Code detection method, device and equipment, medium and product
By combining the language model with the language model to generate features, attack features and obfuscated features, the problem of difficulty in detecting the language model generation attack obfuscated code is solved in the existing technology, and more efficient security protection is achieved.
Patent Information
- Application Number
- CN202510128138.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-27
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-27
AI Technical Summary
The prior art is difficult to effectively detect attack obfuscated codes generated by language models, resulting in insufficient protection capabilities of security protection products.
The hybrid expert model is adopted, including a first expert model for extracting attack-related features, a second expert model for extracting features related to obfuscated codes, and a third expert model for extracting features related to the language model to generate codes. By performing word segmentation and feature extraction of the code, different features are comprehensively considered to identify whether the code is an attack-related obfuscated code generated by the language model.
Effectively and comprehensively identify whether the code is an attack obfuscated code generated by the language model, improve the protection performance of security protection products, and reduce the risk of false alarms and missed reports.
Smart Images

Figure CN119939541A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a code detection method, device, electronic device, computer-readable storage medium, and computer program product. Background Art
[0002] With the continuous development of computer technology, security protection products for security testing have emerged. Security protection products can detect physical computing devices such as computers and hosts or virtual computing devices such as containers to ensure safe operation.
[0003] Security protection products can perform multiple tests on computing devices. In order to avoid detection of attack behaviors by security protection products, attackers usually use obfuscation technology to process the code used to execute the attack, obtain the attack obfuscated code, and execute obfuscated attacks.
[0004] In the related technology, a language model is used to generate batches of attack obfuscation codes. How to detect the attack obfuscation codes generated by the language model and improve the protection capabilities of security protection products has become an urgent problem to be solved. Summary of the invention
[0005] The present application provides a code detection method. The method can effectively and comprehensively identify whether the code is an attack obfuscation code generated by a language model, thereby improving the protection performance of security protection products against attack behaviors. The present application also provides a device, an electronic device, a computer-readable storage medium, and a computer program product corresponding to the above method.
[0006] In a first aspect, the present application provides a code detection method, the method comprising:
[0007] Get the first code;
[0008] Segmenting the first code to obtain a plurality of word units;
[0009] The multiple word-grams are input into a hybrid expert model, and a code detection result output by the hybrid expert model is received; wherein the hybrid expert model includes a first expert model for extracting features related to a first type of attack, a second expert model for extracting features related to obfuscated codes, and a third expert model for extracting features related to code generated by a language model; the code detection result is determined based on one or more of the features related to the first type of attack, the features related to the obfuscated codes, and the features related to code generated by the language model; and the code detection result is used to characterize whether the first code is an obfuscated code generated by a language model and used to execute the first type of attack.
[0010] In a second aspect, the present application provides a code detection device, the device comprising:
[0011] An acquisition module, used for acquiring a first code;
[0012] A word segmentation module, used for segmenting the first code to obtain multiple word units;
[0013] A detection module is used to input the multiple word-grams into a hybrid expert model, and receive a code detection result output by the hybrid expert model; wherein the hybrid expert model includes a first expert model for extracting features related to a first type of attack, a second expert model for extracting features related to an obfuscated code, and a third expert model for extracting features related to a code generated by a language model, and the code detection result is determined based on one or more of the features related to the first type of attack, the features related to the obfuscated code, and the features related to the code generated by the language model, and the code detection result is used to characterize whether the first code is an obfuscated code generated by a language model and used to execute the first type of attack.
[0014] In a third aspect, the present application provides an electronic device, the electronic device comprising a processor and a memory. The processor and the memory communicate with each other. The processor is used to execute instructions stored in the memory so that the electronic device performs the code detection method in the first aspect or any implementation of the first aspect.
[0015] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, wherein the instructions instruct an electronic device to execute the code detection method described in the first aspect or any one of the implementations of the first aspect.
[0016] In a fifth aspect, the present application provides a computer program product comprising instructions, which, when executed on an electronic device, enables the electronic device to execute the code detection method described in the first aspect or any one of the implementations of the first aspect.
[0017] Based on the implementations provided in the above aspects, this application can also be further combined to provide more implementations.
[0018] It can be seen from the above technical solutions that this application has the following advantages:
[0019] The present application provides a code detection method, which first obtains a first code, performs word segmentation on the first code to obtain multiple word units, then inputs the multiple word units into a hybrid expert model, and receives a code detection result output by the hybrid expert model, wherein the hybrid expert model includes a first expert model for extracting features related to a first type of attack, a second expert model for extracting features related to an obfuscated code, and a third expert model for extracting features related to a code generated by a language model, and the code detection result is determined based on one or more of the features related to the first type of attack, the features related to the obfuscated code, and the features related to the code generated by the language model, and the code detection result is used to characterize whether the first code is an obfuscated code generated by a language model and used to execute the first type of attack.
[0020] In this method, a hybrid expert model is used for code detection. The three expert models in the hybrid expert model respectively detect whether the code is used to execute the first type of attack, whether it is an obfuscated code, and whether it is generated by a language model. By comprehensively considering different features, it is possible to effectively and comprehensively identify whether the code is an attack obfuscated code generated by a language model, thereby improving the protection performance of security protection products against attack behaviors and reducing the risks of false positives and negatives. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical method of the embodiments of the present application, the drawings required for use in the embodiments are briefly introduced below.
[0022] Figure 1 A flowchart of a code detection method provided in an embodiment of the present application;
[0023] Figure 2 A schematic diagram of the structure of a hybrid expert model provided in an embodiment of the present application;
[0024] Figure 3 A schematic diagram of a hybrid expert model training process provided in an embodiment of the present application;
[0025] Figure 4 A schematic diagram of the structure of a code detection device provided in an embodiment of the present application;
[0026] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0027] The terms "first" and "second" in the embodiments of the present application are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features.
[0028] First, some technical terms and application scenarios involved in the embodiments of this application are introduced.
[0029] With the continuous development of computer technology, security protection products for security detection and protection of physical computing devices such as computers and hosts or virtual computing devices such as containers have emerged. Security protection products can perform multi-faceted security detection for a variety of operating scenarios. For example, the security protection product can be a cloud workload protection platform (CWPP), which can detect host security and network security. For another example, the security protection product can be a host-based intrusion detection system (HIDS), which can perform security detection on the behavior and status of the computer system. For another example, the security protection product can be cloud security posture management (CSPM), which can assess and manage cloud security risks and identify configuration errors and security vulnerabilities in cloud environments.
[0030] In some examples, security products can detect attacks against command execution environments (webshells), which are code execution environments in the form of web page files such as asp, php, jsp, cgi, etc., used to perform operations such as website management, server management, and permission management.
[0031] In a webshell attack, the attacker uses the webshell to execute commands on the target server and gain control of the target server. Specifically, the attacker uploads the code used to execute the webshell attack to the target server, accesses the webshell page through a browser, and enters the command to be executed in the command input box of the webshell page to control the target server.
[0032] In the related art, security protection products usually detect the code used to execute webshell attacks at the static file level. For example, security protection products can match webshell patterns, such as specific strings, function calls, and code structures, through Yara rules. For another example, security protection products can also match webshell features, such as specific keywords (eval, exec, system, etc.) through regular expressions.
[0033] In order to avoid the detection of webshell attacks by security protection products, attackers usually use obfuscation technology to process the code used to execute webshell attacks, obtain webshell attack obfuscated code, and execute obfuscated webshell attacks. In addition, attackers can also use language models to generate batches of webshell attack obfuscated codes. The webshell attack obfuscated codes generated by the language model can achieve anti-killing, that is, the webshell attack obfuscated codes generated by the language model can bypass the detection of security protection products.
[0034] In view of this, the present application provides a code detection method, which first obtains a first code, performs word segmentation on the first code to obtain multiple word units, then inputs the multiple word units into a hybrid expert model, and receives a code detection result output by the hybrid expert model, wherein the hybrid expert model includes a first expert model for extracting features related to a first type of attack, a second expert model for extracting features related to an obfuscated code, and a third expert model for extracting features related to a code generated by a language model, and the code detection result is determined based on one or more of the features related to the first type of attack, the features related to the obfuscated code, and the features related to the code generated by the language model, and the code detection result is used to characterize whether the first code is an obfuscated code generated by a language model and used to execute the first type of attack.
[0035] In this method, a hybrid expert model is used for code detection. The three expert models in the hybrid expert model respectively detect whether the code is used to execute the first type of attack, whether it is an obfuscated code, and whether it is generated by a language model. By comprehensively considering different features, it is possible to effectively and comprehensively identify whether the code is an attack obfuscated code generated by a language model, thereby improving the protection performance of security protection products against attack behaviors and reducing the risks of false positives and negatives.
[0036] To facilitate understanding of the technical solution provided by the embodiments of the present application, the following will be described in conjunction with the accompanying drawings. Figure 1 A flow chart of a code detection method is shown, and the method specifically includes:
[0037] S101: Obtain a first code.
[0038] The first code can be understood as the code to be detected. In other words, there is a need to detect whether the first code is an obfuscated code generated by a language model and used to perform a certain type of attack (such as a webshell attack). For example, the first code can be a code string in the format of asp, php, jsp, cgi, etc.
[0039] S102: Segment the first code to obtain a plurality of word units.
[0040] In the embodiment of the present application, tokenization can be understood as a process of decomposing the first code into a series of meaningful units, and a meaningful unit can be called a token. In the subsequent code detection process, detection is performed in units of tokens, which helps to improve detection efficiency and detection accuracy.
[0041] In a specific implementation, the process of segmenting the first code can be implemented by any tokenizer, and the first code is input into the tokenizer to obtain a plurality of word units output by the tokenizer.
[0042] S103: Inputting multiple word units into the hybrid expert model, and receiving the code detection result output by the hybrid expert model.
[0043] Among them, the mixture of experts (MoE) model is an efficient deep learning architecture. It decomposes an original task into multiple subtasks and uses different expert models to process different subtasks. In this way, each expert model can focus on a specific subtask, which helps to improve the generalization ability and reasoning performance of the mixture of expert models.
[0044] In an embodiment of the present application, the hybrid expert model includes a first expert model for extracting features related to the first type of attack, a second expert model for extracting features related to obfuscated code, and a third expert model for extracting features related to language model generated code.
[0045] It should be noted that the embodiments of the present application do not limit the first type of attack. For example, the first type of attack may be a webshell attack, or the first type of attack may be any other type of attack.
[0046] The language model has natural language processing capabilities, can understand the meaning of natural language, and process different types of natural language tasks. For example, the language model can be a deep learning model trained using code samples.
[0047] That is to say, in the embodiment of the present application, the original task is "detecting whether the first code is an obfuscated code generated by a language model and used to perform a first type of attack". Since the code generated by the language model is different from the manually written code, for example, the content generated by the language model often has a consistent naming rule, comment style and templated code structure, the original task is decomposed into three subtasks: "detecting whether the first code is used to perform the first type of attack", "detecting whether the first code is an obfuscated code" and "detecting whether the first code is generated by a language model".
[0048] The three expert models are used to perform the above three subtasks respectively, and one or more of the features related to the first type of attack, the features related to the obfuscated code, and the features related to the language model generated code in each word are extracted. In other words, the hybrid expert model processes multiple subtasks for each word, and identifies whether there are features representing the first type of attack, features representing the obfuscated code, and features of the generation traces of the language model in each word of the first code. Then, based on one or more of the features related to the first type of attack, features related to the obfuscated code, and features related to the language model generated code (such as consistent grammar, code structure, naming rules, comment style, etc.), the code detection result of the first code is determined. The code detection result can be used to characterize whether the first code belongs to the obfuscated code generated by the language model and used to perform the first type of attack, thereby improving the accuracy and robustness of code detection. The accuracy of code detection is improved through the collaborative processing of multiple expert models.
[0049] The embodiments of the present application do not limit the types of the first expert model, the second expert model, and the third expert model. For example, the first expert model, the second expert model, and the third expert model may be language models with natural language processing capabilities. For another example, the first expert model, the second expert model, and the third expert model may also be other models with code recognition capabilities.
[0050] In a hybrid expert model, each word can be processed by one or more expert models. Figure 2 The structural diagram of a hybrid expert model is shown. The hybrid expert model may further include a gate route, and the output of the gate route is the input of the first expert model, the second expert model and the third expert model respectively.
[0051] Among them, the gate routing, which can also be called a gate network, a router, a gated network, etc., can be implemented based on a neural network. In an embodiment of the present application, the gate routing can be used to receive each word unit of the first code and assign each word unit to one or more expert models in the hybrid expert model, that is, to determine the expert model that needs to be activated for each word unit.
[0052] In specific implementation, for each of the multiple word-grams, the following operations are performed: for each of the multiple word-grams, the following operations are performed: the word-gram is input into the gate route, so that the gate route determines the activation probability of the expert model of the word-gram, and sends the word-gram to the target expert model corresponding to the activation probability of the expert model, and obtains the target sub-feature of the word-gram returned by the target expert model. Then, the code detection result is determined according to the target sub-feature of each word-gram.
[0053] The target expert model is one or more of the first expert model, the second expert model and the third expert model, and the target sub-feature is one or more of the features related to the first type of attack, the features related to the obfuscated code and the features related to the language model generated code.
[0054] That is, the gate extracts the features of the word-gram, and based on the features of the word-gram, determines which expert model or models should process the word-gram, and generates the expert model activation probability (e.g., weight distribution) of the word-gram. The expert model activation probability can be used to represent the probability of each expert model being activated. In this way, the gate combines the expert model activation probability of the word-gram to determine the target expert model for processing the word-gram, and then sends the word-gram to the target expert model, so that the target expert model extracts features from the word-gram and obtains the target sub-features of the word-gram.
[0055] In some embodiments, the gate can activate all expert models whose activation probabilities indicated by the expert model activation probabilities are not 0, that is, the target expert model corresponding to the expert model activation probability is the expert model whose activation probability is not 0. For example, if the expert model activation probability is 0.5 for the first expert model, 0.2 for the second expert model, and 0.3 for the third expert model, then the target expert models corresponding to the expert model activation probability are the first expert model, the second expert model, and the third expert model. If the expert model activation probability is 0.7 for the first expert model, 0 for the second expert model, and 0.3 for the third expert model, then the target expert models corresponding to the expert model activation probability are the first expert model and the third expert model.
[0056] In other embodiments, the gate routing can also be sparsely activated, activating only some expert models to reduce computational overhead. For example, the target expert model corresponding to the expert model activation probability is the expert model selected by Top-K or Top-P. For example, in Top-K selection, K=2, the expert model activation probability is 0.5 for the first expert model, 0.2 for the second expert model, and 0.3 for the third expert model. After sorting the activation probabilities from high to low, since the activation probabilities of the first expert model and the third expert model are in the top 2, the target expert models corresponding to the expert model activation probabilities are the first expert model and the third expert model. In the Top-P selection, P = 0.6, the activation probability of the expert model is 0.55 for the first expert model, 0.25 for the second expert model, and 0.2 for the third expert model. After sorting the activation probabilities from high to low, since the sum of the activation probabilities of the first expert model and the second expert model is greater than 0.6, the target expert models corresponding to the expert model activation probabilities are the first expert model and the second expert model.
[0057] In this way, the gates in the hybrid expert model send different parts of the first code (ie, different word units) to the expert model adapted to the word unit for processing, thereby obtaining the target sub-features of each word unit and improving the efficiency and performance of the hybrid expert model.
[0058] Further, continue as Figure 2 As shown, the hybrid expert model may also include a feedforward neural network and a classifier, the input of the feedforward neural network is the output of the first expert model, the second expert model and the third expert model, and the input of the classifier is the output of the feedforward neural network.
[0059] In an embodiment of the present application, a feedforward neural network can be used to fuse target sub-features of each word unit, and a classifier can be used to classify the first code based on the fused features of each word unit, and output a code detection result of the first code.
[0060] In the specific implementation, for the target sub-feature of each word unit, the following operations are performed: the target sub-feature of the word unit is sent to the feedforward neural network, so that the feedforward neural network fuses the target sub-feature of the word unit according to the activation probability of the expert model of the word unit to obtain the target feature of the word unit. Then, the target feature of each word unit is sent to the classifier to obtain the code detection result output by the classifier.
[0061] Since the activation probability of the expert model of the word-unit can be used to indicate the probability of each expert model being activated, therefore, in the process of feature fusion of the feedforward neural network, the target sub-features extracted by each target expert model can be fused according to the activation probability indicated by the expert model activation probability to obtain the target feature of the word-unit. For example, the expert model activation probability is 0.5 for the first expert model, 0.2 for the second expert model, and 0.3 for the third expert model. The target expert models corresponding to the expert model activation probability are the first expert model and the third expert model. The target sub-features of the word-unit are the features extracted by the first expert model related to the first type of attack and the features extracted by the third expert model related to the language model generated code. The feedforward neural network can fuse the features related to the first type of attack and the features related to the language model generated code in a ratio of 5:3 to obtain the target feature of the word-unit.
[0062] After the feedforward neural network completes the feature fusion of each word unit of the first code, the classifier can classify the first code based on the target features of each word unit to identify whether the first code is an obfuscated code generated by the language model and used to perform the first type of attack.
[0063] After completing the detection of the first code, the code detection result may also be presented to the user. In some possible implementations, in response to the code detection result indicating that the first code is an obfuscated code generated by a language model and used to perform a first type of attack, a disposal suggestion for the first code is generated. The disposal suggestion may include at least one of the following: a code obfuscation method of the first code and code content generated by a language model in the first code.
[0064] That is to say, when the first code is an obfuscated code generated by a language model and used to execute a first type of attack, the code obfuscation method in the first code and the generation traces of the language model are presented to the user to help the user understand the code detection results so as to respond quickly and accurately.
[0065] In this method, a hybrid expert model is used for code detection. The three expert models in the hybrid expert model respectively detect whether the code is used to execute the first type of attack, whether it is an obfuscated code, and whether it is generated by a language model. By comprehensively considering different features, it is possible to effectively and comprehensively identify whether the code is an attack obfuscated code generated by a language model, thereby improving the protection performance of security protection products against attack behaviors and reducing the risks of false positives and negatives.
[0066] The above text describes the code detection method provided in the embodiment of the present application. In the embodiment of the present application, the first code is detected by means of a hybrid expert model. Figure 3A schematic diagram of a hybrid expert model training process is shown, which introduces the training process of the hybrid expert model.
[0067] In some possible implementations, the hybrid expert model can be trained in the following manner: obtain non-attack code samples and first-type attack code samples, use the non-attack code samples as negative samples and the first-type attack code samples as positive samples, train the first pre-trained model, and obtain the first expert model. Obtain unobfuscated code samples and obfuscated code samples, use the unobfuscated code samples as negative samples and the obfuscated code samples as positive samples, train the second pre-trained model, and obtain the second expert model. Obtain manually written code samples and code samples generated by a language model, use the manually written code samples as negative samples and the code samples generated by the language model as positive samples, train the third pre-trained model, and obtain the third expert model.
[0068] Among them, the first pre-trained model, the second pre-trained model and the third pre-trained model can be pre-trained language models. In other words, in an embodiment of the present application, fine-tuning is performed on the basis of the first pre-trained model, the second pre-trained model and the third pre-trained model, so that the fine-tuned first expert model has the ability to extract features related to the first type of attack and detect whether the first code is used for the first type of attack, the fine-tuned second expert model has the ability to extract features related to obfuscated code and detect whether the first code is an obfuscated code, and the fine-tuned third expert model has the ability to extract features related to code generated by the language model and detect whether the first code is generated by the language model.
[0069] In a specific implementation, the first pre-trained model, the second pre-trained model and the third pre-trained model are trained in a supervised training manner to generate a first expert model, a second expert model and a third expert model. In supervised training, model training is performed using labeled training data. In an embodiment of the present application, a label can be understood as a positive sample or a negative sample, that is, for a positive sample, the trained model should output a positive classification result, and for a negative sample, the trained model should output a negative classification result.
[0070] It should be noted that in the embodiment of the present application, in the training stage of the hybrid expert model, in order to better enable the first expert model, the second expert model and the third expert model to focus on feature extraction and improve the generalization ability of the first expert model, the second expert model and the third expert model, an external classifier can be added after the first pre-trained model, the second pre-trained model and the third pre-trained model.
[0071] Specifically, in the training stage of the first expert model, a first classifier is connected externally to the first pre-trained model, and the first classifier can be used to classify the features extracted by the first pre-trained model to obtain a first classification result indicating whether it is used to perform a first type of attack, and then the cross entropy loss is calculated in combination with the label, and the first pre-trained model is trained to obtain the first expert model. In the training stage of the second expert model, a second classifier is connected externally to the second pre-trained model, and the second classifier can be used to classify the features extracted by the second pre-trained model to obtain a second classification result indicating whether it is an obfuscated code, and then the cross entropy loss is calculated in combination with the label, and the second pre-trained model is trained to obtain the second expert model. In the training stage of the third expert model, a third classifier is connected externally to the third pre-trained model, and the third classifier can be used to classify the features extracted by the third pre-trained model to obtain a third classification result indicating whether it is generated by a language model, and then the cross entropy loss is calculated in combination with the label, and the third pre-trained model is trained to obtain the third expert model.
[0072] In the reasoning stage of the hybrid expert model, no external classifier is required after the first expert model, the second expert model and the third expert model. The first expert model, the second expert model and the third expert model only need to extract the features of word units.
[0073] Continue as Figure 3 As shown, the non-attack code sample can be understood as a code that is not used to execute the first type of attack. In some embodiments, the first type of attack is a webshell attack, and the non-attack code sample can be a code in the format of asp, php, jsp, cgi, etc. that is not used to execute the webshell attack. The first type of attack code sample can be understood as a code for executing a webshell attack. In some embodiments, the first type of attack code sample can include at least one of the following: a first type of attack code written manually and a first type of attack obfuscated code generated by a language model.
[0074] The non-obfuscated code sample can be understood as code without code obfuscation, and the obfuscated code sample can be understood as code with code obfuscation. In some embodiments, the obfuscated code sample can include at least one of the following: manually written obfuscated code and obfuscated code generated by a language model.
[0075] The manually written code sample can be understood as code written by humans (e.g., developers), and the language model generated code sample can be understood as code automatically generated by the language model and having traces of language model generation. In some embodiments, the language model generated code sample can include at least one of the following: obfuscated code generated by the language model and code generated by the language model.
[0076] In some possible implementations, the first type of attack obfuscation code generated by the language model and the obfuscation code generated by the language model are generated by: obtaining a first obfuscation code, a second obfuscation code, a first non-obfuscation code, and a second non-obfuscation code, using the first language model to perform code obfuscation methods on the first obfuscation code and the second obfuscation code to obtain at least one code obfuscation method, and then, using the second language model, based on at least one code obfuscation method, performing code obfuscation on the first non-obfuscation code and the second non-obfuscation code to obtain the first type of attack obfuscation code generated by the language model and the obfuscation code generated by the language model.
[0077] The first obfuscated code is an obfuscated code used to execute the first type of attack, the second obfuscated code is an obfuscated code unrelated to the first type of attack, the first non-obfuscated code is a non-obfuscated code used to execute the first type of attack, and the second non-obfuscated code is a non-obfuscated code unrelated to the first type of attack.
[0078] That is to say, by extracting the code obfuscation method of the obfuscated code used to perform the first type of attack and the obfuscated code unrelated to the first type of attack, the extracted code obfuscation method is used as a template, and the non-obfuscated code used to perform the first type of attack and the non-obfuscated code unrelated to the first type of attack are obfuscated, and a large number of obfuscated codes generated by the language model are generated, so as to achieve data enhancement and improve the training effect.
[0079] The code obfuscation method can be understood as a method for obfuscating the code. In some embodiments, the code obfuscation method may include at least one of the following: a method of operating a string in the code using a bitwise operator, a method of concatenating or splitting a string in the code, a method of using random variable names in the code, a method of obfuscating the input and output parameters of a function call in the code, and a method of obfuscating a conditional judgment statement in the code.
[0080] In a method of using bitwise operators to operate strings in the code, bitwise operators (such as "&", "|", and "^") are used to operate strings in the code, making the code difficult to understand. For example, the obfuscated code may be "<?php$var1='string1'&'string2';$var2='string3'|'string4';$var3='string5'^'string6';?>". In a method of concatenating or splitting strings in the code, the string content in the code is hidden by concatenating or splitting strings. For example, the obfuscated code may be "<?php$var4='part1'.'part2'.'part3';$var5='part4'&'part5';?>". In a method of using random variable names in the code, random and meaningless variable names are used to make the code difficult to read and understand. For example, the obfuscated code may be "<?php$complexVar1='value1';$complexVar2='value2';?>". In the method of obfuscating the input and output parameters of the function call in the code, the parameters and return values of the function call in the code are obfuscated to make the code logic difficult to identify. For example, the obfuscated code can be "<?phpif(function1($param1($param2))==$expectedValue){$result=function2($param3,param1($param4.$param5.$param6));$result($param7,$param8,$param9);}?>". In the method of obfuscating the conditional judgment statement in the code, the execution path of the code is difficult to predict through complex conditional judgment. For example, the obfuscated code can be "<?phpif($condition1($param1($param2))==$expectedValue){ / / Execute code}?>".
[0081] In the embodiment of the present application, the code obfuscation method is extracted and the code obfuscation is performed with the help of a language model. Among them, the first language model can be understood as a language model for extracting the code obfuscation method, and the second language model can be understood as a language model for performing code obfuscation. The first language model and the second language model have natural language processing capabilities, can understand the meaning of natural language, and process different types of natural language tasks. For example, the first language model and the second language model can be deep learning models trained using text data.
[0082] The first language model can extract the first obfuscated code and the second obfuscated code in a code obfuscation manner based on a prompt learning method. Among them, the prompt word can be used to guide the language model to perform specific output in a generative task (such as a text generation task, a question-answering task, and a dialogue task). By configuring the prompt word, the language model is helped to understand the background and requirements of the task, so that the language model can handle different types of natural language processing tasks without retraining the language model, thereby increasing the scalability and flexibility of the language model.
[0083] In a specific implementation, a first prompt word is generated, the first prompt word is sent to a first language model, and at least one code obfuscation method returned by the first language model is received.
[0084] The first prompt word may include a first obfuscated code, a second obfuscated code, and information for indicating an obfuscated method for extracting the code. By configuring the above information in the first prompt word, the first language model can extract the code obfuscation method from the first obfuscated code and the second obfuscated code based on the prompt capability of the first prompt word.
[0085] For example, the first prompt word can be as follows:
[0086] “You are a professional code analysis expert who is good at detecting obfuscation in code, accurately analyzing code obfuscation methods, and providing clear obfuscation templates.
[0087] When a user provides a piece of code, carefully check whether the code is obfuscated. If it is obfuscated, analyze the specific code obfuscation method, explain each code obfuscation method in detail, and give examples of the code obfuscation method.
[0088] The code is as follows: {first obfuscated code}, {second obfuscated code}"
[0089] After the code obfuscation method is extracted, the first non-obfuscated code and the second non-obfuscated code are obfuscated using one or more code obfuscation methods with the help of the second language model to obtain the first type of attack obfuscated code generated by the language model and the obfuscated code generated by the language model.
[0090] Similarly, the second language model can perform code obfuscation on the first non-obfuscated code and the second non-obfuscated code based on the prompt learning method. In specific implementation, a second prompt word is generated, the second prompt word is sent to the second language model, and the first type of attack obfuscated code generated by the language model and the obfuscated code generated by the language model after code obfuscation are received from the second language model.
[0091] The second prompt word may include at least one code obfuscation method, a first non-obfuscated code, a second non-obfuscated code, and information for indicating that the code obfuscation method is used to perform code obfuscation. By configuring the above information in the second prompt word, the second language model can perform code obfuscation on the first non-obfuscated code and the second non-obfuscated code based on the prompt capability of the second prompt word.
[0092] For example, the second prompt word can be as follows:
[0093] “You are a professional code obfuscation expert who can accurately confuse the input code according to the given code obfuscation method while ensuring that the obfuscated code functions remain unchanged.
[0094] When the user inputs the code and the code obfuscation method, the code structure and the code obfuscation method are carefully analyzed, and the code is obfuscated strictly according to the code obfuscation method to ensure that the obfuscated code is completely consistent with the original code in terms of function.
[0095] The code obfuscation methods are as follows: {At least one code obfuscation method}
[0096] The code is as follows: {first non-obfuscated code}, {second non-obfuscated code}"
[0097] For example, the first non-obfuscated code is "<?php eval(@$_POST['pass']);?>", the code obfuscation method is "the method of using bitwise operators to operate on strings in the code", and the first type of attack obfuscated code generated by the language model returned by the second language model is "<?php$var='e'^'E';$var2='v'^'V';$var3='a'^'A';$var4='l'^'L';$var5='(@'^'(@';$var6='_POST'^'_POSt';$var7='[\'pass\']'^'[\'pass\']';$code=($var1.$var2.$var3.$var4).$var5.$var6.$var7;eval($code);?>".
[0098] In some possible implementations, the code generated by the language model is generated by obtaining a third non-obfuscated code and a fourth non-obfuscated code, and rewriting the third non-obfuscated code and the fourth non-obfuscated code using a third language model to obtain the code generated by the language model.
[0099] The third non-obfuscated code is a non-obfuscated code used to execute the first type of attack, and the second non-obfuscated code is a non-obfuscated code unrelated to the first type of attack.
[0100] That is to say, the manually written code is rewritten with the help of the third language model to generate a large amount of code generated by the language model, so as to achieve data enhancement and improve the training effect. Among them, the third language model can be understood as a language model used to rewrite the code. The third language model has natural language processing capabilities, can understand the meaning of natural language, and process different types of natural language tasks. For example, the third language model can be a deep learning model trained using text data.
[0101] Similarly, the third language model can rewrite the third non-obfuscated code and the fourth non-obfuscated code based on the prompt learning method. In specific implementation, a third prompt word is generated, the third prompt word is sent to the third language model, and the rewritten code generated by the language model returned by the third language model is received.
[0102] The third prompt word may include a third non-obfuscated code, a fourth non-obfuscated code, and information for indicating that the code is optimized. By configuring the above information in the third prompt word, the third language model can rewrite the third non-obfuscated code and the fourth non-obfuscated code based on the prompt capability of the third prompt word, so that the rewritten code has the generation trace of the language model.
[0103] For example, the third prompt word can be as follows:
[0104] “You are a code optimization master who can accurately analyze and optimize the input code. Whether it is a code standardization problem or an organizational structure problem, you can provide high-quality solutions.
[0105] When receiving a piece of code, carefully check whether it conforms to common programming standards. If there are any standardization issues, point out the problems and provide standard code. If the code standardization is fine, analyze whether its organizational structure can be optimized. Under the premise of keeping the code function unchanged, adjust the organizational structure of the code to make it clearer and easier to read.
[0106] The code is as follows: {third non-obfuscated code}, {fourth non-obfuscated code}"
[0107] In this way, a large amount of effective training data is generated for the first expert model, the second expert model, and the third expert model, enriching the training data set, accelerating the training process of the hybrid expert model, and improving the hybrid expert model's ability to identify the first type of attack in a real environment. In addition, it can quickly adapt to the emergence of new first type attacks, optimize the detection methods for the obfuscated first type attacks, and maintain efficient detection capabilities.
[0108] Furthermore, the hybrid expert model may also include a gate route. Similarly, since the gate route is used to determine the expert model that needs to be activated for each word unit, during the training process of the gate route, code samples for executing the first type of attack (including manually written code for executing the first type of attack and code generated by the language model for executing the first type of attack) and code samples unrelated to the first type of attack are used to train the parameters of the gate route.
[0109] Combination of the above Figures 1 to 3 The code detection method provided in the embodiment of the present application is introduced in detail. The device and equipment provided in the embodiment of the present application will be introduced in conjunction with the accompanying drawings.
[0110] See also Figure 4 The schematic diagram of the structure of the code detection device shown in FIG. 40 includes:
[0111] An acquisition module 401 is used to acquire a first code;
[0112] A word segmentation module 402, used to segment the first code to obtain a plurality of word units;
[0113] The detection module 403 is used to input the multiple word-grams into the hybrid expert model, and receive the code detection result output by the hybrid expert model; wherein the hybrid expert model includes a first expert model for extracting features related to the first type of attack, a second expert model for extracting features related to the obfuscated code, and a third expert model for extracting features related to the code generated by the language model; the code detection result is determined based on one or more of the features related to the first type of attack, the features related to the obfuscated code, and the features related to the code generated by the language model; the code detection result is used to characterize whether the first code is an obfuscated code generated by the language model and used to execute the first type of attack.
[0114] In some possible implementations, the hybrid expert model further includes a gate route, and outputs of the gate route are inputs of the first expert model, the second expert model, and the third expert model respectively; the detection module 403 is specifically used for:
[0115] For each word-gram of the plurality of word-grams, the following operations are performed: inputting the word-gram into the gate route so that the gate route determines the expert model activation probability of the word-gram, and sending the word-gram to the target expert model corresponding to the expert model activation probability, and obtaining the target sub-feature of the word-gram returned by the target expert model; wherein the target expert model is one or more of the first expert model, the second expert model and the third expert model, and the target sub-feature is one or more of the feature related to the first type of attack, the feature related to the obfuscated code and the feature related to the language model generated code;
[0116] The code detection result is determined according to the target sub-feature of each word.
[0117] In some possible implementations, the hybrid expert model further includes a feedforward neural network and a classifier, the input of the feedforward neural network is the output of the first expert model, the second expert model and the third expert model, and the input of the classifier is the output of the feedforward neural network; the detection module 403 is specifically used to:
[0118] For the target sub-feature of each word-gram, the following operations are performed: the target sub-feature of the word-gram is sent to the feedforward neural network, so that the feedforward neural network fuses the target sub-feature of the word-gram according to the activation probability of the expert model of the word-gram to obtain the target feature of the word-gram;
[0119] The target feature of each word is sent to the classifier to obtain the code detection result output by the classifier.
[0120] In some possible implementations, the apparatus 40 further includes a processing module, and the processing module is configured to:
[0121] In response to the code detection result characterizing that the first code is an obfuscated code generated by a language model and used to perform a first type of attack, a disposal suggestion for the first code is generated; wherein the disposal suggestion includes at least one of the following: a code obfuscation method of the first code and code content in the first code generated by the language model.
[0122] In some possible implementations, the hybrid expert model is trained in the following manner:
[0123] Obtaining non-attack code samples and first-type attack code samples, taking the non-attack code samples as negative samples and the first-type attack code samples as positive samples, training a first pre-trained model, and obtaining the first expert model;
[0124] Obtaining an unobfuscated code sample and an obfuscated code sample, taking the unobfuscated code sample as a negative sample and the obfuscated code sample as a positive sample, training a second pre-trained model, and obtaining the second expert model;
[0125] Obtain manually written code samples and code samples generated by a language model, use the manually written code samples as negative samples and the code samples generated by the language model as positive samples, train the third pre-trained model, and obtain the third expert model.
[0126] In some possible implementations, the first type of attack code sample includes at least one of the following: manually written first type attack code and first type attack obfuscated code generated by a language model; the obfuscated code sample includes at least one of the following: manually written obfuscated code and obfuscated code generated by a language model; the code sample generated by the language model includes at least one of the following: obfuscated code generated by a language model and code generated by a language model.
[0127] In some possible implementations, the first type attack obfuscation code generated by the language model and the obfuscation code generated by the language model are generated in the following manner:
[0128] Obtain a first obfuscated code, a second obfuscated code, a first non-obfuscated code, and a second non-obfuscated code; wherein the first obfuscated code is an obfuscated code used to perform a first type of attack, the second obfuscated code is an obfuscated code unrelated to the first type of attack, the first non-obfuscated code is a non-obfuscated code used to perform the first type of attack, and the second non-obfuscated code is a non-obfuscated code unrelated to the first type of attack;
[0129] Using a first language model, extracting code obfuscation methods from the first obfuscated code and the second obfuscated code to obtain at least one code obfuscation method;
[0130] The first non-obfuscated code and the second non-obfuscated code are obfuscated by using the second language model based on the at least one code obfuscation method to obtain the first type of attack obfuscated code generated by the language model and the obfuscated code generated by the language model.
[0131] In some possible implementations, the code obfuscation method includes at least one of the following:
[0132] How to use bitwise operators to manipulate strings in code;
[0133] How to concatenate or split strings in the code;
[0134] How to use random variable names in your code;
[0135] A way to obfuscate the input and output parameters of function calls in the code;
[0136] A way to obfuscate conditional statements in the code.
[0137] In some possible implementations, the code generated by the language model is generated in the following manner:
[0138] Obtain a third non-obfuscated code and a fourth non-obfuscated code; wherein the third non-obfuscated code is a non-obfuscated code used to execute the first type of attack, and the second non-obfuscated code is a non-obfuscated code unrelated to the first type of attack;
[0139] The third non-obfuscated code and the fourth non-obfuscated code are rewritten using a third language model to obtain a code generated by the language model.
[0140] The code detection device 40 according to the embodiment of the present application may correspond to the method described in the embodiment of the present application, and the above and other operations and / or functions of each module / unit of the code detection device 40 are respectively to implement Figure 1 For the sake of brevity, the corresponding processes of each method in the illustrated embodiment are not described in detail here.
[0141] The present application also provides an electronic device. The electronic device is specifically used to implement Figure 4 The function of the code detection device 40 in the illustrated embodiment.
[0142] Figure 5 A schematic diagram of the structure of an electronic device 500 is provided. Figure 5 As shown, the electronic device 500 includes a bus 501, a processor 502, a communication interface 503 and a memory 504. The processor 502, the memory 504 and the communication interface 503 communicate with each other via the bus 501.
[0143] The bus 501 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0144] The processor 502 may be any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0145] The communication interface 503 is used for communicating with the outside. For example, the communication interface 503 can be used for communicating with a terminal.
[0146] The memory 504 may include a volatile memory, such as a random access memory (RAM). The memory 504 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0147] The memory 504 stores executable codes, and the processor 502 executes the executable codes to perform the aforementioned code detection method.
[0148] Specifically, in implementing Figure 4 In the case of the embodiment shown, and Figure 4 When each module or unit of the code detection device 40 described in the embodiment is implemented by software, the execution Figure 4 The software or program code required for the functions of each module / unit in the system may be partially or completely stored in the memory 504. The processor 502 executes the program code corresponding to each unit stored in the memory 504 and executes the aforementioned code detection method.
[0149] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state hard disk). The computer-readable storage medium includes instructions that instruct the computing device to execute the above-mentioned code detection method applied to the code detection device 40.
[0150] The embodiment of the present application further provides a computer program product, which includes one or more computer instructions. When the computer instructions are loaded and executed on a computing device, the process or function described in the embodiment of the present application is generated in whole or in part.
[0151] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer or data center to another website, computer or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.
[0152] When the computer program product is executed by a computer, the computer executes any of the aforementioned code detection methods. The computer program product may be a software installation package, and when any of the aforementioned code detection methods is needed, the computer program product may be downloaded and executed on a computer.
[0153] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to each embodiment of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0154] The units involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the unit / module does not, in some cases, constitute a limitation on the unit itself.
[0155] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0156] In the context of the present application embodiment, machine-readable medium can be a tangible medium that can contain or store a program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the above. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.
[0157] It should be noted that the various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments, and the same or similar parts between the various embodiments can be referred to each other. For the system or device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description.
[0158] It should be understood that in the present application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0159] It should also be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0160] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0161] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A code detection method, characterized in that: The method comprises: Get the first code; Segmenting the first code to obtain a plurality of word units; The multiple word-grams are input into a hybrid expert model, and a code detection result output by the hybrid expert model is received; wherein the hybrid expert model includes a first expert model for extracting features related to a first type of attack, a second expert model for extracting features related to obfuscated codes, and a third expert model for extracting features related to code generated by a language model; the code detection result is determined based on one or more of the features related to the first type of attack, the features related to the obfuscated codes, and the features related to code generated by the language model; and the code detection result is used to characterize whether the first code is an obfuscated code generated by a language model and used to execute the first type of attack.
2. The method according to claim 1, characterized in that The hybrid expert model further includes a gate route, and the outputs of the gate route are respectively inputs of the first expert model, the second expert model and the third expert model; The step of inputting the plurality of word-grams into a hybrid expert model and receiving a code detection result output by the hybrid expert model comprises: For each word-gram of the plurality of word-grams, the following operations are performed: inputting the word-gram into the gate route so that the gate route determines the expert model activation probability of the word-gram, and sending the word-gram to the target expert model corresponding to the expert model activation probability, and obtaining the target sub-feature of the word-gram returned by the target expert model; wherein the target expert model is one or more of the first expert model, the second expert model and the third expert model, and the target sub-feature is one or more of the feature related to the first type of attack, the feature related to the obfuscated code and the feature related to the language model generated code; The code detection result is determined according to the target sub-feature of each word.
3. The method according to claim 2, characterized in that The hybrid expert model further comprises a feedforward neural network and a classifier, the input of the feedforward neural network is the output of the first expert model, the second expert model and the third expert model, and the input of the classifier is the output of the feedforward neural network; The step of determining the code detection result according to the target sub-feature of each word element includes: For the target sub-feature of each word-gram, the following operations are performed: the target sub-feature of the word-gram is sent to the feedforward neural network, so that the feedforward neural network fuses the target sub-feature of the word-gram according to the activation probability of the expert model of the word-gram to obtain the target feature of the word-gram; The target feature of each word is sent to the classifier to obtain the code detection result output by the classifier.
4. The method according to claim 1, characterized in that: The method further comprises: In response to the code detection result characterizing that the first code is an obfuscated code generated by a language model and used to perform a first type of attack, a disposal suggestion for the first code is generated; wherein the disposal suggestion includes at least one of the following: a code obfuscation method of the first code and code content in the first code generated by the language model.
5. The method according to any one of claims 1 to 4, characterized in that: The hybrid expert model is trained in the following way: Obtaining non-attack code samples and first-type attack code samples, taking the non-attack code samples as negative samples and the first-type attack code samples as positive samples, training a first pre-trained model, and obtaining the first expert model; Obtaining an unobfuscated code sample and an obfuscated code sample, taking the unobfuscated code sample as a negative sample and the obfuscated code sample as a positive sample, training a second pre-trained model, and obtaining the second expert model; Obtain manually written code samples and code samples generated by a language model, use the manually written code samples as negative samples and the code samples generated by the language model as positive samples, train the third pre-trained model, and obtain the third expert model.
6. The method according to claim 5, characterized in that The first type of attack code sample includes at least one of the following: manually written first type of attack code and first type of attack obfuscated code generated by a language model; The obfuscated code sample includes at least one of the following: manually written obfuscated code and obfuscated code generated by a language model; The code sample generated by the language model includes at least one of the following: obfuscated code generated by the language model and code generated by the language model.
7. The method according to claim 6, characterized in that The first type of attack obfuscation code generated by the language model and the obfuscation code generated by the language model are generated in the following manner: Obtaining a first obfuscated code, a second obfuscated code, a first non-obfuscated code, and a second non-obfuscated code; wherein the first obfuscated code is an obfuscated code for executing a first type of attack, the second obfuscated code is an obfuscated code unrelated to the first type of attack, the first non-obfuscated code is a non-obfuscated code for executing the first type of attack, and the second non-obfuscated code is a non-obfuscated code unrelated to the first type of attack; Using a first language model, extracting code obfuscation methods from the first obfuscated code and the second obfuscated code to obtain at least one code obfuscation method; The first non-obfuscated code and the second non-obfuscated code are obfuscated by using the second language model based on the at least one code obfuscation method to obtain the first type of attack obfuscated code generated by the language model and the obfuscated code generated by the language model.
8. The method according to claim 7, characterized in that The code obfuscation method includes at least one of the following: How to use bitwise operators to manipulate strings in code; How to concatenate or split strings in the code; How to use random variable names in your code; A way to obfuscate the input and output parameters of function calls in the code; A way to obfuscate conditional statements in the code.
9. The method according to claim 6, characterized in that The code generated by the language model is generated in the following way: Obtain a third non-obfuscated code and a fourth non-obfuscated code; wherein the third non-obfuscated code is a non-obfuscated code used to execute the first type of attack, and the second non-obfuscated code is a non-obfuscated code unrelated to the first type of attack; The third non-obfuscated code and the fourth non-obfuscated code are rewritten using a third language model to obtain a code generated by the language model.
10. A code detection device, characterized in that: The device comprises: An acquisition module, used for acquiring a first code; A word segmentation module, used for segmenting the first code to obtain multiple word units; A detection module is used to input the multiple word-grams into a hybrid expert model, and receive a code detection result output by the hybrid expert model; wherein the hybrid expert model includes a first expert model for extracting features related to a first type of attack, a second expert model for extracting features related to an obfuscated code, and a third expert model for extracting features related to a code generated by a language model, and the code detection result is determined based on one or more of the features related to the first type of attack, the features related to the obfuscated code, and the features related to the code generated by the language model, and the code detection result is used to characterize whether the first code is an obfuscated code generated by a language model and used to execute the first type of attack.
11. An electronic device, characterized in that: The electronic device comprises a processor and a memory; The processor is configured to execute instructions stored in the memory, so that the electronic device performs the method according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that: The method comprises instructions, wherein the instructions instruct an electronic device to execute the method as claimed in any one of claims 1 to 9.
13. A computer program product, characterized in that The computer program product comprises computer readable instructions for implementing the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Malicious application detection method and system for discriminating adversarial network
CN113127872A
Webshell detection method and device
CN113591074A
Malicious code detection model generation method and device, malicious code detection method and device, equipment and medium
CN117370980A
XSS attack detection method and device, computer equipment and storage medium
CN117728995A
Prompt word attack detection method and device for large language model
CN118445815A