Defense Method and Device Against Website Attacks, Non-Volatile Storage Medium, Electronic Device

By processing and clustering the interactive data between the client and the server, an disturbance generation model is generated to interfere with website attacks, the existing defense methods have solved the problems of large and high communication overhead and high cost, and the effect of reducing communication overhead and cost is achieved.

CN115563434BActive Publication Date: 2025-06-10CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211336613.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-28
Publication Date
2025-06-10
Estimated Expiration
2042-10-28

AI Technical Summary

Technical Problem

The existing methods to defend against website attacks have problems such as high communication overhead and high cost.

Method used

By processing the interactive data between the client and the server, a first sequence is generated, and the second sequence is determined based on the plurality of first sequences, clustering is performed to generate cluster clusters, and the third sequence is determined. Then, the loss function and gradient values ​​of the perturbation generation model are determined based on the first sequence, the third sequence, and the sample sequence, and the model is trained to generate the target perturbation value and gradient value for interfering with the website attack.

Benefits of technology

It realizes the reduction of communication overhead between users and websites, reduces the cost of methods to defend against website attacks, and solves the problem of large communication overhead and high cost of existing methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115563434B_ABST
    Figure CN115563434B_ABST
Patent Text Reader

Abstract

The present application discloses a defense method and device for website attacks, a non-volatile storage medium, and an electronic device. Among them, the method includes: processing the interaction data between the client and the server to generate a first sequence; determining the second sequences corresponding to each website and the similarity values between the second sequences, clustering the second sequences whose similarity values meet the preset conditions to generate clustering clusters, and determining the third sequence corresponding to the clustering cluster according to the first sequences included in the clustering cluster; determining the loss function of the perturbation generation model, determining the gradient value of the perturbation generation model, and determining the perturbation generation model; training the perturbation generation model to obtain a target perturbation value and a target gradient value corresponding to the target perturbation value, and adding the target gradient value to the first sequence to generate a first target sequence for interfering with the website attacker. The present application solves the technical problems that the existing methods for defending website attacks have large communication overhead and high costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network traffic, and in particular, to a method and apparatus for defending against website attacks, a non-volatile storage medium, and an electronic device. Background Art

[0002] With the rapid development of Internet technology, the proportion of people obtaining information through the network is increasing continuously, and at the same time, more and more attention is paid to the protection of privacy. Therefore, the Tor (The Onion Router) anonymous network is widely used for information transmission. The Tor network is a low-latency anonymous network based on links, which uses a multi-hop proxy mechanism and an encrypted triple proxy with fast and dynamic changes of proxy nodes to protect user privacy (such as the websites visited). However, website fingerprint (Website-fingerprinting, WF) attacks can be used to analyze the websites visited by anonymous network users, thus destroying the anonymity of network users and resulting in the leakage of user privacy.

[0003] In order to better protect the privacy of network users, it is necessary to effectively defend against website fingerprint attacks. Early defense methods randomly changed the packets transmitted between users and websites (such as adding virtual packets or adding delays), thereby increasing the difficulty for attackers to identify websites. However, this defense method often brings a large communication overhead and high costs.

[0004] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention

[0005] Embodiments of the present application provide a method and apparatus for defending against website attacks, a non-volatile storage medium, and an electronic device, so as to at least solve the technical problem that the existing method for defending against website attacks has a large communication overhead and high costs.

[0006] According to one aspect of the embodiments of the present application, a method for defending against website attacks is provided, including: processing the interaction data between the client and the server to generate a first sequence, where the interaction data is the data generated each time the client accesses the website corresponding to the server; determining the second sequence corresponding to each website according to multiple first sequences corresponding to each website, and determining the similarity value between the second sequences corresponding to each website, clustering the second sequences whose similarity values meet the preset conditions to generate a clustering cluster, and determining the third sequence corresponding to the clustering cluster according to the first sequences included in the clustering cluster; determining the loss function of the perturbation generation model according to the first sequence, the third sequence, and the sample sequence, determining the gradient value of the perturbation generation model according to the loss function and the sample sequence, and determining the perturbation generation model according to the loss function and the gradient value, where the sample sequence is the first sequence added with a preset perturbation value; training the perturbation generation model to obtain the target perturbation value of the first sequence and the target gradient value corresponding to the target perturbation value, and adding the target gradient value to the first sequence to generate a first target sequence for interfering with the website attacker.

[0007] Optionally, determining the similarity value between the second sequences corresponding to each website includes: taking the difference between the values at the same position in the second sequences corresponding to any two websites among each website; summing the differences obtained after taking the difference to obtain the similarity value between the second sequences corresponding to any two websites; and determining the similarity value between the second sequences corresponding to each website among multiple websites according to the similarity value between the second sequences corresponding to any two websites.

[0008] Optionally, processing the interaction data between the client and the server to generate a first sequence includes: if the sub-data of the interaction data is the data sent from the client to the server, representing the sub-data with a first character, and if the sub-data of the interaction data is the data sent from the server to the client, representing the sub-data with a second character; aggregating multiple consecutive first characters to generate a first aggregation result, and aggregating multiple consecutive second characters to generate a second aggregation result; and determining the first sequence according to the first character, the second character, the first aggregation result, and the second aggregation result.

[0009] Optionally, determining the second sequence corresponding to each website according to multiple first sequences corresponding to each website includes: determining the average value of the values at each position according to the values at each position in each of the multiple first sequences; and determining the second sequence according to the average value of the values at each position, where the length of the second sequence is the same as the length of the first sequence.

[0010] Optionally, when the website prediction value of the sample sequence is the same as that of the third sequence, the training of the perturbation generation model is stopped, where the website prediction value of the sample sequence is the first probability value generated by the trained classification model according to the sample sequence, the website prediction value of the third sequence is the second probability value generated by the trained classification model according to the third sequence, the first probability value is the probability that the client accesses the website corresponding to the sample sequence, and the second probability value is the probability that the client accesses the website corresponding to the third sequence.

[0011] Optionally, the trained classification model is used to replace the classification model of the website attacker and is used to output the probability value of the client accessing each website in the preset website library.

[0012] Optionally, the loss function of the perturbation generation model is determined according to the bandwidth threshold, where the bandwidth is the bandwidth of the network used by the client to interact with the website corresponding to the server, and the bandwidth threshold is the minimum and maximum values of the bandwidth.

[0013] Optionally, the perturbation value at the current moment is determined according to the positive value sequence of the perturbation value and the gradient value at the previous adjacent moment of the current moment, where the perturbation value at the current moment is the target perturbation value, and the positive value sequence of the gradient value is the sequence obtained by retaining the elements with positive gradient vectors in the gradient values.

[0014] Optionally, determining the third sequence corresponding to the clustering cluster according to the first sequences included in the clustering cluster includes: taking the absolute value of the numerical values at each position in each of the first sequences included in the clustering cluster to generate a plurality of fourth sequences corresponding to the first sequences; determining the maximum value of the numerical values at each position in the plurality of fourth sequences according to the plurality of fourth sequences, and determining the maximum value as the third sequence corresponding to the clustering cluster.

[0015] Optionally, when the length of the first sequence is less than the preset target length, the length of the first sequence is made equal to the target length by adding a preset numerical value to the tail of the first sequence, where the target length is the preset length of the first sequence; when the length of the first sequence is greater than the target length, the numerical values at the outermost ends of the first sequence are removed in turn until the length of the first sequence is equal to the target length.

[0016] According to another aspect of the embodiments of the present application, a non-volatile storage medium is further provided. The storage medium includes a stored program, where when the program runs, it controls the device where the storage medium is located to execute the above-mentioned defense method against website attacks.

[0017] According to another aspect of the embodiments of the present application, an electronic device is further provided, including: a memory and a processor, where the processor is used to run the program stored in the memory, and when the program runs, it executes the above-mentioned defense method against website attacks.

[0018] In an embodiment of the present application, the interaction data between the client and the server is processed to generate a first sequence. Among them, the interaction data is the data generated each time the client accesses the website corresponding to the server; according to the multiple first sequences corresponding to each website, the second sequence corresponding to each website is determined, and the similarity value between the second sequences corresponding to each website is determined. The second sequences whose similarity values meet the preset conditions are clustered to generate a clustering cluster, and the third sequence corresponding to the clustering cluster is determined according to the first sequences included in the clustering cluster; according to the first sequence, the third sequence, and the sample sequence, the loss function of the perturbation generation model is determined, the gradient value of the perturbation generation model is determined according to the loss function and the sample sequence, and the perturbation generation model is determined according to the loss function and the gradient value. Among them, the sample sequence is the first sequence added with a preset perturbation value; the perturbation generation model is trained to obtain the target perturbation value of the first sequence and the target gradient value corresponding to the target perturbation value, and the target gradient value is added to the first sequence to generate the first target sequence for interfering with the website attacker. By determining the similarity value between the sequences corresponding to each website, the purpose of clustering the sequences whose similarity meets the preset conditions is achieved, thereby realizing the technical effect of reducing the communication overhead between the user and the website and reducing the cost of the method for defending website attacks, and further solving the technical problems of large communication overhead and high cost existing in the existing methods for defending website attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0020] Figure 1 is a flowchart of a method for defending website attacks according to an embodiment of the present application;

[0021] Figure 2 is a flowchart of another method for defending website attacks according to an embodiment of the present application;

[0022] Figure 3 is a schematic diagram of a data sequence model according to an embodiment of the present application;

[0023] Figure 4 is a structural diagram of a device for defending website attacks according to an embodiment of the present application;

[0024] Figure 5 is a hardware structure block diagram of a computer terminal (or electronic device) for a method for defending website attacks provided according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0026] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0027] To better understand the embodiments of this application, the following technical terms involved in the embodiments of this application are explained as follows:

[0028] Website fingerprint attack: Website fingerprint attack is a common traffic analysis method, and its attack method is as follows: The attacker captures the encrypted packet sequence between the user and the website, extracts the traffic characteristics, and then uses a machine learning model (classifier) for classification to identify the website visited by the user.

[0029] Adversarial perturbation: A method for defending against website fingerprint attacks. It draws on the idea of adversarial examples, loads the generated adversarial perturbation on the user's original sample (i.e., the packet sequence), makes the samples of different websites more similar, and can cause the classification model of the website fingerprint attacker to make classification errors. The website fingerprint attack defense technology based on adversarial perturbation has the advantages of small perturbation amount and low implementation cost.

[0030] The related website fingerprint attack defense methods based on adversarial perturbation usually randomly select another website (as an imitation object) for the website to be protected, and use the distance (i.e., the gap) between the feature sequences of the two websites as the loss function. By minimizing this loss function, the adversarial perturbation is gradually generated in an iterative update manner and applied to the original sample of the website. Finally, once the generated perturbation can cause the classification model to make an error, the iteration is stopped and the current perturbation is used as the adversarial perturbation. To sum up, there are still disadvantages in the related technologies that are difficult to resist adversarial training.

[0031] In the present application, by determining the super-sequence (the third sequence) W of the clustering cluster and adding adversarial perturbations to all the burst sequences (the first sequence) in the clustering cluster, all the burst sequences (the first sequence) in the clustering cluster are made to approach the above super-sequence as much as possible, achieving the purpose of making the different website features in the clustering cluster more similar, realizing the technical effect of deceiving the classifier, and further solving the technical problem of being difficult to resist adversarial training.

[0032] According to an embodiment of the present application, a method embodiment of a defense method against website attacks is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0033] Figure 1 is a flowchart of a defense method against website attacks according to an embodiment of the present application, as Figure 1 shown, the method includes the following steps:

[0034] Step S102, process the interaction data between the client and the server to generate a first sequence, where the interaction data is the data generated each time the client accesses the website corresponding to the server.

[0035] According to an optional embodiment of the present application, the interaction data between the client and the server is the data generated each time the client accesses the website corresponding to the server. Each access of the client to the website will generate multiple request data and multiple response data, and the above multiple request data and multiple response data are sub-data of the interaction data between the client and the server. By performing corresponding processing on the above sub-data and aggregating the sub-data of the same type, a first sequence can be generated, that is, a first sequence will be generated each time the client accesses the website corresponding to the server. For example, the first sequence represents the direction of data interaction between the client and the server in the form of numbers, and the first sequence is a sequence composed of numbers.

[0036] Step S104, determine the second sequence corresponding to each website according to the multiple first sequences corresponding to each website, determine the similarity values between the second sequences corresponding to each website, cluster the second sequences whose similarity values meet the preset conditions to generate a clustering cluster, and determine the third sequence corresponding to the clustering cluster according to the first sequences included in the clustering cluster.

[0037] According to another optional embodiment of the present application, a first sequence is generated each time the client accesses the corresponding website of the server. Generally, the number of first sequences is multiple. According to the multiple sequences generated by the client accessing each website, that is, the multiple first sequences corresponding to each website, the second sequence corresponding to each website can be determined, where the second sequence is a sequence obtained by calculating each first sequence, that is, the multiple first sequences corresponding to each website can generate a second sequence. It should be noted that both the first sequence and the second sequence are sequences used to represent website features.

[0038] The similarity value between the second sequences corresponding to two websites can be calculated through the following formula:

[0039]

[0040] where S is the similarity value, A and B represent the second sequences of different websites, A i and B i represent the i-th column of the second sequence, D represents the length of the second sequence, and the length of the second sequence is the same as that of the first sequence.

[0041] The smaller the value of the similarity S, the more similar the two second sequences (website features); on the contrary, the larger the value of the similarity S, the less similar the two second sequences (website features). According to the above formula, the n second sequences (websites) with the most similar features are clustered into one cluster, and then all the second sequences (websites) are divided into multiple clusters.

[0042] Since the second sequence is a sequence composed of multiple first sequences, after all the second sequences are divided into clustering clusters, the third sequence corresponding to the clustering cluster is determined according to the multiple first sequences included in the clustering cluster. Specifically, first, take the absolute value of each value of the first sequence, and the result is expressed as [b 1 , b 2 , b 3 , …, b i . Secondly, calculate the maximum value of each position in all the first sequences in the clustering cluster, and splice the maximum values of each position again to generate a maximum sequence, where the maximum sequence is the third sequence.

[0043] Step S106, determine the loss function of the perturbation generation model according to the first sequence, the third sequence, and the sample sequence, determine the gradient value of the perturbation generation model according to the loss function and the sample sequence, and determine the perturbation generation model according to the loss function and the gradient value, where the sample sequence is the first sequence added with a preset perturbation value.

[0044] In some alternative embodiments of the present application, for the classifier used in the spoofing website fingerprint attack, adversarial perturbations need to be added to all the first sequences in the cluster to make the first sequences as close as possible to the third sequence (the maximum sequence). The purpose is to make the different website features in the cluster more similar, achieving the effect of spoofing the classifier. The loss function of the perturbation generation model is defined as:

[0045] L = αH(I adv , W) + βΓ(OH high , OH low , I adv )

[0046] Wherein,

[0047]

[0048]

[0049] Wherein, I adv is the first sequence (sample sequence) added with a preset perturbation value, W is the third sequence, x i is the probability value of each website in the preset website library accessed by the client output by the classifier used in the website fingerprint attack, I is the first sequence, OH high is the maximum value of the bandwidth of the network used for the interaction between the client and the website corresponding to the server, OH low is the minimum value of the bandwidth of the network used for the interaction between the client and the website corresponding to the server, and α and β are non - negative weights.

[0050] Calculate the gradient Δ of the loss function L with respect to the current sample sequence I adv , and the formula is as follows:

[0051]

[0052] Based on the above - mentioned gradient, iteratively update the current adversarial perturbation.

[0053] Step S108: Train the perturbation generation model to obtain the target perturbation value of the first sequence and the target gradient value corresponding to the target perturbation value, and add the target gradient value to the first sequence to generate the first target sequence for interfering with the website attacker.

[0054] In some alternative embodiments of the present application, adding the target gradient value corresponding to the target perturbation value to the first sequence achieves the purpose of applying the adversarial perturbation to the original sequence (the first sequence), realizes the technical effect of making the features of multiple websites become similar to each other, and thus fundamentally makes it more difficult to identify and distinguish websites.

[0055] According to the above steps, by determining the similarity values between the sequences corresponding to each website, the purpose of clustering the sequences whose similarity meets the preset conditions is achieved, thereby realizing the technical effect of reducing the communication overhead between the user and the website and reducing the cost of the method for defending against website attacks, and further solving the technical problems of large communication overhead and high cost existing in the existing methods for defending against website attacks.

[0056] According to an optional embodiment of the present application, to determine the similarity values between the second sequences corresponding to each website, the following method can be used: subtract the values at the same positions in the second sequences corresponding to any two websites among all websites; sum up the obtained differences to obtain the similarity value between the second sequences corresponding to any two websites; and determine the similarity values between the second sequences corresponding to each website among multiple websites according to the similarity values between the second sequences corresponding to any two websites.

[0057] According to an optional embodiment of the present application, for example, the second sequence corresponding to website A is a sequence with a length of 1024, which is represented by [a 1 , a 2 , a 3 , …, a 1024 ; the second sequence corresponding to website B is also a sequence with a length of 1024, which is represented by [b 1 , b 2 , b 3 , …, b 1024 . Subtract a 1 from b 1 , subtract a 2 from b 2 , subtract a 3 from b 3 , …, subtract a 1024 from b 1024 respectively to obtain the sequence after subtraction, which is represented by [c 1 , c 2 , c 3 , …, c 1024 . Sum up c 1 to c 1024 , and the similarity value between the second sequence corresponding to website A and the second sequence corresponding to website B can be obtained. By using the above method for determining the similarity value, the similarity values between all websites in the preset website library can be determined.

[0058] According to another optional embodiment of the present application, the interaction data between the client and the server is processed to generate a first sequence, which is achieved by the following method: if the sub-data of the interaction data is the data sent from the client to the server, the sub-data is represented by a first character; if the sub-data of the interaction data is the data sent from the server to the client, the sub-data is represented by a second character; a plurality of consecutive first characters are aggregated to generate a first aggregation result, and a plurality of consecutive second characters are aggregated to generate a second aggregation result; the first sequence is determined according to the first character, the second character, the first aggregation result, and the second aggregation result.

[0059] In some optional embodiments of the present application, if the sub-data is the data sent from the client to the server, the sub-data is represented by "+1"; if the sub-data is the data sent from the server to the client, the sub-data is represented by "-1". Figure 3 It is a schematic diagram of a data sequence model according to an embodiment of the present application, as Figure 3 shown, the sub-data sent by the client is represented by "+1", the sub-data received by the client is represented by "-1", and all consecutive "+1" and all consecutive "-1" are aggregated. If there are discontinuous "+1" and "-1", they are represented by the original representation method. Figure 3 The sequence obtained by processing the interaction data shown is [+4, -2, +3, -4, +2, -1]. In addition, the length of the interaction data is a preset fixed value. Assume Figure 3 the length of the interaction data shown in is 1024. When the length of the processed sequence does not meet the above preset fixed value, 0 is added at the end of the sequence to make it up. The sequence after making up is [+4, -2, +3, -4, +2, -1, …, 0, 0], where the length of the sequence is also 1024.

[0060] It should be noted that before processing the interaction data between the client and the server, the redundant part and the noise information in the interaction data need to be removed.

[0061] As an optional embodiment of the present application, according to the multiple first sequences corresponding to each website, a second sequence corresponding to each website is determined, which is achieved by the following method: according to the values at each position in each of the multiple first sequences, the average value of the values at each position is determined; according to the average value of the values at each position, the second sequence is determined, where the length of the second sequence is the same as the length of the first sequence.

[0062] In some other alternative embodiments of the present application, each time the client accesses the corresponding website of the server, a first sequence is generated. Generally, the number of first sequences is multiple. According to the multiple sequences generated by the client accessing each website, that is, the multiple first sequences corresponding to each website, the second sequence corresponding to each website can be determined. Suppose there are three first sequences: First Sequence A, First Sequence B, and First Sequence C. Among them, First Sequence A is [a 1 , a 2 , a 3 , …, a 1024 , First Sequence B is [b 1 , b 2 , b 3 , …, b 1024 , and First Sequence C is [c 1 , c 2 , c 3 , …, c 1024 . Calculate the average value of the values at the first position, that is, the average value of a 1 , b 1 , and c 1 , the average value of the values at the second position, that is, the average value of a 2 , b 2 , and c 2 , …, the average value of the values at the last position, that is, the average value of a 1024 , b 1024 , and c 1024 . Concatenate the average values of each position to obtain an average sequence, and this average sequence is the above-mentioned second sequence.

[0063] As another alternative embodiment of the present application, when the website prediction value of the sample sequence is the same as the website prediction value of the third sequence, the training of the perturbation generation model is stopped, where the website prediction value of the sample sequence is the first probability value generated by the trained classification model according to the sample sequence, the website prediction value of the third sequence is the second probability value generated by the trained classification model according to the third sequence, the first probability value is the probability that the client accesses the website corresponding to the sample sequence, and the second probability value is the probability that the client accesses the website corresponding to the third sequence.

[0064] According to an alternative embodiment of the present application, the trained classification model is used to replace the classification model of the website attacker and is used to output the probability value of the client accessing each website in the preset website library.

[0065] According to another alternative embodiment of the present application, the loss function of the perturbation generation model is determined according to the bandwidth threshold, where the bandwidth is the bandwidth of the network used by the client to interact with the website corresponding to the server, and the bandwidth threshold is the minimum value and the maximum value of the bandwidth.

[0066] In some alternative embodiments of the present application, the loss function of the perturbation generation model is defined as:

[0067] L = αH(I adv , W) + βΓ(OH high , OH low , I adv )

[0068] Wherein,

[0069]

[0070]

[0071] Wherein, Γ(OH high , OH low , I adv ) is a part of the perturbation function, which is used to make the bandwidth consumption ratio caused by the perturbation within a certain reasonable threshold range. OH high is the maximum value of the bandwidth of the network used for the client to interact with the website corresponding to the server, and OH low is the minimum value of the bandwidth of the network used for the client to interact with the website corresponding to the server.

[0072] As an alternative embodiment of the present application, the perturbation value at the current moment is determined according to the positive value sequence of the perturbation value and the gradient value at the previous adjacent moment of the current moment, wherein the perturbation value at the current moment is the target perturbation value, and the positive value sequence of the gradient value is the sequence obtained by retaining the elements with positive gradient vectors in the gradient values.

[0073] As another alternative embodiment of the present application, the third sequence corresponding to the clustering cluster is determined according to the first sequence included in the clustering cluster, which is implemented by the following method: taking the absolute value of the numerical value at each position in each first sequence included in the clustering cluster to generate a plurality of fourth sequences corresponding to each first sequence; determining the maximum value of the numerical value at each position in the plurality of fourth sequences according to the plurality of fourth sequences, and determining the maximum value as the third sequence corresponding to the clustering cluster.

[0074] According to an alternative embodiment of the present application, when the length of the first sequence is less than the preset target length, the length of the first sequence is made equal to the target length by adding a preset numerical value to the tail of the first sequence, wherein the target length is the preset length of the first sequence; when the length of the first sequence is greater than the target length, the numerical values at the outermost ends of the first sequence are removed in turn until the length of the first sequence is equal to the target length.

[0075] Figure 2 is a flowchart of another method for defending against website attacks according to an embodiment of the present application, as shown in Figure 2 shown, and the method includes the following steps:

[0076] Step S202, generate a traffic feature sequence.

[0077] According to an optional embodiment of the present application, first, process the interaction data of multiple websites accessed by the user, define the data direction from the client to the server as the positive direction, represented by "+1", and the data direction from the server to the client as the negative direction, represented by "-1". The processed data sequence model is as Figure 3 shown. Secondly, aggregate the data into a first sequence with a length of D. If the length of the aggregated sequence is less than D, pad it with 0 at the end. For example, Figure 3 the data sequence model in

[0078] Step S204, website similarity measurement and website clustering.

[0079] According to an optional embodiment of the present application, since different websites with similar features are more likely to become similar by adding perturbation features, cluster websites with similar features into a cluster. For this purpose, first, it is necessary to measure the similarity between different websites. Since the defender can only protect the user's communication by adding virtual packets, this makes the adversarial perturbation can only be a sequence formed by non-negative integers (negative numbers represent deleting packets, which will affect the user's normal communication and is unacceptable). This particularity also makes the traditional vector distance measurement method inapplicable to the present application. The measurement method proposed in the present application is as follows: Calculate the mean value of each column of the burst sequence (the first sequence) for each website, and then obtain the "central sequence" (the second sequence). Considering websites with similar features, the burst values of their burst sequences at each position will be relatively close. Therefore, calculate the sum of the differences at each position between the central sequences (the second sequences) corresponding to two websites to measure the similarity S between the two websites (the second sequences corresponding to the two websites). The calculation formula is as follows:

[0080]

[0081] where A and B represent the central sequences (the second sequences) of different website types, A i and B i represent the i-th column of the central sequence (the second sequence), and D represents the length of the burst sequence (the first sequence). The smaller the value of the similarity S, the more similar the features of the two websites; conversely, the larger the value, the less similar the features of the two websites. According to the above formula, cluster the second sequences of the n websites with the most similar features into a cluster, and then divide the second sequences of all websites into multiple clusters.

[0082] Step S206, calculate the super burst sequence.

[0083] According to another optional embodiment of the present application, first, the absolute value of each value of the burst sequence (first sequence) is taken, and the result is expressed as [b 1 ,b 2 ,b 3 ,…,b i ]. Secondly, the maximum value of each position in all sequences in the cluster is calculated and concatenated to form a super sequence (third sequence) W.

[0084] Step S208, calculating the adversarial disturbance and adding the disturbance to the original sample of the website.

[0085] In some optional embodiments of the present application, in order to deceive the classifier used for the website fingerprint attack, it is necessary to add adversarial perturbations to all burst sequences (first sequence) in the cluster to be as close to the super sequence (third sequence) W as possible, so that the characteristics of different websites in the cluster become more similar, thereby achieving the effect of deceiving the classifier.

[0086] Assume that the classifier trained on the original sample is F(x). The loss function L designed to generate adversarial perturbations needs to consider two factors: (1) making the features of different websites in the cluster more similar; (2) controlling the introduced bandwidth consumption within a certain range. Based on the above two considerations, the loss function can be divided into two parts.

[0087] The first part of the loss function is to add the perturbed sample burst sequence I adv The predicted value F(I adv ) and the predicted value F(W) of the super sequence W, the calculation formula is as follows:

[0088]

[0089] Among them, m represents the number of websites in the preset website library, x i Represents the probability value of each website, I adv The initial value of is the original sample I.

[0090] The second part of the loss function makes the bandwidth consumption ratio caused by the disturbance within a certain reasonable threshold range. Assume that the highest bandwidth threshold and the lowest bandwidth threshold are OH high and OH low Indicates that the second part of the loss function is as follows:

[0091]

[0092] In summary, the loss function calculated by perturbation is defined as:

[0093] L=αH(I adv ,W)+βΓ(OH high ,OHlow , I adv )

[0094] where α and β are non - negative weights. Next, calculate the gradient Δ of the loss function L with respect to the current perturbation burst sequence I adv as follows:

[0095]

[0096] Based on the gradient, iteratively update the current adversarial perturbation. Considering that the added perturbation should ensure that the value at each position of the original burst sequence is not reduced (i.e., avoid packet loss), we first calculate the positive value sequence of the gradient Δ, denoted as |Δ|. This positive value sequence is obtained by retaining the elements in the gradient vector that are positive and zeroing the other elements.

[0097] Subsequently, perturb and update the current burst sequence using the following formula:

[0098] I adv (t + 1)=I adv (t)+γ|Δ|

[0099] where γ is the adjustment step size and t is the iteration round.

[0100] After multiple rounds of iteration, when the website prediction value F(I adv ) of the perturbed sample in the cluster is the same as the website prediction value F(W) of the super - sequence W, end the current training process and start calculating the adversarial perturbation of the next burst sequence. Eventually, make the sample features of different websites in the cluster become more similar.

[0101] In summary, the embodiments of the present application can deceive the classifier of the website fingerprint attack under the condition of controllable communication overhead by introducing key steps such as website similarity measurement, website clustering, and adversarial perturbation calculation. Since the present application makes the features of multiple websites become similar to each other, it fundamentally makes it more difficult to identify and distinguish websites. Therefore, the present application can better resist adversarial training.

[0102] Figure 4 is a structural diagram of a defense device for website attacks according to an embodiment of the present application, as Figure 4 shown. The device includes:

[0103] A generation module 40, configured to process the interaction data between the client and the server to generate a first sequence, where the interaction data is the data generated by the client each time it accesses the website corresponding to the server;

[0104] The clustering module 42 is configured to determine a second sequence corresponding to each website according to multiple first sequences corresponding to each website, determine a similarity value between the second sequences corresponding to each website, cluster the second sequences whose similarity values meet a preset condition to generate a clustering cluster, and determine a third sequence corresponding to the clustering cluster according to the first sequences included in the clustering cluster;

[0105] The determination module 44 is configured to determine a loss function of the perturbation generation model according to the first sequence, the third sequence, and the sample sequence, determine a gradient value of the perturbation generation model according to the loss function and the sample sequence, and determine the perturbation generation model according to the loss function and the gradient value, where the sample sequence is the first sequence added with a preset perturbation value;

[0106] The addition module 46 is configured to train the perturbation generation model to obtain a target perturbation value of the first sequence and a target gradient value corresponding to the target perturbation value, and add the target gradient value to the first sequence to generate a first target sequence for interfering with the website attacker.

[0107] It should be noted that each of the above Figure 4 modules may be a program module (for example, a set of program instructions for implementing a specific function), or a hardware module. For the latter, it may be presented in the following forms, but not limited to: the presentation form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.

[0108] According to an embodiment of the present application, a method embodiment of a defense method against website attacks is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0109] Figure 5 shows a hardware structure block diagram of a computer terminal (or mobile device) for implementing a defense method against website attacks. As Figure 5 shown, the computer terminal 50 (or mobile device 50) may include one or more (shown as 502a, 502b,..., 502n in the figure) processors 502 (the processor 502 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 504 for storing data, and a transmission module 506 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand, Figure 5The structure shown is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 50 may further include more or fewer components than those shown in Figure 5 or have a different configuration from that shown in Figure 5 .

[0110] It should be noted that one or more of the above-mentioned processors 502 and / or other data processing circuits may generally be referred to as "data processing circuits" herein. The data processing circuit may be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computer terminal 50 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistance terminal path connected to an interface).

[0111] The memory 504 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the website attack defense method in the embodiments of the present application. The processor 502 executes various functional applications and data processing by running the software programs and modules stored in the memory 504, that is, implements the above-mentioned website attack defense method. The memory 504 may include high-speed random access memory, and may further include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 504 may further include a memory remotely located relative to the processor 502, and these remote memories can be connected to the computer terminal 50 through a network. Examples of the above-mentioned network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.

[0112] The transmission device 506 is used to receive or send data via a network. Specific examples of the above-mentioned network may include the wireless network provided by the communication provider of the computer terminal 50. In one instance, the transmission device 506 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 506 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0113] The display may be, for example, a touch-screen liquid crystal display (LCD), which enables the user to interact with the user interface of the computer terminal 50 (or mobile device).

[0114] It should be noted here that in some alternative embodiments, the above-mentioned Figure 5The computer device (or electronic device) shown may include hardware elements (including circuits), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that Figure 5 is only an example of a specific concrete instance and is intended to illustrate the types of components that may exist in the above-mentioned computer device (or electronic device).

[0115] It should be noted that Figure 5 the electronic device shown is used to execute Figure 1 the defense method for website attacks shown. Therefore, the relevant explanations in the execution method of the above commands also apply to this electronic device and will not be elaborated here.

[0116] The embodiment of this application also provides a non-volatile storage medium. The non-volatile storage medium includes a stored program. Wherein, when the program runs, it controls the device where the storage medium is located to execute the above defense method for website attacks.

[0117] A program for the non-volatile storage medium to execute the following functions: process the interaction data between the client and the server to generate a first sequence, where the interaction data is the data generated each time the client accesses the website corresponding to the server; determine the second sequence corresponding to each website according to the multiple first sequences corresponding to each website, and determine the similarity value between the second sequences corresponding to each website, cluster the second sequences whose similarity values meet the preset conditions to generate a clustering cluster, and determine the third sequence corresponding to the clustering cluster according to the first sequences included in the clustering cluster; determine the loss function of the perturbation generation model according to the first sequence, the third sequence, and the sample sequence, determine the gradient value of the perturbation generation model according to the loss function and the sample sequence, and determine the perturbation generation model according to the loss function and the gradient value, where the sample sequence is the first sequence added with a preset perturbation value; train the perturbation generation model to obtain the target perturbation value of the first sequence and the target gradient value corresponding to the target perturbation value, and add the target gradient value to the first sequence to generate the first target sequence for interfering with the website attacker.

[0118] The embodiment of this application also provides an electronic device, including: a memory and a processor. The processor is used to run the program stored in the memory. Wherein, when the program runs, it executes the above defense method for website attacks.

[0119] The processor is used to run a program that performs the following functions: process the interaction data between the client and the server to generate a first sequence, where the interaction data is the data generated each time the client accesses the website corresponding to the server; determine the second sequence corresponding to each website according to the multiple first sequences corresponding to each website, and determine the similarity value between the second sequences corresponding to each website, cluster the second sequences whose similarity values meet the preset conditions to generate a clustering cluster, and determine the third sequence corresponding to the clustering cluster according to the first sequences included in the clustering cluster; determine the loss function of the perturbation generation model according to the first sequence, the third sequence, and the sample sequence, determine the gradient value of the perturbation generation model according to the loss function and the sample sequence, and determine the perturbation generation model according to the loss function and the gradient value, where the sample sequence is the first sequence added with a preset perturbation value; train the perturbation generation model to obtain the target perturbation value of the first sequence and the target gradient value corresponding to the target perturbation value, and add the target gradient value to the first sequence to generate a first target sequence for interfering with the website attacker.

[0120] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages and disadvantages of the embodiments.

[0121] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0122] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in an electrical or other form.

[0123] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0124] In addition, the functional units in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0125] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the related technology, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.

[0126] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.

Claims

1. A defense method against website attacks, characterized in that, it includes: processing the interaction data between the client and the server to generate a first sequence, where the interaction data is the data generated each time the client accesses the website corresponding to the server; determining, according to the multiple first sequences corresponding to each website, a second sequence corresponding to each website, determining the similarity values between the second sequences corresponding to each website, clustering the second sequences whose similarity values meet the preset conditions to generate a clustering cluster, and determining a third sequence corresponding to the clustering cluster according to the first sequences included in the clustering cluster; determining the loss function of the perturbation generation model according to the first sequence, the third sequence and the sample sequence, determining the gradient value of the perturbation generation model according to the loss function and the sample sequence, and determining the perturbation generation model according to the loss function and the gradient value, where the sample sequence is the first sequence added with a preset perturbation value; training the perturbation generation model to obtain the target perturbation value of the first sequence and the target gradient value corresponding to the target perturbation value, and adding the target gradient value to the first sequence to generate a first target sequence for interfering with website attackers.

2. The method according to claim 1, characterized in that, determining the similarity values between the second sequences corresponding to each website includes: subtracting the values at the same positions in the second sequences corresponding to any two websites among each website; summing up the differences obtained after subtraction to obtain the similarity value between the second sequences corresponding to any two websites; determining the similarity values between the second sequences corresponding to each website among the multiple websites according to the similarity values between the second sequences corresponding to any two websites.

3. The method according to claim 1, characterized in that, processing the interaction data between the client and the server to generate a first sequence includes: if the sub-data of the interaction data is the data sent from the client to the server, representing the sub-data with a first character, and if the sub-data of the interaction data is the data sent from the server to the client, representing the sub-data with a second character; aggregating multiple consecutive first characters to generate a first aggregation result, and aggregating multiple consecutive second characters to generate a second aggregation result; determining the first sequence according to the first character, the second character, the first aggregation result and the second aggregation result.

4. The method according to claim 1, characterized in that, determining the second sequence corresponding to each website according to the multiple first sequences corresponding to each website includes: determining the average value of the values at each position according to the values at each position in each of the multiple first sequences; determining the second sequence according to the average value of the values at each position, where the length of the second sequence is the same as the length of the first sequence.

5. The method according to claim 1, characterized in that, the method further includes: When the website prediction value of the sample sequence is the same as the website prediction value of the third sequence, stop training the perturbation generation model, where the website prediction value of the sample sequence is the first probability value generated by the trained classification model according to the sample sequence, the website prediction value of the third sequence is the second probability value generated by the trained classification model according to the third sequence, the first probability value is the probability that the client accesses the website corresponding to the sample sequence, and the second probability value is the probability that the client accesses the website corresponding to the third sequence.

6. The method according to claim 5, wherein, the trained classification model is used to replace the classification model of the website attacker and is used to output the probability value of the client accessing each website in the preset website library.

7. The method according to claim 1, wherein, the method further includes: determining the loss function of the perturbation generation model according to the bandwidth threshold, where the bandwidth is the bandwidth of the network used by the client to interact with the website corresponding to the server, and the bandwidth threshold is the minimum value and the maximum value of the bandwidth.

8. The method according to claim 1, wherein, the method further includes: determining the perturbation value at the current moment according to the perturbation value and the positive value sequence of the gradient value at the previous adjacent moment of the current moment, where the perturbation value at the current moment is the target perturbation value, and the positive value sequence of the gradient value is a sequence obtained by retaining the elements with positive gradient vectors in the gradient value.

9. The method according to claim 1, wherein, determining the third sequence corresponding to the clustering cluster according to the first sequence included in the clustering cluster includes: taking the absolute value of the numerical value at each position in each of the first sequences included in the clustering cluster to generate a plurality of fourth sequences corresponding to the first sequences; determining the maximum value of the numerical values at each position in the plurality of fourth sequences according to the plurality of fourth sequences, and determining the maximum value as the third sequence corresponding to the clustering cluster.

10. The method according to claim 1, wherein, the method further includes: when the length of the first sequence is less than the preset target length, making the length of the first sequence equal to the target length by adding a preset numerical value to the tail of the first sequence, where the target length is the preset length of the first sequence; when the length of the first sequence is greater than the target length, sequentially removing the numerical values at the outermost ends of the first sequence until the length of the first sequence is equal to the target length.

11. A defense device for website attacks, wherein, comprising: a generation module, configured to process the interaction data between the client and the server to generate a first sequence, where the interaction data is the data generated by the client each time it accesses the website corresponding to the server; A clustering module, configured to determine a second sequence corresponding to each website according to a plurality of the first sequences corresponding to each website, determine a similarity value between the second sequences corresponding to each website, cluster the second sequences whose similarity values meet a preset condition to generate a clustering cluster, and determine a third sequence corresponding to the clustering cluster according to the first sequences included in the clustering cluster; A determination module, configured to determine a loss function of a perturbation generation model according to the first sequence, the third sequence, and a sample sequence, determine a gradient value of the perturbation generation model according to the loss function and the sample sequence, and determine the perturbation generation model according to the loss function and the gradient value, where the sample sequence is the first sequence added with a preset perturbation value; An addition module, configured to train the perturbation generation model to obtain a target perturbation value of the first sequence and a target gradient value corresponding to the target perturbation value, and add the target gradient value to the first sequence to generate a first target sequence for interfering with a website attacker.

12. A non-volatile storage medium, characterized in that, the non-volatile storage medium includes a stored program, wherein when the program runs, it controls the device where the non-volatile storage medium is located to execute the defense method for website attacks according to any one of claims 1 to 10.

13. An electronic device, characterized in that, it includes: a memory and a processor, the processor is configured to run a program stored in the memory, wherein when the program runs, it executes the defense method for website attacks according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Differential privacy-based data exception detection method

    CN110334548A

  • Intelligent traffic confusion method and system for website fingerprint defense and computer storage medium

    CN113347156A