Method, apparatus, device and storage medium for generating attack traffic detection rules
By obtaining data packets of abnormal traffic, using preset classification models and labeling models to extract malicious features, and combining preset attack templates to generate detection rules, the problem of inability to identify attack traffic in the existing technology is solved, and accurate attack traffic detection and defense is achieved.
Patent Information
- Application Number
- CN202310210967.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-07
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-03-07
AI Technical Summary
The prior art cannot accurately identify attack traffic and generate corresponding detection rules, resulting in the inability to effectively identify and defend attack traffic in network security protection.
By obtaining data packets of abnormal traffic, the byte sequence of attack traffic is determined using the preset classification model, malicious features are extracted based on the preset annotation model, and relevant malicious features are determined based on the preset attack template, and detection rules are generated.
It realizes accurate identification and generation detection rules for attack traffic, improves network security defense capabilities, and reduces missed and false alarms.
Smart Images

Figure CN116192527B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet technologies, and in particular, to a method, apparatus, device, and storage medium for generating attack traffic detection rules. Background Art
[0002] With the increase in cloud services, the proportion of Web application services has risen sharply. Therefore, the security protection of Web application services is particularly important. The protection of these application services mainly uses intrusion detection systems. The intrusion detection system discovers malicious events and generates alarms by monitoring network traffic or host behavior. The alarms generated by the intrusion detection system mainly depend on the attack traffic detection rule set inside the system.
[0003] In related technologies, the solutions for generating detection rules for attack traffic are mainly terminal-side program analysis and network-side common substrings / subsets. These two solutions mainly rely on honeypots, honeynets, and anomaly detection methods when identifying network attack traffic, and cannot accurately identify attack traffic. Furthermore, they cannot generate rules for attack traffic; that is, in network security protection, attack traffic cannot be accurately identified and detection rules cannot be generated for it. Summary of the Invention
[0004] The main purpose of the present application is to provide a method, apparatus, device, and storage medium for generating attack traffic detection rules, aiming to solve the technical problem in related technologies that attack traffic cannot be accurately identified and detection rules cannot be generated for it.
[0005] To achieve the above object, an embodiment of the present application provides a method for generating attack traffic detection rules, and the method includes:
[0006] Obtain the data packets carried by abnormal traffic, and determine the string sequences belonging to attack traffic from the data packets based on a preset classification model;
[0007] Extract malicious features from the string sequences based on a preset annotation model;
[0008] According to the malicious features and a preset attack template, determine the relevant malicious features adjacent to the malicious features, where the preset attack template is used to extract the relevant malicious features;
[0009] Map the set composed of the malicious features and the relevant malicious features to the rule keywords in the intrusion detection system to generate detection rules.
[0010] In a possible implementation manner of the present application, the step of extracting malicious features from the string sequences based on a preset annotation model includes:
[0011] Convert the string sequence into a byte sequence, and based on a preset annotation model, annotate the byte sequence to output an annotated byte sequence;
[0012] Determine the position information of malicious bytes according to multiple annotation types of the annotated byte sequence;
[0013] Extract malicious features in the string sequence according to the position information.
[0014] In a possible implementation manner of the present application, the step of determining the position information of malicious bytes according to multiple annotation types of the annotated byte sequence includes:
[0015] Determine intermediate annotated bytes according to multiple annotation types of the annotated byte sequence;
[0016] Based on the position of the intermediate annotated byte in the annotated byte sequence, determine the position information of malicious bytes, where the intermediate annotated byte corresponds to the malicious byte.
[0017] In a possible implementation manner of the present application, the step of determining related malicious features adjacent to the malicious feature according to the malicious feature and a preset attack template, where the preset attack template is used to extract the related malicious feature, includes:
[0018] According to the malicious feature and the preset attack template, determine the position information of the malicious feature, and extract sibling nodes and father nodes adjacent to the malicious feature;
[0019] Determine related malicious features according to the sibling nodes and the father nodes.
[0020] In a possible implementation manner of the present application, before the step of determining a string sequence belonging to attack traffic in the data packet based on a preset classification model, it includes:
[0021] Recombine the data packet to obtain flow data;
[0022] According to the application layer data obtained after processing the flow data, divide the application layer data into multiple string list items, and convert the string list items into corresponding byte sequences;
[0023] The step of determining a string sequence belonging to attack traffic in the data packet based on a preset classification model includes:
[0024] Based on a preset classification model, identify each input byte sequence to obtain a predicted identification result;
[0025] Based on the predicted recognition result, determine the first byte sequence belonging to the attack traffic in the byte sequence, and convert the first byte sequence into a string sequence belonging to the attack traffic.
[0026] In a possible implementation manner of the present application, after the step of determining the first byte sequence belonging to the attack traffic in the byte sequence according to the predicted recognition result and converting the first byte sequence into a string sequence belonging to the attack traffic, it includes:
[0027] Determine the attack type of the output string sequence according to the string sequence;
[0028] Visually display the attack type of the string sequence.
[0029] In a possible implementation manner of the present application, the step of mapping the set composed of the malicious feature and the related malicious feature to the rule keyword in the intrusion detection system to generate a detection rule includes:
[0030] Take the malicious feature and the related malicious feature as a malicious feature set of single or multiple attack traffics, and map them to the corresponding rule keywords;
[0031] Generate a detection rule according to the rule keyword.
[0032] The present application also provides an attack traffic detection rule generation device, and the attack traffic detection rule generation device further includes:
[0033] An acquisition module, configured to acquire the data packets carried by the abnormal traffic, and determine the string sequence belonging to the attack traffic from the data packets based on a preset classification model;
[0034] An extraction module, configured to extract the malicious features in the string sequence based on a preset annotation model;
[0035] A determination module, configured to determine the related malicious features adjacent to the malicious features according to the malicious features and a preset attack template, where the preset attack template is used to extract the related malicious features;
[0036] A generation module, configured to map the set composed of the malicious feature and the related malicious feature to the rule keyword in the intrusion detection system to generate a detection rule.
[0037] The present application also provides an attack traffic detection rule generation device, which is an entity node device. The attack traffic detection rule generation device includes: a memory, a processor, and a program of the attack traffic detection rule generation method stored on the memory and executable on the processor. When the program of the attack traffic detection rule generation method is executed by the processor, the steps of the attack traffic detection rule generation method as described above can be implemented.
[0038] To achieve the above object, a storage medium is also provided. An attack traffic detection rule generation program is stored on the storage medium. When the attack traffic detection rule generation program is executed by a processor, the steps of any one of the above-mentioned attack traffic detection rule generation methods are implemented.
[0039] The present application provides an attack traffic detection rule generation method, apparatus, device, and storage medium. Compared with the methods relying on honeypots, honeynets, and anomaly detection in the related art, which cannot accurately identify attack traffic and thus cannot generate corresponding attack traffic detection rules, in the present application, packets carried by abnormal traffic are obtained, and based on a preset classification model, a first byte sequence belonging to attack traffic is determined from the packets; based on a preset annotation model, malicious features in the first byte sequence are extracted; according to the malicious features and a preset attack template, related malicious features adjacent to the malicious features are determined, where the preset attack template is used to extract the related malicious features; a set composed of the malicious features and the related malicious features is mapped to corresponding rule keywords to generate a detection rule. It can be understood that in the present application, through the packets carried by the obtained abnormal traffic, a first byte sequence belonging to attack traffic in the abnormal traffic is determined through a preset classification model. Furthermore, through a preset annotation model, malicious features in the first byte sequence are extracted, bytes belonging to malicious features in the first byte sequence are determined, and then according to a preset attack template, related malicious features adjacent to the malicious features are determined. The related malicious features and the malicious features are used as a malicious feature set. Merely using the malicious features of attack traffic cannot completely represent the conditions for triggering vulnerabilities, so corresponding related malicious features are determined, and the malicious feature set is mapped to rule keywords in the intrusion detection system to ensure that attack traffic can be accurately identified and thus a detection rule is generated. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 It is a schematic flowchart of the first embodiment of the attack traffic detection rule generation method of the present application;
[0041] Figure 2 It is a schematic overall execution flowchart of the attack traffic detection rule generation method of the present application;
[0042] Figure 3Schematic diagram of the device structure of the hardware operating environment involved in the solution of the embodiment of the present application;
[0043] Figure 4 Schematic diagram of the working process of the preset classification model and the preset annotation model in the attack traffic detection rule generation method of the present application;
[0044] Figure 5 Schematic diagram of the preset attack template in the attack traffic detection rule generation method of the present application. Detailed implementation manners
[0045] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0046] The embodiment of the present application provides an attack traffic detection rule generation method. In the first embodiment of the attack traffic detection rule generation method of the present application, refer to Figure 1 , which is applied to the verification component, and the method includes:
[0047] Step S10: Obtain the data packets carried by the abnormal traffic, and based on the preset classification model, determine the first byte sequence belonging to the attack traffic from the data packets;
[0048] Step S20: Extract the malicious features in the first byte sequence based on the preset annotation model;
[0049] Step S30: Determine the relevant malicious features adjacent to the malicious features according to the malicious features and the preset attack template, where the preset attack template is used to extract the relevant malicious features;
[0050] Step S40: Map the set composed of the malicious features and the relevant malicious features to the corresponding rule keywords to generate a detection rule.
[0051] The purpose of this embodiment is to accurately identify the attack traffic and generate a detection rule for it.
[0052] The specific steps are as follows:
[0053] Step S10: Obtain the data packets carried by the abnormal traffic, and based on the preset classification model, determine the first byte sequence belonging to the attack traffic from the data packets;
[0054] As an example, the attack traffic detection rule generation method can be applied to an attack traffic detection rule generation device. The attack traffic detection rule generation device belongs to an attack traffic detection rule generation system, and the attack traffic detection rule generation system belongs to an attack traffic detection rule generation device.
[0055] As an example, the scenario where the attack traffic detection rule generation method is applied can be the process in which, when external traffic invades the system, the intrusion detection system monitors the network traffic, discovers malicious events, and generates alarms.
[0056] As an example, the way to obtain abnormal traffic can be to receive abnormal traffic of external intrusion, and the abnormal traffic includes multiple data packets.
[0057] As an example, during the transmission of data packets, due to the limitation of the amount of information transmitted, the data packets need to be split during the transmission process and then reorganized after the transmission is completed. Before inputting the data packets into the preset classification model, the data packets need to be reorganized and then further processed.
[0058] As an example, the preset classification model is specifically a byte stream classification model. The byte stream classification model uses a token-free method to classify the input bytes, avoiding the problem that the model cannot effectively identify when all words not in the vocabulary (also called tokens) are marked as (UNK). The byte stream classification model uses bytes as input. Before inputting the data packets into the byte stream classification model, the obtained data packets need to be preprocessed to obtain a byte sequence, and then the transformed byte sequence is input into the byte stream classification model.
[0059] As an example, the preset classification model belongs to a multi-classification model. This model uses the SoftMax loss function to calculate the loss during training. The preset classification model has been trained when in use. After classifying the bytes, the result label of each byte sequence is determined. The result label can be normal or different attack category names, and the byte sequence belonging to the attack traffic in the data packet is determined through the result label.
[0060] As an example, the first byte sequence is the classified byte sequence output. Specifically, the first byte sequence is the byte sequence determined to be attack traffic. During the process in which the preset classification model determines the attack traffic to obtain the first byte sequence, only the first byte sequence can be determined to belong to the attack traffic, but there is still a lot of content unrelated to the attack in the first byte sequence, and further processing needs to be performed on the first byte sequence.
[0061] Step S20: Extract malicious features in the first byte sequence based on the preset annotation model;
[0062] As an example, the preset annotation model is specifically a byte stream sequence annotation model. The preset annotation model is used to extract malicious features in the first byte sequence. This model uses CER (Character Error Rate) as the loss function during training. During the process of using the preset annotation model to extract malicious features, the preset annotation model has been trained.
[0063] As an example, the working processes of the byte stream classification model and the byte stream sequence annotation model are as Figure 4 shown.
[0064] As an example, during the process of the preset annotation model annotating the byte sequence, each byte in the byte sequence is sequentially input into the Encoder module of the sequence annotation, and the Decoder module will have a corresponding predicted annotation output for each byte input.
[0065] As an example, the preset annotation model uses the method of annotating bytes to determine the position information of the malicious features in the first byte sequence, and annotates the input byte sequence, so as to determine the malicious features in the first byte sequence and extract the malicious features in the first byte sequence.
[0066] As an example, the preset annotation model will have corresponding annotation outputs for each byte in the input first byte sequence, and determine the bytes belonging to the malicious features according to different annotation outputs.
[0067] As an example, the malicious features can be malicious bytes, that is, one or more bytes related to the attack that are annotated.
[0068] As an example, after the malicious features are determined, the part of the input byte sequence that has nothing to do with the attack can be excluded, and only the byte sequence related to the attack is extracted.
[0069] Step S30: Determine the relevant malicious features adjacent to the malicious features according to the malicious features and the preset attack template, where the preset attack template is used to extract the relevant malicious features;
[0070] As an example, the message data sent by the client is called an HTTP request message / HTTP request packet, which is composed of a request line, a request header, a blank line, and a request body.
[0071] As an example, the message content responded by the server to the client is called an HTTP response message / HTTP response packet, which is composed of a status line, a response header, a blank line, and a response body.
[0072] As an example, the preset attack template is specifically an attack feature template applicable to multiple attack categories. The preset attack template processes the data packet into application layer data, analyzes the HTTP requests and responses of the application layer data, and constructs the application layer data into a tree structure. According to the HTTP protocol format, the application layer data is split into request / response lines, request / response headers, and request / response bodies, so as to determine the relevant malicious features adjacent to the malicious feature.
[0073] As an example, since the data structure of the request / response body is complex and includes various data structures such as json and xml, it is necessary to analyze it emphatically and construct it into a tree structure, specifically as Figure 5 shown.
[0074] As an example, the relevant malicious features include the sibling nodes and the father node adjacent to the root node to which the malicious feature belongs, as well as http_uri and http_method.
[0075] As an example, http_uri and http_method are the corresponding attributes and values (key-value) divided according to the Deep Packet Inspection (DPI) technology. When an attacker launches an attack, the attack traffic sent must have a combination of one or both of these parameters. Http_uri and http_method are equivalent to the necessary conditions for the attacker to carry out the attack.
[0076] Among them, the step of determining the relevant malicious features adjacent to the malicious feature according to the malicious feature and the preset attack template, wherein the step of using the preset attack template to extract the relevant malicious features includes:
[0077] Step S31, according to the malicious feature and the preset attack template, determine the location information of the malicious feature, and extract the sibling nodes and the father node adjacent to the root node to which the malicious feature belongs;
[0078] As an example, after determining the location information of the malicious feature, according to the tree structure constructed according to the HTTP protocol format by the preset attack template, correspondingly, the root node where the malicious feature is located can be determined.
[0079] As an example, only using the malicious features related to the attack cannot completely represent the conditions for triggering and exploiting the vulnerability, which will lead to the occurrence of missed reports and false reports. Furthermore, it is necessary to determine the relevant malicious features similar to the malicious feature.
[0080] As an example, the sibling node is a node adjacent to the root node to which the malicious feature belongs, and the sibling node and the root node to which the malicious feature belongs belong to the same father node.
[0081] As an example, the father node is the previous node adjacent to the root node to which the malicious feature belongs, and the root node to which the malicious feature belongs is a child node subordinate to the father node.
[0082] Step S32: Determine relevant malicious features according to the sibling nodes and the father node.
[0083] As an example, after determining the sibling nodes and the father node, the sibling nodes, the father node, and the http_uri and http_method in the tree structure corresponding to each node are used as relevant malicious features.
[0084] Step S40: Map the set composed of the malicious features and the relevant malicious features to corresponding rule keywords to generate a detection rule.
[0085] As an example, the rule keyword is a keyword in a preset detection rule set in the system, and one rule keyword corresponds to one or more malicious features.
[0086] As an example, by making the set of malicious features and relevant malicious features correspond to rule keywords one by one, a detection rule is generated.
[0087] Among them, the step of mapping the set composed of the malicious features and the relevant malicious features to the rule keywords in the intrusion detection system to generate a detection rule includes:
[0088] Step S41: Use the malicious features and the relevant malicious features as the malicious feature set of single or multiple attack flows and map them to corresponding rule keywords;
[0089] As an example, in the related art, when identifying attack flows and generating detection rules, it is necessary to analyze multiple attack flows before running, and the generated rules contain too many features irrelevant to attacks, resulting in the generated detection rules having poor network security protection due to excessive false negatives in actual use.
[0090] In this embodiment, the malicious feature set composed of malicious features and relevant malicious features can be used as the malicious feature of a single attack flow, so that a rule can also be generated for a single attack flow, and the relevant features irrelevant to the attack are excluded, thus avoiding the occurrence of false negative alarms.
[0091] Step S42: Generate a detection rule according to the rule keyword.
[0092] As an example, the rule keyword corresponding to the malicious feature can be one or a set of multiple rule keywords, and the detection rule changes in real time according to the situation of the attack flow, so as to accurately monitor the network traffic in real time.
[0093] As an example, the detection rules are a set of rule keywords that have completed mapping.
[0094] In this embodiment, the overall execution flow diagram is as Figure 2 shown. By receiving a data packet, it is determined whether the received data packet needs to be reorganized. If so, the data packet is reorganized to obtain stream data. If not, the received data packet is directly processed as stream data. It is determined whether the overall process of traversing the stream data is ended. If it is ended, it directly enters the last step. If not, the stream data is processed according to the HTTP protocol to obtain application layer data; the HTTP request or response data of the obtained application layer data is divided into multiple string list items, and it is determined whether the process of traversing the list is ended. If it is ended, it returns to the step of judging the stream data. If not, the string list items are converted into byte sequences, and a byte stream classification model is used to judge whether the byte sequence is a normal or a certain attack sequence. When it is determined to be a byte sequence related to an attack, malicious features and related malicious features are obtained according to the byte stream sequence annotation model and a preset attack template, and the set composed of the malicious features and the related malicious features is mapped to the rule keywords, thereby generating detection rules.
[0095] The present application provides a method, device, equipment and storage medium for generating an attack traffic detection rule. Compared with the methods relying on honeypots, honeynets and anomaly detection in the related art, which cannot accurately identify attack traffic and thus cannot generate corresponding attack traffic detection rules, in the present application, data packets carried by abnormal traffic are obtained, and based on a preset classification model, a first byte sequence belonging to attack traffic is determined from the data packets; based on a preset annotation model, malicious features in the first byte sequence are extracted; according to the malicious features and a preset attack template, related malicious features adjacent to the malicious features are determined, where the preset attack template is used to extract the related malicious features;
[0096] Map the set composed of the malicious features and the related malicious features to corresponding rule keywords to generate a detection rule. It can be understood that in this application, through the data packets carried by the abnormal traffic obtained, the first byte sequence belonging to the attack traffic in the abnormal traffic is determined through a preset classification model. Furthermore, through a preset annotation model, the malicious features in the first byte sequence are extracted, the bytes belonging to the malicious features in the first byte sequence are determined, and then according to a preset attack template, the related malicious features adjacent to the malicious features are determined. The related malicious features and the malicious features are used as a malicious feature set. Merely using the malicious features of the attack traffic cannot completely represent the conditions for triggering a vulnerability. Therefore, the corresponding related malicious features are determined, and the malicious feature set is mapped to the rule keywords in the intrusion detection system to ensure that the attack traffic can be accurately identified, thereby generating a detection rule.
[0097] Further, based on the first embodiment of this application, another embodiment of this application is provided. In this embodiment, the step of extracting the malicious features in the first byte sequence based on the preset annotation model includes:
[0098] Step A1, based on a preset annotation model, annotate the first byte sequence and output an annotated byte sequence;
[0099] As an example, each byte of the first byte sequence input into the preset annotation model corresponds to a predicted annotation output. After determining the predicted annotation output, an annotated byte sequence is output.
[0100] As an example, the predicted annotation output corresponds to multiple annotation types, and each annotation type is represented by a numerical value or an English letter.
[0101] As an example, the values of the predicted annotation output can be 0, B, I, E. 0 represents no annotation, B represents the start of annotation, I represents the middle annotation, and E represents the end of annotation. Among the 4 annotation types, the byte with the middle annotation is the byte related to the attack. The annotations of B and E are used to limit the position of the middle annotation, and 0 indicates no annotation, that is, the byte without annotation is not related to the attack. Specifically, as Figure 4 shown.
[0102] Step A2, according to the multiple annotation types of the annotated byte sequence, determine the position information of the malicious bytes;
[0103] As an example, through the 4 annotation types / predicted annotation outputs, the position information of the malicious bytes and the bytes not related to the attack in the annotated byte sequence can be determined.
[0104] Step A3, according to the position information, extract the malicious features in the first byte sequence.
[0105] As an example, according to the position information of the corresponding malicious bytes, extract the malicious features in the first byte sequence and use them as the output result. The output byte sequence is converted into a character sequence according to the correspondence with characters.
[0106] Among them, the step of determining the position information of malicious bytes according to multiple annotation types of the annotated byte sequence includes:
[0107] Step B1, determine the intermediate annotated byte according to multiple annotation types of the annotated byte sequence;
[0108] As an example, select the byte of the intermediate annotation according to multiple annotation types in the annotated byte sequence.
[0109] Step B2, based on the position of the intermediate annotated byte in the annotated byte sequence, determine the position information of the malicious byte, where the intermediate annotated byte corresponds to the malicious byte.
[0110] As an example, due to the positions of 4 annotation types in the byte, the position of the intermediate annotated byte can be determined, and the intermediate annotated byte is the malicious byte that is annotated.
[0111] As an example, using the form of annotated bytes, each byte in the input byte sequence can be determined, and the corresponding malicious byte can be accurately identified.
[0112] In this embodiment, the input first byte sequence is annotated by a preset annotation model to determine the position information of the malicious features, and there is a corresponding predicted annotation output for each byte, thereby enhancing the accuracy of identifying malicious features.
[0113] Further, based on the first embodiment and the second embodiment of the present application, another embodiment of the present application is provided. In this embodiment, before the step of determining the first byte sequence belonging to the attack traffic in the data packet based on the preset classification model, the method includes:
[0114] Step C1, reorganize the data packet to obtain flow data;
[0115] As an example, to cope with the situation of IP fragmentation and TCP segmentation to evade attack detection, realize the flow reorganization (five-tuple, two-way flow) of IP fragmentation and TCP segmentation, which is convenient for subsequent more accurate analysis of the data streams of both communication parties.
[0116] As an example, during the data packet transmission process, due to the limitations of the transmission channel, before transmitting the data, the data packet needs to be fragmented / segmented first, and then transmitted. After the transmission is completed, the split data packets will be reorganized to obtain the flow data.
[0117] As an example, the flow data is combined according to a five-tuple, which includes the source IP address, source port, destination IP address, destination port, and transport layer protocol.
[0118] Step C2: Divide the application layer data obtained after processing the flow data into multiple string list items, and convert the string list items into corresponding byte sequences.
[0119] As an example, the flow data is processed according to the HTTP protocol. After removing the protocol header of the flow data, the application layer data is obtained.
[0120] As an example, divide the application layer data into multiple string list items according to the HTTP protocol, making it feasible to detect the entire application layer protocol content. Then convert the string list items into multiple byte sequences and use the byte sequences as input, enabling the preset classification model to detect each list item, thereby increasing the accuracy of the preset classification model in identifying bytes.
[0121] The step of determining the first byte sequence belonging to the attack traffic in the data packet based on the preset classification model includes:
[0122] Step C3: Based on the preset classification model, identify each of the input byte sequences to obtain a predicted identification result.
[0123] As an example, after identifying each input byte sequence through the preset classification model, a predicted identification result is output.
[0124] As an example, the predicted identification result can be normal or a certain attack category.
[0125] Step C4: According to the predicted identification result, determine the first byte sequence belonging to the attack traffic in the byte sequence.
[0126] As an example, according to the corresponding predicted identification result, the byte sequences belonging to the attack traffic and the normal byte sequences can be determined.
[0127] As an example, take the byte sequence determined to belong to the attack traffic as the first byte sequence and perform the next processing.
[0128] Among them, the step of determining the first byte sequence belonging to the attack traffic in the byte sequence according to the predicted identification result further includes:
[0129] Step D1: According to the predicted identification result, determine the attack type of the output first byte sequence.
[0130] As an example, the attack type can be SQL injection attack, command injection attack, etc., without specific limitation.
[0131] Step D2, visually display the attack type of the first byte sequence.
[0132] As an example, visually display the attack type of the first byte sequence to the user for viewing, and the user can also perform manual operations according to the corresponding attack type.
[0133] In this embodiment, by processing the obtained data packets, multiple string list items are obtained after division, and then each string list item is converted into a byte sequence and input into a preset classification model for processing, so as to determine the byte sequence belonging to the attack traffic, improving the recognition accuracy of the preset classification model for the attack traffic.
[0134] Refer to Figure 3 , Figure 3 is a schematic diagram of the device structure of the hardware operating environment involved in the solution of the embodiment of the present application.
[0135] As Figure 3 shown, the attack traffic detection rule generation device may include: a processor 1001, a memory 1005, and a communication bus 1002. The communication bus 1002 is used to realize the connection and communication between the processor 1001 and the memory 1005.
[0136] Optionally, the attack traffic detection rule generation device may further include a user interface, a network interface, a camera, an RF (Radio Frequency) circuit, sensors, a WiFi module, etc. The user interface may include a display screen (Display) and an input sub-module such as a keyboard (Keyboard). Optionally, the user interface may further include a standard wired interface and a wireless interface. The network interface may include a standard wired interface and a wireless interface (such as a WI-FI interface).
[0137] Those skilled in the art can understand that Figure 3 the attack traffic detection rule generation device structure shown in
[0138] As Figure 3As shown in the figure, in a memory 1005 serving as a storage medium, an operating system, a network communication module, and an attack traffic detection rule generation program may be included. The operating system is a program that manages and controls the hardware and software resources of the attack traffic detection rule generation device, and supports the operation of the attack traffic detection rule generation program and other software and / or programs. The network communication module is used to implement communication between components inside the memory 1005, as well as communication with other hardware and software in the attack traffic detection rule generation system.
[0139] In Figure 3 In the attack traffic detection rule generation device shown in the figure, a processor 1001 is used to execute the attack traffic detection rule generation program stored in the memory 1005, and implement the steps of the attack traffic detection rule generation method described in any one of the above.
[0140] The specific implementation manner of the attack traffic detection rule generation device of the present application is basically the same as each embodiment of the above attack traffic detection rule generation method, and will not be elaborated here.
[0141] The present application also provides an attack traffic detection rule generation device, and the attack traffic detection rule generation device includes:
[0142] An acquisition module, configured to acquire data packets carried by abnormal traffic, and determine a first byte sequence belonging to attack traffic from the data packets based on a preset classification model;
[0143] An extraction module, configured to extract malicious features in the first byte sequence based on a preset annotation model;
[0144] A determination module, configured to determine related malicious features adjacent to the malicious features according to the malicious features and a preset attack template, where the preset attack template is used to extract the related malicious features;
[0145] A generation module, configured to map a set composed of the malicious features and the related malicious features to corresponding rule keywords, and generate a detection rule.
[0146] In a possible implementation manner of the present application, the extraction module includes:
[0147] An output unit, configured to annotate the first byte sequence based on a preset annotation model, and output an annotated byte sequence;
[0148] A first determination unit, configured to determine the position information of malicious bytes according to multiple annotation types of the annotated byte sequence;
[0149] A first extraction unit, configured to extract malicious features in the first byte sequence according to the position information.
[0150] In a possible implementation manner of the present application, the first determination unit includes:
[0151] A first determination subunit, configured to determine intermediate annotation bytes according to multiple annotation types of the annotation byte sequence;
[0152] A second determination subunit, configured to determine the position information of malicious bytes based on the position of the intermediate annotation bytes in the annotation byte sequence, where the intermediate annotation bytes correspond to malicious bytes.
[0153] In a possible implementation manner of the present application, the determination module includes:
[0154] A second determination unit, configured to determine the position information of the malicious feature according to the malicious feature and a preset attack template, and extract sibling nodes and parent nodes adjacent to the malicious feature;
[0155] A third determination unit, configured to determine relevant malicious features according to the sibling nodes and the parent nodes.
[0156] In a possible implementation manner of the present application, the device further includes:
[0157] A recombination module, configured to recombine the data packet to obtain flow data;
[0158] A division module, configured to divide the application layer data obtained after processing the flow data into multiple string list items, and convert the string list items into corresponding byte sequences.
[0159] In a possible implementation manner of the present application, the acquisition module includes:
[0160] An identification unit, configured to identify each of the input byte sequences based on a preset classification model to obtain a predicted identification result;
[0161] A fourth determination unit, configured to determine a first byte sequence belonging to attack traffic in the byte sequence according to the predicted identification result.
[0162] In a possible implementation manner of the present application, the fourth determination unit includes:
[0163] A third determination subunit, configured to determine the attack type of the output first byte sequence according to the predicted identification result;
[0164] A display subunit, configured to visually display the attack type of the first byte sequence.
[0165] In a possible implementation manner of the present application, the generation module includes:
[0166] A mapping unit, configured to use the malicious feature and the related malicious feature as a set of malicious features of one or more attack flows, and map them to corresponding rule keywords;
[0167] A generating unit, configured to generate a detection rule according to the rule keyword.
[0168] It should be noted that in this document, the terms "including", "comprising" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "including one..." does not exclude the presence of additional identical elements in the process, method, article or system including that element.
[0169] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.
[0170] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present application.
[0171] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.
Claims
1. A method for generating attack traffic detection rules, characterized in that The method includes the following steps: Obtain the data packets carried by abnormal traffic, and based on a preset classification model, determine a first byte sequence belonging to attack traffic from the data packets; Based on a preset annotation model, extract malicious features in the first byte sequence, where the malicious features are one or more bytes related to an attack; According to the malicious features and a preset attack template, determine related malicious features adjacent to the malicious features, where the preset attack template is used to extract the related malicious features, and the related malicious features include related adjacent sibling nodes and the father node of the root node to which the malicious features belong, and the combination of attack parameters in the tree structure corresponding to the sibling nodes and the father node; Map the set composed of the malicious features and the related malicious features to corresponding rule keywords to generate a detection rule.
2. The attack traffic detection rule generation method according to claim 1, wherein The step of extracting malicious features in the first byte sequence based on a preset annotation model includes: Based on a preset annotation model, annotate the first byte sequence and output an annotated byte sequence; According to multiple annotation types of the annotated byte sequence, determine the position information of malicious bytes; According to the position information, extract malicious features in the first byte sequence.
3. The attack traffic detection rule generation method according to claim 2, characterized in that, The step of determining the position information of malicious bytes according to multiple annotation types of the annotated byte sequence includes: According to multiple annotation types of the annotated byte sequence, determine intermediate annotated bytes; Based on the position of the intermediate annotated bytes in the annotated byte sequence, determine the position information of malicious bytes, where the intermediate annotated bytes correspond to malicious bytes.
4. The attack traffic detection rule generation method according to claim 1, wherein The step of determining related malicious features adjacent to the malicious features according to the malicious features and a preset attack template, where the preset attack template is used to extract the related malicious features, includes: According to the malicious features and a preset attack template, determine the position information of the malicious features, and extract adjacent sibling nodes and the father node of the malicious features; According to the sibling nodes and the father node, determine related malicious features.
5. The method for generating an attack traffic detection rule according to claim 1, wherein Before the step of determining a first byte sequence belonging to attack traffic in the data packets based on a preset classification model, it includes: Recombine the data packets to obtain flow data; According to the application layer data obtained after processing the flow data, divide the application layer data into multiple string list items, and convert the string list items into corresponding byte sequences; The step of determining a first byte sequence belonging to attack traffic in the data packets based on a preset classification model includes: Based on a preset classification model, identify each input byte sequence to obtain a predicted identification result; According to the predicted identification result, determine a first byte sequence belonging to attack traffic in the byte sequence.
6. The attack traffic detection rule generation method according to claim 5, characterized in that The step of determining a first byte sequence belonging to attack traffic in the byte sequence according to the predicted identification result further includes: According to the predicted identification result, determine the attack type of the output first byte sequence; Visually display the attack type of the first byte sequence.
7. The attack traffic detection rule generation method according to claim 1, wherein The step of mapping the set composed of the malicious feature and the related malicious features to corresponding rule keywords to generate a detection rule includes: Regarding the malicious feature and the related malicious features as a malicious feature set of single or multiple attack traffic, and mapping them to corresponding rule keywords; Generating a detection rule according to the rule keywords.
8. An attack traffic detection rule generation device, characterized in that, The attack traffic detection rule generation device includes: An acquisition module, configured to acquire data packets carried by abnormal traffic, and based on a preset classification model, determine a first byte sequence belonging to attack traffic from the data packets; An extraction module, configured to extract malicious features in the first byte sequence based on a preset annotation model, where the malicious features are one or more bytes related to an attack; A determination module, configured to determine related malicious features adjacent to the malicious features according to the malicious features and a preset attack template, where the preset attack template is used to extract the related malicious features, and the related malicious features include related adjacent sibling nodes and father nodes related to the root node to which the malicious features belong, and combinations of attack parameters in the tree structures corresponding to the sibling nodes and the father nodes; A generation module, configured to map the set composed of the malicious feature and the related malicious features to corresponding rule keywords to generate a detection rule.
9. An attack traffic detection rule generation device, characterized in that The device includes: a memory, a processor, and an attack traffic detection rule generation program stored on the memory and executable on the processor, and the attack traffic detection rule generation program is configured to implement the steps of the attack traffic detection rule generation method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, An attack traffic detection rule generation program is stored on the computer-readable storage medium, and when the attack traffic detection rule generation program is executed by a processor, it implements the steps of the attack traffic detection rule generation method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Malware detection method based on HTTP behavior graph
CN109525577A
Web attack detection method and device, electronic equipment and storage medium
CN113132316A