Attack Detection Method, Device, Electronic Device and Storage Medium

By detecting whether the user agent of the access request carries the unique attribute information of the specified activity, the problem of weak generalization ability of legitimacy verification rules in the prior art is solved, and the accuracy and efficiency of attack detection are improved.

CN116112245BActive Publication Date: 2025-06-17BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310063832.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-12
Publication Date
2025-06-17
Estimated Expiration
2043-01-12

AI Technical Summary

Technical Problem

When detecting off-end attacks, the legitimacy verification rules have weak generalization ability and cannot cover all access requests of black industries, resulting in low detection efficiency.

Method used

By obtaining access requests for the specified activity, it detects whether the user agent carries the pre-mined specific attribute information of the specified activity. If not carried, determine that the access request is an attack.

Benefits of technology

Improves the accuracy and detection efficiency of attack detection for specified activities, and can effectively identify and intercept malicious attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116112245B_ABST
    Figure CN116112245B_ABST
Patent Text Reader

Abstract

The present disclosure provides an attack detection method, apparatus, electronic device, and storage medium, which relate to technical fields such as information flow and network security. The specific implementation solution is as follows: obtaining an access request for a specified activity; detecting whether the user agent of the access request carries specific attribute information of the specified activity mined in advance, where the specific attribute information of the specified activity is the attribute information commonly carried in all normal access requests of the specified activity; if not carried, determining that the access request is an attack. The technology of the present disclosure can effectively improve the accuracy and detection efficiency of attack detection for the specified activity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technologies, and particularly to the fields of information flow, network security, etc. In particular, it relates to an attack detection method, device, electronic device, and storage medium. Background Art

[0002] The off-site attack is an important way for the black industry to participate in marketing activities.

[0003] The black industry launches an attack on the activity interface by forging parameters in the access request to achieve an off-site attack. The user agent (UA) of the browser is one of the important parameters in the access request. The UA of the browser can contain a lot of key information, such as the version information of the operating system, the version information of the rendering engine, and the version information of the browser, etc. Summary of the Invention

[0004] The present disclosure provides an attack detection method, device, electronic device, and storage medium.

[0005] According to one aspect of the present disclosure, there is provided a method for detecting an attack, including:

[0006] Obtaining an access request for a specified activity;

[0007] Detecting whether the user agent of the access request carries the unique attribute information of the specified activity mined in advance; the unique attribute information of the specified activity is the attribute information commonly carried in all normal access requests of the specified activity;

[0008] If not carried, determining that the access request is an attack.

[0009] According to another aspect of the present disclosure, there is provided an attack detection device, including:

[0010] A first obtaining module, configured to obtain an access request for a specified activity;

[0011] A detection module, configured to detect and determine that the user agent of the access request does not carry the unique attribute information of the specified activity mined in advance; the unique attribute information of the specified activity is the attribute information commonly carried in all normal access requests of the specified activity;

[0012] A determination module, configured to determine that the access request is an attack.

[0013] According to still another aspect of the present disclosure, there is provided an electronic device, including:

[0014] At least one processor; and

[0015] A memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the methods of the aspects and any possible implementation manners as described above.

[0017] According to another aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the methods of the aspects and any possible implementation manners as described above.

[0018] According to still another aspect of the present disclosure, there is provided a computer program product including a computer program which, when executed by a processor, implements the methods of the aspects and any possible implementation manners as described above.

[0019] According to the technology of the present disclosure, the accuracy and detection efficiency of attack detection for a specified activity can be effectively improved. It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:

[0021] Figure 1 is a schematic diagram according to the first embodiment of the present disclosure;

[0022] Figure 2 is a schematic diagram according to the second embodiment of the present disclosure;

[0023] Figure 3 is a schematic diagram according to the third embodiment of the present disclosure;

[0024] Figure 4 is a schematic diagram according to the fourth embodiment of the present disclosure;

[0025] Figure 5 is a schematic diagram according to the fifth embodiment of the present disclosure;

[0026] Figure 6 is a block diagram of an electronic device for implementing the method of the embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, descriptions of well-known functions and structures are omitted in the following description for clarity and conciseness.

[0028] Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts fall within the scope of protection of the present disclosure.

[0029] It should be noted that the terminal devices involved in the embodiments of the present disclosure may include, but are not limited to, intelligent devices such as mobile phones, personal digital assistants (PDAs), wireless handheld devices, and tablet computers; the display devices may include, but are not limited to, devices with display functions such as personal computers and televisions.

[0030] In addition, the term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the preceding and following associated objects.

[0031] Generally, the legitimacy of the UA in the access request can be verified to detect whether the access request is a normal access or an attack by black production. In the prior art, the rules for legitimacy verification can be preset based on historical access requests. However, the generalization ability of the legitimacy verification rules is weak and cannot cover all access requests of black production, resulting in low detection efficiency of the existing attack detection methods.

[0032] Figure 1 is a schematic diagram according to the first embodiment of the present disclosure; as Figure 1 shown, this embodiment provides an attack detection method, which may specifically include the following steps:

[0033] S101. Obtain the access request for a specified activity;

[0034] S102. Detect whether the specific attribute information of the specified activity pre-mined is carried in the UA of the access request;

[0035] S103. If not carried, determine that the access request is an attack.

[0036] The attack detection method of this embodiment can be applied on the server side. By deploying an attack detection device, it can detect access requests for a specified activity to determine whether an access request for the specified activity is an attack.

[0037] That is to say, the attack detection method of this embodiment is not applicable to all access requests in general, but only to access requests for a specified activity. For multiple different activities, it is necessary to deploy the attack detection method for each activity and detect the access requests for the corresponding activity respectively.

[0038] In this embodiment, the unique attribute information of the specified activity in the UA can be mined in advance, and based on the unique attribute information of the specified activity in the UA, the attack detection method for the specified activity can be deployed. The unique attribute information of the specified activity can be regarded as the attribute information jointly carried by all normal access requests of the specified activity mined in advance. Specifically, obtain the access request for the entrance of the specified activity. The access request for the entrance of the specified activity must be an access request for the specified activity. Then, detect whether the UA of the access request carries the unique attribute information of the specified activity mined in advance. If not, it can be determined that the access request is not a normal access request for the specified activity, but an attack.

[0039] The attack detection method of this embodiment determines that an access request is an attack by detecting whether the UA of the access request for the specified activity carries the unique attribute information of the specified activity. Since the unique attribute information of the specified activity is the attribute information jointly carried by all normal access requests of the specified activity, the attack detection method of this embodiment can accurately and effectively detect all access requests for the specified activity, effectively improving the accuracy and detection efficiency of attack detection for access requests of the specified activity.

[0040] Figure 2 It is a schematic diagram according to the second embodiment of the present disclosure; as Figure 2 shown, this embodiment provides an attack detection method, which specifically may include the following steps:

[0041] S201. Obtain an access request for the specified activity;

[0042] S202. Detect whether the UA of the access request carries the unique attribute information of the specified activity mined in advance; if not, execute step S203; if so, execute step S204;

[0043] The unique attribute information of the specified activity is the attribute information jointly carried by all normal access requests of the specified activity. For example, in the present disclosure, the unique attribute information of the specified activity may be a string, and this string can identify that the access request is a normal access request for the specified activity.

[0044] S203. Determine that the access request is an attack; execute step S205;

[0045] S204. Determine that the access request is a normal access request, then release it and end.

[0046] S205. Intercept the access request and end.

[0047] The attack detection method of this embodiment, based on the technical solution of the above Figure 1 shown embodiment, when it is detected that the access request is an attack, intercept the access request, which can timely prevent malicious attacks, avoid the occurrence of risks, and effectively reduce the risk crisis of the specified activity.

[0048] Moreover, in this embodiment, when the UA of the access request carries the specific attribute information of the specified activity mined in advance, it is considered that the access request is a normal access request, and it can be released directly, effectively ensuring the normal progress of the normal access request.

[0049] Figure 3 It is a schematic diagram according to the third embodiment of the present disclosure; as Figure 3 shown, this embodiment mainly introduces the mining scheme of the specific attribute information of the specified activity, which may specifically include the following steps:

[0050] S301. Obtain all access requests within a preset time length of the specified activity;

[0051] Specifically, all access requests within a preset time length after the start of the specified activity can be obtained. Among them, the selection of the preset time length can be determined according to the number of access requests within the preset time length. For example, after the start of the specified activity, as time accumulates, the number of access requests gradually increases. At a certain specified moment, the number of access requests reaches the preset quantity threshold. At this time, the preset time length can be taken as the time length between the start moment of the activity and the specified moment. In this way, based on all access requests within the preset time length just after the start of the specified activity, the specific attribute information of the specified activity can be mined, and then based on the characteristic attribute information of the specified activity, an attack detection scheme for the specified activity can be deployed on the server side, which can timely and effectively detect attacks on the access requests of the specified activity.

[0052] Optionally, all access requests within any preset time length after the start of the specified activity can also be taken, and no limitation is made here.

[0053] S302. Classify all access requests according to the UA to obtain multiple access request groups for each UA, and each access request group for each UA includes at least one access request;

[0054] In practical applications, each access request carries a UA. The UAs of different access requests can be the same or different. In this step, all the obtained access requests are classified according to the UA, and access request groups for multiple UAs are obtained. Each access request group for a UA may include at least one access request.

[0055] S303. Mine the specific attribute information of the specified activity based on at least one access request corresponding to each UA among multiple UAs.

[0056] Specifically, by analyzing at least one access request for each UA among multiple UAs, the attribute information of the specified activity is mined.

[0057] For example, when specifically implementing this step S303, it may include the following steps:

[0058] (1) Based on at least one access request corresponding to each UA among multiple UAs and a preset scoring strategy, obtain the score of each UA.

[0059] For each UA, according to at least one access request in the access request group of this UA and a preset scoring strategy, score this UA and obtain the score of this UA.

[0060] For example, when specifically implementing this step (1), it may include the following steps:

[0061] (a) For each UA among multiple UAs, obtain the basic attribute information of each access request of the UA; the basic attribute information includes at least one type of attribute information;

[0062] Specifically, the basic attribute information included in the access request may include at least one type of attribute information among device attribute information, account attribute information, network attribute information, location attribute information, service behavior attribute information, and black and white list attribute information. For example, each access request is affected by different factors such as the initiating user and the initiating device, resulting in different categories of attribute information included in the basic attribute information of different access requests. For example, in some access requests, the user does not authorize the acquisition of account information. At this time, the basic attribute information of the corresponding access request does not include account attribute information, but may include device attribute information, network attribute information, location attribute information, service behavior attribute information, and black and white list attribute information. In some other access requests, the corresponding account is a new account. Due to less historical access data, the black and white list attribute information and service behavior attribute information of this account cannot be identified. At this time, the basic attribute information of the corresponding access request does not include black and white list attribute information and service behavior attribute information, but may include device attribute information, account attribute information, network attribute information, and location attribute information. That is to say, in practical applications, all the basic attribute information of the access request that can be obtained can be acquired according to the specific situation of each access request. The categories of attribute information included in the basic attribute information of different access requests corresponding to the same UA may be the same or different, which does not affect the subsequent acquisition of the score of this UA.

[0063] Alternatively, in practical applications, the categories of attribute information included in the basic attribute information of each access request can also be preconfigured based on requirements or experience. For example, it can be preconfigured that the basic attribute information of each access request of the UA may include 6 types of attribute information: device attribute information, account attribute information, network attribute information, location attribute information, service behavior attribute information, and black and white list attribute information. In some scenarios, to avoid some attribute information not being obtained, it is preconfigured that the basic attribute information of each access request of the UA includes 4 types of attribute information: device attribute information, network attribute information, location attribute information, and service behavior attribute information. In some other scenarios, some categories of attribute information that have a greater impact on the UA score calculation can be selected in the basic attribute information, that is, the categories of attribute information with a preset higher weight. For example, in one embodiment, the preset weights of account attribute information, network attribute information, and service behavior attribute information are greater than the weights of other categories of attribute information. At this time, it can be preconfigured that the basic attribute information of each access request of the UA only includes 3 types of attribute information: account attribute information, network attribute information, and service behavior attribute information. Of course, in practical applications, the categories of attribute information included in the basic attribute information of each access request of the UA can also be preconfigured according to other requirements, as long as it is ensured that the basic attribute information includes at least one type of attribute information, and no specific limitation is made here.

[0064] In the embodiments of the present disclosure, the categories of attribute information included in the basic attribute information can be very rich, which can effectively improve the accuracy of the scores of UAs. Of course, in practical applications, the more categories of attribute information included in the access request, the more accurate the scores of each UA obtained.

[0065] Among them, the device attribute information may include information such as the brand and operating system version of the device that issues the access request.

[0066] The account attribute information may include information such as the registration time, type, and nickname of the account that issues the access request. These information can be obtained under the premise of the authorization of the user corresponding to the account.

[0067] The network attribute information may include the IP type corresponding to the access request. For example, the IP type may include a proxy IP or a personal IP. Among them, the probability that an access request with an IP type of proxy IP is an attack is greater than the probability that an access request with an IP type of personal IP is an attack.

[0068] The location attribute information may include information such as the place of origin of the IP of the access request and the place of origin of the mobile phone number of the user corresponding to the access request.

[0069] The service behavior attribute information may include the attribute information shown when the user corresponding to the access request performs service behaviors such as logging in or participating in other activities on the platform where the specified activity belongs. Moreover, based on the service behavior of the user, the user can be divided into various types such as normal users, risk users, and users with the attribute of wool pulling.

[0070] The black and white list attribute information can identify whether the account of the access request belongs to the black list or the white list, and this identification result is set based on all the historical access requests of this account.

[0071] (b) Based on the attribute information of each access request of the UA and the preset scoring strategy, obtain the scores corresponding to the attribute information of the UA;

[0072] For any attribute information of any UA, at least one access request in the access request group of this UA can be obtained first, and the attribute information in each access request is obtained, corresponding to at least one piece of attribute information corresponding to this UA. Then, according to at least one piece of attribute information corresponding to this UA and in accordance with the preset scoring strategy, obtain the score corresponding to this attribute information of this UA.

[0073] For example, according to the preset scoring strategy, the score of the service behavior attribute information of a certain UA can be equal to the proportion of risk users * 100 in at least one access request under the specified activity of this UA. The higher this score, the greater the risk of this UA.

[0074] For example, according to the preset scoring strategy, the score of the location attribute information of a certain UA can be equal to the percentage of the inconsistency between the mobile phone number's place of origin and the IP address's place of origin in at least one access request under the specified activity of the UA * 100. The higher the score, the greater the risk of the UA.

[0075] For example, according to the preset scoring strategy, the score of the network attribute information of a certain UA can be equal to the percentage of proxy IPs in at least one access request under the specified activity of the UA * 100. The higher the score, the greater the risk of the UA.

[0076] For example, according to the preset scoring strategy, the score of the account attribute information of a certain UA can be equal to the percentage of the account registration time not within the preset time period in at least one access request under the specified activity of the UA * 100. The higher the score, the greater the risk of the UA.

[0077] For example, according to the preset scoring strategy, the score of the black and white list attribute information of a certain UA can be equal to the percentage of accounts with blacklist attributes in at least one access request under the specified activity of the UA * 100. The higher the score, the greater the risk of the UA.

[0078] The above are only examples of the scoring strategies for several types of attribute information. In actual applications, other scoring strategies for various attribute information can also be configured according to the actual situation, and no further examples will be given here.

[0079] In addition, in the above embodiments, it is taken as an example that the higher the score of the attribute information, the greater the risk of the corresponding UA for explanation. In actual applications, the opposite strategy can also be set, that is, the lower the score of the attribute information, the greater the risk of the corresponding UA, and its implementation principle is similar. For example, for the score of the black and white list attribute information of a certain UA, it can be equal to the percentage of accounts with whitelist attributes in at least one access request under the specified activity of the UA * 100. The lower the score, the greater the risk of the UA. For the scoring strategies of other attribute information, the principle is similar, and no further examples will be given here.

[0080] And the rules of the scoring strategies for each attribute information must be consistent. For example, in all cases, the higher the score, the greater the risk of the corresponding UA. Or in all cases, the lower the score, the greater the risk of the corresponding UA.

[0081] For each attribute information of each UA, the corresponding score can be obtained in the above manner.

[0082] (c) Based on the scores corresponding to the attribute information of the UA and the preset weights of each attribute information, perform weighted summation to obtain the score of the corresponding UA.

[0083] When multiple attribute information is included in at least one access request of the same UA, the scores of the respective attribute information obtained above can be multiplied by the preset weights and then added together to obtain the score of the corresponding UA.

[0084] For example, in at least one access request of a certain UA, six attribute information including device attribute information, account attribute information, network attribute information, location attribute information, service behavior attribute information, and black and white list attribute information are included at the same time.

[0085] According to the above method, the scores corresponding to the six attribute information can be calculated as S1, S2, S3, S4, S5, and S6 respectively; and the preset weights of the six attribute information correspond to W1, W2, W3, W4, W5, and W6 respectively. Correspondingly, the score of the UA can be equal to S1*W1 + S2*W2 + S1*W1 + S3*W3 + S4*W4 + S5*W5 + S6*W6.

[0086] By using the above method, the scores of each UA can be obtained very accurately and efficiently.

[0087] (2) Based on the scores of each UA and the preset score threshold, multiple target UAs are obtained from multiple UAs; the confidence levels of the multiple target UAs are greater than the confidence levels of the other UAs except the target UAs among the multiple UAs;

[0088] In this embodiment, due to different rules of the scoring strategy based on each attribute information, the confidence levels represented by the scores of the UAs are different. If in the rules of the scoring strategy, the higher the limited score, the greater the risk of the corresponding UA, then the lower the confidence level of the corresponding UA. If in the rules of the scoring strategy, the higher the limited score, the smaller the risk of the corresponding UA, then the higher the confidence level of the corresponding UA. That is to say, the confidence level of the UA is consistent with the risk level of the UA, and is consistent or reverse with the score of the UA.

[0089] For example, if the higher the score of the UA, the higher the risk and the lower the confidence level, multiple target UAs with scores less than the preset score threshold can be obtained according to the scores of each UA and the preset score threshold. The confidence levels of the multiple target UAs are greater than the confidence levels of the UAs with scores greater than the preset score threshold.

[0090] If the lower the score of the UA, the higher the risk and the lower the confidence level, multiple target UAs with scores greater than the preset score threshold can be obtained according to the scores of each UA and the preset score threshold. At this time, the confidence levels of the multiple target UAs are greater than the confidence levels of the UAs with scores less than the preset score threshold.

[0091] No matter which method is adopted, multiple target UAs can be accurately obtained from multiple UAs.

[0092] (3) Mine the unique attribute information of the specified activity based on multiple target UAs.

[0093] According to the above-mentioned method for obtaining multiple target UAs, it can be known that among all the access requests within the preset time length of the specified activity for the multiple target UAs, the multiple UAs with the highest confidence have the lowest corresponding risks. At this time, it can be considered that the multiple target UAs are all UAs for normal access requests. Therefore, in this embodiment, the unique attribute information of the specified activity can be mined from the multiple target UAs.

[0094] When this step (3) is specifically implemented, the multiple target UAs can be first simplified respectively to obtain corresponding multiple strings. For example, for each target UA, at least one of the numbers, symbols, version identifiers of the operating system, and the type of the central processing unit (CPU) in the target UA is removed to obtain the corresponding string.

[0095] For example, for a certain UA: mozilla / 5.0 (linux; android 10; wlz-an00 build / huawei wlz-an00; wv) applewebkit / 537.36 (khtml, like gecko) version / 4.0 chrome / 97.0.4692.98 mobile safari / 537.36 t7 / 13.19 swan / 2.57.0 swan-baiduboxapp / 13.19.5.10 baiduboxapp / 13.19.5.10 (baidu; p1 10), where mozilla / 5.0 (linux; android 10; wlz-an00 build / huawei wlz-an00; wv) represents the version information of the operating system; applewebkit / 537.36 (khtml, like gecko) version / 4.0 represents the version information of the engine; chrome / 97.0.4692.98 mobile safari / 537.36 t7 / 13.19 swan / 2.57.0 swan-baiduboxapp / 13.19.5.10 baiduboxapp / 13.19.5.10 (baidu; p1 10) represents the version information of the browser.

[0096] According to the simplification process of this embodiment, the corresponding string obtained can be expressed as: mozilla applewebkit version chrome mobile safari swan swan-baiduboxapp baiduboxapp.

[0097] For each target UA, the corresponding string can be accurately obtained according to the above simplified processing method. For multiple UAs, multiple strings can be correspondingly obtained.

[0098] Then, based on multiple strings, the specific attribute information of the specified activity is mined. For example, based on the Smith-Waterman algorithm, the specific attribute information of the specified activity can be mined from multiple strings. The Smith-Waterman algorithm can perform local sequence alignment. Instead of looking at the entire sequence, this algorithm compares segments of all possible lengths and optimizes the similarity metric. Based on this method, the similarity between the multiple strings corresponding to the multiple target UAs after simplified processing can be detected, thereby obtaining the commonality of the multiple target UAs, that is, the specific attribute information of the specified activity carried. By using the Smith-Waterman algorithm, the specific attribute information of the specified activity can be accurately and efficiently mined from multiple strings.

[0099] Since UAs accessing the same specified activity must jointly carry the specific attribute information of this specified activity. For example, the "swan-baiduboxapp" carried in the above string can be the specific attribute information of a specified activity.

[0100] The above simplified processing method can remove the information in each target UA that is irrelevant to the specific attribute information of the specified activity and eliminate interference. Compared with directly mining the specific attribute information of the specified activity from multiple target UAs, mining the specific attribute information of the specified activity based on the multiple strings after simplified processing can effectively shorten the mining speed and further improve the accuracy and mining efficiency of the mined specific attribute information of the specified activity.

[0101] The mining process of the specific attribute information of the specified activity in this embodiment can be an offline mining process. For a specified activity, the mining process of the specific attribute information of this specified activity can be executed only once. Then, based on the specific attribute information of this specified activity, an attack detection method for access requests of this specified activity can be deployed online, such as the Figure 1 and Figure 2 shown embodiments, which can achieve timely, accurate, and effective detection of all access requests after deployment.

[0102] The attack detection method of this embodiment can accurately and efficiently mine the specific attribute information of the specified activity by adopting the method of the above embodiment, and thus can effectively improve the accuracy and detection efficiency of the attack detection scheme for this specified activity.

[0103] The attack detection method of the present disclosure is an identification method based on specific attributes in the UA of an access request. Compared with the prior art, which only limits the verification of browser system parameters in the UA, it can effectively identify specific attributes in the browser UA inherent in a specified activity, and thus can effectively improve the ability to identify forged UAs for malicious attacks.

[0104] Figure 4 It is a schematic diagram according to the fourth embodiment of the present disclosure; as Figure 4 shown, this embodiment provides an attack detection device 400, including:

[0105] A first acquisition module 401, configured to acquire an access request for a specified activity;

[0106] A detection module 402, configured to detect whether the user agent of the access request carries the specific attribute information of the specified activity pre-mined; the specific attribute information of the specified activity is the attribute information jointly carried in all normal access requests of the specified activity;

[0107] A determination module 403, configured to determine that the access request is an attack if it is not carried.

[0108] For the attack detection device 400 of this embodiment, the implementation principle and technical effects of implementing attack detection by using the above modules are the same as those of the above related method embodiments. For details, reference can be made to the records of the above related method embodiments, which will not be elaborated here.

[0109] Figure 5 It is a schematic diagram according to the fifth embodiment of the present disclosure; as Figure 5 shown, this embodiment provides an attack detection device 500, including: the above Figure 4 shown same-name and same-function modules: a first acquisition module 501, a detection module 502, and a determination module 503.

[0110] Furthermore, in the attack detection device 500 of this embodiment, it further includes:

[0111] An interception module 504, configured to intercept the access request.

[0112] In an embodiment of the present disclosure, the attack detection device 500 further includes:

[0113] A second acquisition module 505, configured to acquire all access requests within a preset time length of the specified activity;

[0114] A classification module 506, configured to classify all the access requests according to the user agent to obtain access request groups of multiple user agents, and each access request group of the user agents includes at least one access request;

[0115] A mining module 507, configured to mine specific attribute information of the specified activity based on the at least one access request corresponding to each user agent among the multiple user agents.

[0116] Further, in an embodiment of the present disclosure, the mining module 507 is configured to:

[0117] Obtain scores of each user agent based on the at least one access request corresponding to each user agent among the multiple user agents and a preset scoring strategy;

[0118] Obtain multiple target user agents from the multiple user agents based on the scores of each user agent and a preset score threshold; the confidence levels of the multiple target user agents are greater than the confidence levels of other user agents other than the target user agents among the multiple user agents;

[0119] Mine specific attribute information of the specified activity based on the multiple target user agents.

[0120] Further, in an embodiment of the present disclosure, the mining module 507 is configured to:

[0121] For each user agent among the multiple user agents, obtain basic attribute information of each access request of the user agent; the basic attribute information includes at least one type of attribute information;

[0122] Obtain scores corresponding to each attribute information of the user agent based on each attribute information of each access request of the user agent and a preset scoring strategy;

[0123] Perform weighted summation based on the scores corresponding to each attribute information of the user agent and preset weights of each attribute information to obtain the score of the corresponding user agent.

[0124] Further, in an embodiment of the present disclosure, the basic attribute information includes at least one type of attribute information among device attribute information, account attribute information, network attribute information, location attribute information, service behavior attribute information, and black and white list attribute information.

[0125] Further, in an embodiment of the present disclosure, the mining module 507 is configured to:

[0126] Perform a simplification process on each of the multiple target user agents to obtain corresponding multiple strings;

[0127] Mine specific attribute information of the specified activity based on the multiple strings.

[0128] Further, in an embodiment of the present disclosure, the mining module 507 is configured to:

[0129] For each of the target user agents, remove at least one of numbers, symbols, version identifiers of the operating system, and types of central processing units in the target user agent to obtain the corresponding string.

[0130] Further, in an embodiment of the present disclosure, the mining module 507 is configured to:

[0131] Based on the Smith-Waterman algorithm, mine the unique attribute information of the specified activity from the multiple strings.

[0132] The attack detection device 500 of this embodiment realizes the principle and technical effect of attack detection by adopting the above modules, which is the same as that of the above-related method embodiments. For details, reference can be made to the records of the above-related method embodiments, and details will not be repeated here.

[0133] In the technical solution of the present disclosure, the acquisition, storage, and application of user personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0134] According to the embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0135] Figure 6 The schematic block diagram of an example electronic device 600 that can be used to implement the embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0136] As Figure 6 shown, the device 600 includes a computing unit 601, which can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 602 or the computer program loaded from the storage unit 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the device 600 can also be stored. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.

[0137] Multiple components in device 600 are connected to I / O interface 605, including: input unit 606, such as a keyboard, mouse, etc.; output unit 607, such as various types of displays, speakers, etc.; storage unit 608, such as a disk, optical disc, etc.; and communication unit 609, such as a network card, modem, wireless communication transceiver, etc. Communication unit 609 allows device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0138] Computing unit 601 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of computing unit 601 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 601 executes the various methods and processes described above, such as the above-described methods of the present disclosure. For example, in some embodiments, the above-described methods of the present disclosure can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by computing unit 601, one or more steps of the above-described methods of the present disclosure can be executed. Alternatively, in other embodiments, computing unit 601 can be configured to execute the above-described methods of the present disclosure by any other suitable means (e.g., by means of firmware).

[0139] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs, the one or more computer programs can be executed and / or interpreted on a programmable system including at least one programmable processor, the programmable processor can be a special or general-purpose programmable processor, can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0140] The program code for implementing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the program codes cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program codes may be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0141] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0142] In order to provide interaction with a user, the systems and techniques described herein may be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the computer. Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, speech input, or tactile input).

[0143] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0144] A computer system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, can also be a server of a distributed system, or a server incorporating a blockchain.

[0145] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this is not limited herein.

[0146] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.

Claims

1. An attack detection method, comprising: Obtain an access request for a specified activity; Detect whether the user agent of the access request carries the unique attribute information of the specified activity mined in advance; The unique attribute information of the specified activity is the attribute information commonly carried in all normal access requests of the specified activity; If not carried, determine that the access request is an attack; Among them, before detecting whether the user agent of the access request carries the unique attribute information of the specified activity mined in advance, the method further includes: Obtain all access requests within a preset time length of the specified activity; Classify all the access requests according to the user agent to obtain access request groups of multiple user agents, and each access request group of the user agents includes at least one access request; Mine the unique attribute information of the specified activity based on at least one access request corresponding to each user agent among the multiple user agents.

2. The method according to claim 1, wherein, After determining that the access request is a risk attack, it further includes: Intercept the access request.

3. The method according to claim 1, wherein, Mining the unique attribute information of the specified activity based on at least one access request corresponding to each user agent among the multiple user agents includes: Obtain the score of each user agent based on at least one access request corresponding to each user agent among the multiple user agents and a preset scoring strategy; Obtain multiple target user agents from the multiple user agents based on the scores of each user agent and a preset score threshold; the confidence levels of the multiple target user agents are greater than the confidence levels of other user agents other than the target user agents among the multiple user agents; Mine the unique attribute information of the specified activity based on the multiple target user agents.

4. The method according to claim 3, wherein, Obtaining the score of each user agent based on at least one access request corresponding to each user agent among the multiple user agents and a preset scoring strategy includes: For each user agent among the multiple user agents, obtain the basic attribute information of each access request of the user agent; the basic attribute information includes at least one type of attribute information; Obtain the score corresponding to each attribute information of the user agent based on each attribute information of each access request of the user agent and a preset scoring strategy; Perform weighted summation based on the scores corresponding to each attribute information of the user agent and the preset weights of each attribute information to obtain the score of the corresponding user agent.

5. The method according to claim 4, wherein, The basic attribute information includes at least one type of attribute information among device attribute information, account attribute information, network attribute information, location attribute information, service behavior attribute information, and black and white list attribute information.

6. The method according to claim 4, wherein, Mining the unique attribute information of the specified activity based on the multiple target user agents includes: Perform simplification processing on each of the multiple target user agents to obtain corresponding multiple strings; Mine the unique attribute information of the specified activity based on the multiple strings.

7. The method according to claim 6, wherein, Performing simplification processing on each of the multiple target user agents to obtain corresponding multiple strings includes: For each of the target user agents, remove at least one of the numbers, symbols, version identifiers of the operating system, and types of central processing units in the target user agent to obtain the corresponding string.

8. The method according to claim 6, wherein, Based on the multiple strings, mine the unique attribute information of the specified activity, including: Based on the Smith-Waterman algorithm, mine the unique attribute information of the specified activity from the multiple strings.

9. An attack detection device, comprising: The first acquisition module is used to acquire an access request for the specified activity; The detection module is used to detect whether the user agent of the access request carries the unique attribute information of the specified activity mined in advance; The unique attribute information of the specified activity is the attribute information jointly carried in all normal access requests of the specified activity; The determination module is used to determine that the access request is an attack if it is not carried; The device further includes: The second acquisition module is used to acquire all access requests within a preset time length of the specified activity; The classification module is used to classify all the access requests according to the user agent to obtain access request groups of multiple user agents, and each access request group of the user agents includes at least one access request; The mining module is used to mine the unique attribute information of the specified activity based on at least one access request corresponding to each of the multiple user agents in the multiple user agents.

10. The device according to claim 9, wherein, It further includes: The interception module is used to intercept the access request.

11. The device according to claim 9, wherein, The mining module is used to: Based on at least one access request corresponding to each of the multiple user agents in the multiple user agents and a preset scoring strategy, obtain the scores of each user agent; Based on the scores of each user agent and a preset score threshold, obtain multiple target user agents from the multiple user agents; The confidence levels of the multiple target user agents are greater than the confidence levels of other user agents other than the target user agents in the multiple user agents; Based on the multiple target user agents, mine the unique attribute information of the specified activity.

12. The device according to claim 11, wherein, The mining module is used to: For each of the multiple user agents, obtain the basic attribute information of each access request of the user agent; the basic attribute information includes at least one type of attribute information; Based on each attribute information of each access request of the user agent and a preset scoring strategy, obtain the scores corresponding to each attribute information of the user agent; Based on the scores corresponding to each attribute information of the user agent and the preset weights of each attribute information, perform weighted summation to obtain the score of the corresponding user agent.

13. The device according to claim 12, wherein, The basic attribute information includes at least one type of attribute information among device attribute information, account attribute information, network attribute information, location attribute information, service behavior attribute information, and black and white list attribute information.

14. The device according to claim 12, wherein, The mining module is used to: Perform a simplification process on each of the multiple target user agents to obtain corresponding multiple strings; Based on the multiple strings, mine the unique attribute information of the specified activity.

15. The device according to claim 14, wherein, The mining module is used to: For each of the target user agents, at least one of numbers, symbols, version identifiers of operating systems, and types of central processing units in the target user agent is removed to obtain the corresponding string.

16. The device according to claim 14, wherein, The mining module is configured to: Based on the Smith-Waterman algorithm, mine the unique attribute information of the specified activity from the multiple strings.

17. An electronic device, comprising: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 1-8.

18. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to execute the method according to any one of claims 1-8.

19. A computer program product, comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • UA character string anomaly detection method and device, equipment and medium

    CN113382000A

  • Black product attack detection method and device

    CN114338171A