A traffic attack detection method and device

By intercepting, extracting, modifying and comparing the requested traffic received by the user terminal, the problem of identification and response in the case of high attack traffic is solved in the existing technology, and fast and accurate traffic attack detection and analysis are achieved.

CN115314281BActive Publication Date: 2025-05-30BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210933489.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-04
Publication Date
2025-05-30
Estimated Expiration
2042-08-04

AI Technical Summary

Technical Problem

The prior art is difficult to quickly and accurately identify and respond to attack traffic when there is a large amount of attack traffic.

Method used

By intercepting the requested traffic received by the user terminal, extracting the actual attack payload, and modifying and comparing it in multiple dimensions, generating multi-dimensional attack payloads, matching and analysis of intelligence databases, and finally feedback the analysis results to the operation terminal.

Benefits of technology

It realizes accurate identification of attack traffic at the first time, improves the detection efficiency and accuracy of multi-dimensional attacks, and can effectively respond in scenarios with high attack traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115314281B_ABST
    Figure CN115314281B_ABST
Patent Text Reader

Abstract

The present application provides a flow attack detection method and device, the method comprising: intercepting the request flow received by the user terminal; extracting the actual attack load in the request flow; performing multi-dimensional modification on the actual attack load to obtain a multi-dimensional attack load; performing multi-dimensional comparison based on the multi-dimensional attack load to obtain a comparison response result; performing analysis and processing based on the comparison response result to obtain an analysis and processing result; and feeding back the actual attack load, the multi-dimensional attack load, the comparison response result and the analysis and processing result to the operation terminal. It can be seen that the implementation of this implementation method can accurately identify the attack flow in the first place, so that it can be used in scenarios with more attack flow.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security. Specifically, it relates to a method and device for detecting traffic attacks. Background Art

[0002] With the development of computer networks and the Internet, network security has received increasing attention. Among them, as a network security system, an intrusion detection system is usually used to monitor the network transmission status or system status to detect threatening traffic so that staff can make corresponding judgments on attacks as early as possible. However, in practice, it is found that this method cannot quickly and accurately respond to incoming attacks in the case of a large amount of attack traffic. Summary of the Invention

[0003] The purpose of the embodiments of this application is to provide a method and device for detecting traffic attacks, which can accurately identify attack traffic in the first time, so that it can be applied to scenarios with a large amount of attack traffic.

[0004] The first aspect of the embodiments of this application provides a method for detecting traffic attacks, including:

[0005] Intercept the request traffic received by the user terminal;

[0006] Extract the actual attack payload in the request traffic;

[0007] Modify the actual attack payload in multiple dimensions to obtain a multi-dimensional attack payload;

[0008] Perform multi-dimensional comparison based on the multi-dimensional attack payload to obtain a comparison response result;

[0009] Perform analysis and processing based on the comparison response result to obtain an analysis and processing result;

[0010] Feed back the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to the operation terminal.

[0011] In the above implementation process, the method can preferentially intercept the request traffic received by the user terminal, so that the simulation device can obtain the request traffic obtained by the user terminal, thereby ensuring that the request traffic is obtained by both devices at the same time, and further ensuring that the simulation device can analyze, identify, and perform subsequent processing on the request traffic in a timely manner. Then, the method can extract the actual attack payload from the request traffic; it can be seen that the method can extract the actual attack payload when obtaining the request traffic, thereby ensuring the improvement of the detection efficiency of traffic attacks. Then, the method can modify the actual attack payload in multiple dimensions to obtain a multi-dimensional attack payload; it can be seen that the method can modify the actual attack payload in multiple dimensions through various methods, thereby obtaining multiple attack payloads, and further enabling the method to perform comparative analysis on multiple attack payloads in different dimensions, effectively improving the detection effect of traffic attacks. After that, the method can also perform multi-dimensional comparison based on the multi-dimensional attack payload to obtain a comparison response result; it can be seen that the method can perform intelligence database matching on the attack payload based on different dimensions, thereby facilitating the method to comprehensively and effectively analyze based on the previous intelligence database and the current attack payload. After that, the method can perform analysis and processing based on the comparison response result to obtain an analysis and processing result; it can be seen that the method can analyze each attack payload based on the previous intelligence database, thereby achieving multi-dimensional detection of traffic attacks. Finally, the method can feedback the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to the operation terminal; it can be seen that the method can feedback all the analysis processes and results to the operation terminal, so that the operation personnel can learn about these situations and perform corresponding processing on these situations.

[0012] Further, after the step of intercepting the request traffic received by the user terminal, the method further includes:

[0013] Determine whether there is an actual attack payload in the request traffic;

[0014] When there is the actual attack payload in the request traffic, execute the step of extracting the actual attack payload from the request traffic.

[0015] In the above implementation process, after intercepting the request traffic received by the user terminal, the method can also determine whether there is an actual attack payload in the request traffic; and when there is an actual attack payload in the request traffic, execute the step of extracting the actual attack payload from the request traffic. It can be seen that the method can perform attack determination based on the request traffic received by the user terminal, thereby ensuring that the method is executed when the user terminal is attacked and avoiding the method from occupying unnecessary resources.

[0016] Further, the step of modifying the actual attack payload in multiple dimensions to obtain a multi-dimensional attack payload includes:

[0017] Mark the modifiable positions in the actual attack payload;

[0018] Based on the modifiable positions, perform multi-dimensional modification on the actual attack payload to obtain a multi-dimensional attack payload.

[0019] In the above implementation process, when the method performs multi-dimensional modification on the actual attack payload to obtain a multi-dimensional attack payload, it can first mark the modifiable positions in the actual attack payload; then, based on the modifiable positions, perform multi-dimensional modification on the actual attack payload to obtain a multi-dimensional attack payload. It can be seen that implementing this implementation method can prioritize marking the modifiable positions in the actual attack payload, and then perform multi-dimensional modification based on these positions, so as to obtain a relatively reliable multi-dimensional attack payload, thereby improving the traffic attack detection effect.

[0020] Further, the step of performing multi-dimensional modification on the actual attack payload based on the modifiable positions to obtain a multi-dimensional attack payload includes:

[0021] Based on the modifiable positions, perform replacement of the attack payload and / or injection of garbled characters on the actual attack payload to obtain a multi-dimensional attack payload.

[0022] In the above implementation process, when the method performs multi-dimensional modification on the actual attack payload based on the modifiable positions to obtain a multi-dimensional attack payload, it can be based on the modifiable positions to perform replacement of the attack payload and / or injection of garbled characters on the actual attack payload to obtain a multi-dimensional attack payload. It can be seen that this method can modify the actual attack payload by replacing the attack payload and injecting garbled characters at the specified positions, so as to obtain a multi-dimensional attack payload of a relatively high level and improve the overall traffic attack detection effect.

[0023] Further, the step of performing multi-dimensional comparison based on the multi-dimensional attack payload to obtain a comparison response result includes:

[0024] Based on a preset intelligence database, perform multi-dimensional comparison on the multi-dimensional attack payload to obtain a comparison response result.

[0025] In the above implementation process, when the method performs multi-dimensional comparison based on the multi-dimensional attack payload to obtain a comparison response result, specifically, it can perform multi-dimensional comparison on the multi-dimensional attack payload based on a preset intelligence database to obtain a comparison response result. It can be seen that this method can compare the multi-dimensional attack payload based on a preset intelligence database, so as to determine the attack payloads that are the same as and different from the preset intelligence database, and then facilitate the subsequent steps to perform corresponding and effective detection on these attack payloads, thereby improving the overall traffic detection effect.

[0026] Further, the analysis and processing results include engine warning situations, attack success situations, and engine rule deficiency situations.

[0027] In the above implementation process, the analysis and processing results including engine warning situations, attack success situations, and engine rule deficiency situations can effectively reflect the results of the analysis and processing, so that both the system and relevant staff can easily understand the final results, and thus can proceed with subsequent processes without having to know the intermediate process.

[0028] Further, the step of feeding back the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to the operation terminal includes:

[0029] Summarize and organize the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to obtain a summary result;

[0030] Feed back the summary result to the operation terminal.

[0031] In the above implementation process, in the process of feeding back the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to the operation terminal, the method can first summarize and organize the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to obtain a summary result; then feed back the summary result to the operation terminal. It can be seen that the method can fill in the defaults for some vacant parameters through the process of summarization and organization, so that the method can obtain multiple complete summary results, avoid the operation terminal from outputting a form with some blank parameters or blank content, and further avoid the operation personnel from performing secondary processing on the visualization results, and can achieve the effect of improving the work processing efficiency of the operation personnel.

[0032] The second aspect of the embodiments of the present application provides a traffic attack detection device, and the traffic attack detection device includes:

[0033] An interception unit for intercepting the request traffic received by the user terminal;

[0034] An extraction unit for extracting the actual attack payload in the request traffic;

[0035] A modification unit for performing multi-dimensional modification on the actual attack payload to obtain a multi-dimensional attack payload;

[0036] A comparison unit for performing multi-dimensional comparison based on the multi-dimensional attack payload to obtain a comparison response result;

[0037] An analysis unit for performing analysis and processing based on the comparison response result to obtain an analysis and processing result;

[0038] A feedback unit for feeding back the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to the operation terminal.

[0039] In the above implementation process, the device can intercept the request traffic received by the user terminal through the interception unit, so that the simulation device can obtain the request traffic obtained by the user terminal, thereby ensuring that the request traffic is obtained by both devices at the same time, and further ensuring that the simulation device can analyze, identify, and perform subsequent processing on the request traffic in a timely manner. Then, the device can extract the actual attack payload in the request traffic through the extraction unit; it can be seen that the device can extract the actual attack payload when obtaining the request traffic, thereby ensuring the improvement of the detection efficiency of traffic attacks. Then, the device can modify the actual attack payload in multiple dimensions through the modification unit to obtain a multi-dimensional attack payload; it can be seen that the device can modify the actual attack payload in multiple dimensions in multiple ways, thereby obtaining multiple attack payloads, and further enabling the device to perform comparative analysis on multiple attack payloads in different dimensions, effectively improving the detection effect of traffic attacks. After that, the device can also perform multi-dimensional comparison based on the multi-dimensional attack payload through the comparison unit to obtain a comparison response result; it can be seen that the device can perform intelligence library matching on the attack payload based on different dimensions, thereby facilitating the device to comprehensively and effectively analyze based on the previous intelligence library and the current attack payload. After that, the device can also perform analysis and processing based on the comparison response result through the analysis unit to obtain an analysis and processing result; it can be seen that the device can analyze each attack payload based on the previous intelligence library, thereby achieving multi-dimensional detection of traffic attacks. Finally, the device can feed back the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to the operation terminal through the feedback unit; it can be seen that the device can feed back the entire analysis process and analysis result to the operation terminal, so that the operation personnel can learn about these situations and perform corresponding processing on these situations.

[0040] Furthermore, the traffic attack detection device further includes:

[0041] A judgment unit for judging whether there is an actual attack payload in the request traffic;

[0042] The extraction unit is specifically configured to extract the actual attack payload in the request traffic when there is the actual attack payload in the request traffic.

[0043] In the above implementation process, the device can use a judgment unit to determine whether there is an actual attack payload in the request traffic; and use an extraction unit to extract the actual attack payload in the request traffic when there is an actual attack payload. It can be seen that the device can perform attack determination based on the request traffic received by the user terminal, so as to ensure that the device is executed when the user terminal is attacked, and avoid the device occupying unnecessary resources.

[0044] Further, the modification unit includes:

[0045] A marking subunit, configured to mark modifiable positions in the actual attack payload;

[0046] A modification subunit, configured to perform multi-dimensional modification on the actual attack payload based on the modifiable positions to obtain a multi-dimensional attack payload.

[0047] In the above implementation process, the modification unit can use the marking subunit to mark modifiable positions in the actual attack payload; and use the modification subunit to perform multi-dimensional modification on the actual attack payload based on the modifiable positions to obtain a multi-dimensional attack payload. It can be seen that implementing this implementation method can first mark the modifiable positions in the actual attack payload, and then perform multi-dimensional modification based on these positions, so as to obtain a relatively reliable multi-dimensional attack payload, and further improve the traffic attack detection effect.

[0048] Further, the modification subunit is specifically configured to perform offensive payload replacement and / or garbled code injection on the actual attack payload based on the modifiable positions to obtain a multi-dimensional attack payload.

[0049] In the above implementation process, the modification subunit can perform offensive payload replacement and / or garbled code injection on the actual attack payload based on the modifiable positions to obtain a multi-dimensional attack payload. It can be seen that the device can modify the actual attack payload by replacing the offensive payload and injecting garbled code at specified positions, so as to obtain a multi-dimensional attack payload of a higher level and improve the overall traffic attack detection effect.

[0050] Further, the comparison unit is specifically configured to perform multi-dimensional comparison on the multi-dimensional attack payload based on a preset information database to obtain a comparison response result.

[0051] In the above implementation process, the comparison unit can specifically perform multi-dimensional comparison on the multi-dimensional attack payload based on a preset information database to obtain a comparison response result. It can be seen that the device can compare the multi-dimensional attack payload based on the preset information database, so as to determine the attack payloads that are the same as and different from the preset information database, and further facilitate the subsequent steps to perform corresponding and effective detection on these attack payloads, and improve the overall traffic detection effect.

[0052] Further, the analysis and processing results include engine warning situations, attack success situations, and engine rule deficiency situations.

[0053] In the above implementation process, the analysis and processing results including engine warning situations, attack success situations, and engine rule deficiency situations can effectively reflect the results of the analysis and processing, so that both the system and relevant staff can easily understand the final results, and subsequent processes can be carried out without having to know the intermediate process.

[0054] Further, the feedback unit includes:

[0055] A sorting subunit, configured to summarize and sort the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to obtain a sorting result;

[0056] A feedback subunit, configured to feedback the sorting result to the operation terminal.

[0057] In the above implementation process, the feedback unit can summarize and sort the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result through the sorting subunit to obtain a sorting result; and feedback the sorting result to the operation terminal through the feedback subunit. It can be seen that the device can fill in the default values of some vacant parameters through the summarization and sorting process, so that the device can obtain multiple complete sorting results, avoid the operation terminal from outputting a form with some blank parameters or blank content, and further avoid the operation personnel from performing secondary processing on the visualization result, and can achieve the effect of improving the work processing efficiency of the operation personnel.

[0058] A third aspect of the embodiments of the present application provides an electronic device, including a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the traffic attack detection method according to any one of the first aspects of the embodiments of the present application.

[0059] A fourth aspect of the embodiments of the present application provides a computer-readable storage medium, which stores computer program instructions. When the computer program instructions are read and run by a processor, the traffic attack detection method according to any one of the first aspects of the embodiments of the present application is executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0061] Figure 1 It is a schematic flow chart of a traffic attack detection method provided by an embodiment of the present application;

[0062] Figure 2 It is a schematic structural diagram of a traffic attack detection device provided by an embodiment of the present application. Detailed implementation manners

[0063] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.

[0064] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.

[0065] Embodiment 1

[0066] Please refer to Figure 1 , Figure 1 which is a schematic flow chart of a traffic attack detection method provided by this embodiment. Among them, the traffic attack detection method includes:

[0067] S101. Intercept the request traffic received by the user terminal.

[0068] In this embodiment, this method is executed based on a simulation device.

[0069] In this embodiment, the simulation device is synchronized with the real device (i.e., the user terminal). When receiving the response synchronously, this method can obtain the intelligence in the first time and perform analysis and processing.

[0070] In this embodiment, this method can truncate the received request traffic during the response and trigger subsequent steps for processing.

[0071] S102. Determine whether there is an actual attack payload in the request traffic. If so, execute step S103; if not, end this process.

[0072] In this embodiment, after receiving the request traffic, this method analyzes whether there is an attack payload in the request.

[0073] S103. Extract the actual attack payload in the request traffic.

[0074] S104. Mark the modifiable positions in the actual attack payload.

[0075] In this embodiment, the method can label the positions in the actual attack payload that can be modified into different attack vectors (i.e., modifiable positions), and after labeling, modify the corresponding positions into attack vectors of different dimensions (i.e., multi-dimensional attack payload).

[0076] S105. Based on the modifiable positions, perform offensive payload replacement and / or garbled code injection on the actual attack payload to obtain a multi-dimensional attack payload.

[0077] In this embodiment, the multi-dimensional modification includes two modification methods. One is to replace the labeled position with different payloads of the same attack method, such as modifying into different system commands during command execution. The other is to add garbled code before and after the labeled position.

[0078] In this embodiment, the method can send the above two types of malicious requests and the original request to the simulation environment as a multi-dimensional attack payload.

[0079] S106. Based on a preset information library, perform multi-dimensional comparison on the multi-dimensional attack payload to obtain a comparison response result.

[0080] In this embodiment, after receiving the response packet, the method can use the information library to analyze the response results of different attack vectors, analyze whether the response results match the corresponding vectors. If they match, it is successful; if not, compare with the response results generated by another packet sending form (adding garbled code before and after the labeled position).

[0081] In this embodiment, the method divides the multi-dimensional attack payload into three parts: http_stat_code, http_header, and file_date. Specifically, the method will perform different comparative analyses on these three parts respectively.

[0082] In this embodiment, the http_stat_code part is directly compared.

[0083] In this embodiment, the http_header part adopts a line-by-line comparison method, compares each line one by one, and then compares each line as a group to obtain the comparison result of http_header.

[0084] In this embodiment, the file_data part adopts a character comparison analysis method. Specifically, the method takes five characters as a group, performs the longest common character group matching for each group, then compares within each character group, then shifts the annotation of the calculation group backward by two units, and then repeats the character group matching with five characters as a group. After comparing three times, summarize and analyze the results, reverse process the results, and perform annotation.

[0085] In this embodiment, the method aggregates and annotates the results matched by the above three parts to obtain a comparison response result.

[0086] S107. Analyze and process based on the comparison response result to obtain an analysis and processing result.

[0087] In this embodiment, the analysis and processing result includes the engine alarm situation, the attack success situation, and the lack of engine rules situation.

[0088] In this embodiment, the method can first analyze the response generated by the actual attack payload and attack payloads in other different dimensions, and then combine the analysis result with the intelligence library to judge the engine alarm situation, the attack success situation, and the lack of engine rules situation of this original attack payload.

[0089] In this embodiment, the method not only needs to judge the attack situation of the actual attack payload, but also needs to record and judge the attack situation of the modified attack payload, mark the payloads without alarms, and make judgments in combination with the results of comparative analysis, and also analyze and summarize various situations of such attack payloads in different dimensions.

[0090] In this embodiment, the method can summarize the engine missing rule situations in the two cases and supplement relevant rules. Finally, send the result of the analysis and processing to the feedback result module.

[0091] S108. Aggregate and sort out the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to obtain a sorting result.

[0092] In this embodiment, the method can aggregate and sort out the above multiple results, summarize the actual attack payload and the corresponding results of the modified attack payload together, and list the response comparison results of each attack payload including the original payload and the garbled payload in sequence, and display their alarm information and supplementary rules, and organize these into a report and feedback it as the sorting result.

[0093] S109. Feedback the sorting result to the operation terminal.

[0094] In this embodiment, the method can send the aggregated results to the operation terminal specified by the corresponding manufacturer, which is convenient for the operation personnel to view and process.

[0095] In this embodiment, the method provides a process of simulating a real environment, modifying an actual attack payload in multiple dimensions, and then retesting the simulated environment. Specifically, the method can analyze by combining the response results of the multi-dimensional attack payload with those of the original payload and an intelligence database, so as to determine whether the corresponding real attack payload is successfully attacked and enrich the prevention rules for diverse attack payloads. By means of this method in real time, real threats can be better matched, and other attack methods can be inferred from one instance, thereby improving the work efficiency of security operation personnel.

[0096] In this embodiment, the main process of the method is to simulate a simulated environment parallel to the real environment, diversify and fail the received attacks before this simulated environment, and then send the processed attack payload to the simulation device, use the diverse payloads to complete attack diversification, and conduct comparative analysis on the responses obtained thereby, and feedback the processed results to the real device, so as to realize the optimization process for the real device.

[0097] In this embodiment, the execution subject of the method can be a computing device such as a computer or a server, and no limitation is made in this embodiment.

[0098] In this embodiment, the execution subject of the method can also be a smart device such as a smart phone or a tablet computer, and no limitation is made in this embodiment.

[0099] It can be seen that implementing the traffic attack detection method described in this embodiment can receive malicious traffic in the first time, analyze and process it, and diversify the attack payloads. At the same time, use the simulated real environment to process malicious traffic and provide supplementary suggestions for the prevention rules of real devices. In addition, the method can also determine the success of the attack in the first time. It can be seen that the method can facilitate subsequent responses for security service personnel and users and realize timely and effective protection for user terminals.

[0100] Embodiment 2

[0101] Please refer to Figure 2 , Figure 2 which is a schematic structural diagram of a traffic attack detection device provided in this embodiment. As Figure 2 shown, the traffic attack detection device includes:

[0102] An interception unit 210, configured to intercept the request traffic received by the user terminal;

[0103] An extraction unit 220, configured to extract the actual attack payload in the request traffic;

[0104] A modification unit 230, configured to modify the actual attack payload in multiple dimensions to obtain a multi-dimensional attack payload;

[0105] A comparison unit 240, configured to perform multi-dimensional comparison based on multi-dimensional attack payloads to obtain a comparison response result;

[0106] An analysis unit 250, configured to perform analysis and processing based on the comparison response result to obtain an analysis and processing result;

[0107] A feedback unit 260, configured to feedback the actual attack payload, multi-dimensional attack payloads, comparison response result, and analysis and processing result to an operation terminal.

[0108] As an optional implementation manner, the traffic attack detection device further includes:

[0109] A judgment unit 270, configured to judge whether there is an actual attack payload in the request traffic;

[0110] An extraction unit 220, specifically configured to extract the actual attack payload in the request traffic when there is an actual attack payload in the request traffic.

[0111] As an optional implementation manner, the modification unit 230 includes:

[0112] A marking subunit 231, configured to mark modifiable positions in the actual attack payload;

[0113] A modification subunit 232, configured to perform multi-dimensional modification on the actual attack payload based on the modifiable positions to obtain multi-dimensional attack payloads.

[0114] As an optional implementation manner, the modification subunit 232 is specifically configured to perform attack payload replacement and / or garbled code injection on the actual attack payload based on the modifiable positions to obtain multi-dimensional attack payloads.

[0115] As an optional implementation manner, the comparison unit 240 is specifically configured to perform multi-dimensional comparison on the multi-dimensional attack payloads based on a preset information library to obtain a comparison response result.

[0116] In this embodiment, the analysis and processing result includes engine warning conditions, attack success conditions, and engine rule deficiency conditions.

[0117] As an optional implementation manner, the feedback unit 260 includes:

[0118] An arrangement subunit 261, configured to summarize and arrange the actual attack payload, multi-dimensional attack payloads, comparison response result, and analysis and processing result to obtain an arrangement result;

[0119] A feedback subunit 262, configured to feedback the arrangement result to an operation terminal.

[0120] In the embodiments of the present application, the explanation of the traffic attack detection device can be referred to the description in Embodiment 1, and thus will not be elaborated herein.

[0121] It can be seen that implementing the traffic attack detection device described in this embodiment can receive malicious traffic in a timely manner, analyze and process it, and diversify the attack payloads. Meanwhile, by using the simulated real environment, it processes malicious traffic and provides supplementary suggestions for the prevention rules of real devices. In addition, the device can also determine the success of an attack in a timely manner. It can be seen that the device can facilitate subsequent responses for security service personnel and users, and effectively protect user terminals in a timely manner.

[0122] The embodiments of the present application provide an electronic device, including a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the traffic attack detection method in Embodiment 1 of the present application.

[0123] The embodiments of the present application provide a computer-readable storage medium, which stores computer program instructions. When the computer program instructions are read and run by a processor, they execute the traffic attack detection method in Embodiment 1 of the present application.

[0124] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0125] In addition, in each embodiment of the present application, the functional modules can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part.

[0126] When the above-mentioned functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.

[0127] The above are only the embodiments of this application and are not used to limit the protection scope of this application. For those skilled in the art, this application can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included in the protection scope of this application. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0128] As mentioned above, these are only the specific implementation manners of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in this application, and all of them should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0129] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

Claims

1. A method for detecting traffic attacks, characterized in that, it includes: Intercept the request traffic received by the user terminal; Extract the actual attack payload in the request traffic; Perform multi-dimensional modification on the actual attack payload to obtain a multi-dimensional attack payload; Perform multi-dimensional comparison based on the multi-dimensional attack payload to obtain a comparison response result; Perform analysis and processing based on the comparison response result to obtain an analysis and processing result; Feedback the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to the operation terminal; Among them, the step of performing multi-dimensional modification on the actual attack payload to obtain a multi-dimensional attack payload includes: Mark the modifiable positions in the actual attack payload; Based on the modifiable positions, perform offensive payload replacement and / or garbled code injection on the actual attack payload to obtain a multi-dimensional attack payload; Among them, the step of performing multi-dimensional comparison based on the multi-dimensional attack payload to obtain a comparison response result includes: Based on a preset intelligence library, perform multi-dimensional comparison on the multi-dimensional attack payload to obtain a comparison response result.

2. The traffic attack detection method according to claim 1, characterized in that, after the step of intercepting the request traffic received by the user terminal, the method further includes: Judge whether there is an actual attack payload in the request traffic; When there is the actual attack payload in the request traffic, execute the step of extracting the actual attack payload in the request traffic.

3. The traffic attack detection method according to claim 1, characterized in that, The analysis and processing result includes the engine alarm situation, the attack success situation, and the engine rule deficiency situation.

4. The traffic attack detection method according to claim 1, characterized in that, The step of feeding back the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to the operation terminal includes: Summarize and organize the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to obtain an organized result; Feed back the organized result to the operation terminal.

5. A traffic attack detection device, characterized in that, The traffic attack detection device includes: An interception unit for intercepting the request traffic received by the user terminal; An extraction unit for extracting the actual attack payload in the request traffic; A modification unit for performing multi-dimensional modification on the actual attack payload to obtain a multi-dimensional attack payload; A comparison unit for performing multi-dimensional comparison based on the multi-dimensional attack payload to obtain a comparison response result; An analysis unit for performing analysis and processing based on the comparison response result to obtain an analysis and processing result; A feedback unit for feeding back the actual attack payload, the multi-dimensional attack payload, the comparison response result, and the analysis and processing result to the operation terminal; Among them, the modification unit includes: A marking subunit for marking the modifiable positions in the actual attack payload; A modification subunit for performing multi-dimensional modification on the actual attack payload based on the modifiable positions to obtain a multi-dimensional attack payload; Wherein, the modification subunit is specifically configured to perform offensive payload replacement and / or garbled injection on the actual attack payload based on the modifiable position to obtain a multi-dimensional attack payload; Wherein, the comparison unit is specifically configured to perform multi-dimensional comparison on the multi-dimensional attack payload based on a preset information database to obtain a comparison response result.

6. An electronic device, characterized in that, the electronic device includes a memory and a processor, the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the traffic attack detection method according to any one of claims 1 to 4.

7. A readable storage medium, characterized in that, computer program instructions are stored in the readable storage medium, and when the computer program instructions are read and run by a processor, the traffic attack detection method according to any one of claims 1 to 4 is executed.

Citation Information

Patent Citations

  • Bug detection method, device and equipment

    CN111294345A

  • WEB application-based file uploading vulnerability detection method and system

    CN112182583A