A method, device and electronic device for detecting deserialization attacks
By using the preset behavior pattern library to detect the abnormality of the request when the service interface receives the deserialization request, the problem of difficulty in accurately detecting deserialization attacks in the prior art is solved, and accurate detection and protection of deserialization attacks are achieved.
Patent Information
- Application Number
- CN202510279486.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-03-10
AI Technical Summary
The prior art is difficult to accurately detect deserialization attacks, resulting in the server's possible execution of malicious code and causing losses.
When the service interface receives the deserialization request, the detection information is detected based on the normal information recorded in the preset behavior pattern library to determine whether the deserialization request to be processed is abnormal. This behavior pattern library records information on the specified dimensions of normal deserialization requests, including the object's class, attributes, function call order, and user role.
Accurate detection of deserialization attacks is achieved, and requests that may be used for deserialization attacks can be identified, thereby preventing malicious code execution and protecting the security of the server.
Smart Images

Figure CN119783097B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a deserialization attack detection method, device and electronic device. Background Art
[0002] Deserialization refers to the process of converting serialized data back into an object. Deserialization attacks refer to constructing malicious serialized data and then using the deserialization mechanism to call malicious programs. For example, the front end can send a deserialization request containing serialized data to the back end server, and the server will deserialize the serialized data based on the received serialized data to convert the serialized data into an object. If the attacker embeds malicious code in the serialized data, the server may execute the malicious code during the deserialization process, causing damage to the server.
[0003] Therefore, how to accurately detect deserialization attacks is an urgent problem to be solved. Summary of the invention
[0004] The purpose of the embodiments of the present application is to provide a deserialization attack detection method, device and electronic device to accurately detect deserialization attacks. The specific technical solution is as follows:
[0005] The present application embodiment first provides a deserialization attack detection method, the method comprising:
[0006] Determine the business interface that receives the pending deserialization request as the pending interface;
[0007] Based on the serialized data carried by the pending deserialization request, extract the information of the specified dimension indicated by the pending deserialization request as the information to be detected; wherein the specified dimension includes at least one of the following: the class to which the object represented by the deserialization request belongs, the attribute of the represented object, the calling order of the calling function required for the deserialization operation indicated by the deserialization request, and the user role that initiates the deserialization request;
[0008] Based on the normal information to be used corresponding to the interface to be processed recorded in the preset behavior pattern library, the information to be detected is detected to obtain a final detection result characterizing whether the deserialization request to be processed is abnormal; wherein, the normal information corresponding to an interface is: the information of the specified dimension obtained based on the serialized data carried by the normal deserialization request received by the interface.
[0009] Optionally, the normal information to be utilized corresponding to the interface to be processed recorded in a preset behavior pattern library is used to detect the information to be detected, and a final detection result characterizing whether the deserialization request to be processed is abnormal is obtained, including:
[0010] Obtaining a first sub-detection result and / or a second sub-detection result; wherein the first sub-detection result is obtained by matching the information to be detected with the normal information to be used; the second sub-detection result is obtained by detecting the information to be detected based on a pre-trained detection model; the detection model is obtained by training based on the information recorded in the behavior pattern library;
[0011] Based on the obtained sub-detection results, a final detection result characterizing whether the to-be-processed deserialization request is abnormal is determined.
[0012] Optionally, the behavior pattern library also records the to-be-utilized exception information corresponding to the to-be-processed interface; the exception information corresponding to an interface is: information on the dimension of the exception obtained based on the serialized data carried by the abnormal deserialization request received by the interface;
[0013] Before obtaining the first sub-detection result and / or the second sub-detection result, the method further includes:
[0014] If the information to be detected matches the abnormal information to be utilized, determining that the final detection result indicates that the deserialization request to be processed is abnormal;
[0015] The obtaining of the first sub-detection result and / or the second sub-detection result includes:
[0016] In the case that the information to be detected does not match the abnormal information to be used, a first sub-detection result and / or a second sub-detection result are obtained.
[0017] Optionally, the method for determining the first sub-detection result includes the following steps:
[0018] If at least one of the following conditions is not met, it is determined that the first sub-detection result indicates that the pending deserialization request is abnormal:
[0019] The information to be detected matches the authority of the user role that initiates the deserialization request to be processed;
[0020] The class to which the object in the information to be detected belongs is consistent with the class in the normal information to be used;
[0021] If all the above conditions are met, a first matching result between the attribute of the object in the information to be detected and the attribute in the normal information to be used, and / or a second matching result between the calling sequence of the function in the information to be detected and the calling sequence of the function in the normal information to be used is obtained;
[0022] Determine the first sub-detection result based on the obtained matching result.
[0023] Optionally, the first matching result includes: the first similarity and / or the second similarity; where:
[0024] The method for determining the first similarity includes:
[0025] Obtain the historical attributes of the object in the to-be-detected information from the historical deserialization requests received from the to-be-processed interface;
[0026] Combine the obtained historical attributes with the attributes of the object in the to-be-detected information to obtain a to-be-matched attribute sequence;
[0027] Calculate the similarity between the to-be-matched attribute sequence and the attribute sequence in the to-be-utilized normal information to obtain the first similarity;
[0028] The method for determining the second similarity includes:
[0029] Calculate the similarity between the attributes of the object represented by the to-be-processed deserialization request and the attributes in the to-be-utilized normal information to obtain the second similarity;
[0030] And / or,
[0031] The method for determining the second matching result includes:
[0032] Calculate the similarity between the function sequence representing the call order of the functions in the to-be-detected information and the function sequence representing the call order of the functions in the to-be-utilized normal information to obtain the second matching result.
[0033] Optionally, the determining the first sub-detection result based on the obtained matching result includes:
[0034] Perform weighted addition on the obtained similarities to obtain the total similarity;
[0035] In the case where the total similarity is less than the preset similarity threshold, determine that the first sub-detection result indicates that the to-be-processed deserialization request is abnormal.
[0036] Optionally, the method for determining the second sub-detection result includes the following steps:
[0037] Perform vectorization processing on each dimension of the data in the to-be-detected information to obtain the to-be-utilized vectors for each dimension in the to-be-detected information;
[0038] Fuse the obtained to-be-utilized vectors to obtain a fused feature;
[0039] Use the detection model to detect the fusion feature, and obtain a second sub-detection result indicating whether the to-be-processed deserialization request is abnormal.
[0040] Optionally, the method further includes, when a preset model update condition is satisfied, using the deserialization requests received during the historical detection process and the true results indicating whether these deserialization requests are abnormal to incrementally train the detection model, and obtaining an updated detection model.
[0041] Optionally, extracting the information of the specified dimension indicated by the to-be-processed deserialization request from the serialized data carried by the to-be-processed deserialization request as the information to be detected includes:
[0042] By calling the rewritten deserialization function, extract the information of the specified dimension indicated by the to-be-processed deserialization request from the serialized data carried by the to-be-processed deserialization request as the information to be detected; wherein, the rewritten deserialization function is obtained by inserting code for reading the information carried by the deserialization request into the initial deserialization function in advance.
[0043] The embodiment of the present application also provides an anti-deserialization attack detection device, and the device includes:
[0044] An interface determination module, configured to determine the service interface for receiving the to-be-processed deserialization request as the to-be-processed interface;
[0045] An information extraction module, configured to extract the information of the specified dimension indicated by the to-be-processed deserialization request from the serialized data carried by the to-be-processed deserialization request as the information to be detected; wherein, the specified dimension includes at least one of the following: the class to which the object represented by the deserialization request belongs, the attributes of the represented object, the call order of the functions required for the deserialization operation indicated by the deserialization request, and the user role initiating the deserialization request;
[0046] An information detection module, configured to detect the information to be detected based on the to-be-exploited normal information corresponding to the to-be-processed interface recorded in the preset behavior pattern library, and obtain a final detection result indicating whether the to-be-processed deserialization request is abnormal; wherein, the normal information corresponding to an interface is the information of the specified dimension obtained from the serialized data carried by the normal deserialization request received through this interface.
[0047] Optionally, the information detection module includes:
[0048] The detection result acquisition submodule is used to obtain the first sub-detection result and / or the second sub-detection result; wherein the first sub-detection result is obtained by matching the information to be detected with the normal information to be used; the second sub-detection result is obtained by detecting the information to be detected based on a pre-trained detection model; the detection model is obtained by training based on the information recorded in the behavior pattern library;
[0049] The detection result determination submodule is used to determine a final detection result representing whether the to-be-processed deserialization request is abnormal based on the acquired sub-detection results.
[0050] Optionally, the behavior pattern library also records the to-be-utilized exception information corresponding to the to-be-processed interface; the exception information corresponding to an interface is: information on the dimension of the exception obtained based on the serialized data carried by the abnormal deserialization request received by the interface;
[0051] The device further includes: an abnormal information matching module, configured to determine that the final detection result indicates that the deserialization request to be processed is abnormal if the information to be detected matches the abnormal information to be used before the detection result acquisition submodule acquires the first sub-detection result and / or the second sub-detection result;
[0052] The detection result acquisition submodule is specifically used for:
[0053] In the case that the information to be detected does not match the abnormal information to be used, a first sub-detection result and / or a second sub-detection result are obtained.
[0054] Optionally, the detection result acquisition submodule is specifically used to: if at least one of the following conditions is not met, determine that the first sub-detection result indicates that the deserialization request to be processed is abnormal: the information to be detected matches the permissions of the user role that initiates the deserialization request to be processed; the class to which the object in the information to be detected belongs is consistent with the class in the normal information to be used; if all of the above conditions are met, obtain the attributes of the object in the information to be detected, and a first matching result with the attributes in the normal information to be used, and / or, the calling order of the function in the information to be detected, and a second matching result with the calling order of the function in the normal information to be used; determine the first sub-detection result based on the obtained matching results.
[0055] Optionally, the first matching result includes: a first similarity and / or a second similarity; the detection result acquisition sub-module is specifically configured to: obtain the historical attributes of the object in the to-be-detected information from the historical deserialization requests received by the to-be-processed interface; combine the obtained historical attributes with the attributes of the object in the to-be-detected information to obtain a to-be-matched attribute sequence; calculate the similarity between the to-be-matched attribute sequence and the attribute sequence in the to-be-utilized normal information to obtain a first similarity; calculate the similarity between the attributes of the object represented by the to-be-processed deserialization request and the attributes in the to-be-utilized normal information to obtain a second similarity;
[0056] and / or,
[0057] The detection result acquisition sub-module is specifically configured to: calculate the similarity between the function sequence representing the call order of the functions in the to-be-detected information and the function sequence representing the call order of the functions in the to-be-utilized normal information to obtain a second matching result.
[0058] Optionally, the detection result acquisition sub-module is specifically configured to:
[0059] Perform weighted addition on the obtained similarities to obtain a total similarity; in the case where the total similarity is less than a preset similarity threshold, determine that the first sub-detection result indicates that the to-be-processed deserialization request is abnormal.
[0060] Optionally, the detection result acquisition sub-module includes:
[0061] A data vectorization unit, configured to perform vectorization processing on each dimension of data in the to-be-detected information to obtain a to-be-utilized vector for each dimension in the to-be-detected information;
[0062] A fusion unit, configured to fuse the obtained to-be-utilized vectors to obtain a fusion feature;
[0063] A detection unit, configured to use the detection model to detect the fusion feature to obtain a second sub-detection result indicating whether the to-be-processed deserialization request is abnormal.
[0064] Optionally, the apparatus further includes: a model update module, configured to, when a preset model update condition is satisfied, use the deserialization requests received during the historical detection process and the true results indicating whether the deserialization requests are abnormal to perform incremental training on the detection model to obtain an updated detection model.
[0065] Optionally, the information extraction module is specifically configured to:
[0066] By calling the rewritten deserialization function, based on the serialized data carried by the deserialization request to be processed, the information of the specified dimension indicated by the deserialization request to be processed is extracted as the information to be detected; wherein the rewritten deserialization function is obtained by pre-inserting the code for reading the information carried by the deserialization request into the initial deserialization function.
[0067] The present application also provides an electronic device, including:
[0068] Memory, used to store computer programs;
[0069] The processor is used to implement any of the above-mentioned deserialization attack detection methods when executing the program stored in the memory.
[0070] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, any of the above-mentioned deserialization attack detection methods is implemented.
[0071] An embodiment of the present application also provides a computer program product including instructions, which, when executed on a computer, enables the computer to execute any of the above-mentioned deserialization attack detection methods.
[0072] Beneficial effects of the embodiments of the present application:
[0073] The deserialization attack detection method provided in this embodiment pre-sets a behavior pattern library for the business interface, and the behavior pattern library records the information of the specified dimension indicated by the normal deserialization request, including the class to which the object represented by the deserialization request belongs, the attributes of the represented object, the calling order of the function required for the deserialization operation indicated by the deserialization request, and the user role that initiated the deserialization request; and when the deserialization request is a request for a deserialization attack, the information indicated by the deserialization request will not match the normal deserialization request in at least one of the above dimensions. Therefore, when the pending interface receives the pending deserialization request, this scheme detects the information to be detected indicated by the pending deserialization request based on the normal information to be used corresponding to the pending interface recorded in the preset behavior pattern library to determine whether the pending deserialization request is abnormal. When it is determined that the pending deserialization request is abnormal, it indicates that the pending deserialization request is likely to be a request for a deserialization attack. Therefore, this scheme can accurately detect deserialization attacks.
[0074] Of course, implementing any product or method of the present application does not necessarily require achieving all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other embodiments can also be obtained based on these drawings.
[0076] Figure 1 It is a schematic flowchart of a deserialization attack detection method provided by an embodiment of the present application;
[0077] Figure 2 It is another schematic flowchart of a deserialization attack detection method provided by an embodiment of the present application;
[0078] Figure 3 It is yet another schematic flowchart of a deserialization attack detection method provided by an embodiment of the present application;
[0079] Figure 4 It is a framework diagram of a deserialization attack detection method provided by an embodiment of the present application;
[0080] Figure 5 It is a schematic structural diagram of a deserialization attack detection device provided by an embodiment of the present application;
[0081] Figure 6 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0082] The following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art based on the present application belong to the scope of protection of the present application.
[0083] To accurately detect deserialization attacks, an embodiment of the present application provides a deserialization attack detection method, device, and electronic device. This method can be applied to electronic devices with data processing capabilities, such as computers, servers, etc. In a specific scenario, this method can be applied to the deserialization attack detection program of a backend server. This method may include the following steps:
[0084] Determine the service interface that receives the deserialization request to be processed as the interface to be processed;
[0085] Extract the information of the specified dimension indicated by the deserialization request to be processed from the serialized data carried by the deserialization request to be processed as the information to be detected; where the specified dimension includes at least one of the following: the class to which the object represented by the deserialization request belongs, the attributes of the represented object, the call order of the functions to be called for the deserialization operation indicated by the deserialization request, and the user role that initiates the deserialization request.
[0086] Detect the information to be detected based on the normal information to be exploited corresponding to the interface to be processed recorded in the preset behavior pattern library, and obtain the final detection result indicating whether the deserialization request to be processed is abnormal; where the normal information corresponding to an interface is: the information of the specified dimension obtained from the serialized data carried by the normal deserialization request received by the interface.
[0087] In this embodiment, a behavior pattern library is preset for the service interface in advance. The behavior pattern library records the information of the specified dimension indicated by the normal deserialization request, including the class to which the object represented by the deserialization request belongs, the attributes of the represented object, the call order of the functions to be called for the deserialization operation indicated by the deserialization request, and the user role that initiates the deserialization request; and when the deserialization request is a request for deserialization attack, the information indicated by the deserialization request will not match the normal deserialization request in at least one of the above dimensions. Therefore, in this solution, when the interface to be processed receives the deserialization request to be processed, the information to be detected indicated by the deserialization request to be processed is detected based on the normal information to be exploited corresponding to the interface to be processed recorded in the preset behavior pattern library to determine whether the deserialization request to be processed is abnormal. In the case where it is determined that the deserialization request to be processed is abnormal, it indicates that the deserialization request to be processed is very likely a request for deserialization attack. Therefore, through this solution, deserialization attacks can be accurately detected.
[0088] Next, the deserialization attack detection method provided by the embodiments of the present application will be introduced exemplarily with reference to the accompanying drawings. As Figure 1 shown, the method includes the following steps:
[0089] S101, determine the service interface that receives the deserialization request to be processed as the interface to be processed;
[0090] Among them, the service interface may refer to an interface provided by the service system for the service party to use to process specific business logics. There may be multiple service components in a service system, and the service components can perform deserialization interactions through their respective service interfaces, that is, send deserialization requests to each other. The service system can run on the backend server. And when an interface receives a deserialization request, the method provided by this embodiment can be used to detect the deserialization request.
[0091] S102, based on the serialized data carried by the deserialization request to be processed, extracting information of a specified dimension indicated by the deserialization request to be processed as information to be detected;
[0092] The specified dimension includes at least one of the following: the class to which the object represented by the deserialization request belongs, the attribute of the represented object, the calling order of the function required for the deserialization operation indicated by the deserialization request, and the user role that initiates the deserialization request;
[0093] In this embodiment, the object represented by a deserialization request may refer to an object obtained after executing the deserialization operation indicated by the deserialization request. The attributes of the object may include the name and corresponding value of the attribute of the object, and may also include the state of the object.
[0094] Specifically, by calling the rewritten deserialization function, based on the serialized data carried by the deserialization request to be processed, the information of the specified dimension indicated by the deserialization request to be processed can be extracted as the information to be detected; wherein the rewritten deserialization function is obtained by inserting the code for reading the information indicated by the deserialization request into the initial deserialization function in advance.
[0095] Since the deserialization operation usually needs to be implemented by calling a deserialization function, for example, when the business component is running based on a Java (an object-oriented programming language) application, the deserialization function can be a readObject function (in the field of computer programming, the deserialization function in this embodiment can also be called a deserialization method, and the readObject function is also a readObject method. In order to distinguish it from the deserialization attack detection method in this embodiment, all of the deserialization functions and readObject functions are referred to in this embodiment hereinafter). The application will call the readObject function of the ObjectInputStream class by default to read bytes from the received serialized data stream and convert it into a Java object. When the application of the business component is started or running, the ObjectInputStream class can be extended through Java Agent (a technology that can dynamically modify Java bytecode) to rewrite its readObject function to insert logic code for reading the information indicated by the deserialization request into the readObject function. Therefore, after the business interface of the business component receives the deserialization request, when performing the deserialization operation, the readObject function will be automatically called to obtain the information of the specified dimension indicated by the deserialization request.
[0096] In one implementation, the extracting of information of a specified dimension indicated by the deserialization request to be processed based on the serialized data carried by the deserialization request to be processed includes:
[0097] By calling the rewritten deserialization function, the serialized data carried by the deserialization request to be processed is deserialized, and in the process of executing the deserialization operation, the information of the specified dimension indicated by the deserialization request to be processed is extracted as the information to be detected. In one implementation, the information of the specified dimension extracted by the deserialization function may include detecting the properties of the object represented by the deserialization request, and / or the calling order of the function required for the deserialization operation indicated by the deserialization request. The class to which the object represented by the deserialization request belongs, and / or the user role that initiated the deserialization request, can be parsed from the serialized data carried by the deserialization request to be processed.
[0098] This embodiment rewrites the deserialization function. The rewritten deserialization function not only executes the deserialization process of converting the serialized data stream into an object, but also detects the behavior generated by the execution of the deserialization process in real time during the process. That is, this solution is a dynamic analysis method. One detection method is to analyze the data carried by the deserialization request, or to determine whether the initiator of the deserialization request is in the black and white list, and this method is a static analysis method. In contrast, this solution focuses on detecting whether abnormal behavior changes occur during the deserialization process, rather than just changes in the bytecode, and can capture more complex and hidden forms of attacks, especially attacks that carry legal serialized data but perform abnormal behaviors. Therefore, this solution can effectively reduce the possibility of attackers bypassing the protection mechanism and improve the comprehensiveness of detection.
[0099] In addition, this solution inserts code for reading the information indicated by the deserialization request in the deserialization function to obtain the information of the specified dimension indicated by the deserialization request. Every time a deserialization operation needs to be performed, the deserialization operation can be detected. This is a non-invasive method that does not require modification of business code or major changes to existing business systems. At the same time, it can reduce dependence on existing code and improve compatibility and flexibility.
[0100] S103, based on the normal information to be used corresponding to the interface to be processed recorded in the preset behavior pattern library, the information to be detected is detected to obtain a final detection result characterizing whether the deserialization request to be processed is abnormal; wherein, the normal information corresponding to an interface is: information of a specified dimension obtained based on the serialized data carried by the normal deserialization request received by the interface.
[0101] The to-be-exploited normal information corresponding to the to-be-processed interface recorded in the behavior pattern library can include only one set of information or multiple sets of information; among them, each set of information can include information on each specified dimension obtained from the serialized data carried by a normal deserialization request.
[0102] The behavior pattern library can store a list of interfaces, which contains business interfaces to be detected. In the behavior pattern library, it is also possible to record the normal information indicated by the serialized data carried by the corresponding normal deserialization request for each business interface.
[0103] In one implementation, the above-mentioned to-be-detected information is detected based on the to-be-exploited normal information corresponding to the to-be-processed interface recorded in the preset behavior pattern library, and the final detection result indicating whether the to-be-processed deserialization request is abnormal includes:
[0104] Step A1, obtain a first sub-detection result, and / or, a second sub-detection result; wherein, the first sub-detection result is obtained by matching the to-be-detected information with the to-be-exploited normal information; the second sub-detection result is obtained by detecting the to-be-detected information based on a pre-trained detection model; the detection model is trained based on the information recorded in the behavior pattern library;
[0105] Step A2, determine the final detection result indicating whether the to-be-processed deserialization request is abnormal based on the obtained sub-detection results.
[0106] In one implementation, if both the first sub-detection result and the second sub-detection result are obtained, in order to be able to detect as many abnormal deserialization requests as possible received and improve the recall rate, when one of the first sub-detection result and the second sub-detection result indicates that the to-be-processed deserialization request is abnormal, it can be determined that the final detection result is that the to-be-processed deserialization request is abnormal.
[0107] In one implementation, when matching the to-be-detected information with the to-be-exploited normal information, if the to-be-exploited normal information corresponding to the to-be-processed interface is multiple sets of information, the to-be-detected information can be respectively matched with each set of information among them. When the to-be-detected information matches any one set of information, it can be regarded as the to-be-detected information matching the to-be-exploited normal information. In order to improve the efficiency of matching anomalies, priorities can also be set for each set of information according to importance or credibility to preferentially match the set of information with a higher priority.
[0108] First, the process of determining the first sub-detection result will be introduced below. The determination method of the first sub-detection result includes:
[0109] If at least one of the following conditions is not satisfied, it is determined that the first sub-detection result indicates that the to-be-processed deserialization request is abnormal:
[0110] Condition 1: The information to be detected matches the permissions of the user role that initiated the deserialization request to be processed;
[0111] For example, if the information to be detected indicates an operation that should only be performable by an administrator role (such as deleting information in a database), and the user role that initiated the deserialization request to be processed is not an administrator and does not have the corresponding permissions, then this deserialization request to be processed may be an attack behavior. Therefore, this embodiment can detect whether the information to be detected matches the permissions of the user role that initiated the deserialization request to be processed. If not, it can be determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
[0112] Specifically, in the behavior pattern library, for this interface to be processed, the correct permission level corresponding to the operations that can be performed through this interface can be recorded. In this way, the permission level of the user role that initiated the deserialization request to be processed can be compared with the correct permission level. If the correct permission level corresponding to the operation indicated by the information to be detected exceeds the permission level of the user role that initiated the deserialization request to be processed, it can be determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
[0113] Condition 2: The class to which the object in the information to be detected belongs is the same as the class in the normal information to be exploited;
[0114] For example, under normal circumstances, the normal classes corresponding to a business interface are User or Order, etc. If the class to which the object in the information to be detected belongs is java.lang.Runtime or ProcessBuilder, etc., it indicates that this deserialization request may be a deserialization attack. Therefore, if the class to which the object in the information to be detected belongs is different from the class in the normal information to be exploited, it can be determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
[0115] If all the above conditions are met, the first matching result of the attributes of the object in the information to be detected and the attributes in the normal information to be exploited, and / or the second matching result of the call order of the functions in the information to be detected and the call order of the functions in the normal information to be exploited can be obtained; and the first sub-detection result can be determined based on the obtained matching results.
[0116] Since a deserialization attack may manipulate the numerical values of the attributes of an object to disrupt the running logic of the system or implant malicious code. Therefore, deserialization attacks can be detected based on the attributes of the object.
[0117] The attributes to be utilized in the normal information may include: the type of the attribute, the numerical range of the attribute, the correct assignment of the attribute, the default value of the attribute, etc. In one implementation, when the attribute in the normal information to be utilized includes the correct assignment, it is possible to determine whether the attribute of the object represented by the deserialization request to be processed is the correct assignment. For example, in the object User generated by deserialization, the correct assignment of the role attribute is "user" or "admin". However, if the attribute of the object User represented by the deserialization request to be processed is "root" or other illegal values, the deserialization request to be processed may be an attack behavior. In this case, it can be determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
[0118] When the attribute in the normal information to be utilized includes a numerical range, it is possible to determine whether the attribute of the object in the information to be detected is within that numerical range. For example, if the object in the information to be detected is a shopping cart object Cart and its totalAmount (total quantity) attribute is a negative number or an unreasonably large value (such as 999999999), the deserialization request to be processed may be using deserialization to manipulate field values for a business logic attack. Therefore, a numerical range can be set for the attribute of this object, for example, set to 0 - 99. In this case, if the attribute of the object in the information to be detected is not within that numerical range, it can be determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
[0119] In one implementation, it is also possible to obtain the historical attributes of the object, for example, obtain them from the historical deserialization requests received by the interface to be processed in the past, so as to obtain the change in the attribute of the object in the current information to be detected compared with the historical attribute, and then precisely match this change in the attribute with the change in the attribute in the normal information to be utilized, that is, determine whether this change in the attribute is exactly the same as the change in the attribute in the normal information to be utilized; if it is not exactly the same, it can be determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal. In this embodiment, the so-called change in the attribute may include the change in the assignment of the attribute and also the change in the state of the object.
[0120] For example, the information to be detected includes a shopping cart object Order. Normally, the change in the attribute of this object should be: "awaiting payment", "payment successful". However, if there is only one attribute "order completed" in the sequence of attributes to be matched for this object and there is no "awaiting payment", it may indicate that the attacker is trying to bypass the payment process, that is, the deserialization request to be processed is abnormal.
[0121] For another example, the deserialization request to be processed represents a bank account object Account, and the balance attribute of this object should be incremented or decremented step by step. Therefore, it is possible to determine whether the change amount of the balance attribute in the current deserialization request to be processed compared to the historical balance attribute is greater than a preset change amount threshold. If it is greater, it can be determined that the attribute change does not match the attribute change in the normal information to be utilized, that is, it is determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
[0122] For yet another example, the deserialization request to be processed represents a User object. If the role attribute of this object suddenly changes from "role" to "admin" or "superuser", this may mean that an attacker is attempting to use the deserialization operation for a privilege escalation attack. In this case, the attribute change in the normal information to be utilized can indicate that this attribute is not allowed to change. Thus, when the attribute in the current deserialization request to be processed changes compared to the historical attribute, it can be determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
[0123] In one implementation, the call order of functions in the information to be detected can be precisely matched with the call order of functions in the normal information to be utilized. That is, it is determined whether the functions to be called and their call order required during the deserialization operation represented by the deserialization request to be processed are exactly the same as the functions and call order in the normal information to be utilized. If they are not exactly the same, it can be determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
[0124] During the process of performing the deserialization operation, certain methods (such as the object's constructor, readObject function, readResolve function, etc.) will be automatically called, and attackers may use the order of these functions to tamper with the execution flow. In addition, attackers may also be able to use classes in the Commons Collections (an open-source project that provides additional collection classes and algorithms for Java's collection framework) library, such as functions in classes like InvokerTransformer, MethodInvoker, ChainedTransformer, etc., to construct a malicious chain (i.e., a sequence composed of the functions to be called in the call order), and trigger dangerous operations by calling the readObject function or the reflection mechanism. Therefore, it is necessary to detect whether the call order of functions during the deserialization process conforms to a predefined standard pattern, that is, the function call order in the correct information.
[0125] For example, during a serialization operation, objects of the Order class should usually be executed in the function call sequence of "reading goods, calculating total price, and checking inventory". If the function call sequence of "reading goods, checking inventory, and calculating total price" appears during the deserialization process, it may mean that the business logic has been tampered with. Therefore, this embodiment can determine whether the call sequence of the functions required to be called during the deserialization operation represented by the pending deserialization request matches the function call sequence in the normal information to be used; if they do not match, it can be determined that the first sub-detection result indicates that the pending deserialization request is abnormal.
[0126] Moreover, through the rewritten deserialization function, the calling order of the functions required for the deserialization operation indicated by the pending deserialization request can be obtained from the relevant stack before the deserialization operation is completed. Therefore, the deserialization attack can be successfully detected before it achieves its attack purpose, and then the execution of the deserialization operation can be terminated, thereby intercepting the deserialization attack.
[0127] If it is determined that the final detection result indicates that the pending deserialization request is abnormal, the deserialization operation indicated by the pending deserialization request can be terminated to avoid losses caused by deserialization attacks. This solution can judge the data carried in the deserialization request before executing the deserialization operation to prevent malicious objects or data with abnormal attributes from being successfully deserialized, thereby preventing malicious code from being executed. At the same time, an abnormal notification can also be issued to the staff.
[0128] In this embodiment, a behavior pattern library is preset for the business interface in advance, and the behavior pattern library records the information of the specified dimension indicated by the normal deserialization request, including the class to which the object represented by the deserialization request belongs, the attributes of the represented object, the calling order of the function required for the deserialization operation indicated by the deserialization request, and the user role that initiates the deserialization request; and when the deserialization request is a request for a deserialization attack, the information indicated by the deserialization request will not match the normal deserialization request in at least one of the above dimensions. Therefore, when the pending interface receives the pending deserialization request, the present scheme detects the information to be detected indicated by the pending deserialization request based on the normal information to be used corresponding to the pending interface recorded in the preset behavior pattern library to determine whether the pending deserialization request is abnormal. When it is determined that the pending deserialization request is abnormal, it indicates that the pending deserialization request is likely to be a request for a deserialization attack. Therefore, the present scheme can accurately detect deserialization attacks. Prevent data leakage and business logic damage caused by deserialization attacks.
[0129] Moreover, in this solution, the information recorded in the behavior pattern library is associated with the service interface, enabling the monitoring of the service interface and timely detection of abnormal deserialization requests received by the service interface. Therefore, this solution is also applicable to scenarios of deserialization interaction between various service modules.
[0130] In an embodiment of the present application, the first matching result and / or the second matching result can also be determined by fuzzy matching. The first matching result includes: the first similarity and / or the second similarity; where:
[0131] The determination method of the first similarity includes:
[0132] Step B1, obtain the historical attributes of the object in the to-be-detected information from the historical deserialization requests received by the to-be-processed interface;
[0133] For an object, multiple deserialization requests may be received, causing changes in the attributes of the object, such as changing from uninitialized to initialized.
[0134] Step B2, combine the obtained historical attributes with the attributes of the object in the to-be-detected information to obtain a to-be-matched attribute sequence;
[0135] Specifically, the historical attributes obtained historically can be combined with the attributes of the object in the to-be-detected information and encoded into a sequence to obtain a to-be-matched attribute sequence. For example, the historical attributes and the current attributes can be vectorized first, and then the obtained vectors can be concatenated in order to obtain a to-be-matched attribute sequence.
[0136] Step B3, calculate the similarity between the to-be-matched attribute sequence and the attribute sequence in the to-be-utilized normal information to obtain the first similarity.
[0137] The correct attribute sequence can also be recorded in the behavior pattern library. In this way, the similarity between the to-be-matched attribute sequence and the attribute sequence in the to-be-utilized normal information can be calculated to obtain the first matching result. Specifically, the similarity of the attribute sequence can be obtained by calculating the cosine distance or the Euclidean distance.
[0138] The determination method of the second similarity includes:
[0139] Calculate the similarity between the object in the to-be-detected information and the attributes in the to-be-utilized normal information to obtain the second similarity.
[0140] For example, if the attribute of the object in the to-be-detected information is a numerical value, the difference between the attribute of the object in the to-be-detected information and the attributes in the to-be-utilized normal information can be calculated to obtain the first matching result.
[0141] In the case where the attributes of the object represented by the deserialization request to be processed include multiple numerical values, the Manhattan distance between the attributes of the object represented by the deserialization request to be processed and the attributes in the normal information to be utilized can also be calculated to obtain a first matching result.
[0142] The method for determining the second matching result includes:
[0143] Calculate the similarity between the function sequence representing the call order of functions in the information to be detected and the function sequence representing the call order of functions in the normal information to be utilized to obtain a second matching result.
[0144] Similarly, the similarity of the function sequences can also be calculated to obtain a second matching result.
[0145] In this case, the above-mentioned determination of the first sub-detection result based on the determined similarity includes:
[0146] Step C1: Weightedly sum up the obtained similarities to obtain a total similarity;
[0147] The weights of the similarities in each dimension can be set according to experience and requirements. For example, they can be set according to the permission level of the user role initiating the deserialization request to be processed. That is to say, corresponding weights can be set for different permission levels according to the actual situation, so that after receiving the deserialization request to be processed, the weights corresponding to each dimension can be determined according to the permission level of the user role initiating the deserialization request to be processed.
[0148] Step C2: In the case where the total similarity is less than the preset similarity threshold, determine that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
[0149] In the case where the total similarity is not less than the preset similarity threshold, it can be determined that the first sub-detection result indicates that the deserialization request to be processed is normal.
[0150] This preset similarity threshold can also be set and adjusted in real time according to experience and requirements. For example, it can be set to 0.7, and it can also be set according to the permission level of the user role initiating the deserialization request to be processed. Or, it can also analyze the results based on statistical methods such as cluster analysis according to the detection results of the detection model, so as to adjust this preset similarity threshold in real time to ensure the accuracy and recall rate of detecting abnormal deserialization requests.
[0151] Moreover, the information in the behavior pattern library can be continuously updated and optimized to continuously adapt to new attacks and improve the overall defense ability.
[0152] In this embodiment, considering that the information to be detected of a normal deserialization request may deviate from the data recorded in the behavior pattern library within a certain range, this solution also provides a method for calculating similarity to determine the detection result to adapt to the changes in normal deserialization requests, thereby further improving the accuracy of detecting deserialization attacks.
[0153] In one embodiment of the present application, the behavior pattern library also records the exception information to be used corresponding to the interface to be processed; the exception information corresponding to an interface is: information on the dimension of the exception obtained based on the serialized data carried by the abnormal deserialization request received by the interface. Figure 2 As shown, the deserialization attack detection method may also include the following steps:
[0154] S201, determining a business interface that receives a deserialization request to be processed as the interface to be processed;
[0155] S202, based on the serialized data carried by the deserialization request to be processed, extracting information of a specified dimension indicated by the deserialization request to be processed as information to be detected;
[0156] The specified dimension includes at least one of the following: the class to which the object represented by the deserialization request belongs, the attribute of the represented object, the calling order of the function required for the deserialization operation indicated by the deserialization request, and the user role that initiates the deserialization request;
[0157] S203, if the information to be detected matches the abnormal information to be utilized, determining that the deserialization request to be processed is an abnormal request;
[0158] The behavior pattern library can also record the information indicated by the serialized data carried by abnormal deserialization requests, and the information indicated by the serialized data carried by deserialization requests known to be deserialization attacks. Abnormal deserialization requests are requests that may be risky. Both types of deserialization requests can be regarded as abnormal deserialization requests, and the information indicated by the serialized data carried by both types of deserialization requests can be regarded as abnormal information. The behavior pattern library can perform structured storage of normal information and abnormal information, and each piece of information can be stored in a preset standard format to improve the efficiency of subsequent information matching.
[0159] The abnormal information corresponding to an interface may include: abnormal class, abnormal attribute, abnormal function call sequence, abnormal user role, etc. In this embodiment, the information to be detected can be matched with the abnormal information to be used. If there is information of a certain dimension in the information to be detected that matches the information of the dimension in the abnormal information to be used, it can be directly determined that the final detection result indicates that the deserialization request to be processed is abnormal without matching it with normal information.
[0160] For example, if a certain user role has been previously determined to be an abnormal user role, the user role can be recorded in the behavior pattern library. In this way, when receiving a deserialization request to be processed initiated by the user role, it can be directly determined that the final detection result indicates that the deserialization request to be processed is abnormal. Another example is that the normal classes corresponding to a business interface are User or Order, etc., and the abnormal classes have been previously determined to be java.lang.Runtime and ProcessBuilder. These abnormal classes can be recorded in the behavior pattern library corresponding to the business interface. Thus, when the class to which the object represented by the deserialization request belongs is java.lang.Runtime or ProcessBuilder, it can be directly determined that the final detection result indicates that the deserialization request to be processed is abnormal.
[0161] Similarly, information such as abnormal attributes and abnormal function call sequences can also be recorded in the behavior pattern library.
[0162] When matching abnormal information, it can be matched in sequence according to the abnormal user role, abnormal class, abnormal attributes, and abnormal function call sequence. The current matching sequence is not limited to this. For example, it can be matched in the above-mentioned exact matching manner or in the above-mentioned fuzzy matching manner. Moreover, each item in the abnormal information can also be set with a priority according to importance or credibility to preferentially match the item with a higher priority, thereby improving the matching efficiency.
[0163] S204, in the case where the information to be detected does not match the abnormal information to be utilized, obtain the first sub-detection result, and / or, the second sub-detection result;
[0164] S205, based on the obtained sub-detection results, determine the final detection result indicating whether the deserialization request to be processed is abnormal.
[0165] This step is similar to the previous text and will not be elaborated here.
[0166] In this embodiment, by first matching the information to be detected with the abnormal information to be utilized, it is determined that the final detection result indicates that the deserialization request to be processed is abnormal. At this time, there is no need to match with the normal information to be utilized, which can improve the detection efficiency of the deserialization request in this solution. Moreover, the information recorded in the behavior pattern library in this embodiment is relatively rich, and the deserialization request can be detected from multiple perspectives to improve the accuracy of detecting deserialization attacks.
[0167] In an embodiment of the present application, as Figure 3 shown, the determination method of the above-mentioned second sub-detection result includes the following steps:
[0168] S301, Vectorize the data of each dimension in the information to be detected to obtain the vectors to be utilized for each dimension in the information to be detected, and vectorize the user information of the user role that initiates the deserialization request to be processed to obtain the vector to be utilized in the user dimension;
[0169] Specifically, one-hot encoding can be used to convert the class to which the object belongs, the type of the attribute, and the user information into vectors to be utilized; sequence encoding can be used to convert the call order of the function and the attribute sequence into vectors to be utilized; and the numerical values of the attributes can be directly combined to obtain the vectors to be utilized.
[0170] S302, Fuse the obtained vectors to be utilized to obtain a fused feature;
[0171] In one implementation, the obtained vectors to be utilized can be concatenated to obtain a fused feature. In another implementation, the detection model can include a fusion network, so that the vectors to be utilized can be input into the fusion network to obtain a fused feature.
[0172] S303, Use the detection model to detect the fused feature to obtain a second sub-detection result indicating whether the deserialization request to be processed is abnormal.
[0173] This step is similar to the foregoing embodiments and will not be elaborated herein.
[0174] In one implementation, the detection model can be a machine learning model, such as a random forest algorithm model, which has good classification performance and anti-overfitting ability.
[0175] When training the detection model, a random forest model can be constructed using the machine learning library (scikit-learn) of python (a computer programming language), and the following parameters can be set: the number of trees (n_estimators) is set to 100, the maximum depth (max_depth) is set to None, the minimum number of samples for splitting (min_samples_split) is set to 2, the minimum number of samples in the leaf node (min_samples_leaf) is set to 1, and the maximum number of features (max_features) is set to auto (automatically). And the sample information is divided into a training set and a test set (usually in a ratio of 80 / 20 or 70 / 30), where the sample information can include the information of the specified dimension indicated by the deserialization request with the determined true result, including the normal information and abnormal information recorded in the behavior pattern library.
[0176] After that, the following steps can be executed:
[0177] For any sample information in the training set, vectorize the data of each dimension of the sample information to obtain the sample vector of each dimension of the sample information, and vectorize the user information of the user role that initiates the deserialization request corresponding to the sample information to obtain the sample vector of the user dimension; fuse the obtained sample vectors to obtain the fused sample features; use the detection model with the initial structure to detect the fused sample features to obtain the detection result indicating whether the deserialization request corresponding to the sample information is abnormal; calculate the model loss based on the detection result of the deserialization request corresponding to the sample information and the true result indicating whether the deserialization request is abnormal; perform model parameter tuning on the detection model based on the obtained model loss until the model converges to obtain the trained detection model.
[0178] This embodiment introduces a machine learning algorithm, which can automatically analyze and learn normal deserialization behavior patterns to detect unknown attacks. In this way, this solution can not only rely on predefined rules, but also discover abnormal behaviors through a machine learning model, improving the adaptability and scalability of the business system, and being able to detect new or variant attack patterns in a timely manner, especially zero-day attacks. And through machine learning, the business system is equipped with the ability of self-learning and optimization, making the protection more intelligent and dynamic.
[0179] In an embodiment of the present application, the deserialization attack detection method further includes that when a preset model update condition is met, using the deserialization requests received during the historical detection process as incremental sample information and the labels indicating whether the deserialization requests are abnormal to perform incremental training on the detection model to obtain an updated detection model. The labels of these deserialization requests can be manually marked. Incremental Training, also known as Continual Learning or Online Learning, is a machine learning method, which means that when the model receives new data, it can be updated without losing the knowledge learned before. And to improve the training effect, the incremental sample information can include the deserialization requests that are determined to be detected incorrectly by the detection model manually during the historical detection process.
[0180] For example, this embodiment can periodically evaluate the performance of the detection model. Specifically, the detection model can be tested with manually determined abnormal deserialization requests and / or normal deserialization requests to determine the accuracy, recall, F1-score and other indicators of the detection model. Alternatively, each time the performance of the detection model is evaluated, the accuracy of the detection model for detecting the received deserialization requests within a preset time period between the current detection moments can be obtained. When the accuracy does not reach a preset threshold, it can be determined that the performance of the detection model does not meet the requirements, and the detection model is then incrementally trained.
[0181] Exemplarily, the incremental training process may include the following steps:
[0182] For each acquired incremental sample information and a label indicating whether the incremental sample information is normal, the data of each dimension contained in the incremental sample information is vectorized to obtain an incremental sample vector of each dimension of the incremental sample information, and the user information of the user role that initiates the deserialization request corresponding to the incremental sample information is vectorized to obtain an incremental sample vector of the user dimension; the obtained incremental sample vectors are fused to obtain fused incremental sample features; the fused incremental sample features are detected using the current detection model to obtain a detection result indicating whether the deserialization request corresponding to the incremental sample information is abnormal; the model loss is calculated based on the detection result of the deserialization request corresponding to the incremental sample information and the label of the incremental sample information; the detection model is parameterized based on the obtained model loss to obtain an updated detection model.
[0183] When it is determined through evaluation that the performance of the detection model does not meet the requirements, the detection model can be incrementally trained. The deserialization request used in each incremental training can be the deserialization request received during the time period from the last incremental training to the current incremental training, but it is not limited to this.
[0184] Furthermore, the performance of the updated detection model can be evaluated. If the performance of the updated detection model is significantly improved,
[0185] The updated detection model is used for subsequent detection, otherwise, the detection model before the update is continued to be used. The updated model version can also be recorded in the model management module to ensure the traceability and flexibility of the model.
[0186] The self-optimization of the model and the detection of the model in this embodiment form a closed loop, which can continuously receive feedback, evaluate performance and optimize the model to deal with new threats and attacks. By dynamically updating and improving the detection model, it can adapt to the ever-changing environment and emerging threats, and improve the accuracy of detecting deserialization attacks.
[0187] In this embodiment, by performing vectorization processing on the data of each dimension in the information to be detected, the vectors to be utilized in each dimension of the information to be detected are obtained. Then, the obtained vectors to be utilized are fused to obtain a fused feature. Finally, the detection model is used to detect the fused feature, and a second sub-detection result indicating whether the deserialization request to be processed is abnormal is obtained, which can realize the detection of the deserialization request to be processed using the model. It can be seen that this solution performs deserialization attack detection by combining a behavior pattern library matching and a machine learning model. The solution is more flexible, can dynamically detect and prevent malicious deserialization operations, and reduce the false positive rate and false negative rate. Therefore, through this solution, the accuracy and efficiency of detecting deserialization attacks can be further improved.
[0188] For ease of understanding, the following takes the application of this deserialization attack detection method to the deserialization attack detection program of the backend server as an example, and combines Figure 4 to introduce the embodiments of this application:
[0189] As Figure 4 shown, the deserialization attack detection program may include: a behavior pattern standard process module, an information extraction module, a behavior pattern matching module, a machine learning detection module, an online machine learning self-optimization module, a model management module, and a data storage module.
[0190] The behavior pattern standard process module may include the above-mentioned behavior pattern library. The behavior pattern standard process module may also provide a user interface and related APIs (Application Programming Interfaces) so that staff can easily add, modify, or delete information in the behavior pattern library. A verification mechanism may also be set in the behavior pattern standard process module to ensure the rationality and effectiveness of the information when adding or modifying information in the behavior pattern library. This verification mechanism can be set by developers according to actual situations.
[0191] The information extraction module is used to rewrite the deserialization function when the application of the business component in the back-end server is started or running, and insert the code for reading the information carried by the deserialization request into the deserialization function. When receiving the pending deserialization request, that is, receiving the serialized data carried by the pending deserialization request, the information of the specified dimension indicated by the pending deserialization request is obtained through the rewritten deserialization function as the information to be detected, including: the class to which the object represented by the pending deserialization request belongs, the attributes of the represented object, the calling order of the function required for the deserialization operation indicated by the deserialization request, the user role that initiated the deserialization request, etc.; then send the recorded behavior to the behavior pattern matching module and the machine learning detection module to support subsequent detection and learning; in addition, the information extraction module can also record any abnormal situation during the deserialization operation, record related error information, and persistently store the obtained information to generate logs for subsequent analysis and auditing to ensure the integrity and traceability of the data.
[0192] The behavior pattern matching module is used to receive data from the information extraction module and confirm the integrity and accuracy of the data; then, the information to be detected is matched with the normal information to be used and the normal information to be used to determine whether the deserialization request to be processed is abnormal. If the information to be detected fails to match the normal information, the deserialization request to be processed is determined to be abnormal. A response mechanism can also be set in the behavior pattern matching module to terminate the current deserialization operation when an abnormality is detected in the deserialization request to be processed, and record a detailed audit log including the received behavior data, matching results, and detection results, etc. At the same time, a notification is sent to the security team, and the acquired information to be detected and the detection results are fed back to the online machine learning self-optimization module.
[0193] The machine learning detection module is used to receive the information to be detected, and to extract and preprocess the features of the information to be detected to obtain the features to be detected, such as vectorizing the data of each dimension in the information to be detected to obtain the vector to be used in each dimension of the information to be detected; fusing the obtained vectors to be used to obtain the fused features, and then inputting the features to be detected into the pre-trained detection model to obtain the detection results of the model; finally, according to the detection results of the model, taking corresponding measures, such as recording logs, sending notifications to the security team, terminating the current deserialization operation, etc. when detecting anomalies, and feeding back the obtained information to be detected and the detection results of the model to the online machine learning self-optimization module, which can also be fed back to the detection model. In addition, the machine learning detection module can also divide the data set used to train the detection model into a training set and a test set according to a preset ratio.
[0194] When the machine learning detection module detects that the deserialization request to be processed is normal and the behavior pattern matching module successfully matches the information to be detected with the normal information, it can be determined to continue the deserialization operation.
[0195] An online machine learning self-optimization module is used to collect information fed back from the behavior pattern matching module and the machine learning detection module, regularly analyze the collected information to evaluate the performance of the current detection model; and when it is determined that incremental training is required, fine-tune the parameters of the detection model to obtain an updated model; in addition, the updated detection model can also be evaluated.
[0196] The online machine learning self-optimization module and the machine learning detection module can form a closed loop, continuously receive feedback, evaluate performance and optimize the detection model to cope with new threats and attacks.
[0197] The model management module is used to manage the detection model. The data storage module is used to store the data required by the program, such as the information in the behavior pattern library, logs, etc.
[0198] In this embodiment, through the deserialization attack detection program, the deserialization attack detection method provided by the embodiments of the present application can be automatically executed to achieve the detection of deserialization attacks.
[0199] Based on the same inventive concept, the embodiments of the present application also provide a deserialization attack detection device, as Figure 5 shown, the device includes:
[0200] The interface determination module 501 is used to determine the service interface for receiving the deserialization request to be processed as the to-be-processed interface;
[0201] The information extraction module 502 is used to extract the information of the specified dimension indicated by the deserialization request to be processed based on the serialized data carried by the deserialization request to be processed as the information to be detected; wherein, the specified dimension includes at least one of the following: the class to which the object represented by the deserialization request belongs, the attributes of the represented object, the call order of the functions required for the deserialization operation indicated by the deserialization request, and the user role initiating the deserialization request;
[0202] The information detection module 503 is used to detect the information to be detected based on the to-be-exploited normal information corresponding to the to-be-processed interface recorded in the preset behavior pattern library to obtain the final detection result indicating whether the deserialization request to be processed is abnormal; wherein, the normal information corresponding to an interface is: the information of the specified dimension obtained based on the serialized data carried by the normal deserialization request received through this interface.
[0203] Optionally, the information detection module 503 includes:
[0204] The detection result acquisition submodule is used to obtain the first sub-detection result and / or the second sub-detection result; wherein the first sub-detection result is obtained by matching the information to be detected with the normal information to be used; the second sub-detection result is obtained by detecting the information to be detected based on a pre-trained detection model; the detection model is obtained by training based on the information recorded in the behavior pattern library;
[0205] The detection result determination submodule is used to determine a final detection result representing whether the to-be-processed deserialization request is abnormal based on the acquired sub-detection results.
[0206] Optionally, the behavior pattern library also records the to-be-utilized exception information corresponding to the to-be-processed interface; the exception information corresponding to an interface is: information on the dimension of the exception obtained based on the serialized data carried by the abnormal deserialization request received by the interface;
[0207] The device further includes: an abnormal information matching module, configured to determine that the final detection result indicates that the deserialization request to be processed is abnormal if the information to be detected matches the abnormal information to be used before the detection result acquisition submodule acquires the first sub-detection result and / or the second sub-detection result;
[0208] The detection result acquisition submodule is specifically used for:
[0209] In the case that the information to be detected does not match the abnormal information to be used, a first sub-detection result and / or a second sub-detection result are obtained.
[0210] Optionally, the detection result acquisition submodule is specifically used to: if at least one of the following conditions is not met, determine that the first sub-detection result indicates that the deserialization request to be processed is abnormal: the information to be detected matches the permissions of the user role that initiates the deserialization request to be processed; the class to which the object in the information to be detected belongs is consistent with the class in the normal information to be used; if all of the above conditions are met, obtain the attributes of the object in the information to be detected, and a first matching result with the attributes in the normal information to be used, and / or, the calling order of the function in the information to be detected, and a second matching result with the calling order of the function in the normal information to be used; determine the first sub-detection result based on the obtained matching results.
[0211] Optionally, the first matching result includes: a first similarity and / or a second similarity; the detection result acquisition sub-module is specifically configured to: obtain the historical attributes of the object in the to-be-detected information from the historical deserialization requests received by the to-be-processed interface; combine the obtained historical attributes with the attributes of the object in the to-be-detected information to obtain a to-be-matched attribute sequence; calculate the similarity between the to-be-matched attribute sequence and the attribute sequence in the to-be-utilized normal information to obtain a first similarity; calculate the similarity between the attributes of the object represented by the to-be-processed deserialization request and the attributes in the to-be-utilized normal information to obtain a second similarity.
[0212] Optionally, the detection result acquisition sub-module is specifically configured to: calculate the similarity between the function sequence representing the call order of the functions in the to-be-detected information and the function sequence representing the call order of the functions in the to-be-utilized normal information to obtain a second matching result.
[0213] Optionally, the detection result acquisition sub-module is specifically configured to:
[0214] Perform weighted addition on the obtained similarities to obtain a total similarity; in the case where the total similarity is less than a preset similarity threshold, determine that the first sub-detection result indicates that the to-be-processed deserialization request is abnormal.
[0215] Optionally, the detection result acquisition sub-module includes:
[0216] A data vectorization unit, configured to perform vectorization processing on each dimension of data in the to-be-detected information to obtain a to-be-utilized vector for each dimension in the to-be-detected information;
[0217] A fusion unit, configured to fuse the obtained to-be-utilized vectors to obtain a fusion feature;
[0218] A detection unit, configured to use the detection model to detect the fusion feature to obtain a second sub-detection result indicating whether the to-be-processed deserialization request is abnormal.
[0219] Optionally, the apparatus further includes: a model update module, configured to, when a preset model update condition is satisfied, perform incremental training on the detection model by using the deserialization requests received during the historical detection process and the true results indicating whether the deserialization requests are abnormal to obtain an updated detection model.
[0220] Optionally, the information extraction module 502 is specifically configured to:
[0221] By invoking the rewritten deserialization function, based on the serialized data carried in the deserialization request to be processed, extract the information of the specified dimension indicated by the deserialization request to be processed as the information to be detected; wherein, the rewritten deserialization function is obtained by pre-inserting code for reading the information carried in the deserialization request into the initial deserialization function.
[0222] An embodiment of this application also provides an electronic device, as Figure 6 shown, including:
[0223] A memory 601 for storing a computer program;
[0224] A processor 602, when executing the program stored on the memory 601, implements the steps of any of the above deserialization attack detection methods.
[0225] And the above electronic device may further include a communication bus and / or a communication interface, and the processor 602, the communication interface, and the memory 601 complete communication with each other through the communication bus.
[0226] The communication bus mentioned in the above electronic device may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus.
[0227] The communication interface is used for communication between the above electronic device and other devices.
[0228] The memory may include a Random Access Memory (RAM), or may also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.
[0229] The above-mentioned processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0230] In another embodiment provided by the present application, a computer-readable storage medium is further provided. A computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the steps of any of the above deserialization attack detection methods are implemented.
[0231] In another embodiment provided by the present application, a computer program product including instructions is further provided. When it runs on a computer, it causes the computer to execute any of the deserialization attack detection methods in the above embodiments.
[0232] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a Solid State Disk (SSD), etc.
[0233] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0234] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the embodiments of the device, electronic device, and readable storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and reference can be made to the corresponding parts of the method embodiments for the relevant content.
[0235] The above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application are included in the protection scope of the present application.
Claims
1. A deserialization attack detection method, characterized in that: The method comprises: Determine the business interface that receives the pending deserialization request as the pending interface; Based on the serialized data carried by the pending deserialization request, extract the information of the specified dimension indicated by the pending deserialization request as the information to be detected; wherein the specified dimension includes at least one of the following: the class to which the object represented by the deserialization request belongs, the attribute of the represented object, the calling order of the calling function required for the deserialization operation indicated by the deserialization request, and the user role that initiates the deserialization request; Based on the normal information to be used corresponding to the interface to be processed recorded in the preset behavior pattern library, the information to be detected is detected to obtain a final detection result characterizing whether the deserialization request to be processed is abnormal; wherein the normal information corresponding to an interface is: the information of the specified dimension obtained based on the serialized data carried by the normal deserialization request received by the interface; The final detection result is determined based on the first sub-detection result; the first sub-detection result is determined based on the first matching result; The first matching result includes: a first similarity; wherein: The method for determining the first similarity includes: Obtaining historical attributes of the object in the information to be detected from the historical deserialization request received by the interface to be processed; Combining the acquired historical attributes with the attributes of the object in the information to be detected to obtain a sequence of attributes to be matched; The similarity between the attribute sequence to be matched and the attribute sequence in the normal information to be used is calculated to obtain a first similarity.
2. The method according to claim 1, characterized in that The normal information to be utilized corresponding to the interface to be processed recorded in the preset behavior pattern library is used to detect the information to be detected, and a final detection result characterizing whether the deserialization request to be processed is abnormal is obtained, including: Obtaining a first sub-detection result and a second sub-detection result; wherein the second sub-detection result is obtained by detecting the information to be detected based on a pre-trained detection model; and the detection model is obtained by training based on the information recorded in the behavior pattern library; Based on the obtained sub-detection results, a final detection result characterizing whether the to-be-processed deserialization request is abnormal is determined.
3. The method according to claim 2, characterized in that The behavior pattern library also records the to-be-used exception information corresponding to the to-be-processed interface; the exception information corresponding to an interface is: information on the dimension of the exception obtained based on the serialized data carried by the abnormal deserialization request received by the interface; Before obtaining the first sub-detection result and the second sub-detection result, the method further includes: If the information to be detected matches the abnormal information to be utilized, determining that the final detection result indicates that the deserialization request to be processed is abnormal; The obtaining of the first sub-detection result and the second sub-detection result includes: In a case where the information to be detected does not match the abnormal information to be used, a first sub-detection result and a second sub-detection result are obtained.
4. The method according to claim 2 or 3, characterized in that: The method for determining the first sub-detection result comprises the following steps: If at least one of the following conditions is not met, it is determined that the first sub-detection result indicates that the pending deserialization request is abnormal: The information to be detected matches the authority of the user role that initiates the deserialization request to be processed; The class to which the object in the information to be detected belongs is consistent with the class in the normal information to be used; If all the above conditions are met, a first matching result between the attribute of the object in the information to be detected and the attribute in the normal information to be used, and a second matching result between the calling sequence of the function in the information to be detected and the calling sequence of the function in the normal information to be used are obtained; A first sub-detection result is determined based on the acquired matching result.
5. The method according to claim 4, characterized in that The first matching result also includes: a second similarity; wherein: The second similarity is determined in the following manner: Calculating the similarity between the attribute of the object in the information to be detected and the attribute in the normal information to be used to obtain a second similarity; and / or, The method for determining the second matching result includes: The similarity between the function sequence representing the calling order of the functions in the information to be detected and the function sequence representing the calling order of the functions in the normal information to be utilized is calculated to obtain a second matching result.
6. The method according to claim 5, characterized in that The determining the first sub-detection result based on the acquired matching result includes: The obtained similarities are weighted added to obtain the total similarity; When the total similarity is less than a preset similarity threshold, it is determined that the first sub-detection result indicates that the deserialization request to be processed is abnormal.
7. The method according to claim 2, characterized in that The method for determining the second sub-detection result comprises the following steps: Performing vectorization processing on the data of each dimension in the information to be detected to obtain a vector to be used of each dimension in the information to be detected; The obtained vectors to be used are fused to obtain fusion features; The fusion feature is detected using the detection model to obtain a second sub-detection result indicating whether the deserialization request to be processed is abnormal.
8. The method according to claim 7, characterized in that The method also includes: when a preset model update condition is met, using the deserialization request received during the historical detection process and the real result indicating whether the deserialization request is abnormal, incrementally training the detection model to obtain an updated detection model.
9. The method according to claim 1, characterized in that: The extracting, based on the serialized data carried by the deserialization request to be processed, information of a specified dimension indicated by the deserialization request to be processed as information to be detected includes: By calling the rewritten deserialization function, based on the serialized data carried by the deserialization request to be processed, the information of the specified dimension indicated by the deserialization request to be processed is extracted as the information to be detected; wherein the rewritten deserialization function is obtained by pre-inserting the code for reading the information carried by the deserialization request into the initial deserialization function.
10. A deserialization attack detection device, characterized in that: The device comprises: An interface determination module, used to determine a business interface for receiving a deserialization request to be processed as an interface to be processed; An information extraction module is used to extract information of a specified dimension indicated by a pending deserialization request based on serialized data carried by the pending deserialization request as information to be detected; wherein the specified dimension includes at least one of the following: a class to which an object represented by the deserialization request belongs, an attribute of the represented object, a calling sequence of functions required for a deserialization operation indicated by the deserialization request, and a user role that initiates the deserialization request; An information detection module is used to detect the information to be detected based on the normal information to be used corresponding to the interface to be processed recorded in a preset behavior pattern library, and obtain a final detection result characterizing whether the deserialization request to be processed is abnormal; wherein the normal information corresponding to an interface is: the information of the specified dimension obtained based on the serialized data carried by the normal deserialization request received by the interface; The final detection result is determined based on the first sub-detection result; the first sub-detection result is determined based on the first matching result; The first matching result includes: a first similarity; wherein: The method for determining the first similarity includes: Obtaining historical attributes of the object in the information to be detected from the historical deserialization request received by the interface to be processed; Combining the acquired historical attributes with the attributes of the object in the information to be detected to obtain a sequence of attributes to be matched; The similarity between the attribute sequence to be matched and the attribute sequence in the normal information to be used is calculated to obtain a first similarity.
11. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, for implementing any of the methods described in claims 1-9 when executing a program stored in a memory.
12. A computer program product comprising instructions, characterized in that When the computer program product is run on a computer, the computer is enabled to execute the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
De-serialization attack detection method and device, electronic equipment and medium
CN115080061A