A method for identifying brute force attacks and related components
By obtaining login data packets at the target server kernel layer and identifying brute force cracking accounts based on the number of failures, the real-time and accuracy of identifying brute force cracking behavior in the prior art is solved, ensuring the security of the server.
Patent Information
- Application Number
- CN202211027137.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-25
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2042-08-25
AI Technical Summary
The existing technology is difficult to quickly and accurately identify brute-force cracking behaviors, and relying on third-party libraries has security risks, affecting server security.
Get the login data packets of each login account at the kernel layer of the target server. By identifying the destination port and login status, determine the number of failures of the login account within the preset time period. When the number of failures exceeds the threshold, it is identified as a brute-force cracking account.
Real-time and accurate identification of brute-force cracking behaviors is achieved, avoiding the delay and security risks caused by system log generation and third-party library use, and ensuring the security of the target server.
Smart Images

Figure CN115396202B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of communication security, and particularly to a method for identifying brute-force cracking and related components. Background Art
[0002] Brute-force cracking refers to the behavior that an attacker enumerates all possible sensitive information such as the username and password of the target server and attempts accordingly until the cracking is successful. Brute-force cracking has the advantages of simple operation and low cost, so it has become the preferred attack means of attackers. In order to ensure the security of the target server, it is necessary to identify brute-force cracking behavior. In the prior art, the login account, the login times of the login account, and whether the login is successful recorded in the system log of the target server are read to identify whether the login account is the account used by the attacker. However, it takes a certain amount of time for the target server to generate the system log, and sometimes the system log will be closed during the operation of the target server, which will result in the inability to quickly and accurately identify brute-force cracking. In addition, in the prior art, the system traffic of the target server is obtained through third-party libraries such as winpcap to identify brute-force cracking, but the open-source third-party libraries have potential security risks and are not conducive to maintaining the security of the target server. Summary of the Invention
[0003] The purpose of the present invention is to provide a method for identifying brute-force cracking and related components, which can identify brute-force cracking in real time and accurately, and ensure the security of the target server.
[0004] To solve the above technical problems, the present invention provides a method for identifying brute-force cracking, including:
[0005] Obtaining the login data packets of each login account at the kernel layer of the target server, where the login data packet includes the destination port accessed by the login account and the login status of the login account;
[0006] When the destination port is a risk port in the target server, determining the number of failure times when the login status of the login account is login failure within a preset time period after the current moment;
[0007] When the number of failure times is greater than a preset number threshold, identifying the login account as a brute-force cracking account.
[0008] Preferably, the login data packet further includes the transport layer protocol used by the login account to access the target server;
[0009] Before determining the number of failure times when the login status of the login account is login failure within a preset time period after the current moment, it further includes:
[0010] When it is determined that the transport layer protocol is a risky transport layer protocol corresponding to the target server, proceed to the step of determining the number of failed attempts in which the login status of the login account is a login failure within a preset time period after the current moment.
[0011] Preferably, the risky ports include:
[0012] Any one or a combination of multiple ports among the RDP port for remote desktop connection in the target server, the port for sharing files within the target server, and the port for connecting to a shared output device in the target server.
[0013] Preferably, the login data packet further includes the source IP and source port used by the login account;
[0014] After identifying that the login account is a brute - force cracking account, it further includes:
[0015] Intercept the login account with the source IP and / or source port at the kernel layer.
[0016] Preferably, after identifying that the login account is a brute - force cracking account, it further includes:
[0017] Generate a prompt message for notifying the user that the target server is under brute - force cracking.
[0018] Preferably, determining the number of failed attempts in which the login status of the login account is a login failure within a preset time period after the current moment includes:
[0019] When the login status is a login success, clear the first login failure time;
[0020] When the login status is a login failure, increment the number of login failures by one;
[0021] When it is determined that the first login failure time is not empty, subtract the first login failure time from the time when the current login status of the login account is a login failure to obtain the login duration;
[0022] When it is determined that the first login failure time is empty, record the time when the current login status of the login account is a login failure as the first login failure time, and increment the number of login failures by one;
[0023] When the login duration is less than the preset time period, proceed to the step of identifying the login account as a brute - force cracking account when the number of failed attempts is greater than a preset number threshold;
[0024] When the login duration is greater than the preset time period, clear the first login failure time and use the time when the current login status of the login account is login failure as the first login failure time.
[0025] To solve the above technical problems, the present application also provides an identification system for brute-force cracking, including:
[0026] A login data packet acquisition unit, configured to acquire login data packets of each login account in the kernel layer of the target server, where the login data packet includes the destination port accessed by the login account and the login status of the login account;
[0027] A failure times determination unit, configured to determine the number of times the login status of the login account is login failure within a preset time period after the current moment when the destination port is a risk port in the target server;
[0028] An identification unit, configured to identify the login account as a brute-force cracking account when the number of failures is greater than a preset number threshold.
[0029] Preferably, the login data packet further includes the transport layer protocol used by the login account to access the target server, and further includes:
[0030] A risk transport layer protocol determination unit, configured to trigger the failure times determination unit when it is determined that the transport layer protocol is the risk transport layer protocol corresponding to the target server.
[0031] Preferably, the risk ports include:
[0032] Any one or a combination of the RDP port for remote desktop connection in the target server, the port for sharing files in the target server, and the port for connecting to a shared output device in the target server.
[0033] Preferably, the login data packet further includes the source IP and source port used by the login account, and further includes:
[0034] An interception unit, configured to intercept the login account with the source IP and / or the source port after identifying the login account as a brute-force cracking account in the kernel layer.
[0035] Preferably, it further includes:
[0036] A prompt unit, configured to generate a prompt message for prompting the user that the target server is under brute-force cracking after identifying the login account as a brute-force cracking account.
[0037] Preferably, the failure times determination unit includes:
[0038] A clearing unit, configured to clear the first login failure time when the destination port is a risk port in the target server and the login status is login success;
[0039] A counting unit, configured to increment the login failure count by one when the login status is login failure;
[0040] A login duration determination unit, configured to, when determining that the first login failure time is not empty, obtain the login duration by subtracting the first login failure time from the time when the current login status of the login account is login failure;
[0041] A first login failure time determination unit, configured to, when determining that the first login failure time is empty, record the time when the current login status of the login account is login failure as the first login failure time and increment the login failure count by one;
[0042] A triggering unit, configured to trigger the recognition unit when the login duration is less than the preset time period;
[0043] A first login failure time update unit, configured to, when the login duration is greater than the preset time period, clear the first login failure time and use the time when the current login status of the login account is login failure as the first login failure time.
[0044] To solve the above technical problems, the present application further provides a brute-force cracking recognition device, including:
[0045] A memory, configured to store a computer program;
[0046] A processor, configured to implement the steps of the above-mentioned brute-force cracking recognition method when executing the computer program.
[0047] To solve the above technical problems, the present application further provides a server, including the above-mentioned brute-force cracking recognition device.
[0048] To solve the above technical problems, the present application further provides a computer-readable storage medium, on which a computer program is stored, and the computer program, when executed by a processor, implements the steps of the above-mentioned brute-force cracking recognition method.
[0049] In summary, the present invention provides a method for identifying brute-force cracking and related components, including obtaining login data packets of each logged-in account at the kernel layer of the target server, and further determining the number of failed attempts when the destination port recorded in the login data packet is a risk port in the target server, and when the number of failed attempts is greater than the preset threshold, identifying the logged-in account as a brute-force cracking account. Obtaining the login data packet from the kernel layer can reflect the information of the logged-in account in real time, and the method of identifying brute-force cracking accounts based on the number of failed attempts within a preset time period after the current moment is more accurate, ensuring the security of the target server. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the prior art and the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0051] Figure 1 Schematic flowchart of a method for identifying brute-force cracking provided by the present invention;
[0052] Figure 2 Schematic flowchart of another method for identifying brute-force cracking provided by the present invention;
[0053] Figure 3 Schematic structural diagram of a system for identifying brute-force cracking provided by the present invention;
[0054] Figure 4 Schematic structural diagram of a device for identifying brute-force cracking provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] The core of the present invention is to provide a method for identifying brute-force cracking and related components, which can identify brute-force cracking in real time and accurately, ensuring the security of the target server.
[0056] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0057] Please refer to Figure 1 , Figure 1Flow chart of a method for identifying brute-force cracking provided by the present invention. The method for identifying brute-force cracking includes:
[0058] S1: Obtain the login data packets of each login account at the kernel layer of the target server. The login data packets include the destination port accessed by the login account and the login status of the login account.
[0059] Since generating system logs, obtaining system logs, and identifying brute-force cracking based on the login accounts, the number of login times of the login accounts, and whether the login is successful in the system logs all require a certain amount of time, the real-time performance of identifying brute-force cracking in the prior art is relatively poor, and it is also affected by the possible closure of the system logs, resulting in the inability to identify the brute-force cracking behavior suffered by the server, bringing great security risks to the server.
[0060] Therefore, in this application, obtaining the login data packets of the login accounts at the kernel layer of the target server can obtain the login data packets of the login accounts in real time. The login data packets include the destination port and the login status. The destination port refers to the port of the target server actually accessed by the login account, and the login status includes login success and login failure. It should be noted that the login data packets generally can also include the source IP, source port, destination IP, and transport layer protocol. The source IP and source port reflect the information of the login account, the destination IP reflects the information of the target server, and the transport layer protocol can reflect what kind of function process in the target server the login account wants to access. In addition, the login status in this application can be determined by reading the code identification code in the login data packet. For example, when the login data packet is an RDP login data packet, the code identification code is 80000003, then it can be determined that the login status of the login account corresponding to the RDP login data packet is login failure.
[0061] It should also be noted that this application does not make special limitations on how to obtain the login data packet information from the kernel layer. For example, in the kernel layer, the source IP, source port, destination IP, destination port, and transport layer protocol are obtained through defining a callout function and creating a filter through filtering conditions.
[0062] S2: When the destination port is a risk port in the target server, determine the number of failure times when the login status of the login account is login failure within a preset time period after the current moment.
[0063] S3: When the number of failure times is greater than the preset number threshold, identify the login account as a brute-force cracking account.
[0064] Considering that attackers mainly attack the target server through remote desktop connection, shared files, or shared printers, etc., and different brute-force cracking behaviors attack different ports in the target server. Therefore, in this application, when the destination port is a risk port in the target server, it is determined that the login account corresponding to the destination port may be an attack account for brute-force cracking. The risk ports in this application are predefined before brute-force cracking recognition. The risk ports are the ports that attackers may access during brute-force cracking. The specific types of risk ports in this application are not particularly limited.
[0065] To further enhance the accuracy of the brute-force cracking recognition result in this application, after determining that the destination port is a risk port in the target server, the number of login failures of the login account within a preset time period after the current moment will also be determined. Brute-force cracking generally tries all possible passwords or accounts until successful. Therefore, during the attacker's brute-force cracking process, there will inevitably be multiple login failures. Therefore, the brute-force cracking behavior can be identified by judging the number of login failures. Moreover, the method of identifying brute-force cracking based on the number of login failures of the login account within a preset time period after the current moment in this application can more accurately reflect the current attack state of the login account compared to the commonly used method in the prior art of reading the number of failures within a preset time period before the current time, ensuring the real-time nature of the brute-force cracking recognition result.
[0066] In summary, the present invention provides a method for identifying brute-force cracking, including obtaining login data packets of each login account at the kernel layer of the target server, and further determining the number of failures when the login status of the login account within a preset time period after the current moment is a login failure when the destination port recorded in the login data packet is a risk port in the target server. When the number of failures is greater than the preset number threshold, the login account is identified as a brute-force cracking account. Obtaining the login data packet from the kernel layer can reflect the information of the login account in real time, and the method of identifying the brute-force cracking account based on the number of failures of the login account within a preset time period after the current moment is more accurate, ensuring the security of the target server.
[0067] Based on the above embodiments:
[0068] As a preferred embodiment, the login data packet further includes the transport layer protocol used by the login account to access the target server;
[0069] Before determining the number of failures when the login status of the login account within a preset time period after the current moment is a login failure, it further includes:
[0070] When it is determined that the transport layer protocol is the risk transport layer protocol corresponding to the target server, the process proceeds to determine the number of failed attempts in which the login status of the login account is a login failure within a preset time period after the current moment.
[0071] In this embodiment, in order to further ensure the accuracy of the result of identifying brute force cracking, the transport layer protocol used by the login account to access the target server is also obtained at the kernel layer of the target server. Different transport layer protocols indicate that the login account has accessed different processes in the target server. Therefore, a risk transport layer protocol is predefined in this application. The so-called risk transport layer protocol refers to the transport layer protocol that an attacker may use when performing brute force cracking. The specific type of the risk transport layer protocol in this embodiment is not particularly limited. For example, when an attacker performs brute force cracking on the target server, they usually access the process of remote control or the process of shared files. The transport layer protocol corresponding to remote access and the transport layer protocol corresponding to shared files can be used as the risk transport layer protocol.
[0072] In summary, in this embodiment, on the basis of detecting whether the destination port is a risk port in the target server, it is further detected whether the transport layer protocol is the risk transport layer protocol corresponding to the target server. Only when it is detected that the destination port is a risk port in the target server and the transport layer protocol is the risk transport layer protocol corresponding to the target server does the subsequent step of identifying brute force cracking proceed. On the one hand, the task volume of identifying brute force cracking is reduced, and on the other hand, the accuracy of the identification result of identifying brute force cracking is ensured.
[0073] As a preferred embodiment, the risk ports include:
[0074] Any one or a combination of the RDP port used for remote desktop connection in the target server, the port used for sharing files in the target server, and the port used for connecting to a shared output device in the target server.
[0075] In this embodiment, considering that an attacker generally realizes brute force cracking of the target server by means of remote desktop connection, shared files, and shared output devices such as shared printers, any one or a combination of the RDP port used for remote desktop connection in the target server, the port used for sharing files in the target server, and the port used for connecting to a shared output device in the target server is used as a risk port, further optimizing the method for identifying brute force cracking and ensuring the security of the target server.
[0076] For example, when the destination port is 3389, it indicates that the login account wants to establish a remote desktop connection with the target server. At this time, the login account is considered likely to be a brute force cracking account.
[0077] As a preferred embodiment, the login data packet further includes the source IP and source port used by the login account;
[0078] After identifying the login account as a brute-force cracking account, it further includes:
[0079] Intercept the login account with the source IP and / or source port at the kernel layer.
[0080] After identifying brute-force cracking, in order to ensure that the target server will no longer bear the brute-force cracking initiated by the attacker subsequently, in this embodiment, the source IP and source port used by the login account are also obtained at the kernel layer, and the login account that meets any one of the source IP and source port is intercepted at the kernel layer to achieve the protection of the target server.
[0081] As a preferred embodiment, after identifying the login account as a brute-force cracking account, it further includes:
[0082] Generate a prompt message for prompting the user that the target server has been brute-force cracked.
[0083] In order to timely remind the user that the target server has received brute-force cracking, in this embodiment, after identifying the login account as a brute-force cracking account, a prompt message for prompting the user that the target server has been brute-force cracked is also generated, such as sending a voice prompt or outputting a prompt message on the display device, etc. The present application does not make a special limitation on the specific type of the prompt message.
[0084] In addition, after identifying the login account as a brute-force cracking account, the five-tuple data of the login account can also be output, that is, the source IP, source port, destination IP, destination port, and transport layer protocol, so that the maintenance personnel of the target server can analyze the brute-force cracking behavior to ensure the security of the target server.
[0085] As a preferred embodiment, determining the number of failed attempts of the login account in the preset time period after the current moment as a login failure includes:
[0086] When the login status is a successful login, clear the first login failure time;
[0087] When the login status is a login failure, increment the number of login failures by one;
[0088] When it is determined that the first login failure time is not empty, subtract the first login failure time from the time when the current login status of the login account is a login failure to obtain the login duration;
[0089] When it is determined that the first login failure time is empty, record the time when the current login status of the login account is a login failure as the first login failure time, and increment the number of login failures by one;
[0090] When the login duration is less than the preset time period, enter the step of identifying the logged-in account as a brute-force cracking account when the number of failed attempts is greater than the preset number threshold;
[0091] When the login duration is greater than the preset time period, clear the first login failure time and use the time when the current login status of the logged-in account is a login failure as the first login failure time.
[0092] Please refer to Figure 2 , Figure 2 is a flowchart of another method for identifying brute-force cracking provided by the present invention. In this embodiment, the specific number of failed attempts to determine that the login status of the logged-in account is a login failure within the preset time period after the current moment is as follows: First, determine the login status of the logged-in account at the current moment. When the login status is a login success, it is considered that the logged-in account is not the account of the attacker corresponding to brute-force cracking, so the first login failure time is cleared; when the login status is a login failure, it is considered that the logged-in account may be the account corresponding to the attacker of brute-force cracking, so the number of failed login attempts is incremented by one to further confirm whether the logged-in account is a brute-force cracking account based on the total number of failed attempts within the preset time period. To determine the number of failed attempts of the logged-in account within the preset time period, it is necessary to first determine the duration of the preset time period. When the first login failure time is not empty, subtract the first login failure time from the time when the current login status of the logged-in account is a login failure to obtain the login duration. And only when the login duration is less than the preset time period, will it enter the step of identifying the logged-in account as a brute-force cracking account when the number of failed attempts is greater than the preset number threshold. When the login duration is greater than the preset time period, clear the first login failure time and use the time when the current login status of the logged-in account is a login failure as the first login failure time. When the first login failure time is empty, it indicates that the logged-in account fails to log in for the first time. Therefore, record the time when the current login status of the logged-in account is a login failure as the first login failure time, and increment the number of failed login attempts by one.
[0093] It can be seen that the method for determining the number of failed attempts to determine that the login status of the logged-in account is a login failure within the preset time period after the current moment in this embodiment is simple and accurate, and can further optimize the accuracy of the identification result of brute-force cracking.
[0094] Please refer to Figure 3 , Figure 3 is a structural schematic diagram of a brute-force cracking identification system provided by the present invention. The brute-force cracking identification system includes:
[0095] A login data packet acquisition unit 11, configured to acquire login data packets of each logged-in account at the kernel layer of the target server, where the login data packet includes the destination port accessed by the logged-in account and the login status of the logged-in account;
[0096] A failure count determination unit 12, configured to determine the number of failures when the login status of the login account is a login failure within a preset time period after the current moment when the destination port is a risk port in the target server;
[0097] An identification unit 13, configured to identify the login account as a brute - force cracking account when the number of failures is greater than a preset number threshold.
[0098] For the relevant introduction of a brute - force cracking identification system provided herein, please refer to the embodiments of the above - mentioned brute - force cracking identification method, and details will not be elaborated herein.
[0099] Based on the above - mentioned embodiments:
[0100] As a preferred embodiment, the login data packet further includes the transport layer protocol used by the login account to access the target server, and further includes:
[0101] A risk transport layer protocol determination unit, configured to trigger the failure count determination unit when it is determined that the transport layer protocol is the risk transport layer protocol corresponding to the target server.
[0102] As a preferred embodiment, the risk ports include:
[0103] Any one or a combination of multiple of the RDP port used for remote desktop connection in the target server, the port used for sharing files in the target server, and the port used for connecting to a shared output device in the target server.
[0104] As a preferred embodiment, the login data packet further includes the source IP and source port used by the login account, and further includes:
[0105] An interception unit, configured to intercept the login account with the source IP and / or source port after identifying the login account as a brute - force cracking account at the kernel layer.
[0106] As a preferred embodiment, it further includes:
[0107] A prompt unit, configured to generate a prompt message for prompting the user that the target server is under brute - force cracking after identifying the login account as a brute - force cracking account.
[0108] As a preferred embodiment, the failure count determination unit includes:
[0109] A clearing unit, configured to clear the first login failure time when the destination port is a risk port in the target server and the login status is a login success;
[0110] A counting unit, configured to increment the number of login failures by one when the login status is a login failure;
[0111] A login duration determination unit, configured to, when determining that the first login failure time is not empty, obtain the login duration by subtracting the first login failure time from the time when the current login status of the login account is a login failure;
[0112] A first login failure time determination unit, configured to, when determining that the first login failure time is empty, record the time when the current login status of the login account is a login failure as the first login failure time, and increment the number of login failures by one;
[0113] A trigger unit, configured to trigger the recognition unit 13 when the login duration is less than a preset time period;
[0114] A first login failure time update unit, configured to, when the login duration is greater than the preset time period, clear the first login failure time and use the time when the current login status of the login account is a login failure as the first login failure time.
[0115] Please refer to Figure 4 , Figure 4 , which is a schematic structural diagram of an identification device for brute-force cracking provided by the present invention. The identification device for brute-force cracking includes:
[0116] A memory 21, configured to store a computer program;
[0117] A processor 22, configured to implement the steps of the above-mentioned brute-force cracking identification method when executing the computer program.
[0118] For the relevant introduction of an identification device for brute-force cracking provided by the present application, please refer to the above-mentioned embodiments of the brute-force cracking identification. The present application will not elaborate herein.
[0119] The present application further provides a server, including the above-mentioned identification device for brute-force cracking.
[0120] For the relevant introduction of a server provided by the present application, please refer to the above-mentioned embodiments of the brute-force cracking identification method. Details will not be repeated herein.
[0121] The present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned brute-force cracking identification method are implemented.
[0122] For the relevant introduction of a computer-readable storage medium provided by the present application, please refer to the above-mentioned embodiments of the brute-force cracking identification method. Details will not be repeated herein.
[0123] It can be understood that if the methods in the above embodiments are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the present application, in essence, or the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.
[0124] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.
[0125] It should also be noted that in this specification, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the said element.
[0126] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for identifying brute-force cracking, characterized in that, Including: Obtaining login data packets of each logged-in account at the kernel layer of the target server, where the login data packet includes the destination port accessed by the logged-in account and the login status of the logged-in account; the login status is determined by the code identification code in the login data packet; When the destination port is a risk port in the target server, determining the number of failed attempts where the login status of the logged-in account is a login failure within a preset time period after the current moment; When the number of failed attempts is greater than a preset number threshold, identifying the logged-in account as a brute-force cracking account; And, the login data packet further includes the transport layer protocol used by the logged-in account to access the target server; Correspondingly, before determining the number of failed attempts where the login status of the logged-in account is a login failure within a preset time period after the current moment, it further includes: When it is determined that the transport layer protocol is the risk transport layer protocol corresponding to the target server, entering the step of determining the number of failed attempts where the login status of the logged-in account is a login failure within a preset time period after the current moment.
2. The method for identifying brute-force cracking according to claim 1, characterized in that, The risk ports include: Any one or a combination of the RDP port for remote desktop connection in the target server, the port for sharing files in the target server, and the port for connecting to a shared output device in the target server.
3. The method for identifying brute-force cracking according to claim 1, characterized in that, The login data packet further includes the source IP and source port used by the logged-in account; After identifying the logged-in account as a brute-force cracking account, it further includes: Intercepting, at the kernel layer, the logged-in account with the source IP and / or source port.
4. The method for identifying brute-force cracking according to claim 3, characterized in that, After identifying the logged-in account as a brute-force cracking account, it further includes: Generating a prompt message for prompting the user that the target server has been brute-force cracked.
5. The method for identifying brute-force cracking according to any one of claims 1 to 4, characterized in that, Determining the number of failed attempts where the login status of the logged-in account is a login failure within a preset time period after the current moment includes: When the login status is a login success, clearing the first login failure time; When the login status is a login failure, incrementing the number of login failures by one; When it is determined that the first login failure time is not empty, subtracting the first login failure time from the time when the current login status of the logged-in account is a login failure to obtain the login duration; When it is determined that the first login failure time is empty, recording the time when the current login status of the logged-in account is a login failure as the first login failure time and incrementing the number of login failures by one; When the login duration is less than the preset time period, entering the step of identifying the logged-in account as a brute-force cracking account when the number of failed attempts is greater than the preset number threshold; When the login duration is greater than the preset time period, clearing the first login failure time and using the time when the current login status of the logged-in account is a login failure as the first login failure time.
6. A system for identifying brute-force cracking, characterized in that, Including: A login data packet acquisition unit, configured to acquire login data packets of each login account at the kernel layer of a target server, where the login data packets include the destination ports accessed by the login accounts and the login statuses of the login accounts; the login status is determined by a code identification code in the login data packet; A failure times determination unit, configured to determine the number of times of login failure of the login account within a preset time period after the current moment when the destination port is a risk port in the target server; An identification unit, configured to identify the login account as a brute-force cracking account when the number of failure times is greater than a preset number threshold; Moreover, the login data packet further includes the transport layer protocol used by the login account to access the target server; Correspondingly, the brute-force cracking identification system further includes: A risk transport layer protocol determination unit, configured to trigger the failure times determination unit when it is determined that the transport layer protocol is the risk transport layer protocol corresponding to the target server.
7. A device for identifying brute-force cracking, characterized in that, Comprising: A memory, configured to store a computer program; A processor, configured to implement the steps of the brute-force cracking identification method according to any one of claims 1 to 5 when executing the computer program.
8. A server, characterized in that,Comprising the brute-force cracking identification device according to claim 7.
9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the brute-force cracking identification method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
A method and a system for determining TCP performance parameters
CN109842511A
Method and device for recognizing and intercepting brute force cracking behavior
CN113110980A