Vulnerability determination method and device, electronic equipment and storage medium

By simulating attacks on the metadata service of cloud server instances, vulnerabilities were detected, thus mitigating the risk of metadata leakage from cloud server instances and improving the security and detection efficiency of cloud services.

CN116707836BActive Publication Date: 2025-11-21TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210171714.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-24
Publication Date
2025-11-21
Estimated Expiration
2042-02-24

AI Technical Summary

Technical Problem

Cloud server instances pose a risk of metadata leakage, which affects the security of cloud services.

Method used

By simulating attacks on the metadata service of cloud server instances, and utilizing site requests carrying preset abnormal parameters and preset metadata service request information, vulnerabilities in the metadata service can be detected.

Benefits of technology

It enables proactive detection of cloud server instance metadata services, improving the security and flexibility of cloud services and enhancing the detection efficiency of metadata leaks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116707836B_ABST
    Figure CN116707836B_ABST
Patent Text Reader

Abstract

The application discloses a vulnerability determination method and device, electronic equipment and storage medium. The method comprises the following steps: in response to a vulnerability determination instruction, a site request indicating a specified site is determined; when the site request carries a preset abnormal parameter, the site request is updated by using a preset metadata service request information; the updated site request is sent to the specified site to obtain a site response; when the site response carries at least one preset identity credential parameter, a target vulnerability determination result indicating that the metadata service has a vulnerability is obtained. The application can be applied to various scenes such as cloud technology, artificial intelligence, intelligent transportation and auxiliary driving. The application uses the site deployed on the cloud server instance to detect the vulnerability of the metadata service of the cloud server instance, realizes active detection of metadata leakage, and improves the use safety of the cloud service instance. The active detection of metadata leakage disclosed in the application has good adaptability in application.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet communication, and in particular to a vulnerability determination method and device, electronic equipment and a storage medium. BACKGROUND

[0002] With the development of Internet communication technology, cloud services have emerged. Cloud services are based on the increase, use and interaction mode of related services on the Internet, and usually involve providing dynamically scalable and often virtualized resources through the Internet. Related objects can achieve cloud service use experience through related Internet products that provide cloud service business. In related technologies, there are certain security risks in the cloud service use experience of related objects, such as the risk of metadata leakage of the used cloud server instance. Therefore, a safer cloud service use scheme needs to be provided. SUMMARY

[0003] In order to solve the problem that the used cloud server instance has a metadata leakage risk when the related object uses the cloud server instance in the prior art, the present application provides a vulnerability determination method, device, electronic equipment and storage medium:

[0004] According to a first aspect of the present application, a vulnerability determination method is provided, the method comprising:

[0005] In response to a vulnerability determination instruction, a site request indicating a specified site is determined; wherein the specified site is created by an object with identity credentials on a specified cloud server instance, and the specified cloud server instance provides metadata services;

[0006] When the site request carries a preset abnormal parameter, the site request is updated using a preset metadata service request information; wherein the preset metadata service request information is used to simulate an attack on the metadata service;

[0007] The updated site request is sent to the specified site to obtain a site response;

[0008] When the site response carries at least one preset identity credential parameter, a target vulnerability determination result indicating that the metadata service has a vulnerability is obtained.

[0009] According to a second aspect of the present application, a vulnerability determination device is provided, the device comprising:

[0010] A response module: configured to determine, in response to a vulnerability determination instruction, a site request indicating a specified site; wherein the specified site is created by an object with identity credentials on a specified cloud server instance, and the specified cloud server instance provides metadata services;

[0011] an updating module configured to update the site request by using preset metadata service request information when the site request carries preset abnormal parameters, wherein the preset metadata service request information is used to simulate an attack on the metadata service;

[0012] a sending module configured to send the updated site request to the specified site to obtain a site response;

[0013] a determining module configured to obtain a target vulnerability determination result indicating that the metadata service has a vulnerability when the site response carries at least one preset identity credential parameter.

[0014] According to a third aspect of the present application, an electronic device is provided, which includes a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the vulnerability determination method according to the first aspect.

[0015] According to a fourth aspect of the present application, a computer-readable storage medium is provided, the storage medium storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by a processor to implement the vulnerability determination method according to the first aspect.

[0016] According to a fifth aspect of the present application, a computer program product or a computer program is provided, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions to enable the computer device to perform the vulnerability determination method according to the first aspect.

[0017] The vulnerability determination method, device, electronic device and storage medium provided by the present application have the following technical effects:

[0018] The application determines a site request indicating a specified site in response to a vulnerability determination instruction; then, when the site request carries a preset abnormal parameter, the site request is updated by using preset metadata service request information; further, the updated site request is sent to the specified site to obtain a site response; finally, when the site response carries at least one preset identity credential parameter, a target vulnerability determination result indicating that the metadata service has a vulnerability is obtained. The application performs vulnerability detection on the metadata service of the cloud server instance by means of the site deployed on the cloud server instance, realizes active detection of metadata leakage, and improves the use safety of the cloud service instance. Compared with passive defense of metadata leakage, the active detection of metadata leakage involved in the application is more flexible, adaptive and convenient in application, and ensures the effectiveness of realizing safer cloud service use. Compared with an arbitrary site request, the application uses a site request carrying a preset abnormal parameter and preset metadata service request information to perform a simulation attack on the metadata service, improves the pertinence of the simulation attack, and improves the efficiency of active detection of metadata leakage. BRIEF DESCRIPTION OF DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, and the advantages thereof, a brief introduction will be given to the drawings needed in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can be obtained without creative labor based on these drawings.

[0020] Figure 1 is a schematic diagram of an application environment provided by an embodiment of the application;

[0021] Figure 2 is a flowchart of a vulnerability determination method provided by an embodiment of the application;

[0022] Figure 3 is a flowchart of obtaining a first site request indicating a target abnormal parameter provided by an embodiment of the application;

[0023] Figure 4 is an interface diagram related to vulnerability determination provided by an embodiment of the application;

[0024] Figure 5 is a block diagram of a vulnerability determination device provided by an embodiment of the application;

[0025] Figure 6 is a structural diagram of an electronic device provided by an embodiment of the application. DETAILED DESCRIPTION

[0026] With reference to the drawings and the embodiments of the present application, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments of the present application, all the other embodiments obtained by those skilled in the art without creative work fall within the scope of the present application.

[0027] It should be noted that the terms “include” and “have” and any variations thereof in the specification and claims of the present application and the above drawings are intended to cover the non-exclusive inclusion, for example, a process, method, system, product or server including a series of steps or units need not be limited to those clearly listed steps or units, but can include other steps or units not clearly listed or inherent to the process, method, product or device.

[0028] Before the embodiments of the present application are further described in detail, the terms and phrases involved in the embodiments of the present application are explained, which are applicable to the following explanations.

[0029] Instance metadata: relevant data of an instance, which can be used to configure or manage a running instance. A user can view the metadata of an instance in a running instance through a metadata service.

[0030] POC (Proof of Concept): opinion proof, which can be an explanation or an example of an attack, to confirm that the relevant vulnerability is real.

[0031] Web crawler: a program or script that automatically crawls the World Wide Web information according to certain rules.

[0032] Please refer to Figure 1 , Figure 1 is a schematic diagram of an application environment provided by the embodiments of the present application, which can include a client 10 and a server 20. The client 10 and the server 20 can be directly or indirectly connected through wired or wireless communication. Related objects (such as users, simulators) can send vulnerability determination instructions to the server 20 through the client 10. The server 20 can determine a site request indicating a specified site according to the received vulnerability determination instruction; then, when the site request carries a preset abnormal parameter, update the site request by using a preset metadata service request information; further, send the updated site request to the specified site to obtain a site response; finally, when the site response carries at least one preset identity credential parameter, obtain a target vulnerability determination result indicating that the metadata service has a vulnerability. It should be noted that, Figure 1It is only an example. The client 10 can be an entity device such as a smart phone, a computer (such as a desktop computer, a tablet computer, a notebook computer), an augmented reality (AR) / virtual reality (VR) device, a digital assistant, a smart voice interaction device (such as a smart speaker), a smart wearable device, a smart home appliance, a vehicle terminal, etc., or a software such as a computer program running in the entity device. The operating system corresponding to the client 10 can be an Android system, an iOS system (a mobile operating system developed by Apple Inc.), a Linux system, a Microsoft Windows system, etc.

[0033] The server 20 can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and basic cloud computing services such as big data and artificial intelligence platforms. The server can include a network communication unit, a processor, a memory, etc. The server 20 can provide background services for the corresponding client.

[0034] In actual applications, the vulnerability determination scheme provided in the present application can be applied to cloud security (Cloud Security) technology. Cloud security refers to a general term for security software, hardware, users, institutions, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and unknown virus behavior judgment. Through the abnormal monitoring of software behavior in the network by a large number of clients in a network, the latest information of Internet Trojans and malicious programs is obtained and sent to the server for automatic analysis and processing, and the solutions for viruses and Trojans are distributed to each client. The main research directions of cloud security include: 1. Cloud computing security, mainly studying how to protect the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, compliance audit, etc.; 2. Cloudification of security infrastructure, mainly studying how to build and integrate security infrastructure resources using cloud computing, optimize security protection mechanisms, including building a large-scale security event, information collection and processing platform through cloud computing technology, realizing the collection and correlation analysis of massive information, and improving the network security event control ability and risk control ability; 3. Cloud security services, mainly studying various security services provided for users based on cloud computing platforms, such as antivirus services, etc.

[0035] The vulnerability determination scheme provided by the application can be applied to a vulnerability scanning product for a service on a cloud and a risk assessment tool on the cloud, and the data leakage of a metadata service in an instance on the cloud is determined through scanning and detection of assets on the cloud, risks are found, and metadata leakage problems existing in the service are detected, so that serious security problems caused by metadata information leakage are prevented.

[0036] The following introduces a specific embodiment of a vulnerability determination method of the application, Figure 2 is a flowchart of a vulnerability determination method provided by an embodiment of the application, and the application provides the method operation steps as described in the embodiments or the flowchart, but more or fewer operation steps can be included based on conventional or non-creative labor. The order of steps listed in the embodiments is only one of the many execution orders of the steps, and does not represent the only execution order. In actual system or product execution, the method order shown in the embodiments or the drawings can be executed in sequence or in parallel (for example, in a parallel processor or multi-threaded processing environment). Specifically, as shown in Figure 2 The method can include:

[0037] S201: In response to a vulnerability determination instruction, a site request indicating a specified site is determined; wherein the specified site is created by an object with an identity credential on a specified cloud server instance, and the specified cloud server instance provides a metadata service;

[0038] In an embodiment of the application, in response to a vulnerability determination instruction, a server end determines a site request indicating a specified site. The vulnerability determination instruction can be triggered and generated by a client and sent to the server end, or the vulnerability determination instruction can be triggered and generated by the server end. The vulnerability determination instruction can carry the representation information of the specified site, and the site request can be determined through the representation information of the specified site. Exemplarily, a first object (such as a user, a simulator) can send a vulnerability determination instruction to the server end through a client, and the vulnerability determination instruction can be generated based on the representation information of the specified site.

[0039] The specified site is set on the specified cloud server instance, and the specified site can be a website supported by the specified cloud server instance. The specified site is created on the specified cloud server instance by a second object (such as a user, a simulator) having identity credentials. The identity credentials possessed by the second object can be a use permission for the specified cloud server instance, and accordingly, the second object having the identity credentials can deploy the specified site on the specified cloud server instance. The specified cloud server instance provides a metadata service, and the second object can view relevant data about the specified cloud server instance through the metadata service, that is, data that can be used to configure or manage the specified cloud server instance. It can be understood that the second object can realize a cloud service use experience through a relevant Internet product (such as a product provided by a cloud vendor) that provides a cloud service business. The second object can own the use permission of the cloud resource by transferring the resource value. The cloud resource owned by the second object can be a cloud server resource, and the cloud server resource can correspond to the specified cloud server instance. The second object can create a website service based on a web application running on the specified cloud server instance, and the website service can correspond to the specified site. It should be noted that the first object in the above example can be the second object, or can not be the second object.

[0040] The following will introduce the site request indicating the specified site:

[0041] 1) The site request indicating the specified site is determined in response to the vulnerability determination instruction, which can include the following steps: first, determining site interface information indicating the specified site from a preset interface document according to the vulnerability determination instruction; then, obtaining an access request matched with the site interface information to obtain the site request.

[0042] The method for determining the site request by means of the preset interface document can ensure the accuracy of the determined site request, and can provide a reliable data source for the subsequent step for sending to the specified site. The vulnerability determination instruction can carry the characterization information of the specified site, and the characterization information of the specified site can be an interface identifier (such as an interface name) indicating the specified site. The preset interface document can record interface information in the interface identifier dimension, such as recording interface description information (such as interface call description and interface parameter description) corresponding to an interface identifier. The interface description information corresponding to the interface identifier indicating the specified site can be determined from the preset interface document to obtain the site interface information. The access request matched with the site interface information can be an access request meeting the requirements indicated by the site description information. The interface involved herein can be an application programming interface (API). It can be understood that the preset interface document can be a special interface document of the specified site, and the interface information recorded in the preset interface document is all related to the specified site. Therefore, the interface identifier indicating the specified site can be regarded as an anchor point, and thus the site interface information is determined and the access request matched therewith is obtained, which can improve the pertinence of the determined site request. In combination with the subsequent preset abnormal parameter, the interface identifier indicating the specified site can be an interface identifier containing the preset abnormal parameter. The preset interface document can also be a general interface document for site creation, and there can be interface information unrelated to the specified site in the interface information recorded in the preset interface document. Therefore, the interface identifier indicating the specified site can also be regarded as an anchor point, and thus the site interface information is determined and the access request matched therewith is obtained, which can ensure that the determined site request is the one indicating the specified site.

[0043] 2) The site request indicating the specified site can be determined in response to the vulnerability determination instruction, which can include the following steps: first, determining site description information indicating the specified site according to the vulnerability determination instruction; then, obtaining a corresponding candidate link according to the site description information; and further, performing site-dimension filtering processing on the candidate link to obtain the site request by using the filtering result.

[0044] The method provided herein can improve the efficiency and accuracy of determining the site request, and can provide a reliable and rich data source for subsequent steps for sending to the specified site. The vulnerability determination instruction can carry the characterization information of the specified site, and the characterization information of the specified site can be site description information (such as site address information) indicating the specified site. The site description information indicating the specified site can be read from the vulnerability determination instruction, and then the candidate links matching the site description information can be crawled. Taking www.A.com as an example of site description information, the page links related to www.A.com (including the first type of page links directly related to www.A.com, and the second type of page links contained in the page corresponding to the first type of page links) can be crawled as candidate links. Considering that there can be page links pointing to other sites (such as www.B.com) in the candidate links (such as the second type of page links), the candidate links are filtered in relation to www.A.com, and then the access request corresponding to the filtering result, i.e., the site request, is obtained. The process of obtaining candidate links can involve web page js code analysis and html tag parsing.

[0045] In actual applications, the determined site request indicating the specified site can be a POST request, a GET request, etc. The determined site request indicating the specified site can be multiple, and then a site request list is obtained.

[0046] S202: When the site request carries a preset abnormal parameter, updating the site request by using a preset metadata service request information; wherein, the preset metadata service request information is used to simulate an attack on the metadata service;

[0047] In the embodiments of the present application, when the site request carries a preset abnormal parameter, the server side updates the site request by using a preset metadata service request information. The preset abnormal parameter can be a parameter item associated with the metadata service vulnerability, and the preset abnormal parameter can be determined based on the feedback result indicating the metadata service vulnerability. The metadata service vulnerability can be determined by using the vulnerability determination scheme provided in the embodiments of the present application, or can be determined according to other vulnerability determination schemes. The feedback result indicating the metadata service vulnerability can include the relevant parameters of the code logic triggering data leakage determined after investigation.

[0048] The site request carries an abnormal parameter, which means that the site request has the possibility of triggering data leakage, and then it is also convenient to use it as the basis for constructing a simulated attack request, and the efficiency of active detection of metadata leakage is also improved.

[0049] The preset metadata service request information is used to simulate an attack on the metadata service. The preset metadata service request information can include a request to obtain the content of the metadata service, such as interface address information indicating the metadata service. The preset metadata service request information is used to update the site request, and the updated site request is a simulation attack request. In the process of updating the site request, the preset metadata service request information is transmitted into the site request to add a simulation attack function to the site request.

[0050] In an exemplary embodiment, before the site request is updated by using the preset metadata service request information, the method can further include the following steps: first, determining whether the site request carries matching parameters based on a preset abnormal parameter set; and then, when the site request carries matching parameters, determining that the site request carries the preset abnormal parameters. That is, whether the site request carries matching parameters can be determined based on the preset abnormal parameter set, and then the determination of whether the site request carries the preset abnormal parameters is realized.

[0051] With reference to the preset abnormal parameter set, if there is a parameter in the parameters carried by the site request that falls within the preset abnormal parameter set, it is determined that the site request carries the preset abnormal parameters; otherwise, it is determined that the site request does not carry the preset abnormal parameters. The site request that does not carry the preset abnormal parameters is not used as the basis for constructing a simulation attack request and does not need to be updated by using the preset metadata service request information. For example, the parameters carried by the site request 1 include {parameter 1, parameter 2, parameter 3, parameter 4, parameter 5}, and the preset abnormal parameter set includes parameters {parameter 3, parameter 4, parameter 5, parameter 6, parameter 7}. The parameters {parameter 3, parameter 4, parameter 5} carried by the site request 1 are matching parameters, and accordingly, the site request 1 carries the preset abnormal parameters. It can be understood that if there is at least one matching parameter in the parameters carried by the site request, the site request carries at least one preset abnormal parameter, and the at least one matching parameter corresponds to the at least one preset abnormal parameter one-to-one. As long as there is one matching parameter in the parameters carried by the site request, it can be determined that the site request carries the preset abnormal parameters, and then the site request carrying the preset abnormal parameters is used as the basis for constructing a simulation attack request, so that the site request carrying the preset abnormal parameters is updated by using the preset metadata service request information. In this way, the number of site requests used as the basis for constructing a simulation attack request can be increased, and the richness of the site requests used as the basis for constructing a simulation attack request can be realized. On this basis, the sufficiency and comprehensiveness of the active detection of metadata leakage can be ensured, and the accuracy of vulnerability determination can be improved.

[0052] If the site request carries a preset abnormal parameter, the preset abnormal parameter is taken as a basis for constructing the simulation attack request. The following describes a process of updating the site request by using the preset metadata service request information:

[0053] 1) The site request carries a preset abnormal parameter:

[0054] The preset metadata service request information can be added to the site request, and an association between the preset metadata service request information and the preset abnormal parameter can be established. The establishment of the association can improve the simulation attack effect of the preset metadata service request information. It can be understood that the establishment of the association ensures that the specified site responds to the preset abnormal parameter and also responds to the preset metadata service request information. It should be noted that the specified site responding to the preset metadata service request information can only read the preset metadata service request information without providing feedback information, or can read the preset metadata service request information and provide feedback information.

[0055] 2) The site request carries at least two preset abnormal parameters:

[0056] When the site request carries at least two preset abnormal parameters, the updating of the site request by using the preset metadata service request information can include the following steps: first, for each of the at least two preset abnormal parameters, the following steps are performed to obtain an updated first site request indicating each preset abnormal parameter: determining that the preset abnormal parameter is a target abnormal parameter; and adding the preset metadata service request information to the site request and establishing an association between the preset metadata service request information and the target abnormal parameter to obtain an updated first site request indicating the target abnormal parameter; then, based on the updated first site request indicating each of the at least two preset abnormal parameters, at least two updated site requests are obtained; wherein the at least two updated site requests correspond one-to-one to the at least two preset abnormal parameters.

[0057] The establishment of the association between the preset metadata service request information and the target abnormal parameter can refer to the above "establishment of the association between the preset metadata service request information and the preset abnormal parameter", and will not be described again. For example, the at least two preset abnormal parameters carried by the site request 1 are {parameter 3, parameter 4, parameter 5}, then:

[0058] a) Taking parameter 3 as a target abnormal parameter, adding a preset metadata service request information to the site request 1, and establishing an association between the preset metadata service request information and parameter 3, to obtain an updated first site request 1 indicating parameter 3, i.e. a simulation attack request a;

[0059] b) adding the preset metadata service request information to the site request 1, taking the parameter 4 as the target abnormal parameter, and establishing the association between the preset metadata service request information and the parameter 4, obtaining the updated first site request 2 indicating the parameter 4, i.e. the simulation attack request b;

[0060] c) adding the preset metadata service request information to the site request 1, taking the parameter 5 as the target abnormal parameter, and establishing the association between the preset metadata service request information and the parameter 5, obtaining the updated first site request 3 indicating the parameter 5, i.e. the simulation attack request c.

[0061] Therefore, based on the updated first site request 1 indicating the parameter 3, the updated first site request 2 indicating the parameter 4, and the updated first site request 3 indicating the parameter 5, three updated site requests 1, i.e. simulation attack requests a-c, can be obtained. When the site request carries at least two preset abnormal parameters, the preset metadata service request information is transmitted to construct the simulation attack request according to the dimension of the preset abnormal parameter. This can improve the efficiency, accuracy and convenience of identifying the code logic that triggers data leakage after determining the vulnerability.

[0062] Considering the number of simulation attack codes included in the preset metadata service request information, the process of updating the site request using the preset metadata service request information can be further introduced as follows:

[0063] 1.1) The site request carries one preset abnormal parameter, and the preset metadata service request information includes one piece of simulation attack code:

[0064] The simulation attack code can be transmitted to the target position of the site request, which is the position associated with the preset abnormal parameter in the site request, such as splicing the simulation attack code with the parameter information corresponding to the preset abnormal parameter, and the splicing point can be the tail of the parameter information corresponding to the preset abnormal parameter. The target position of the site request needs to ensure that the specified site responds to the preset abnormal parameter while also responding to the simulation attack code.

[0065] 1.2) The site request carries one preset abnormal parameter, and the preset metadata service request information includes at least two pieces of simulation attack code:

[0066] First, for each of the at least two pieces of simulated attack code, the following steps are performed to obtain an updated second site request indicating each piece of simulated attack code: determining the simulated attack code as a target simulated attack code; and, inputting the target simulated attack code into a target position of the site request to obtain an updated second site request indicating the target simulated attack code; wherein the target position is a position in the site request associated with the preset abnormal parameter. Then, based on the updated second site request indicating each of the at least two pieces of simulated attack code, an updated first site request indicating the preset abnormal parameter is obtained, and the updated first site request indicating the preset abnormal parameter is taken as an updated site request. This process can refer to the related content in the above 1.1), and will not be repeated here. It should be noted that the number of updated site requests obtained in this way is the number of pieces of simulated attack code.

[0067] 2.1) The site request carries at least two preset abnormal parameters, and the preset metadata service request information includes a piece of simulated attack code:

[0068] First, for each of the at least two preset abnormal parameters, the following steps are performed to obtain an updated first site request indicating each preset abnormal parameter: determining the preset abnormal parameter as a target abnormal parameter; and, inputting the simulated attack code into a target position of the site request to obtain an updated first site request indicating the target abnormal parameter; wherein the target position is a position in the site request associated with the target abnormal parameter. Then, based on the updated first site request indicating each of the at least two preset abnormal parameters, at least two updated site requests are obtained. This process can refer to the related content in the above 1.1), and will not be repeated here. It should be noted that the number of updated site requests obtained in this way is the number of preset abnormal parameters.

[0069] 2.2) The site request carries at least two preset abnormal parameters, and the preset metadata service request information includes at least two pieces of simulated attack code:

[0070] It can be combined with "adding the preset metadata service request information to the site request, establishing an association between the preset metadata service request information and the target abnormal parameter, to obtain an updated first site request indicating the target abnormal parameter" in the above 2.1), as shown in Figure 3 The "adding the preset metadata service request information to the site request, establishing an association between the preset metadata service request information and the target abnormal parameter, to obtain an updated first site request indicating the target abnormal parameter" includes:

[0071] S301: For each of the at least two pieces of simulated attack code, the following steps are performed respectively to obtain an updated second site request indicating each piece of simulated attack code: determining the simulated attack code as a target simulated attack code; and passing the target simulated attack code into a target position of the site request to obtain an updated second site request indicating the target simulated attack code; wherein the target position is a position in the site request associated with the target abnormal parameter;

[0072] S302: Based on the updated second site request indicating each of the at least two pieces of simulated attack code, an updated first site request indicating the target abnormal parameter is obtained.

[0073] Based on the updated first site request indicating the target abnormal parameter, at least two updated site requests can be obtained based on the updated first site request indicating each of the at least two preset abnormal parameters. The related sub-steps in S301 can refer to the related content in 1.1) above. It should be noted that the number of updated site requests obtained is the product of the number of pieces of simulated attack code and the number of at least two preset abnormal parameters.

[0074] For example, the at least two preset abnormal parameters carried by the site request 1 are {parameter 3, parameter 4, parameter 5}, and the at least two pieces of simulated attack code are {code 1, code 2}, then:

[0075] A) Taking parameter 3 as the target abnormal parameter and code 1 as the target simulated attack code, code 1 is passed into the position associated with parameter 3 in site request 1 to obtain an updated second site request 1 indicating code 1 (belongs to the updated first site request 1 indicating parameter 3 above), that is, simulated attack request A;

[0076] B) Taking parameter 4 as the target abnormal parameter and code 1 as the target simulated attack code, code 1 is passed into the position associated with parameter 4 in site request 1 to obtain an updated second site request 2 indicating code 1 (belongs to the updated first site request 2 indicating parameter 4 above), that is, simulated attack request B;

[0077] C) Taking parameter 5 as the target abnormal parameter and code 1 as the target simulated attack code, code 1 is passed into the position associated with parameter 5 in site request 1 to obtain an updated second site request 3 indicating code 1 (belongs to the updated first site request 3 indicating parameter 5 above), that is, simulated attack request C;

[0078] D) taking parameter 3 as a target abnormal parameter and code 2 as a target simulation attack code, transmitting code 2 into a position associated with parameter 3 in site request 1 to obtain an updated second site request 4 (belonging to the above-mentioned updated first site request 1 indicating parameter 3) indicating code 2, that is, simulation attack request D;

[0079] E) taking parameter 4 as a target abnormal parameter and code 2 as a target simulation attack code, transmitting code 2 into a position associated with parameter 4 in site request 1 to obtain an updated second site request 5 (belonging to the above-mentioned updated first site request 2 indicating parameter 4) indicating code 2, that is, simulation attack request E;

[0080] F) taking parameter 5 as a target abnormal parameter and code 2 as a target simulation attack code, transmitting code 2 into a position associated with parameter 5 in site request 1 to obtain an updated second site request 6 (belonging to the above-mentioned updated first site request 3 indicating parameter 5) indicating code 2, that is, simulation attack request F.

[0081] Thus, based on the above-mentioned updated second site requests 1-3 indicating code 1 and the above-mentioned updated second site requests 4-6 indicating code 2, six updated site requests 1, that is, simulation attack requests A-F, can be obtained.

[0082] The difference of different segment simulation attack codes can point to different related Internet products (such as products provided by cloud vendors) providing cloud service businesses. For the case that the characterization information of the specified site is known but the specific information of the specified cloud server instance is unknown, the introduction of different segment simulation attack codes can improve the adaptability of active probing related to metadata leakage when updating site requests. Of course, if the specific information of the specified cloud server instance is known, the simulation attack code matching the specified cloud server instance can be selected when updating the site request to improve the efficiency of active probing related to metadata leakage.

[0083] In actual application, the determined site request indicating the specified site can be a POST request, a GET request, etc. The determined site request indicating the specified site can be multiple, and then a site request list is obtained. The site request list can be traversed, and each site request is taken out for processing. The specific processing is as follows: analyzing the POST / GET request to obtain all parameter names (items) of the POST / GET request, and finding whether there is a high-risk parameter name string (which can correspond to the above-mentioned preset abnormal parameter) in the parameter name as shown in Table 1:

[0084] Serial Number High-risk parameter name string 1 target 2 domain 3 site 4 callback 5 URL 6 image 7 src 8 address 9 share 10 wap 11 Link 12 Display 13 imageURL 14 sourceURl 15 3g 16 ImageMagick

[0085] Table 1

[0086] The high-risk parameter name string list can be flexibly extended by continuously collecting high-risk parameter names. Whether a high-risk parameter name string is included in all parameter names of each POST / GET request can be found by using a regular expression. If there is no less than one high-risk parameter name in a site request, the site request is taken as a basis for constructing a simulated attack request, and the site request is updated by using the preset metadata service request information; otherwise, the next site request is taken out for processing.

[0087] The preset metadata service request information can be a code related to a POC: metadata service payload. When the code related to the POC includes at least two segments, a configuration file of the code related to the POC can be constructed, as shown in Table 2.

[0088] Serial Number payload 1 http: / / 169.254.169.254 / latest / meta-data / iam / security-credentials / 2 http: / / 169.254.169.254 / latest / meta-data / 3 http: / / metadata / computeMetadata / v1 / 4 http: / / 169.254.169.254 / metadata / v1 / 5 http: / / 192.0.0.192 / latest / 6 http: / / 100.100.100.200 / latest / meta-data / 7 http: / / 169.254.169.254 / metadata / v1 / user-data

[0089] Table 2

[0090] The process of transmitting the preset metadata service request information into the site request can include reading the metadata service payload from the configuration file, traversing the metadata service payload, taking out a metadata service payload, and transmitting the metadata service payload into a position associated with parameter information corresponding to the high-risk parameter name in the site request, and then sending the constructed simulated attack request to the specified site. The metadata service payload in the configuration file can be an interface for accessing a metadata service to obtain credentials in products provided by different cloud vendors. When the specified site has a metadata leakage situation, the metadata service can be accessed by sending a simulated attack request to the specified site. At this time, the simulated attack request will leak the temporary credentials of the role bound to the instance on the cloud, and accordingly, it can be determined whether the specified site has an instance metadata service leakage situation.

[0091] S203: sending the updated site request to the specified site to obtain a site response;

[0092] In the embodiments of the present application, the server sends the updated site request to the specified site to obtain a site response. In combination with the description of the foregoing step S202, the updated site request is a simulated attack request, the simulated attack request is sent to the specified site, and the specified site responds to the simulated attack request, which can include a response to the site request as a basis for constructing the simulated attack request and a response to the preset metadata service request information. The response to the site request as a basis for constructing the simulated attack request can be regarded as a basic response in the site dimension. The response to the preset metadata service request information can be regarded as an extended response in the instance dimension. The former is closer to the user service of the site, and the latter is closer to the underlying service of the instance.

[0093] In combination with the foregoing content about "the station request carrying at least two preset abnormal parameters" and "adding the preset metadata service request information into the station request, and establishing the association between the preset metadata service request information and the target abnormal parameter, to obtain at least two updated station requests" in the step S202, the at least two updated station requests can be respectively sent to the specified station to obtain at least two station responses; wherein the at least two station responses correspond to the at least two updated station requests one by one.

[0094] S204: obtaining a target vulnerability determination result indicating that the metadata service has a vulnerability when the station response carries at least one preset identity credential parameter.

[0095] In the embodiments of the present application, the server obtains a target vulnerability determination result indicating that the metadata service has a vulnerability when the station response carries at least one preset identity credential parameter. In combination with the foregoing description of the step S203, the response to the station request as the basis for constructing the simulated attack request generally does not carry the preset identity credential parameter. Correspondingly, the preset identity credential parameter generally comes from the response to the preset metadata service request information. Of course, the response to the station request as the basis for constructing the simulated attack request can also carry the preset identity credential parameter. See Figure 4 Figure 4 The case where the station response carries the preset identity credential parameter is shown. The "TmpSecretId" contains the preset identity credential parameter "secretid", and the "TmpSecretKey" contains the preset identity credential parameter "secretkey".

[0096] ​The preset identity credential parameter can be at least one. The preset identity credential parameter can be a parameter item associated with instance usage permissions, such as secretid, secretkey, token, and the like. With reference to the preset identity credential parameter set, if the parameter in the parameter carried by the site response falls within the preset identity credential parameter set, it is determined that the site response carries the preset identity credential parameter; otherwise, it is determined that the site response does not carry the preset identity credential parameter. When the site response carries at least one preset identity credential parameter, a target vulnerability determination result indicating that the metadata service has a vulnerability is obtained, and then the code logic triggering data leakage is checked and the processing result of the check (such as correcting the code logic triggering data leakage) is processed. The site response carries the preset identity credential parameter, which indicates that the parameter information corresponding to the preset identity credential parameter is leaked, and there can be a security risk of using the parameter information to perform malicious operations based on instance usage permissions, especially for parameter information indicating high instance usage permissions (such as AdministratorAccess permissions). When the site response does not carry the preset identity credential parameter, a target vulnerability determination result indicating that the metadata service does not have a vulnerability is obtained.

[0097] In actual applications, the preset identity credential parameter can indicate a role temporary credential. The following strings can be matched in the body of the request response through a regular expression: secretid, secretkey, token, and if any of the three strings is matched, it indicates that the specified cloud service instance can have a metadata leakage situation.

[0098] In a cloud environment, metadata leakage of a cloud server instance has extremely high harmfulness. The instance metadata leakage detection method provided by the embodiments of the present application can effectively detect whether a web application deployed in a cloud server instance has a metadata leakage situation, and can avoid the occurrence of a metadata leakage event by actively discovering a metadata leakage risk. The embodiments of the present application can test high-risk parameters that can have a metadata leakage risk in all interfaces of a web application running on a cloud host instance in the form of active scanning, to discover whether the web application has a metadata leakage situation, and then protect the security of a tenant cloud business. The embodiments of the present application can actively scan requests of an instance on the cloud to discover a metadata information leakage situation of a cloud host instance. Compared with the difficulty of discovering a vulnerability through code auditing, this is more efficient and convenient.

[0099] It can be seen from the technical solutions provided by the embodiments of the present application that the embodiments of the present application determine a site request indicating a specified site in response to a vulnerability determination instruction; then, when the site request carries a preset abnormal parameter, the site request is updated by using preset metadata service request information; further, the updated site request is sent to the specified site to obtain a site response; finally, when the site response carries at least one preset identity credential parameter, a target vulnerability determination result indicating that the metadata service has a vulnerability is obtained. The embodiments of the present application perform vulnerability detection of the metadata service of the cloud server instance by means of the site deployed on the cloud server instance, and thus active detection of metadata leakage is realized, and the use safety of the cloud service instance is improved. Compared with passive defense against metadata leakage, the active detection of metadata leakage involved in the embodiments of the present application is more flexible, adaptive and convenient in application, and the effectiveness of realizing safer cloud service use is ensured. Compared with an arbitrary site request, the embodiments of the present application use the site request carrying the preset abnormal parameter and the preset metadata service request information to perform simulation attack on the metadata service, and thus the pertinence of the simulation attack and the efficiency of active detection of metadata leakage are improved.

[0100] The embodiments of the present application also provide a vulnerability determination apparatus, as shown in the following table: Figure 5 The vulnerability determination apparatus 50 comprises:

[0101] A response module 501 is configured to determine a site request indicating a specified site in response to a vulnerability determination instruction; wherein the specified site is created by an object with an identity credential on a specified cloud server instance, and the specified cloud server instance provides a metadata service;

[0102] An update module 502 is configured to update the site request by using preset metadata service request information when the site request carries a preset abnormal parameter; wherein the preset metadata service request information is used to simulate attack on the metadata service;

[0103] A sending module 503 is configured to send the updated site request to the specified site to obtain a site response;

[0104] A determination module 504 is configured to obtain a target vulnerability determination result indicating that the metadata service has a vulnerability when the site response carries at least one preset identity credential parameter.

[0105] It should be noted that the apparatuses in the apparatus embodiments and the method embodiments are based on the same inventive concept.

[0106] The electronic device provided by the embodiments of the present application comprises a processor and a memory, the memory stores at least one instruction or at least one program, the at least one instruction or the at least one program is loaded and executed by the processor to implement the vulnerability determination method provided by the above method embodiments.

[0107] Further, Figure 6 A hardware structure schematic diagram of an electronic device for implementing the vulnerability determination method provided by the embodiments of the present application is shown, and the electronic device can participate in constituting or containing the vulnerability determination apparatus provided by the embodiments of the present application. As shown in the figure, Figure 6 The electronic device 100 can comprise one or more processors 1002 (the processor 1002 can comprise but is not limited to a microprocessor MCU or a programmable logic device FPGA processing device, etc.), a memory 1004 for storing data, and a transmission device 1006 for communication function. In addition, it can also include a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the I / O interface), a network interface, a power supply and / or a camera. Those skilled in the art can understand that, Figure 6 The structure shown in the figure is only a schematic, which does not limit the structure of the above-mentioned electronic device. For example, the electronic device 100 can also include more or less components than those shown in the figure, or have a different configuration from that shown in the figure. Figure 6 Figure 6

[0108] It should be noted that the one or more processors 1002 and / or other data processing circuits described above can be referred to as "data processing circuits" herein. The data processing circuit can be embodied in whole or in part as software, hardware, firmware or any other combination. In addition, the data processing circuit can be a single independent processing module, or any one of the other elements combined into the electronic device 100 (or mobile device) in whole or in part. As referred to in the embodiments of the present application, the data processing circuit serves as a processor to control (for example, the selection of the variable resistance terminal path connected to the interface).

[0109] ​​The memory 1004 can be used to store software programs of application software and modules, such as program instructions / data storage means corresponding to the vulnerability determination method in the embodiments of the present application, and the processor 1002 can execute various functional applications and data processing, i.e., implement the vulnerability determination method described above, by running the software programs and modules stored in the memory 1004. The memory 1004 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 1004 can further include memories remotely arranged with respect to the processor 1002, which can be connected to the electronic device 100 through a network. Examples of the network can include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0110] The transmission device 1006 is configured to receive or send data via a network. Specific examples of the network can include a wireless network provided by a communication provider of the electronic device 100. In one example, the transmission device 1006 includes a network interface controller (NIC) that can be connected to other network devices through a base station so as to be able to communicate with the Internet. In one embodiment, the transmission device 1006 can be a radio frequency (RF) module configured to communicate with the Internet in a wireless manner.

[0111] The display can be, for example, a touch screen type liquid crystal display (LCD) that can enable a user to interact with a user interface of the electronic device 100 (or mobile device).

[0112] The embodiments of the present application also provide a computer readable storage medium that can be arranged in an electronic device to save at least one instruction or at least one program for implementing a vulnerability determination method in the method embodiments, and the at least one instruction or the at least one program is loaded and executed by the processor to implement the vulnerability determination method provided by the above method embodiments.

[0113] Optionally, in the present embodiment, the above-mentioned storage medium can be located in at least one of a plurality of network servers of a computer network. Optionally, in the present embodiment, the above-mentioned storage medium can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0114] It should be noted that the above-mentioned order of the embodiments of the present application is only for description, and does not represent the advantages and disadvantages of the embodiments. And the above-mentioned specific embodiments of the present application are described. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from the order in the embodiments and still achieve the desired result. In addition, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve the desired results. In certain implementations, multi-task processing and parallel processing are possible or can be advantageous.

[0115] Each of the embodiments in the present application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. Especially, for the device and electronic equipment embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiments.

[0116] A person of ordinary skill in the art can understand that all or part of the steps of the above-mentioned embodiments can be completed by hardware, or by program instructing relevant hardware to complete, and the program can be stored in a computer readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk.

[0117] The above-mentioned is only the preferred embodiment of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A vulnerability identification method, characterized in that, The method includes: In response to a vulnerability determination instruction, a site request indicating a specified site is determined; wherein the specified site is created by an object with identity credentials on a specified cloud server instance, the specified site is a website supported by the specified cloud server instance, and the specified cloud server instance provides metadata services; When the site request carries preset abnormal parameters, the site request is updated using preset metadata service request information; wherein, the preset metadata service request information is used to simulate an attack on the metadata service, and the preset abnormal parameters are parameter items that are related to metadata service vulnerabilities; Send an updated site request to the specified site to obtain a site response; When the site response carries at least one preset identity credential parameter, a target vulnerability determination result indicating that the metadata service has a vulnerability is obtained.

2. The method according to claim 1, characterized in that, Before updating the site request using preset metadata service request information, the method further includes: The system determines whether the site request carries matching parameters based on a preset set of abnormal parameters; wherein the preset set of abnormal parameters includes multiple candidate parameters. When the site request carries matching parameters, it is determined that the site request carries the preset abnormal parameters.

3. The method according to claim 1, characterized in that: When the site request carries at least two preset exception parameters, updating the site request using preset metadata service request information includes: For each of the at least two preset abnormal parameters, the following steps are performed to obtain an updated first site request indicating each preset abnormal parameter: determining the preset abnormal parameter as a target abnormal parameter; and adding the preset metadata service request information to the site request and establishing the association between the preset metadata service request information and the target abnormal parameter to obtain an updated first site request indicating the target abnormal parameter. Based on the updated first site request indicating each of the at least two preset abnormal parameters, at least two updated site requests are obtained; wherein, the at least two updated site requests correspond one-to-one with the at least two preset abnormal parameters; Sending the updated site request to the designated site to obtain a site response includes: The at least two updated site requests are sent to the designated site respectively to obtain at least two site responses; wherein the at least two site responses correspond one-to-one with the at least two updated site requests.

4. The method according to claim 3, characterized in that, The preset metadata service request information includes at least two pieces of simulated attack code. Adding the preset metadata service request information to the site request and establishing the association between the preset metadata service request information and the target anomaly parameter to obtain a first site request indicating an update to the target anomaly parameter includes: For each of the at least two simulated attack code segments, the following steps are performed to obtain an updated second site request indicative of each simulated attack code segment: determining the simulated attack code as the target simulated attack code; and passing the target simulated attack code to the target location of the site request to obtain an updated second site request indicative of the target simulated attack code; wherein, the target location is the location in the site request associated with the target anomaly parameter; Based on the updated second site request indicating each of the at least two simulated attack code segments, an updated first site request indicating the target anomaly parameters is obtained.

5. The method according to claim 1, characterized in that, The response to the vulnerability determination instruction, determining the site request indicating the specified site, includes: Based on the vulnerability determination instruction, determine the site interface information indicating the specified site from the preset interface document; Obtain the access request that matches the site interface information to obtain the site request.

6. The method according to claim 1, characterized in that, The response to the vulnerability determination instruction, determining the site request indicating the specified site, includes: Based on the vulnerability determination instruction, determine the site description information indicating the specified site; Obtain the corresponding candidate links based on the site description information; The candidate links are filtered at the site level to obtain the site request using the filtering results.

7. A vulnerability determination device, characterized in that, The device includes: Response module: Used to respond to vulnerability determination instructions and determine the site request indicating the specified site; wherein, the specified site is created by an object with identity credentials on the specified cloud server instance, the specified site is a website supported by the specified cloud server instance, and the specified cloud server instance provides metadata services; Update module: used to update the site request with preset metadata service request information when the site request carries preset abnormal parameters; wherein, the preset metadata service request information is used to simulate an attack on the metadata service, and the preset abnormal parameters are parameter items that are related to metadata service vulnerabilities; Sending module: Used to send the updated site request to the specified site to obtain a site response; Determination module: When the site response carries at least one preset identity credential parameter, it obtains a target vulnerability determination result indicating that the metadata service has a vulnerability.

8. The apparatus according to claim 7, characterized in that, The device is further configured to: before updating the site request using preset metadata service request information, determine whether the site request carries matching parameters based on a preset abnormal parameter set; wherein the preset abnormal parameter set includes multiple candidate parameters; when the site request carries matching parameters, it is determined that the site request carries the preset abnormal parameters.

9. The apparatus according to claim 7, characterized in that: When the site request carries at least two preset exception parameters, the update module is also used to: For each of the at least two preset abnormal parameters, the following steps are performed to obtain an updated first site request indicating each preset abnormal parameter: determining the preset abnormal parameter as a target abnormal parameter; and adding the preset metadata service request information to the site request and establishing the association between the preset metadata service request information and the target abnormal parameter to obtain an updated first site request indicating the target abnormal parameter. Based on the updated first site request indicating each of the at least two preset abnormal parameters, at least two updated site requests are obtained; wherein, the at least two updated site requests correspond one-to-one with the at least two preset abnormal parameters; The sending module is further configured to: send the at least two updated site requests to the designated site respectively to obtain at least two site responses; wherein the at least two site responses correspond one-to-one with the at least two updated site requests.

10. The apparatus according to claim 9, characterized in that, The preset metadata service request information includes at least two pieces of simulated attack code. Adding the preset metadata service request information to the site request and establishing the association between the preset metadata service request information and the target anomaly parameter to obtain a first site request indicating an update to the target anomaly parameter includes: For each of the at least two simulated attack code segments, the following steps are performed to obtain an updated second site request indicative of each simulated attack code segment: determining the simulated attack code as the target simulated attack code; and passing the target simulated attack code to the target location of the site request to obtain an updated second site request indicative of the target simulated attack code; wherein, the target location is the location in the site request associated with the target anomaly parameter; Based on the updated second site request indicating each of the at least two simulated attack code segments, an updated first site request indicating the target anomaly parameters is obtained.

11. The apparatus according to claim 7, characterized in that, The response module is further configured to: determine the site interface information indicating the specified site from a preset interface document according to the vulnerability determination instruction; and obtain an access request that matches the site interface information to obtain the site request.

12. The apparatus according to claim 7, characterized in that, The response module is further configured to: determine site description information indicating the specified site according to the vulnerability determination instruction; obtain corresponding candidate links according to the site description information; and perform site-level filtering on the candidate links to obtain the site request using the filtering results.

13. An electronic device, characterized in that, The electronic device includes a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the vulnerability determination method as described in any one of claims 1-6.

14. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction or at least one program segment, which is loaded and executed by a processor to implement the vulnerability determination method as described in any one of claims 1-6.

15. A computer program product, characterized in that, The computer program product includes at least one instruction or at least one program segment, which is loaded and executed by a processor to implement the vulnerability determination method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Cross-domain resource sharing vulnerability detection method and device, equipment and medium

    CN110266737A

  • Vulnerability detection method and device, computer equipment and storage medium

    CN112231711A