Attack countermeasure method and system

By obtaining data through browsers and advanced keyboard loggers to generate attacker portraits, and analyzing and generating countermeasures, the problem of difficulty in determining the identity of attackers in Web site attacks is solved, and precise attack countermeasures and site security are achieved.

CN115514535BActive Publication Date: 2025-09-30BEIJING HUASHUN XIN AN TECH CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211066097.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-01
Publication Date
2025-09-30
Estimated Expiration
2042-09-01

AI Technical Summary

Technical Problem

In existing technologies, it is difficult to determine the attacker's identity, attack time, and attack behavior in attacks against websites, resulting in low attack countermeasure accuracy and affecting website security.

Method used

The attacker's identity information and attack time are obtained through the browser, and the attack behavior information is obtained by combining with a high-level keyboard logger to generate an attacker portrait. Based on the portrait analysis, a countermeasure strategy is generated to counter the attack.

Benefits of technology

It improves the accuracy of attack countermeasures, ensures the security of websites, and can accurately locate attackers from multiple dimensions and take effective countermeasures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115514535B_ABST
    Figure CN115514535B_ABST
Patent Text Reader

Abstract

The present invention relates to an attack countermeasure method and system, belonging to the technical field of network security. The method comprises: obtaining first data from a browser based on an attacker identification; the first data includes the attacker's identity information and the time of the attack; obtaining second data from a high-level keylogger based on the attacker identification; the second data includes attack behavior information generated by the attacker in a cloned business system; generating an attacker profile based on the first data and the second data; analyzing the attacker profile, generating a countermeasure strategy, and initiating a countermeasure against the attacker based on the countermeasure strategy. The present invention generates a countermeasure strategy by analyzing the attacker profile including user identity information, attack time, and attack behavior information, thereby countering the attacker's attack, improving the accuracy of the attack countermeasure and ensuring the security of the website.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to an attack countermeasure method and system. Background Art

[0002] With the rapid development of Internet systems, network attacks have become increasingly rampant. Correspondingly, network protection capabilities have been continuously improved, gradually evolving from passive defense to active defense, and then to attack counterattack.

[0003] In attacks against websites, hackers launch attacks through browsers. Since it is difficult to simultaneously determine the identity of the attacker, the time of the attack, the attack behavior, and other information, the accuracy of attack countermeasures using traditional methods is low, which seriously affects the security of the website. Summary of the Invention

[0004] In order to improve the accuracy of attack countermeasures, in a first aspect, the present invention provides an attack countermeasure method, which adopts the following technical solutions:

[0005] An attack countermeasure method, comprising:

[0006] Based on the attacker identifier, first data is obtained from the browser; the first data includes the attacker's identity information and the attack time;

[0007] Based on the attacker identifier, second data is obtained from the advanced keyboard logger; the second data is attack behavior information generated by the attacker in the cloned business system;

[0008] generating an attacker profile based on the first data and the second data;

[0009] The attacker profile is analyzed to generate a countermeasure strategy, and a countermeasure is launched against the attacker based on the countermeasure strategy.

[0010] By adopting the above technical solution, the first data representing the attacker's identity information and attack time is obtained through the browser, and the second data representing the attack behavior information generated by the attacker in the cloned business system is obtained through the high-level keyboard recorder. The attacker portrait is generated based on the first data and the second data, and then a countermeasure strategy is generated by analyzing the attacker portrait to counter the attacker's attack, thereby improving the accuracy of the attack countermeasure and ensuring the security of the website.

[0011] Optionally, the attacker identity information includes username, password, attacker IP, operating system and device type.

[0012] By adopting the above technical solution, the attacker's identity information can be characterized from multiple dimensions, so that the attacker can be accurately located from multiple dimensions, further improving the accuracy of attack countermeasures.

[0013] Optionally, the cloned business system is a preset virtual system corresponding to a real website.

[0014] By adopting the above technical solution, while protecting the real website from attacks, the attacker's attack behavior information is collected based on the cloned business system, and then the attacker is accurately countered.

[0015] Optionally, analyzing the attacker profile and generating a countermeasure strategy specifically includes:

[0016] Analyze the attacker profile to generate an attack frequency, and generate a first attack weight based on the attack frequency;

[0017] Analyzing the attacker profile to generate an attack intensity level, and generating a second attack weight based on the attack intensity level;

[0018] A countermeasure strategy is generated based on the first attack weight, the second attack weight, and the attacker profile.

[0019] By adopting the above technical solution, corresponding countermeasure strategies are generated according to the attack weight and attacker profile, which helps to improve the accuracy of attack countermeasures and ensure the security of the website.

[0020] Optionally, generating a countermeasure strategy based on the first attack weight, the second attack weight, and the attacker profile specifically includes:

[0021] Determining a counterattack strength level according to the first attack weight and the second attack weight;

[0022] The countermeasure strategy is generated according to the countermeasure strength level and the attacker profile.

[0023] By adopting the above technical solution, corresponding countermeasure strategies are generated according to the countermeasure intensity level and attacker profile, which helps to improve the accuracy of attack countermeasures and ensure the security of the website.

[0024] Optionally, after the step of obtaining the first data from the browser based on the attacker identifier, the method further includes:

[0025] Obtaining an attacker IP address based on the first data, and determining whether the attacker IP address exists in threat intelligence and / or security device logs;

[0026] If so, obtain the corresponding alarm level, and select one or more of email, SMS or other IM tools to send the alarm information according to the alarm level.

[0027] By adopting the above technical solution, after obtaining the first data, it is possible to determine whether to send an alarm message and issue an alarm based on threat intelligence and / or security device logs, and send an alarm message when an alarm is needed, which helps to obtain the alarm information as soon as possible, so as to quickly take effective measures to defend against and counter attacks.

[0028] In a second aspect, the present invention provides an attack countermeasure system, which adopts the following technical solution:

[0029] An attack countermeasure system, comprising:

[0030] A first data acquisition module is configured to acquire first data from the browser based on the attacker identifier; the first data includes the attacker's identity information and the attack time;

[0031] A second data acquisition module is configured to acquire second data from the advanced keyboard logger based on the attacker identifier; the second data is attack behavior information generated by the attacker in the cloned business system;

[0032] A portrait generation module, configured to generate an attacker portrait based on the first data and the second data;

[0033] The countermeasure module is used to analyze the attacker's profile, generate a countermeasure strategy, and initiate a countermeasure against the attacker based on the countermeasure strategy.

[0034] By adopting the above technical solution, the first data representing the attacker's identity information and attack time is obtained through the browser, and the second data representing the attack behavior information generated by the attacker in the cloned business system is obtained through the high-level keyboard recorder. The attacker portrait is generated based on the first data and the second data, and then a countermeasure strategy is generated by analyzing the attacker portrait to counter the attacker's attack, thereby improving the accuracy of the attack countermeasure and ensuring the security of the website.

[0035] Optionally, the attacker identity information includes username, password, attacker IP, operating system and device type.

[0036] By adopting the above technical solution, the attacker's identity information can be characterized from multiple dimensions, so that the attacker can be accurately located from multiple dimensions, further improving the accuracy of attack countermeasures.

[0037] In a third aspect, the present invention provides an electronic device, which adopts the following technical solution:

[0038] An electronic device includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and execute the method described.

[0039] In a fourth aspect, the present invention provides a computer-readable storage medium, which adopts the following technical solution:

[0040] A computer-readable storage medium stores a computer program capable of being loaded by a processor and executing the method described.

[0041] In summary, the present invention includes at least one of the following beneficial technical effects:

[0042] 1. The first data representing the attacker's identity information and attack time is obtained through the browser, and the second data representing the attacker's attack behavior information generated in the cloned business system is obtained through the advanced keylogger. The attacker portrait is generated based on the first data and the second data. Then, a countermeasure strategy is generated by analyzing the attacker portrait to counter the attacker's attack, thereby improving the accuracy of the attack countermeasure and ensuring the security of the website.

[0043] 2. Characterize the attacker's identity information from multiple dimensions, so that the attacker can be accurately located from multiple dimensions, further improving the accuracy of attack countermeasures. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 This is a flow chart of the attack countermeasure method according to an embodiment of the present invention.

[0045] Figure 2 It is a flow chart of the present invention for generating a countermeasure strategy.

[0046] Figure 3 It is a structural block diagram of the attack countermeasure system according to an embodiment of the present invention.

[0047] Figure 4 It is a structural block diagram of the present invention for generating a countermeasure strategy.

[0048] Explanation of the accompanying drawings: 10. First data acquisition module; 20. Second data acquisition module; 30. Portrait generation module; 40. Countermeasure module; 401. First attack weight generation module; 402. Second attack weight generation module; 403. Countermeasure strategy generation module. DETAILED DESCRIPTION

[0049] In order to make the purpose, technical solutions and advantages of the present invention more clear, the following Figure 1-4 It should be understood that the specific embodiments described herein are only used to illustrate the present invention and are not intended to limit the present invention.

[0050] The embodiment of the present invention discloses an attack countermeasure method, referring to Figure 1 , the attack countermeasure method includes the following steps:

[0051] S11. Obtaining first data from the browser based on the attacker identifier;

[0052] The attacker identifier is the attacker's ID, which can be an internal code within the cloned business system or the attacker's username. The first piece of data is the attacker's browser history, including the attacker's identity information and the time of the attack. The attacker's identity information includes the username, password, attacker's IP address, operating system, and device type. The history record can be one or multiple, each representing an attack launched by the attacker. The attacker's IP address can be the attacker's real IP address or the IP address of a proxy machine.

[0053] The cloned business system is a pre-set virtual system corresponding to a real website and can be deployed based on virtualization-Docker containers. For example, the cloned business system is an OA system or email system corresponding to the real website. When an attacker initiates an access request to the real website, the virtual network information released is used to trick the attacker into accessing the cloned business system. This protects the real website from attacks while collecting information about the attacker's attack behavior based on the cloned business system, which is conducive to accurately countering the attacker. In addition, the cloned business system is a resource that no legitimate visitor will access. Only potential attackers will access the cloned business system. Therefore, users who access the cloned business system are marked as attackers, and based on the attacker's identification, the first data representing the user's identity information and access time is obtained from the browser, which is conducive to accurately countering the attacker.

[0054] It should be noted that this embodiment supports conventional browsers, such as Chrome browser, Firefox browser, 360 browser, IE browser and Sogou browser.

[0055] S12. Obtaining second data from the advanced keylogger based on the attacker identifier;

[0056] Among them, the advanced keyboard logger is a keyboard recording method created by JavaScript technology and web front-end technology, which is used to record the keyboard operations performed by users in the cloned business system, specifically including the user's input information and operation information in the cloned business system, which represents the attacker's attack behavior in the cloned business system; the second data is the attack behavior information generated by the attacker in the cloned business system, and the second data is obtained through statistical analysis of the keyboard operation information performed by the attacker in the cloned business system.

[0057] S13. Generate an attacker profile based on the first data and the second data;

[0058] After obtaining the first data and the second data, an attacker portrait is generated based on the first data and the second data, where the portrait includes user name, password, attacker IP, operating system, device type, attack time, and attack behavior information.

[0059] S14. Analyze the attacker's profile, generate a countermeasure strategy, and launch a countermeasure against the attacker based on the countermeasure strategy.

[0060] After obtaining the attacker's profile, the attacker's information is analyzed based on the attacker's profile, a corresponding countermeasure strategy is generated, and a countermeasure is launched against the attacker based on the countermeasure strategy.

[0061] Reference Figure 2 , analyze the attacker's profile and generate a countermeasure strategy, which includes the following sub-steps:

[0062] S141. Analyze the attacker profile, generate an attack frequency, and generate a first attack weight based on the attack frequency;

[0063] The attacker profile includes one or more historical attack times of the attacker. In sub-step S141, the attack frequency is calculated based on the historical attack times in the attacker profile. The attack frequency represents the frequency of the attacker's attacks on the target website. The higher the attack frequency, the greater the value of the first attack weight, and the smaller the attack frequency, the smaller the value of the first attack weight.

[0064] S142. Analyze the attacker profile to generate an attack intensity level, and generate a second attack weight based on the attack intensity level;

[0065] The attacker portrait includes information about the attack behavior initiated by the attacker. In this sub-step S142, the attack behavior information in the attacker portrait is obtained, and a corresponding attack intensity level is generated based on the attack behavior information, and then a second attack weight is generated based on the attack intensity level, wherein the attack intensity level and the second attack weight are in one-to-one correspondence.

[0066] S143. Generate a countermeasure strategy based on the first attack weight, the second attack weight, and the attacker profile.

[0067] Specifically, the countermeasure strength level is determined based on the first and second attack weights, and a corresponding countermeasure strategy is generated based on the countermeasure strength level and the attacker's profile. The larger the first and second attack weights, the greater the threat posed by the attacker. In this case, a countermeasure strategy with a closer countermeasure time and stronger countermeasure measures is generated. The countermeasure strategy includes the attacker's identity, countermeasure time, and countermeasure measures.

[0068] In step S14, when launching a countermeasure against an attacker based on the countermeasure strategy, the attacker's identity information, countermeasure time, and countermeasure means contained in the countermeasure strategy are first obtained. Then, at the corresponding countermeasure time, the corresponding countermeasure means are used to launch a countermeasure against the attacker target. The attacker's identity information includes multiple dimensions such as username, password, attacker's IP address, operating system, and device type, which can accurately locate the attacker from multiple dimensions.

[0069] As an embodiment, after step S11, the method further includes: obtaining the attacker's IP address based on the first data, and determining whether the attacker's IP address exists in threat intelligence or security device logs. If so, determining an alert level based on the threat intelligence or security device logs, and selecting, based on the alert level, to send an alert message via one or more of email, SMS, or other IM tools; if not, performing no action. The alert level is set in the threat intelligence and / or security device logs, and the threat intelligence and security device logs are pre-set documents based on historical attack scenarios.

[0070] As another implementation, after step S14, the threat intelligence and / or security device logs are updated based on the countermeasure strategy. Specifically, if the attacker IP address exists in the threat intelligence and / or security device logs, its corresponding warning level is updated. If the attacker IP address does not exist in the threat intelligence and / or security device logs, the attacker IP address and the corresponding warning level are added to the threat intelligence and / or security device logs. The warning level of the added attacker IP address is set based on the attacker profile.

[0071] It should be noted that, in the above embodiment, the timing for countering the attack may be when an attacker is monitored to access the cloned business system, the attacker's current access time to the cloned business system exceeds a preset threshold, the attacker performs a preset operation in the cloned business system or reaches a preset period, wherein the timing for countering the attack refers to the timing of executing steps S11-S14, that is, the timing of starting the process.

[0072] In the above embodiment, first data representing the attacker's identity information and attack time is obtained through a browser, and second data representing the attacker's attack behavior information generated in the cloned business system is obtained through a high-level keyboard recorder. An attacker portrait is generated based on the first data and the second data, and a countermeasure strategy is generated by analyzing the attacker portrait to counter the attacker's attack, thereby improving the accuracy of the attack countermeasure and ensuring the security of the Web site.

[0073] The embodiment of the present invention discloses an attack countermeasure system, referring to Figure 3 , the attack countermeasure system includes:

[0074] A first data acquisition module 10 is configured to acquire first data from a browser based on an attacker identifier;

[0075] The attacker identifier is the attacker's ID, which can be an internal code within the cloned business system or the attacker's username. The first piece of data is the attacker's browser history, including the attacker's identity information and the time of the attack. The attacker's identity information includes the username, password, attacker's IP address, operating system, and device type. The history record can be one or multiple, each representing an attack launched by the attacker. The attacker's IP address can be the attacker's real IP address or the IP address of a proxy machine.

[0076] The cloned business system is a pre-set virtual system corresponding to a real website and can be deployed based on virtualization-Docker containers. For example, the cloned business system is an OA system or email system corresponding to the real website. When an attacker initiates an access request to the real website, the virtual network information released is used to trick the attacker into accessing the cloned business system. This protects the real website from attacks while collecting information about the attacker's attack behavior based on the cloned business system, which is conducive to accurately countering the attacker. In addition, the cloned business system is a resource that no legitimate visitor will access. Only potential attackers will access the cloned business system. Therefore, users who access the cloned business system are marked as attackers, and based on the attacker's identification, the first data representing the user's identity information and access time is obtained from the browser, which is conducive to accurately countering the attacker.

[0077] It should be noted that this embodiment supports conventional browsers, such as Chrome browser, Firefox browser, 360 browser, IE browser and Sogou browser.

[0078] A second data acquisition module 20 is configured to acquire second data from the advanced keylogger based on the attacker identifier;

[0079] Among them, the advanced keyboard logger is a keyboard recording method created by JavaScript technology and web front-end technology, which is used to record the keyboard operations performed by users in the cloned business system, specifically including the user's input information and operation information in the cloned business system, which represents the attacker's attack behavior in the cloned business system; the second data is the attack behavior information generated by the attacker in the cloned business system, and the second data is obtained through statistical analysis of the keyboard operation information performed by the attacker in the cloned business system.

[0080] A portrait generation module 30, configured to generate an attacker portrait based on the first data and the second data;

[0081] After obtaining the first data and the second data, an attacker portrait is generated based on the first data and the second data, where the portrait includes user name, password, attacker IP, operating system, device type, attack time, and attack behavior information.

[0082] The countermeasure module 40 is used to analyze the attacker's profile, generate a countermeasure strategy, and initiate a countermeasure against the attacker based on the countermeasure strategy.

[0083] After obtaining the attacker's profile, the attacker's information is analyzed based on the attacker's profile, a corresponding countermeasure strategy is generated, and a countermeasure is launched against the attacker based on the countermeasure strategy.

[0084] Reference Figure 4 , analyze the attacker's profile and generate a countermeasure strategy, which includes the following sub-modules:

[0085] A first attack weight generating module 401 is configured to analyze the attacker profile, generate an attack frequency, and generate a first attack weight based on the attack frequency;

[0086] The attacker profile contains one or more historical attack times of the attacker. The attack frequency is calculated based on the historical attack times in the attacker profile. The attack frequency represents the frequency of the attacker's attacks on the target website. The higher the attack frequency, the greater the value of the first attack weight, and the smaller the attack frequency, the smaller the value of the first attack weight.

[0087] A second attack weight generating module 402 analyzes the attacker profile, generates an attack intensity level, and generates a second attack weight based on the attack intensity level;

[0088] The attacker profile includes information about the attack behavior initiated by the attacker. The attack behavior information in the attacker profile is obtained, and a corresponding attack intensity level is generated based on the attack behavior information. Then, a second attack weight is generated based on the attack intensity level, wherein the attack intensity level and the second attack weight are in one-to-one correspondence.

[0089] The countermeasure strategy generating module 403 is configured to generate a countermeasure strategy based on the first attack weight, the second attack weight, and the attacker profile.

[0090] Specifically, the countermeasure strength level is determined based on the first and second attack weights, and a corresponding countermeasure strategy is generated based on the countermeasure strength level and the attacker's profile. The larger the first and second attack weights, the greater the threat posed by the attacker. In this case, a countermeasure strategy with a closer countermeasure time and stronger countermeasure measures is generated. The countermeasure strategy includes the attacker's identity, countermeasure time, and countermeasure measures.

[0091] When launching a countermeasure against an attacker based on a countermeasure strategy, countermeasure module 40 first obtains the attacker's identity information, countermeasure time, and countermeasure means contained in the countermeasure strategy. Then, at the corresponding countermeasure time, the corresponding countermeasure means are used to launch a countermeasure against the attacker's target. The attacker's identity information includes multiple dimensions such as username, password, attacker's IP address, operating system, and device type, enabling precise identification of the attacker from multiple dimensions.

[0092] As an embodiment, after obtaining the first data, the method further includes: obtaining the attacker's IP address based on the first data, and determining whether the attacker's IP address exists in threat intelligence or security device logs. If so, determining an alarm level based on the threat intelligence or security device logs, and selecting, based on the alarm level, to send an alarm message via one or more of email, SMS, or other IM tools; if not, performing no action. The alarm level is set in the threat intelligence and / or security device logs, and the threat intelligence and security device logs are pre-set documents based on historical attack situations.

[0093] As another implementation, after launching a countermeasure against an attacker based on a countermeasure strategy, threat intelligence and / or security device logs are updated based on the countermeasure strategy. Specifically, if the attacker's IP address exists in the threat intelligence and / or security device logs, its corresponding warning level is updated. If the attacker's IP address does not exist in the threat intelligence and / or security device logs, the attacker's IP address and corresponding warning level are added to the threat intelligence and / or security device logs. The warning level of the added attacker's IP address is set based on the attacker's profile.

[0094] It should be noted that in the above embodiment, the timing for countering the attack may be when an attacker is detected accessing the cloned business system, the attacker's current access time to the cloned business system exceeds a preset threshold, the attacker performs a preset operation in the cloned business system, or reaches a preset period.

[0095] In the above embodiment, first data representing the attacker's identity information and attack time is obtained through a browser, and second data representing the attacker's attack behavior information generated in the cloned business system is obtained through a high-level keyboard recorder. An attacker portrait is generated based on the first data and the second data, and a countermeasure strategy is generated by analyzing the attacker portrait to counter the attacker's attack, thereby improving the accuracy of the attack countermeasure and ensuring the security of the Web site.

[0096] Based on the same technical concept, an embodiment of the present disclosure also provides an electronic device. The electronic device includes a processor, a memory, and a bus. The memory is used to store computer programs and includes internal memory and external memory. The internal memory is used to temporarily store calculation data in the processor and data exchanged with external memory such as a hard disk. The processor exchanges data with the external memory through the internal memory.

[0097] In the embodiments of the present application, the memory is specifically used to store a computer program for executing the technical solution of the present application, and the execution is controlled by the processor. That is, when the electronic device is running, the processor and the memory communicate via a bus, so that the processor executes the computer program stored in the memory, thereby performing the method described in any of the aforementioned embodiments.

[0098] The memory may be, but is not limited to, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), etc.

[0099] The processor may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor.

[0100] It is understood that the structures illustrated in the embodiments of the present application do not constitute specific limitations on the electronic device. In other embodiments of the present application, the electronic device 500 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0101] This embodiment also provides a computer-readable storage medium, such as a floppy disk, a CD, a hard disk, a flash memory, a USB flash drive, an SD (Secure Digital Memory Card) card, an MMC (Multimedia Card), etc., in which a computer program for implementing the above steps is stored. The computer program can be executed by one or more processors to implement the method in the above embodiment.

[0102] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interface, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0103] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0104] The above are preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Unless otherwise stated, any feature disclosed in this specification (including the abstract and drawings) may be replaced by other equivalent or similar features. In other words, unless otherwise stated, each feature is merely an example of a series of equivalent or similar features.

Claims

1. An attack countermeasure method, characterized in that: include: Based on the attacker identifier, first data is obtained from the browser; the first data includes the attacker's identity information and the attack time; Based on the attacker identifier, second data is obtained from the advanced keyboard logger; the second data is attack behavior information generated by the attacker in the cloned business system; The attack behavior information includes the attacker's input information and operation information in the cloned business system; generating an attacker profile based on the first data and the second data; Analyze the attacker's profile, generate a countermeasure strategy, and initiate a countermeasure against the attacker based on the countermeasure strategy; The analysis of the attacker profile and generation of a countermeasure strategy specifically includes: Analyze the attacker profile to generate an attack frequency, and generate a first attack weight based on the attack frequency; Analyzing the attacker profile to generate an attack intensity level, and generating a second attack weight based on the attack intensity level; generating a countermeasure strategy based on the first attack weight, the second attack weight, and the attacker profile; Generating a countermeasure strategy based on the first attack weight, the second attack weight, and the attacker profile specifically includes: Determining a counterattack strength level according to the first attack weight and the second attack weight; The countermeasure strategy is generated according to the countermeasure strength level and the attacker profile; the countermeasure strategy includes attacker identity information, countermeasure time and countermeasure means.

2. The method according to claim 1, characterized in that The attacker identity information includes username, password, attacker IP, operating system and device type.

3. The method according to claim 1 or 2, characterized in that The cloned business system is a preset virtual system corresponding to a real Web site.

4. The method according to claim 1, wherein After the step of obtaining the first data from the browser based on the attacker identifier, the method further includes: Obtaining an attacker IP address based on the first data, and determining whether the attacker IP address exists in threat intelligence and / or security device logs; If so, obtain the corresponding alarm level, and select one or more of email, SMS or other IM tools to send the alarm information according to the alarm level.

5. An attack countermeasure system, characterized in that: include: A first data acquisition module is configured to acquire first data from the browser based on the attacker identifier; the first data includes the attacker's identity information and the attack time; A second data acquisition module is configured to acquire second data from the advanced keyboard logger based on the attacker identifier; the second data is attack behavior information generated by the attacker in the cloned business system; the attack behavior information includes input information and operation information of the attacker in the cloned business system; A portrait generation module, configured to generate an attacker portrait based on the first data and the second data; A countermeasure module is used to analyze the attacker's profile, generate a countermeasure strategy, and initiate a countermeasure against the attacker based on the countermeasure strategy; The analysis of the attacker profile and generation of a countermeasure strategy specifically includes: Analyze the attacker profile to generate an attack frequency, and generate a first attack weight based on the attack frequency; Analyzing the attacker profile to generate an attack intensity level, and generating a second attack weight based on the attack intensity level; generating a countermeasure strategy based on the first attack weight, the second attack weight, and the attacker profile; Generating a countermeasure strategy based on the first attack weight, the second attack weight, and the attacker profile specifically includes: Determining a counterattack strength level according to the first attack weight and the second attack weight; The countermeasure strategy is generated according to the countermeasure strength level and the attacker profile; the countermeasure strategy includes attacker identity information, countermeasure time and countermeasure means.

6. The system according to claim 5, characterized in that The attacker identity information includes username, password, attacker IP, operating system and device type.

7. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and execute the method according to any one of claims 1 to 4.

8. A computer-readable storage medium, characterized in that: A computer program is stored which can be loaded by a processor and execute the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Data safety operation online monitoring method and system

    CN114826880A