CSV file injection attack detection method and device, electronic device and storage medium
By reading and detecting data on CSV files, determining the location of attack data and sending alarm signals, the problem of lack of detection methods for CSV injection attacks in the prior art is solved, and effective detection and early warning of CSV injection attacks is achieved.
Patent Information
- Application Number
- CN202210411365.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-19
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2042-04-19
AI Technical Summary
The existing technology lacks effective detection methods for CSV injection attacks, which leads to this attack being ignored and poses a security threat to end users.
By obtaining the CSV file to be detected, using the data security reading scheme to read the data, obtain the target text, and use the preset detection scheme to detect the target text, determine the location of the attack data, and finally send an alarm signal.
It effectively detects whether there is injection of attack data in the CSV file and promptly sends an alert to the user, avoiding the impact of attacks on the user when opening the CSV file.
Smart Images

Figure CN114662097B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security, and in particular to a method and device for detecting CSV file injection attacks, an electronic device, and a storage medium. Background Art
[0002] Often, in the actual application management of network security, people are wary of external input and ignore some security issues of internal data. They treat CSV (Comma-Separated Values) files as simple text files and fail to pay attention to them. Moreover, many of the exported table data are controlled by users, such as voting applications and mailbox exports. In addition, when encountering the export function in penetration, testers generally focus on: arbitrary file downloads, or unauthorized viewing and other behaviors that are actually harmful to the website, and ignore CSV injection, because it will not harm the website itself, but will cause arbitrary OS command execution, information leakage and other harm to the end user. In some more common uses, CSV injection can also be used for phishing purposes by jumping to web pages.
[0003] Since Excel, Word, RTF, and Outlook all use the DDE (dynamic data exchange) communication mechanism to update content based on the processing results of external applications, if an attacker creates a CSV file containing a DDE formula, when the user opens the file, Excel will try to execute the external application to achieve its attack purpose.
[0004] There are many detection methods for common injection attacks such as SQL injection and command injection. However, since the attack conditions of CSV injection attacks are relatively harsh, the industry does not pay much attention to them, so there is a lack of relevant detection methods. Summary of the invention
[0005] The present application provides a method and device for detecting a CSV file injection attack, an electronic device, and a storage medium, so as to at least solve the problem that the related art lacks means for detecting a CSV injection attack.
[0006] According to one aspect of an embodiment of the present application, a method for detecting a CSV file injection attack is provided, the method comprising:
[0007] Get the CSV file to be tested;
[0008] Read the CSV file using a data security reading solution to obtain the target text;
[0009] Detecting the target text using a preset detection scheme, and when determining that the attack data is injected into the target text, determining that the attack data is located at a target position in the CSV file;
[0010] An alarm signal is sent based on the target location to indicate that the CSV file contains the attack data.
[0011] According to another aspect of an embodiment of the present application, a CSV file injection attack detection device is also provided, the device comprising:
[0012] A first acquisition unit, used for acquiring a CSV file to be detected;
[0013] A reading unit, used for reading data from the CSV file through a data security reading solution to obtain a target text;
[0014] A detection unit, configured to detect the target text using a preset detection scheme, and when it is determined that the attack data is injected into the target text, determine that the attack data is located at a target position in the CSV file;
[0015] A sending unit is used to send an alarm signal based on the target position to prompt that the CSV file contains the attack data.
[0016] Optionally, the detection unit includes:
[0017] An acquisition module, used for acquiring a plurality of preset codes and a plurality of preset characters corresponding to the dynamic data exchange protocol, wherein the preset code is a character string related to the dynamic data exchange protocol and used to characterize the executable file and the external application, and the preset character is used to characterize the first character of the command to be executed when opening the CSV file;
[0018] A matching module, used for matching the target text with the preset characters and preset codes to obtain a matching result;
[0019] A judgment module is used to judge whether the attack data is injected into the CSV file according to the matching result.
[0020] Optionally, the matching module includes:
[0021] A detection subunit, used for detecting the separation value contained in the target text;
[0022] The matching subunit is used to perform character matching between the reference data after the separation value and the preset code to obtain the matching result when it is determined that the separation value is the same as any of the preset characters.
[0023] Optionally, the device further comprises:
[0024] A determination unit is used for, after detecting the separator value contained in the target text, if it is determined that the separator value is not the same as any of the preset characters, cyclically detecting the next separator value and matching the next separator value with the preset character, until the number of execution cycles is equal to a preset threshold, and there is still no separator value that matches the preset character, then determining that the attack data is not injected into the CSV file.
[0025] Optionally, the device further comprises:
[0026] A second acquisition unit is used to acquire file information of the CSV file, wherein the file information includes an occupied space value of the CSV file, an original storage address of the CSV file, a detection time of the CSV file, whether the CSV file is injected with attack data, and a target position where the target text of the CSV file is injected with the attack data;
[0027] The storage unit is used to store the file information into a log.
[0028] Optionally, the device further comprises:
[0029] The isolation unit is used to isolate the target file from the target system by using an isolation tool before reading the data of the CSV file through the data security reading solution.
[0030] Optionally, the device further comprises:
[0031] A starting unit is used to start the target program where the CSV file is located after determining that the attack data is not injected into the CSV file, and open the CSV file based on the target program, so that a user can use the CSV file normally.
[0032] According to another aspect of the embodiments of the present application, there is also provided an electronic device, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; wherein the memory is used to store a computer program; and the processor is used to execute the method steps in any of the above embodiments by running the computer program stored in the memory.
[0033] According to another aspect of the embodiments of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the method steps in any of the above embodiments when executed.
[0034] In the embodiment of the present application, a CSV file to be detected is obtained; data of the CSV file is read through a data security reading scheme to obtain a target text; the target text is detected using a preset detection scheme, and when it is determined that attack data is injected into the target text, the target position of the attack data in the target text is determined; an alarm signal is sent based on the target position to prompt that the CSV file contains attack data. Because the embodiment of the present application can detect the CSV file before the user uses the target program (such as Excel) to open the CSV file, check whether there is a CSV injection attack and warn the user, thereby effectively preventing the user from being affected and harmed by the CSV injection attack, thereby solving the problem that the related technology lacks a detection method for CSV injection attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0036] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0037] Figure 1 is a schematic diagram of a hardware environment of an optional CSV file injection attack detection method according to an embodiment of the present invention;
[0038] Figure 2 It is a flowchart of an optional CSV file injection attack detection method according to an embodiment of the present application;
[0039] Figure 3 It is a flowchart of the entire use process of an optional user opening a CSV file according to an embodiment of the present application;
[0040] Figure 4 It is a flowchart of another optional CSV file injection attack detection process according to an embodiment of the present application;
[0041] Figure 5 is a structural block diagram of an optional CSV file injection attack detection device according to an embodiment of the present application;
[0042] Figure 6 It is a structural block diagram of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0043] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0044] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0045] First, some basic concepts:
[0046] CSV file:
[0047] CSV stands for Comma Separated Values, sometimes also called Character Separated Values, because the delimiting character can be anything other than a comma. CSV files store tabular data (numbers and text) in plain text. Plain text means that the file is a sequence of characters and does not contain data that must be interpreted like binary numbers. CSV files consist of any number of records, separated by some kind of line break character; each record consists of fields, and the separator between fields is another character or string, most commonly a comma or a tab. Usually, all records have exactly the same sequence of fields. They are usually plain text files.
[0048] CSV Injection Attack:
[0049] A CSV injection attack is to insert an Excel formula containing malicious commands into a text file that can be exported to a format such as CSV or xls. When the user opens the CSV file in Excel, the file will be converted to Excel format and provide the execution function of Excel formulas, thereby executing malicious code commands and controlling the user's computer.
[0050] DDE:
[0051] DDE is an inter-process communication protocol under Windows. It is a dynamic data exchange mechanism. Using DDE communication requires two Windows applications, one of which processes information as a server and the other obtains information from the server as a client. (A DDE conversation is identified by the window handles participating in the conversation.) DDE supports Microsoft Excel, LibreOffice and Apache OpenOffice. One use of DDE in Excel is to update the content of a cell based on the results of an external application. CSV injection attacks are based on this mechanism.
[0052] Regular Expression:
[0053] A regular expression is a text pattern that includes common characters (for example, letters from a to z) and special characters (called "metacharacters"). A regular expression uses a single string to describe and match a series of strings that match a certain syntactic rule.
[0054] According to one aspect of an embodiment of the present application, a method for detecting a CSV file injection attack is provided. Optionally, in this embodiment, the above-mentioned method for detecting a CSV file injection attack can be applied to Figure 1 In the hardware environment shown in the figure. Figure 1 As shown, the terminal 102 may include a memory 104, a processor 106, and a display 108 (optional component). The terminal 102 may be connected to a server 112 via a network 110 for communication. The server 112 may be used to provide services (such as application services, etc.) for the terminal or a client installed on the terminal. A database 114 may be set on the server 112 or independently of the server 112 to provide data storage services for the server 112. In addition, a processing engine 116 may be running in the server 112, and the processing engine 116 may be used to execute the steps executed by the server 112.
[0055] Optionally, the terminal 102 may be, but is not limited to, a terminal that can calculate data, such as a mobile terminal (e.g., a mobile phone, a tablet computer), a laptop, a PC (Personal Computer), etc. The above network may include, but is not limited to, a wireless network or a wired network. The wireless network includes: Bluetooth, WIFI (Wireless Fidelity) and other networks that implement wireless communication. The above wired network may include, but is not limited to: a wide area network, a metropolitan area network, and a local area network. The above server 112 may include, but is not limited to, any hardware device that can perform calculations.
[0056] In addition, in this embodiment, the above-mentioned CSV file injection attack detection method can also be applied to, but not limited to, an independent processing device with a relatively powerful processing capability without data interaction. For example, the processing device can be, but not limited to, a terminal device with a relatively powerful processing capability, that is, each operation in the above-mentioned CSV file injection attack detection method can be integrated in an independent processing device. The above is only an example, and this embodiment does not make any limitation to this.
[0057] Optionally, in this embodiment, the above-mentioned CSV file injection attack detection method can be executed by the server 112, can be executed by the terminal 102, or can be executed by the server 112 and the terminal 102. Among them, the terminal 102 executes the CSV file injection attack detection method of the embodiment of the present application, or it can be executed by a client installed thereon.
[0058] Take running on the server as an example, Figure 2 FIG. 1 is a flow chart of an optional CSV file injection attack detection method according to an embodiment of the present application, such as Figure 2 As shown, the process of the method may include the following steps:
[0059] Step S201, obtaining a CSV file to be detected;
[0060] Step S202, reading data from the CSV file using a data security reading solution to obtain a target text;
[0061] Step S203, detecting the target text using a preset detection scheme, and if it is determined that attack data is injected into the target text, determining the target position of the attack data in the CSV file;
[0062] Step S204, sending an alarm signal based on the target location to indicate that the CSV file contains attack data.
[0063] Optionally, in an embodiment of the present application, the server first determines and obtains the CSV file to be detected. Before detecting the CSV file, it is necessary to use an isolation tool, such as sandbox isolation, to isolate it to prevent it from being combined with other attack methods, thereby providing a safe environment for file detection. Then, the CSV file is read through a data text reading method (or scheme) of a secure data stream to read the target text.
[0064] Afterwards, the target text is detected for attack data using the preset detection scheme set in the embodiment of the present application. The preset detection scheme is a scheme for detecting and analyzing the target text generated during the execution of the data security reading scheme to confirm whether there is malicious code for CSV injection attack.
[0065] If it is determined that attack data (i.e., malicious code) is injected into the target text, the server will locate the position of the attack data in the target text, and then obtain the target position of the attack data in the CSV file, and then send an alarm signal to the user based on the target position to inform the user that the attack data is injected into the CSV file and the CSV file cannot be opened.
[0066] If the CSV file is detected to be safe, the target program currently being used by the user, such as Excel, will be automatically started, and then Excel can be opened directly.
[0067] In the embodiment of the present application, a CSV file to be detected is obtained; data of the CSV file is read through a data security reading scheme to obtain a target text; the target text is detected using a preset detection scheme, and when it is determined that attack data is injected into the target text, the target position of the attack data in the target text is determined; an alarm signal is sent based on the target position to prompt that the CSV file contains attack data. Because the embodiment of the present application can detect the CSV file before the user uses the target program (such as Excel) to open the CSV file, check whether there is a CSV injection attack and warn the user, thereby effectively preventing the user from being affected and harmed by the CSV injection attack, thereby solving the problem that the related technology lacks a detection method for CSV injection attacks.
[0068] As an optional embodiment, Figure 3 , Figure 3 This is a flow chart of the entire use process of an optional user opening a CSV file according to an embodiment of the present application, specifically:
[0069] When the user uses this detection method to open the CSV file, the server's detection method detects its data. When the CSV file contains injection statements of CSV injection attacks, it will be isolated in the sandbox and the user will be reminded that the file is unsafe. When no CSV injection attack statements are detected, the method will automatically start the Excel program and use the Excel program to open the CSV file for normal use by the user.
[0070] As an optional embodiment, detecting the target text using a preset detection scheme includes:
[0071] Obtain multiple preset codes and multiple preset characters corresponding to the dynamic data exchange protocol, wherein the preset code is a character string related to the dynamic data exchange protocol and used to represent executable files and external applications, and the preset character is used to represent the first character of the command to be executed when opening the CSV file;
[0072] Match the target text with the preset characters and preset codes to obtain a matching result;
[0073] Based on the matching results, determine whether attack data is injected into the CSV file.
[0074] Optionally, the CSV injection attack is based on Excel calling other programs through DDE (Dynamic Data Exchange protocol) when opening a CSV file, and the CSV file itself is just a plain text file. Therefore, the detection of whether there is CSV injection is to determine whether there is relevant code with DDE protocol implementation in the CSV file.
[0075] Specifically, the server obtains multiple preset codes and multiple characters pre-set by the dynamic data exchange protocol, wherein the preset code can be some file suffix characters, such as "cmd", "msExcel", "msiexec", etc.; it can also be any external application string of the file name that is globally available in some environments, for example, "regsvr32", "certutil", "rundll32", etc. The preset character can be some Excel execution of the preset character, that is, the first character of the run command to open the CSV file, such as "=", "+", "-" and "@", etc., and then all data in the target text are matched with the preset characters and preset codes, and according to the matching results, it is determined whether the attack data is injected into the CSV file.
[0076] When matching the target text with preset characters and preset codes, the preset characters need to be matched first. Only when the preset characters exist in the target text, the target text is further matched with the preset code, such as a regular expression, to finally obtain a matching result.
[0077] Furthermore, the separator value contained in the target text is detected. When it is determined that the separator value is the same as any preset character, the reference data after the separator value is matched with the preset code. Then, when there is a complete match or the matching degree is greater than a matching degree threshold (preset, such as 90%), it is considered that attack data has been injected into the CSV file. Otherwise, it is considered that no attack data has been injected into the CSV file.
[0078] At the same time, when detecting the separator value contained in the target text, if the separator value identical to the above-mentioned preset character is not found in the target text in this detection, the next separator value is detected until the number of executed cycles is equal to the preset threshold. It is considered that the preset character does not exist in the target text. At this time, it is also directly determined that no attack data is injected into the CSV file.
[0079] The processing method for the CSV file that has not been injected with attack data is as follows: start the target program where the CSV file is located, open the CSV file based on the target program, and allow the user to use the CSV file normally.
[0080] In the embodiment of the present application, by setting the default opening method of the CSV file to the injection attack detection method set in the embodiment of the present application, the user can open the file without using other dangerous methods to open it during normal use, while at the same time performing security detection on the file, thereby ensuring convenience during use while ensuring safety.
[0081] As an optional embodiment, the method further includes:
[0082] Obtaining file information of the CSV file, wherein the file information includes the occupied space value of the CSV file, the original storage address of the CSV file, the detection time of the CSV file, whether the CSV file is injected with attack data, and the target location of the target text of the CSV file into which the attack data is injected;
[0083] Store file information in the log.
[0084] Optionally, the server of the embodiment of the present application includes a log recording module, and the server obtains and records some file information of the CSV file, such as: the size of the detected file (i.e., the value of the occupied space), the original storage address of the file, the detection time, whether there is a CSV injection attack, the location of the injection attack, and other information to facilitate user viewing and security personnel to locate and analyze the attack.
[0085] Based on the above process, see Figure 4 , Figure 4 This is a flow chart of another optional CSV file injection attack detection process according to an embodiment of the present application, specifically:
[0086] When opening a CSV file, the detection method will first isolate it from the target system through sandbox isolation, and perform secure data reading through a data security reading solution in an isolated secure environment. After safely reading the files in the CSV file, the injection attack detection method of the embodiment of the present application will perform injection detection on the read data to see if there is injected malicious code. If it exists, it will enter branch 1, locate the detected malicious code and alarm the user to remind the user that the file is unsafe, and then record the location information of the malicious code and other information in the log. If it does not exist, it will enter branch 2, and the Excel startup module will use the Excel program to open the CSV file normally for normal use by the user.
[0087] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0088] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM (Read-Only Memory) / RAM (Random Access Memory), a magnetic disk, or an optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods of each embodiment of the present application.
[0089] According to another aspect of an embodiment of the present application, a CSV file injection attack detection device for implementing the above-mentioned CSV file injection attack detection method is also provided. Figure 5 is a structural block diagram of an optional CSV file injection attack detection device according to an embodiment of the present application, such as Figure 5 As shown, the device may include:
[0090] A first acquisition unit 501 is used to acquire a CSV file to be detected;
[0091] A reading unit 502 is used to read data from the CSV file through a data security reading solution to obtain a target text;
[0092] The detection unit 503 is used to detect the target text using a preset detection scheme, and when it is determined that the attack data is injected into the target text, determine the target position of the attack data in the CSV file;
[0093] The sending unit 504 is used to send an alarm signal based on the target location to prompt that the CSV file contains attack data.
[0094] It should be noted that the first acquisition unit 501 in this embodiment can be used to execute the above step S201, the reading unit 502 in this embodiment can be used to execute the above step S202, the detection unit 503 in this embodiment can be used to execute the above step S203, and the reading unit 504 in this embodiment can be used to execute the above step S204.
[0095] Through the above module, the CSV file can be detected before the user uses the target program (such as Excel) to open the CSV file to check whether there is a CSV injection attack and warn the user, thereby effectively preventing the user from being affected and harmed by the CSV injection attack, thereby solving the problem that related technologies lack detection methods for CSV injection attacks.
[0096] As an optional embodiment, the detection unit includes:
[0097] An acquisition module, used to acquire a plurality of preset codes and a plurality of preset characters corresponding to the dynamic data exchange protocol, wherein the preset code is a character string related to the dynamic data exchange protocol and used to represent an executable file and an external application, and the preset character is used to represent the first character of a command to be executed when opening a CSV file;
[0098] A matching module is used to match the target text with preset characters and preset codes to obtain a matching result;
[0099] The judgment module is used to judge whether attack data is injected into the CSV file based on the matching results.
[0100] As an optional embodiment, the matching module includes:
[0101] A detection subunit, used for detecting the separation value contained in the target text;
[0102] The matching subunit is used to perform character matching between the reference data after the separation value and the preset code to obtain a matching result when it is determined that the separation value is the same as any preset character.
[0103] As an optional embodiment, the device further includes:
[0104] The determination unit is used to detect the separator value contained in the target text, and when it is determined that the separator value is not the same as any preset character, cyclically detect the next separator value and match the next separator value with the preset character until the number of execution cycles is equal to the preset threshold. If there is still no separator value that matches the preset character, it is determined that no attack data is injected into the CSV file.
[0105] As an optional embodiment, the device further includes:
[0106] A second acquisition unit is used to acquire file information of the CSV file, wherein the file information includes an occupied space value of the CSV file, an original storage address of the CSV file, a detection time of the CSV file, whether the CSV file is injected with attack data, and a target position of the target text of the CSV file into which the attack data is injected;
[0107] The storage unit is used to store file information in the log.
[0108] As an optional embodiment, the device further includes:
[0109] The isolation unit is used to isolate the target file from the target system by using an isolation tool before reading data from the CSV file by using a data security reading solution.
[0110] As an optional embodiment, the device further includes:
[0111] The starting unit is used to start the target program where the CSV file is located after determining that no attack data is injected into the CSV file, and open the CSV file based on the target program, so that the user can use the CSV file normally.
[0112] It should be noted that the examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the contents disclosed in the above embodiments. It should be noted that the above modules as part of the device can be run in Figure 1 In the hardware environment shown, it can be implemented by software or by hardware, wherein the hardware environment includes a network environment.
[0113] According to another aspect of an embodiment of the present application, an electronic device for implementing the above-mentioned CSV file injection attack detection method is also provided. The electronic device may be a server, a terminal, or a combination thereof.
[0114] Figure 6 is a structural block diagram of an optional electronic device according to an embodiment of the present application, such as Figure 6 As shown, it includes a processor 601, a communication interface 602, a memory 603 and a communication bus 604, wherein the processor 601, the communication interface 602 and the memory 603 communicate with each other through the communication bus 604, wherein,
[0115] Memory 603, used for storing computer programs;
[0116] The processor 601 is used to implement the following steps when executing the computer program stored in the memory 603:
[0117] Get the CSV file to be tested;
[0118] Read the data from the CSV file through the data security reading solution to obtain the target text;
[0119] Detect the target text using a preset detection scheme, and if it is determined that attack data is injected into the target text, determine the target location of the attack data in the CSV file;
[0120] Send alerts based on target location to indicate attack data contained in CSV files.
[0121] Optionally, in this embodiment, the communication bus may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. The communication bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0122] The communication interface is used for communication between the above electronic device and other devices.
[0123] The memory may include RAM, or may include non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.
[0124] As an example, Figure 6 As shown, the memory 603 may include, but is not limited to, the first acquisition unit 501, the reading unit 502, the detection unit 503, and the sending unit 504 in the detection device for the CSV file injection attack. In addition, other module units in the detection device for the CSV file injection attack may also be included but are not limited to, which will not be repeated in this example.
[0125] The above-mentioned processor can be a general-purpose processor, which can include but not be limited to: CPU (Central Processing Unit), NP (Network Processor), etc.; it can also be DSP (Digital Signal Processing), ASIC (Application Specific Integrated Circuit), FPGA (Field-Programmable Gate Array) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0126] In addition, the electronic device also includes: a display for displaying the detection result of the CSV file injection attack.
[0127] Optionally, the specific examples in this embodiment may refer to the examples described in the above embodiments, and this embodiment will not be described in detail here.
[0128] It can be understood by those skilled in the art that Figure 6 The structure shown is for illustration only. The device for implementing the above-mentioned CSV file injection attack detection method may be a terminal device, which may be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (Mobile Internet Devices, MID), a PAD, and other terminal devices. Figure 6 It does not limit the structure of the above electronic device. For example, the terminal device may also include Figure 6 More or fewer components (such as network interfaces, display devices, etc.) shown in, or having Figure 6 Different configurations shown.
[0129] A person of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, which can include: a flash drive, ROM, RAM, a magnetic disk or an optical disk, etc.
[0130] According to another aspect of the embodiment of the present application, a storage medium is also provided. Optionally, in this embodiment, the storage medium can be used to execute the program code of the method for detecting CSV file injection attack.
[0131] Optionally, in this embodiment, the storage medium may be located on at least one network device among a plurality of network devices in the network shown in the above embodiment.
[0132] Optionally, in this embodiment, the storage medium is configured to store program codes for executing the following steps:
[0133] Get the CSV file to be tested;
[0134] Read the data from the CSV file through the data security reading solution to obtain the target text;
[0135] Detect the target text using a preset detection scheme, and if it is determined that attack data is injected into the target text, determine the target location of the attack data in the CSV file;
[0136] Send alerts based on target location to indicate attack data contained in CSV files.
[0137] Optionally, the specific examples in this embodiment may refer to the examples described in the above embodiments, which will not be described in detail in this embodiment.
[0138] Optionally, in this embodiment, the storage medium may include but is not limited to: a U disk, a ROM, a RAM, a mobile hard disk, a magnetic disk or an optical disk, and other media that can store program codes.
[0139] According to another aspect of the embodiments of the present application, a computer program product or a computer program is also provided, which includes computer instructions, and the computer instructions are stored in a computer-readable storage medium; a processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the steps of the detection method for CSV file injection attacks in any of the above embodiments.
[0140] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0141] If the integrated units in the above embodiments are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or part of the contribution to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling one or more computer devices (which can be personal computers, servers or network devices, etc.) to execute all or part of the steps of the detection method for CSV file injection attacks in various embodiments of the present application.
[0142] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0143] In the several embodiments provided in the present application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only schematic, for example, the division of units is only a logical function division, and there may be other division methods in actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0144] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution provided in this embodiment.
[0145] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0146] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A method for detecting CSV file injection attacks, characterized in that: The method comprises: Before the user opens the CSV file using the target program, obtain the CSV file to be detected; Read the CSV file using a data security reading solution to obtain the target text; The target text is detected by using a preset detection scheme, and when it is determined that the attack data is injected into the target text, the target position of the attack data in the CSV file is determined, wherein the detection of the target text by using the preset detection scheme includes: obtaining a plurality of preset codes and a plurality of preset characters corresponding to the dynamic data exchange protocol, wherein the preset code is a character string related to the dynamic data exchange protocol and used to characterize executable files and external applications, and the preset character is used to characterize the first character of a command to be executed when opening the CSV file; matching the target text with the preset character and the preset code to obtain a matching result; judging whether the attack data is injected into the CSV file according to the matching result; matching the target text with the preset character and the preset code to obtain a matching result includes: detecting a separator value contained in the target text; when it is determined that the separator value is the same as any of the preset characters, character matching the reference data located after the separator value with the preset code, and when there is a complete match or the matching degree is greater than a matching degree threshold, it is considered that the attack data is injected into the CSV file; An alarm signal is sent based on the target location to indicate that the CSV file contains the attack data.
2. The method according to claim 1, characterized in that After detecting the separation value contained in the target text, the method includes: When it is determined that the separation value is not the same as any of the preset characters, a next separation value is detected in a loop and matched with the preset character until the number of execution loops is equal to a preset threshold. If there is still no separation value that matches the preset character, it is determined that the attack data has not been injected into the CSV file.
3. The method according to claim 1, characterized in that The method further comprises: Obtaining file information of the CSV file, wherein the file information includes an occupied space value of the CSV file, an original storage address of the CSV file, a detection time of the CSV file, whether the CSV file is injected with attack data, and a target position where the target text of the CSV file is injected with the attack data; The file information is stored in a log.
4. The method according to claim 1, characterized in that: Before reading data from the CSV file using the data security reading solution, the method further includes: Use isolation tools to isolate target files from target systems.
5. The method according to claim 2, characterized in that: After determining that the attack data is not injected into the CSV file, the method further includes: The target program where the CSV file is located is started, and the CSV file is opened based on the target program, so that the user can use the CSV file normally.
6. A detection device for CSV file injection attack, characterized in that: The device comprises: A first acquisition unit, used for acquiring the CSV file to be detected before the user uses the target program to open the CSV file; A reading unit, used for reading data from the CSV file through a data security reading solution to obtain a target text; A detection unit is used to detect the target text using a preset detection scheme, and when it is determined that the target text has been injected with attack data, determine that the attack data is located at a target position in the CSV file, wherein the detection unit includes: an acquisition module, used to acquire a plurality of preset codes and a plurality of preset characters corresponding to the dynamic data exchange protocol, wherein the preset code is a character string related to the dynamic data exchange protocol and used to characterize executable files and external applications, and the preset character is used to characterize the first character of a command to be executed when opening a CSV file; a matching module, used to match the target text with the preset character and the preset code to obtain a matching result; the matching module includes: a detection subunit, used to detect a separator value contained in the target text; a matching subunit, used to match the reference data located after the separator value with the preset code when it is determined that the separator value is the same as any preset character, and when a complete match is found or the matching degree is greater than a matching degree threshold, it is considered that the attack data has been injected into the CSV file; a judgment module, used to judge whether the attack data has been injected into the CSV file according to the matching result; A sending unit is used to send an alarm signal based on the target position to prompt that the CSV file contains the attack data.
7. An electronic device comprising a processor, a communication interface, a memory and a communication bus, wherein: The processor, the communication interface and the memory communicate with each other via the communication bus, wherein: The memory is used to store computer programs; The processor is configured to execute the method steps of any one of claims 1 to 5 by running the computer program stored in the memory.
8. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program implements the method steps described in any one of claims 1 to 5 when executed by a processor.