Protection capability detection method, system, storage medium and terminal device

By receiving detection requests to generate data attack packages, simulating attacks and obtaining response information, and automatically calculating the protection rate, the problem of complex and time-consuming WAF protection capability detection is solved, and an automated and stable protection capability evaluation is achieved.

CN115776380BActive Publication Date: 2025-09-16TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202111044185.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-07
Publication Date
2025-09-16
Estimated Expiration
2041-09-07

AI Technical Summary

Technical Problem

In existing technologies, WAF protection capability testing relies on manual evaluation, which is a complex and time-consuming process and results in unstable testing results.

Method used

By receiving detection requests, generating data attack packages, simulating attack target detection sites, obtaining response information from the protection system, and automatically calculating the protection rate, automated detection of protection capabilities is achieved.

Benefits of technology

It simplifies the detection process, improves detection efficiency, ensures the stability of detection results, and can automatically evaluate the protection capability of the protection system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115776380B_ABST
    Figure CN115776380B_ABST
Patent Text Reader

Abstract

The embodiments of the present invention relate to the field of information processing technology, and disclose a protection capability detection method, system, storage medium and terminal device, which can be applied to various scenarios such as cloud technology, artificial intelligence, smart transportation, and Internet of Vehicles. The protection capability detection system will automatically generate a data attack packet based on the attack type included in the detection request of the protection system of the target detection site, and send the data attack packet to the target detection site, thereby simulating the attack process on the target detection site. When the response information of the protection system of the target detection site to the data attack packet is obtained, the protection rate of the protection system to the target detection site can be determined based on the response information. In this way, the attack on the target detection site is automatically simulated, and the protection capability of the protection system can be determined based on the response information, thereby realizing the automation process of the protection capability detection of the protection system, eliminating the need for manual evaluation, simplifying the process of protection capability detection, and achieving stable detection effect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information processing technology, and in particular to a protection capability detection method, system, storage medium, and terminal equipment. Background Art

[0002] A Web Application Firewall (WAF) is a Web application firewall that provides protection for Web applications by executing a series of security policies for the Hypertext Transport Protocol (HTTP) / HTTPS. It can be widely used in various Web application scenarios such as credit reporting, banking, gaming, security, and the Internet of Things.

[0003] In the existing technology, in order to ensure the protection capability of WAF for Web applications, it is necessary to test the protection capability of WAF, mainly through manual evaluation based on WAF protection logs. This detection process is relatively complicated, time-consuming, and the detection effect is unstable. Summary of the Invention

[0004] The embodiments of the present invention provide a protection capability detection method, system, storage medium and terminal equipment, which realize automatic detection of the protection capability of a website protection system.

[0005] An embodiment of the present invention provides a method for detecting a protection capability, including:

[0006] receiving a detection request from a protection system for a target detection site, wherein the detection request includes an attack type for the target detection site;

[0007] generating a data attack packet according to the attack type, wherein the data attack packet includes an attack feature corresponding to the attack type;

[0008] Sending the data attack packet to the target detection site;

[0009] Response information of the protection system of the target detection site to the data attack packet is obtained, and a protection rate of the protection system for the target detection site is determined according to the response information.

[0010] Another embodiment of the present invention provides a protection capability detection system, including:

[0011] a request receiving unit, configured to receive a detection request from a protection system for a target detection site, wherein the detection request includes an attack type for the target detection site;

[0012] a data generating unit, configured to generate a data attack packet according to the attack type, wherein the data attack packet includes an attack feature corresponding to the attack type;

[0013] A data sending unit, configured to send the data attack packet to the target detection site;

[0014] The detection unit is used to obtain response information of the protection system of the target detection site to the data attack packet, and determine the protection rate of the protection system for the target detection site according to the response information.

[0015] Another aspect of the embodiment of the present invention further provides a computer-readable storage medium storing a plurality of computer programs, wherein the computer programs are suitable for being loaded by a processor and executing the protection capability detection method as described in the first aspect of the embodiment of the present invention.

[0016] Another aspect of the present invention provides a terminal device, including a processor and a memory;

[0017] The memory is used to store multiple computer programs, and the computer programs are used to be loaded by the processor and execute the protection capability detection method as described in one aspect of an embodiment of the present invention; the processor is used to implement each computer program in the multiple computer programs.

[0018] Another aspect of an embodiment of the present invention further provides a computer program product, comprising: computer instructions; the computer instructions are stored in a computer-readable storage medium, and the computer instructions are suitable for being loaded by a processor and executed by the protection capability detection method as described in one aspect of an embodiment of the present invention.

[0019] It can be seen that in the method of this embodiment, the protection capability detection system will automatically generate a data attack packet based on the attack type included in the detection request of the protection system to the target detection site, and send the data attack packet to the target detection site, thereby simulating the attack process on the target detection site. When the response information of the protection system of the target detection site to the data attack packet is obtained, the protection rate of the protection system to the target detection site can be determined based on the response information. In the process of detecting the capability of the protection system, the attack on the target detection site can be automatically simulated, and then the protection capability of the protection system can be automatically determined based on the response information, realizing the automation process of the protection capability detection of the protection system without the need for manual evaluation, simplifying the process of detecting the protection capability, and achieving stable detection effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0021] Figure 1 is a schematic diagram of a protection capability detection method provided by an embodiment of the present invention;

[0022] Figure 2 This is a flow chart of a protection capability detection method provided by one embodiment of the present invention;

[0023] Figure 3 This is a schematic diagram of the logical structure of a protection capability detection system in an application embodiment of the present invention;

[0024] Figure 4 This is a flow chart of a protection capability detection method provided by an application embodiment of the present invention;

[0025] Figure 5 is a schematic diagram of a detection setting interface displayed by a protection capability detection system in an application embodiment of the present invention;

[0026] Figure 6 is a schematic diagram of a protection success rate determined by a detection module displayed by a protection capability detection system in an application embodiment of the present invention;

[0027] Figure 7 is a schematic diagram of a distributed system to which a protection capability detection method according to another application embodiment of the present invention is applied;

[0028] Figure 8 is a schematic diagram of a block structure in another application embodiment of the present invention;

[0029] Figure 9 This is a logical structure diagram of a protection capability detection system provided by an embodiment of the present invention;

[0030] Figure 10 This is a schematic diagram of the logical structure of a terminal device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0031] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0032] The terms "first", "second", "third", "fourth", etc. (if any) in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the invention described herein can, for example, be implemented in orders other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or apparatus that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or apparatus.

[0033] The embodiment of the present invention provides a protection capability detection method, which mainly automatically detects the protection capability of the protection system of the target detection site by deploying a protection capability detection system. Figure 1 As shown, the protection capability detection system can implement the protection capability detection according to the following steps:

[0034] Receive a detection request for a protection system of a target detection site, the detection request including an attack type for the target detection site; generate a data attack packet according to the attack type, the data attack packet including attack features corresponding to the attack type; send the data attack packet to the target detection site; obtain response information of the protection system of the target detection site to the data attack packet, and determine a protection rate of the protection system for the target detection site according to the response information.

[0035] In this way, during the process of testing the capabilities of the protection system, the attack on the target detection site can be automatically simulated, and the protection capability of the protection system can be automatically determined based on the response information, thereby realizing the automation process of testing the protection capability of the protection system without the need for manual evaluation, simplifying the process of testing the protection capability, and stabilizing the detection effect.

[0036] In specific implementation, the above-mentioned target detection site and its protection system can be deployed on the same physical device, or on different physical devices. Figure 1 The example above uses deployment on the same physical device as the target detection site and its protection system. However, the protection capability detection system is deployed on a separate physical device from the target detection site and its protection system. In specific applications, the target detection site can be any of the following: radio, music, video, refueling, charging, parking, itinerary sharing, advertising, travel, and other related IoV sites.

[0037] The method of the embodiment of the present invention can be applied to a system implemented by cloud technology, wherein cloud technology (Cloud technology) is a general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the application of cloud computing business model, which can form a resource pool and be used on demand, flexibly and conveniently. Cloud computing technology will become an important support. The background services of technical network systems require a large amount of computing and storage resources, such as video websites, picture websites and more portal websites. With the rapid development and application of the Internet industry, each item may have its own identification mark in the future, and all need to be transmitted to the background system for logical processing. Data of different levels will be processed separately, and all types of industry data require strong system backing support, which can only be achieved through cloud computing.

[0038] When implementing the protection capability detection method of this embodiment, cloud technology primarily serves as a cloud security computing method. Cloud security refers to the collective term for security software, hardware, users, organizations, and secure cloud platforms based on the cloud computing business model. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and the identification of unknown virus behavior. Through a network of numerous clients, cloud security monitors software behavior anomalies on the network, obtains the latest information on Trojans and malicious programs on the internet, and sends it to the server for automatic analysis and processing. Solutions to these viruses and Trojans are then distributed to each client. The main research directions of cloud security include: 1. Cloud computing security, which focuses on how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, compliance auditing, etc.; 2. Cloudification of security infrastructure, which focuses on how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building ultra-large-scale security event, information collection and processing platforms through cloud computing technology, realizing the collection and correlation analysis of massive amounts of information, and improving the ability to control security incidents and risks across the entire network; 3. Cloud security services, which focuses on various security services provided to users based on cloud computing platforms, such as antivirus services.

[0039] The embodiment of the present invention provides a method for detecting protection capability, which is mainly a method executed by a protection capability detection system. The flow chart is as follows: Figure 2 As shown, including:

[0040] Step 101: Receive a detection request for a protection system of a target detection site, where the detection request includes an attack type for the target detection site.

[0041] It can be understood that the protection capability detection system of this embodiment can automatically detect the protection capability of the protection system of any site. Specifically, the protection capability detection system will provide a user interface, and the user can initiate a detection request for the protection system of any site (such as the target detection site) by operating the user interface, thereby triggering the detection process of this embodiment. Among them, the detection request may include information about the target detection site (such as domain name and network protocol address information, etc.), and may also include the type of attack on the target detection site, and may also include the protection mechanism of the protection system of the target detection site against the attack, such as black mechanism or white mechanism and other information. Among them, the target detection site can specifically be a website server, i.e., a Web server, or a website application, i.e., a Web application, etc.

[0042] The attack types here may include but are not limited to at least one of the following attack types: Structured Query Language (SQL) injection attack, Cross Site Scripting (XSS) attack, system command injection attack, vulnerability scanning behavior, web crawler behavior, web server attack, web application attack, backdoor connection behavior and unauthorized access behavior, etc.

[0043] Specifically, the protection capability detection system can first display a detection setting interface, which includes a first parameter setting interface for the target detection site, a second parameter setting interface for the protection system, and a detection initiation interface; receive the first parameter value of the target detection site and the second parameter value of the protection system input by the user from the first parameter setting interface and the second parameter setting interface respectively, where the second parameter value includes the attack type; in response to the operation of the detection initiation interface, receive a detection request for the protection system of the target detection site, where the detection request includes the first parameter value and the second parameter value input by the user.

[0044] Among them, the user can input the first parameter value of the target detection site from the first parameter setting interface, including the domain name and network protocol address of the target detection site, etc., and can input the second parameter value of the protection system from the second parameter setting interface, including the protection mechanism of the protection system for the target detection site and the attack types that the protection system can protect.

[0045] Furthermore, the detection setting interface may also include a setting interface for matching features, so that the protection capability detection system can receive the matching features input by the user from the setting interface for matching features, and include the matching features input by the user in the detection request initiated. The matching features input by the user are mainly used in the process of determining the protection rate of the protection system for the target detection site in the subsequent step 104. Specifically, based on whether the response information returned by the protection system includes the matching features input by the user, it is determined whether the protection system has successfully protected the data attack packet, and then the protection rate of the protection system for the target detection site is calculated based on the information on whether the protection is successful.

[0046] Among them, if the second parameter setting interface includes a setting interface for the protection mechanism of the protection system, and the second parameter value input by the user through the protection mechanism setting interface includes whether the protection mechanism of the protection system is a black mechanism or a white mechanism. Then, when the protection capability detection system subsequently determines whether the protection system successfully protects against the attack of the data attack packet based on whether the response information includes the matching feature input by the user, if the second parameter value includes the black mechanism and the response information includes the matching feature input by the user, it is determined that the protection system successfully protects against the attack of the data attack packet; if the second parameter value includes the white mechanism and the response information includes the matching feature input by the user, it is determined that the protection system did not successfully protect against the attack of the data attack packet.

[0047] The matching feature here is the characteristic information returned to the protection capability detection system by the protection system during the process of protecting against the attack of the data attack packet. The characteristic information can identify whether the protection system has successfully performed the protection. Specifically, the matching feature can be the error information returned when the protection mechanism of the protection system is a black mechanism and the attack of the data attack packet is protected; it can also be the information returned when the protection mechanism of the protection system is a white mechanism and the attack of the data attack packet is not protected.

[0048] Step 102: Generate a data attack package according to the attack type, where the data attack package includes attack features corresponding to the attack type.

[0049] Specifically, attack signatures refer to information used to describe and identify a particular attack type. Different attack types correspond to different attack signatures, including but not limited to the following types:

[0050] (1) The attack type is SQL injection attack

[0051] SQL is a database query and programming language used to access data, as well as query, update, and manage relational database systems. SQL injection attacks work by sending specially crafted SQL commands in a request to a target site's normal functional interface. If the target site's security system fails to protect the request, the SQL commands can enter the target site's database through the front-end functional interface. These dangerous SQL commands are then received and executed by the target site's database, ultimately leading to data leakage, modification, or corruption. The SQL injection payload can be present in HTTP request parameters, cookies, or even custom headers.

[0052] In this case, when the protection capability detection system generates a data attack packet, it generates a data attack packet including specific structured query language instructions, namely SQL instructions, wherein the attack feature can specifically be a specific SQL instruction, and the type of the data attack packet can specifically be an http request message, etc.

[0053] (2) The attack type is XSS attack

[0054] XSS attacks work by exploiting security vulnerabilities in the target website to cause it to load a malicious webpage. This exploits the user's permissions to perform dangerous operations and obtain sensitive information, including private webpage content, session information, and cookies. XSS injection is essentially a form of Hypertext Markup Language (HTML) injection. Data entered by the user into the target website is treated as part of the HTML code and executed, thus obfuscating the original semantics and creating new ones.

[0055] In this case, when the protection capability detection system generates a data attack packet, the generated data attack packet includes a specific web page program code, wherein the attack feature can specifically be the specific web page program code.

[0056] (3) The attack type is a system command injection attack

[0057] The principle of system command execution attack is that since the target site does not strictly filter the parameters passed in from the outside, when the parameter passed in by the attacker is a system command, the target site will directly execute the system command as an external command, allowing the attacker to remotely control the system of the target site and eventually compromise the system.

[0058] In this case, when the protection capability detection system generates a data attack packet, the generated data attack packet includes a system command, and the attack feature may specifically be a system command.

[0059] (4) The attack type is vulnerability scanning behavior

[0060] Vulnerability scanning is the act of detecting whether the target site has security vulnerabilities. It often occurs in the first step of an attack. Attackers use vulnerability scanning to discover possible security vulnerabilities in the target site, and then launch targeted attacks on the target site, obtaining sensitive data from the target site and even obtaining full permissions to the target site.

[0061] In this case, when the protection capability detection system generates a data attack package, the data attack package is generated to scan for vulnerabilities in the target detection site.

[0062] (5) The attack type is web crawler behavior

[0063] Web crawlers mainly obtain the entire content of the target site through web crawling and save the visited pages. First of all, the resources of the target site will be consumed in the process of crawling web pages. At the same time, there is a risk of sensitive data leakage after some sensitive directories are crawled by the crawler.

[0064] In this case, when the protection capability detection system generates a data attack packet, it generates a data attack packet for acquiring all the contents in the target detection site, wherein the attack feature may specifically be a request feature of a web crawler.

[0065] (6) Attack type is Web server attack

[0066] Web server attacks mainly exploit security issues in the target site's server itself, mainly focusing on attacks on web servers such as IIS, Apache and Nginx. The flaws exploited include illegal information uploading, parsing vulnerabilities and overflow vulnerabilities.

[0067] In this case, when the protection capability detection system generates a data attack package, the data attack package is generated for uploading specific information, parsing vulnerabilities, or overflow vulnerabilities.

[0068] (7) The attack type is a Web application attack

[0069] Web applications mainly refer to terminals with web application functions. The main target of web application attacks is the web application of the target site. Due to the rich variety of web applications on the current Internet, web application attacks are also the most diverse. The main attack points include unauthorized access, command execution and overflow vulnerabilities.

[0070] In this case, when the protection capability detection system generates a data attack packet, the data attack packet is generated for unauthorized access, specific command execution, or overflow vulnerability.

[0071] (8) Attack type is backdoor connection behavior

[0072] Some interfaces (i.e. backdoors) in the target site are not allowed to be accessed. The access behavior of these interfaces is also one of the important features for identifying site attacks. The main attack behaviors include uploading malicious suffix files, inserting dangerous functions and directly connecting to backdoor files.

[0073] In this case, when the protection capability detection system generates a data attack package, it generates a data attack package for accessing a specific interface of the target detection site, such as accessing a file upload interface of the target detection site to upload a specific suffix file, or accessing a function insertion interface of the target detection site to insert a specific function, or accessing a file connection interface to connect to a specific backdoor file of the target detection site, etc., and the attack characteristics accordingly include specific suffix files, specific functions or specific backdoor files, etc.

[0074] (9) The attack type is unauthorized access behavior

[0075] The target site itself usually provides external access to business interfaces. Sensitive resources of the system itself, including directories and files, cannot be directly accessed by external users. When unauthorized access to sensitive resources occurs, the target site itself may have security issues. Therefore, unauthorized access is also an important feature of attack detection.

[0076] In this case, when the protection capability detection system generates a data attack packet, it generates an access request to a specific directory or file in the target detection site, wherein the attack feature may specifically be information of the specific directory or file.

[0077] Step 103: Send a data attack packet to the target detection site.

[0078] In this way, the data attack packet will first reach the protection system, and the protection system will determine whether to protect the data attack packet. If not, the data attack packet will be transmitted to the target detection site, and the target detection site will return the response information of the data attack packet to the protection capability detection system through the protection system. Among them, if the protection mechanism of the protection system is a white mechanism, when the response information of the data attack packet reaches the protection system, the protection system will add matching features to the response information and return it to the protection capability detection system; if protection is required, the protection system will not send the data attack packet to the target detection site, but will perform protection according to a certain protection mechanism. For example, when using the white mechanism for protection, it can be discarded directly, and when using the black mechanism for protection, the protection system can return response information to the protection capability detection system, and the response information may include matching features.

[0079] It should be noted that the detection request received in step 101 may include multiple attack types against the target detection site. Thus, when executing steps 102 and 103, the protection capability detection system may initiate multiple threads. For each attack type, at least one thread may generate a corresponding data attack packet and send the data attack packet to the target detection site. Furthermore, the protection capability detection system may generate multiple data attack packets for a single attack type. Thus, multiple threads may be initiated for a single attack type, with these threads concurrently sending data attack packets for the same attack type.

[0080] In this way, the protection capability detection system can generate and send data attack packets concurrently through multiple threads running at the same time, fully tapping the resource processing capabilities of the multi-core central processing unit (CPU) of the protection capability detection system. The action of sending data attack packets can be executed on each core at the same time, saving a lot of time and improving detection efficiency.

[0081] Step 104: Acquire response information of the protection system of the target detection site to the data attack packet, and determine the protection rate of the protection system for the target detection site based on the response information.

[0082] It should be noted that the protection capability detection system sends multiple data attack packets to the target detection site based on an attack type in a detection request, thereby obtaining response information corresponding to the multiple data attack packets. When determining the protection system's protection rate for the target detection site, the system can first count the number of successful attacks against the multiple data attack packets based on the response information corresponding to the multiple data attack packets. The protection rate for the attack type is then determined as the ratio of the number of successful attacks against the multiple data attack packets of that attack type to the total number of attacks from these multiple data attack packets. This method can be used to determine the protection rate for various attack types.

[0083] Among them, when counting the number of times the protection system successfully defends against attacks of multiple data attack packets based on the response information corresponding to multiple data attack packets, if the protection mechanism of the protection system is a black mechanism, the number of successful defenses is the number of response information including matching features; if the protection mechanism of the protection system is a white mechanism, the number of successful defenses is the difference between the total number of protections and the number of response information including matching features.

[0084] It can be seen that in the method of this embodiment, the protection capability detection system will automatically generate a data attack packet based on the attack type included in the detection request of the protection system to the target detection site, and send the data attack packet to the target detection site, thereby simulating the attack process on the target detection site. When the response information of the protection system of the target detection site to the data attack packet is obtained, the protection rate of the protection system to the target detection site can be determined based on the response information. In the process of detecting the capability of the protection system, the attack on the target detection site can be automatically simulated, and then the protection capability of the protection system can be automatically determined based on the response information, realizing the automation process of the protection capability detection of the protection system without the need for manual evaluation, simplifying the process of detecting the protection capability, and achieving stable detection effect.

[0085] The following is a specific application example to illustrate the protection capability detection method of the present invention. The method of this embodiment can be applied to Figure 3 The system shown includes: a protection capability detection system 10, a target detection site 11, and a protection system 12 for the target detection site. In this embodiment, the protection system 12 and the target detection site 11 are deployed in two physical devices. The protection capability detection system 10 may include an operation module 110, a packet sending module 120, a detection module 130, a storage module 140, and a log module 150. Specifically:

[0086] The operation module 110 is used to provide an interface for interacting with the user, which can display a detection setting interface. Through the detection setting interface, the information of the target detection site 11 and the information of its protection system 12 can be set, and a detection request for the protection system 12 of the target detection site 11 can be initiated through the detection setting interface.

[0087] The packet sending module 120 is used to generate a corresponding data attack packet based on the detection request received by the operation module 110, and send the generated data attack packet to the target detection site 11. In order to ensure the sending speed, the packet sending module 120 can use multiple threads to synchronously generate data attack packets and send the generated data attack packets at the same time.

[0088] The detection module 130 is used to obtain the response information returned by the protection system 12 to the data attack packet sent by the packet sending module 120, and to determine whether the protection system 12 successfully protects against the attack of the data attack packet. If successful, it means that the protection system 12 has the ability to protect against the attack of the data attack packet; otherwise, it does not have the ability to protect.

[0089] The storage module 140 is used to store the configuration information of the protection capability detection system, including a complete set of database clusters. The database architecture adopts a one-master and one-backup method to ensure that data will not be lost.

[0090] The log module 150 is used to record the operation log of the protection capability detection system to ensure that the operation information of the protection capability detection system can be traced.

[0091] Specifically, if Figure 4 As shown, the protection capability detection system 10 can detect the protection capability of the protection system of the target detection site according to the following steps:

[0092] In step 201 , the operation module 110 displays a detection setting interface, which includes a first parameter setting interface of the target detection site 11 , a second parameter setting interface of the protection system 12 , a matching feature setting interface, and a detection initiation interface.

[0093] Specifically, if Figure 5 The following figure shows the detection setting interface, including the setting interfaces for "target domain name", "target IP", "protection mechanism", "matching characteristics" and "attack type", and may also include a detection initiation interface, i.e., a "start detection" button. The "target domain name" setting interface can be used to set the domain name of the target detection site 11, the "target IP" setting interface can be used to set the network protocol address of the target detection site 11, the "protection mechanism" setting interface can be used to set the protection mechanism of the protection system 12 to a black mechanism or a white mechanism, and the "matching characteristics" setting interface can be used to set the matching characteristics.

[0094] In step 202, the user enters the corresponding parameter values ​​through the setting interface of each parameter in the detection setting interface, and operates the detection initiation interface. The operation module 110 will receive the detection request, which includes the parameter values ​​of each parameter entered by the user in the detection setting interface, which may specifically include: at least one attack type, protection mechanism, matching feature, target IP and target domain name.

[0095] Step 203: The packet sending module 120 starts multiple threads according to the parameters in the detection request. Each thread generates a corresponding data attack packet for an attack type in the detection request and sends the data attack packet to the target detection site 11. Multiple threads can perform corresponding operations in parallel.

[0096] In step 204, the data attack packet sent by the packet sending module 120 will first reach the protection system 12, and the protection system 12 will perform protection according to a certain protection mechanism. Taking the black mechanism as an example, if the attack of the data attack packet is protected, the data attack packet will not be sent to the target detection site 11, but a response message carrying matching features will be directly returned to the protection capability detection system 10; if the attack of the data attack packet is not protected, the protection system will send the data attack packet to the target detection site 11, and the target detection site 11 will return the corresponding response information to the protection capability detection system through the protection system 12. In this case, the response information will not include matching features.

[0097] In step 205, the detection module 130 determines whether the protection system 12 successfully protects against the attacks of the data attack packets of each attack type based on the response information returned for the multiple data attack packets. If the response information of any data attack packet includes a matching feature, the protection system 12 successfully protects against the attack of the data attack packet; if the response information does not include a matching feature, the protection system 12 fails to protect against the attack of the data attack packet.

[0098] It should be noted that the above steps 204 and 205 are explained using the black mechanism as an example. In other embodiments, if the protection mechanism included in the detection request is the white mechanism, then in the above step 204, when the data attack packet sent by the packet sending module 120 reaches the protection system 12, if the attack of the data attack packet is protected, the data attack packet is directly discarded; if the attack of the data attack packet is not protected, the protection system will send the data attack packet to the target detection site 11. When the target detection site 11 returns the response information, the protection system 12 will add matching features to the response information and return it to the protection capability detection system.

[0099] In this case, when the detection module 130 determines whether the protection system 12 successfully protects against the data attack packets of each attack type, if the response information of any data attack packet includes a matching feature, the protection system 12 fails to protect against the attack of the data attack packet.

[0100] In step 206, the detection module 130 counts the number of times the protection system 12 successfully protects against attacks of data attack packets of each attack type, and the total number of attacks of data attack packets of each attack type, and calculates the protection rate of the protection system 12 against data attack packets of any attack type, specifically: the ratio of the number of times the protection system successfully protects against attacks of data attack packets of the corresponding attack type to the total number of attacks.

[0101] In step 207, the detection module 130 can transmit the protection rate of each attack type to the front end for display, such as Figure 6Shown is the protection rate corresponding to each attack type, specifically the protection success rate.

[0102] In step 208 , the storage module 140 stores the protection rate corresponding to each attack type obtained by the detection module 130 in the local system.

[0103] In step 209 , the log module 150 records all information during the process of the protection capability detection system automatically detecting the protection capability of the protection system.

[0104] It can be seen that the protection capability detection method of this embodiment can achieve the following effective effects:

[0105] (1) Improved detection efficiency: In the embodiment of the present invention, the capability detection of the protection system is platform-based and automatically implemented. A detection request is sent with one click, and data attack packets are simulated and sent in parallel, which can quickly generate results.

[0106] (2) Elimination of false alarms: In the embodiment of the present invention, the capability detection process of the protection system is standardized and streamlined, thereby ensuring the consistency of the detection process and allowing the details of the detection process to be traced back and restored.

[0107] (3) Expanded attack types: The current detection types are relatively limited. In this embodiment, the protection system can detect and monitor the protection capabilities of the target detection site for data attack packets of a wider range of attack types.

[0108] The following is another specific application example to illustrate the protection capability detection method in the present invention. The protection capability detection system in the embodiment of the present invention is mainly a distributed system 100, which may include a client 300 and multiple nodes 200 (any form of computing device in the access network, such as a server, a user terminal), and the client 300 and the node 200 are connected through network communication.

[0109] Taking the distributed system as the blockchain system as an example, see Figure 7 This is a schematic diagram of an optional architecture for a distributed system 100, as provided in an embodiment of the present invention, applied to a blockchain system. The system consists of multiple nodes 200 (any type of computing device connected to a network, such as a server or user terminal) and clients 300. The nodes form a peer-to-peer (P2P) network. The P2P protocol is an application layer protocol that runs on top of the Transmission Control Protocol (TCP). In a distributed system, any machine, such as a server or terminal, can join and become a node. A node comprises a hardware layer, an intermediate layer, an operating system layer, and an application layer.

[0110] See also Figure 7The functions of each node in the blockchain system shown include:

[0111] 1) Routing: A basic function of a node, used to support communication between nodes.

[0112] In addition to the routing function, nodes can also have the following functions:

[0113] 2) Applications, deployed in the blockchain, implement specific services based on actual business needs, record data related to the implementation of functions to form record data, carry digital signatures in the record data to indicate the source of the task data, and send the record data to other nodes in the blockchain system for other nodes to add the record data to a temporary block when they successfully verify the source and integrity of the record data.

[0114] For example, the services implemented by the application include: code for implementing a protection capability detection function, which mainly includes:

[0115] Receive a detection request for a protection system of a target detection site, the detection request including an attack type for the target detection site; generate a data attack packet according to the attack type, the data attack packet including attack features corresponding to the attack type; send the data attack packet to the target detection site; obtain response information of the protection system of the target detection site to the data attack packet, and determine a protection rate of the protection system for the target detection site according to the response information.

[0116] 3) Blockchain, including a series of blocks that are connected to each other in the order of their generation. Once a new block is added to the blockchain, it will not be removed. The block records the record data submitted by the nodes in the blockchain system.

[0117] See also Figure 8 This is an optional schematic diagram of the block structure provided by an embodiment of the present invention. Each block includes the hash value of the transaction records stored in the block (the hash value of the current block) and the hash value of the previous block. The blocks are connected by hash values ​​to form a blockchain. In addition, the block may also include information such as the timestamp when the block was generated. Blockchain is essentially a decentralized database, a series of data blocks generated using cryptographic methods. Each data block contains relevant information used to verify the validity of the information (anti-counterfeiting) and generate the next block.

[0118] The embodiment of the present invention also provides a protection capability detection system, the structural diagram of which is shown as follows: Figure 9 Specifically, it may include:

[0119] The request receiving unit 20 is configured to receive a detection request from the protection system of a target detection site, wherein the detection request includes an attack type on the target detection site.

[0120] The data generating unit 21 is configured to generate a data attack packet according to the attack type in the detection request received by the request receiving unit 20 , wherein the data attack packet includes an attack feature corresponding to the attack type.

[0121] The data sending unit 22 is configured to send the data attack packet generated by the data generating unit 21 to the target detection site.

[0122] The detection unit 23 is configured to obtain response information of the protection system of the target detection site to the data attack packet sent by the data sending unit 22, and determine a protection rate of the protection system for the target detection site according to the response information.

[0123] In a specific embodiment, if the detection request includes an attack type, the data generation unit 21 is specifically used to generate multiple data attack packets based on the attack type; the detection unit 23 is specifically used to count the number of times the protection system successfully protects against the attacks of the multiple data attack packets based on the response information corresponding to the multiple data attack packets; and determine the protection rate of the protection system against an attack type as the ratio of the counted number to the total number of attacks of the multiple data attack packets.

[0124] In another specific embodiment, the request receiving unit 20 is specifically used to display a detection setting interface, which includes a first parameter setting interface for the target detection site, a second parameter setting interface for the protection system, and a detection initiation interface; receiving a first parameter value for the target detection site and a second parameter value for the protection system input by the user from the first parameter setting interface and the second parameter setting interface, respectively, wherein the second parameter value includes an attack type; and receiving a detection request for the protection system of the target detection site in response to an operation on the detection initiation interface, wherein the detection request includes the first parameter value and the second parameter value.

[0125] Furthermore, the detection setting interface also includes: a setting interface for matching features; the request receiving unit 20 is also used to receive matching features input by the user from the setting interface for matching features, and the detection request includes the matching features input by the user; the detection unit 23 is specifically used to determine whether the protection system successfully protects against the attack of the data attack package based on whether the response information includes the matching features input by the user; and calculate the protection rate of the protection system for the target detection site based on the information on whether the protection is successful.

[0126] Among them, if the second parameter setting interface includes the setting interface of the protection mechanism of the protection system, and the second parameter value includes whether the protection mechanism of the protection system is a black mechanism or a white mechanism; then the detection unit 23, when determining whether the protection system successfully protects against the attack of the data attack package based on whether the response information includes the matching feature input by the user, is specifically used to determine the first information that the protection system successfully protects against the attack of the data attack package if the second parameter value includes the black mechanism and the response information includes the matching feature input by the user; and determine the second information that the protection system did not successfully protect against the attack of the data attack package if the second parameter value includes the white mechanism and the response information includes the matching feature input by the user.

[0127] In other embodiments, if the detection request received by the request receiving unit 20 includes multiple attack types on the target detection site, multiple threads can also be opened, each thread including a data generation unit 21 and a data sending unit 22, each of which generates a data attack package according to an attack type and sends the data attack package to the target detection site.

[0128] In other embodiments, if the attack type is a structured query language SQL injection attack, the data generation unit 21 is specifically used to generate a data attack package including specific SQL instructions; if the attack type is a cross-site scripting attack XSS, the data generation unit 21 is specifically used to generate a data attack package including specific web page program code; if the attack type is a system command injection attack, the data generation unit 21 is specifically used to generate a data attack package including system commands; if the attack type is a backdoor connection behavior, the data generation unit 21 is specifically used to generate a data attack package for accessing a specific interface of the target detection site, and the attack features in the data attack package include information about a specific suffix file, a specific function or a specific backdoor file; if the attack type is an unauthorized access behavior, the data generation unit 21 is specifically used to generate an access request to a specific directory or file in the target detection site.

[0129] Furthermore, if the attack type is vulnerability scanning behavior, the data generation unit 21 is specifically used to generate a data attack package for scanning vulnerabilities in the target detection site; if the attack type is web crawler behavior, the data generation unit 21 is specifically used to generate a data attack package for obtaining all the contents in the target detection site; if the attack type is a Web server attack, the data generation unit 21 is specifically used to generate an access request to a specific directory or file in the target detection site; if the attack type is a Web application attack, the data generation unit 21 is specifically used to generate a data attack package for unauthorized access, specific command execution or overflow vulnerability.

[0130] It can be seen that in the protection capability detection system of this embodiment, the data generation unit 21 will automatically generate a data attack packet based on the attack type included in the detection request of the protection system of the target detection site, and the data sending unit 22 will send the data attack packet to the target detection site, thereby simulating the attack process on the target detection site. When the detection unit 23 obtains the response information of the protection system of the target detection site to the data attack packet, the protection rate of the protection system for the target detection site can be determined based on the response information. In the process of detecting the capability of the protection system, the attack on the target detection site can be automatically simulated, and then the protection capability of the protection system can be automatically determined based on the response information, realizing the automation process of the protection capability detection of the protection system without the need for manual evaluation, simplifying the process of protection capability detection, and achieving stable detection effect.

[0131] The embodiment of the present invention further provides a terminal device, the structural diagram of which is shown in FIG. Figure 10 As shown, the terminal device may have relatively large differences due to different configurations or performances, and may include one or more central processing units (CPUs) 30 (for example, one or more processors) and memory 31, and one or more storage media 32 (for example, one or more mass storage devices) storing application programs 321 or data 322. Memory 31 and storage medium 32 may be temporary storage or permanent storage. The program stored in the storage medium 32 may include one or more modules (not shown), each module may include a series of instruction operations in the terminal device. Furthermore, the central processing unit 30 may be configured to communicate with the storage medium 32 to execute a series of instruction operations in the storage medium 32 on the terminal device.

[0132] Specifically, the application 321 stored in the storage medium 32 includes a list processing application, and the application may include the request receiving unit 20, data generating unit 21, data sending unit 22, and detection unit 23 of the above-mentioned list processing device, which are not described in detail here. Furthermore, the central processing unit 30 can be configured to communicate with the storage medium 32 and execute a series of operations corresponding to the list processing application stored in the storage medium 32 on the terminal device.

[0133] The terminal device may also include one or more power supplies 33, one or more wired or wireless network interfaces 34, one or more input and output interfaces 35, and / or one or more operating systems 323, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0134] The steps performed by the protection capability detection system in the above method embodiment can be based on the Figure 10 In specific applications, terminal devices may include but are not limited to mobile phones, computers, intelligent voice interaction devices, smart home appliances, and vehicle-mounted terminals.

[0135] In addition, another aspect of an embodiment of the present invention further provides a computer-readable storage medium, which stores a plurality of computer programs, and the computer programs are suitable for being loaded by a processor and executed by the protection capability detection method executed by the above-mentioned protection capability detection system.

[0136] Another aspect of the present invention provides a terminal device, including a processor and a memory;

[0137] The memory is used to store multiple computer programs, and the computer programs are used to be loaded by the processor and executed by the protection capability detection method performed by the above-mentioned protection capability detection system; the processor is used to implement each computer program in the multiple computer programs.

[0138] In addition, according to one aspect of the present application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the protection capability detection method provided in the various optional implementations described above.

[0139] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, which may include: read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc.

[0140] The above is a detailed introduction to the protection capability detection method, system, storage medium and terminal device provided in the embodiments of the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.

Claims

1. A method for detecting protection capability, characterized in that: include: Display the detection setting interface, which includes a first parameter setting interface for the target detection site, a second parameter setting interface for the protection system, and a detection initiation interface; Receiving, from the first parameter setting interface and the second parameter setting interface, respectively, a first parameter value of the target detection site and a second parameter value of the protection system input by a user, the second parameter value including a protection mechanism of the protection system for the target detection site and a type of attack that the protection system can protect against, the second parameter setting interface including an interface for setting the protection mechanism of the protection system, the second parameter value including whether the protection mechanism of the protection system is a black mechanism or a white mechanism; In response to an operation on the detection initiation interface, receiving a detection request for the protection system of the target detection site, the detection request including a matching feature of the first parameter value, the second parameter value, and the user input; generating a data attack packet according to the attack type, wherein the data attack packet includes an attack feature corresponding to the attack type; Sending the data attack packet to the target detection site; Obtaining response information of the protection system of the target detection site to the data attack packet, and if the second parameter value includes a black mechanism and the response information includes the matching feature input by the user, determining first information indicating that the protection system has successfully protected against the attack of the data attack packet; If the second parameter value includes a white mechanism, and the response information includes the matching feature input by the user, second information is determined to indicate that the protection system has failed to successfully protect against the attack of the data attack packet; The protection rate of the protection system for the target detection site is calculated based on the information of whether the protection is successful.

2. The method according to claim 1, wherein The detection request includes multiple attack types on the target detection site; Then, generating a data attack packet according to the attack type and sending the data attack packet to the target detection site specifically includes: For each attack type, a data attack packet is generated through at least one thread, and the data attack packet is sent to the target detection site.

3. The method according to any one of claims 1 to 2, characterized in that If the attack type is a structured query language injection attack, generating a data attack packet according to the attack type specifically includes: generating a data attack packet including specific structured query language instructions; If the attack type is a cross-site scripting attack, generating a data attack packet according to the attack type specifically includes: generating a data attack packet including a specific web page program code; If the attack type is a system command injection attack, generating a data attack packet according to the attack type specifically includes: generating a data attack packet including a system command; If the attack type is a backdoor connection behavior, generating a data attack packet according to the attack type specifically includes: generating a data attack packet for accessing a specific interface of the target detection site, wherein the attack characteristics in the data attack packet include information about a specific suffix file, a specific function, or a specific backdoor file; If the attack type is unauthorized access behavior, generating a data attack package according to the attack type specifically includes: generating an access request to a specific directory or file in the target detection site.

4. The method according to any one of claims 1 to 2, characterized in that If the attack type is vulnerability scanning behavior, generating a data attack packet according to the attack type specifically includes: generating a data attack packet that scans for vulnerabilities in the target detection site; If the attack type is a web crawler behavior, generating a data attack packet according to the attack type specifically includes: generating a data attack packet for acquiring all contents in the target detection site; If the attack type is a website server attack, generating a data attack packet according to the attack type specifically includes: generating an access request to a specific directory or file in the target detection site; If the attack type is a website application attack, generating a data attack package according to the attack type specifically includes: generating a data attack package for performing unauthorized access, executing a specific command, or overflowing a vulnerability.

5. The method according to any one of claims 1 to 2, characterized in that The detection request includes an attack type, and generating a data attack packet according to the attack type specifically includes: generating multiple data attack packets according to the attack type; Then, determining the protection rate of the protection system for the target detection site according to the response information specifically includes: counting, based on the response information corresponding to the multiple data attack packets, the number of times the protection system successfully protects against attacks by the multiple data attack packets; Determining the protection rate of the protection system against one attack type is a ratio of the statistical number of times to the total number of attacks of the multiple data attack packets.

6. A protection capability detection system, characterized in that: include: A request receiving unit, configured to display a detection setting interface, wherein the detection setting interface includes a first parameter setting interface for a target detection site, a second parameter setting interface for a protection system, and a detection initiation interface; Receiving, from the first parameter setting interface and the second parameter setting interface, respectively, a first parameter value of the target detection site and a second parameter value of the protection system input by the user, the second parameter value including the protection mechanism of the protection system for the target detection site and the type of attack that the protection system can protect against, the second parameter setting interface including an interface for setting the protection mechanism of the protection system, the second parameter value including whether the protection mechanism of the protection system is a black mechanism or a white mechanism; in response to an operation on the detection initiation interface, receiving a detection request for the protection system of the target detection site, the detection request including the first parameter value and the second parameter value and a matching feature of the user input; a data generating unit, configured to generate a data attack packet according to the attack type, wherein the data attack packet includes an attack feature corresponding to the attack type; A data sending unit, configured to send the data attack packet to the target detection site; A detection unit is used to obtain response information of the protection system of the target detection site to the data attack packet, and if the second parameter value includes a black mechanism and the response information includes the matching feature input by the user, determine first information that the protection system successfully protects against the attack of the data attack packet; if the second parameter value includes a white mechanism and the response information includes the matching feature input by the user, determine second information that the protection system did not successfully protect against the attack of the data attack packet; and calculate the protection rate of the protection system for the target detection site based on the information of whether the protection is successful.

7. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of computer programs, and the computer programs are suitable for being loaded by a processor and executing the protection capability detection method according to any one of claims 1 to 5.

8. A terminal device, characterized in that: including processor and memory; The memory is used to store multiple computer programs, and the computer programs are used to be loaded by the processor and execute the protection capability detection method according to any one of claims 1 to 5; the processor is used to implement each computer program in the multiple computer programs.

Citation Information

Patent Citations

  • Network security flow generating method and network security flow generating system

    CN104219221A

  • Vulnerability detection method based on plug-in

    CN104426850A

  • Attack testing method and device of application system, computer equipment and storage medium

    CN111427767A

  • Automatic penetration test system based on AI

    CN111488587A