XSS injection attack detection method, device, equipment and storage medium
The method enhances XSS attack detection by analyzing network traffic with a word frequency-based dictionary and attribute scoring, addressing misidentification and inefficiencies in existing methods, achieving high precision and adaptability.
Patent Information
- Application Number
- CN202211378925.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-04
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-11-04
AI Technical Summary
Current methods for detecting XSS (Cross-Site Scripting) attacks face challenges in accuracy due to misidentification of business JavaScript as XSS or failing to detect new types of attacks, and existing virtual environment checks are inefficient for high traffic scenarios, leading to false negatives.
A method involving data packet analysis, three-tuple matching with a model dictionary, and attribute scoring to identify suspicious segments in network traffic, using a word frequency-based dictionary and Newton's interpolation for probability calculations to enhance detection precision.
The method improves XSS attack detection accuracy by accurately identifying XSS attacks and detecting new variants, ensuring high precision and adaptability across various scenarios.
Smart Images

Figure CN115720159B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to an XSS injection attack detection method, device, equipment and storage medium. Background Art
[0002] Currently, XSS injection attacks are common network attacks in web attacks, and they are very harmful. Since XSS injections are composed of JS statements, when detecting XSS injection attacks, it is possible to mistakenly identify business JS as XSS injection attacks, or to misjudge XSS injections as business JS. No matter which misjudgment occurs, it will cause certain risks to the system.
[0003] The detection scheme based on rule matching can detect the malware behavior well, but it will cause some business js statements to be hit, resulting in identification as xss injection attacks; or some new xss injection attacks, there is no matching rule, resulting in failure to identify and detect. At the same time, the efficiency and accuracy of rule hits are largely dependent on the experience and ability of the rule writers. Whether the rules can be accurately identified is affected by certain human factors and the experience of security analysts. The inspection method based on virtual environment execution executes the relevant xss statements in a virtual environment to monitor and check whether it will cause harm to the virtual environment. This method can effectively detect xss attacks, but this method has low detection efficiency and cannot effectively cope with large-traffic environment detection. At the same time, the virtual environment does not cover all scenarios, resulting in underreporting of xss, which leads to underreporting, and then the attacker's attack is successful. Summary of the invention
[0004] In view of this, the purpose of the present invention is to provide an XSS injection attack detection method, device, equipment and storage medium, which can improve the detection accuracy of XSS injection attacks. The specific scheme is as follows:
[0005] In a first aspect, the present application discloses a method for detecting an XSS injection attack, comprising:
[0006] Parsing the captured data packets of the traffic to be detected to obtain parsed data, and processing the parsed data according to preset processing rules to obtain processed tuples;
[0007] Matching the target triple in the processed tuple with the triple string stored in the model dictionary to query whether the target triple exists in the model dictionary; the model dictionary is a dictionary constructed using a pre-built word frequency file;
[0008] If so, all suspicious segments in the traffic data packet to be detected are determined according to the target triplet, and the attribute scores of the suspicious segments are calculated;
[0009] The suspicious segment corresponding to the attribute score with the highest score is determined as the target suspicious segment, and based on the target attribute score corresponding to the target suspicious segment, it is determined whether the attack category of the target suspicious segment is an XSS injection attack.
[0010] Optionally, the parsing of the captured traffic data packet to be detected to obtain parsed data includes:
[0011] Extract the request header information and request body information from the traffic data packet to be detected captured from the target gateway;
[0012] URL encoding is performed on the request header information and the request body information to obtain parsed data.
[0013] Optionally, calculating the attribute score of the suspicious segment includes:
[0014] Performing segmentation processing on the suspicious segment to obtain sub-segments;
[0015] Calculate the attack sub-attribute score and the normal sub-attribute score corresponding to each of the sub-segments based on the word frequency information in the triples corresponding to the sub-segments;
[0016] Determine the attack attribute score and the normal attribute score of the suspicious segment based on the attack sub-attribute score and the normal sub-attribute score corresponding to each of the sub-segments;
[0017] Accordingly, determining the suspicious segment corresponding to the attribute score with the highest score as the target suspicious segment includes:
[0018] The attack attribute score with the highest score is determined to obtain a target attack attribute score, and the suspicious segment corresponding to the target attack attribute score is determined as a target suspicious segment.
[0019] Optionally, determining whether the attack category of the target suspicious segment is an XSS injection attack based on the target attribute score corresponding to the target suspicious segment includes:
[0020] Determine whether the target attack attribute score corresponding to the target suspicious segment is lower than a preset XSS threshold to obtain a first determination result, and determine whether the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment to obtain a second determination result;
[0021] Based on the first judgment result and the second judgment result, determine whether the attack category of the target suspicious segment is an XSS injection attack.
[0022] Optionally, determining whether the attack category of the target suspicious segment is an XSS injection attack based on the first judgment result and the second judgment result includes:
[0023] If the first judgment result indicates that the target attack attribute score corresponding to the target suspicious segment is lower than the preset XSS threshold and the second judgment result indicates that the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment, then the attack type of the target suspicious segment is determined to be a non-XSS injection attack;
[0024] If the first judgment result indicates that the target attack attribute score corresponding to the target suspicious segment is not lower than the preset XSS threshold and the second judgment result indicates that the target attack attribute score is lower than the target normal attribute score corresponding to the target suspicious segment, then the attack type of the target suspicious segment is determined to be a non-XSS injection attack;
[0025] If the first judgment result indicates that the target attack attribute score corresponding to the target suspicious segment is not lower than the preset xss threshold and the second judgment result indicates that the target attack attribute score is not less than the target normal attribute score corresponding to the target suspicious segment, then the attack type of the target suspicious segment is determined to be an xss injection attack.
[0026] Optionally, after segmenting the suspicious segment to obtain sub-segments, the method further includes:
[0027] Determining whether the sub-segment is a character string in a whitelist stored in the model dictionary;
[0028] If yes, filtering the sub-segment to obtain a filtered sub-segment;
[0029] Accordingly, the calculating of the attack sub-attribute score and the normal sub-attribute score corresponding to each sub-segment based on the word frequency information in the triples corresponding to the sub-segments includes:
[0030] The attack sub-attribute score and the normal sub-attribute score corresponding to each of the filtered sub-segments are calculated based on the word frequency information in the triples corresponding to the sub-segments.
[0031] Optionally, the processing the parsed data according to a preset processing rule to obtain a processed tuple includes:
[0032] The parsed data is processed according to a target processing rule consisting of any one or a combination of several of a character replacement rule, a character case conversion rule and a generalization processing rule to obtain a processed tuple.
[0033] In a second aspect, the present application discloses an XSS injection attack detection device, comprising:
[0034] The data packet parsing module is used to parse the captured traffic data packets to be detected to obtain parsed data;
[0035] A data processing module, used for processing the parsed data according to preset processing rules to obtain processed tuples;
[0036] A triple matching module, used for matching the target triple in the processed tuple with the triple string stored in the model dictionary to query whether the target triple exists in the model dictionary; the model dictionary is a dictionary constructed by using a pre-built word frequency file;
[0037] A suspicious segment determination module, used for determining all suspicious segments in the traffic data packet to be detected according to the target triplet when the target triplet exists in the model dictionary;
[0038] An attribute score calculation module, used to calculate the attribute score of the suspicious segment;
[0039] The xss injection attack determination module is used to determine the suspicious segment corresponding to the attribute score with the highest score as the target suspicious segment, and determine whether the attack category of the target suspicious segment is an xss injection attack based on the target attribute score corresponding to the target suspicious segment.
[0040] In a third aspect, the present application discloses an electronic device, comprising:
[0041] Memory, used to store computer programs;
[0042] A processor is used to execute the computer program to implement the steps of the aforementioned disclosed XSS injection attack detection method.
[0043] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the aforementioned disclosed XSS injection attack detection method are implemented.
[0044] It can be seen that the present application provides an XSS injection attack detection method, including: parsing the captured traffic data packet to be detected to obtain parsed data, and processing the parsed data according to preset processing rules to obtain a processed tuple; matching the target triplet in the processed tuple with the triplet string stored in the model dictionary to query whether the target triplet exists in the model dictionary; the model dictionary is a dictionary constructed using a pre-constructed word frequency file; if so, determining all suspicious fragments in the traffic data packet to be detected according to the target triplet, and calculating the attribute score of the suspicious fragment; determining the suspicious fragment corresponding to the attribute score with the highest score as the target suspicious fragment, and determining whether the attack category of the target suspicious fragment is an XSS injection attack based on the target attribute score corresponding to the target suspicious fragment. It can be seen that the present application will parse the captured traffic data packets, and then process the parsed data into processed tuples according to preset processing rules, and then query whether the processed tuple exists in the model dictionary. If it exists, the target attribute score of the target suspicious segment in the traffic data packet to be detected is calculated, and then based on the target attribute score, it is determined whether the target suspicious segment is an xss injection attack. In other words, the technical solution of the present application can be universal for the identification of xss injection attacks, can have a high detection accuracy for most xss injection attacks, and also has a certain detection capability for newly emerging xss injection attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0046] Figure 1 This is a flow chart of an XSS injection attack detection method disclosed in this application;
[0047] Figure 2 A schematic diagram of a character string to be detected disclosed in this application;
[0048] Figure 3 A schematic diagram of a generalized string tuple to be detected disclosed in this application;
[0049] Figure 4 A schematic diagram of a suspicious segment attribute score disclosed in this application;
[0050] Figure 5 This is a specific flow chart of the XSS injection attack detection method disclosed in this application;
[0051] Figure 6 This is a schematic diagram of the structure of an XSS injection attack detection device disclosed in this application;
[0052] Figure 7 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0053] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0054] At present, in the prior art, XSS injection attack is a common network attack in web attacks, which is very harmful. Since XSS injection is composed of JS statements, when detecting the XSS injection attack, it is possible to mistakenly identify the business JS as an XSS injection attack, or misjudge the XSS injection as a business JS. No matter which misjudgment occurs, it will cause certain risks to the system. To this end, the present application provides a new XSS injection attack detection scheme, which can improve the detection accuracy of XSS injection attacks.
[0055] The embodiment of the present invention discloses a method for detecting xss injection attacks, see Figure 1 As shown, the method includes:
[0056] Step S11: parsing the captured traffic data packet to be detected to obtain parsed data, and processing the parsed data according to preset processing rules to obtain a processed tuple.
[0057] In this embodiment, the flow probe of the relevant device is used to capture the flow on the relevant target gateway to obtain the flow data packet to be detected, and then the flow data packet to be detected is parsed to obtain the parsed data, such as Figure 2As shown, the parsed data is then processed according to the preset processing rules to obtain the processed tuple. Specifically, the request header information and the request body information in the traffic data packet to be detected captured from the target gateway are extracted; the request header information and the request body information are URL (Uniform Resource Locator, i.e., Uniform Resource Locator) encoded and parsed to obtain the parsed data. The parsed data is processed according to the target processing rules composed of any one or a combination of character replacement rules, character case conversion rules, and generalization processing rules to obtain the processed tuple. It can be understood that the traffic data packet information to be detected is parsed, the request header information and the request body information in the traffic data packet information to be detected are extracted, and then the extracted request header information and the request body information are URL encoded and parsed three times to obtain the parsed data, and then the parsed data is subjected to character replacement, character case conversion or generalization and other processing to obtain the processed tuple in the traffic data packet to be detected, and the tuple is a data record. The parsed data is plain text data, and then the parsed plain text data is input into the pre-built detection model for xss injection attack detection.
[0058] For example, Figure 3 As shown, for the above Figure 2 The xss statements in the are generalized. The generalization refers to replacing various uncommon character strings that conform to a certain type with certain characters, so that the detection model can have a better recognition ability for xss statements. For example, the numbers in the xss statements are generalized and replaced with Digital. Then all numeric types can be replaced with Digital. In subsequent recognition, there is no need to prepare a large number of existing numbers for database preparation, which reduces the capacity of the database file and makes model calculation and recognition more convenient and efficient.
[0059] Step S12: Match the target triple in the processed tuple with the triple string stored in the model dictionary to query whether the target triple exists in the model dictionary; the model dictionary is a dictionary constructed using a pre-built word frequency file.
[0060] It should be pointed out that the word frequency file is pre-built, and the word frequency file may include but is not limited to js.data, js.fp, normal.data, normal.fp, dictAggregate.py and other files, wherein the above js.data stores related js (javascript) statements, and the above normal.data stores related web statements, which are used to calculate the vocabulary of related word frequencies and the construction connectivity of related phrases when building the model, the js.fp stores the white-name word groups in the js statements, and the normal.fp stores the white-name word groups in the web statements, which filter the related phrases in the detection and interrupt the sentence connectivity during the detection, and the dictAggregate.py stores the artificially set scores of important word frequencies, so that important word frequencies play a more important role in scoring. The model file is constructed by using the files of js.data, js.fp, normal.data, and normal.fp, and calculating the word frequency of each triple in the js.data and normal.data files by Newton's interpolation theorem. The word frequency can be calculated by Newton's interpolation theorem, wherein the Newton's interpolation theorem is a type of probability calculation algorithm, mainly used to calculate conditional probability. In this embodiment, the triple word frequency is calculated by Newton's interpolation algorithm, and the relevant algorithm is as follows:
[0061] p(abc)=[k1*Num(c) / Num(all)]+[k2*Num(bc) / Num(c)]+[k3*Num(abc) / Num(bc)]p(abc)=p(c / c_n)+p(bc / c)+p(abc / bc);
[0062] Among them, ki=(i / 10)+1, abc refers to the triple abc, p(c / c_n) refers to the word frequency of the unigram word c under the unigram condition, p(bc / c) refers to the word frequency of the bigram word bc under the unigram condition containing only the word c, and p(abc / bc) refers to the word frequency of the triple word abc under the bigram condition containing only the word bc.
[0063] For example: eval (Digital's word frequency in the entire js.data file) returns Digital's word frequency in the entire js.data file; and the phrases in js.fp are stored in the model file to form a model file, so the model file stores the relevant phrase frequency and white-name word groups, that is, the model dictionary. Therefore, when performing xss injection attack detection, it is mainly based on the phrase frequency information and related white-name word groups stored in the model dictionary in the detection model, and then the attribute score is calculated through weights and Newton's cooling theorem. The Newton's cooling theorem was originally one of the basic laws of heat transfer, used to calculate the amount of convective heat. At the same time, this theorem can also be applied to anomaly detection algorithms, by analyzing the frequency and order of its first appearance to calculate relevant scores. For example, it can be applied between non-continuous matching points to reduce the score of the previous matching point data, and then calculate the score of the abnormal fragment. Among them, the weight is used to weight the score of a single phrase so that it can produce a corresponding effect when detecting a continuous phrase. For example, it can make the feature more continuous, that is, the single phrase is more continuous. The larger the weight of the subsequent phrase, the faster the speed of weight increase can be. Moreover, the more continuous the recognition sentence is, the greater the improvement in the recognition score is.
[0064] In this embodiment, the captured traffic data packet to be detected is parsed to obtain parsed data, and the parsed data is processed according to the preset processing rules to obtain the processed tuple, and then the processed tuples are traversed in sequence, and the target triples in the processed tuples are matched with the triple strings stored in the model dictionary to query whether the target triples exist in the model dictionary, that is, the triples in the processed tuples are traversed, and the matching related triple information is searched in the model dictionary. And, if the target triple has a related record in the dictAggregate.py file in the model dictionary, the word frequency in the dictAggregate.py is replaced with the word frequency in the model.
[0065] Step S13: If so, all suspicious segments in the traffic data packet to be detected are determined according to the target triplet, and the attribute scores of the suspicious segments are calculated.
[0066] In this embodiment, after matching a triplet consistent with the target triplet in the model dictionary, relevant information of the target triplet is extracted, for example, the initial position of the triplet, the attack category, and the word frequency, and then according to the attack category, the relevant positions of all triples consistent with the attack category are traversed, and then the corresponding suspicious fragments are determined according to the triples, and then the attribute score of the suspicious fragment is calculated so as to subsequently determine whether the current attack category is an XSS injection attack based on the attribute score.
[0067] In this embodiment, the calculation of the attribute score of the suspicious segment may include: segmenting the suspicious segment to obtain each sub-segment; calculating the attack sub-attribute score and the normal sub-attribute score corresponding to each sub-segment based on the word frequency information in the triples corresponding to the sub-segments; and determining the attack attribute score and the normal attribute score of the suspicious segment based on the attack sub-attribute score and the normal sub-attribute score corresponding to each sub-segment. It can be understood that after finding all the suspicious segments, when calculating the attribute scores of each suspicious segment respectively, firstly, the suspicious segment is segmented to obtain each sub-segment, and then the attack sub-attribute score and the normal sub-attribute score corresponding to each sub-segment are calculated based on the word frequency information in the triples corresponding to the sub-segments, and then the attack attribute and the normal attribute score of the suspicious segment can be determined based on the attack sub-attribute score and the normal sub-attribute score corresponding to each sub-segment obtained after the suspicious segment is segmented.
[0068] In this embodiment, after the suspicious segment is segmented to obtain each sub-segment, the following may also be included: determining whether the sub-segment is a string in the whitelist stored in the model dictionary; if so, filtering the sub-segment to obtain a filtered sub-segment; and calculating the attack sub-attribute score and the normal sub-attribute score corresponding to each filtered sub-segment based on the word frequency information in the triple corresponding to the sub-segment. It can be understood that when the suspicious segment is segmented to obtain each sub-segment corresponding to the suspicious segment, a part of these sub-segments may belong to the string in the whitelist stored in the model dictionary, so these sub-segments can be directly filtered, and then when calculating the sub-attribute score, only the sub-attribute score of the filtered sub-segment needs to be calculated, and then the attribute score of the suspicious segment is determined based on the sub-attribute score corresponding to the filtered sub-segment.
[0069] For example, the algorithm for calculating the corresponding sub-attribute scores of the sub-segments may be as follows:
[0070] Initialize weight, match_count, and continuous_n, and set the initial values of weight, match_count, and continuous_n to 1, where the Weight variable represents the weight, the Match_count variable represents the number of triples that the sub-segment has participated in calculating, and the Continuous_n variable represents a parameter involved in the algorithm calculation and has no meaning. The calculation rules of the Continuous_n variable are as follows:
[0071] continuous_n=(match_count×match_count-0.3)×0.08×continuous_n;
[0072] If continuous_n is less than 1, the calculation rule of the Weight variable is: weight i =weight i-1 ×(continuous_n) 3 ;
[0073] If continuous_n is not less than 1, the calculation rule of the Weight variable is: weight i =weight i-1 ×(continuous_n) 2 ;
[0074] The weight i Represents the weight of the i-th triplet in the sub-segment.
[0075] Then, it is determined whether the weight variable exceeds a preset threshold value. The upper limit of the weight score is preset to 400, that is, when the weight variable is greater than the threshold value, the value corresponding to the weight variable is determined as the current threshold value.
[0076] When calculating the weight of a triple in a sub-segment, the Match_count variable is incremented by one, that is, match_count += 1, and then the weight is output. i , and determine whether all triples in all sub-segments have been traversed. If all triples in the sub-segment have been traversed to obtain the weights corresponding to each triple, then the process ends; if all triples in the sub-segment have not been traversed, then continue the above step of calculating the triple weights until the weights of all triples in the sub-segment are output, and then calculate the attribute score of the suspicious segment containing multiple sub-segments through the Newton cooling algorithm, wherein the Newton cooling algorithm is applied between non-continuous matching points, and the algorithm related to reducing the score of the previous matching point data is as follows:
[0077]
[0078] Among them, the x i represents the sub-attribute score of the ith sub-segment in the same suspicious segment; i = 1, 2, 3, ..., n, n represents the number of sub-segments contained in the suspicious segment, and the y i represents the cooling coefficient of the i-th sub-segment, that is:
[0079]
[0080] Step S14: Determine the suspicious segment corresponding to the attribute score with the highest score as the target suspicious segment, and determine whether the attack category of the target suspicious segment is an XSS injection attack based on the target attribute score corresponding to the target suspicious segment.
[0081] In this embodiment, after determining the attribute scores of each of the suspicious segments, the suspicious segment corresponding to the attribute score with the highest score is determined as the target suspicious segment. Specifically, the attack attribute score with the highest score is determined to obtain the target attack attribute score, and the suspicious segment corresponding to the target attack attribute score is determined as the target suspicious segment. Then, based on the target attribute score corresponding to the target suspicious segment, it is determined whether the attack category of the target suspicious segment is an xss injection attack. Specifically, it is determined whether the target attack attribute score corresponding to the target suspicious segment is lower than the preset xss threshold to obtain a first judgment result, and it is determined whether the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment to obtain a second judgment result. Based on the first judgment result and the second judgment result, it is determined whether the attack category of the target suspicious segment is an xss injection attack. It can be understood that if the first judgment result shows that the target attack attribute score corresponding to the target suspicious segment is lower than the preset xss threshold and the second judgment result shows that the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment, then the attack type of the target suspicious segment is determined to be a non-xss injection attack; if the first judgment result shows that the target attack attribute score corresponding to the target suspicious segment is not lower than the preset xss threshold and the second judgment result shows that the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment, then the attack type of the target suspicious segment is determined to be a non-xss injection attack; if the first judgment result shows that the target attack attribute score corresponding to the target suspicious segment is not lower than the preset xss threshold and the second judgment result shows that the target attack attribute score is not less than the target normal attribute score corresponding to the target suspicious segment, then the attack type of the target suspicious segment is determined to be an xss injection attack. For example, Figure 4 As shown, based on the above Figure 3 According to the information in the model dictionary in the detection model and the related word frequency, the target suspicious segment is identified as the phrase "alert`Digital`". The score of each phrase is calculated by the word frequency of the triples in each phrase. The calculated related score is 36.33644, which is greater than the normal score of 0.4348 corresponding to the segment and greater than the set threshold of 17, so it is judged as xss injection.
[0082] The detection method of the present application can build a relevant model by analyzing the characteristics of js, efficiently analyze and detect xss injection in the web, and has good versatility, and also has good detection effect on malicious xss injection in new scenarios.
[0083] It can be seen that in the embodiment of the present application, the captured traffic data packet is parsed, and then the parsed data is processed into a processed tuple according to the preset processing rules, and then the model dictionary is queried whether the processed tuple exists. If it exists, the target attribute score of the target suspicious segment in the traffic data packet to be detected is calculated, and then based on the target attribute score, it is determined whether the target suspicious segment is an xss injection attack. In other words, the technical solution of the present application can be universal for the identification of xss injection attacks, can have a high detection accuracy for most xss injection attacks, and also has a certain detection capability for newly emerging xss injection attacks.
[0084] For example, Figure 5As shown, the detection model is loaded, the triple string and its word frequency information stored in the model dictionary of the detection model and the string in the whitelist are extracted, the traffic data packet is input into the detection model, and the traffic data packet information is parsed, that is, the request header information and the request body information in the traffic data packet information are extracted, the extracted request header information and the request body information are url encoded and parsed three times to obtain the parsed data, and then the parsed data is processed by character replacement, character lowercase conversion and generalization to obtain the tuple after the generalization of the string to be detected, and then the triples in the generalized tuple of the string to be detected are traversed in turn, and the matching related information is searched in the model dictionary, that is, the model dictionary is queried whether the triple exists. If the triple is recorded in dictAggregate.py in the dictionary model, the word frequency in dictAggregate.py is replaced with the word frequency in the model, and the relevant initial position, relevant attack category and relevant word of the triple are extracted. Frequency, according to the attack category in the triplet, traverse all the triplet related positions under the attack category, and use the triplet to find the suspicious segment in the string to be detected, and then extract the suspicious segment in the string to be detected, and segment the segment at the same time. If the sub-segment of the suspicious segment is a string in the whitelist, the sub-segment is filtered, and after filtering the sub-segment of the string in the whitelist in the suspicious segment, for each triple in the sub-segment of the suspicious segment, multiply the word frequency and the position weight and accumulate them one by one, calculate the attack attribute score and the normal attribute score of each segment, extract the suspicious segment with the highest attack attribute score and its score information, and judge whether the highest attack attribute score is greater than the normal attribute score. If not, judge that the current attack category is normal. If yes, judge whether the highest attack attribute score is higher than the XSS threshold. If not, judge that the current attack category is an XSS injection attack. If yes, judge that the current attack category is an XSS injection attack.
[0085] Correspondingly, the embodiment of the present application also discloses an XSS injection attack detection device, see Figure 6 As shown, the device comprises:
[0086] The data packet parsing module 11 is used to parse the captured traffic data packet to be detected to obtain parsed data;
[0087] A data processing module 12, used to process the parsed data according to a preset processing rule to obtain a processed tuple;
[0088] A triple matching module 13 is used to match the target triple in the processed tuple with the triple string stored in the model dictionary to query whether the target triple exists in the model dictionary; the model dictionary is a dictionary constructed using a pre-built word frequency file;
[0089] A suspicious segment determination module 14, configured to determine all suspicious segments in the traffic data packet to be detected according to the target triplet when the target triplet exists in the model dictionary;
[0090] An attribute score calculation module 15, used to calculate the attribute score of the suspicious segment;
[0091] The xss injection attack determination module 16 is used to determine the suspicious segment corresponding to the attribute score with the highest score as the target suspicious segment, and determine whether the attack category of the target suspicious segment is an xss injection attack based on the target attribute score corresponding to the target suspicious segment.
[0092] As can be seen from the above, in this embodiment, the captured traffic data packet is parsed, and then the parsed data is processed into a processed tuple according to the preset processing rules, and then the model dictionary is queried whether the processed tuple exists. If it exists, the target attribute score of the target suspicious segment in the traffic data packet to be detected is calculated, and then based on the target attribute score, it is determined whether the target suspicious segment is an xss injection attack. In other words, the technical solution of the present application can be universal for the identification of xss injection attacks, can have a high detection accuracy for most xss injection attacks, and also has a certain detection capability for newly emerging xss injection attacks.
[0093] In some specific embodiments, the data packet parsing module 11 may specifically include:
[0094] An information extraction module is used to extract request header information and request body information from the traffic data packet to be detected captured from the target gateway;
[0095] The encoding and parsing module is used to perform URL encoding and parsing on the request header information and the request body information to obtain parsed data.
[0096] In some specific embodiments, the attribute score calculation module 15 may specifically include:
[0097] A segmentation module, used for segmenting the suspicious segment to obtain sub-segments;
[0098] A sub-attribute score calculation module, used to calculate the attack sub-attribute score and the normal sub-attribute score corresponding to each of the sub-segments based on the word frequency information in the triples corresponding to the sub-segments;
[0099] an attribute score determination module, configured to determine an attack attribute score and a normal attribute score of the suspicious segment based on the attack sub-attribute score and the normal sub-attribute score corresponding to each of the sub-segments;
[0100] In some specific embodiments, after the suspicious segment is segmented to obtain sub-segments, the following steps may be specifically performed:
[0101] A first judging module, configured to judge whether the sub-segment is a character string in a whitelist stored in the model dictionary;
[0102] A segment filtering module, configured to filter the sub-segment to obtain a filtered sub-segment when the sub-segment is a character string in a whitelist stored in the model dictionary;
[0103] In some specific embodiments, the sub-attribute score calculation module may specifically include:
[0104] The sub-attribute score calculation unit is used to calculate the attack sub-attribute score and the normal sub-attribute score corresponding to each of the filtered sub-segments based on the word frequency information in the triples corresponding to the sub-segments.
[0105] In some specific embodiments, the attribute score calculation module 15 may specifically include:
[0106] A target score determination module, used to determine the attack attribute score with the highest score to obtain a target attack attribute score;
[0107] The target segment determination module is used to determine the suspicious segment corresponding to the target attack attribute score as a target suspicious segment.
[0108] In some specific embodiments, the XSS injection attack determination module 16 may specifically include:
[0109] The first judgment module is used to judge whether the target attack attribute score corresponding to the target suspicious segment is lower than a preset XSS threshold to obtain a first judgment result;
[0110] The second judgment module is used to judge whether the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment to obtain a second judgment result;
[0111] An attack category determination module is used to determine whether the attack category of the target suspicious segment is an XSS injection attack based on the first judgment result and the second judgment result.
[0112] In some specific embodiments, the attack category determination module may specifically include:
[0113] A first determination module is configured to determine that the attack type of the target suspicious segment is a non-XSS injection attack if the first determination result indicates that the target attack attribute score corresponding to the target suspicious segment is lower than the preset XSS threshold and the second determination result indicates that the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment;
[0114] A second determination module is configured to determine that the attack type of the target suspicious segment is a non-XSS injection attack if the first determination result indicates that the target attack attribute score corresponding to the target suspicious segment is not lower than the preset XSS threshold and the second determination result indicates that the target attack attribute score is lower than the target normal attribute score corresponding to the target suspicious segment;
[0115] The third judgment module is used to determine that the attack type of the target suspicious segment is an XSS injection attack if the first judgment result shows that the target attack attribute score corresponding to the target suspicious segment is not lower than the preset XSS threshold and the second judgment result shows that the target attack attribute score is not less than the target normal attribute score corresponding to the target suspicious segment.
[0116] In some specific embodiments, the data processing module 12 may specifically include:
[0117] The data processing unit is used to process the parsed data according to a target processing rule composed of any one or a combination of several character replacement rules, character case conversion rules and generalization processing rules to obtain a processed tuple.
[0118] Furthermore, an embodiment of the present application also provides an electronic device. Figure 7 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.
[0119] Figure 7 A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the XSS injection attack detection method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0120] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0121] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0122] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the XSS injection attack detection method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.
[0123] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium, in which a computer program is stored. When the computer program is loaded and executed by a processor, the steps of the XSS injection attack detection method disclosed in any of the aforementioned embodiments are implemented.
[0124] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0125] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0126] The above is a detailed introduction to the XSS injection attack detection method, device, equipment and storage medium provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
Claims
1. A method for detecting xss injection attacks, characterized in that: include: Parsing the captured data packets of the traffic to be detected to obtain parsed data, and processing the parsed data according to preset processing rules to obtain processed tuples; Matching the target triple in the processed tuple with the triple string stored in the model dictionary to query whether the target triple exists in the model dictionary; the model dictionary is a dictionary constructed using a pre-built word frequency file; If so, all suspicious segments in the traffic data packet to be detected are determined according to the target triplet, and the attribute scores of the suspicious segments are calculated; Determine the suspicious segment corresponding to the attribute score with the highest score as the target suspicious segment, and determine whether the attack category of the target suspicious segment is an XSS injection attack based on the target attribute score corresponding to the target suspicious segment; The calculating the attribute score of the suspicious segment includes: Performing segmentation processing on the suspicious segment to obtain sub-segments; Calculate the attack sub-attribute score and the normal sub-attribute score corresponding to each of the sub-segments based on the word frequency information in the triples corresponding to the sub-segments; Determine the attack attribute score and the normal attribute score of the suspicious segment based on the attack sub-attribute score and the normal sub-attribute score corresponding to each of the sub-segments; Accordingly, determining the suspicious segment corresponding to the attribute score with the highest score as the target suspicious segment includes: Determine the attack attribute score with the highest score to obtain a target attack attribute score, and determine the suspicious segment corresponding to the target attack attribute score as a target suspicious segment; The determining, based on the target attribute score corresponding to the target suspicious segment, whether the attack category of the target suspicious segment is an XSS injection attack includes: Determine whether the target attack attribute score corresponding to the target suspicious segment is lower than a preset XSS threshold to obtain a first determination result, and determine whether the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment to obtain a second determination result; Based on the first judgment result and the second judgment result, determine whether the attack category of the target suspicious segment is an XSS injection attack.
2. The XSS injection attack detection method according to claim 1 is characterized in that: The step of parsing the captured traffic data packet to be detected to obtain parsed data includes: Extract the request header information and request body information from the traffic data packet to be detected captured from the target gateway; URL encoding is performed on the request header information and the request body information to obtain parsed data.
3. The XSS injection attack detection method according to claim 1 is characterized in that: The determining, based on the first judgment result and the second judgment result, whether the attack category of the target suspicious segment is an XSS injection attack includes: If the first judgment result indicates that the target attack attribute score corresponding to the target suspicious segment is lower than the preset XSS threshold and the second judgment result indicates that the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment, then the attack type of the target suspicious segment is determined to be a non-XSS injection attack; If the first judgment result indicates that the target attack attribute score corresponding to the target suspicious segment is not lower than the preset XSS threshold and the second judgment result indicates that the target attack attribute score is lower than the target normal attribute score corresponding to the target suspicious segment, then the attack type of the target suspicious segment is determined to be a non-XSS injection attack; If the first judgment result indicates that the target attack attribute score corresponding to the target suspicious segment is not lower than the preset xss threshold and the second judgment result indicates that the target attack attribute score is not less than the target normal attribute score corresponding to the target suspicious segment, then the attack type of the target suspicious segment is determined to be an xss injection attack.
4. The XSS injection attack detection method according to claim 1 is characterized in that: After the suspicious segment is segmented to obtain sub-segments, the method further includes: Determining whether the sub-segment is a character string in a whitelist stored in the model dictionary; If yes, filtering the sub-segment to obtain a filtered sub-segment; Accordingly, the calculating of the attack sub-attribute score and the normal sub-attribute score corresponding to each sub-segment based on the word frequency information in the triples corresponding to the sub-segments includes: The attack sub-attribute score and the normal sub-attribute score corresponding to each of the filtered sub-segments are calculated based on the word frequency information in the triples corresponding to the sub-segments.
5. The XSS injection attack detection method according to any one of claims 1 to 4, characterized in that: The step of processing the parsed data according to a preset processing rule to obtain a processed tuple includes: The parsed data is processed according to a target processing rule consisting of any one or a combination of several of a character replacement rule, a character case conversion rule and a generalization processing rule to obtain a processed tuple.
6. An xss injection attack detection device, characterized in that: include: The data packet parsing module is used to parse the captured traffic data packets to be detected to obtain parsed data; A data processing module, used for processing the parsed data according to preset processing rules to obtain processed tuples; A triple matching module, used for matching the target triple in the processed tuple with the triple string stored in the model dictionary to query whether the target triple exists in the model dictionary; the model dictionary is a dictionary constructed by using a pre-built word frequency file; A suspicious segment determination module, used for determining all suspicious segments in the traffic data packet to be detected according to the target triplet when the target triplet exists in the model dictionary; An attribute score calculation module, used to calculate the attribute score of the suspicious segment; An xss injection attack determination module is used to determine the suspicious segment corresponding to the attribute score with the highest score as a target suspicious segment, and determine whether the attack category of the target suspicious segment is an xss injection attack based on the target attribute score corresponding to the target suspicious segment; The attribute score calculation module specifically includes: A segmentation module, used for segmenting the suspicious segment to obtain sub-segments; A sub-attribute score calculation module, used to calculate the attack sub-attribute score and the normal sub-attribute score corresponding to each of the sub-segments based on the word frequency information in the triples corresponding to the sub-segments; an attribute score determination module, configured to determine an attack attribute score and a normal attribute score of the suspicious segment based on the attack sub-attribute score and the normal sub-attribute score corresponding to each of the sub-segments; A target score determination module, used to determine the attack attribute score with the highest score to obtain a target attack attribute score; A target segment determination module, configured to determine the suspicious segment corresponding to the target attack attribute score as a target suspicious segment; The xss injection attack determination module specifically includes: The first judgment module is used to judge whether the target attack attribute score corresponding to the target suspicious segment is lower than a preset XSS threshold to obtain a first judgment result; The second judgment module is used to judge whether the target attack attribute score is less than the target normal attribute score corresponding to the target suspicious segment to obtain a second judgment result; An attack category determination module is used to determine whether the attack category of the target suspicious segment is an XSS injection attack based on the first judgment result and the second judgment result.
7. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the steps of the XSS injection attack detection method as described in any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, the steps of the XSS injection attack detection method as described in any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Network attack detection method and equipment
CN105187408A
File maliciousness assessment method and device, electronic equipment and medium
CN114637990A