Intelligent unauthorized detection method, device and electronic equipment
By obtaining candidate data packets based on proxy services within the specified time period after logging in to the detected platform after the target account is logged in to the detected platform, and using the permission authentication information of different reference accounts to generate detection data packets, combined with the content, length and response status code of the response packets, the problem of high false alarm rate of existing overprivileged detection methods is solved, and higher detection accuracy and overprivileged risk identification capabilities are achieved.
Patent Information
- Application Number
- CN202410536016.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-29
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-04-29
AI Technical Summary
The existing overprivileged detection methods have a high false alarm rate and cannot effectively identify the risk of overprivileged.
The candidate data packet is obtained based on the proxy service within the specified time period after the target account is logged in to the detected platform, and the detection data packet is generated using the permission authentication information of different reference accounts, and a comprehensive analysis is conducted based on the content, length and response status code of the response data packet to determine whether there is a risk of overreach.
The false alarm rate of overprivileged detection is reduced, the detection accuracy is improved, and the risk of overprivileged detection is effectively identified.
Smart Images

Figure CN118138372B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to flow detection technology, and in particular to intelligent unauthorized detection methods, devices and electronic equipment. Background Art
[0002] The risk of unauthorized access is mainly caused by the responder over-trusting the data operation request made by the requester and ignoring the determination of the operation authority, which makes it easy for attackers to obtain unauthorized sensitive information, such as user information and user transaction records. The most fundamental solution to the risk of unauthorized access is to perform unauthorized access detection. However, the current unauthorized access detection only performs a simple similarity calculation on the response message of each access address, and the unauthorized access detection has a high false positive rate. Summary of the invention
[0003] The present application provides an intelligent unauthorized detection method, device and electronic device to reduce the false alarm rate of unauthorized detection.
[0004] The embodiment of the present application provides an intelligent unauthorized detection method, which is applied to an electronic device and includes:
[0005] Within a specified time period after the target account logs in to the detected platform, candidate data packets are obtained based on the proxy service configured on the device, and all candidate data packets are filtered to obtain target data packets that meet the unauthorized detection requirements; the target data packets include at least one request data packet and at least one response data packet;
[0006] After each reference account other than the target account has successfully logged into the platform under inspection, obtaining the permission authentication information of the reference account;
[0007] Generate a detection data packet of the request data packet based on each request data packet; different detection data packets of the same request data packet carry the authority authentication information of different reference accounts;
[0008] For each request data packet, each detection data packet of the request data packet is sent to the detected platform to obtain a detection response packet corresponding to the detection data packet, and based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet, it is determined whether there is a risk of unauthorized access.
[0009] The embodiment of the present application provides an intelligent unauthorized detection device, which is applied to an electronic device, including:
[0010] The proxy module is used to obtain candidate data packets based on the proxy service configured on the device within a specified time period after the target account logs in to the detected platform, and filter all candidate data packets to obtain target data packets that meet the unauthorized detection requirements; the target data packets include at least one request data packet and at least one response data packet;
[0011] An automatic login module, used to obtain the authority authentication information of each reference account other than the target account after the reference account successfully logs into the detected platform;
[0012] An adjustment module, used to generate a detection data packet of the request data packet according to each request data packet; different detection data packets of the same request data packet carry the authority authentication information of different reference accounts;
[0013] The detection module is used to send each detection data packet of each request data packet to the detected platform to obtain a detection response packet corresponding to the detection data packet, and determine whether there is a risk of unauthorized access based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet.
[0014] An embodiment of the present application provides an electronic device, the electronic device comprising: a processor and a memory;
[0015] Wherein, the memory is used to store machine executable instructions;
[0016] The processor is used to read and execute the machine executable instructions stored in the memory to implement the above method.
[0017] An embodiment of the present application provides a computer program product, wherein a computer program is stored in the computer program product, and when the computer program is executed by a processor, the above method is implemented.
[0018] It can be seen from the above technical scheme that in this embodiment, the permission authentication information of each reference account is obtained by automatically logging into the detected platform. Based on the permission authentication information of each reference account, a corresponding detection data packet is generated for each request data packet in the target data packet that meets the unauthorized detection and is obtained by the agent within a specified time period after the target account logs into the detected platform. Then, unauthorized detection is performed with the help of a response data packet corresponding to the request data packet and a detection response packet corresponding to the detection data packet obtained after the detection data packet of the request data packet is sent to the detected platform. Unauthorized detection is not simply performed with the help of similarity, thereby reducing the false alarm rate of unauthorized detection.
[0019] Furthermore, in this embodiment, a comprehensive analysis is performed based on the data packet content, length and response status code to determine whether there is an unauthorized detection, rather than simply performing an unauthorized detection based on the data packet content. This greatly reduces the false alarm rate of unauthorized detection and improves detection accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0021] Figure 1 A flow chart of the method provided in the embodiment of the present application;
[0022] Figure 2 A flowchart for implementing step 104 provided in an embodiment of the present application;
[0023] Figure 3 Another implementation flow chart of step 104 provided in an embodiment of the present application;
[0024] Figure 4 A structural diagram of a device provided in an embodiment of the present application;
[0025] Figure 5 A structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0026] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0027] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms "a", "said" and "the" used in this application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0028] In order to enable those skilled in the art to better understand the technical solutions provided by the embodiments of the present application and to make the above-mentioned purposes, features and advantages of the embodiments of the present application more obvious and understandable, the technical solutions in the embodiments of the present application are further described in detail below in conjunction with the accompanying drawings.
[0029] See also Figure 1 , Figure 1The method flow chart provided in the embodiment of the present application. The method is applied to an electronic device. For example, as an embodiment, the electronic device here can be an Internet of Things gateway or other network device in the Internet of Things, which is not specifically limited in this embodiment.
[0030] like Figure 1 As shown, the process may include the following steps:
[0031] Step 101, within a specified time period after the target account logs into the detected platform, candidate data packets are obtained based on the proxy service configured on this device, and all candidate data packets are filtered to obtain target data packets that meet the unauthorized detection requirements; the reference data packets include request data packets and response data packets.
[0032] In this embodiment, the electronic device provides a proxy service to obtain all data packets (recorded as candidate data packets) of the detected platform within the specified time period. The candidate data packets here include at least multiple request data packets and a response data packet of the detected platform responding to at least one request data packet.
[0033] Optionally, after obtaining candidate data packets based on the proxy service configured on this device, all candidate data packets are filtered. As an embodiment, the filtering here mainly filters out data packets that meet static characteristics (belonging to static traffic) and data packets that meet set characteristics (belonging to specific traffic). Optionally, the data packets that meet static characteristics here refer to data packets that carry invalid static traffic characteristics such as css, js, toff, png, etc. Similarly, the data packets that meet the set characteristics here refer to data packets that do not require authentication as defined by preset rules, such as data packets carrying isapi, etc.
[0034] By filtering all candidate data packets, a target data packet that satisfies the unauthorized detection can be obtained in the end. Here, the target data packet includes at least one request data packet and a response data packet to which the detected platform responds based on the request data packet.
[0035] Step 102, after each reference account other than the target account has successfully logged into the detected platform, the permission authentication information of the reference account is obtained.
[0036] In this embodiment, N accounts (including the target account and at least one remaining reference account) logged into the detected platform are input into the electronic device in advance. Optionally, N here can be set according to actual needs, such as setting N to 3.
[0037] In this embodiment, for each reference account obtained except the target account, the reference account is automatically logged into the detected platform by simulating the manual input of the reference account. Specifically, the corresponding login interface can be opened based on the obtained login address, and then the account login identification area (such as an input box) of the login interface can be located, and the login information corresponding to the reference account to the above-mentioned detected platform can be automatically filled into the corresponding account login identification area and submitted. Once the reference account successfully logs in to the above-mentioned detected platform, the authority authentication information of the reference account is obtained.
[0038] As an embodiment, the permission authentication information of any reference account is, for example, cookie, token, basic authentication, digest authentication, sid or defined related authentication information.
[0039] Step 103 , generating a detection data packet of the request data packet according to each request data packet; different detection data packets of the same request data packet carry the authority authentication information of different reference accounts.
[0040] As an embodiment, for each request data packet in the target data packet, the following steps are performed:
[0041] For each reference account, the existing permission authentication information in the request data packet is replaced with the permission authentication information of the reference account to obtain a reference data packet of the request data packet, and the access parameter information of the reference data packet is adjusted to obtain a detection data packet corresponding to the request data packet; wherein the types of the access parameter information before and after the adjustment are the same.
[0042] As an embodiment, the access parameter information is used to indicate the object to be accessed, such as the address to be accessed, the device identifier to be accessed, etc.
[0043] Optionally, as described above, the types of access parameter information before and after adjustment are the same. For example, if the type of access parameter information before adjustment is a digital type, then the type of access parameter information after adjustment is also a digital type; for another example, if the type of access parameter information before adjustment is a character type, then the type of access parameter information after adjustment is also a character type; for another example, if the type of access parameter information before adjustment is a base64 encoding type, then the type of access parameter information after adjustment is also a base64 encoding type. By adjusting the access parameter information, the problem of unauthorized detection failure and underreporting caused by different types of access parameter information is effectively reduced.
[0044] Through the above description, it is finally achieved to adjust each request data packet in the target data packet to obtain the detection data packet of the request data packet. Different detection data packets of the same request data packet carry the authority authentication information of different reference accounts.
[0045] Step 104, for each request data packet, each detection data packet of the request data packet is sent to the detected platform to obtain a detection response packet corresponding to the detection data packet, and determine whether there is a risk of unauthorized access based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet.
[0046] In the present embodiment, for each request data packet, each detection data packet of the request data packet is sent to the above-mentioned detected platform to obtain the detection response packet corresponding to the detection data packet. As an embodiment, the detection response packet here at least carries: data packet content, length and response status code. Optionally, the length here is the length of the detection response packet. The response code here is the response status code specified in the http protocol. For example, if the response status code is 200, it means that the detection response packet currently carrying the response status code 200 is valid, and if the response status code is 404, 405, etc., it means that the detection response packet currently carrying the response status code 404, 405, etc. is invalid.
[0047] It can be seen that when performing unauthorized access detection, this embodiment comprehensively analyzes from the perspectives of length, response status code, response content, etc. to determine whether there is an unauthorized access risk, with high detection accuracy, effectively reducing the false alarm rate of unauthorized access risk. As for how to determine whether there is an unauthorized access risk based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet, the following will give an example description, which will not be repeated here.
[0048] So far, completed Figure 1 The process shown.
[0049] pass Figure 1 It can be seen from the shown process that in this embodiment, the permission authentication information of each reference account is obtained by automatically logging into the detected platform. Based on the permission authentication information of each reference account, a corresponding detection data packet is generated for each request data packet in the target data packet that meets the unauthorized detection and is obtained by the agent within a specified time period after the target account logs into the detected platform. Then, unauthorized detection is performed with the help of a response data packet corresponding to the request data packet and a detection response packet corresponding to the detection data packet obtained after the detection data packet of the request data packet is sent to the detected platform. Unauthorized detection is not simply performed with the help of similarity, so as to reduce the false alarm rate of unauthorized detection.
[0050] Furthermore, in this embodiment, a comprehensive analysis is performed based on the data packet content, length and response status code to determine whether there is an unauthorized detection, rather than simply performing an unauthorized detection based on the data packet content. This greatly reduces the false alarm rate of unauthorized detection and improves detection accuracy.
[0051] Furthermore, in this embodiment, the reference account is automatically logged into the platform to be tested to obtain the authority authentication information after the successful login, thereby improving the efficiency of unauthorized detection and increasing the automation rate of unauthorized detection.
[0052] The following describes how to perform unauthorized detection in step 104:
[0053] See also Figure 2 , Figure 2 This is a flowchart of an unauthorized detection embodiment provided in the present application. Figure 2 As shown, the process may include the following steps:
[0054] Step 201, execute the following step 202 for each request data packet.
[0055] Step 202 : for each detection data packet of the request data packet, if the length carried by the response data packet corresponding to the request data packet matches the length carried by the detection response packet corresponding to the detection data packet, then execute step 203 .
[0056] As an embodiment, the length carried by the response data packet corresponding to the request data packet matches the length carried by the detection response packet corresponding to the detection data packet. For example, the length carried by the response data packet corresponding to the request data packet is the same as the length carried by the detection response packet corresponding to the detection data packet.
[0057] Step 203, when the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid, if the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet do not contain a preset invalid field, then it is determined that the request data packet has a risk of unauthorized access.
[0058] For example, the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid. It can be that the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet are both 200.
[0059] In addition, in the present embodiment, the reason for further determining whether the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet contain preset invalid fields such as error, unauth, etc. is mainly for reducing the false alarm rate of unauthorized detection, because once the response data packet corresponding to the request data packet contains preset invalid fields such as error, unauth, etc., it means that the request data packet is wrong or invalid, and the obtained response data packet must also be wrong, which may increase the false alarm rate.
[0060] So far, completed Figure 2 The process shown.
[0061] pass Figure 2 The process shown ultimately implements step 104 to determine whether there is an unauthorized detection based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet.
[0062] See also Figure 3 , Figure 3 This is a flowchart of an unauthorized detection embodiment provided in the present application. Figure 3 As shown, the process may include the following steps:
[0063] Step 301, execute the following step 302 for each request data packet.
[0064] Step 302 : for each detection data packet of the request data packet, if the length carried by the response data packet corresponding to the request data packet does not match the length carried by the detection response packet corresponding to the detection data packet, then execute step 303 .
[0065] As an embodiment, the length of the response data packet corresponding to the request data packet does not match the length of the detection response packet corresponding to the detection data packet. For example, the length of the response data packet corresponding to the request data packet is different from the length of the detection response packet corresponding to the detection data packet.
[0066] Step 303, when the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid, if the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet do not contain a preset invalid field and the similarity is greater than the set similarity threshold, it is determined that the request data packet has a risk of unauthorized access.
[0067] For example, the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid. It can be that the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet are both 200.
[0068] If the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet do not contain a preset invalid field, the specific purpose is as described above and will not be repeated here.
[0069] It can be found that when the length of the response data packet corresponding to the request data packet does not match the length of the detection response packet corresponding to the detection data packet, it is necessary to analyze the similarity between the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet. The reason is: the response data packet or the detection response packet may contain special characters or special fields, which cannot be accurately verified by length, resulting in an increase in the false alarm rate. At this time, combining the similarity will be more accurate and can greatly reduce the false alarm rate.
[0070] As an embodiment, the similarity between the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet can be determined in the following manner: extracting feature data belonging to a specified feature type, such as data under dataget sucees, from the data packet content carried by the response data packet and the detection response packet respectively, and performing similarity calculation on the extracted feature data to obtain the similarity between the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet.
[0071] Optionally, the above similarity calculation can be implemented based on machine learning, specifically, it can be implemented by methods such as Euclidean distance, cosine similarity, Jaccard similarity and Dice coefficient, which is not specifically limited in this embodiment.
[0072] In addition, in this embodiment, the above-mentioned similarity threshold can be set according to actual needs, such as being set to 90%, etc., and this embodiment does not specifically limit it.
[0073] So far, completed Figure 3 The process shown.
[0074] pass Figure 3The process shown ultimately determines whether there is an unauthorized detection based on the data packet content, length and response status code of the response data packet corresponding to the request data packet, and the data packet content, length and response status code of the detection response packet corresponding to each detection data packet of the request data packet.
[0075] Optionally, in this embodiment, when it is determined that any request data packet has a risk of unauthorized access, the method may further include: adjusting the permissions of the access address carried by the request data packet, such as a URL address, to control the request data packet carrying the access address subsequently sent by the above-mentioned target account to the detected platform so that there is no risk of unauthorized access when performing unauthorized access detection.
[0076] The method provided in the embodiment of the present application is described above. The device provided in the embodiment of the present application is described below:
[0077] See also Figure 4 , Figure 4 This is a diagram of the structure of a device provided in an embodiment of the present application. The device is applied to an electronic device and may include:
[0078] The proxy module is used to obtain candidate data packets based on the proxy service configured on the device within a specified time period after the target account logs in to the detected platform, and filter all candidate data packets to obtain target data packets that meet the unauthorized detection requirements; the target data packets include at least one request data packet and at least one response data packet;
[0079] An automatic login module, used to obtain the authority authentication information of each reference account other than the target account after the reference account successfully logs into the detected platform;
[0080] An adjustment module, used to generate a detection data packet of the request data packet according to each request data packet; different detection data packets of the same request data packet carry the authority authentication information of different reference accounts;
[0081] The detection module is used to send each detection data packet of each request data packet to the detected platform to obtain a detection response packet corresponding to the detection data packet, and determine whether there is a risk of unauthorized access based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet.
[0082] Optionally, filtering all candidate data packets to obtain target data packets that meet the unauthorized detection includes: filtering all candidate data packets to filter out data packets that meet static characteristics and data packets that meet set characteristics, and obtaining target data packets that meet the unauthorized detection; wherein, the data packets that meet the static characteristics refer to data packets that carry preset static characteristics, and the data packets that meet the set characteristics refer to data packets that carry set specific parameters that do not require authentication; and / or,
[0083] The step of generating a detection data packet of the request data packet according to each request data packet comprises:
[0084] For each request packet, the following steps are performed:
[0085] For each reference account, the existing permission authentication information in the request data packet is replaced with the permission authentication information of the reference account to obtain a reference data packet of the request data packet, and the access parameter information of the reference data packet is adjusted to obtain a detection data packet corresponding to the request data packet; wherein the types of the access parameter information before and after the adjustment are the same.
[0086] Optionally, determining whether there is an unauthorized detection based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet includes:
[0087] For each request packet, the following steps are performed:
[0088] For each detection data packet of the request data packet, if the length carried by the response data packet corresponding to the request data packet matches the length carried by the detection response packet corresponding to the detection data packet, then when the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid, if the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet do not contain a preset invalid field, then it is determined that the request data packet has a risk of unauthorized access; and / or,
[0089] If the length of the response data packet corresponding to the request data packet does not match the length of the detection response packet corresponding to the detection data packet, then:
[0090] When the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid, if the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet do not contain preset invalid fields and the similarity is greater than the set similarity threshold, then it is determined that the request data packet has a risk of unauthorized access.
[0091] So far, completed Figure 4 Structural description of the device shown.
[0092] Correspondingly, the embodiment of the present application also provides Figure 4 The hardware structure of the device is described in FIG. Figure 5 As shown, the hardware structure is an electronic device, and the electronic device includes: a processor and a memory;
[0093] Wherein, the memory is used to store machine executable instructions;
[0094] The processor is used to read and execute the machine executable instructions stored in the memory to implement the method disclosed in the above example of this application.
[0095] Based on the same application concept as the above method, an embodiment of the present application also provides a machine-readable storage medium, on which a number of computer instructions are stored. When the computer instructions are executed by a processor, the method disclosed in the above example of the present application can be implemented.
[0096] Based on the same application concept as the above method, an embodiment of the present application further provides a computer program product, wherein the computer program product stores a computer program, and when the computer program is executed by a processor, the method disclosed in the above example of the present application is implemented.
[0097] Exemplarily, the above-mentioned machine-readable storage medium can be any electronic, magnetic, optical or other physical storage device, which can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium can be: RAM (Radom Access Memory), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), solid state drive, any type of storage disk (such as optical disk, DVD, etc.), or similar storage medium, or a combination thereof.
[0098] The systems, devices, modules or units described in the above embodiments may be implemented by computers or entities, or by products with certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver, a game console, a tablet computer, a wearable device or a combination of any of these devices.
[0099] For the convenience of description, the above device is described in terms of functions and is described separately in various units. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0100] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0101] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0102] Moreover, these computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0103] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0104] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. An intelligent unauthorized detection method, characterized in that: The method is applied to an electronic device, comprising: Within a specified time period after the target account logs in to the detected platform, candidate data packets are obtained based on the proxy service configured on the device, and all candidate data packets are filtered to obtain target data packets that meet the unauthorized detection requirements; the target data packets include at least one request data packet and a response data packet of the detected platform in response to the at least one request data packet; For each reference account obtained except the target account, log the reference account into the detected platform in a manner simulating manual input of the reference account, so as to obtain the authority authentication information of the reference account after the reference account successfully logs into the detected platform; Generate a detection data packet of the request data packet according to each request data packet; different detection data packets of the same request data packet are obtained by replacing the existing permission authentication information in the request data packet with the permission authentication information of each reference account, so that different detection data packets of the same request data packet carry the permission authentication information of different reference accounts; For each request data packet, each detection data packet of the request data packet is sent to the detected platform to obtain a detection response packet corresponding to the detection data packet, and whether there is an unauthorized risk is determined based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet; the determining whether there is an unauthorized risk based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet includes: For each request data packet, perform the following steps: for each detection data packet of the request data packet, If the length of the response data packet corresponding to the request data packet matches the length of the detection response packet corresponding to the detection data packet, then when the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid, if the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet do not contain a preset invalid field, it is determined that the request data packet has a risk of unauthorized access; If the length of the response data packet corresponding to the request data packet does not match the length carried by the detection response packet corresponding to the detection data packet, then: when the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid, if the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet do not have a preset invalid field and the similarity is greater than the set similarity threshold, it is determined that the request data packet has a risk of unauthorized access.
2. The method according to claim 1, characterized in that The filtering of all candidate data packets to obtain target data packets that meet the unauthorized detection includes: All candidate data packets are filtered to filter out data packets that meet static characteristics and data packets that meet set characteristics, and obtain target data packets that meet unauthorized detection; wherein, the data packets that meet static characteristics refer to data packets carrying preset static characteristics, and the data packets that meet set characteristics refer to data packets carrying set specific parameters that do not require authentication.
3. The method according to claim 1, characterized in that The reference account logs into the detected platform through the following steps: For each reference account obtained except the target account, the login information of the reference account to the above-mentioned detected platform is automatically input into the account login identification area on the login interface corresponding to the obtained login address and submitted in a manner simulating manual input, so that the reference account is logged in to the detected platform.
4. The method according to claim 1, characterized in that: The step of generating a detection data packet of the request data packet according to each request data packet comprises: For each request packet, the following steps are performed: For each reference account, the existing permission authentication information in the request data packet is replaced with the permission authentication information of the reference account to obtain a reference data packet of the request data packet, and the access parameter information of the reference data packet is adjusted to obtain a detection data packet corresponding to the request data packet; wherein the types of the access parameter information before and after the adjustment are the same.
5. The method according to claim 1, characterized in that When it is determined that any request data packet has an unauthorized risk, the method further includes: The permissions of the access address carried in the request data packet are adjusted to control the target account to subsequently send request data packets carrying the access address to the detected platform without any risk of unauthorized access when performing unauthorized access detection.
6. An intelligent unauthorized detection device, characterized in that: The device is applied to electronic equipment, including: The proxy module is used to obtain candidate data packets based on the proxy service configured on the device within a specified time period after the target account logs in to the detected platform, and filter all candidate data packets to obtain target data packets that meet the unauthorized detection; the target data packets include at least one request data packet and a response data packet of the detected platform in response to the at least one request data packet; An automatic login module, for automatically logging into the detected platform in a manner simulating manual input of the reference account for each reference account obtained except the target account, and obtaining the authority authentication information of the reference account if the login to the detected platform is successful; an adjustment module, configured to generate a detection data packet of the request data packet according to each request data packet; different detection data packets of the same request data packet are obtained by replacing the existing permission authentication information in the request data packet with the permission authentication information of each reference account, so that different detection data packets of the same request data packet carry the permission authentication information of different reference accounts; A detection module, for each request data packet, sending each detection data packet of the request data packet to the detected platform to obtain a detection response packet corresponding to the detection data packet, and determining whether there is an unauthorized risk based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet; Wherein, determining whether there is an unauthorized risk based on the data packet content, length and response status code carried by the response data packet corresponding to the request data packet, and the data packet content, length and response status code carried by the detection response packet corresponding to each detection data packet of the request data packet includes: For each request data packet, perform the following steps: for each detection data packet of the request data packet, If the length of the response data packet corresponding to the request data packet matches the length of the detection response packet corresponding to the detection data packet, then when the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid, if the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet do not contain a preset invalid field, it is determined that the request data packet has a risk of unauthorized access; If the length of the response data packet corresponding to the request data packet does not match the length carried by the detection response packet corresponding to the detection data packet, then: when the response status code carried by the response data packet corresponding to the request data packet and the response status code carried by the detection response packet corresponding to the detection data packet match and both indicate that the data packets are valid, if the data packet content carried by the response data packet corresponding to the request data packet and the data packet content carried by the detection response packet corresponding to the detection data packet do not have a preset invalid field and the similarity is greater than the set similarity threshold, it is determined that the request data packet has a risk of unauthorized access.
7. An electronic device, characterized in that: The electronic device includes: a processor and a memory; Wherein, the memory is used to store machine executable instructions; The processor is used to read and execute the machine executable instructions stored in the memory to implement the method according to any one of claims 1 to 5.
8. A computer program product, characterized in that The computer program product stores a computer program, and when the computer program is executed by a processor, the method described in any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Out-of-authority vulnerability detection method, system and device and storage medium
CN111416811A
Interface permission detection method and device, medium and electronic equipment
CN112560025A