Attack detection method, device, readable medium and electronic device for container

By combining data on the network side and device side, analyzing the container's network access request and process execution events, the problem of single latitude and false alarm risks in the prior art detection of WebRCE intrusion attacks is solved, and more efficient and accurate attack detection is achieved.

CN118764310BActive Publication Date: 2025-05-09BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411155645.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-21
Publication Date
2025-05-09
Estimated Expiration
2044-08-21

AI Technical Summary

Technical Problem

When detecting WebRCE intrusion attacks, the detection latitude is single, there is a risk of false alarms, and it is difficult to detect new attacks such as 0-Day vulnerabilities that do not conform to known vulnerabilities or attack methods.

Method used

By obtaining the network access request of the service loaded by the container from the network side and obtaining process execution events from the device side of the target container, combining analysis of exception access requests and exception process events, the attack detection combined with the terminal network is realized.

Benefits of technology

It improves the detection rate and accuracy of intrusion attacks, reduces the risk of attacks to bypass vulnerabilities, and has good detection adaptability and robustness, which facilitates subsequent traceability analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118764310B_ABST
    Figure CN118764310B_ABST
Patent Text Reader

Abstract

The present disclosure relates to an attack detection method, device, readable medium and electronic device for containers, which realizes attack detection by combining end-to-network analysis, and analyzes intrusion attacks on containers based on multiple dimensions, thereby improving attack detection rate and accuracy. The attack detection method comprises: obtaining a network access request for a service that accesses a target container load from the network side, and obtaining a process execution event in the target container from the device side where the target container is located; determining an abnormal access request in the network access request and an abnormal process event in the process execution event; and determining an attack detection result based on the abnormal access request and the abnormal process event.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular, to an attack detection method, device, readable medium, and electronic device for a container. Background Art

[0002] With the rapid development of the Internet industry, network security issues have become increasingly prominent. For example, exploiting vulnerabilities in Web (network) applications to conduct WebRCE (Remote Code / Common Execute) intrusion attacks is a common intrusion attack method.

[0003] In the related technology, the detection method of WebRCE is usually to use attack detection tools to separately detect access requests on the network side or process events of the system, such as detecting access requests for services loaded by containers. The detection dimension is single and there is a risk of false alarms. Summary of the invention

[0004] This summary is provided to introduce concepts in a brief form that will be described in detail in the detailed description below. This summary is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0005] In a first aspect, the present disclosure provides an attack detection method for a container, the attack detection method comprising:

[0006] Obtaining a network access request for a service loaded by a target container from a network side, and obtaining a process execution event in the target container from a device side where the target container is located;

[0007] Determining abnormal access requests in the network access requests and abnormal process events in the process execution events;

[0008] In a second aspect, the present disclosure provides an attack detection device for a container, the attack detection device comprising:

[0009] An acquisition module, configured to acquire a network access request for a service loaded by a target container from a network side, and acquire a process execution event in the target container from a device side where the target container is located;

[0010] A first determining module, configured to determine an abnormal access request in the network access request and an abnormal process event in the process execution event;

[0011] The second determination module is used to determine the attack detection result based on the abnormal access request and the abnormal process event.

[0012] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of any one of the methods described in the first aspect.

[0013] In a fourth aspect, the present disclosure provides an electronic device, including:

[0014] a storage device having a computer program stored thereon;

[0015] A processing device is used to execute the computer program in the storage device to implement the steps of any method described in the first aspect above.

[0016] In a fifth aspect, the present disclosure provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of any one of the methods in the first aspect.

[0017] Through the above technical solution, the network access request for the service that accesses the target container load is obtained from the network side, and the process execution event in the target container is obtained from the device side where the target container is located, and then the abnormal access request in the network access request and the abnormal process event in the process execution event are combined and analyzed to obtain the final attack detection result, thereby realizing attack detection with end-to-network combined analysis. And the intrusion attack on the container is analyzed based on multiple dimensions to improve the detection rate and accuracy of the intrusion attack. In addition, it is also convenient to determine the source of the attack based on the abnormal access request and the impact of the attack based on the abnormal process event, thereby improving the efficiency of security analysis.

[0018] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and the originals and elements are not necessarily drawn to scale. In the drawings:

[0020] Figure 1 is a flow chart of an attack detection method for a container according to an exemplary embodiment of the present disclosure;

[0021] Figure 2 is a schematic diagram of a process of constructing an access request model according to an exemplary embodiment of the present disclosure;

[0022] Figure 3is a schematic diagram showing a request address and a request feature list according to an exemplary embodiment of the present disclosure;

[0023] Figure 4 is a schematic diagram of a process for determining an abnormal access request according to an exemplary embodiment of the present disclosure;

[0024] Figure 5 is a flow chart showing a process of building a process event model according to an exemplary embodiment of the present disclosure;

[0025] Figure 6 is a schematic diagram showing a process name, a parent process name and a parameter feature list according to an exemplary embodiment of the present disclosure;

[0026] Figure 7 is a schematic diagram of a process for determining an abnormal process event according to an exemplary embodiment of the present disclosure;

[0027] Figure 8 is a schematic diagram of a correlation analysis process according to an exemplary embodiment of the present disclosure;

[0028] Fig. 9 is a schematic diagram showing a timing association according to an exemplary embodiment of the present disclosure;

[0029] Fig.10 is a schematic diagram showing an abnormal mapping according to an exemplary embodiment of the present disclosure;

[0030] Fig.11 is a process diagram of an attack detection method for a container according to an exemplary embodiment of the present disclosure;

[0031] Fig.12 is a structural block diagram of an attack detection device for a container according to an exemplary embodiment of the present disclosure;

[0032] Fig.13 It is a schematic structural diagram of an electronic device according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION

[0033] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein, which are instead provided for a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.

[0034] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.

[0035] The term "including" and its variations used herein are open inclusions, i.e., "including but not limited to". The term "based on" means "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0036] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0037] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0038] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0039] It is understandable that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, scope of use, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0040] For example, in response to receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested to be performed will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, application, server, or storage medium that performs the operation of the technical solution of the present disclosure according to the prompt message.

[0041] As an optional but non-limiting implementation, in response to receiving an active request from the user, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0042] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that meet the relevant laws and regulations may also be applied to the implementation of the present disclosure.

[0043] At the same time, it is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.

[0044] WebRCE intrusion attack is an intrusion method that exploits vulnerabilities in Web application software and sends malicious code instructions through Web remote calls to control the server, invade or steal data.

[0045] In the related technologies, for WebRCE intrusion, WAF (Web Application Firewall) is usually used to perform abnormal detection on access requests on the network side, or EDR (Endpoint Detection and Response) is used to perform attack detection on process execution events on the terminal side. The core principle of both is to use known vulnerabilities or attack methods to design corresponding detection rules, and perform regular (pattern) matching detection on all access requests or process execution events and attack detection rules to detect abnormal access requests or abnormal process events. For example, the access request of the business loaded by the container is detected, where the container is a lightweight operating system layer virtualization technology of the kernel, which can form an isolated operating system space for running specific services. Therefore, the detection latitude of the above detection means is single, and there is a risk of false alarms. And because the above detection means are based on the detection rules designed for known vulnerabilities or attack methods for attack detection, it is very easy to be bypassed, and there is a risk of high false alarm rate. There is almost no detection capability for vulnerability attacks that do not meet the detection rules, such as 0-Day vulnerabilities.

[0046] In view of this, the present disclosure provides an attack detection method, device, readable medium and electronic device for a container to solve the above technical problems.

[0047] The embodiments of the present disclosure are further explained below with reference to the accompanying drawings.

[0048] Figure 1 FIG. 1 is a flow chart of an attack detection method for a container according to an exemplary embodiment of the present disclosure. Figure 1 , the attack detection method includes:

[0049] S101: Obtain a network access request for a service loaded by a target container from a network side, and obtain a process execution event in the target container from a device side where the target container is located.

[0050] For example, the device side is a terminal that runs an application, such as a server terminal such as a Linux server. The network traffic for the application loaded by the container running on the device side can be obtained from the network side, and then the network access request, such as HTTP (Hypertext Transfer Protocol) access request, can be parsed. The network access request can be obtained through the WAF's diversion technology, and the process execution event occurring in the container on the device side can be obtained by using the EDR's system event collection technology, or other tools can be used to obtain network access requests and process execution events, and the present disclosure does not limit this.

[0051] S102: Determine abnormal access requests in network access requests and abnormal process events in process execution events.

[0052] It should be understood that after attack detection is enabled, network access requests and process execution events will be obtained in real time and continuously. There are normal access requests and abnormal access requests in network access requests. Correspondingly, there are normal process events and abnormal process events in process execution events. It is necessary to filter network access requests and process execution events to obtain abnormal access requests and abnormal process events so that abnormal access requests and abnormal process events can be combined and analyzed later.

[0053] S103: Determine an attack detection result based on the abnormal access request and the abnormal process event.

[0054] By adopting the above method, the network access request of the service that accesses the target container load is obtained from the network side, and the process execution event in the target container is obtained from the device side where the target container is located, and then the abnormal access request in the network access request and the abnormal process event in the process execution event are combined and analyzed to obtain the final attack detection result, thereby realizing the attack detection of end-to-network combined analysis. And the intrusion attack of the container is analyzed based on multiple dimensions to improve the detection rate and accuracy of the intrusion attack. In addition, it is also convenient to determine the source of the attack based on the abnormal access request and the impact of the attack based on the abnormal process event, thereby improving the efficiency of security analysis.

[0055] Among them, attack detection with combined end-to-end analysis refers to a technology that combines the security protection mechanisms on the terminal side and the network side to perform attack detection, including a security protection mechanism that intercepts and detects the network traffic of the container load on the network side, and a security detection and protection mechanism for the container load application running on the terminal device. As described above, the detection means of the related technology is to perform attack detection based on detection rules designed based on known vulnerabilities or attack techniques, which are very easy to be bypassed and have a high risk of missed reports. Therefore, the present invention performs anomaly detection through trained access request models and process event models, thereby improving the detection rate and accuracy of WebRCE intrusion attacks and reducing the risk of attacks that bypass vulnerabilities.

[0056] In a possible manner, determining an abnormal access request in a network access request and an abnormal process event in a process execution event may include: determining the abnormal access request in the network access request based on an access request model, and determining the abnormal process event in the process execution event based on a process event model, wherein the access request model is modeled based on a normal access request for a service loaded by a target container, and the process event model is modeled based on a normal process event in the target container.

[0057] For example, a behavior baseline is modeled based on normal access requests for services loaded by the target container obtained from the network side to obtain an access request model, and a behavior baseline is modeled based on normal process events in the target container to obtain a process event model. Therefore, model deviation detection can be performed on network access requests or process execution events based on the model to obtain abnormal access requests or abnormal process events. Compared with the detection methods of related technologies, model-based anomaly detection can improve the detection rate and accuracy of WebRCE intrusion attacks, reduce the risk of attacks that bypass vulnerabilities, and have better detection adaptability and robustness.

[0058] It is worth noting that the attack detection method provided in the present disclosure can perform attack detection on the device side, and can also perform attack detection on the container in the device side separately, and the present disclosure does not limit this.

[0059] For example, in the host load on the device side, multiple different application software services may be deployed at the same time, so the business services on the host are complex and changeable. In the container load, since containers are usually microservice designs, they focus on providing one service, such as mysql container, tomcat container, redis container, etc., that is, the container's business is single and stable.

[0060] Therefore, the attack detection method provided by the present invention is applied to attack detection on containers. Compared with the complex host environment, the access requests and process events corresponding to a single and stable container are relatively simple, which is conducive to better training the model and obtaining a more accurate model.

[0061] In a possible manner, the access request model is determined in the following manner: obtaining multiple normal access requests for the business of the target container load; parsing the normal access request for each normal access request to obtain a normal request address and a normal request feature of the normal access request; clustering and analyzing the normal request features of the multiple normal access requests according to the normal request address to obtain a request feature index corresponding to each normal request address; and determining the access request model based on all normal request addresses and their corresponding request feature indexes.

[0062] The request characteristic index includes at least one of the request body length, request letter ratio, request number ratio and request special character ratio.

[0063] For example, the request characteristic indicator may be one or more of the request body length, request letter ratio, request number ratio, and request special characters, or may be other characteristic indicators, which may be set according to requirements and are not limited in this disclosure.

[0064] For example, during the model building phase, network access requests can be obtained through the WAF tool, from which normal access requests can be filtered out for model building. Figure 2 As shown, based on the feature extractor, feature extraction is performed on normal access requests to obtain request features and request addresses of each normal access request, where the request address may be a URL (uniform resource location). The feature extractor may be a pre-trained neural network model for extracting access request features, and the present disclosure does not impose any specific restrictions on this.

[0065] For example, Figure 3 Taking the request address and request feature list extracted by the feature extractor shown in the figure as an example, cluster analysis is performed on the request features of the same URL to obtain the request feature index corresponding to each URL. The request feature index corresponding to each URL can be represented in the form of a feature vector {URL, bodysize, alphabetPercent, numberPercent, specialPercent}, where bodysize represents the length of the body in the request, alphabetPercent represents the proportion of letters in the request, numberPercent represents the proportion of numbers in the request, and specialPercent represents the proportion of special characters in the request.

[0066] Furthermore, by performing threshold calculation on the feature vector of each URL, the mean, standard deviation, variance, etc. of each feature dimension (body length, letter ratio, number ratio, special character ratio) can be calculated, which can be set according to the needs, and the present disclosure does not limit this. Thus, the access request model of a single URL is obtained, and the access request models of all URLs are aggregated to obtain the final access request model.

[0067] It is worth noting that the access request model obtained based on the above method can be used as a behavioral baseline for normal access requests, which is convenient for subsequent abnormal detection of network access requests. Different access request models can be created for different request characteristics of different containers, thereby improving the detection rate and accuracy of abnormal access requests, reducing the risk of attacks that bypass vulnerabilities, and having good detection adaptability and robustness.

[0068] In a possible manner, determining an abnormal access request in a network access request based on an access request model may include: parsing the network access request to obtain a network request address and a network request feature of the network access request; for each target access request in the network access request, if there is no normal request address in the access request model that is consistent with the network request address of the target access request, determining that the target access request is an abnormal access request; or, if there is a normal request address in the access request model that is consistent with the network request address of the target access request, and a feature value corresponding to at least one network request feature of the target access request exceeds a first indicator range, determining that the target access request is an abnormal access request, and the first indicator range is determined based on a request feature indicator corresponding to the normal request address.

[0069] For example, the web traffic on the network side is collected in real time to obtain the network access request of the service that accesses the target container load. Figure 4 , extract features from network access requests, and obtain the corresponding network request address and network request features. Taking the URL corresponding to the target access request as "AAA" as an example, check whether "AAA" exists in the access request model. If it does not exist, it means that the target access request is an abnormal access request. If it does exist, further analysis can be performed based on the request features of the target access request and the request feature indicators corresponding to "AAA".

[0070] For example, the body length, letter ratio, number ratio, and special character ratio of the target access request can be compared with their respective corresponding indicator ranges. If the feature value corresponding to at least one feature in the target access request is not within its corresponding indicator range, the target access request is determined to be an abnormal access request.

[0071] It should be noted that the first indicator range is determined based on the request feature indicator corresponding to the normal request address. The request feature indicators of different request addresses are different. When comparing, if the request address of the target access request is "AAA", it is necessary to compare the indicator range determined based on the request feature indicator corresponding to "AAA". When constructing the access model, determine the mean, standard deviation, variance, etc. of each feature dimension of each request address. Taking the request feature A of a certain URL as an example, its indicator range can be expressed as [A 均值 -Default value, A 均值 +Default], [A 均值 -N×A 标准差 , A 均值 +N×A 标准差 ], N can be set according to the needs, and so on. It can be set according to the needs, and the present disclosure does not limit this.

[0072] It is worth mentioning that you can also use WAF tools to perform anomaly detection on network access requests. If there is a match, it is judged as an abnormal access request.

[0073] In this way, anomaly detection of network access requests can be performed in real time from multiple feature dimensions. Based on the access request model, the detection rate and accuracy of abnormal access requests can be improved, the risk of attacks that bypass vulnerabilities can be reduced, and detection has good adaptability and robustness.

[0074] In a possible manner, the process event model is determined in the following manner: obtaining multiple normal process events in the target container; parsing the normal process event for each normal process event to obtain normal combination features and normal parameter features of the normal process event, where the normal combination features include the process name and parent process name of the normal process event; clustering the normal parameter features of multiple normal process events according to the normal combination features to obtain parameter feature indicators corresponding to each normal combination feature; and determining the process event model based on all normal combination features and their corresponding parameter feature indicators.

[0075] The parameter characteristic index may include the process parameter length, which indicates the length of the parameter string in the process command line, or may be other characteristic indexes, which may be set according to requirements, and the present disclosure does not limit this.

[0076] For example, during the model building phase, the EDR tool can be used to obtain the process execution events in the target container on the device side, from which normal process events are filtered out for model building. Figure 5As shown, the normal process events are analyzed, the process event behaviors are modeled, and the combined features and parameter features of each normal process event are obtained. Of course, the pre-trained neural network model for extracting process event features can also be used to extract features of normal process events, and the present disclosure does not make specific restrictions on this.

[0077] For example, Figure 6 Taking the process name, parent process name and parameter feature list shown in the figure as an example, cluster analysis is performed on the parameter features of the same "process name + parent process name" combination to obtain the parameter feature index corresponding to each "process name + parent process name" combination. Of course, the parameter feature index corresponding to each "process name + parent process name" combination can also be represented in the form of a feature vector {processName, parentprocessName, parameterPercent}, where processName represents the process name, parentprocessName represents the parent process name, and parameterPercent represents the process parameter length.

[0078] Furthermore, threshold calculation is performed on the parameter features of each group of process combinations, such as calculating the mean, standard deviation, variance, etc. of the length of each group of process parameters, which can be set according to needs, and the present disclosure does not limit this. Thus, a process event model corresponding to a single "process name + parent process name" combination is obtained, and the process event models corresponding to all "process name + parent process name" combinations are aggregated to obtain the final process event model.

[0079] It is worth noting that the process event model obtained based on the above method can be used as the behavioral baseline of normal process events, which is convenient for subsequent abnormal detection of process execution events. Different process event models can be created for different process characteristics of different containers, thereby improving the detection rate and accuracy of abnormal process events, reducing the risk of attacks that bypass vulnerabilities, and having good detection adaptability and robustness.

[0080] In a possible manner, determining abnormal process events in process execution events based on a process event model may include: parsing the process execution event to obtain process combination characteristics and process parameter characteristics of the process execution event; for each target process event in the process execution event, if there is no normal combination characteristic consistent with the process combination characteristic of the target process event in the process event model, then determining that the target process event is an abnormal process event; or, if there is a normal combination characteristic consistent with the process combination characteristic of the target process event in the process event model, and the characteristic value corresponding to the process parameter characteristic of the target process event exceeds a second indicator range, then determining that the target process event is an abnormal process event, and the second indicator range is determined based on the parameter characteristic indicator corresponding to the normal combination characteristic.

[0081] For example, real-time collection of process execution events in the target container on the device side, refer to Figure 7 , parse the process execution event, and obtain the corresponding process combination features and process parameter features. Taking the process name "A" and the parent process name "B" corresponding to the target process event as an example, query whether there is an "A+B" process combination in the process event model. If not, it means that the target process event is an abnormal process event. If it exists, further analysis can be performed based on the parameter features of the target process event and the parameter feature indicators corresponding to the "A+B" process combination.

[0082] For example, taking the parameter feature as parameter length, the process parameter length of the target process event can be compared with the parameter length indicator range. If the feature value corresponding to the process parameter length of the target process event is not within the corresponding parameter length indicator range, the target process event is determined to be an abnormal process event.

[0083] It should be noted that the second indicator range is determined based on the parameter characteristic indicators corresponding to the normal combination characteristics. The parameter characteristic indicators of different combination characteristics are different. When comparing, if the combination characteristics of the target process event are "A+B", it is necessary to compare the indicator range determined based on the parameter characteristic indicators corresponding to "A+B". When constructing the process event model, the mean, standard deviation, variance, etc. of the process parameter length of each process combination are determined. Taking the process parameter characteristic S of a certain process combination as an example, its indicator range can be expressed as [S 均值 -Default value, S 均值 +Default], [S 均值 -N×S 标准差 , S 均值 +N×S 标准差 ], N can be set according to the needs, and so on. It can be set according to the needs, and the present disclosure does not limit this.

[0084] It is worth mentioning that the EDR tool can also be used to perform anomaly detection on process execution events. If a match is found, it is judged as an abnormal process event.

[0085] In this way, anomalies of process execution events can be detected in real time. Based on the process event model, the detection rate and accuracy of process execution events can be improved, the risk of attacks bypassing vulnerabilities can be reduced, and detection has good adaptability and robustness.

[0086] After obtaining the abnormal access request and the abnormal process event, the abnormal access request and the abnormal process event can be combined and analyzed to obtain the attack detection result, thereby realizing the attack detection of end-to-network combined analysis.

[0087] In a possible manner, determining the attack detection result based on abnormal access requests and abnormal process events may include: performing a timing correlation analysis on the abnormal access requests and abnormal process events to obtain a timing correlation sequence; determining a target abnormal sequence in the timing correlation sequence based on the timing correlation sequence and a preset abnormal condition; determining the attack detection result based on the target abnormal access requests and target abnormal process events corresponding to the target abnormal sequence, the attack detection result including a mapping relationship between the target abnormal access request and the target abnormal process event.

[0088] For example, refer to Figure 8 , aggregates abnormal access requests and abnormal process events. It is worth noting that in actual application scenarios, access requests with codes other than 200 can be eliminated from abnormal access requests, and only access requests with code 200 are retained. Code 200 indicates a successful response request, that is, there is no need to analyze abnormal access requests that have not been successfully responded to, reducing resource waste.

[0089] Then, the time sequences of abnormal access requests and abnormal process events are respectively constructed to perform time correlation analysis. In a possible manner, the time correlation analysis is performed on the abnormal access requests and the abnormal process events to obtain the time correlation sequence, which may include: for each abnormal access request, determining the target time of the abnormal access request, taking the number of abnormal access requests within a first preset time after the target time as the target number of abnormal requests corresponding to the target time, and taking the number of abnormal process events within a second preset time after the target time as the target number of abnormal processes corresponding to the target time, the second preset time being greater than the first preset time; determining the abnormal request sequence according to the target number of abnormal requests corresponding to all target times, and determining the abnormal process sequence according to the target number of abnormal processes corresponding to all target times; determining the subsequences in the abnormal request sequence and the abnormal process sequence that have a positive correlation as the time correlation sequence.

[0090] For example, continue to refer to Figure 8 ,Continuing with the WebRCE intrusion attack scenario as an example, WebRCE intrusion attacks generally implant shell execution commands in HTTP requests. At the same time, one HTTP request may trigger the execution of multiple commands, so the network access request and process execution event are a one-to-many relationship. The time window statistics of abnormal access requests and abnormal process events can be performed separately according to the time series.

[0091] For example, taking the time T of the occurrence of the abnormal access request as the starting point, the statistical time window is T+xs, and the number of occurrences P of the abnormal access request is counted, where x represents the first preset duration, for example, 10s, 15s, etc., and the present disclosure does not limit this. Since the process execution event will lag behind the network access request, the statistical time window of the process execution event can increase a certain overflow time compared to the network access request, such as 5s, 10s, etc., that is, the second preset duration is greater than the first preset duration, so as to include the process execution event triggered by the network access request as much as possible. For example, based on time T, the number of process execution events in the time window T+(x+10)s is counted Q. By continuously counting real-time abnormal access requests and abnormal process events, an abnormal request sequence and abnormal process sequence on a time series can be constructed.

[0092] Furthermore, the above abnormal request sequence and abnormal process sequence are subjected to timing correlation analysis. For example, the timing correlation calculation can be performed by using the DTW algorithm (Dynamic Time Warping), that is, dynamic programming is used to calculate the similarity between the two time series, so as to obtain the time series associated with P and Q. Of course, other algorithms can also be used for timing correlation analysis, and the present disclosure does not limit this. Fig. 9 As shown, the subsequence marked with a thick line is the timing correlation sequence, which means that when an abnormal access request occurs, an abnormal process sequence also occurs, and there is a positive correlation between the two.

[0093] Continue to refer to Figure 8 After obtaining the timing association sequence, the timing association sequence can be further analyzed to determine whether it is an abnormal sequence. In a possible manner, based on the timing association sequence and the preset abnormal condition, determining the target abnormal sequence in the timing association sequence can include: if there is an abnormal subsequence in the timing association sequence, determining the abnormal subsequence as the target abnormal sequence in the timing association sequence, the abnormal access request corresponding to the abnormal subsequence includes the process name of the abnormal process event corresponding to the abnormal subsequence, and the abnormal process event corresponding to the abnormal subsequence is successfully executed; and / or, if the number of subsequences in the timing association sequence within the third preset time length is greater than the preset number threshold, determining the timing association sequence as the target abnormal sequence, and the third preset time length is greater than the second preset time length.

[0094] For example, let's continue with the WebRCE intrusion attack as an example. For example, if the process name of the abnormal process event Y in the abnormal access request X in the timing association sequence exists in the body or header of the abnormal access request X, it means that there is a payload of the shell command in the abnormal access request X, and the abnormal process event Y has been successfully executed remotely in the device to be detected, then the subsequence can be determined as the target abnormal sequence, that is, there is a WebRCE intrusion attack. In addition, if the number of associated subsequences is greater than the preset number threshold within the third preset time length, the timing association sequence can also be determined as the target abnormal sequence.

[0095] Then, taking the WebRCE intrusion attack as an example, the corresponding target abnormal access request and target abnormal process event in the target abnormal sequence are mapped to obtain the following: Fig.10 The abnormal mapping of the end-to-end network behavior of the WebRCE intrusion attack shown in the figure, where the execution of CMD (command, command prompt) triggers the corresponding process execution event. In turn, the corresponding WebRCE intrusion attack alarm is triggered to detect the WebRCE intrusion attack of real-time traffic.

[0096] Combine the following Fig.11 The overall process of the attack detection method for a container provided by the present disclosure is described by way of example.

[0097] Reference Fig.11 In the training phase, the access request model learner can be used to train the historical access requests of the container and learn the access request model of the container on the network side. For the specific learning process, please refer to Figure 2 On the other hand, through the process event model learner, the historical process events triggered in response to historical access requests in the container are trained to learn the process event model of the container on the device side. The specific learning process can be referred to Figure 5 As well as related embodiments, the present disclosure will not be repeated here.

[0098] Furthermore, in the real-time detection phase, anomaly detection is first performed on the network side and the terminal side.

[0099] Among them, on the network side, through the abnormal access request detector, based on the access request model, the collected real-time network access requests are detected for access request anomalies to determine whether there are abnormal access requests. The specific judgment process can be referred to Figure 4 At the same time, the WAF detector is also used to determine whether it is an abnormal access request.

[0100] On the device side, the abnormal process event detector performs process event anomaly detection on the collected real-time process execution events based on the process event model to determine whether there are abnormal process events. For the specific judgment process, please refer to Figure 7 At the same time, the EDR detector is also used to determine whether it is an abnormal process event.

[0101] Then, through the end-to-end network detector, the abnormal access request on the network side and the abnormal process event on the device side are correlated and analyzed in time series to find the associated abnormal sequence and determine whether there is a WebRCE intrusion attack. For the specific judgment process, please refer to Figure 8 And related embodiments, which are not described in detail in this disclosure. And when it is determined that there is a WebRCE intrusion attack, an intrusion attack alarm is generated.

[0102] Using the above method, based on the business singleness and stability characteristics of container load, the behavior of the end and the network are combined to determine whether there is a WebRCE intrusion attack. First, the network access request for the business of the container load is obtained by using the WAF diversion technology, and the network access request of a single container is modeled, and the process execution event occurring in the container is obtained by using the system event collection technology of EDR, and then modeled. After the model is built, the container can be subjected to real-time WebRCE attack detection, and the network access request and process execution event collected by the network and the end are matched with the model respectively, and the abnormal access request and abnormal process event that deviate from the model are analyzed. Finally, the characteristics of the WebRCE intrusion attack are used, that is, the payload is carried in the network access request, and the payload is driven to execute the system command in the container to achieve the effect of the intrusion attack. In this way, the abnormal access request and abnormal process event are associated and analyzed in the time window in the timing, and the sequence of the WebRCE intrusion attack is found, and finally the attack detection of WebRCE is realized.

[0103] Through the above method, by correlating abnormal process events with abnormal access requests, end-to-end combined analysis of attack detection is achieved, which can not only improve the detection rate and accuracy of WebRCE intrusion attacks and reduce the risk of attacks that obfuscate bypass vulnerabilities, but also is suitable for attack detection of WebRCE vulnerabilities such as 0-day, with good detection adaptability and robustness. In addition, it is also convenient to determine the source of the attack based on abnormal access requests and the impact of the attack based on abnormal process events, thereby improving the efficiency of tracing analysis.

[0104] Based on the same concept, the embodiment of the present disclosure also provides an attack detection device for a container, referring to Fig.12 , the attack detection device 120 comprises:

[0105] An acquisition module 121 is used to acquire a network access request for a service loaded by a target container from a network side, and acquire a process execution event in the target container from a device side where the target container is located;

[0106] A first determining module 122, configured to determine an abnormal access request in the network access request and an abnormal process event in the process execution event;

[0107] The second determination module 123 is configured to determine an attack detection result based on the abnormal access request and the abnormal process event.

[0108] By using the above device, the network access request of the service that accesses the target container load is obtained from the network side, and the process execution event in the target container is obtained from the device side where the target container is located, and then the abnormal access request in the network access request and the abnormal process event in the process execution event are combined and analyzed to obtain the final attack detection result, thereby realizing the attack detection of end-to-network combined analysis. And the intrusion attack of the container is analyzed based on multiple dimensions to improve the detection rate and accuracy of the intrusion attack. In addition, it is also convenient to determine the source of the attack based on the abnormal access request and the impact of the attack based on the abnormal process event, thereby improving the efficiency of security analysis.

[0109] Optionally, the first determining module 122 is used to:

[0110] Determine the abnormal access request in the network access request based on the access request model, and determine the abnormal process event in the process execution event based on the process event model;

[0111] The access request model is obtained by modeling a normal access request for a service loaded by the target container, and the process event model is obtained by modeling a normal process event in the target container.

[0112] Optionally, the access request model is determined by a first training module, and the first training module includes:

[0113] A first acquisition submodule, configured to acquire a plurality of normal access requests for the services loaded by the target container;

[0114] A first parsing submodule, configured to parse each normal access request to obtain a normal request address and a normal request feature of the normal access request;

[0115] A first analysis submodule, configured to perform cluster analysis on the normal request features of the plurality of normal access requests according to the normal request addresses, to obtain a request feature index corresponding to each of the normal request addresses;

[0116] The first determination submodule is used to determine the access request model based on all the normal request addresses and their corresponding request feature indicators.

[0117] Optionally, the first determining module 122 is used to:

[0118] Parsing the network access request to obtain a network request address and network request characteristics of the network access request;

[0119] For each target access request in the network access request, if there is no normal request address consistent with the network request address of the target access request in the access request model, the target access request is determined to be an abnormal access request; or, if there is a normal request address consistent with the network request address of the target access request in the access request model, and the feature value corresponding to at least one network request feature of the target access request exceeds a first indicator range, then the target access request is determined to be an abnormal access request, and the first indicator range is determined based on the request feature indicator corresponding to the normal request address.

[0120] Optionally, the request characteristic indicator includes at least one of the request body length, request letter ratio, request number ratio and request special character ratio.

[0121] Optionally, the process event model is determined by a second training module, and the second training module includes:

[0122] A second acquisition submodule, configured to acquire a plurality of normal process events in the target container;

[0123] A second parsing submodule is used to parse each normal process event to obtain a normal combination feature and a normal parameter feature of the normal process event, wherein the normal combination feature includes a process name and a parent process name of the normal process event;

[0124] A second analysis submodule is used to perform cluster analysis on the normal parameter features of the plurality of normal process events according to the normal combination features to obtain a parameter feature index corresponding to each normal combination feature;

[0125] The second determination submodule is used to determine the process event model based on all the normal combination features and their corresponding parameter feature indicators.

[0126] Optionally, the first determining module 122 is used to:

[0127] Parsing the process execution event to obtain a process combination feature and a process parameter feature of the process execution event;

[0128] For each target process event in the process execution event, if there is no normal combination feature consistent with the process combination feature of the target process event in the process event model, then the target process event is determined to be an abnormal process event; or, if there is a normal combination feature consistent with the process combination feature of the target process event in the process event model, and the feature value corresponding to the process parameter feature of the target process event exceeds a second indicator range, then the target process event is determined to be an abnormal process event, and the second indicator range is determined based on the parameter feature indicator corresponding to the normal combination feature.

[0129] Optionally, the parameter characteristic indicator includes a process parameter length.

[0130] Optionally, the second determining module 123 includes:

[0131] A correlation module, used for performing a time sequence correlation analysis on the abnormal access request and the abnormal process event to obtain a time sequence correlation sequence;

[0132] An abnormal sequence determination module, used to determine a target abnormal sequence in the time series association sequence based on the time series association sequence and a preset abnormal condition;

[0133] A result determination module is used to determine the attack detection result based on the target abnormal access request and the target abnormal process event corresponding to the target abnormal sequence, wherein the attack detection result includes a mapping relationship between the target abnormal access request and the target abnormal process event.

[0134] Optionally, the association module is used to:

[0135] For each of the abnormal access requests, determine a target time for the abnormal access request, use the number of abnormal access requests within a first preset time after the target time as the target number of abnormal requests corresponding to the target time, and use the number of abnormal process events within a second preset time after the target time as the target number of abnormal processes corresponding to the target time, where the second preset time is greater than the first preset time;

[0136] Determine an abnormal request sequence according to the target number of abnormal requests corresponding to all the target times, and determine an abnormal process sequence according to the target number of abnormal processes corresponding to all the target times;

[0137] A subsequence having a positive correlation between the abnormal request sequence and the abnormal process sequence is determined as the timing association sequence.

[0138] Optionally, the association module is used to:

[0139] If there is an abnormal subsequence in the timing association sequence, the abnormal subsequence is determined as the target abnormal sequence in the timing association sequence, the abnormal access request corresponding to the abnormal subsequence includes the process name of the abnormal process event corresponding to the abnormal subsequence, and the abnormal process event corresponding to the abnormal subsequence is executed successfully; and / or,

[0140] If the number of subsequences of the time series association sequence within a third preset time length is greater than a preset number threshold, the time series association sequence is determined as the target abnormal sequence, and the third preset time length is greater than the second preset time length.

[0141] Regarding the device in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.

[0142] Based on the same concept, an embodiment of the present disclosure further provides a computer-readable medium on which a computer program is stored. When the program is executed by a processing device, the steps of the above-mentioned attack detection method for a container are implemented.

[0143] Based on the same concept, an embodiment of the present disclosure further provides an electronic device, which may include:

[0144] a storage device having a computer program stored thereon;

[0145] A processing device is used to execute the computer program in the storage device to implement the steps of the above-mentioned attack detection method for a container.

[0146] Based on the same concept, an embodiment of the present disclosure further provides a computer program product, including a computer program, which implements the steps of the above-mentioned attack detection method for a container when executed by a processor.

[0147] Reference below Fig.13 , which shows a schematic diagram of the structure of an electronic device 130 suitable for implementing the embodiment of the present disclosure. The device end to be detected in the embodiment of the present disclosure may include but is not limited to mobile terminals such as mobile phones, notebook computers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), vehicle terminals (such as vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc., and may also be a server end. Fig.13 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0148] like Fig.13As shown, the electronic device 130 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 131, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 132 or a program loaded from a storage device 138 to a random access memory (RAM) 133. In the RAM 133, various programs and data required for the operation of the electronic device 130 are also stored. The processing device 131, the ROM 132, and the RAM 133 are connected to each other via a bus 134. An input / output (I / O) interface 135 is also connected to the bus 134.

[0149] Typically, the following devices may be connected to the I / O interface 135: an input device 136 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 137 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 138 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 139. The communication device 139 may allow the electronic device 130 to communicate with other devices wirelessly or by wire to exchange data. Figure 6 The electronic device 130 is shown with various devices, but it should be understood that it is not required to implement or possess all the devices shown. More or fewer devices may be implemented or possessed instead.

[0150] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 139, or installed from the storage device 138, or installed from the ROM 132. When the computer program is executed by the processing device 131, the above-mentioned functions defined in the method of the embodiment of the present disclosure are executed.

[0151] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. Computer readable signal media may also be any computer readable medium other than computer readable storage media, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0152] In some embodiments, any currently known or future developed network protocol such as HTTP (HyperText Transfer Protocol) can be used for communication, and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0153] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.

[0154] The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: obtains a network access request for a service loaded by a target container from a network side, and obtains a process execution event in the target container from a device side where the target container is located; determines an abnormal access request in the network access request and an abnormal process event in the process execution event; and determines an attack detection result based on the abnormal access request and the abnormal process event.

[0155] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages ​​or a combination thereof, including, but not limited to, object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0156] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0157] The modules involved in the embodiments described in the present disclosure may be implemented by software or hardware, wherein the name of a module does not, in some cases, limit the module itself.

[0158] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.

[0159] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0160] The above description is only a preferred embodiment of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosed concept. For example, the above features are replaced with the technical features with similar functions disclosed in the present disclosure (but not limited to) by each other to form a technical solution.

[0161] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.

[0162] Although the subject matter has been described in language specific to structural features and / or method logic actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. On the contrary, the specific features and actions described above are merely example forms of implementing the claims. Regarding the device in the above embodiment, the specific manner in which each module performs the operation has been described in detail in the embodiment related to the method, and will not be elaborated here.

Claims

1. A method for detecting an attack on a container, characterized in that: The attack detection method comprises: Obtaining a network access request for a service loaded by a target container from a network side, and obtaining a process execution event in the target container from a device side where the target container is located; Determining abnormal access requests in the network access requests and abnormal process events in the process execution events; Determine an attack detection result based on the abnormal access request and the abnormal process event; The determining an abnormal access request in the network access request includes: The abnormal access request in the network access request is determined based on an access request model, wherein the access request model is determined in the following manner: Acquire multiple normal access requests for the services loaded by the target container; For each of the normal access requests, the normal access request is parsed to obtain a normal request address and a normal request feature of the normal access request; Performing cluster analysis on the normal request features of the plurality of normal access requests according to the normal request addresses to obtain a request feature index corresponding to each of the normal request addresses; The access request model is determined based on all the normal request addresses and their corresponding request characteristic indicators.

2. The attack detection method for a container according to claim 1, characterized in that: Determining an abnormal process event in the process execution event includes: Determining abnormal process events in the process execution events based on a process event model; The process event model is modeled based on normal process events in the target container.

3. The attack detection method for a container according to claim 1, characterized in that: The determining the abnormal access request in the network access request based on the access request model includes: Parsing the network access request to obtain a network request address and network request characteristics of the network access request; For each target access request in the network access request, if there is no normal request address consistent with the network request address of the target access request in the access request model, the target access request is determined to be an abnormal access request; or, if there is a normal request address consistent with the network request address of the target access request in the access request model, and the feature value corresponding to at least one network request feature of the target access request exceeds a first indicator range, then the target access request is determined to be an abnormal access request, and the first indicator range is determined based on the request feature indicator corresponding to the normal request address.

4. The attack detection method for a container according to claim 1, characterized in that: The request characteristic index includes at least one of the request body length, the request letter ratio, the request number ratio and the request special character ratio.

5. The attack detection method for a container according to claim 2, characterized in that: The process event model is determined as follows: Acquire a plurality of the normal process events in the target container; For each of the normal process events, the normal process event is parsed to obtain a normal combination feature and a normal parameter feature of the normal process event, wherein the normal combination feature includes a process name and a parent process name of the normal process event; Performing cluster analysis on the normal parameter features of the plurality of normal process events according to the normal combination features to obtain a parameter feature index corresponding to each normal combination feature; Based on all the normal combination features and their corresponding parameter feature indicators, the process event model is determined.

6. The attack detection method for a container according to claim 5, characterized in that: The determining the abnormal process event in the process execution event based on the process event model includes: Parsing the process execution event to obtain a process combination feature and a process parameter feature of the process execution event; For each target process event in the process execution event, if there is no normal combination feature consistent with the process combination feature of the target process event in the process event model, then the target process event is determined to be an abnormal process event; or, if there is a normal combination feature consistent with the process combination feature of the target process event in the process event model, and the feature value corresponding to the process parameter feature of the target process event exceeds a second indicator range, then the target process event is determined to be an abnormal process event, and the second indicator range is determined based on the parameter feature indicator corresponding to the normal combination feature.

7. The attack detection method for a container according to claim 5, characterized in that: The parameter characteristic indicator includes the process parameter length.

8. The attack detection method for a container according to any one of claims 1 to 7, characterized in that: The determining the attack detection result based on the abnormal access request and the abnormal process event includes: Performing a time sequence correlation analysis on the abnormal access request and the abnormal process event to obtain a time sequence correlation sequence; Based on the time series association sequence and a preset abnormal condition, determining a target abnormal sequence in the time series association sequence; Based on the target abnormal access request and the target abnormal process event corresponding to the target abnormal sequence, the attack detection result is determined, and the attack detection result includes a mapping relationship between the target abnormal access request and the target abnormal process event.

9. The attack detection method for a container according to claim 8, characterized in that: The performing a timing correlation analysis on the abnormal access request and the abnormal process event to obtain a timing correlation sequence includes: For each of the abnormal access requests, determine a target time for the abnormal access request, use the number of abnormal access requests within a first preset time after the target time as the target number of abnormal requests corresponding to the target time, and use the number of abnormal process events within a second preset time after the target time as the target number of abnormal processes corresponding to the target time, where the second preset time is greater than the first preset time; Determine an abnormal request sequence according to the target number of abnormal requests corresponding to all the target times, and determine an abnormal process sequence according to the target number of abnormal processes corresponding to all the target times; A subsequence having a positive correlation between the abnormal request sequence and the abnormal process sequence is determined as the timing association sequence.

10. The attack detection method for a container according to claim 9, characterized in that: The step of determining a target abnormal sequence in the time series association sequence based on the time series association sequence and a preset abnormal condition includes: If there is an abnormal subsequence in the timing association sequence, the abnormal subsequence is determined as the target abnormal sequence in the timing association sequence, the abnormal access request corresponding to the abnormal subsequence includes the process name of the abnormal process event corresponding to the abnormal subsequence, and the abnormal process event corresponding to the abnormal subsequence is executed successfully; and / or, If the number of subsequences of the time series association sequence within a third preset time length is greater than a preset number threshold, the time series association sequence is determined as the target abnormal sequence, and the third preset time length is greater than the second preset time length.

11. An attack detection device for a container, characterized in that: The attack detection device comprises: An acquisition module, configured to acquire a network access request for a service loaded by a target container from a network side, and acquire a process execution event in the target container from a device side where the target container is located; A first determining module, configured to determine an abnormal access request in the network access request and an abnormal process event in the process execution event; A second determination module, configured to determine an attack detection result based on the abnormal access request and the abnormal process event; The first determining module is configured to determine the abnormal access request in the network access request based on an access request model, wherein the access request model is determined in the following manner: Acquire multiple normal access requests for the services loaded by the target container; For each of the normal access requests, the normal access request is parsed to obtain a normal request address and a normal request feature of the normal access request; Performing cluster analysis on the normal request features of the plurality of normal access requests according to the normal request addresses to obtain a request feature index corresponding to each of the normal request addresses; The access request model is determined based on all the normal request addresses and their corresponding request characteristic indicators.

12. A computer readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps of the method according to any one of claims 1 to 10 are implemented.

13. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1 to 10.

14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.

Citation Information

Patent Citations

  • Attack event processing method and device, equipment and storage medium

    CN113591072A