Vulnerability anti-intrusion control method, vulnerability anti-intrusion processing method and related equipment
By implementing dynamic control of third-party library switch components on the browser client, detecting and closing third-party libraries with unresolved vulnerabilities, the problem of time repairing browser third-party library vulnerabilities is solved, preventing vulnerabilities from being exploited and attacked, and protecting user security.
Patent Information
- Application Number
- CN202311594737.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, it takes time to fix vulnerabilities in third-party libraries of browsers, resulting in users being unable to be blocked in a short period of time, especially for zero-day vulnerabilities, which cause losses to a large number of users.
By sending security configuration information to the client at a predetermined time on the server, detecting vulnerabilities in the third-party library, and sending switch off instructions to the client when unresolved vulnerabilities are found, closing the corresponding third-party library switch components to prevent them from loading and calling.
It effectively prevents unresolved vulnerabilities from being exploited and launches attacks, and solves the problem of user losses caused by time fixing browser third-party library vulnerabilities.
Smart Images

Figure CN120046141A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer and communication technology, and in particular to a vulnerability anti-intrusion control method, a processing method and related equipment. Background Art
[0002] A vulnerability is a flaw in the specific implementation of hardware, software, a protocol, or a system security policy that could allow an attacker to access or damage the system without authorization.
[0003] As an important tool for users to access web browsing information, browsers are one of the important entrances to network attacks. A large number of third-party libraries are integrated into browsers, such as ffmpeg, webrtc, libusb, libwebp, etc. When vulnerabilities in these third-party libraries are discovered and exploited by network attackers, ordinary users usually cannot detect that they are being attacked. Browser manufacturers usually solve vulnerability problems by fixing vulnerabilities and releasing update packages, but since it takes a certain amount of time to fix vulnerabilities and release update packages, browser manufacturers cannot prevent users from being attacked in a short period of time, especially for zero-day vulnerabilities, causing various losses to a large number of users. Summary of the invention
[0004] The embodiments of the present application provide a vulnerability anti-intrusion control method, a processing method and related equipment, which can at least to a certain extent overcome the problem that the browser third-party library vulnerability repair in the prior art takes time and causes huge losses to users.
[0005] Other features and advantages of the present application will become apparent from the following detailed description, or may be learned in part by the practice of the present application.
[0006] According to one aspect of an embodiment of the present application, a vulnerability anti-intrusion control method is provided, which is applied to a server, and the vulnerability anti-intrusion control method includes: sending security configuration information to a client at predetermined intervals, the security configuration information including information of multiple predetermined third-party libraries and corresponding switch components; detecting vulnerability information of each of the predetermined third-party libraries, and determining whether the predetermined third-party library has any unresolved vulnerabilities; if the predetermined third-party library has any unresolved vulnerabilities, sending a switch closing instruction to the client to close the switch component corresponding to the predetermined third-party library.
[0007] In an embodiment of the present application, before sending security configuration information to the client at predetermined intervals, the vulnerability anti-intrusion control method also includes: obtaining browser environment information of the client at predetermined intervals; determining a callable third-party library based on the browser environment information; and generating the security configuration information based on the callable third-party library.
[0008] In an embodiment of the present application, generating the security configuration information according to the callable third-party library specifically includes: inputting the callable third-party libraries into the judgment model one by one to obtain whether the third-party library is a predetermined third-party library; generating the security configuration information according to each of the predetermined third-party libraries.
[0009] In an embodiment of the present application, the vulnerability anti-intrusion control method also includes: obtaining a third-party library sample set, the third-party library sample set including multiple third-party library samples, each of the third-party library samples is marked with a label of whether it is a predetermined third-party library; inputting the third-party library samples into the judgment model one by one to obtain a result of whether the judgment model outputs whether it is a predetermined third-party library; updating the parameters of the judgment model according to the result of whether it is a predetermined third-party library and the label of whether it is a predetermined third-party library until the end condition is met, stopping the training, and obtaining a trained judgment model.
[0010] In an embodiment of the present application, detecting vulnerability information of each of the predetermined third-party libraries to determine whether the predetermined third-party libraries have unresolved vulnerabilities specifically includes: accessing the homepage or official website of the developer of the predetermined third-party library to crawl the release information of the predetermined third-party library; determining vulnerability information of the predetermined third-party library based on the release information of the predetermined third-party library; and determining whether the predetermined third-party library has unresolved vulnerabilities based on the vulnerability information of the predetermined third-party library.
[0011] According to one aspect of an embodiment of the present application, a vulnerability anti-intrusion processing method is provided, which is applied to a client, and the vulnerability anti-intrusion processing method includes: obtaining security configuration information at predetermined intervals, the security configuration information including information of multiple predetermined third-party libraries and corresponding switch components; adding the switch component according to the security configuration information; receiving a switch closing instruction, the switch closing instruction including information of a predetermined third-party library with unresolved vulnerabilities; according to the switch closing instruction, closing the switch component corresponding to the predetermined third-party library with unresolved vulnerabilities to prevent the loading and calling of the predetermined third-party library with unresolved vulnerabilities.
[0012] In an embodiment of the present application, after the switch component corresponding to the predetermined third-party library with unresolved vulnerabilities is turned off according to the switch closing instruction, the vulnerability anti-intrusion processing method also includes: determining whether the predetermined third-party library with unresolved vulnerabilities has been loaded into the memory; if the predetermined third-party library with unresolved vulnerabilities has been loaded into the memory, unloading the predetermined third-party library from the memory.
[0013] In an embodiment of the present application, adding the switch component according to the security configuration information specifically includes: adding the switch component at the calling layer according to the security configuration information; adding the switch component at the loading layer according to the security configuration information.
[0014] According to one aspect of an embodiment of the present application, a vulnerability anti-intrusion control device is provided, and the vulnerability anti-intrusion control device includes: a configuration sending module, which is used to send security configuration information to a client at predetermined intervals, and the security configuration information includes information of multiple predetermined third-party libraries and corresponding switch components; a vulnerability detection module, which is used to detect the vulnerability information of each of the predetermined third-party libraries and determine whether the predetermined third-party library has unresolved vulnerabilities; an instruction sending module, which is used to send a switch closing instruction to the client if the predetermined third-party library has unresolved vulnerabilities, so as to close the switch component corresponding to the predetermined third-party library.
[0015] In an embodiment of the present application, the vulnerability anti-intrusion control device also includes: an information acquisition module, used to obtain the browser environment information of the client at predetermined intervals; a library file calling module, used to determine a callable third-party library based on the browser environment information; a configuration generation module, used to generate the security configuration information based on the callable third-party library.
[0016] In an embodiment of the present application, the configuration generation module specifically includes: a model input submodule, which is used to input the callable third-party libraries into the judgment model one by one to obtain whether the third-party library is a predetermined third-party library; a configuration information submodule, which is used to generate the security configuration information according to each of the predetermined third-party libraries.
[0017] In an embodiment of the present application, the vulnerability anti-intrusion control device also includes: a sample acquisition module, which is used to obtain a third-party library sample set, wherein the third-party library sample set includes multiple third-party library samples, and each of the third-party library samples is marked with a label of whether it is a predetermined third-party library; a sample input module, which is used to input the third-party library samples one by one into the judgment model to obtain a result of whether the judgment model outputs the predetermined third-party library; a parameter update module, which is used to update the parameters of the judgment model according to the result of whether it is a predetermined third-party library and the label of whether it is a predetermined third-party library, until the end condition is met, stop training, and obtain a trained judgment model.
[0018] In an embodiment of the present application, the vulnerability detection module specifically includes: an information crawling module, which is used to access the homepage or official website of the developer of the predetermined third-party library and crawl the release information of the predetermined third-party library; an information parsing module, which is used to determine the vulnerability information of the predetermined third-party library based on the release information of the predetermined third-party library; and a vulnerability query module, which is used to determine whether the predetermined third-party library has unresolved vulnerabilities based on the vulnerability information of the predetermined third-party library.
[0019] According to one aspect of an embodiment of the present application, a vulnerability anti-intrusion processing device is provided, and the vulnerability anti-intrusion processing device includes: a configuration acquisition module, which is used to obtain security configuration information at predetermined intervals, and the security configuration information includes information of multiple predetermined third-party libraries and corresponding switch components; a switch adding module, which is used to add the switch component according to the security configuration information; an instruction receiving module, which is used to receive a switch closing instruction, and the switch closing instruction includes information of a predetermined third-party library with unresolved vulnerabilities; a switch closing module, which is used to close the switch component corresponding to the predetermined third-party library with unresolved vulnerabilities according to the switch closing instruction, so as to prevent the loading and calling of the predetermined third-party library with unresolved vulnerabilities.
[0020] In an embodiment of the present application, the vulnerability anti-intrusion processing device also includes: a loading determination module, used to determine whether the predetermined third-party library with unresolved vulnerabilities has been loaded into the memory; and a memory unloading module, used to unload the predetermined third-party library from the memory if the predetermined third-party library with unresolved vulnerabilities has been loaded into the memory.
[0021] In an embodiment of the present application, the switch adding module specifically includes: a calling layer submodule, used to add the switch component in the calling layer according to the security configuration information; and a loading layer submodule, used to add the switch component in the loading layer according to the security configuration information.
[0022] According to one aspect of an embodiment of the present application, a computer-readable medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the vulnerability anti-intrusion control method described in the above embodiments and / or the vulnerability anti-intrusion processing method described above is implemented.
[0023] According to one aspect of an embodiment of the present application, an electronic device is provided, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the vulnerability anti-intrusion control method as described in the above embodiments and / or the vulnerability anti-intrusion processing method as described above.
[0024] In the technical solutions provided by some embodiments of the present application, by sending security configuration information to the client at regular intervals, adding a switch component corresponding to the third-party library to the client, when a third-party library is found to have a vulnerability, sending a command to close the corresponding switch component to the client, so that the corresponding switch component in the client is closed, at this time, the client can no longer call or load the third-party library, and the premise for the vulnerability of the third-party library to be exploited to launch an attack is that this library is loaded and called. Therefore, at this time, although the third-party library has a vulnerability, it cannot be called or loaded, resulting in the vulnerability of the third-party library cannot be exploited to launch an attack, thereby solving the problem that the browser third-party library vulnerability repair in the prior art takes time and causes a large loss to users.
[0025] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0027] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solution of the embodiments of the present application can be applied is shown.
[0028] Figure 2 A flow chart of a vulnerability anti-intrusion control method provided in an embodiment of the present application is shown.
[0029] Figure 3 Shown according to Figure 2 Another specific implementation flow chart of the vulnerability anti-intrusion control method shown in the corresponding embodiment.
[0030] Figure 4 A flow chart of a vulnerability anti-intrusion processing method provided in an embodiment of the present application is shown.
[0031] Figure 5 Shown according to Figure 4 Another specific implementation flow chart of the vulnerability anti-intrusion processing method shown in the corresponding embodiment.
[0032] Figure 6 A schematic diagram of the structure of a vulnerability anti-intrusion control device provided in an embodiment of the present application is shown.
[0033] Figure 7A schematic diagram of the structure of a vulnerability anti-intrusion processing device provided in an embodiment of the present application is shown.
[0034] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0035] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more comprehensive and complete and fully convey the concept of the example embodiments to those skilled in the art.
[0036] In addition, described feature, structure or characteristic can be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present application. However, those skilled in the art will appreciate that the technical scheme of the present application can be put into practice without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, known methods, devices, realizations or operations are not shown or described in detail to avoid blurring the various aspects of the application.
[0037] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0038] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to actual conditions.
[0039] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solution of the embodiment of the present application can be applied is shown. Figure 1 As shown, the system architecture may include a client 100 and a server 200 .
[0040] The client 100 is installed with a browser, which is a terminal device for users to operate the browser. It can be a mobile terminal, notebook, desktop computer, wearable device, digital camera, etc. All terminal devices with browsers installed. The server 200 is a computing device that provides computing, application and management services for the client 100. It can detect vulnerability information and send information and instructions to the client 100. It can be a data center, server cluster, server, desktop workstation, etc.
[0041] At predetermined intervals, the server 200 sends security configuration information to the client 100, and the security configuration information includes information of multiple predetermined third-party libraries and corresponding switch components. The client 100 adds the switch component according to the security configuration information. The server 200 detects the vulnerability information of each predetermined third-party library, and when it detects that the predetermined third-party library has an unresolved vulnerability, it sends a switch-off instruction to the client 100. According to the switch-off instruction, the client 100 turns off the switch component corresponding to the predetermined third-party library with the unresolved vulnerability to prevent the loading and calling of the predetermined third-party library with the unresolved vulnerability.
[0042] It should be noted that the client 100 and the server 200 may be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc., but are not limited thereto. The client 100 and the server 200 may be connected via Bluetooth, USB (Universal Serial Bus) or other communication connection methods, and the present invention does not limit this.
[0043] The implementation details of the technical solution of the embodiment of the present application are described in detail below:
[0044] Figure 2 A flowchart of a vulnerability anti-intrusion control method according to an embodiment of the present application is shown. The vulnerability anti-intrusion control method can be executed by a server, which can be Figure 1 The server 200 shown in FIG. Figure 2 As shown, the vulnerability anti-intrusion control method at least includes:
[0045] Step S210: sending security configuration information to the client at predetermined intervals, wherein the security configuration information includes information of a plurality of predetermined third-party libraries and corresponding switch components.
[0046] Step S220: Detect vulnerability information of each of the predetermined third-party libraries to determine whether the predetermined third-party library has any unresolved vulnerability.
[0047] Step S230: If the predetermined third-party library has an unresolved vulnerability, a switch closing instruction is sent to the client to close the switch component corresponding to the predetermined third-party library.
[0048] In the embodiment of the present application, by sending security configuration information to the client at regular intervals, adding the switch component corresponding to the third-party library to the client, when a third-party library is found to have a vulnerability, sending the corresponding switch component shutdown instruction to the client, so that the corresponding switch component in the client is shut down, at this time, the client can no longer call or load the third-party library, and the premise for the vulnerability of the third-party library to be exploited to launch an attack is that this library is loaded and called. Therefore, at this time, although the third-party library has a vulnerability, it cannot be called or loaded, resulting in the vulnerability of the third-party library cannot be exploited to launch an attack, thereby solving the problem that the browser third-party library vulnerability repair in the prior art takes time and causes a large amount of loss to users.
[0049] In step S210, the server needs to send security configuration information to the client at predetermined intervals. The security configuration information includes multiple switch components and corresponding predetermined third-party library information to ensure that different switch components can control different predetermined third-party libraries.
[0050] The security configuration information can be automatically generated according to the browser environment information, or it can be configured manually. It is also possible to first automatically generate a configuration template according to the browser environment information, and then manually edit and modify the configuration template to finally obtain the security configuration information.
[0051] In some embodiments, Figure 3 As shown, before step S210, the vulnerability anti-intrusion control method may further include:
[0052] Step S310: Obtain the browser environment information of the client at predetermined intervals.
[0053] Step S320: determining a callable third-party library based on the browser environment information.
[0054] Step S330: Generate the security configuration information according to the callable third-party library.
[0055] In an embodiment of the present application, security configuration information is automatically generated based on browser environment information. Specifically, the server obtains the environment information of the browser, i.e., the browser environment information, from the client at predetermined intervals; then, based on the browser environment information, it is determined that the browser can load and call a third-party library, i.e., the third-party library can be called; finally, based on the above-mentioned callable third-party library, security information is configured to generate security configuration information.
[0056] In step S310, the server obtains the environment information of the browser from the client at predetermined intervals. The browser environment information includes the programming language used by the browser, interface parameters, and codes of associated libraries.
[0057] In step S320, the browser environment information is parsed to obtain a third-party library that can be loaded and called by the browser.
[0058] In step S330, the above-mentioned callable third-party libraries are analyzed one by one to determine whether they have the possibility of being exploited, and then generate security configuration information.
[0059] In some embodiments, all callable third-party libraries may be directly identified as third-party libraries.
[0060] Specifically, in other embodiments, the specific implementation of step S330 can refer to the following embodiments. Figure 3 The detailed description of step S330 in the vulnerability intrusion prevention control method shown in the corresponding embodiment, in the vulnerability intrusion prevention control method, step S330 may include the following steps:
[0061] The callable third-party libraries are input into the judgment model one by one to obtain whether the callable third-party library is a predetermined third-party library.
[0062] The security configuration information is generated according to each of the predetermined third-party libraries.
[0063] In the embodiment of the present application, a neural network model is used to judge the third-party library. Since different third-party libraries use different syntaxes, different neural networks need to be prepared for different databases. After the callable third-party libraries are input into the judgment model one by one, the judgment model uses the corresponding neural network to parse the callable third-party library to determine whether the callable third-party library is a predetermined third-party library.
[0064] After the predetermined third-party libraries are determined, the switch components are associated with each predetermined third-party library to form security configuration information.
[0065] Specifically, the training method of the above judgment model may include:
[0066] A third-party library sample set is obtained, wherein the third-party library sample set includes a plurality of third-party library samples, and each of the third-party library samples is marked with a label indicating whether it is a predetermined third-party library.
[0067] The third-party library samples are input into the judgment model one by one to obtain a result of whether the judgment model outputs the predetermined third-party library.
[0068] According to the result of whether it is a predetermined third-party library and the label of whether it is a predetermined third-party library, the parameters of the judgment model are updated until the end condition is met, the training is stopped, and a trained judgment model is obtained.
[0069] In this embodiment, in order to analyze and learn the third-party library, the convolutional neural network can well capture the information features contained in the third-party library itself, mine the correlation between the third-party libraries, and has strong generalization ability and robustness. When training, the conditions for stopping training, that is, the conditions for model training, can be multiple, and the specific embodiments can be referred to as follows.
[0070] Specifically, in some embodiments, the above-mentioned updating of parameters of the judgment model according to the result of whether it is a predetermined third-party library and the label of whether it is a predetermined third-party library until the end condition is met, and the training is stopped. The trained judgment model may specifically include the following steps:
[0071] If, in the third-party library sample set, less than a predetermined number of third-party library samples are input into the judgment model and the output result of whether it is a predetermined third-party library is consistent with the label of whether it is a predetermined third-party library, the judgment model parameters are updated.
[0072] If in the third-party library sample set, more than a predetermined number of third-party library samples are input into the judgment model and the output result of whether it is the predetermined third-party library is consistent with the label of whether it is the predetermined third-party library, then the predetermined end condition is met, the training is ended, and a trained judgment model is obtained.
[0073] Specifically, in some other embodiments, the above-mentioned updating of parameters of the judgment model according to the result of whether it is a predetermined third-party library and the label of whether it is a predetermined third-party library until the end condition is met, and the training is stopped. The trained judgment model can specifically include the following steps:
[0074] A loss function is determined according to a label of whether the third-party library sample is a predetermined third-party library and a corresponding result of whether the third-party library sample is a predetermined third-party library.
[0075] The parameters of the judgment model are updated according to the loss function until a predetermined end condition is reached, and the training is terminated to obtain a trained judgment model.
[0076] In this embodiment, the loss function reaching a predetermined end condition may be that the loss function converges or the loss function is less than a predetermined loss (eg, 0.001).
[0077] In the above embodiment, log text recognition is performed through a neural network model obtained through multiple trainings to obtain corresponding judgment results. The neural network model is obtained through multiple trainings. The more samples it trains, the more accurate the results obtained. It basically does not require maintenance during operation, which also reduces maintenance costs, improves the efficiency and accuracy of traffic identification, and reduces the false alarm rate.
[0078] It should be noted that, in some other embodiments, the third-party library sample set may also be divided into a training set, a test set, and a validation set for training, and K-fold cross-validation folds may be used.
[0079] In step S220, the detection and acquisition of vulnerability information can be completed in a variety of ways. It can be obtained by passively obtaining input vulnerability reporting instructions, or by actively accessing official websites, forums, and information platforms where vulnerabilities are published.
[0080] Specifically, in some embodiments, the specific implementation of step S220 can refer to the following embodiments. Figure 2 The detailed description of step S220 in the vulnerability intrusion prevention control method shown in the corresponding embodiment, in the vulnerability intrusion prevention control method, step S220 may include the following steps:
[0081] Visit the homepage or official website of the developer of the predetermined third-party library and crawl the release information of the predetermined third-party library.
[0082] According to the release information of the predetermined third-party library, vulnerability information of the predetermined third-party library is determined.
[0083] According to the vulnerability information of the predetermined third-party library, it is determined whether the predetermined third-party library has any unresolved vulnerability.
[0084] In an embodiment of the present application, the homepage or official website of the developer of the predetermined third-party library is first visited, the release information related to the predetermined third-party library is crawled, the release information related to the predetermined third-party library is parsed, and the vulnerability information related to the third-party library, i.e., the vulnerability information of the predetermined third-party library, is determined. Then, based on the vulnerability information of the predetermined third-party library and the environment information of the client browser, it is determined whether there are unresolved vulnerabilities. Since the vulnerabilities of the third-party library will be continuously discovered, some vulnerabilities already have solutions, and the vulnerability will be solved as long as the corresponding patch is applied, and the vulnerability will not be exploited to launch an attack.
[0085] Optionally, when crawling information, network information such as multiple hacker forums and network security information publishing platforms can also be crawled to obtain vulnerability information of each predetermined third-party library in a more timely manner.
[0086] In addition, in some other embodiments, the detection of vulnerability information can also rely on vulnerability instructions transmitted to the server, the vulnerability instructions contain a corresponding predetermined third-party library, and according to the vulnerability instructions, it can be confirmed that the predetermined third-party library contained therein has unresolved vulnerabilities.
[0087] In step S230, when there is an unresolved vulnerability in the predetermined third-party library, a switch-off instruction is sent to the corresponding client, and after receiving the switch-off instruction, the client turns off the switch component corresponding to the predetermined third-party library. When the switch component is turned off, the client can no longer call or load the corresponding third-party library, resulting in the vulnerability of the third-party library cannot be exploited to launch an attack, thereby solving the problem of the prior art that it takes time to repair the vulnerability of the browser third-party library, causing a large loss to users.
[0088] Figure 4 A flowchart of a vulnerability anti-intrusion processing method according to an embodiment of the present application is shown. The vulnerability anti-intrusion processing method can be executed by a client, which can be Figure 1 The client shown in . Figure 4 As shown, the vulnerability anti-intrusion processing method at least includes:
[0089] Step S410: obtaining security configuration information at predetermined intervals, wherein the security configuration information includes information of a plurality of predetermined third-party libraries and corresponding switch components.
[0090] Step S420: adding the switch component according to the security configuration information.
[0091] Step S430: receiving a switch-off instruction, wherein the switch-off instruction includes information about a predetermined third-party library having an unresolved vulnerability.
[0092] Step S440: According to the switch closing instruction, the switch component corresponding to the predetermined third-party library with unresolved vulnerabilities is closed to prevent the loading and calling of the predetermined third-party library with unresolved vulnerabilities.
[0093] In the embodiment of the present application, by obtaining the security configuration information sent by the server at regular intervals, adding the switch component corresponding to the third-party library, when a third-party library is found to have a vulnerability, an instruction to close the corresponding switch component will be sent, the switch closing instruction is received, and the switch closing instruction is executed to close the corresponding switch component. At this time, the client can no longer call or load the third-party library, and the premise for the vulnerability of the third-party library to be exploited to launch an attack is that this library is loaded and called. Therefore, at this time, although the third-party library has a vulnerability, it cannot be called or loaded, resulting in the vulnerability of the third-party library cannot be exploited to launch an attack, thereby solving the problem that the browser third-party library vulnerability repair in the prior art takes time and causes a large amount of loss to users.
[0094] In step S410, the client needs to receive security configuration information sent by the server at predetermined intervals. The security configuration information includes multiple switch components and corresponding predetermined third-party library information to ensure that different switch components can control different predetermined third-party libraries.
[0095] In step S420, according to the above security configuration information, a switch component is added to the relevant policy structure and corresponding position of the browser.
[0096] Specifically, in some embodiments, the specific implementation of step S420 can refer to the following embodiments. Figure 4 The detailed description of step S420 in the vulnerability intrusion prevention control method shown in the corresponding embodiment, in the vulnerability intrusion prevention control method, step S420 may include the following steps:
[0097] According to the security configuration information, the switch component is added at the calling layer.
[0098] According to the security configuration information, the switch component is added in the loading layer.
[0099] In the embodiment of the present application, a switch component needs to be added to both the call layer and the loading layer to control the loading and calling process of the third-party library respectively. The switch components added on the client are all located in the call layer or the loading layer and are associated with the corresponding third-party library.
[0100] In step S430, when there are unresolved vulnerabilities in the predetermined third-party library, the server will send a switch-off instruction to the corresponding client, and the client receives the switch-off instruction, which includes information about the predetermined third-party library with the unresolved vulnerability.
[0101] In step S440, after receiving the switch off instruction, the client turns off the switch component corresponding to the predetermined third-party library. When the switch component is turned off, the client can no longer call or load the corresponding third-party library, resulting in the vulnerability of the third-party library cannot be exploited to launch an attack, thereby solving the problem of the prior art that it takes time to repair the vulnerability of the browser third-party library, causing a large amount of loss to users.
[0102] Specifically, when the client's browser needs to load or call a third-party library, it is necessary to first determine whether the switch component of the third-party library is in the off state. If it is in the off state, the third-party library cannot be called or loaded. If it is in the on state, the third-party library can be called or loaded.
[0103] In some embodiments, Figure 5 As shown, after step S440, the vulnerability anti-intrusion processing method may further include:
[0104] Step S510, determining whether the predetermined third-party library with the unresolved vulnerability has been loaded into the memory.
[0105] Step S520: If the predetermined third-party library with the unresolved vulnerability has been loaded into the memory, the predetermined third-party library is unloaded from the memory.
[0106] In an embodiment of the present application, after the switch component is turned off, it is also necessary to determine whether the third-party library has been loaded into the client's memory. If it has been loaded, it needs to be unloaded from the client's memory to avoid vulnerabilities in the loaded third-party library from being exploited to launch attacks, leaving security risks.
[0107] The following describes an embodiment of the device of the present application, which can be used to execute the vulnerability anti-intrusion control method and / or vulnerability anti-intrusion processing method in the above-mentioned embodiments of the present application. For details not disclosed in the embodiment of the device of the present application, please refer to the embodiments of the vulnerability anti-intrusion control method and / or vulnerability anti-intrusion processing method in the above-mentioned embodiments of the present application.
[0108] Figure 6 A block diagram of a vulnerability anti-intrusion control device according to an embodiment of the present application is shown.
[0109] Reference Figure 6 As shown, a vulnerability intrusion prevention control device 600 according to an embodiment of the present application includes: a configuration sending module 610, a vulnerability detection module 620, and an instruction sending module 630.
[0110] Among them, the configuration sending module 610 is used to send security configuration information to the client at predetermined intervals, and the security configuration information includes information of multiple predetermined third-party libraries and corresponding switch components; the vulnerability detection module 620 is used to detect the vulnerability information of each of the predetermined third-party libraries and determine whether there are unresolved vulnerabilities in the predetermined third-party libraries; the instruction sending module 630 is used to send a switch closing instruction to the client if there are unresolved vulnerabilities in the predetermined third-party library, so as to close the switch component corresponding to the predetermined third-party library.
[0111] In an embodiment of the present application, the vulnerability anti-intrusion control device also includes: an information acquisition module, used to obtain the browser environment information of the client at predetermined intervals; a library file calling module, used to determine a callable third-party library based on the browser environment information; a configuration generation module, used to generate the security configuration information based on the callable third-party library.
[0112] In an embodiment of the present application, the configuration generation module specifically includes: a model input submodule, which is used to input the callable third-party libraries into the judgment model one by one to obtain whether the third-party library is a predetermined third-party library; a configuration information submodule, which is used to generate the security configuration information according to each of the predetermined third-party libraries.
[0113] In an embodiment of the present application, the vulnerability anti-intrusion control device also includes: a sample acquisition module, which is used to obtain a third-party library sample set, wherein the third-party library sample set includes multiple third-party library samples, and each of the third-party library samples is marked with a label of whether it is a predetermined third-party library; a sample input module, which is used to input the third-party library samples one by one into the judgment model to obtain a result of whether the judgment model outputs the predetermined third-party library; a parameter update module, which is used to update the parameters of the judgment model according to the result of whether it is a predetermined third-party library and the label of whether it is a predetermined third-party library, until the end condition is met, stop training, and obtain a trained judgment model.
[0114] In an embodiment of the present application, the vulnerability detection module specifically includes: an information crawling module, which is used to access the homepage or official website of the developer of the predetermined third-party library and crawl the release information of the predetermined third-party library; an information parsing module, which is used to determine the vulnerability information of the predetermined third-party library based on the release information of the predetermined third-party library; and a vulnerability query module, which is used to determine whether the predetermined third-party library has unresolved vulnerabilities based on the vulnerability information of the predetermined third-party library.
[0115] In the embodiment of the present application, by sending security configuration information to the client at regular intervals, adding the switch component corresponding to the third-party library to the client, when a third-party library is found to have a vulnerability, sending the corresponding switch component shutdown instruction to the client, so that the corresponding switch component in the client is shut down, at this time, the client can no longer call or load the third-party library, and the premise for the vulnerability of the third-party library to be exploited to launch an attack is that this library is loaded and called. Therefore, at this time, although the third-party library has a vulnerability, it cannot be called or loaded, resulting in the vulnerability of the third-party library cannot be exploited to launch an attack, thereby solving the problem that the browser third-party library vulnerability repair in the prior art takes time and causes a large amount of loss to users.
[0116] Figure 7 A block diagram of a vulnerability anti-intrusion processing device according to an embodiment of the present application is shown.
[0117] Reference Figure 7 As shown, a vulnerability anti-intrusion processing device 700 according to an embodiment of the present application includes: a configuration acquisition module 710, a switch adding module 720, an instruction receiving module 730, and a switch closing module 740.
[0118] Among them, the configuration acquisition module 710 is used to obtain security configuration information at predetermined intervals, and the security configuration information includes information of multiple predetermined third-party libraries and corresponding switch components; the switch addition module 720 is used to add the switch component according to the security configuration information; the instruction receiving module 730 is used to receive a switch closing instruction, and the switch closing instruction includes information of a predetermined third-party library with unresolved vulnerabilities; the switch closing module 740 is used to close the switch component corresponding to the predetermined third-party library with unresolved vulnerabilities according to the switch closing instruction, so as to prevent the loading and calling of the predetermined third-party library with unresolved vulnerabilities.
[0119] In an embodiment of the present application, the vulnerability anti-intrusion processing device also includes: a loading determination module, used to determine whether the predetermined third-party library with unresolved vulnerabilities has been loaded into the memory; and a memory unloading module, used to unload the predetermined third-party library from the memory if the predetermined third-party library with unresolved vulnerabilities has been loaded into the memory.
[0120] In an embodiment of the present application, the switch adding module specifically includes: a calling layer submodule, used to add the switch component in the calling layer according to the security configuration information; and a loading layer submodule, used to add the switch component in the loading layer according to the security configuration information.
[0121] In the embodiment of the present application, by obtaining the security configuration information sent by the server at regular intervals, adding the switch component corresponding to the third-party library, when a third-party library is found to have a vulnerability, an instruction to close the corresponding switch component will be sent, the switch closing instruction is received, and the switch closing instruction is executed to close the corresponding switch component. At this time, the client can no longer call or load the third-party library, and the premise for the vulnerability of the third-party library to be exploited to launch an attack is that this library is loaded and called. Therefore, at this time, although the third-party library has a vulnerability, it cannot be called or loaded, resulting in the vulnerability of the third-party library cannot be exploited to launch an attack, thereby solving the problem that the browser third-party library vulnerability repair in the prior art takes time and causes a large amount of loss to users.
[0122] Figure 8 A schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application is shown.
[0123] It should be noted that Figure 8 The computer system of the electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0124] like Figure 8As shown, the computer system includes a central processing unit (CPU) 1801, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1802 or the program loaded from the storage part 1808 to the random access memory (RAM) 1803, such as executing the method described in the above embodiment. In RAM 1803, various programs and data required for system operation are also stored. CPU 1801, ROM 1802 and RAM 1803 are connected to each other through bus 1804. Input / output (I / O) interface 1805 is also connected to bus 1804.
[0125] The following components are connected to the I / O interface 1805: an input section 1806 including a keyboard, a mouse, etc.; an output section 1807 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1808 including a hard disk, etc.; and a communication section 1809 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 1809 performs communication processing via a network such as the Internet. A drive 1810 is also connected to the I / O interface 1805 as needed. A removable medium 1811, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1810 as needed so that a computer program read therefrom is installed into the storage section 1808 as needed.
[0126] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication section 1809, and / or installed from a removable medium 1811. When the computer program is executed by a central processing unit (CPU) 1801, various functions defined in the system of the present application are executed.
[0127] It should be noted that the computer-readable medium shown in the embodiment of the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, - but not limited to - an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by an instruction execution system, device or device or used in combination with it. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, wherein a computer-readable computer program is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which may send, propagate, or transmit programs for use by or in conjunction with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0128] The flowchart and block diagram in the accompanying drawings illustrate the possible architecture, functions and operations of the system, method and computer program product according to various embodiments of the present application. Wherein, each box in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0129] The units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor. The names of these units do not, in some cases, constitute limitations on the units themselves.
[0130] As another aspect, the present application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiment; or may exist independently without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the method described in the above embodiment.
[0131] It should be noted that, although several modules or units of the equipment for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into being embodied by multiple modules or units.
[0132] Through the description of the above implementation methods, it is easy for those skilled in the art to understand that the example implementation methods described here can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the implementation methods of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the implementation methods of the present application.
[0133] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the embodiments disclosed herein. The present application is intended to cover any variations, uses or adaptations of the present application, which follow the general principles of the present application and include common knowledge or customary technical means in the art that are not disclosed in the present application.
[0134] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A vulnerability anti-intrusion control method, characterized in that, applied to the server side, the vulnerability anti-intrusion control method includes: Sending security configuration information to the client at regular intervals, where the security configuration information includes information on multiple predetermined third-party libraries and corresponding switch components; Detecting vulnerability information of each of the predetermined third-party libraries to determine whether there are unresolved vulnerabilities in the predetermined third-party libraries; If there are unresolved vulnerabilities in the predetermined third-party libraries, sending a switch closing instruction to the client to close the switch components corresponding to the predetermined third-party libraries.
2. The vulnerability anti-intrusion control method according to claim 1, characterized in that, Before sending the security configuration information to the client at regular intervals, the vulnerability anti-intrusion control method further includes: Obtaining the browser environment information of the client at regular intervals; Determining the third-party libraries that can be called according to the browser environment information; Generating the security configuration information according to the third-party libraries that can be called.
3. The vulnerability anti-intrusion control method according to claim 1, characterized in that, The detecting vulnerability information of each of the predetermined third-party libraries to determine whether there are unresolved vulnerabilities in the predetermined third-party libraries specifically includes: Accessing the homepage or official website of the developer of the predetermined third-party library and crawling the release information of the predetermined third-party library; Determining the vulnerability information of the predetermined third-party library according to the release information of the predetermined third-party library; Determining whether there are unresolved vulnerabilities in the predetermined third-party library according to the vulnerability information of the predetermined third-party library.
4. A vulnerability anti-intrusion processing method, characterized in that, applied to the client side, the vulnerability anti-intrusion processing method includes: Obtaining security configuration information at regular intervals, where the security configuration information includes information on multiple predetermined third-party libraries and corresponding switch components; Adding the switch components according to the security configuration information; Receiving a switch closing instruction, where the switch closing instruction contains information on the predetermined third-party library with unresolved vulnerabilities; Closing the switch components corresponding to the predetermined third-party library with unresolved vulnerabilities according to the switch closing instruction to prevent the loading and calling of the predetermined third-party library with unresolved vulnerabilities.
5. The vulnerability anti-intrusion processing method according to claim 4, characterized in that, After closing the switch components corresponding to the predetermined third-party library with unresolved vulnerabilities according to the switch closing instruction, the vulnerability anti-intrusion processing method further includes: Determining whether the predetermined third-party library with unresolved vulnerabilities has been loaded into the memory; If the predetermined third-party library with unresolved vulnerabilities has been loaded into the memory, unloading the predetermined third-party library from the memory.
6. The vulnerability anti-intrusion processing method according to claim 4, characterized in that, The adding the switch components according to the security configuration information specifically includes: Adding the switch components at the call layer according to the security configuration information; Adding the switch components at the loading layer according to the security configuration information.
7. A vulnerability anti-intrusion control device, characterized in that, The vulnerability anti-intrusion control device includes: A configuration sending module, which is used to send security configuration information to the client at regular intervals. The security configuration information includes information on multiple predetermined third-party libraries and corresponding switch components; A vulnerability detection module, which is used to detect vulnerability information of each of the predetermined third-party libraries and determine whether there are unresolved vulnerabilities in the predetermined third-party libraries; An instruction sending module, which is used to send a switch closing instruction to the client if there are unresolved vulnerabilities in the predetermined third-party libraries, so as to close the switch component corresponding to the predetermined third-party library.
8. A vulnerability prevention and intrusion handling device, characterized in that, the vulnerability prevention and intrusion handling device includes: A configuration acquisition module, which is used to acquire security configuration information at regular intervals. The security configuration information includes information on multiple predetermined third-party libraries and corresponding switch components; A switch adding module, which is used to add the switch components according to the security configuration information; An instruction receiving module, which is used to receive a switch closing instruction. The switch closing instruction contains information on the predetermined third-party library with unresolved vulnerabilities; A switch closing module, which is used to close the switch component corresponding to the predetermined third-party library with unresolved vulnerabilities according to the switch closing instruction, so as to prevent the loading and calling of the predetermined third-party library with unresolved vulnerabilities.
9. A computer-readable medium, on which a computer program is stored, characterized in that, when the computer program is executed by a processor, it implements the vulnerability prevention and intrusion control method according to any one of claims 1 to 3 and / or the vulnerability prevention and intrusion handling method according to any one of claims 4 to 6.
10. An electronic device, characterized in that, it includes: one or more processors; a storage device, which is used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the vulnerability prevention and intrusion control method according to any one of claims 1 to 3 and / or the vulnerability prevention and intrusion handling method according to any one of claims 4 to 6.