Error interception identification method and device, equipment and storage medium
By obtaining and analyzing the interception log of the Web firewall, determining the candidate log and performing replay processing, the problem of emergency response personnel intercepting requests is solved, the recognition accuracy and efficiency are improved, and business stability is ensured.
Patent Information
- Application Number
- CN202510238030.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-09
AI Technical Summary
In the offensive and defensive confrontation of the Internet of Things, emergency response personnel are prone to launching wrong WAF interception rules, resulting in user's normal requests being accidentally intercepted and business interruption. The existing recognition methods have low recognition accuracy and many interferences, so they cannot targeted identification of each interception log.
Provides an identification method of misinterception. By obtaining the preset web firewall's interception log data set, determining the candidate log based on the access information in the interception log, and replaying the interception request in the candidate log to obtain the error interception identification result. This method includes three steps: log acquisition, candidate log determination and playback processing, which improves the recognition accuracy of error interception.
Through preliminary screening and playback processing, it is possible to accurately find which request was accidentally intercepted, improve the identification accuracy and efficiency of the false interception, assist emergency response personnel in launching the correct WAF interception rules, and reduce business interruptions.
Smart Images

Figure CN119966745A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of firewalls in the field of Internet of Things, and in particular to a method, device, equipment and storage medium for identifying false interception. Background Art
[0002] In the attack and defense confrontation of the Internet of Things, emergency responders usually use WAF (Web Application Firewall) to deal with sudden application layer vulnerabilities. However, emergency responders are more likely to put the wrong WAF interception rules online, causing the user's normal requests to be intercepted by mistake, resulting in business interruption. Summary of the invention
[0003] The present disclosure provides a method, device, equipment and storage medium for identifying false interception.
[0004] According to a first aspect of the present disclosure, a method for identifying a false interception is provided, comprising:
[0005] Obtaining a preset interception log data set of a first Web firewall; wherein the interception log data set includes a plurality of interception logs;
[0006] Determine a candidate log according to the access information in each of the interception logs; wherein the access information represents information requesting access to a Web application, and the probability that the candidate log represents that the interception log is intercepted by mistake is greater than a preset probability value;
[0007] The interception request in the candidate log is replayed to obtain an erroneous interception identification result; wherein the erroneous interception identification result indicates whether the candidate log is an interception log of erroneous interception.
[0008] According to a second aspect of the present disclosure, a device for identifying a misinterception is provided, comprising:
[0009] A log acquisition unit, used to acquire a preset interception log data set of a first Web firewall; wherein the interception log data set includes a plurality of interception logs;
[0010] A candidate determination unit, configured to determine a candidate log according to the access information in each of the interception logs; wherein the access information represents information of a request to access a Web application, and the probability that the candidate log represents that the interception log is intercepted by mistake is greater than a preset probability value;
[0011] The request identification unit is used to replay the interception request in the candidate log to obtain an erroneous interception identification result; wherein the erroneous interception identification result indicates whether the candidate log is an interception log of erroneous interception.
[0012] According to a third aspect of the present disclosure, there is provided an electronic device, including:
[0013] at least one processor; and
[0014] a memory communicatively coupled to the at least one processor;
[0015] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method described in the first aspect of the present disclosure.
[0016] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to execute the method according to the first aspect of the present disclosure.
[0017] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising a computer program, which implements the steps of the method described in the first aspect of the present disclosure when executed by a processor.
[0018] According to the technology disclosed in the present invention, the recognition accuracy of false interception is improved.
[0019] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings are used to better understand the present solution and do not constitute a limitation of the present disclosure.
[0021] Figure 1 It is a flowchart of a method for identifying a false interception provided according to an embodiment of the present disclosure;
[0022] Figure 2 It is a flowchart of a method for identifying a false interception provided according to an embodiment of the present disclosure;
[0023] Figure 3 It is a flowchart of a method for identifying a false interception provided according to an embodiment of the present disclosure;
[0024] Figure 4 It is a schematic diagram of engine dialing test of a second Web firewall provided according to an embodiment of the present disclosure;
[0025] Figure 5 is an overall flow chart of false interception identification provided according to an embodiment of the present disclosure;
[0026] Figure 6is a structural block diagram of a device for identifying misinterception provided according to an embodiment of the present disclosure;
[0027] Figure 7 is a structural block diagram of a device for identifying misinterception provided according to an embodiment of the present disclosure;
[0028] Figure 8 A frame of an electronic device for implementing a method for identifying a false interception according to an embodiment of the present disclosure;
[0029] Fig. 9 It is a block diagram of an electronic device used to implement a method for identifying false interception according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0030] The following is a description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those of ordinary skill in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0031] In the attack and defense confrontation, emergency response personnel will upload the configuration file of WAF interception rules and use WAF interception rules to deal with sudden application layer vulnerabilities. WAF interception rules can be used to determine which requests should not be passed and intercept them. However, due to objective factors such as time pressure and insufficient configuration files, emergency response personnel are more likely to upload wrong WAF interception rules, resulting in the user's normal requests being intercepted by mistake, causing business interruption.
[0032] The current interception identification method usually issues an alarm when there is a sudden increase in indicators such as the number of interceptions. However, this identification method has a lot of interference and may trigger unexpected alarms. It is also unable to perform targeted identification on each interception log, and the identification accuracy is low.
[0033] The present disclosure provides a method, device, equipment and storage medium for identifying false interception, which are applied to the firewall field in the field of Internet of Things to improve the accuracy of identifying false interception.
[0034] It should be noted that the data in this embodiment is not targeted at a specific user and cannot reflect the personal information of a specific user. It should be noted that the data in this embodiment comes from a public data set.
[0035] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0036] In order to enable readers to more deeply understand the implementation principle of the present disclosure, the following Figure 1-Figure 9 The embodiment is further refined.
[0037] Figure 1 FIG. 1 is a flow chart of a method for identifying a misinterception according to an embodiment of the present disclosure, and the method can be performed by a misinterception identification device. Figure 1 As shown, the method comprises the following steps:
[0038] S101. Obtain a preset interception log data set of a first Web firewall; wherein the interception log data set includes a plurality of interception logs.
[0039] Exemplarily, the Web firewall is a Web application-level intrusion prevention system, which can be referred to as WAF in this embodiment. Web applications can receive various access requests, and WAF can respond to sudden application layer vulnerabilities. According to the WAF interception rules put online by emergency response personnel, abnormal access requests are intercepted, and an interception log can be generated for each abnormal access request. The first Web firewall is a preset WAF engine. The interception log includes information such as the content, time, and visitor IP (Internet Protocol Address) of the intercepted request.
[0040] According to a preset time period, multiple interception logs generated by the WAF can be obtained regularly to obtain an interception log data set. That is, the interception log data set can include multiple interception logs. For example, the interception logs within one month can be obtained as the interception log data set.
[0041] S102, determining candidate logs according to access information in each interception log; wherein the access information represents information of a request to access a Web application, and the probability that the candidate log represents that the interception log is intercepted by mistake is greater than a preset probability value.
[0042] Exemplarily, each interception log contains access information and interception requests, where the access information is related information for issuing the interception request, for example, it may include the visitor's IP address, access time, etc. When a visitor issues an access request to a Web application, and the access request is intercepted, it is an interception request.
[0043] A visitor can make multiple access requests, and multiple access requests made by a visitor may be intercepted. Therefore, the access information in different interception logs may be repeated. For example, a visitor IP makes two access requests, and both access requests are intercepted, generating two interception logs. The visitor IP in these two interception logs is the same.
[0044] Obtain the respective access information from each interception log, and determine one or more interception logs from these interception logs according to the access information in these interception logs as candidate logs. Candidate logs refer to interception logs that may be intercepted by mistake. For example, the probability value of the interception log being intercepted by mistake can be determined according to the access information in the interception log. A known probability value is preset, and the calculated probability value is compared with the preset probability value. If the calculated probability value is greater than the preset probability value, it means that the interception log may be intercepted by mistake. That is, according to the access information in each interception log, determine which interception requests in the interception log may be intercepted by mistake, and determine the interception logs that may be intercepted by mistake as candidate logs. For example, determine the visitor IP in the interception log. If the visitor IP in multiple interception logs is the same, it means that multiple access requests issued by the same visitor IP are intercepted, and the normal business of the visitor IP may be affected. It can be considered that the access request of the visitor IP may be intercepted by mistake, and the interception log corresponding to the visitor IP is determined as a candidate log.
[0045] S103: replay the interception request in the candidate log to obtain an erroneous interception identification result; wherein the erroneous interception identification result indicates whether the candidate log is an interception log of erroneous interception.
[0046] Exemplarily, after determining the candidate log, it can be further determined whether the candidate log is really an interception log of mistaken interception. The interception request in the candidate log can be replayed, that is, the interception request in the candidate log is reissued. The interception request in the candidate log can be resent to the Web application to determine the response of one or more Web firewalls to the interception request. In this embodiment, there is no specific limitation on the one or more Web firewalls that re-respond to the interception request, and the Web firewall can be the first Web firewall or other Web firewalls other than the first Web firewall.
[0047] Determine the response results of each Web firewall to the interception request. According to the response results of each Web firewall to the interception request, the false interception identification result can be determined. The false interception identification result can indicate whether the candidate log is really an interception log that is intercepted by mistake. The response result indicates the processing of the interception request by the Web firewall. The response results may include interception, release, error, etc. Interception means that the Web firewall cannot allow the interception request to pass, and the false interception identification result is normal interception; release means that the Web firewall allows the interception request to pass normally, and the false interception identification result is false interception, that is, the interception request in the candidate log should not be intercepted; error means that the false interception identification result is unknown.
[0048] In the disclosed embodiment, the interception log data set of the WAF is obtained, and the access information is obtained from each interception log in the interception log data set. According to the access information in each interception log, the interception log is preliminarily screened to obtain the interception log that may be a mistaken interception as a candidate log, which effectively reduces the subsequent amount of calculation and improves the efficiency of identifying mistaken interceptions. Then the interception request in the candidate log is reissued, that is, the replay process is performed. The mistaken interception identification result is obtained based on the replay result, so as to accurately determine whether the interception log is a mistaken interception. Through preliminary screening and replay, the disclosed embodiment can accurately find which request is mistakenly intercepted, improve the recognition accuracy and efficiency of mistaken interceptions, and then assist emergency response personnel to launch the correct WAF interception rules.
[0049] Figure 2 A flowchart of a method for identifying false interception provided in an embodiment of the present disclosure.
[0050] In this embodiment, the access information includes the visitor IP; determining the candidate logs based on the access information in each interception log includes: determining the number of interception logs corresponding to each visitor IP; determining the target IP from each visitor IP based on the number of interception logs corresponding to each visitor IP; and determining the interception log corresponding to the target IP as the candidate log.
[0051] This embodiment is based on the above embodiment. Figure 2 As shown, the method comprises the following steps:
[0052] S201. Obtain a preset interception log data set of a first Web firewall; wherein the interception log data set includes a plurality of interception logs.
[0053] Exemplarily, this step may refer to the above-mentioned step S101 and will not be described in detail.
[0054] S202: Determine the number of interception logs corresponding to each visitor IP.
[0055] For example, each interception log contains a visitor IP, and the visitor IPs in different interception logs may be the same or different. Determine the visitor IP corresponding to each interception log, and for each visitor IP, determine the number of repetitions of the visitor IP, that is, the number of interception logs corresponding to the visitor IP. For example, there are 20 million interception logs, and the visitor IPs in 100 interception logs are all 1.2.3.4, then the number of interception logs corresponding to 1.2.3.4 is 100.
[0056] In this embodiment, the access information includes domain names and Web firewall rules; determining the number of interception logs corresponding to the visitor IP includes: determining the number of domain names and the number of Web firewall rules corresponding to the visitor IP; in response to determining that the number of domain names corresponding to the visitor IP is less than a preset first threshold or the number of Web firewall rules is less than a preset second threshold, determining the number of interception logs corresponding to the visitor IP.
[0057] Specifically, the access information may include domain names and Web firewall rules. The domain name can be called Host, and the Web firewall rule is the WAF interception rule, which can be called Rulename. For each interception log, determine the Host and Rulename in the interception log. The Host of the same visitor IP in different interception logs may be the same or different; the Rulename of the same visitor IP in different interception logs may be the same or different. For each visitor IP, it is possible to determine how many different Hosts there are in all interception logs corresponding to the visitor IP as the number of domain names, and determine how many different Rulenames there are in all interception logs corresponding to the visitor IP as the number of Web firewall rules.
[0058] The number of domain names and the number of Web firewall rules corresponding to the visitor IP can be determined according to the preset access information statistics rules. The access information statistics rules can be to count the visitor IPs belonging to the same Host and the same Rulename, and to determine the number of the visitor IPs counted. For example, the visitor IPs whose Host is a.com and Rulename is sqli, and the visitor IPs whose Host is b.com and Rulename is cmd_exec, the statistical results are as follows:
[0059]
[0060] The number after the visitor IP is the number of interception logs for the visitor IP under the corresponding Host and Rulename. For example, '1.2.3.1':10 means that there are 10 1.2.3.1s with Host a.com and Rulename sqli. Based on the statistical results, the number of domain names and Web firewall rules of the visitor IP can be obtained. For example, the Host of 1.2.3.1 has a.com and b.com, and the number of domain names is 2; the Rulename of 1.2.3.1 has sqli and cmd_exec, and the number of Web firewall rules is 2.
[0061] In Web applications, scanners will bring more than 99% of the interception logs, and the interception logs brought by scanners are not false interceptions. Therefore, it is necessary to identify the interception logs corresponding to the scanner in the interception log data set, so as to conduct subsequent analysis on only the 1% non-scanner interception logs.
[0062] A first threshold can be set in advance, and the number of domain names corresponding to the visitor IP is compared with the preset first threshold. If the number of domain names corresponding to the visitor IP is equal to or greater than the preset first threshold, the visitor IP can be marked as a scanner, and subsequent false interception identification of the visitor IP will no longer be performed; if the number of domain names corresponding to the visitor IP is less than the preset first threshold, the visitor IP can be marked as a non-scanner, and the number of interception logs corresponding to the visitor IP can be determined.
[0063] A second threshold may also be preset, and the number of Web firewall rules corresponding to the visitor IP may be compared with the preset second threshold. If the number of Web firewall rules corresponding to the visitor IP is equal to or greater than the preset second threshold, the visitor IP may be marked as a scanner, and subsequent false interception identification of the visitor IP will no longer be performed; if the number of Web firewall rules corresponding to the visitor IP is less than the preset second threshold, the visitor IP may be marked as a non-scanner, and the number of interception logs corresponding to the visitor IP may be determined.
[0064] The beneficial effect of this setting is that it filters out the interception logs brought by the scanner, reduces the subsequent calculation amount, and significantly improves the detection efficiency and accuracy of false interception.
[0065] In this embodiment, the access information includes the location information of the visitor IP; determining the number of interception logs corresponding to each visitor IP includes: grouping each visitor IP according to the area to which the location information of each visitor IP belongs to obtain a visitor group; wherein the visitor group corresponds to the area one-to-one; determining the number of interception logs corresponding to each visitor IP in the visitor group.
[0066] Specifically, the access information may include the location information of the visitor IP, and the location information may indicate the geographical location of the visitor IP. According to the location information, the region to which the visitor IP belongs may be determined, and in this embodiment, the region may be accurately determined to a city.
[0067] Determine the region to which the location information of each visitor IP belongs, and group the visitor IPs belonging to the same region into one group, thereby obtaining multiple visitor groups. That is, one visitor group corresponds to one region, and the visitor group includes all visitor IPs belonging to the same region. For each visitor group, determine the number of interception logs corresponding to each visitor IP in the visitor group.
[0068] The beneficial effect of this setting is that the visitor IPs are grouped by geographical location, so that false interceptions in different areas can be identified, the actual identification needs of different areas can be met, and the flexibility and accuracy of false interception identification can be improved.
[0069] In this embodiment, the method further includes: grouping each visitor IP according to the IP-C segment of each visitor IP to obtain a visitor group; wherein the visitor group corresponds to the IP-C segment one by one.
[0070] Specifically, for each visitor IP, determine the IP-C segment in the visitor IP. The visitor IP may include four segments: A, B, C, and D, and the IP-C segment may include three segments: A, B, and C. For example, if the visitor IP is 1.2.3.4, the IP-C segment may be 1.2.3. According to the IP-C segment of each visitor IP, each visitor IP is grouped. For example, visitor IPs with the same IP-C segment may be grouped together, that is, all visitor IPs in a visitor group have the same IP-C segment.
[0071] After obtaining multiple visitor groups, for each visitor group, the number of interception logs corresponding to each visitor IP in the visitor group is determined.
[0072] The beneficial effect of this setting is that the visitor IP is grouped according to the IP-C segment, and the false interception of different IP-C segments can be identified, meeting the actual identification needs and improving the flexibility and accuracy of false interception identification.
[0073] In this embodiment, the access information includes a uniform resource identifier (URI) resource type; and further includes: grouping each visitor IP according to the URI resource type of each visitor IP to obtain a visitor group; wherein the visitor group corresponds to the URI resource type one by one.
[0074] Specifically, the access information may include a URI (Uniform Resource Identifier) resource type, and the URI resource type may include static_uri (static resource) and dynamic_uri (dynamic resource). According to the URI resource type of each visitor IP, each visitor IP is grouped to obtain multiple visitor groups, and the visitor groups correspond to the URI resource type one by one. In this embodiment, two visitor groups can be obtained, one visitor group corresponds to static_uri, and the other visitor group corresponds to dynamic_uri.
[0075] After obtaining multiple visitor groups, for each visitor group, the number of interception logs corresponding to each visitor IP in the visitor group is determined.
[0076] The beneficial effect of such a setting is that the visitor IP is grouped according to the URI resource, so that the false interception of different resource types can be identified, the actual identification needs can be met, and the flexibility and accuracy of false interception identification can be improved.
[0077] S203: Determine the target IP from each visitor IP according to the number of interception logs corresponding to each visitor IP.
[0078] Exemplarily, determine how many different visitor IPs there are in all interception logs, and determine the number of interception logs corresponding to each visitor IP. According to the number of interception logs corresponding to each visitor IP, determine one or more visitor IPs from these visitor IPs as target IPs. For example, the visitor IP with the largest number of interception logs can be determined as the target IP.
[0079] In this embodiment, the target IP is determined from each visitor IP according to the number of interception logs corresponding to each visitor IP, including: determining the number that meets the preset sampling strategy according to the number of interception logs corresponding to each visitor IP, and determining the number that meets the preset sampling strategy as the target number; determining the visitor IP corresponding to the target number as the target IP.
[0080] Specifically, a sampling strategy is pre-set, for example, the sampling strategy is to extract the maximum value, mode, and / or median from multiple numbers. Each visitor IP corresponds to a number, which represents the number of interception logs corresponding to the visitor IP. According to the preset sampling strategy, numbers that meet the requirements are extracted from these numbers, that is, the number of interception logs that meet the requirements is extracted. The extracted number is determined as the target number. For example, there are five types of visitor IPs, namely 1.2.3.1, 1.2.3.2, 1.2.3.3, 1.2.3.4, and 1.2.3.5, and the corresponding numbers of interception logs are 100, 90, 110, 50, and 70 respectively. The sampling strategy is to sample the maximum value, then the target number can be determined to be 110.
[0081] Determine the visitor IP corresponding to the target number, for example, determine the visitor IP corresponding to 110, the visitor IP is 1.2.3.3. Determine the visitor IP corresponding to the target number as the target IP, that is, the target IP is 1.2.3.3.
[0082] The beneficial effect of this setting is that, according to the sampling strategy of actual needs, the number of interception logs corresponding to each visitor IP is sampled, which improves the pertinence of false interception identification, meets actual identification needs, reduces subsequent calculations, and improves identification efficiency.
[0083] If the visitor IP is divided into multiple visitor groups, a sampling strategy can be preset for each visitor group. According to the number of interception logs corresponding to each visitor IP in the visitor group, the number that meets the preset sampling strategy is determined, and then the visitor IP corresponding to the target number is determined as the target IP of the visitor group.
[0084] In this embodiment, a target IP is determined from each visitor IP according to the number of interception logs corresponding to each visitor IP, including: in response to determining that the number of interception logs corresponding to the visitor IP is greater than a preset number threshold, the visitor IP is determined as a candidate IP for incorrect interception; and according to the number of interception logs corresponding to each candidate IP for incorrect interception, the target IP is determined from each candidate IP for incorrect interception.
[0085] Specifically, a quantity threshold is preset, and according to the quantity threshold, the visitor IPs in the interception log can be screened once, and then the target IP is determined from the visitor IPs retained after the screening.
[0086] For each visitor IP, the number of interception logs corresponding to the visitor IP is compared with the preset number threshold. If the number of interception logs corresponding to the visitor IP is less than or equal to the preset number threshold, it is considered that the visitor of the visitor IP is normally intercepted, and the visitor IP can be screened out, that is, the interception log of the visitor IP does not belong to a wrong interception; if the number of interception logs corresponding to the visitor IP is greater than the preset number threshold, it means that the interception log of the visitor IP may belong to a wrong interception, and the visitor IP is determined as a wrong interception candidate IP. After obtaining all the wrong interception candidate IPs, the target IP can be determined from these wrong interception candidate IPs according to the number of interception logs corresponding to the wrong interception candidate IPs. For example, according to the preset sampling strategy, the number that meets the preset sampling strategy can be determined from the number of interception logs corresponding to the wrong interception candidate IPs as the target number, and then the wrong interception candidate IP corresponding to the target number is determined as the target IP.
[0087] For each visitor IP, the IP-C segment of the visitor IP can also be determined. According to the IP-C segment of the visitor IP, the wrong interception candidate IP is determined. For example, if the number of IP-C segments of the visitor IP is greater than the specified threshold, the visitor IP is marked as a wrong interception candidate IP, otherwise, the visitor IP is screened out.
[0088] The beneficial effect of this setting is that preliminary screening is performed based on the number of logs corresponding to the visitor's IP. IPs with a larger number of logs are more likely to be mistakenly intercepted, reducing the subsequent calculation amount and improving the recognition accuracy and efficiency of false interceptions.
[0089] S204: Determine the interception log corresponding to the target IP as a candidate log.
[0090] Exemplarily, after determining the target IP, the interception log corresponding to the target IP can be obtained, and the interception log corresponding to the target IP can be determined as a candidate log, or one or more interception logs can be selected from the interception logs corresponding to the target IP as candidate logs.
[0091] In this embodiment, each interception log includes the visitor IP. The visitor IP in different interception logs may be the same. Therefore, the number of logs corresponding to each visitor IP can be determined, and the visitor IP can be used as the screening granularity to perform preliminary screening of the interception logs, effectively reducing the computational complexity of false interception identification and improving the identification accuracy and efficiency of false interceptions.
[0092] In this embodiment, the access information includes a domain name, a URI path, and a Web firewall rule; determining the interception log corresponding to the target IP as a candidate log includes: determining a first application fingerprint corresponding to the domain name and URI path of the target IP according to a preset first association relationship; wherein the first association relationship represents an association relationship between the domain name and URI path, and the application fingerprint; the application fingerprint represents a Web application framework; determining a second application fingerprint corresponding to the Web firewall rule of the target IP according to a preset second association relationship; wherein the second association relationship represents an association relationship between the Web firewall rule and the application fingerprint; in response to determining that the first application fingerprint is consistent with the second application fingerprint, determining the interception log corresponding to the target IP as a candidate log.
[0093] Specifically, the access information may include the visitor's IP, domain name, URI path, Web firewall rules, etc., wherein the URI path may be referred to as uri_path.
[0094] A first association relationship is preset, and the first association relationship can represent the association relationship between the two information, Host and uri_path, and the application fingerprint. The application fingerprint refers to a Web application framework, for example, the application fingerprint can be an apache framework, etc. The Host and uri_path in the interception log of the target IP are determined, and according to the preset first association relationship, the application fingerprint corresponding to the Host and uri_path is determined as the first application fingerprint.
[0095] A second association relationship is preset, and the second association relationship can represent the association relationship between Rulename and application fingerprint. Rulename in the interception log of the target IP is determined, and the application fingerprint corresponding to the Rulename is determined according to the preset second association relationship as the second application fingerprint.
[0096] The first application fingerprint and the second application fingerprint are matched. If the first application fingerprint and the second application fingerprint are inconsistent, it means that the interception log of the target IP is not a false interception, and the interception log is not a candidate log; if the first application fingerprint is consistent with the second application fingerprint, it means that the interception log corresponding to the target IP may be a false interception, and the interception log can be determined as a candidate log.
[0097] The beneficial effect of such a setting is that, by matching application fingerprints, the interception logs of normal interception can be screened out, and the interception logs of normal interception do not need to be subsequently replayed, thereby reducing the subsequent processing calculation amount and improving processing efficiency.
[0098] S205 , replaying the interception request in the candidate log to obtain an erroneous interception identification result; wherein the erroneous interception identification result indicates whether the candidate log is an interception log of erroneous interception.
[0099] Exemplarily, this step may refer to the above-mentioned step S103 and will not be described in detail.
[0100] In the disclosed embodiment, the interception log data set of the WAF is obtained, and the access information is obtained from each interception log in the interception log data set. According to the access information in each interception log, the interception log is preliminarily screened to obtain the interception log that may be a mistaken interception as a candidate log, which effectively reduces the subsequent amount of calculation and improves the efficiency of identifying mistaken interceptions. Then the interception request in the candidate log is reissued, that is, the replay process is performed. The mistaken interception identification result is obtained based on the replay result, so as to accurately determine whether the interception log is a mistaken interception. Through preliminary screening and replay, the disclosed embodiment can accurately find which request is mistakenly intercepted, improve the recognition accuracy and efficiency of mistaken interceptions, and then assist emergency response personnel to launch the correct WAF interception rules.
[0101] Figure 3 A flowchart of a method for identifying false interception provided in an embodiment of the present disclosure.
[0102] In this embodiment, the interception request in the candidate log is replayed to obtain the false interception identification result, including: converting the interception request in the candidate log into a preset protocol request according to a preset protocol conversion format; replaying the preset protocol request to a preset second Web firewall to obtain the false interception identification result.
[0103] This embodiment is based on the above embodiment. Figure 3 As shown, the method comprises the following steps:
[0104] S301. Obtain a preset interception log data set of a first Web firewall; wherein the interception log data set includes a plurality of interception logs.
[0105] Exemplarily, this step may refer to the above-mentioned step S101 and will not be described in detail.
[0106] S302. Determine candidate logs according to access information in each interception log; wherein the access information represents information of a request to access a Web application, and the probability that the candidate log represents that the interception log is incorrectly intercepted is greater than a preset probability value.
[0107] Exemplarily, this step may refer to the above-mentioned step S102 and will not be described in detail.
[0108] S303: Convert the interception request in the candidate log into a preset protocol request according to a preset protocol conversion format.
[0109] Exemplarily, a protocol conversion format is pre-set, and according to the preset protocol conversion format, the interception request in the candidate log is converted into a preset protocol request. In this embodiment, the preset protocol request may be an HTTP (Hyper Text Transfer Protocol) request. The interception request in the interception log is in the format of a JSON data group, that is, the JSON data group is converted into an HTTP request. In this embodiment, the preset protocol conversion format is not specifically limited.
[0110] The interception request in the interception log may include multiple JSON data groups, each of which may include a field and a corresponding field value. For example, the field may be method, host, version, etc. By performing format conversion, multiple JSON data groups may be converted into a complete string as a preset protocol request. In the preset protocol request, the description, format, instance, etc. corresponding to each field may be included. Table 1 is a schematic table of the data content of the preset protocol request.
[0111] Table 1 Schematic diagram of data content requested by preset protocol
[0112]
[0113] S304: replay the preset protocol request to the preset second Web firewall to obtain a false interception identification result.
[0114] Exemplarily, one or more web firewalls are pre-set as the second web firewall, and the second web firewall is a WAF engine that is not homologous to the first web firewall. For example, an open source cloud WAF engine can be used as the second web firewall.
[0115] When the visitor sends an access request for the first time, the access request is intercepted by the first Web firewall, and the access request is an interception request in the interception log. The interception request is re-issued to the second Web firewall to determine whether the second Web firewall intercepts the request, that is, the second Web firewall performs a dial test on the interception request to obtain a false interception identification result. If the second Web firewall does not intercept the request, it means that the interception log is a false interception by the first Web firewall; if the second Web firewall still intercepts the request, it means that the interception log is a normal interception.
[0116] In this embodiment, the intercepted request is restored to a request of a preset protocol, which facilitates replay of the preset protocol request. Through the second Web firewall, it can be verified whether the intercepted request is really a mistaken interception, thereby improving the recognition accuracy of mistaken interception.
[0117] In this embodiment, the preset protocol request is replayed to the preset second Web firewall to obtain the false interception identification result, including: in response to determining that the transmission interface in the preset protocol request is not the preset interface, obtaining request message information from the preset protocol request; wherein the request message information includes a request header and a request body; in response to determining that the request message information does not meet the preset interception identification condition, replaying the preset protocol request to the preset second Web firewall to obtain the false interception identification result.
[0118] Specifically, after obtaining the preset protocol request, the preset protocol request can be first screened according to the content in the preset protocol request, and only the preset protocol request retained after screening can be replayed. The transmission interface can be obtained from the preset protocol request, and the transmission interface represents the resource type of the transmission. Determine whether the transmission interface in the preset protocol request is the preset interface. The preset interface is a preset interface that is not allowed to be released. The preset interface can be a log transmission interface, a binary file transmission interface, and a text interface, etc. The resource type represented by the log transmission interface is JSON data, the resource type represented by the binary file transmission interface is binary data, and the resource type represented by the text interface is a file. That is, determine whether the resource type of the transmission is JSON data, binary data, or a file, etc.
[0119] If the transmission interface in the preset protocol request is the preset interface, the interception request corresponding to the preset protocol request is directly marked as an incorrect interception, and no replay verification is required; if the transmission interface in the preset protocol request is not the preset interface, the request message information is obtained from the preset protocol request, and the request message information includes a request header and a request body, that is, the request header and the request body are obtained from the preset protocol request.
[0120] An interception identification condition is preset, and the interception identification condition is used to determine whether the interception request corresponding to the preset protocol request is a normal interception based on the request message information. For example, the interception identification condition can be to determine whether the request header and / or request body contains a preset attack behavior description. If it does, the interception request corresponding to the preset protocol request is marked as a normal interception, that is, the interception log belongs to a normal interception, not an erroneous interception, and no subsequent replay is required; if it does not contain it, the preset protocol request needs to be replayed to the preset second Web firewall. The attack behavior description indicates that the request is an attack behavior that should be intercepted. For example, the preset attack behavior description can be:
[0121]
[0122] The beneficial effect of such a setting is that by judging whether the transmission interface is a preset interface, interception requests that are definitely intercepted by mistake can be screened out, and by judging whether the request message information meets the preset interception identification conditions, interception requests that are definitely intercepted normally can be screened out. The remaining requests are replayed, which effectively reduces the amount of replayed requests and improves the efficiency of identifying false interceptions.
[0123] In this embodiment, the preset protocol request is replayed to the preset second Web firewall to obtain the false interception identification result, including: replaying the preset protocol request to multiple preset second Web firewalls, receiving the response results fed back by each preset second Web firewall; wherein the response result indicates whether the preset second Web firewall intercepts the preset protocol request; and determining the false interception identification result according to the response results fed back by each preset second Web firewall.
[0124] Specifically, a plurality of different second Web firewalls are pre-set, and the preset protocol request is replayed to these second Web firewalls respectively, and the response results fed back by each second Web firewall are received. The response result indicates whether the second Web firewall intercepts the preset protocol request, and the response result can be a result type such as release, interception, or error. Release indicates that the Web firewall does not intercept the preset protocol request, interception indicates that the Web firewall intercepts the preset protocol request, and error indicates that it is unknown what processing the Web firewall has performed on the preset protocol request.
[0125] If there is only one second Web firewall, the false interception identification result can be directly determined based on the response result of the second Web firewall. For example, if the response result is release, it is determined that the interception request corresponding to the preset protocol request is a false interception; if the response result is interception, it is determined that the interception request corresponding to the preset protocol request is a normal interception; if the response result is error, it is determined that the interception request corresponding to the preset protocol request is unknown. If there are multiple second Web firewalls, the false interception identification result can be determined in combination with the response results fed back by each second Web firewall. For example, the false interception identification result can be determined based on the result type with the largest number among all response results.
[0126] The beneficial effect of such a setting is that the response results of multiple second Web firewalls are combined to determine the false interception identification result, thereby avoiding the one-sidedness of the result and improving the identification accuracy of the false interception.
[0127] In this embodiment, the response results fed back by each preset second Web firewall include at least one result type of release, interception, and error; determining the false interception identification result according to the response results fed back by each preset second Web firewall includes: in response to determining that the response results fed back by each preset second Web firewall include at least two result types, determining the false interception identification result according to the quantity of each result type in the at least two result types.
[0128] Specifically, the response results fed back by each second Web firewall are obtained to determine whether the response results fed back by each second Web firewall are different. If the response results fed back by each second Web firewall are the same, the false interception identification result can be directly determined based on the response results.
[0129] If the response results fed back by the second Web firewalls are different, that is, the response results fed back by the second Web firewalls include at least two result types, the number of each result type in the response result can be determined, and the false interception identification result can be determined based on the number of each result type. For example, a "majority decision algorithm" can be used to determine the result type with the largest number, and the false interception identification result can be determined based on the result type with the largest number.
[0130] The beneficial effect of such a setting is that, when there are multiple response results, a majority decision algorithm is used to determine the response result with the highest probability, thereby improving the recognition accuracy of false interception.
[0131] In this embodiment, the false interception identification result is determined based on the quantity of each result type in at least two result types, including: in response to determining that the quantity of each result type in at least two result types is the same, determining the target type from at least two result types according to a preset result type priority; determining the false interception identification result according to the target type.
[0132] Specifically, if the number of each result type in the response result is the same, the "majority decision algorithm" cannot be used. Priorities for various result types are preset. For example, the priority may be release < error < interception. According to the preset priority, one result type can be determined from at least two result types of the response result as the target type. For example, if the response result includes the same number of interceptions, releases, and errors, the target type can be determined to be interception; for another example, if the response result includes the same number of releases and errors, the target type can be determined to be error. According to the target type, the false interception identification result is determined. For example, if the target type is interception, the false interception identification result is determined to be normal interception.
[0133] The beneficial effect of such a setting is that the final response result can be determined according to the preset priority, ensuring that the false interception identification result can be obtained, thereby improving the recognition efficiency of false interception.
[0134] In this embodiment, the preset protocol request is replayed to the preset second Web firewall to obtain the false interception identification result, including: desensitizing the preset field in the preset protocol request to obtain the desensitized preset protocol request; replaying the desensitized preset protocol request to the preset second Web firewall to obtain the false interception identification result.
[0135] Specifically, the preset protocol request may contain sensitive information of the visitor, so the preset protocol request may be desensitized to remove the sensitive information. The information of the preset field in the preset protocol request may be removed, for example, the preset field may be a cookie field in the request header, thereby obtaining a desensitized preset protocol request. The desensitized preset protocol request is then replayed to one or more second Web firewalls to obtain a final false interception identification result.
[0136] The beneficial effect of such a setting is that, through desensitization processing, sensitive information can be removed and the security of information can be improved.
[0137] In this embodiment, it also includes: determining the number of logs that are mistakenly intercepted in the interception log data set; determining and outputting the false interception ratio based on the number of logs that are mistakenly intercepted and the total number of interception logs in the interception log data set; wherein the false interception ratio represents the ratio of the number of logs that are mistakenly intercepted to the total number of interception logs.
[0138] Specifically, according to the result of the false interception identification, the number of interception logs belonging to false interception is determined as the number of false interception logs. The total number of interception logs in the interception log data set is determined, and the number of false interception logs is divided by the total number of interception logs to obtain the false interception ratio. The false interception ratio is output to the emergency response personnel for manual confirmation of the false interception. The details of the interception logs belonging to the false interception can also be output, for example, the content of the interception log, the detection time of the false interception identification, the preset protocol request after format conversion, etc. can be output.
[0139] The beneficial effect of this setting is that it determines and outputs the proportion of false interceptions to prompt emergency response personnel to improve the WAF interception rules and improve the subsequent attack and defense business level.
[0140] Figure 4 This is a diagram of the engine dial test of the second Web firewall. Figure 4 The HTTP request is a preset protocol request, the cloud WAF engine is the second web firewall, and N cloud WAF engines can be set. Each cloud WAF engine corresponds to a target machine, which can be used to receive HTTP requests and send HTTP requests to the cloud WAF engine. The dial test process is to resend the HTTP request, replay the HTTP request to the target machine, and the target machine sends the HTTP request to the cloud WAF engine. According to the response of the cloud WAF engine, the response result is determined.
[0141] Figure 5 The overall flow chart of false interception identification. Figure 5 In the process, first obtain the interception log, and determine whether the interception log is a log brought by the scanner based on the access information in the interception log. If so, directly filter out the log brought by the scanner without subsequent identification; if not, perform subsequent sampling operations. It is also possible to determine whether the visitor IP in the interception log is a candidate IP for misinterception based on the access information in the interception log. If so, perform subsequent sampling operations; if not, directly mark it as normal interception.
[0142] Adopt the preset sampling strategy to determine the target IP from the visitor IPs retained after screening. Determine the first application fingerprint and the second application fingerprint in the interception log corresponding to the target IP, and compare the fingerprints. If the two fingerprints are inconsistent, mark it as normal interception; if the two fingerprints are consistent, restore the interception request to an HTTP request and desensitize it to obtain the preset protocol request. According to the transmission interface in the preset protocol request, determine whether the interception request corresponding to the preset protocol request is intercepted by mistake. If the transmission interface in the preset protocol request is the preset interface, mark it as a wrong interception; if not, continue to identify the attack behavior. If the preset protocol request contains attack behavior, mark it as normal interception; if there is no attack behavior, replay the preset protocol request to the preset WAF engine, and the WAF engine will perform a dial test to obtain the wrong interception identification result. Finally, summarize the wrong interception identification results.
[0143] In the disclosed embodiment, the interception log data set of the WAF is obtained, and the access information is obtained from each interception log in the interception log data set. According to the access information in each interception log, the interception log is preliminarily screened to obtain the interception log that may be a mistaken interception as a candidate log, which effectively reduces the subsequent amount of calculation and improves the efficiency of identifying mistaken interceptions. Then the interception request in the candidate log is reissued, that is, the replay process is performed. The mistaken interception identification result is obtained based on the replay result, so as to accurately determine whether the interception log is a mistaken interception. Through preliminary screening and replay, the disclosed embodiment can accurately find which request is mistakenly intercepted, improve the recognition accuracy and efficiency of mistaken interceptions, and then assist emergency response personnel to launch the correct WAF interception rules.
[0144] Figure 6 This is a structural block diagram of a device for identifying misinterception provided by an embodiment of the present disclosure. For ease of explanation, only the parts related to the embodiment of the present disclosure are shown. Figure 6 The device 600 for identifying a false interception includes: a log obtaining unit 601 , a candidate determining unit 602 , and a request identifying unit 603 .
[0145] The log acquisition unit 601 is used to acquire a preset interception log data set of a first Web firewall; wherein the interception log data set includes a plurality of interception logs;
[0146] A candidate determination unit 602 is used to determine a candidate log according to the access information in each of the interception logs; wherein the access information represents information of a request to access a Web application, and the probability that the candidate log represents that the interception log is intercepted by mistake is greater than a preset probability value;
[0147] The request identification unit 603 is used to replay the interception request in the candidate log to obtain an erroneous interception identification result; wherein the erroneous interception identification result indicates whether the candidate log is an interception log of erroneous interception.
[0148] Figure 7 A structural block diagram of a misinterception identification device provided by an embodiment of the present disclosure, such as Figure 7 As shown, the device for identifying false interception 700 includes a log acquisition unit 701, a candidate determination unit 702 and a request identification unit 703, wherein the access information includes the visitor IP, and the candidate determination unit 702 includes a quantity determination module 7021, an IP determination module 7022 and a candidate determination module 7023.
[0149] The quantity determination module 7021 is used to determine the quantity of interception logs corresponding to each visitor IP;
[0150] The IP determination module 7022 is used to determine the target IP from each of the visitor IPs according to the number of interception logs corresponding to each of the visitor IPs;
[0151] The candidate determination module 7023 is used to determine the interception log corresponding to the target IP as the candidate log.
[0152] In one example, the IP determination module 7022 includes:
[0153] A sampling submodule, for determining the number of interception logs corresponding to each visitor IP address that satisfies a preset sampling strategy, and determining the number of interception logs that satisfies the preset sampling strategy as a target number;
[0154] The IP determination submodule is used to determine the visitor IPs corresponding to the target number as the target IPs.
[0155] In one example, the IP determination module 7022 includes:
[0156] A candidate submodule, configured to determine the visitor IP as a candidate IP for misinterception in response to determining that the number of interception logs corresponding to the visitor IP is greater than a preset number threshold;
[0157] The target IP determination submodule is used to determine the target IP from each of the erroneously intercepted candidate IPs according to the number of interception logs corresponding to each of the erroneously intercepted candidate IPs.
[0158] In one example, the access information includes a domain name and a Web firewall rule; the quantity determination module 7021 includes:
[0159] A quantity determination submodule, used to determine the number of domain names and the number of Web firewall rules corresponding to the visitor IP;
[0160] The quantity judgment submodule is used to determine the number of interception logs corresponding to the visitor IP in response to determining that the number of domain names corresponding to the visitor IP is less than a preset first threshold or the number of Web firewall rules is less than a preset second threshold.
[0161] In one example, the access information includes the location information of the visitor's IP address; the quantity determination module 7021 includes:
[0162] A location grouping submodule, for grouping each visitor IP according to the region to which the location information of each visitor IP belongs, to obtain a visitor group; wherein the visitor group corresponds to the region one by one;
[0163] The log quantity determination submodule is used to determine the quantity of interception logs corresponding to each visitor IP in the visitor group.
[0164] In one example, the quantity determination module 7021 includes:
[0165] The IP grouping submodule is used to group each visitor IP according to the IP-C segment of each visitor IP to obtain a visitor group; wherein the visitor group corresponds to the IP-C segment one by one.
[0166] In one example, the access information includes a uniform resource identifier (URI) resource type; the quantity determination module 7021 includes:
[0167] The resource grouping submodule is used to group each of the visitor IPs according to the URI resource type of each of the visitor IPs to obtain a visitor group; wherein the visitor group corresponds to the URI resource type one by one.
[0168] In one example, the access information includes a domain name, a URI path, and a Web firewall rule; the candidate determination module 7023 includes:
[0169] A first determination submodule is used to determine a first application fingerprint corresponding to the domain name and URI path of the target IP according to a preset first association relationship; wherein the first association relationship represents an association relationship between the domain name and URI path and the application fingerprint; and the application fingerprint represents a Web application framework;
[0170] A second determination submodule is used to determine a second application fingerprint corresponding to the Web firewall rule of the target IP according to a preset second association relationship; wherein the second association relationship represents an association relationship between the Web firewall rule and the application fingerprint;
[0171] The fingerprint comparison submodule is used to determine the interception log corresponding to the target IP as the candidate log in response to determining that the first application fingerprint is consistent with the second application fingerprint.
[0172] In one example, the request identification unit 703 includes:
[0173] A request conversion module, used to convert the interception request in the candidate log into a preset protocol request according to a preset protocol conversion format;
[0174] The result obtaining module is used to replay the preset protocol request to the preset second Web firewall to obtain the false interception identification result.
[0175] In one example, the resulting modules include:
[0176] An information acquisition submodule, configured to, in response to determining that the transmission interface in the preset protocol request is not the preset interface, acquire request message information from the preset protocol request; wherein the request message information includes a request header and a request body;
[0177] The request replay submodule is used to, in response to determining that the request message information does not meet the preset interception identification condition, replay the preset protocol request to the preset second Web firewall to obtain the false interception identification result.
[0178] In one example, the resulting module includes:
[0179] A response receiving submodule, used for replaying the preset protocol request to multiple preset second Web firewalls, and receiving response results fed back by each preset second Web firewall; wherein the response result indicates whether the preset second Web firewall intercepts the preset protocol request;
[0180] The result determination submodule is used to determine the false interception identification result according to the response results fed back by each preset second Web firewall.
[0181] In one example, the response result fed back by each preset second Web firewall includes at least one result type of release, interception, and error; the result determination submodule is specifically used to:
[0182] In response to determining that the response results fed back by each preset second Web firewall include at least two result types, the false interception identification result is determined according to the quantity of each result type in the at least two result types.
[0183] In one example, the result determination submodule is specifically used to:
[0184] In response to determining that the number of each of the at least two result types is the same, determining a target type from the at least two result types according to a preset result type priority;
[0185] The false interception identification result is determined according to the target type.
[0186] In one example, the resulting modules include:
[0187] A desensitization submodule, used for performing desensitization processing on the preset fields in the preset protocol request to obtain a desensitized preset protocol request;
[0188] The replay submodule is used to replay the desensitized preset protocol request to the preset second Web firewall to obtain the false interception identification result.
[0189] In one example, it also includes:
[0190] a wrong interception number determination unit, used to determine the number of wrongly intercepted logs in the interception log data set;
[0191] The proportion determination unit is used to determine and output the proportion of false interception according to the number of logs belonging to false interception and the total number of interception logs in the interception log data set; wherein the false interception proportion represents the ratio of the number of logs belonging to false interception to the total number of interception logs.
[0192] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device.
[0193] Figure 8 A structural block diagram of an electronic device provided in an embodiment of the present disclosure, such as Figure 8 As shown, the electronic device 800 includes: at least one processor 802; and a memory 801 communicatively connected to the at least one processor 802; wherein the memory stores instructions executable by the at least one processor 802, and the instructions are executed by the at least one processor 802 so that the at least one processor 802 can execute the method for identifying false interceptions disclosed in the present invention.
[0194] The electronic device 800 further includes a receiver 803 and a transmitter 804. The receiver 803 is used to receive instructions and data sent by other devices, and the transmitter 804 is used to send instructions and data to external devices.
[0195] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium and a computer program product.
[0196] According to an embodiment of the present disclosure, the present disclosure also provides a computer program product, which includes: a computer program, the computer program is stored in a readable storage medium, at least one processor of an electronic device can read the computer program from the readable storage medium, and at least one processor executes the computer program so that the electronic device executes the solution provided by any of the above embodiments.
[0197] Fig. 9 A schematic block diagram of an example electronic device 900 that can be used to implement an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.
[0198] like Fig. 9 As shown, the device 900 includes a computing unit 901, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 902 or a computer program loaded from a storage unit 908 into a random access memory (RAM) 903. In the RAM 903, various programs and data required for the operation of the device 900 can also be stored. The computing unit 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. An input / output (I / O) interface 905 is also connected to the bus 904.
[0199] A number of components in the device 900 are connected to the I / O interface 905, including: an input unit 906, such as a keyboard, a mouse, etc.; an output unit 907, such as various types of displays, speakers, etc.; a storage unit 908, such as a disk, an optical disk, etc.; and a communication unit 909, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 909 allows the device 900 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0200] The computing unit 901 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 901 performs the various methods and processes described above, such as the identification method of misinterception. For example, in some embodiments, the identification method of misinterception may be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as a storage unit 908. In some embodiments, part or all of the computer program may be loaded and / or installed on the device 900 via ROM 902 and / or communication unit 909. When the computer program is loaded into RAM 903 and executed by the computing unit 901, one or more steps of the identification method of misinterception described above may be performed. Alternatively, in other embodiments, the computing unit 901 may be configured to perform the identification method of misinterception by any other appropriate means (e.g., by means of firmware).
[0201] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0202] The program code for implementing the method of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, enables the functions / operations specified in the flow chart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0203] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0204] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0205] The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0206] A computer system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The relationship between the client and the server is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services ("Virtual Private Server", or "VPS" for short). The server may also be a server of a distributed system, or a server combined with a blockchain.
[0207] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this disclosure can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this document does not limit this.
[0208] The above specific implementations do not constitute a limitation on the protection scope of the present disclosure. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.
Claims
1. A method for identifying a false interception, comprising: Obtaining a preset interception log data set of a first Web firewall; wherein the interception log data set includes a plurality of interception logs; Determine a candidate log according to the visitor information in each interception log; wherein the visitor information represents information requesting access to a Web application, and the probability that the candidate log represents that the interception log is intercepted by mistake is greater than a preset probability value; The interception request in the candidate log is replayed to obtain an erroneous interception identification result; wherein the erroneous interception identification result indicates whether the candidate log is an interception log of erroneous interception.
2. The method according to claim 1, wherein: The access information includes the visitor IP; the determining the candidate log according to the access information in each interception log includes: Determine the number of interception logs corresponding to each of the visitor IPs; Determine the target IP from each of the visitor IPs according to the number of interception logs corresponding to each of the visitor IPs; The interception log corresponding to the target IP is determined as the candidate log.
3. The method according to claim 2, wherein: Determining the target IP from each of the visitor IPs according to the number of interception logs corresponding to each of the visitor IPs includes: According to the number of interception logs corresponding to each of the visitor IPs, the number that meets the preset sampling strategy is determined, and the number that meets the preset sampling strategy is determined as the target number; The visitor IP corresponding to the target number is determined as the target IP.
4. The method according to claim 2 or 3, wherein: Determining the target IP from each of the visitor IPs according to the number of interception logs corresponding to each of the visitor IPs includes: In response to determining that the number of interception logs corresponding to the visitor IP is greater than a preset number threshold, determining the visitor IP as a wrongly intercepted candidate IP; According to the number of interception logs corresponding to each of the erroneously intercepted candidate IPs, a target IP is determined from each of the erroneously intercepted candidate IPs.
5. The method according to any one of claims 2 to 4, wherein: The access information includes a domain name and a Web firewall rule; the determining the number of interception logs corresponding to each visitor IP includes: Determine the number of domain names and web firewall rules corresponding to the visitor IP; In response to determining that the number of domain names corresponding to the visitor IP is less than a preset first threshold or the number of Web firewall rules is less than a preset second threshold, the number of interception logs corresponding to the visitor IP is determined.
6. The method according to any one of claims 2 to 5, wherein: The access information includes the location information of the visitor IP; the determining the number of interception logs corresponding to each of the visitor IPs includes: According to the region to which the location information of each visitor IP belongs, each visitor IP is grouped to obtain a visitor group; wherein the visitor group corresponds to the region one by one; Determine the number of interception logs corresponding to each visitor IP in the visitor group.
7. The method according to claim 6, further comprising: According to the IP-C segment of each visitor IP, each visitor IP is grouped to obtain a visitor group; wherein the visitor group corresponds to the IP-C segment one by one.
8. The method according to claim 6 or 7, wherein the access information includes a uniform resource identifier (URI) resource type; and further includes: According to the URI resource type of each visitor IP, each visitor IP is grouped to obtain a visitor group; wherein the visitor group corresponds to the URI resource type one by one.
9. The method according to any one of claims 2 to 8, wherein: The access information includes a domain name, a URI path, and a Web firewall rule; the interception log corresponding to the target IP is determined as the candidate log, including: According to a preset first association relationship, determine a first application fingerprint corresponding to the domain name and URI path of the target IP; wherein the first association relationship represents the association relationship between the domain name and URI path and the application fingerprint; the application fingerprint represents the Web application framework; Determine, according to a preset second association relationship, a second application fingerprint corresponding to the Web firewall rule of the target IP; wherein the second association relationship represents an association relationship between the Web firewall rule and the application fingerprint; In response to determining that the first application fingerprint is consistent with the second application fingerprint, the interception log corresponding to the target IP is determined as the candidate log.
10. The method according to any one of claims 1 to 9, wherein: The replaying of the interception request in the candidate log to obtain the false interception identification result includes: According to a preset protocol conversion format, the interception request in the candidate log is converted into a preset protocol request; The preset protocol request is replayed to a preset second Web firewall to obtain the false interception identification result.
11. The method according to claim 10, wherein: The step of replaying the preset protocol request to a preset second Web firewall to obtain the false interception identification result includes: In response to determining that the transmission interface in the preset protocol request is not a preset interface, obtaining request message information from the preset protocol request; wherein the request message information includes a request header and a request body; In response to determining that the request message information does not meet the preset interception identification condition, the preset protocol request is replayed to a preset second Web firewall to obtain the false interception identification result.
12. The method according to claim 10 or 11, wherein: The step of replaying the preset protocol request to a preset second Web firewall to obtain the false interception identification result includes: replaying the preset protocol request to multiple preset second Web firewalls, and receiving response results fed back by each preset second Web firewall; wherein the response results indicate whether the preset second Web firewall intercepts the preset protocol request; The false interception identification result is determined according to the response results fed back by each preset second Web firewall.
13. The method according to claim 12, wherein: The response result fed back by each preset second Web firewall includes at least one result type of release, interception, and error; The determining the false interception identification result according to the response result fed back by each preset second Web firewall includes: In response to determining that the response results fed back by each preset second Web firewall include at least two result types, the false interception identification result is determined according to the quantity of each result type in the at least two result types.
14. The method according to claim 13, wherein: The determining the false interception identification result according to the quantity of each result type of the at least two result types includes: In response to determining that the number of each of the at least two result types is the same, determining a target type from the at least two result types according to a preset result type priority; The false interception identification result is determined according to the target type.
15. The method according to any one of claims 10 to 14, wherein: The step of replaying the preset protocol request to a preset second Web firewall to obtain the false interception identification result includes: Desensitizing the preset fields in the preset protocol request to obtain a desensitized preset protocol request; The desensitized preset protocol request is replayed to a preset second Web firewall to obtain the false interception identification result.
16. The method according to any one of claims 1 to 15, further comprising: Determining the number of logs that are mistakenly intercepted in the interception log data set; According to the number of logs belonging to false interception and the total number of interception logs in the interception log data set, the false interception ratio is determined and output; wherein the false interception ratio represents the ratio of the number of logs belonging to false interception to the total number of interception logs.
17. A device for identifying a false interception, comprising: A log acquisition unit, used to acquire a preset interception log data set of a first Web firewall; wherein the interception log data set includes a plurality of interception logs; A candidate determination unit, configured to determine a candidate log according to the access information in each of the interception logs; wherein the access information represents information of a request to access a Web application, and the probability that the candidate log represents that the interception log is intercepted by mistake is greater than a preset probability value; The request identification unit is used to replay the interception request in the candidate log to obtain an erroneous interception identification result; wherein the erroneous interception identification result indicates whether the candidate log is an interception log of erroneous interception.
18. An electronic device, comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 16.
19. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-16.
20. A computer program product, wherein: The invention comprises a computer program, which implements the steps of the method according to any one of claims 1 to 16 when being executed by a processor.