Training methods, devices, equipment, and media for business logic attack detection models

By training a decision tree model and integrating it into the Java Virtual Machine, the real-time problem of business logic attack detection was solved, enabling accurate and rapid detection and classification of business logic attacks.

CN118940045BActive Publication Date: 2025-10-31CHINA MOBILE GRP FUJIAN CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411194181.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-28
Publication Date
2025-10-31
Estimated Expiration
2044-08-28

AI Technical Summary

Technical Problem

In existing technologies, business logic attack detection methods lack real-time capabilities and cannot effectively identify and prevent attacks that exploit the intended functions and processes of an application.

Method used

By acquiring initial business datasets and reference attack types, detection metrics and metric feature values ​​are extracted, a decision tree model is trained to implement a business logic attack detection model, and it is integrated into the Java Virtual Machine for real-time detection.

Benefits of technology

The model training effect of business logic attack detection has been improved, enabling accurate and rapid detection and classification of business logic attacks, thus improving the real-time performance and accuracy of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118940045B_ABST
    Figure CN118940045B_ABST
Patent Text Reader

Abstract

This disclosure proposes a training method, apparatus, device, and medium for a business logic attack detection model. The method includes: acquiring an initial business dataset and reference attack types, each reference attack type having at least one corresponding attack element; extracting detection indicators corresponding to each attack element from the initial business dataset; determining indicator feature values ​​corresponding to the detection indicators from the initial business dataset; determining labeled detection results corresponding to the initial business dataset based on the indicator feature values; and training an initial business logic attack detection model based on the initial business dataset and the labeled detection results corresponding to the initial business dataset to obtain a target business logic attack detection model. This effectively improves the model training performance of the business logic attack detection model, and the trained target business logic attack detection model can accurately and quickly detect and classify incoming business logic attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network security technology, and in particular to a training method, apparatus, electronic device, and storage medium for a business logic attack detection model. Background Technology

[0002] Business logic attacks are a type of cyberattack that differs from traditional vulnerability attacks. Instead, they exploit the intended functionality and processes of an application. Specifically, attackers manipulate workflows, bypass traditional security measures, and abuse legitimate functions to gain unauthorized access or cause damage, often without triggering security alerts.

[0003] In related technologies, business logic attack detection methods involve collecting business operation logs after the business system is running and then analyzing the business logic attacks in the logs, which lacks a certain degree of real-time capability. Summary of the Invention

[0004] This disclosure aims to at least partially address one of the technical problems in the related art.

[0005] Therefore, this disclosure proposes a training method for a business logic attack detection model, a business logic attack detection method, an apparatus, an electronic device, a storage medium, and a computer program product.

[0006] The training method for the business logic attack detection model proposed in the first aspect of this disclosure includes:

[0007] Obtain the initial business dataset and reference attack types, wherein each reference attack type has at least one corresponding attack element;

[0008] From the initial business dataset, the detection metrics corresponding to each attack element are extracted;

[0009] Determine the indicator feature values ​​corresponding to the detection indicators from the initial business dataset;

[0010] Based on the indicator feature values ​​corresponding to the detection indicators, the labeled detection results corresponding to the initial business dataset are determined. The labeled detection results are used to indicate whether there is a business logic attack of the reference attack type.

[0011] Based on the initial business dataset and the labeled detection results corresponding to the initial business dataset, an initial business logic attack detection model is trained to obtain a target business logic attack detection model, wherein the business logic attack detection model is a decision tree model.

[0012] The business logic attack detection method proposed in the second aspect of this disclosure includes:

[0013] Obtain the target business logic attack detection model, wherein the target business logic attack identification model is trained by the training method of the above-mentioned business logic attack detection model;

[0014] Write the target business logic attack identification model into the business agent program to obtain a distributable file;

[0015] Integrate the distributable file package into the Java Virtual Machine in the business scenario to be tested;

[0016] When the Java Virtual Machine is running, it triggers the execution of distributable files to detect business logic attacks.

[0017] The training apparatus for the business logic attack detection model proposed in the third aspect embodiment of this disclosure includes:

[0018] The first acquisition module is used to acquire the initial business dataset and reference attack types, wherein each reference attack type has at least one corresponding attack element;

[0019] The extraction module is used to extract the detection metrics corresponding to each attack element from the initial business dataset;

[0020] The first determination module is used to determine the indicator feature values ​​corresponding to the detection indicators from the initial business dataset;

[0021] The second determining module is used to determine the labeled detection result corresponding to the initial business dataset based on the indicator feature value corresponding to the detection indicator. The labeled detection result is used to indicate whether there is a business logic attack of the reference attack type.

[0022] The training module is used to train an initial business logic attack detection model based on the initial business dataset and the labeled detection results corresponding to the initial business dataset, so as to obtain a target business logic attack detection model, wherein the business logic attack detection model is a decision tree model.

[0023] The business logic attack detection apparatus proposed in the fourth aspect embodiment of this disclosure includes:

[0024] The second acquisition module is used to acquire the target business logic attack detection model, wherein the target business logic attack identification model is trained by the training device of the above-mentioned business logic attack detection model.

[0025] The writing module is used to write the target business logic attack identification model into the business agent program to obtain a distributable file;

[0026] The integration module is used to integrate distributable file packages into the Java Virtual Machine in the business scenario to be tested;

[0027] The detection module is used to trigger the execution of distributable files to detect business logic attacks when the Java Virtual Machine is started.

[0028] A fifth aspect of this disclosure provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements a training method for a business logic attack detection model as proposed in a first aspect of this disclosure, or implements a business logic attack detection method as proposed in a second aspect of this disclosure.

[0029] A sixth aspect of this disclosure provides a non-transitory computer-readable storage medium having a computer program stored thereon. When executed by a processor, the program implements a training method for a business logic attack detection model as proposed in a first aspect of this disclosure, or implements a business logic attack detection method as proposed in a second aspect of this disclosure.

[0030] A seventh aspect of this disclosure provides a computer program product that, when executed by an instruction processor, performs a training method for a business logic attack detection model as proposed in a first aspect of this disclosure, or implements a business logic attack detection method as proposed in a second aspect of this disclosure.

[0031] The training method, apparatus, electronic device, storage medium, and computer program product of the business logic attack detection model proposed in this disclosure have at least the following beneficial effects: acquiring an initial business dataset and reference attack types, wherein each reference attack type has at least one corresponding attack element; extracting detection indicators corresponding to each attack element from the initial business dataset; determining indicator feature values ​​corresponding to the detection indicators from the initial business dataset; determining labeled detection results corresponding to the initial business dataset based on the indicator feature values ​​corresponding to the detection indicators; wherein the labeled detection results are used to indicate whether a business logic attack of the reference attack type exists; training an initial business logic attack detection model based on the initial business dataset and the labeled detection results corresponding to the initial business dataset to obtain a target business logic attack detection model; wherein the business logic attack detection model is a decision tree model. Therefore, by combining the initial business dataset and the labeled detection results corresponding to the initial business dataset, the model training effect of the business logic attack detection model can be effectively improved, and the trained target business logic attack detection model can accurately and quickly detect and classify incoming business logic attacks.

[0032] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this disclosure. Attached Figure Description

[0033] The above and / or additional aspects and advantages of this disclosure will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, in which:

[0034] Figure 1 This is a flowchart illustrating the training method of a business logic attack detection model proposed in an embodiment of this disclosure;

[0035] Figure 2 This is a schematic diagram of a business logic attack indicator system proposed according to an embodiment of this disclosure;

[0036] Figure 3 This is a flowchart illustrating the training method of a business logic attack detection model proposed in another embodiment of this disclosure;

[0037] Figure 4 This is a flowchart illustrating a business logic attack detection method proposed in another embodiment of this disclosure;

[0038] Figure 5 This is a schematic diagram of the structure of a training device for a business logic attack detection model proposed in an embodiment of this disclosure;

[0039] Figure 6 This is a schematic diagram of the structure of a business logic attack detection device proposed in an embodiment of this disclosure;

[0040] Figure 7 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation

[0041] Embodiments of this disclosure are described in detail below, with examples of embodiments illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are used only to explain this disclosure, and should not be construed as limiting this disclosure. Rather, embodiments of this disclosure include all variations, modifications, and equivalents falling within the spirit and scope of the appended claims.

[0042] The technical solutions provided in this disclosure are applicable to a variety of systems, especially 5G systems. For example, applicable systems may include Global System for Mobile Communication (GSM), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA) General Packet Radio Service (GPRS), Long Term Evolution (LTE), LTE Frequency Division Duplex (FDD), LTE Time Division Duplex (TDD), Long Term Evolution Advanced (LTE-A), Universal Mobile Telecommunication System (UMTS), and 5G New Radio (NR). All of these systems include terminals and network equipment. The systems may also include a core network component, such as Evolved Packet System (EPS) or 5G system (5GS).

[0043] Figure 1 This is a flowchart illustrating the training method of a business logic attack detection model proposed in one embodiment of this disclosure.

[0044] It should be noted that the execution entity of the training method for the business logic attack detection model in this embodiment is the training device for the business logic attack detection model. This device can be implemented by software and / or hardware, and it can be configured in a network device without limitation.

[0045] like Figure 1 As shown, the training method for this business logic attack detection model includes:

[0046] S101: Obtain the initial business dataset and reference attack types, wherein each reference attack type has at least one corresponding attack element.

[0047] The initial business dataset contains multiple initial business data sets, which refer to historical business data collected during the execution of historical business processes.

[0048] In this embodiment of the disclosure, business logic attacks can be classified into several reference attack types, which may include: privilege escalation type; phishing type; bomb type; data theft type.

[0049] In this embodiment of the disclosure, when determining whether the current business access is a business logic attack of a certain reference attack type, it is first necessary to determine whether the current business access has an attack element corresponding to the reference attack type. That is, when it is determined that the current business access has an attack element corresponding to the reference attack type, it is determined that there is a business logic attack of the reference attack type.

[0050] In this embodiment of the disclosure, the attack elements corresponding to the privilege escalation type include:

[0051] Horizontal overstepping of authority elements and vertical overstepping of authority elements;

[0052] Among them, the attack elements corresponding to phishing types include: class method exception elements;

[0053] Among them, the attack elements corresponding to the bomb type include:

[0054] Landing-type bomb elements and operational bombs;

[0055] Among them, the attack elements corresponding to data theft types include:

[0056] Data export features and data query features.

[0057] S102: Extract the detection metrics corresponding to each attack element from the initial business dataset.

[0058] Among them, the detection indicators can be used to determine what kind of attack elements are contained in the initial business data. For example, it can be based on two detection indicators, namely permission verification or consistency verification, to determine whether there are horizontal privilege escalation elements in the current business.

[0059] In this embodiment of the disclosure, see Figure 2 , Figure 2 This is a schematic diagram of a business logic attack indicator system proposed according to an embodiment of this disclosure. The diagram illustrates the mapping relationship between each attack type, attack element, and corresponding detection indicator, and can be a combination of... Figure 2 The diagram shown illustrates the business logic attack indicator system. Detection indicators corresponding to each attack element are extracted from the initial business dataset.

[0060] S103: Determine the indicator feature values ​​corresponding to the detection indicators from the initial business dataset.

[0061] Among them, the indicator feature value refers to the specific feature value corresponding to the detection indicator. For example, the indicator feature value corresponding to SMS overload verification can be: whether there is an overload of SMS or not, and there is no restriction on this.

[0062] In this embodiment of the disclosure, the initial business dataset also includes: basic features, which are the basic attributes that reflect the sample data, such as account, Internet Protocol (IP), role, etc., and there are no restrictions on them.

[0063] In other words, in this embodiment of the present disclosure, after extracting the detection index corresponding to each attack element from the initial business dataset, the indicator feature value corresponding to the detection index can be determined from the initial business dataset. That is, the initial business dataset can be identified to determine whether the detection index exists in the initial business dataset, so as to obtain the determination result, and the determination result is used as the indicator feature value corresponding to the detection index.

[0064] S104: Based on the indicator feature values ​​corresponding to the detection indicators, determine the labeled detection results corresponding to the initial business dataset. The labeled detection results are used to indicate whether there is a business logic attack of the reference attack type.

[0065] The labeled detection results corresponding to the initial business dataset include: the labeled detection results corresponding to each initial business data in the initial business dataset.

[0066] The labeled detection results are used to indicate whether there is a business logic attack of the reference attack type. The labeled detection results can be, for example, whether there is an unauthorized business logic attack, a phishing business logic attack, a bomb-type business logic attack, a data theft business logic attack, or no business logic attack, etc. There are no restrictions on this.

[0067] In this embodiment of the present disclosure, after determining the indicator feature value corresponding to the detection indicator from the initial business dataset, the labeled detection result corresponding to the initial business data can be determined based on the indicator feature value corresponding to the detection indicator.

[0068] In some embodiments, based on the indicator feature value corresponding to the detection indicator, the labeled detection result corresponding to the initial business data is determined, it is determined whether a certain detection indicator exists in the initial business data, and if it is determined that the detection indicator exists in the initial business data, the above is combined with... Figure 2The diagram shown illustrates the business logic attack indicator system. It identifies the attack element corresponding to the detection indicator and determines the reference attack type to which the attack element belongs. This allows for further determination of the labeled detection result corresponding to the initial business data: there is a business logic attack of the reference attack type, without any restrictions.

[0069] S105: Train an initial business logic attack detection model based on the initial business dataset and the labeled detection results corresponding to the initial business dataset to obtain a target business logic attack detection model, wherein the business logic attack detection model is a decision tree model.

[0070] The business logic attack detection model can be used to detect business logic attacks in actual business scenarios. This business logic attack detection model is a decision tree model, or it can be configured as any other possible model, such as a deep learning model, a neural network model, etc., without any restrictions.

[0071] In this embodiment of the disclosure, the initial business logic attack detection model may be iteratively trained based on the initial business data and the labeled detection results corresponding to the initial business data until the model convergence condition is met, and then the trained initial business logic attack detection model is used as the target business logic attack detection model.

[0072] In this embodiment, an initial business dataset and reference attack types are obtained, wherein each reference attack type has at least one corresponding attack element. Detection indicators corresponding to each attack element are extracted from the initial business dataset. Indicator feature values ​​corresponding to the detection indicators are determined from the initial business dataset. Based on the indicator feature values ​​corresponding to the detection indicators, labeled detection results corresponding to the initial business dataset are determined. The labeled detection results are used to indicate whether a business logic attack of the reference attack type exists. An initial business logic attack detection model is trained based on the initial business dataset and the labeled detection results corresponding to the initial business dataset to obtain a target business logic attack detection model. The business logic attack detection model is a decision tree model. Thus, the initial business dataset and the labeled detection results corresponding to the initial business dataset can be combined to effectively improve the model training effect of the business logic attack detection model. Furthermore, the trained target business logic attack detection model can accurately and quickly detect and classify incoming business logic attacks.

[0073] Figure 3 This is a flowchart illustrating the training method of a business logic attack detection model proposed in another embodiment of this disclosure.

[0074] like Figure 3 As shown, the training method for this business logic attack detection model includes:

[0075] S301: Obtain the initial business dataset and reference attack types, wherein each reference attack type has at least one corresponding attack element.

[0076] S302: Extract the detection metrics corresponding to each attack element from the initial business dataset.

[0077] S303: Determine the indicator feature values ​​corresponding to the detection indicators from the initial business dataset.

[0078] S304: Based on the indicator feature values ​​corresponding to the detection indicators, determine the labeled detection results corresponding to the initial business dataset. The labeled detection results are used to indicate whether there is a business logic attack of the reference attack type.

[0079] For detailed descriptions of S301-S304, please refer to the above embodiments, which will not be repeated here.

[0080] S305: Based on the distribution of results in the initial business dataset and the labeled detection results, determine the labeled detection results as the initial entropy where a business logic attack exists.

[0081] Wherein, the initial entropy is the distribution of the attack label X (attacking / not attacking) in the initial business dataset D. For example, out of 10 initial business data entries, 5 are currently under attack. The probability is 5 / 10 = 0.5, and the initial business data without attack consists of 5 records. If the probability is 5 / 10 = 0.5, then calculate... The initial entropy for labeling detection results as indicating the presence of business logic attacks can be calculated as follows:

[0082] (0.5)+ (0.5) = 1.

[0083] S306: Determine the information gain of each detection metric relative to the initial business dataset based on the initial entropy.

[0084] In this embodiment of the disclosure, after determining that the labeled detection results are the initial entropy of a business logic attack based on the distribution of results in the initial business dataset and labeled detection results, the information gain of each detection index relative to the initial business dataset can be determined based on the initial entropy.

[0085] For example, assuming three detection metrics: permission verification metric (Y1), consistency metric (Y2), and over-extraction metric (Y3), the information gain of permission verification metric (Y1) relative to the initial business dataset can be expressed as follows:

[0086] g(D,Y1)=H(x)-[8 / 10*H(x1)+2 / 10*H(x2)]=1-[8 / 10*(-5 / 8 -3 / 8* )+2 / 10*0]≈0.28

[0087] The information gain of the consistency metric (Y2) relative to the initial business dataset can be expressed as follows:

[0088] g(D,Y2)=H(x)-[5 / 10*H(x1)+5 / 10*H(x2)]= 1-[5 / 10*0+5 / 10*0]≈1

[0089] The information gain of the over-derived metric (Y3) relative to the initial business dataset can be expressed as follows:

[0090] g(D,Y3)=H(x)-[10 / 10*H(X1)+0 / 10*H(x2)]=1-[10 / 10*1+0]=0.

[0091] Therefore, the information gains of the three detection metrics relative to the initial business dataset are 0.28, 1, and 0, respectively: permission verification metric (Y1), consistency metric (Y2), and excess export metric (Y3).

[0092] S307: Train the initial business logic attack detection model based on the information gain of each detection metric relative to the initial business dataset to obtain the target business logic attack detection model.

[0093] In this embodiment of the disclosure, after determining the information gain of each detection index relative to the initial business dataset based on the initial entropy, the initial business logic attack detection model can be trained based on the information gain of each detection index relative to the initial business dataset to obtain the target business logic attack detection model.

[0094] Optionally, in some embodiments, an initial business logic attack detection model is trained based on the information gain of each detection metric relative to the initial business dataset to obtain a target business logic attack detection model. This can be achieved by using the detection metric corresponding to the maximum information gain as the root node of the initial business logic attack detection model, where the detection metric corresponding to the maximum information gain has n first indicator feature values, where n is a positive integer. The initial business dataset is divided into n root node datasets based on the first indicator feature values. The detection metric with the maximum information gain in each first dataset is used as a child node of the root node, where the detection metric with the maximum information gain in the root node dataset has m second indicator feature values, where m is a positive integer. The corresponding root node dataset is divided into m child node datasets based on the first indicator feature values. The detection metric with the maximum information gain in the child node dataset is used as the next-level child node of the child node, until the node partitioning depth of the decision tree model reaches a preset depth. The trained initial business logic attack detection model is then used as the target business logic attack detection model.

[0095] In other words, in this embodiment of the present disclosure, the information gain with the largest value can be determined from the information gain of each detection index relative to the initial business dataset, and the detection index corresponding to the information gain with the largest value can be used as the root node. The initial business dataset can be divided into n root node datasets according to the feature value corresponding to the detection index of the root node. Then, the detection index with the largest information gain in the root node dataset can be determined and used as the child node corresponding to the root node. This process is repeated until the node calculation reaches the maximum depth of the preset tree, thus completing the training of the initial business logic detection model. The trained initial business logic detection model can then be used as the target business logic detection model.

[0096] In this embodiment, an initial business dataset and reference attack types are obtained, wherein each reference attack type has at least one corresponding attack element. Detection indicators corresponding to each attack element are extracted from the initial business dataset. Indicator feature values ​​corresponding to the detection indicators are determined from the initial business dataset. Based on the indicator feature values ​​corresponding to the detection indicators, labeled detection results corresponding to the initial business dataset are determined. The labeled detection results are used to indicate whether a business logic attack of the reference attack type exists. Based on the result distribution in the initial business dataset and the labeled detection results, the labeled detection results are determined as the initial entropy indicating the existence of a business logic attack. Based on the initial entropy, the information gain of each detection indicator relative to the initial business dataset is determined. Based on the information gain of each detection indicator relative to the initial business dataset, an initial business logic attack detection model is trained to obtain a target business logic attack detection model. Thus, by combining the initial business dataset and the labeled detection results corresponding to the initial business dataset, the model training effect of the business logic attack detection model can be effectively improved, and the trained target business logic attack detection model can accurately and quickly detect and classify incoming business logic attacks.

[0097] Figure 4 This is a flowchart illustrating a business logic attack detection method proposed in one embodiment of this disclosure.

[0098] It should be noted that the execution subject of the business logic attack detection method in this embodiment is a business logic attack detection device. This device can be implemented by software and / or hardware, and it can be configured in a network device. There are no restrictions on this.

[0099] like Figure 4 As shown, this business logic attack detection method includes:

[0100] S401: Obtain the target business logic attack detection model, wherein the target business logic attack identification model is trained by the training method of the above-mentioned business logic attack detection model.

[0101] In this disclosure, the explanations of the same terms as in the above embodiments can be found in the above embodiments, and will not be repeated here.

[0102] Among them, the target business logic attack detection model can be used to detect business logic attacks in real time during business operation.

[0103] S402: Write the target business logic attack identification model into the business agent program to obtain a distributable file.

[0104] The business agent program can be, for example, a Java Agent, without any restrictions.

[0105] The distributable file can be, for example, a JAVA Agent (Bla.jar), and there are no restrictions.

[0106] In this embodiment, after obtaining the target business logic attack detection model, the code for the target business logic attack identification model can be written into a function named BLA with the function BLA.PrivilegeEscalation(in data,outresult). This function is the business logic attack detection function. `in data` is the input parameter, i.e., the real-time running data of the HTTPS application, and `out result` is the output parameter, i.e., whether it is a business logic attack; if so, the output label value is "Attack in Progress". After the decision tree model function is generated, it will be written into the JAVA Agent to obtain a distributable file, enabling the distributable file to have the ability to detect business logic attacks.

[0107] Optionally, in some embodiments, writing the target business logic attack identification model into the business agent program to obtain a distributable file may involve writing the business logic attack identification model into the initial attack detection function to obtain the target attack detection function, and then writing the target attack detection function into the business agent program based on the runtime application self-protection RASP method to obtain a distributable file.

[0108] In other words, in this embodiment, a business agent program can be pre-created. This business agent program is a JAVA Agent built based on the Java Virtual Machine (JVM). The entry point of this AVA Agent, the `premain` method, is called first when the HTTPS application starts the JVM. The instructions in this method are then written into the code of the HTTPS application system. The instructions in the `premain` method are business logic attack detection code, etc. Assuming `BLA.PrivilegeEscalation(in dataout result)` is the business logic attack detection code, then an `Instrumentation.addTransformer(ClassFileTransformer)` converter can be added to the `premain` method. The purpose of adding and registering this converter is to convert the instructions (business logic attack detection code) into bytecode that the JVM can recognize when the HTTPS application starts the JVM, loads the JAVA Agent, and calls `premain`. The bytecode is the JVM binary instruction, and then iterates through every class and method of the business system: when the HTTPS application starts the JVM, the `ClassFileTransformer` converter iterates through every method of all classes in the business system. The goal is to inject business logic attack detection code into every method of the HTTPS application, and then inject this code into every method of every class within the HTTPS application code. After injection, `CtClass.toBytecode` needs to be called to save the modified code snippets. Following these steps, the target business logic attack detection model can be written into the JavaAgent and generated as Bla.jar using RASP distribution. This Bla.jar is fully capable of real-time detection of business logic attacks and is unaffected by the HTTPS protocol of the business system.

[0109] S403: Integrate the distributable file package into the Java Virtual Machine of the business scenario to be tested.

[0110] In this embodiment of the disclosure, after writing the target business logic attack identification model into the business agent program to obtain a distributable file, the distributable file package can be integrated into the Java Virtual Machine in the business scenario to be detected.

[0111] The Java Virtual Machine (JVM) provides a runtime environment for distributable file packages.

[0112] In other words, in this embodiment of the disclosure, the JAVA Agent (Bla.jar) can be integrated into the JVM. In this case, the JVM has the ability to detect business logic attacks in real time. Once the JVM-based HTTPS application starts, the JAVA Agent (Bla.jar) will be automatically started and injected into the functions of the HTTPS application. After injection, all business logic attacks against the HTTPS application will be accurately detected by the JAVA Agent (Bla.jar).

[0113] In this embodiment of the disclosure, when integrating the distributable file package into the Java Virtual Machine (JVM) of the business scenario to be detected, it is necessary to modify or specify the JVM startup parameters so that the JAVA Agent is loaded when the JVM starts. This is typically achieved by adding the `-java agent` parameter to the JVM startup command, followed by the path to the JAVA Agent's JAR file. At this point, the JAVA Agent may require some configuration parameters to initialize its functionality or define its behavior. These parameters can be passed as a subsequent part of the `-java agent` parameter, or specified in the `MANIFEST.MF` file within the JAVA Agent's JAR file. Before the JVM starts, it is verified that all configuration parameters are correctly set and that the JAVA Agent's JAR file is accessible, and then the JVM is started using a new command containing the `-java agent` parameter and its related configuration.

[0114] S404: Triggers execution of a distributable file for business logic attack detection when the Java Virtual Machine is running.

[0115] In this embodiment, when the JVM starts, it loads the specified JAVAAgent (Bla.jar) according to the -java agent parameter. The premain method in the JAVA Agent is executed before the JVM's main class (usually the class containing the main method) is loaded. This is a critical moment for the JAVA Agent to initialize and set up. In the premain method, one or more Class File Transformers are registered using the Instrumentation API. These transformers are called before the class is loaded into the JVM, allowing modification of the class's bytecode. The ClassFileTransformer traverses all classes and methods in the business system to find suitable locations where business logic attack detection function code needs to be injected. Injection code: At the found suitable locations, using methods such as Javassist, the business logic attack detection code is injected into the classes and methods of the business system. When the business system's classes are loaded into the JVM, the injected code is executed along with them. This allows the business system to detect business logic attack risks in real time during operation. The injected code monitors the operation of the business system and takes corresponding measures when potential business logic attacks are detected, such as logging, triggering alerts, or preventing attacks.

[0116] In this embodiment of the disclosure, a target business logic attack detection model is obtained, wherein the target business logic attack identification model is trained by the above-mentioned training method for the business logic attack detection model. The target business logic attack identification model is written into the business agent program to obtain a distributable file. The distributable file package is integrated into the Java Virtual Machine in the business scenario to be detected. When the Java Virtual Machine starts, the execution of the distributable file is triggered to perform business logic attack detection. Thus, when the Java Virtual Machine starts, the execution of the distributable file can be triggered, thereby automatically triggering business logic attack detection in the business scenario, thereby improving the real-time performance and accuracy of business logic attack detection.

[0117] Figure 5 This is a schematic diagram of the structure of a training device for a business logic attack detection model proposed in an embodiment of this disclosure.

[0118] like Figure 5 As shown, the training device 50 for the business logic attack detection model includes:

[0119] The first acquisition module 501 is used to acquire an initial business dataset and reference attack types, wherein each reference attack type has at least one corresponding attack element;

[0120] The extraction module 502 is used to extract the detection indicators corresponding to each attack element from the initial business dataset;

[0121] The first determining module 503 is used to determine the indicator feature values ​​corresponding to the detection indicators from the initial business dataset;

[0122] The second determining module 504 is used to determine the labeled detection result corresponding to the initial business dataset based on the indicator feature value corresponding to the detection indicator. The labeled detection result is used to indicate whether there is a business logic attack of the reference attack type.

[0123] Training module 505 is used to train an initial business logic attack detection model based on the initial business dataset and the labeled detection results corresponding to the initial business dataset, so as to obtain a target business logic attack detection model, wherein the business logic attack detection model is a decision tree model.

[0124] In some embodiments of this disclosure, the attack types include at least one of the following:

[0125] Unauthorized access type;

[0126] Types of fishing;

[0127] Bomb type;

[0128] Data theft types.

[0129] In some embodiments of this disclosure, the attack elements corresponding to the privilege escalation type include:

[0130] Horizontal overstepping of authority elements and vertical overstepping of authority elements;

[0131] Among them, the attack elements corresponding to phishing types include: class method exception elements;

[0132] Among them, the attack elements corresponding to the bomb type include:

[0133] Landing-type bomb elements and operational bombs;

[0134] Among them, the attack elements corresponding to data theft types include:

[0135] Data export features and data query features.

[0136] In some embodiments of this disclosure, the training module 505 is further configured to:

[0137] Based on the distribution of results in the initial business dataset and the labeled detection results, the labeled detection results are determined to be the initial entropy where business logic attacks exist.

[0138] Based on the initial entropy, determine the information gain of each detection metric relative to the initial business dataset;

[0139] The initial business logic attack detection model is trained based on the information gain of each detection metric relative to the initial business dataset to obtain the target business logic attack detection model.

[0140] In some embodiments of this disclosure, the training module 505 is further configured to:

[0141] The detection index corresponding to the maximum information gain is used as the root node of the initial business logic attack detection model. The detection index corresponding to the maximum information gain has n first index feature values, where n is a positive integer.

[0142] The initial business dataset is divided into n root node datasets based on the first indicator feature value;

[0143] The detection index with the largest information gain in each first dataset is taken as the child node of the root node. The detection index with the largest information gain in the root node dataset has m second index feature values, where m is a positive integer.

[0144] The corresponding root node dataset is divided into m child node datasets based on the first indicator feature value;

[0145] The detection index with the highest information gain in the child node dataset is taken as the next level child node, until the node partitioning depth of the decision tree model reaches the preset depth, and the initial business logic attack detection model obtained from the training is taken as the target business logic attack detection model.

[0146] With the above Figures 1 to 3 Corresponding to the training method of the business logic attack detection model provided in the embodiments, this disclosure also provides a training device for the business logic attack detection model. Since the training device for the business logic attack detection model provided in the embodiments of this disclosure is similar to the one described above... Figures 1 to 3 The training method for the business logic attack detection model provided in the embodiments corresponds to the training device for the business logic attack detection model proposed in the embodiments of this disclosure, and will not be described in detail in the embodiments of this disclosure.

[0147] Figure 6 This is a schematic diagram of the structure for business logic attack detection proposed in an embodiment of this disclosure.

[0148] like Figure 6 As shown, the business logic attack detection 60 includes:

[0149] The second acquisition module 601 is used to acquire the target business logic attack detection model, wherein the target business logic attack identification model is trained by the training device of the above-mentioned business logic attack detection model.

[0150] The writing module 602 is used to write the target business logic attack identification model into the business agent program to obtain a distributable file;

[0151] Integration module 603 is used to integrate the distributable file package into the Java Virtual Machine in the business scenario to be tested;

[0152] The detection module 604 is used to trigger the execution of a distributable file for business logic attack detection when the Java Virtual Machine is started.

[0153] In some embodiments of this disclosure, the writing module 602 is further configured to:

[0154] The business logic attack identification model is written into the initial attack detection function to obtain the target attack detection function;

[0155] Based on the runtime application self-protection RASP method, the target attack detection function is written into the business agent program to obtain a distributable file.

[0156] With the above Figure 4 Corresponding to the business logic attack detection method provided in the embodiments, this disclosure also provides a business logic attack detection device. Because the business logic attack detection device provided in the embodiments of this disclosure is similar to the one described above... Figure 4 The implementation of the business logic attack detection method provided in the embodiments corresponds to the business logic attack detection device proposed in the embodiments of this disclosure, and will not be described in detail in the embodiments of this disclosure.

[0157] In this embodiment of the disclosure, a target business logic attack detection model is obtained. The target business logic attack identification model is trained by the training method of the above-mentioned business logic attack detection model. The target business logic attack identification model is written into the business agent program to obtain a distributable file. The distributable file package is integrated into the Java Virtual Machine in the business scenario to be detected. When the Java Virtual Machine is started, the execution of the distributable file is triggered to perform business logic attack detection. Thus, when the Java Virtual Machine is started, the execution of the distributable file can be triggered, thereby automatically triggering business logic attack detection in the business scenario, thereby improving the real-time performance and accuracy of business logic attack detection.

[0158] To implement the above embodiments, this disclosure also proposes an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the training method for the business logic attack detection model proposed in the foregoing embodiments of this disclosure.

[0159] To implement the above embodiments, this disclosure also proposes a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a training method for a business logic attack detection model as proposed in the foregoing embodiments of this disclosure.

[0160] To implement the above embodiments, this disclosure also proposes a computer program product that, when the instruction processor in the computer program product is executed, performs a training method for the business logic attack detection model as proposed in the foregoing embodiments of this disclosure.

[0161] Figure 7 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present disclosure is shown. Figure 7 The electronic device 12 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.

[0162] like Figure 7 As shown, the electronic device 12 is represented in the form of a general-purpose computing device. The components of the electronic device 12 may include, but are not limited to: one or more processors or processing units 16, system memory 28, and bus 18 connecting different system components (including system memory 28 and processing unit 16).

[0163] Bus 18 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. Examples of these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0164] Electronic device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 12, including volatile and non-volatile media, removable and non-removable media.

[0165] Memory 28 may include computer system readable media in the form of volatile memory, such as Random Access Memory (RAM) 30 and / or cache memory 32. Electronic device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media (… Figure 7 Not shown; usually referred to as a "hard drive".

[0166] although Figure 7 As not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disc drive for reading and writing to a removable non-volatile optical disc (e.g., a compact disc read-only memory (CD-ROM), a digital video disc read-only memory (DVD-ROM), or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. Memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this disclosure.

[0167] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 42 typically perform the functions and / or methods described in the embodiments of this disclosure.

[0168] Electronic device 12 can also communicate with one or more external devices 14 (e.g., keyboard, pointing device, display 24, etc.), and with one or more devices that enable a user to interact with electronic device 12, and / or with any device that enables electronic device 12 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed via input / output (I / O) interface 22. Furthermore, electronic device 12 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 20. As shown, network adapter 20 communicates with other modules of electronic device 12 via bus 18. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0169] The processing unit 16 executes various functional applications and business processes by running programs stored in the system memory 28, such as implementing the training method for the business logic attack detection model mentioned in the foregoing embodiments.

[0170] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0171] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

[0172] It should be noted that in the description of this disclosure, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this disclosure, unless otherwise stated, "a plurality of" means two or more.

[0173] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of preferred embodiments of this disclosure includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this disclosure pertain.

[0174] It should be understood that various parts of this disclosure can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0175] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0176] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0177] The storage media mentioned above can be read-only memory, disk, or optical disk, etc.

[0178] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this disclosure. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0179] Although embodiments of the present disclosure have been shown and described above, it is to be understood that the above embodiments are exemplary and should not be construed as limiting the present disclosure. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present disclosure.

Claims

1. A training method for a business logic attack detection model, characterized in that, The method includes: Obtain the initial business dataset and reference attack types, wherein each reference attack type has at least one corresponding attack element; From the initial business dataset, detection metrics corresponding to each attack element are extracted; Determine the indicator feature values ​​corresponding to the detection indicators from the initial business dataset; Based on the indicator feature value corresponding to the detection indicator, a labeled detection result corresponding to the initial business dataset is determined, wherein the labeled detection result is used to indicate whether there is a business logic attack of the reference attack type; Based on the initial business dataset and the labeled detection results corresponding to the initial business dataset, an initial business logic attack detection model is trained to obtain a target business logic attack detection model, wherein the business logic attack detection model is a decision tree model. The step of training an initial business logic attack detection model based on the initial business dataset and the labeled detection results corresponding to the initial business dataset to obtain a target business logic attack detection model includes: Based on the initial business dataset and the distribution of results in the labeled detection results, the labeled detection results are determined to be the initial entropy where a business logic attack exists; Based on the initial entropy, determine the information gain of each detection metric relative to the initial business dataset; The detection index corresponding to the maximum information gain is used as the root node of the initial business logic attack detection model, wherein the detection index corresponding to the maximum information gain has n first index feature values, and n is a positive integer; The initial business dataset is divided into n root node datasets based on the first indicator feature value; The detection index with the largest information gain in each of the root node datasets is taken as the child node of the root node, wherein the detection index with the largest information gain in the root node dataset has m second index feature values, where m is a positive integer; The root node dataset is divided into m child node datasets based on the first indicator feature value. The detection index with the largest information gain in the child node dataset is taken as the next level child node of the child node, until the node partitioning depth of the decision tree model reaches the preset depth, and the initial business logic attack detection model obtained by training is taken as the target business logic attack detection model.

2. The method as described in claim 1, characterized in that, The attack type includes at least one of the following: Unauthorized access type; Types of fishing; Bomb type; Data theft types.

3. The method as described in claim 2, characterized in that, The attack elements corresponding to the aforementioned privilege escalation type include: Horizontal overreach elements and vertical overreach elements; Among them, the attack elements corresponding to the phishing type include: class method exception elements; The attack elements corresponding to the bomb type include: Landing-type bomb elements and operational bombs; The attack elements corresponding to the aforementioned data theft type include: Data export features and data query features.

4. A method for detecting business logic attacks, characterized in that, The method includes: A target business logic attack detection model is obtained, wherein the target business logic attack identification model is trained by the training method of the business logic attack detection model according to any one of claims 1-3 above; The target business logic attack identification model is written into the business agent program to obtain a distributable file; The distributable file package is integrated into the Java Virtual Machine in the business scenario to be tested; When the Java Virtual Machine is started, the distributable file is executed to detect business logic attacks.

5. The method as described in claim 4, characterized in that, The step of writing the target business logic attack identification model into the business agent program to obtain a distributable file includes: The business logic attack identification model is written into the initial attack detection function to obtain the target attack detection function; Based on the Runtime Application Self-Protection (RASP) method, the target attack detection function is written into the business agent program to obtain the distributable file.

6. A training device for a business logic attack detection model, characterized in that, The device includes: The first acquisition module is used to acquire the initial business dataset and reference attack types, wherein each reference attack type has at least one corresponding attack element; The extraction module is used to extract detection indicators corresponding to each attack element from the initial business dataset; The first determining module is used to determine the indicator feature value corresponding to the detection indicator from the initial business dataset; The second determining module is used to determine the labeled detection result corresponding to the initial business dataset based on the indicator feature value corresponding to the detection indicator, wherein the labeled detection result is used to indicate whether there is a business logic attack of the reference attack type; The training module is used to train an initial business logic attack detection model based on the initial business dataset and the labeled detection results corresponding to the initial business dataset, so as to obtain a target business logic attack detection model, wherein the business logic attack detection model is a decision tree model. The step of training an initial business logic attack detection model based on the initial business dataset and the labeled detection results corresponding to the initial business dataset to obtain a target business logic attack detection model includes: Based on the initial business dataset and the distribution of results in the labeled detection results, the labeled detection results are determined to be the initial entropy where a business logic attack exists; Based on the initial entropy, determine the information gain of each detection metric relative to the initial business dataset; The detection index corresponding to the maximum information gain is used as the root node of the initial business logic attack detection model, wherein the detection index corresponding to the maximum information gain has n first index feature values, and n is a positive integer; The initial business dataset is divided into n root node datasets based on the first indicator feature value; The detection index with the largest information gain in each of the root node datasets is taken as the child node of the root node, wherein the detection index with the largest information gain in the root node dataset has m second index feature values, where m is a positive integer; The root node dataset is divided into m child node datasets based on the first indicator feature value. The detection index with the largest information gain in the child node dataset is taken as the next level child node of the child node, until the node partitioning depth of the decision tree model reaches the preset depth, and the initial business logic attack detection model obtained by training is taken as the target business logic attack detection model.

7. A business logic attack detection device, characterized in that, The device includes: The second acquisition module is used to acquire the target business logic attack detection model, wherein the target business logic attack identification model is trained by the training device of the business logic attack detection model as described in claim 6. The writing module is used to write the target business logic attack identification model into the business agent program to obtain a distributable file; An integration module is used to integrate the distributable file package into the Java Virtual Machine in the business scenario to be tested; The detection module is used to trigger the execution of the distributable file to perform business logic attack detection when the Java Virtual Machine is started.

8. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-5.

9. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-5.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Dynamic network abnormal attack detection method and device, electronic equipment and storage medium

    CN113206824A

  • Service logic vulnerability attack detection model training method and device

    CN116346456A