Detection Method, Device, Electronic Device and Storage Medium for Interface Attack
By establishing a user agent cluster information library and building access triples, the problems of high cost and low efficiency of interface attack detection are solved, and efficient and accurate interface attack detection and protection are achieved.
Patent Information
- Application Number
- CN202211678179.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-26
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-12-26
AI Technical Summary
The existing interface attack detection scheme is costly and inefficient, making it difficult to effectively identify and protect interface attacks.
By establishing a user agent cluster information library, obtaining the identity of the target user agent cluster based on access requests, building an access triple and detecting whether the request is an attack, realizing the detection of interface attacks.
Without relying on the JavaScript SDK, reduce access costs, improve the efficiency and accuracy of interface attack detection, and provide dynamic, comprehensive and continuous protection.
Smart Images

Figure CN116094772B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technologies, specifically to the fields of information flow, network security, artificial intelligence, machine learning, etc., and particularly relates to a method, device, electronic device, and storage medium for detecting interface attacks. Background Art
[0002] With the development of Internet technologies, more and more interfaces are exposed on the Internet, and various functions can be realized through the interfaces, such as registering an account, posting and replying to posts, sending instant messages, etc.
[0003] Legal interface access requests usually come from clients, such as applications (Apps) of browsers ios or Android, etc. Black production abuses legal clients to access interfaces, thereby achieving attacks. Summary of the Invention
[0004] The present disclosure provides a method, device, electronic device, and storage medium for detecting interface attacks.
[0005] According to one aspect of the present disclosure, there is provided a method for detecting interface attacks, including:
[0006] Obtaining an access request for an interface;
[0007] Based on the access request, obtaining an identifier of a target user agent cluster that matches from a pre-established user agent cluster information library;
[0008] Based on the identifier of the target user agent cluster and the access request, obtaining a plurality of access triples; each of the access triples includes the identifier of the target user agent cluster, key information in the header of the access request, and value information corresponding to the key information;
[0009] Based on the plurality of access triples, detecting whether the access request is an attack.
[0010] According to another aspect of the present disclosure, there is provided a device for detecting interface attacks, including:
[0011] A request obtaining module, configured to obtain an access request for an interface;
[0012] An identifier obtaining module, configured to obtain an identifier of a target user agent cluster that matches from a pre-established user agent cluster information library based on the access request;
[0013] A triple obtaining module, configured to obtain a plurality of access triples based on the identifier of the target user agent cluster and the access request; each of the access triples includes the identifier of the target user agent cluster, key information in the header of the access request, and value information corresponding to the key information;
[0014] A detection module, configured to detect whether the access request is an attack based on the multiple access triples.
[0015] According to another aspect of the present disclosure, there is provided an electronic device, including:
[0016] At least one processor; and
[0017] A memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the methods in the above-mentioned aspect and any possible implementation manners.
[0019] According to yet another aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, and the computer instructions are used to cause a computer to execute the methods in the above-mentioned aspect and any possible implementation manners.
[0020] According to still another aspect of the present disclosure, there is provided a computer program product, including a computer program, and when the computer program is executed by a processor, the methods in the above-mentioned aspect and any possible implementation manners are implemented.
[0021] According to the technology of the present disclosure, the detection efficiency of interface attacks can be effectively improved.
[0022] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:
[0024] Figure 1 is a schematic diagram according to the first embodiment of the present disclosure;
[0025] Figure 2 is a schematic diagram according to the second embodiment of the present disclosure;
[0026] Figure 3 is a schematic diagram according to the third embodiment of the present disclosure;
[0027] Figure 4 is a schematic diagram according to the fourth embodiment of the present disclosure;
[0028] Figure 5 is a block diagram of an electronic device for implementing the method of the embodiment of the present disclosure. DETAILED DESCRIPTION
[0029] The following is a description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, which include various details of the embodiments of the present disclosure to facilitate understanding, and should be considered as merely exemplary.
[0030] Those skilled in the art will appreciate that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Likewise, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0031] Obviously, the described embodiments are only part of the embodiments of the present disclosure, but not all of them. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present disclosure.
[0032] It should be noted that the terminal devices involved in the embodiments of the present disclosure may include but are not limited to
[0033] Smart devices such as mobile phones, personal digital assistants (PDA), wireless handheld devices, tablet computers, etc.; display devices may include but are not limited to personal computers, televisions, and other devices with display functions.
[0034] In addition, the term "and / or" in this article is only a description of the association relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, and
[0035] In A and B, there are three cases where B exists alone. In addition, the character " / " in this article generally indicates that the objects before and after are in an "or" relationship.
[0036] Traditional methods of identifying interface attacks usually require the use of a Token / Sign mechanism.
[0037] It is necessary to cooperate with the client's software development kit (SDK) and protect the Token / Sign output mechanism. Specifically, it requires a front-end SDK and a back-end interface
[0038] The interfaces must be accessed one by one, otherwise the interfaces cannot be protected; however, in general, there are dozens or even hundreds of interfaces on the backend, and it is difficult to access these interfaces one by one. Therefore, the existing interface attack detection solutions have high access costs and low interface attack detection efficiency.
[0039] Figure 1is a schematic diagram according to the first embodiment of the present disclosure; as Figure 1 shown, this embodiment provides a method for detecting interface attacks, which may specifically include the following steps:
[0040] S101. Obtain an access request for the interface;
[0041] The access request for the interface in this embodiment may be an access request sent by a browser, or an access request sent by various mobile applications (Application; APP), or an access request for any other type of interface.
[0042] S102. Based on the access request, obtain the identifier of the target UA cluster that matches from the pre-established user agent (User Agent; UA) cluster information library;
[0043] S103. Based on the identifier of the target UA cluster and the access request, obtain multiple access triples;
[0044] Each access triple includes the identifier of the target UA cluster, the key information of the header of the access request, and the value information corresponding to the key information.
[0045] S104. Based on multiple access triples, detect whether the access request is an attack.
[0046] The execution subject of the interface attack detection method in this embodiment is an interface attack detection device. This device can be deployed at the traffic entry position of the server to detect the access requests of all interfaces, identify the traffic belonging to interface attacks, and effectively block them to avoid the risks brought by attacks.
[0047] In this embodiment, the UA information in each access triple is the identifier of the target UA cluster, that is, it refers to the information of a class of UAs. Compared with a single UA, it contains more traffic. Therefore, it can avoid the situation where the traffic of a single UA is too small and the accuracy of interface attack detection is poor.
[0048] For the current access request, the number of access triples that can be obtained corresponds to the number of Keys included in its header Header.
[0049] In this embodiment, the pre-established UA cluster information library may include multiple UA clusters, each UA cluster corresponds to a UA cluster identifier, and each UA cluster may include at least two clustered UA information.
[0050] The detection method of interface attack in this embodiment can protect cloud interfaces without accessing the JavaScript (abbreviated as JS) SDK, effectively reducing the access cost and improving the detection efficiency of interface attacks. Moreover, the interface attack detection method in this embodiment can be applied to detect any attack on any interface, and has very strong dynamic protection performance for interface attack detection. It can detect interface attacks in a timely, accurate, comprehensive and continuous manner, identify risks, effectively improve the detection efficiency of interface attacks, and enhance the protection ability of interfaces.
[0051] Figure 2 is a schematic diagram according to the second embodiment of the present disclosure; as Figure 2 shown, this embodiment provides a detection method for interface attacks, which may specifically include the following steps:
[0052] S201. Obtain the access request of the interface;
[0053] S202. Obtain the UA information from the access request;
[0054] Specifically, the corresponding UA information is carried in the header of the access request, and it can be obtained.
[0055] S203. Based on each segment of the UA information, each segment of each clustered UA information in each UA cluster in the pre-established UA cluster information library, and the preset weight of each segment, calculate the edit distance between the UA information and each clustered UA information in each UA cluster respectively;
[0056] The UA cluster information library in this embodiment includes multiple UA clusters, and each UA cluster may include at least two clustered UA information. Each UA cluster corresponds to a UA cluster identifier. The edit distance between at least two clustered UA information in each UA cluster is less than the preset distance threshold.
[0057] In this embodiment, when calculating the edit distance between any two clustered UA information in the same UA cluster, the weights of each segment in the UA information need to be considered. Specifically, the UA may include multiple segments, and each segment identifies different information. When calculating the edit distance between two UAs, a preset weight is configured for each segment.
[0058] Assume that the UA may include n segments, and the preset weights of each segment can be respectively identified as Wn. In this way, the edit distance between two UAs can be expressed as: the edit distance between segment 1 of the two UAs * W1 + the edit distance between segment 2 of the two UAs * W2 +... + the edit distance between segment n of the two UAs * Wn.
[0059] Among them, the edit distance between two fragments of UA can be understood as the number of characters that need to be edited to make the two fragments of UA consistent.
[0060] For example, UA1 is: Mozilla / 5.0 (Windows NT 10.0; Win64; x64) AppleWebKit / 537.36 (KHTML, like Gecko) Chrome / 58.0.3029.110 Safari / 537.36; This UA1 can be divided into three fragments. The first fragment Mozilla / 5.0 (Windows NT 10.0; Win64; x64) represents the version information of the operating system. The second fragment AppleWebKit / 537.36 (KHTML, like Gecko) represents the version information of the engine. The third fragment Chrome / 58.0.3029.110 Safari / 537.36 represents the version information of the browser.
[0061] UA2 is: Mozilla / 5.0 (Windows NT 10.0; Win64; x64) AppleWebKit / 537.36 (KHTML, like Gecko) Chrome / 62.0.3143.10 Safari / 537.36; Similarly, this UA2 can be divided into three fragments. The first fragment Mozilla / 5.0 (Windows NT 10.0; Win64; x64) represents the version information of the operating system. The second fragment AppleWebKit / 537.36 (KHTML, like Gecko) represents the version information of the engine. The third fragment Chrome / 62.0.3143.10 Safari / 537.36 represents the version information of the browser.
[0062] According to the above calculation method, first, calculate the edit distance between the three fragments of UA1 and the corresponding fragments of UA2 respectively; The first fragment of UA1 is exactly the same as the first fragment of UA2, and the corresponding edit distance is 0. The second fragment of UA1 is also exactly the same as the second fragment of UA2, and the corresponding edit distance is also 0. The "58.0.3029.110" in the third fragment of UA1 is different from the "62.0.3143.10" in the third fragment of UA2, and the corresponding edit distance is 7. The preset weights of the three fragments are W1, W2, and W3 respectively; According to the above calculation formula for the edit distance between two UAs, the edit distance between the above UA1 and UA2 can be equal to 0*W1 + 0*W2 + 7*W3. Specifically, the preset weights W1, W2, and W3 of the three fragments can be configured according to experience or the importance of each fragment, etc.
[0063] In this embodiment, a preset distance threshold can also be configured based on experience. If the edit distance between two UAs is less than the preset distance threshold, it can be considered that these two UAs can be clustered into one UA cluster. For example, when the edit distance between the above-mentioned UA1 and UA2 is less than the preset distance threshold, they can be clustered into one UA cluster.
[0064] In the above manner, the UA information of all collected access requests can be clustered to establish a UA cluster information library. The UA cluster information library can include multiple UA clusters, and each UA cluster corresponds to a UA cluster identifier. Each UA cluster can include at least two clustered UA information.
[0065] For the UA information of the current access request, the edit distance between the current UA information and each clustered UA information in each UA cluster can be calculated according to the above calculation method of the edit distance.
[0066] S204. Obtain the edit distance between the UA information and the clustered UA information with the closest edit distance;
[0067] Specifically, based on the edit distance between the UA information and each clustered UA information in each UA cluster calculated above, the edit distance between the UA information and the clustered UA information with the closest edit distance can be obtained therefrom. Among them, the edit distance between the UA information and the clustered UA information with the closest edit distance is the minimum edit distance among the edit distances between the UA information and each clustered UA information in each UA cluster. That is to say, in this embodiment, the minimum edit distance is also referred to as the closest edit distance.
[0068] S205. Detect whether the edit distance is less than the preset distance threshold; if so, execute step S206; otherwise, when the edit distance is greater than or equal to the preset distance threshold, execute step S207;
[0069] In this embodiment, the preset distance threshold can be set according to experience.
[0070] S206. Obtain the identifier of the UA cluster corresponding to the clustered UA information with the closest edit distance to the UA information as the identifier of the target UA cluster; execute step S208;
[0071] At this time, through the above steps S202 - S206, the identifier of the target UA cluster with the closest edit distance to the UA information can be obtained from the UA cluster information library based on the UA information. Further, the UA information can be updated to the target UA cluster in the UA cluster information library. The identifier of the target UA cluster obtained in this way is very accurate.
[0072] S207. Determine that the UA information in the access request does not exist in the UA cluster information library. Temporarily consider this access request as normal traffic and just release it to end the process.
[0073] In this embodiment, the reason for clustering is that in the global traffic, due to the access requests of various mobile APPs, their UAs are significantly different from those of standard browsers. For example, OBUA UCBrowser / 8.6.0.199Mobile is a UA information of a non-standard browser. To accurately model this large number of non-standard UAs, it is necessary to expand the data source. By clustering UAs, similar UAs can be aggregated together; at the same time, the state space is greatly reduced. Otherwise, due to the small amount of traffic under each UA, no meaningful scores can be produced. In this embodiment, for UAs that do not exist in the cluster, they are also released as normal traffic to avoid detection errors. However, for UAs that do not exist in the cluster, the interface attack detection device needs to record the UA information and periodically detect whether there are clusters in these UAs. If there are, update them to the UA cluster information library.
[0074] S208. Based on the identifier of the target UA cluster and the access request, obtain multiple access triples. Each access triple includes the identifier of the target UA cluster, the Header Key, and the corresponding Header Value; then execute step S209.
[0075] S209. Detect whether there are pre-computed scores for each access triple; if there are, execute step S210; if not, execute step S214.
[0076] If there are no pre-computed scores for each access triple, it can indicate that the traffic of each access triple is small and does not reach the preset quantity threshold. At this time, the corresponding access request is temporarily regarded as normal traffic and released. In this embodiment, it can be assumed that as long as there is one access triple for which the score does not exist, that is, cannot be obtained, among the multiple access triples corresponding to the access request, the access request is considered as normal traffic.
[0077] Before this step S209, the following steps can also be included:
[0078] (a) Periodically obtain the access feature information of each access triple;
[0079] (b) Based on the access feature information of each access triple, use the pre-trained trusted scoring model to obtain the scores of each access triple.
[0080] For example, the access feature information of each access triple can include the traffic, IP, and access feature information in the historical behavior dimension of each access triple.
[0081] Specifically, for each access triple, obtain the following access feature information within a preset time length before the current moment: the number of access requests initiated based on this access triple, the number of normal access requests initiated based on this access triple, the number of malicious attacks initiated based on this access triple, the number of access requests corresponding to risky IPs among the access requests initiated based on this access triple, as well as the number of IPs corresponding to the access requests initiated based on this access triple, the number of access requests with browser risks among the access requests initiated based on this access triple, the number of users corresponding to the access requests initiated based on this access triple, and the number of risky users among the access requests initiated based on this access triple, at least one of them.
[0082] For example, within the preset time length, the more the number of normal access requests initiated based on this access triple, and the fewer the number of malicious attacks, it indicates that this access triple is more trustworthy. The more the number of access requests corresponding to risky IPs among the access requests initiated based on this access triple, it indicates that this access triple is less trustworthy. The fewer the number of IPs corresponding to the access requests based on this access triple, it indicates that the possibility of malicious attacks is greater, and this access triple is less trustworthy. The more the number of access requests with browser risks among the access requests initiated based on this access triple, it indicates that this access triple is less trustworthy. The more the number of users corresponding to the access requests initiated based on this access triple, it indicates that this access triple is more trustworthy; on the contrary, the fewer the number of users corresponding to the access requests initiated based on this access triple, it indicates that the possibility of malicious attacks is greater, and this access triple is less trustworthy. The more the number of risky users among the access requests initiated based on this access triple, it indicates that this access triple is less trustworthy.
[0083] The above access feature information is partial feature information of the traffic, IP, and historical behavior dimensions of the access triple. In practical applications, more and richer access feature information can also be obtained, and no more examples will be given here.
[0084] The preset time length in this embodiment can be 1 hour, 2 hours, or other time lengths. In practical applications, in order to obtain more accurate, comprehensive, and rich feature information of the access triple, the above feature information within multiple different preset time lengths before the current moment can be obtained simultaneously to more accurately obtain the scores of each access triple. Then, input the access feature information of each access triple into the trusted scoring model, and this trusted scoring model can predict and output the corresponding score.
[0085] If the score predicted by the trusted scoring model is closer to 0, it indicates that this access triple is more trustworthy. And the higher the output score, it indicates that this access triple is less trustworthy.
[0086] In this embodiment, since the UA clusters of each access triple may cluster a relatively large amount of traffic, it is necessary to periodically use a trust scoring model in advance to obtain the scores of each access triple, so as to improve the efficiency of interface attack detection.
[0087] The periodic duration of this embodiment can be set according to the characteristics of the access traffic of the interface. For example, it can be once a day, or once every few hours, or other periodic durations, which are not limited here.
[0088] Of course, optionally, after receiving an access request, a trust scoring model can also be used to calculate the scores of each access triple online. Compared with the above-mentioned pre-calculation in advance periodically, it will cause the interface attack detection to be time-consuming.
[0089] It should be noted that in the technical solution of this embodiment, since the UA cluster identifier in the access triple is the clustered UA cluster information, the corresponding access triple feature information may include a relatively rich number of features and a large amount of content. If the scores of each access triple are calculated online in real time, it will be time-consuming. Therefore, in this embodiment, the scores of each access triple are pre-calculated periodically. Among them, the access triples also need to be statistically obtained periodically in advance. For example, all access requests within a periodic period can be statistically counted periodically, and all corresponding access triples can be obtained. And analyze whether the number of accesses corresponding to each access triple reaches a preset number threshold. If not, the scores of the corresponding access triples may not be pre-calculated and obtained.
[0090] For example, for an access triple, the number of access requests is only 1, 2, or a single-digit number, which is not enough to obtain an accurate score for this access triple. At this time, the score of this access triple may not be pre-calculated. Wait until the number of access requests corresponding to this access triple reaches the preset number threshold before calculating. For the above reasons, there are no scores for some access triples that are pre-calculated.
[0091] S210. Obtain the scores of each pre-calculated access triple; execute step S211;
[0092] S211. Detect whether there is a score greater than the preset score threshold among the scores of each access triple in multiple access triples. If so, execute step S212; if not, execute step S214;
[0093] S212. Determine that the access request is an attack; execute step S213;
[0094] S213. Intercept the access request and end.
[0095] S214. Determine that the access request is normal traffic and just let it go, then end.
[0096] In this embodiment, among the scores of multiple access triples corresponding to an access request, if the score of any one access triple is greater than a preset score threshold, then it is considered that this access triple is untrustworthy, and correspondingly, it can be considered that this access request is an attack. Otherwise, when the scores of all access triples corresponding to the access request are less than or equal to the preset score threshold, it is considered that this access request is a normal access request, that is, this access request is a normal traffic.
[0097] In this embodiment, the detection method for detecting whether an access request is an attack based on the scores of each access triple is very accurate and efficient.
[0098] In this embodiment, the trusted score model is trained using trusted access request data during training. For example, the training of this trusted score model may specifically include the following steps:
[0099] (1) Obtain multiple trusted access requests;
[0100] For example, multiple trusted access requests can be sent to the security cloud by controlling the JS SDK; and multiple trusted access requests can be obtained from the security cloud; and / or
[0101] Based on an automated test suite, all known secure browser lists can be collected. For example, it can include browsers such as all versions of Chrome and Firefox. Then, the browsers in the known secure browser list are controlled to initiate HTTP access requests to the security cloud, and these access requests are also trusted access requests. Correspondingly, the security cloud can receive multiple trusted access requests; and then multiple trusted access requests can be obtained from the security cloud.
[0102] Alternatively, in practical applications, multiple original access requests can also be obtained; and multiple trusted access requests are screened out from the multiple original access requests according to a preset screening policy for trusted access requests.
[0103] The multiple original access requests in this implementation method can be the real access traffic received by the backend server. However, some of these access traffic are normal and trusted access requests of users; while some may be malicious attacks. Therefore, it is necessary to screen out multiple trusted access requests from the multiple original access requests according to a preset screening policy for trusted access requests.
[0104] For example, the preset trusted access request filtering policy can be based on the policy statistically calculated from the user's normal historical access requests. For example, it can include at least one of the following: the UA is from a legitimate browser, the value of the Key is reasonable, the order of the Keys is reasonable, and the value of the Value is reasonable. For example, the Key in the header of a trusted access request of a browser should include the content type "Content-Type". The trusted access request of the IE browser should not include the cross-origin access permission identifier "Access-Control-Allow-Origin". For the IE browser, the Coding type value of "Accept-Encoding" in its trusted access request should not include "br".
[0105] (2) Based on each trusted access request, obtain the corresponding multiple access triples;
[0106] For each trusted access request, the UA information of the trusted access request can be obtained first, and then the target UA cluster identifier matching the UA information can be obtained from the UA cluster information library. For details, reference can be made to the method in the above embodiment, which will not be elaborated here.
[0107] Then, based on the UA cluster identifier corresponding to each trusted access request, obtain the multiple access triples corresponding to each trusted access request. Correspondingly, for each trusted access request, multiple access triples can be obtained. Each access triple includes a UA cluster identifier, a Header Key, and a Header Value.
[0108] (3) Obtain the access feature information of each access triple; and configure the trusted label of each access triple to 0; that is, the score is 0;
[0109] In this embodiment, the method for obtaining the access feature information of each access triple refers to the description in the above embodiment, which will not be elaborated here.
[0110] In this embodiment, configuring the trusted label of each access triple to 0 means configuring the score of each access triple to 0. The scoring rule of this embodiment requires that the lower the score of the access triple, that is, the closer it is to 0, the more trustworthy the access triple is; on the contrary, if the score of the access triple is higher, that is, the farther it is from 0, the less trustworthy the access triple is.
[0111] (4) Based on the feature information and trusted label of each access triple, train the trusted scoring model.
[0112] In this embodiment, the feature information of all access triples corresponding to multiple trusted access requests and the corresponding trusted labels are selected to train the trusted scoring model. Since the access requests are trusted access requests, the corresponding access triples are also all trusted access triples, and the corresponding trusted label scores are all 0. It can be understood that in this embodiment, the training data for training the trusted scoring model are all positive sample data. Through this training, the trusted scoring model can learn the ability to score access triples based on the access feature information of the access triples.
[0113] When the trained trusted scoring model is in use, the lower the score of an access triple, the more trusted the access triple is, while the higher the score of an access triple, the more
[0114] untrusted the access triple is. Specifically, it can be used in combination with a preset scoring threshold. For example, if the score of the trusted scoring model for an access triple is less than or equal to the preset scoring threshold, it can be determined that the access triple is trusted; while if the score of the trusted scoring model for an access triple is greater than the preset scoring threshold, it can be determined that the access triple is untrusted.
[0115] For example, during training, the feature information of each access triple is input into the trusted scoring
[0116] model. The trusted scoring model predicts a score based on the input information. And based on the score value 0 of the trusted label and the predicted score, the parameters of the trusted scoring model are adjusted to make the predicted score of the trusted scoring model tend to be close to the score value of the trusted label. Using the access feature information of multiple access triples of multiple trusted access requests and the corresponding trusted labels, the trusted scoring model is continuously trained in the above manner, which can make the model converge to obtain the trusted scoring model.
[0117] The interface attack detection method of this embodiment can dynamically detect interface attacks and intercept the access request in time when it detects that the access request is an attack. The technical solution of this embodiment can be applied to detect any type of access request for any type of interface. The dynamic protection performance of interface attack
[0118] detection is very strong, and it can detect interface attacks in a timely, accurate, comprehensive and continuous manner, effectively improving the detection efficiency of interface attacks and enhancing the protection ability of the interface.
[0119] The interface attack detection method of this embodiment is deployed at the backend of the access party when in application. During detection, all traffic enters the backend of the access party. By using the interface attack detection method of this embodiment, all incoming traffic can be detected, and when the traffic is an interface attack, it can be intercepted
[0120]
[0121] Intercept. This solution can protect the cloud interface without accessing the JS SDK, and can implement security protection for various interfaces to prevent the interfaces from being attacked by risks.
[0122] Figure 3 is a schematic diagram according to the third embodiment of the present disclosure; as Figure 3 shown, this embodiment provides a detection device 300 for interface attacks, including:
[0123] A request acquisition module 301, configured to acquire an access request for an interface;
[0124] An identifier acquisition module 302, configured to acquire an identifier of a target user agent cluster that matches from a pre-established user agent cluster information library based on the access request;
[0125] A triple acquisition module 303, configured to acquire a plurality of access triples based on the identifier of the target user agent cluster and the access request; each of the access triples includes the identifier of the target user agent cluster, the key information of the header of the access request, and the value information corresponding to the key information;
[0126] A detection module 304, configured to detect whether the access request is an attack based on the plurality of access triples.
[0127] For the detection device 300 for interface attacks in this embodiment, the implementation principle and technical effects of implementing the detection of interface attacks by adopting the above modules are the same as those of the above-related method embodiments. For details, reference can be made to the records of the above-related method embodiments, and details are not described herein again.
[0128] Figure 4 is a schematic diagram according to the fourth embodiment of the present disclosure; as Figure 4 shown, this embodiment provides a detection device 400 for interface attacks, including the above Figure 3 shown modules with the same name and function: a request acquisition module 401, an identifier acquisition module 402, a triple acquisition module 403, and a detection module 404.
[0129] In this embodiment, the identifier acquisition module 402 is configured to:
[0130] Acquire user agent information from the access request;
[0131] Based on the user agent information, acquire the identifier of the target user agent cluster that has the closest edit distance to the user agent information from the user agent cluster information library.
[0132] In an embodiment of the present disclosure, the identifier acquisition module 402 is configured to:
[0133] Based on each segment of the user agent information and the clustered user agent information in each user agent cluster in the user agent cluster information library, and the preset weights of each segment, calculate the edit distance between the user agent information and the clustered user agent information in each user agent cluster respectively;
[0134] Obtain the identifier of the user agent cluster corresponding to the clustered user agent information with the closest edit distance to the user agent information as the identifier of the target user agent cluster.
[0135] As Figure 4 shown, in an embodiment of the present disclosure, the interface attack detection device 400 further includes:
[0136] A determination module 405, configured to determine that the edit distance between the user agent information and the clustered user agent information with the closest edit distance is less than a preset distance threshold.
[0137] In an embodiment of the present disclosure, the detection module 404 is further configured to:
[0138] If the edit distance between the user agent information and the clustered user agent information with the closest edit distance is greater than or equal to the preset distance threshold, determine that the access request is normal traffic.
[0139] In an embodiment of the present disclosure, the detection module 404 is configured to:
[0140] Obtain the scores of each of the access triples calculated in advance;
[0141] If there is a score greater than a preset score threshold among the scores of each of the access triples in the multiple access triples, determine that the access request is an attack.
[0142] In an embodiment of the present disclosure, the detection module 404 is configured to:
[0143] If the scores of each of the access triples are not obtained, or the scores of each of the access triples obtained are all less than the preset score threshold, determine that the access request is normal traffic.
[0144] As Figure 4 shown, in an embodiment of the present disclosure, the interface attack detection device 400 further includes:
[0145] A feature acquisition module 406, configured to periodically acquire the access feature information of each of the access triples;
[0146] A scoring module 407, configured to obtain scores for each of the access triples based on the access feature information of each of the access triples by using a pre-trained trusted scoring model.
[0147] As Figure 4 shown, in an embodiment of the present disclosure, the interface attack detection device 400 further includes:
[0148] An interception module 408, configured to intercept the access request if the access request is an attack.
[0149] For the interface attack detection device 400 in this embodiment, the implementation principle and technical effects of detecting interface attacks by using the above modules are the same as those of the above related method embodiments. For details, reference can be made to the records of the above related method embodiments and will not be elaborated here.
[0150] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0151] Figure 5 FIG. shows a schematic block diagram of an exemplary electronic device 500 that can be used to implement embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0152] As Figure 5 shown, the device 500 includes a computing unit 501, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 502 or a computer program loaded from a storage unit 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the device 500 can also be stored. The computing unit 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0153] Multiple components in device 500 are connected to I / O interface 505, including: an input unit 506, such as a keyboard, a mouse, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a disk, an optical disc, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0154] The computing unit 501 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 501 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 501 executes the various methods and processes described above, such as the above-mentioned methods of the present disclosure. For example, in some embodiments, the above-mentioned methods of the present disclosure can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the computing unit 501, one or more steps of the above-mentioned methods of the present disclosure described above can be executed. Alternatively, in other embodiments, the computing unit 501 can be configured to execute the above-mentioned methods of the present disclosure in any other suitable manner (e.g., by means of firmware).
[0155] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0156] The program code for implementing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, a special purpose computer, or other programmable data processing device, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code may execute entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.
[0157] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0158] In order to provide interaction with a user, the systems and techniques described herein may be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0159] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0160] A computer system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, a server of a distributed system, or a server incorporating blockchain.
[0161] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps recited in the present disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in the present disclosure can be achieved, and this is not limited herein.
[0162] The above specific embodiments do not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. A detection method for interface attacks, comprising: Obtaining an access request for an interface; Based on the access request, obtaining the identifier of a target user agent cluster that matches from a pre-established user agent cluster information library; Based on the identifier of the target user agent cluster and the access request, obtaining a plurality of access triples; each of the access triples includes the identifier of the target user agent cluster, the key information of the header of the access request, and the value information corresponding to the key information; Based on the plurality of access triples, detecting whether the access request is an attack; Based on the plurality of access triples, detecting whether the access request is an attack, including: Obtaining the scores of each of the access triples that have been pre-computed; If there is a score greater than a preset score threshold among the scores of each of the access triples in the plurality of access triples, determining that the access request is an attack.
2. The method according to claim 1, wherein Based on the access request, obtaining the identifier of a target user agent cluster that matches from a pre-established user agent cluster information library, including: Obtaining user agent information from the access request; Based on the user agent information, obtaining the identifier of the target user agent cluster that has the closest edit distance to the user agent information from the user agent cluster information library.
3. The method according to claim 2, wherein Based on the user agent information, obtaining the identifier of the target user agent cluster that has the closest edit distance to the user agent information from the user agent cluster information library, including: Based on the user agent information, each segment of the clustered user agent information in each user agent cluster in the user agent cluster information library, and the preset weight of each segment, respectively calculating the edit distance between the user agent information and the clustered user agent information in each user agent cluster; Obtaining the identifier of the user agent cluster corresponding to the clustered user agent information that has the closest edit distance to the user agent information as the identifier of the target user agent cluster.
4. The method according to claim 3, wherein, Before obtaining the identifier of the user agent cluster corresponding to the clustered user agent information that has the closest edit distance to the user agent information as the identifier of the target user agent cluster, the method further includes: Determining that the edit distance between the user agent information and the clustered user agent information with the closest edit distance is less than a preset distance threshold.
5. The method according to claim 4, wherein The method further includes: If the edit distance between the user agent information and the clustered user agent information with the closest edit distance is greater than or equal to the preset distance threshold, determining that the access request is normal traffic.
6. The method according to claim 1, wherein Based on the plurality of access triples, detecting whether the access request is an attack, further includes: If the scores of each of the access triples are not obtained, or the scores of each of the access triples obtained are all less than the preset score threshold, determining that the access request is normal traffic.
7. The method according to claim 1, wherein, Before obtaining the scores of each of the access triples that have been pre-computed, the method further includes: Periodically obtaining the access feature information of each of the access triples; Based on the access feature information of each of the access triples, using a pre-trained trusted scoring model to obtain the scores of each of the access triples.
8. According to the method as claimed in any one of claims 1-7, wherein, After detecting whether the access request is an attack based on the multiple access triples, the method further includes: If the access request is an attack, intercept the access request.
9. A detection device for interface attacks, comprising: A request acquisition module, configured to acquire an access request for an interface; An identifier acquisition module, configured to acquire an identifier of a target user agent cluster that matches from a pre-established user agent cluster information library based on the access request; A triple acquisition module, configured to acquire multiple access triples based on the identifier of the target user agent cluster and the access request; each of the access triples includes the identifier of the target user agent cluster, key information in the header of the access request, and value information corresponding to the key information; A detection module, configured to detect whether the access request is an attack based on the multiple access triples; The detection module is configured to: Acquire scores of each of the access triples calculated in advance; If there is a score greater than a preset score threshold among the scores of each of the access triples in the multiple access triples, determine that the access request is an attack.
10. The apparatus according to claim 9, wherein, The identifier acquisition module is configured to: Acquire user agent information from the access request; Based on the user agent information, acquire the identifier of the target user agent cluster that has the closest edit distance to the user agent information from the user agent cluster information library.
11. The apparatus according to claim 10, wherein, The identifier acquisition module is configured to: Based on the user agent information, each segment of each clustered user agent information in each user agent cluster in the user agent cluster information library, and preset weights of each segment, respectively calculate the edit distance between the user agent information and each clustered user agent information in each user agent cluster; Acquire the identifier of the user agent cluster corresponding to the clustered user agent information with the closest edit distance to the user agent information as the identifier of the target user agent cluster.
12. The device according to claim 11, wherein, The device further includes: A determination module, configured to determine that the edit distance between the user agent information and the clustered user agent information with the closest edit distance is less than a preset distance threshold.
13. The device according to claim 12, wherein The detection module is further configured to: If the edit distance between the user agent information and the clustered user agent information with the closest edit distance is greater than or equal to the preset distance threshold, determine that the access request is normal traffic.
14. The device according to claim 9, wherein The detection module is configured to: If scores of each of the access triples are not acquired, or the scores of each of the access triples acquired are all less than the preset score threshold, determine that the access request is normal traffic.
15. The device according to claim 9, wherein, The device further includes: A feature acquisition module, configured to periodically acquire access feature information of each of the access triples; A scoring module, configured to acquire scores of each of the access triples by using a pre-trained trusted scoring model based on the access feature information of each of the access triples.
16. The device according to any one of claims 9-15, wherein, The device further includes: An interception module, configured to intercept the access request if the access request is an attack.
17. An electronic device, comprising: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 1-8.
18. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are for causing the computer to execute the method according to any one of claims 1-8.
19. A computer program product, comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1-8.
Citation Information
Patent Citations
Abnormal access request screening method and device
CN110457626A
Website attack detection and protection method and system
US20190207973A1