A high-performance Iast external detection method, apparatus, electronic device, and medium
Patent Information
- Application Number
- CN202310131272.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-17
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2043-02-17
AI Technical Summary
[0003]为了阻止拦截上述恶意攻击,现有的web应用安全检测进程是选择与正常业务进程一起展开,但因为web应用的业务逻辑越来越复杂,数个进程一同打开导致正常业务进程不稳定甚至崩溃现象上升,无法对用户的数据安全进行保障
本申请提供了一张高性能的Iast外部检测方法、装置、电子设备及可读存储介质,与相关技术相比,在本申请中,通过得到的链路信息确定了链路通道信息和链路点信息,链路点信息内包含两部分可进行连接使用的信息,即链路插入信息和链路承接信息;链路通道信息内包含了两部分供数据传输以及处理的信息,即数据通道信息和数据解析信息。
Smart Images

Figure CN116089962B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of web application security testing, and in particular to a high-performance Iast external testing method, apparatus, electronic device, and medium. Background Technology
[0002] Over the past two years, the industries most affected by malicious web application attacks include manufacturing and retail, two sectors vital to everyone's lives. Radware's global threat analysis report highlights that in 2020-2021, the number of malicious web application requests surged by 88%, and the annual growth rate of distributed denial-of-service (DDoS) attacks was 37%, doubling from the previous year. Furthermore, as more enterprises migrate their critical resources to the public cloud, DDoS attacks targeting the public cloud are also becoming a reality.
[0003] To prevent and intercept the aforementioned malicious attacks, the existing web application security detection process is to run together with the normal business process. However, as the business logic of web applications becomes increasingly complex, the simultaneous operation of several processes leads to an increase in instability or even crashes of the normal business process, making it impossible to guarantee the security of user data. Summary of the Invention
[0004] To address the problems existing in the prior art, this application provides a high-performance Iast external detection method, apparatus, electronic device, and storage medium.
[0005] Firstly, this application provides a high-performance Iast external detection method, employing the following technical solution: A high-performance Iast external process detection method includes: Obtain link information, which includes link channel information and link point information; Based on the link point information, link insertion information and link acceptance information are determined; Based on the link channel information, determine the data channel information and data parsing information; The link insertion information and the link acceptance information are respectively associated and bound to obtain link association information; The link association information is screened to obtain application information; The application information is parsed based on the data channel information and data parsing information to obtain parsing program information; The control displays the parsing program information.
[0006] In another possible implementation, the application information is parsed based on the data channel information and the data parsing information to obtain parsing program information, and this process further includes: Obtain the application information transmitted from the data channel information, wherein the application information includes a single data packet composed of the parsed link association information; Based on the data parsing information, the application information is processed to obtain fixed parameters of the application information; The fixed parameters are filled into a preset collection container within the data channel information.
[0007] In another possible implementation, the fixed parameters are populated into the collection container, preceded by: Obtain first-level data packets and second-level data packets, wherein the first-level data packet is the first uploaded data packet in the data packet, and the second-level data packet is the data packet in the data packet excluding the first-level data packet; The first-level data packet and the second-level data packet are disassembled respectively to obtain first-level data corresponding to the first-level data packet and second-level data corresponding to the second-level data packet; The primary data is imported into the collection container for key value extraction to obtain the data key values of the primary data. Based on the key data values, determine whether the secondary data can be imported into the collection container; If the secondary data cannot be imported into the collection container, then the secondary data is discarded.
[0008] In another possible implementation, a preset set container within the data channel information is filled based on the fixed parameters, and then the process further includes: Determine whether the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters; If the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters, a vulnerability detection instruction is generated to control the execution of the preset vulnerability detection process.
[0009] In another possible implementation, the execution of a pre-defined vulnerability detection process is controlled, including: Screen whether the data filled in the collection container contains parameters processed by a preset fixed acceptance function; If the data filled in the collection container does not contain parameters processed by the fixed acceptor function, then it is considered to have a vulnerability in the parsing program information; If the data filled in the collection container contains parameters processed by the fixed acceptor function, then check whether the data filled in the collection container contains data information that has been safely escaped; If the data filled in the collection container does not contain data information that has been securely escaped, then it is considered to have a vulnerability in the parsing program information.
[0010] In another possible implementation, the method also includes: Based on the parsing procedure information, insecure data in the link association information is determined; Based on the insecure data, determine the corresponding existing package name information; The corresponding software security warning is generated based on the package name information; The number of security alerts issued by the same software within a fixed time period is counted, and the alert frequency information is calculated based on the number of security alerts. Record the number of security alerts issued by the same software within the fixed time period and the frequency of the alerts to obtain security alert information; The security warning information is evaluated to obtain the security factor of the corresponding software within the fixed time period. The security warning information, the fixed time period, and the security factor are data-bound together to obtain a security report; The control displays the report.
[0011] In another possible implementation, the security alert information, the fixed time period, and the security factor are data-bound to obtain a security report, which then includes: The source network address of the insecure data is located and tracked, and a description of the problems caused by the insecure data, technical interpretation, and user solution guide are generated within the fixed time period. The report is automatically archived and saved according to the fixed time period, and a dynamic graph of the insecure data within the fixed time period is generated.
[0012] Secondly, this application provides a high-performance Iast external detection device, comprising: The information acquisition module is used to acquire link information, which includes link channel information and link point information. The link determination module is used to determine link insertion information and link acceptance information based on the link point information. The channel determination module is used to determine data channel information and data parsing information based on the link channel information; The association information module is used to associate and bind the link insertion information and the link acceptance information respectively to obtain link association information; The information screening module is used to screen the link association information to obtain application information; The parsing information module is used to parse the application information based on the data channel information and data parsing information to obtain parsing program information; The display information module is used to control the display of the parsing program information.
[0013] In another possible implementation, the apparatus further includes an application information acquisition module, an application information processing module, and a parameter information filling module, wherein, The application information acquisition module is used to acquire the application information transmitted by the data channel information, wherein the application information includes a single data packet composed of the parsed link association information; The application information processing module is used to process the application information based on the data parsing information to obtain fixed parameters of the application information; The parameter information filling module is used to fill the fixed parameters into a preset collection container within the data channel information.
[0014] In another possible implementation method, the device further includes a data classification module, a data disassembly module, a data extraction module, an import determination module, and a retention determination module, wherein, The data classification module is used to acquire first-level data packets and second-level data packets. The first-level data packet is the first data packet uploaded in the data packet, and the second-level data packet is the data packet in the data packet excluding the first-level data packet. The data disassembly module is used to disassemble the first-level data packet and the second-level data packet respectively to obtain first-level data corresponding to the first-level data packet and second-level data corresponding to the second-level data packet; The data extraction module is used to import the primary data into the collection container for key value extraction to obtain the data key values of the primary data. The import determination module is used to determine whether the secondary data can be imported into the collection container based on the data key values. The retention determination module is used to discard the secondary data if it cannot be imported into the collection container.
[0015] In another possible implementation method, the apparatus further includes a parameter determination module and a vulnerability rule module, wherein, The parameter determination module is used to determine whether the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters; The vulnerability rule module is used to generate vulnerability detection instructions and control the execution of preset vulnerability detection processes if the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters.
[0016] In another possible implementation method, the apparatus further includes a screening parameter module, a vulnerability identification module, a security judgment module, and a vulnerability identification module, wherein, The parameter screening module is used to screen whether the data filled in the collection container contains parameters that have been processed by a preset fixed acceptance function. The vulnerability identification module is used to identify a vulnerability in the parsing program information if the data filled in the collection container does not contain parameters processed by the fixed acceptor function. The security module is used to screen whether the data filled in the collection container contains data information that has been safely escaped if the data in the collection container contains parameters processed by the fixed acceptor function. The vulnerability identification module is used to identify a vulnerability in the parsing program information if the data filled in the collection container does not contain data information that has been securely escaped.
[0017] In another possible implementation, the apparatus further includes a data determination module, a packet name determination module, a security warning module, a frequency determination module, a security warning module, a security factor module, a security report module, and a report display module, wherein, The data determination module is used to determine insecure data in the link association information based on the parsing program information. The package name determination module is used to determine the corresponding existing package name information based on the insecure data; The security alert module is used to generate security alerts for the corresponding software based on the package name information; The frequency determination module is used to count the number of security alerts issued by the same software within a fixed time period, and to calculate the alert frequency information based on the number of security alerts. The security alert module is used to record the number of security alerts issued by the same software within the fixed time period and the alert frequency information to obtain security alert information; The security factor module is used to evaluate the security factor of the security warning information and obtain the security factor of the corresponding software within the fixed time period. The security report module is used to bind the security warning information, the fixed time period, and the security factor to obtain a security report; The report display module is used to control the display of the report.
[0018] In another possible implementation, the apparatus further includes a data generation module and a chart generation module, wherein, The data generation module is used to locate and track the source network address of the insecure data, and generate a description of the problems caused by the insecure data, technical interpretation, and user solution guide within the fixed time period. The chart generation module is used to automatically archive and save the report according to the fixed time period, and generate a dynamic chart about the insecure data within the fixed time period.
[0019] Thirdly, this application provides an electronic device that adopts the following technical solution: An electronic device comprising: At least one processor; Memory; At least one application, wherein the at least one application is stored in memory and configured to be executed by at least one processor, the at least one application being configured to: perform the above-described high-performance Iast external detection method.
[0020] Fourthly, a computer-readable storage medium is provided, the storage medium storing at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded and executed by a processor to implement a high-performance Iast external detection method as shown in any possible implementation of the first aspect.
[0021] In summary, this application includes the following beneficial technical effects: This application provides a high-performance IAST external detection method, apparatus, electronic device, and readable storage medium. Compared with related technologies, in this application, the link channel information and link point information are determined by the obtained link information. The link point information contains two parts of information that can be used for connection, namely link insertion information and link acceptance information. The link channel information contains two parts of information for data transmission and processing, namely data channel information and data parsing information.
[0022] The link insertion information is integrated into the link acceptance information, at which point the data channel information is activated and ready for use. Simultaneously, the link acceptance information begins collecting information from the user terminal to obtain link association information. Afterward, functions pre-set in the link point information are called to process the link association information into application information.
[0023] Application information is transmitted to the data parsing information via the initiated data channel. The data parsing information then checks the application information for required data to detect any security vulnerabilities in the user terminal data and generates parsing program information about the user terminal data. This establishes a complete external link for processing user terminal data, eliminating the computational burden previously incurred by terminal or server-side data processing, reducing memory usage on the user terminal, and effectively ensuring user data security. Attached Figure Description
[0024] Figure 1 This is a flowchart illustrating a high-performance Iast external detection method according to an embodiment of this application. Figure 2 This is a block diagram of a high-performance Iast external detection device according to an embodiment of this application; Figure 3 This is a schematic diagram of a high-performance Iast external detection electronic device according to an embodiment of this application. Detailed Implementation
[0025] The following is in conjunction with the appendix Figure 1 -Appendix Figure 3 This application will be described in further detail.
[0026] After reading this specification, those skilled in the art may make modifications to this embodiment without contributing any inventive step, but such modifications are protected by patent law as long as they fall within the scope of the claims of this application.
[0027] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0028] Furthermore, the term "and / or" in this document merely describes the relationship between related objects, indicating that three relationships can exist. For example, "a high-performance Iast external detection method, device, electronic device, and storage medium and / or B" can represent: the existence of a high-performance Iast external detection method, device, device, and medium alone; the simultaneous existence of a high-performance Iast external detection method, device, device, and medium and B; or the existence of B alone. Additionally, the character " / " in this document, unless otherwise specified, generally indicates that the related objects are in an "or" relationship.
[0029] The embodiments of this application will now be described in further detail with reference to the accompanying drawings.
[0030] This application provides a high-performance IAST external detection method executed by an electronic device, which can be a server or a terminal device. The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smartphone, tablet, laptop, desktop computer, etc., but is not limited to these. The terminal device and the server can be directly or indirectly connected via wired or wireless communication. This application does not impose any limitations on this connection. Figure 1 As shown, the method includes: Step A001: Obtain link information, which includes link channel information and link point information.
[0031] Step A002: Determine link insertion information and link acceptance information based on link point information.
[0032] Step A003: Determine the data channel information and data parsing information based on the link channel information.
[0033] Among them, link information includes link channel information and link point information; Link point information: link insertion information and link acceptance information; Link channel information: data channel information and data parsing information; Link insertion information: probe instrumentation information; Link connection information: hook instrumentation point information and instrumentation function information; Data channel information: External process channel information.
[0034] In the embodiments of this application, JVM technology is used to establish a probe instrumenter, JVM agent+asm technology is used to hook the instrumentation points of the classes and methods that need to be instrumented, instrumentation functions are established, and UnixDomainSocket socket communication technology is used to establish an external process channel (hereinafter referred to as unixsocket channel).
[0035] Step A004: Link insertion information and link acceptance information are associated and bound to obtain link association information.
[0036] Among them, the link association information is: hook point data.
[0037] In the embodiments of this application, the probe instrumenter is connected to the hook instrumentation point for data binding. At this time, the unixsocket channel starts up. When the data flows to the hook instrumentation point, the user terminal data is collected. The data collected at this time is the hook point data.
[0038] Step A005: Screen the link association information to obtain application information.
[0039] In this embodiment of the application, the screening process includes parsing the hook point data and extracting some parameters. Specifically, the hook point data is parsed by calling the instrumentation function, and the memory address of the args parameter and the stage parameters of the stage are extracted from the hook point data to obtain application information.
[0040] Step A006: Parse the application information based on the data channel information and data parsing information to obtain the parsing program information.
[0041] Step A007: Control the display of parsing program information.
[0042] In this embodiment of the application, application information is obtained through the Unix socket channel in step A005. This application information is then parsed based on the data parsing information to determine if it contains any security vulnerabilities, and parsing program information is generated. This parsing program information is then uploaded and displayed.
[0043] This application provides a high-performance IAST external detection method, which determines link channel information and link point information through the obtained link information. The link point information contains two parts of information that can be used for connection, namely link insertion information and link acceptance information; the link channel information contains two parts of information for data transmission and processing, namely data channel information and data parsing information.
[0044] The link insertion information is integrated into the link acceptance information, at which point the data channel information is activated and ready for use. Simultaneously, the link acceptance information begins collecting information from the user terminal to obtain link association information. Afterward, functions pre-set in the link point information are called to process the link association information into application information.
[0045] Application information is transmitted to the data parsing information via the initiated data channel. The data parsing information then checks the application information for required data to detect any security vulnerabilities in the user terminal data and generates parsing program information about the user terminal data. This establishes a complete external link for processing user terminal data, eliminating the computational burden previously incurred by terminal or server-side data processing, reducing memory usage on the user terminal, and effectively ensuring user data security.
[0046] In one possible implementation of this application embodiment, steps B001 (not shown in the figure), B002 (not shown in the figure), and B003 (not shown in the figure) are included before step A006, wherein, Step B001: Obtain the application information transmitted from the data channel information. The application information includes a single data packet composed of the link association information after parsing.
[0047] Step B002: Process the application information based on the data parsing information to obtain the fixed parameters of the application information.
[0048] Among them, the fixed parameters are: the memory address of args, the stage parameters of stage, and other parsed hook point data.
[0049] In the embodiments of this application, the instrumentation function packages the application information into a data packet and sends it to the unixsocket channel. The data packet is then transmitted to the data parsing information through the unixsocket channel.
[0050] Based on the data parsing information, extract the information from the data packet, find the memory address of args generated in step A005, the stage parameters of stage, and other parsed hook point data.
[0051] Step B003: Fill the fixed parameters into the preset collection container in the data channel information.
[0052] Among them, the pre-set collection container is the sludge pool.
[0053] In this embodiment of the application, the taint pool (i.e., hashmap, hereinafter referred to as hashmap) is filled according to the stage parameters of stage obtained in step B002 and the memory address of args.
[0054] Specifically, different methods can be used to construct the internal structure of a hashmap based on the arrangement of different parameters, such as numerical analysis, division and remainder method, and direct addressing method.
[0055] In one possible implementation of this application embodiment, steps B004 (not shown in the figure), B005 (not shown in the figure), B006 (not shown in the figure), B007 (not shown in the figure), and B008 (not shown in the figure) are included before step B003. Step B004: Obtain the first-level data packet and the second-level data packet. The first-level data packet is the first data packet uploaded in the data packet, and the second-level data packet is the data packet other than the first-level data packet.
[0056] Step B005: Disassemble the first-level data packet and the second-level data packet respectively to obtain the first-level data corresponding to the first-level data packet and the second-level data corresponding to the second-level data packet.
[0057] The first-level data packet is the data packet transmitted for the first time when application information is first processed and parsed. Secondary data packets: All data packets transmitted after the initial data packet used for parsing the data. In this embodiment of the application, the first-level data packet and the second-level data packet are disassembled to obtain the corresponding data in the data packet. At this time, the corresponding data are all parsed hook instrumentation point data.
[0058] Step B006: Import the primary data into a collection container to extract key values and obtain the primary data key values.
[0059] The key data values are hashkey and hashvalue.
[0060] The primary data obtained in step B005 is categorized, and primary hash keys and primary hash values are determined based on the primary data. The addresses of the first-level data in the hashmap (hereinafter referred to as hash addresses) are calculated, and the first-level data is evenly distributed across the hash address set. Import the first-level data into a hashmap, and extract the first-level hashkey and the first-level hashvalue.
[0061] Step B007: Determine whether secondary data can be imported into the collection container based on the key data values.
[0062] In this embodiment of the application, the secondary data obtained in step B005 is classified, and the secondary hashkey and secondary hashvalue are determined based on the secondary data.
[0063] Specifically, when determining the secondary hashkey and secondary hashvalue based on the secondary data, the secondary hashkey is defined as key 1, key 2, key 3... key n-1, key n, according to the order in which all secondary data packets arrive at the data parsing information in serial transport.
[0064] For example, when determining the secondary hash key based on the data obtained from the first data packet transmitted to the data parsing information within the secondary data packet, it is defined as the first secondary hash key (hereinafter referred to as key1). When determining the secondary hash key based on the data obtained from the second data packet transmitted to the data parsing information within the secondary data packet, it is defined as the second secondary hash key (hereinafter referred to as key2). When determining the secondary hash key based on the data obtained from the third data packet transmitted to the data parsing information within the secondary data packet, it is defined as the third secondary hash key (hereinafter referred to as key3). When determining the secondary hash key based on the data obtained from the nth data packet transmitted to the data parsing information within the secondary data packet, it is defined as the nth secondary hash key (hereinafter referred to as key n). The method for determining the secondary hash value based on the secondary data is the same as above, and will not be repeated in the embodiments of this application.
[0065] Extract the first-level hash key, first-level hash value, key1 from the second-level hash key, and value1 from the second-level hash value within the hashmap. If the value1 in the second-level hash value can be obtained by performing a pre-defined basic operation on the first-level hash value and the first-level hash key, then key1 in the second-level hash key is added to the hashmap. For example, if the first-level hash key is 'a', the first-level hash value is '1', the key1 in the second-level hash key is 'b', and the value1 in the second-level hash value is 'a+1', meaning the value1 in the second-level hash value equals the sum of the first-level hash value and the first-level hash value, then key1 'b' in the second-level hash key can be added to the hashmap.
[0066] Similarly, if key1 in the second-level hashkey is b, value1 in the second-level hashvalue is a+1, key2 in the second-level hashkey is c, and value2 in the second-level hashvalue is b+1, that is, value2 in the second-level hashvalue = key1 + value1, then key2 c in the second-level hashkey can be entered into the hashmap.
[0067] Once it is determined that a second-level hash key can be included in a hashmap, the hash address of the second-level data corresponding to the key is calculated, so that the second-level data corresponding to the key is evenly distributed in the hash address set, and the second-level data corresponding to the key is imported into the hashmap.
[0068] Specifically, when determining the secondary hashkey and secondary hashvalue based on the secondary data, the secondary hashkey is defined as key 1, key 2, key 3... key n-1, key n, according to the order in which all secondary data packets arrive at the data parsing information in serial transport.
[0069] For example, when determining the secondary hash key based on the data obtained from the first data packet transmitted to the data parsing information within the secondary data packet, it is defined as the first secondary hash key (hereinafter referred to as key1). When determining the secondary hash key based on the data obtained from the second data packet transmitted to the data parsing information within the secondary data packet, it is defined as the second secondary hash key (hereinafter referred to as key2). When determining the secondary hash key based on the data obtained from the third data packet transmitted to the data parsing information within the secondary data packet, it is defined as the third secondary hash key (hereinafter referred to as key3). When determining the secondary hash key based on the data obtained from the nth data packet transmitted to the data parsing information within the secondary data packet, it is defined as the nth secondary hash key (hereinafter referred to as key n). The method for determining the secondary hash value based on the secondary data is the same as above, and will not be repeated in the embodiments of this application.
[0070] Extract the first-level hash key, first-level hash value, key1 from the second-level hash key, and value1 from the second-level hash value within the hashmap. If the value1 in the second-level hash value can be obtained by performing a pre-defined basic operation on the first-level hash value and the first-level hash key, then key1 in the second-level hash key is added to the hashmap. For example, if the first-level hash key is 'a', the first-level hash value is '1', the key1 in the second-level hash key is 'b', and the value1 in the second-level hash value is 'a+1', meaning the value1 in the second-level hash value equals the sum of the first-level hash value and the first-level hash value, then key1 'b' in the second-level hash key can be added to the hashmap.
[0071] Similarly, if key1 in the second-level hashkey is b, value1 in the second-level hashvalue is a+1, key2 in the second-level hashkey is c, and value2 in the second-level hashvalue is b+1, that is, value2 in the second-level hashvalue = key1 + value1, then key2 c in the second-level hashkey can be entered into the hashmap.
[0072] Once it is determined that a second-level hash key can be included in a hashmap, the hash address of the second-level data corresponding to the key is calculated, so that the second-level data corresponding to the key is evenly distributed in the hash address set, and the second-level data corresponding to the key is imported into the hashmap.
[0073] Step B008: If the secondary data cannot be imported into the collection container, then discard the secondary data.
[0074] In this embodiment of the application, if the hashkey cannot be obtained by the calculation method in step B007, a new link node is generated, and then the data corresponding to the hashkey is discarded.
[0075] In one possible implementation of this application embodiment, step B003 is followed by steps B009 (not shown in the figure) and B010 (not shown in the figure), wherein... Step B009: Determine whether the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters.
[0076] The preset parameter is the final stage parameter of the stage.
[0077] In the embodiments of this application, if the parsed hook point data enters the hashmap, it is determined that there is a certain link at this time, triggering a detection of whether the data entering the hashmap is the final stage parameter of the stage.
[0078] Step B010: If the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters, then generate a vulnerability detection instruction and control the execution of the preset vulnerability detection process.
[0079] In the embodiments of this application, if the data entering the hashmap is detected to be the final stage parameter of the stage, then the vulnerability rule is triggered to determine the vulnerability type.
[0080] In one possible implementation of this application embodiment, step B010 further includes steps B011 (not shown in the figure), B012 (not shown in the figure), B013 (not shown in the figure), and B014 (not shown in the figure), wherein, Step B011: Screen whether the data filled in the collection container contains parameters that have been processed by the preset receiving function.
[0081] Step B012: If the data filled in the collection container does not contain parameters processed by the preset acceptor function, it is identified as a vulnerability in the parsing program information.
[0082] Among them, the preset receiving function is the function that performs the processing within the instrumentation function.
[0083] In this embodiment of the application, a preset instruction is executed according to the vulnerability rule triggered in step B010. For example, the vulnerability rule is to execute a command injection instruction or an SQL injection instruction.
[0084] The system uses preset instructions to determine whether the hashmap contains data that has been processed by a preset handler function. For example, command injection instructions determine whether the hook point data contains data processed by the runtime.exec handler, and SQL injection instructions determine whether it contains parameters processed by the sql.query handler.
[0085] If the judgment result is that the screened data does not contain data processed by the preset acceptance function, then the result is determined to be: there is a vulnerability.
[0086] Step B013: If the data filled in the collection container contains parameters processed by the acceptance function, then check whether the data filled in the collection container contains data information that has been safely escaped.
[0087] Step B014: If the data filled in the collection container does not contain data information that has been securely escaped, then the vulnerability is identified in the parsing program information.
[0088] For the embodiments of this application, if the determination result obtained in step B012 is: no vulnerability, then the data entering the hashmap in step B010 is screened to see if it contains parameters that have been security-escaped. If it does not contain them, the determination result is: a vulnerability exists.
[0089] Specifically, security functions are language or system-specific functions used by the terminal and are widely available in the market.
[0090] In one possible implementation of this application embodiment, after step A007, it further includes steps B015 (not shown in the figure), B016 (not shown in the figure), B017 (not shown in the figure), B018 (not shown in the figure), B019 (not shown in the figure), B020 (not shown in the figure), B021 (not shown in the figure), and B022 (not shown in the figure), wherein, Step B015: Determine insecure data in the link association information based on the parsing program information.
[0091] Step B016: Determine the corresponding existing package name information based on the insecure data.
[0092] In the embodiments of this application, when the determination result of step B014 or step B012 is that there is a vulnerability, the insecure data is locked, that is, the original data that the determination result of step B012 or step B014 is insecure is locked.
[0093] Data analysis is performed on the locked original data to find its source, i.e., tainted source data (hook data). For example, shadow memory technology can be used to mark the original data as tainted data, so that shadow memory generates a tainted source index that corresponds to the tainted data.
[0094] Locate the taint source data, determine new taints generated during the propagation of the taint source data based on the propagation relationship of the taint source data, and record the instructions executed in the process of determining new taints in order to determine whether the instructions involve the processing of the taint source data, so as to ensure the accuracy of the taint analysis results, such as preventing the possibility of misuse of instructions.
[0095] The obtained taint source data, new taint information, and instruction information are processed to generate an attack log.
[0096] The attack logs contain tainted source data, new tainted information, and command information. Tracing techniques include, but are not limited to, IP address localization, ID tracking, website URL analysis, and same-origin analysis. This allows the determination of the network address that outputs the tainted source data and the software that outputs it.
[0097] Step B017: Generate a security warning for the corresponding software based on the package name information.
[0098] Step B018: Count the number of security alerts for the same software within a fixed time period, and calculate the alert frequency information based on the number of security alerts.
[0099] Step B019: Record the number of security alerts and the frequency of alerts for the same software within a fixed time period to obtain security alert information.
[0100] Among them, safety warning information includes the number and frequency of safety warnings.
[0101] In this embodiment of the application, the security alert for the corresponding software is generated using the output software name obtained in step B016. The number of security alerts for a fixed software within a fixed time period is collected, and the frequency is determined by the number of alerts and the fixed time period. For example, the number of security alerts for software A generated within a week (7 times) is collected, and the generation frequency is (1 time / 24h).
[0102] Record the number and frequency of safety alerts received.
[0103] Step B020: Evaluate the security factor of the security warning information to obtain the security factor of the corresponding software within a fixed time period.
[0104] Step B021 involves binding the safety warning information, fixed time period, and safety factor to generate a safety report.
[0105] Step B022, control the display report.
[0106] In this embodiment of the application, the number and frequency of software security warnings in step B019 are obtained. The number and frequency of security warnings generated by different software are compared. If the number and frequency of software security warnings are in the top 50% of all software in the statistics, the security coefficient (the possibility of safe use) is determined to be 40. If the number and frequency of software security warnings are in the top 50% of all software in the statistics, the security coefficient is determined to be 80.
[0107] The safety factor, the fixed time period in step B019, the number of safety warnings, and the frequency are bound together to generate a safety report and display it.
[0108] In one possible implementation of this application embodiment, step B021 is followed by steps B023 (not shown in the figure) and B024 (not shown in the figure), wherein... Step B023 involves locating and tracing the source network address of the insecure data, and generating a description of the problems caused by the insecure data, technical explanations, and user solutions for a fixed time period.
[0109] In this embodiment of the application, the insecure data obtained in step B015 is reverse-tracked to obtain the insecure network address. This is then used to reverse-track the tainted source data, new tainted information, and instruction information in the attack log, employing techniques such as IP location tracking, ID tracking, website URL analysis, and same-origin analysis. This yields the network address that outputs the tainted source data and the output software.
[0110] Collect the package name information obtained in step B016 and compare the paths when tracing back to the same package name information. Summarize the reasons for the occurrence of insecure data in the same software and generate problem descriptions, technical interpretations and user solutions based on this.
[0111] For example, if the package name obtained from the analysis corresponds to software A, and the path similarity when tracing software A in reverse is high, indicating a phishing attack, then the problem that most likely caused the insecure data is a phishing email attack. In this case, the problem description generated is: high-frequency malicious email attack; the technical interpretation is: using disguised emails to trick users into entering critical information such as bank card numbers and payment passwords; the user solution guide is: find recently received emails requesting critical privacy information and selectively block the sender's account.
[0112] Step B024: Automatically archive and save the report according to a fixed time period, and generate a dynamic graph of insecure data within the fixed time period.
[0113] The animated graphic is a hazard information chart.
[0114] In this embodiment of the application, the security reports generated within the fixed time period in step B021 are categorized and saved according to the fixed time period. The total amount of danger information is obtained by summarizing the insecure data within the time period. The total amount of danger information in different time periods is used to generate a danger information chart to observe the current status of network security in order to better realize network detection.
[0115] For example, summarizing unsafe data for the first week of January 2000 yields a total of 1000 hazard information; summarizing unsafe data for the second week of January 2000 yields a total of 2000 hazard information; summarizing unsafe data for the third week of January 2000 yields a total of 3000 hazard information. A line graph is generated with time as the horizontal axis and the total number of hazard information as the vertical axis.
[0116] In summary, by establishing an external process that runs asynchronously with normal business operations, the computational burden on the terminal is reduced, the user experience is improved, and user data security is better protected.
[0117] The above embodiments describe a high-performance LIMIT external detection method from the perspective of method flow. The following embodiments describe a high-performance LIMIT external detection device from the perspective of virtual module or virtual unit. For details, please refer to the following embodiments.
[0118] This application provides a high-performance Iast external detection device, such as... Figure 2 As shown, the high-performance Iast external detection device 20 may specifically include: an information acquisition module 21, a link determination module 22, a channel determination module 23, an association information module 24, a screening information module 25, an information parsing module 26, and a display information module 27, wherein, Information acquisition module 21 is used to acquire link information, which includes link channel information and link point information; Link determination module 22 is used to determine link insertion information and link acceptance information based on link point information; Channel determination module 23 is used to determine data channel information and data parsing information based on link channel information; The association information module 24 is used to associate and bind the link insertion information and the link acceptance information respectively to obtain the link association information; The information screening module 25 is used to screen the link association information to obtain application information; The parsing information module 26 is used to parse the application information based on the data channel information and the data parsing information to obtain the parsing program information; The display information module 27 is used to control the display of parsing program information.
[0119] In one possible implementation of this application embodiment, the apparatus 20 further includes: an application information acquisition module, an application information processing module, and a parameter information filling module, wherein... The application information acquisition module is used to acquire application information transmitted from the data channel. The application information includes a single data packet composed of the link association information after parsing. The application information processing module is used to process application information based on data parsing information to obtain fixed parameters of the application information; The parameter information filling module is used to fill fixed parameters into a preset collection container within the data channel information.
[0120] In another possible implementation of this application embodiment, the apparatus 20 further includes: a data classification module, a data disassembly module, a data extraction module, an import determination module, and a retention determination module, wherein... The data classification module is used to obtain first-level data packets and second-level data packets. The first-level data packet is the first data packet uploaded in the data packet, and the second-level data packet is the data packet in the data packet excluding the first-level data packet. The data disassembly module is used to disassemble the primary data packets and the secondary data packets respectively, to obtain the primary data corresponding to the primary data packets and the secondary data corresponding to the secondary data packets; The data extraction module is used to import primary data into a collection container for key value extraction, thereby obtaining the key values of the primary data. The import module is used to determine whether secondary data can be imported into the collection container based on key data values. The retention module is used to discard secondary data if it cannot be imported into the collection container.
[0121] In another possible implementation of this application embodiment, the apparatus 20 further includes: a parameter determination module and a vulnerability rule module, wherein... The parameter determination module is used to determine whether the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters; The vulnerability rule module is used to generate vulnerability detection instructions and control the execution of preset vulnerability detection processes if the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters.
[0122] In another possible implementation of this application embodiment, the apparatus 20 further includes: a screening parameter module, a vulnerability identification module, a security judgment module, and a vulnerability identification module, wherein... The screening parameter module is used to screen whether the data filled in the collection container contains parameters that have been processed by a preset fixed acceptance function. The vulnerability identification module is used to identify a vulnerability in the parsed program information if the data filled in the collection container does not contain parameters processed by a fixed acceptor function. The security module is used to screen whether the data filled in the collection container contains data information that has been safely escaped if the data in the collection container contains parameters that have been processed by a fixed acceptor function. The vulnerability identification module is used to identify a vulnerability in the parsing program information if the data filled in the collection container does not contain data information that has been securely escaped.
[0123] In another possible implementation of this application embodiment, the device 20 further includes: a data determination module, a packet name determination module, a security warning module, a frequency determination module, a security warning module, a security factor module, a security report module, and a report display module, wherein... The data identification module is used to determine insecure data in the link association information based on the parsing program information. The package name determination module is used to determine the corresponding existing package name information based on insecure data; The security alert module is used to generate security alerts for the corresponding software based on package name information; The frequency determination module is used to count the number of security alerts issued by the same software within a fixed time period, and to calculate the alert frequency information based on the number of security alerts. The security alert module is used to record the number and frequency of security alerts issued by the same software within a fixed time period, and to obtain security alert information. The security factor module is used to evaluate the security factor of security warning information and obtain the security factor of the corresponding software within a fixed time period. The safety report module is used to bind safety warning information, fixed time periods, and safety levels to generate a safety report. The report display module is used to control the display of reports.
[0124] In another possible implementation of this application embodiment, the apparatus 20 further includes: a data generation module and a chart generation module, wherein... The data generation module is used to locate and track the source network address of insecure data, and generate descriptions of problems caused by insecure data, technical interpretations, and user solutions for a fixed time period. The chart generation module is used to automatically archive and save reports according to fixed time periods and generate dynamic charts about insecure data within those fixed time periods.
[0125] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0126] This application also describes an electronic device from the perspective of a physical device, such as... Figure 3 As shown, Figure 3 The illustrated electronic device 300 includes a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, for example, via a bus 302. Optionally, the electronic device 300 may also include a transceiver 304. It should be noted that in practical applications, the transceiver 304 is not limited to one type, and the structure of this electronic device 300 does not constitute a limitation on the embodiments of this application.
[0127] Processor 301 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 301 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0128] Bus 302 may include a pathway for transmitting information between the aforementioned components. Bus 302 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 302 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 3 The symbol is represented by only one line, but this does not mean that there is only one bus or one type of bus.
[0129] The memory 303 may be a ROM (Read Only Memory) or other type of static storage device capable of storing static information and instructions, RAM (Random Access Memory) or other type of dynamic storage device capable of storing information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0130] The memory 303 is used to store application code that executes the solution of this application, and its execution is controlled by the processor 301. The processor 301 is used to execute the application code stored in the memory 303 to implement the content shown in the foregoing method embodiments.
[0131] Among them, electronic devices include, but are not limited to: mobile terminals such as mobile phones, laptops, digital radio receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and in-vehicle terminals (such as in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers, and can also be servers, etc. Figure 3 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0132] This application provides a computer-readable storage medium storing a computer program that, when run on a computer, enables the computer to execute the corresponding content in the aforementioned method embodiments. In this application embodiment, link channel information and link point information are determined through the obtained link information. The link point information includes two parts of information that can be used for connection: link insertion information and link acceptance information. The link channel information includes two parts of information for data transmission and processing: data channel information and data parsing information.
[0133] The link insertion information is integrated into the link acceptance information, at which point the data channel information is activated and ready for use. Simultaneously, the link acceptance information begins collecting information from the user terminal to obtain link association information. Afterward, functions pre-set in the link point information are called to process the link association information into application information.
[0134] Application information is transmitted to the data parsing information via the initiated data channel. The data parsing information then checks the application information for required data to detect any security vulnerabilities in the user terminal data and generates parsing program information about the user terminal data. This establishes a complete external link for processing user terminal data, eliminating the computational burden previously incurred by terminal or server-side data processing, reducing memory usage on the user terminal, and effectively ensuring user data security.
[0135] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0136] The above are only some embodiments of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A high-performance Iast external detection method, characterized in that, This includes: obtaining link information, which includes link channel information and link point information; Based on the link point information, link insertion information and link acceptance information are determined; Based on the link channel information, data channel information and data parsing information are determined as external process channel information; the link insertion information and the link acceptance information are respectively associated and bound to obtain link association information; the link association information is screened to obtain application information; The application information is parsed using the external link corresponding to the data channel information and the data parsing information to obtain parsing program information. The parsing includes: screening whether the application information contains parameters processed by a preset fixed receiving function during the flow process. If the application information does not contain parameters processed by the preset fixed acceptor function, it is identified as having a vulnerability in the parsing program information; if the application information contains parameters processed by the preset fixed acceptor function, it is further screened to see if the application information contains data information that has been securely escaped; if the application information does not contain data information that has been securely escaped, it is identified as having a vulnerability in the parsing program information; and the parsing program information is controlled to be displayed.
2. The method according to claim 1, characterized in that, The step of parsing the application information based on the data channel information and data parsing information to obtain parsed program information further includes: obtaining the application information transmitted from the data channel information, wherein the application information includes a single data packet composed of the parsed link association information; processing the application information based on the data parsing information to obtain fixed parameters of the application information; and filling the fixed parameters into a preset collection container within the data channel information.
3. The method according to claim 2, characterized in that, Before filling the collection container with the fixed parameters, the process includes: obtaining a primary data packet and a secondary data packet, wherein the primary data packet is the first uploaded data packet in the data packet, and the secondary data packet is the data packet in the data packet excluding the primary data packet; disassembling the primary data packet and the secondary data packet respectively to obtain primary data corresponding to the primary data packet and secondary data corresponding to the secondary data packet; importing the primary data into the collection container for key value extraction to obtain the data key value of the primary data; determining whether the secondary data can be imported into the collection container based on the data key value; and discarding the secondary data if it cannot be imported into the collection container.
4. The method according to claim 3, characterized in that, The data channel information is filled with a preset collection container based on the fixed parameters. Then, the method further includes: determining whether the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters; if the data parameters corresponding to the first-level data packet and the second-level data packet contain preset parameters, a vulnerability detection instruction is generated to control the execution of the preset vulnerability detection process.
5. The method according to claim 4, characterized in that, The control executes a preset vulnerability detection process, including: screening whether the data filled in the collection container contains parameters processed by a preset fixed acceptor function; if the data filled in the collection container does not contain parameters processed by the fixed acceptor function, then it is identified as having a vulnerability in the parsing program information; if the data filled in the collection container contains parameters processed by the fixed acceptor function, then it screens whether the data filled in the collection container contains data information that has been securely escaped; if the data filled in the collection container does not contain data information that has been securely escaped, then it is identified as having a vulnerability in the parsing program information.
6. The method according to claim 1, characterized in that, Also includes: Based on the parsing procedure information, insecure data in the link association information is determined; Based on the insecure data, determine the corresponding existing package name information; The corresponding software security warning is generated based on the package name information; The number of security alerts for the same software within a fixed time period is counted, and the alert frequency information is calculated based on the number of security alerts; the number of security alerts for the same software within the fixed time period and the alert frequency information are recorded to obtain security alert information; The security warning information is evaluated to obtain the security factor of the corresponding software within the fixed time period; the security warning information, the fixed time period, and the security factor are data-bound to obtain a security report; the report is then displayed.
7. The method according to claim 6, characterized in that, The security alert information, the fixed time period, and the security coefficient are data-bound to obtain a security report. The report further includes: locating and tracing the source network address of the insecure data; generating a description of the problems caused by the insecure data within the fixed time period, a technical interpretation, and a user solution guide; automatically archiving and saving the report according to the fixed time period; and generating a dynamic graph of the insecure data within the fixed time period.
8. An external process detection device for improving the performance of Iast, characterized in that, include: The information acquisition module is used to acquire link information, which includes link channel information and link point information. The link determination module is used to determine link insertion information and link acceptance information based on the link point information. The channel determination module is used to determine data channel information and data parsing information, which serve as external process channel information, based on the link channel information. The association information module is used to associate and bind the link insertion information and the link acceptance information respectively to obtain link association information; The information screening module is used to screen the link association information to obtain application information; The parsing information module is used to parse the application information through the external link corresponding to the data channel information and the data parsing information to obtain parsing program information. The parsing includes: screening whether the application information contains parameters processed by a preset fixed acceptor function during the flow; if the application information does not contain parameters processed by the preset fixed acceptor function, it is identified as having a vulnerability in the parsed program information; if the application information contains parameters processed by the preset fixed acceptor function, it is further screened whether the application information contains data information that has been securely escaped; if the application information does not contain data information that has been securely escaped, it is identified as having a vulnerability in the parsed program information; the display information module is used to control the display of the parsed program information.
9. An electronic device, characterized in that, The electronic device includes: at least one processor; a memory; at least one application program, wherein the at least one application program is stored in the memory and configured to be executed by the at least one processor, the at least one application program being configured to: perform the high-performance Iast external detection method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed in the computer, the computer is instructed to perform the high-performance Iast external detection method according to any one of claims 1 to 7.