Attack trapping processing method, device, electronic device and storage medium
Access request feature information is obtained through switch mirror traffic, and trapping response is initiated using the trapping rule library, solving the problem of low malicious attack processing efficiency in bypass protection scenarios, and achieving fast and effective attack countermeasures.
Patent Information
- Application Number
- CN202211294149.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-21
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2042-10-21
AI Technical Summary
The prior art has low efficiency in handling malicious attacks in bypass protection scenarios, and cannot effectively block the session, resulting in the attacks being sustainable.
The feature information of the access request is obtained through the switch mirror traffic, and the preset trapping rule base is used to determine and initiate a trapping response, including calculating hash value matching or direct feature information matching, and quickly launching a trapping response packet to block the attack.
It improves the efficiency of handling malicious attacks, achieves timely and effective countermeasures, reduces intrusion and cost, and does not require changes to the network topology.
Smart Images

Figure CN115801324B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, specifically to technical fields such as information flow, and more particularly to a method, device, electronic device, and storage medium for trapping and processing attacks. Background Art
[0002] During network sessions, various malicious messages are often constructed to launch malicious attacks against web sites.
[0003] In bypass protection scenarios, the switch can restore attacking Hypertext Transfer Protocol (HTTP) packets based on mirrored traffic and detect them to determine whether they are malicious attacks. For example, if the packets are detected as malicious attacks, a reset (RST) connection message can be sent to block the Transmission Control Protocol (TCP) session, or an Internet Control Message Protocol (ICMP) port unreachable message can be sent to disrupt the User Datagram Protocol (UDP) session, thereby blocking the session. Summary of the Invention
[0004] The present disclosure provides a method, device, electronic device, and storage medium for trapping and processing attacks.
[0005] According to one aspect of the present disclosure, a method for trapping an attack is provided, comprising:
[0006] Obtaining a first access request sent to the server based on the mirrored traffic of the switch;
[0007] Obtaining characteristic information of the first access request;
[0008] Determining, based on the characteristic information of the first access request and a preset trapping rule library, that a trapping response needs to be initiated;
[0009] Based on the first access request, a trap response is performed.
[0010] According to another aspect of the present disclosure, there is provided an attack trapping processing device, comprising:
[0011] A request acquisition module, configured to acquire a first access request sent to the server based on the mirrored traffic of the switch;
[0012] A feature acquisition module, configured to acquire feature information of the first access request;
[0013] a determination module, configured to determine, based on the characteristic information of the first access request and a preset trapping rule library, whether a trapping response needs to be initiated;
[0014] The trapping response module is used to perform a trapping response based on the first access request.
[0015] According to another aspect of the present disclosure, there is provided an electronic device, comprising:
[0016] at least one processor; and
[0017] a memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any possible implementation manner and the aspects described above.
[0019] According to yet another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to execute the method of the above-mentioned aspect and any possible implementation manner.
[0020] According to yet another aspect of the present disclosure, a computer program product is provided, including a computer program, which implements the above-mentioned aspects and any possible implementation method when executed by a processor.
[0021] According to the technology disclosed in the present invention, the efficiency of processing malicious attacks can be effectively improved.
[0022] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present disclosure.
[0024] Figure 1 is a schematic diagram according to a first embodiment of the present disclosure;
[0025] Figure 2 is a schematic diagram according to a second embodiment of the present disclosure;
[0026] Figure 3 This is a schematic diagram of a trapping request response provided in this embodiment;
[0027] Figure 4This is a diagram of the architecture of the attack trapping process of this embodiment;
[0028] Figure 5 is a schematic diagram according to a third embodiment of the present disclosure;
[0029] Figure 6 is a schematic diagram according to a fourth embodiment of the present disclosure;
[0030] Figure 7 is a block diagram of an electronic device for implementing the method according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0031] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0032] Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.
[0033] It should be noted that the terminal devices involved in the embodiments of the present disclosure may include but are not limited to mobile phones, personal digital assistants (PDAs), wireless handheld devices, tablet computers and other smart devices; display devices may include but are not limited to personal computers, televisions and other devices with display functions.
[0034] In this document, the term "and / or" simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0035] In existing bypass protection scenarios, while it's possible to block TCP sessions by sending a reset (RST) connection message, or disrupt UDP sessions by sending an ICMP port unreachable message, this process takes time as traffic is mirrored by the switch to the security device, which then analyzes and issues a blocking message. Consequently, sessions may not be effectively blocked, allowing attacks to continue. Consequently, existing methods are very inefficient in handling malicious attacks.
[0036] Figure 1 is a schematic diagram according to the first embodiment of the present disclosure; Figure 1 As shown, this embodiment provides a method for trapping an attack, which is applied to a bypass trapping security device and may specifically include the following steps:
[0037] S101. Acquire a first access request sent to a server based on mirrored traffic of a switch;
[0038] S102: Obtain characteristic information of the first access request;
[0039] S103: Determining that a trapping response needs to be initiated based on the characteristic information of the first access request and a preset trapping rule library;
[0040] S104: Perform a trapping response based on the first access request.
[0041] In a network access scenario, the user's first access request first reaches the switch, and then is sent by the switch to the server of the source station to be accessed.
[0042] The attack trapping method of this embodiment is applied to a bypass trapping security device, which is located on a bypass path relative to the access link from the switch to the server. After the switch receives the first access request, it can obtain the first access request to the server through a mirroring method. Specifically, the first access request can be multiple TCP packets, and by restoring the multiple TCP packets, a mirrored HTTP request can be obtained.
[0043] In this embodiment, the need for a trapping response can be determined by analyzing the characteristic information of the first access request and a preset trapping rule library. Specifically, the first access request can be determined to be an attack, and a trapping response can be quickly initiated to the first access request, enabling timely and effective countermeasures against the first attack request.
[0044] The attack trapping processing method of this embodiment is different from the existing session blocking principle. By adopting the above-mentioned technical solution, it can be determined based on the characteristic information of the first access request and the preset trapping rule library that a trapping response needs to be initiated, and the first access request can be actively trapped to respond, thereby effectively countering the attack and effectively improving the processing efficiency of malicious attacks.
[0045] Figure 2 is a schematic diagram according to the second embodiment of the present disclosure; the attack trapping processing method of this embodiment, in the above Figure 1 Based on the technical solutions of the embodiments shown, the technical solutions of the present disclosure are further described in more detail. Figure 2As shown, the attack trapping processing method of this embodiment may specifically include the following steps:
[0046] S201. Acquire a first access request sent to a server based on the mirrored traffic of the switch;
[0047] Specifically, the first access request sent to the server can be restored based on the mirrored traffic obtained from the switch. In actual applications, an access request and HTTP request may include multiple TCP packets. It is necessary to obtain multiple TCP packets to restore the corresponding HTTP request. Specifically, please refer to the above Figure 1 The implementation of step S101 in the illustrated embodiment will not be described in detail here.
[0048] S202: Obtain feature information in the first access request;
[0049] In this embodiment, the acquired characteristic information in the first access request may include the first access request IP address; or may include both the first access request IP address and the identity characteristic information of the first access request.
[0050] It should be noted that the identity feature information of the first access request can be understood as the identity feature information generated by the server for the client of the first access request when the client accesses the server. The server can perform session tracking based on the first access request, obtain the user feature information of the access client and / or the device feature information of the access client, and then generate the identity feature information. This identity feature information can easily identify the identity of the accessing user and is stored on the local terminal of the client. The next time the user uses the terminal to access the server through the client, he can quickly initiate access. Therefore, the identity feature information of the first access request in this embodiment can be the access cookie feature corresponding to the first access request.
[0051] In this embodiment, when the first access request contains access cookie features, it is necessary to obtain the access cookie features of the first access request. Specifically, the feature information in the first access request includes the IP address and the access cookie features. However, in actual applications, some malicious accesses may delete the corresponding access cookie features, making them unavailable. In this case, the feature information in the first access request only includes the IP address. In summary, this step ensures that the most accurate feature information for the first access request is obtained.
[0052] S203: Calculate the hash value of the feature information in the first access request;
[0053] In a specific implementation, a hash value of the feature information is calculated based on the first access request IP address and the access cookie feature included in the feature information of the first access request. If the feature information of the first access request does not include the access cookie feature, a hash value of the feature information can be calculated based on the first access request IP address and an empty access cookie feature.
[0054] S204: Check whether the hash value matches the trapping rule in the trapping rule library. If so, execute step S205; otherwise, if not, execute step S211.
[0055] S205: Determine that a trapping response needs to be initiated; execute step S206;
[0056] In this embodiment, the trapping rules stored in the trapping rule library are hash values of the characteristic information of the attack request. Since hash value matching is very accurate and fast, a trapping response can be quickly initiated when the hash value matches the trapping rule, ensuring that the trapping response is issued before the server's normal response, thus promptly countering the attack.
[0057] Alternatively, in one embodiment of the present disclosure, if the trapping rule library contains relatively few trapping rules, the characteristic information of each attack request can be directly used as the trapping rule and stored in the trapping rule library. During use, the characteristic information of the attack request is directly matched against each trapping rule in the trapping rule library. If any trapping rule is matched, a trapping response is initiated. This detection method offers very high accuracy, as it directly uses the characteristic information of the attack request to detect whether a trapping rule is matched. Furthermore, since the number of trapping rules is relatively small, rapid countermeasures can be implemented. However, if the number of trapping rules is large, this method can be very time-consuming, as each trapping rule contains a large amount of characteristic information, and it is not possible to quickly detect whether a trapping rule is matched. Therefore, if the trapping rule library contains a large number of trapping rules, it is preferable to construct the trapping rule using the hash value of the characteristic information of each attack request. Furthermore, the hash value calculation process should utilize a hash algorithm that avoids hash collisions, effectively ensuring that the characteristic information of different access requests does not generate the same hash value.
[0058] Based on the above, when the number of trapping rules in the trapping rule library is less than a preset threshold, the characteristic information of the attack request is used as the trapping rule to construct the trapping rule library. When the number of trapping rules is greater than or equal to the preset threshold, the hash value of the characteristic information of the attack request is used as the trapping rule to construct the trapping rule library. The preset threshold can be set according to actual needs, for example, 20, 30, or other values.
[0059] In practical applications, no matter which of the above methods is adopted, the timing for initiating a trapping response can be accurately determined.
[0060] It should be noted that if the hash value corresponding to the characteristic information of the first access request hits the trapping rule in the trapping rule library, then correspondingly, before step S201, the following steps may also be included: obtaining a second access request with characteristic information; detecting and determining that the second access request is an attack; and updating the trapping rule library based on the characteristic information.
[0061] The second access request is an access request corresponding to the same characteristic information before the first access request. For example, it can be the first access request initiated by the characteristic information to the server. That is to say, when the access request corresponding to the characteristic information is detected as an attack during the first access request, the trapping rule base is updated based on the characteristic information. For example, with reference to the construction of the trapping rule base in the above embodiment, the characteristic information can be directly updated as a trapping rule to the trapping rule base; or a hash value can be calculated based on the characteristic information; and the hash value of the characteristic information can be used as a trapping rule and updated to the trapping rule base. Through the above processing, the trapping rule base can be updated accurately and timely when an attack is detected.
[0062] S206. Initiate a pre-created response header packet based on the serial number of the first access request; and execute step S207.
[0063] S207, assemble the trapping script to form a trapping response packet; execute step S208;
[0064] S208: Initiate a trapping response packet; execute step S209;
[0065] By implementing the above steps S206-S208, a trapping response can be accurately initiated for the first access request.
[0066] S209, receiving the trapping data returned by the trapping script; executing step S210;
[0067] The trapped data is data collected after the trapping script runs on the client of the first access request, including user feature information of the client of the first access request, device feature information of the client, and social traceability information of the user.
[0068] Through the trapping of this embodiment, the trapped data that can be obtained is very rich in content, and the user feature information in the trapped data can very accurately locate the user, the device feature information can very accurately locate the device, and the user's social tracing information can also very accurately locate the user. Based on these trapped data, very accurate and effective countermeasures can be carried out, which can effectively improve the efficiency of countering malicious attacks.
[0069] The client's device feature information refers to the device feature information of the local terminal device on which the client is running.
[0070] For example Figure 3 This is a schematic diagram of a decoy request response provided by this embodiment. For example, if the HTTP request packet has seq=1, ack=1, and an HTTP length of 481, a 200 status code first packet response is quickly issued to quickly complete the response before the source server's response packet. A TCP packet with seq=1, ack=482, and flags=PA is constructed and sent via the network card to the malicious user corresponding to the first access request. The first packet has a length of 17 and contains the following: HTTP / 1.0 200 OK\x0d\x0a.
[0071] Then the decoy script JS is combined with the forged page and loaded, and divided into multiple TCP packets for sending.
[0072] Specifically, after the trapping response packet is delivered to the malicious user's browser client, the trapping script js is automatically executed to collect the user's characteristic information and the characteristic information of the user's device. The user's characteristic information can be called the user's fingerprint information, or it can be understood as the user's cookie characteristics, including attribute information of at least one dimension of the user. The characteristic information of the user's device can be called the device's fingerprint information, or it can be understood as the cookie characteristics of the user's device, including information of at least one dimension of the user's device. In addition, after the trapping script captures the user's cookie characteristics and the device's cookie characteristics, it can update the cookie characteristics of the source server configuration on the user's local terminal, including the user's cookie characteristics and the device's cookie characteristics. In this way, when the user subsequently uses the device to initiate an access request to the server again, the user's cookie characteristics and the device's cookie characteristics will be carried. At the same time, the trapping script can also perform social tracing to obtain the user's social tracing information. The technical principle of this cross-tracing is to call the JSONP interface of the relevant social platform and obtain social information such as social accounts based on the interface callback. In other words, the user's social tracing information can include information of multiple social accounts of the user, etc. Finally, the decoy script packages the captured data, assembles the relevant data into a request body, and calls back to the source server, completing the transmission of the decoy results. On the decoy security device side, the decoy data can be retrieved by obtaining mirrored traffic from the switch.
[0073] In this embodiment, a decoy script is delivered through forged response messages to proactively identify malicious users and user devices, and collect social intelligence information. This solution accurately identifies attacking users while maintaining stealth, effectively avoiding the inefficiency of IP-based session protection methods caused by the use of a large number of proxies. Furthermore, it can collect social intelligence related to malicious users to facilitate rapid countermeasures.
[0074] Moreover, this embodiment has low implementation cost and low invasiveness. It can complete all the trapping script delivery and information recovery work without the need for serial equipment cooperation, and does not require changes to the original business network topology. It is very convenient to use and very practical.
[0075] S210. Perform access denial processing based on the trapped data; end.
[0076] For example, the following three situations may be included:
[0077] In the first scenario, based on the user characteristic information of the client of the first access request in the trapping data, the malicious user information table is updated; and the malicious user information table is sent to the server so that the server performs access rejection processing based on the malicious user information table.
[0078] The user characteristic information in the entrapped data, such as the user's cookie characteristics, can be used to more accurately locate the malicious user and determine their identity. In this embodiment, the user characteristic information in the entrapped data is updated into a malicious user information table, and the malicious user information table is sent to the server. In this way, when the server receives an access request containing any user characteristic information in the malicious user information table, it can deny access to the corresponding access request. For example, the server can respond by constructing an access denial page to implement access denial.
[0079] In the second scenario, based on the device feature information of the client of the first access request in the trapping data, the malicious device information table is updated; and the malicious device information table is sent to the server, so that the server performs access rejection processing based on the malicious device information table;
[0080] The device feature information in the trapping data can be, for example, a device cookie feature. In this embodiment, the device feature information in the trapping data is updated into a malicious device information table, and the malicious device information table is sent to the server. Thus, when the server receives an access request containing any device feature information in the malicious device information table, it can deny access to the corresponding access request.
[0081] The third scenario is to send the user's social tracing information in the trapping data to the server so that the server can perform access rejection based on the user's social tracing information.
[0082] In actual applications, when users use various social applications, they can also initiate access requests based on their social application accounts. When the server receives such access requests, it can also directly deny access.
[0083] The above three situations can be used individually or in combination.
[0084] It should be noted that in actual applications, after collecting user feature information, device feature information and user social traceability information in the trapped data, other analyses and uses can be performed, which are not limited here.
[0085] By performing access denial processing based on the above-mentioned trapping data, malicious access can be effectively denied and the processing efficiency of malicious access can be improved.
[0086] S211. Detect whether the first access request is an attack; if so, execute step S212; if not, do not perform any operation for the time being and end.
[0087] Specifically, a continuous security check can be performed on the HTTP session of the first access request, for example, to detect whether the request and response involve unsafe factors such as data leakage. If so, the first access request is considered an attack. For details, please refer to relevant technologies and will not be repeated here.
[0088] S212, obtain characteristic information of the first access request; execute step S213;
[0089] Specifically, please refer to the description of step S202 above, which will not be repeated here.
[0090] S213: Update the trapping rule library based on the characteristic information of the first access request, and end.
[0091] Specifically, referring to the relevant descriptions of the above embodiment, when the number of trapping rules included in the trapping rule base is small, such as less than a preset threshold, the characteristic information of the first access request can be directly used as a trapping rule and updated to the trapping rule base. If the number of trapping rules included in the trapping rule base is large, such as greater than or equal to the preset threshold, a hash value can be calculated based on the characteristic information; the hash value of the characteristic information can be used as a trapping rule and updated to the trapping rule base.
[0092] Based on the above, we can see that for any access request, if it is detected as an attack during the first access, the trapping rule base will be updated based on the characteristic information of the access. When the access request corresponding to the characteristic information is subsequently initiated again, the access request can be directly trapped based on the trapping rule base, and the corresponding trapping data such as user characteristic information, device characteristic information, and the user's social traceability information can be collected. Based on this trapping data, access denial processing can be performed, or other analysis and processing can be performed.
[0093] Figure 4 This is the architecture diagram of the attack trapping process of this embodiment. Figure 4 As shown in the figure, the client initiates a service HTTP request to the switch. The switch sends the mirrored service HTTP request to the bypass trap security device through traffic mirroring, and sends the normal service HTTP request to the server. After the bypass trap security device obtains the service HTTP request, it can follow the above steps. Figure 4 In the embodiment shown, it is determined whether a trapping response needs to be initiated. If so, a trapping response is quickly initiated and sent by the switch to the client. It should be noted that the trapping response must be sent before the server's service response to achieve a quick countermeasure.
[0094] The attack trapping method of this embodiment, by employing the above-described technical solution, can proactively initiate a trapping response when the characteristic information of a first access request matches a trapping rule base, effectively countering the attack and effectively improving the efficiency of handling malicious attacks. Furthermore, when the first access request does not match the trapping rule base, but is an attack, the trapping rule base is updated based on the characteristic information of the first access request, so that a timely, accurate, and rapid trapping response can be initiated when an access request corresponding to the characteristic information is initiated again, effectively countering the attack and effectively improving the efficiency of handling malicious attacks.
[0095] The attack trapping processing method of this embodiment can enrich and strengthen the bypass countermeasures, and achieve the purpose of effective countermeasures in a low-invasive and low-cost manner.
[0096] Figure 5 is a schematic diagram according to the third embodiment of the present disclosure; Figure 5 As shown, this embodiment provides an attack trapping processing device 500, which is applied to a bypass trapping security device, including:
[0097] A request acquisition module 501 is configured to acquire a first access request sent to a server based on the mirrored traffic of the switch;
[0098] A feature acquisition module 502 is configured to acquire feature information of the first access request;
[0099] A determination module 503 is configured to determine whether a trapping response needs to be initiated based on the characteristic information of the first access request and a preset trapping rule library;
[0100] The trapping response module 504 is configured to perform a trapping response based on the first access request.
[0101] The attack trapping processing device 500 of this embodiment adopts the implementation principle and technical effects of the attack trapping processing of the above-mentioned related method embodiments, which are the same as those of the above-mentioned related method embodiments. For details, please refer to the records of the above-mentioned related method embodiments, which will not be repeated here.
[0102] Figure 6 is a schematic diagram according to a fourth embodiment of the present disclosure; Figure 6 As shown, this embodiment provides an attack trapping processing device 600, including: Figure 5 The modules with the same name and function shown are a request acquisition module 601, a feature acquisition module 602, a determination module 603 and a trapping response module 604.
[0103] In the attack trapping processing device 600 of this embodiment, the determination module 603 is used to:
[0104] detecting and determining that the characteristic information of the first access request matches a trapping rule in the trapping rule library, and determining that a trapping response needs to be initiated; or
[0105] Calculating a hash value of the characteristic information; detecting and determining whether the hash value of the characteristic information hits a trapping rule in the trapping rule library, and determining that a trapping response needs to be initiated.
[0106] Further optionally, in one embodiment of the present disclosure, the trapping response module 604 is configured to:
[0107] Initiating a pre-created response header packet based on the serial number of the first access request;
[0108] Assemble the decoy script to form a decoy response package;
[0109] The decoy response packet is initiated.
[0110] Further optionally, in one embodiment of the present disclosure, the attack trapping processing device 600 further includes:
[0111] The receiving module 605 is used to receive the trapped data returned by the trapping script. The trapped data is the data collected after the trapping script is run on the client of the first access request, including the user feature information of the client of the first access request, the device feature information of the client, and the social traceability information of the user.
[0112] Further optionally, in one embodiment of the present disclosure, the attack trapping processing device 600 further includes:
[0113] The rejection processing module 606 is configured to perform access rejection processing based on the trapping data.
[0114] Further optionally, in one embodiment of the present disclosure, the interception processing module 606 is configured to:
[0115] updating a malicious user information table based on user characteristic information of the client of the first access request in the trapping data; and sending the malicious user information table to the server so that the server performs access rejection processing based on the malicious user information table.
[0116] updating a malicious device information table based on device feature information of the client of the first access request in the trapping data; and sending the malicious device information table to the server so that the server performs access rejection processing based on the malicious device information table.
[0117] The social tracing information of the user in the trapping data is sent to the server, so that the server can perform access rejection processing based on the social tracing information of the user.
[0118] Further optionally, in one embodiment of the present disclosure, the feature acquisition module 602 is configured to:
[0119] Obtaining the IP address of the first access request; or
[0120] Obtain the IP address of the first access request and identity feature information of the first access request.
[0121] Further optionally, in one embodiment of the present disclosure, the attack trapping processing device 600 further includes: an updating module 607;
[0122] A request obtaining module 601 is configured to obtain a second access request for the feature information;
[0123] The determination module 603 is further configured to detect and determine that the second access request is an attack;
[0124] The updating module 607 is configured to update the trapping rule library based on the feature information.
[0125] Further optionally, in one embodiment of the present disclosure, the updating module 607 is configured to:
[0126] updating the feature information as a trapping rule into the trapping rule library; or
[0127] Based on the feature information, a hash value is calculated; and the hash value of the feature information is used as a trapping rule and updated into the trapping rule library.
[0128] The attack trapping processing device 600 of this embodiment adopts the implementation principle and technical effects of the attack trapping processing of the above-mentioned related method embodiments, which are the same as those of the above-mentioned related method embodiments. For details, please refer to the records of the above-mentioned related method embodiments, which will not be repeated here.
[0129] In the technical solutions disclosed herein, the acquisition, storage, and application of user personal information involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0130] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0131] Figure 7 A schematic block diagram of an example electronic device 700 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0132] like Figure 7 As shown, the device 700 includes a computing unit 701, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. Various programs and data required for the operation of the device 700 can also be stored in the RAM 703. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0133] Various components in device 700 are connected to I / O interface 705, including an input unit 706, such as a keyboard, mouse, etc.; an output unit 707, such as various types of displays, speakers, etc.; a storage unit 708, such as a magnetic disk, optical disk, etc.; and a communication unit 709, such as a network card, modem, wireless communication transceiver, etc. The communication unit 709 allows device 700 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0134] The computing unit 701 can be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 701 performs the various methods and processes described above, such as the above-mentioned methods of the present disclosure. For example, in some embodiments, the above-mentioned methods of the present disclosure can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as a storage unit 708. In some embodiments, part or all of the computer program can be loaded and / or installed on the device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the computing unit 701, one or more steps of the above-mentioned methods of the present disclosure described above can be performed. Alternatively, in other embodiments, the computing unit 701 can be configured to perform the above-mentioned methods of the present disclosure by any other appropriate means (e.g., by means of firmware).
[0135] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0136] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0137] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0138] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0139] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0140] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.
[0141] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not a limitation herein.
[0142] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.
Claims
1. A method for trapping and processing an attack, comprising: Obtaining a first access request sent to the server based on the mirrored traffic of the switch; Obtaining characteristic information of the first access request; The characteristic information of the first access request includes the IP address and access cookie characteristics of the first access request; Based on the characteristic information of the first access request and a preset trapping rule library, determining that a trapping response needs to be initiated; when the number of trapping rules in the trapping rule library is less than a preset threshold, using the characteristic information of the attack request in the trapping rule library as the trapping rule; when the number of trapping rules in the trapping rule library is greater than or equal to the preset threshold, using a hash value of the characteristic information of the attack request as the trapping rule; the characteristic information of the attack request includes an IP address of the attack request and a cookie feature of the attack request; Performing a trap response based on the first access request; Performing a trapping response based on the first access request includes: Assemble the decoy script to form a decoy response package; Initiating the trapping response packet; After performing a trapping response based on the first access request, the method further includes: Receive the trapped data returned by the trapping script, where the trapped data is data collected after the trapping script is run on the client of the first access request, including user feature information of the client of the first access request, device feature information of the client, and social traceability information of the user.
2. The method according to claim 1, wherein Determining, based on the characteristic information of the first access request and a preset trapping rule library, that a trapping response needs to be initiated includes: detecting and determining that the characteristic information of the first access request matches a trapping rule in the trapping rule library, and determining that a trapping response needs to be initiated; or Calculating a hash value of the characteristic information; detecting and determining whether the hash value of the characteristic information hits a trapping rule in the trapping rule library, and determining that a trapping response needs to be initiated.
3. The method according to claim 1, wherein Performing a trapping response based on the first access request further includes: Based on the serial number of the first access request, a pre-created response header packet is initiated.
4. The method according to claim 1, wherein After receiving the trapping data returned by the trapping script, the method further includes: Based on the trapping data, access denial processing is performed.
5. The method according to claim 4, wherein Based on the trapped data, access denial processing is performed, including: updating a malicious user information table based on user characteristic information of the client of the first access request in the trapping data; and sending the malicious user information table to the server so that the server performs access rejection processing based on the malicious user information table. updating a malicious device information table based on device feature information of the client of the first access request in the trapping data; and sending the malicious device information table to the server so that the server performs access rejection processing based on the malicious device information table. The social tracing information of the user in the trapping data is sent to the server, so that the server can perform access rejection processing based on the social tracing information of the user.
6. The method according to claim 1, wherein Obtaining characteristic information of the first access request includes: Obtaining the IP address of the first access request; or Obtain the IP address of the first access request and identity feature information of the first access request.
7. The method according to claim 1, wherein Before obtaining the first access request sent to the server based on the mirrored traffic of the switch, the method further includes: a second access request to obtain the characteristic information; detecting and determining that the second access request is an attack; Based on the feature information, the trapping rule library is updated.
8. The method according to claim 7, wherein: Based on the feature information, updating the trapping rule base includes: updating the feature information as a trapping rule into the trapping rule library; or Based on the feature information, a hash value is calculated; and the hash value of the feature information is used as a trapping rule and updated into the trapping rule library.
9. An attack trapping and processing device, comprising: A request acquisition module, configured to acquire a first access request sent to the server based on the mirrored traffic of the switch; a feature acquisition module, configured to acquire feature information of the first access request; the feature information of the first access request including an IP address and access cookie features of the first access request; a determination module configured to determine, based on the characteristic information of the first access request and a preset trapping rule library, that a trapping response needs to be initiated; when the number of trapping rules in the trapping rule library is less than a preset threshold, use the characteristic information of the attack request in the trapping rule library as the trapping rule; and when the number of trapping rules in the trapping rule library is greater than or equal to the preset threshold, use a hash value of the characteristic information of the attack request as the trapping rule; a trapping response module, configured to perform a trapping response based on the first access request; The trapping response module is used to: Assemble the decoy script to form a decoy response package; Initiating the trapping response packet; Wherein, the device further includes: A receiving module is used to receive the trapped data returned by the trapping script, where the trapped data is data collected after the trapping script is run on the client of the first access request, including user feature information of the client of the first access request, device feature information of the client, and social traceability information of the user.
10. The device according to claim 9, wherein The determining module is configured to: detecting and determining that the characteristic information of the first access request matches a trapping rule in the trapping rule library, and determining that a trapping response needs to be initiated; or Calculating a hash value of the feature information; Detect and determine whether the hash value of the characteristic information hits the trapping rule in the trapping rule library, and determine that a trapping response needs to be initiated.
11. The device according to claim 9, wherein The trapping response module is further configured to: Based on the serial number of the first access request, a pre-created response header packet is initiated.
12. The device according to claim 9, wherein Also includes: The rejection processing module is used to perform access rejection processing based on the trapped data.
13. The device according to claim 12, wherein The rejection processing module is used to: updating a malicious user information table based on user characteristic information of the client of the first access request in the trapping data; Sending the malicious user information table to the server, so that the server performs access rejection processing based on the malicious user information table; updating a malicious device information table based on device feature information of the client of the first access request in the trapping data; Sending the malicious device information table to the server, so that the server performs access rejection processing based on the malicious device information table; The social tracing information of the user in the trapping data is sent to the server, so that the server can perform access rejection processing based on the social tracing information of the user.
14. The device according to claim 9, wherein The feature acquisition module is used to: Obtaining the IP address of the first access request; or Obtain the IP address of the first access request and identity feature information of the first access request.
15. The device according to claim 9, wherein Also includes update modules; The request acquisition module is used to obtain a second access request for the feature information; The determination module is further configured to detect and determine that the second access request is an attack; The updating module is used to update the trapping rule library based on the feature information.
16. The device according to claim 15, wherein The update module is used to: updating the feature information as a trapping rule into the trapping rule library; or Based on the feature information, a hash value is calculated; and the hash value of the feature information is used as a trapping rule and updated into the trapping rule library.
17. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.
18. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-8.
19. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Access behavior processing method and device, storage medium and electronic equipment
CN112995151A
Honeypot bait distribution method and device, storage medium and electronic equipment
CN113037777A