Attack object tracing method and device, equipment and medium

By monitoring the target function on the business system server and generating an attack interception page to obtain the characteristic information of the attack target, the problem of being unable to trace the source in the existing technology is solved, and the effective tracing of the attack target and the improvement of network security are realized.

CN117749446BActive Publication Date: 2026-04-24CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE INFORMATION TECHNOLOGY CO LTD
Filing Date
2023-12-07
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

In existing technologies, attack target attribution methods based on web logs or network traffic cannot effectively trace the source because when the attack target uses a proxy to access the network, the information left behind is modified, making it impossible to obtain real characteristic information, thus leading to network security threats.

Method used

By deploying security detection probes on the servers of business systems, monitoring target functions, generating attack interception pages and embedding source code, the target characteristic information of the attack object is obtained and sent to the security detection cloud for source tracing analysis.

Benefits of technology

It enables the acquisition and tracing of the true characteristics of the attack targets, reducing cybersecurity threats and improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117749446B_ABST
    Figure CN117749446B_ABST
Patent Text Reader

Abstract

The application discloses an attack object tracing method and device, equipment and a medium. The attack object tracing method comprises the following steps: monitoring a target function in a business system by a security detection probe, and determining whether an attack behavior exists, wherein the security detection probe is arranged on a server where the business system is located; in the case that the attack behavior exists, an attack interception page is generated, and a tracing code is pre-implanted in the attack interception page; in the case that an attack object accesses the attack interception page through a browser, target characteristic information of the attack object is acquired, the target characteristic information is obtained by running the tracing code on a terminal of the attack object; and the security detection probe sends the target characteristic information to a security detection cloud end, so that the security detection cloud end traces the attack object according to the target characteristic information. According to the embodiment of the application, the real characteristic information of the attack object can be acquired, and the tracing analysis of the attack object can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network security technology, and in particular relates to a method, apparatus, device and medium for tracing the source of attack targets. Background Technology

[0002] An attack target refers to an individual who accesses a system or website through a network attack; these targets are often hackers. By analyzing the information left behind by the attackers when they attack a system or website, we can obtain their characteristic information and trace the attackers back to their source, thus reducing network security threats.

[0003] However, in related technologies, when attack targets are traced based on web logs or network traffic, the information obtained when the attack target uses a proxy to access the system or website is all modified information left by the attack target, and the true characteristic information of the attack target cannot be obtained. This makes it impossible to effectively trace the attack target, and network security is threatened. Summary of the Invention

[0004] This application provides a method, apparatus, device, and medium for tracing the source of an attack target, which can realize the source analysis of the attack target.

[0005] In a first aspect, embodiments of this application provide a method for tracing the source of an attack target, the method comprising:

[0006] The security detection probes are used to monitor the target functions in the business system to determine whether there are any attack behaviors. The security detection probes are deployed on the server where the business system is located.

[0007] In the event of an attack, an attack interception page is generated, which contains pre-embedded source code.

[0008] When the target of the attack accesses the attack interception page through a browser, the target feature information of the target is obtained. The target feature information is obtained in response to the tracing source code being run on the target's terminal.

[0009] The security detection probe sends the target feature information to the security detection cloud, so that the security detection cloud can trace the attack target based on the target feature information.

[0010] Secondly, embodiments of this application provide an attack target tracing device, the device comprising:

[0011] The monitoring module is used to monitor the target functions in the business system through security detection probes to determine whether there are any attack behaviors. The security detection probes are deployed on the server where the business system is located.

[0012] The generation module is used to generate an attack interception page in the event of an attack, wherein the attack interception page contains pre-embedded source code.

[0013] The acquisition module is used to acquire target feature information of the attack target when the attack target accesses the attack interception page through a browser. The target feature information is obtained in response to the tracing source code being run on the attack target's terminal.

[0014] The sending module is used to send the target feature information to the security detection cloud through the security detection probe, so that the security detection cloud can trace the attack target based on the target feature information.

[0015] Thirdly, embodiments of this application provide an electronic device, which includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the steps of the attack target tracing method as described in any embodiment of the first aspect.

[0016] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement the steps of the attack target tracing method as described in any embodiment of the first aspect.

[0017] The attack target tracing method, apparatus, device, and medium of this application embodiment monitor target functions in the business system using security detection probes deployed on the server where the business system resides to determine whether attack behavior exists. If attack behavior is found, an attack interception page is generated to detect and intercept the attack behavior of the target. Furthermore, by writing the tracing source code into the attack interception page, the tracing source code runs on the target's terminal when the target accesses the page through a browser, enabling the acquisition of the target's target feature information and obtaining the true feature information used for attack target tracing. Further, the acquired target feature information is sent to a security detection cloud for attack target tracing analysis, thereby reducing network security threats. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1This is a flowchart illustrating an attack target tracing method provided in an embodiment of this application;

[0020] Figure 2 This is a flowchart illustrating another method for tracing the source of an attack target provided in an embodiment of this application;

[0021] Figure 3 This is a schematic diagram of the structure of an attack target tracing device provided in an embodiment of this application;

[0022] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0023] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0024] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

[0025] It should be noted that the acquisition, storage, use, and processing of data in this application embodiment all comply with the relevant provisions of national laws and regulations.

[0026] RASP (Runtime Application Self-Protection) is a new type of application security protection technology. RASP technology is usually built into an application or application runtime environment, which can integrate security defense functions into the running application.

[0027] JSONP is used to represent a "use pattern" of JSON, which can be used to solve the problem of cross-domain data access in mainstream browsers. Due to the browser's same-origin policy, requests from different origins will cause cross-domain problems. However, by using this open policy, web pages can obtain dynamically generated JSON data from other sources. This use pattern is called JSONP.

[0028] Browser fingerprinting technology is used to track web browsers by representing information such as website configurations and settings visible through the browser. It is like a human fingerprint, with individual identifiability and uniqueness.

[0029] An attack target refers to an individual who accesses a system or website through a network attack; these targets are often hackers. By analyzing the information left behind by the attackers when they attack a system or website, we can obtain their characteristic information and trace the attackers back to their source, thus reducing network security threats.

[0030] However, in related technologies, when attack targets are traced based on web logs or network traffic, the information obtained when the attack target uses a proxy to access the system or website is all modified information left by the attack target, and the true characteristic information of the attack target cannot be obtained. This makes it impossible to effectively trace the attack target, and network security is threatened.

[0031] For example, in attack and defense drills, the defending side often uses web honeypots, combined with JSONP vulnerabilities in third-party sites, to capture the attacker's ID for further tracing and countermeasures. However, this cannot ensure the accuracy of the attack source information, thus affecting the tracing and analysis.

[0032] To address the problems in related technologies, embodiments of this application provide a method, apparatus, device, and medium for tracing the source of attack targets.

[0033] The attack target tracing method provided in this application will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.

[0034] Figure 1 A flowchart illustrating an attack target tracing method 100 according to an embodiment of this application is shown. Figure 1 As shown, the attack target tracing method 100 may specifically include the following steps:

[0035] S101. Monitor the target function in the business system using a security detection probe to determine whether there is any attack behavior. The security detection probe is deployed on the server where the business system is located.

[0036] S102. In the event of an attack, an attack interception page is generated, wherein the attack interception page contains pre-embedded source code.

[0037] S103. When the attack target accesses the attack interception page through a browser, the target feature information of the attack target is obtained. The target feature information is obtained in response to the tracing source code being run on the terminal of the attack target.

[0038] S104. The target feature information is sent to the security detection cloud through the security detection probe, so that the security detection cloud can trace the attack target based on the target feature information.

[0039] Therefore, by deploying security detection probes on the server hosting the business system, the target functions in the business system are monitored to determine whether there are any attack behaviors. If an attack behavior is found, an attack interception page is generated to detect and intercept the attack behavior of the target. Furthermore, by writing the traceability source code into the attack interception page, the traceability source code is executed on the target's terminal when the target accesses the attack interception page through a browser, so as to obtain the target characteristic information of the target and obtain the real characteristic information for the attack target tracing. In addition, the obtained target characteristic information is sent to the security detection cloud for the attack target tracing analysis, thereby reducing network security threats.

[0040] The specific implementation methods for each of the above steps are described below.

[0041] In some embodiments, the security detection probe can be a RASP security detection probe based on runtime application self-protection technology. Thus, by deploying the RASP security detection probe on the server corresponding to the business system (or website or application), it is possible to perform security monitoring of the business system based on RASP technology to detect and intercept attacks against the business system in real time.

[0042] In some embodiments, the objective function is determined by classifying the importance of relevant functions in the business system according to security requirements. It can be understood that the objective function corresponds to the highest importance level, and it can be a function that plays a crucial role in the operation and maintenance of the business system, such as functions related to file uploading, modification, or deletion, database operations, and modification of administrative permissions.

[0043] In some embodiments, the security detection probe is configured with security rules. Specifically, the security rules can be generated by a dedicated rule configuration terminal and then sent to the security detection probe. These security rules may specifically include at least one of the following: the request source identity information matches a legitimate identity; the request source IP address matches a legitimate IP address; and the number of requests within a preset time period is less than or equal to a preset threshold.

[0044] Among them, legitimate identity can be identity information in the pre-established identity whitelist in the security rules. That is, the identity information of legitimate access objects is registered as legitimate identity information and stored in the identity whitelist, which may include account, name and corresponding verification and authentication information, etc.; legitimate IP can be address information in the pre-established IP whitelist in the security rules.

[0045] In addition, in some embodiments, before step S101, a request message sent to the business system through a browser is received, the request message is parsed to obtain identity information, IP address, request time and number of requests; if the identity information, IP address, request time and number of requests do not meet the security rules, the request message is rejected.

[0046] In other words, the identity of the requesting object is verified based on the request message. The request message will be approved only if the identity information of the requesting source matches the legitimate identity, the IP address of the requesting source matches the legitimate IP, and the number of requests within a preset time is less than or equal to a preset threshold.

[0047] In some embodiments, the request message may be an access request from a requesting object to a target page. The target page may be a page of a business system (or website or application) that is accessible only to a specific object, such as a login page for a specific object, or a page that has access to a specific database.

[0048] In practice, when a requesting object accesses a target page, it needs to enter identity information before it can initiate an access request. This allows the system to receive the access request, parse it to obtain the requesting object's identity information, and then compare this identity information with the identity information in the identity whitelist in the security rules. If the requesting object's identity information matches the legitimate identity, the system will further verify the source IP address and access request frequency corresponding to the access request.

[0049] In another embodiment, the request message may be a call request to a target function in the business system. If a security detection probe detects that the request message includes a preset field, it is determined that the request message is a call request to the target function. The preset field corresponds to the target function. That is, if the request message includes a specific field corresponding to the target function, it can be determined that the request message is a call request to the target function. Therefore, due to the call request to the target function, the target function needs to be monitored.

[0050] Furthermore, in some embodiments, in step S101, the call stack of the target function is parsed by a security detection probe to obtain the parameter information of the target function call; if malicious code is found in the parameter information, it is determined that an attack has occurred.

[0051] In practice, since the function call stack records the order of function calls and the process of parameter passing, the function call path, parameter information, and return value can be determined by parsing the call stack of the target function through a security detection probe.

[0052] In practice, when it is detected that the parameters of the target function call have incorrect parameter types, incorrect number of parameters, incorrect parameter names, etc., or when the parameters of the target function call contain malicious code or data, such as SQL injection, XSS attack, buffer overflow, etc., it is determined that there is an attack.

[0053] Alternatively, in another embodiment, the call stack of the target function is parsed using a security detection probe; a standard stack matching the target function is queried in a database; and if the call stack of the target function is inconsistent with the standard stack, an attack is determined to exist.

[0054] It's understandable that, in the absence of attacks, calls to the target function follow fixed rules, or that some target functions are immutable. However, when attacks occur, calls to the target function or changes to the target function do not conform to these fixed rules.

[0055] More specifically, since the call stack of the target function corresponds to the actual operation request, if the call stack of the target function is inconsistent with the standard operation request information recorded in the standard stack of the target function, it indicates that the operation request does not belong to the pre-defined standard operation requests that can call the target function. Therefore, it may be an attack on the business system. Thus, the operation request should be intercepted to prevent it from being further executed. The specific methods for implementing the interception will be described in more detail in subsequent embodiments.

[0056] Furthermore, in some embodiments, after step S101, since the target function includes defense code, after determining that an attack has occurred if malicious code exists in the parameter information, updated defense code can be generated based on the malicious code to increase the complexity of the defense code by modifying key characters or paragraphs; and an updated first target function can be generated based on the updated defense code.

[0057] In practice, the defense code can be updated according to the malicious code and the target function. For example, if the target function is a function related to file upload, the updated defense code will be the file upload-related defense code.

[0058] In some embodiments, after determining that an attack has occurred when the call stack of the target function is inconsistent with the standard stack, the attacked field of the target function can be determined based on the call stack of the target function and the standard stack; then, the attacked field is modified according to a preset modification rule to generate an updated second target function, thereby rewriting the data packet against the attack.

[0059] It can be understood that the attacked fields of the target function are the fields corresponding to parameters in the call stack that differ from the standard stack. Specifically, for the attacked fields, the attack data packets can be rewritten by modifying, deleting, or adding specific strings.

[0060] In this way, by rewriting the defense code of the target function and modifying its attacked fields, the attacking object fails to execute when accessing the target function, i.e., the call to the target function fails. Thus, the attacking behavior of the target object is detected and intercepted.

[0061] In some embodiments, in step S102, an attack interception page is generated if an attack on the business system is detected. Specifically, the traceability code pre-embedded in the attack interception page may include browser fingerprinting code and data request interface execution code (JSONP interface execution code).

[0062] Therefore, in step S103, when the attack target accesses the attack interception page through a browser, the target feature information of the attack target can be obtained.

[0063] It's important to note that the target's signature information is obtained by running the traceability code on the target's device. Specifically, since browser fingerprinting code can reach the target's browser, be automatically downloaded, and executed, browser fingerprinting technology can be used to obtain device information such as system fonts, system language, browser plugins, and IP address. It can also obtain keystrokes, access logs, and social media accounts. Therefore, a device fingerprint blacklist can be established to prevent and trace attacks based on this mechanism.

[0064] Furthermore, JSONP technology can overcome browser cross-domain restrictions, allowing attackers to execute JavaScript code and access different JSONP interfaces without the attacker's knowledge, thereby obtaining relevant information about the attacker, such as the attacker's name and address.

[0065] In other words, target feature information can include the target's terminal device information and other characteristic information. This target feature information can then be used for source tracing and location analysis of the target. This reduces website security problems caused by attackers stealing identity information and using methods such as (dynamic) proxies and virtual private networks to hide their identities and evade tracking.

[0066] In some embodiments, in step S104, the target feature information of the attack target is sent to the security detection cloud through the security detection probe, so that the security detection cloud can display the target feature information and process the target feature information to conduct source tracing analysis of the attack target based on the target feature information.

[0067] It is understandable that, compared to local systems, security testing cloud systems are more efficient at processing data, and RASP security testing probes can also be deployed and run in the security testing cloud system.

[0068] In practice, the security detection cloud can aggregate target characteristic information and intercepted information (i.e., malicious code and attacked fields) and perform correlation analysis. Specifically, it can search for matching attack records in the historical database based on the aggregated information to classify the attack targets and their attack behaviors, and further formulate corresponding countermeasures and defenses for subsequent similar attacks.

[0069] In practice, attack profiles of attack targets can be drawn based on the aggregated information, enabling targeted tracing of the attack targets that initiate attacks and association with their malicious attack behaviors. The attack behaviors of the attack targets can be mapped and traced.

[0070] As another implementation of this application, refer to Figure 2This application also provides another method for tracing the source of attack targets 200.

[0071] like Figure 2 As shown, the attack object tracing method 200 is applied to the RASP interception system 202 and the RASP cloud 203. That is, the attack object tracing method 200 is implemented through the interaction between the access object (attack object) 201, the RASP interception system 202 and the RASP cloud 203.

[0072] The RASP interception system 202 is equipped with RASP probes, which can use RASP technology to detect and intercept attacks in real time.

[0073] In step S210, the RASP interception system 202 receives the call request from the access object 201 to the target function; in step S220, the RASP interception system 202 monitors the target function to determine whether the access object 201 has any attack behavior; further, in step S230, the RASP interception system 202 intercepts the attack, obtains the interception information, and generates an attack interception page, wherein the attack interception page contains browser fingerprinting code and data request interface execution code.

[0074] In this way, when the target accesses the attack interception page through a browser, the browser fingerprinting code and data request interface execution code are implanted into the target's terminal and run automatically on that terminal, thereby obtaining the target characteristic information of the target 201.

[0075] Specifically, the intercepted information includes malicious code in the call request and the attacked fields of the target function; the target feature information includes attack target information and browser fingerprint information.

[0076] Furthermore, since the RASP cloud 203 is more efficient at processing data than the local machine, in step S240, the interception information and target feature information are sent to the RASP cloud 203 through the RASP probe.

[0077] Therefore, in step S250, RASP cloud 203 summarizes the target feature information and interception information to obtain summary information; and in step S260, it draws an attack profile of the attack target based on the summary information to achieve targeted tracing of the attack target that initiated the attack.

[0078] Therefore, based on the RASP interception system 202, RASP probe and RASP cloud 203, the identification and interception of attacks are realized, and the source analysis of the attack targets can be performed, thereby improving network security.

[0079] It should be noted that the above description describes some embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0080] Based on the same technical concept, corresponding to any of the above embodiments, this application also provides an attack target tracing device 300.

[0081] like Figure 3 As shown, the attack target tracing device 300 may include:

[0082] Monitoring module 301 is used to monitor target functions in the business system through security detection probes to determine whether there are any attack behaviors. The security detection probes are deployed on the server where the business system is located.

[0083] The generation module 302 is used to generate an attack interception page in the event of an attack, wherein the attack interception page contains pre-embedded source code.

[0084] The acquisition module 303 is used to acquire target feature information of the attack target when the attack target accesses the attack interception page through a browser. The target feature information is obtained in response to the tracing source code being run on the attack target's terminal.

[0085] The sending module 304 is used to send the target feature information to the security detection cloud through the security detection probe, so that the security detection cloud can trace the attack target based on the target feature information.

[0086] In some embodiments, the monitoring module 301 is specifically used to parse the call stack of the target function through a security detection probe to obtain the parameter information of the target function call; if malicious code exists in the parameter information, it is determined that an attack has occurred.

[0087] In some embodiments, the monitoring module 301 is further configured to parse the call stack of the target function using a security detection probe; query a database for a standard stack that matches the target function; and determine that an attack has occurred if the call stack of the target function is inconsistent with the standard stack.

[0088] In some embodiments, the attack target tracing device 300 further includes an update module ( Figure 3(Not shown in the image), used to determine the attacked field of the target function based on the call stack of the target function and the standard stack; modify the attacked field according to a preset modification rule to generate an updated target function.

[0089] In some embodiments, the attack target tracing device 300 further includes a determination module ( Figure 3 (Not shown in the image) is used to receive request messages sent to the business system through a browser; if a security detection probe detects that the request message includes a preset field, it is determined that the request message is a call request to the target function, and the preset field corresponds to the target function.

[0090] In some embodiments, the security detection probe is configured with security rules. These security rules include at least one of the following: the identity information matches a legitimate identity; the IP address matches a legitimate IP address; and the number of requests within a preset time period is less than or equal to a preset threshold.

[0091] In some embodiments, the attack target tracing device 300 further includes a parsing module ( Figure 3 (Not shown in the image) is used to parse the request message to obtain identity information, IP address, request time, and request count; if the identity information, IP address, request time, and request count do not meet the security rules, the request message is rejected.

[0092] In some embodiments, the traceability source code includes browser fingerprinting code and data request interface execution code.

[0093] In some embodiments, the attack target tracing device 300 further includes a functional simulation module ( Figure 3 (Not shown in the image), this function simulation module is used to perform function simulation on the monitoring information obtained from the monitoring to obtain simulation information.

[0094] In some embodiments, the attack target tracing device 300 further includes a classification module ( Figure 3 (Not shown in the image), this classification module is used to classify monitoring information to obtain normal data packets and attack data packets; and to classify simulated information to obtain normal data packets and attack data packets.

[0095] It should be noted that, for ease of description, the above devices are described in terms of function, divided into various modules. Of course, in implementing this application, the functions of each module can be implemented in one or more software and / or hardware.

[0096] The apparatus described above is used to implement the corresponding attack target tracing method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0097] Based on the same technical concept, corresponding to any of the above embodiments, this application also provides an electronic device.

[0098] Figure 4 A schematic diagram of a more specific electronic device hardware structure provided in this embodiment is shown.

[0099] The electronic device 400 may include a processor 401 and a memory 402 storing computer program instructions.

[0100] Specifically, the processor 401 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0101] Memory 402 may include mass storage for data or instructions. For example, and not limitingly, memory 402 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 402 may include removable or non-removable (or fixed) media. Where appropriate, memory 402 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 402 is non-volatile solid-state memory.

[0102] In certain embodiments, the memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Thus, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of this application.

[0103] The processor 401 reads and executes computer program instructions stored in the memory 402 to implement any of the attack target tracing methods in the above embodiments.

[0104] In some examples, electronic device 400 may also include communication interface 403 and bus 410. For example, Figure 4As shown, the processor 401, memory 402, and communication interface 403 are connected through bus 410 and complete communication with each other.

[0105] The communication interface 403 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0106] Bus 410 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not as a limitation, bus 410 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 410 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.

[0107] For example, the electronic device 400 can be a mobile phone, tablet computer, laptop computer, handheld computer, in-vehicle electronic device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc.

[0108] Based on the same technical concept, corresponding to any of the methods in the above embodiments, this application also provides a non-transitory computer-readable storage medium. This computer-readable storage medium stores computer program instructions; when executed by a processor, these computer program instructions implement any of the attack target tracing methods in the above embodiments. Examples of computer-readable storage media include non-transitory computer-readable storage media, such as portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, etc.

[0109] Based on the same technical concept, corresponding to any of the above embodiments, this application also provides a computer program product, which includes computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of a computer to cause the computer and / or the processors to perform the attack target tracing method. Corresponding to the execution entity for each step in each embodiment of the attack target tracing method, the processor executing the corresponding step can belong to the corresponding execution entity.

[0110] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0111] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0112] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0113] The aspects of this application have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by dedicated hardware performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0114] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A method for tracing the source of an attack target, characterized in that, include: The security detection probe is deployed on the server where the business system is located to monitor the target function in the business system and determine whether there is any attack behavior. The target function is the function with the highest importance level determined after classifying the relevant functions in the business system according to security requirements. In the event of an attack, an attack interception page is generated, which contains pre-embedded source code. When the target of the attack accesses the attack interception page through a browser, the target feature information of the target is obtained. The target feature information is obtained in response to the tracing source code being run on the target's terminal. The security detection probe sends the target feature information to the security detection cloud, so that the security detection cloud can trace the attack target based on the target feature information; The monitoring of target functions in the business system using security detection probes to determine whether attack behavior exists includes: By analyzing the call stack of the target function using a security detection probe, the parameter information of the target function call can be obtained; If malicious code is found in the parameter information, an attack is confirmed. The method of monitoring target functions in the business system using security detection probes to determine whether attack behavior exists also includes: The call stack of the target function is analyzed using a security detection probe; Search the database for a standard stack that matches the objective function; If the call stack of the target function is inconsistent with the standard stack, it is determined that an attack has occurred. Based on the call stack of the target function and the standard stack, determine the attacked field of the target function; The attacked field is modified according to a preset modification rule to generate an updated target function; The security detection cloud is also used to: summarize the target feature information, the malicious code, and the attacked fields, and perform correlation analysis to obtain summary information; draw an attack profile of the attack target based on the summary information to achieve targeted tracing of the attack target.

2. The method according to claim 1, characterized in that, Before monitoring the target function in the business system using security detection probes to determine whether an attack has occurred, the method further includes: Receive request messages sent to the business system through a browser; If a security detection probe detects that the request message includes a preset field, it is determined that the request message is a call request to the target function, and the preset field corresponds to the target function.

3. The method according to claim 2, characterized in that, The security detection probe is configured with security rules; Before determining that the request message is a call request to the target function when the security detection probe detects that the request message includes a preset field, the method further includes: Parse the request message to obtain identity information, IP address, request time, and number of requests; If the identity information, IP address, request time, and number of requests do not meet the security rules, the request message is rejected.

4. The method according to claim 3, characterized in that, The security rules include at least one of the following: the identity information matches a legitimate identity, the IP address matches a legitimate IP, and the number of requests within a preset time period is less than or equal to a preset threshold.

5. The method according to claim 1, characterized in that, The traceability source code includes browser fingerprinting code and data request interface execution code.

6. An attack target tracing device, characterized in that, The device includes: The monitoring module is used to monitor the target function in the business system through security detection probes to determine whether there is any attack behavior. The security detection probes are deployed on the server where the business system is located. The target function is the function with the highest importance level determined after classifying the relevant functions in the business system according to security requirements. The generation module is used to generate an attack interception page in the event of an attack, wherein the attack interception page contains pre-embedded source code. The acquisition module is used to acquire target feature information of the attack target when the attack target accesses the attack interception page through a browser. The target feature information is obtained in response to the tracing source code being run on the attack target's terminal. The sending module is used to send the target feature information to the security detection cloud through the security detection probe, so that the security detection cloud can trace the attack target based on the target feature information; The monitoring module is specifically used to analyze the call stack of the target function through a security detection probe to obtain the parameter information of the target function call; if malicious code is found in the parameter information, it is determined that an attack has occurred. The monitoring module is also specifically used to analyze the call stack of the target function through a security detection probe; query the database for a standard stack that matches the target function; and determine that an attack has occurred if the call stack of the target function is inconsistent with the standard stack. The update module is used to determine the attacked field of the target function based on the call stack of the target function and the standard stack; modify the attacked field according to a preset modification rule to generate an updated target function; The security detection cloud is also used to: summarize the target feature information, the malicious code, and the attacked fields, and perform correlation analysis to obtain summary information; draw an attack profile of the attack target based on the summary information to achieve targeted tracing of the attack target.

7. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; when the processor invokes the computer program instructions, it implements the attack target tracing method as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when invoked by a processor, implement the attack target tracing method as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Traceability countering method, device, equipment and medium

    CN115051832A

  • RASP-based WAF linkage protection method, apparatus and device, and medium

    CN115720150A

  • Web application security probe management method and system, electronic equipment and storage medium

    CN116208432A