A cross-domain resource sharing vulnerability detection method and system

By constructing a multi-dimensional trial request set and injecting the request set into an isolated sandbox environment, capturing the policy declaration vector and resource loading trajectory, calculating the policy deviation parameter and interface exposure parameter, and generating a cross-domain risk coefficient, the problems of low adaptability and insufficient precision in cross-domain resource sharing vulnerability detection in existing technologies are solved, and efficient vulnerability detection and risk assessment are achieved.

CN119788439BActive Publication Date: 2025-09-19BEIJING DAFANG YUNTU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510286524.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-09-19
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

Existing cross-domain resource sharing vulnerability detection methods have problems of low adaptability and insufficient detection accuracy, making it difficult to effectively respond to rapidly evolving network security threats.

Method used

By constructing a multi-dimensional set of probing requests, performing dynamic parameter inheritance link adjustments, generating a dynamically associated request set, and injecting the request set into an isolated sandbox environment, we simultaneously capture policy declaration vectors and resource loading trajectories. We use a multi-dimensional spatial projection algorithm to calculate policy deviation parameters, combined with a deep interface scanning engine to identify interface exposure parameters. This integration generates a cross-domain risk factor to trigger vulnerability alerts.

Benefits of technology

It achieves accurate detection of potential vulnerabilities in cross-domain resource sharing, improves the accuracy and comprehensiveness of security assessments, and enhances the ability to identify unauthorized access and data leakage risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788439B_ABST
    Figure CN119788439B_ABST
Patent Text Reader

Abstract

The present application provides a vulnerability detection method and system for cross-domain resource sharing. Among them, first, a multi-dimensional trial request set containing a protocol conversion sequence, a sub-domain penetration feature and a null value parameter combination is constructed, and a dynamic association request set is generated through dynamic parameter inheritance link adjustment; then, these requests are injected into an isolated sandbox environment, and the policy declaration vector and resource loading trajectory are captured at the same time; then, a multi-dimensional space projection algorithm is used to map the policy declaration vector to the behavior trajectory space to calculate the policy deviation parameter; based on this parameter, the deep interface scanning engine is activated to identify the callback function dependency chain of the unverified source and generate the interface exposure parameter; finally, the policy deviation parameter and the interface exposure parameter are integrated to generate a cross-domain risk coefficient, and a vulnerability alarm is triggered according to the dynamic weight distribution mechanism. The technical solution provided by the embodiment of the present application improves the accuracy and efficiency of security threat detection in cross-domain resource sharing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of cross-domain resource sharing, and in particular to a vulnerability detection method and system for cross-domain resource sharing. Background Art

[0002] With the increasing complexity and diversity of internet services, Cross-Origin Resource Sharing (CORS) has become an indispensable part of modern network applications. However, this resource sharing method also brings potential security risks, especially during data exchange between different security domains, which may lead to unauthorized access and data leakage.

[0003] Existing cross-origin resource sharing vulnerability detection solutions primarily rely on static code analysis, rule-based security policy checks, and simple penetration testing. These methods typically identify known vulnerabilities using predefined rule sets or pattern matching, and further verify potential security risks through manual review. Additionally, some automated tools can simulate attack behavior to detect weaknesses in the system.

[0004] The main drawbacks of existing solutions lie in their limited adaptability and low detection accuracy. First, due to their reliance on fixed rule sets or pattern matching, existing methods struggle to cope with rapidly evolving cybersecurity threats, particularly those exploiting unknown vulnerabilities or advanced persistent threats (APTs). Second, traditional detection tools and methods mostly focus on identifying known attack patterns, but are unable to detect highly evasive and logically complex attack paths. Finally, some existing solutions often require significant manpower and resources for configuration and maintenance during actual deployment, and are prone to false positives and false negatives, which impacts their effectiveness and reliability in practical applications. Summary of the Invention

[0005] The embodiments of the present application provide a vulnerability detection method and system for cross-domain resource sharing, which are used to solve the problems of insufficient accuracy and low efficiency in security threat detection in cross-domain resource sharing in the prior art.

[0006] In a first aspect, an embodiment of the present application provides a vulnerability detection method for cross-domain resource sharing, including:

[0007] Constructing a multi-dimensional probe request set and performing dynamic parameter inheritance link adjustment to generate a dynamic association request set, wherein the multi-dimensional probe request set includes a protocol conversion sequence, a subdomain penetration feature, and a null value parameter combination;

[0008] Inject a set of dynamically associated requests into an isolated sandbox environment and synchronously capture policy declaration vectors and resource loading trajectories. The policy declaration vectors extract response header policy declaration features through a semantic parsing engine, and the resource loading trajectories use behavioral fingerprinting technology to record the timing of cross-domain resource interactions and generate a trajectory spatial coordinate sequence.

[0009] Executing a deviation map construction between the strategy declaration vector and the trajectory space coordinate sequence, and mapping the strategy declaration vector to the behavior trajectory space using a multidimensional space projection algorithm and calculating a strategy deviation parameter;

[0010] Activating a deep interface scanning engine based on the policy deviation parameter, the deep interface scanning engine constructs a message monitoring topology graph through an adaptive port clustering algorithm, identifies the callback function dependency chain of unverified sources and generates an interface exposure parameter;

[0011] The policy deviation parameter and the interface exposure parameter are integrated to generate a cross-domain risk coefficient. The deep interface scanning engine performs nonlinear superposition on the policy deviation parameter and the exposure parameter through a dynamic weight distribution mechanism. When the superposition result meets the dynamic threshold judgment condition generated based on the protocol conversion sequence weight distribution, a cross-domain resource sharing vulnerability alarm is triggered.

[0012] Optionally, the step of constructing a deviation map of the strategy declaration vector and the trajectory space coordinate sequence, and mapping the strategy declaration vector to the behavior trajectory space using a multidimensional space projection algorithm and calculating a strategy deviation parameter includes:

[0013] A multi-dimensional attention mechanism is used to adjust the dynamic parameter association strength of the protocol conversion sequence, and a cross-protocol path coupling unit is used to interactively calculate the cross-protocol jump path of the protocol conversion sequence and the nested domain name mapping structure of the subdomain penetration feature, outputting a semantic association parameter set carrying the cross-protocol jump feature;

[0014] Based on the spatiotemporal evolution law of the empty parameter request template and the trajectory spatial coordinate sequence fused by the bidirectional temporal network, the topological alignment unit is used to transform the behavioral fingerprint marking pattern of the resource loading trajectory with the multi-level domain name space distribution of the subdomain penetration feature, thereby generating a trajectory mapping parameter set containing the spatiotemporal features of cross-domain interaction;

[0015] Establishing a manifold space constraint relationship between the semantic association parameter set and the trajectory mapping parameter set, generating multidimensional projection constraints based on the dynamic path distribution of the protocol conversion sequence, and calculating the spatiotemporal offset of semantic features and spatiotemporal features using a shared subspace reconstruction algorithm;

[0016] The cross-protocol jump feature and the spatiotemporal offset are integrated to generate a policy deviation parameter, a dynamic coupling unit is used to nonlinearly associate the offset calculation result with the path weight of the protocol conversion sequence, and the calibration rule of the request template with the null value parameter is combined to output the policy deviation parameter carrying the cross-protocol association feature.

[0017] Optionally, the multi-dimensional attention mechanism is used to adjust the dynamic parameter association strength of the protocol conversion sequence, and a cross-protocol path coupling unit is used to interactively calculate the cross-protocol jump path of the protocol conversion sequence and the nested domain name mapping structure of the subdomain penetration feature, and output a semantic association parameter set carrying the cross-protocol jump feature, including:

[0018] A multi-level protocol conversion path analysis network is constructed to capture the topological connection pattern of the cross-protocol jump path, and a heterogeneous convolution kernel group is used to perform multi-granularity path correlation analysis on the protocol conversion sequence. The protocol conversion hierarchical features and the nested domain name space distribution of the subdomain penetration features are coordinate-converted to generate a dynamic path parameter set carrying the cross-protocol jump feature.

[0019] A protocol-aware parameter coupling unit is used to perform cross-protocol association strength adjustment on the dynamic path parameter set, and a protocol-aware parameter set carrying path association characteristics is generated based on a coupling relationship between a topological connectivity parameter and a domain name mapping density parameter of the subdomain penetration characteristic;

[0020] The protocol-aware parameter set and the empty-value parameter request template are integrated in the spatiotemporal dimension using the cross-protocol gating interaction module. The temporal distribution characteristics of the cross-protocol jump path are reconstructed using the path evolution law modeling unit to generate a dynamic coupling parameter set with spatiotemporal correlation characteristics.

[0021] A feature pyramid fusion algorithm is used to perform a manifold space alignment operation on the multi-level domain name mapping relationship between the dynamic coupling parameter set and the subdomain penetration feature, and topological constraint rules are used to eliminate the structural deviation between the protocol jump trajectory and the domain name space distribution to generate a semantic association parameter set carrying cross-protocol semantic association features.

[0022] Optionally, the protocol-aware parameter coupling unit is used to perform cross-protocol association strength adjustment on the dynamic path parameter set, and a protocol-aware parameter set carrying path association characteristics is generated based on a coupling relationship between a topological connectivity parameter and a domain name mapping density parameter of the subdomain penetration characteristic, including:

[0023] Performing multi-level path association analysis on the protocol conversion sequence through a path topology analysis unit, capturing the path connection density distribution pattern and directional evolution law of the cross-protocol jump behavior in the protocol conversion sequence based on a spatial convolution kernel group, and outputting a path topology parameter set;

[0024] Utilizing a domain name density parsing unit to perform a hierarchical spatial compression operation on the nested topological structure, extracting spatial distribution intensity features of the multi-level domain name mapping relationship based on an adaptive pooling strategy, and outputting a domain name density parameter set;

[0025] The path topology parameter set and the domain name density parameter set are input into a timing constraint module using a cross-protocol coupling unit, and a dynamic coupling parameter vector is generated by the gated loop unit based on the timing variation law of the cross-protocol association path and the topological constraint relationship of the subdomain penetration feature;

[0026] A topology constraint projection algorithm is used to perform a spatial dimension alignment operation between the dynamic coupling parameter vector and the request template of the null value parameter, and based on the topology constraint rules, the structural deviation between the protocol jump trajectory and the domain name space distribution is eliminated, and a protocol-aware parameter set carrying cross-protocol semantic association features is output.

[0027] Optionally, the cross-protocol coupling unit is used to input the path topology parameter set and the domain name density parameter set into a timing constraint module, and a gated loop unit is used to generate a dynamic coupling parameter vector based on the timing change law of the cross-protocol association path and the topological constraint relationship of the subdomain penetration feature, including:

[0028] Based on the connection density distribution pattern of the path topology parameter set and the spatial intensity characteristics of the domain name density parameter set, a multi-scale path correlation analysis is performed on the temporal evolution trajectory of the cross-protocol jump path to generate a primary temporal feature vector carrying short-term fluctuations and long-term evolution rules;

[0029] Using the primary time series feature vector, a multi-window weight dynamic allocation process is performed on the cross-protocol association strength to generate a dynamic weight parameter set reflecting the coupling strength of the cross-protocol jump path and the subdomain penetration feature in different time intervals;

[0030] Based on the hierarchical evolution law of the cross-protocol jump path under the constraints of the nested topology structure and the spatial distribution intensity of the domain name mapping density parameter, the dynamic weight parameter set and the domain name density parameter set are interactively calculated and processed to generate an intermediate fusion parameter set carrying spatiotemporal correlation features;

[0031] According to the topological constraint relationship between the intermediate fusion parameter set and the subdomain penetration feature, the timing deviation of the cross-protocol jump path and the difference in the spatial structure dimension of the domain name mapping are eliminated to generate a dynamic coupling feature parameter vector that is adapted to subsequent spatial alignment operations.

[0032] Optionally, the method of using the primary time series feature vector to perform multi-window weight dynamic allocation processing on the cross-protocol association strength to generate a dynamic weight parameter set reflecting the coupling strength of the cross-protocol jump path and the subdomain penetration feature in different time intervals includes:

[0033] A hierarchical time window division mechanism is constructed based on the short-term fluctuation characteristics and long-term evolution laws carried by the primary time series feature vector, and a multi-granularity time slicing operation is performed on the time series evolution trajectory of the cross-protocol jump path to generate a set of window feature vectors carrying different time scale correlation strengths;

[0034] Performing a dynamic analysis of path association strength on the window feature vector set using a cross-protocol attention screening module, and generating an attention weight matrix reflecting the coupling strength between the cross-protocol jump path and the subdomain penetration feature based on the spatial distribution intensity parameter under the nested topological structure constraint;

[0035] A multimodal interaction unit is used to perform hierarchical fusion calculation on the attention weight matrix and the spatial distribution characteristics of the domain name density parameter set, and an intermediate parameter set carrying dynamic coupling weights is generated based on the temporal evolution law of the cross-protocol jump path and the spatial constraint relationship of the domain name mapping density;

[0036] Perform a topological dimension matching operation between the intermediate parameter set and the subdomain penetration feature, eliminate the conflict between the timing slice deviation of the cross-protocol jump path and the structural dimension of the domain name space distribution through the path trajectory reconstruction algorithm, and output a dynamic weight parameter set that is adapted to subsequent interactive calculation processing.

[0037] Optionally, establishing a manifold space constraint relationship between the semantic association parameter set and the trajectory mapping parameter set, generating a multidimensional projection constraint condition according to the dynamic path distribution of the protocol conversion sequence, and calculating the spatiotemporal offset of semantic features and spatiotemporal features using a shared subspace reconstruction algorithm includes:

[0038] Based on the cross-protocol jump characteristics of the semantic association parameter set and the spatiotemporal evolution law of the trajectory mapping parameter set, a manifold space alignment constraint is constructed, and the semantic feature vector and the spatiotemporal feature vector are projected into a shared manifold space using a nonlinear mapping unit to generate a dynamic projection tensor carrying the cross-protocol spatiotemporal association;

[0039] Extracting multi-dimensional path evolution features based on the dynamic path distribution of the protocol conversion sequence, and performing feature decoupling operations on the dynamic projection tensor in combination with a tensor decomposition algorithm to generate multi-dimensional projection constraint conditions that reflect the coupling strength between the cross-protocol jump path and the subdomain penetration feature;

[0040] Performing a subspace reconstruction calculation on the multidimensional projection constraint condition based on a topological alignment rule of a shared manifold space, and utilizing a spatiotemporal coupling unit to nonlinearly superpose the semantic feature vector and the manifold space offset of the spatiotemporal feature vector to generate an offset parameter set that carries the dynamic evolution law of the cross-protocol jump path;

[0041] Perform a topological dimension alignment operation between the offset parameter set and the subdomain penetration feature, eliminate the spatiotemporal feature dimension deviation between the semantic association parameter set and the trajectory mapping parameter set through a manifold space compensation algorithm, and output a dynamic coupling offset parameter set that integrates the adaptation strategy deviation parameters.

[0042] In a second aspect, an embodiment of the present application provides a vulnerability detection system for cross-domain resource sharing, including:

[0043] A construction module is configured to construct a multi-dimensional probe request set and perform dynamic parameter inheritance link adjustment to generate a dynamic association request set, wherein the multi-dimensional probe request set includes a protocol conversion sequence, a subdomain penetration feature, and a null value parameter combination;

[0044] A synchronization module is used to inject a set of dynamically associated requests into an isolated sandbox environment and synchronously capture policy declaration vectors and resource loading trajectories. The policy declaration vectors extract response header policy declaration features through a semantic parsing engine, and the resource loading trajectories use behavioral fingerprinting technology to record the timing of cross-domain resource interactions and generate a trajectory spatial coordinate sequence.

[0045] a processing module, configured to construct a deviation map of the strategy declaration vector and the trajectory space coordinate sequence, map the strategy declaration vector to the behavior trajectory space using a multidimensional space projection algorithm, and calculate a strategy deviation parameter;

[0046] A monitoring module is used to activate a deep interface scanning engine based on the policy deviation parameter, wherein the deep interface scanning engine constructs a message monitoring topology structure map through an adaptive port clustering algorithm, identifies the callback function dependency chain of unverified sources, and generates an interface exposure parameter;

[0047] An integration module is used to integrate the policy deviation parameter and the interface exposure parameter to generate a cross-domain risk coefficient. The deep interface scanning engine performs nonlinear superposition on the policy deviation parameter and the exposure parameter through a dynamic weight distribution mechanism. When the superposition result meets the dynamic threshold judgment condition generated based on the protocol conversion sequence weight distribution, a cross-domain resource sharing vulnerability alarm is triggered.

[0048] In a third aspect, an embodiment of the present application provides a computing device comprising a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a cross-domain resource sharing vulnerability detection method as described in the first aspect above.

[0049] In a fourth aspect, an embodiment of the present application provides a computer storage medium storing a computer program. When the computer program is executed by a computer, it implements a cross-domain resource sharing vulnerability detection method as described in the first aspect.

[0050] In an embodiment of the present application, a multi-dimensional probe request set is constructed and dynamic parameter inheritance link adjustment is performed to generate a dynamic association request set, wherein the multi-dimensional probe request set includes a protocol conversion sequence, a sub-domain penetration feature and a null value parameter combination; the dynamic association request set is injected into an isolated sandbox environment, and the policy declaration vector and the resource loading trajectory are captured synchronously, the policy declaration vector extracts the response header policy declaration feature through a semantic parsing engine, and the resource loading trajectory records the cross-domain resource interaction timing and generates a trajectory space coordinate sequence through a behavioral fingerprint marking technology; the deviation map of the policy declaration vector and the trajectory space coordinate sequence is constructed, and a multi-dimensional space projection algorithm is used to convert the policy declaration vector and the resource loading trajectory into a dynamic association request set; ... The policy declaration vector is mapped to the behavior trajectory space and the policy deviation parameter is calculated; based on the policy deviation parameter, the deep interface scanning engine is activated, and the deep interface scanning engine constructs a message monitoring topology structure map through an adaptive port clustering algorithm, identifies the callback function dependency chain of unverified sources and generates an interface exposure parameter; the policy deviation parameter and the interface exposure parameter are integrated to generate a cross-domain risk coefficient, and the deep interface scanning engine performs nonlinear superposition on the policy deviation parameter and the exposure parameter through a dynamic weight distribution mechanism, and triggers a cross-domain resource sharing vulnerability alarm when the superposition result meets the dynamic threshold judgment condition generated based on the protocol conversion sequence weight distribution.

[0051] The technical solution of this application has the following beneficial effects:

[0052] This application combines a multi-dimensional set of trial requests, dynamic parameter inheritance link adjustment, request injection in an isolated sandbox environment, and the simultaneous capture of policy declaration vectors and resource loading trajectories. This not only enables accurate detection of potential vulnerabilities in cross-domain resource sharing, but also effectively improves the accuracy and comprehensiveness of security assessments. Furthermore, through an adaptive port clustering algorithm and dynamic weight allocation mechanism, the ability to identify unauthorized access and data leakage risks is further enhanced, providing strong technical support for protecting the security of network resources.

[0053] Furthermore, this method constructs a deviation map between the policy declaration vector and the trajectory spatial coordinate sequence through a series of sophisticated data processing steps and calculates a policy deviation parameter. First, a multi-dimensional attention mechanism and a cross-protocol path coupling unit are used to adjust and interactively calculate the dynamic parameter association strength of the protocol transition sequence and the nested domain name mapping structure between the cross-protocol jump path and subdomain penetration characteristics, generating a semantic association parameter set that carries cross-protocol jump characteristics. Next, a bidirectional temporal network is used to fuse the spatiotemporal evolution of the empty parameter request template and the trajectory spatial coordinate sequence. A topological alignment unit is used to transform the behavioral fingerprint marking pattern of the resource loading trajectory with the subdomain penetration characteristics, forming a trajectory mapping parameter set that contains the spatiotemporal characteristics of cross-domain interactions. A manifold spatial constraint relationship is then established between the two parameter sets, and a shared subspace reconstruction algorithm is used to calculate the spatiotemporal offset between the semantic and spatiotemporal features. Finally, the cross-protocol jump characteristics and spatiotemporal offset are integrated, and the dynamic coupling unit is combined with the calibration rules of the empty parameter request template to output the final policy deviation parameter.

[0054] Through the above method, the accuracy and comprehensiveness of cross-domain resource sharing vulnerability detection are significantly improved by utilizing a highly customized data processing process. Specifically, by utilizing technical means such as multi-dimensional attention mechanisms and cross-protocol path coupling units, not only can the complex changes in the protocol conversion and subdomain penetration process be captured in detail, but spatiotemporal features can also be effectively integrated to more accurately identify potential security threats. In addition, by establishing a manifold space constraint relationship and applying a shared subspace reconstruction algorithm, the correlation analysis between semantic features and spatiotemporal features is further enhanced, making the calculation of policy deviation parameters more scientific and reasonable. This not only helps to improve the sensitivity and specificity of vulnerability detection, but also provides a solid foundation for subsequent risk assessment. Ultimately, this method can provide more accurate and reliable cross-domain resource sharing security protection in complex network environments.

[0055] These and other aspects of the present application will become more readily apparent from the description of the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0057] Figure 1 A flowchart of a cross-domain resource sharing vulnerability detection method provided by the present application is shown;

[0058] Figure 2A schematic diagram of the structure of a cross-domain resource sharing vulnerability detection system provided by the present application is shown;

[0059] Figure 3 A schematic structural diagram of a computing device provided by the present application is shown. DETAILED DESCRIPTION

[0060] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.

[0061] In some of the processes described in the specification and claims of this application and the above-mentioned figures, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this document or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this document are used to distinguish different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to being different types.

[0062] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.

[0063] Figure 1 A flowchart of a vulnerability detection method for cross-domain resource sharing is provided for an embodiment of the present application. Figure 1 As shown, the method includes:

[0064] 101. Construct a multi-dimensional probe request set and perform dynamic parameter inheritance link adjustment to generate a dynamic association request set, wherein the multi-dimensional probe request set includes a protocol conversion sequence, a subdomain penetration feature, and a null value parameter combination;

[0065] The multi-dimensional probing request set includes various types of requests designed to test the security of cross-domain resource sharing from different dimensions and angles. Specifically, it includes protocol conversion sequences, subdomain penetration characteristics, and null parameter combinations.

[0066] Dynamic parameter inheritance link adjustment: This refers to dynamically adjusting the parameters of subsequent requests based on the results of the previous request when building a request set to more accurately simulate the actual attack path.

[0067] Dynamically associated request set: The adjusted request set can more accurately reflect the potential risks in the actual cross-origin resource sharing process.

[0068] Protocol conversion sequence: A series of requests arranged in the order of different network protocol conversions, used to test cross-protocol security vulnerabilities.

[0069] Subdomain penetration characteristics: A structured data model used to represent the relationship between different subdomains and their potential security weaknesses.

[0070] Empty value parameter combination: contains various parameter combinations with undefined or empty values. The purpose is to test the system's ability to handle abnormal input.

[0071] In practice, we first collect and construct a multi-dimensional set of probing requests, including protocol conversion sequences, subdomain penetration characteristics, and null parameter combinations. We then optimize these requests using dynamic parameter inheritance to ensure that each request simulates realistic attack behavior to the greatest extent possible, adjusting the parameters of subsequent requests based on the results of the previous request.

[0072] For example, imagine a bank evaluating the security of its Cross-Origin Resource Sharing (CORS) policy. The security team first constructed a multi-dimensional set of probing requests, including various protocol conversion attempts (such as from HTTP to HTTPS) targeting different API endpoints, subdomain penetration signatures (simulating attackers attempting to access resources through different subdomains), and requests with empty parameters (testing the server's handling of unusual input). These requests were then adjusted through a dynamic parameter inheritance chain, for example, adjusting parameter values ​​for subsequent requests based on the status code returned by the initial request. This ultimately resulted in a series of dynamically linked requests ready for the next step of testing.

[0073] 102. Inject a set of dynamically associated requests into the isolated sandbox environment and simultaneously capture the policy declaration vector and resource loading trajectory. The policy declaration vector extracts the response header policy declaration features through the semantic parsing engine. The resource loading trajectory uses behavioral fingerprinting technology to record the cross-domain resource interaction time sequence and generate a trajectory spatial coordinate sequence.

[0074] Among them, isolated sandbox environment: a controlled and closed testing environment used to run unknown or potentially dangerous code without affecting the main system.

[0075] Policy Statement Vector: A security policy feature extracted by analyzing the response header to describe the server's permitted scope for cross-origin requests.

[0076] Resource loading trajectory: records the time sequence and behavior patterns of cross-domain resource interactions. The resulting spatial coordinate sequence helps understand the actual usage of resources.

[0077] Semantic parsing engine: A tool that can automatically parse and extract key information from text, mainly used here to identify the security policy of the response header.

[0078] Behavioral fingerprinting technology: By monitoring the behavioral characteristics of resource loading, such as timestamps and access frequency, a unique "fingerprint" is generated for tracking and analysis.

[0079] In actual operation, the previously prepared dynamic association request set is deployed to an isolated sandbox environment for execution. At the same time, the policy declaration characteristics of all response headers and the resource loading timing are monitored and recorded to form a trajectory space coordinate sequence, providing basic data for subsequent analysis.

[0080] Continuing with the banking example above, dynamically associated request sets are executed in an isolated sandbox environment. Each time a request is sent, the system captures the policy statement in the response header and uses behavioral fingerprinting technology to track each resource load, recording detailed timing information. For example, when a request attempts to access specific account information, the system records key information such as the timestamp and source IP address of the request, enabling subsequent analysis to determine whether there has been unauthorized data access.

[0081] 103. Execute a deviation map construction between the strategy declaration vector and the trajectory space coordinate sequence, and use a multi-dimensional space projection algorithm to map the strategy declaration vector to the behavior trajectory space and calculate a strategy deviation parameter;

[0082] Among them, the deviation map construction: by comparing the differences between the policy declaration vector and the resource loading trajectory, a chart showing the degree of deviation between the two is constructed.

[0083] Multidimensional space projection algorithm: A mathematical method that can map high-dimensional data into a low-dimensional space for easy visualization and analysis.

[0084] Policy deviation parameter: A numerical indicator that quantifies the gap between the policy declaration vector and the actual resource loading behavior.

[0085] Deviation graph construction: By comparing the differences between the policy declaration vector and the resource loading trajectory, a graph showing the degree of deviation between the two is constructed.

[0086] Multidimensional space projection algorithm: A mathematical method that can map high-dimensional data into a low-dimensional space for easy visualization and analysis.

[0087] Policy deviation parameter: A numerical indicator that quantifies the gap between the policy declaration vector and the actual resource loading behavior.

[0088] In actual operation, a deviation map is constructed based on the policy declaration vector and trajectory space coordinate sequence, and a multi-dimensional space projection algorithm is used to map the policy declaration vector to the behavior trajectory space, so as to quantify the policy deviation parameters and identify potential security threats.

[0089] Continuing with the previous example, the security team began constructing a deviation map, comparing the policy declaration vector for each request with the actual resource loading trajectory. If a request is permitted by the policy declaration but the actual loading trajectory exhibits unusual behavior (such as frequent attempts to access sensitive data), the request is marked as having a high policy deviation. Using a multidimensional spatial projection algorithm, the team can clearly identify these deviations and further confirm whether there are security vulnerabilities.

[0090] 104. Activate a deep interface scanning engine based on the policy deviation parameter. The deep interface scanning engine constructs a message monitoring topology graph using an adaptive port clustering algorithm, identifies callback function dependency chains of unverified sources, and generates an interface exposure parameter.

[0091] Among them, Deep Interface Scanning Engine: an advanced tool for in-depth detection and analysis of the security of application interfaces.

[0092] Adaptive Port Clustering Algorithm: An intelligent algorithm that automatically groups similar network connections based on traffic characteristics for further analysis.

[0093] Message monitoring topology diagram: A graphical representation of the message flow and their relationships in network communication.

[0094] Interface exposure parameter: measures the degree of external exposure of the API interface and reflects the potential security risk level.

[0095] In actual operation, the policy deviation parameter is used to trigger the deep interface scanning engine, and the message monitoring topology structure map is constructed through the adaptive port clustering algorithm to identify the callback function dependency chain of unverified sources, and then evaluate the exposure of the interface.

[0096] According to the above embodiment, once requests with high policy deviation scores are identified, the security team activates the deep interface scanning engine. This engine rapidly scans the entire network, focusing specifically on the ports and services involved in those requests with high policy deviation scores. Using an adaptive port clustering algorithm, it efficiently locates interfaces that may pose security risks and generates interface exposure metrics to help the team understand which interfaces are most vulnerable to attack.

[0097] 105. Integrate the policy deviation parameter and the interface exposure parameter to generate a cross-domain risk coefficient. The deep interface scanning engine nonlinearly superimposes the policy deviation parameter and the exposure parameter through a dynamic weight distribution mechanism. When the superposition result meets the dynamic threshold judgment condition generated based on the protocol conversion sequence weight distribution, a cross-domain resource sharing vulnerability alarm is triggered.

[0098] Among them, the cross-domain risk coefficient is an overall security risk assessment value obtained by comprehensively considering the policy deviation parameters and interface exposure parameters.

[0099] Dynamic weight allocation mechanism: A flexible weight calculation method that can adjust the importance of different factors according to specific circumstances.

[0100] Dynamic threshold judgment conditions: A set of criteria. When these conditions are met, the system will trigger an alarm to notify relevant personnel.

[0101] In practice, the cross-domain risk coefficient is generated by integrating the policy deviation parameter with the interface exposure parameter. The deep interface scanning engine nonlinearly superimposes these two parameters using a dynamic weight distribution mechanism. When the superposition result meets the dynamic threshold judgment criteria generated based on the weight distribution of the protocol conversion sequence, a cross-domain resource sharing vulnerability alert is triggered.

[0102] Continuing with the above example, the development team finally calculated the cross-domain risk factor for the entire e-commerce platform by combining the data from all previous steps. Taking into account the different types of interfaces and their respective exposure levels, the team employed a dynamic weighting mechanism to perform a weighted average and arrive at a final risk score. If this score exceeds a preset dynamic threshold, the system automatically issues an alert, prompting the security team to take immediate action.

[0103] By implementing steps 101 to 105, this solution not only comprehensively assesses security risks in cross-domain resource sharing, but also accurately locates the problem and provides effective solutions. From constructing a multi-dimensional set of trial requests to ultimately generating a cross-domain risk factor and triggering an alert, each step is closely linked, ensuring a systematic and complete detection process. This approach significantly improves the ability to discover and mitigate cross-domain resource sharing vulnerabilities, providing strong support for network security.

[0104] In order to solve the complex correlation problem between the policy declaration vector and the resource loading trajectory and further improve the accuracy and comprehensiveness of cross-domain resource sharing vulnerability detection, in some embodiments, step 103 includes constructing a deviation map of the policy declaration vector and the trajectory space coordinate sequence, and using a multidimensional space projection algorithm to map the policy declaration vector to the behavior trajectory space and calculate the policy deviation parameter, including:

[0105] A multi-dimensional attention mechanism is used to adjust the dynamic parameter association strength of the protocol conversion sequence, and a cross-protocol path coupling unit is used to interactively calculate the cross-protocol jump path of the protocol conversion sequence and the nested domain name mapping structure of the subdomain penetration feature, and output a semantic association parameter set carrying the cross-protocol jump feature; based on the bidirectional temporal network fusion empty value parameter request template and the spatiotemporal evolution law of the trajectory space coordinate sequence, a topological alignment unit is used to coordinate the behavioral fingerprint marking pattern of the resource loading trajectory with the multi-level domain name space distribution of the subdomain penetration feature, and generate a trajectory containing cross-domain interactive spatiotemporal features. Trace mapping parameter set; establish a manifold space constraint relationship between the semantic association parameter set and the trajectory mapping parameter set, generate multidimensional projection constraints according to the dynamic path distribution of the protocol conversion sequence, and use a shared subspace reconstruction algorithm to realize the spatiotemporal offset calculation of semantic features and spatiotemporal features; integrate the cross-protocol jump features and the spatiotemporal offset to generate a strategy deviation parameter, use a dynamic coupling unit to nonlinearly associate the offset calculation result with the path weight of the protocol conversion sequence, and combine the calibration rules of the request template of the null value parameter to output the strategy deviation parameter carrying the cross-protocol association feature.

[0106] In this embodiment, a multi-dimensional attention mechanism: a technology that can automatically adjust the weights of different input features to enhance the model's attention to key information, is used here to optimize the dynamic parameter association strength in the protocol conversion sequence.

[0107] Cross-protocol path coupling unit: A specially designed module used to handle the data interaction logic between different network protocols, ensuring that the cross-protocol jump path can be correctly mapped to the nested domain name structure of the subdomain penetration feature.

[0108] Bidirectional Time Series Network: A neural network architecture that combines forward and backward time series analysis capabilities. It is suitable for capturing spatiotemporal evolution patterns and is particularly well suited for processing time-tagged data.

[0109] Topological alignment unit: This unit uses coordinate transformation technology to align the behavioral patterns of different data sources to facilitate subsequent analysis. Here, it is used to match the behavioral fingerprint marking pattern of resource loading trajectories with the spatial distribution of subdomain penetration characteristics.

[0110] Manifold space constraint relationship: A mathematical model that defines the relationship between points in a high-dimensional space. It is used to constrain the relative positions between semantic features and spatiotemporal features, helping to more accurately calculate the offset between them.

[0111] Shared Subspace Reconstruction Algorithm: A method for finding common low-dimensional representations among multiple high-dimensional datasets, extracting core features and reducing redundant information by reconstructing the subspace.

[0112] Dynamic coupling unit: responsible for handling the nonlinear relationship between two or more variables. Its purpose here is to associate the offset calculation result with the path weight of the protocol conversion sequence to generate the final policy deviation parameter.

[0113] In an embodiment of the present application, a multi-dimensional attention mechanism and a cross-protocol path coupling unit are first used to adjust the dynamic parameters of the protocol conversion sequence, and then interactively calculate them with the nested domain name mapping structure of the subdomain penetration feature to generate a semantic association parameter set carrying cross-protocol jump features.

[0114] Then, based on the bidirectional temporal network, the spatiotemporal evolution law of the empty value parameter request template and the trajectory spatial coordinate sequence is fused. The topological alignment unit is used to match the behavior pattern of the resource loading trajectory with the spatial distribution of the subdomain penetration characteristics to generate a trajectory mapping parameter set.

[0115] Next, a manifold space constraint relationship is established between the two parameter sets, and the shared subspace reconstruction algorithm is used to calculate the spatiotemporal offset of semantic features and spatiotemporal features.

[0116] Finally, these features are integrated and a dynamic coupling unit is used to generate the strategy deviation parameter.

[0117] Here's a specific example:

[0118] In the case of an online education platform, the development team wanted to assess the security of its API, specifically targeting potential cross-origin resource sharing (CORS) threats. They first constructed a multi-dimensional set of probing requests, including various protocol conversion sequences, subdomain penetration characteristics, and null parameter combinations. They then generated a dynamically associated set of requests through dynamic parameter inheritance link adjustment.

[0119] Next, they ran these requests in an isolated sandbox environment, synchronously capturing policy declaration vectors and resource loading traces. To deeply analyze this data, the team employed a multi-dimensional attention mechanism and a cross-protocol path coupling unit to process protocol conversion sequences, while also utilizing a bidirectional temporal network and a topology alignment unit to process resource loading traces.

[0120] Using this approach, they not only discovered the risk of unauthorized access to certain API interfaces, but also identified specific cross-protocol jump paths and subdomain penetration patterns. Ultimately, the policy deviation parameters calculated based on these findings helped the team identify security risks that needed to be remediated first, significantly improving the overall security of the platform.

[0121] In order to solve the complex association problem between the cross-protocol jump path and the subdomain penetration structure and further improve the accuracy and comprehensiveness of the policy deviation parameter calculation, in one of the above embodiments, the multi-dimensional attention mechanism is used to adjust the dynamic parameter association strength of the protocol conversion sequence, and the cross-protocol path coupling unit is used to interactively calculate the cross-protocol jump path of the protocol conversion sequence and the nested domain name mapping structure of the subdomain penetration feature, and output a semantic association parameter set carrying the cross-protocol jump feature, including:

[0122] A multi-level protocol conversion path analysis network is constructed to capture the topological connection pattern of the cross-protocol jump path, and a heterogeneous convolution kernel group is used to perform multi-granularity path association analysis on the protocol conversion sequence. The protocol conversion hierarchical features and the nested domain name space distribution of the sub-domain penetration feature are coordinate-converted to generate a dynamic path parameter set carrying the cross-protocol jump feature. A protocol-aware parameter coupling unit is used to perform cross-protocol association strength adjustment on the dynamic path parameter set. Based on the coupling relationship between the topological connectivity parameter and the domain name mapping density parameter of the sub-domain penetration feature, a protocol-aware parameter set carrying path association features is generated. A cross-protocol gated interaction module is used to fuse the protocol-aware parameter set with the null-value parameter request template in spatiotemporal dimensions. The path evolution law modeling unit is used to reconstruct the trajectory of the temporal distribution characteristics of the cross-protocol jump path to generate a dynamic coupling parameter set carrying spatiotemporal association features. A feature pyramid fusion algorithm is used to perform a manifold space alignment operation on the multi-level domain name mapping relationship of the dynamic coupling parameter set and the sub-domain penetration feature. Topological constraint rules are used to eliminate the structural deviation between the protocol jump trajectory and the domain name space distribution to generate a semantic association parameter set carrying cross-protocol semantic association features.

[0123] In this embodiment, a multi-level protocol conversion path analysis network is a network architecture specifically designed to capture the topological connection pattern of jump paths between different protocols, through which complex protocol conversion paths can be identified.

[0124] Heterogeneous convolution kernel group: A set of convolution kernels optimized for different types of data features, capable of performing multi-granularity path correlation analysis on protocol conversion sequences to extract richer path features.

[0125] Dynamic path parameter set: A data set containing the coordinate conversion results from protocol conversion layer features to nested domain name space distribution, used to describe the specific characteristics of the cross-protocol jump path.

[0126] Protocol-aware parameter coupling unit: A module designed to adjust the cross-protocol association strength based on topological connectivity and domain mapping density, ensuring an effective match between path characteristics and subdomain structures.

[0127] Cross-protocol gating interaction module: Combining the empty value parameter request template with the protocol-aware parameter set, it generates a dynamic coupling parameter set with spatiotemporal correlation characteristics through spatiotemporal fusion, simulating cross-domain resource sharing behavior in the real world.

[0128] Path evolution law modeling unit: Responsible for reconstructing the temporal distribution characteristics of cross-protocol jump paths, helping to understand path change trends, and generating trajectory data with time dimension information.

[0129] Feature Pyramid Fusion Algorithm: A multi-level feature fusion method that can integrate features at different scales. It is used here to align the dynamic coupling parameter set with the subdomain penetration features in manifold space.

[0130] Topology constraint rules: A set of rules used to eliminate the structural deviation between the protocol jump trajectory and the domain name space distribution, ensuring that the final generated semantic association parameter set is more accurate.

[0131] In an embodiment of the present application, a multi-level protocol conversion path analysis network is first constructed to capture the topological connection pattern of the cross-protocol jump path, and a heterogeneous convolution kernel group is used to perform multi-granularity path association analysis on the protocol conversion sequence to generate a dynamic path parameter set.

[0132] Then, a protocol-aware parameter coupling unit is used to adjust the cross-protocol correlation strength of these path parameter sets, and a protocol-aware parameter set is generated based on the relationship between topological connectivity and domain name mapping density.

[0133] Then, the protocol-aware parameter set and the empty-value parameter request template are fused in the spatiotemporal dimensions through the cross-protocol gating interaction module. Combined with the path evolution law modeling unit, the temporal distribution characteristics of the cross-protocol jump path are reconstructed to generate a dynamic coupling parameter set.

[0134] Finally, the feature pyramid fusion algorithm is used to align these parameter sets with the subdomain penetration features in manifold space, and topological constraint rules are applied to eliminate structural deviations to generate semantically associated parameter sets carrying cross-protocol semantic association features.

[0135] Here's a specific example:

[0136] The development team of an online medical service platform wanted to assess the security of its APIs, specifically the risks posed by Cross-Origin Resource Sharing (CORS). They first constructed a multi-level protocol conversion path analysis network to capture the transition paths and topological connectivity patterns between different protocols. Using a heterogeneous convolutional kernel group, they performed a detailed path correlation analysis of the platform's protocol conversion sequences and generated a dynamic path parameter set.

[0137] Next, they used a protocol-aware parameter coupling unit to adjust the correlation strength of these path parameter sets and generated protocol-aware parameter sets based on the topological connectivity and domain name mapping density of subdomain penetration characteristics. To further enhance the analysis, the team used a cross-protocol gating interaction module to integrate these parameter sets with the empty parameter templates in actual user requests in the spatiotemporal dimensions. Furthermore, they used a path evolution law modeling unit to reconstruct the temporal distribution characteristics of cross-protocol jump paths and generate a dynamic coupling parameter set.

[0138] Finally, a feature pyramid fusion algorithm was used to align these parameter sets with the subdomain penetration features in manifold space. Topological constraints were then applied to eliminate potential structural deviations, ultimately resulting in a semantically correlated parameter set that carries cross-protocol semantic correlation features. This series of operations helped the team identify several key security risks and implement corresponding protective measures, significantly improving the security of the platform.

[0139] In order to solve the complex association problem between the cross-protocol jump path and the subdomain mapping structure and further improve the accuracy and comprehensiveness of the path association feature extraction, in the above-mentioned multiple embodiments, the protocol-aware parameter coupling unit is used to perform cross-protocol association strength adjustment on the dynamic path parameter set, and a protocol-aware parameter set carrying the path association feature is generated based on the coupling relationship between the topological connectivity parameter and the domain name mapping density parameter of the subdomain penetration feature, including:

[0140] The protocol conversion sequence is subjected to multi-level path association analysis by a path topology analysis unit, and the path connection density distribution pattern and directional evolution law of the cross-protocol jump behavior in the protocol conversion sequence are captured based on the spatial convolution kernel group, and a path topology parameter set is output; a domain name density analysis unit is used to perform a hierarchical spatial compression operation on the nested topology structure, and the spatial distribution intensity characteristics of the multi-level domain name mapping relationship are extracted based on the adaptive pooling strategy, and a domain name density parameter set is output; a cross-protocol coupling unit is used to input the path topology parameter set and the domain name density parameter set into a timing constraint module, and a dynamic coupling parameter vector is generated by a gated loop unit based on the timing change law of the cross-protocol association path and the topological constraint relationship of the sub-domain penetration feature; a topology constraint projection algorithm is used to perform a spatial dimension alignment operation between the dynamic coupling parameter vector and the request template of the null value parameter, and the structural deviation between the protocol jump trajectory and the domain name space distribution is eliminated based on the topology constraint rule, and a protocol perception parameter set carrying cross-protocol semantic association features is output.

[0141] In this embodiment, the path topology analysis unit is a technical module for parsing and identifying the path connection density distribution pattern and directional evolution law of cross-protocol jump behavior in the protocol conversion sequence.

[0142] Spatial convolution kernel group: A set of convolution kernels specially designed to capture path features at different levels, suitable for multi-granularity analysis of complex path structures.

[0143] Path topology parameter set: A data set that includes everything from path connection density distribution patterns to directional evolution patterns, used to describe the specific characteristics of cross-protocol jump paths.

[0144] Domain Density Parsing Unit: A module for processing nested topological structures and extracting their spatial distribution intensity features, achieved through hierarchical spatial compression operations.

[0145] Adaptive pooling strategy: A method that dynamically adjusts the data sampling rate to efficiently extract the spatial distribution intensity characteristics of multi-level domain name mapping relationships.

[0146] Cross-protocol coupling unit: responsible for integrating the path topology parameter set and the domain density parameter set, and generating a dynamic coupling parameter vector that reflects the temporal change rules and topological constraint relationship between the two.

[0147] Gated Recurrent Unit (GRU): An improved recurrent neural network unit that is particularly suitable for processing long-term dependencies in sequence data. It is used here to capture the temporal changes in cross-protocol association paths.

[0148] Topologically constrained projection algorithm: A technique for performing spatial dimension alignment operations, ensuring structural consistency between the dynamic coupling parameter vector and the null-value parameter request template, and eliminating deviations.

[0149] In an embodiment of the present application, a path topology analysis unit is first used to perform multi-level path association analysis on the protocol conversion sequence, and a path topology parameter set is generated based on a spatial convolution kernel group to capture the path connection density distribution pattern and directional evolution law.

[0150] Then, the domain name density parsing unit is used to perform hierarchical spatial compression operations on the nested topological structure. The spatial distribution intensity characteristics of the multi-level domain name mapping relationship are extracted based on the adaptive pooling strategy to generate a domain name density parameter set.

[0151] Then, the cross-protocol coupling unit is used to input the path topology parameter set and the domain density parameter set into the timing constraint module, and the gated recurrent unit is used to generate a dynamic coupling parameter vector that reflects the timing change law of the cross-protocol associated path.

[0152] Finally, a topological constraint projection algorithm is used to perform spatial dimension alignment on the dynamic coupling parameter vector and the empty value parameter request template to eliminate the structural deviation between the protocol jump trajectory and the domain name space distribution, and generate a protocol-aware parameter set carrying cross-protocol semantic association features.

[0153] Here's a specific example:

[0154] In the application scenario of an online financial services platform, the development team wanted to assess the security of its API interface, specifically the potential risks posed by Cross-Origin Resource Sharing (CORS). They first used a path topology analysis unit to perform multi-level path correlation analysis on the various protocol conversion sequences involved in the service. Using a spatial convolution kernel group, they captured the path connection density distribution pattern and directional evolution of cross-protocol jump behavior, generating a detailed set of path topology parameters.

[0155] Next, the team used a domain density resolution unit to perform hierarchical spatial compression on the nested topological structure of all subdomains within the platform. Using an adaptive pooling strategy, they extracted the spatial distribution intensity characteristics of these subdomains and generated a domain density parameter set. To better understand the relationship between these paths and domain structure, the team employed a cross-protocol coupling unit to feed the path topology parameter set and the domain density parameter set into the timing constraint module. Using a gated recurrent unit, they generated a dynamic coupling parameter vector that reflects the temporal variations of the cross-protocol associated paths.

[0156] Finally, using a topologically constrained projection algorithm, they spatially aligned these parameter vectors with the null-value parameter templates in actual user requests. This eliminated the structural misalignment between protocol transitions and the domain name space distribution, resulting in a protocol-aware parameter set with cross-protocol semantic associations. This series of operations helped the team identify multiple potential security risks and implement appropriate protective measures, significantly improving the platform's security.

[0157] In order to solve the complex association problem between cross-protocol jump paths and timing variation patterns, and further improve the accuracy and comprehensiveness of dynamic coupling parameter vector generation, in the above-mentioned multiple embodiments, the cross-protocol coupling unit is used to input the path topology parameter set and the domain name density parameter set into the timing constraint module, and the gated recurrent unit is used to generate a dynamic coupling parameter vector based on the timing variation pattern of the cross-protocol association path and the topological constraint relationship of the sub-domain penetration feature, including:

[0158] Based on the connection density distribution pattern of the path topology parameter set and the spatial intensity characteristics of the domain name density parameter set, a multi-scale path correlation analysis is performed on the temporal evolution trajectory of the cross-protocol jump path to generate a primary temporal feature vector carrying short-term fluctuations and long-term evolution laws; using the primary temporal feature vector, a multi-window weight dynamic allocation process is performed on the cross-protocol correlation strength to generate a dynamic weight parameter set that reflects the coupling strength of the cross-protocol jump path and the sub-domain penetration characteristics in different time intervals; based on the hierarchical evolution law of the cross-protocol jump path under the constraints of the nested topology structure and the spatial distribution intensity of the domain name mapping density parameters, the dynamic weight parameter set and the domain name density parameter set are interactively calculated to generate an intermediate fusion parameter set carrying spatiotemporal correlation characteristics; according to the topological constraint relationship between the intermediate fusion parameter set and the sub-domain penetration characteristics, the timing deviation of the cross-protocol jump path and the difference in the spatial structure dimension of the domain name mapping are eliminated to generate a dynamic coupling feature parameter vector that is adapted to subsequent spatial alignment operations.

[0159] In this embodiment, multi-scale path correlation analysis processing: a technical means to extract short-term fluctuations and long-term evolution laws by performing multi-level time series analysis on the path topology parameter set and the domain name density parameter set.

[0160] Primary temporal feature vector: A data set containing everything from path connection density distribution patterns to spatial intensity features, used to describe the temporal variation characteristics of cross-protocol jump paths.

[0161] Multi-window weight dynamic allocation processing: A method that captures the coupling strength between cross-protocol hopping paths and subdomain penetration characteristics by adjusting weights in different time intervals.

[0162] Dynamic weight parameter set: A set of parameters calculated based on the primary time series feature vector that reflects the coupling strength between the cross-protocol jump path and the subdomain penetration characteristics in different time intervals.

[0163] Intermediate fusion parameter set: combines the spatial distribution intensity characteristics of the dynamic weight parameter set and the domain density parameter set to generate a fused dataset with spatiotemporal correlation features.

[0164] Dynamically coupled characteristic parameter vector: The final output after multiple calculations and optimizations is suitable for subsequent spatial alignment operations and can effectively eliminate timing deviations and spatial structure dimension differences.

[0165] In an embodiment of the present application, first, based on the connection density distribution pattern of the path topology parameter set and the spatial intensity characteristics of the domain name density parameter set, a multi-scale path correlation analysis is performed on the temporal evolution trajectory of the cross-protocol jump path to generate a primary temporal feature vector carrying short-term fluctuations and long-term evolution laws.

[0166] Then, the primary time series feature vector is used to perform multi-window weight dynamic allocation processing on the cross-protocol correlation strength, generating a dynamic weight parameter set that reflects the coupling strength of the cross-protocol jump path and subdomain penetration characteristics in different time intervals.

[0167] Then, based on the hierarchical evolution law of the cross-protocol jump path under the constraints of the nested topology structure and the spatial distribution intensity of the domain name mapping density parameters, the dynamic weight parameter set and the domain name density parameter set are interactively calculated and processed to generate an intermediate fusion parameter set carrying spatiotemporal correlation characteristics.

[0168] Finally, based on the topological constraint relationship between the intermediate fusion parameter set and the subdomain penetration characteristics, the timing deviation of the cross-protocol jump path and the difference in the spatial structure dimension of the domain name mapping are eliminated, and a dynamic coupling feature parameter vector that adapts to subsequent spatial alignment operations is generated.

[0169] Here's a specific example:

[0170] In an online travel service platform application scenario, the development team sought to assess the security of its API, specifically addressing potential risks associated with Cross-Origin Resource Sharing (CORS). They first used a path topology analysis unit to perform multi-level path correlation analysis on various protocol conversion sequences within the service. Using a spatial convolution kernel group, they captured the path connection density distribution patterns and directional evolution patterns of cross-protocol hop behavior, generating a detailed set of path topology parameters. Next, they used a domain density analysis unit to perform hierarchical spatial compression on the nested topology of all subdomains within the platform. Using an adaptive pooling strategy, they extracted the spatial distribution intensity characteristics of these subdomains, generating a set of domain density parameters.

[0171] To better understand the relationship between these paths and domain structure, the team used a cross-protocol coupling unit to input the path topology parameter set and the domain density parameter set into the timing constraint module. Using a gated recurrent unit, they conducted an in-depth analysis of the topological constraint relationship between the timing variation patterns of cross-protocol jump paths and the subdomain penetration characteristics, generating a primary timing feature vector.

[0172] Next, they used primary time series feature vectors to dynamically assign multi-window weights to cross-protocol association strengths, generating a dynamic weight parameter set. Based on the hierarchical evolution of cross-protocol jump paths under nested topology constraints and the spatial distribution intensity of domain name mapping density parameters, the team interactively calculated the dynamic weight parameter set and the domain name density parameter set to generate an intermediate fusion parameter set.

[0173] Finally, based on the topological constraints between the intermediate fusion parameter set and the subdomain penetration characteristics, the team eliminated the timing deviations in cross-protocol jump paths and the differences in the spatial structure dimensions of domain name mappings, resulting in a dynamic coupling feature parameter vector suitable for subsequent spatial alignment operations. This series of operations helped the team identify and address multiple potential security risks, significantly improving the overall security of the platform.

[0174] In order to solve the complex correlation problem between cross-protocol jump paths and timing variation patterns and further improve the accuracy and comprehensiveness of dynamic weight parameter set generation, in the above-mentioned multiple embodiments, the primary timing feature vector is used to perform multi-window weight dynamic allocation processing on the cross-protocol correlation strength, and a dynamic weight parameter set is generated that reflects the coupling strength between the cross-protocol jump paths and subdomain penetration characteristics in different time intervals, including:

[0175] A hierarchical time window division mechanism is constructed based on the short-term fluctuation characteristics and long-term evolution laws carried by the primary time series feature vector, and a multi-granularity time slicing operation is performed on the time series evolution trajectory of the cross-protocol jump path to generate a window feature vector set with different time scale correlation strengths; a cross-protocol attention screening module is used to perform path correlation strength dynamic analysis on the window feature vector set, and an attention weight matrix reflecting the coupling strength between the cross-protocol jump path and the sub-domain penetration feature is generated based on the spatial distribution intensity parameters under the nested topological structure constraints; a multimodal interaction unit is used to hierarchically fuse the attention weight matrix with the spatial distribution characteristics of the domain name density parameter set, and an intermediate parameter set carrying dynamic coupling weights is generated based on the spatial constraint relationship between the time series evolution law of the cross-protocol jump path and the domain name mapping density; a topological dimension matching operation is performed between the intermediate parameter set and the sub-domain penetration feature, and a path trajectory reconstruction algorithm is used to eliminate the conflict between the time series slicing deviation of the cross-protocol jump path and the structural dimension of the domain name spatial distribution, and output a dynamic weight parameter set adapted to subsequent interactive calculation processing.

[0176] In this embodiment, the hierarchical time window division mechanism is a technical means to capture short-term fluctuations and long-term evolution laws by slicing time series data at different time scales.

[0177] Window feature vector set: contains multiple sub-vector sets after time slicing operations, each sub-vector represents the path correlation strength in different time intervals.

[0178] Cross-protocol attention filtering module: A technical module for dynamically analyzing path association strength, generating an attention weight matrix based on the spatial distribution strength parameters of the nested topological structure.

[0179] Attention weight matrix: A matrix that reflects the coupling strength between cross-protocol jump paths and sub-domain penetration features, used to guide weight allocation in subsequent calculations.

[0180] Multimodal interaction unit: A technical unit that integrates different data modes and performs hierarchical fusion calculations on the spatial distribution characteristics of the attention weight matrix and the domain density parameter set.

[0181] Intermediate parameter set: A dataset that combines the spatial distribution characteristics of the attention weight matrix and the domain density parameter set to generate the final parameter set carrying dynamic coupling weights.

[0182] Path Trajectory Reconstruction Algorithm: A technique used to eliminate the conflict between the timing slice deviation of the cross-protocol jump path and the dimensionality of the domain name space distribution structure, ensuring that the generated parameter set is suitable for subsequent calculations.

[0183] In an embodiment of the present application, the scheme first constructs a hierarchical time window division mechanism based on the short-term fluctuation characteristics and long-term evolution laws carried by the primary timing feature vector, performs multi-granularity time slicing operations on the timing evolution trajectory of the cross-protocol jump path, and generates a set of window feature vectors carrying different time scale correlation strengths.

[0184] Then, the cross-protocol attention screening module is used to perform dynamic analysis of path association strength on the window feature vector set, and an attention weight matrix reflecting the coupling strength between the cross-protocol jump path and the subdomain penetration feature is generated based on the spatial distribution intensity parameters of the nested topological structure.

[0185] Then, a multimodal interaction unit is used to hierarchically fuse the spatial distribution characteristics of the attention weight matrix and the domain name density parameter set, and an intermediate parameter set carrying dynamic coupling weights is generated based on the temporal evolution law of the cross-protocol jump path and the spatial constraint relationship of the domain name mapping density.

[0186] Finally, a topological dimension matching operation is performed between the intermediate parameter set and the subdomain penetration characteristics. The path trajectory reconstruction algorithm is used to eliminate the conflict between the timing slicing deviation of the cross-protocol jump path and the structural dimension of the domain name space distribution, and output a dynamic weight parameter set that is adapted to subsequent interactive calculation processing.

[0187] Here's a specific example:

[0188] In an online payment platform application scenario, the development team wanted to assess the security of its API, specifically addressing the potential risks posed by Cross-Origin Resource Sharing (CORS). They first used a path topology analysis unit to perform multi-level path correlation analysis on various protocol conversion sequences within the service. Using a spatial convolution kernel group, they captured the path connection density distribution patterns and directional evolution patterns of cross-protocol hop behavior, generating a detailed set of path topology parameters.

[0189] Then, the domain name density resolution unit was used to perform a hierarchical spatial compression operation on the nested topological structure of all subdomains in the platform. The spatial distribution intensity characteristics of these subdomains were extracted based on the adaptive pooling strategy to generate a domain name density parameter set.

[0190] To better understand the relationship between these paths and domain name structures, the team constructed a hierarchical time window division mechanism based on the short-term fluctuation characteristics and long-term evolution laws carried by the primary timing feature vectors. They performed multi-granularity time slicing operations on the timing evolution trajectories of cross-protocol jump paths and generated a set of window feature vectors carrying different time scale correlation strengths.

[0191] Then, the cross-protocol attention screening module is used to perform dynamic analysis of path association strength on the window feature vector set, and an attention weight matrix reflecting the coupling strength between the cross-protocol jump path and the subdomain penetration feature is generated based on the spatial distribution intensity parameters of the nested topological structure.

[0192] Then, a multimodal interaction unit was used to hierarchically fuse the spatial distribution characteristics of the attention weight matrix and the domain name density parameter set. Based on the temporal evolution law of the cross-protocol jump path and the spatial constraint relationship of the domain name mapping density, an intermediate parameter set carrying dynamic coupling weights was generated.

[0193] Finally, they performed a topological matching operation on the intermediate parameter set and the subdomain penetration characteristics. Using a path trajectory reconstruction algorithm, they eliminated the conflict between the timing slicing deviations of the cross-protocol jump path and the structural dimension of the domain name space distribution, resulting in a dynamic weight parameter set suitable for subsequent interactive calculations. This series of operations helped the team identify and address multiple potential security risks, significantly improving the overall security of the platform.

[0194] In order to solve the complex association problem between semantic features and spatiotemporal features and further improve the accuracy and comprehensiveness of the coupling strength analysis of cross-protocol jump paths and subdomain penetration features, as another embodiment, the manifold space constraint relationship between the semantic association parameter set and the trajectory mapping parameter set is established, multidimensional projection constraints are generated according to the dynamic path distribution of the protocol conversion sequence, and the spatiotemporal offset calculation of the semantic features and spatiotemporal features is realized by using a shared subspace reconstruction algorithm, including:

[0195] Based on the cross-protocol jump characteristics of the semantic association parameter set and the spatiotemporal evolution law of the trajectory mapping parameter set, a manifold space alignment constraint is constructed, and the semantic feature vector and the spatiotemporal feature vector are projected into the shared manifold space by using a nonlinear mapping unit to generate a dynamic projection tensor carrying cross-protocol spatiotemporal association; according to the dynamic path distribution of the protocol conversion sequence, the multi-dimensional path evolution feature is extracted, and the feature decoupling operation is performed on the dynamic projection tensor in combination with the tensor decomposition algorithm to generate a multi-dimensional projection constraint condition reflecting the coupling strength between the cross-protocol jump path and the subdomain penetration feature; based on the shared flow The topological alignment rule of the shape space performs subspace reconstruction calculation on the multidimensional projection constraint condition, and uses the spatiotemporal coupling unit to nonlinearly superimpose the semantic feature vector and the manifold space offset of the spatiotemporal feature vector to generate an offset parameter set that carries the dynamic evolution law of the cross-protocol jump path; performs a topological dimension alignment operation on the offset parameter set and the subdomain penetration feature, eliminates the spatiotemporal feature dimension deviation between the semantic association parameter set and the trajectory mapping parameter set through the manifold space compensation algorithm, and outputs a dynamic coupling offset parameter set that integrates the adaptation strategy deviation parameters.

[0196] In this embodiment, a manifold space alignment constraint is a mathematical model used to align different types of feature vectors in a high-dimensional space, ensuring that they are compared and analyzed in the same coordinate system.

[0197] Nonlinear mapping unit: A technical means to map high-dimensional data into a low-dimensional space or shared manifold space for subsequent processing and analysis.

[0198] Dynamic Projection Tensor: A data structure containing cross-protocol spatiotemporal correlation information, generated through nonlinear mapping, used to describe the relationship between cross-protocol jump paths and spatiotemporal evolution laws.

[0199] Multi-dimensional path evolution features: Path change features at different levels and time points extracted from the protocol conversion sequence are used to describe the trend of path changes over time and protocol changes.

[0200] Tensor decomposition algorithm: An advanced data analysis method used to decompose complex high-dimensional data into multiple more understandable low-dimensional components, here used for feature decoupling operations.

[0201] Multidimensional projection constraints: A set of constraints generated based on the path evolution characteristics, which are used to guide the subsequent subspace reconstruction calculations to ensure that the results meet the expected coupling strength.

[0202] Spatiotemporal coupling unit: A fusion technology used to combine the offsets of semantic feature vectors and spatiotemporal feature vectors to generate an offset parameter set that carries dynamic evolution rules.

[0203] Manifold space compensation algorithm: A technique used to eliminate dimensional deviations between different feature sets, ensuring that the final generated parameter set is consistent with the deviation parameters of the adaptation strategy.

[0204] In an embodiment of the present application, a manifold space alignment constraint is first constructed based on the cross-protocol jump characteristics of the semantic association parameter set and the spatiotemporal evolution law of the trajectory mapping parameter set, and a nonlinear mapping unit is used to project the semantic feature vector and the spatiotemporal feature vector into a shared manifold space to generate a dynamic projection tensor carrying cross-protocol spatiotemporal association.

[0205] Then, the multi-dimensional path evolution features are extracted according to the dynamic path distribution of the protocol conversion sequence, and the tensor decomposition algorithm is combined to perform feature decoupling operations on the dynamic projection tensor to generate multi-dimensional projection constraints that reflect the coupling strength between the cross-protocol jump path and the sub-domain penetration feature.

[0206] Then, based on the topological alignment rules of the shared manifold space, subspace reconstruction calculations are performed on the multidimensional projection constraints, and the manifold space offsets of the semantic feature vector and the spatiotemporal feature vector are nonlinearly superimposed using the spatiotemporal coupling unit to generate an offset parameter set that carries the dynamic evolution law of the cross-protocol jump path.

[0207] Finally, the topological dimension alignment operation of the offset parameter set and the subdomain penetration feature is performed, and the spatiotemporal feature dimension deviation between the semantic association parameter set and the trajectory mapping parameter set is eliminated through the manifold space compensation algorithm, and the dynamic coupling offset parameter set that integrates the adaptation strategy deviation parameters is output.

[0208] Here's a specific example:

[0209] In the application scenario of an online medical appointment booking platform, the development team wanted to assess the security of its API, specifically the potential risks posed by Cross-Origin Resource Sharing (CORS). They first constructed a detailed, multi-dimensional set of probing requests, including protocol conversion sequences, subdomain penetration characteristics, and null parameter combinations. They then generated a dynamically correlated set of requests through dynamic parameter inheritance link adjustment. Next, they executed these requests in an isolated sandbox environment, simultaneously capturing policy assertion vectors and resource loading traces.

[0210] To further analyze this data, the team constructed manifold space alignment constraints based on the cross-protocol jump characteristics of the semantic association parameter set and the spatiotemporal evolution of the trajectory mapping parameter set. Using a nonlinear mapping unit, the semantic feature vectors and spatiotemporal feature vectors were projected onto a shared manifold space, generating a dynamic projection tensor that carries cross-protocol spatiotemporal associations. Next, they extracted multidimensional path evolution features based on the dynamic path distribution of the protocol conversion sequence. Using a tensor decomposition algorithm, they performed feature decoupling on the dynamic projection tensor, generating multidimensional projection constraints that reflect the coupling strength between cross-protocol jump paths and subdomain penetration features.

[0211] Based on the topological alignment rules of the shared manifold space, the team performed subspace reconstruction calculations on the multidimensional projection constraints and used the spatiotemporal coupling unit to nonlinearly superimpose the manifold space offsets of the semantic feature vector and the spatiotemporal feature vector, generating an offset parameter set that carries the dynamic evolution law of the cross-protocol jump path. Finally, by performing a topological dimension alignment operation on the offset parameter set and the subdomain penetration feature, the manifold space compensation algorithm was used to eliminate the spatiotemporal feature dimension deviation between the semantic association parameter set and the trajectory mapping parameter set, resulting in a dynamically coupled offset parameter set that integrates the adaptation strategy deviation parameters. This series of operations helped the team identify and fix multiple potential security risks, significantly improving the overall security of the platform.

[0212] Figure 2 A schematic diagram of the structure of a vulnerability detection device (or system) for cross-domain resource sharing is provided in the embodiment of the present application, such as Figure 2 As shown, the device includes:

[0213] A construction module 21 is configured to construct a multi-dimensional probe request set and perform dynamic parameter inheritance link adjustment to generate a dynamic association request set, wherein the multi-dimensional probe request set includes a protocol conversion sequence, a subdomain penetration feature, and a null value parameter combination;

[0214] Synchronization module 22, for injecting a set of dynamically associated requests into the isolated sandbox environment and synchronously capturing a policy declaration vector and a resource loading trajectory. The policy declaration vector extracts response header policy declaration features through a semantic parsing engine, and the resource loading trajectory uses behavioral fingerprinting technology to record the cross-domain resource interaction sequence and generate a trajectory spatial coordinate sequence.

[0215] a processing module 23 for constructing a deviation map between the strategy declaration vector and the trajectory space coordinate sequence, mapping the strategy declaration vector to the behavior trajectory space using a multidimensional space projection algorithm, and calculating a strategy deviation parameter;

[0216] A monitoring module 24 is configured to activate a deep interface scanning engine based on the policy deviation parameter, wherein the deep interface scanning engine constructs a message monitoring topology graph through an adaptive port clustering algorithm, identifies the callback function dependency chain of the unverified source, and generates an interface exposure parameter;

[0217] The integration module 25 is used to integrate the policy deviation parameter and the interface exposure parameter to generate a cross-domain risk coefficient. The deep interface scanning engine performs nonlinear superposition on the policy deviation parameter and the exposure parameter through a dynamic weight distribution mechanism. When the superposition result meets the dynamic threshold judgment condition generated based on the protocol conversion sequence weight distribution, a cross-domain resource sharing vulnerability alarm is triggered.

[0218] Figure 2 The vulnerability detection device for cross-domain resource sharing can be executed Figure 1 The implementation principle and technical effects of the cross-domain resource sharing vulnerability detection method described in the illustrated embodiment are not further described. The specific manner in which each module and unit performs operations in the cross-domain resource sharing vulnerability detection device in the above embodiment has been described in detail in the embodiment of the method and will not be elaborated on here.

[0219] In one possible design, Figure 2 The cross-domain resource sharing vulnerability detection device of the embodiment shown can be implemented as a computing device, such as Figure 3 As shown, the computing device may include a storage component 31 and a processing component 32;

[0220] The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 32 .

[0221] The processing component 32 is used for the above Figure 1 The embodiment provides a vulnerability detection method for cross-domain resource sharing.

[0222] The processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be implemented as one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above method.

[0223] The storage component 31 is configured to store various types of data to support operations at the terminal. The storage component can be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.

[0224] Of course, a computing device may also include other components, such as input / output interfaces, display components, communication components, etc.

[0225] The input / output interface provides an interface between the processing component and the peripheral interface module, which can be an output device, an input device, etc.

[0226] The communication component is configured to facilitate, among other things, wired or wireless communications between the computing device and other devices.

[0227] Among them, the computing device can be a physical device or an elastic computing host provided by a cloud computing platform, etc. In this case, the computing device can refer to a cloud server, and the above-mentioned processing components, storage components, etc. can be basic server resources rented or purchased from the cloud computing platform.

[0228] The present application also provides a computer storage medium storing a computer program, wherein the computer program can achieve the above-mentioned Figure 1 The embodiment shown is a vulnerability detection method for cross-domain resource sharing.

[0229] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0230] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0231] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.

[0232] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A vulnerability detection method for cross-domain resource sharing, characterized in that: include: Constructing a multi-dimensional probe request set and performing dynamic parameter inheritance link adjustment to generate a dynamic association request set, wherein the multi-dimensional probe request set includes a protocol conversion sequence, a subdomain penetration feature, and a null value parameter combination; Inject a set of dynamically associated requests into an isolated sandbox environment and synchronously capture policy declaration vectors and resource loading trajectories. The policy declaration vectors extract response header policy declaration features through a semantic parsing engine, and the resource loading trajectories use behavioral fingerprinting technology to record the timing of cross-domain resource interactions and generate a trajectory spatial coordinate sequence. Executing a deviation map construction between the strategy declaration vector and the trajectory space coordinate sequence, and mapping the strategy declaration vector to the behavior trajectory space using a multidimensional space projection algorithm and calculating a strategy deviation parameter; Activating a deep interface scanning engine based on the policy deviation parameter, the deep interface scanning engine constructs a message monitoring topology graph through an adaptive port clustering algorithm, identifies the callback function dependency chain of unverified sources and generates an interface exposure parameter; The policy deviation parameter and the interface exposure parameter are integrated to generate a cross-domain risk coefficient. The deep interface scanning engine performs nonlinear superposition on the policy deviation parameter and the exposure parameter through a dynamic weight distribution mechanism. When the superposition result meets the dynamic threshold judgment condition generated based on the protocol conversion sequence weight distribution, a cross-domain resource sharing vulnerability alarm is triggered.

2. The method according to claim 1, characterized in that The step of constructing a deviation map of the strategy declaration vector and the trajectory space coordinate sequence, and mapping the strategy declaration vector to the behavior trajectory space using a multi-dimensional space projection algorithm and calculating a strategy deviation parameter includes: A multi-dimensional attention mechanism is used to adjust the dynamic parameter association strength of the protocol conversion sequence, and a cross-protocol path coupling unit is used to interactively calculate the cross-protocol jump path of the protocol conversion sequence and the nested domain name mapping structure of the subdomain penetration feature, outputting a semantic association parameter set carrying the cross-protocol jump feature; Based on the spatiotemporal evolution law of the empty parameter request template and the trajectory spatial coordinate sequence fused by the bidirectional temporal network, the topological alignment unit is used to transform the behavioral fingerprint marking pattern of the resource loading trajectory with the multi-level domain name space distribution of the subdomain penetration feature, thereby generating a trajectory mapping parameter set containing the spatiotemporal features of cross-domain interaction; Establishing a manifold space constraint relationship between the semantic association parameter set and the trajectory mapping parameter set, generating multidimensional projection constraints based on the dynamic path distribution of the protocol conversion sequence, and calculating the spatiotemporal offset of semantic features and spatiotemporal features using a shared subspace reconstruction algorithm; The cross-protocol jump feature and the spatiotemporal offset are integrated to generate a policy deviation parameter, a dynamic coupling unit is used to nonlinearly associate the offset calculation result with the path weight of the protocol conversion sequence, and the calibration rule of the request template with the null value parameter is combined to output the policy deviation parameter carrying the cross-protocol association feature.

3. The method according to claim 2, characterized in that The multi-dimensional attention mechanism is used to adjust the dynamic parameter association strength of the protocol conversion sequence, and the cross-protocol path coupling unit is used to interactively calculate the cross-protocol jump path of the protocol conversion sequence and the nested domain name mapping structure of the subdomain penetration feature, and output a semantic association parameter set carrying the cross-protocol jump feature, including: A multi-level protocol conversion path analysis network is constructed to capture the topological connection pattern of the cross-protocol jump path, and a heterogeneous convolution kernel group is used to perform multi-granularity path correlation analysis on the protocol conversion sequence. The protocol conversion hierarchical features and the nested domain name space distribution of the subdomain penetration features are coordinate-converted to generate a dynamic path parameter set carrying the cross-protocol jump feature. A protocol-aware parameter coupling unit is used to perform cross-protocol association strength adjustment on the dynamic path parameter set, and a protocol-aware parameter set carrying path association characteristics is generated based on a coupling relationship between a topological connectivity parameter and a domain name mapping density parameter of the subdomain penetration characteristic; The protocol-aware parameter set and the empty-value parameter request template are integrated in the spatiotemporal dimension using the cross-protocol gating interaction module. The temporal distribution characteristics of the cross-protocol jump path are reconstructed using the path evolution law modeling unit to generate a dynamic coupling parameter set with spatiotemporal correlation characteristics. A feature pyramid fusion algorithm is used to perform a manifold space alignment operation on the multi-level domain name mapping relationship between the dynamic coupling parameter set and the subdomain penetration feature, and topological constraint rules are used to eliminate the structural deviation between the protocol jump trajectory and the domain name space distribution to generate a semantic association parameter set carrying cross-protocol jump features.

4. The method according to claim 3, wherein The protocol-aware parameter coupling unit is used to perform cross-protocol association strength adjustment on the dynamic path parameter set, and a protocol-aware parameter set carrying path association characteristics is generated based on a coupling relationship between a topology connectivity parameter and a domain name mapping density parameter of the subdomain penetration characteristic, including: Performing multi-level path association analysis on the protocol conversion sequence through a path topology analysis unit, capturing the path connection density distribution pattern and directional evolution law of the cross-protocol jump behavior in the protocol conversion sequence based on a spatial convolution kernel group, and outputting a path topology parameter set; Using a domain name density parsing unit to perform a hierarchical spatial compression operation on the nested topological structure, and extracting the spatial distribution intensity characteristics of the multi-level domain name mapping relationship based on an adaptive pooling strategy, and outputting a domain name density parameter set; The path topology parameter set and the domain name density parameter set are input into a timing constraint module using a cross-protocol coupling unit, and a dynamic coupling parameter vector is generated by the gated loop unit based on the timing variation law of the cross-protocol jump path and the topological constraint relationship of the subdomain penetration feature; A topology constraint projection algorithm is used to perform a spatial dimension alignment operation between the dynamic coupling parameter vector and the request template of the null value parameter, and based on the topology constraint rules, the structural deviation between the protocol jump trajectory and the domain name space distribution is eliminated, and a protocol perception parameter set carrying path association features is output.

5. The method according to claim 4, characterized in that The cross-protocol coupling unit is used to input the path topology parameter set and the domain name density parameter set into the timing constraint module, and the gated loop unit is used to generate a dynamic coupling parameter vector based on the timing change law of the cross-protocol jump path and the topological constraint relationship of the subdomain penetration feature, including: Based on the connection density distribution pattern of the path topology parameter set and the spatial intensity characteristics of the domain name density parameter set, a multi-scale path correlation analysis is performed on the temporal evolution trajectory of the cross-protocol jump path to generate a primary temporal feature vector carrying short-term fluctuations and long-term evolution rules; Using the primary time series feature vector, a multi-window weight dynamic allocation process is performed on the cross-protocol association strength to generate a dynamic weight parameter set reflecting the coupling strength of the cross-protocol jump path and the subdomain penetration feature in different time intervals; Based on the hierarchical evolution law of the cross-protocol jump path under the constraints of the nested topology structure and the spatial distribution intensity of the domain name mapping density parameter, the dynamic weight parameter set and the domain name density parameter set are interactively calculated and processed to generate an intermediate fusion parameter set carrying spatiotemporal correlation features; According to the topological constraint relationship between the intermediate fusion parameter set and the subdomain penetration characteristics, the timing deviation of the cross-protocol jump path and the difference in the spatial structure dimension of the domain name mapping are eliminated to generate a dynamic coupling parameter vector that adapts to subsequent spatial alignment operations.

6. The method according to claim 5, characterized in that The method of using the primary time series feature vector to dynamically allocate multi-window weights to the cross-protocol association strength to generate a dynamic weight parameter set reflecting the coupling strength of the cross-protocol jump path and the subdomain penetration feature in different time intervals includes: A hierarchical time window division mechanism is constructed based on the short-term fluctuation characteristics and long-term evolution laws carried by the primary time series feature vector, and a multi-granularity time slicing operation is performed on the time series evolution trajectory of the cross-protocol jump path to generate a set of window feature vectors carrying different time scale correlation strengths; Performing a dynamic analysis of path association strength on the window feature vector set using a cross-protocol attention screening module, and generating an attention weight matrix reflecting the coupling strength between the cross-protocol jump path and the subdomain penetration feature based on the spatial distribution intensity parameter under the nested topological structure constraint; A multimodal interaction unit is used to perform hierarchical fusion calculation on the spatial distribution characteristics of the attention weight matrix and the domain name density parameter set, and an intermediate parameter set carrying dynamic coupling weights is generated based on the temporal evolution law of the cross-protocol jump path and the spatial constraint relationship of the domain name mapping density parameter; Perform a topological dimension matching operation between the intermediate parameter set and the subdomain penetration feature, eliminate the conflict between the timing slice deviation of the cross-protocol jump path and the structural dimension of the domain name space distribution through the path trajectory reconstruction algorithm, and output a dynamic weight parameter set that is adapted to subsequent interactive calculation processing.

7. The method according to claim 2, characterized in that The method of establishing a manifold space constraint relationship between the semantic association parameter set and the trajectory mapping parameter set, generating a multidimensional projection constraint condition according to the dynamic path distribution of the protocol conversion sequence, and calculating the spatiotemporal offset of semantic features and spatiotemporal features using a shared subspace reconstruction algorithm includes: Based on the cross-protocol jump characteristics of the semantic association parameter set and the spatiotemporal evolution law of the trajectory mapping parameter set, a manifold space alignment constraint is constructed, and the semantic feature vector and the spatiotemporal feature vector are projected into a shared manifold space using a nonlinear mapping unit to generate a dynamic projection tensor carrying the cross-protocol spatiotemporal association; Extracting multi-dimensional path evolution features based on the dynamic path distribution of the protocol conversion sequence, and performing feature decoupling operations on the dynamic projection tensor in combination with a tensor decomposition algorithm to generate multi-dimensional projection constraint conditions that reflect the coupling strength between the cross-protocol jump path and the subdomain penetration feature; Performing a subspace reconstruction calculation on the multidimensional projection constraint condition based on a topological alignment rule of a shared manifold space, and utilizing a spatiotemporal coupling unit to nonlinearly superpose the semantic feature vector and the manifold space offset of the spatiotemporal feature vector to generate an offset parameter set that carries the dynamic evolution law of the cross-protocol jump path; Perform a topological dimension alignment operation between the offset parameter set and the subdomain penetration feature, eliminate the spatiotemporal feature dimension deviation between the semantic association parameter set and the trajectory mapping parameter set through a manifold space compensation algorithm, and output a dynamic coupling offset parameter set that integrates the adaptation strategy deviation parameters.

8. A vulnerability detection system for cross-domain resource sharing, characterized in that: include: A construction module is configured to construct a multi-dimensional probe request set and perform dynamic parameter inheritance link adjustment to generate a dynamic association request set, wherein the multi-dimensional probe request set includes a protocol conversion sequence, a subdomain penetration feature, and a null value parameter combination; A synchronization module is used to inject a set of dynamically associated requests into an isolated sandbox environment and synchronously capture policy declaration vectors and resource loading trajectories. The policy declaration vectors extract response header policy declaration features through a semantic parsing engine, and the resource loading trajectories use behavioral fingerprinting technology to record the timing of cross-domain resource interactions and generate a trajectory spatial coordinate sequence. a processing module, configured to construct a deviation map of the strategy declaration vector and the trajectory space coordinate sequence, map the strategy declaration vector to the behavior trajectory space using a multidimensional space projection algorithm, and calculate a strategy deviation parameter; A monitoring module is used to activate a deep interface scanning engine based on the policy deviation parameter, wherein the deep interface scanning engine constructs a message monitoring topology structure map through an adaptive port clustering algorithm, identifies the callback function dependency chain of unverified sources, and generates an interface exposure parameter; An integration module is used to integrate the policy deviation parameter and the interface exposure parameter to generate a cross-domain risk coefficient. The deep interface scanning engine performs nonlinear superposition on the policy deviation parameter and the exposure parameter through a dynamic weight distribution mechanism. When the superposition result meets the dynamic threshold judgment condition generated based on the protocol conversion sequence weight distribution, a cross-domain resource sharing vulnerability alarm is triggered.

9. A computing device, characterized in that It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a cross-domain resource sharing vulnerability detection method as described in any one of claims 1 to 7.

10. A computer storage medium, characterized in that A computer program is stored, and when the computer program is executed by a computer, the method for detecting a vulnerability in cross-domain resource sharing according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Cross-domain resource sharing vulnerability detection method and device, equipment and medium

    CN110266737A

  • CORS vulnerability detection method, apparatus and device, and medium

    CN113411332A