A vulnerability exploit program detection method and system based on vulnerability exploit program features
By constructing a packaging area and a virtual space, extracting data features using a tracking network, and comparing abnormal behavior features with standard features, the problem of difficulty in comprehensively detecting vulnerability exploits in existing technologies has been solved, and the stable operation of the system has been achieved.
Patent Information
- Application Number
- CN202411942607.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-12-27
AI Technical Summary
Existing technologies are insufficient to fully detect exploits in accessed data, leading to system instability.
By constructing a packaging area and a virtual space, data features are extracted using a tracking network. Abnormal behavior features are compared with standard features, and data that does not conform to the standard features is marked as an exploit.
It enables comprehensive monitoring and identification of exploit programs, ensuring stable system operation.
Smart Images

Figure CN119885175B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of exploit detection technology, and specifically to an exploit detection method and system based on exploit characteristics. Background Technology
[0002] Exploit programs are code or programs written by hackers or attackers that exploit security vulnerabilities in a target system to perform malicious operations. These programs are typically used for malicious purposes such as unauthorized access, data theft, system damage, or the spread of malware. Exploit programs are easily mixed into the accessed data and are difficult to detect. They can be directly used on the data, causing serious problems such as system instability, and it is impossible to conduct comprehensive testing on the accessed data. Summary of the Invention
[0003] The purpose of this invention is to provide a method and system for detecting exploits based on their characteristics, in order to address the shortcomings of the prior art.
[0004] To achieve the above objectives, the present invention provides the following technical solution: a method for detecting exploits based on exploit characteristics, comprising the following steps:
[0005] Data accessed from the network is acquired as data to be detected. The data to be detected is then fed into the packaging area to obtain packaging data, which includes the data to be detected and the data tracking network.
[0006] The packaging data is then input into the virtual space corresponding to the target system.
[0007] Based on the tracking network, abnormal behavior features of the data to be detected in the virtual space are extracted. The abnormal behavior features are compared with standard features, and the data to be detected corresponding to the behavior features that do not conform to the standard features are marked as exploit programs.
[0008] In a preferred embodiment, the step of acquiring data accessed in the network as data to be detected and inputting the data to be detected into the packaging area to obtain packaging data includes:
[0009] A packaging area is constructed between the network access terminal and the target system, wherein the packaging area includes tracking network elements and multiple tracking network pending areas;
[0010] The data accessed in the network is used as the data to be detected and put into the packaging area. Multiple data features are extracted from the data to be detected, and the corresponding tracking network undetermined area is matched according to the number of data features.
[0011] The tracking network in the waiting area of the matching tracking network is packaged to obtain the packaged data.
[0012] In a preferred embodiment, the step of constructing a wrapper region between the network access terminal and the target system includes:
[0013] A data processing area is set up between the network access terminal and the target system to establish a communication connection. Multiple main tracking points are set up in the data processing area, and communication channels are set up between the multiple main tracking points. Multiple strain channel points are set up for each communication channel between the multiple main tracking points to obtain the tracking network element.
[0014] Multiple tracking frames are set up, and the corresponding tracking levels are marked for each tracking frame. A replication architecture is set up between the multiple tracking frames and the tracking elements. The replication architecture includes the tracking point architecture for the tracking level of the corresponding tracking frame.
[0015] The replication architecture is attached to the tracking network element to replicate the main tracking point and the communication channel between the main tracking points. The replication architecture of the replicated main tracking point is then separated from the tracking network element to obtain multiple tracking points connected by the communication channel. These multiple tracking points connected by the communication channel are loaded into the tracking network frame to obtain the tracking network undetermined area.
[0016] The tracking network element and multiple tracking network pending areas are used as the packaging area.
[0017] In a preferred embodiment, the step of packaging the tracking network in the corresponding tracking network waiting area to obtain packaged data includes:
[0018] The matching tracking network in the waiting area is called and removed from the waiting area. After the tracking network is removed from the waiting area, a new tracking network is copied and stored in the waiting area through the copy architecture corresponding to the waiting area.
[0019] Obtain the location information of multiple data features, including the data location and data volume of the data features in the data to be detected;
[0020] The tracking points in the tracking network are bound one-to-one with data features. The communication positions of multiple strain channel points in the communication channels between multiple tracking points are arranged. The fixed trajectory of the communication channel is determined based on the communication positions of multiple strain channel points. The data to be detected is covered by multiple tracking points and the communication channels with fixed trajectories between multiple tracking points to obtain packaging data.
[0021] In a preferred embodiment, the step of inputting the packaging data into the virtual space corresponding to the target system includes:
[0022] A virtual system is obtained by copying the target system.
[0023] In the data processing area, a running space is defined, and the virtual system is deployed into the running space to obtain the virtual space;
[0024] The packaging data is put into virtual space for processing.
[0025] In a preferred embodiment, the step of marking the data to be detected corresponding to behavioral features that do not conform to the standard features as exploit programs includes:
[0026] Based on the tracking network, the running status information of the data to be detected in the virtual space is extracted, and the abnormal behavior characteristics are determined based on the running status information;
[0027] Determine the standard characteristics of the data to be detected, compare the abnormal behavior characteristics with the standard characteristics, and mark the data to be detected corresponding to the behavior characteristics that do not conform to the standard characteristics as exploit programs.
[0028] In a preferred embodiment, the step of extracting the operational status information of the data to be detected in the virtual space based on the tracking network and determining the behavioral characteristics based on the operational status information includes:
[0029] The system acquires offset information from multiple tracking points and the communication channels between these points within the packaging data. Based on this offset information, it calculates the state index of the data to be detected and determines the operational status information. The formula for calculating the state index includes:
[0030] in, G is the state index. L n is the offset of the tracking point due to a change in its communication location. y G represents the number of communication position changes that occur at strain channel points in the communication channel connected to the tracking point. q The number of communication channels for which the communication position changes when the tracking point is connected to the strain channel point, where ε, α and μ are all constants greater than zero;
[0031] Define operational status information, which includes multiple status index ranges and their corresponding operational status levels;
[0032] Based on the operational status information, the operational status level corresponding to the status index is matched, and the tracking points that exceed the level of safe operational status are identified as abnormal behavior features.
[0033] This invention also provides a vulnerability exploit detection system based on exploit characteristics, comprising:
[0034] The packaging module is used to acquire data accessed in the network as data to be detected, and put the data to be detected into the packaging area to obtain packaging data. The packaging data includes the data to be detected and the data tracking network.
[0035] The data input module, connected to the packaging module, is used to input packaging data into the virtual space corresponding to the target system.
[0036] The detection module, connected to the data input module, is used to extract abnormal behavior features of the data to be detected in the virtual space based on the tracking network, compare the abnormal behavior features with standard features, and mark the data to be detected corresponding to behavior features that do not conform to the standard features as exploit programs.
[0037] The technical effects and advantages provided by the present invention in the above technical solution are as follows:
[0038] This invention allows for the modification of the transmission path of the communication channel through strain channel points. Here, the transmission path is the fixed trajectory of the communication channel. After fixing the communication channel path, the data to be detected is covered by multiple tracking points and communication channels with fixed trajectories between multiple tracking points to obtain packaged data. It can cover the data to be detected by multiple tracking points and communication channels with fixed trajectories between multiple tracking points, which has a more comprehensive monitoring effect on exploit programs and better identification of exploit programs. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.
[0040] Figure 1 This is a flowchart of the method of the present invention.
[0041] Figure 2 This is a system block diagram of the present invention. Detailed Implementation
[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0043] Example 1, please refer to Figure 1 As shown in this embodiment, a vulnerability exploit detection method based on vulnerability exploit characteristics includes the following steps:
[0044] S1. Obtain data accessed in the network as data to be detected, and put the data to be detected into the packaging area to obtain packaging data. The packaging data includes the data to be detected and the data to be detected tracking network.
[0045] S2. Input the packaging data into the virtual space corresponding to the target system;
[0046] S3. Based on the tracking network, extract the abnormal behavior features of the data to be detected in the virtual space, compare the abnormal behavior features with standard features, and mark the data to be detected corresponding to the behavior features that do not conform to the standard features as exploit programs.
[0047] As described in steps S1-S3 above, an exploit is a piece of code or program written by a hacker or attacker to exploit security vulnerabilities in a target system and perform malicious operations. These programs are typically used for malicious purposes such as unauthorized access, data theft, system damage, or the spread of malware. Exploit programs are easily mixed into the accessed data, making them difficult to detect. They can be directly used to cause system instability and other serious problems, making it impossible to comprehensively detect the accessed data. In contrast, this application uses adaptive channel points to modify the transmission route of the communication channel. This transmission route is the fixed trajectory of the communication channel. After fixing the communication channel route, the data to be detected is covered by multiple tracking points and communication channels with fixed trajectories between these tracking points to obtain packaged data. This allows for data coverage of the data to be detected through multiple tracking points and communication channels with fixed trajectories between these tracking points, resulting in a more comprehensive monitoring effect for exploits and better identification of exploits.
[0048] In one embodiment, step S1, which involves acquiring data accessed from the network as data to be detected and inputting the data to be detected into the packaging area to obtain packaging data, includes:
[0049] S11. Construct a packaging area between the network access terminal and the target system, wherein the packaging area includes tracking network elements and multiple tracking network pending areas;
[0050] S12. Take the data accessed in the network as the data to be detected and put it into the packaging area. Extract multiple data features from the data to be detected and match the corresponding tracking network waiting area according to the number of data features.
[0051] S13. Package the data to be detected from the tracking network in the waiting area of the matching tracking network to obtain packaged data;
[0052] As described in steps S11-S13 above, a packaging area is constructed between the network access terminal and the target system. The target system is the system used to receive data from the network. The packaging area is the running server between the network access terminal and the target system. The packaging area includes tracking network elements and multiple tracking network pending areas, which are areas for storing tracking networks. Then, the data accessed from the network is used as the data to be detected. This data to be detected will not be directly used in the target system to avoid the presence of exploit programs in the accessed data to attack the target system and ensure the stable operation of the target system. The data accessed from the network is used as the data to be detected and put into the packaging area. Multiple data features are extracted from the data to be detected. The corresponding tracking network pending area is matched according to the number of data features. The appropriate tracking network can be obtained according to the actual data to be detected. The tracking network and the data to be detected are used to detect subsequent behavioral features to determine whether the data to be detected has exploit program features. Then, the data to be detected is packaged by matching the tracking network in the corresponding tracking network pending area to obtain packaged data. This completes the preprocessing of the data to be detected, which is convenient for subsequent monitoring of the exploit program features of the data to be detected.
[0053] In one embodiment, step S11 of constructing the encapsulation region between the network access terminal and the target system includes:
[0054] S111. Set up a data processing area for communication between the network access terminal and the target system. Set up multiple main tracking points in the data processing area. Set up communication channels between the multiple main tracking points. Set up multiple strain channel points for each communication channel between the multiple main tracking points to obtain the tracking network element.
[0055] S112. Set up multiple tracking frames, mark the corresponding tracking level for each tracking frame, and set up a replication architecture between the multiple tracking frames and tracking elements. The replication architecture includes the tracking point architecture for the tracking level of the corresponding tracking frame.
[0056] S113. Adhere the replication architecture to the tracking network element to replicate the main tracking point and the communication channel between the main tracking points. Decouple the replication architecture of the replicated main tracking point from the tracking network element to obtain multiple tracking points connected by the communication channel. Load the multiple tracking points connected by the communication channel into the tracking network frame to obtain the tracking network undetermined area.
[0057] S114. The tracking network element and multiple tracking network pending areas are used as the packaging area;
[0058] As described in steps S111-S114 above, a data processing area is set up between the network access terminal and the target system. The data processing area is connected to the network access terminal and the target system via communication. This area serves as the detection zone for exploit programs between the network access terminal and the target system. To detect exploit programs, multiple main tracking points are set up in the data processing area. Communication channels are established between these main tracking points, and multiple strain channel points are set up for each communication channel between the main tracking points. These strain channel points can determine the communication trajectory of the communication channel. As connection nodes within the communication channel, multiple tracking frames are set up. These tracking frames are used to store multiple tracking points connected through the communication channel for subsequent replication. Each tracking frame is marked with a corresponding tracking level (the tracking level represents the number of tracking points). A replication architecture is set between multiple tracking frames and tracking network elements. The replication architecture includes the tracking point architecture corresponding to the tracking level of the tracking frame. For example, if the tracking level of the tracking frame corresponds to N tracking points, then the replication architecture corresponding to the tracking frame has N replication points. The multiple replication points are connected to obtain the tracking point architecture. Then, the replication architecture is attached to the tracking network element to replicate the main tracking point and the communication channel between the main tracking points. The replication architecture of the replicated main tracking point is then decoupled from the tracking network element to obtain multiple tracking points connected by the communication channel. The multiple tracking points connected by the communication channel are loaded into the tracking frame to obtain the tracking network pending area. The tracking network element and multiple tracking network pending areas are used as the packaging area.
[0059] In one embodiment, step S13, which involves packaging the tracking network data to be detected in the corresponding tracking network waiting area to obtain packaged data, includes:
[0060] S131. The matching tracking network in the waiting area is called and removed from the waiting area. After the tracking network is removed from the waiting area, a new tracking network is copied and stored in the waiting area through the copy architecture corresponding to the waiting area.
[0061] S132. Obtain the location information of multiple data features, wherein the location information includes the data location and data volume of the data features in the data to be detected;
[0062] S133. Bind the tracking points in the tracking network to the data features one-to-one, arrange the communication positions of multiple strain channel points in the communication channel between multiple tracking points, determine the fixed trajectory of the communication channel according to the communication positions of multiple strain channel points, and cover the data to be detected through multiple tracking points and the communication channel with fixed trajectory between multiple tracking points to obtain the packaging data.
[0063] As described in steps S131-S133 above, the data accessed in the network is used as the data to be detected and put into the packaging area. Multiple data features are extracted from the data to be detected. Each data feature has a corresponding position and the amount of data involved in the entire data to be detected. The corresponding tracking network waiting area is matched according to the number of data features. The tracking network in the corresponding tracking network waiting area is called and removed from the tracking network waiting area. After the tracking network is removed from the tracking network waiting area, a new tracking network is copied through the replication architecture corresponding to the tracking network waiting area and stored in the tracking network waiting area. After the tracking network in the tracking network waiting area is used, the same new tracking network is copied again by the tracking network element through the replication architecture. The used tracking network is then directly destroyed. The tracking network in multiple tracking waiting areas can be continuously replenished through the tracking network element and the replication architecture. After obtaining multiple data features, the tracking network in multiple tracking waiting areas can be continuously replenished. After obtaining the location information of the data features, the tracking points in the tracking network are bound one-to-one with the data features. The communication positions of multiple strain channel points in the communication channels between multiple tracking points are arranged randomly to obtain a transmission channel with a fixed transmission trajectory. The fixed trajectory of the communication channel is determined based on the communication positions of multiple strain channel points. The transmission route of the communication channel can be changed through the strain channel points. This transmission route is the fixed trajectory of the communication channel. After fixing the route of the communication channel, the data to be detected is covered by multiple tracking points and the communication channels with fixed trajectories between multiple tracking points to obtain packaged data. This data coverage of the data to be detected by multiple tracking points and the communication channels with fixed trajectories between multiple tracking points provides a more comprehensive monitoring effect for vulnerability exploits and better identifies vulnerability exploits.
[0064] In one embodiment, step S2, which involves inputting the packaging data into the virtual space corresponding to the target system, includes:
[0065] S21. Copy the target system to obtain a virtual system;
[0066] S22. Determine a running space in the data processing area, and put the virtual system into the running space to obtain the virtual space;
[0067] S23. Put the packaging data into the virtual space for operation.
[0068] As described in steps S21-S23 above, the target system is a system that accesses data through the network. To avoid the presence of exploit programs, a virtual system with the same system structure as the target system is copied. Then, a running space is determined in the data processing area. This running space is used to carry the virtual system. The running space carrying the virtual system is called the virtual space. Then, the packaged data is put into the virtual space for operation. The behavior characteristics of the packaged data in the virtual system can be used to detect whether there are exploit program behaviors in the data accessed by the network. This allows for comprehensive monitoring of the security of network access data.
[0069] In one embodiment, step S3, which marks the data to be detected corresponding to behavioral features that do not conform to the standard features as exploit programs, includes:
[0070] S31. Extract the running status information of the data to be detected in the virtual space based on the tracking network, and determine the abnormal behavior characteristics based on the running status information;
[0071] S32. Determine the standard features of the data to be detected, compare the abnormal behavior features with the standard features, and mark the data to be detected corresponding to the behavior features that do not conform to the standard features as exploit programs.
[0072] In one embodiment, step S31, which involves extracting operational status information of the data to be detected in the virtual space based on the tracking network and determining behavioral characteristics based on the operational status information, includes:
[0073] S311. Obtain offset information of multiple tracking points and communication channels between multiple tracking points in the packaging data; calculate the state index of the data to be detected based on the offset information; determine the operating state information based on the state index; the formula for calculating the state index includes:
[0074] Where φ is the state exponent, G L n is the offset of the tracking point due to a change in its communication location. y G represents the number of communication position changes that occur at strain channel points in the communication channel connected to the tracking point. q The number of communication channels connecting the tracking point to the strain channel point where the communication position changes is ε, α, and μ are all constants greater than zero. It should be noted that G L G q With n y The larger the value, the better. The larger the value, the worse the state of the data to be detected;
[0075] S312. Develop operational status information, which includes multiple status index ranges and corresponding operational status levels.
[0076] S313. Match the operational status level corresponding to the status index based on the operational status information, and take the tracking points that exceed the level of safe operational status as abnormal behavior features. The operational status level guarantees the level of safe operational status, the level of suspicious operational status, and the level of dangerous operational status. Each operational status level corresponds to a numerical range of a status index.
[0077] As described in steps S131-S313 above, when packaged data is put into the virtual space for vulnerability exploit detection, the state index of the data to be detected in the virtual space is calculated based on the tracking network. When a vulnerability exploit exists in the data to be detected, the exploit will exhibit abnormal behavior when entering the virtual space, thereby changing the data characteristics in the data to be detected. Here, the movement of the data to be detected can be tracked through tracking points. The security of the data to be detected can be understood by data such as the number of communication position changes of strain channel points in the communication channels connected to the tracking points and the number of communication channels connected to the tracking points with communication position changes of strain channel points. Then, the data characteristics corresponding to the tracking points with abnormal changes are taken as abnormal behavior. The abnormal behavior characteristics include changes in the abnormal communication location of data characteristics in virtual space. Then, standard characteristics of the data to be detected are determined. The abnormal behavior characteristics are compared with the standard characteristics. The data to be detected corresponding to the behavior characteristics that do not conform to the standard characteristics are marked as exploits, which can better detect exploits. By packaging data, we can more comprehensively understand whether exploits are mixed in with network access data. Then, if the packaged data is secure, the tracking points in the packaged data can be separated from the data to be detected, the tracking points can be invalidated, and the data to be detected can be used normally in the target system. By using virtual space to assist the target system in detecting exploits, the security of the data used by the target system is ensured.
[0078] Example 2, please refer to Figure 2 As shown in this embodiment, a vulnerability exploit detection system based on vulnerability exploit characteristics includes:
[0079] The packaging module is used to acquire data accessed in the network as data to be detected, and put the data to be detected into the packaging area to obtain packaging data. The packaging data includes the data to be detected and the data tracking network.
[0080] The data input module, connected to the packaging module, is used to input packaging data into the virtual space corresponding to the target system.
[0081] The detection module, connected to the data input module, is used to extract abnormal behavior features of the data to be detected in the virtual space based on the tracking network, compare the abnormal behavior features with standard features, and mark the data to be detected corresponding to behavior features that do not conform to the standard features as exploit programs.
[0082] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for detecting exploits based on exploit characteristics, characterized in that, Includes the following steps: Data accessed from the network is acquired as data to be detected. The data to be detected is then fed into the packaging area to obtain packaging data, which includes the data to be detected and the data tracking network. The step of acquiring data accessed from the network as data to be detected and inputting the data to be detected into the packaging area to obtain packaging data includes: A packaging area is constructed between the network access terminal and the target system, wherein the packaging area includes tracking network elements and multiple tracking network pending areas; The step of constructing a wrapper area between the network access terminal and the target system includes: A data processing area is set up between the network access terminal and the target system to establish a communication connection. Multiple main tracking points are set up in the data processing area, and communication channels are set up between the multiple main tracking points. Multiple strain channel points are set up for each communication channel between the multiple main tracking points to obtain the tracking network element. Multiple tracking frames are set up, and the corresponding tracking levels are marked for each tracking frame. A replication architecture is set up between the multiple tracking frames and the tracking elements. The replication architecture includes the tracking point architecture for the tracking level of the corresponding tracking frame. The replication architecture is attached to the tracking network element to replicate the main tracking point and the communication channel between the main tracking points. The replication architecture of the replicated main tracking point is then separated from the tracking network element to obtain multiple tracking points connected by the communication channel. These multiple tracking points connected by the communication channel are loaded into the tracking network frame to obtain the tracking network undetermined area. The tracking network element and multiple tracking network pending areas are used as the packaging area; The data accessed in the network is used as the data to be detected and put into the packaging area. Multiple data features are extracted from the data to be detected, and the corresponding tracking network undetermined area is matched according to the number of data features. The tracking network in the waiting area of the matching tracking network is packaged to obtain the data to be detected, thus obtaining the packaged data. The packaging data is then input into the virtual space corresponding to the target system. Based on the tracking network, abnormal behavior features of the data to be detected in the virtual space are extracted. The abnormal behavior features are compared with standard features, and the data to be detected corresponding to the behavior features that do not conform to the standard features are marked as exploit programs.
2. The method for detecting exploits based on exploit characteristics according to claim 1, characterized in that: The step of packaging the tracking network in the corresponding undetermined area of the tracking network to obtain packaged data includes: The matching tracking network in the waiting area is called and removed from the waiting area. After the tracking network is removed from the waiting area, a new tracking network is copied and stored in the waiting area through the copy architecture corresponding to the waiting area. Obtain the location information of multiple data features, including the data location and data volume of the data features in the data to be detected; The tracking points in the tracking network are bound one-to-one with data features. The communication positions of multiple strain channel points in the communication channels between multiple tracking points are arranged. The fixed trajectory of the communication channel is determined based on the communication positions of multiple strain channel points. The data to be detected is covered by multiple tracking points and the communication channels with fixed trajectories between multiple tracking points to obtain packaging data.
3. The method for detecting exploits based on exploit characteristics according to claim 1, characterized in that: The step of inputting the packaging data into the virtual space corresponding to the target system includes: A virtual system is obtained by copying the target system. In the data processing area, a running space is defined, and the virtual system is deployed into the running space to obtain the virtual space; The packaging data is put into virtual space for processing.
4. The method for detecting exploits based on exploit characteristics according to claim 1, characterized in that: The step of marking the data to be detected corresponding to behavioral characteristics that do not conform to the standard characteristics as exploit programs includes: Based on the tracking network, the running status information of the data to be detected in the virtual space is extracted, and the abnormal behavior characteristics are determined based on the running status information; Determine the standard characteristics of the data to be detected, compare the abnormal behavior characteristics with the standard characteristics, and mark the data to be detected corresponding to the behavior characteristics that do not conform to the standard characteristics as exploit programs.
5. The exploit detection method based on exploit characteristics according to claim 4, characterized in that: The step of extracting the operational status information of the data to be detected in the virtual space based on the tracking network, and determining the behavioral characteristics based on the operational status information, includes: The system acquires offset information from multiple tracking points and the communication channels between these points within the packaging data. Based on this offset information, it calculates the state index of the data to be detected and determines the operational status information. The formula for calculating the state index includes: ,in, For state index, The offset of the tracking point due to a change in communication location. This refers to the number of communication position changes that occur at strain channel points in the communication channel connected to the tracking point. The number of communication channels connected to the tracking point where the communication position changes. , and All are constants greater than zero; Define operational status information, which includes multiple status index ranges and their corresponding operational status levels; Based on the operational status information, the operational status level corresponding to the status index is matched, and the tracking points that exceed the level of safe operational status are identified as abnormal behavior features.
6. A vulnerability exploit detection system based on vulnerability exploit characteristics, used to implement the vulnerability exploit detection method based on vulnerability exploit characteristics as described in any one of claims 1-5, characterized in that, include: The packaging module is used to acquire data accessed in the network as data to be detected, and put the data to be detected into the packaging area to obtain packaging data. The packaging data includes the data to be detected and the data tracking network. The data input module, connected to the packaging module, is used to input packaging data into the virtual space corresponding to the target system. The detection module, connected to the data input module, is used to extract abnormal behavior features of the data to be detected in the virtual space based on the tracking network, compare the abnormal behavior features with standard features, and mark the data to be detected corresponding to behavior features that do not conform to the standard features as exploit programs.
Citation Information
Patent Citations
Program bug positioning method and device, computer equipment and readable storage medium
CN108170609A
Security vulnerability analysis method based on deep learning and big data and cloud computing system
CN114584361A