A security protection method, device, storage medium and electronic equipment
By injecting a sectional program into a business application to detect intrusion attacks and directing it to the honeypot system, the problems of high cost and low capture rate of honeypot system are solved, and efficient and economical security protection is achieved.
Patent Information
- Application Number
- CN202210845185.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-18
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2042-07-18
AI Technical Summary
When protecting business systems, the existing honeypot system has high cost and high workload, and the honeypot system passively waits for attacks, with a low capture rate.
By injecting a facet program into a business application, detecting intrusion attacks and obtaining operation data, guiding intrusion attacks to the honeypot system, and achieving active boot security protection.
When a small number of honeypot systems are deployed, the capture rate of honeypot systems will be improved, the security protection costs will be reduced, and the business system's defense capabilities against intrusion attacks will be enhanced.
Smart Images

Figure CN115277142B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a security protection method, device, storage medium and electronic device. Background Art
[0002] With the development of technology, various businesses have shifted from offline to online. The resulting problem is that attackers can use network attacks to attack the servers or computer clusters where the business systems are located to obtain information.
[0003] In the prior art, a honeypot system is usually deployed to protect the business system to prevent the leakage of private data. The honeypot system disguises itself as a fake operating system or business system with vulnerabilities to lure attackers to actively attack, so as to collect their attack data and analyze it. In order to improve the capture rate of the honeypot system, the number of honeypot systems deployed is usually increased, resulting in excessively high costs and huge workload.
[0004] To this end, this specification provides a security protection method, device, storage medium and electronic device based on security aspects. Summary of the invention
[0005] This specification provides a safety protection method and device for improving safety protection while reducing the cost of safety protection.
[0006] This manual adopts the following technical solutions:
[0007] This manual provides a safety protection method, including:
[0008] Receive an injection request;
[0009] Injecting the aspect program included in the injection request into the business application and running it, wherein the aspect program is used to detect intrusion attacks;
[0010] If an intrusion attack is detected by the aspect program during the execution of the business corresponding to the business application, then the operation data corresponding to the intrusion attack is obtained;
[0011] According to the operation data, the intrusion attack is directed to the honeypot system so as to perform security protection through the honeypot system.
[0012] Optionally, injecting the aspect program included in the injection request into the business application program specifically includes:
[0013] Parsing the injection request, determining an injection location of the aspect program included in the injection request in the business application as a target location;
[0014] The aspect program is injected into the target location to inject the aspect program into the business application.
[0015] Optionally, injecting the aspect program included in the injection request into the business application program specifically includes:
[0016] Parsing the injection request to determine an injection method, wherein the injection method includes at least one of a static proxy and a dynamic proxy;
[0017] According to the injection method, the aspect program included in the injection request is injected into the business application program.
[0018] Optionally, the method further comprises:
[0019] If an opening instruction for the aspect program is received, the state corresponding to the aspect program is switched to an opening state, and the aspect program is executed during the execution of the business corresponding to the business application program;
[0020] If a closing instruction for the aspect program is received, the state corresponding to the aspect program is switched to a closed state, and the aspect program is not executed during the execution of the business corresponding to the business application program.
[0021] Optionally, injecting the aspect program included in the injection request into the business application program specifically includes:
[0022] By pre-deploying the aspect base in the business application, the aspect program included in the injection request is injected into the aspect point of the business application into which the aspect program is injected, so as to deploy the aspect program in the business application.
[0023] Optionally, according to the operation data, the intrusion attack is directed to a honeypot system to perform security protection through the honeypot system, specifically including:
[0024] The operation data is sent to the aspect program management and control platform, so that the aspect program management and control platform guides the intrusion attack to the honeypot system through the received operation data.
[0025] This manual provides a safety protection device, including:
[0026] A deployment module, configured to receive an injection request; deploy a slice program included in the injection request in a business application program and run the slice program, wherein the slice program is used to detect intrusion attacks;
[0027] An intrusion detection module, used for obtaining operation data corresponding to the intrusion attack if an intrusion attack is detected by the aspect program during the execution of the business corresponding to the business application program;
[0028] The security protection module is used to guide the intrusion attack to the honeypot system according to the operation data, so as to perform security protection through the honeypot system.
[0029] Optionally, the security protection module is specifically used to send the operation data to the aspect program management and control platform, so that the aspect program management and control platform guides the intrusion attack to the honeypot system through the received operation data.
[0030] This specification provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned security protection method is implemented.
[0031] This specification provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned security protection method when executing the program.
[0032] At least one of the above technical solutions adopted in this specification can achieve the following beneficial effects:
[0033] In the security protection method provided in this specification, the server injects the aspect program for detecting intrusion attacks contained in the injection request into the business application according to the received injection request. When the aspect program detects an intrusion attack during the execution of the business application, the operation data corresponding to the intrusion attack can be obtained, and the intrusion attack can be directed to the honeypot system according to the operation data corresponding to the intrusion attack.
[0034] From the above method, it can be seen that this method does not passively wait for attackers to attack the honeypot system, but guides the intrusion attack to the honeypot system through the aspect program deployed in the business application system. Based on this, this method can improve the capture rate of the honeypot system when a small number of honeypot systems are deployed, and at the same time, it also saves the cost of deploying the honeypot system. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The drawings described herein are used to provide a further understanding of this specification and constitute a part of this specification. The illustrative embodiments and descriptions of this specification are used to explain this specification and do not constitute an improper limitation on this specification. In the drawings:
[0036] Figure 1 This is a flowchart of a safety protection method in this manual;
[0037] Figure 2This is a schematic diagram of a safety protection structure in this manual;
[0038] Figure 3 A schematic diagram of a safety protection device provided in this manual;
[0039] Figure 4 The corresponding Figure 1 Schematic diagram of electronic equipment. DETAILED DESCRIPTION
[0040] In order to make the purpose, technical solutions and advantages of this specification more clear, the technical solutions of this specification will be clearly and completely described below in combination with the specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this specification.
[0041] With the rapid development of computer technology, various data or information are usually transmitted through the network. In order to avoid information leakage, network security has become one of the key concerns. At present, honeypot technology is used to protect the server. Honeypot technology is essentially a technology that deceives attackers. It arranges some hosts and network services as bait to make attackers mistake them for real hosts or servers, so that attackers attack the honeypot system and avoid attackers from attacking the real host or server. The honeypot system can capture the attacker's attack behavior and analyze the captured attack behavior to understand the attacker's attack intention, attack tools, attack means, etc. In this way, you can clearly understand the security threats you are facing and can more effectively enhance the security protection capabilities of the real host or server.
[0042] Among them, because the honeypot system simulates the real business system and is not used by real users, the attacker will not obtain real information from the honeypot system, so the information or data in the real business system will not be leaked. In addition, the honeypot system is not deployed on the real business system. The honeypot system and the real business system are deployed separately and are independent of each other.
[0043] Under normal circumstances, the honeypot system is passively waiting for attackers to invade and attack it. In order to increase the capture rate of the honeypot system for attackers, the number of honeypot systems deployed is usually increased. The real business system is usually composed of server clusters. Thousands of servers are connected together to form a mesh structure. The honeypot system can be deployed near each network node. However, the honeypot system is a virtual business system, that is, a fake business system with no actual business access. Deploying it near each network node will also occupy memory resources. In addition, as the number of honeypot systems deployed increases, the cost of network security protection will also increase.
[0044] In addition, when the value of a certain data or information is higher, it is more attractive to attackers, and the possibility of the data or information being stolen is higher. Therefore, the capture rate of the honeypot system can also be improved by deploying the honeypot system close to the key position of the actual business system. However, this will expose the network structure of the real business system and its position (vulnerability point) that can be easily attacked and invaded. In actual operation, after deploying the honeypot system close to the key position of the network, the capture rate of the honeypot system will not be significantly improved, and the risk of the real business system being attacked will increase.
[0045] This specification provides a security protection method that uses a security aspect to improve the capture rate of the honeypot system against intrusion attacks, thereby increasing the business system's defense capabilities against intrusion attacks without increasing the number of honeypot system deployments and exposing the network structure of the real business system and its locations that are vulnerable to attacks and intrusions.
[0046] The security aspect mentioned above refers to a method of dynamically adding or modifying the aspect program for implementing the security aspect business in the running logic of the business application without modifying the business application by adopting the aspect-oriented programming (AOP) method. While implementing the security aspect business, the program for implementing the security aspect business is decoupled from the business application, thereby avoiding the development iteration problem caused by high coupling.
[0047] The aspect program mentioned here is an enhancement program that implements the security aspect business based on the business operation logic. The aspect program can be injected into the corresponding point of the business application by adopting the aspect-oriented programming method. The aspect program is triggered and executed during the execution of the business application to implement the required security aspect business function.
[0048] When business applications execute business, they usually perform business execution through calls between methods. Therefore, any method in the business application can be used as the entry point of the aspect program, that is, the above-mentioned pointcut, and the aspect program is injected into the corresponding pointcut. When the business application executes to the pointcut, that is, when the method of the business application corresponding to the pointcut is called, the aspect program injected at the pointcut is executed.
[0049] Usually, the code responsible for injecting the aspect program into the pointcut is highly reusable. Therefore, the program that implements this process is usually abstracted into a service module, namely the aspect base. The aspect base can obtain the aspect program to be deployed and the pointcut in the business application from a third party that provides security aspect services. After the application container is started, it is injected into the corresponding aspect program at the pointcut of the business application by the environment.
[0050] The business application may be a business application that provides business services in the server of the business platform. The business service may be a business service provided by the server of the business platform to users, such as query services, payment services, etc. The business service may also be a business service provided by a server of the business platform to other servers, such as settlement services, etc.
[0051] Of course, from the above description, it can be seen that in order to decouple the security aspect business program from the business application, this specification adopts an aspect-oriented programming approach so that the security aspect business program and the business application are intertwined during business execution, but they are parallel to each other and can be maintained independently. Therefore, unlike the business provider of the business application, the third party providing the security aspect business can manage the content involved in the security aspect business through the management and control platform, such as the configuration of the security aspect business management and control strategy, the version iteration of the aspect program, the deployment rule configuration of the aspect program, etc. Of course, the security aspect service can be provided by a third party or a business provider.
[0052] When managing the content involved in the security aspect business, the control platform can record various configuration information through configuration files, such as the configuration of various policies, the configuration of the deployment rules of the aspect program, etc. This allows the aspect base to complete the deployment of the aspect program according to the configuration file, or the control platform can implement the security aspect business according to the configuration file.
[0053] In actual applications, the service provider usually has a computer room including several physical machines or physical servers, and provides the physical resources required by the business application through the physical machine. Of course, a business application may not need all the physical resources of the entire physical machine, so it is generally necessary to run multiple virtual hosts (virtual hosting) on a physical machine through virtualization technology. Each virtual host is independent of each other and each enjoys part of the physical resources of the physical machine. Then, the application container can be deployed in the virtual host, and the business application can be run through the application container. The application container usually contains physical resources allocated to the application container, such as CPU, memory, etc., and the operating environment provided to the application container, such as the operating system (OS) or other operating environment data, such as the serial number (SN) of the container, the assigned IP (Influential Property), the application name, the tenant, the environment variables, etc.). Business applications can be deployed in the application container to execute business.
[0054] In the scenario where services are executed based on security aspects, the service provider or a third-party server that provides security aspect services can provide a management and control platform to manage the content involved in the security aspect services, deploy the aspect base in the application container, and inject the aspect program into the business application in the business application container through the aspect base to provide support for the security aspect services of the service provider's application container.
[0055] Therefore, the aspect base can be deployed in the application container of the service provider in advance. Generally, when the application container is started, the operating system provided to the application container can be called up, and the pre-deployed aspect base can be run. The aspect program and the point of intersection of the business application can be obtained from the management and control platform through the aspect base, and the aspect program can be injected into the point of intersection of the business application in the application container. In addition, the aspect base can also obtain the point of intersection of the aspect program and the business application from the management and control platform during the execution of the business application, and inject the aspect program into the point of intersection of the business application in the application container.
[0056] Of course, how the aspect base obtains the information required for deploying the aspect program from the control platform can be set as needed. For example, the required information can be actively pulled from the control platform according to the configuration file, or the control platform can actively send the required information to the aspect base.
[0057] After the aspect program is injected into the point of entry of the business application, the aspect program can be triggered during the execution of the business application to implement the corresponding security aspect business function.
[0058] The technical solutions provided by the embodiments of this specification are described in detail below in conjunction with the accompanying drawings.
[0059] Figure 1 The following is a flow chart of a safety protection method in this manual, which specifically includes the following steps:
[0060] S100: receiving an injection request.
[0061] S102: Injecting the aspect program included in the injection request into the business application and running it, wherein the aspect program is used to detect intrusion attacks.
[0062] First of all, the core idea of the security protection method provided in this specification is: inject an aspect program with intrusion detection function into the business application that needs security protection. In the process of the business application executing the business, the aspect program injected into the business application can be started together with the business application to detect whether there is an intrusion attack at any time. When an intrusion attack on the business application occurs during the execution of the business corresponding to the business application, the aspect program can detect the intrusion attack, and at this time, the operation data corresponding to the intrusion attack can be obtained. Afterwards, the intrusion attack can be directed to the honeypot system based on the obtained operation data corresponding to the intrusion attack. The security protection method provided in this specification can improve the capture rate of the honeypot system through an active guidance method, rather than making the honeypot system passively wait for the attacker to launch an intrusion attack on it.
[0063] Based on the above description of the core idea of the security protection method provided in this specification, the security protection method provided in this specification can be executed by the server or electronic device corresponding to the business application that needs to be protected, such as a laptop computer, a mobile phone, etc., and can also be executed by a monitoring system for monitoring business applications. The monitoring system is deployed in an independent server, and this specification does not limit this. In addition, in addition to the business application system, the server or host corresponding to the business application that needs to be protected can be used as the execution subject of this method.
[0064] The following only takes the server corresponding to the business application system that needs to be protected as the execution subject as an example to illustrate the security protection method provided in this specification.
[0065] Specifically, the server corresponding to the business application may receive an injection request including a slice program with an intrusion detection function, and the server may inject the slice program with the intrusion detection function included in the injection request into the business application.
[0066] Among them, the injection request includes not only the aspect program, but also the location where the aspect program is to be injected (i.e., the tangent point mentioned above) and the injection method. In addition, other information can be included in the injection request according to actual needs, and this manual does not limit this.
[0067] The server can parse the received injection request, and can parse the aspect program to be injected into the business application for enhancing the security aspect of intrusion detection, the injection position of the aspect program, and the injection method of the aspect program from the injection request. After that, the server can inject the parsed aspect program into the position where it should be injected according to the parsed injection method through the aspect base. The injection method can be a static proxy or a dynamic proxy.
[0068] If the aspect program is injected in a static proxy manner, the server can first stop the business application, then inject the aspect program into the business application, and then start the business application with the injected aspect program.
[0069] If the aspect is injected in the form of dynamic proxy, the server can inject the aspect program into the business application while the business application is running. In actual operation, dynamic proxy is usually used as the main injection method.
[0070] Among them, the injection position is equivalent to the tangent point of the business application injection aspect program, which can be a part of a function of a class in the business application. The mentioned part can be the starting point, end point or exception throwing point of the code used to implement the business function in the business application, for example, before, return or throw, etc. This manual does not limit this.
[0071] S104: If an intrusion attack is detected by the aspect program during the execution of the business corresponding to the business application, operation data corresponding to the intrusion attack is obtained.
[0072] Taking the example of injecting the aspect program before the code used to implement business functions in the business application, when the user performs an operation on the business application software, since the aspect program used for intrusion detection is injected before the code used to implement the business function, the aspect program can determine whether there is abnormal behavior in the current user's operation through the user's operation. When it is determined that the current user's operation is abnormal behavior, it can be determined that the business application system has been attacked by an intrusion.
[0073] At this time, in order to protect user data in the business application system from being stolen by attackers, the business application program can stop executing subsequent business and obtain the operation data corresponding to the current intrusion attack when it is determined that it has been attacked.
[0074] S106: According to the operation data, the intrusion attack is directed to a honeypot system, so as to perform security protection through the honeypot system.
[0075] Specifically, the operation of directing the intrusion attack to the honeypot system is as follows: the server corresponding to the business application can send the operation data corresponding to the intrusion attack to the aspect program management and control platform, and the aspect program management and control platform can replay the intrusion attack to the honeypot system through the received operation data corresponding to the intrusion attack, so that the honeypot system establishes a connection with the attacker corresponding to the intrusion attack to direct the intrusion attack to the honeypot system.
[0076] based on Figure 1 In the security protection method shown, the server corresponding to the business application deploys the aspect program for detecting intrusion attacks contained in the injection request in the business application according to the injection request received. During the business execution process of the business application, when the aspect program detects an intrusion attack, the operation data corresponding to the intrusion attack can be obtained, and the intrusion attack can be directed to the honeypot system according to the operation data corresponding to the intrusion attack. It can be seen from the above method that this method does not passively wait for the attacker to attack the honeypot system, but guides the intrusion attack to the honeypot system by injecting the aspect program in the business application system. Based on this, this method can improve the capture rate of the honeypot system when a small number of honeypot systems are deployed, and at the same time, it also saves the cost of deploying the honeypot system.
[0077] In the embodiments of this specification, the above-mentioned security protection method is actually implemented by a security protection system, wherein the structure of the security protection system is as follows: Figure 2 The security protection system provided in this manual includes a section program management and control platform, a server corresponding to the business application program, and a honeypot system.
[0078] Specifically, the staff can pre-set intrusion detection rules, and the aspect program management and control platform can determine the aspect program with intrusion detection function according to the preset intrusion detection rules. Among them, the intrusion detection rules can be understood as pre-specifying some specified operations. When it is detected that the user's operation meets the specified operation, it can be determined that the business application has been attacked by an intrusion. At this time, the operation data generated by the operation performed by the user belongs to the operation data corresponding to the intrusion attack. In addition, different intrusion detection rules can be set for different businesses, and this manual does not limit this.
[0079] For example, for payment services, even if the user makes a mistake in operation, the situation where the password is entered multiple times and still the password is incorrect will not occur. Therefore, it can be set that when it is detected that the user enters the wrong password more than a specified number of times, it is determined that an intrusion attack has been detected.
[0080] It can be seen from the above description that the aspect program used for intrusion detection is actually an enhanced program that detects intrusion attacks based on the business operation logic, which is used to enhance the security aspect business of intrusion detection. The security protection method provided in this specification adopts the security aspect method to realize the injection of the aspect program. Specifically, the aspect base pre-deployed in the business application program can be started together with the operation of the business application program. The aspect base can parse the injection request to determine the aspect program in the business application program. The deployment method of the injected aspect program. Afterwards, the aspect program can be deployed through the aspect base in the parsed injection method and injected into the above-mentioned point in the business program.
[0081] After that, the aspect program, as an enhanced program for intrusion detection, can play its role in detecting intrusion attacks. When an intrusion attack is detected through the aspect program, the operation data corresponding to the intrusion attack can be sent to the attack replay module of the aspect program management and control platform, and the aspect program management and control platform can replay the operation data corresponding to the intrusion attack to the honeypot system. Among them, the operation data corresponding to the intrusion attack at least includes attack information and context traffic data, and the operation data corresponding to the intrusion attack can be regarded as data corresponding to the specified operation specified in the intrusion detection rules. For example, for payment operations, the intrusion detection rules stipulate that during the user's payment process, if the number of password input operations of the user reaches the specified number, and it is detected that the correct password has not been entered, the number of password input operations performed by the current user can be used as operation data.
[0082] like Figure 2 As shown in the figure, after receiving the operation data corresponding to the intrusion attack, the honeypot system can simulate the business application and establish an interactive connection with the attacker to respond to the attacker's attack traffic, thereby guiding the attacker to attack the honeypot system and prevent the attacker from attacking the business application. After that, the honeypot system can further parse the attack information and other information to analyze the attack tools, attack techniques, attack intentions, etc. used by the attacker. In the case of understanding the other party's intrusion attack, other effective protection measures can be better taken for the business application system.
[0083] For example, when an attacker wants to attack the server corresponding to a business application, the attacker can operate according to the business process corresponding to the business application. When the aspect program in the business application detects that the operation currently performed by the attacker meets the specified operation corresponding to the intrusion detection, it is determined that the business application has been attacked by an intrusion. At this time, the business application can stop executing subsequent business operations and display jump links such as URLs to the attacker. After the attacker clicks on the displayed jump link, the attacker will jump from the real business application to the honeypot system. After that, any operation of the attacker on the business application is an interaction with the honeypot system, and will not generate any interaction with the server corresponding to the real business application system.
[0084] Furthermore, for actual application scenarios, in some special cases, the pre-set intrusion detection rules are not applicable. In order to prevent the aspect program from identifying normal user operations as intrusion operations, a switch program can be configured for the aspect program. For example, during the time when some e-commerce companies are promoting sales, users will frequently perform payment operations, which is normal behavior. In order to prevent the aspect program from mistaking the current frequent payment operations for intrusion operations, the aspect program management and control platform can send a shutdown instruction for the aspect program, so that the aspect program will not be executed during the process of the business application executing the payment business. Conversely, the aspect management and control platform can also send an opening instruction for the aspect program, so that the aspect program will be executed during the process of the business application executing the business.
[0085] The above is a safety protection method provided by one or more embodiments of this specification. Based on the same idea, this specification also provides corresponding safety protection devices, such as Figure 3 shown.
[0086] Figure 3 A schematic diagram of a safety protection device provided for this manual specifically includes:
[0087] Injection module 301, intrusion detection module 302, security protection module 303, wherein:
[0088] The injection module 301 is used to receive an injection request; inject the aspect program included in the injection request into the business application and run it, wherein the aspect program is used to detect intrusion attacks;
[0089] The intrusion detection module 302 is used to obtain operation data corresponding to the intrusion attack if an intrusion attack is detected by the aspect program during the execution of the business corresponding to the business application program;
[0090] The security protection module 303 is used to guide the intrusion attack to the honeypot system according to the operation data, so as to perform security protection through the honeypot system.
[0091] Optionally, the injection module 301 is specifically used to parse the injection request, determine the injection position of the aspect program contained in the injection request in the business application as the target position; inject the aspect program into the target position to inject the aspect program into the business application.
[0092] Optionally, the injection module 301 is specifically used to parse the injection request and determine an injection method, wherein the injection method includes at least one of a static proxy and a dynamic proxy; according to the injection method, the aspect program included in the injection request is injected into the business application.
[0093] Optionally, the intrusion detection module 302 is also used to, if an opening instruction for the aspect program is received, switch the state corresponding to the aspect program to an opening state, and execute the aspect program during the execution of the business corresponding to the business application; if a closing instruction for the aspect program is received, switch the state corresponding to the aspect program to a closing state, and do not execute the aspect program during the execution of the business corresponding to the business application.
[0094] Optionally, the injection module 301 is specifically used to inject the aspect program contained in the injection request into the aspect point of the business application program by pre-deploying the aspect base in the business application, so as to inject the aspect program into the business application.
[0095] Optionally, the security protection module 303 is specifically used to send the operation data to the aspect program management and control platform, so that the aspect program management and control platform guides the intrusion attack to the honeypot system through the received operation data.
[0096] It should be noted that all actions of acquiring signals, information or data in this application are carried out in compliance with the relevant data protection laws and policies of the country where they are located, and with the authorization given by the owner of the corresponding device.
[0097] This specification also provides a computer-readable storage medium, which stores a computer program, which can be used to execute the above Figure 1 Provides security protection methods.
[0098] This manual also provides Figure 4 The schematic structure diagram of the electronic device shown in FIG. Figure 4As mentioned above, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include other hardware required for the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to achieve the above Figure 1 Of course, in addition to the software implementation, this specification does not exclude other implementations, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0099] In the 1990s, improvements to a technology could be clearly distinguished as hardware improvements (for example, improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the method flow). However, with the development of technology, many improvements to the method flow today can be regarded as direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.
[0100] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.
[0101] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0102] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0103] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0104] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0105] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0106] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0107] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0108] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0109] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0110] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0111] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0112] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0113] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0114] The above description is only an embodiment of the present specification and is not intended to limit the present specification. For those skilled in the art, the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims of the present specification.
Claims
1. A security protection method, comprising: Receive an injection request; Injecting the aspect program included in the injection request into the business application and running it, wherein the aspect program is used to detect intrusion attacks; If an intrusion attack is detected by the aspect program during the execution of the business corresponding to the business application, the business application is stopped from executing subsequent business and operation data corresponding to the intrusion attack is obtained; The operation data is sent to the aspect program management and control platform, so that the aspect program management and control platform replays the intrusion attack to the honeypot system through the received operation data, so as to establish a connection between the honeypot system and the attacker corresponding to the intrusion attack, and guide the intrusion attack to the honeypot system.
2. The method according to claim 1, injecting the aspect program contained in the injection request into the business application, specifically comprising: Parsing the injection request, determining an injection location of the aspect program included in the injection request in the business application as a target location; The aspect program is injected into the target location to inject the aspect program into the business application.
3. The method according to claim 1 or 2, wherein injecting the aspect program contained in the injection request into the business application program specifically comprises: Parsing the injection request to determine an injection method, wherein the injection method includes at least one of a static proxy and a dynamic proxy; According to the injection method, the aspect program included in the injection request is injected into the business application program.
4. The method of claim 1, further comprising: If an opening instruction for the aspect program is received, the state corresponding to the aspect program is switched to an opening state, and the aspect program is executed during the execution of the business corresponding to the business application program; If a closing instruction for the aspect program is received, the state corresponding to the aspect program is switched to a closed state, and the aspect program is not executed during the execution of the business corresponding to the business application program.
5. The method according to claim 1, injecting the aspect program contained in the injection request into the business application, specifically comprising: By pre-deploying an aspect base in the business application, the aspect program included in the injection request is injected into the aspect point of the business application into which the aspect program is injected, so as to inject the aspect program into the business application.
6. A safety protection device, comprising: An injection module, used for receiving an injection request; Injecting the aspect program included in the injection request into the business application and running it, wherein the aspect program is used to detect intrusion attacks; An intrusion detection module, used to stop the business application from executing subsequent business and obtain operation data corresponding to the intrusion attack if an intrusion attack is detected by the aspect program during the execution of the business corresponding to the business application; The security protection module is used to send the operation data to the aspect program management and control platform, so that the aspect program management and control platform replays the intrusion attack to the honeypot system through the received operation data, so as to establish a connection between the honeypot system and the attacker corresponding to the intrusion attack, and guide the intrusion attack to the honeypot system.
7. A computer-readable storage medium, wherein the storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 5 when executing the program.
Citation Information
Patent Citations
User ticket buying behavior detection method and device
CN110675228A
Monitoring method and monitoring system for business application
CN114706734A