An attack determination method, device, equipment and medium

By extracting and rendering the response traffic of the victim host when the attack payload does not have a target address, it solves the problem of high misjudgment rate in the prior art and improves the accuracy of the successful judgment of the attack.

CN117439807BActive Publication Date: 2025-05-27BEIJING THREATBOOK TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311578702.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-23
Publication Date
2025-05-27
Estimated Expiration
2043-11-23

AI Technical Summary

Technical Problem

When detecting cross-site scripting attacks, a single method can easily cause misjudgment, resulting in a decrease in the accuracy of successful attack judgments.

Method used

By extracting the victim host's response traffic when the target address does not exist in the attack payload, it is possible to determine whether the victim host is successfully attacked based on the rendering result.

Benefits of technology

Improves the accuracy of successful attack judgment, reduces misjudgment, and improves the security of the equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117439807B_ABST
    Figure CN117439807B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides an attack determination method, device, equipment and medium. The method includes: when detecting an attack event in a victim host, parsing an attack payload corresponding to the attack event to determine whether a target address exists in the attack payload; when confirming that the target address does not exist in the attack payload, extracting response traffic of the victim host, where the target address is used to cause the victim host to perform an external connection operation; rendering the response traffic to obtain a rendering result, and determining whether the victim host is successfully attacked according to the rendering result. Through some embodiments of the present application, it is possible to judge whether an attack is successful by rendering response traffic, so as to accurately judge the behavior of a successful attack on an attack event and improve the security of the device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and particularly to a method, device, equipment and medium for attack determination. Background Art

[0002] With the rapid development of information technology, computers and networks have become essential tools and means for daily office work, communication and collaborative interaction. Therefore, information security has become increasingly important, and threat detection, as an important topic in the field of information security, has been receiving increasing attention.

[0003] The data packet detection technology based on network traffic is a key link in threat detection. In related technologies, when a security device detects a large number of attacks caused by cross-site scripting, it gives an alarm. Further, by extracting the suspected reverse connection address in the attack payload, it determines whether the connection request corresponding to the suspected reverse connection address is detected. If detected, it determines that the attack is successful; if not detected, it determines that the attack is not successful. However, the methods in related technologies are relatively single in implementation and are prone to misjudgment, thus reducing the accuracy rate of determining the success of an attack.

[0004] Therefore, how to improve the accuracy of attack success determination has become a problem to be solved. Summary of the Invention

[0005] Embodiments of this application provide a method, device, equipment and medium for attack determination. Through some embodiments of this application, at least in the case where the target address does not exist in the attack payload, the response traffic is rendered to determine whether the attack is successful, so as to accurately determine the behavior of a successful attack on an attack event and improve the security of the device.

[0006] In a first aspect, this application provides a method for attack determination. The method includes: when an attack event is detected in a victim host, parsing the attack payload corresponding to the attack event to determine whether a target address exists in the attack payload; when it is confirmed that the target address does not exist in the attack payload, extracting the response traffic of the victim host, where the target address is used to cause the victim host to perform an external connection operation; rendering the response traffic to obtain a rendering result, and determining whether the victim host is successfully attacked according to the rendering result.

[0007] Therefore, different from the method in related technologies that only judges whether a victim host is successfully attacked by whether the victim host performs an external connection behavior, in the embodiments of this application, in the case where the target address does not exist in the attack payload, the response traffic is rendered to determine whether the attack is successful, so as to accurately determine the behavior of a successful attack on an attack event and improve the security of the device.

[0008] In combination with the first aspect, in an embodiment of the present application, the response traffic is rendered to obtain a rendering result, and whether the victim host is successfully attacked is determined according to the rendering result, including: rendering the response body code in the response traffic through a sandbox, determining the execution situation of the events in the attack payload, and determining whether the victim host is successfully attacked according to the execution situation of the events in the attack payload.

[0009] Therefore, in the embodiment of the present application, by rendering the response body code to determine whether the victim host is successfully attacked, the attack success behavior of the attack event can be determined more accurately.

[0010] In combination with the first aspect, in an embodiment of the present application, the step of rendering the response body code in the response traffic through a sandbox to determine the execution situation of the events in the attack payload includes: rendering the response body code in the response traffic through a simulated browser in the sandbox to obtain a rendered page, comparing the rendered page with a preset normal page, and determining the execution situation of the events in the attack payload according to the comparison result.

[0011] Therefore, in the embodiment of the present application, by rendering the page in a simulated browser and comparing it with a normal page, the execution situation of the attack event can be quickly and accurately determined.

[0012] In combination with the first aspect, in an embodiment of the present application, the step of determining whether the victim host is successfully attacked according to the execution situation of the events in the attack payload includes: if the rendered page is different from the preset normal page, it is determined that the events in the attack payload are executed and the victim host is successfully attacked; if the rendered page is the same as the preset normal page, it is determined that the events in the attack payload are not executed and the victim host is not successfully attacked.

[0013] Therefore, in the embodiment of the present application, by determining that the victim host is successfully attacked when the rendered page is different from the preset normal page, the attack success behavior of the attack event can be more accurately alerted.

[0014] In combination with the first aspect, in an embodiment of the present application, the method further includes: when it is confirmed that the target address exists in the attack payload, determining whether the victim host has the behavior of connecting externally to the target address; if the victim host has the behavior of connecting externally to the target address, it is determined that the victim host is successfully attacked; if the victim host does not have the behavior of connecting externally to the target address, it is determined that the victim host is not successfully attacked.

[0015] Therefore, the embodiments of the present application can prevent misjudgment in the attack determination process by detecting external connection behaviors when there is a target address and rendering response traffic when there is no target address.

[0016] In combination with the first aspect, in an implementation manner of the present application, after determining that the victim host has been successfully attacked, the method further includes: raising the threat alert level of the attack event.

[0017] Therefore, after determining a successful attack, the embodiments of the present application can raise the level of the attack event, enabling quick positioning of more critical attack events, that is, attack events with a higher threat alert level, among a large number of alert events, and making an emergency response to the successful attack event in a timely manner, thus greatly saving the time for users to analyze and judge attack events.

[0018] In combination with the first aspect, in an implementation manner of the present application, after determining that the victim host has not been successfully attacked, the method further includes: sending an alert of detecting the attack event to the victim host.

[0019] In a second aspect, the present application provides an attack determination device, which includes: a payload parsing module configured to parse an attack payload corresponding to the attack event and determine whether there is a target address in the attack payload when an attack event is detected in the victim host; a traffic extraction module configured to extract the response traffic of the victim host when it is confirmed that there is no such target address in the attack payload, where the target address is used to cause the victim host to perform an external connection operation; an attack success judgment module configured to obtain a rendering result by rendering the response traffic and determine whether the victim host has been successfully attacked according to the rendering result.

[0020] In combination with the second aspect, in an implementation manner of the present application, the attack success judgment module is further configured to: render the response body code in the response traffic through a sandbox, determine the execution situation of the event in the attack payload, and determine whether the victim host has been successfully attacked according to the execution situation of the event in the attack payload.

[0021] In combination with the second aspect, in an implementation manner of the present application, the attack success judgment module is further configured to: render the response body code in the response traffic through a simulated browser in the sandbox to obtain a rendered page, compare the rendered page with a preset normal page, and determine the execution situation of the event in the attack payload according to the comparison result.

[0022] In combination with the second aspect, in an implementation of the present application, the attack success determination module is further configured to: if the rendered page is different from the preset normal page, determine that the event in the attack payload is executed and the victim host is successfully attacked; if the rendered page is the same as the preset normal page, determine that the event in the attack payload is not executed and the victim host is not successfully attacked.

[0023] In combination with the second aspect, in an implementation of the present application, the attack determination device is further configured to: when it is confirmed that the target address exists in the attack payload, determine whether the victim host has an external connection behavior to the target address; if the victim host has an external connection behavior to the target address, determine that the victim host is successfully attacked; if the victim host does not have an external connection behavior to the target address, determine that the victim host is not successfully attacked.

[0024] In combination with the second aspect, in an implementation of the present application, the attack success determination module is further configured to: raise the threat warning level of the attack event.

[0025] In combination with the second aspect, in an implementation of the present application, the attack success determination module is further configured to: send an alarm of detecting the attack event to the victim host.

[0026] In a third aspect, the present application provides an electronic device, including: a processor, a memory, and a bus; the processor is connected to the memory through the bus, and the memory stores a computer program, and when the computer program is executed by the processor, the method described in any embodiment of the first aspect can be implemented.

[0027] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed, the method described in any embodiment of the first aspect can be implemented. Description of the Drawings

[0028] Figure 1 It is a schematic diagram of the composition of a scenario for attack determination shown in an embodiment of the present application;

[0029] Figure 2 It is one of the flowcharts of a method for attack determination shown in an embodiment of the present application;

[0030] Figure 3 It is the second of the flowcharts of another method for attack determination shown in an embodiment of the present application;

[0031] Figure 4 It is a schematic diagram of the composition of a device for attack determination shown in an embodiment of the present application;

[0032] Figure 5 A schematic diagram of the composition of an electronic device shown in the embodiments of the present application. Detailed implementation manners

[0033] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Usually, the components of the embodiments of the present application described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of the present application provided in the accompanying drawings here is not intended to limit the scope of the claimed present application, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of the present application.

[0034] In related technologies, the product categories for threat detection include network intrusion detection systems (NIDS), network traffic detection and response systems (NDR), etc. These threat detection products all adopt deep packet inspection technology and perform threat detection by analyzing threat information from network traffic. In NIDS or NDR products, detecting cross-site scripting attacks (XSS) will generate a large number of attack alerts, and it is impossible to distinguish which alerts are related to successful attacks from these alerts, thus causing a large amount of analysis pressure on users. To solve the above problems, in related technologies, rules and regular expressions are written to match attack characteristics, and alerts are issued when attack characteristics appear. However, the technical solution for detecting attack characteristics can only detect the existence of XSS attacks and it is difficult to determine whether the XSS attacks are successful against the victim host. Therefore, there is still a problem of a large number of alerts to be processed. In addition, using the method of writing rules and regular expressions to match the characteristics of successful attacks is also likely to cause false alarms.

[0035] Therefore, to solve the above technical problems, the present application provides an attack determination method to achieve accurate alerts for successful attacks on attack payloads, thereby saving the analysis time of users for a large number of alerts.

[0036] The method steps in the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0037] The embodiments of the present application can be applied to scenarios for determining whether an attack event is successful in attacking a victim host. To address the problems in the background art, in a specific embodiment of the present application, first, when detecting an XSS attack behavior, the XSS attack payload is parsed. If a target address exists in the attack payload, it is detected whether the victim host has a behavior of connecting to an external device corresponding to the target address, and whether the attack is successful is determined based on its behavior. At the same time, if no target address exists in the attack payload, the HTML code of the HTTP response body part in the passive traffic is rendered, and whether the attack is successful is determined. Then, when it is confirmed that the attack is successful, the threat level of the XSS attack success event is automatically increased, so that attack determination can be comprehensively performed, achieving a comprehensive and accurate determination of the success of XSS injection attacks, and effectively improving the user's analysis and processing efficiency of XSS attack events.

[0038] Figure 1 A schematic diagram of the composition of an attack determination scenario in some embodiments of the present application is provided. The scenario includes: a network security device 110 and a victim host 120. Specifically, the network security device 110 monitors the victim host 120 in real time. When an attack event is detected in the victim host, an attack determination is performed to determine whether the victim host has been successfully attacked.

[0039] Taking the above network security device as an example, an attack determination method executed by the network security device of the present application is described exemplarily. It can be understood that the network security device can be an NIDS or NDR type device, and software can be deployed on this type of device to receive traffic through a network switch, and then execute the attack determination method.

[0040] At least to solve the problems in the background art, such as Figure 2 As shown, some embodiments of the present application provide an attack determination method, and the method includes:

[0041] S210, when an attack event is detected in the victim host, parse the attack payload related to the attack event to determine whether a target address exists in the attack payload.

[0042] It should be noted that the attack event can be any type of attack event, which can be an XSS attack event or other types of attack events, and the embodiments of the present application do not limit this.

[0043] It can be understood that the victim host is a host that already has an attack event. The present application does not limit the method for detecting an attack event in the victim host, and well-known technical solutions in the art can be used for detection.

[0044] In an implementation manner of the present application, before performing attack determination, it is necessary to record the response traffic in the normal service traffic (for example: HTTP response body), and then render the response traffic in the normal service traffic in the built-in browser sandbox to obtain a rendering result corresponding to the normal response traffic. The rendering result of the normal response traffic is used to compare with the rendering result after rendering the response traffic in the attack event during the subsequent attack determination process.

[0045] It should be noted that the response traffic in the above normal service traffic refers to the secure service traffic that has not been attacked by an attack event. The rendering result corresponding to the normal response traffic can be a page snapshot under normal service conditions (i.e., a preset normal page), or it can be the returned data under normal service conditions.

[0046] In an implementation manner of the present application, when parsing the attack payload corresponding to the attack event to determine whether there is a target address in the attack payload, it specifically includes: First, use the attack detection rule corresponding to the attack type (for example, if the attack type is an XSS attack, then use the detection rule corresponding to the XSS attack) to detect the attack event in the victim host. Then, parse and record the attack payload used in this attack event. If there is a target address in the attack payload, record the current target address and execute S2101 - S2102. If there is no target address in the attack payload, record the attack payload and execute S220 - S230.

[0047] It should be noted that the target address includes an IP address and / or a domain name, and can also be other address types. The present application does not limit this.

[0048] S2101: When it is confirmed that there is a target address in the attack payload, determine whether the victim host has the behavior of connecting externally to the target address.

[0049] That is to say, when there is an IP address or a domain name in the attack payload, by determining whether the victim host generates the behavior of connecting externally to the address included in the current attack payload, it is judged whether the victim host has been successfully attacked by the attack event.

[0050] As a specific embodiment of the present application, the type of the attack event is XSS. Since the principle of the XSS attack is to steal the cookie information of the victim host and thus impersonate the identity of the victim host, when it is detected that an XSS attack event occurs and there is an IP address or a domain name in the attack payload, it indicates that the attacking host is stealing the cookie information of the victim host. Therefore, in this embodiment, by determining whether the victim host transmits cookie information to the IP address or the domain name in the XSS attack payload from the network traffic, it is judged whether the victim host generates an external connection behavior, and thus it is judged whether the victim host has been successfully attacked by the attack event.

[0051] As another specific embodiment of the present application, by querying the Domain Name System (DNS) log of the victim host, it can be determined whether the victim host has an access behavior targeting the target address. If an access record targeting the target address is found in the DNS log, it is determined that the victim host has an outbound connection behavior. If no access record targeting the target address is found in the DNS log, it is determined that the victim host does not have an outbound connection behavior.

[0052] S2102: If the victim host has an outbound connection behavior to the target address, it is determined that the victim host has been successfully attacked. In another embodiment, if the victim host does not have an outbound connection behavior to the target address, it is determined that the victim host has not been successfully attacked.

[0053] As a specific embodiment of the present application, the type of the attack event is XSS. If it is determined that the victim host has a behavior of transmitting cookie information, and the cookie information can exactly match the cookie information of the current victim host, it is determined that the XSS attack event is a successful attack, and the attacking host has successfully stolen the cookie information of the victim host. Then, an alarm is issued to detect the successful attack behavior, and the threat alarm level of the attack event is increased, so as to automatically increase the threat alarm level, highlight the successful attack event, and thus be able to block the attack in the first time.

[0054] That is to say, if there is a callback address in the XSS attack payload, the callback address used in the XSS attack payload is cached, and the cookie information of the victim host user is cached. Then, it is detected and determined whether the victim host transmits cookie information to the callback address. If it is detected that the victim host transmits cookie information to the callback address, it is determined that the attack is successful.

[0055] S220, in the case of confirming that there is no target address in the attack payload, extract the response traffic of the victim host.

[0056] S230, render the response traffic to obtain a rendering result, and determine whether the victim host has been successfully attacked according to the rendering result.

[0057] That is to say, in order to ensure the accuracy of the attack success determination, in the case of confirming that there is no target address in the attack payload, it is necessary to further perform a rendering operation on the response traffic of the victim host, and determine whether the victim host has been successfully attacked through the rendering result obtained from the rendering operation.

[0058] It should be noted that the rendering operation is the process of loading the response traffic of the victim host. For example, the response traffic of the victim host is loaded to obtain the corresponding page.

[0059] Specifically, the specific steps for determining whether the victim host has been successfully attacked are as follows:

[0060] S2301: Render the response body code in the response traffic through a sandbox to determine the execution situation of the events in the attack payload.

[0061] In one implementation of S2301, render the response body code in the response traffic through a simulated browser in the sandbox to obtain a rendered page, compare the rendered page with a preset normal page, and determine the execution situation of the events in the attack payload according to the comparison result.

[0062] That is to say, use the sandbox environment of the built-in browser of the network security device to perform a rendering operation on the response body code, generate a rendered page that is easy to identify and compare by rendering the response body code, and then compare the rendered page with the preset normal page obtained by rendering the normal response traffic, and determine the execution situation of the events in the attack payload according to the comparison result.

[0063] It should be noted that the response body code can be the HTTP response partial traffic.

[0064] In another implementation of S2301, load the response body code in the response traffic through a simulated browser in the sandbox to obtain the returned data after loading, and compare the returned data with the preset normal returned data. If the returned data is the same as the preset normal returned data, it is determined that the events in the attack payload have not been executed, and further determine that the victim host has not been successfully attacked. If the returned data is different from the preset normal returned data, it is determined that the events in the attack payload have been executed, and further determine that the victim host has been successfully attacked.

[0065] S2302: Determine whether the victim host has been successfully attacked according to the execution situation of the events in the attack payload.

[0066] In one implementation of S2302, if the rendered page is different from the preset normal page, it is determined that the events in the attack payload have been executed, and the victim host has been successfully attacked.

[0067] It should be noted that since the events in the attack payload mark the signs indicating successful attack, therefore, when the events in the attack payload are executed, the signs indicating successful attack will appear in the rendered page, that is, the rendered page is different from the preset normal page. Correspondingly, when the events in the attack payload are not executed, the signs indicating successful attack will not appear, that is, the rendered page is the same as the preset normal page.

[0068] It can be understood that the sign indicating the success of the attack can be a pop-up window on the rendered page, or it can be a link at a certain place on the rendered page. The present application does not limit this.

[0069] That is to say, if there are N differences (N is an integer greater than or equal to 1) between the rendered page and the preset normal page, it means that the execution result of the event in the attack payload has been marked on the rendered page, the attack event has been executed, and the victim host has been successfully attacked by the attack event. Then, the threat alarm level of the attack event is increased, and the alarm corresponding to the successful attack is highlighted among many alarms.

[0070] It should be noted that the value of N can be set according to the actual production situation. That is, in one case, it can be determined that the attack event has been executed when there is 1 difference between the rendered page and the preset normal page. Or, it can also be determined that the attack event has been executed when there are more than 2 differences between the rendered page and the preset normal page.

[0071] In an implementation manner of S2302, if the rendered page is the same as the preset normal page, it is determined that the event in the attack payload has not been executed, and the victim host has not been successfully attacked.

[0072] That is to say, if the rendered page is exactly the same as the preset normal page without any differences, it means that there is no execution result for the event in the attack payload, the attack event has not been executed, and the victim host has not been attacked by the attack event. Then, an alarm indicating that an attack event has been detected is sent to the victim host.

[0073] For example, in the case where the type of the attack event is an XSS attack, if there is no callback address (i.e., the target address) in the XSS attack payload, the built-in browser sandbox is used to render the HTTP response traffic, and then it is compared with the preset normal page to determine whether the XSS attack payload is triggered, and further determine whether the victim host has been successfully attacked.

[0074] That is, when an XSS attack event occurs, the HTTP response part of the traffic of the victim host is extracted from the network traffic and placed in the built-in browser sandbox environment for page rendering. Then, the rendered result is compared with the preset normal page. If differences are found in the page (for example, two differences are found), it means that the XSS attack payload has been successfully triggered, and it is determined that the XSS attack event has been successfully attacked. Then, the successful attack event is alarmed, and the threat alarm level of the attack event is increased.

[0075] As a specific embodiment of the present application, such as Figure 3As shown, the specific process for attack determination includes: S301 monitors the victim host and detects an XSS attack behavior. S303 parses the XSS attack payload. S304 checks whether there is a domain name or IP in the XSS attack payload. If there is a domain name or IP, then S305 is executed to check whether the victim host transmits cookie information to the address in the XSS attack payload. If so, it indicates that the attack is successful, and S307 is executed to determine that the XSS attack is successful. If not, then S310 is executed to alert that an XSS attack behavior has been detected, and then S311 is executed to output an alert message. If there is no domain name or IP address in the attack payload, then S306 is executed to determine whether the code rendering triggers the XSS attack payload behavior. If it triggers, then S307, S308, and S311 are executed. If it does not trigger, then S310 and S311 are executed.

[0076] It can be understood that after determining that the attack is successful, the alert message output can be that a certain attacking host conducts an XSS attack on a certain victim host, that a certain victim host transmits cookie information outward after being subjected to an XSS attack, that the XSS attack is successful, and that the XSS attack is successful and the threat alert level is increased.

[0077] That is to say, the network security device in this application can be deployed in a network traffic detection and response (NDR) product for detecting threat intelligence, and can perform threat detection on zombies, Trojans, worms, APTs, Web, and non-Web attacks on a threat detection and response platform based on bypass traffic. By deeply analyzing the traffic payload, it automatically identifies the successful behavior of XSS injection based on the response traffic. Specifically, when it is detected that the victim host transmits cookie information to the callback address in the XSS attack and the transmitted cookie information is exactly the same as the cookie information of the victim host, it alerts that the attack is successful and raises the threat level (for example, upgrades from low risk to medium risk). When it is detected that there is no target address in the attack payload of the victim host, it calls the built-in browser sandbox to render the response body content, that is, performs page rendering, and then compares it with the recorded preset normal page. If it is found that the page response content is different (for example, a pop-up window behavior appears), it is determined that the XSS attack payload is successfully triggered, alerts that the attack is successful, and upgrades the threat level from low risk to medium risk.

[0078] Therefore, different from the method of using rules or regular expressions to detect XSS attack events in the NDR device in the related art, since the successful attack is more harmful to the victim host than an attack attempt, the attack determination method in this application can perform an alert response to the successful XSS attack event, highlighting the successful attack event, and thus can block the attack event in the first time.

[0079] The above describes a specific embodiment of an attack determination method. The following will describe an attack determination device.

[0080] As Figure 4 shown, some embodiments of the present application provide an attack determination device 400, which includes: a payload parsing module 410, a traffic extraction module 420, and an attack success determination module 430.

[0081] The payload parsing module 410 is configured to, when detecting an attack event in the victim host, parse the attack payload corresponding to the attack event and determine whether a target address exists in the attack payload; the traffic extraction module 420 is configured to, when confirming that the target address does not exist in the attack payload, extract the response traffic of the victim host, where the target address is used to cause the victim host to perform an external connection operation; the attack success determination module 430 is configured to render the response traffic to obtain a rendering result and determine whether the victim host is successfully attacked according to the rendering result.

[0082] In an embodiment of the present application, the attack success determination module 430 is further configured to: render the response body code in the response traffic through a sandbox, determine the execution situation of the event in the attack payload, and determine whether the victim host is successfully attacked according to the execution situation of the event in the attack payload.

[0083] In an embodiment of the present application, the attack success determination module 430 is further configured to: render the response body code in the response traffic through a simulated browser in the sandbox to obtain a rendered page, compare the rendered page with a preset normal page, and determine the execution situation of the event in the attack payload according to the comparison result.

[0084] In an embodiment of the present application, the attack success determination module 430 is further configured to: if the rendered page is different from the preset normal page, determine that the event in the attack payload is executed and the victim host is successfully attacked. If the rendered page is the same as the preset normal page, determine that the event in the attack payload is not executed and the victim host is not successfully attacked.

[0085] In an embodiment of the present application, the attack determination device is further configured to: when confirming that the target address exists in the attack payload, determine whether the victim host has the behavior of externally connecting to the target address; if the victim host has the behavior of externally connecting to the target address, determine that the victim host is successfully attacked; if the victim host does not have the behavior of externally connecting to the target address, determine that the victim host is not successfully attacked.

[0086] In one embodiment of the present application, the attack success determination module 430 is further configured to: raise the threat warning level of the attack event.

[0087] In one embodiment of the present application, the attack success determination module 430 is further configured to: send an alarm indicating that the attack event has been detected to the victim host.

[0088] In an embodiment of the present application, Figure 4 the modules shown can implement Figure 1 、 Figure 2 and Figure 3 each process in the method embodiments. Figure 4 The operations and / or functions of each module in Figure 1 、 Figure 2 and Figure 3 are respectively for implementing the corresponding processes in the method embodiments in

[0089] As Figure 5 shown, an embodiment of the present application provides an electronic device 500, including: a processor 510, a memory 520, and a bus 530. The processor is connected to the memory through the bus. The memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, they are used to implement the method described in any one of the above embodiments. For details, reference can be made to the description in the above method embodiments. To avoid repetition, the detailed description is appropriately omitted here.

[0090] Among them, the bus is used to realize the direct connection and communication of these components. Among them, in an embodiment of the present application, the processor may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0091] The memory may be, but is not limited to, Random Access Memory (RAM), Read Only Memory (ROM), Programmable Read-Only Memory (PROM), Erasable Programmable Read-Only Memory (EPROM), Electric Erasable Programmable Read-Only Memory (EEPROM), etc. Computer-readable instructions are stored in the memory. When the computer-readable instructions are executed by the processor, the methods described in the above embodiments can be executed.

[0092] It can be understood that Figure 5 The structure shown is only schematic and may also include more or fewer components than those Figure 5 shown therein, or have a different configuration from that Figure 5 shown. Figure 5 Each component shown therein may be implemented by hardware, software, or a combination thereof.

[0093] An embodiment of the present application also provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by the server, the method described in any one of the above all embodiments is implemented. For details, reference may be made to the description in the above method embodiments. To avoid repetition, the detailed description is appropriately omitted here.

[0094] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that: similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0095] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An attack determination method, characterized in that, the method includes: When an attack event is detected in the victim host, parsing the attack payload corresponding to the attack event, and determining whether there is a target address in the attack payload; When it is confirmed that there is no such target address in the attack payload, extracting the response traffic of the victim host, where the target address is used to cause the victim host to perform an external connection operation; Rendering the response body code in the response traffic through a sandbox, determining the execution situation of the event in the attack payload, and determining whether the victim host is successfully attacked according to the execution situation of the event in the attack payload; The rendering the response body code in the response traffic through a sandbox and determining the execution situation of the event in the attack payload includes: Rendering the response body code in the response traffic through a simulated browser in the sandbox to obtain a rendered page, comparing the rendered page with a preset normal page, and determining the execution situation of the event in the attack payload according to the comparison result; wherein, the preset normal page is obtained by rendering the response traffic in normal service traffic through a simulated browser in the sandbox, and the response traffic in the normal service traffic is recorded before the attack determination; The determining whether the victim host is successfully attacked according to the execution situation of the event in the attack payload includes: If the rendered page is different from the preset normal page, it is determined that the event in the attack payload is executed and the victim host is successfully attacked; If the rendered page is the same as the preset normal page, it is determined that the event in the attack payload is not executed and the victim host is not successfully attacked.

2. The method according to claim 1, characterized in that, the method further includes: When it is confirmed that there is such target address in the attack payload, determining whether the victim host has an act of externally connecting to the target address; If the victim host has an act of externally connecting to the target address, it is determined that the victim host is successfully attacked; If the victim host does not have an act of externally connecting to the target address, it is determined that the victim host is not successfully attacked.

3. The method according to claim 1 or 2, characterized in that, After determining that the victim host is successfully attacked, the method further includes: Raising the threat warning level of the attack event.

4. The method according to claim 1 or 2, characterized in that, After determining that the victim host is not successfully attacked, the method further includes: Sending an alarm of detecting the attack event to the victim host.

5. An attack determination device, characterized in that, the device includes: A payload parsing module, configured to parse the attack payload corresponding to the attack event when an attack event is detected in the victim host, and determine whether there is a target address in the attack payload; A traffic extraction module, configured to extract the response traffic of the victim host when it is confirmed that the target address does not exist in the attack payload, where the target address is used to cause the victim host to perform an outbound connection operation; An attack success judgment module, configured to render the response body code in the response traffic through a sandbox, determine the execution situation of the events in the attack payload, and determine whether the victim host is successfully attacked according to the execution situation of the events in the attack payload; The attack success judgment module is further configured to: Render the response body code in the response traffic through a simulated browser in the sandbox to obtain a rendered page, compare the rendered page with a preset normal page, and determine the execution situation of the events in the attack payload according to the comparison result; wherein, the preset normal page is obtained by rendering the response traffic in normal service traffic through a simulated browser in the sandbox, and the response traffic in the normal service traffic is recorded before the attack determination; The attack success judgment module is further configured to: If the rendered page is different from the preset normal page, it is determined that the events in the attack payload are executed and the victim host is successfully attacked; if the rendered page is the same as the preset normal page, it is determined that the events in the attack payload are not executed and the victim host is not successfully attacked.

6. An electronic device, characterized in that, it includes: a processor, a memory and a bus; The processor is connected to the memory through the bus, and the memory stores a computer program, and when the computer program is executed by the processor, the method described in any one of claims 1-4 can be implemented.

7. A computer-readable storage medium, characterized in that, a computer program is stored on the computer-readable storage medium, and when the computer program is executed, the method described in any one of claims 1-4 can be implemented.

Citation Information

Patent Citations

  • Method and device for judging attack success through reverse connection

    CN113965419A

  • XSS attack detection method and device

    CN114499968A