Detection Method, System and Device for Request Information
By storing the user's IP address and permission information in the network server, comparing it, and combining with the back-end server's detection of encrypted data, the problem of inaccurately preventing overright access in the prior art is solved, and the strict overriding behavior control and operation requests for the web system of network security products is achieved.
Patent Information
- Application Number
- CN202211303455.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-24
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-10-24
AI Technical Summary
The prior art prevents overprivileged access by binding the key to the user's identity, but cannot accurately prevent the problem of overprivileged access.
By storing the user's IP address and permission information in the network server and comparing it when receiving the operation request, the legality of the operation request is determined. If there is no abnormality in the comparison result, the operation request is sent to the backend server for detection of encrypted data to determine the risk-freeness of the request information.
It realizes strict control of the overriding behavior of the web system of network security products, ensures the legality and security of operation requests, and prevents information tampering and overriding access.
Smart Images

Figure CN115664794B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet information processing, and in particular, to a method, a system and a device for detecting request information. Background Art
[0002] Network security products are involved in all walks of life, and the learning costs for the configuration, management and maintenance of network security products are relatively high. With the rapid development of Web system-related technologies and the continuous enhancement of Web security capabilities, the current mainstream management method for network security products is through Web systems, which can greatly reduce the learning costs of network security products.
[0003] Configuring network security products through Web systems is convenient and fast, but it also exposes a lot of information to the client. If no permission-related control is performed or the control is not thorough, it is very easy to be maliciously exploited by people, and various means can be used to tamper with or replay HTTP (Hyper Text Transfer Protocol) requests sent by the Web system, leading to horizontal privilege escalation, vertical privilege escalation, or unauthorized privilege escalation, resulting in a series of very serious consequences in business such as network paralysis and information leakage. Due to the limited capabilities of each manager and the strict permission requirements for administrators in some special industries for different roles (such as system administrators, security administrators, and audit administrators), it is necessary to perform safe and strict privilege escalation behavior control on the Web system of network security products to ensure the normal use of network security products.
[0004] In the prior art, when preventing unauthorized access, the method adopted is to bind user information with a dynamically allocated key and determine the user identity according to the key, so as to prevent the occurrence of unauthorized access behavior. However, this method only binds user information and the key, and when modifying other contents in the HTTP access sent to the Web system, the unauthorized access operation can be completed while the user information and the key remain unchanged.
[0005] Regarding the problem that the method of binding a key with a user identity in the related art cannot accurately prevent unauthorized access, no effective solution has been proposed yet. Summary of the Invention
[0006] The present application provides a method, a system and a device for detecting request information to solve the problem in the related art that the method of binding a key with a user identity cannot accurately prevent unauthorized access.
[0007] According to one aspect of the present application, a method for detecting request information is provided. The method includes: a network server receives operation request information sent by a front-end server, where the operation request information is the information sent after a user logs in to the front-end server, and the operation request information at least includes encrypted data and target data, the target data at least includes a first IP address and a first permission information, and the encrypted data is obtained by encrypting the target data; obtaining a second IP address and a second permission information stored in the network server, and respectively comparing the first IP address with the second IP address and comparing the first permission information with the second permission information to obtain a first detection result, where the second IP address is the IP address when the user logs in to the front-end server, and the second permission information is the permission information when the user logs in to the front-end server; in the case where the first detection result indicates that the operation request information is normal, the network server sends the operation request information to the back-end server, and the back-end server detects the encrypted data to obtain a second detection result, where in the case where the second detection result indicates that the operation request information is normal, it is determined that the operation request information is a risk-free request information.
[0008] Optionally, respectively comparing the first IP address with the second IP address and comparing the first permission information with the second permission information to obtain a first detection result includes: comparing the first IP address with the second IP address to obtain a first comparison result; in the case where the first comparison result indicates that the first IP address is different from the second IP address, it is determined that the operation request information is abnormal, obtaining a first abnormal detection result, and sending a first warning message, where the first warning message indicates that the user's IP address is abnormal; in the case where the first comparison result indicates that the first IP address is the same as the second IP address, comparing the first permission information with the second permission information to obtain a second comparison result; in the case where the second comparison result indicates that the first permission information is different from the second permission information, it is determined that the operation request information is abnormal, obtaining a second abnormal detection result, and sending a second warning message, where the second warning message indicates that the permission information has changed; in the case where the second comparison result indicates that the first permission information is the same as the second permission information, it is determined that the operation request information is normal, obtaining a normal detection result, where the first detection result includes the first abnormal detection result, the second abnormal detection result, and the normal detection result, and the normal detection result is used to indicate that the operation request information is normal.
[0009] Optionally, the first permission information includes at least one of the following: a preset account, a first role, a first identifier, and the second permission information includes at least one of the following: an account, a second identifier, a second role. Comparing the first permission information with the second permission information, the obtained second comparison result includes: comparing the first role with the second role to obtain a second comparison result; comparing the first identifier with the second identifier to obtain a third comparison result; comparing the preset account with the account in the second permission information to obtain a fourth comparison result; in the case where there is an abnormal comparison result among the second comparison result, the third comparison result, and the fourth comparison result, determining the second comparison result as that the first permission information is different from the second permission information, where the abnormal comparison result indicates that the contents of the comparison object and the object to be compared are inconsistent; in the case where there is no abnormal comparison result among the second comparison result, the third comparison result, and the fourth comparison result, determining the second comparison result as that the first permission information is the same as the second permission information.
[0010] Optionally, before the network server receives the operation request information sent by the front-end server, the method further includes: the network server receives the login request information sent by the front-end server and obtains a second IP address, where the login request information includes the user's account and password; sending the login request information to the login program through the network server and receiving the verification result and the second role returned by the login program; in the case where the verification result indicates that the login request information is correct, creating a second identifier through the network server and determining the account, the second identifier, and the second role as the second permission information; storing the second permission information and the second IP address in the memory of the network server and sending the second permission information to the front-end server.
[0011] Optionally, after storing the second permission information and the second IP address in the memory of the network server, the method further includes: determining the storage duration of the second identifier in the memory to obtain a target duration; judging whether the target duration exceeds a preset duration; in the case where the target duration exceeds the preset duration, deleting the second permission information and the second IP address from the memory of the network server.
[0012] Optionally, after storing the second permission information and the second IP address in the memory of the network server, the method further includes: after receiving the user logout instruction sent by the front-end server, deleting the second permission information and the second IP address from the memory of the network server.
[0013] According to one aspect of the present application, a method for detecting request information is provided. The method includes: receiving operation request information sent by a network server, and performing combined encryption on target data in the operation request information to obtain target encrypted data, where the operation request information at least includes encrypted data and target data, and the encrypted data is obtained by encrypting the target data; comparing the target encrypted data with the encrypted data in the operation request information to obtain a third comparison result; in the case where the third comparison result indicates that the target encrypted data is different from the encrypted data in the operation request information, determining that the operation request information is abnormal and sending a third warning message, where the third warning message indicates that the operation request information has been tampered with; in the case where the third comparison result indicates that the target encrypted data is the same as the encrypted data in the operation request information, determining that the operation request information is normal.
[0014] According to another aspect of the present application, a system for detecting request information is provided. The system includes: a front-end server for sending the user's login request information to the network server and sending the user's operation request information to the network server after successful login, where the operation request information at least includes encrypted data and target data, the target data at least includes a first IP address and first permission information, the encrypted data is obtained by encrypting the target data, and the login request information includes the user's account and password; a network server for receiving the login request information sent by the front-end server, obtaining a second IP address, sending the login request information to a login program, and determining the user's second permission information and storing the second permission information and the second IP address in the case where the login program passes the verification, and further for receiving the operation request information sent by the front-end server, detecting the operation request information based on the second IP address and the second permission information, and sending the operation request information to the back-end server in the case where no abnormality is detected in the operation request information; a login program for receiving the login request information and verifying the login request information, and sending a message to the network server in the case where the verification passes; a back-end server for receiving the operation request information, performing combined encryption on the target data in the operation request information to obtain target encrypted data, and comparing the target encrypted data with the encrypted data in the operation request information, and determining that the operation request information is risk-free information in the case where the target encrypted data is the same as the encrypted data in the operation request information.
[0015] According to another aspect of the present application, a detection device for request information is provided. The device includes: a sending unit, configured to receive, by a network server, operation request information sent by a front-end server, where the operation request information is information sent after a user logs in to the front-end server, and the operation request information at least includes encrypted data and target data, the target data at least includes a first IP address and first permission information, and the encrypted data is obtained by encrypting the target data; a first comparison unit, configured to obtain a second IP address and second permission information stored in the network server, and respectively compare the first IP address with the second IP address and compare the first permission information with the second permission information to obtain a first detection result, where the second IP address is the IP address when the user logs in to the front-end server, and the second permission information is the permission information when the user logs in to the front-end server; a detection unit, configured to, when the first detection result indicates that the operation request information is normal, the network server sends the operation request information to a back-end server, and the back-end server detects the encrypted data to obtain a second detection result, where when the second detection result indicates that the operation request information is normal, it is determined that the operation request information is a risk-free request information.
[0016] According to another aspect of the present application, a detection device for request information is provided. The device includes: a first receiving unit, configured to receive operation request information sent by a network server and perform combined encryption on the target data in the operation request information to obtain target encrypted data, where the operation request information at least includes encrypted data and target data, and the encrypted data is obtained by encrypting the target data; a second comparison unit, configured to compare the target encrypted data with the encrypted data in the operation request information to obtain a third comparison result; a first determination unit, configured to, when the third comparison result indicates that the target encrypted data is different from the encrypted data in the operation request information, determine that the operation request information is abnormal and issue a third warning message, where the third warning message indicates that the operation request information has been tampered with; a second determination unit, configured to, when the third comparison result indicates that the target encrypted data is the same as the encrypted data in the operation request information, determine that the operation request information is normal.
[0017] According to another aspect of an embodiment of the present invention, a computer storage medium is further provided. The computer storage medium is used to store a program, where when the program runs, it controls a device where the computer storage medium is located to execute a detection method for request information.
[0018] According to another aspect of an embodiment of the present invention, an electronic device is further provided, including one or more processors and a memory; the memory stores computer-readable instructions, and the processor is configured to run the computer-readable instructions, where when the computer-readable instructions run, they execute a detection method for request information.
[0019] Through this application, the following steps are adopted: The network server receives the operation request information sent by the front-end server. Among them, the operation request information is the information sent after the user logs in to the front-end server. The operation request information at least includes encrypted data and target data. The target data at least includes a first IP address and first permission information. The encrypted data is obtained by encrypting the target data; obtain the second IP address and second permission information stored in the network server, and compare the first IP address with the second IP address and compare the first permission information with the second permission information respectively to obtain a first detection result. Among them, the second IP address is the IP address when the user logs in to the front-end server, and the second permission information is the permission information when the user logs in to the front-end server; when the first detection result indicates that the operation request information is normal, the network server sends the operation request information to the back-end server, and the back-end server detects the encrypted data to obtain a second detection result. Among them, when the second detection result indicates that the operation request information is normal, it is determined that the operation request information is a risk-free request information. This solves the problem in the related art that by binding the key to the user identity to prevent unauthorized access, it is impossible to accurately prevent unauthorized access. By comparing the IP address at the time of sending the operation request with the IP address stored in the network server at the time of login, and comparing the permission information in the operation request information with the second permission information stored in the network server at the time of login, and when the comparison result is normal, the back-end server verifies the encrypted information in the operation request information, so as to ensure that when there is a difference between the operation request information and the request information registered when the user is allowed to operate on the front-end server, the difference phenomenon can be discovered and processed in time, and thus the effect of accurately and comprehensively preventing the occurrence of unauthorized access caused by information tampering is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The drawings constituting a part of this application are used to provide a further understanding of this application. The schematic embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation of this application. In the drawings:
[0021] Figure 1 is the flowchart of the method for detecting request information provided by an embodiment of this application Figure 1 ;
[0022] Figure 2 is the flowchart of an optional method for detecting login request information provided by an embodiment of this application;
[0023] Figure 3 is the flowchart of the method for detecting request information provided by an embodiment of this application Figure 2 ;
[0024] Figure 4It is a flowchart of an optional method for detecting operation request information provided according to an embodiment of the present application;
[0025] Figure 5 It is a schematic diagram of a detection system for request information provided according to an embodiment of the present application;
[0026] Figure 6 It is a schematic Figure 1 ;
[0027] Figure 7 It is a schematic Figure 2 。 Detailed implementation manners
[0028] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0029] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so as to describe the embodiments of the present application here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0031] It should be noted that the relevant information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in the present disclosure are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set between the present system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and after receiving the consent information feedback by the aforementioned users or institutions, the relevant information is obtained.
[0032] It should be noted that the detection method, system, and device for request information determined by the present disclosure can be used in the field of Internet information processing, and can also be used in any field other than the field of Internet information processing. The application field of the detection method, system, and device for request information determined by the present disclosure is not limited.
[0033] According to an embodiment of the present application, a method for detecting request information is provided.
[0034] Figure 1 is the flow of the method for detecting request information provided according to an embodiment of the present application Figure 1 As Figure 1 shown, the method includes the following steps:
[0035] Step S102, the network server receives the operation request information sent by the front-end server. Among them, the operation request information is the information sent after the user logs in to the front-end server. The operation request information at least includes encrypted data and target data. The target data at least includes a first IP address and first permission information, and the encrypted data is obtained by encrypting the target data.
[0036] Specifically, the front-end server is also the front-end of the network security product, which is used to interact with the user. The network server is used for data transmission and storage verification. The operation request information is the information carried in the request sent by the user, and can be an HTTP request. The first IP address is the IP address from which the user sends the request information, and the first permission information is also the permission information of the user, which can represent information such as the user's role, account, and attributes. Thus, according to the permission information, it can be determined whether the user can execute the request.
[0037] When a user configures a network security product using a Web system, the user can log in at the login interface of the network security product and perform network security configuration on the front-end page of the network security product after logging in. After filling in the data and clicking "OK", an operation request for the network security configuration and operation request information are generated in the front-end server. Among them, the operation request is an HTTP request, and the operation request information carried in the HTTP request includes three parts. One part is the network security configuration filled in by the user. For example, user A sets user B as the administrator of the network security product. Another part is the information of this request and this user, that is, the target data. Among them, the first IP address included in the target data is the IP address of the user who sent this request, and the first permission information is the information such as the role, random identifier, and account of this user obtained by this user from the front-end server. The target data may also include the URI and HTTP method of this operation request. The last part is the encrypted data, which is obtained by encrypting the target data. That is, the URI, HTTP method, account, role, network security configuration content, and random identifier are combined and encrypted. Among them, the role is the identity information of this user. For example, the role of this user is an administrator or an employee, etc.
[0038] After the front-end server generates the operation request information corresponding to the user request, the front-end server sends the operation request information to the network server for content determination, so as to check the operation request information in the network server.
[0039] Step S104: Obtain the second IP address and the second permission information stored in the network server, and compare the first IP address with the second IP address and the first permission information with the second permission information respectively to obtain the first detection result. Among them, the second IP address is the IP address when the user logs in to the front-end server, and the second permission information is the permission information when the user logs in to the front-end server.
[0040] Specifically, after the network server receives the operation request information, it first determines whether the IP address of the user who sent the operation request information has changed. Therefore, it is necessary to verify the first IP address in the target data of the operation request information. The verification method is to compare the second IP address stored in the network server when the user logs in with the first IP address, so as to determine whether the IP address is abnormal according to the comparison result.
[0041] Furthermore, when the IP address is normal, it is further determined whether the permission information is the same. The determination method is to compare the second permission information stored in the network server when the user logs in with the first permission information, so as to determine whether the permission information is abnormal according to the comparison result.
[0042] Step S106, when the first detection result indicates that the operation request information is normal, the network server sends the operation request information to the backend server, and the backend server detects the encrypted data to obtain a second detection result. Among them, when the second detection result indicates that the operation request information is normal, it is determined that the operation request information is risk-free request information.
[0043] Specifically, when both the first permission information and the first IP address are normal, the network server will send the operation request information to the backend server. The backend server verifies the encrypted data. When the encrypted data is normal, it is determined that there is no phenomenon of unauthorized access for this operation request, and the network security product can be configured according to the network security configuration filled in by the user in the operation request information. Among them, the method for verifying the encrypted data can be to encrypt the target data through the same encryption method in the backend server and compare the encryption result with the encrypted data, so as to determine whether the target data has been tampered with according to the comparison result.
[0044] The request information detection method provided by the embodiments of this application receives, through a network server, operation request information sent by a front-end server. The operation request information is information sent after a user logs in to the front-end server, and at least includes encrypted data and target data. The target data at least includes a first IP address and first permission information, and the encrypted data is obtained by encrypting the target data. Obtain a second IP address and second permission information stored in the network server, and compare the first IP address with the second IP address and the first permission information with the second permission information respectively to obtain a first detection result. The second IP address is the IP address when the user logs in to the front-end server, and the second permission information is the permission information when the user logs in to the front-end server. When the first detection result indicates that the operation request information is normal, the network server sends the operation request information to the back-end server, and the back-end server detects the encrypted data to obtain a second detection result. When the second detection result indicates that the operation request information is normal, it is determined that the operation request information is a risk-free request information. This solves the problem in the related art that by binding a key to a user identity to prevent unauthorized access, unauthorized access cannot be accurately prevented. By comparing the IP address when sending an operation request with the IP address stored in the network server during login, and comparing the permission information in the operation request information with the second permission information stored in the network server during login, and when the comparison result is normal, the back-end server verifies the encrypted information in the operation request information, so as to ensure that when there is a difference between the operation request information and the request information registered when the user is allowed to operate on the front-end server, the difference phenomenon can be discovered and processed in time, and further achieves the effect of accurately and comprehensively preventing the occurrence of unauthorized access caused by information tampering.
[0045] Optionally, in the request information detection method provided by the embodiments of this application, before the network server receives the operation request information sent by the front-end server, the method further includes: The network server receives the login request information sent by the front-end server and obtains the second IP address. The login request information includes the user's account and password. Send the login request information to the login program through the network server, and receive the verification result and the second role returned by the login program. When the verification result indicates that the login request information is correct, create a second identifier through the network server, and determine the account, the second identifier, and the second role as the second permission information. Store the second permission information and the second IP address in the memory of the network server, and send the second permission information to the front-end server.
[0046] Specifically, the second IP address is the IP address of the user obtained by the front end when the user logs in to the network security product. The login request includes the user's account name and password. After the network server obtains the login request and the IP address, it temporarily stores the second IP address, sends the login request to the login program, and the login program determines whether the account and password in the login request information are correct and returns the verification result.
[0047] Optionally, in the request information detection method provided in the embodiments of the present application, the login program is used to determine whether the account and password in the login request information are correct, and is also used to send the second role to the network server.
[0048] It should be noted that there is a comparison table of account-password-role stored in the login program. After receiving the login request information, the login program will determine whether there is an account in the login request information in the comparison table. If the account exists, it will determine whether the password is the same as the corresponding password. When both the account and password are correct, the login program will obtain the role corresponding to the account from the comparison table to get the second role, and return the second role and the verification result to the network server. At this time, the verification result is that the login request information is correct.
[0049] If the account does not exist in the comparison table or the password is incorrect compared with the corresponding password in the comparison table, the verification result will be determined as abnormal, and the abnormal verification result will be returned to the network server. The network server will return the abnormal verification result to the front-end server to inform the user that the login fails.
[0050] Further, when the verification result received by the network server is that the login request information is correct, a random identifier, that is, the second identifier, is created, and the second identifier, the second role, and the user's account are determined as the second permission information, and the second permission information is stored in the network server to identify requests when the user sends subsequent requests, ensuring that there is no phenomenon of unauthorized access to request information.
[0051] It should be noted that after obtaining the second permission information, the network server will send the second permission information to the front-end server and store it in the front-end server. When the front-end server receives an operation request, it will regenerate the target information according to the information of the operation request and the second permission information. At this time, the second permission information in the front-end server may be tampered with and changed to the first permission information. Therefore, it is possible to determine whether the first permission information has been tampered with by comparing the first permission information with the second permission information.
[0052] Figure 2 It is a flowchart of an optional login request information detection method provided according to the embodiments of the present application, as Figure 2As shown, after the user enters the account and password in the client of the front-end server, the client will generate login request information, including: the account, password, and the user's IP address, and send the login request information to the network server. The network server stores the IP address and determines that the request information is login request information. In the case of login request information, the login request information is sent to the login program. Whether the user can log in is determined by the comparison table of account-password-role stored in the login program. In the case where the account or password is incorrect, an exception message is returned to the client through the network server. In the case where the account and password are correct, the user role is obtained and sent to the network server. After generating a random identifier, the network server sends the role, account, and identifier to the client, thus completing the user's login.
[0053] Optionally, in the request information detection method provided in the embodiment of the present application, in the request information detection method provided in the embodiment of the present application, the first IP address is compared with the second IP address respectively, and the first permission information is compared with the second permission information. The first detection result obtained includes: comparing the first IP address with the second IP address to obtain a first comparison result; in the case where the first comparison result indicates that the first IP address is different from the second IP address, it is determined that the operation request information is abnormal, and a first abnormal detection result is obtained, and a first warning message is sent, where the first warning message indicates that the user's IP address is abnormal; in the case where the first comparison result indicates that the first IP address is the same as the second IP address, the first permission information is compared with the second permission information to obtain a second comparison result; in the case where the second comparison result indicates that the first permission information is different from the second permission information, it is determined that the operation request information is abnormal, and a second abnormal detection result is obtained, and a second warning message is sent, where the second warning message indicates that the permission information has changed; in the case where the second comparison result indicates that the first permission information is the same as the second permission information, it is determined that the operation request information is normal, and a normal detection result is obtained. The first detection result includes the first abnormal detection result, the second abnormal detection result, and the normal detection result, and the normal detection result is used to indicate that the operation request information is normal.
[0054] Specifically, after the network server receives the operation request information, it first obtains the first IP address in the operation request information and compares the first IP address with the second IP address stored in the network server. In the case where the IP address has changed, the first IP address is different from the second IP address. At this time, it is determined that the user has changed the IP address and there may be a risk. Therefore, a first warning message is sent, and it is determined that the operation request information is abnormal, thereby blocking the operation request.
[0055] Optionally, in the method for detecting request information provided in the embodiments of the present application, the first permission information at least includes one of the following: a preset account, a first role, and a first identifier, and the second permission information at least includes one of the following: an account, a second identifier, and a second role. Comparing the first permission information with the second permission information, the obtained second comparison result includes: comparing the first role with the second role to obtain a second comparison result; comparing the first identifier with the second identifier to obtain a third comparison result; comparing the preset account with the account in the second permission information to obtain a fourth comparison result; in the case where there is an abnormal comparison result among the second comparison result, the third comparison result, and the fourth comparison result, determining the second comparison result as that the first permission information is different from the second permission information, where the abnormal comparison result indicates that the content of the comparison object and the object to be compared is inconsistent; in the case where there is no abnormal comparison result among the second comparison result, the third comparison result, and the fourth comparison result, determining the second comparison result as that the first permission information is the same as the second permission information.
[0056] Further, in the case where the first IP address is the same as the second IP address, obtain the first permission information in the operation request information, and compare the preset account information, the first role, and the first identifier in the first permission information with the account information, the second role, and the second identifier in the second permission information in sequence. Wherein, the preset account information is the account information of the account used by the user when sending the operation request information, and the account information in the second permission information is the account information recorded when the user logs in. Since the first permission information is the second permission information sent from the network server to the front-end server, therefore, in the case where the first permission information is not tampered with, it should be exactly the same as the second permission information. Therefore, in the case where the account information, the first role, and the first identifier in the first permission information are exactly the same as the account information, the second role, and the second identifier in the second permission information, it indicates that the first permission information is the same as the second permission information, and there is no abnormality in the operation request information. Through this method, it is possible to accurately determine whether the user has tampered with the role, identifier, and account information in the operation request information when sending the operation request, thereby ensuring that there will be no phenomenon of unauthorized access to the request information.
[0057] Optionally, in the method for detecting request information provided in the embodiments of the present application, after storing the second permission information and the second IP address in the memory of the network server, the method further includes: determining the storage duration of the second identifier in the memory to obtain a target duration; judging whether the target duration exceeds a preset duration; in the case where the target duration exceeds the preset duration, deleting the second permission information and the second IP address from the memory of the network server.
[0058] It should be noted that, in order to prevent excessive memory occupation in the network server and affect the normal operation of the network server, it is necessary to periodically delete the permission information of each request stored in the network server.
[0059] Specifically, when the network server creates each identifier, it will record the generation time of the identifier at the same time, and periodically determine the time difference between the current time and the generation time, that is, the storage duration of the identifier in the memory. When this duration is greater than the preset duration, it indicates that the storage time of the second permission information and the second IP address corresponding to the identifier in the network server is too long and needs to be cleared, so as to ensure that the memory occupation pressure of the network server is small.
[0060] Optionally, in the request information detection method provided in the embodiments of the present application, after storing the second permission information and the second IP address in the memory of the network server, the method further includes: after receiving the user logout instruction sent by the front-end server, deleting the second permission information and the second IP address from the memory of the network server.
[0061] Similarly, in addition to determining whether to delete the second permission information and the second IP address based on the existence duration of the identifier, it can also be determined whether the user corresponding to the second permission information and the second IP address has logged out of the front-end login interface of the network security product. After the user logs out, the front-end will send the user logout instruction to the network server, and the network server will determine the second permission information and the second IP address corresponding to this login of the user according to the identifier in the user logout instruction, and delete the second permission information and the second IP address, so as to ensure that the memory occupation pressure of the network server is small.
[0062] According to an embodiment of the present application, a request information detection method is provided.
[0063] Figure 3 It is the flow of the request information detection method provided in the embodiments of the present application Figure 2 As Figure 3 shown, the method includes the following steps:
[0064] Step S302, receive the operation request information sent by the network server, and perform combined encryption on the target data in the operation request information to obtain target encrypted data, where the operation request information at least includes encrypted data and target data, and the encrypted data is obtained by encrypting the target data.
[0065] Specifically, the backend server receives the operation request information sent by the network server. At this time, the first IP address and the first permission information in the operation request information are both correct. At this time, it is necessary to determine whether the remaining content in the operation request information is correct. The target encrypted data can be obtained by encrypting the target data in the operation request information. That is, the URI, HTTP method, account, role, network security configuration content, and random identifier are combined and encrypted, so as to judge the encrypted data according to the target encrypted data.
[0066] Step S304: Compare the target encrypted data with the encrypted data in the operation request information to obtain a third comparison result.
[0067] Specifically, after obtaining the target encrypted data, the target encrypted data can be compared with the encrypted data carried in the operation request information to determine whether the target encrypted data is correct.
[0068] Step S306: When the third comparison result indicates that the target encrypted data is different from the encrypted data in the operation request information, it is determined that the operation request information is abnormal, and a third warning message is sent, where the third warning message indicates that the operation request information has been tampered with.
[0069] Specifically, when the target encrypted data is different from the encrypted data in the operation request information, it indicates that the target encrypted data is abnormal. Furthermore, it can indicate that parameters such as the URI or HTTP method in the request sending process in the operation request information have changed, so as to discover the unauthorized operation of this user.
[0070] For example, when the content of the URI, HTTP method, or network security configuration in the request information changes, the encrypted data in the corresponding request information also needs to be updated synchronously. Since the data tamperer does not know the encryption method agreed upon by the front-end server and the back-end server, the tamperer cannot modify the encrypted data synchronously. That is, at this time, the encrypted data calculated by the back-end server according to the request information will be inconsistent with the encrypted data actually carried in the request information, and thus it can be detected that the data in the request information has been tampered with, and the unauthorized operation can be discovered.
[0071] Step S308: When the third comparison result indicates that the target encrypted data is the same as the encrypted data in the operation request information, it is determined that the operation request information is normal.
[0072] Specifically, when the target encrypted data is the same as the encrypted data in the operation request information, it indicates that all the operation request information of this user is correct and error-free, and conforms to the identity information and access permissions corresponding to this user. At this time, the network security configuration filled in the operation request information of this user can be executed to complete this request.
[0073] The detection method for request information provided by the embodiments of the present application receives an operation request information sent by a network server, combines and encrypts target data in the operation request information to obtain target encrypted data, where the operation request information at least includes encrypted data and target data, and the encrypted data is obtained by encrypting the target data; compares the target encrypted data with the encrypted data in the operation request information to obtain a third comparison result; when the third comparison result indicates that the target encrypted data is different from the encrypted data in the operation request information, it is determined that the operation request information is abnormal, and a third warning message is sent, where the third warning message indicates that the operation request information has been tampered with; when the third comparison result indicates that the target encrypted data is the same as the encrypted data in the operation request information, it is determined that the operation request information is normal. This solves the problem in the related art that by binding the key to the user identity to prevent unauthorized access, unauthorized access cannot be accurately prevented. By comparing the IP address at the time of sending the operation request with the IP address stored in the network server at the time of login, and comparing the permission information in the operation request information with the second permission information stored in the network server at the time of login, and when the comparison results are normal, the back-end server verifies the encrypted information in the operation request information, so as to ensure that when there is a difference between the operation request information and the request information registered when the user is allowed to operate on the front-end server, the difference phenomenon can be discovered and processed in time, and thus the effect of accurately and comprehensively preventing the occurrence of unauthorized access caused by information tampering is achieved.
[0074] Figure 4 is a flowchart of an optional detection method for operation request information provided by the embodiments of the present application. As Figure 4 shown, after the user logs in to the front-end server, the user can fill in configuration information, which is the network security configuration content. After filling in the network security configuration content, the front-end server combines and encrypts the HTTP request method, URI, account, role, network security configuration content, and random identifier to obtain encrypted data, and sends the encrypted data, HTTP request method, URI, account, role, network security configuration content, random identifier, and IP address as operation request information to the network server.
[0075] Further, after receiving the operation request information, the network server first determines whether the IP address of this request is consistent with the IP address stored when the user logged in. If it is inconsistent, it indicates that there is a risk of unauthorized access to this request, so the request is blocked. If it is consistent, the network server sequentially determines whether the account, identifier, and role are consistent with the account, identifier, and role stored in the network server when logging in. If it is inconsistent, it indicates that there is a risk of unauthorized access to this request, so the request is blocked. If it is consistent, the network server sends the operation request information to the back-end server.
[0076] Finally, the backend server combines and encrypts the HTTP request method, URI, account, role, network security configuration content, and random identifier in the request information to obtain new encrypted data, and determines whether the new encrypted data is the same as the encrypted information in the request information. If they are inconsistent, it indicates that the request has been tampered with, and this request is blocked; if they are consistent, it indicates that the request has not been modified without authorization, and then the network security configuration content in the request can be executed. Thus, it is ensured that in the case of a difference between the operation request information and the request information registered when the user is allowed to operate on the front-end server, the difference phenomenon can be discovered and processed in a timely manner, and further, the effect of accurately and comprehensively preventing the occurrence of unauthorized access caused by information tampering is achieved.
[0077] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0078] The embodiment of the present application also provides a detection system for request information. It should be noted that the detection system for request information in the embodiment of the present application can be used to execute the detection method for request information provided by the embodiment of the present application. The following introduces the detection system for request information provided by the embodiment of the present application.
[0079] Figure 5 is a schematic diagram of the detection system for request information provided by the embodiment of the present application. As Figure 5 shown, the system includes:
[0080] A front-end server 51, configured to send the user's login request information to a network server 52, and send the user's operation request information to the network server 52 after successful login. Among them, the operation request information at least includes encrypted data and target data, the target data at least includes a first IP address and first permission information, the encrypted data is obtained by encrypting the target data, and the login request information includes the user's account and password.
[0081] Specifically, the front-end server 51 includes a client. The user can fill in the account and password in the client to log in to the network security product. After receiving the account and password, the client will send the account and password to the network server 52, that is, the login request information, and receive the verification result of the login request information. In the case of correct verification, the user can perform network security configuration content in the client, and the front-end server 51 will send operation request information to the network server 52 according to the content of the network security configuration content and the user information, so that the user can configure the network security product.
[0082] It should be noted that after the user successfully logs in, the front-end server 51 will receive the second permission information of the user during login, including: random identifier, role, and account during login, and store the second permission information as the first permission information in the front-end server 51. When the user sends an operation request message to the network server 52, since the operation request is an HTTP request, the front-end server 51 will obtain the HTTP request method and URI of the operation request message, and encrypt the HTTP request method, URI, first permission information, and network security configuration content to obtain encrypted data, and send the IP address, HTTP request method, URI, first permission information, and encrypted data to the network server 52 as the operation request message.
[0083] The network server 52 is used to receive the login request message sent by the front-end server 51, obtain the second IP address, send the login request message to the login program 53, and determine the second permission information of the user and store the second permission information and the second IP address when the verification by the login program 53 is passed. It is also used to receive the operation request message sent by the front-end server 51, detect the operation request message through the second IP address and the second permission information, and send the operation request message to the back-end server 54 when no abnormality is detected in the operation request message.
[0084] Specifically, when the network server 52 receives a request sent by the front-end server 51, it first determines whether the request is a login request through the request information of the request. In the case of a login request, it obtains the account and password from the login request message, as well as the IP address that sent the request, and sends the account and password to the login program 53, and receives the verification information returned by the login program 53. When the verification information is passed, the login program 53 will also return the second role, and the network server 52 will generate a random identifier, and send the identifier, role, and account information back to the front-end server 51, and store the identifier, role, and account information (i.e., the second permission information) and the IP address in the login request message in the network server 52.
[0085] When the user successfully logs in to the client of the front-end server 51, the user can send operation request information carrying network security configuration content to the network server 52. At this time, the network server 52 will obtain the first permission information from the operation request information. Since the first permission information is the second permission information sent by the network server 52 to the front-end server 51, therefore, when the first permission information has not been tampered with, it should be exactly the same as the second permission information. For this reason, the second permission information and the second IP address stored in the network server 52 can be used to compare with the first permission information and the first IP address in the operation request information. When they are exactly the same, it indicates that the permission information and the IP address have not been tampered with, and thus the operation request information can be sent to the back-end server 54.
[0086] The login program 53 is used to receive login request information, verify the login request information, and send a message to the network server 52 when the verification passes.
[0087] Specifically, a comparison table of account-password-role is stored in the login program 53. After receiving the login request information, the login program 53 will determine whether there is an account in the login request information in the comparison table. If the account exists, it will determine whether the password is the same as the corresponding password. When both the account and the password are correct, the login program 53 will obtain the role corresponding to the account from the comparison table, get the second role, and return the second role and the verification result to the network server 52. At this time, the verification result is that the login request information is correct.
[0088] If the account does not exist in the comparison table or the password is incorrect compared with the corresponding password in the comparison table, the verification result will be determined as abnormal, and the abnormal verification result will be returned to the network server 52. The network server 52 will return the abnormal verification result to the front-end server 51, thereby informing the user that the login failed.
[0089] The back-end server 54 is used to receive the operation request information, perform combined encryption on the target data in the operation request information to obtain target encrypted data, and compare the target encrypted data with the encrypted data in the operation request information. When the target encrypted data is the same as the encrypted data in the operation request information, it is determined that the operation request information is risk-free information.
[0090] Specifically, after receiving the operation request information, the backend server 54 extracts the URI, HTTP method, account, role, network security configuration content, and random identifier in the operation request, encrypts the URI, HTTP method, account, role, network security configuration content, and random identifier to obtain new encrypted data, and compares the new encrypted data with the encrypted data carried in the operation request information. When the new encrypted data is exactly the same as the carried encrypted data, it indicates that the content in the operation request information is completely correct, and the network security configuration content in the operation request information can be executed. This prevents the occurrence of unauthorized access caused by information tampering.
[0091] The embodiment of the present application also provides a detection device for request information. It should be noted that the detection device for request information in the embodiment of the present application can be used to execute the detection method for request information provided by the embodiment of the present application. The following introduces the detection device for request information provided by the embodiment of the present application.
[0092] Figure 6 It is a schematic diagram of the detection device for request information provided by the embodiment of the present application. Figure 1 As Figure 6 shown, the device includes: a sending unit 61, a first comparison unit 62, and a detection unit 63.
[0093] The sending unit 61 is configured to receive, by the network server, the operation request information sent by the front-end server. The operation request information is the information sent after the user logs in to the front-end server. The operation request information at least includes encrypted data and target data. The target data at least includes a first IP address and first permission information. The encrypted data is obtained by encrypting the target data.
[0094] Specifically, when a user configures a network security product using a Web system, the user can log in to the login interface of the network security product and perform network security configuration on the front-end page of the network security product after logging in. After filling in the data and clicking OK, an operation request for the network security configuration and operation request information are generated in the front-end server. Among them, the operation request is an HTTP request, and the operation request information carried in the HTTP request includes three parts. One part is the network security configuration filled in by the user. For example, user A sets user B as the administrator of the network security product. Another part is the information of this request and this user, that is, the target data. Among them, the first IP address included in the target data is the IP address of the user who sent this request, and the first permission information is the information such as the role, random identifier, account, etc. of this user obtained from the front-end server by this user. The target data may also include the URI and HTTP method of this operation request. The last part is the encrypted data, which is obtained by encrypting the target data. That is, the URI, HTTP method, account, role, network security configuration content, and random identifier are combined and encrypted. Among them, the role is the identity information of this user. For example, the role of this user is an administrator or an employee, etc.
[0095] After the front-end server generates the operation request information corresponding to the user request, the front-end server sends the operation request information to the network server for content determination, so as to check the operation request information in the network server.
[0096] The first comparison unit 62 is used to obtain the second IP address and the second permission information stored in the network server, and compare the first IP address with the second IP address and the first permission information with the second permission information respectively to obtain the first detection result. Among them, the second IP address is the IP address when the user logs in to the front-end server, and the second permission information is the permission information when the user logs in to the front-end server.
[0097] Specifically, after the network server receives the operation request information, it first determines whether the IP address of the user who sent the operation request information has changed. Therefore, it is necessary to verify the first IP address in the target data of the operation request information. The verification method is to compare the second IP address stored in the network server when the user logs in with the first IP address, so as to determine whether the IP address is abnormal according to the comparison result.
[0098] Furthermore, when the IP address is normal, it is further determined whether the permission information is the same. The determination method is to compare the second permission information stored in the network server when the user logs in with the first permission information, so as to determine whether the permission information is abnormal according to the comparison result.
[0099] The detection unit 63 is configured to, when the first detection result indicates that the operation request information is normal, the network server sends the operation request information to the backend server, and the backend server detects the encrypted data to obtain a second detection result. Wherein, when the second detection result indicates that the operation request information is normal, it is determined that the operation request information is risk-free request information.
[0100] Specifically, when both the first permission information and the first IP address are normal, the network server will send the operation request information to the backend server, and the backend server will verify the encrypted data. When the encrypted data is normal, it is determined that there is no phenomenon of unauthorized access for this operation request, and the network security product can be configured according to the network security configuration filled in by the user in the operation request information. Among them, the method for verifying the encrypted data can be to encrypt the target data in the backend server by the same encryption method and compare the encryption result with the encrypted data, so as to determine whether the target data has been tampered with according to the comparison result.
[0101] The detection device for request information provided by the embodiment of the present application receives, through the sending unit 61, the operation request information sent by the front-end server from the network server. The operation request information is the information sent after the user logs in to the front-end server. The operation request information at least includes encrypted data and target data. The target data at least includes a first IP address and first permission information. The encrypted data is obtained by encrypting the target data. The first comparison unit 62 obtains the second IP address and second permission information stored in the network server, and respectively compares the first IP address with the second IP address and the first permission information with the second permission information to obtain a first detection result. The second IP address is the IP address when the user logs in to the front-end server, and the second permission information is the permission information when the user logs in to the front-end server. The detection unit 63, when the first detection result indicates that the operation request information is normal, the network server sends the operation request information to the back-end server, and the back-end server detects the encrypted data to obtain a second detection result. When the second detection result indicates that the operation request information is normal, it is determined that the operation request information is a risk-free request information. This solves the problem in the related art that by binding the key to the user identity to prevent unauthorized access, unauthorized access cannot be accurately prevented. By comparing the IP address at the time of sending the operation request with the IP address stored in the network server at the time of login, and comparing the permission information in the operation request information with the second permission information stored in the network server at the time of login, and when the comparison result is normal, the back-end server verifies the encrypted information in the operation request information, so as to ensure that when there is a difference between the operation request information and the request information registered when the user is allowed to operate on the front-end server, the difference phenomenon can be timely discovered and processed, and thus the effect of accurately and comprehensively preventing the occurrence of unauthorized access caused by information tampering is achieved.
[0102] Optionally, in the detection device for request information provided in the embodiments of the present application, the first comparison unit 62 includes: a first comparison module for comparing the first IP address with the second IP address to obtain a first comparison result; a first determination module for determining that the operation request information is abnormal, obtaining a first abnormal detection result, and sending a first warning message when the first comparison result indicates that the first IP address is different from the second IP address, where the first warning message indicates that the user's IP address is abnormal; a second comparison module for comparing the first permission information with the second permission information to obtain a second comparison result when the first comparison result indicates that the first IP address is the same as the second IP address; a second determination module for determining that the operation request information is abnormal, obtaining a second abnormal detection result, and sending a second warning message when the second comparison result indicates that the first permission information is different from the second permission information, where the second warning message indicates that the permission information has changed; a third determination module for determining that the operation request information is normal and obtaining a normal detection result when the second comparison result indicates that the first permission information is the same as the second permission information, where the first detection result includes the first abnormal detection result, the second abnormal detection result, and the normal detection result, and the normal detection result is used to indicate that the operation request information is normal.
[0103] Specifically, after the network server receives the operation request information, it first obtains the first IP address in the operation request information and compares the first IP address with the second IP address stored in the network server. When the IP address has changed, the first IP address is different from the second IP address. At this time, it is determined that the user has changed the IP address and there may be a risk. Therefore, a first warning message is sent, and it is determined that the operation request information is abnormal, thereby blocking the operation request.
[0104] Optionally, in the detection device for request information provided in the embodiments of the present application, the first permission information includes at least one of the following: a preset account, a first role, and a first identifier. The second permission information includes at least one of the following: an account, a second identifier, and a second role. The second comparison module includes: a first comparison sub-module for comparing the first role with the second role to obtain a second comparison result; a second comparison sub-module for comparing the first identifier with the second identifier to obtain a third comparison result; a third comparison sub-module for comparing the preset account with the account in the second permission information to obtain a fourth comparison result; a first determination sub-module for, when there is an abnormal comparison result among the second comparison result, the third comparison result, and the fourth comparison result, determining that the first permission information is different from the second permission information, where the abnormal comparison result indicates that the content of the comparison object and the object to be compared is inconsistent; a second determination sub-module for, when there is no abnormal comparison result among the second comparison result, the third comparison result, and the fourth comparison result, determining that the first permission information is the same as the second permission information.
[0105] Further, when the first IP address is the same as the second IP address, the first permission information in the operation request information is obtained, and the account information, the first role, and the first identifier in the first permission information are respectively compared with the account information, the second role, and the second identifier in the second permission information in sequence. Since the first permission information is the second permission information sent by the network server to the front-end server, it should be exactly the same as the second permission information when the first permission information has not been tampered with. Therefore, when the account information, the first role, and the first identifier in the first permission information are exactly the same as the account information, the second role, and the second identifier in the second permission information, it indicates that the first permission information is the same as the second permission information and there is no abnormality in the operation request information. Through this method, it can be accurately determined whether the user has tampered with the role, identifier, and account information in the operation request information when sending the operation request, thus ensuring that there will be no phenomenon of unauthorized access to the request information.
[0106] Optionally, in the detection device for request information provided in the embodiments of the present application, before the network server receives the operation request information sent by the front-end server, the device further includes: a second receiving unit, configured to receive, by the network server, the login request information sent by the front-end server and obtain a second IP address, where the login request information includes the user's account and password; a third receiving unit, configured to send, by the network server, the login request information to the login program and receive the verification result and the second role returned by the login program; a creation unit, configured to, when the verification result indicates that the login request information is correct, create a second identifier by the network server and determine the account, the second identifier, and the second role as the second permission information; a storage unit, configured to store the second permission information and the second IP address in the memory of the network server and send the second permission information to the front-end server.
[0107] Specifically, the second IP address is the IP address of the user obtained by the front end when the user logs in to the network security product. The login request includes the user's account name and password. After the network server obtains the login request and the IP address, it temporarily stores the second IP address, sends the login request to the login program, and the login program determines whether the account and password in the login request information are correct and returns the verification result.
[0108] Furthermore, the login program is configured to determine whether the account and password in the login request information are correct and is further configured to send the second role to the network server.
[0109] It should be noted that there is a comparison table of account-password-role stored in the login program. After receiving the login request information, the login program determines whether there is an account in the login request information in the comparison table. If the account exists, it determines whether the password is the same as the corresponding password. When both the account and password are correct, the login program obtains the role corresponding to the account from the comparison table to obtain the second role and returns the second role and the verification result to the network server. At this time, the verification result is that the login request information is correct.
[0110] If the account does not exist in the comparison table or the password is incorrect compared to the corresponding password in the comparison table, the verification result is determined to be abnormal, and the abnormal verification result is returned to the network server. The network server will return the abnormal verification result to the front-end server, thereby informing the user that the login fails.
[0111] Further, when the verification result received by the network server indicates that the login request information is correct, a random identifier, i.e., the second identifier, is created, and the second identifier, the second role, and the user's account are determined as the second permission information, which is stored in the network server, so as to identify requests when the user sends subsequent requests, ensuring that there is no unauthorized access to the request information.
[0112] It should be noted that after obtaining the second permission information, the network server will send the second permission information to the front-end server and store it in the front-end server. When the front-end server receives an operation request, it will regenerate the target information based on the information of the operation request and the second permission information. At this time, the second permission information in the front-end server may be tampered with and changed to the first permission information. Therefore, it is possible to determine whether the first permission information has been tampered with by comparing the first permission information with the second permission information.
[0113] Figure 2 is a flowchart of an optional method for detecting login request information provided by an embodiment of the present application. As Figure 2 shown, after the user enters the account and password in the client of the front-end server, the client will generate login request information, including: the account, the password, and the user's IP address, and send the login request information to the network server. The network server stores the IP address and determines that the request information is login request information. In the case of login request information, the login request information is sent to the login program, and it is determined whether the user can log in by using the account-password-role comparison table stored in the login program. If the account or password is incorrect, an exception message is returned to the client through the network server. If the account and password are correct, the user role is obtained and sent to the network server. After generating a random identifier, the network server sends the role, the account, and the identifier to the client, thus completing the user's login.
[0114] Optionally, in the request information detection device provided by an embodiment of the present application, the device further includes: a third determination unit, configured to determine the storage duration of the second identifier in the memory to obtain a target duration; a judgment unit, configured to judge whether the target duration exceeds a preset duration; a first deletion unit, configured to delete the second permission information and the second IP address from the memory of the network server when the target duration exceeds the preset duration.
[0115] It should be noted that in order to prevent the memory occupancy in the network server from being too large and affecting the normal operation of the network server, it is necessary to regularly delete the permission information of each request stored in the network server.
[0116] Specifically, when each identifier is created by the network server, the generation time of the identifier is recorded simultaneously, and the time difference between the current time and the generation time is determined regularly, that is, the storage duration of the identifier in the memory. When this duration is greater than the preset duration, it indicates that the storage time of the second permission information and the second IP address corresponding to the identifier in the network server is too long and needs to be cleared, so as to ensure that the memory occupancy pressure of the network server is relatively small.
[0117] Optionally, in the request information detection device provided in the embodiments of the present application, the device further includes: a second deletion unit, configured to delete the second permission information and the second IP address from the memory of the network server after receiving a user logout instruction sent by the front-end server.
[0118] Similarly, in addition to determining whether to delete the second permission information and the second IP address based on the existence duration of the identifier, it can also be determined whether the user corresponding to the second permission information and the second IP address has logged out of the front-end login interface of the network security product. After the user logs out, the front-end will send a user logout instruction to the network server, and the network server will determine the second permission information and the second IP address corresponding to this login of the user according to the identifier in the user logout instruction, and delete the second permission information and the second IP address, so as to ensure that the memory occupancy pressure of the network server is relatively small.
[0119] The embodiments of the present application further provide a request information detection device. It should be noted that the request information detection device in the embodiments of the present application can be used to execute the request information detection method provided in the embodiments of the present application. The following introduces the request information detection device provided in the embodiments of the present application.
[0120] Figure 7 is a schematic diagram of the request information detection device provided in the embodiments of the present application Figure 2 As Figure 7 shown, the device includes: a first receiving unit 71, a second comparison unit 72, a first determination unit 73, and a second determination unit 74.
[0121] The first receiving unit 71 is configured to receive the operation request information sent by the network server, and perform combined encryption on the target data in the operation request information to obtain target encrypted data, where the operation request information at least includes encrypted data and target data, and the encrypted data is obtained by encrypting the target data.
[0122] Specifically, the backend server receives the operation request information sent by the network server. At this time, the first IP address and the first permission information in the operation request information are both correct. At this time, it is necessary to determine whether the remaining content in the operation request information is correct. The target encrypted data can be obtained by encrypting the target data in the operation request information. That is, the URI, HTTP method, account, role, network security configuration content, and random identifier are combined and encrypted, so as to judge the encrypted data according to the target encrypted data.
[0123] The second comparison unit 72 is used to compare the target encrypted data with the encrypted data in the operation request information to obtain a third comparison result.
[0124] Specifically, after obtaining the target encrypted data, the target encrypted data can be compared with the encrypted data carried in the operation request information to determine whether the target encrypted data is correct.
[0125] The first determination unit 73 is used to determine that the operation request information is abnormal and issue a third warning message when the third comparison result indicates that the target encrypted data is different from the encrypted data in the operation request information, where the third warning message indicates that the operation request information has been tampered with.
[0126] Specifically, when the target encrypted data is different from the encrypted data in the operation request information, it indicates that the target encrypted data is abnormal, and further indicates that the parameters in the request sending process such as the URI or HTTP method in the operation request information have changed, thus discovering the unauthorized operation of this user.
[0127] The second determination unit 74 is used to determine that the operation request information is normal when the third comparison result indicates that the target encrypted data is the same as the encrypted data in the operation request information.
[0128] Specifically, when the target encrypted data is the same as the encrypted data in the operation request information, it indicates that all the operation request information of this user is correct and conforms to the identity information and access permission corresponding to this user. At this time, the network security configuration filled in the operation request information of this user can be executed to complete this request.
[0129] The detection device for request information provided by the embodiment of the present application receives the operation request information sent by the network server through the first receiving unit 71, and combines and encrypts the target data in the operation request information to obtain target encrypted data. Among them, the operation request information at least includes encrypted data and target data, and the encrypted data is obtained by encrypting the target data. The second comparison unit 72 compares the target encrypted data with the encrypted data in the operation request information to obtain a third comparison result. When the third comparison result indicates that the target encrypted data is different from the encrypted data in the operation request information, the first determination unit 73 determines that the operation request information is abnormal and issues a third warning message, where the third warning message indicates that the operation request information has been tampered with. When the third comparison result indicates that the target encrypted data is the same as the encrypted data in the operation request information, the second determination unit 74 determines that the operation request information is normal. It solves the problem in the related technology that by binding the key to the user identity to prevent unauthorized access, it is impossible to accurately prevent unauthorized access. By comparing the IP address at the time of sending the operation request with the IP address stored in the network server at the time of login, and comparing the permission information in the operation request information with the second permission information stored in the network server at the time of login, and when the comparison result is normal, the back-end server verifies the encrypted information in the operation request information, so as to ensure that when there is a difference between the operation request information and the request information registered when the user is allowed to operate on the front-end server, the difference phenomenon can be discovered and processed in time, and further achieves the effect of accurately and comprehensively preventing the occurrence of unauthorized access caused by information tampering.
[0130] The above-mentioned detection device for request information includes a processor and a memory. The above-mentioned sending unit 61, the first comparison unit 62, the detection unit 63, the first receiving unit 71, the second comparison unit 72, the first determination unit 73, the second determination unit 74, etc. are all stored in the memory as program units, and the processor executes the above program units stored in the memory to implement corresponding functions.
[0131] The processor contains a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set, and by adjusting the kernel parameters, the problem in the related technology that by binding the key to the user identity to prevent unauthorized access, it is impossible to accurately prevent unauthorized access is solved.
[0132] The memory may include non-permanent memory in the computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0133] An embodiment of the present invention provides a computer-readable storage medium, on which a program is stored, and when the program is executed by a processor, the detection method of the request information is implemented.
[0134] An embodiment of the present invention provides a processor, which is used to run a program, wherein when the program runs, the detection method of the request information is executed.
[0135] An embodiment of the present invention provides an electronic device, including a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, the detection method of the request information is implemented. The device herein may be a server, a PC, a PAD, a mobile phone, etc.
[0136] The present application also provides a computer program product, which is suitable for executing a program initialized with the steps of the detection method of the request information when executed on a data processing device.
[0137] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0138] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified function in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0139] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the specified function in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0140] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 steps of the functions specified in one block or multiple blocks.
[0141] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0142] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0143] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can be implemented by any method or technology for information storage. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0144] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "including one..." does not exclude the presence of additional identical elements in the process, method, commodity or device including the element.
[0145] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A method for detecting request information, characterized in that, it includes: The network server receives the operation request information sent by the front-end server. Among them, the operation request information is the information sent after the user logs in to the front-end server. The operation request information at least includes encrypted data and target data. The target data at least includes a first IP address and a first permission information. The encrypted data is obtained by encrypting the target data; Obtain the second IP address and the second permission information stored in the network server, and respectively compare the first IP address with the second IP address and compare the first permission information with the second permission information to obtain a first detection result. Among them, the second IP address is the IP address when the user logs in to the front-end server, and the second permission information is the permission information when the user logs in to the front-end server; When the first detection result indicates that the operation request information is normal, the network server sends the operation request information to the back-end server, and the back-end server detects the encrypted data to obtain a second detection result. Among them, when the second detection result indicates that the operation request information is normal, it is determined that the operation request information is a risk-free request information.
2. The method according to claim 1, characterized in that, Respectively comparing the first IP address with the second IP address and comparing the first permission information with the second permission information to obtain a first detection result includes: Compare the first IP address with the second IP address to obtain a first comparison result; When the first comparison result indicates that the first IP address is different from the second IP address, it is determined that the operation request information is abnormal, and a first abnormal detection result is obtained, and a first warning message is sent. Among them, the first warning message indicates that the user's IP address is abnormal; When the first comparison result indicates that the first IP address is the same as the second IP address, compare the first permission information with the second permission information to obtain a second comparison result; When the second comparison result indicates that the first permission information is different from the second permission information, it is determined that the operation request information is abnormal, and a second abnormal detection result is obtained, and a second warning message is sent. Among them, the second warning message indicates that the permission information has changed; When the second comparison result indicates that the first permission information is the same as the second permission information, it is determined that the operation request information is normal, and a normal detection result is obtained. Among them, the first detection result includes the first abnormal detection result, the second abnormal detection result, and the normal detection result. The normal detection result is used to indicate that the operation request information is normal.
3. The method according to claim 2, characterized in that, The first permission information includes at least one of the following: a preset account, a first role, and a first identifier. The second permission information includes at least one of the following: an account, a second identifier, and a second role. Comparing the first permission information with the second permission information, the obtained second comparison result includes: Comparing the first role with the second role to obtain a second comparison result; Comparing the first identifier with the second identifier to obtain a third comparison result; Comparing the preset account with the account in the second permission information to obtain a fourth comparison result; In the case where there is an abnormal comparison result among the second comparison result, the third comparison result, and the fourth comparison result, determining the second comparison result as that the first permission information is different from the second permission information, where the abnormal comparison result indicates that the contents of the comparison object and the object being compared are inconsistent; In the case where there is no abnormal comparison result among the second comparison result, the third comparison result, and the fourth comparison result, determining the second comparison result as that the first permission information is the same as the second permission information.
4. The method according to claim 3, characterized in that, before the network server receives the operation request information sent by the front-end server, the method further includes: The network server receives the login request information sent by the front-end server and obtains the second IP address, where the login request information includes the user's account and password; Sending the login request information to the login program through the network server, and receiving the verification result returned by the login program and the second role; In the case where the verification result indicates that the login request information is correct, creating the second identifier through the network server, and determining the account, the second identifier, and the second role as the second permission information; Storing the second permission information and the second IP address in the memory of the network server, and sending the second permission information to the front-end server.
5. The method according to claim 4, characterized in that, after storing the second permission information and the second IP address in the memory of the network server, the method further includes: Determining the storage duration of the second identifier in the memory to obtain a target duration; Judging whether the target duration exceeds a preset duration; In the case where the target duration exceeds the preset duration, deleting the second permission information and the second IP address from the memory of the network server.
6. The method according to claim 4, characterized in that, after storing the second permission information and the second IP address in the memory of the network server, the method further includes: After receiving the user logout instruction sent by the front-end server, deleting the second permission information and the second IP address from the memory of the network server.
7. A detection system for request information, characterized in that, including: A front-end server, which is used to send the user's login request information to a network server and send the user's operation request information to the network server after successful login. Among them, at least encrypted data and target data are included in the operation request information. The target data includes at least a first IP address and first permission information. The encrypted data is obtained by encrypting the target data. The login request information includes the user's account and password; The network server is used to receive the login request information sent by the front-end server, obtain a second IP address, send the login request information to a login program, and determine the second permission information of the user and store the second permission information and the second IP address when the login program passes the verification. It is also used to receive the operation request information sent by the front-end server, detect the operation request information through the second IP address and the second permission information, and send the operation request information to the back-end server when no abnormality is detected in the operation request information; The login program is used to receive the login request information, verify the login request information, and send a message to the network server when the verification passes; The back-end server is used to receive the operation request information, perform combined encryption on the target data in the operation request information to obtain target encrypted data, and compare the target encrypted data with the encrypted data in the operation request information. When the target encrypted data is the same as the encrypted data in the operation request information, it is determined that the operation request information is risk-free information.
8. A detection device for request information, characterized in that, it includes: A sending unit, which is used for the network server to receive the operation request information sent by the front-end server. Among them, the operation request information is the information sent after the user logs in to the front-end server. At least encrypted data and target data are included in the operation request information. The target data includes at least a first IP address and first permission information. The encrypted data is obtained by encrypting the target data; A first comparison unit, which is used to obtain the second IP address and second permission information stored in the network server, and respectively compare the first IP address with the second IP address and the first permission information with the second permission information to obtain a first detection result. Among them, the second IP address is the IP address when the user logs in to the front-end server, and the second permission information is the permission information when the user logs in to the front-end server; A detection unit, which is used for the network server to send the operation request information to the back-end server and detect the encrypted data through the back-end server to obtain a second detection result when the first detection result indicates that the operation request information is normal. When the second detection result indicates that the operation request information is normal, it is determined that the operation request information is a risk-free request information.
Citation Information
Patent Citations
Data transmission method, data security verification method and data transmission system
CN112422494A