Aggressive behavior processing method and apparatus

By injecting scripts into the honeypot system, page behavior information of the attacker's device is transmitted to the monitoring terminal in real time. This solves the problem that the honeypot system cannot intuitively view the page displayed and operation of the attacker's client, and enables intuitive analysis of attack behavior.

CN116248401BActive Publication Date: 2025-10-21BEIJING KNOWNSEC INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310245070.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-14
Publication Date
2025-10-21
Estimated Expiration
2043-03-14

AI Technical Summary

Technical Problem

In the attack and defense of honeypot systems, existing technologies cannot intuitively view the attacker's client display page and operations, making it inconvenient to analyze attack behavior.

Method used

By injecting scripts into the attacker's device, it can send page behavior information to the monitoring device in real time. The monitoring device then draws and displays the page content and operations of the attacker's device.

Benefits of technology

It enables monitors to view the attacker's client display page and operations in real time and intuitively, facilitating the analysis of attack behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116248401B_ABST
    Figure CN116248401B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an attack behavior processing method and device, and relate to the technical field of computing technology. The method is applied to a monitoring terminal device, and the method comprises: receiving page behavior information sent by a first target attacker device in real time after the first target attacker device receives response information of a honeypot, the response information comprising a script for enabling the first target attacker device to communicate with other devices, the page behavior information comprising page information and behavior information of an attacker, the page information being used to describe a display page of the first target attacker device, and the behavior information being used to describe an operation of the attacker on the first target attacker device; and according to the page information, drawing page content of the first target attacker device onto a page of the monitoring terminal device and simultaneously displaying the behavior information. In this way, a monitor can view the display page of the client of the attacker and the operation of the attacker on the client in real time and intuitively, so as to analyze the behavior of the attacker.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method and device for processing attack behaviors. Background Art

[0002] In a honeypot attack and defense scenario, the attacker accesses a honeypot that has been pre-installed by the defender. The defender analyzes the attacker's data requests, shell commands, and uploaded files to determine the attacker's attack methods, attack phases, and scope of impact. However, this method doesn't allow for direct visibility into the attacker's client interface or operations. Summary of the Invention

[0003] The embodiments of the present application provide an attack behavior processing method, device, electronic device, and readable storage medium, which enable a monitor to view the display page of the attacker's client and the attacker's operations on the client in real time and intuitively.

[0004] The embodiments of the present application can be implemented as follows:

[0005] In a first aspect, an embodiment of the present application provides an attack behavior processing method, which is applied to a monitoring terminal device. The method includes:

[0006] Receiving page behavior information sent in real time by the first target attacker device after receiving response information from the honeypot, wherein the response information includes a script for enabling the first target attacker device to communicate with other devices, the page behavior information includes page information and attacker behavior information, the page information is used to describe a display page of the first target attacker device, and the behavior information is used to describe an operation of the attacker on the first target attacker device;

[0007] According to the page information, the page content of the first target attacker device is drawn onto the page of the monitoring terminal device, and the behavior information is displayed at the same time.

[0008] In a second aspect, an embodiment of the present application provides an attack behavior processing method, which is applied to a communication system, wherein the communication system includes an attacker device and a monitoring terminal device, and the method includes:

[0009] The attacker device sends a web page request to the honeypot and receives response information from the honeypot, wherein the response information includes a script for enabling the attacker device to communicate with other devices;

[0010] The attacker device sends page behavior information to the monitoring device in real time, wherein the page behavior information includes page information and attacker behavior information, the page information is used to describe the display page of the attacker device, and the behavior information is used to describe the attacker's operation on the attacker device;

[0011] The monitoring terminal device draws the page content of the attacker device onto the page of the monitoring terminal device according to the page information, and displays the behavior information at the same time.

[0012] In a third aspect, an embodiment of the present application provides an attack behavior processing device, which is applied to a monitoring terminal device, and the device includes:

[0013] An information receiving module is configured to receive page behavior information sent in real time by a first target attacker device after receiving response information from a honeypot, wherein the response information includes a script for enabling the first target attacker device to communicate with other devices, the page behavior information includes page information and attacker behavior information, the page information is used to describe a display page of the first target attacker device, and the behavior information is used to describe an attacker's operation on the first target attacker device;

[0014] A processing module is used to draw the page content of the first target attacker device onto the page of the monitoring terminal device according to the page information, and simultaneously display the behavior information.

[0015] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores machine-executable instructions that can be executed by the processor, and the processor can execute the machine-executable instructions to implement the attack behavior processing method described in the aforementioned embodiment.

[0016] In a fifth aspect, an embodiment of the present application provides a readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the attack behavior processing method as described in the aforementioned embodiment is implemented.

[0017] The attack behavior processing method, device, electronic device and readable storage medium provided in the embodiments of the present application are such that the monitoring end device receives the page behavior information sent in real time by the first target attacker device after receiving the response information from the honeypot, and based on the page information in the page behavior information, draws the page content of the first target attacker device onto the page of the monitoring end device, and simultaneously displays the behavior information in the page behavior information. The response information includes a script for enabling the first target attacker device to communicate with other devices, the page information is used to describe the display page of the first target attacker device, and the behavior information is used to describe the attacker's operations on the first target attacker device. In this way, the monitor can view the display page of the attacker's client and the attacker's operations on the client in real time and intuitively. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0019] Figure 1 A block diagram of a communication system provided in an embodiment of the present application;

[0020] Figure 2 A block diagram of an electronic device provided in an embodiment of the present application;

[0021] Figure 3 This is a flow chart of the attack behavior processing method provided in the embodiment of the present application;

[0022] Figure 4 This is a second flow chart of the attack behavior processing method provided in an embodiment of the present application;

[0023] Figure 5 This is a flowchart of the attack behavior processing method provided in the embodiment of the present application;

[0024] Figure 6 This is a fourth flow chart of the attack behavior processing method provided in an embodiment of the present application;

[0025] Figure 7 Flowchart 5 of the attack behavior processing method provided in the embodiment of the present application;

[0026] Figure 8 Flowchart 6 of the attack behavior processing method provided in the embodiment of the present application;

[0027] Figure 9Schematic diagram of the communication process between the attacker end and the honeypot gateway, honeypot API server and monitoring end provided in the embodiment of the present application;

[0028] Figure 10 A schematic diagram of the interaction process between the attacker and the monitoring end provided in an embodiment of the present application;

[0029] Figure 11 Flowchart 7 of the attack behavior processing method provided in the embodiment of the present application;

[0030] Figure 12 Flowchart 8 of the attack behavior processing method provided in the embodiment of the present application;

[0031] Figure 13 A block diagram of an attack behavior processing device provided in an embodiment of the present application.

[0032] Icons: 10-communication system; 11-attacker device; 12-honeypot device; 13-monitoring device; 14-honeypot gateway; 15-honeypot interface server; 100-electronic device; 110-memory; 120-processor; 130-communication unit; 200-attack behavior processing device; 210-information receiving module; 220-processing module. DETAILED DESCRIPTION

[0033] To make the objectives, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Generally, the components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.

[0034] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of the present application.

[0035] It should be noted that relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.

[0036] The following first explains the terms involved in this application.

[0037] Honeypot system: A system service that serves as a deception defense in network security attack and defense confrontation.

[0038] Honeypot: A series of services provided to confuse attackers by simulating business systems.

[0039] WebRTC: A real-time P2P communication solution in browsers that supports two-way transmission of video and data.

[0040] ICE: A peer-to-peer communication protocol that uses a STUN server on the public network to obtain the current device's egress network information. This egress network information includes signaling.

[0041] Signaling: Device and network information obtained by the ICE protocol. Suppose there are two machines, A and B. A tells B its signaling, and B tells A its signaling. Then, A and B can communicate with each other.

[0042] In an attack-defense confrontation in a honeypot system, the honeypot accessed by the attacker is pre-installed by the defender. All traffic to the honeypot (for example, access to the honeypot via network ports 22 / 80 / 443 / 3306 / 3398) is forwarded through the gateway. In existing honeypot systems, when an attacker is lured into an attack by the honeypot, the defender analyzes the attack request traffic, including captured HTTP request parameters, shell commands, SQL commands, and uploaded files, to determine the attacker's current attack method, attack stage, and impact range. However, this method does not allow for intuitive visualization of the attacker's client display page or their operations.

[0043] To solve the above problems, the embodiments of the present application provide an attack behavior processing method, device, electronic device and readable storage medium, which enable the monitor to view the display page of the attacker's client and the attacker's operations on the client in real time and intuitively, so as to facilitate the analysis of the attacker's behavior.

[0044] The following describes some embodiments of the present application in detail with reference to the accompanying drawings. In the absence of conflict, the following embodiments and features therein may be combined with each other.

[0045] Please refer to Figure 1 , Figure 1 This is a block diagram of a communication system 10 provided in an embodiment of the present application. The communication system 10 may include a monitoring device 13 and an attacker device 11. The attacker device 11 is used by the attacker, while the monitoring device 13 is used by the monitor to monitor the attacker. In this embodiment, a device that accesses the honeypot system may be identified as an attacker device.

[0046] The attacker device 11 may first send a web page request to the honeypot device 12 where the honeypot is located, and then receive the response information from the honeypot device 12. Since the present application is aimed at web page attacks, the honeypot is a Web honeypot. The response information received by the attacker device 11 includes a script for enabling the attacker device 11 to communicate with other devices. The other devices may be monitoring end devices 13 or other devices that are communicatively connected to the monitoring end device 13. Through the script, after receiving the response information, the attacker device sends page behavior information to the monitoring end device 13 in real time. The page behavior information includes page information and attacker's behavior information, the page information is used to describe the display page of the attacker device, and the behavior information is used to describe the attacker's operations on the attacker device. That is, the page behavior information describes the page display content of the attacker device and the attacker's operations on the client.

[0047] Afterwards, the monitoring end device 13 can draw the page content of the attacker's device onto the page of the monitoring end device based on the page information, and display the behavior information at the same time, so that the monitor can view the display page of the attacker's client and the attacker's operations on the client in real time and intuitively, so as to analyze the attacker's behavior.

[0048] Optionally, in this embodiment, if Figure 1As shown, the communication system 10 may further include a honeypot gateway 14, through which the attacker device 11 communicates with the honeypot device 12. The script in the response message may be added by the honeypot device 12 or the honeypot gateway 14, depending on actual needs. The script may be a JavaScript script.

[0049] Optionally, the attacker device 11 and the monitoring terminal device 13 may be directly connected to each other in communication, or may be connected to each other through a honeypot interface server 15 serving as a transit server, and the specific setting may be based on actual needs.

[0050] Optionally, the other devices may include a honeypot interface server 15, which can receive and store page behavior information sent by the attacker device 11 and provide playback and / or download services to the monitoring terminal device 13 based on the stored page behavior information. In this way, playback and download forensics functions can be implemented without occupying space on the monitoring terminal device 13.

[0051] Optionally, as a possible implementation manner, the monitoring terminal device 13 may also control and modify the page displayed by the attacker device 11 .

[0052] Please refer to Figure 2 , Figure 2 This is a block diagram of an electronic device 100 provided in an embodiment of the present application. In this embodiment, the electronic device 100 can serve as the monitoring terminal device 13. The electronic device 100 can be, but is not limited to, a computer, etc. The electronic device 100 can include a memory 110, a processor 120, and a communication unit 130. The memory 110, processor 120, and communication unit 130 are electrically connected to each other directly or indirectly to enable data transmission or interaction. For example, these components can be electrically connected to each other via one or more communication buses or signal lines.

[0053] The memory 110 is used to store programs or data. The memory 110 may be, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc.

[0054] The processor 120 is used to read / write data or programs stored in the memory 110 and execute corresponding functions. For example, the memory 110 stores an attack behavior processing device 200, which includes at least one software function module stored in the memory 110 in the form of software or firmware. The processor 120 executes software programs and modules stored in the memory 110, such as the attack behavior processing device 200 in the embodiment of the present application, to perform various functional applications and data processing, thereby implementing the attack behavior processing method in the embodiment of the present application.

[0055] The communication unit 130 is used to establish a communication connection between the electronic device 100 and other communication terminals through a network, and to send and receive data through the network.

[0056] It should be understood that Figure 2 The structure shown is only a schematic diagram of the structure of the electronic device 100. The electronic device 100 may also include Figure 2 More or fewer components than shown, or with Figure 2 Different configurations shown. Figure 2 Each component shown in the figure can be implemented by hardware, software or a combination thereof.

[0057] Please refer to Figure 3 , Figure 3 This is a flow chart of one embodiment of the attack behavior processing method provided in this application. The method can be applied to the monitoring terminal device described above. The specific process of the attack behavior processing method is described in detail below. In this embodiment, the method may include steps S130 to S140.

[0058] Step S130: receiving page behavior information sent in real time by the first target attacker device after receiving the response information from the honeypot.

[0059] In this embodiment, the attacker device of the attacker whose real-time behavior is being monitored by the monitoring end device can be used as the first target attacker device. The first target attacker device first sends a web page request to the honeypot and receives the response information from the honeypot. The response information received by the first target attacker device includes a script for enabling the first target attacker device to communicate with other devices. The other device can be the monitoring end device; or it can be other devices that can communicate with the monitoring end device. The monitoring end device can communicate with the first target attacker device through the other device so as to receive the page behavior information sent in real time by the first target attacker device. The script can be injected by the honeypot, or it can be added by other devices when the original response information returned by the honeypot is transmitted to the first target attacker device. No specific limitation is made here.

[0060] After receiving the response information, the first target attacker device executes the script and then communicates data with the monitoring device. The first target attacker device can collect local page behavior information in real time and send the collected page behavior information to the monitoring device in real time. The first target attacker device and the monitoring device can be connected directly or through a relay device.

[0061] The page behavior information includes page information and attacker behavior information. The page information is used to describe the display page of the first target attacker device, and the behavior information is used to describe the attacker's operations on the first target attacker device. In other words, the page behavior information describes the content of the page on the first target attacker device and the attacker's operations on the first target attacker device client.

[0062] Step S140: Based on the page information, the page content of the first target attacker device is drawn onto the page of the monitoring terminal device, and the behavior information is displayed at the same time.

[0063] In this embodiment, after obtaining the page behavior information, the monitoring terminal device performs page rendering based on the page information in the page behavior information, thereby rendering the page content of the first target attacker device onto the page of the monitoring terminal device and simultaneously displaying the behavior information on the page of the monitoring terminal device. The specific display method of the behavior information can be set according to actual needs and is not specifically limited here. In this way, the monitor can view the displayed page of the attacker's client and the attacker's operations on the client in real time and intuitively, facilitating analysis of the attacker's behavior.

[0064] Optionally, in this embodiment, the first target attacker device first sends a web page request to the honeypot through the honeypot gateway. When the honeypot gateway determines that the first target attacker device requests HTML content (i.e., requests web page content), the honeypot gateway injects a section into the HTML of the honeypot response. <script>标签代码(即JavaScript脚本),并将经过处理之后的响应信息发送给第一目标攻击者设备。第一目标攻击者设备在接收到响应信息之后,第一目标攻击者设备的浏览器渲染页面,并执行注入的JavaScript脚本,以与其他设备进行通信。

[0065] 可选地,作为一种可能的实现方式,所述其他设备包括所述监控端设备,所述第一目标攻击者设备在接收到蜜罐的响应信息之后,通过执行该响应信息中的代码,可以与所述监控端设备进行通信。例如,该代码中可以包括所述监控端设备的IP地址或域名等。如此,便于所述第一目标攻击者设备直接与所述监控端设备进行通信。

[0066] 可选地,作为另一种可能的实现方式,可通过图4中的步骤S111~步骤S113实现所述第一目标攻击者设备与所述监控端设备的通信。请参照图4,图4为本申请实施例提供的攻击行为处理方法的流程示意图之二。在本实施例中,所述其他设备包括蜜罐接口服务器,在步骤S130之前,所述方法可以包括步骤S111~步骤S113。

[0067] 步骤S111,从STUN服务器处获得本机对应的第一设备出口网络信息。

[0068] 步骤S112,通过所述蜜罐接口服务器与所述第一目标攻击者设备交换设备出口网络信息,获得所述第一目标攻击者设备的第二设备出口网络信息。

[0069] 步骤S113,根据所述第二设备出口网络信息与所述第一目标攻击者设备建立WebRTC连接以传输所述页面行为信息。

[0070] 在本实施例中,所述第一目标攻击者设备通过执行接收到的响应信息中的代码,可与蜜罐接口服务器进行通信。所述监控端设备可与STUN服务器进行通信,以获得自身对应的设备出口网络信息,并将自身对应的设备出口网络信息作为第一设备出口网络信息。同理,所述第一目标攻击者设备也可与所述STUN服务器进行通信,以获得自身对应的设备出口网络信息,并将自身对应的设备出口网络信息作为第二设备出口网络信息。之后,所述第一目标攻击者设备及所述监控端设备通过所述蜜罐接口服务器进行设备出口网络信息的交换,使得所述第一目标攻击者设备获得所述监控端设备的第一设备出口网络信息、以及所述监控端设备获得所述第一目标攻击者设备的第二设备出口网络信息。也即,所述第二设备出口网络信息由所述第一目标攻击者设备从所述STUN服务器处获得、并发送给所述蜜罐接口服务器。接着,所述第一目标攻击者设备与所述监控端设备,可以根据第一设备出口网络信息及第二设备出口网络信息,建立WebRTC连接以传输所述页面行为信息。如此,即使所述监控端设备位于防护墙后,所述第一目标攻击者设备与所述监控端设备也可以建立用于传输实时数据的P2P通道,从而提供更加实时的交互体验效果。

[0071] 可选地,作为再一种可能的实现方式,所述其他设备包括蜜罐接口服务器。所述第一目标攻击者设备通过执行接收到的响应信息中的代码,可与蜜罐接口服务器进行通信。所述监控端设备与所述蜜罐接口服务器进行通信。所述蜜罐接口服务器可以作为所述第一目标攻击者设备与所述监控端设备之间的中转设备,也即,所述第一目标攻击者设备与所述监控端设备之间的数据通信通过所述蜜罐接口服务器进行转发。例如,所述第一目标攻击者设备实时发送页面行为信息给所述蜜罐接口服务器,所述蜜罐接口服务器将该页面行为信息转发给所述监控端设备。

[0072] 可选地,由于同一时间可能存在多个活动中的攻击者设备,而所述监控端设备无法同时监控较多的攻击者设备,因此可以从活动中的攻击者设备中选出所述第一目标攻击者设备。其中,活动中的攻击者设备为与蜜罐系统中的Web蜜罐通信的设备、且该设备中注入的所述脚本被执行,即可以将向蜜罐发送了网页请求、且执行了接收到的响应信息中的脚本确定为活动中的攻击者设备。也即,活动中的攻击者设备为被执行的脚本所在的攻击者设备,所述攻击者设备为与蜜罐通信的设备,所述攻击者设备接收到的蜜罐的响应信息中包括所述脚本。第一目标攻击者设备的具体确定方式可以结合实际需求进行设置。

[0073] 作为一种可能的实现方式,请参照图5图5为本申请实施例提供的攻击行为处理方法的流程示意图之三。在本实施例中,在步骤S130之前,所述方法还可以包括步骤S121及步骤S122,可通过步骤S201及步骤S122确定出所述第一目标攻击者设备。

[0074] 步骤S121,显示活动中的攻击者设备。

[0075] 步骤S122,根据接收到的攻击者选择操作,从活动中的攻击者设备中确定出所述第一目标攻击者设备。

[0076] 其中,所述监控端设备可以通过任意方式确定出目前活动中的攻击设备。比如,任意的攻击者设备在接收到蜜罐的响应信息之后,通过执行该响应信息中的代码,可向监控端设备发送数据;监控端设备在接收到攻击者设备传输的数据后,可认为该监控端设备为活动中的设备。或者,任意的攻击者设备在接收到蜜罐的响应信息之后,通过执行该响应信息中的代码,与蜜罐接口服务器进行通信,在此情况下,蜜罐接口服务器可以将该攻击者设备确定为活动中的攻击者设备,并将活动中的攻击者设备的设备相关信息发送给所述监控端设备,以便所述监控端设备确定出活动中的攻击者设备。可以理解的是,上述活动中的攻击者设备的确定方式仅为举例说明,也可以采用其他方式使所述监控端设备确定出活动中的攻击者设备。

[0077] 所述监控端设备在确定出活动中的攻击者设备之后,可将活动中的攻击者设备进行显示。之后,监控端设备处的工作人员可在活动中的攻击者设备进行选择,监控端设备根据接收到的攻击者选择操作,从活动的攻击者设备中确定出第一目标攻击者设备。即,工作人员从活动中的攻击者设备选出作为当前监控对象的第一攻击者设备。接着,监控端设备可以接收第一攻击者设备实时发送的页面行为信息,进而进行页面信息绘制及行为信息展示。如此,为便于工作工作人员根据实际需求确定出作为监控对象的第一目标攻击者设备。

[0078] 可选地,所述第一目标攻击者设备可以是由于接收到所述蜜罐接口服务器的页面行为录制指令、或者所述监控端设备的页面行为录制指令、或者是响应信息中的脚本中所携带的页面行为录制指令等,采集所述页面行为信息。比如,所述监控端设备与所述蜜罐接口服务器通信连接,工作人员在监控端设备中设置了自动录制,则蜜罐接口服务器在获得该设置的情况下,在与第一目标攻击者设备连接之后,可向第一目标攻击者设备发送页面录制指令,以使第一目标攻击者设置持续采集页面行为信息。

[0079] 其中,所述页面行为信息中的页面信息可以包括浏览器DOM(Document ObjectModel,文档对象模型) / Style数据内容。浏览器的页面内容和样式是HTML和CSS代码组成的。DOM指HTML,Style指CSS。相当于将第一目标攻击者设备的页面当时的HTML和CSS代码导出来保存,后续可以通过这两者内容重新渲染出一样的页面内容。

[0080] 所述页面行为信息中的行为信息可以包括鼠标事件、键盘事件及窗口事件中的至少一项。其中,所述窗口事件可以包括:页面上的滚动、页面的放大、页面的缩小、对输入框输入了内容等等。

[0081] 虽然通过后端接口可以大致记录攻击者在客户端的操作,但是如果是不会产生接口调用的行为(例如在前端的交互动作),将无法通过后端监控到该行为。但本申请通过使所述第一目标攻击者设备自身去监听鼠标事件、键盘事件及窗口事件,则可以使得可以监控到攻击者在前端的交互动作。

[0082] 其中,所述行为信息的具体种类,可以是所述代码中预先指定好的,也可以是其他的设备控制所述第一目标攻击者设备进行页面行为信息采集时指定的。

[0083] 作为一种可能的实现方式,所述行为信息包括鼠标事件、键盘事件及窗口事件。如此,攻击者攻击设备上的所有操作都可以被监控端的工作人员查看到,包括攻击者在前端界面上的交互动作。

[0084] 可选地,所述第一目标攻击者设备可以按照一定频率进行页面行为信息的采集,也可以在监控到渲染内容变化或被事件触发时执行页面行为信息的采集,只要保证渲染内容变化或被事件触发对应的页面行为信息被发送给所述监控端设备即可。

[0085] 所述监控端设备在接收到所述第一目标攻击者设备发送的页面行为信息之后,可以根据所述页面行为信息中的页面信息,将所述第一目标攻击者设备页面内容绘制到所述监控端设备的页面上,并同时展示所述页面行为信息中的行为信息。其中,所述行为信息的具体展示方式可以结合实际需求设置。

[0086] 例如,在所述行为信息中包括鼠标事件时,所述鼠标事件中至少包括鼠标指针的位置,可以将所述监控端设备显示所述第一目标攻击者设备的页面内容的页面上,展示鼠标指针位置。在所述行为信息中包括键盘事件时,所述键盘事件可以包括攻击者在键盘上按过的按键,可以在所述监控端设备显示所述第一目标攻击者设备的页面内容的页面上,展示被按过的按键图标,比如,假设攻击者按了控制按键ctrl,则将ctrl的图标显示在所述监控端设备显示所述第一目标攻击者设备的页面内容的页面上。在攻击者按过的按键有多个的情况下,还可以按照按键被按的先后顺序控制按键图像在所述监控端设备的页面上的排列顺序,以向监控端设备的工作人员展示出按键被按的先后顺序,具体可以按照实际需求设置。

[0087] 请参照图6,图6为本申请实施例提供的攻击行为处理方法的流程示意图之四。在本实施例中,所述方法还可以包括步骤S151及步骤S152。

[0088] 步骤S151,在检测到远程控制选项被选择的情况下,根据接收到的控制操作获得控制指令。

[0089] 步骤S152,将所述控制指令发送给所述第一目标攻击者设备,以使所述第一目标攻击者设备的页面上显示出与所述控制指令对应的控制效果。

[0090] 在本实施例中,所述监控端设备的页面上还可以显示有一远程控制选项。该远程控制选项可以是一个页面按钮,也可以是某菜单内的选项等,具体可以结合实际需求设置。监控端设备处的工作人员在需要对第一目标攻击者设备进行远程控制时,可选择该远程控制选项,然后工作人员可输入与控制指令对应的控制操作。在该远程控制选项被选择的情况下,所述监控端设备可以根据接收到的工作人员输入的控制操作,确定出所述控制指令。其中,所述控制指令中包括目标操作对象及对应的目标动作,所述目标操作对象为所述第一目标攻击者设备的页面中的元素,所述目标动作可以包括点击按钮、滚动列表、下拉选择等操作。

[0091] 可选地,可以通过绑定监控端设备的鼠标和键盘事件的监听,以确定出监控端设备处的工作人员点击和操作了监控页面中的哪些元素以及这些元素对应的动作(比如,点击,或者具体的操作方式),进而确定出所述控制指令,便于后续通过向所述第一目标攻击者设备发送控制指令,以向所述第一目标攻击者设备下发操作对象(即元素)及动作。

[0092] 所述第一目标攻击者设备在接收到所述控制指令后,可以在第一目标攻击者设备的对应页面元素上,利用dispatchEvent接口将所述控制指令描述的事件在攻击者端浏览器触发,从而在所述第一目标攻击者设备的页面上显示出与所述控制指令对应的控制效果。由此,可实现远程操作,进而中断或影响攻击者的攻击动作。

[0093] 请参照图7,图7为本申请实施例提供的攻击行为处理方法的流程示意图之五。在本实施例中,所述方法还可以包括步骤S161及步骤S162。

[0094] 步骤S161,在检测到内容标注选项被选择的情况下,根据接收到的标注操作获得标注指令。

[0095] 步骤S162,将所述标注指令发送给所述第一目标攻击者设备,以使所述第一目标攻击者设备的页面上显示出与所述标注指令对应的标注效果。

[0096] 在本实施例中,所述监控端设备的页面上还可以显示有一内容标注选项。该内容标注选项可以是一个页面按钮,也可以某菜单内的选项等,具体可以结合实际需求设置。监控端设备处的工作人员在需要在第一目标攻击设备的页面上进行标注时,可以选择该内容标注选项,然后工作人员可输入相应的标注操作。在该内容标注选项被选择的情况下,所述监控端设备可以根据接收到的工作人员输入的标注操作,确定出所述标注指令。其中,所述标注指令包括标注内容,所述标注内容可以是文字和 / 或图片等。

[0097] 可选地,所述标注指令中还可以包括所述标注内容对应的位置、样式等。所述第一目标攻击者设备在接收到所述标注指令后,可以将所述标注指令中包括的文字和图片,以相应的样式和位置展示到所述第一目标攻击者设备的页面中,以达到警告和威慑的作用。

[0098] 请参照图8,图8为本申请实施例提供的攻击行为处理方法的流程示意图之六。在本实施例中,所述方法还可以包括步骤S170。

[0099] 步骤S170,向所述蜜罐接口服务器发送回放指令和 / 或下载指令。

[0100] 在本实施例中,所述蜜罐接口服务器中可以保存多个攻击者设备发送的页面行为信息,也即,各攻击者设备在接收到得到响应信息中包括用于使攻击者设备与其他设备通信的脚本的情况下,会持续采集到页面行为信息,并将持续采集到的页面行为信息发送到所述蜜罐接口服务器进行保存。

[0101] 其中,可选地,作为一种可能的实现方式,所述其他设备包括所述蜜罐接口服务器,也即,响应信息中的脚本被攻击者设备执行之后,攻击者设备会直接将采集到的页面行为信息发送给所述蜜罐接口服务器进行保存。

[0102] 可选地,作为另一种可能的实现方式,所述其他设备为另外的设备,另外设备可以将接收到的由攻击者设备发送的页面行为信息发送给所述蜜罐接口服务器进行保存。值得说明的是,蜜罐接口服务器获得各攻击者设备的页面行为信息的上述方式仅为举例说明,蜜罐接口服务器也可以通过其他方式获得并保存各攻击者设备的页面行为信息。

[0103] 所述监控端设备处的工作人员还可以结合实际需求回放某攻击者之前的攻击动作,和 / 或,下载某攻击者之前的攻击行为情况以作为攻击行为证据。在有回放和 / 或下载的需求的情况下,所述监控端设备可以向所述蜜罐接口服务器发送回放指令和 / 或下载指令。其中,所述回放指令中至少包括第二目标攻击者设备的设备标注,以用于通过所述蜜罐接口服务器回放第二目标攻击者设备的页面行为;所述下载指令中至少包括第二目标攻击者设备的设备标注,以用于从所述蜜罐接口服务器处下载第二目标攻击者设备的页面行为信息。

[0104] 可选地,所述回放指令中还可以包括回放开始时刻,用于指示从哪个时刻开始进行攻击动作的回放。所述回放指令中还可以回放停止时刻,以便于确定何时停止回放。所述下载指令中还可以包括下载时间段,以便确定出需要下载的第二目标攻击者设备的页面行为信息对应的时间端。如此,工作人员可以选取之前的时间点,回看之前的攻击工作;还可以选取一个时间端,下载这段时间的录制,作为攻击行为证据。

[0105] 本申请实施例提供的攻击行为处理方法,可对实时攻击者页面进行页面监控、录制、远程控制、页面内容标注、回放及下载取整等,从而使得能够通过一种更加直观的方案分析和取证攻击者的攻击行为。在本实施例中,给访问Web蜜罐的攻击者浏览器注入JavaScript脚本,该脚本可获取浏览器DOM / Style数据内容,监听浏览器鼠标和键盘相关事件,并实时上报给管理端和 / 或监控端。之后,可将页面数据内容,重绘到监控端浏览器中,实时播放给监控端处的工作人员,此时监控端处的工作人员可以看到攻击者正在访问页面的所有交互。还可以向监控端提供回放、下载取证、远程控制、页面内容标注等相关操作功能。

[0106] 下面结合图9及图10,对上述攻击行为处理方法进行举例说明。

[0107] 如图9所示,通信系统包括:攻击者端、蜜罐网关、蜜罐系统所在的蜜罐设备、蜜罐API服务器(即前文的蜜罐接口服务器)以及监控端。

[0108] 首先结合图9,对如何向攻击者端注入脚本以及攻击者端如何与监控端建立P2P通道进行说明。

[0109] S1.攻击者端访问某Web蜜罐。访问Web蜜罐的流量统一经过蜜罐网关处理,蜜罐网关中的网卡可以对经过的流量进行修改和控制。

[0110] S2.蜜罐网关在确定攻击者端请求的是html内容时,自动给被访问的蜜罐所响应的html中注入一段<script>标签代码,然后发送给攻击者端。

[0111] S3.攻击者端根据接收到的html内容进行页面渲染,以显示相应的网页;添加的<script>标签代码被加载到攻击者端的浏览器中,然后被执行,以便与后续对攻击者端的浏览器的API事件和鼠标键盘等时间进行监听及控制等。

[0112] S4.注入的代码被执行后,与蜜罐API服务器建立通信,之后可接收到蜜罐API下发的指令。其中,下发的指令可以包括页面录制指令等。代码在接收到页面录制指令之后,会实时获取页面的DOM / Style数据及攻击者的行为信息等以得到页面行为信息,并上报给蜜罐API服务器,如此相当于将实时变化的页面及相应的攻击者行为组成可回放的视频。其中,蜜罐API服务器获得的是一帧帧的页面及相应的行为,并不是视频格式的视频。

[0113] S5.蜜罐API服务器可确定为活动中的攻击者端,并将活动中的攻击者端告知给监控端管理员;如果管理员点击查看和控制某位攻击者,则从监控端发起指令监控当前攻击者页面(即监控攻击者打开的Web仿真系统页面),此时蜜罐API也会下发指令给被管理员选中的攻击者端准备与监控端建立P2P连接。其中,注入的JavaScript代码被执行了,就说明这是一个正在活跃的攻击者;代码加载到浏览器被运行起来了就会上报给蜜罐API服务器,蜜罐API服务器将其标记为活跃状态。

[0114] S6.攻击者端和监控端分别请求STUN服务器,获取本机的设备网络出口信息,以便建立P2P通信。

[0115] S7.攻击者端和监控端通过蜜罐API服务器交换设备网络出口信息。

[0116] S8.交换设备网络出口信息后,攻击者端和监控端建立WebRTC数据通道,攻击者端实时接收监控端数据指令。

[0117] 下面结合图10对攻击者与管理端的交互流程进行说明。

[0118] 攻击者端打开页面初始化的流程如下:

[0119] 执行注入的JavaScript脚本,监听并接收蜜罐API服务器数据指令;

[0120] 在接收到蜜罐API服务器的以页面录制指令的情况下,绑定鼠标、键盘、窗口事件监听,实时将行为上报给蜜罐API服务器;以及实时获取页面DOM / Style数据上报到蜜罐API服务器,最终可将实时变化的页面组成可回放的视频。

[0121] 在监控端进行监控的情况下,攻击者端还可以通过与监控端之间的P2P数据通信,将监听到的事件及获取的页面DOM / Style数据,发送给所述监控端;所述监控端则将接收到的页面内容绘制到监控端页面上,同时展示鼠标指针的位置、攻击者按钮的按钮、发生的窗口事件等。其中,只要攻击者端的渲染内容变化或者触发了事件,变化的内容及触发的事件均会被发送给监控端。如果攻击者端的页面一直不断拜年话,则实时更新到监控端。

[0122] 监控端远程控制的流程如下:

[0123] 监控端发起与攻击者端的P2P数据通道,监控端可实时下发指令给攻击者端。监控端实时获取攻击者端的页面数据,不断更新渲染到监控端的界面上实现页面监控。如果监控端的管理员点击了监控端上的远程控制按钮,监控端则监听管理端鼠标和键盘事件,以监听管理员对监控页面中的元素的点击和操作,从而确定出控制指令。该控制指令指示了操作的元素及具体的操作。监控端将控制指令发送给攻击者端。攻击者端在接收到控制之后,在攻击者端对应页面元素上,利用dispatchEvent接口将事件在攻击者端浏览器触发。由可实现远程操作,进而中断或影响攻击者的攻击动作。

[0124] 监控端内容标注的流程如下:

[0125] 监控端发起与攻击者端的P2P数据通道,监控端可实时下发指令给攻击者端。监控端实时获取攻击者端的页面数据,不断更新渲染到监控端的界面上实现页面监控。如果监控端的管理员点击了监控端上的内容标注按钮,管理员可选择和填入文本和图片内容,并将内容拖动到监控页面某位置,之后监控端自动将文本图片、位置和样式下发给攻击者端。攻击者端接收到数据,将文字和图片以相应样式和位置展示页面中,以达到警告和威慑作用。

[0126] 监控端还可以与蜜罐API服务器进行如下交互:

[0127] 回放:针对某攻击者端,选取之前的时间点,会看之前的攻击动作。也即,蜜罐API服务器基于存储的攻击者端的页面行为信息,向监控端提供回放服务。

[0128] 下载取证:针对某攻击者端,选择一个时间段,下载这段时间的录制,作为攻击行为证据。也即,蜜罐API服务器基于存储的攻击者端的页面行为信息,向监控端提供下载取证服务。

[0129] 其中,上述举例中的P2P的数据通道提供了更加实时的交互体验效果。但是,值得说明的是,上述举例中的P2P技术,可以使用中转设备替代,可实现同样的上报和下发指令的管理。

[0130] 本申请实施例提供的攻击行为处理方法,可以使监控者查看对方网页页面内容,并直观精确的查看到攻击者的动作行为;还可以通过录制页面内容以进行取证及回放等;以及,还可以通过远程控制中断和影响攻击者的攻击操作;并且,可以通过在攻击者端网页标注文本和图片,对攻击者进行告警和震慑。

[0131] 请参照图11,图11为本申请实施例提供的攻击行为处理方法的流程示意图之七。图11所示的攻击行为处理方法应用于通信系统,所述通信系统包括攻击者设备就监控端设备,所述方法可以包括步骤S210~步骤S230。

[0132] 步骤S210,所述攻击者设备向蜜罐发送网页请求,并接收蜜罐的响应信息。

[0133] 其中,所述响应信息中包括用于使所述攻击者设备与其他设备通信的脚本。

[0134] 步骤S220,所述攻击者设备向所述监控端设备实时发送页面行为信息。

[0135] 其中,所述页面行为信息包括页面信息及攻击者的行为信息,所述页面信息用于描述所述攻击者设备的显示页面,所述行为信息用于描述攻击者在所述攻击者设备上的操作。

[0136] 步骤S230,所述监控端设备根据所述页面信息,将所述攻击者设备的页面内容绘制到所述监控端设备的页面上,并同时展示所述行为信息。

[0137] 请参照图12,图12为本申请实施例提供的攻击行为处理方法的流程示意图之八。在本实施例中,所述其他设备包括蜜罐接口服务器,所述方法还包括步骤S241~步骤S243。

[0138] 步骤S241,所述蜜罐接口服务器向所述攻击者设备发送页面行为录制指令。

[0139] 步骤S242,所述攻击者设备在接收到所述页面行为录制指令后,将所述页面行为信息发送给所述蜜罐接口服务器;

[0140] 步骤S243,所述蜜罐接口服务器对接收到的页面行为信息进行保存,以基于保存的页面行为信息向所述监控端设备提供回放和 / 或下载服务。

[0141] 在本实施例中,关于应用于通信系统的攻击行为处理方法的具体说明可以参照上文对应用于监控端设备的攻击行为处理方法的说明,在此不再赘述。

[0142] 为了执行上述实施例及各个可能的方式中的相应步骤,下面给出一种攻击行为处理装置200的实现方式,可选地,该攻击行为处理装置200可以采用上述图2所示的电子设备100的器件结构。进一步地,请参照图13,图13为本申请实施例提供的攻击行为处理装置200的方框示意图。需要说明的是,本实施例所提供的攻击行为处理装置200,其基本原理及产生的技术效果和上述实施例相同,为简要描述,本实施例部分未提及之处,可参考上述的实施例中相应内容。在本实施例中,所述攻击行为处理装置200可以应用于监控端设备,所述攻击行为处理装置200可以包括:信息接收模块210及处理模块220。

[0143] 所述信息接收模块210,用于接收第一目标攻击者设备在接收到蜜罐的响应信息后实时发送的页面行为信息。

[0144] 其中,所述响应信息中包括用于使所述第一目标攻击者设备与其他设备通信的脚本,所述页面行为信息包括页面信息及攻击者的行为信息,所述页面信息用于描述所述第一目标攻击者设备的显示页面,所述行为信息用于描述攻击者在所述第一目标攻击者设备上的操作。

[0145] 所述处理模块220,用于根据所述页面信息,将所述第一目标攻击者设备的页面内容绘制到所述监控端设备的页面上,并同时展示所述行为信息。

[0146] 可选地,上述模块可以软件或固件(Firmware)的形式存储于图2所示的存储器110中或固化于攻击行为处理装置200的操作系统(Operating System,OS)中,并可由图2中的处理器120执行。同时,执行上述模块所需的数据、程序的代码等可以存储在存储器110中。

[0147] 本申请实施例还提供一种可读存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现所述的攻击行为处理方法。

[0148] 综上所述,本申请实施例提供一种攻击行为处理方法、装置、电子设备及可读存储介质,监控端设备接收第一目标攻击者设备在接收到蜜罐的响应信息后实时发送的页面行为信息,并根据页面行为信息中的页面信息,将所述第一目标攻击者设备的页面内容绘制到所述监控端设备的页面上,并同时展示页面行为信息中的行为信息。其中,响应信息中包括用于使所述第一目标攻击者设备与其他设备通信的脚本,页面信息用于描述所述第一目标攻击者设备的显示页面,所述行为信息用于描述攻击者在所述第一目标攻击者设备上的操作。如此,能够让监控者实时、直观地查看到攻击者的客户端的显示页面以及攻击者在客户端的操作。

[0149] 在本申请所提供的几个实施例中,应该理解到,所揭露的装置和方法,也可以通过其它的方式实现。以上所描述的装置实施例仅仅是示意性的,例如,附图中的流程图和框图显示了根据本申请的多个实施例的装置、方法和计算机程序产品的可能实现的体系架构、功能和操作。在这点上,流程图或框图中的每个方框可以代表一个模块、程序段或代码的一部分,所述模块、程序段或代码的一部分包含一个或多个用于实现规定的逻辑功能的可执行指令。也应当注意,在有些作为替换的实现方式中,方框中所标注的功能也可以以不同于附图中所标注的顺序发生。例如,两个连续的方框实际上可以基本并行地执行,它们有时也可以按相反的顺序执行,这依所涉及的功能而定。也要注意的是,框图和 / 或流程图中的每个方框、以及框图和 / 或流程图中的方框的组合,可以用执行规定的功能或动作的专用的基于硬件的系统来实现,或者可以用专用硬件与计算机指令的组合来实现。

[0150] 另外,在本申请各个实施例中的各功能模块可以集成在一起形成一个独立的部分,也可以是各个模块单独存在,也可以两个或两个以上模块集成形成一个独立的部分。

[0151] 所述功能如果以软件功能模块的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。

[0152] 以上所述仅为本申请的可选实施例而已,并不用于限制本申请,对于本领域的技术人员来说,本申请可以有各种更改和变化。凡在本申请的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本申请的保护范围之内。< / script>

Claims

1. A method for processing attack behavior, characterized in that: Applied to a monitoring terminal device, the method includes: Obtain the first device egress network information corresponding to the local device from the STUN server; Obtaining second device egress network information of the first target attacker device by exchanging device egress network information between the honeypot interface server and the first target attacker device, wherein the second device egress network information is obtained by the first target attacker device from the STUN server and sent to the honeypot interface server; Establishing a WebRTC connection with the first target attacker device according to the second device egress network information to transmit page behavior information; Receiving the page behavior information sent in real time by the first target attacker device after receiving the response information from the honeypot, wherein the response information includes a script for enabling the first target attacker device to communicate with the honeypot interface server, and the page behavior information includes page information and attacker behavior information, the page information is used to describe the display page of the first target attacker device, and the behavior information is used to describe the attacker's operation on the first target attacker device; Based on the page information, the page content of the first target attacker device is drawn onto the page of the monitoring end device, and the behavior information is displayed at the same time, so that the monitor can intuitively view the display page of the attacker's client and the attacker's operations on the client in real time.

2. The method according to claim 1, characterized in that The behavior information includes at least one of a mouse event, a keyboard event, and a window event.

3. The method according to claim 1, characterized in that The method further comprises: When detecting that the remote control option is selected, obtaining a control instruction according to the received control operation, wherein the control instruction includes a target operation object and a corresponding target action, and the target operation object is an element in the page of the first target attacker device; The control instruction is sent to the first target attacker device, so that a control effect corresponding to the control instruction is displayed on a page of the first target attacker device.

4. The method according to claim 1, wherein The method further comprises: When detecting that the content annotation option is selected, obtaining an annotation instruction according to the received annotation operation, wherein the annotation instruction includes the annotation content; The annotation instruction is sent to the first target attacker device, so that a annotation effect corresponding to the annotation instruction is displayed on a page of the first target attacker device.

5. The method according to claim 1, wherein The honeypot interface server stores page behavior information sent by the attacker's device. The method further includes: Send a playback instruction and / or a download instruction to the honeypot interface server, wherein the playback instruction is used to replay the page behavior of the second target attacker device through the honeypot interface server, and the download instruction is used to download the page behavior information of the second target attacker device from the honeypot interface server.

6. The method according to claim 1, characterized in that Before receiving the page behavior information sent in real time by the first target attacker device after receiving the response information from the honeypot, the method further includes: Display active attacker devices, wherein the active attacker device is the attacker device where the executed script is located, the attacker device is a device communicating with the honeypot, and the response information received by the attacker device from the honeypot includes the script; According to the received attacker selection operation, the first target attacker device is determined from active attacker devices.

7. An attack behavior processing device, characterized in that: Applied to monitoring terminal equipment, the device includes: An information receiving module is configured to receive page behavior information sent in real time by the first target attacker device after receiving response information from the honeypot, wherein the response information includes a script for enabling the first target attacker device to communicate with the honeypot interface server, the page behavior information includes page information and attacker behavior information, the page information is used to describe the display page of the first target attacker device, and the behavior information is used to describe the attacker's operations on the first target attacker device; a processing module, configured to draw the page content of the first target attacker device onto a page of the monitoring terminal device based on the page information, and simultaneously display the behavior information, so that the monitor can intuitively view the display page of the attacker's client and the attacker's operations on the client in real time; Before receiving the page behavior information sent in real time by the first target attacker device after receiving the response information of the honeypot, the device also includes: obtaining the first device exit network information corresponding to the local device from the STUN server; obtaining the second device exit network information of the first target attacker device by exchanging the device exit network information with the first target attacker device through the honeypot interface server, wherein the second device exit network information is obtained by the first target attacker device from the STUN server and sent to the honeypot interface server; and establishing a WebRTC connection with the first target attacker device according to the second device exit network information to transmit the page behavior information.

Citation Information

Patent Citations

  • Web attack behavior detection method and system

    CN112134837A

  • Active-protection webpage security protection device

    CN113918946A