finally determining the enumerated vulnerability status of the target user according to the behavior characteristics. By analyzing the traffic in the target link, it can be determined whether the target user has an enumerated vulnerability, preventing the batch leakage of sensitive information. At the same time, the enumerated vulnerability detection does not target a specific enumerated type, improving the coverage rate of the enumerated vulnerability detection and the security of the data.
[0114] Please refer to Figure 5 , which provides a schematic structural diagram of a data processing device in the embodiment of the present application. The data processing device can be a computer program (including program code) running in a computer device. For example, the data processing device is an application software; this device can be used to execute the corresponding steps in the method provided in the embodiment of the present application. As Figure 5 shown, the data processing device 1 in the embodiment of the present application may include: a traffic acquisition unit 11, a traffic processing unit 12, and a behavior analysis unit 13.
[0115] The traffic acquisition unit 11 is used to obtain the traffic sequence in the target link, and obtain the target traffic for the target user according to the traffic sequence. The traffic sequence includes at least two traffics, the target traffic belongs to the traffic sequence, and the target traffic includes at least two traffics;
[0116] The traffic processing unit 12 is used to normalize each traffic in the target traffic to generate the normalized target traffic;
[0117] The behavior analysis unit 13 is used to analyze the behavior characteristics of the target user according to the normalized target traffic, and determine the enumerated vulnerability status of the target user according to the behavior characteristics.
[0118] Please refer to Figure 5 , the data processing device 1 in the embodiment of the present application may further include: a priority determination unit 14.
[0119] A priority determination unit 14, configured to extract response information of each traffic in the traffic sequence of the target link and determine the information type of the response information;
[0120] According to the information type of the response information and the number of traffic, determine the sensitivity of the traffic corresponding to each user among one user or at least two users, and determine the target user from one user or at least two users according to the priority of the sensitivity.
[0121] The traffic acquisition unit 11 is specifically configured to:
[0122] Determine a time threshold corresponding to the traffic sequence, determine a target time period according to the time threshold and the current time, and acquire the traffic sequence within the target time period from the target link;
[0123] Acquire the user identifier of each traffic in the traffic sequence, and divide the traffic with the same user identifier into the traffic set corresponding to the user identifier;
[0124] Acquire the target user identifier corresponding to the target user, acquire the target traffic set corresponding to the target user identifier, and determine the traffic in the target traffic set as the target traffic of the target user.
[0125] Please refer to Figure 5 , the traffic processing unit 12 in the embodiment of the present application may include: a traffic to be processed acquisition subunit 121, a first normalization processing subunit 122, and a second normalization processing subunit 123.
[0126] The traffic to be processed acquisition subunit 121 is configured to acquire the traffic to be processed in the target traffic, and the traffic to be processed is any one traffic in the target traffic; each traffic includes cookie information and a uniform resource locator;
[0127] The first normalization processing subunit 122 is configured to acquire the cookie information in the traffic to be processed and perform normalization processing on the cookie information to generate normalized cookie information;
[0128] The second normalization processing subunit 123 is configured to acquire the uniform resource locator in the traffic to be processed and perform normalization processing on the uniform resource locator to generate a normalized uniform resource locator;
[0129] Determine the normalized cookie information and the normalized uniform resource locator as the normalized traffic to be processed;
[0130] When all the traffic in the target traffic is determined to be the traffic to be processed, determine all the normalized traffic to be processed as the normalized target traffic.
[0131] The first normalization processing subunit 122 is specifically configured to:
[0132] Determine the first parameter in the cookie in the traffic to be processed, extract the first parameter value corresponding to the first parameter, and store the first parameter and the first parameter value in a parameter list; the first parameter is used to identify the personal identity information of the target user;
[0133] Set the first parameter value in the cookie information to zero to generate normalized cookie information.
[0134] The second normalization processing subunit 123 is specifically configured to:
[0135] If the access method of the traffic to be processed is the GET method, determine the second parameter in the uniform resource locator in the traffic to be processed, extract the second parameter value corresponding to the second parameter, and store the second parameter and the second parameter value in a parameter list;
[0136] Set the second parameter value in the uniform resource locator to zero to generate a normalized uniform resource locator;
[0137] If the access method of the traffic to be processed is the POST method, determine the third parameter in the uniform resource locator in the traffic to be processed, and the POST parameter in the traffic to be processed, extract the third parameter value corresponding to the third parameter and the POST parameter value corresponding to the POST parameter, and store the third parameter and the third parameter value, and the POST parameter and the POST parameter value in a parameter list;
[0138] Set the third parameter value and the POST parameter value in the uniform resource locator to zero to generate a normalized uniform resource locator and a normalized POST parameter.
[0139] The behavior analysis unit 13 is specifically configured to:
[0140] Divide the normalized target traffic into one or at least two sets to be detected; the normalized target traffic in each set to be detected is the same;
[0141] Obtain the parameter list corresponding to the normalized target traffic in each set to be detected; the parameter list is used to store the parameters in the target traffic and the parameter values corresponding to the parameters;
[0142] Detect the number of non-repeated changes of the parameter value of each parameter in the parameter list, and use the maximum number of changes of the parameter value in the detection list as the number of changes of the set to be detected;
[0143] When the change count of any set to be detected is less than the count threshold, there is no enumeration vulnerability for the target user. When the change count of any set to be detected is greater than or equal to the count threshold, the target user has an enumeration vulnerability.
[0144] Please refer to Figure 5 , the data processing device 1 in the embodiment of the present application may further include: an alarm unit 15.
[0145] The enumeration vulnerability status includes having an enumeration vulnerability and not having an enumeration vulnerability;
[0146] The alarm unit 15 is used to send an alarm message to the target user when the target user has an enumeration vulnerability, so as to prompt the target user to intercept the enumeration vulnerability.
[0147] In the embodiment of the present application, by obtaining the traffic sequence in the target link, obtaining the target traffic for the target user according to the traffic sequence, normalizing each traffic in the target traffic to generate the normalized target traffic, further analyzing the behavior characteristics of the target user according to the normalized target traffic, and finally determining the enumeration vulnerability status of the target user according to the behavior characteristics. By analyzing the traffic in the target link, it can be determined whether the target user has an enumeration vulnerability, preventing the batch leakage of sensitive information. At the same time, the enumeration vulnerability detection does not target a specific enumeration type, improving the coverage rate of the enumeration vulnerability detection and the security of the data.
[0148] Please refer to Figure 6 , which provides a schematic structural diagram of a computer device for the embodiment of the present application. As Figure 6 shown, the computer device 1000 may include: at least one processor 1001, such as a CPU, at least one network interface 1004, a user interface 1003, a memory 1005, and at least one communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. Among them, the user interface 1003 may include a display screen (Display), and optionally the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a random access memory (Random Access Memory, RAM), or a non-volatile memory (non-volatile memory, NVM), such as at least one disk memory. The memory 1005 may optionally be at least one storage device located far from the aforementioned processor 1001. As Figure 6As shown in the figure, the memory 1005, which is a computer storage medium, may include an operating system, a network communication module, a user interface module, and a data processing application program.
[0149] In Figure 6 the computer device 1000 shown in the figure, the network interface 1004 can provide network communication functions, and the user interface 1003 is mainly used to provide an interface for users to input; while the processor 1001 can be used to call the data processing application program stored in the memory 1005 to implement the above Figures 2 - 4 description of the data processing method in any of the corresponding embodiments, which will not be elaborated here.
[0150] It should be understood that the computer device 1000 described in the embodiments of the present application can execute the description of the data processing method in any of the previous Figures 2 - 4 corresponding embodiments, and can also execute the description of the data processing device in the previous Figure 5 corresponding embodiments, which will not be elaborated here. In addition, the description of the beneficial effects of using the same method will not be elaborated either.
[0151] In addition, it should be pointed out here that: the embodiments of the present application also provide a computer-readable storage medium, and the computer-readable storage medium stores a computer program executed by the aforementioned data processing device, and the computer program includes program instructions. When the processor executes the program instructions, it can execute the description of the data processing method in any of the previous Figures 2 - 4 corresponding embodiments, so it will not be elaborated here. In addition, the description of the beneficial effects of using the same method will not be elaborated either. For the technical details not disclosed in the embodiments of the computer-readable storage medium involved in the present application, please refer to the description of the method embodiments of the present application. As an example, the program instructions can be deployed to be executed on one computing device, or on multiple computing devices located at one location, or on multiple computing devices distributed at multiple locations and interconnected through a communication network. The multiple computing devices distributed at multiple locations and interconnected through a communication network can form a blockchain system.
[0152] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disc, an NVM, or a RAM, etc.
[0153] The above disclosure is only for the preferred embodiments of the present application. Of course, it cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.
Claims
1. A data processing method, characterized in that, Including: Obtain the traffic sequence in the target link, and obtain the target traffic for the target user according to the traffic sequence. The traffic sequence includes at least two traffic flows, the target traffic belongs to the traffic sequence, and the target traffic includes at least two traffic flows; Perform normalization processing on each traffic flow in the target traffic to generate normalized target traffic; Divide the normalized target traffic into one or at least two sets to be detected; The normalized target traffic in each set to be detected is the same; Obtain the parameter list corresponding to the normalized target traffic in each set to be detected; the parameter list is used to store the parameters in the target traffic and the parameter values corresponding to the parameters; Detect the number of non-repeated changes in the parameter values of each parameter in the parameter list, and use the largest number of changes in the parameter values in the detection list as the number of changes in the set to be detected; When the number of changes in any set to be detected is less than the number threshold, it means that the target user does not have an enumeration vulnerability. When the number of changes in any set to be detected is greater than or equal to the number threshold, it means that the target user has an enumeration vulnerability.
2. The method according to claim 1, wherein The data processing method further includes: Extract the response information of each traffic flow in the traffic sequence of the target link, and determine the information type of the response information; Determine the sensitivity of the traffic corresponding to each user among one user or at least two users according to the information type of the response information and the number of traffic flows, and determine the target user from one user or at least two users according to the priority of the sensitivity.
3. The method according to claim 1, characterized in that, The obtaining the traffic sequence in the target link and obtaining the target traffic for the target user according to the traffic sequence includes: Determine the time threshold corresponding to the traffic sequence, determine the target time period according to the time threshold and the current time, and obtain the traffic sequence within the target time period from the target link; Obtain the user identifier of each traffic flow in the traffic sequence, and divide the traffic flows with the same user identifier into the traffic flow set corresponding to the user identifier; Obtain the target user identifier corresponding to the target user, obtain the target traffic flow set corresponding to the target user identifier, and determine the traffic flows in the target traffic flow set as the target traffic of the target user.
4. The method according to claim 1, characterized in that, The performing normalization processing on each traffic flow in the target traffic to generate normalized target traffic includes: Obtain the traffic flow to be processed in the target traffic, and the traffic flow to be processed is any traffic flow in the target traffic; each traffic flow includes cookie information and a uniform resource locator; Obtain the cookie information in the traffic flow to be processed, and perform normalization processing on the cookie information to generate normalized cookie information; Obtain the uniform resource locator in the traffic flow to be processed, and perform normalization processing on the uniform resource locator to generate normalized uniform resource locator; Determine the normalized cookie information and the normalized uniform resource locator as the normalized traffic flow to be processed; When all the traffic flows in the target traffic are determined to be traffic flows to be processed, determine all the normalized traffic flows to be processed as the normalized target traffic.
5. The method according to claim 4, characterized in that, Obtaining cookie information in the traffic to be processed and performing normalization processing on the cookie information to generate normalized cookie information includes: Determining a first parameter in the cookie of the traffic to be processed, extracting a first parameter value corresponding to the first parameter, and storing the first parameter and the first parameter value in a parameter list; the first parameter is used to identify personal identity information of the target user; Setting the first parameter value in the cookie information to zero to generate normalized cookie information.
6. The method according to claim 4, wherein Obtaining a uniform resource locator in the traffic to be processed and performing normalization processing on the uniform resource locator to generate a normalized uniform resource locator includes: If the access method of the traffic to be processed is the GET method, determining a second parameter in the uniform resource locator of the traffic to be processed, extracting a second parameter value corresponding to the second parameter, and storing the second parameter and the second parameter value in a parameter list; Setting the second parameter value in the uniform resource locator to zero to generate a normalized uniform resource locator; If the access method of the traffic to be processed is the POST method, determining a third parameter in the uniform resource locator of the traffic to be processed and the POST parameter in the traffic to be processed, extracting a third parameter value corresponding to the third parameter and a POST parameter value corresponding to the POST parameter, and storing the third parameter and the third parameter value, and the POST parameter and the POST parameter value in a parameter list; Setting the third parameter value and the POST parameter value in the uniform resource locator to zero to generate a normalized uniform resource locator and normalized POST parameters.
7. The method according to claim 1, characterized in that The data processing method further includes: The enumerated vulnerability status includes the existence of an enumerated vulnerability and the non-existence of an enumerated vulnerability; When the target user has an enumerated vulnerability, sending an alarm message to the target user to prompt the target user to intercept the enumerated vulnerability.
8. A data processing device, characterized in that, Including: A traffic acquisition unit, configured to acquire a traffic sequence in a target link, and acquire target traffic for a target user according to the traffic sequence, the traffic sequence includes at least two traffics, the target traffic belongs to the traffic sequence, and the target traffic includes at least two traffics; A traffic processing unit, configured to perform normalization processing on each traffic in the target traffic to generate normalized target traffic; A behavior analysis unit, configured to divide the normalized target traffic into one or at least two sets to be detected; The normalized target traffic in each set to be detected is the same; The behavior analysis unit is further configured to obtain a parameter list corresponding to the normalized target traffic in each set to be detected; the parameter list is used to store parameters in the target traffic and parameter values corresponding to the parameters; The behavior analysis unit is further configured to detect the number of non-repeating changes in the parameter values of each parameter in the parameter list, and use the largest number of changes in the parameter values in the detection list as the number of changes in the set to be detected. When the number of changes in any set to be detected is less than the number threshold, it indicates that the target user does not have an enumeration vulnerability. When the number of changes in any set to be detected is greater than or equal to the number threshold, it indicates that the target user has an enumeration vulnerability.
9. A computer-readable storage medium, characterized in that, The computer storage medium stores a computer program, and the computer program includes program instructions. When the program instructions are executed by a processor, the method according to any one of claims 1-7 is executed.
Citation Information
Patent Citations
Method, Apparatus, and Device for Detecting E-Mail Attack
US20150033343A1