Web Honeypot Emulation Method, Device, Computer Equipment and Readable Storage Medium
By classifying requests and returning tailored responses using a database and renderer, the method enhances web honeypot simulation, consuming attacker resources and improving information capture.
Patent Information
- Application Number
- CN202211114811.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-14
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-09-14
AI Technical Summary
Traditional web honeypot technology has a low degree of simulation, and the attacker has doubts about the authenticity of the web website, it is difficult to consume attack resources and delay time, and it is difficult to capture useful attacker information.
By obtaining pending requests, distinguishing between static resource requests and dynamic resource requests, and returning corresponding static or dynamic response information based on the request type, the renderer generates dynamic response information, and simulating the response method in the real environment.
It improves the authenticity of the honeypot, consumes more resources of the attacking party and delays time, increases the probability of capturing effective attack information, and provides an effective reference for the research and defense of cyber attack behavior.
Smart Images

Figure CN115499192B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of honeypot emulation technology, and particularly to a web honeypot emulation method, device, computer device, and readable storage medium. Background Art
[0002] With the rapid development of Internet technology, network attacks and network defense technologies against network attacks are also constantly evolving, and the honeypot technology applied in network defense technologies has emerged accordingly. The network honeypot technology lures the attacker into attacking the host, network service, or information arranged as bait, so that the attack behavior can be captured and analyzed, the tools and methods used by the attacker can be understood, and the attack intention and motivation can be speculated. The network honeypot technology enables the defense party to clearly understand the security threats they face and enhance the security protection ability of the real system through technical and management means.
[0003] However, the emulation degree of traditional network honeypot technology, especially web honeypot technology, is relatively low. When the attacker browses the web page and views the content of the interface request response, they will doubt the authenticity of the web site, which greatly reduces the role of the honeypot in continuously consuming attack resources and delaying the attack time, and it is also difficult to capture useful attacker information. Therefore, there is an urgent need for a technology in the traditional technology that can improve the emulation degree of web honeypots. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a web honeypot emulation method, device, computer device, and readable storage medium that can improve the emulation degree of web honeypots.
[0005] In a first aspect, this application provides a web honeypot emulation method. The method includes:
[0006] Obtain a request to be processed;
[0007] Determine a static resource request and a dynamic resource request based on the request to be processed;
[0008] Return static response information based on the static resource request, where the static response information is stored in a database;
[0009] Input the dynamic resource request into a renderer to obtain dynamic response information and return it.
[0010] In one embodiment, the determining a static resource request and a dynamic resource request based on the request to be processed includes:
[0011] Match the request to be processed with a preset request;
[0012] If the match is successful, it is determined whether there is a renderer corresponding to the to-be-processed request;
[0013] If there is, it is determined that the to-be-processed request is a dynamic resource request;
[0014] If not, it is determined that the to-be-processed request is a static resource request.
[0015] In one embodiment, before returning the static response information based on the static resource request, it further includes:
[0016] Sending a preset request to the target website to obtain the static response information returned based on the preset request;
[0017] Storing the static response information in the database.
[0018] In one embodiment, returning the static response information based on the static resource request includes:
[0019] Determining the response information path based on the static resource request;
[0020] Obtaining the corresponding static response information from the database based on the response information path and returning it.
[0021] In one embodiment, before inputting the dynamic resource request into the renderer, it includes:
[0022] Inputting the routing address information in the preset request into a routing feature matching model to obtain a dynamic request route, and the routing feature matching model is obtained through machine learning training;
[0023] Configuring a renderer for the dynamic request route, and the renderer is used to generate dynamic response information.
[0024] In one embodiment, after obtaining the to-be-processed request, it includes:
[0025] Obtaining the routing address information in the to-be-processed request and storing it.
[0026] In one embodiment, returning the static response information based on the static resource request and the response information path includes:
[0027] If the to-be-processed request does not match the preset request, an error status information and an error static response information are returned;
[0028] Or;
[0029] Returning the static response information based on the static resource request and the response information path.
[0030] In a second aspect, the present application further provides a web honeypot emulation device, which includes:
[0031] A request acquisition module, configured to acquire a request to be processed;
[0032] A request processing module, configured to determine a static resource request and a dynamic resource request based on the request to be processed;
[0033] A static request response module, configured to return static response information based on the static resource request, where the static response information is stored in a database;
[0034] A dynamic request response module, configured to input the dynamic resource request into a renderer, obtain dynamic response information and return it.
[0035] In a third aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the method according to any one of the above first aspects are implemented.
[0036] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method according to any one of the above first aspects are implemented.
[0037] For the above web honeypot emulation method, device, computer device and readable storage medium, by acquiring a request to be processed, determining a static resource request and a dynamic resource request based on the request to be processed, acquiring the request to be processed; determining a static resource request and a dynamic resource request based on the request to be processed; returning static response information based on the static resource request, where the static response information is stored in a database; inputting the dynamic resource request into a renderer, obtaining dynamic response information and returning it. The web honeypot emulation method provided by the embodiments of the present application classifies the request to be processed into a static resource request or a dynamic resource request, and returns corresponding static response information or dynamic response information for different request types, and can return different response information for different requests of the attacker, effectively improving the authenticity of the honeypot. On the other hand, for dynamic resource requests that require information verification such as login and registration, the dynamic response information can also simulate the response method in a real environment, further improving the emulation degree of the web honeypot. By improving the emulation degree of the web honeypot, the embodiments of the present application can consume more resources of the attacker and delay the attacker for more time, thereby increasing the probability of capturing more effective attack information and providing an effective reference for the research and defense of network attack behaviors.
[0038] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. Brief Description of the Drawings
[0039] The drawings described herein are provided to further understand the present application and form a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0040] Figure 1 It is an application environment diagram of the web honeypot emulation method in an embodiment;
[0041] Figure 2 It is a flowchart of the web honeypot emulation method in an embodiment;
[0042] Figure 3 It is a flowchart of the web honeypot emulation preprocessing work in an embodiment;
[0043] Figure 4 It is a flowchart of the web honeypot emulation processing request in an embodiment;
[0044] Figure 5 It is a structural block diagram of the web honeypot emulation device in an embodiment. Detailed Description of the Embodiments
[0045] In order to make the purpose, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0046] Unless otherwise defined, technical terms or scientific terms involved in this application shall have the ordinary meanings understood by those with ordinary skills in the technical field to which this application belongs. In this application, words such as "a", "an", "one kind", "the", "these", etc. do not indicate a limitation in quantity, and they can be singular or plural. Terms such as "include", "comprise", "have" and any variants thereof involved in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device that includes a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products or devices. Words such as "connect", "be connected", "couple" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The term "plurality" involved in this application means two or more. "And / or" describes the relationship between associated objects and indicates that three relationships may exist. For example, "A and / or B" may represent: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " indicates that the objects associated before and after are in an "or" relationship. Terms such as "first", "second", "third", etc. involved in this application are only used to distinguish similar objects and do not represent a specific order for the objects.
[0047] As used hereinafter, terms such as "module", "unit", etc. are combinations of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in hardware, implementation in software, or a combination of software and hardware, is also possible and contemplated.
[0048] The web honeypot emulation method provided by the embodiments of this application can be applied to, for example Figure 1In the application environment shown. Among them, the web honeypot emulation system 100 includes a server 101, a database 102, and a renderer 103. Among them, the server 101 can be implemented by an independent server or a server cluster composed of multiple servers. The database 102 can store the static response information that the server 101 needs to return. The database 102 can be integrated on the server 101, or can be set on the cloud or other network servers. The renderer 103 is used to generate dynamic response information. When the client 104 sends a request to be processed to the web honeypot emulation system, the server 101 obtains the request to be processed and determines a static resource request and a dynamic resource request based on the request to be processed. Further, the server 101 sends the static resource request to the database 102 and obtains the static response information, and sends the dynamic resource request to the renderer 103 and obtains the dynamic response information. Subsequently, the server 101 returns the response information to the client 104, and the response information includes static response information and / or dynamic response information.
[0049] In the embodiment of the present application, as Figure 2 shown, a web honeypot emulation method is provided. Taking the application environment in Figure 1 as an example, the method includes the following steps:
[0050] S201: Obtain a request to be processed.
[0051] In the embodiment of the present application, the request to be processed includes resource request information received by the web side (World Wide Web, that is, the global wide area network). The resource request information includes routing address information, request parameter information, and request method information. Among them, the routing address information may include the routing address information of the requestor, or may include the routing address information of the requested party associated with the request information to be processed. The request parameters may include timestamp information and random parameter information. In other embodiments, the request parameters may further include request body information. The request method information may include get requests, head requests, post requests, etc. In the embodiment of the present application, when the client sends resource request information to the web server, the web side can obtain the resource request information as the request to be processed.
[0052] S203: Determine a static resource request and a dynamic resource request based on the request to be processed.
[0053] In the embodiments of the present application, the static resource request includes a to-be-processed request for the web end to return static resources. Among them, the static resources include information such as HTML (Hyper Text Markup Language), CSS (Cascading Style Sheets), JS (JavaScript, the scripting language of web pages), and pictures. The dynamic resource request includes a to-be-processed request for the web end to return dynamic resources. Among them, the dynamic resources may include resource information that needs to be verified. The dynamic resource request may include request information such as login requests, verification code requests, and registration requests.
[0054] In the embodiments of the present application, static resource requests and dynamic resource requests can be determined based on the request parameters in the to-be-processed request. In some embodiments, when the request parameters include mapping information pointing to static resources, the to-be-processed request can be determined as a static resource request. On the other hand, when the request parameters include verification information, such as login mobile phone numbers, verification codes, login passwords, etc., the to-be-processed request can be determined as a dynamic resource request. In other embodiments, static resource requests and dynamic resource requests can also be determined based on the routing address information in the to-be-processed request. In the routing address information, if the route corresponding to the routing address information of the requested end is set to only return static response information, the to-be-processed request can be determined as a static resource request. Conversely, if the route corresponding to the routing address information of the requested end is set to only return dynamic response information, the to-be-processed request can be determined as a dynamic resource request. It can be understood that the to-be-processed request may include a static resource request and / or a dynamic resource request.
[0055] S205: Return static response information based on the static resource request, and the static response information is stored in the database.
[0056] In the embodiments of the present application, the static response information includes the static resources requested to be obtained in the static resource request, and the static response information is stored in the database. In some embodiments, the static response information can be stored in the same database, and when the static response information needs to be returned, it can be directly called and returned from the database. In some other embodiments, the static resources can also be stored in any database in the form of independent files, and their storage paths are saved as the static response information paths in the database that can be called by the web honeypot. When the static response information needs to be returned, the static response information path can be called to obtain and return from the corresponding storage location. In other embodiments, returning the static response information does not require program processing, and a display page can be directly returned to the static resource request.
[0057] S207: Input the dynamic resource request into a renderer to obtain dynamic response information and return it.
[0058] In the embodiments of the present application, if it is determined that the request to be processed is a dynamic resource request, the dynamic resource request is input into a renderer to obtain dynamic response information and return it. Among them, the renderer can generate dynamic response information based on the dynamic resource request. Specifically, in some embodiments, identity information, verification code information, etc. that need to be verified are input into the renderer. Based on the matching result with preset information, the renderer can generate response results such as successful matching and failed matching, and render them into pages such as successful login, failed login, or failed verification as dynamic response information. In other embodiments, the renderer can also generate a random verification code based on the dynamic resource request to further improve the simulation degree of the web honeypot. The server side returns the dynamic response information generated by the renderer, simulating the response method in a real request scenario. Compared with the traditional technology that can only return static response information, the simulation degree of the web honeypot is significantly improved.
[0059] The web honeypot simulation method provided by the embodiments of the present application classifies the request to be processed into a static resource request or a dynamic resource request, and returns corresponding static response information or dynamic response information for different request types, and can return different response information for different requests of the client, effectively improving the authenticity of the web honeypot. On the other hand, for dynamic resource requests that require information verification such as login and registration, the dynamic response information can also simulate the response method in a real environment, further improving the simulation degree of the web honeypot. By improving the simulation degree of the web honeypot, the embodiments of the present application can consume more resources of the attacker and delay the attacker for more time, thereby increasing the probability of capturing more effective attack information and providing an effective reference for the research and defense of network attack behaviors.
[0060] To simulate the response to request information in a real environment, the embodiments of the present application will return different corresponding results for different request types. Therefore, it is necessary to determine the type of the request to be processed. In step S203, the determining the static resource request and the dynamic resource request based on the request to be processed includes:
[0061] S301: Match the request to be processed with a preset request.
[0062] S303: If the match is successful, determine whether there is a renderer corresponding to the request to be processed.
[0063] S305: If there is, determine that the request to be processed is a dynamic resource request.
[0064] S307: If there is no renderer, determine that the request to be processed is a static resource request.
[0065] In the embodiments of the present application, the preset request includes request information sent to a target website. Wherein, the target website is a real website to be simulated, and the resource response information includes static response information or dynamic response information. In some embodiments, the resource response information can be obtained from the target website by means such as a crawler. The crawler can simulate user requests by means of a headless browser, etc. The crawler sends a request to the target website by simulating real request information, and obtains the returned resource response information from the target website. Then, the real request information simulated by the crawler can be used as the preset request, and the returned resource response information is correspondingly set as dynamic response information or static response information according to the type of the request.
[0066] In the embodiments of the present application, the to-be-processed request is matched with the preset request. If the match is successful, it indicates that the web honeypot has obtained the response information corresponding to the to-be-processed request. Further, it is determined whether there is a renderer corresponding to the to-be-processed request. When building the web honeypot in the embodiments of the present application, a corresponding renderer is set based on the dynamic resource request in the preset request to implement the return of dynamic response information. Therefore, it can be understood that if there is a renderer corresponding to the to-be-processed request, it can be determined that the to-be-processed request is a dynamic resource request, and vice versa, if not, it can be determined that the to-be-processed request is a static resource request. In some other embodiments, if the to-be-processed request does not match the preset request, the to-be-processed request is determined as an error request, and status codes such as 404 or 405 and corresponding static response information can be returned based on the to-be-processed request.
[0067] In the embodiments of the present application, based on the match with the preset request, it can be quickly determined whether the to-be-processed request can obtain resource response information from the web honeypot, and then based on whether there is a corresponding renderer, the type of the to-be-processed request can be further determined. On the one hand, it provides support for returning different resource response information for different request types, improving the authenticity of the web honeypot; on the other hand, by quickly determining the type of the to-be-processed request, the response speed of the web honeypot is improved, and the probability of capturing more effective attack information is increased.
[0068] To improve the simulation degree of the target website, before step S205 in the embodiments of the present application, that is, before returning the static response information based on the static resource request, it further includes:
[0069] S401: Send a preset request to the target website, and obtain the static response information returned based on the preset request.
[0070] S403: Store the static response information in a database.
[0071] In the embodiments of the present application, after sending a preset request to the target website, if the preset request is a static resource request, the static response information returned by the target website can be obtained. The static response information includes information such as HTML, CSS, JS, and pictures. In other embodiments, if the target website cannot respond to the preset request, an error status code and corresponding error response information will be returned. Specifically, if the routing address in the preset request is not found, a 404 status code and corresponding error response information may be returned; if the request method in the preset request is not matched, a 405 status code and corresponding error response information may be returned. It can be understood that although most websites may return an error status code and corresponding error response information during the response process, the return forms of different websites are not the same. For example, the fonts, font sizes, and colors of the returned 404 and 405 may be different. Therefore, in order to simulate the target website, it is necessary to obtain the error status code and corresponding error response information of the target website. After obtaining the static response information, it is stored in the database for subsequent use when responding to pending requests.
[0072] In the embodiments of the present application, by obtaining the real static response information returned by the target website through a preset request and storing it in the database, a mapping relationship between the real request and the real response can be established. Based on this, the web honeypot established has a high degree of authenticity. When the web honeypot receives a static resource request sent by the client, it can simulate the static response information of the target website in the real environment, effectively improving the simulation effect.
[0073] If the response speed of the real website environment is fast, improving the speed at which the web honeypot returns the response static resources can further improve the simulation degree. In the embodiments of the present application, in step S205, the returning of the static response information based on the static resource request includes:
[0074] S501: Determine the response information path based on the static resource request.
[0075] S503: Obtain the corresponding static response information from the database based on the response information path and return it.
[0076] In the embodiments of the present application, the static resources can be stored either in the database where the web honeypot calls the preset request and response information, or at any location independent of the database, or in other service environments or websites. After the storage location of the static resources is determined, the corresponding static resources to be returned can be determined based on the static resource request, and then the storage path of the static resources can be used as the response information path. When the web honeypot receives a static resource request, the corresponding static response information can be obtained from the database based on the response information path and returned. Specifically, in some embodiments, the static resources can be separately stored in files in multiple levels of directories according to the hash algorithm to avoid conflicts caused by duplicate response information paths. Correspondingly, the preset request and the response information path can be stored in the database and a mapping relationship can be established, and the storage path of the static resources stored in the file can be used as the response information path. In other embodiments, if the static resources requested by the static resource request are stored in a local file, the local file address can be used as the response information path. In still other embodiments, if the static resources are stored in other service environments, the remote URL address can be used as the response information path.
[0077] In the embodiments of the present application, by storing the static resources in independent files, the call and return of the static resources can be realized only by storing the response information path in the database, avoiding the reduction of the throughput speed due to the storage of a large number of static resources in the database, releasing the resources of the database where the web honeypot calls the preset request and response information, improving the response speed of the database, and enhancing the emulation degree of the web honeypot to a certain extent. On the other hand, the static resources can also be stored in an external environment, and the remote URL address can be used as the response information path to further release the local resources and improve the system operation speed.
[0078] In the embodiments of the present application, the returning of the static response information based on the static resource request includes:
[0079] S601: If the to-be-processed request does not match the preset request successfully, an error status information and an error static response information are returned;
[0080] Or;
[0081] S603: A static response information is returned based on the static resource request and the response information path.
[0082] In the embodiments of the present application, the error status information includes an error status code. In some embodiments, if the pending request does not match the preset request successfully and the routing address information in the pending request is not found, a 404 status code is returned as the error status information, and the corresponding static response information is returned based on the response information path of the 404 status code. In other embodiments, if the pending request does not match the preset request successfully, the routing address information in the pending request exists, but the request method does not match successfully, a 405 status code is returned as the error status information, and the static response information corresponding to the response information path of the 405 status code is returned.
[0083] In other embodiments, if it is determined that the pending request is a static resource request, the static response information can be returned according to the method described in step S503 above. In other embodiments, the static resource to be returned can also be determined based on the static resource request and the response information path, and after simulating the static resource to be returned, it is returned as the static response information. Among them, the simulation process may include simulating the response header or response body in the response information. In some specific embodiments, the domain name / IP address in the response body can be changed to a relative path to avoid the situation of jumping to a real website during the process of using its content as response information. The fields such as Date, Content-Length, and Content-Encoding in the response header can also be removed. Because the values of some response header fields will reduce the authenticity of the response and may also cause errors when returned as response information later.
[0084] In the embodiments of the present application, the simulation process for the returned static response information can simulate the response process of the static resource request in the real scenario, effectively improving the authenticity when returning the static response information.
[0085] In the traditional technology, when a web honeypot receives information that needs to be verified, such as a login account, a login password, a verification code, etc., static resources are returned as the response information, which greatly reduces the authenticity of the web honeypot and it is difficult to obtain effective attack information from the attacking end. Based on this, before step S207 in the embodiments of the present application, that is, before inputting the dynamic resource request into the renderer, it includes:
[0086] S701: Input the routing address information in the preset request into a routing feature matching model to obtain a dynamic request route, and the routing feature matching model is obtained through machine learning training.
[0087] S703: Configure a renderer for the dynamic request route, and the renderer is used to generate dynamic response information.
[0088] In the embodiments of the present application, in order to return dynamic response information for a dynamic resource request, it is necessary to determine the common routing address information in the dynamic resource request. Inputting the routing address information in the preset request into a routing feature matching model can obtain a dynamic request route. Among them, the routing feature matching model may include a computing engine for big data processing, or may be a model component trained by machine learning, or may also be a combination of multiple models or computing engines. The present application does not limit this. Among them, the machine learning method may include deep learning methods, reinforcement learning methods, etc. The generated model components may include convolutional neural network model components (Convolutional Neural Networks, CNN), recurrent neural network model components (Recurrent Neural Network, RNN), LeNet, ResNet, long short-term memory network model components (Long Short-Term Memory, LSTM), bidirectional long short-term memory network model components (Bi-LSTM), etc. The present application does not limit this here. The routing feature matching model obtained by machine learning can match common routing features according to the input routing address information to obtain a route for responding to dynamic requests.
[0089] In the embodiments of the present application, after obtaining the dynamic request route, a renderer can be configured for the dynamic request route, and the renderer is used to generate dynamic response information. The renderer can implement functions such as verifying login accounts, passwords, etc., and can also implement functions such as returning random verification codes and performing routing permission restrictions. In a specific embodiment, if the dynamic request route address obtained by the routing feature matching model is / login, a renderer can be configured to render LoginRender(“username”=”name”,“password”=”test1234”). When the dynamic resource requests this route address, the account password will be matched, and different response results will be returned according to whether the match is successful, such as dynamic response information such as “login failed”, “login successful”, “verification failed” after rendering. At the same time, the account password can be stored in cookies and other information to update the login status, realizing the permission control of the routing address. In some other embodiments, the renderer can also be configured for the preset route manually.
[0090] In the embodiments of the present application, by training the routing feature matching model to determine the general feature route in the dynamic resource request and configuring a renderer for the route, when the web honeypot receives different dynamic resource requests, it can verify the dynamic resource requests and return different dynamic response information, greatly simulating the response method for dynamic resource requests in a real website, and effectively improving the simulation degree of the web honeypot.
[0091] When attacking the web honeypot at the attacking end, the attack information can be collected for subsequent processing or analysis of the attack behavior. In the embodiment of the present application, after step S201, that is, after obtaining the request to be processed, it includes:
[0092] S801: Obtain the routing address information in the request to be processed and store it.
[0093] In the embodiment of the present application, after obtaining the request to be processed, the routing address information therein can be obtained and stored. Among them, the routing address information may include the routing address information of the requestor or the routing address information of the requested web end. In some embodiments, the routing corresponding to the request to be processed can be determined based on the routing address information, and then the verification information submitted via the routing is stored as possible attack information to provide a reference for subsequent analysis of the attack behavior. The verification information may include information such as the login address, registration form information, mobile phone number, login password, etc. In a specific embodiment, a routing configurator can be configured for the routing address information. When the form information associated with the request to be processed is submitted via the routing, the field content of the form submission is recorded and stored. In some embodiments, a form routing matching model can be trained by machine learning to identify the characteristics of common form routings. By inputting a preset request into the form routing matching model, the associated routing of the request to be processed can be obtained, and the routing address information can be obtained based on the associated routing.
[0094] In the embodiment of the present application, by obtaining and storing the routing address information in the request to be processed, the possible attack information can be recorded and stored, providing a basis and foundation for subsequent analysis of the attack behavior. On the other hand, by obtaining the routing address information in the request to be processed and then determining the routing, the attack information can be quickly screened and obtained to avoid confusion in a large amount of request data.
[0095] In other embodiments of the present application, after obtaining the request to be processed, the request parameters in the request to be processed can also be ignored. In some embodiments, the request parameters in the request to be processed may include timestamp parameters or random parameters, such as t = 1647331324, _n = 244444, etc. These request parameters may cause interference when matching the parameters of the request to be processed. For example, different timestamps or random parameters may be considered to map to different response information. In the embodiment of the present application, a parameter processing model can be trained by machine learning to process the request parameters into wildcard parameters, and the wildcard parameters can make all timestamp or random parameters map to the response information corresponding to the request to be processed. By inputting the request to be processed into the parameter processing model, a wildcard request to be processed can be obtained.
[0096] The following is a specific example to illustrate the preprocessing work before obtaining the pending request. Figure 3 As shown, the target website-related resource information can be obtained by crawling the target website's static resource information or dynamic resource information. The obtained resource information is processed and stored, and the static resources can be stored in a database, or the static resources can be stored independently and the storage path can be stored in a database. For a special route configuration processor, it can include determining a commonly used dynamic route based on a dynamic resource request, and configuring a renderer that responds to the dynamic mobilization to return dynamic response information. After the preprocessing work is completed, the simulation service program of the web honeypot is started to respond to the pending requests that may be received.
[0097] In a specific embodiment, the web honeypot processes the received request to be processed as follows: Figure 4 As shown, the client initiates a request, the web honeypot receives the pending request, and matches the database record. If the pending request matches the preset request successfully, the processor runs and determines the static resource request and the dynamic resource request based on the pending request. The server returns static response information based on the static resource request, and / or inputs the dynamic resource request into the renderer, obtains dynamic response information and returns it. On the other hand, if the pending request does not match the preset request successfully, the server returns an error page response, and the error page response includes an error status code such as 404 or 405 and the static response information corresponding to the status code.
[0098] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0099] Based on the same inventive concept, an embodiment of the present application further provides a web honeypot simulation device 900 for implementing the web honeypot simulation method involved above. The solution provided by this device for solving problems is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the web honeypot simulation device 900 provided below can refer to the limitations on the web honeypot simulation method in the above text, and will not be repeated here.
[0100] In one embodiment, as Figure 5 shown, a web honeypot simulation device 900 is provided, including:
[0101] A request acquisition module 901, configured to acquire a request to be processed;
[0102] A request processing module 902, configured to determine a static resource request and a dynamic resource request based on the request to be processed;
[0103] A static request response module 903, configured to return static response information based on the static resource request, and the static response information is stored in a database;
[0104] A dynamic request response module 904, configured to input the dynamic resource request into a renderer, obtain dynamic response information and return it.
[0105] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the method described in any one of the above are implemented.
[0106] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. It is characterized in that when the computer program is executed by a processor, the steps of the method described in any one of the above are implemented.
[0107] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data that have been authorized by the user or fully authorized by all parties.
[0108] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0109] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0110] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A web honeypot emulation method, characterized in that, The method includes: Obtain a request to be processed; Determine a static resource request and a dynamic resource request based on the request to be processed; Return static response information based on the static resource request, where the static response information is stored in a database; Input the dynamic resource request into a renderer to obtain and return dynamic response information; Wherein, the determining the static resource request and the dynamic resource request based on the request to be processed includes: Match the request to be processed with a preset request; If the match is successful, determine whether there is a renderer corresponding to the request to be processed; If there is, determine the request to be processed as a dynamic resource request; If not, determine the request to be processed as a static resource request.
2. The method according to claim 1, characterized in that, Before returning the static response information based on the static resource request, it further includes: Send a preset request to a target website to obtain static response information returned based on the preset request; Store the static response information in the database.
3. The method according to claim 1, characterized in that The returning the static response information based on the static resource request includes: Determine a response information path based on the static resource request; Obtain and return the corresponding static response information from the database based on the response information path.
4. The method according to claim 1, wherein Before inputting the dynamic resource request into the renderer, it includes: Input the routing address information in the preset request into a routing feature matching model to obtain a dynamic request route, where the routing feature matching model is obtained through machine learning training; Configure a renderer for the dynamic request route, where the renderer is used to generate dynamic response information.
5. The method according to claim 1, wherein After obtaining the request to be processed, it includes: Obtain the routing address information in the request to be processed and store it.
6. The method according to claim 3, wherein The returning the static response information based on the static resource request includes: If the request to be processed does not match the preset request, return an error status information and an error static response information; Or; Return static response information based on the static resource request and the response information path.
7. A web honeypot simulation device, characterized in that The device includes: A request obtaining module, configured to obtain a request to be processed; A request processing module, configured to determine a static resource request and a dynamic resource request based on the request to be processed; wherein, the determining the static resource request and the dynamic resource request based on the request to be processed includes: matching the request to be processed with a preset request; if the match is successful, determine whether there is a renderer corresponding to the request to be processed; if there is, determine the request to be processed as a dynamic resource request; if not, determine the request to be processed as a static resource request; A static request response module, configured to return static response information based on the static resource request, where the static response information is stored in a database; A dynamic request response module, configured to input the dynamic resource request into a renderer to obtain and return dynamic response information.
8. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Anti-crawler method, device and equipment and computer storage medium
CN115037526A