Information security protection method, device and electronic equipment

By obtaining firewall log files, capturing abnormal behavior traffic and performing session hijacking program analysis, the problem of large errors in traditional information security protection methods when identifying abnormal code attacks is solved, and stronger information security protection capabilities are achieved.

CN119854047BActive Publication Date: 2025-06-06江西省科技基础条件平台中心(江西省计算中心)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510334769.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-06-06
Estimated Expiration
2045-03-20

AI Technical Summary

Technical Problem

Traditional information security protection methods have problems such as large errors in identifying abnormal code attacks and weak information security protection capabilities.

Method used

By obtaining the firewall log file, abnormal behavior traffic is captured, and packet capture is carried out for exception frequency programs. Next, the session hijacking program parsing and verification logic evade code structure recognition based on the exception frequency program packet capture data set. Finally, adjust the session security protection strategy based on the parsing data and verifying the evasion code structure data.

Benefits of technology

Effectively identify and capture attack behaviors, reduce errors in abnormal code attack identification, improve information security protection capabilities, and improve the overall protection capabilities of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119854047B_ABST
    Figure CN119854047B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of information security protection technology, and in particular to an information security protection method, device and electronic device. The method comprises the following steps: obtaining a firewall log file; capturing abnormal behavior traffic based on the firewall log file to obtain abnormal behavior traffic; performing abnormal frequency program packet capture processing according to the abnormal behavior traffic to obtain an abnormal frequency program packet capture data set; performing session hijacking program parsing based on the abnormal frequency program packet capture data set to obtain session hijacking program parsing data; performing verification logic avoidance code structure identification on the session hijacking program parsing data to obtain verification avoidance code structure data; adjusting the session security protection strategy based on the session hijacking program parsing data and the verification avoidance code structure data to obtain session security protection strategy adjustment data. The present invention makes the information security protection technology more perfect by optimizing the information security protection technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security protection technology, and in particular to an information security protection method, device and electronic equipment. Background Art

[0002] With the rapid development of information technology, digitalization and networking have become the mainstream trend of modern social development, and information security issues have become increasingly severe. The popularization of the Internet and the widespread application of technologies such as the Internet of Things, artificial intelligence, and big data have brought convenience to people's lives and work, but also brought huge challenges to information security. Globally, security incidents such as cyber attacks, data leaks, and malware are emerging in an endless stream, seriously threatening personal privacy and corporate secrets. At present, information security protection methods urgently need to develop in a more intelligent and automated direction. Especially in a diversified network environment, how to achieve real-time monitoring, dynamic response, and precise defense has become a hot topic in information security research. To this end, more and more emerging technologies are being introduced into the field of information security. For example, security protection technology based on artificial intelligence can continuously improve the ability to identify and prevent new attacks by learning a large amount of network data; blockchain-based technology can improve the transparency and security of data in a decentralized manner and reduce the risk of single point failures; in addition, cloud security technology and edge computing have also become new research directions. The application of these technologies enables information security protection to not only cope with traditional attack methods, but also show stronger adaptability and flexibility in the face of emerging threats. However, a traditional information security protection method has the problem of large errors in identifying abnormal code attacks and weak information security protection capabilities. Summary of the invention

[0003] Based on this, it is necessary to provide an information security protection method, device and electronic device to solve at least one of the above technical problems.

[0004] To achieve the above object, an information security protection method is provided, the method comprising the following steps:

[0005] Step S1: Obtain a firewall log file; capture abnormal behavior traffic based on the firewall log file to obtain abnormal behavior traffic; perform abnormal frequency program packet capture processing based on the abnormal behavior traffic to obtain an abnormal frequency program packet capture data set;

[0006] Step S2: parsing the session hijacking program based on the abnormal frequency program packet capture data set to obtain session hijacking program parsing data; performing verification logic avoidance code structure identification on the session hijacking program parsing data to obtain verification avoidance code structure data; wherein step S2 includes:

[0007] Step S21: Analyze the abnormal IP address change trajectory on the abnormal frequency program packet capture data set to obtain the abnormal IP address change trajectory;

[0008] Step S22: Identify the session attack target based on the abnormal IP address change trajectory and abnormal frequency program packet capture data set to obtain the session attack target;

[0009] Step S23: performing session hijacking program analysis on the session attack target based on the abnormal frequency program packet capture data set to obtain session hijacking program analysis data;

[0010] Step S24: performing verification logic avoidance code structure identification on the session hijacking program parsing data to obtain verification avoidance code structure data;

[0011] Step S3: adjusting the session security protection strategy based on the session hijacking program parsing data and the verification avoidance code structure data to obtain session security protection strategy adjustment data.

[0012] Preferably, step S1 comprises the following steps:

[0013] Step S11: Obtain firewall log files;

[0014] Step S12: Analyze the frequency of abnormal connection requests according to the firewall log file to obtain the frequency of abnormal connection requests;

[0015] Step S13: capturing abnormal behavior traffic based on the abnormal connection request frequency to obtain abnormal behavior traffic;

[0016] Step S14: performing abnormal frequency program packet capture processing on the abnormal connection request frequency according to the abnormal behavior traffic to obtain an abnormal frequency program packet capture data set.

[0017] Preferably, step S23 includes the following steps:

[0018] Step S231: extracting session target state attribute elements from the session attack target to obtain session target state attribute elements; wherein the session target state attribute elements include cookies, session ID and URL parameters;

[0019] Step S232: Based on the abnormal frequency program packet capture data set, abnormal code element injection identification is performed on the session target state attribute element to obtain element injection abnormal code data;

[0020] Step S233: quantifying the risk of multiple parameter injections on the URL parameters in the session target state attribute element according to the element injection abnormal code data, and obtaining multiple parameter injection risk quantification data;

[0021] Step S234: performing session hijacking program analysis on the session attack target based on the element injection abnormal code data and the multiple parameter injection risk quantification data to obtain session hijacking program analysis data.

[0022] Preferably, step S233 includes the following steps:

[0023] Perform code execution logic analysis on element injected abnormal code data to obtain abnormal code execution logic;

[0024] Marking the URL parameter in the session target state attribute element with a key parameter variable to obtain a URL key parameter variable;

[0025] According to the abnormal code execution logic, the abnormal variable manipulation of the URL key parameter variables is identified to obtain the abnormal variable manipulation code;

[0026] Define the scope exception level for the abnormal variable manipulation code and obtain the scope exception level data;

[0027] Based on the scope exception level data, the code execution exception life cycle is analyzed for the exception variable manipulation code to obtain the code execution exception life cycle;

[0028] Based on the code execution exception life cycle and scope exception level data, the abnormal variable manipulation code is identified with abnormal modification hidden logic branches to obtain abnormal modification hidden logic branches;

[0029] Based on the abnormal modification of hidden logic branches, the abnormal life cycle of code execution and the abnormal variable manipulation code, the risk quantification of multiple parameter injections is performed to obtain the quantitative data of multiple parameter injection risks.

[0030] Preferably, step S24 comprises the following steps:

[0031] Step S241: performing program code control flow analysis on the session hijacking program parsing data to obtain a program code control flow graph;

[0032] Step S242: Decompile the attack call behavior of the session hijacking program parsed data according to the program code control flow graph to obtain code attack call behavior decompilation data;

[0033] Step S243: Based on the code attack call behavior decompilation data, the session hijacking program parsing data is subjected to underlying code vulnerability identification to obtain underlying code vulnerability data;

[0034] Step S244: performing attack vector construction analysis on the decompiled data of the code attack call behavior to obtain code attack vector construction data;

[0035] Step S245: performing race condition analysis based on the code attack vector construction data to obtain code attack vector race condition data;

[0036] Step S246: performing verification logic avoidance code structure identification according to the code attack carrier race condition data and the underlying code vulnerability data to obtain verification avoidance code structure data.

[0037] Preferably, step S242 includes the following steps:

[0038] Perform conditional jump analysis on the program code control flow graph to obtain program code conditional jump data;

[0039] Perform function call static analysis on session hijacking program parsing data based on program code conditional jump data to obtain function call static data;

[0040] Perform reverse analysis of attack behavior code snippets on session hijacking program analysis data according to function call static data to obtain attack behavior code reverse analysis data;

[0041] Reverse-parse the attack behavior code data to identify the hijacking return address and obtain the hijacking return address data;

[0042] Reverse-analyze the attack behavior code data to identify the tampered call stack and obtain the tampered call stack data;

[0043] The attack call behavior is decompiled according to the hijacked return address data and the tampered call stack data to obtain the code attack call behavior decompilation data.

[0044] Preferably, step S3 comprises the following steps:

[0045] Step S31: performing attack link correlation analysis based on session hijacking program parsing data and verification avoidance code structure data to obtain a session hijacking attack link;

[0046] Step S32: Perform multi-dimensional penetration identification on the session hijacking attack link to obtain multi-dimensional penetration data of the session hijacking attack;

[0047] Step S33: adjusting the session security protection strategy based on the multi-dimensional penetration data of the session hijacking attack to obtain session security protection strategy adjustment data.

[0048] Preferably, the present invention further provides an information security protection device for executing the above-mentioned information security protection method, the information security protection device comprising:

[0049] The program packet capture processing module is used to obtain the firewall log file; based on the firewall log file, the abnormal behavior traffic is captured to obtain the abnormal behavior traffic; based on the abnormal behavior traffic, the abnormal frequency program packet capture processing is performed to obtain the abnormal frequency program packet capture data set;

[0050] The verification avoidance code structure identification module is used to parse the session hijacking program based on the abnormal frequency program packet capture data set to obtain the session hijacking program analysis data; perform verification logic avoidance code structure identification on the session hijacking program analysis data to obtain the verification avoidance code structure data;

[0051] The session security protection strategy adjustment module is used to adjust the session security protection strategy based on the session hijacking program parsing data and the verification avoidance code structure data to obtain the session security protection strategy adjustment data.

[0052] Preferably, an electronic device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the information security protection method as described in any one of the above items is implemented.

[0053] The beneficial effect of the present invention is that, by collecting firewall log files, it is possible to deeply understand the potential abnormal behaviors in network traffic, especially the attackers implementing intrusions through specific patterns or traffic modes. On this basis, abnormal behavior traffic is captured to effectively identify potential malicious traffic patterns. By analyzing these abnormal traffic and capturing packets, an abnormal frequency program packet capture data set is generated to lay a data foundation for subsequent analysis. The key to this process is to accurately identify and capture the attack behavior, thereby providing an important basis for subsequent protection. Based on the abnormal frequency program packet capture data set obtained in the first step, it is possible to further analyze whether there is session hijacking behavior behind the traffic. By performing a detailed analysis of the packet capture data, it is possible to identify the existing session hijacking program, that is, the behavior of the attacker using session information for malicious control. Next, the session hijacking program parsing data is verified to avoid the identification of the code structure, and the code technology used by the attacker can be accurately captured, such as forging requests, bypassing authentication and other means. This step helps to understand the attack mode more deeply, discover the means by which the attacker avoids protection, and provide support for formulating countermeasures. After identifying and parsing the potential session hijacking behavior and the avoidance code structure in the first two steps, it is necessary to adjust the existing session security protection strategy according to this information. This policy adjustment includes enhancing defense measures against hijacking attacks, such as strengthening session token verification, setting a strict session timeout mechanism, encrypted transmission, etc. At the same time, for the identified verification circumvention code, the verification logic can be optimized and an additional layer of protection can be added to prevent attackers from circumventing protection by modifying request or session information. Through this policy adjustment, session security can be effectively improved, further attack behaviors can be prevented, and the overall protection capability of the system can be improved. Therefore, the present invention is an optimization processing of a traditional information security protection method, which solves the problem that a traditional information security protection method has large errors in identifying abnormal code attacks and weak information security protection capabilities, reduces the errors in identifying abnormal code attacks, and improves the information security protection capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 A schematic diagram of a process flow of an information security protection method;

[0055] Figure 2 for Figure 1 Detailed implementation steps of step S2 in the flowchart;

[0056] Figure 3 for Figure 1 Detailed implementation steps of step S3 in FIG. DETAILED DESCRIPTION

[0057] The technical method of the present invention is described clearly and completely below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by technicians in this field without creative work are within the scope of protection of the present invention.

[0058] In addition, the accompanying drawings are only schematic illustrations of the present invention and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor methods and / or microcontroller methods.

[0059] It should be understood that, although the terms "first", "second", etc. may be used herein to describe various units, these units should not be limited by these terms. These terms are used only to distinguish one unit from another unit. For example, without departing from the scope of the exemplary embodiments, the first unit may be referred to as the second unit, and similarly the second unit may be referred to as the first unit. The term "and / or" used herein includes any and all combinations of one or more of the listed associated items.

[0060] To achieve this, please refer to Figures 1 to 3 , an information security protection method, the method comprising the following steps:

[0061] Step S1: Obtain a firewall log file; capture abnormal behavior traffic based on the firewall log file to obtain abnormal behavior traffic; perform abnormal frequency program packet capture processing based on the abnormal behavior traffic to obtain an abnormal frequency program packet capture data set;

[0062] Step S2: parsing the session hijacking program based on the abnormal frequency program packet capture data set to obtain session hijacking program parsing data; performing verification logic avoidance code structure identification on the session hijacking program parsing data to obtain verification avoidance code structure data;

[0063] Step S3: adjusting the session security protection strategy based on the session hijacking program parsing data and the verification avoidance code structure data to obtain session security protection strategy adjustment data.

[0064] In the embodiment of the present invention, reference Figure 1 FIG. 1 is a schematic diagram of a process flow of an information security protection method of the present invention. In this example, the information security protection method includes the following steps:

[0065] Step S1: Obtain a firewall log file; capture abnormal behavior traffic based on the firewall log file to obtain abnormal behavior traffic; perform abnormal frequency program packet capture processing based on the abnormal behavior traffic to obtain an abnormal frequency program packet capture data set;

[0066] In the embodiment of the present invention, it is first necessary to obtain the original log file from the firewall. These log files usually contain detailed records of network traffic, including source IP, target IP, port, protocol type, timestamp and other information. After obtaining these log files, abnormal behavior traffic is captured. This process first needs to perform statistical analysis on the traffic based on certain threshold standards (such as number of connections, connection interval, etc.) according to the traffic characteristics, and mark the part with abnormal characteristics in the traffic. For example, if the connection request frequency of a certain IP increases abnormally within a certain period of time, or the request frequency of a certain port is too concentrated, it can be regarded as potential abnormal behavior. At this time, according to the set standards (such as the number of connections exceeds the threshold, the request frequency exceeds the normal value, etc.), the records that meet the abnormal traffic characteristics are captured and extracted. Next, it is necessary to perform abnormal frequency program packet capture processing. By further processing the captured data of these abnormal behavior traffic, a packet capture data set that does not conform to the normal traffic pattern in the network can be obtained. This data set is called "abnormal frequency program packet capture data set". During the packet capture process, you can use network packet capture tools (such as Wireshark) to perform detailed analysis on the data packets and extract key features of abnormal traffic, such as the transmission timing and content of the data packets, to further confirm the abnormality of the traffic and classify it.

[0067] Step S2: parsing the session hijacking program based on the abnormal frequency program packet capture data set to obtain session hijacking program parsing data; performing verification logic avoidance code structure identification on the session hijacking program parsing data to obtain verification avoidance code structure data;

[0068] In the embodiment of the present invention, the session hijacking program is first parsed based on the "abnormal frequency program packet capture data set" obtained from step S1. This process identifies the program code segment containing the session hijacking attack through in-depth analysis of the packet capture data. Session hijacking attacks usually disguise themselves as legitimate users by forging or tampering with session IDs, so it is necessary to fully extract and parse the session information (such as cookies, session IDs, etc.) in the packet capture data to further find out whether there are signs of tampering or forgery. In the parsing process, a traffic parsing algorithm, such as a session-based timing analysis method, is used to gradually track the sessions with hijacking behavior in combination with the life cycle characteristics of the data packet. If an abnormal behavior pattern is found in the session, such as the jump of the session identifier, frequent authentication requests, etc., it can be determined as a session hijacking behavior. After completing the preliminary parsing of the session hijacking program, the verification logic circumvention code structure identification is performed next. Session hijacking attackers usually use some code structures that circumvent the verification mechanism, such as forging verification codes, bypassing multi-factor authentication, etc., to attack. At this time, it is necessary to further identify the structure of the circumvention verification mechanism in the code based on the parsed session hijacking program. During this process, static analysis technology is used to parse the authentication and verification codes in the session hijacking program to find abnormal control flow or circumvention logic, and then identify potential security vulnerabilities or attack paths.

[0069] Step S3: adjusting the session security protection strategy based on the session hijacking program parsing data and the verification avoidance code structure data to obtain session security protection strategy adjustment data.

[0070] In an embodiment of the present invention, the session security protection strategy is adjusted based on the session hijacking program parsing data and verification avoidance code structure data obtained in step S2. First, these data need to be input into a protection strategy adjustment module, which will adjust the existing session security protection strategy based on the analyzed attack features. In this process, the attack link is first analyzed to determine the various stages of the attack and its security vulnerabilities. For example, if the session hijacking attack mainly attacks by transmitting session information through unsafe cookies, the protection strategy can be enhanced for the security of cookies, such as encrypting cookies with encryption algorithms, or adding stricter verification mechanisms to cookies. Next, based on multi-dimensional penetration identification, further analyze which channels the session hijacking attack breaks through the protection layer. Penetration analysis can perform a comprehensive inspection of different attack paths by simulating attacks, thereby identifying existing vulnerabilities. Finally, based on the analysis results of these attack paths, the session security protection strategy is adjusted in a targeted manner, such as strengthening session timeout control, increasing authentication methods, enabling HTTPS encryption and other measures to further enhance the security of the session. The adjustment of these strategies needs to be based on a comprehensive understanding of attack patterns, vulnerability characteristics, and protection mechanisms, combined with a detailed analysis of data traffic to ensure the targeting and effectiveness of each protection measure.

[0071] Step S1 includes the following steps:

[0072] Step S11: Obtain firewall log files;

[0073] Step S12: Analyze the frequency of abnormal connection requests according to the firewall log file to obtain the frequency of abnormal connection requests;

[0074] Step S13: capturing abnormal behavior traffic based on the abnormal connection request frequency to obtain abnormal behavior traffic;

[0075] Step S14: performing abnormal frequency program packet capture processing on the abnormal connection request frequency according to the abnormal behavior traffic to obtain an abnormal frequency program packet capture data set.

[0076] In an embodiment of the present invention, it is first necessary to obtain a log file from a firewall device or a firewall management platform. The firewall usually records network traffic logs including source IP, target IP, protocol type, port number, timestamp, etc. By configuring a log generation policy in the firewall, various types of information related to network security can be captured. In this embodiment, a log rotation mechanism is used to ensure the integrity and timeliness of the log. Whenever the log file size exceeds a predetermined value or reaches a set time interval (such as generating a log file every 24 hours), the system will automatically save the current log file and generate a new log file. The specific method of obtaining the log file is usually to download the log data from the management port or storage system of the firewall to ensure that the obtained log file contains all records of the system within the specified time period. The log content is obtained through a network transmission protocol (such as FTP or SFTP) or directly accessing the file storage system of the firewall to ensure that it has not been tampered with or lost. The firewall log obtained in step S11 is preprocessed. This includes parsing the connection request data involved in the log file and extracting the key fields of each connection, such as the source IP address, target IP address, connection protocol, port number, and connection timestamp. Subsequently, according to the connection request frequency in the log, the frequency analysis method is used to detect abnormal connection requests. At this time, the time window analysis method is adopted. First, a time window is defined (for example, one window per minute or hour), and the number of connections of the source IP to the target IP is counted in each time window, and the connection frequency in the time period is recorded. On this basis, statistical methods (such as standard deviation method, percentile-based outlier detection, etc.) are used to identify those source IP addresses whose connection request frequencies are significantly deviated from the normal state. These high-frequency or frequently changing connection requests are very indicative of abnormal behavior, especially on certain sensitive ports (such as port 22, port 80, port 443, etc.). If the request frequency of a source IP is significantly higher than that of other source IPs or exceeds a predetermined threshold in the same time window, it is regarded as an abnormal connection request. Through this frequency analysis method, connection requests with potential attack risks can be preliminarily screened out. Based on the abnormal connection request frequency data identified in step S12, abnormal behavior traffic is captured. First, by matching the frequently connected source IP and target IP, the traffic with attack behavior is screened out. Use a rule-based traffic filtering method to separate the traffic of these abnormal source IPs from normal traffic. Then, use traffic capture devices (such as IDS / IPS systems) or traffic monitoring tools to conduct in-depth analysis of the traffic of these abnormal source IPs. Specifically, it is necessary to combine the three-way handshake process of the TCP connection, perform detailed traffic marking and analysis on the traffic, and record the source, destination, protocol type, packet size, frequency and other characteristics of the abnormal traffic.In addition, to ensure that the captured traffic data is not missed, it is also necessary to set a suitable traffic capture threshold to ensure that each abnormal traffic record can be captured in the case of high-frequency requests. After the traffic is captured, the relevant traffic data is saved to a packet capture file, which is usually in the format of a PCAP file. Subsequently, these packet capture files are further analyzed to determine whether there is abnormal behavior, for example, whether there are too many attempts to connect, abnormal protocol usage, or abnormal data transmission. Based on the abnormal behavior traffic obtained in step S13, the packet capture process of the abnormal frequency program is further performed. First, a deep analysis of the traffic data is performed for the abnormal traffic that has been captured. During the analysis process, the captured data packet is first decoded to extract various types of information therein, such as IP header, transport layer protocol, data content, etc. By carefully checking the source IP address, destination IP address, port number, and protocol type in the data packet header, it is confirmed whether there are frequent connection attempts, especially high-frequency connection requests in a short period of time. Next, the time interval and connection mode of each connection request are analyzed using a timestamp-based traffic analysis method. If it is found that some IP sources or targets frequently initiate connection requests, and the time interval is shorter than the normal threshold, or the same IP source frequently requests connections in different time periods, it can be regarded as abnormal behavior. At this time, these data packets are marked as "abnormal frequency program packet capture data set" for subsequent analysis. For these abnormal data packets, the system will record detailed information such as the time of each connection request, data packet content, traffic pattern, etc., and generate a packet capture data set based on the frequency pattern. These packet capture data sets will be further used for subsequent security protection strategy adjustments and in-depth analysis to ensure that attack behaviors or vulnerabilities can be effectively identified.

[0077] Step S2 includes the following steps:

[0078] Step S21: Analyze the abnormal IP address change trajectory on the abnormal frequency program packet capture data set to obtain the abnormal IP address change trajectory;

[0079] Step S22: Identify the session attack target based on the abnormal IP address change trajectory and abnormal frequency program packet capture data set to obtain the session attack target;

[0080] Step S23: performing session hijacking program analysis on the session attack target based on the abnormal frequency program packet capture data set to obtain session hijacking program analysis data;

[0081] Step S24: performing verification logic avoidance code structure identification on the session hijacking program parsing data to obtain verification avoidance code structure data.

[0082] As an example of the present invention, refer to Figure 2 As shown, in this example, step S2 includes:

[0083] Step S21: Analyze the abnormal IP address change trajectory on the abnormal frequency program packet capture data set to obtain the abnormal IP address change trajectory;

[0084] In an embodiment of the present invention, a detailed analysis is performed on the abnormal frequency program packet capture data set to identify the abnormal change trajectory of the IP address in multiple connection requests. In order to achieve this goal, the source IP and target IP addresses and their change rules can be extracted by parsing the IP field in the packet capture data. First, each data packet is sorted based on the timestamp, and each connection request is arranged in chronological order. The change of the IP address is recorded in each connection request. If the same source IP address is frequently changed to different target IP addresses in different time periods, or the correlation between the source IP and the target IP addresses changes abnormally, it can be considered that there is an abnormal change trajectory. This abnormal IP address change usually indicates that the attacker disguises or hijacks the session through different network paths. In the actual implementation process, the sliding time window algorithm is used to detect the IP address change. Assume that a time window is set, for example, every 10 seconds is a window, and the number of different target IP addresses connected to a certain source IP address in the time window is counted. If it exceeds a preset threshold (such as 3 target IP addresses), it is considered that the IP address change is abnormal. On this basis, the trajectory analysis algorithm is used to analyze the change trajectory of each source IP address and record all change histories of each source IP address. By drawing a change trajectory diagram, we can further identify whether there is abnormal behavior. If the frequency of IP address changes is significantly higher than the normal level, it will be marked as an abnormal IP address. Finally, based on these change trajectory data, we can get the abnormal change trajectory of IP addresses, which can be further used as input data for subsequent session attack target identification.

[0085] Step S22: Identify the session attack target based on the abnormal IP address change trajectory and abnormal frequency program packet capture data set to obtain the session attack target;

[0086] In an embodiment of the present invention, the session attack target is identified by combining the abnormal change trajectory of the IP address extracted in step S21 with the abnormal frequency program capture data set. The specific implementation method is to first filter out all source IPs with frequent IP address changes from the abnormal IP change trajectory obtained in step S21, and associate these source IPs with the abnormal frequency program capture data set obtained in step S14. For each source IP, if it has abnormal frequency connection requests in multiple time periods, and the target IPs of these connection requests have large differences or frequent changes, it indicates that the source IP is attempting to perform session hijacking or other malicious behaviors. Through further analysis of the abnormal frequency program capture data, the number of visits and time distribution of the target IP address are extracted, and combined with the abnormal change trajectory of the source IP address, the connection mode between the source IP and the target IP can be tracked by building a session chain. If the source IP frequently changes the target IP in a short period of time, and the access mode of the target IP is also inconsistent with the normal connection, it can be inferred that the source IP has performed session hijacking on the target IP. At this point, using time series analysis and graph model construction, the identification of session attack targets can be confirmed by detecting abnormally high-frequency connections between source IP and target IP. All IP addresses suspected of being session attack targets are aggregated to obtain session attack targets.

[0087] Step S23: performing session hijacking program analysis on the session attack target based on the abnormal frequency program packet capture data set to obtain session hijacking program analysis data;

[0088] In an embodiment of the present invention, based on the session attack target identified in step S22, a session hijacking program needs to be parsed. Session hijacking is usually manifested as tampering with or controlling identifiers (such as session IDs, verification tokens, cookies, etc.) in a communication session, so that an attacker can impersonate a legitimate user to access. Therefore, it is first necessary to extract all session information related to the target IP address from the abnormal frequency program packet capture data set in step S14, especially the identity authentication data, session identifiers, tokens, and traffic control packets. Next, these data packets are parsed to identify whether there are traces of hijacking behavior. Specifically, by checking the TCP connection identifier, session ID, sequence number and other information in the data packet, it can be confirmed whether the session between the source IP and the target IP has been illegally tampered with or reused. This process involves analyzing the life cycle of each connection session. From connection establishment, data transmission to connection disconnection, by comparing the normal session process with the abnormal session process, it is further confirmed whether there are signs of session hijacking. For example, if a source IP pretends to be a victim in a legitimate session of the target IP, the connection request it sends will carry a forged session ID, or there will be a maliciously tampered session identifier. By comparing the TCP sequence number and session identifier in each data packet, it is possible to identify whether there is any inconsistent behavior, thereby analyzing the specific procedures and behaviors of session hijacking.

[0089] Step S24: performing verification logic avoidance code structure identification on the session hijacking program parsing data to obtain verification avoidance code structure data.

[0090] In an embodiment of the present invention, the session hijacking program parsing data is further identified to identify the verification logic circumvention code structure. Session hijacking programs usually use certain circumvention techniques, such as injecting malicious code into legitimate requests or circumventing verification mechanisms in a dynamic manner. To identify these circumvention codes, it is first necessary to obtain the program data of the session hijacking from step S23 and analyze the code structure therein. Through the static code analysis method, check whether there is logic to bypass identity authentication in the program, such as forging user credentials, tampering with session IDs, etc. In specific implementation, the abstract syntax tree (AST) analysis technology is used to convert the instructions and control flows in the program into a tree structure, which is convenient for detecting and identifying the circumvention logic therein. In particular, when identifying the circumvention code structure, special attention should be paid to those code segments involving conditional branches, identity authentication skipping, encryption cracking, etc. By comparing the normal session processing flow with the code structure in the hijacked session, those code blocks that bypass verification by special means are identified. For example, if an encryption algorithm is used in a certain code segment, but its key is hard-coded, or the normal verification process is bypassed, the code segment can be identified as malicious logic to circumvent verification. In addition, regular expressions can be used to search for common feature strings that bypass verification in the program to identify malicious circumvention code. Finally, verification circumvention code structure data is obtained to provide a basis for the formulation of subsequent protection strategies.

[0091] Step S23 includes the following steps:

[0092] Step S231: extracting session target state attribute elements from the session attack target to obtain session target state attribute elements; wherein the session target state attribute elements include cookies, session ID and URL parameters;

[0093] Step S232: Based on the abnormal frequency program packet capture data set, abnormal code element injection identification is performed on the session target state attribute element to obtain element injection abnormal code data;

[0094] Step S233: quantifying the multiple parameter injection risks of the URL parameters in the session target state attribute element according to the element injection abnormal code data to obtain multiple parameter injection risk quantification data;

[0095] Step S234: performing session hijacking program analysis on the session attack target based on the element injection abnormal code data and the multiple parameter injection risk quantification data to obtain session hijacking program analysis data.

[0096] In the embodiment of the present invention, the state attribute elements of the session attack target are extracted, mainly including three important elements: cookie, session ID and URL parameters. The state information of the session attack target is usually stored in the header and URL of the HTTP request and response. By parsing the captured packet data, all key elements related to session management can be extracted, especially in the cookie field, URL parameter and session ID of the HTTP request. When extracting these elements, firstly, by analyzing the HTTP header of each data packet, find the relevant fields of cookie and session ID, and record each session identifier therein. For URL parameters, regular expression technology is used to extract all query parameters from the URL in the HTTP request. Since the URL parameters contain session identifiers, user credentials or other sensitive information, special attention is paid to these parameters with identity authentication functions during extraction. The extraction process should not only pay attention to the plaintext session identifier, but also process the encoding format existing in the URL, such as URL encoding or Base64 encoding. For the extraction of cookies and session IDs, it is necessary to pay attention to the life cycle and update rules of these identifiers, such as whether the session ID is regularly updated during the session. In addition, the request and response timestamps of each session should also be extracted to facilitate subsequent abnormal behavior analysis. Finally, the obtained session target state attribute elements include cookies, session IDs, and URL parameters, which provide basic data for subsequent injection identification and risk quantification. Based on the session target state attribute elements extracted in step S231, abnormal code element injection is identified. Injection attacks usually insert malicious code into the state attribute elements of HTTP requests (such as cookies, session IDs, and URL parameters) in an attempt to tamper with session information or bypass verification mechanisms. First, parse each request in the abnormal frequency program capture data set to check whether it contains abnormal code elements. For cookies and session IDs, check whether their formats conform to normal session identifier rules, such as whether they contain malicious characters or script code, for example <script>...< / script> For URL parameter injection detection, regular expression technology can be used to identify whether it contains illegal scripts, SQL injection, command injection and other malicious codes. By matching with known injection attack feature libraries, such as common SQL injection keywords (such as 'OR 1=1) or JavaScript injection (such as ), which can effectively identify whether there is an injection attack. This process can scan all state attribute elements in each request, analyze whether they are consistent with known attack patterns, and mark elements containing malicious code. If suspected malicious code is found in cookies, session IDs or URL parameters, it is marked as injected abnormal code data as a basis for subsequent analysis and protection strategies. For the element injection abnormal code data identified in step S232, a quantitative analysis of the multiple parameter injection risk of URL parameters is performed. The core purpose of the quantification of multiple parameter injection risks is to evaluate the degree of risk to session security when multiple URL parameters are subjected to injection attacks. In this process, it is first necessary to analyze the characteristics of each URL parameter injected by abnormal code, including their type, format, and whether there is a mutual influence after multiple parameter combinations. The risk assessment model is used to quantify the risk of each URL parameter. First, a preliminary risk value is assigned to each type of injection attack through historical data and known attack characteristics. For example, the risk of SQL injection and XSS injection is higher, while simple parameter tampering has a lower risk. Then, the interaction between each URL parameter and other parameters is calculated. If multiple injection parameters appear in the request at the same time and their attack types can cooperate with each other, the risk will be doubled. At this time, a weighted scoring model is applied to quantify and score these parameters, taking into account the type, frequency, correlation between parameters and complexity of the injected code. Finally, multiple injection risk quantification data of each URL parameter is obtained as a key basis for evaluating the session hijacking program. The session hijacking program is parsed by combining the element injection abnormal code data obtained in step S232 with the multiple parameter injection risk quantification data obtained in step S233. The session hijacking program usually uses injected malicious code to tamper with or hijack session state elements (such as cookies, sessionID and URL parameters) to impersonate legitimate users for malicious access. In order to effectively parse these hijacking behaviors, it is first necessary to comprehensively analyze the element injection abnormal code data and the multiple parameter injection risk quantification data to identify whether there is a high-risk injection behavior. Based on these data, by establishing a session hijacking model, the malicious access process after the session state element is tampered with can be simulated to further confirm whether there is a hijacking behavior. For example, if the session ID in the URL parameter is tampered with and matches the abnormal code injection, it means that the attacker has used the parameter to steal session information. By comparing the traffic patterns of normal sessions with the traffic injected into the attack, the specific operations of the hijacking program can be revealed, and the attacker's attack path, attack method, and potential targets can be analyzed. Finally, through the comprehensive analysis of these parsed data, it is determined whether the session has been hijacked, and the protection strategy is adjusted according to the identified attack pattern to ensure that the security of the session is effectively protected.

[0097] Step S233 includes the following steps:

[0098] Perform code execution logic analysis on element injected abnormal code data to obtain abnormal code execution logic;

[0099] Marking the URL parameter in the session target state attribute element with a key parameter variable to obtain a URL key parameter variable;

[0100] According to the abnormal code execution logic, the abnormal variable manipulation of the URL key parameter variables is identified to obtain the abnormal variable manipulation code;

[0101] Define the scope exception level for the abnormal variable manipulation code and obtain the scope exception level data;

[0102] Based on the scope exception level data, the code execution exception life cycle is analyzed for the exception variable manipulation code to obtain the code execution exception life cycle;

[0103] Based on the code execution exception life cycle and scope exception level data, the abnormal variable manipulation code is identified with abnormal modification hidden logic branches to obtain abnormal modification hidden logic branches;

[0104] Based on the abnormal modification of hidden logic branches, the abnormal life cycle of code execution and the abnormal variable manipulation code, the risk quantification of multiple parameter injections is performed to obtain the quantitative data of multiple parameter injection risks.

[0105] In the embodiment of the present invention, it is first necessary to conduct an in-depth code execution logic analysis on the element injection abnormal code data obtained from step S232. The key to this process is to analyze whether the injected code can be executed by the server and the abnormal behavior caused by the execution. The first step of the analysis is to identify the type of malicious code based on common injection attack methods (such as SQL injection, XSS injection, command injection, etc.). For example, in SQL injection, the injected code often contains commands such as "OR 1=1" or "DROPTABLE"; in XSS injection, the code contains JavaScript fragments such as <script>alert('XSS')< / script>. Next, analyze the execution path and whether it can bypass conventional security protection mechanisms by parsing these codes. For each suspicious code, check whether it can affect the core data of session management, such as cookies or session IDs, when it is executed. This step can use static analysis technology to check the code structure line by line, and identify its potential execution logic in combination with known attack patterns. In addition, it is necessary to analyze whether these malicious codes will be triggered only under specific conditions (for example, at a specific time or under specific conditions) to provide guidance for subsequent protection strategies. Mark the URL parameters in the session target state attribute element as key parameter variables. The purpose of this step is to identify parameters in the URL that are critical to session security, such as session_id, user_token, auth_key, etc. These parameters often contain user authentication information or session identifiers and are the targets of injection attacks by attackers. First, extract all query parameters from the URL through regular expressions and analyze which parameters are related to session management. For each parameter, check whether it is an authentication parameter, such as session identifiers, login credentials, etc., and mark these parameters as "key parameters". After marking the key parameters, record their frequency of occurrence, type, and relationship with other parameters. For URL parameters containing session information, special attention should be paid to their update mechanism and transmission method. For example, if the session ID in the parameter is updated in each request, this parameter is critical to session security, while if the parameter is not updated or appears repeatedly, it is a target of injection attack. In this way, each parameter in the URL is marked to provide data support for subsequent anomaly identification and risk quantification. Through a combination of static and dynamic analysis methods, it is possible to identify whether there is unauthorized tampering during transmission. For example, in the case of SQL injection, characters such as "' OR 1=1 --" will be seen in the URL parameters, indicating that the attacker is trying to bypass authentication by manipulating the parameters. If the parameter value in the URL does not match the server processing logic or does not meet expectations, the parameter is considered to be manipulated. Further analysis can be carried out through reverse engineering technology to identify the details of these manipulation behaviors, including debugging the server response, checking whether the returned HTTP status code is normal, and whether there are abnormal phenomena such as permission overstepping and identity tampering. By analyzing the abnormal variable manipulation code identified in the previous step, the scope abnormal level is defined. The purpose of the scope abnormal level definition is to determine the scope and level of its impact by analyzing the context of abnormal variable manipulation. First, analyze the scope of the injected malicious code in the session, including whether it is limited to a certain request, or can affect multiple requests, multiple sessions, or multiple system modules.If the malicious code is limited to a single request, the risk is low; if the malicious code can spread across sessions or modules, the risk should be considered high. Furthermore, by tracing the execution path of abnormal variable manipulation, it can be associated with other components in session management (such as authentication, authorization, encryption, etc.). If the malicious code is found to have an effect at different stages of the session and can have an impact at multiple levels (such as client, server, database, etc.), it can be judged that the attack is an advanced attack with high harm. The data record of the scope abnormal level can provide a basis for subsequent risk assessment and adjustment of protection strategies. Based on the scope abnormal level data, the execution life cycle analysis of the abnormal variable manipulation code is performed. The goal of code execution life cycle analysis is to evaluate the entire process of malicious code from injection to execution and then disappearance, so as to identify whether the code has a continuous impact on session security during execution. Through backtracking analysis, how the malicious code spreads during the request process and observes its behavior patterns during the life cycle. Specifically, each key event (such as parameter manipulation, server response, etc.) is first marked with a timestamp, and then the various stages of its life cycle are determined according to the propagation path of the abnormal code, including the injection stage, execution stage, and result stage. If the malicious code can still maintain control over the session or application at multiple stages of the life cycle, it indicates that the attack has a long-term risk and requires special attention. By analyzing the code life cycle, the root cause of the attack can be revealed, which code segments pose a threat to session management, and the subsequent attack path can be predicted. At this point, by comparing with the normal life cycle, the persistence and impact range of the abnormal behavior can be effectively judged. According to the code execution abnormal life cycle and scope abnormal level data, the abnormal variable manipulation code is abnormally modified to identify hidden logical branches. The core of this process is to find out the logical branches hidden by the attacker through malicious code, especially the logical jumps caused by controlling variables or modifying session data. In session hijacking and injection attacks, attackers usually hide malicious behavior by tampering with key variables in the session to avoid detection. In order to identify these hidden logical branches, it is first necessary to combine the analyzed abnormal life cycle with the scope level data, track the changes of variables in the program flow, and analyze whether they trigger undisclosed logical paths in the program. Through code auditing technology, it is possible to find out how malicious code bypasses verification by modifying key parameters and enters abnormal code branches. For example, by manipulating the session ID in the URL, an attacker can cause the server to enter an unexpected logical branch, thereby circumventing protection measures. These hidden branches are eventually identified and recorded as an important basis for subsequent adjustments to protection measures. Based on the identified abnormal modification of hidden logical branches, abnormal code execution life cycle, and abnormal variable manipulation code, multiple parameter injection risks are quantified.The core of multi-parameter injection risk quantification is to evaluate the comprehensive risk brought by injection attacks based on the complexity, life cycle and impact scope of the identified malicious behaviors. Through comprehensive analysis of multiple related parameters, the risk level brought by each attack is quantified. For the combination of multiple malicious parameters, a weighted algorithm is used to calculate the final risk score based on their scope of action, life cycle and complexity of hidden logic branches. This risk score will be weighted according to factors such as the type of injected code, the interaction of malicious parameters and the persistence of the life cycle, so as to obtain multi-parameter injection risk quantification data. This data can be used as a basis for subsequent session protection and anomaly detection strategy adjustments, helping to identify high-risk attack scenarios and take corresponding protective measures.

[0106] Step S24 includes the following steps:

[0107] Step S241: performing program code control flow analysis on the session hijacking program parsing data to obtain a program code control flow graph;

[0108] Step S242: Decompile the attack call behavior of the session hijacking program parsed data according to the program code control flow graph to obtain code attack call behavior decompilation data;

[0109] Step S243: Based on the code attack call behavior decompilation data, the session hijacking program parsing data is subjected to underlying code vulnerability identification to obtain underlying code vulnerability data;

[0110] Step S244: performing attack vector construction analysis on the decompiled data of the code attack call behavior to obtain code attack vector construction data;

[0111] Step S245: performing race condition analysis based on the code attack vector construction data to obtain code attack vector race condition data;

[0112] Step S246: performing verification logic avoidance code structure identification according to the code attack carrier race condition data and the underlying code vulnerability data to obtain verification avoidance code structure data.

[0113] In an embodiment of the present invention, the program code control flow analysis is performed on the session hijacking program parsing data to obtain the program code control flow graph. The goal of the program code control flow analysis is to identify the different execution paths that the session hijacking program passes through during the execution process and draw its control flow graph. First, the code logic contained in the session hijacking program parsing data is extracted, especially the conditional judgment, loop structure, function call, etc. Through static analysis, each statement in the code is interpreted line by line, and its execution order is recorded. On the execution path, if a conditional judgment statement is encountered, it is necessary to determine which conditions will change the execution path of the program, and draw different paths according to different conditional branches. When constructing the control flow graph, the main focus is on the specific paths in the program that cause the attack. By analyzing these paths, potential attack points can be identified, especially those paths that the attacker can change by controlling input or environmental conditions. For example, if there is a path in the control flow graph that skips the verification check, the path is the attacker's utilization point. In addition, the function call part in the program should also be analyzed in detail because these calls trigger specific logic related to session hijacking. Through this process, the generated control flow graph can help analyze the execution process of the program, identify all vulnerability paths, and provide data support for the subsequent attack behavior decompilation. According to the program code control flow graph, the attack call behavior is decompiled for the parsed data of the session hijacking program. The goal of attack call behavior decompilation is to reversely deduce the attack behavior pattern from the execution process of the session hijacking program. First, according to the control flow graph obtained in step S241, the relationship between each execution path and the function call is analyzed to identify the key call used by the attacker. By checking the parameters passed during the function call, it is determined which functions have vulnerabilities in processing key links such as user input and session management. Then, the disassembly technology is used to convert the binary code in the session hijacking program into assembly language, and then the assembly code is analyzed to find out the malicious call pattern therein. During the decompilation process, special attention should be paid to the input verification part in the program and the code fragments of data transmission, because these parts usually involve the key links of the session hijacking attack. For example, after decompilation, it can be found whether the attacker uses a specific function to inject malicious data, modify session parameters or perform other malicious operations. In addition, symbolic execution technology can be used to automatically explore program code paths, analyze the potential offensiveness of each path, and ultimately obtain decompiled attack call behavior data. This data provides detailed information for identifying attack patterns and discovering potential vulnerabilities. Based on the decompiled data of code attack call behavior, the session hijacking program parsing data is used to identify underlying code vulnerabilities. The purpose of identifying underlying code vulnerabilities is to find code vulnerabilities that attackers can exploit, thereby gaining a deeper understanding of the weaknesses of the session hijacking program. First, by analyzing the decompiled attack call behavior data and combining it with static analysis tools, a comprehensive inspection of the program is performed to find the input and output points that can be manipulated by attackers.Pay special attention to low-level operations such as user input validation, memory management, and resource access, because these parts are easy to become a breakthrough for attacks. By checking the underlying code, the following types of vulnerabilities are mainly identified: buffer overflow, uninitialized memory access, lax permission control, insufficient input validation, etc. Use static analysis tools to scan the decompiled code for vulnerabilities to detect whether there are obvious errors or design flaws. For example, if the program fails to correctly validate the input data type or length, the attacker can control the program behavior or tamper with the session information by sending malicious input. Through further analysis of the vulnerability, the specific path used by the attacker can be identified, and data support can be provided for the subsequent attack vector construction analysis. Perform attack vector construction analysis on the decompiled data of the code attack call behavior. The purpose of attack vector construction analysis is to identify the vector used by the attacker and determine how to construct the attack vector to achieve the purpose of hijacking the session. The attack vector usually refers to the code part used to deliver malicious code or manipulate the session in the attack, usually including malicious scripts, input data in a specific format, malicious links, etc. Through in-depth analysis of the decompiled code attack call behavior data, determine which input or behavior can be used as an attack vector. Specifically, we first analyze how the program accepts external inputs and how these inputs affect the behavior of the program. If an attacker can manipulate these inputs, they can trigger program vulnerabilities by constructing input data in a specific format. The construction of attack vectors is not just through simple malicious inputs, but also involves the use of specific network requests, file uploads, database queries and other technical means. Through this analysis, attack vectors can be constructed, such as carefully constructed malicious URLs, specially crafted POST packets, or input content containing malicious scripts. This analysis can help identify how attackers can successfully hijack sessions through these vectors. Based on the code attack vector construction data, race condition analysis is performed to obtain code attack vector race condition data. The purpose of race condition analysis is to identify the race conditions generated by the attack vector during execution with other processes or operations, and analyze how these race conditions affect the execution results of the program. Race conditions occur when multiple processes or threads try to access shared resources in an inconsistent manner. In a session hijacking attack, race conditions can cause the execution order of the attack vector to be inconsistent with expectations, thereby bypassing normal security protection mechanisms. When analyzing race conditions, you first need to identify the concurrently executed code blocks in the session hijacking program, especially those that handle user input, session verification, data access, etc. By checking the execution order of these parts, determine whether there are potential race conditions. For example, an attacker will use race conditions to affect the state of the program by manipulating input data at a certain moment in the program, thereby achieving the purpose of session hijacking. Through accurate race condition analysis, it can reveal how attackers use race conditions at specific times to achieve their attack goals, and generate race condition data to provide a basis for subsequent protection measures.Verification logic circumvention code structure identification is performed based on the code attack vector race condition data and the underlying code vulnerability data. The goal of verification logic circumvention code structure identification is to analyze and identify the code structure in the program that is used by attackers to circumvent verification by combining race conditions and underlying vulnerabilities. Attackers usually bypass the verification logic in the program by cleverly constructing attack vectors to achieve malicious purposes. In this step, the verification logic that is circumvented in the program is identified by analyzing the underlying vulnerabilities and race condition data. The specific operation is to combine the race condition data with the underlying vulnerability data to analyze whether the program can skip or bypass the normal verification logic when encountering a race condition. Special attention is paid to those verification parts that rely on time sequence, external input or other non-deterministic factors. Through static and dynamic analysis, these logic vulnerabilities are identified and the attack path is drawn. Finally, the generated verification circumvention code structure data will provide a basis for subsequent protection strategies and help design effective protection measures to identify and prevent such attacks.

[0114] Step S242 includes the following steps:

[0115] Perform conditional jump analysis on the program code control flow graph to obtain program code conditional jump data;

[0116] Perform function call static analysis on session hijacking program parsing data based on program code conditional jump data to obtain function call static data;

[0117] Perform reverse analysis of attack behavior code snippets on session hijacking program analysis data according to function call static data to obtain attack behavior code reverse analysis data;

[0118] Reverse-parse the attack behavior code data to identify the hijacking return address and obtain the hijacking return address data;

[0119] Reverse-analyze the attack behavior code data to identify the tampered call stack and obtain the tampered call stack data;

[0120] The attack call behavior is decompiled according to the hijacked return address data and the tampered call stack data to obtain the code attack call behavior decompilation data.

[0121] In an embodiment of the present invention, a conditional jump analysis is performed on a program code control flow graph, the purpose of which is to identify all conditional jump paths in a program through static analysis, and to determine potential risks in the program execution process based on these paths. When performing conditional jump analysis, all conditional statements in the program, such as control flow statements such as if, switch, for, while, etc., are first parsed. These control statements determine the execution path of the program according to different input data. By identifying these jump conditions, a complete control flow graph can be constructed, marking each branch path and its corresponding conditional logic. During the analysis process, it is necessary to pay attention to those conditional judgments that are closely related to external inputs, such as user-submitted data, network request parameters, etc. Attackers usually try to manipulate these inputs in order to force the program to a malicious path. By combining the program control flow graph with the input data, it is possible to reveal which conditional judgments become the entry point for the attack. For example, when the program checks the user's identity, if sufficient verification is not performed, the attacker skips the identity authentication through malicious input. Finally, based on all conditional jump paths, program code conditional jump data is generated, which provides a conditional basis for subsequent static analysis. Based on the program code conditional jump data obtained above, the session hijacking program parsing data is subjected to function call static analysis. The purpose of static analysis of function calls is to identify all function calls in the program and determine which function calls lead to potential attack behaviors based on the jump paths of the control flow graph. First, parse the function calls in the program to identify the function names, passed parameters, and return values. Focus on security-related functions such as session management, input validation, and permission control, especially those that interact directly with external data. During the analysis process, the function paths manipulated by the attacker are identified by combining the conditional jump data of the program code. For example, if a function fails to perform effective input validation under certain conditions, it is exploited by the attacker. Through static analysis tools, the calling process of each function is deeply checked, its execution path is analyzed, and whether there are vulnerabilities. Through this analysis, the potential dangerous functions in the program can be identified, and these function call paths are recorded to generate function call static data to provide support for the subsequent reverse analysis of attack behaviors. Based on the function call static data obtained above, the attack behavior code snippet is reversely parsed for the session hijacking program parsing data. The purpose of reverse parsing the attack behavior code snippet is to identify the code snippet related to the attack behavior from the program and analyze how it is executed in the program. Through static analysis tools, first locate all external inputs, network requests, session states, and other information involved in function calls. Then, track how these inputs affect the behavior of the program, especially those that affect session states, skip authentication, or tamper with data. During the reverse analysis process, focus on analyzing those abused code snippets, such as the processing of illegal inputs, memory management errors, and permission vulnerabilities.Attackers usually try to trigger vulnerabilities by manipulating function inputs, injecting malicious data, or constructing specific attack vectors. By identifying these attack behavior code snippets, we can analyze how attackers exploit code defects to break through the program's security defenses. Finally, the generated attack behavior code reverse parsing data can provide detailed information support for subsequent code analysis and vulnerability repair. The hijacked return address is identified for the attack behavior code reverse parsing data, with the goal of finding the return address manipulated by the attacker from the code reverse parsing data. The return address is usually stored in the program's stack frame and determines where the program jumps to after a function call. By tampering with the return address, the attacker can transfer the control of the program to the location of the malicious code or attack vector, achieving session hijacking or other types of attacks. When performing return address identification, first locate the pointer related to the function return address in the stack. Then, by analyzing the function call process in the code, especially in the stack operation part, identify which return addresses have been tampered with. Attackers can change the control flow of the program by overflowing the stack, modifying the data in the stack, or constructing specific inputs. By analyzing these attack paths, the return addresses that can be tampered with in the program are identified. The identified return address data will provide a key basis for subsequent stack tampering identification and help understand how attackers manipulate program execution. The purpose of identifying the tampered call stack by the attacker is to identify the call stack tampered by the attacker. The call stack is a memory structure maintained when the program is running, which records the currently executed functions and their call relationships. By tampering with the data in the call stack, the attacker can change the execution flow of the program and control the behavior of the program. In the process of tampering call stack identification, the stack frame operations of function calls and returns in the program are first analyzed, especially the operations at the call parameter passing and the return address at the top of the stack. Focus on analyzing how attackers use stack overflow, data tampering and other technologies to modify the return address or function pointer in the call stack. Through static analysis tools, identify the manipulated data in the stack and determine which function calls are maliciously tampered during the attack. Through this process, the tampered call stack data is obtained, which provides a basis for further vulnerability repair and protection. Based on the hijacked return address data and tampered call stack data obtained above, the attack call behavior is decompiled. The core goal of this process is to combine the previously identified return address and call stack tampering information to completely decompile the attack mode used by the attacker. By combining the hijacked return address data, we analyze how the attacker forces the program to jump to the malicious code area specified by the attacker by tampering with the stack frame or return address. During the decompilation process, we mainly focus on how the attacker uses the return address and call stack information to successfully bypass the program's verification logic, manipulate session data, or perform other malicious operations. By accurately identifying the attack behavior, detailed attack call behavior data can be generated, which provides important analysis basis for vulnerability repair, attack protection, and security strategy design.

[0122] Step S3 includes the following steps:

[0123] Step S31: performing attack link correlation analysis based on session hijacking program parsing data and verification avoidance code structure data to obtain a session hijacking attack link;

[0124] Step S32: Perform multi-dimensional penetration identification on the session hijacking attack link to obtain multi-dimensional penetration data of the session hijacking attack;

[0125] Step S33: adjusting the session security protection strategy based on the multi-dimensional penetration data of the session hijacking attack to obtain session security protection strategy adjustment data.

[0126] As an example of the present invention, refer to Figure 3 As shown, in this example, step S3 includes:

[0127] Step S31: performing attack link correlation analysis based on session hijacking program parsing data and verification avoidance code structure data to obtain a session hijacking attack link;

[0128] In the embodiment of the present invention, it is first necessary to conduct an in-depth analysis of the session hijacking program parsing data and the verification avoidance code structure data, the purpose of which is to reveal the complete path of the attack link through in-depth association of the attack behavior. The core of this step is to connect the independent attack elements in the session hijacking program into a complete attack chain through logical and temporal association. First, the attack behaviors in the session hijacking program parsing data are parsed, such as tampering with the session state, bypassing the session verification, and other operations. These behaviors are usually manifested as illegal modification of cookies, tampering with session IDs, injecting malicious URLs, etc. Then, using the verification avoidance code structure data, the verification bypass logic is analyzed to identify which steps play a key role in the attack chain, such as which functions or code segments are used to bypass identity authentication, skip permission control, etc. Based on these data, logical reasoning, control flow analysis, and path analysis methods are used to connect the various attack actions in the attack chain to form a complete attack chain. Specifically, by parsing the various branch paths in the control flow graph, it can be determined how the attacker gradually achieves session hijacking. In this process, it is necessary to use the shortest path algorithm in graph theory, or other path derivation algorithms, to ensure that each attack step can be clearly linked. Finally, through this analysis method, the complete session hijacking attack link data is obtained, which describes the starting point of the attack, the steps of the attack behavior and their interrelationships.

[0129] Step S32: Perform multi-dimensional penetration identification on the session hijacking attack link to obtain multi-dimensional penetration data of the session hijacking attack;

[0130] In an embodiment of the present invention, multi-dimensional penetration identification is performed on the session hijacking attack link data generated in step S31. This process is intended to deeply explore potential penetration points in the attack chain and identify various vulnerabilities exploited by attackers. First, each link in the attack chain is analyzed to identify links related to external input, network requests, user identity authentication, etc., which are usually the main targets of attackers for penetration. Through a method combining static analysis with dynamic behavior analysis, each link is reviewed in detail to evaluate the vulnerabilities therein. During static analysis, it is necessary to check the input validation and permission control in the session hijacking program, especially when the program fails to fully validate the user input, the attacker can inject malicious data or manipulate the request. During dynamic analysis, the attacker's behavior is simulated to reproduce each step in the attack chain to verify how the attacker achieves the purpose of controlling the session and bypassing the security mechanism through gradual penetration. For example, at a certain node in the session hijacking attack chain, the attacker captures an unencrypted session identifier through network sniffing or obtains sensitive data through SQL injection. At another node, the attacker hijacks the user's session state by tampering with the cookie value in the HTTP request. Based on these analyses, each penetration link in the attack chain can be identified and its degree of harm can be assessed, providing a basis for defense strategies.

[0131] Step S33: adjusting the session security protection strategy based on the multi-dimensional penetration data of the session hijacking attack to obtain session security protection strategy adjustment data.

[0132] In an embodiment of the present invention, the session security protection strategy is adjusted according to the multi-dimensional penetration data of the session hijacking attack obtained in step S32. The core of this process is to adjust and optimize the existing protection measures in real time according to the weaknesses in the identified attack chain to prevent potential attack behaviors. First, based on the penetration identification results, the existing session management mechanism is reviewed, including the storage method of cookies, the generation and verification method of session IDs, the transmission security of URL parameters, etc. If it is found that some links have security risks (such as unencrypted session identifiers, parameters that are easily tampered with, etc.), these links need to be reinforced. For example, a more complex encryption algorithm is used to encrypt the session identifier, or a more stringent verification mechanism is introduced to verify the legitimacy of the request. In addition, according to the multi-dimensional penetration data, the code of the application program needs to be modified to add more security checks and protection measures. For example, more input verification logic is added to prevent common attack methods such as SQL injection and XSS. Session hijacking can also be prevented by introducing a timestamp-based mechanism, or the expiration time of the session is increased to prevent attackers from performing malicious operations through long-unused sessions. In this process, it is also necessary to use risk assessment methods, such as probability-based models and decision trees, to optimize and adjust existing protection strategies to ensure that protection measures can cover all identified penetration points and effectively prevent potential attacks. Ultimately, the adjusted session security protection strategy data will provide a more complete protection layer for the defense system and reduce the probability of successful attacks. For example, in the multi-dimensional penetration identification process, it was found that a link in the session hijacking attack chain was to obtain an unencrypted session identifier (Session ID) through network sniffing, and then use the Session ID to implement session hijacking. In order to prevent such attacks, the TLS encryption mechanism can be introduced in session management to encrypt and transmit all session identifiers. The specific steps are as follows: Enable the HTTPS protocol and encrypt all HTTP requests and responses to ensure that the session identifier cannot be sniffed during transmission. Encrypt the Session ID not only during transmission, but also when storing it on the server. The Session ID can be encrypted using a symmetric encryption algorithm (such as AES) or an asymmetric encryption algorithm (such as RSA) to ensure that even if the attacker obtains the Session ID storage file on the server, the data cannot be directly used. With the dynamic SessionID mechanism, a new session identifier is generated each time a user requests a session, and the old Session ID is marked as invalid. In this way, even if an attacker obtains the old Session ID, the new Session ID has been activated and the attack cannot continue.In multi-dimensional penetration identification, it is found that attackers can achieve session hijacking or privilege escalation attacks by tampering with certain parameters in the URL (such as user_id, session_token). To this end, URL parameters can be strengthened in the session management strategy. The specific implementation method is as follows: All sensitive parameters related to the session (such as Session Token, user identifier, etc.) are encrypted and then placed in the URL. The encryption algorithm should ensure that the parameter values ​​of each request are not easy to be cracked or guessed. Timestamp-based encryption can be used to ensure that the parameters in each request are unique. Avoid transmitting sensitive data as URL parameters. URL parameters are easily obtained by attackers through browser logs, history records, or network sniffing. Therefore, sensitive information can be transmitted through the body part of the POST request instead of passing it through the URL. Set an expiration time for sensitive parameters in the URL, that is, each session or request is only valid for a certain period of time. After the expiration date, the attacker cannot use the URL parameter to continue session hijacking. Assume that in the multi-dimensional penetration analysis, it is found that during the session hijacking process, the attacker injects malicious SQL code or malicious JavaScript code (such as XSS attack) to perform illegal operations or tamper with session information. To this end, strict validation and filtering of user input is required. The specific implementation steps are as follows: All data received from the user side, whether through forms, URL parameters, or cookies, needs to be strictly input validated. For the data in the URL parameters, ensure that their format is as expected (for example, ensure that user_id is a positive integer, not a piece of malicious code). For the data submitted by the form, verify the length, character set, etc. to ensure that it does not contain SQL injection or XSS attack code. Escape and filter the data entered by the user, remove or escape special characters (such as <, >, &, etc.) to prevent malicious script injection. Existing input filtering frameworks (such as OWASP ESAPI) can be used for processing. For SQL queries, use prepared statements (PreparedStatements) to prevent SQL injection. For all HTML content entered by users, ensure that malicious JavaScript code is not executed. You can use the Content Security Policy (CSP) header to limit which scripts can be executed and filter and remove the input HTML. <script>标签、事件处理属性(如onmouseover、onclick)等。会话劫持攻击有时利用的是"会话长期有效”这一漏洞。在多维度渗透分析中,如果发现攻击链中利用的是已过期但仍有效的会话标识符,可以通过会话超时和重认证机制来加强防护,具体实施步骤如下:设置合理的会话超时策略。例如,如果用户在一定时间内没有进行任何操作,则自动终止会话。可以通过设置session_timeout参数,确保每个会话在预定的时间段内自动失效。在用户会话维持期间,定期要求用户进行身份验证。比如,每过一段时间就要求用户输入密码进行验证,或者进行二次身份验证(如短信验证码或指纹认证)。除了固定时间超时外,还可以根据会话活动的类型动态调整会话的有效期。例如,当检测到异常登录行为(如不同地理位置的IP登录),则立即使当前会话失效,要求用户重新认证。基于行为分析的异常检测与实时阻断,为了对抗会话劫持攻击中的"隐蔽性”攻击行为,可以通过行为分析进行实时监控和异常检测,具体实施步骤如下:首先对系统中用户的正常行为进行建模。这可以通过收集用户历史会话数据,分析用户的访问频次、访问模式、登录地理位置等信息,构建每个用户的行为模型。在用户会话过程中,实时分析其行为是否符合正常模式。例如,如果用户的登录地点发生剧烈变化,或者频繁地进行高风险操作(如修改账户信息、修改密码等),则系统会触发警报。一旦发现异常行为,立即采取措施,如要求用户重新认证、锁定当前会话或发送安全警告。可以结合机器学习模型(如聚类分析、异常检测算法)对行为数据进行实时分析,提高攻击的识别速度。通过这种基于行为的检测机制,可以在攻击者对会话进行劫持后,及时发现并阻断恶意行为,从而提升会话安全防护的实时性和准确性。

[0133] 一种信息安全防护装置,用于执行如上所述的信息安全防护方法,该信息安全防护装置包括:

[0134] 程序抓包处理模块,用于获取防火墙日志文件;基于防火墙日志文件进行异常行为流量抓取,得到异常行为流量;根据异常行为流量进行异常频次程序抓包处理,得到异常频次程序抓包数据集;

[0135] 验证规避代码结构识别模块,用于基于异常频次程序抓包数据集进行会话劫持程序解析,得到会话劫持程序解析数据;对会话劫持程序解析数据进行验证逻辑规避代码结构识别,得到验证规避代码结构数据;

[0136] 会话安全防护策略调整模块,用于基于会话劫持程序解析数据和验证规避代码结构数据进行会话安全防护策略调整,得到会话安全防护策略调整数据。

[0137] 一种电子设备,包括存储器、处理器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述处理器执行所述程序时实现如上的任一项所述信息安全防护方法。

[0138] 因此,无论从哪一点来看,均应将实施例看作是示范性的,而且是非限制性的,本发明的范围由所附权利要求而不是上述说明限定,因此旨在将落在申请文件的等同要件的含义和范围内的所有变化涵括在本发明内。

[0139] 以上所述仅是本发明的具体实施方式,使本领域技术人员能够理解或实现本发明。对这些实施例的多种修改对本领域的技术人员来说将是显而易见的,本文中所定义的一般原理可以在不脱离本发明的精神或范围的情况下,在其它实施例中实现。因此,本发明将不会被限制于本文所示的这些实施例,而是要符合与本文所发明的原理和新颖特点相一致的最宽的范围。< / script>

Claims

1. An information security protection method, characterized in that: The following steps are involved: Step S1: Obtain firewall log files; Capture abnormal behavior traffic based on firewall log files to obtain abnormal behavior traffic; Perform abnormal frequency program packet capture processing according to abnormal behavior traffic to obtain an abnormal frequency program packet capture data set; Step S2: parsing the session hijacking program based on the abnormal frequency program packet capture data set to obtain session hijacking program parsing data; The session hijacking program parsing data is subjected to verification logic avoidance code structure identification to obtain verification avoidance code structure data; wherein step S2 includes: Step S21: Analyze the abnormal IP address change trajectory on the abnormal frequency program packet capture data set to obtain the abnormal IP address change trajectory; Step S22: Identify the session attack target based on the abnormal IP address change trajectory and abnormal frequency program packet capture data set to obtain the session attack target; Step S23: performing session hijacking program analysis on the session attack target based on the abnormal frequency program packet capture data set to obtain session hijacking program analysis data; wherein step S23 includes: Step S231: extracting session target state attribute elements from the session attack target to obtain session target state attribute elements; wherein the session target state attribute elements include cookies, session ID and URL parameters; Step S232: Based on the abnormal frequency program packet capture data set, abnormal code element injection identification is performed on the session target state attribute element to obtain element injection abnormal code data; Step S233: quantifying the multiple parameter injection risks of the URL parameters in the session target state attribute element according to the element injection abnormal code data to obtain multiple parameter injection risk quantification data; Step S234: performing session hijacking program analysis on the session attack target based on the element injection abnormal code data and the multiple parameter injection risk quantification data to obtain session hijacking program analysis data; Step S24: performing verification logic avoidance code structure identification on the session hijacking program parsing data to obtain verification avoidance code structure data; wherein step S24 includes: Step S241: performing program code control flow analysis on the session hijacking program parsing data to obtain a program code control flow graph; Step S242: Decompile the attack call behavior of the session hijacking program parsed data according to the program code control flow graph to obtain code attack call behavior decompilation data; Step S243: Based on the code attack call behavior decompilation data, the session hijacking program parsing data is subjected to underlying code vulnerability identification to obtain underlying code vulnerability data; Step S244: performing attack vector construction analysis on the decompiled data of the code attack call behavior to obtain code attack vector construction data; Step S245: performing race condition analysis based on the code attack vector construction data to obtain code attack vector race condition data; Step S246: performing verification logic avoidance code structure identification according to the code attack carrier race condition data and the underlying code vulnerability data to obtain verification avoidance code structure data; Step S3: adjusting the session security protection strategy based on the session hijacking program parsing data and the verification avoidance code structure data to obtain session security protection strategy adjustment data.

2. The information security protection method according to claim 1, characterized in that: Step S1 includes the following steps: Step S11: Obtain firewall log files; Step S12: Analyze the frequency of abnormal connection requests according to the firewall log file to obtain the frequency of abnormal connection requests; Step S13: capturing abnormal behavior traffic based on the abnormal connection request frequency to obtain abnormal behavior traffic; Step S14: performing abnormal frequency program packet capture processing on the abnormal connection request frequency according to the abnormal behavior traffic to obtain an abnormal frequency program packet capture data set.

3. The information security protection method according to claim 1, characterized in that: Step S233 includes the following steps: Perform code execution logic analysis on element injected abnormal code data to obtain abnormal code execution logic; Marking the URL parameter in the session target state attribute element with a key parameter variable to obtain a URL key parameter variable; According to the abnormal code execution logic, the abnormal variable manipulation of the URL key parameter variables is identified to obtain the abnormal variable manipulation code; Define the scope exception level for the abnormal variable manipulation code and obtain the scope exception level data; Based on the scope exception level data, the code execution exception life cycle is analyzed for the exception variable manipulation code to obtain the code execution exception life cycle; Based on the code execution exception life cycle and scope exception level data, the abnormal variable manipulation code is identified with abnormal modification hidden logic branches to obtain abnormal modification hidden logic branches; Based on the abnormal modification of hidden logic branches, the abnormal life cycle of code execution and the abnormal variable manipulation code, the risk quantification of multiple parameter injections is performed to obtain the quantitative data of multiple parameter injection risks.

4. The information security protection method according to claim 1, characterized in that: Step S242 includes the following steps: Perform conditional jump analysis on the program code control flow graph to obtain program code conditional jump data; Perform function call static analysis on session hijacking program parsing data based on program code conditional jump data to obtain function call static data; Perform reverse analysis of attack behavior code snippets on session hijacking program analysis data according to function call static data to obtain attack behavior code reverse analysis data; Reverse-parse the attack behavior code data to identify the hijacking return address and obtain the hijacking return address data; Reverse-analyze the attack behavior code data to identify the tampered call stack and obtain the tampered call stack data; The attack call behavior is decompiled according to the hijacked return address data and the tampered call stack data to obtain the code attack call behavior decompilation data.

5. The information security protection method according to claim 1, characterized in that: Step S3 includes the following steps: Step S31: performing attack link correlation analysis based on session hijacking program parsing data and verification avoidance code structure data to obtain a session hijacking attack link; Step S32: Perform multi-dimensional penetration identification on the session hijacking attack link to obtain multi-dimensional penetration data of the session hijacking attack; Step S33: adjusting the session security protection strategy based on the multi-dimensional penetration data of the session hijacking attack to obtain session security protection strategy adjustment data.

6. An information security protection device, characterized in that: Used to execute the information security protection method according to claim 1, the information security protection device comprises: The program packet capture processing module is used to obtain the firewall log file; based on the firewall log file, the abnormal behavior traffic is captured to obtain the abnormal behavior traffic; based on the abnormal behavior traffic, the abnormal frequency program packet capture processing is performed to obtain the abnormal frequency program packet capture data set; The verification avoidance code structure identification module is used to parse the session hijacking program based on the abnormal frequency program packet capture data set to obtain the session hijacking program analysis data; perform verification logic avoidance code structure identification on the session hijacking program analysis data to obtain the verification avoidance code structure data; The session security protection strategy adjustment module is used to adjust the session security protection strategy based on the session hijacking program parsing data and the verification avoidance code structure data to obtain the session security protection strategy adjustment data.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it implements the information security protection method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Network information security analysis method and system based on big data

    CN118337485A