A method, device, equipment and storage medium for obtaining unauthorized vulnerability detection results
By optimizing the classification layer and adopting preset overprivileged vulnerability detection methods, the current traffic data is automatically detected, which solves the problem of difficulty in obtaining the overprivileged vulnerability detection results in the existing technology, and achieves efficient and stable detection results acquisition.
Patent Information
- Application Number
- CN202411177254.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-26
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-08-26
AI Technical Summary
It is difficult for the prior art to effectively obtain the detection results of the overprivileged vulnerability of the current traffic data, resulting in inefficient detection and unstable results.
By obtaining sensitive URLs, URLs to be confirmed and non-sensitive URLs, the training set is composed and the classification layer is optimized, and the current tag is output based on the current URL. When the tag is sensitive or to be confirmed, the current traffic data is detected using a preset overprivileged vulnerability detection method to generate detection results.
It realizes automated acquisition of detection results of overprivileged vulnerabilities, reduces manual intervention, and improves detection efficiency and stability of results.
Smart Images

Figure CN118972144B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to a method, device, equipment and storage medium for obtaining unauthorized vulnerability detection results. Background Art
[0002] Unauthorized access vulnerabilities are one of the most common security issues in software systems. They involve the ability of unauthorized users or processes to obtain resources or perform operations beyond their permissions. Detecting and preventing unauthorized access vulnerabilities is critical to protecting system and user data security.
[0003] An unauthorized vulnerability is one in which an attacker exploits a vulnerability to bypass the permission control mechanism of an application and obtain unauthorized access rights or execution capabilities. This type of vulnerability usually exists in the permission verification logic, access control policy, or session management of the software system. Unauthorized vulnerabilities can lead to serious security consequences, including data leakage, identity theft, system paralysis, etc. Therefore, early detection and repair of these vulnerabilities is crucial to maintaining the security of the system. Detecting unauthorized vulnerabilities not only helps prevent hacker intrusions and data leaks, but also helps comply with regulations and protect user privacy.
[0004] In order to effectively detect unauthorized vulnerabilities, security researchers and development teams have adopted a variety of technical means and methods, including static code analysis, dynamic vulnerability scanning, and permission access testing. Although there are a variety of detection technologies available, the detection of unauthorized vulnerabilities still faces many challenges. Therefore, how to obtain the unauthorized vulnerability detection results of the current traffic data is an urgent problem to be solved. Summary of the invention
[0005] The present invention provides a method and device for obtaining unauthorized vulnerability detection results, a network security device and a storage medium to solve the technical problem of how to obtain unauthorized vulnerability detection results of current flow data.
[0006] In a first aspect, a method for obtaining an unauthorized vulnerability detection result is provided, comprising:
[0007] Obtain a sensitive URL, a URL to be confirmed, and a non-sensitive URL, wherein the sensitive URL is a URL for accessing sensitive content, the URL to be confirmed is a URL for accessing content to be confirmed, and the non-sensitive URL is a URL for accessing non-sensitive content;
[0008] The sensitive URL and the sensitive label form a sensitive sample, the URL to be confirmed and the label to be confirmed form a sample to be confirmed, the non-sensitive URL and the non-sensitive label form a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples form a training set;
[0009] Select the sensitive URL, the URL to be confirmed, and the non-sensitive URL of the training set as preset URLs, and obtain the predicted label output by the classification layer based on the preset URL according to the preset URL and a predefined acquisition method;
[0010] Obtaining the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method;
[0011] Obtaining a current URL in the current traffic data, and obtaining a current tag output by the optimized classification layer based on the current URL;
[0012] When the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data to generate an unauthorized vulnerability detection result of the current traffic data.
[0013] Furthermore, the sensitive URL and the sensitive label form a sensitive sample, the URL to be confirmed and the label to be confirmed form a sample to be confirmed, the non-sensitive URL and the non-sensitive label form a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples form a training set, including:
[0014] Obtaining a preset label set, wherein the label set includes sensitive labels, labels to be confirmed, and non-sensitive labels;
[0015] The sensitive URL and sensitive label are combined into a sensitive sample, the URL to be confirmed and the label to be confirmed are combined into a sample to be confirmed, the non-sensitive URL and non-sensitive label are combined into a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples are combined into a training set.
[0016] Furthermore, the step of selecting the sensitive URL, the URL to be confirmed, and the non-sensitive URL of the training set as preset URLs, and obtaining the predicted label output by the classification layer based on the preset URL according to the preset URL and a predefined acquisition method, includes:
[0017] Select the sensitive URL, the URL to be confirmed, and the non-sensitive URL in the training set as preset URLs, input the preset URLs into a BERT model, and obtain a first feature vector output by the BERT model based on the preset URLs;
[0018] The first feature vector is input into a preset Dropout layer, the first feature vector is converted into a second feature vector through the Dropout layer, the second feature vector is input into a preset classification layer, and a predicted label output by the classification layer based on the second feature vector is obtained.
[0019] Further, the step of obtaining the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method includes:
[0020] Obtain the cross entropy loss value between the predicted label and the real label annotating the preset URL through a preset cross entropy loss function, so as to reduce the cross entropy loss value as an optimization goal, and optimize the parameters of the classification layer through a back propagation algorithm;
[0021] When the reduction amplitude of the cross entropy loss value is less than a preset amplitude, the optimization of the parameters of the classification layer is stopped, and the optimized classification layer is saved.
[0022] Furthermore, the step of obtaining a current URL in the current traffic data and obtaining a current tag output by the optimized classification layer based on the current URL includes:
[0023] Capturing a request packet sent by a client to a server, and capturing a return packet sent by the server to the client;
[0024] The request packet or the return packet is set as the current traffic data, the current URL in the current traffic data is obtained, and the current label output by the optimized classification layer based on the current URL is obtained.
[0025] Furthermore, when the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data, and an unauthorized vulnerability detection result of the current traffic data is generated, including:
[0026] When the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is obtained, wherein the unauthorized vulnerability detection method includes an authentication bypass detection method, a vertical unauthorized vulnerability detection method, and a horizontal unauthorized vulnerability detection method;
[0027] An authentication bypass detection method is adopted to detect the content of each line of the current traffic data to generate a first result. A vertical overauthorization detection method is adopted to detect the content of each line of the current traffic data to generate a second result. A horizontal overauthorization detection method is adopted to detect the content of each line of the current traffic data to generate a third result. The first result, the second result, and the third result are concatenated to generate the overauthorization vulnerability detection result.
[0028] Furthermore, when the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data, and after the unauthorized vulnerability detection result of the current traffic data is generated, the unauthorized vulnerability detection result acquisition method includes:
[0029] A preset storage area is obtained, and the unauthorized vulnerability detection result is stored in the storage area.
[0030] In a second aspect, a device for obtaining an unauthorized vulnerability detection result is provided, comprising:
[0031] A first acquisition module is used to acquire sensitive URLs, to-be-confirmed URLs, and non-sensitive URLs, wherein the sensitive URLs are URLs for accessing sensitive content, the to-be-confirmed URLs are URLs for accessing to-be-confirmed content, and the non-sensitive URLs are URLs for accessing non-sensitive content;
[0032] A composition module, used to combine the sensitive URL and the sensitive label into a sensitive sample, combine the URL to be confirmed and the label to be confirmed into a sample to be confirmed, combine the non-sensitive URL and the non-sensitive label into a non-sensitive sample, and combine multiple sensitive samples, multiple samples to be confirmed and multiple non-sensitive samples into a training set;
[0033] A second acquisition module is used to select the sensitive URL, the URL to be confirmed and the non-sensitive URL in the training set as the preset URL, and obtain the predicted label output by the classification layer based on the preset URL according to the preset URL and a predefined acquisition method;
[0034] A third acquisition module is used to acquire the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method;
[0035] A fourth acquisition module is used to acquire a current URL in the current traffic data, and acquire a current tag output by the optimized classification layer based on the current URL;
[0036] A generation module is used to detect the content of each line of the current traffic data using a preset unauthorized vulnerability detection method when the current label is the sensitive label or the label to be confirmed, and generate an unauthorized vulnerability detection result for the current traffic data.
[0037] In a third aspect, a network security device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned method for obtaining unauthorized vulnerability detection results when executing the computer program.
[0038] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned method for obtaining unauthorized vulnerability detection results are implemented.
[0039] The present application provides a method, apparatus, network security device and storage medium for obtaining unauthorized vulnerability detection results, which obtain sensitive URLs, to-be-confirmed URLs and non-sensitive URLs, wherein the sensitive URLs are URLs for accessing sensitive content, the to-be-confirmed URLs are URLs for accessing to-be-confirmed content, and the non-sensitive URLs are URLs for accessing to non-sensitive content; the sensitive URLs and sensitive labels are combined into sensitive samples, the to-be-confirmed URLs and to-be-confirmed labels are combined into to-be-confirmed samples, the non-sensitive URLs and non-sensitive labels are combined into non-sensitive samples, and a plurality of the sensitive samples, a plurality of the to-be-confirmed samples and a plurality of the non-sensitive samples are combined into a training set; the sensitive URLs, to-be-confirmed URLs and non-sensitive URLs of the training set are selected as preset URLs, and a predicted label output by a classification layer based on the preset URL is obtained according to the preset URL and a predefined acquisition method; an optimized label is obtained according to a cross entropy loss value between the predicted label and a real label annotated with the preset URL and a predefined optimization method. The optimized classification layer; obtain the current URL in the current traffic data, and obtain the current label output by the optimized classification layer based on the current URL; when the current label is the sensitive label or the label to be confirmed, the preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data, and the unauthorized vulnerability detection result of the current traffic data is generated. The beneficial effects are in two aspects. On the one hand, when the current label is the sensitive label or the label to be confirmed, the preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data, and the unauthorized vulnerability detection result of the current traffic data is generated. Since manual acquisition is not required, the acquisition time of the unauthorized vulnerability detection result of the current traffic data is reduced, which is conducive to improving the acquisition efficiency of the unauthorized vulnerability detection result of the current traffic data; on the other hand, due to automatic detection, it will not be affected by subjective factors, so it is conducive to improving the stability of the unauthorized vulnerability detection result of the current traffic data obtained. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative labor.
[0041] Figure 1 It is a schematic diagram of an application environment of a method for obtaining unauthorized vulnerability detection results in one embodiment of the present invention;
[0042] Figure 2 A flowchart of a method for obtaining unauthorized vulnerability detection results provided by an embodiment of the present invention;
[0043] Figure 3 yes Figure 1 A schematic flow chart of a specific implementation of step S23;
[0044] Figure 4 yes Figure 1 A schematic flow chart of a specific implementation of step S25;
[0045] Figure 5 yes Figure 1 A schematic flow chart of a specific implementation of step S26;
[0046] Figure 6 It is a structural diagram of a device for obtaining unauthorized vulnerability detection results in one embodiment of the present invention. DETAILED DESCRIPTION
[0047] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0048] See also Figure 1 , Figure 1 FIG. 1 is a schematic diagram of an application environment of a method for obtaining an unauthorized vulnerability detection result according to an embodiment of the present invention. The method for obtaining an unauthorized vulnerability detection result according to an embodiment of the present invention is used in the following manner: Figure 1 In a network security device in an application environment, the client communicates with the server through the network security device.
[0049] The network security device obtains a sensitive URL, a URL to be confirmed, and a non-sensitive URL through a client, wherein the sensitive URL is a URL for accessing sensitive content, the URL to be confirmed is a URL for accessing content to be confirmed, and the non-sensitive URL is a URL for accessing non-sensitive content;
[0050] The sensitive URL and the sensitive label form a sensitive sample, the URL to be confirmed and the label to be confirmed form a sample to be confirmed, the non-sensitive URL and the non-sensitive label form a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples form a training set;
[0051] Select the sensitive URL, the URL to be confirmed, and the non-sensitive URL of the training set as preset URLs, and obtain the predicted label output by the classification layer based on the preset URL according to the preset URL and a predefined acquisition method;
[0052] Obtaining the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method;
[0053] Obtaining a current URL in the current traffic data, and obtaining a current tag output by the optimized classification layer based on the current URL;
[0054] When the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data to generate an unauthorized vulnerability detection result of the current traffic data.
[0055] In the scheme implemented by the above-mentioned method, device, equipment and medium for obtaining unauthorized vulnerability detection results, the beneficial effects are in two aspects. On the one hand, when the current label is the sensitive label or the label to be confirmed, the preset unauthorized vulnerability detection method is used to detect the content of each row of the current traffic data to generate the unauthorized vulnerability detection result of the current traffic data. Since manual acquisition is not required, the acquisition time of the unauthorized vulnerability detection result of the current traffic data is reduced, which is conducive to improving the acquisition efficiency of the unauthorized vulnerability detection result of the current traffic data. On the other hand, due to automatic detection, it will not be affected by subjective factors, which is conducive to improving the stability of the unauthorized vulnerability detection result of the current traffic data obtained.
[0056] The client may include but is not limited to various personal computers, laptops, smart phones, tablet computers, and portable wearable devices.
[0057] The server can be implemented with an independent task database or a task database cluster composed of multiple task databases. The present invention is described in detail below through specific embodiments.
[0058] See also Figure 2 , Figure 2 A flowchart of a method for obtaining unauthorized vulnerability detection results provided by an embodiment of the present invention includes the following steps:
[0059] S21, obtaining a sensitive URL, a URL to be confirmed, and a non-sensitive URL, wherein the sensitive URL is a URL for accessing sensitive content, the URL to be confirmed is a URL for accessing the content to be confirmed, and the non-sensitive URL is a URL for accessing non-sensitive content;
[0060] The full name of URL in Chinese is: Uniform Resource Locator, and the full name in English is: Uniform Resource Locator. URL is a concise representation of the location and access method of resources available on the Internet, and is the address of standard resources on the Internet.
[0061] S22, the sensitive URL and the sensitive label form a sensitive sample, the URL to be confirmed and the label to be confirmed form a sample to be confirmed, the non-sensitive URL and the non-sensitive label form a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples form a training set;
[0062] Among them, the sensitive label is the label corresponding to the sensitive content.
[0063] The tag to be confirmed is a tag corresponding to the content to be confirmed.
[0064] Among them, the non-sensitive label is a label corresponding to the non-sensitive content.
[0065] For the sake of illustration, an example is given below:
[0066] The sensitive label is marked as 2, the pending label is marked as 1, and the non-sensitive label is marked as 0.
[0067] The sensitive URL and the sensitive label form a sensitive sample, the URL to be confirmed and the label to be confirmed form a sample to be confirmed, the non-sensitive URL and the non-sensitive label form a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples form a training set, including:
[0068] Obtaining a preset label set, wherein the label set includes sensitive labels, labels to be confirmed, and non-sensitive labels;
[0069] The sensitive URL and sensitive label are combined into a sensitive sample, the URL to be confirmed and the label to be confirmed are combined into a sample to be confirmed, the non-sensitive URL and non-sensitive label are combined into a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples are combined into a training set.
[0070] S23, selecting the sensitive URL, the URL to be confirmed, and the non-sensitive URL in the training set as preset URLs, and obtaining, according to the preset URLs and a predefined acquisition method, a predicted label output by a classification layer based on the preset URLs;
[0071] For the sake of illustration, an example is given below:
[0072] Select any sensitive URL in the training set as a preset URL;
[0073] Select any one of the to-be-confirmed URLs in the training set as a preset URL;
[0074] Any one of the non-sensitive URLs in the training set is selected as a preset URL.
[0075] S24, obtaining the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method;
[0076] The step of obtaining the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method includes:
[0077] Obtain the cross entropy loss value between the predicted label and the real label annotating the preset URL through a preset cross entropy loss function, so as to reduce the cross entropy loss value as an optimization goal, and optimize the parameters of the classification layer through a back propagation algorithm;
[0078] When the reduction amplitude of the cross entropy loss value is less than a preset amplitude, the optimization of the parameters of the classification layer is stopped, and the optimized classification layer is saved.
[0079] S25, obtaining a current URL in the current traffic data, and obtaining a current tag output by the optimized classification layer based on the current URL;
[0080] Exemplarily, obtaining the current tag output by the classification layer based on the current URL after optimization includes:
[0081] The current URL is input into the BERT model, a third feature vector output by the BERT model is obtained, the third feature vector is input into the Dropout layer, the third feature vector is converted into a fourth feature vector through the Dropout layer, the fourth feature vector is input into the optimized classification layer, and a current label output by the optimized classification layer based on the fourth feature vector is obtained.
[0082] S26, when the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data to generate an unauthorized vulnerability detection result of the current traffic data.
[0083] Wherein, when the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data, and after the unauthorized vulnerability detection result of the current traffic data is generated, the unauthorized vulnerability detection result acquisition method includes:
[0084] Step A, obtaining a preset storage area, and storing the unauthorized vulnerability detection result in the storage area.
[0085] Exemplarily, when the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data, and after the unauthorized vulnerability detection result of the current traffic data is generated, the unauthorized vulnerability detection result acquisition method includes:
[0086] Step B, obtaining a preset display page, and displaying the unauthorized vulnerability detection result in the display page.
[0087] Among them, step A can be executed before or after step B, and step A can also be executed simultaneously with step B. The specific execution order is not limited here.
[0088] In the embodiment of the present invention, the beneficial effects lie in two aspects. On the one hand, when the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each row of the current traffic data to generate an unauthorized vulnerability detection result of the current traffic data. Since no manual acquisition is required, the acquisition time of the unauthorized vulnerability detection result of the current traffic data is reduced, which is beneficial to improving the acquisition efficiency of the unauthorized vulnerability detection result of the current traffic data. On the other hand, due to automatic detection, it will not be affected by subjective factors, which is beneficial to improving the stability of the unauthorized vulnerability detection result of the current traffic data obtained.
[0089] See also Figure 3 , Figure 3 yes Figure 1 A specific implementation flow diagram of step S23 is described in detail as follows:
[0090] S31, selecting the sensitive URL, the URL to be confirmed, and the non-sensitive URL in the training set as a preset URL, inputting the preset URL into a BERT model, and obtaining a first feature vector output by the BERT model based on the preset URL;
[0091] Among them, the BERT model is a bidirectional encoder based on Transformer. The full English name of the BERT model is: Bidirectional Encoder Representations from Transformers.
[0092] S32, input the first feature vector to a preset Dropout layer, convert the first feature vector into a second feature vector through the Dropout layer, input the second feature vector to a preset classification layer, and obtain a predicted label output by the classification layer based on the second feature vector.
[0093] In the embodiment of the present invention, obtaining the prediction label is helpful to monitor the training process and ensure that the classification layer does not have overfitting or underfitting. By observing the changing trend of the prediction label, these problems can be discovered and corrected in time, thereby improving the generalization ability of the classification layer.
[0094] See also Figure 4 , Figure 4 yes Figure 1 A specific implementation flow diagram of step S25 is described in detail as follows:
[0095] S41, capturing a request packet sent by the client to the server, and capturing a return packet sent by the server to the client;
[0096] S42, setting the request packet or the return packet as the current traffic data, obtaining the current URL in the current traffic data, and obtaining the current label output by the optimized classification layer based on the current URL.
[0097] In the embodiment of the present invention, the current tag outputted by the optimized classification layer based on the current URL is obtained, thereby realizing an automated data processing process and greatly improving work efficiency.
[0098] See also Figure 5 , Figure 5 yes Figure 1 A specific implementation flow diagram of step S26 is described in detail as follows:
[0099] S51, when the current label is the sensitive label or the label to be confirmed, obtaining a preset unauthorized vulnerability detection method, wherein the unauthorized vulnerability detection method includes an authentication bypass detection method, a vertical unauthorized vulnerability detection method, and a horizontal unauthorized vulnerability detection method;
[0100] S52, using an authentication bypass detection method to detect the content of each line of the current traffic data to generate a first result, using a vertical overauthorization detection method to detect the content of each line of the current traffic data to generate a second result, using a horizontal overauthorization detection method to detect the content of each line of the current traffic data to generate a third result, and splicing the first result, the second result, and the third result to generate the overauthorization vulnerability detection result.
[0101] For ease of explanation, the authentication bypass detection method is adopted to detect the content of each line of the current traffic data, and the process of generating the first result is as follows:
[0102] The value of the first header field in each row of the current traffic data is queried from the database, and after deleting the cookie content in the first header field, the first header field after the cookie content is deleted is used as the second header field.
[0103] Use the current URL and the second header field to form a new request and obtain the new return content of the new request.
[0104] The value of the text field with the same identifier is queried in the original returned content, and the value of the text field is compared with the new returned content. If the key information of the original returned content and the new returned content is consistent, it is determined that an authentication bypass vulnerability exists. If the key information of the original returned content and the new returned content is inconsistent, it is determined that there is no authentication bypass vulnerability.
[0105] Among them, Cookie is a text file stored on the user's browser and used to track user sessions or store user preferences.
[0106] If the key information of the original returned content and the new returned content is consistent, it is determined that an authentication bypass vulnerability exists, including:
[0107] The current similarity between the original returned content and the new returned content is obtained through a preset similarity algorithm. If the current similarity is greater than the preset similarity, it is determined that the key information of the original returned content and the new returned content is consistent, and it is judged that there is an authentication bypass vulnerability.
[0108] The similarity algorithm includes but is not limited to an algorithm for calculating cosine similarity and an algorithm for calculating edit distance.
[0109] For ease of explanation, a vertical overriding detection method is used to detect the content of each row of the current traffic data, and the process of generating the second result is as follows:
[0110] Use the administrator account to log in to the system and capture the cookie information of the administrator account.
[0111] Log out of the administrator account, log in with a non-administrator account, and replace the browser's cookie information with the administrator account's cookie information just captured.
[0112] Perform administrator operations through a non-administrator account and obtain the return content after the non-administrator account performs administrator operations;
[0113] If the return content after a non-administrator account performs an administrator operation is the same as the return content after an administrator account performs an administrator operation, it means that the system allows the non-administrator account to perform these administrator operations, which means that there is a vertical authority overflow vulnerability in the system.
[0114] If the returned content after a non-administrator account performs an administrator operation is different from the returned content after an administrator account performs an administrator operation, it means that the system does not allow non-administrator accounts to perform these administrator operations, which means that there is no vertical authority overflow vulnerability in the system.
[0115] For ease of explanation, a horizontal overriding detection method is used to detect the content of each row of the current traffic data, and the process of generating the third result is as follows:
[0116] Use the first account to log in to the system and capture the cookie information of the first account.
[0117] The first account and the second account have the same access rights. Log out of the first account, log in to the system with the second account, and replace the browser's cookie information with the cookie information of the first account just captured.
[0118] Perform a personal information query operation through the second account to obtain the personal information after the second account performs the personal information query operation;
[0119] If the personal information obtained after the second account performs a personal information query operation is the same as the personal information obtained after the first account performs a personal information query operation, it means that the system allows the second account to perform these personal information query operations, which means that the system has a horizontal unauthorized access vulnerability.
[0120] If the personal information obtained after the second account performs a personal information query operation is different from the personal information obtained after the first account performs a personal information query operation, it means that the system does not allow the second account to perform these personal information query operations, which means that there is no horizontal authority violation in the system.
[0121] In an embodiment of the present invention, the first result, the second result, and the third result are spliced together to generate the unauthorized vulnerability detection result. Since manual acquisition is not required, the acquisition time of the unauthorized vulnerability detection result of the current traffic data is reduced, which is beneficial to improving the acquisition efficiency of the unauthorized vulnerability detection result of the current traffic data.
[0122] See also Figure 6 , Figure 6 is a structural diagram of a device for obtaining unauthorized vulnerability detection results in one embodiment of the present invention. Figure 6 As shown, the unauthorized vulnerability detection result acquisition device based on unauthorized vulnerability detection result acquisition includes a first acquisition module 101, a composition module 102, a second acquisition module 103, a third acquisition module 104, a fourth acquisition module 105, and a generation module 106. The functional modules are described in detail as follows:
[0123] The first acquisition module 101 is used to acquire a sensitive URL, a URL to be confirmed, and a non-sensitive URL, wherein the sensitive URL is a URL for accessing sensitive content, the URL to be confirmed is a URL for accessing content to be confirmed, and the non-sensitive URL is a URL for accessing non-sensitive content;
[0124] Composition module 102, used for combining the sensitive URL and sensitive label to form a sensitive sample, combining the URL to be confirmed and the label to be confirmed to form a sample to be confirmed, combining the non-sensitive URL and non-sensitive label to form a non-sensitive sample, and combining a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples to form a training set;
[0125] A second acquisition module 103 is used to select the sensitive URL, the URL to be confirmed and the non-sensitive URL in the training set as preset URLs, and obtain the predicted label output by the classification layer based on the preset URL according to the preset URL and a predefined acquisition method;
[0126] A third acquisition module 104 is used to acquire the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method;
[0127] The fourth acquisition module 105 is used to acquire the current URL in the current traffic data, and acquire the current tag output by the optimized classification layer based on the current URL;
[0128] The generation module 106 is used to detect the content of each line of the current traffic data using a preset unauthorized vulnerability detection method when the current label is the sensitive label or the unconfirmed label, and generate an unauthorized vulnerability detection result of the current traffic data.
[0129] In the embodiment of the present invention, the beneficial effects lie in two aspects. On the one hand, when the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each row of the current traffic data to generate an unauthorized vulnerability detection result of the current traffic data. Since no manual acquisition is required, the acquisition time of the unauthorized vulnerability detection result of the current traffic data is reduced, which is beneficial to improving the acquisition efficiency of the unauthorized vulnerability detection result of the current traffic data. On the other hand, due to automatic detection, it will not be affected by subjective factors, which is beneficial to improving the stability of the unauthorized vulnerability detection result of the current traffic data obtained.
[0130] The specific limitations of the device for obtaining unauthorized vulnerability detection results can be found in the above limitations of the method for obtaining unauthorized vulnerability detection results, which will not be repeated here.
[0131] Each module in the above-mentioned unauthorized vulnerability detection result acquisition device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of the processor in the network security device in the form of hardware, or can be stored in the memory in the network security device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0132] In one embodiment, a network security device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor.
[0133] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or network security device can refer to the relevant description in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.
[0134] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a graphics processing unit (GPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components.
[0135] The above description and the accompanying drawings fully illustrate the embodiments of the present disclosure so that those skilled in the art can practice them. Other embodiments may include structural, logical, electrical, process and other changes. The embodiments represent possible changes only. Unless explicitly required, separate components and functions are optional, and the order of operation may vary. Parts and subsamples of some embodiments may be included in or replace parts and subsamples of other embodiments. Moreover, the words used in this application are only used to describe the embodiments and are not used to limit the claims. As used in the description of the embodiments and the claims, unless the context clearly indicates, the singular forms of "a", "an" and "the" are intended to include plural forms as well. Similarly, the term "and / or" as used in this application refers to any and all possible combinations of listings containing one or more associated ones. In addition, when used in the present application, the term "comprise" and its variants "comprises" and / or comprising refer to the presence of a stated sub-sample, whole, step, operation, element, and / or component, but do not exclude the presence or addition of one or more other sub-samples, wholes, steps, operations, elements, components and / or groups of these. In the absence of further restrictions, the elements defined by the sentence "comprising a ..." do not exclude the presence of other identical elements in the process, method or device comprising the elements. In this article, each embodiment may focus on the differences from other embodiments, and the same and similar parts between the various embodiments may refer to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method part disclosed in the embodiments, then the relevant parts can refer to the description of the method part.
[0136] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software may depend on the specific application and design constraints of the technical solution. Technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of the present disclosure. Technicians can clearly understand that for the convenience and simplicity of description, the specific working process of the above-described system, device and unit can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0137] In the embodiments disclosed herein, the disclosed methods and products (including but not limited to devices, equipment, etc.) can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of units can be only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some sub-samples can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms. The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected according to actual needs to implement this embodiment. In addition, each functional unit in the embodiment of the present disclosure may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit.
[0138] The flowchart and block diagram in the accompanying drawings show the possible architecture, function and operation of the system, method and computer program product according to the embodiment of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. In some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, which can depend on the functions involved. In the description corresponding to the flowchart and the block diagram in the accompanying drawings, the operations or steps corresponding to different boxes can also occur in a different order from the order disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, which can depend on the functions involved. Each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs the specified functions or actions, or may be implemented by a combination of dedicated hardware and computer instructions.
Claims
1. A method for obtaining unauthorized vulnerability detection results, characterized in that: include: Obtain a sensitive URL, a URL to be confirmed, and a non-sensitive URL, wherein the sensitive URL is a URL for accessing sensitive content, the URL to be confirmed is a URL for accessing content to be confirmed, and the non-sensitive URL is a URL for accessing non-sensitive content; The sensitive URL and the sensitive label form a sensitive sample, the URL to be confirmed and the label to be confirmed form a sample to be confirmed, the non-sensitive URL and the non-sensitive label form a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples form a training set; Select the sensitive URL, the URL to be confirmed, and the non-sensitive URL of the training set as preset URLs, and obtain the predicted label output by the classification layer based on the preset URL according to the preset URL and a predefined acquisition method; Obtaining the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method; Obtaining a current URL in the current traffic data, and obtaining a current tag output by the optimized classification layer based on the current URL; When the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data to generate an unauthorized vulnerability detection result of the current traffic data; Obtaining the current tag output by the classification layer based on the current URL after optimization, including: Input the current URL into the BERT model, obtain a third feature vector output by the BERT model, input the third feature vector into a Dropout layer, convert the third feature vector into a fourth feature vector through the Dropout layer, input the fourth feature vector into the optimized classification layer, and obtain a current label output by the optimized classification layer based on the fourth feature vector; When the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data to generate an unauthorized vulnerability detection result of the current traffic data, including: When the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is obtained, wherein the unauthorized vulnerability detection method includes an authentication bypass detection method, a vertical unauthorized vulnerability detection method, and a horizontal unauthorized vulnerability detection method; An authentication bypass detection method is adopted to detect the content of each line of the current traffic data to generate a first result. A vertical overauthorization detection method is adopted to detect the content of each line of the current traffic data to generate a second result. A horizontal overauthorization detection method is adopted to detect the content of each line of the current traffic data to generate a third result. The first result, the second result, and the third result are concatenated to generate the overauthorization vulnerability detection result.
2. The method for obtaining unauthorized vulnerability detection results according to claim 1, characterized in that: The sensitive URL and the sensitive label form a sensitive sample, the URL to be confirmed and the label to be confirmed form a sample to be confirmed, the non-sensitive URL and the non-sensitive label form a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples form a training set, including: Obtaining a preset label set, wherein the label set includes sensitive labels, labels to be confirmed, and non-sensitive labels; The sensitive URL and sensitive label are combined into a sensitive sample, the URL to be confirmed and the label to be confirmed are combined into a sample to be confirmed, the non-sensitive URL and non-sensitive label are combined into a non-sensitive sample, and a plurality of the sensitive samples, a plurality of the samples to be confirmed and a plurality of the non-sensitive samples are combined into a training set.
3. The method for obtaining unauthorized vulnerability detection results according to claim 1, characterized in that: The step of selecting the sensitive URL, the URL to be confirmed, and the non-sensitive URL of the training set as preset URLs, and obtaining the predicted label output by the classification layer based on the preset URL according to the preset URL and a predefined acquisition method, includes: Select the sensitive URL, the URL to be confirmed, and the non-sensitive URL in the training set as preset URLs, input the preset URLs into a BERT model, and obtain a first feature vector output by the BERT model based on the preset URLs; The first feature vector is input into a preset Dropout layer, the first feature vector is converted into a second feature vector through the Dropout layer, the second feature vector is input into a preset classification layer, and a predicted label output by the classification layer based on the second feature vector is obtained.
4. The method for obtaining unauthorized vulnerability detection results according to claim 1, characterized in that: The step of obtaining the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method includes: Obtain the cross entropy loss value between the predicted label and the real label annotating the preset URL through a preset cross entropy loss function, so as to reduce the cross entropy loss value as an optimization goal, and optimize the parameters of the classification layer through a back propagation algorithm; When the reduction amplitude of the cross entropy loss value is less than a preset amplitude, the optimization of the parameters of the classification layer is stopped, and the optimized classification layer is saved.
5. The method for obtaining unauthorized vulnerability detection results according to claim 1, characterized in that: The step of obtaining the current URL in the current traffic data and obtaining the current tag output by the optimized classification layer based on the current URL includes: Capturing a request packet sent by a client to a server, and capturing a return packet sent by the server to the client; The request packet or the return packet is set as the current traffic data, the current URL in the current traffic data is obtained, and the current label output by the optimized classification layer based on the current URL is obtained.
6. The method for obtaining unauthorized vulnerability detection results according to claim 1, characterized in that: When the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data, and after the unauthorized vulnerability detection result of the current traffic data is generated, the unauthorized vulnerability detection result acquisition method includes: A preset storage area is obtained, and the unauthorized vulnerability detection result is stored in the storage area.
7. A device for obtaining unauthorized vulnerability detection results, characterized in that: include: A first acquisition module is used to acquire sensitive URLs, to-be-confirmed URLs, and non-sensitive URLs, wherein the sensitive URLs are URLs for accessing sensitive content, the to-be-confirmed URLs are URLs for accessing to-be-confirmed content, and the non-sensitive URLs are URLs for accessing non-sensitive content; A composition module, used to combine the sensitive URL and the sensitive label into a sensitive sample, combine the URL to be confirmed and the label to be confirmed into a sample to be confirmed, combine the non-sensitive URL and the non-sensitive label into a non-sensitive sample, and combine multiple sensitive samples, multiple samples to be confirmed and multiple non-sensitive samples into a training set; A second acquisition module is used to select the sensitive URL, the URL to be confirmed and the non-sensitive URL in the training set as the preset URL, and obtain the predicted label output by the classification layer based on the preset URL according to the preset URL and a predefined acquisition method; A third acquisition module is used to acquire the optimized classification layer according to the cross entropy loss value between the predicted label and the real label annotating the preset URL and a predefined optimization method; A fourth acquisition module is used to acquire a current URL in the current traffic data, and acquire a current tag output by the optimized classification layer based on the current URL; A generating module, for detecting the content of each row of the current traffic data by using a preset unauthorized vulnerability detection method when the current label is the sensitive label or the unconfirmed label, and generating an unauthorized vulnerability detection result of the current traffic data; Obtaining the current tag output by the classification layer based on the current URL after optimization, including: Input the current URL into the BERT model, obtain a third feature vector output by the BERT model, input the third feature vector into a Dropout layer, convert the third feature vector into a fourth feature vector through the Dropout layer, input the fourth feature vector into the optimized classification layer, and obtain a current label output by the optimized classification layer based on the fourth feature vector; When the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is used to detect the content of each line of the current traffic data to generate an unauthorized vulnerability detection result of the current traffic data, including: When the current label is the sensitive label or the label to be confirmed, a preset unauthorized vulnerability detection method is obtained, wherein the unauthorized vulnerability detection method includes an authentication bypass detection method, a vertical unauthorized vulnerability detection method, and a horizontal unauthorized vulnerability detection method; An authentication bypass detection method is adopted to detect the content of each line of the current traffic data to generate a first result. A vertical overauthorization detection method is adopted to detect the content of each line of the current traffic data to generate a second result. A horizontal overauthorization detection method is adopted to detect the content of each line of the current traffic data to generate a third result. The first result, the second result, and the third result are concatenated to generate the overauthorization vulnerability detection result.
8. A network security device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method for obtaining unauthorized vulnerability detection results as described in any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method for obtaining unauthorized vulnerability detection results as described in any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Vulnerability detection method and device, storage medium and electronic equipment
CN116383823A
M-Bert-based malicious website detection model training and detection method
CN117235532A
Malicious website identification method, website sample generation method and related equipment
CN117997571A