A method, device, medium and equipment for identifying brute-force cracking database behaviors

By obtaining database login traffic and using IDS to analyze source IP and destination IP, the problem of low efficiency of identifying brute force database attacks in the existing technology is solved, and efficient and accurate identification and traceability are achieved.

CN116318809BActive Publication Date: 2025-07-25BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211693965.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-28
Publication Date
2025-07-25
Estimated Expiration
2042-12-28

AI Technical Summary

Technical Problem

In the prior art, the efficiency of identifying brute-force database attacks is low, which is not conducive to timely discovery and processing.

Method used

By obtaining the login traffic of the target database, using the intrusion detection system (IDS) to determine the judgment traffic value of each preset duration based on the traffic determination rules, and analyzing the source IP and the destination IP to determine whether there is brute-force cracking.

Benefits of technology

It realizes rapid and accurate identification of brute-force database behavior, improves identification efficiency, reduces manpower investment, and can promptly detect and track malicious behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116318809B_ABST
    Figure CN116318809B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, and in particular to a method, device, medium and equipment for identifying brute-force cracking of a database. It includes obtaining the login traffic of the target database. Obtaining the traffic determination rules of the target database. According to the traffic determination rules, determining the determined traffic value corresponding to each preset time period. According to the determined traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period, determining whether there is an act of brute-force cracking the target database in each preset time period. In the present invention, it is possible to quickly determine whether there is an act of brute-force cracking the target database in each preset time period according to the determined traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period. Compared with the traditional manual analysis method, the method of using an intrusion detection system to identify the behavior of brute-force cracking the database password in the present invention is more efficient and accurate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method, device, medium and equipment for identifying brute-force cracking of database behavior. Background Art

[0002] With the development of the enterprise informatization process, users have placed the core business data and customer information of the enterprise in the database, and the security management requirements of the database have become more and more urgent. Due to reasons such as the insufficient security of the database itself, attackers can access illegally through various channels. Such as brute-force cracking, which means that attackers use automated scripts to systematically combine all possible accounts and passwords, and try to crack sensitive information such as the account name and password of the real user through all possible accounts and passwords to achieve illegal access to the database.

[0003] In the existing technology, the attack behavior of brute-force cracking the database is mostly identified by manual analysis. However, the identification methods in the existing technology have the problems of low identification efficiency and being not conducive to timely and effective discovery of the attack behavior of brute-force cracking the database. Summary of the Invention

[0004] In view of the above technical problems of low identification efficiency and being not conducive to timely and effective discovery of the attack behavior of brute-force cracking the database, the technical solution adopted by the present invention is as follows:

[0005] According to one aspect of the present invention, a method for identifying brute-force cracking of database behavior is provided, and the method includes the following steps:

[0006] Obtain the login traffic of the target database.

[0007] Obtain the traffic determination rules of the target database. The traffic determination rules include a login success determination rule and a login failure determination rule. The traffic determination rules are used to determine the type of login traffic.

[0008] According to the traffic determination rules, determine the determination traffic value corresponding to each preset time period. The determination traffic value is the number of each type of traffic in the login traffic obtained in the preset time period.

[0009] According to the determination traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period, determine whether there is a behavior of brute-force cracking the target database in each preset time period.

[0010] In the present invention, further, according to the determination traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period, determining whether there is a behavior of brute-force cracking the target database in each preset time period includes:

[0011] If the sum of the determined traffic values corresponding to the preset duration is greater than the first threshold, perform an abnormal determination process on the login traffic obtained for the preset duration.

[0012] Based on the abnormal determination process, determine whether there is an act of brute - force cracking the target database during the preset duration.

[0013] In the present invention, further, both the source IP and the destination IP in the login traffic obtained for the preset duration are multiple, and multiple source IPs are the same and multiple destination IPs are the same.

[0014] The abnormal determination process includes:

[0015] If the number of traffic belonging to the login - failure type in the determined traffic values corresponding to the preset duration is greater than the first threshold, and the number of traffic belonging to the login - success type is zero, then determine that the source IP is the attacker, and the attacker is performing a brute - force cracking behavior on the target database corresponding to the destination IP.

[0016] In the present invention, further, both the source IP and the destination IP in the login traffic obtained for the preset duration are multiple, and multiple source IPs are the same and multiple destination IPs are the same.

[0017] The abnormal determination process includes:

[0018] If there is traffic belonging to the login - success type in the determined traffic values corresponding to the preset duration, and there are multiple traffic belonging to the login - failure type before each traffic belonging to the login - success type, then determine that the source IP is the attacker, and the attacker is performing a brute - force cracking on the target database corresponding to the destination IP and has cracked it successfully.

[0019] In the present invention, further, both the source IP and the destination IP in the login traffic obtained for the preset duration are multiple, and multiple source IPs are the same and multiple destination IPs are different.

[0020] The abnormal determination process includes:

[0021] If the source IP does not belong to the malicious IP, and the number of traffic belonging to the login - failure type in the determined traffic values corresponding to the preset duration is greater than the first threshold, then determine that the source IP is the victim, and the victim is performing a brute - force cracking behavior on the target databases corresponding to multiple destination IPs.

[0022] In the present invention, further, the abnormal determination process further includes:

[0023] If there is a weak password in the login traffic obtained for the preset duration, then determine that the target database corresponding to the destination IP is being brute - force cracked.

[0024] In the present invention, further, obtaining the traffic determination rule of the target database includes:

[0025] Build the database environment corresponding to each target database.

[0026] Simulate the login behavior of the target database in each database environment. The login behavior includes login request behavior, login success behavior, and login failure behavior.

[0027] Generate a traffic determination rule for the target database according to the characteristics corresponding to the login behavior.

[0028] According to a second aspect of the present invention, there is provided an apparatus for identifying brute-force cracking database behavior, including:

[0029] A first acquisition module for acquiring the login traffic of the target database.

[0030] A second acquisition module for acquiring the traffic determination rule of the target database. The traffic determination rule includes a login success determination rule and a login failure determination rule. The traffic determination rule is used to determine the type of login traffic.

[0031] A determination module for determining the determined traffic value corresponding to each preset time period according to the traffic determination rule. The determined traffic value is the number of each type of traffic in the login traffic obtained in the preset time period.

[0032] A cracking behavior determination module for determining whether there is a behavior of brute-force cracking the target database in each preset time period according to the determined traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period.

[0033] According to a third aspect of the present invention, there is provided a non-transitory computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above-mentioned method for identifying brute-force cracking database behavior is implemented.

[0034] According to a fourth aspect of the present invention, there is provided an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the computer program, the above-mentioned method for identifying brute-force cracking database behavior is implemented.

[0035] The present invention has at least the following beneficial effects:

[0036] Since, during the brute-force cracking process, the attacker will use a large number of possible account and password combinations to attempt to access the target database. However, usually a large number of account and password combinations are incorrect, so a large amount of login failure traffic will be generated in a short period of time. In response to this situation, the present invention can quickly determine whether there is a behavior of brute-forcing the target database in each preset time period according to the determined traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period.

[0037] Compared with the traditional manual analysis method, the method for identifying the behavior of brute-forcing the database password in the present invention is more efficient and accurate. At the same time, it can also detect the behavior of brute-forcing the database password more comprehensively without spending a large amount of manpower. Furthermore, the identification efficiency can be improved, which is beneficial to timely and effectively discovering the attack behavior of brute-forcing the database. Further, the present invention can also trace the malicious behavior through the source IP and destination IP in the login traffic. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0039] Figure 1 It is a flowchart of a method for identifying the behavior of brute-forcing a database provided by an embodiment of the present invention;

[0040] Figure 2 It is a structural block diagram of a device for identifying the behavior of brute-forcing a database provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0041] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.

[0042] According to one aspect of the present invention, as Figure 1 shown, a method for identifying the behavior of brute-forcing a database is provided, and the method includes the following steps:

[0043] S100: Obtain the login traffic of the target database.

[0044] Specifically, the target database can be a certain database in the system or different databases in multiple systems. Different target databases will have corresponding destination IPs for correspondence determination. The login traffic in this step specifically refers to the network traffic used to log in and access the corresponding target database. The traffic data packets related to the login traffic can be captured through existing packet capture software (such as Wireshark, Fiddler). This login traffic can be monitored by an IDS (intrusion detection system) deployed in the corresponding system. The IDS is an important technology to protect computer systems from data theft or malicious damage to the computer. By combining the intrusion detection system with a firewall, malicious intrusion actions from external networks or internal networks can be effectively prevented, and the built-in intrusion detection rules are used to filter network intrusion behaviors.

[0045] In order to monitor the login traffic of the corresponding target database through the intrusion detection system, it is necessary to extract the characteristics of the login traffic and form corresponding detection rules based on these characteristics. By inputting the detection rules into the corresponding IDS, the IDS can be enabled to have the ability to detect and monitor the login traffic of the target database. Among them, extracting the characteristics of the login traffic and forming corresponding detection rules based on these characteristics are existing technologies and will not be elaborated here.

[0046] S200: Obtain the traffic determination rules of the target database. The traffic determination rules include a login success determination rule and a login failure determination rule. The traffic determination rules are used to determine the type of login traffic.

[0047] The traffic determination rules of the target database obtained in this step can be the above-mentioned extraction of the characteristics of the login traffic and the formation of corresponding detection rules based on these characteristics. Thus, the login success determination rule can be used to determine the network attack traffic that successfully cracks the target database and successfully logs in among the login traffic. The login failure determination rule can be used to determine the network attack traffic that fails to crack the target database and cannot log in among the login traffic.

[0048] S300: Determine the determination traffic value corresponding to each preset time period according to the traffic determination rules.

[0049] Specifically, use the intrusion detection system to determine the determination traffic value corresponding to each preset time period according to the traffic determination rules. The determination traffic value is the quantity of each type of traffic in the login traffic obtained in the preset time period. The types in this step include login success and login failure.

[0050] In this step, the login success determination rule and the login failure determination rule corresponding to each target database determined in S200 are input into the corresponding IDS. Then, relevant traffic data packets are captured through existing packet capture software (such as Wireshark, Fiddler). Subsequently, the IDS can be used to monitor the login traffic of the corresponding target database, and thus the number of successful login traffic and the number of failed login traffic in the login traffic of any target database within any time period can be counted.

[0051] Meanwhile, during the brute-force cracking process, the attacker will use a large number of possible account and password combinations to attempt to access the target database. However, usually a large number of account and password combinations are incorrect, so a large amount of failed login traffic will be generated in a short period of time. Therefore, in order to more accurately identify the attack behavior with the above characteristics, in this step, the intrusion detection system is used to determine the determination traffic value corresponding to each preset duration according to the traffic determination rule. Thus, it can be quickly determined whether there is a behavior of brute-forcing the target database in each preset duration. Correspondingly, the preset duration needs to be determined by itself according to the corresponding usage scenario. Usually, the frequency of login requests to the target database generated by the brute-force cracking attack method is much higher than the frequency of login requests sent by normal users. For example, the frequency of login requests to the target database generated by the brute-force cracking attack method can reach a magnitude greater than 100 times per minute, such as 200 times / min or 300 times / min, etc. While the frequency of login requests sent by normal users is usually 15 - 40 times / min. The preset time in this step can be 30S - 90S. Thus, the IDS can compare and judge the corresponding determination traffic value generated within each preset duration. When it is greater than the corresponding threshold, it is considered that there is a high possibility of a brute-force cracking attack behavior. In this embodiment, the number of failed login traffic corresponding to each target database can be compared and judged with the corresponding threshold; or the sum of the number of successful login traffic and the number of failed login traffic corresponding to each target database can be compared and judged with the corresponding threshold.

[0052] S400: Determine whether there is a behavior of brute-forcing the target database in each preset duration according to the determination traffic value corresponding to each preset duration and the source IP and destination IP in the login traffic obtained for each preset duration.

[0053] In this step, the data packets in the login traffic obtained through IDS monitoring can be used to obtain the corresponding source IP and destination IP in the login traffic.

[0054] To further confirm whether there is an act of brute - force cracking the target database in each preset time period, it is also necessary to further analyze and judge the source IP and destination IP in the login traffic obtained for each preset time period. Generally, when a large number of source IPs are the same IP, it can be determined that there is an act of brute - force cracking the target database in the corresponding preset time period. Through the source IP, malicious behaviors can be traced back to determine the corresponding attacker. Through the destination IP, it can be determined which target database is being attacked, so as to further take relevant protection measures.

[0055] In the present invention, the traffic determination rules for each target database can be input into the intrusion detection system, so that the corresponding intrusion detection system has the ability to detect the determination traffic value corresponding to each preset time period. Specifically, it can detect the login success traffic and login failure traffic of each target database. Furthermore, by classifying and modeling the events of brute - force cracking the database password, the model can effectively achieve a more comprehensive analysis of the traffic. Thus, according to the determination traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained for each preset time period, it can be quickly determined whether there is an act of brute - force cracking the target database in each preset time period.

[0056] Compared with the traditional manual analysis method, the method of using the intrusion detection system to identify the act of brute - force cracking the database password in the present invention is more efficient and accurate. At the same time, it can also detect the act of brute - force cracking the database password more comprehensively without spending a large amount of manpower. Furthermore, the identification efficiency can be improved, which is beneficial to timely and effectively discovering the attack behavior of brute - force cracking the database. Further, the present invention can also trace back malicious behaviors through the source IP and destination IP in the login traffic.

[0057] As a possible embodiment of the present invention, S400: According to the determination traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained for each preset time period, determine whether there is an act of brute - force cracking the target database in each preset time period, including:

[0058] S401: If the sum of the determination traffic values corresponding to the preset time period is greater than the first threshold, perform an abnormal determination process on the login traffic obtained for the preset time period. The abnormal determination process is used to determine whether there is an act of brute - force cracking the target database in the preset time period according to the determination traffic value corresponding to the preset time period and the source IP and destination IP in the obtained login traffic.

[0059] In this embodiment, if the sum of the determined traffic values corresponding to the preset duration is greater than the first threshold, subsequent abnormal determination processing is enabled to further determine whether there is an act of brute - force cracking of the target database during the corresponding preset duration. By setting the determination conditions, the abnormal determination processing can be carried out more targeted. Furthermore, the number of mis - starts of the abnormal determination processing can be reduced, and the consumption of system resources can be reduced.

[0060] As a possible embodiment of the present invention, both the source IP and the destination IP in the login traffic obtained for the preset duration are multiple, and all the multiple source IPs are the same and all the multiple destination IPs are the same.

[0061] The abnormal determination processing includes:

[0062] S411: If the number of traffic belonging to the login - failure type in the determined traffic values corresponding to the preset duration is greater than the first threshold, and the number of traffic belonging to the login - success type is zero, it is determined that the source IP is the attacker, and the attacker is performing a brute - force cracking act on the target database corresponding to the destination IP.

[0063] This embodiment is a determination method for the situation where the attacker brute - force cracks the database password but fails.

[0064] Specifically, when all the multiple source IPs are the same and all the multiple destination IPs are the same, and it is detected that all the traffic generated within the current preset duration belongs to the login - failure type. Then at this time, it can be considered that the source IP is the attacker, and the attacker is performing a brute - force cracking on the target database corresponding to the destination IP. This embodiment can more accurately and quickly determine the act of brute - force cracking the database that is in progress and has not been successful.

[0065] As a possible embodiment of the present invention, both the source IP and the destination IP in the login traffic obtained for the preset duration are multiple, and all the multiple source IPs are the same and all the multiple destination IPs are the same.

[0066] The abnormal determination processing includes:

[0067] S421: If there is traffic belonging to the login - success type in the determined traffic values corresponding to the preset duration, and there are multiple traffic belonging to the login - failure type before each traffic belonging to the login - success type, it is determined that the source IP is the attacker, and the attacker is performing a brute - force cracking on the target database corresponding to the destination IP and has cracked it successfully.

[0068] This embodiment is a determination method for the situation where the attacker brute - force cracks the database password and succeeds.

[0069] Generally, when an attacker writes an automated script to combine the correct username and password, there are two situations. One is that when the script produces a username and password that can successfully log in to the target database, it stops producing subsequent new username and password attempts for logging in. The other is that when the script produces a username and password that can successfully log in to the target database, it still produces subsequent new username and password attempts for logging in. Also, since the probability of producing the correct username and password is relatively small, usually a large number of incorrect usernames and passwords need to be produced before it is possible to produce a correct username and password. Therefore, in the detected login traffic, there will be a large amount of traffic of the login failure type before a traffic of the login success type appears. And this form will have multiple cycles.

[0070] Correspondingly, this embodiment is exactly a determination method set for the above attack method. Specifically, when it is detected that there is traffic of the login success type in the generated login traffic within the current preset duration. And there are multiple traffic of the login failure type before each traffic of the login success type. Then at this time, it can be considered that the source IP is the attacker, and the attacker is performing brute-force cracking on the target database corresponding to the destination IP and has successfully cracked it. This embodiment can more accurately and quickly determine the behavior of brute-force cracking the database that is in progress and has been successful.

[0071] As a possible embodiment of the present invention, both the source IP and the destination IP in the login traffic obtained in the preset duration are multiple, and multiple source IPs are the same and multiple destination IPs are different.

[0072] The abnormal determination process includes:

[0073] S431: If the source IP does not belong to a malicious IP, and the number of traffic of the login failure type in the determination traffic value corresponding to the preset duration is greater than the first threshold, then it is determined that the source IP is the victim, and the victim is performing brute-force cracking on the target databases corresponding to multiple destination IPs.

[0074] Specifically, since the IDS can not only monitor the network traffic sent from the outside to the system, but also monitor the network traffic sent from the system to the external system. Therefore, it is also possible to perform abnormal judgment and monitoring on the network traffic sent from the inside to the outside. In addition, an existing threat intelligence system can be used to determine whether the source IP belongs to a malicious IP.

[0075] This embodiment is a determination method mainly for the situation of brute-force cracking the database on the controlled host (which may be invaded and used as a puppet machine to initiate a database blasting attack externally).

[0076] Typically, in order to hide their identity and IP address and further prevent detection by existing security protection software, attackers will plant corresponding viruses into a normal host and control the host (the puppet machine) to initiate database brute-force attacks externally. Since the IP address of the controlled host is not an existing marked malicious IP, it is easier to bypass the detection of existing security software, which can increase the success rate of the attack.

[0077] In this case, the source IP is the victim, that is, the controlled host. Therefore, through this embodiment, it is not only possible to detect whether the target database in the system has been subjected to a brute-force cracking attack, but also to detect whether the host in the system has become a puppet machine.

[0078] As a possible embodiment of the present invention, the abnormal determination process further includes:

[0079] S441: If there is a weak password in the login traffic obtained within a preset time period, it is determined that the target database corresponding to the destination IP is being brute-force cracked.

[0080] Since, at the beginning of each database establishment, relatively simple initial accounts and passwords will be configured for users, such as: account: admin; password: 111111. For the convenience of users. And, after the user registers successfully, the user will be reminded to modify the initial account and password. However, there will still be cases where users forget to modify the initial account and password. Therefore, for the above situation, brute-force attacks are usually more likely to crack weak passwords. That is, attackers use automated scripts to preferentially generate usernames and passwords with weak security strength to achieve the attack purpose as soon as possible.

[0081] In this embodiment, by adding the judgment of the existence of weak passwords in the login traffic, the accuracy of the determined brute-force cracking attack can be improved.

[0082] As a possible embodiment of the present invention, S200: Obtain the traffic determination rule of the target database, including:

[0083] S201: Build a database environment corresponding to each target database.

[0084] The target database is basically an existing mainstream database. Such as databases like MySQL, SQLServer, Oracle, PostgreSQL, DB2, MongoDB, Redis, ElasticSearch, etc.

[0085] S202: Simulate the login behavior of the target database in each database environment. The login behavior includes login request behavior, login success behavior, and login failure behavior.

[0086] Simulate relevant behaviors (such as login requests, login successes, login failures), and use packet capture software (such as Wireshark, Fiddler) to capture relevant traffic data packets.

[0087] S203: Generate traffic determination rules for the target database according to the characteristics corresponding to the login behavior.

[0088] View the captured traffic data packets and identify the traffic characteristics therein. Taking the successful login to the MySql database server as an example, the length and content of the server return value are both fixed values. Therefore, the server return value (such as: 07 0000 02 00 00 00 02 00 00 00) can be used as the traffic characteristic.

[0089] Then, write intrusion detection rules according to the above traffic characteristics.

[0090] Write intrusion detection rules according to the syntax of the Intrusion Detection System (IDS). Currently, common open-source IDSs include Snort and Suricata. Taking the syntax of Snort as an example, according to the above traffic characteristics, the intrusion detection rule for extracting features is as follows: alert tcp any any->any any(msg:"Database MySQL Login Success";content:"|07 00 00 02 00 00 00 02 00 00 00|").

[0091] According to this embodiment, the corresponding traffic characteristics can be extracted more accurately, and the traffic determination rules for the target database can be generated more accurately.

[0092] According to the second aspect of the present invention, as Figure 2 shown, a device for identifying brute-force cracking database behaviors is provided. The device includes:

[0093] A first acquisition module for acquiring the login traffic of the target database.

[0094] A second acquisition module for acquiring the traffic determination rules of the target database. The traffic determination rules include login success determination rules and login failure determination rules. The traffic determination rules are used to determine the type of login traffic.

[0095] A determination module for determining the determined traffic value corresponding to each preset time period according to the traffic determination rules. The determined traffic value is the quantity of each type of traffic in the login traffic acquired in the preset time period.

[0096] A cracking behavior determination module, configured to determine whether there is a behavior of brute - force cracking a target database in each preset time period according to the determination traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period.

[0097] In the present invention, the traffic determination rules for each target database can be input into the intrusion detection system, so that the corresponding intrusion detection system has the ability to detect the determination traffic value corresponding to each preset time period. Specifically, it can detect the login success traffic and login failure traffic of each target database. Since, during the brute - force cracking process, the attacker will use a large number of possible account and password combinations to attempt to access the target database. However, usually a large number of account and password combinations are incorrect, so a large amount of login failure traffic will be generated in a short time. Therefore, in view of this situation, the present invention can quickly determine whether there is a behavior of brute - force cracking the target database in each preset time period according to the determination traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period.

[0098] Compared with the traditional manual analysis method, the method of using the intrusion detection system to identify the behavior of brute - force cracking the database password in the present invention is more efficient and accurate. At the same time, it can also detect the behavior of brute - force cracking the database password more comprehensively without spending a large amount of manpower. Furthermore, it can improve the recognition efficiency and is conducive to timely and effectively discovering the attack behavior of brute - force cracking the database. Further, the present invention can also trace the malicious behavior through the source IP and destination IP in the login traffic.

[0099] An embodiment of the present invention also provides a non - transitory computer - readable storage medium, which can be set in an electronic device to store at least one instruction or at least one program segment related to implementing a method in the method embodiment. The at least one instruction or the at least one program segment is loaded and executed by the processor to implement the method provided in the above - mentioned embodiment.

[0100] An embodiment of the present invention also provides an electronic device, including a processor and the aforementioned non - transitory computer - readable storage medium.

[0101] An embodiment of the present invention also provides a computer program product, which includes program code. When the program product runs on an electronic device, the program code is used to cause the electronic device to execute the steps in the method according to various exemplary embodiments of the present invention described above in this specification.

[0102] Although some specific embodiments of the present invention have been described in detail by way of examples, those skilled in the art should understand that the above examples are for illustrative purposes only and not for limiting the scope of the present invention. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the present invention. The scope of the present invention is defined by the appended claims.

Claims

1. A method for identifying brute-force cracking behavior of a database, characterized in that, The method includes the following steps: Obtain the login traffic of the target database; Obtain the traffic determination rules of the target database; the traffic determination rules include a login success determination rule and a login failure determination rule; the traffic determination rules are used to determine the type of the login traffic; According to the traffic determination rules, determine the determination traffic value corresponding to each preset time period; The determination traffic value is the quantity of each type of traffic in the login traffic obtained in the preset time period; According to the determination traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period, determine whether there is an act of brute-forcing the target database in each preset time period; According to the determination traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic obtained in each preset time period, determining whether there is an act of brute-forcing the target database in each preset time period includes: If the sum of the determination traffic values corresponding to the preset time period is greater than the first threshold, perform abnormal determination processing on the login traffic obtained in the preset time period; Based on the abnormal determination processing, determine whether there is an act of brute-forcing the target database in the preset time period; The source IP and destination IP in the login traffic obtained in the preset time period are both multiple, and multiple said source IPs are the same and multiple said destination IPs are different; The abnormal determination processing includes: If the source IP does not belong to a malicious IP, and the quantity of the traffic belonging to the login failure type in the determination traffic value corresponding to the preset time period is greater than the first threshold, determine that the source IP is a victim, and the victim is performing a brute-forcing act on the target databases corresponding to multiple said destination IPs.

2. The method according to claim 1, wherein The source IP and destination IP in the login traffic obtained in the preset time period are both multiple, and multiple said source IPs are the same and multiple said destination IPs are the same; The abnormal determination processing includes: If the quantity of the traffic belonging to the login failure type in the determination traffic value corresponding to the preset time period is greater than the first threshold, and the quantity of the traffic belonging to the login success type is zero, determine that the source IP is an attacker, and the attacker is performing a brute-forcing act on the target database corresponding to the destination IP.

3. The method according to claim 1, characterized in that, The source IP and destination IP in the login traffic obtained in the preset time period are both multiple, and multiple said source IPs are the same and multiple said destination IPs are the same; The abnormal determination processing includes: If there is traffic belonging to the login success type in the determination traffic value corresponding to the preset time period, and there are multiple traffic of the login failure type before each traffic of the login success type, determine that the source IP is an attacker, and the attacker is performing a brute-forcing act on the target database corresponding to the destination IP and has successfully cracked it.

4. The method according to any one of claims 2-3, characterized in that, The abnormal determination processing further includes: If there is a weak password in the login traffic obtained in the preset time period, determine that the target database corresponding to the destination IP is being brute-forced.

5. The method according to claim 1, wherein Obtaining the traffic determination rules of the target database includes: Build a database environment corresponding to each target database; Simulate the login behavior of the target database in each of the said database environments; the login behavior includes login request behavior, login success behavior, and login failure behavior; Generate a traffic determination rule for the target database according to the characteristics corresponding to the login behavior.

6. An identification device for brute-force cracking database behavior, characterized in that, It includes: A first acquisition module for acquiring the login traffic of the target database; A second acquisition module for acquiring the traffic determination rule of the target database; the traffic determination rule includes a login success determination rule and a login failure determination rule; the traffic determination rule is used to determine the type of the login traffic; A determination module for determining the determined traffic value corresponding to each preset time period according to the traffic determination rule; The determined traffic value is the quantity of each type of traffic in the login traffic acquired in the preset time period; A cracking behavior determination module for determining whether there is a brute-force cracking behavior of the target database in each preset time period according to the determined traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic acquired in each preset time period; Determining whether there is a brute-force cracking behavior of the target database in each preset time period according to the determined traffic value corresponding to each preset time period and the source IP and destination IP in the login traffic acquired in each preset time period includes: If the sum of the determined traffic values corresponding to the preset time period is greater than a first threshold, perform abnormal determination processing on the login traffic acquired in the preset time period; Based on the abnormal determination processing, determine whether there is a brute-force cracking behavior of the target database in the preset time period; There are multiple source IPs and destination IPs in the login traffic acquired in the preset time period, and multiple said source IPs are the same and multiple said destination IPs are different; The abnormal determination processing includes: If the source IP does not belong to a malicious IP, and the quantity of the traffic belonging to the login failure type in the determined traffic value corresponding to the preset time period is greater than the first threshold, determine that the source IP is a victim, and the victim is performing a brute-force cracking behavior on the target databases corresponding to multiple said destination IPs.

7. A non-transitory computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements a method for identifying a brute-force cracking database behavior as described in any one of claims 1 to 5.

8. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements a method for identifying a brute-force cracking database behavior as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • A method and a system for coping with violent cracking behaviors by using big data analysis

    CN109862029A

  • Brute force attack identification method and related assembly

    CN115396202A