Detection Method of Malware-Injected Webpage, Electronic Device, Storage Medium, and Computer Program Product

Through the feature extraction, analysis and detection process of the result of a web page request, combined with the strategies in the preset strategy library, efficient detection of the web pages on the Hangma page is solved, and the computing resource occupation and detection efficiency caused by multiple visits in the existing technology is solved.

CN119740224BActive Publication Date: 2025-06-20BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411912578.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-06-20
Estimated Expiration
2044-12-24

AI Technical Summary

Technical Problem

In the prior art, when detecting web pages on horses, it requires multiple visits to the web pages, resulting in excessive computing resource usage and inefficient detection.

Method used

Through the obtained web page request results at one time, perform a comprehensive feature extraction, analysis and detection process, and use the feature extraction strategies, rule analysis strategies and detection strategies in the preset policy library to process the target URL in a targeted manner, reduce computing resource usage and improve detection efficiency.

Benefits of technology

It realizes comprehensive web page detection without multiple visits to the web page, which reduces computing resource usage, improves detection efficiency, and avoids unnecessary resource consumption when a single strategy is used to process different web pages.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119740224B_ABST
    Figure CN119740224B_ABST
Patent Text Reader

Abstract

The present application provides a method for detecting a trojan-infected web page, an electronic device, a computer-readable storage medium, and a computer program product, including: parsing a target URL from a web page request result of a target web page; extracting features from the web page request result respectively according to several feature extraction plugins in a feature extraction policy corresponding to the target URL in a preset policy library, and forming a feature result set with the feature results extracted by each feature extraction plugin; processing the feature result set respectively according to several rule analysis plugins in a rule analysis policy corresponding to the target URL in the policy library, and forming a rule analysis result set with the rule analysis results processed by each rule analysis plugin; processing the rule analysis result set according to a detection policy corresponding to the target URL in the policy library to obtain a detection result; wherein, the detection result indicates whether the target web page is trojan-infected. The solution of the present application reduces the computing resources required for detection and improves the detection efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method for detecting Trojan-infected web pages, an electronic device, a computer-readable storage medium, and a computer program product. Background Art

[0002] The means of spreading web Trojans have changed from deceiving users to download and install them to attacking security vulnerabilities in the system and automatically downloading and installing them. More and more browser and browser plug-in vulnerabilities have been discovered, resulting in a rapid increase in the number of Trojan-infested web pages. How to efficiently detect and analyze Trojan-infested web pages on websites in order to cope with the growing number of browser vulnerabilities and Trojan-infested web pages is an important topic in current website security testing.

[0003] In the related scheme, the detection of Trojan-infected web pages is completed through the web page URL (Uniform Resource Locator) and the virtual machine sandbox. The web page URL is accessed in the virtual machine sandbox, and the access results are processed by setting rules. After multiple visits and obtaining the processing results, it can be determined whether it is a Trojan-infected web page.

[0004] However, the related solutions require the use of a virtual machine sandbox to complete multiple visits to web pages. When there are a large number of website URLs, it takes up too many computing resources and has low detection efficiency. Summary of the invention

[0005] The purpose of the embodiments of the present application is to provide a method for detecting Trojan-infected web pages, an electronic device, a computer-readable storage medium, and a computer program product, which are used to perform a comprehensive feature extraction, analysis, and detection process through a web page request result obtained once, thereby reducing the computing resources required for detection and improving detection efficiency.

[0006] On the one hand, the present application provides a method for detecting Trojan-infected web pages, comprising:

[0007] Parse the target URL from the web page request result of the target web page;

[0008] According to a plurality of feature extraction plug-ins in the feature extraction strategy corresponding to the target URL in the preset strategy library, feature extraction is performed on the web page request result respectively, and the feature results extracted by each feature extraction plug-in constitute a feature result set;

[0009] According to a plurality of rule analysis plug-ins in the rule analysis strategy corresponding to the target URL in the strategy library, the feature result set is processed respectively, and the rule analysis result processed by each rule analysis plug-in constitutes a rule analysis result set;

[0010] Process the rule analysis result set according to the detection strategy corresponding to the target URL in the strategy library to obtain a detection result, where the detection result indicates whether the target web page is infected with malware.

[0011] The strategy library is preconfigured with feature extraction strategies, rule analysis strategies, and detection strategies corresponding to multiple URL types.

[0012] Before performing feature extraction on the web page request results respectively using several feature extraction plugins in the feature extraction strategy corresponding to the target URL in the preset strategy library, the method further includes:

[0013] Determine the URL type to which the target URL belongs, and search for the feature extraction strategy corresponding to this URL type in the strategy library.

[0014] Before processing the feature result sets respectively using several rule analysis plugins in the rule analysis strategy corresponding to the target URL in the strategy library, the method further includes:

[0015] Determine the URL type to which the target URL belongs, and search for the rule analysis strategy corresponding to this URL type in the strategy library.

[0016] Before processing the rule analysis result set according to the detection strategy corresponding to the target URL in the strategy library, the method further includes:

[0017] Determine the URL type to which the target URL belongs, and search for the detection strategy corresponding to this URL type in the strategy library.

[0018] Through the above measures, based on the web page request results obtained once, a comprehensive process of feature extraction, analysis, and detection can be executed, without the need to access the web page multiple times, reducing the computing resources required for detection and improving the detection efficiency. In addition, this solution sets corresponding feature extraction strategies, rule analysis strategies, and detection strategies for different URLs, making the process of feature extraction, analysis, and detection of web pages more targeted, the processing results more accurate, and also avoiding the problem of unnecessary resource consumption when a single strategy processes different web pages.

[0019] Through this measure, different feature extraction strategies can be selected for different URL types, enabling the web pages of different URL types to be targeted for feature extraction results for subsequent analysis and processing. In this case, the feature results can better characterize whether the web page is infected with malware, and the feature extraction process also avoids the problem of inaccurate feature extraction and unnecessary resource consumption caused by selecting a single feature extraction strategy.

[0020] Through this measure, different rule analysis strategies can be selected for different URL types. The rule analysis strategy can be adapted to the feature extraction strategy selected for different URL types, enabling the targeted processing of the feature result sets for web pages of different URL types. In this case, the rule analysis results can better characterize whether a web page is maliciously infected.

[0021] Through this measure, based on the web page request results obtained once, a comprehensive process of feature extraction, analysis, and detection can be executed, eliminating the need to access the web page multiple times, reducing the computing resources required for detection, and improving the detection efficiency. In addition, this solution sets corresponding feature extraction strategies, rule analysis strategies, and detection strategies for different URLs, making the processes of feature extraction, analysis, and detection of web pages more targeted, the processing results more accurate, and also avoiding the problem of unnecessary resource consumption when a single strategy processes different web pages.

[0022] In one embodiment, the feature extraction strategy records the plugin paths and start / stop states of several feature extraction plugins;

[0023] Performing feature extraction on the web page request results respectively according to several feature extraction plugins in the feature extraction strategy corresponding to the target URL in the preset strategy library includes:

[0024] Screening out several feature extraction plugins with the start / stop state being the enabled state as available feature extraction plugins;

[0025] Asynchronously invoking each available feature extraction plugin from its plugin path, enabling the available feature extraction plugin to perform feature extraction on the web page request results.

[0026] Through this measure, all enabled feature extraction plugins recorded in the feature extraction strategy can be used to perform feature extraction on the web page request results in parallel, thus efficiently obtaining a comprehensive feature result set.

[0027] In one embodiment, the rule analysis strategy records the plugin paths and start / stop states of several rule analysis plugins;

[0028] Processing the feature result sets respectively according to several rule analysis plugins in the rule analysis strategy corresponding to the target URL in the strategy library includes:

[0029] Screening out several rule analysis plugins with the start / stop state being the enabled state as available rule analysis plugins;

[0030] Asynchronously invoking each available rule analysis plugin from its plugin path, enabling the rule analysis plugin to process the feature result set.

[0031] Through this measure, by using all the enabled rule analysis plugins recorded in the rule analysis strategy, the feature result set can be analyzed for rules in parallel, so that a comprehensive rule analysis result set can be obtained efficiently.

[0032] In one embodiment, the rule analysis results in the rule analysis result set are numerical values;

[0033] Processing the rule analysis result set according to the detection strategy corresponding to the target URL in the strategy library to obtain a detection result, including:

[0034] Respectively determining whether each rule analysis result in the rule analysis results is greater than a preset threshold to obtain a plurality of determination results;

[0035] Determining the detection result according to the plurality of determination results and the detection determination rules in the detection strategy.

[0036] Through the above measures, the detection strategy corresponding to the target URL can be used to effectively process the rule analysis result set, thereby obtaining a detection result.

[0037] In one embodiment, the method further includes:

[0038] In response to a first instruction corresponding to any URL type in the strategy library, configuring a corresponding feature extraction strategy for this URL type; wherein, the feature extraction strategy records several feature extraction plugins in a preset plugin library;

[0039] In response to a second instruction corresponding to any URL type in the strategy library, configuring a corresponding rule analysis strategy for this URL type; wherein, the rule analysis strategy records several rule analysis plugins in the plugin library;

[0040] In response to a third instruction corresponding to any URL type in the strategy library, configuring a corresponding detection strategy for this URL type.

[0041] Through this measure, the feature extraction strategy, rule analysis strategy, and detection strategy can be flexibly configured for each URL type as needed.

[0042] In one embodiment, the method further includes:

[0043] In response to a plugin editing instruction that matches the interface standard and naming rules of the plugin library, generating a feature extraction plugin or a rule analysis plugin, and writing the generated plugin into the plugin library.

[0044] Through the above measures, the traversal degree of the update of the entire detection system can be improved by the plug-in model, and the update iteration speed of the system's detection ability for new web trojan files can be increased; while through the standardized interface standard and naming rules, the scalability of the plug-in library can be improved.

[0045] On the other hand, the present application provides a detection device for a trojan-infected web page, including:

[0046] A parsing module, configured to parse a target URL from the web page request result of a target web page;

[0047] An extraction module, configured to perform feature extraction on the web page request result respectively according to several feature extraction plug-ins in the feature extraction policy corresponding to the target URL in a preset policy library, and form a feature result set with the feature results extracted by each feature extraction plug-in;

[0048] An analysis module, configured to process the web page request result respectively according to several rule analysis plug-ins in the rule analysis policy corresponding to the target URL in the policy library, and form a rule analysis result set with the rule analysis results processed by each rule analysis plug-in;

[0049] A detection module, configured to process the rule analysis result set according to the detection policy corresponding to the target URL in the policy library to obtain a detection result; wherein, the detection result indicates whether the target web page is trojan-infected.

[0050] On the other hand, the present application provides an electronic device, and the electronic device includes:

[0051] A processor;

[0052] A memory for storing instructions executable by the processor;

[0053] Wherein, the processor is configured to execute the above-mentioned detection method for a trojan-infected web page.

[0054] Furthermore, the present application provides a computer-readable storage medium, and the storage medium stores a computer program, and the computer program can be executed by the processor to complete the above-mentioned detection method for a trojan-infected web page.

[0055] In addition, the present application provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by the processor, the above-mentioned detection method for a trojan-infected web page is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below.

[0057] Figure 1 Schematic diagram of the application scenario of the method for detecting malicious web pages provided by an embodiment of the present application;

[0058] Figure 2 Schematic diagram of the structure of an electronic device provided by an embodiment of the present application;

[0059] Figure 3 Flowchart of the method for detecting malicious web pages provided by an embodiment of the present application;

[0060] Figure 4 Overall flowchart of the method for detecting malicious web pages provided by an embodiment of the present application;

[0061] Figure 5 Flowchart of the feature extraction method provided by an embodiment of the present application;

[0062] Figure 6 Flowchart of the rule analysis method provided by an embodiment of the present application;

[0063] Figure 7 Flowchart of the execution method of the detection measurement provided by an embodiment of the present application;

[0064] Figure 8 Schematic diagram of the service architecture for detecting malicious web pages provided by an embodiment of the present application;

[0065] Figure 9 Block diagram of the device for detecting malicious web pages provided by an embodiment of the present application. Detailed implementation manners

[0066] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.

[0067] Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.

[0068] Figure 1 Schematic diagram of the application scenario of the method for detecting malicious web pages provided by an embodiment of the present application. As Figure 1 shown, this application scenario includes a client 20 and a server 30; the client 20 can be a server, a server cluster, or a cloud computing center carrying the web page to be detected; the server 30 can be a server, a server cluster, or a cloud computing center, and can detect the web page to be detected on the client 20 to determine whether the web page to be detected is maliciously infected.

[0069] As Figure 2As shown in the figure, this embodiment provides an electronic device 1, including: at least one processor 11 and a memory 12. Figure 2 Taking one processor 11 as an example. The processor 11 and the memory 12 are connected through a bus 10. The memory 12 stores instructions executable by the processor 11. When the instructions are executed by the processor 11, the electronic device 1 can execute all or part of the processes of the methods in the following embodiments. In one embodiment, the electronic device 1 can be the above-mentioned server 30 for executing the method for detecting a trojan-infected web page.

[0070] The memory 12 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM for short), an electrically erasable programmable read-only memory (EEPROM for short), an erasable programmable read-only memory (EPROM for short), a programmable read-only memory (PROM for short), a read-only memory (ROM for short), a magnetic memory, a flash memory, a magnetic disk, or an optical disc.

[0071] This application also provides a computer-readable storage medium storing a computer program executable by the processor 11 to complete the method for detecting a trojan-infected web page provided by this application.

[0072] This application also provides a computer program product including a computer program / instructions. When the computer program / instructions are executed by the processor, the method for detecting a trojan-infected web page provided by this application is implemented.

[0073] Refer to Figure 3 , which is a schematic flowchart of the method for detecting a trojan-infected web page provided by an embodiment of this application. As Figure 3 shown, the method may include the following steps 310-step 340.

[0074] Step 310: Parse the target URL from the web page request result of the target web page.

[0075] Among them, the target web page is the web page that needs to be detected for trojan-infected web pages. Exemplarily, if it is necessary to detect whether all web pages of a website are trojan-infected, each web page of the website can be used as the target web page respectively to execute the subsequent detection process.

[0076] The web page request result is an entity object obtained by requesting a single URL in the main website monitoring service. This entity object includes request data, response data, and process data. Exemplarily, the web page request result can be expressed as: {target URL, browser information {name, version, browser plugin set}, URL entity set [{time, cache, request {url, request method, request headers}, response {status code, response headers, response content}}, {...}]}.

[0077] The target URL is the URL of the target web page, and the target URL can be parsed from the web page request result.

[0078] For the target web page determined by the main website monitoring service, after obtaining the web page request result of this target web page, the target URL can be parsed from it.

[0079] Step 320: According to several feature extraction plugins in the feature extraction strategy corresponding to the target URL in the preset policy library, perform feature extraction on the web page request result respectively, and form a feature result set with the feature results extracted by each feature extraction plugin.

[0080] Among them, the policy library is responsible for uniformly managing, configuring, and storing feature extraction strategies, and can be customized and extended through the user interface.

[0081] Each feature extraction strategy can include a policy identifier, a policy name, and a plugin set. The plugin set contains several feature extraction plugins; here, the feature extraction plugins are used to extract different types of feature information from the web page request result, including JS (JavaScript) features, CSS (Cascading Style Sheets) features, HTML (Hyper Text Markup Language) features, URL features, behavior features, and other feature information. Each feature extraction plugin in the plugin set includes information such as a plugin identifier, a plugin name, a plugin path, a maximum execution time, and a start / stop status. Among them, the plugin path is the path to load the feature extraction plugin; the maximum execution time is the maximum time allowed for the feature extraction plugin to execute; the start / stop status is the enabled state or the disabled state. The enabled state indicates that the feature extraction plugin is available, and the disabled state indicates that the feature extraction plugin is unavailable.

[0082] Exemplarily, the feature extraction strategy can be expressed as: {policy identifier, policy name, plugin set [{plugin identifier, plugin name, plugin path, maximum execution time, start / stop status}, {...}]}.

[0083] After obtaining the target URL, a feature extraction strategy corresponding to the target URL can be obtained from the policy library, and several feature extraction plugins can be parsed from the feature extraction strategy. According to each feature extraction plugin, feature extraction is performed on the web page request result respectively, and the feature result obtained by the feature extraction plugin can be obtained. The several feature results of several feature extraction plugins can constitute a feature result set.

[0084] In one embodiment, feature extraction strategies corresponding to multiple URL types are preconfigured in the policy library. Here, the URL types may include, but are not limited to, global type, domain name type, second-level domain name type, single-page type, customer asset type, custom scenario type, etc.

[0085] Before executing step 320, after obtaining the target URL, the URL type to which the target URL belongs can be determined. The string of the target URL contains information related to the URL type. By parsing the information related to the URL type in the target URL, the URL type to which the target URL belongs can be determined.

[0086] According to the URL type to which the target URL belongs, the feature extraction strategy corresponding to this URL type can be searched in the policy library as the feature extraction strategy corresponding to the target URL.

[0087] By this measure, different feature extraction strategies can be selected for different URL types, so that feature results can be extracted for web pages of different URL types specifically for subsequent analysis and processing. In this case, the feature results can better represent whether the web page is infected with malware, and the feature extraction process can also avoid the problem of inaccurate feature extraction and unnecessary resource consumption caused by selecting a single feature extraction strategy.

[0088] Step 330: Analyze several rule analysis plugins in the rule analysis strategy corresponding to the target URL in the policy library, process the feature result set respectively, and form a rule analysis result set with the rule analysis results processed by each rule analysis plugin.

[0089] Among them, the policy library is responsible for unified management, configuration, and storage of the rule analysis strategy, and can be customized and extended through the user interface.

[0090] Each rule analysis strategy may include a strategy representation, a strategy name, and a plugin set. The plugin set includes several rule analysis plugins. Here, the rule analysis plugin is used to perform numerical calculations on the feature result set according to the pre-designed calculation rules. Each rule analysis plugin in the plugin set may include information such as a plugin identifier, a plugin name, a plugin path, a maximum execution time, a start / stop status, etc.

[0091] Exemplarily, the rule analysis strategy can be expressed as: {strategy identifier, strategy name, plugin set [{plugin identifier, plugin name, plugin path, longest execution time, start / stop status}, {...}]}.

[0092] After obtaining the target URL, the rule analysis strategy corresponding to the target URL can be obtained from the strategy library, and several rule analysis plugins can be parsed from the rule analysis strategy. Feature extraction can be performed on the feature result set according to each rule analysis plugin, and the rule analysis result obtained by the rule analysis plugin can be obtained. The rule analysis results of several rule analysis plugins can constitute a rule analysis result set.

[0093] In one embodiment, rule analysis strategies corresponding to multiple URL types are pre-configured in the strategy library. Here, the URL types can include but are not limited to global type, domain name type, second-level domain name type, single-page type, customer asset type, custom scenario type, etc.

[0094] Before executing step 330, after obtaining the target URL, the URL type to which the target URL belongs can be determined. Here, the target URL can be obtained after executing step 310, or can be obtained after executing step 320 (for example: the feature result set is associated and stored with the target URL, and before executing step 330, the corresponding target URL can be determined for the feature result set to be processed).

[0095] According to the URL type to which the target URL belongs, the rule analysis strategy corresponding to this URL type can be searched in the strategy library as the rule analysis strategy corresponding to the target URL.

[0096] By this measure, different rule analysis strategies can be selected for different URL types. The rule analysis strategy can be adapted to the feature extraction strategy selected for different URL types, so that the feature result set of web pages of different URL types can be processed specifically. In this case, the rule analysis result can better represent whether the web page is infected with malware.

[0097] Step 340: Process the rule analysis result set according to the detection strategy corresponding to the target URL in the strategy library to obtain a detection result; wherein, the detection result indicates whether the target web page is infected with malware.

[0098] Among them, the strategy library is responsible for uniformly managing, configuring, and storing detection strategies, and can be customized and extended through the user interface.

[0099] Each detection strategy can include detection rules for each rule analysis result in the rule analysis result set. Exemplarily, the detection strategy can be expressed as: {strategy identifier, strategy name, detection and determination rules}.

[0100] After obtaining the target URL, a detection policy corresponding to the target URL can be obtained from the policy library to process the rule analysis result set, thereby obtaining a detection result. The detection result is that the target web page is infected with malware, or the detection result is that the target web page is not infected with malware.

[0101] In one embodiment, detection policies corresponding to multiple URL types are pre-configured in the policy library. Here, the URL types may include but are not limited to global type, domain name type, sub-domain name type, single-page type, customer asset type, custom scenario type, etc.

[0102] Before executing step 340, after obtaining the target URL, it is possible to determine the URL type to which the target URL belongs. Here, the target URL can be obtained after executing step 310, or can be obtained after executing step 330 (for example: the rule analysis result set is associated and stored with the target URL, and before executing step 330, a corresponding target URL can be determined for the rule analysis result set to be processed).

[0103] According to the URL type to which the target URL belongs, the detection policy corresponding to this URL type can be found in the policy library as the detection policy corresponding to the target URL. In this case, different detection policies can be selected for different URL types, and the detection policy can be adapted to the rule analysis policy selected for different URL types, so that it can accurately detect whether the web pages of different URL types are infected with malware.

[0104] See Figure 4 , which is the overall flowchart of the method for detecting malware-infected web pages provided by an embodiment of the present application. As Figure 4 shown, after obtaining the web page request result, the target URL can be parsed from it. With this target URL, a feature extraction policy can be found in the policy library. With this feature extraction policy, a feature extraction plugin can be obtained from the plugin library, and the feature extraction plugin is used to extract features from the web page request result, and a feature result set is formed by multiple extracted feature results. Among them, the plugin library is a file collection that combines script programs for performing feature extraction and rule analysis. The plugins in the plugin library conform to a unified interface and can be customized and extended.

[0105] With this target URL, a rule analysis policy can be found in the policy library. With this rule analysis policy, a rule analysis plugin can be obtained from the plugin library, and the rule analysis plugin is used to analyze and process the feature result set to obtain multiple rule analysis results, and a rule analysis result set is formed by multiple rule analysis results.

[0106] With this target URL, a detection policy can be found in the policy library. Using this detection policy to process the analysis result set, a detection result indicating whether the web page corresponding to the target URL is infected with malware can be obtained.

[0107] Through the above measures, based on the web page request results obtained once, a comprehensive feature extraction, analysis, and detection process can be executed without accessing the web page multiple times, reducing the computing resources required for detection and improving the detection efficiency. In addition, this solution sets corresponding feature extraction strategies, rule analysis strategies, and detection strategies for different URLs, making the process of feature extraction, analysis, and detection of web pages more targeted, the processing results more accurate, and also avoiding the problem of unnecessary resource consumption when a single strategy processes different web pages.

[0108] In one embodiment, when performing step 320, after obtaining the feature extraction strategy corresponding to the target URL, the feature extraction plugins recorded in the feature extraction strategy can be screened to filter out the feature extraction plugins with the start / stop state being the disabled state, and several feature extraction plugins with the start / stop state being the enabled state can be selected as available feature extraction plugins.

[0109] The available feature extraction plugins are asynchronously called from the plugin paths of each available feature extraction plugin respectively, so that the available feature extraction plugin performs feature extraction on the web page request results. In this case, different available feature extraction plugins can perform feature extraction tasks in parallel and can notify the main traversal task through the callback / loop event after execution, so that the main traversal task obtains the execution result. Here, the main traversal task is responsible for traversing each feature extraction plugin and asynchronously calling the available feature extraction plugins. When the available feature extraction plugin successfully extracts the feature result, the execution result is the feature result. In the case where the available feature extraction plugin times out, the execution result is a timeout notification.

[0110] Exemplarily, the feature result can be expressed as: {Feature X: Feature Value 1}, and the feature value type can support strings, numbers, boolean values, array structures, etc.

[0111] Exemplarily, the feature result set can be expressed as {Target URL, Feature Result: [{Feature X: Feature Value 1}, {Feature Y: Feature Value 2}, {...}]}.

[0112] See Figure 5 , which is a schematic flowchart of the feature extraction method provided by an embodiment of the present application. As Figure 5 shown, after obtaining the web page request results, according to the target URL in the web page request results, the feature extraction strategy corresponding to the target URL is obtained from the policy library. Analyzing the feature extraction strategy, the plugin information of several feature extraction plugins can be obtained, and the feature extraction plugin set is obtained from the plugin library based on the plugin information. The feature extraction plugins in the feature extraction plugin set are traversed to filter out the feature extraction plugins with the start / stop state being the enabled state as available feature extraction plugins.

[0113] Further, each available feature extraction plugin is asynchronously called so that each available feature extraction plugin separately performs a feature extraction task on the web page request result. Each available feature extraction plugin may record the feature value as the feature result and notify the main traversal task after completion. The main traversal task obtains the feature results returned by each available feature extraction plugin and forms a feature result set with multiple feature results.

[0114] Through this measure, all enabled feature extraction plugins recorded in the feature extraction policy can be used to perform feature extraction on the web page request result in parallel, so that a comprehensive feature result set can be efficiently obtained.

[0115] In one embodiment, when performing step 330, after obtaining the rule analysis policy corresponding to the target URL, the rule analysis plugins recorded in the rule analysis policy can be screened to filter out the rule analysis plugins with the start / stop status being the disabled status, and several rule analysis plugins with the start / stop status being the enabled status are selected as the available rule analysis plugins.

[0116] The available rule analysis plugin is asynchronously called from the plugin path of each available rule analysis plugin respectively, so that the available rule analysis plugin processes the feature result set. In this case, different available rule analysis plugins can perform the rule analysis task in parallel and can notify the main traversal task by means of a callback / loop event after completion, so that the main traversal task obtains the execution result. Here, the main traversal task is responsible for traversing each rule analysis plugin and asynchronously calling the available rule analysis plugins. When the rule analysis plugin successfully executes the rule analysis, the execution result is the rule analysis result. In the case where the available rule analysis plugin times out, the execution result is a timeout notification.

[0117] Exemplarily, the rule analysis result can be expressed as: {Rule A: rule analysis result value 1}, and the value range of the rule analysis result value can be normalized to between 0 and 1.

[0118] Exemplarily, the rule analysis result set can be expressed as: {target URL, rule analysis result: [{Rule A: rule analysis result value 1}, {Rule B: rule analysis result value 2}, {...}]}.

[0119] See Figure 6 , which is a schematic flowchart of the rule analysis method provided by an embodiment of the present application, as Figure 6As shown, after obtaining the feature result set, the target URL corresponding to the feature result set is used to obtain the rule analysis policy corresponding to the target URL in the policy library. Parsing the rule analysis policy can obtain the plug-in information of several rule analysis plug-ins, and the rule analysis plug-in set is obtained from the plug-in library based on the plug-in information. Traverse the rule analysis plug-ins in the rule analysis plug-in set to filter out the rule analysis plug-ins with the start / stop status being the enabled status as the available rule analysis plug-ins.

[0120] Further, asynchronously call each available rule analysis plug-in, so that each available rule analysis plug-in respectively executes the rule analysis task on the feature result set. Each available rule analysis plug-in can record the result value as the rule analysis result and notify the main traversal task after execution. The main traversal task obtains the rule analysis results returned by each available rule analysis plug-in, and forms a rule analysis result set with multiple rule analysis results.

[0121] Through this measure, all the enabled rule analysis plug-ins recorded in the rule analysis policy can be used to perform rule analysis on the feature result set in parallel, so that a comprehensive rule analysis result set can be obtained efficiently.

[0122] In one embodiment, the rule analysis results in the rule analysis result set are numerical values.

[0123] When executing step 340, it is possible to respectively determine whether each rule analysis result in the rule analysis results is greater than a preset threshold to obtain multiple judgment results. Here, the threshold is configured according to needs. To enable different rule analysis results to be compared with the same threshold, different rule analysis results can be normalized so that the rule analysis results are numerical values between 0 and 1; at this time, the threshold is also a numerical value between 0 and 1.

[0124] After obtaining multiple judgment results, the detection result can be determined according to the multiple judgment results and the detection determination rules in the detection policy. Exemplarily, the detection determination rule is "if all the judgment results are 'yes', then the web page is infected with malware"; or, the detection determination rule is "if at least n 'yes' in the judgment results, then the web page is infected with malware", where n can be configured according to needs, for example: n can be one of numerical values such as 1, 2, 3, etc.

[0125] Exemplarily, the detection result can be expressed as: {whether infected with malware: true / false, detection items: [{rule A: rule analysis result 1, feature items: [{feature X: feature extraction result 1}, {feature Y: feature extraction result 2}]}, {rule B: rule analysis result 2, feature items: [...]}]}

[0126] See Figure 7, is a flowchart of the execution method for detection and measurement provided by an embodiment of the present application. As Figure 7 shown, after obtaining the rule analysis result set, use the target URL corresponding to the rule analysis result set to obtain the detection policy corresponding to the target URL in the policy library.

[0127] Determine whether each rule analysis result in the rule analysis result is greater than the preset threshold K in the detection policy to obtain multiple judgment results. If the detection determination rule in the detection policy is "if all judgment results are 'yes', then the web page is hacked", then it is possible to determine whether all are "yes" based on the multiple judgment results, and then obtain the detection result. If the detection determination rule in the detection policy is "if at least one of the judgment results is 'yes', then the web page is hacked", then it is possible to determine whether there is one "yes" based on the multiple judgment results, and then obtain the detection result.

[0128] Through the above measures, the rule analysis result set can be effectively processed by using the detection policy corresponding to the target URL, so as to obtain the detection result.

[0129] The following uses a specific example to illustrate the overall detection process of the web page hacking detection method:

[0130] See Figure 8 , is a schematic diagram of the service architecture for detecting hacked web pages provided by an embodiment of the present application. As Figure 8 shown, the service architecture includes a website security monitoring service, a website information collection service, a unified scheduling service, a policy management service, and a plugin management service. The website security monitoring service is responsible for issuing the hacked web page detection task. The unified scheduling service and the website information collection service are responsible for obtaining the web page request results. The policy management service is responsible for managing the policy library. The plugin management service is responsible for managing the plugin library.

[0131] In the website security detection service, issue a remote hacked web page detection task for the website "***.cn". After obtaining the web page request results (webData) through the unified scheduling service and the website information collection service, hand it over to the hacked web page detection task. Taking the web page request of a page "http: / / 1.***.cn / " of the website as an example, execute the following hacked web page detection process.

[0132] First, use the target URL "http: / / 1.***.cn / " to request the feature extraction policy from the policy management service, so as to obtain the feature extraction policy corresponding to the URL type of the target URL. The feature extraction policy is: {1. Policy 1, plugin set: [{11. Number of occurrences of suspicious strings, feature / a_feature_extract.py, 5 minutes, enabled}, {12. Number of occurrences of suspicious tags, feature / b_feature_extract.py, 10 minutes, disabled}, {13. Abnormal frame size setting, feature / c_feature_extract.py, 10 minutes, enabled}]}. There are 3 feature extraction plugins recorded in this feature extraction policy, 2 are in the enabled state and 1 is in the disabled state.

[0133] According to the feature extraction policy, load the two enabled plugin scripts a_feature_extract.py and c_feature_extract.py from the plugin library, and asynchronously call and execute the feature extraction task. The feature result of the number of occurrences of suspicious strings is 7; the feature result of the abnormal frame size setting is "true".

[0134] Complete the feature extraction within the maximum execution time, and obtain the feature result set: {Target URL: http: / / 1.***.cn / , feature results: [{Number of occurrences of suspicious strings: 7}, {Abnormal frame size setting: true}]}.

[0135] Furthermore, use the target URL "http: / / 1.***.cn / " to request the rule analysis policy from the policy management service, so as to obtain the rule analysis policy corresponding to the URL type of the target URL. The rule analysis policy is: {2. Frame rule policy, plugin set: [{21. Frame keyword rule plugin, rule / a_rule_analyze.py, 1 minute, enabled}, {22. Frame-tag rule plugin, rule / b_rule_analyze.py, 2 minutes, disabled}]}. There are 2 rule analysis plugins recorded in this rule analysis policy, 1 is in the enabled state and 1 is in the disabled state.

[0136] According to the rule analysis policy, load the plugin script a_rule_analyze.py of the frame keyword rule plugin from the plugin library, and asynchronously call this plugin script to execute the rule analysis task to analyze and process the foregoing feature result set.

[0137] The execution logic of the rule analysis plugin is as follows: when the abnormal feature of the frame size setting is false, the rule analysis result is 0; when the abnormal feature of the frame size setting is true, the rule analysis result = 7 / 10 = 0.7. After rule analysis, the rule analysis result is 0.7.

[0138] Complete the rule analysis within the maximum execution time to obtain the rule analysis result set: {http: / / 1.***.cn / , rule analysis result: [{frame keyword rule: 0.7}]}.

[0139] Finally, request the detection policy from the policy management service according to the target URL "http: / / 1.***.cn / ": {3, frame keyword detection, existence result greater than 0.5}.

[0140] Process the rule analysis result set with this detection policy, traverse the rule analysis results, and the rule analysis result 0.7 of the frame keyword rule is greater than 0.5. The determination result is true, that is, the web page is infected with malware. The summary detection result is: {whether malware-infected: true, detection items: [{frame keyword rule: 0.7, feature items: [{number of occurrences of suspicious strings: 7}, {abnormal frame size setting: true}]}]}.

[0141] In the website security monitoring service, feedback the malware detection result of the web page http: / / 1.***.cn / to the main process to support the malware detection of the website.

[0142] In one embodiment, the policies in the policy library can be customized and extended according to business requirements.

[0143] Perform combined configuration management of rules and detection methods in the user interface to issue instructions to extend the policies in the policy library.

[0144] In response to the first instruction corresponding to any URL type in the policy library, configure the corresponding feature extraction policy for this URL type. Among them, the feature extraction policy records several feature extraction plugins in the plugin library. Here, the first instruction is used to indicate configuring the feature extraction policy, and the first instruction can carry the URL type and the feature extraction policy. The first instruction can indicate generating a feature extraction policy, deleting a feature extraction policy, or adjusting a feature extraction policy (for example: modifying the start / stop status of the feature extraction plugins in the feature extraction policy).

[0145] Through this measure, the feature extraction policy can be flexibly configured for each URL type as needed.

[0146] In response to a second instruction corresponding to any URL type in the policy library, configure a corresponding rule analysis policy for this URL type. Among them, the rule analysis policy records several rule analysis plugins in the plugin library. Here, the second instruction is used to indicate the configuration of the rule analysis policy, and the second instruction can carry the URL type and the rule analysis policy. The second instruction can indicate generating a rule analysis policy, deleting a rule analysis policy, or adjusting a rule analysis policy (for example: modifying the start / stop status of the rule analysis plugins in the rule analysis policy).

[0147] Through this measure, the rule analysis policy can be flexibly configured for each URL type as needed.

[0148] In response to a third instruction corresponding to any URL type in the policy library, configure a corresponding detection policy for this URL type. Among them, the third instruction is used to indicate the configuration of the detection policy, and the third instruction can carry the URL type and the detection policy. The third instruction can indicate generating a detection policy, deleting a detection policy, or adjusting a detection policy.

[0149] Through this measure, the detection policy can be flexibly configured for each URL type as needed.

[0150] In one embodiment, the plugin scripts in the plugin library can be customized and extended according to business requirements.

[0151] Write a plugin based on the interface standard and naming rule of the plugin library in the user interface, and then a plugin editing instruction can be generated. In response to a plugin editing instruction that matches the interface standard and naming rule of the plugin library, a feature extraction plugin or a rule analysis plugin can be generated, and the generated plugin can be written into the plugin library.

[0152] Exemplarily, the feature extraction plugin can uniformly adopt the extraction interface extract(webData) and the completion callback interface callback(featureResult). Here, webData is the web page request result, and featureResult is the feature result. The naming rule can be ending with _feature_extract.py, for example: a_feature_extract.py.

[0153] Exemplarily, the rule analysis plugin can uniformly adopt analyze(featureResults) and the completion callback interface callback(analyzeResult). Here, featureResults is the set of feature results after all feature extraction plugins are executed, and analyzeResult is a single rule analysis result. The naming rule can be ending with _run_analyze.py, for example: s_run_analyze.py.

[0154] Through the above measures, the traversal degree of the update of the entire detection system can be improved by the plug-in model, and the update iteration speed of the system's detection ability for new web trojan files can be increased; while through the standardized interface standard and naming rules, the scalability of the plug-in library can be improved.

[0155] Figure 9 It is a block diagram of a detection device for a trojan-infected web page according to an embodiment of the present invention. As Figure 9 shown, the device may include:

[0156] A parsing module 910, configured to parse a target URL from a web page request result of a target web page;

[0157] An extraction module 920, configured to perform feature extraction on the web page request result respectively according to a plurality of feature extraction plug-ins in a feature extraction policy corresponding to the target URL in a preset policy library, and form a feature result set with feature results extracted by each feature extraction plug-in;

[0158] An analysis module 930, configured to process the web page request result respectively according to a plurality of rule analysis plug-ins in a rule analysis policy corresponding to the target URL in the policy library, and form a rule analysis result set with rule analysis results processed by each rule analysis plug-in;

[0159] A detection module 940, configured to process the rule analysis result set according to a detection policy corresponding to the target URL in the policy library to obtain a detection result; wherein, the detection result indicates whether the target web page is trojan-infected.

[0160] For the specific implementation process of the functions and roles of each module in the above device, please refer to the implementation process of the corresponding steps in the above detection method for trojan-infected web pages, which will not be elaborated here.

[0161] In several embodiments provided by this application, the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and a module, a program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0162] In addition, in each embodiment of this application, the various functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0163] If the function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

Claims

1. A method for detecting Trojan-infected web pages, characterized in that: include: Parse the target URL from the web page request result of the target web page; According to a plurality of feature extraction plug-ins in the feature extraction strategy corresponding to the target URL in the preset strategy library, feature extraction is performed on the web page request result respectively, and the feature results extracted by each feature extraction plug-in constitute a feature result set; According to a plurality of rule analysis plug-ins in the rule analysis strategy corresponding to the target URL in the strategy library, the feature result set is processed respectively, and the rule analysis result processed by each rule analysis plug-in constitutes a rule analysis result set; According to the detection policy corresponding to the target URL in the policy library, the rule analysis result set is processed to obtain a detection result; wherein the detection result indicates whether the target webpage is infected with Trojans; The strategy library is pre-configured with feature extraction strategies, rule analysis strategies and detection strategies corresponding to multiple URL types; Before extracting features from the web page request results respectively according to the feature extraction plug-ins in the feature extraction strategy corresponding to the target URL in the preset strategy library, the method further includes: Determine the URL type to which the target URL belongs, and search the strategy library for a feature extraction strategy corresponding to the URL type; Before the feature result set is processed respectively according to a plurality of rule analysis plug-ins in the rule analysis strategy corresponding to the target URL in the strategy library, the method further includes: Determine the URL type to which the target URL belongs, and search the policy library for a rule analysis policy corresponding to the URL type; Before processing the rule analysis result set according to the detection policy corresponding to the target URL in the policy library, the method further includes: Determine the URL type to which the target URL belongs, and search the policy library for a detection policy corresponding to the URL type.

2. The method according to claim 1, characterized in that The feature extraction strategy records the plug-in paths and start / stop states of several feature extraction plug-ins; The method of extracting features of the web page request results respectively according to several feature extraction plug-ins in the feature extraction strategy corresponding to the target URL in the preset strategy library includes: Filter out several feature extraction plug-ins whose start / stop states are enabled as available feature extraction plug-ins; Each available feature extraction plug-in is asynchronously called from its plug-in path, so that the available feature extraction plug-in performs feature extraction on the web page request result.

3. The method according to claim 1, characterized in that The rule analysis strategy records the plug-in paths and start / stop states of several rule analysis plug-ins; The processing of the feature result set respectively according to several rule analysis plug-ins in the rule analysis strategy corresponding to the target URL in the strategy library includes: Filter out several rule analysis plug-ins whose start / stop status is enabled as available rule analysis plug-ins; Each available rule analysis plug-in is asynchronously called from its plug-in path, so that the rule analysis plug-in processes the feature result set.

4. The method according to claim 1, characterized in that: The rule analysis results in the rule analysis result set are numerical values; The step of processing the rule analysis result set according to the detection strategy corresponding to the target URL in the strategy library to obtain the detection result includes: Determine whether each rule analysis result in the rule analysis results is greater than a preset threshold value to obtain multiple determination results; The detection result is determined according to the multiple judgment results and the detection decision rules in the detection strategy.

5. The method according to claim 1, characterized in that: The method further comprises: In response to a first instruction corresponding to any URL type in the policy library, a corresponding feature extraction strategy is configured for the URL type; wherein the feature extraction strategy records a number of feature extraction plug-ins in a preset plug-in library; In response to a second instruction corresponding to any URL type in the policy library, a corresponding rule analysis policy is configured for the URL type; wherein the rule analysis policy records a number of rule analysis plug-ins in the plug-in library; In response to a third instruction corresponding to any URL type in the policy library, a corresponding detection policy is configured for the URL type.

6. The method according to claim 5, characterized in that The method further comprises: In response to a plug-in editing instruction that matches the interface standard and naming rule of the plug-in library, a feature extraction plug-in or a rule analysis plug-in is generated, and the generated plug-in is written into the plug-in library.

7. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing processor-executable instructions; The processor is configured to execute the method for detecting Trojan-infected web pages as described in any one of claims 1 to 6.

8. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and the computer program can be executed by a processor to complete the method for detecting Trojan-infected web pages as described in any one of claims 1 to 6.

9. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the method for detecting Trojan-infected web pages described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Web trojan monitoring methods, devices and equipment and memory medium

    CN109347882A

  • Webpage Embedded Trojan detection method

    CN112543178A