A network protection method, device, equipment and storage medium
By employing version-specific rule matching based on processor load and server component versions, the method addresses WAF performance bottlenecks, reducing resource usage and enhancing detection efficiency in Web security.
Patent Information
- Application Number
- CN202310111646.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-16
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2043-01-16
AI Technical Summary
Existing Web Application Firewalls (WAFs) face performance bottlenecks when large rule sets are used, leading to resource exhaustion and potential failure to detect malicious attacks due to rule matching limitations.
Implement a method that first performs full rule set matching and then sends probe packets to determine server component versions, switching to precise matching based on processor load and server component versions to reduce resource usage and enhance detection efficiency.
This approach reduces system resource consumption and enhances network security by minimizing false negatives in attack detection, ensuring efficient and effective protection against malicious requests.
Smart Images

Figure CN116260635B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to a network protection method, device, equipment and storage medium. Background Art
[0002] Web attacks are attacks on users' Internet access or devices such as website servers. They are carried out through attacks such as xss (Cross Site Scripting), csrf (Cross-site request forgery), and sql (Structured Query Language) injection. They can implant malicious code, modify website permissions, obtain website users' private information, and other malicious intrusions. The security of Web applications is an important part of any Web-based business, so it is very important to ensure the security of Web applications.
[0003] In the prior art, for malicious Web attacks, a dedicated WAF (Web Application Firewall) security protection product is generally used for security protection. The existing WAF security protection product is deployed in the front-end network of the protected server. Malicious attack messages will first pass through the WAF product. After receiving the attack message, the WAF product will identify the attack characteristics of various web attack messages and match them with the built-in security protection rule library. Once the match hits the rule, it is considered to be a malicious attack request, triggering security protection, intercepting malicious messages, and protecting the back-end network server from security attacks. However, when the attack protection rule library is too large, rule matching will consume a lot of resources. Once the attack frequency exceeds the performance upper limit of the WAF security protection product matching, it will cause the attack message to be missed, bringing network security risks. Summary of the invention
[0004] In view of this, the purpose of the present invention is to provide a network protection method, device, equipment and storage medium, which can enable accurate matching for the current server component version according to the processor resource occupancy, and use the protection rule library corresponding to the current server component version to match malicious attack messages, which can effectively save system resources, effectively improve network security efficiency and avoid the problem of missing protection when the protection performance is insufficient. The specific scheme is as follows:
[0005] In the first aspect, the present application discloses a network protection method, which is applied to a server front end, comprising:
[0006] Enable full match protection based on all protection rule libraries, and send a probe message to the server through a preset probe message sending rule, so that the server returns a corresponding response message according to the probe message, and determines the component version information of the server based on the response message;
[0007] Determine whether the processor resource usage is greater than a preset first resource usage threshold;
[0008] If so, then based on the component version information, accurate matching protection for the server is enabled, and after receiving the network request, the network request is accurately matched based on the target protection rule base to determine the matching result; the target protection rule base is a rule base corresponding to the component version information;
[0009] If the matching result indicates a successful match, the network request is determined to be a malicious request, and the network request is blocked.
[0010] Optionally, before enabling full match protection based on all protection rule bases and sending a detection message to the server according to a preset detection message sending rule, the method further includes:
[0011] A plurality of detection messages are generated, a detection message library is generated based on the plurality of detection messages, and a plurality of corresponding protection rule libraries are generated based on different component version information of the server.
[0012] Optionally, sending a probe message to a server according to a preset probe message sending rule so that the server returns a corresponding response message according to the probe message, and determining the component version information of the server based on the response message includes:
[0013] Sending a detection message in the detection message library to the server based on a preset detection message sending rule, so that the server returns a corresponding response message based on the detection message;
[0014] The response message is received, and the database version, system version, and structs framework version of the server are determined according to the characteristic information in the response message.
[0015] Optionally, the sending the detection message in the detection message library to the server based on a preset detection message sending rule so that the server returns a corresponding response message based on the detection message, includes:
[0016] Sending a single detection message to the server based on a detection sending rule, and determining whether the version information of the server can be determined from a response message returned by the server based on the single detection message;
[0017] If not, a combined detection message including multiple detection messages is sent to the server based on the combined detection sending rule, so as to determine the version information of the server from a response message returned by the server based on the combined message.
[0018] Optionally, enabling accurate matching protection for the server based on the component version information, and after receiving the network request, accurately matching the network request based on a target protection rule library to determine a matching result, includes:
[0019] Determine the target protection rule base based on the database version, the system version, and the structs framework version, and enable precise matching protection for the server;
[0020] Determine whether a network request is received, and if so, accurately match the network request based on the target protection rule library to determine a matching result.
[0021] Optionally, enabling accurate matching protection for the server based on the component version information includes:
[0022] Determine whether the processor resource usage is greater than a preset second resource usage threshold;
[0023] If not, enable accurate matching protection for the server based on the component version information;
[0024] If so, an automatic release operation is triggered, and after receiving the network request, an automatic release operation is performed on the to-be-matched network request to alleviate the resource occupation of the own processor.
[0025] Optionally, if the matching result indicates a successful match, determining that the network request is a malicious request and blocking the network request further includes:
[0026] Malicious requests that have not been successfully blocked are collected, and the malicious requests that have not been successfully blocked are added to a protection rule base to update the protection rule base.
[0027] In a second aspect, the present application discloses a network protection device, comprising:
[0028] A version determination module, used to enable full match protection based on all protection rule libraries, and send a detection message to the server through a preset detection message sending rule, so that the server returns a corresponding response message according to the detection message, and determines the component version information of the server based on the response message;
[0029] A threshold determination module, used to determine whether the resource occupation of its own processor is greater than a preset first resource occupation threshold;
[0030] a matching result determination module, configured to enable accurate matching protection for the server based on the component version information if the processor resource usage is greater than the first resource usage threshold, and to accurately match the network request based on a target protection rule base after receiving the network request to determine a matching result; the target protection rule base is a rule base corresponding to the component version information;
[0031] The request blocking module is used to determine that the network request is a malicious request and block the network request if the matching result indicates a successful match.
[0032] In a third aspect, the present application discloses an electronic device, comprising:
[0033] Memory, used to store computer programs;
[0034] A processor is used to execute the computer program to implement the network protection method as described above.
[0035] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the network protection method as described above.
[0036] In this application, first, full match protection is enabled based on all protection rule libraries, and a detection message is sent to the server through a preset detection message sending rule, so that the server returns a corresponding response message according to the detection message, and determines the component version information of the server based on the response message, and then determines whether its own processor resource occupancy is greater than the preset first resource occupancy threshold. If its own processor resource occupancy is greater than the first resource occupancy threshold, then based on the component version information, enable precise match protection for the server, and after receiving the network request, perform precise matching on the network request based on the target protection rule library to determine the matching result. The target protection rule library is a rule library corresponding to the component version information, and if the matching result indicates a successful match, the network request is determined to be a malicious request, and the network request is blocked. It can be seen that, using the network protection method described in this application, a detection message can be sent to the server after enabling full match protection, and the component version information of the server can be determined according to the response message returned by the server, and then the precise matching for the server version can be enabled according to the occupancy of its own processor resources. Enable precise matching and match protection according to the protection rule library corresponding to the server component version information. In this way, by matching malicious attack messages with the protection rule library corresponding to the current server component version, system resources can be effectively saved, network security efficiency can be effectively improved, and the problem of missing defenses when protection performance is insufficient can be avoided. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0038] Figure 1 A flow chart of a network protection method provided for this application;
[0039] Figure 2 A specific network protection method flow chart provided for this application;
[0040] Figure 3 A message matching schematic diagram provided for this application;
[0041] Figure 4 A specific network protection method flow chart provided for this application;
[0042] Figure 5 A schematic diagram of the structure of a network protection device provided for this application;
[0043] Figure 6 A structural diagram of an electronic device provided for this application. DETAILED DESCRIPTION
[0044] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0045] In the prior art, for malicious Web attacks, a dedicated WAF (Web Application Firewall) security protection product is generally used for security protection. The existing WAF security protection product is deployed in the front-end network of the protected server. Malicious attack messages will first pass through the WAF product. After receiving the attack message, the WAF product will identify the attack characteristics of various web attack messages and match them with the built-in security protection rule library. Once the match hits the rule, it is considered to be a malicious attack request, triggering security protection, intercepting malicious messages, and protecting the back-end network server from security attacks. However, when the attack protection rule library is too large, rule matching will consume a lot of resources. Once the attack frequency exceeds the performance upper limit of the WAF security protection product matching, it will cause the attack message to be missed, bringing network security risks.
[0046] In order to overcome the above-mentioned technical problems, the present application provides a network protection method, which can enable precise matching for the current server component version according to its own processor resource occupancy, and use the protection rule library corresponding to the current server component version to match malicious attack messages, which can effectively save system resources, effectively improve network security efficiency and avoid the problem of missing protection when the protection performance is insufficient.
[0047] See also Figure 1 As shown, an embodiment of the present invention discloses a network protection method, which is applied to a server front end, including:
[0048] Step S11, enable full match protection based on all protection rule libraries, and send a probe message to the server through a preset probe message sending rule, so that the server returns a corresponding response message according to the probe message, and determines the component version information of the server based on the response message.
[0049] In this embodiment, full match protection is enabled based on all protection rule libraries, and a probe message is sent to the server through a preset probe message sending rule, so that the server returns a corresponding response message according to the probe message, and the component version information of the server is determined based on the response message. That is, after network protection is enabled, full match protection is first enabled based on all pre-created protection libraries, that is, after receiving a network request, the network request is matched in all the protection libraries, and then after full match protection is enabled, a single probe message in the probe message library is sent to the server one by one according to the preset probe message sending rule. If the response message returned by the server based on the single probe message does not meet the requirements, a combined message in the probe message library is sent to the server, so that the server returns a corresponding response message according to the combined message. After receiving the response message, the component version information of the server, such as the database version, system version, and structs framework version, can be determined based on the response message.
[0050] It should be noted that, based on all protection rule libraries, full match protection is enabled, and before sending a probe message to the server through a preset probe message sending rule, it also includes: generating a number of probe messages, generating a probe message library based on the several probe messages, and generating a number of corresponding protection rule libraries based on different component version information of the server. That is, according to the network protection method in this application, before sending a probe message to the server, a special probe message library will be established and maintained in the detection engine of the waf product in advance, and the probe message will be sent to the server periodically according to the probe message sending rule, and various component version information of the server will be collected, and corresponding different protection rule libraries will be created according to different component versions, so that the network request can be matched using the created protection rule library after receiving the network request.
[0051] Step S12: determine whether the resource occupation of the processor itself is greater than a preset first resource occupation threshold.
[0052] In this embodiment, after receiving the corresponding response message returned by the server according to the sent detection message, and determining the component version information of the server according to the response message, it is necessary to determine whether the processor resource occupancy reaches the preset first resource occupancy threshold, so as to determine whether to enable the precise matching protection for the server version. It should be noted that the first resource occupancy threshold can be set according to user needs, or can be set according to the system preset threshold, for example, the first resource occupancy threshold can be set to CPU occupancy reaching 50%.
[0053] Step S13: If the processor resource occupancy is greater than the first resource occupancy threshold, precise matching protection for the server is enabled based on the component version information, and after receiving the network request, the network request is precisely matched based on the target protection rule library to determine the matching result; the target protection rule library is a rule library corresponding to the component version information.
[0054] In this embodiment, if the processor resource usage is greater than the first resource usage threshold, accurate matching protection for the server is enabled based on the component version information, and after receiving the network request, the network request is accurately matched based on the target protection rule library to determine the matching result. That is, if the processor resource usage is greater than the first resource usage threshold set by the user, or greater than the first resource usage threshold preset by the system, accurate matching protection for the server component version is enabled based on the server component version information determined based on the response message returned by the server using the protection library corresponding to the server component version information. For example, if the database type of the server is mysql, the system version is win10, and the structs framework version is structs2.4, then after receiving a network request for the server, only the rule base with the database version of mysql, the windows system version not less than win10, and the structs framework version not less than structs2.4 is used for matching, and other database components, windows system versions lower than win10 or other system versions, and structs framework versions lower than structs2.4 are no longer matched. If the database type of the server is pg database, the system version is linux7.5, and the structs framework version is structs2.5, only the rule base with the database version of pg, the linux system version not less than linux7.5, and the structs framework version not less than 2.5 is used for matching, and other sql components, windows, linux versions lower than linux7.5, and structs framework versions lower than structs2.5 are no longer matched. In this way, the number of rules that need to be matched can be reduced, effectively saving system resources.
[0055] Step S14: If the matching result indicates a successful match, the network request is determined to be a malicious request, and the network request is blocked.
[0056] In this embodiment, if the matching result indicates a successful match, the network request is determined to be a malicious request and the network request is blocked. That is, if the received network request successfully matches the protection rule library, the network request is characterized as a request to initiate a malicious attack, and the network request can be blocked to protect the server.
[0057] It can be seen that in this embodiment, firstly, full match protection is enabled based on all protection rule bases, and a detection message is sent to the server through a preset detection message sending rule, so that the server returns a corresponding response message according to the detection message, and determines the component version information of the server based on the response message, and then determines whether the processor resource occupancy is greater than the preset first resource occupancy threshold. If the processor resource occupancy is greater than the first resource occupancy threshold, then based on the component version information, accurate matching protection for the server is enabled, and after receiving the network request, the network request is accurately matched based on the target protection rule base to determine the matching result. The target protection rule base is a rule base corresponding to the component version information, and if the matching result indicates a successful match, the network request is determined to be a malicious request, and the network request is blocked. It can be seen that, using the network protection method described in this application, a detection message can be sent to the server after enabling full match protection, and the component version information of the server can be determined according to the response message returned by the server, and then the accurate matching for the server version can be enabled according to the processor resource occupancy. The accurate matching can be enabled according to the protection rule base corresponding to the server component version information. Matching protection. In this way, for the protected objects, the information characteristics of the protected objects can be identified and collected in advance, and the protection rules can be customized for matching, reducing the number of protection rules that need to be matched. This can effectively improve the matching performance, solve the problem of missed protection when the protection performance is insufficient, save system resources and improve the network security protection rate.
[0058] Based on the previous embodiment, it can be seen that in this application, it is necessary to send a detection message to the server according to the preset message sending rules, and it is necessary to enable exact matching according to the server component version information. For this reason, this embodiment describes in detail how to send a detection message to the server according to the preset message sending rules and how to enable exact matching. Figure 2 As shown, an embodiment of the present invention discloses a network protection method, including:
[0059] Step S21: Enable full match protection based on all protection rule libraries, and send a detection message in the detection message library to the server based on a preset detection message sending rule, so that the server returns a corresponding response message based on the detection message.
[0060] In this embodiment, after the WAF product is running, full match protection based on all protection rule bases will be enabled first, and Figure 3 As shown, a detection message in a detection message library is sent to a server according to a preset message sending rule, and the specific implementation method of sending the detection message to the server according to the preset message sending rule is as follows: a single detection message is sent to the server based on a single detection sending rule, and it is determined whether the version information of the server can be determined from a response message returned by the server based on the single detection message; if not, a combined detection message containing multiple detection messages is sent to the server based on a combined detection sending rule, so as to determine the version information of the server from the response message returned by the server based on the combined message. That is, according to the one-time detection sending rule, single detection messages are sent to the server one by one to determine the current component version information of the server. If the current component version information of the server can be determined based on the response message returned by the server based on the first detection message sent one by one, then the single detection sending rule is continued to be sent to the server one by one to determine the next component version information of the server. If the current component version information of the server cannot be determined by sending single detection messages to the server one by one according to the one-time detection sending rule, then based on the combined detection sending rule, a combined detection message containing multiple detection messages is sent to the server to determine the current component version information of the server based on the response message returned by the server based on the combined detection message. If the component version information of the server cannot be determined by both methods, a response message indicating that the component version information is unknown is returned. For example, the waf product determines whether the response message sent by the server matches the built-in detection message expectation. If the matching expectation is MySQL, it can be determined that the server database is MySQL, and further detection messages can be sent to continue to detect the specific version of MySQL. If it does not match, another detection message can be further sent. If none of the detection messages match, a combined detection message is sent. If the results in the combined detection message are all in line with the expectation of MySQL, then the database is determined to be MySQL. If the combined detection message also does not meet expectations, a detection message of the next database type is sent to determine the server database type. If all database types cannot be matched, it is determined to be an unknown type of database.
[0061] Step S22: Receive the response message, and determine the database version, system version, and structs framework version of the server according to the characteristic information in the response message.
[0062] In this embodiment, the response message is received, and the database version, system version, and structs framework version of the server are determined according to the characteristic information in the response message. That is, the database version, system version, and structs framework version of the server are determined according to the response message returned by the server according to various detection messages. For example, it is determined that the database version of the server is Oracle version, the system version is win11, and the structs framework version is structs2.5.
[0063] Step S23: determine whether the resource occupation of the processor itself is greater than a preset first resource occupation threshold.
[0064] Step S24: If the processor resource usage is greater than a preset first resource usage threshold, the target protection rule base is determined based on the database version, the system version, and the structs framework version, and precise matching protection for the server is enabled.
[0065] In this embodiment, if the processor resource occupancy is greater than the preset first resource occupancy threshold, the target protection rule base is determined based on the database version, the system version, and the structs framework version, and accurate matching protection for the server is enabled. That is, if the processor resource itself is greater than the first resource occupancy threshold set by the user, or greater than the system preset first resource occupancy threshold, the corresponding target protection rule base corresponding to the server component version information is determined from all protection rule bases according to the database version, system version, and structs framework version of the server, and accurate matching protection for the server is enabled. For example, according to the server component version information that the database version of the server is Oracle version, the system version is win11, and the structs framework version is structs2.5 in the aforementioned embodiment, the target protection rule base is selected as the rule base with the database version of Oracle version, the windows system version is not less than win11, and the structs framework version is not less than structs2.5 version for matching.
[0066] Step S25: determine whether a network request is received. If so, accurately match the network request based on the target protection rule library to determine a matching result.
[0067] In this embodiment, it is determined whether a network request is received. If so, the network request is accurately matched based on the target protection rule library to determine the matching result. That is, the received network request is matched according to the target protection rule library corresponding to the server component version information to determine the matching result based on the network request. If the network request is successfully matched in the target protection rule library, the network request is characterized as a malicious request. If no match is successful, the network request is characterized as a normal network request. In this way, the number of protection rules that need to be matched can be reduced, effectively improving the processing efficiency of the network protection method in this application.
[0068] Step S26: If the matching result indicates a successful match, the network request is determined to be a malicious request, and the network request is blocked.
[0069] It should be noted that for a more detailed description of step S23 and step S26, reference can be made to the aforementioned embodiment, which will not be repeated here.
[0070] It can be seen that in this embodiment, first, full match protection is enabled based on all protection rule libraries, and based on the preset detection message sending rules, the detection message in the detection message library is sent to the server, so that the server returns a corresponding response message based on the detection message, and receives the response message, and determines the database version, system version, and structs framework version of the server according to the characteristic information in the response message, and then determines whether its own processor resource occupancy is greater than the preset first resource occupancy threshold. If its own processor resource occupancy is greater than the preset first resource occupancy threshold, the target protection rule library is determined based on the database version, the system version, and the structs framework version, and accurate match protection for the server is enabled. Finally, it is determined whether a network request is received. If so, the network request is accurately matched based on the target protection rule library to determine the matching result. If the matching result indicates a successful match, the network request is determined to be a malicious request, and the network request is blocked. In this way, a detection message can be sent to the server according to a single detection sending rule and a combined detection sending rule, which can make the determination of the server component version information more accurate, and the received network request can be matched according to the target protection rule library corresponding to the server component version information, thereby reducing the number of protection rules that need to be matched and effectively improving the processing efficiency of the network protection method in this application.
[0071] Based on the above embodiments, it can be seen that in this application, it is necessary to determine whether the processor resource occupancy of the server has reached a preset threshold, and after determining whether the server resource occupancy has reached the first resource occupancy threshold, it is also necessary to determine whether the server resource occupancy has reached the second resource occupancy threshold. For this reason, this embodiment describes in detail the processing after the server resource occupancy reaches the second resource occupancy threshold, see Figure 4 As shown, an embodiment of the present invention discloses a network protection method, including:
[0072] Step S31: Enable full match protection based on all protection rule libraries, and send a probe message to the server through a preset probe message sending rule, so that the server returns a corresponding response message according to the probe message, and determines the component version information of the server based on the response message.
[0073] Step S32: determine whether the processor resource usage is greater than a preset first resource usage threshold.
[0074] Step S33: If yes, determine whether the resource occupation of the processor itself is greater than a preset second resource occupation threshold.
[0075] In this embodiment, if the server's own resource occupation is greater than the first resource occupation threshold, precise matching protection for the server is enabled based on the component version information, and it is necessary to determine whether the server's own resource occupation is greater than the second resource occupation threshold. It should be noted that the second resource occupation threshold is often used to determine whether the server's resource occupation is on the verge of collapse, and in the precise matching protection mode, if the resource occupation is too high, it is necessary to reduce the server's resource occupation first to avoid the server crashing due to excessive resource occupation. In this way, the second resource occupation threshold is generally set to 100%.
[0076] Step S34: If not, enable precise matching protection for the server based on the component version information.
[0077] In this embodiment, if not, accurate matching protection for the server is enabled based on the component version information. That is, if the server's own resource usage is greater than the first resource usage threshold but less than the second resource usage threshold, accurate matching protection for the server is enabled based on the server's database version, system version, and structs framework version.
[0078] Step S35: If yes, trigger an automatic release operation, and after receiving the network request, perform an automatic release operation on the to-be-matched network request to alleviate the resource occupation of the own processor.
[0079] In this embodiment, if the server's own resource occupancy is greater than the second resource occupancy threshold, it indicates that the server resource occupancy is too high and is on the verge of collapse. In order to avoid increasing the server burden, the server resource occupancy needs to be temporarily reduced. After receiving the network request, an automatic release operation needs to be performed.
[0080] Step S36: Collect the malicious requests that have not been successfully blocked, and add the malicious requests that have not been successfully blocked to the protection rule library to update the protection rule library.
[0081] In this embodiment, if there is a malicious request that is not successfully blocked, the malicious request needs to be added to the protection rule library to update the protection rule library and avoid the server being attacked by the malicious request again when the same type of malicious request is received again. It should be noted that the update of the protection rule library and the update of the message library are both performed when the server occupancy is low, rather than real-time updates, to avoid occupying the server's own processor resources and affecting the protection of the server by the WAF product.
[0082] It should be noted that for a more detailed description of step S31 and step S32, reference can be made to the aforementioned embodiment, which will not be repeated here.
[0083] It can be seen that in this embodiment, firstly, full match protection is enabled based on all protection rule libraries, and a detection message is sent to the server through a preset detection message sending rule, so that the server returns a corresponding response message according to the detection message, and determines the component version information of the server based on the response message, and then determines whether the resource occupancy of its own processor is greater than the preset first resource occupancy threshold. If so, it determines whether the resource occupancy of its own processor is greater than the preset second resource occupancy threshold. If not, based on the component version information, accurate match protection for the server is enabled, and if so, an automatic release operation is triggered, and after receiving a network request, an automatic release operation is performed on the network request to be matched to alleviate the resource occupancy of the processor itself, and finally malicious requests that are not successfully blocked are collected, and the malicious requests that are not successfully blocked are added to the protection rule library to realize the update of the protection rule library. In this way, when the server resource occupancy is tight, the network request can be automatically released to avoid the server crash, and the malicious request that is not successfully blocked can be updated to the protection rule library, thereby improving the reliability of the network protection method described in the present application.
[0084] See also Figure 5 As shown, an embodiment of the present invention discloses a network protection device, including:
[0085] The version determination module 11 is used to enable full match protection based on all protection rule libraries, and send a detection message to the server through a preset detection message sending rule, so that the server returns a corresponding response message according to the detection message, and determines the component version information of the server based on the response message;
[0086] A threshold determination module 12 is used to determine whether the resource occupation of its own processor is greater than a preset first resource occupation threshold;
[0087] A matching result determination module 13 is used to enable accurate matching protection for the server based on the component version information if the processor resource usage is greater than the first resource usage threshold, and after receiving the network request, accurately match the network request based on the target protection rule base to determine the matching result; the target protection rule base is a rule base corresponding to the component version information;
[0088] The request blocking module 14 is configured to determine that the network request is a malicious request and block the network request if the matching result indicates a successful match.
[0089] It can be seen that in this embodiment, firstly, full match protection is enabled based on all protection rule bases, and a detection message is sent to the server through a preset detection message sending rule, so that the server returns a corresponding response message according to the detection message, and determines the component version information of the server based on the response message, and then determines whether the processor resource occupancy is greater than the preset first resource occupancy threshold. If the processor resource occupancy is greater than the first resource occupancy threshold, then based on the component version information, accurate matching protection for the server is enabled, and after receiving the network request, the network request is accurately matched based on the target protection rule base to determine the matching result. The target protection rule base is a rule base corresponding to the component version information, and if the matching result indicates a successful match, the network request is determined to be a malicious request, and the network request is blocked. It can be seen that, using the network protection method described in this application, a detection message can be sent to the server after enabling full match protection, and the component version information of the server can be determined according to the response message returned by the server, and then the accurate matching for the server version can be enabled according to the processor resource occupancy. The accurate matching can be enabled according to the protection rule base corresponding to the server component version information. Matching protection. In this way, by matching malicious attack messages with the protection rule library corresponding to the current server component version, system resources can be effectively saved, network security efficiency can be effectively improved, and the problem of missing defenses when protection performance is insufficient can be avoided.
[0090] In some embodiments, the network protection device may further include:
[0091] A message library generation module, used to generate a number of detection messages, and generate a detection message library based on the number of detection messages;
[0092] The rule base generation module is used to generate a number of corresponding protection rule bases based on different component version information of the server.
[0093] In some embodiments, the version determination module 11 may specifically include:
[0094] A message sending submodule, used for sending the detection message in the detection message library to the server based on a preset detection message sending rule, so that the server returns a corresponding response message based on the detection message;
[0095] The version determination submodule is used to receive the response message and determine the database version, system version, and structs framework version of the server according to the characteristic information in the response message.
[0096] In some embodiments, the message sending submodule may specifically include:
[0097] A single message sending unit, used to send a single detection message to the server based on a detection sending rule, and determine whether the version information of the server can be determined from a response message returned by the server based on the single detection message;
[0098] The combined message sending unit is used to send a combined detection message containing multiple detection messages to the server based on a combined detection sending rule if the version information of the server cannot be determined, so as to determine the version information of the server from a response message returned by the server based on the combined message.
[0099] In some embodiments, the matching result determination module 13 may specifically include:
[0100] A first matching protection unit, configured to determine the target protection rule base based on the database version, the system version, and the structs framework version, and enable accurate matching protection for the server;
[0101] The matching result determination unit is used to determine whether a network request is received, and if so, to accurately match the network request based on the target protection rule library to determine the matching result.
[0102] In some embodiments, the matching result determination module 13 may specifically include:
[0103] A threshold determination unit, used to determine whether the resource occupation of its own processor is greater than a preset second resource occupation threshold;
[0104] A second matching protection unit, configured to enable accurate matching protection for the server based on the component version information if the value is not greater than the second resource occupancy threshold;
[0105] The request release unit is used to trigger an automatic release operation if it is greater than the second resource occupancy threshold, and after receiving the network request, perform an automatic release operation on the to-be-matched network request to alleviate the resource occupancy of the own processor.
[0106] In some embodiments, the network protection device may further include:
[0107] The rule base updating unit is used to collect the malicious requests that have not been successfully blocked, and add the malicious requests that have not been successfully blocked to the protection rule base to update the protection rule base.
[0108] Furthermore, the present application also discloses an electronic device. Figure 6 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be considered as any limitation on the scope of use of the present application.
[0109] Figure 6 A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the network protection method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0110] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0111] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0112] The operating system 221 is used to manage and control the hardware devices and computer programs 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the network protection method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.
[0113] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein the computer program, when executed by a processor, implements the aforementioned disclosed network protection method. The specific steps of the method can refer to the corresponding contents disclosed in the aforementioned embodiments, and will not be repeated here.
[0114] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0115] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0116] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0117] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0118] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technicians in this field, according to the idea of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A network protection method, characterized in that: Applied to the server front end, including: Enable full match protection based on all protection rule libraries, and send a probe message to the server through a preset probe message sending rule, so that the server returns a corresponding response message according to the probe message, and determines the component version information of the server based on the response message; Determine whether the processor resource usage is greater than a preset first resource usage threshold; If so, then based on the component version information, accurate matching protection for the server is enabled, and after receiving the network request, the network request is accurately matched based on the target protection rule base to determine the matching result; the target protection rule base is a rule base corresponding to the component version information; If the matching result indicates a successful match, the network request is determined to be a malicious request, and the network request is blocked.
2. The network protection method according to claim 1, characterized in that: Before enabling full match protection based on all protection rule bases and sending a detection message to the server according to a preset detection message sending rule, the method further includes: A plurality of detection messages are generated, a detection message library is generated based on the plurality of detection messages, and a plurality of corresponding protection rule libraries are generated based on different component version information of the server.
3. The network protection method according to claim 2, characterized in that: The sending of a detection message to the server by using a preset detection message sending rule so that the server returns a corresponding response message according to the detection message, and determining the component version information of the server based on the response message includes: Sending a detection message in the detection message library to the server based on a preset detection message sending rule, so that the server returns a corresponding response message based on the detection message; The response message is received, and the database version, system version, and structs framework version of the server are determined according to the characteristic information in the response message.
4. The network protection method according to claim 3, characterized in that: The sending of the detection message in the detection message library to the server based on the preset detection message sending rule, so that the server returns a corresponding response message based on the detection message, includes: Sending a single detection message to the server based on a detection sending rule, and determining whether the version information of the server can be determined from a response message returned by the server based on the single detection message; If not, a combined detection message including multiple detection messages is sent to the server based on the combined detection sending rule, so as to determine the version information of the server from a response message returned by the server based on the combined message.
5. The network protection method according to claim 3, characterized in that: The enabling of accurate matching protection for the server based on the component version information, and after receiving the network request, accurately matching the network request based on the target protection rule library to determine the matching result, includes: Determine the target protection rule base based on the database version, the system version, and the structs framework version, and enable precise matching protection for the server; Determine whether a network request is received, and if so, accurately match the network request based on the target protection rule library to determine a matching result.
6. The network protection method according to claim 1, characterized in that: The enabling of accurate matching protection for the server based on the component version information includes: Determine whether the processor resource usage is greater than a preset second resource usage threshold; If not, enable accurate matching protection for the server based on the component version information; If so, an automatic release operation is triggered, and after receiving the network request, an automatic release operation is performed on the to-be-matched network request to alleviate the resource occupation of the own processor.
7. The network protection method according to any one of claims 1 to 6, characterized in that: If the matching result indicates that the match is successful, then after determining that the network request is a malicious request and blocking the network request, the method further includes: Malicious requests that have not been successfully blocked are collected, and the malicious requests that have not been successfully blocked are added to a protection rule base to update the protection rule base.
8. A network protection device, characterized in that: include: A version determination module, used to enable full match protection based on all protection rule libraries, and send a detection message to the server through a preset detection message sending rule, so that the server returns a corresponding response message according to the detection message, and determines the component version information of the server based on the response message; A threshold determination module, used to determine whether the resource occupation of its own processor is greater than a preset first resource occupation threshold; a matching result determination module, configured to enable accurate matching protection for the server based on the component version information if the processor resource usage is greater than the first resource usage threshold, and to accurately match the network request based on a target protection rule base after receiving the network request to determine a matching result; the target protection rule base is a rule base corresponding to the component version information; The request blocking module is used to determine that the network request is a malicious request and block the network request if the matching result indicates a successful match.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the network protection method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store a computer program, which, when executed by a processor, implements the network protection method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Website protection method and device, website protection equipment and readable storage medium
CN107580005A
Message speed limiting system and method of firewall, equipment and medium
CN112231107A