A Dynamic Defense Method and System Based on Web Application Firewall
By building a dynamic transmission channel between the firewall and the target Internet, using folding space and verification nodes to process access data, the problem of data being easily tampered in the prior art is solved, and the security and integrity of data transmission are achieved.
Patent Information
- Application Number
- CN202510028824.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-01-08
AI Technical Summary
In the process of obtaining access data through the Internet, existing web application firewalls are difficult to block the intrusion of malicious network traffic other than the Internet, resulting in the access data being easily tampered with malicious processes and lacking effective security defenses.
A dynamic transmission channel is built between the firewall and the target Internet, and the access data is processed through the folding space and verification nodes to ensure the security of data transmission, including setting up a folding space and multiple verification nodes in the information acquisition channel, folding and verifying the access data through the dynamic transmission channel, destroying data that does not meet the preset conditions until it meets the conditions and transmitting it to the firewall.
It effectively avoids tampering and destruction during the data transmission between the target Internet and the firewall, ensures the security and integrity of data, and improves the security guarantee of data transmission.
Smart Images

Figure CN119892448B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network defense, and specifically relates to a dynamic defense method and system based on a web application firewall. Background Art
[0002] A web application firewall is a security device or service specifically used to protect web applications from malicious attacks. It is located in front of the web server and serves as an intermediate layer between the application and the Internet, responsible for monitoring, filtering, and blocking malicious traffic, and can reduce the probability of malicious traffic attacking the application. Currently, existing web application firewalls are difficult to block the intrusion of network malicious traffic other than the Internet during the process of obtaining access data through the Internet. For example, during the process of obtaining access data, the obtained access data is easily tampered with by external networks, and the originally secure access data is tampered into malicious traffic, without a good security defense effect. Summary of the Invention
[0003] The purpose of the present invention is to provide a dynamic defense method and system based on a web application firewall to solve the deficiencies in the background art.
[0004] To achieve the above purpose, the present invention provides the following technical solution: A dynamic defense method based on a web application firewall, including the following steps:
[0005] Determine the target Internet and target application program connected to the firewall to obtain a web application;
[0006] Construct a dynamic transmission channel between the firewall and the target Internet;
[0007] Obtain access data through the target Internet, and fold the access data through the dynamic transmission channel to obtain folded data;
[0008] Transmit the folded data through the dynamic transmission channel, destroy the folded data that does not meet the preset conditions as abnormal data, and re-obtain access data until it meets the preset conditions and is transmitted to the firewall. Restore the folded data and provide it to the target application program through the firewall.
[0009] In a preferred embodiment, the step of constructing a dynamic transmission channel between the firewall and the target Internet includes:
[0010] Set up an information acquisition channel between the firewall and the target Internet, and set up a folding space at a position close to the target Internet end in the information acquisition channel;
[0011] Set up a plurality of information boxes and corresponding mutagenic points in the information acquisition channel to obtain a plurality of verification nodes;
[0012] Set the folding space and the information acquisition channel after verifying the nodes as the dynamic transmission channel.
[0013] In a preferred embodiment, the steps of setting an information acquisition channel between the firewall and the target Internet and setting a folding space at a position close to the target Internet end in the information acquisition channel include:
[0014] Set a preprocessing space at a position close to the target Internet end in the information acquisition channel;
[0015] Set a plurality of information architecture chains in the preprocessing space, where the information architecture chain is composed of a plurality of information architectures in sequence, the information architecture includes a plurality of information cells, and the plurality of information cells are linked and the positions of the plurality of information cells are fixed;
[0016] Use the preprocessing space storing a plurality of information architecture chains as the folding space.
[0017] In a preferred embodiment, the steps of setting a plurality of information boxes and corresponding mutagenesis points in the information acquisition channel to obtain a plurality of verification nodes include:
[0018] Set a plurality of transmission areas in the information acquisition channel, set a plurality of verification points in the transmission areas, and use the transmission area where the plurality of verification points are set as the information box. The number of information boxes in the information acquisition channel is the same as the number of information architectures in a single information architecture chain;
[0019] Establish a communication relationship between the information box and the folding space based on the information acquisition channel, and set a mutagenesis point corresponding to the folding space in the information box;
[0020] Use the plurality of information boxes and the corresponding mutagenesis points as the plurality of verification nodes.
[0021] In a preferred embodiment, the steps of obtaining access data through the target Internet and folding the access data through the dynamic transmission channel to obtain folded data include:
[0022] Obtain access data through the target Internet, transmit the access data through the dynamic transmission channel, and divide the access data into a plurality of sub-access data when passing through the folding space. The number of sub-access data is the same as the number of information cells;
[0023] Randomly select an information architecture chain, and use the first information architecture in the information architecture chain as the target architecture;
[0024] Store the plurality of sub-access data one-to-one in the information cells in the target architecture to obtain the folded data.
[0025] In a preferred embodiment, the steps of restoring the folded data and providing it to the target application through the firewall include:
[0026] Transmitting the information architectures in the randomly selected information architecture chain to the mutagenesis points of the verification nodes one by one in sequence;
[0027] Transmitting both the folded data and the information architectures other than the target architecture in the randomly selected information architecture chain through the dynamic transmission channel. When the folded data passes through the verification node, the folded data that does not meet the preset conditions is destroyed as abnormal data;
[0028] Reacquiring the access data and processing it into folded data until it meets the preset conditions and is transmitted to the firewall. The folded data is restored and provided to the target application through the firewall.
[0029] In a preferred embodiment, the steps of transmitting the folded data through the dynamic transmission channel and destroying the folded data that does not meet the preset conditions as abnormal data when the folded data passes through the verification node include:
[0030] The verification points in the information box are arranged in positions according to the information architectures in the mutagenesis points. When the folded data passes through the verification node, the information cells in the folded data are position-corresponded with the verification points;
[0031] The situation where the positions of the information cells in the folded data and the verification points do not correspond is regarded as not meeting the preset conditions. The folded data that does not meet the preset conditions is taken as abnormal data and destroyed.
[0032] The present invention also provides a dynamic defense system based on a web application firewall, including:
[0033] A determination module for determining the target Internet connected to the firewall and the target application to obtain a web application;
[0034] A construction module connected to the determination module for constructing a dynamic transmission channel between the firewall and the target Internet;
[0035] A processing module connected to the construction module for obtaining access data through the target Internet and folding the access data through the dynamic transmission channel to obtain folded data;
[0036] A defense module connected to the processing module for transmitting the folded data through the dynamic transmission channel, destroying the folded data that does not meet the preset conditions as abnormal data, and reacquiring the access data until it meets the preset conditions and is transmitted to the firewall. The folded data is restored and provided to the target application through the firewall.
[0037] In the above technical solution, the technical effects and advantages provided by the present invention are as follows:
[0038] Multiple verification points of the present invention are communicatively connected to mutagenesis points set in the corresponding information boxes. The multiple information boxes and the corresponding mutagenesis points are used as multiple verification nodes. Through the mutagenesis points, the verification points can be arranged, which is convenient for the verification points to perform transmission verification on the data after folding the data to be accessed subsequently. It has a good role in ensuring data transmission security and can avoid being tampered with and damaged on the channel between the target Internet and the firewall. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.
[0040] Figure 1 It is a flowchart of the method of the present invention.
[0041] Figure 2 It is a system block diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0043] Embodiment 1. Please refer to Figure 1 As shown, a dynamic defense method based on a web application firewall in this embodiment includes the following steps:
[0044] S1. Determine the target Internet connected to the firewall and the target application program to obtain a web application;
[0045] S2. Build a dynamic transmission channel between the firewall and the target Internet;
[0046] S3. Obtain access data through the target Internet, and fold the access data through the dynamic transmission channel to obtain folded data;
[0047] S4. Transmit the folded data through the dynamic transmission channel, destroy the folded data that does not meet the preset conditions as abnormal data, and re-obtain the access data until it meets the preset conditions and is transmitted to the firewall. Then restore the folded data and provide it to the target application through the firewall;
[0048] As described in the above steps S1 - S4, the verification points can be changed through the mutagenic points. The number of verification points is the same as the number of cells in a single transmission architecture. The number of information frames in the information acquisition channel is the same as the number of information architectures in a single information architecture chain. There is a communication connection between multiple verification points and the mutagenic points set in the corresponding information frames. The multiple information frames and the corresponding mutagenic points are used as multiple verification nodes. The verification points can be arranged through the mutagenic points, which is convenient for the verification points to verify the transmission of the data after folding the subsequent access data, has a good data transmission security guarantee effect, and can avoid being tampered with and damaged on the channel between the target Internet and the firewall.
[0049] In one embodiment, step S2 of constructing a dynamic transmission channel between the firewall and the target Internet includes:
[0050] S21. Set up an information acquisition channel between the firewall and the target Internet, and set up a folding space at a position close to the target Internet end in the information acquisition channel;
[0051] S22. Set up multiple information frames and corresponding mutagenic points in the information acquisition channel to obtain multiple verification nodes;
[0052] S23. Use the information acquisition channel with the folding space and verification nodes set as the dynamic transmission channel;
[0053] As described in the above steps S21 - S23, the firewall serves as an intermediate layer between the application program and the Internet, responsible for monitoring, filtering, and blocking malicious traffic. Therefore, the firewall is connected to the target Internet and the target application program respectively. Since the target application program obtains data through the target Internet, the data security of the target Internet needs to be concerned. Therefore, an information acquisition channel is set up between the firewall and the target Internet, and a folding space is set at a position close to the target Internet end in the information acquisition channel. The folding space is at the network position close to the data output port of the target Internet in the information acquisition channel. Then, multiple verification nodes are set up in the information acquisition channel. Among them, the verification node includes an information frame and the corresponding mutagenic point. Using the information acquisition channel with the folding space and verification nodes set as the dynamic transmission channel can facilitate the subsequent guarantee of the source of the access data obtained from the target Internet, avoid being tampered with and damaged on the channel between the target Internet and the firewall, and has a good information security guarantee effect.
[0054] In one embodiment, step S21 of setting up an information acquisition channel between the firewall and the target Internet and setting up a folding space at a position close to the target Internet end in the information acquisition channel includes:
[0055] S211. Set up a preprocessing space at a position close to the target Internet end in the information acquisition channel;
[0056] S212. Set up a plurality of information architecture chains in the preprocessing space. Among them, the information architecture chain is composed of a plurality of information architectures in sequence. The information architecture includes a plurality of information cells, and the plurality of information cells are linked and fix the positions of the plurality of information cells;
[0057] S213. Use the preprocessing space storing a plurality of information architecture chains as the folding space;
[0058] In one embodiment, step S22 of setting up a plurality of information boxes and corresponding mutagenic points in the information acquisition channel to obtain a plurality of verification nodes includes:
[0059] S221. Set up a plurality of transmission areas in the information acquisition channel, set a plurality of verification points in the transmission areas, and use the transmission areas where the plurality of verification points are set as information boxes. Among them, the number of information boxes in the information acquisition channel is the same as the number of information architectures in a single information architecture chain;
[0060] S222. Establish a communication relationship between the information box and the folding space based on the information acquisition channel, and set a mutagenic point corresponding to the folding space in the information box;
[0061] S223. Use the plurality of information boxes and the corresponding mutagenic points as a plurality of verification nodes;
[0062] As described in the above steps S211 - S213 and S221 - S223, a pre - processing space is set at a position close to the target Internet end in the information acquisition channel. Here, the pre - processing space is a data processing library connected to the information acquisition channel. Multiple information architecture chains are set in the pre - processing space. The number of information architectures in multiple information architecture chains is the same. Multiple information cells are set in the information architecture. Here, the information cell is a data storage unit for storing data and capable of transmission. Multiple information cells are linked. Here, the linking process is to fix the positions and bind multiple information cells. After the information cell accesses the data after subsequent storage partitioning, the information cell cannot store other data anymore. In this way, during the transmission process, the number of information cells is fixed. To ensure the stability of subsequent transmission, the change of access data transmission is completed through a single information architecture chain, reducing the probability that the transmission of the unchanging information architecture will be easily replaced. The replaced information architecture will not be changed through subsequent mutagenesis points. Such a situation is abnormal. The number of information cells in the information architecture of a single information architecture chain is the same, but the positional relationship between information cells in multiple information architectures is different. Then, the pre - processing space storing multiple information architecture chains is used as a folding space. Multiple transmission areas are set in the information acquisition channel. Multiple verification points are set in the transmission area. Each transmission area has multiple verification points, and the verification points are changeable. The verification points can be changed through mutagenesis points. The number of verification points is the same as the number of information cells in a single transmission architecture. The number of information frames in the information acquisition channel is the same as the number of information architectures in a single information architecture chain. Multiple verification points are communicatively connected to the mutagenesis points set in the corresponding information frame. Multiple information frames and the corresponding mutagenesis points are used as multiple verification nodes. The verification points can be arranged through mutagenesis points, facilitating the verification of the data after folding the access data for subsequent transmission, having a good role in ensuring data transmission security, and being able to avoid being tampered with and damaged on the channel between the target Internet and the firewall.
[0063] In one embodiment, step S3 of obtaining access data through the target Internet and folding the access data through a dynamic transmission channel to obtain folded data includes:
[0064] S31. Obtain access data through the target Internet, transmit the access data through a dynamic transmission channel, and divide the access data into multiple sub - access data when passing through the folding space. The number of sub - access data is the same as the number of information cells;
[0065] S32. Randomly select an information architecture chain, and use the information architecture ranked first in the information architecture chain as the target architecture;
[0066] S33. Store multiple sub-access data one by one in the information cells in the target architecture to obtain folded data;
[0067] As described in the above steps S31 - S33, the target Internet is a platform for the target application to obtain information. Access data is obtained through the target Internet, and this access data needs to be transmitted through a dynamic transmission channel. The folding space is located at the information output port of the target Internet. Therefore, it is equivalent to that the access data is directly input into the folding space as soon as it is output from the target Internet. There are multiple information architecture chains in the folding space. Here, a random information architecture chain is selected, and the first information architecture in the sorted information architecture chain is used as the target architecture. The target architecture is the information architecture initially used for the transmission of access data. When passing through the folding space, the access data is divided to obtain multiple sub-access data, and the number of sub-access data is the same as the number of information cells. Then, the multiple sub-access data are stored one by one in the information cells in the target architecture to obtain folded data. The randomly selected information architecture chain, except for the target architecture, also transmits following the folded information, and the information cells in the information architecture except for the target architecture are in a closed state and will not be used by other information.
[0068] In one embodiment, the step S4 of restoring the folded data and providing it to the target application through the firewall includes:
[0069] S41. Transmit the information architectures in the randomly selected information architecture chain one by one in sequence to the mutagenesis points of the verification nodes;
[0070] S42. Transmit both the folded data and the information architectures in the randomly selected information architecture chain except for the target architecture through the dynamic transmission channel. When the folded data passes through the verification node, the folded data that does not meet the preset conditions is destroyed as abnormal data;
[0071] S43. Re-obtain the access data and process it into folded data until it meets the preset conditions and is transmitted to the firewall. Restore the folded data and provide it to the target application through the firewall;
[0072] In one embodiment, the step S42 of transmitting the folded data through the dynamic transmission channel and destroying the folded data that does not meet the preset conditions as abnormal data when the folded data passes through the verification node includes:
[0073] S421. Arrange the verification points in the information box according to the information architectures in the mutagenesis points. When the folded data passes through the verification node, the information cells in the folded data correspond to the verification points in terms of position;
[0074] S422. Regard the situation where the positions of the information cells in the folded data do not correspond to the verification points as not meeting the preset conditions, and regard the folded data that does not meet the preset conditions as abnormal data and destroy it.
[0075] As described in the above steps S41 - S43, transfer the information architectures in the randomly selected information architecture chain to the mutagenic points of the verification nodes one by one in order. For example, if there are three information architectures A, B, and C in the randomly selected information architecture chain, then there are three verification nodes in the dynamic transmission channel, namely 1, 2, and 3. Then store information architecture A in the mutagenic point of verification node 1, information architecture B in the mutagenic point of verification node 2, and information architecture C in the mutagenic point of verification node 3. Through the mutagenic points, the verification points in the corresponding verification nodes can be arranged in position. When the information architectures other than the target architecture in the folded data and the randomly selected information architecture chain pass through the verification nodes, the positions of the information cells in the folded data correspond to the verification points. When the folded data passes through the first verification node 1, the corresponding information architecture is A. The folded data is stored and transmitted according to the information architecture ranked first, so it can correspond to the verification point corresponding to information architecture A in verification node 1. Here, the verification points are connected to each other and can communicate with each other to understand whether all the verification points can correspond to the information cells of the corresponding folded data. Regard the situation where the positions of the information cells in the folded data do not correspond to the verification points as not meeting the preset conditions, and regard the folded data that does not meet the preset conditions as abnormal data and destroy it. If it meets the preset conditions, transfer and store the multiple sub - access data in the folded data to the information architectures other than the target architecture in the next randomly selected information architecture chain, continue the transmission, and verify with the subsequent verification nodes in the same way as above until it meets the preset conditions and is transmitted to the firewall. Restore the folded data (extract the multiple sub - access data from the folded data and combine them in order, and also split the access data in order when splitting). Provide it to the target application program through the firewall, which can complete the acquisition of the complete data and avoid the probability of the access data being tampered with during the transmission process, and can achieve timely transmission termination.
[0076] Embodiment 2. Please refer to Figure 2 As shown, a dynamic defense system based on a web application firewall in this embodiment includes:
[0077] A determination module, used to determine the target Internet connected to the firewall and the target application program to obtain a web application;
[0078] A construction module, connected to the determination module, used to construct a dynamic transmission channel between the firewall and the target Internet;
[0079] A processing module, connected to the construction module, is used to obtain access data through the target Internet and fold the access data through a dynamic transmission channel to obtain folded data;
[0080] A defense module, connected to the processing module, is used to transmit the folded data through the dynamic transmission channel, destroy the folded data that does not meet the preset conditions as abnormal data, and re-obtain the access data until it meets the preset conditions and is transmitted to the firewall. The folded data is restored and provided to the target application program through the firewall.
[0081] As mentioned above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A dynamic defense method based on a web application firewall, characterized in that, It includes the following steps: Determine the target Internet connected by the firewall and the target application to obtain a web application; Build a dynamic transmission channel between the firewall and the target Internet; Obtain access data through the target Internet, fold the access data through the dynamic transmission channel to obtain folded data. The folded data is the data obtained by storing multiple sub-access data one-to-one in the information cells of the target architecture. The target architecture is the information architecture ranked first in the information architecture chain; Transmit the folded data through the dynamic transmission channel, destroy the folded data that does not meet the preset conditions as abnormal data, and re-obtain access data until it meets the preset conditions and is transmitted to the firewall. Restore the folded data and provide it to the target application through the firewall.
2. A dynamic defense method based on a web application firewall according to claim 1, characterized in that: The step of building a dynamic transmission channel between the firewall and the target Internet includes: Set up an information acquisition channel between the firewall and the target Internet, and set a folding space at a position close to the target Internet end in the information acquisition channel. The folding space stores multiple information architecture chains, and the information architecture chain is composed of multiple information architectures in sequence; Set multiple information boxes and corresponding mutagenic points in the information acquisition channel to obtain multiple verification nodes. The mutagenic points are used to store the corresponding information architectures; Use the information acquisition channel with the folding space and verification nodes set as the dynamic transmission channel.
3. A dynamic defense method based on a web application firewall according to claim 2, characterized in that: The step of setting up an information acquisition channel between the firewall and the target Internet and setting a folding space at a position close to the target Internet end in the information acquisition channel includes: Set up a preprocessing space at a position close to the target Internet end in the information acquisition channel; Set multiple information architecture chains in the preprocessing space. Among them, the information architecture chain is composed of multiple information architectures in sequence. The information architecture includes multiple information cells, and the multiple information cells are linked and the positions of the multiple information cells are fixed; Use the preprocessing space storing multiple information architecture chains as the folding space.
4. A dynamic defense method based on a web application firewall according to claim 3, characterized in that: The step of setting multiple information boxes and corresponding mutagenic points in the information acquisition channel to obtain multiple verification nodes includes: Set multiple transmission areas in the information acquisition channel, set multiple verification points in the transmission areas, and use the transmission areas with multiple verification points set as information boxes. Among them, the number of information boxes in the information acquisition channel is the same as the number of information architectures in a single information architecture chain; Establish a communication relationship between the information box and the folding space based on the information acquisition channel, and set a mutagenic point in the information box corresponding to the folding space; Use multiple information boxes and corresponding mutagenic points as multiple verification nodes.
5. A dynamic defense method based on a web application firewall according to claim 1, characterized in that: The step of obtaining access data through the target Internet and folding the access data through the dynamic transmission channel to obtain folded data includes: Obtain access data through the target Internet, transmit the access data through the dynamic transmission channel, and divide the access data when passing through the folding space to obtain multiple sub-access data. The number of sub-access data is the same as the number of information cells; Randomly select an information architecture chain, and use the information architecture ranked first in the information architecture chain as the target architecture; Store multiple sub-access data one-to-one in the information cells of the target architecture to obtain folded data.
6. The dynamic defense method based on a web application firewall according to claim 1, characterized in that: The steps of restoring the folded data and providing it to the target application through the firewall include: Transmitting the information schemas in the randomly selected information schema chain to the mutagenic points of the verification nodes one by one in sequence; Transmitting both the folded data and the information schemas in the randomly selected information schema chain except the target schema through the dynamic transmission channel. When the folded data passes through the verification node, the folded data that does not meet the preset conditions is destroyed as abnormal data; Re-obtaining the access data and processing it into folded data until it meets the preset conditions and is transmitted to the firewall. The folded data is restored and provided to the target application through the firewall.
7. A dynamic defense method based on a web application firewall according to claim 6, characterized in that: The steps of transmitting the folded data through the dynamic transmission channel and destroying the folded data that does not meet the preset conditions as abnormal data when the folded data passes through the verification node include: The verification points in the information box are arranged in positions according to the information schemas in the mutagenic points. When the folded data passes through the verification node, the information cells in the folded data are positionally corresponding to the verification points; The situation where the positions of the information cells in the folded data and the verification points do not correspond is regarded as not meeting the preset conditions, and the folded data that does not meet the preset conditions is taken as abnormal data and destroyed.
8. A dynamic defense system based on a web application firewall, which is used to implement the dynamic defense method based on a web application firewall according to any one of claims 1-7, characterized in that, It includes: A determination module for determining the target Internet connected by the firewall and the target application to obtain a web application; A construction module connected to the determination module for constructing a dynamic transmission channel between the firewall and the target Internet; A processing module connected to the construction module for obtaining access data through the target Internet and folding the access data through the dynamic transmission channel to obtain folded data; A defense module connected to the processing module for transmitting the folded data through the dynamic transmission channel, destroying the folded data that does not meet the preset conditions as abnormal data, and re-obtaining the access data until it meets the preset conditions and is transmitted to the firewall. The folded data is restored and provided to the target application through the firewall.
Citation Information
Patent Citations
Firewall deployment method and device based on network security architecture, equipment and medium
CN114143090A
Method for discovering interface resources and related equipment
CN118368236A