Security protection method and device for Web application, equipment, medium and program product

By calculating the attack probability index and implementation index of web applications, and taking multi-level security protection measures, the problem of Web application security being threatened by multiple attacks is solved, and the effect of improving security performance and defense capabilities is achieved.

CN120046147APending Publication Date: 2025-05-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510185253.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The security of web applications is threatened by multiple attacks, which affects the normal operation of the business and may lead to information leakage.

Method used

By obtaining the attack path of the web application, the attack probability index and the attack realization index are calculated, and corresponding security protection measures are taken for the browser layer, transport layer, server layer and database layer based on these indexes, including single data verification, overall data verification, encrypted transmission, token verification, precompiled structured query statements and database permission restrictions, etc.

Benefits of technology

Establish multiple protection mechanisms to weaken or resist multiple attacks, improve the confidentiality, integrity and availability of web applications, and enhance the security performance of applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046147A_ABST
    Figure CN120046147A_ABST
Patent Text Reader

Abstract

The invention provides a Web application security protection method and device, equipment, a medium and a program product, and relates to the field of information security. The method comprises the following steps: acquiring an attack path of a Web application, and calculating an attack possibility index and an attack realization degree index of the Web application according to the attack path; and under the condition that the attack possibility index is greater than a first preset value or the attack realization degree index is greater than a second preset value, taking corresponding security protection measures on the browser layer, the transmission layer, the server layer and the database layer. According to the method provided by the invention, corresponding security protection measures are taken for the browser, the transmission layer, the server layer and the database layer to establish multiple protection for the Web application, so that multiple attacks can be weakened or resisted, three attributes of confidentiality, integrity and availability of the overall Web application are improved, and the security performance of the application is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security, and in particular, to a security protection method, device, equipment, medium, and program product for Web applications. Background Art

[0002] A Web application is an application program accessed through a network (usually the Internet) and can be used normally only relying on a browser. The dependence of various industries on Web applications has been gradually strengthened, such as online banking, electronic office work, etc.

[0003] However, when the security of a Web application is threatened, it will affect people's normal business, and even lead to the leakage of personal or company information, affecting personal or company security. Therefore, how to protect the security of Web applications is a relatively important issue. Summary of the Invention

[0004] This application provides a security protection method, device, equipment, medium, and program product for Web applications to solve the security problems of Web applications.

[0005] In a first aspect, this application provides a security protection method for a Web application, including:

[0006] Obtaining the attack path of the Web application, and calculating the attack possibility index and attack implementation degree index of the Web application according to the attack path;

[0007] When the attack possibility index is greater than a first preset value, or the attack implementation degree index is greater than a second preset value, corresponding security protection measures are taken for the browser layer, transport layer, server layer, and database layer;

[0008] The security protection measures corresponding to the browser layer include at least one of single-item data verification, overall data verification, and weak password detection;

[0009] The security protection measures corresponding to the transport layer include encrypting the transmitted data;

[0010] The security protection measures corresponding to the server layer include at least one of single-item data verification, overall data verification, token verification, server status verification, pre-compiled structured query statements, and distributed deployment;

[0011] The security protection measures corresponding to the database layer include at least one of restricting database permissions and encrypting private data.

[0012] In a second aspect, this application provides a security protection device for a Web application, including:

[0013] The first processing module is used to obtain the attack path of the Web application and calculate the attack possibility index and attack implementation degree index of the Web application according to the attack path;

[0014] The second processing module is used to take corresponding security protection measures for the browser layer, transport layer, server layer, and database layer when the attack possibility index is greater than a first preset value or the attack implementation degree index is greater than a second preset value;

[0015] The security protection measures corresponding to the browser layer include at least one of single-item data verification, overall data verification, and weak password detection;

[0016] The security protection measures corresponding to the transport layer include encrypting the transmitted data;

[0017] The security protection measures corresponding to the server layer include at least one of single-item data verification, overall data verification, token verification, server status verification, pre-compiled structured query statements, and distributed deployment;

[0018] The security protection measures corresponding to the database layer include at least one of restricting database permissions and encrypting private data.

[0019] In a third aspect, the present application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0020] The memory stores computer-executable instructions;

[0021] The processor executes the computer-executable instructions stored in the memory to implement the method described in the first aspect.

[0022] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the method described in the first aspect.

[0023] In a fifth aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method described in the first aspect.

[0024] The security protection method, device, equipment, medium and program product for Web applications provided by this application obtain the attack paths of Web applications, calculate the attack possibility index and attack implementation degree index of Web applications according to the attack paths, and take corresponding security protection measures for the browser, transport layer, server layer and database layer when the attack possibility index of the Web application is greater than the first preset value or the attack implementation degree index is greater than the second preset value, so as to establish multiple protections, thereby weakening or resisting various attacks, improving the three major CIA attributes of the overall Web application, and increasing the application security performance. Description of the Drawings

[0025] The drawings here are incorporated into the specification and form a part of this specification, showing the embodiments consistent with this application, and are used together with the specification to explain the principles of this application.

[0026] Figure 1 Schematic flowchart of the security protection method for Web applications provided by this application Figure 1 ;

[0027] Figure 2 Schematic flowchart of the security protection method for Web applications provided by this application Figure 2 ;

[0028] Figure 3 Schematic diagram of an attack graph model provided by an embodiment of this application;

[0029] Figure 4 Schematic diagram of another attack graph model provided by an embodiment of this application;

[0030] Figure 5 Schematic diagram of the structure of the security protection device provided by this application;

[0031] Figure 6 Schematic diagram of the structure of the electronic device provided by this application.

[0032] Through the above drawings, the clear embodiments of this application have been shown, and there will be more detailed descriptions later. These drawings and text descriptions are not intended to limit the scope of the concept of this application in any way, but to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. Detailed Embodiments

[0033] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with this application. On the contrary, they are only examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.

[0034] It should be noted that the user information involved in this application (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, for the processing of relevant data such as collection, use, processing, transmission, provision, disclosure, and application, relevant laws, regulations, and standards of relevant countries and regions are complied with, necessary confidentiality measures are taken, public order and good customs are not violated, and corresponding operation entrances are provided for users to choose to authorize or reject.

[0035] Furthermore, for the technical solution of this application that involves big data analysis of user information (including but not limited to personal biometric features, identity data, consumption data, asset data, electronic terminal operation data, etc.), and uses artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights and interests based on the results of automated decision-making, a corresponding operation entrance is provided for users to choose to agree or reject the results of automated decision-making; if the user chooses to reject, the expert decision-making process will be entered.

[0036] It should be noted that the security protection method, device, equipment, medium, and program product of the Web application in this application can be used in the field of information security, or can be used in any field other than information security. The application field of the security protection method, device, equipment, medium, and program product of the Web application in this application is not limited.

[0037] Network information security is always related to three fundamental aspects of attributes: confidentiality (Confidentiality, C), integrity (Integrity, I), and availability (Availability, A). Confidentiality refers to whether the user's information is secure and at risk of being stolen; integrity refers to whether the user's information is complete and has been tampered with by a third party; availability refers to whether it is normal during use and whether there are phenomena such as network unavailability. The three major attributes of CIA complement each other and are indispensable for the normal use of the Internet. Any problem in each aspect will put people at security risk, and the security of Web applications based on the Internet is thus derived.

[0038] The security threats faced by existing Web applications and possible attacks can include attacks on the browser side, attacks on the server side, and attacks on the transmission channel. Attacks on the browser side can include XSS (Cross Site Scripting) attacks and CSRF (Cross-site request forgery) attacks. Attacks on the server side can include Sql Injection (Structured Query Language Injection) vulnerabilities, Replay Attacks, DDOS (Distributed Denial of Service) attacks, and extra-large payload attacks. Attacks on the transmission channel can include network sniffing and HTTP (HyperText Transfer Protocol) hijacking.

[0039] Therefore, this application proposes a security protection method for Web applications. When the attack possibility index of the Web application is greater than the first preset value or the attack implementation degree index is greater than the second preset value, corresponding security protection measures are taken for the browser, the transport layer, the server layer, and the database layer to establish multiple protections, so as to weaken or resist various attacks, improve the three major CIA attributes of the overall Web application, and increase the application security performance.

[0040] An embodiment of the present application provides a scenario diagram of a Web application. The electronic device obtains the attack path of the Web application, calculates the attack possibility index and the attack implementation degree index of the Web application according to the attack path. When the attack possibility index is greater than the first preset value or the attack implementation degree index is greater than the second preset value, the electronic device performs at least one of single data verification, overall data verification, and weak password detection on the user data received by the browser layer, thereby preventing XSS attacks. Then, the electronic device encrypts the user data through the transport layer and transmits it to the server layer, so that after HTTP hijacking or network sniffing occurs, the user data can be protected from being stolen or cracked. Subsequently, the electronic device is distributedly deployed at the server layer, and at least one of single data verification, overall data verification, token verification, server status verification, and precompiled structured query statements is performed on the second data at the server, thereby preventing the attacker's Sql Injection attack and preventing a certain degree of large payload attack and HTTP hijacking attack, and also improving the defense ability against DDOS attacks and RepalyAttacks. Subsequently, the electronic device can also store the user data processed by the server layer verification in the database layer, encrypt the private data in the database layer, and restrict the access rights of the database, so that when the database is successfully attacked by the attacker's Sql Injection, the data loss can be reduced.

[0041] The following uses specific embodiments to describe in detail the technical solutions of the present application and how the technical solutions of the present application solve the above technical problems. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.

[0042] Figure 1 A security protection method for a Web application provided by an embodiment of the present application, as Figure 1 shown, the security protection method for a Web application provided by an embodiment of the present application may include:

[0043] S101. Obtain the attack path of the Web application, and calculate the attack possibility index and the attack implementation degree index of the Web application according to the attack path.

[0044] Among them, the attack path refers to the steps and methods that an attacker may use to achieve its attack goal. The attack path may include attack states and attack behaviors, and the attack states may include the initial state, the attack process state, the attack target state, and the attack success state.

[0045] The attack implementation degree refers to the degree to which an attacker achieves their attack goal, and the attack possibility refers to the possibility that an attacker uses a certain method to conduct an attack. The larger the attack implementation degree index, the higher the risk factor faced by the Web application; the smaller the attack implementation degree index, the lower the risk factor faced by the Web application; the larger the attack possibility index, the higher the risk factor faced by the Web application; the smaller the attack possibility index, the lower the risk factor faced by the Web application.

[0046] In this step, the security of the Web application is quantified according to the attack path so as to determine whether security protection is required.

[0047] S102. In the case where the attack possibility index is greater than the first preset value or the attack possibility index is greater than the second preset value, corresponding security protection measures are taken for the browser layer, the transport layer, the server layer, and the database layer.

[0048] For example, there can be multiple attack paths for a Web application, and each attack path has a corresponding attack possibility index. When the attack possibility index of any attack path is greater than the first preset value or the attack implementation degree is greater than the second preset value, corresponding security protection measures can be taken for the browser layer, the transport layer, the server layer, and the database layer to improve the security of the Web application.

[0049] Among them, the security protection measures corresponding to the browser can include at least one of single-item data verification, overall data verification, and weak password detection; the security protection measures corresponding to the transport layer can include encrypting the transmitted data; the security protection measures corresponding to the server layer can include at least one of single-item data verification, overall data verification, token verification, server state verification, pre-compiled structured query statements, and distributed deployment; the security protection measures corresponding to the database layer can include at least one of restricting database permissions and encrypting private data.

[0050] For example, on the browser side, standardize the operations of users, and prohibit users from setting weak passwords to prevent attackers from brute-forcing; use single-item data verification technology to add as many data verification judgments as possible to verify the standardization of user data on the browser side. Prevent XSS attacks by filtering and parsing the input data on the browser side. In addition, perform an overall data verification operation before data transmission to generate a verification code and attach it to the overall data.

[0051] At the transport layer, the transmitted data is encrypted. For example, HTTPS (Hypertext Transfer Protocol Secure) can be used to establish a transmission channel. Even if an attacker performs HTTP hijacking or network sniffing, the data packets obtained are encrypted. This prevents user data from being stolen or cracked after HTTP hijacking or network sniffing.

[0052] At the server layer, single data verification and overall data verification technology are used to filter sensitive characters and characters that exceed the design specifications, and only respond to requests with correct overall data verification codes; Sql (Structured Query Language) pre-compilation is performed, and only parameters in the corresponding format are received. By checking the rules of the parameters, dynamic assembly of Sql is prohibited to prevent attackers' Sql Injection attacks, and to prevent a certain degree of large payload attacks and HTTP hijacking attacks; multiple rule verifiers are established to verify the token submitted by the browser and the parameters in the HTTP request header; and the service deployment is distributed, which can improve the defense capabilities against DDOS attacks and replay attacks, thus defending against DDOS attacks and Replay Attacks to a certain extent.

[0053] At the database layer, the core private data of the database is encrypted and stored, so that information security can be guaranteed even if the database is cracked; the database permissions should be as low as possible to reduce data loss when attacked, so as to improve the security and stability of database operations. Among them, private data includes user passwords.

[0054] In this way, through multiple protections at the browser layer, transport layer, server layer, and database layer, we can defend against XSS attacks, CSRF attacks, Sql Injection attacks, HTTP hijacking, and network sniffing attacks, and can reduce the hazards of extremely large payloads, DDOS attacks, and Replay Attacks to a certain extent, which will greatly improve the three major properties of the overall Web application CIA and increase application security performance.

[0055] For example, XSS and Sql Injection are injection vulnerabilities, and their causes are due to over-trusting user input and not filtering and detecting input and output. The difference is that XSS is a front-end vulnerability that requires malicious code to be parsed and executed in the browser, while Sql Injection is a back-end vulnerability in the interaction process between the server and the database, which is implemented through Sql statements. Extra-large payloads are submitted data messages or uploaded data that is too large, resulting in excessive consumption of server resources and damage to system availability.

[0056] Single - data verification means that for the data input by users, format verification and filtering of special characters are carried out. On the premise of restricting the input data and output data, malicious data constructed by attackers in XSS and Sql Injection attacks cannot cause harm in an injected manner; for extremely large payloads, the length of the data packet can be restricted by verifying the length of the data, thereby alleviating the threat of extremely large payloads to a certain extent.

[0057] Among them, verifying the format of the data can be to restrict the format or length of the data input by users. Restricting the data type can be, for example, only allowing int type (such as phone numbers) to be input, and the character - length restriction can be, for example, restricting the phone number to be only 11 digits, which can be determined according to the specific business logic. For data types and data lengths that do not conform to the rules, the request is rejected.

[0058] Content filtering of the data can be to verify the input content on the browser side, and different content verifications can be carried out for different types of injection vulnerabilities.

[0059] For example, for XSS data filtering: XSS occurs on the browser side, mainly due to the execution of JS scripts inserted by attackers, which poses a threat. Therefore, it can be verified whether the request submitted to the server contains characters in JS scripts.

[0060] Another example is for Sql Injection content filtering: Sql Injection attacks are carried out by processing some Sql statements as request parameters without filtering and injecting them into the database layer through the request address to achieve the intended attack means. Therefore, for data filtering against such attack methods, it can be defended from the characteristics of Sql statements. Generally speaking, special characters in Sql statements will not be transmitted as interactive content in the form of data, such as single quotes, "--", "#", "|", "and", "or", "where", "from", "select", etc. According to different requests in the request, the above characters are filtered. If they do not exist, the next step is to access the database; if they exist, access is refused.

[0061] For example, CSRF is an attack where an attacker forges a user's identity and sends a legitimate but malicious request to the browser that is not intended by the user. HTTP hijacking occurs because during data transmission, the corresponding network protocol coordinates to establish a dedicated data channel for communication between the browser and the server. The server packages the data according to the specified network protocol to form a data packet. The browser receives the data packet from the server through the specified network port. An HTTP hijacking attack monitors specific data information in this dedicated data channel. When the set trigger condition is met, the originally set data packet is inserted into the normal data stream, resulting in abnormal display on the browser side, popping up ads, or performing SQL injection.

[0062] Although the principles of the two attack methods of CSRF and HTTP hijacking are different, they both require interaction with the server. Therefore, before the browser submits data to the server, the data is first overall verified, and a unique verification code is generated and attached to the data, and then transmitted to the server together. After the server receives it, it first needs to perform the same method of verification and compare it with the attached verification code. If the comparison result is incorrect, it is regarded as being attacked and access is refused. Therefore, when an attacker inserts data through HTTP hijacking, the attack will fail because the generated data verification code is incorrect, or when forging a user to perform a CSRF attack, it increases the difficulty of the attack.

[0063] Correspondingly, even if the attacker switches to the "HTTP hijacking" state, they are largely restricted because they cannot inject information.

[0064] For example, overall data verification can only reduce the risk of a successful CSRF attack to a certain extent. The root cause of CSRF attacks is the defect in the implicit authentication mechanism of the Web. Although the Web authentication mechanism can ensure that the request comes from the user's browser, it cannot ensure that the request is sent by the user. In a situation where an attacker can forge a user's identity and maliciously manipulate the user's browser to send a request, this mechanism cannot recognize and defend against this attack. Therefore, for CSRF attacks, the method of adding a security token can be used to further identify and verify the user's identity.

[0065] The reason why CSRF attacks can succeed is that attackers perfectly forge themselves as users, thereby deceiving the server. The server verifies users through the Cookie information in the request. Since all user authentication information is stored in the Cookie information, attackers can directly steal the Cookie information of the attacked user for Cookie spoofing without stealing the identity authentication information, in order to pass the security verification and access the Web application as the user. Based on this situation, a security token can be added to the hidden field of the form in a particularly sensitive request. This security token is randomly generated by the server and is different each time it is generated (destroyed after use). An interceptor is designed on the server side to verify the security token. This security token is not stored in the Cookie, thus preventing attackers from obtaining user identity information. If the security token is abnormal, it can be judged that it is not a normal request sent by an authenticated user and can be considered a CSRF attack, thus rejecting the service. In addition, some custom attributes can be added to the HTTP request header and also verified on the server side to effectively defend against CSRF attacks.

[0066] For example, data transmission is an essential part of the entire Web system. In the Web system, data is transmitted from the server to the user's browser for display, and the user data submitted by the user on the browser side is also fed back to the server for response. At this stage, attackers often use attack methods such as network sniffing attacks and HTTP hijacking to attack to obtain the data they want, or inject their own attack data code. Encrypting the data to be transmitted during the data transmission process will reduce the harm to the system even if the data or the transmission channel is hijacked by the attacker if the encryption and decryption rules are not known.

[0067] For example, the HTTPS encryption protocol can be used. This protocol incorporates SSL (Secure Socket Layer). Its trusted digital certificate mainly has server identity authentication and data encryption functions. The key is exchanged in SSL through the key exchange algorithm, and the key is used to encrypt the data. After the data is transmitted, the integrity of the data is verified by using the hash algorithm, and the identity is verified according to the digital certificate. In the HTTPS protocol, the data is first passed to SSL. SSL encrypts the data and adds its own SSL header, and then transmits it downward to ensure the privacy and integrity of the data.

[0068] For example, the destructiveness of SQL injection is mainly reflected in the compilation process of SQL statements. The compiler cannot recognize which content is maliciously added by the attacker and which is normal data. Therefore, when making data requests, parameterized SQL should be used, and the concatenation of SQL statements should be prohibited. In this way, when performing operations such as adding, deleting, modifying, and querying data during the data storage process, the security of the database will be higher. If the concatenated SQL statements are no longer parsed, SQL injection attacks can be fundamentally prevented. Therefore, the method of using pre-compiled statements is adopted to implement this function. By using the built-in pre-compiled statement set, when it is necessary to interact with the database, only the corresponding set method needs to be called to pass the data parameters. Since only the input data is treated as a parameter when the statement is executed, dynamic concatenation of SQL statements can be avoided when operating the database, improving security. At the same time, the code has high readability and high maintainability. And because the pre-compiled SQL statements can save the compilation process and improve performance.

[0069] For example, other protections can also be carried out, such as CSRF defense, server status verification, connecting to the database with the lowest possible privilege, prohibiting weak passwords, and deploying the server side distributively.

[0070] CSFR defense can include using the POST request method as much as possible for data requests. The POST method can limit some attacks using the page tags that are indispensable for HTML. It can also include verifying the Referer field in the HTTP request.

[0071] In the HTTP protocol, a Referer field is designed in the HTTP header. The function of this field is to record the source address of the HTTP request. Generally speaking, when a user accesses a web application, they need to log in to use the application's functions normally. After logging in, it will be recorded which user this is from which IP address. Therefore, the Referer field sent for all operations of this user in the web system should be consistent with that at the time of login. If it is inconsistent, it can be considered that this request comes from a host request with a different IP address, and it is very likely a CSRF attack by a hacker. Based on this, the request can be rejected.

[0072] For example, for the attack states of "DDOS" and "Replay Attacks" that seriously damage availability, since their attack characteristics are large-scale or repeated normal requests, it is difficult to defend against such attacks, and only appropriate mitigation can be carried out to raise the bottom line of damaged availability. The server-side status verification method can be adopted to reduce its subsequent impact on the server.

[0073] For example, on the server side, a small piece of memory can be allocated to record the status of each user and monitor their user behavior. Corresponding rules based on business logic are established to monitor the behavior of each user. If it is found that a user's behavior reaches the threshold, it is determined as a malicious attack, and then restrictive measures are taken to restrict the user's behavior, or an IP blacklist is established to add the user to the blacklist to reduce the impact on the server.

[0074] Exemplarily, database permissions can be restricted to connect to the database with the lowest possible permissions. Once the system is successfully attacked by SqlInjection or other malicious operations that connect to the database, it will cause database data leakage or directly cause direct and very serious damage to the data stored in the database. Using relatively low permissions when connecting to the database and encrypting the storage of core data can reduce the losses suffered by the system after being attacked.

[0075] Exemplarily, weak passwords are prohibited. If the password set by the user is too simple, it may allow attackers to crack the user's username and password through the method of "dictionary running". Therefore, on the browser side, weak password detection should be carried out to let the user set a more complex password to increase the cracking difficulty for attackers.

[0076] Exemplarily, the server side is deployed distributively. When building the project, a distributed cluster is adopted to distribute the same business processing to different servers to improve the anti-pressure ability and increase the attack difficulty. When the traffic of a certain service is too large, dynamic server allocation is carried out to increase the server's carrying capacity and avoid the situation where normal traffic is rejected, so as to ensure the normal access of normal traffic and improve the upper limit of the server's ability to resist availability damage.

[0077] Therefore, in some embodiments, weak password detection is performed on the user data received by the browser layer. After the weak password detection passes, format verification and filtering of preset characters are performed on the individual data in the user data; after the individual data verification passes, overall verification of the user data is performed; after the overall verification passes, a corresponding first verification code is generated, and the user data and the first verification code after the overall verification pass are sent to the transport layer. Thus, it is possible to prevent attackers from brute-forcing by prohibiting users from setting weak passwords, and prevent XSS attacks by filtering and parsing the input data on the browser side. In addition, before data transmission, overall data verification operations are performed to generate a verification code, which is attached to the overall data for the convenience of verification by the server layer.

[0078] In some embodiments, format verification and filtering of preset characters are performed on individual items of user data received by the server layer; after the individual item data verification passes, overall verification of the user data is performed; after the overall verification passes, a corresponding second verification code is generated, and the second verification code is compared with the first verification code; after the comparison is consistent, token verification of the user data is performed; after the token verification passes, format screening of the user data is performed through a precompiled structured query statement, and the screened user data is sent to the database layer. The individual item data verification and overall data verification technologies are used to filter sensitive and characters exceeding the design specifications, and only respond to requests with correct overall data verification codes; dynamic assembly of Sql can be prohibited through precompiled structured query statements to prevent Sql Injection attacks by attackers, prevent a certain degree of large payload attacks and HTTP hijacking attacks; CSRF attacks can be effectively defended through token verification.

[0079] The security protection method for a Web application provided by an embodiment of the present application takes corresponding security protection measures for the browser, transport layer, server layer, and database layer when the attack possibility index of the Web application is greater than a first preset value or the attack implementation degree index is greater than a second preset value, so as to establish multiple protections, thereby weakening or resisting various attacks, improving the three major CIA attributes of the overall Web application, and increasing the application security performance.

[0080] Figure 2 Shows the security protection method for a Web application provided by an embodiment of the present application, as Figure 2 shown, step S101, obtaining the attack path of the Web application, and calculating the attack possibility index and attack implementation degree index of the Web application according to the attack path, may include:

[0081] S201, obtaining the attack behavior of the Web application, where the attack behavior is used to control the Web application to perform state transitions.

[0082] Among them, the states of the Web application include an initial state, an attack process state, an attack target state, and an attack success state. The state transition can be from the initial state to the attack process state, from the attack process state to the attack target state, and from the attack target state to the attack success state.

[0083] The initial state usually represents the conditions or environment before the attacker starts the attack. The initial state can be: the attacker may have obtained access to the target network; the attacker may have a legitimate user account, although with limited permissions, which can be used as a starting point for further attacks; there are known security vulnerabilities in the system, and the attacker can use these vulnerabilities as the initial attack vector; the attacker can use information obtained from public resources (such as company websites, social media) to plan the attack.

[0084] Considering the confidentiality, integrity, and availability of Web applications and combining the degree of damage to the system, the attack states are divided into three categories: "confidentiality breach", "data integrity breach", and "availability breach". Therefore, the attack target states can include the data integrity breach state, the confidentiality breach state, and the availability breach state.

[0085] The attack process states can include the XSS attack state, the CSRF attack state, the Replay Attacks state, the SqlInjection vulnerability state, the DDOS attack state, the extra-large payload attack state, the network sniffing state, and the HTTP hijacking state. And considering the complexity of hosts in the network, an additional "attack springboard" state is added. The "attack springboard" state refers to the attack state where, starting from the current host or application system, the application vulnerabilities of this host are used to launch attacks on other hosts or application systems, thereby damaging the applications of other hosts (such as the zombie computers in DDOS). For the sake of easy understanding and in line with the analysis, the attack success state is added. For unknown vulnerabilities, due to their unpredictability, they may pose a great threat to the system, equivalent to the destructive power of Trojans, so they are pointed to the state of injecting Trojans.

[0086] In some examples, the states of a Web application include the initial state, multiple attack process states, multiple attack target states, and the attack success state. Obtain the attack behaviors for the Web application to transfer from the initial state to at least one attack process state, from each attack process state to at least one attack target state, from one attack process state to another attack process state, from each attack target state to the attack success state, and from one attack process state to the attack success state.

[0087] For example, attack behavior 1 controls the Web application to transfer from the initial state to the XSS attack state, attack behavior 2 controls the Web application to transfer from the initial state to the CSRF attack state, attack behavior 3 controls the Web application to transfer from the initial state to the Replay Attacks state, attack behavior 4 controls the Web application to transfer from the initial state to the Sql Injection vulnerability state, attack behavior 5 controls the Web application to transfer from the initial state to the DDOS attack state, attack behavior 6 controls the Web application to transfer from the initial state to the extra-large payload attack state, attack behavior 7 controls the Web application to transfer from the initial state to the network sniffing state, attack behavior 8 controls the Web application to transfer from the initial state to the HTTP hijacking state, and attack behavior 9 controls the Web application to transfer from the initial state to the unknown vulnerability state.

[0088] Attack behavior 10 controls the Web application to transfer from the XSS attack state to the data integrity breach state. Attack behavior 11 controls the Web application to transfer from the XSS attack state to the confidentiality breach state. Attack behavior 12 controls the Web application to transfer from the XSS attack state to the Trojan injection state. Attack behavior 13 controls the Web application to transfer from the XSS attack state to the CSRF attack state. Attack behavior 14 controls the Web application to transfer from the CSRF attack state to the data integrity breach state. Attack behavior 15 controls the Web application to transfer from the CSRF attack state to the confidentiality breach state. Attack behavior 16 controls the Web application to transfer from the Replay Attacks state to the availability breach state.

[0089] Attack behavior 17 controls the Web application to transfer from the Sql Injection vulnerability state to the data integrity breach state. Attack behavior 18 controls the Web application to transfer from the Sql Injection vulnerability state to the confidentiality breach state. Attack behavior 19 controls the Web application to transfer from the Sql Injection vulnerability state to the attack springboard state. Attack behavior 20 controls the Web application to transfer from the SqlInjection vulnerability state to the Trojan injection state. Attack behavior 21 controls the Web application to transfer from the DDOS attack state to the availability breach state. Attack behavior 22 controls the Web application to transfer from the extra-large payload attack state to the availability breach state.

[0090] Attack behavior 23 controls the Web application to transfer from the network sniffing state to the Sql Injection vulnerability state; Attack behavior 24 controls the Web application to transfer from the network sniffing state to the confidentiality breach state. Attack behavior 25 controls the Web application to transfer from the HTTP hijacking state to the Sql Injection vulnerability state; Attack behavior 26 controls the Web application to transfer from the HTTP hijacking state to the confidentiality breach state; Attack behavior 27 controls the Web application to transfer from the HTTP hijacking state to the attack springboard state. Attack behavior 28 controls the Web application to transfer from the unknown vulnerability state to the attack springboard state.

[0091] Attack behavior 29 controls the Web application to transfer from the Trojan injection state to the data integrity breach state; Attack behavior 30 controls the Web application to transfer from the Trojan injection state to the confidentiality breach state; Attack behavior 31 controls the Web application to transfer from the Trojan injection state to the availability breach state; Attack behavior 32 controls the Web application to transfer from the Trojan injection state to the attack springboard state.

[0092] Attack behavior 33 controls the Web application to transfer from the data integrity breach state to the attack success state. Attack behavior 34 controls the Web application to transfer from the confidentiality breach state to the attack success state. Attack behavior 35 controls the Web application to transfer from the availability breach state to the attack success state. Attack behavior 36 controls the Web application to transfer from the attack springboard state to the attack success state.

[0093] S202. Construct an attack graph model according to the state of the Web application and the attack behavior.

[0094] Exemplarily, according to the initial state, the attack process state, the attack target state, and the attack success state, as well as the attack behavior for the initial state to transfer to at least one attack process state, the attack behavior for each attack process state to transfer to at least one attack target state, the attack behavior for one attack process state to transfer to another attack process state, the attack behavior for each attack target state to transfer to the attack success state, and the attack behavior for one attack process state to transfer to the attack success state, a state attack graph model can be constructed. Correspondingly, the attack graph model can show the specific path for one state to transfer to another state, that is, the attack path.

[0095] Exemplarily, as Figure 3 shown, after determining the attack behavior for controlling the state transfer of the Web application, an attack graph model can be constructed according to the attack behavior and the state. In the attack graph model shown in the figure, each state and the attack behavior between each state can be shown, so as to clearly show each attack path. Figure 3 In the figure, the ellipse represents the state, and the directed arrow represents the attack behavior. For clear and intuitive display, the number on the arrow represents the attack behavior number. The mutual combination of the attack state and the corresponding attack behavior forms a complex attack path, starting from the "initial state" and ending with "attack success".

[0096] It should be noted that the attack graph graphically represents the attack process vividly, which can visualize the arrangement and path of the attack process for more clear and definite analysis. It stands from the perspective of the attacker to simulate the attack path that the attacker needs to take to achieve the attack goal.

[0097] The attack graph correlates various seemingly independent vulnerabilities in the Web application. Analyzing the attack graph based on the established attack graph can quantify the weak points in the network environment, which will play a guiding role when developers develop applications, and achieve the goal of preventing attackers from reaching their attack goals with the least cost and more quickly and efficiently.

[0098] The research on attack graphs can be divided into two branches: attribute attack graphs and state attack graphs. Attribute attack graphs are based on attributes, which make all attack paths more compact and comprehensive, but it is not very intuitive to display attack paths and difficult to understand; state attack graphs are based on attack states, which can display attack paths more clearly, but the attack paths displayed in this way will increase exponentially with the scale of the attacker's attack methods and the scale of the number of security risks they have, and the states will increase explosively. Considering that the number of Web security threats involved in this application is limited, the state explosion problem can be avoided and the attack paths can be clearly displayed. By comprehensively analyzing the advantages and disadvantages of the two attack graphs, a state attack graph is used to construct an attack graph model.

[0099] S203. Calculate the attack possibility index and attack realization degree index of the Web application according to the attack graph model.

[0100] In some embodiments, when transitioning from the current state to the next state, the selection probability of each attack behavior between the current state and the next state can be obtained, and the attack possibility index and attack realization degree index of the Web application can be determined according to the selection probability of each attack behavior. By quantifying the attack possibility and attack realization degree through the selection probability of attack behaviors, the accuracy and practicality of the attack possibility index and attack realization degree index are improved. Among them, the current state can be the initial state, any attack process state or any attack target state. Correspondingly, the next state can be any attack process state, any attack target state or the attack success state.

[0101] Specifically, let V(S i ) be the probability of transferring from state S i to the next state through attack behavior D i . It can be known that V(S i ) ∈ [0, 1]. Considering that the attack process is progressive step by step, each state of the attack graph is discrete and discontinuous, and when the attacker reaches a certain attack state, the choice of the next attack path will only be based on the current state and conditions, and the attack breakthrough achieved in the previous step has no impact on the choice of the next attack. Therefore, the Web security state attack graph model conforms to the Markov chain property.

[0102] From the properties of the Markov chain, it can be known that the next state in the attack process is related to the current state and independent of the previous state, that is, the value of V n-1 (S i ) is related to the value of V n (S i ). According to the attacker's selection probability, the iterative formula for calculating the attack possibility index of the attack graph is:

[0103]

[0104] The left side of the equation is V n (S m ) means that at a certain stage of the Markov chain, through n steps from state S m The attack probability of transferring the attack state to the attacker's attack target, where n = 0, 1, 2, 3..., N. In the attack graph, the attack success state can be reached from the initial state of the attack in at most N steps. When the attacker is in the initial state of the attack, if the attacker does not achieve the attack target in the next step, let V 0 (S i )=0,i=1,2,3…,m-1(m is the number of attack states), S i ∈I u (I u is the set of states that do not achieve the attack goal). Due to the characteristics of the attack graph, its final state is the state that can achieve the attacker's attack goal, so let V 0 (S i )=1,i=1,2,3…,m-1,S i ∈I s (I s is the set of attack states that achieve the attack goal, and S i ∪I s =I). The right side of the equation The attacker is in attack state S m When the attack behavior D is selected i Transfer to the next state S i The probability of SUBSQT(S m ) is in attack state S m , including all possible attack behaviors on the path after this state, and the set of all states reached by only one transfer; RULES(S m →S i ) is from state S m Transfer to S i A collection of optional attack behaviors.

[0105] According to the conditional convergence of the Markov chain, after a sufficient number of finite N iterations, the N+1th iteration must converge, and its attack probability index value is equal to the N+1th attack probability index and is a fixed value. Under the convergence condition, the formula is used to get the initial state S 0 After N transfers, the probability V(S 0 ), V 2 (S 0 ) is the attack possibility index of the attack graph.

[0106] Similarly, let W(S i)Indicates the attack implementation degree of transferring from state S i to the next attack state, S i ∈I, then the iterative formula for the attack implementation degree index can be obtained as follows:

[0107]

[0108] W on the left side of the equation n (S i ) refers to the attack implementation degree index of transferring from state S i to the next state, where n = 0, 1, 2, 3…, N. Similar to the attack possibility index, in the attack graph model, N represents that the attacker can transfer from the initial state S 0 to the attack success state in at most N steps. Similarly to the attack possibility index, W 0 (S i ) = 0, i = 1, 2, 3…, m - 1 (m is the number of attack states), S i ∈I u (I u is the set of states that have not achieved the attack goal), let W 0 (S i ) = 1, i = 1, 2, 3…, m - 1 (m is the number of attack states), S i ∈I s (I s is the set of attack states that have achieved the attack goal, and S i ∪I s = I). The right side of the equation SUBSQT(S m ) have the same meaning as the meaning of the attack possibility index formula, which will not be elaborated here. E(D i ) is the attack implementation degree corresponding to the attack behavior D i . Similarly, starting from the initial state S 0 , after a sufficient number of finite iterations N times, it will surely converge. Then W(S 0 ) is the attack implementation degree index.

[0109] In some examples, when obtaining the transfer from the current state to the next state, the weight of each attack behavior between the current state and the next state is obtained, and the weight ratio of each attack behavior is calculated to determine the selection probability of each attack behavior. The higher the weight ratio of the attack behavior, the greater the possibility and influence of the attack behavior can be represented, and the greater the possibility of being selected. The selection probability of each attack behavior is determined through the weight ratio, so that the selection probability of each attack behavior can be accurately determined.

[0110] Specifically, assume that the attacker starts from state S 0 and through the attack behavior D iTransfer to the next state S i , where i = 0, 1, 2, 3…, n. Let I be the set of all states S i , then S i ∈I. The weight value of the attack implementation degree corresponding to the attack behavior D i is ω i . Then the probability formula for the attacker to transfer from the state S 0 to the next state S i through the attack behavior D i is as follows:

[0111]

[0112] Among them, the left side of the equation represents the probability that the attacker will choose to transfer from the state S 0 to S i through the attack behavior D i . The right side ω i represents the weight value of the attack implementation degree corresponding to the attack behavior D i .

[0113] For example, in the state S 0 , the attacker starts to attack. Assuming that it can transfer to S 1 , S 2 through two attack behaviors D 1 , S 2 respectively. If the attack implementation degrees corresponding to D 1 , D 2 are E3 and E6 respectively, then according to the values obtained from Table 1 and combined with the selection probability formula, it can be calculated that:

[0114]

[0115] At the same time, it can also be obtained that indicates its normalization, that is, the sum of the weights of all directed edges starting from a state node is equal to 1.

[0116] In a specific implementation manner, the weight of the attack implementation degree can be determined according to the attack method, attack steps, harm degree of the vulnerability, and attack tool. Then, when transferring from the current state to the next state, the weight of the attack behavior can be determined according to the weight of the attack implementation degree corresponding to each attack behavior between the current state and the next state. By considering multiple factors, the complexity and feasibility of the attack can be evaluated more comprehensively.

[0117] Table 1 Attack Implementation Degree Hierarchical Weight Table

[0118] Marker Stratification level of attack implementation degree Weight value E6 There are open-source attack tools on the Internet with detailed attack steps 0.9 E5 The attack tool is not open-source but can be customized with detailed attack steps 0.8 E4 There is no available attack tool with relatively detailed attack steps 0.6 E3 The attack has been exposed, but the attack method is not detailed 0.5 E2 The attack has been exposed, only mentioning the possible attack methods 0.2 E1 The attack has been exposed, but the attack method is not involved 0.1 E0 The attack has been exposed, but the attack is only theoretically possible to be implemented 0.05

[0119] For example, as shown in Table 1, there is a positive correlation between the weight value of the attack implementation degree and the attacker's attack method, attack steps, and attack tools.

[0120] To understand the solution of this embodiment more clearly, the following takes Figure 3 the attack implementation degrees of each attack behavior in

[0121] Table 2 Attack Implementation Degree Value Table of the State Attack Graph of Web Applications

[0122]

[0123] In Table 2, the attack number corresponds to the attack behavior that the attacker in the attack graph model wants to use to transfer from one state to another. According to the existing facts, for the attack tools and attack steps of various attack means, their corresponding implementation degree hierarchical levels in Table 1 are determined, and the corresponding weight values are obtained according to the corresponding levels. The attack implementation degree is taken according to the weight value. On the attack path of the attack graph, when the attack state transfers to "data integrity destruction", "confidentiality destruction", "availability destruction", and "attack springboard", these four states have reached the destruction of the CIA (confidentiality, integrity, and availability) of the application system, and the malicious purpose of the attacker has been achieved. Therefore, it is regarded that the attacker has transferred to the attack success state. According to the conclusion of the previous section, the attack implementation degree levels of attack behaviors 33, 34, 35, and 36 are represented by "~", and their weight values and attack implementation degrees are all taken as 1.0.

[0124] It can be seen from the attack graph model that among all the attack paths, starting from the initial state S 0 it can transfer to the attack success state after at most 4 transfers. Therefore, in the formula, the maximum number of iterations N is taken as 4, and its attack possibility exponential formula is V 4 (S 0 ), and the attack implementation degree exponential formula is W n (S 0 ). Substituting the data in Table 3.4 into Formula (1), Formula (2), and Formula (3), after iterative calculation, it is obtained that:

[0125] The attack possibility index result converges at the 4th iteration, V 4 (S 0 ) = 0.237067.

[0126] The attack implementation degree index result converges at the 4th iteration, W 4 (S 0 ) = 0.092686.

[0127] The security protection method provided in this embodiment constructs an attack graph model through the status of the Web application and attack behaviors, visualizes the attack paths of attackers, and optimizes its state explosion problem, making the evaluation model fit the security risks of the Web application, perfectly used for Web application security assessment. Based on the mathematical principle of the discrete stochastic process of the Markov chain, the attack possibility index and the attack realization degree index are proposed to quantitatively evaluate the security of the proposed Web application to detect its security, facilitating subsequent security protection.

[0128] In the embodiment of this application, in order to further verify the effect after taking corresponding security protection measures for the browser layer, transport layer, server layer, and database layer, a new state attack graph model is generated, as Figure 4 shown, comparing Figure 3 and Figure 4 it can be known that:

[0129] (1) When the current state is the initial state, theoretically, the Sql Injection attack and XSS attack, which belong to the injection attack, can be completely prevented. Therefore, the attack paths through this attack state are completely blocked, and in Figure 4 the attack paths through this attack state will be cancelled.

[0130] For the CSRF attack and HTTP hijacking, the difficulty of successful attack increases. Starting from the initial state, it is almost impossible to transfer to these states according to the original tools and methods, and there is only a theoretical possibility of successful transfer. Therefore, their corresponding attack realization degree levels should correspond to the E0 level. Figure 4 In

[0131] the attack realization degrees of attack behaviors 1, 5, and 6 are taken according to the weight value, that is, 0.05. Figure 4 For the replay attack, extra-large payload attack, and DDOS attack, since they are legitimate requests and cannot be weakened, therefore

[0132] (2) Once reaching the states of "CSRF attack" and "network sniffing", the attack capabilities of the next states in their paths for "data integrity" and "confidentiality" remain unchanged. Therefore, the attack realization degree levels and attack realization degrees of attack behaviors 8, 9, and 13 in Figure 4 remain unchanged.

[0133] For the "HTTP hijacking" state, on the premise of reaching this state, its ability to damage the confidentiality of the application remains unchanged, but the possibility of using it as a springboard to attack other hosts only holds theoretically. Therefore, the attack behavior 14 during this state remains unchanged, the attack implementation degree level of attack behavior 15 is reduced to E0, and the attack implementation degree value is 0.05.

[0134] When the current state is "Replay Attacks", "Extra-large Payload Attack", or "DDOS", due to the corresponding protection measures taken, under the original attack tools and attack steps, the degree of security threat to the application is weakened to a certain extent. Under the same conditions, it becomes more difficult for the attacker's attack to transfer from these three states to the "Availability Breach" state. Therefore, the attack implementation degree level remains unchanged, but the corresponding attack implementation degree should be reduced.

[0135] Since the threats of Replay Attacks and Extra-large Payload Attacks to the application are mainly related to the performance of the actual server host, the better the performance, the smaller the impact. The improvement of host performance is mainly related to the current level of technological development, but the improvement is limited. Therefore, the attack implementation degrees of attack behaviors 10 and 12 are approximately valued at the E4 level, that is, taken as 0.6. The threat of DDOS attack to the application is related not only to the performance of the actual server host but also to the number of hosts deployed distributively. With a reasonable distributed deployment, its attack implementation degree will be reduced. Therefore, the attack implementation degree of attack behavior 11 is approximately taken at the E3 level, that is, taken as 0.5.

[0136] (3) When the current state is "Trojan Injection" and it transfers to "Data Integrity Breach", "Confidentiality Breach", "Availability Breach", and "Attack Springboard", the attack implementation degree levels and attack implementation degrees remain unchanged.

[0137] (4) When transferring from the states of "Data Integrity Breach", "Confidentiality Breach", "Availability Breach", and "Attack Springboard" to "Attack Success", the attack implementation degree levels and attack implementation degrees remain unchanged.

[0138] In summary, the attack implementation degree levels and attack implementation degree values of the corresponding state attack graph of the secure Web are changed accordingly according to the above. According to the different states after the change, different attack implementation degree levels are corresponding, and different attack implementation degrees are obtained according to the implementation degree levels. Due to the particularity of attack behaviors 21, 22, 23, and 24, the attack implementation degree levels of these three are represented by "~", and the implementation degree is taken as 1.0. The results are shown in Table 3 below:

[0139] Table 3 Attack Implementation Degree Value Table of the State Attack Graph of Web Applications

[0140]

[0141] According to Figure 4 , substitute the relevant values in Table 3 above into Formula (1), Formula (2), and Formula (3), and through iterative calculation, it is obtained that:

[0142] The result of the attack possibility index converges at the 4th iteration, and V 4 (S 0 ) = 0.018519.

[0143] The result of the attack realization degree index converges at the 4th iteration, and W 4 (S 0 ) = 0.000750.

[0144] Compared with the final result of the relevant index of the attack Figure 3 , its attack possibility index is reduced by about 92.19%, and its attack realization degree index is reduced by about 99.19%. From this, it can be analyzed that under the vulnerability information already collected by the attacker and combined with its existing attack tools and means, the possibility of attacking the application is reduced by 92.19%; if the attacker still chooses to attack in this situation, the success degree of finally achieving its attack purpose is reduced by 99.19%. The attacker's attack desire is reduced, and even if the attack is implemented, the success rate is reduced. Therefore, after the present application takes corresponding security protection measures for the browser layer, transport layer, server layer, and database layer, the security performance of the Web application can be improved.

[0145] Figure 5 is a schematic structural diagram of the security protection device for the Web application provided by the present application. As Figure 5 shown, the security protection device 40 for the Web application provided in this embodiment includes:

[0146] The first processing module 11 is configured to obtain the attack path of the Web application and calculate the attack possibility index and attack realization degree index of the Web application according to the attack path;

[0147] The second processing module 12 is configured to take corresponding security protection measures for the browser layer, transport layer, server layer, and database layer when the attack possibility index is greater than a first preset value or the attack realization degree index is greater than a second preset value;

[0148] The security protection measures corresponding to the browser layer include at least one of single-item data verification, overall data verification, and weak password detection;

[0149] The security protection measures corresponding to the transport layer include encrypting the transmitted data;

[0150] The security protection measures corresponding to the server layer include at least one of single data verification, overall data verification, token verification, server status verification, pre-compiled structured query statements, and distributed deployment;

[0151] The security protection measures corresponding to the database layer include at least one of restricting database permissions and encrypting private data.

[0152] In a possible implementation manner, the second processing module 12 is specifically configured to perform weak password detection on the user data received by the browser layer; after the weak password detection passes, perform format verification and filtering of preset characters on the single data in the user data; after the single data verification passes, perform overall verification on the user data; after the overall verification passes, generate a corresponding first verification code, and send the user data and the first verification code after the overall verification passes to the transport layer.

[0153] In a possible implementation manner, the second processing module 12 is specifically configured to perform format verification and filtering of preset characters on the single data in the user data received by the server layer; after the single data verification passes, perform overall verification on the user data; after the overall verification passes, generate a corresponding second verification code, and compare the second verification code with the first verification code; after the comparison is consistent, perform token verification on the user data; after the token verification passes, perform format screening on the user data through pre-compiled structured query statements, and send the screened user data to the database layer.

[0154] In a possible implementation manner, the first processing module 11 is specifically configured to obtain the attack behavior of the Web application, where the attack behavior is used to control the state transition of the Web application, and the states of the Web application include an initial state, an attack process state, an attack target state, and an attack success state; construct an attack graph model according to the state of the Web application and the attack behavior; calculate the attack possibility index and the attack realization degree index of the Web application according to the attack graph model.

[0155] In a possible implementation manner, the attack target state includes at least one of a data integrity destruction state, a confidentiality destruction state, and an availability destruction state; the attack process state includes at least one of a cross-site scripting attack state, a cross-site request forgery attack state, a structured query statement injection vulnerability state, a replay attack state, a distributed denial of service attack state, a very large payload attack state, a network sniffing state, a hypertext transfer protocol hijacking state, an unknown vulnerability attack state, a trojan injection state, and an attack jump state.

[0156] In a possible implementation, the first processing module 11 is specifically configured to obtain the selection probability of each attack behavior between the current state and the next state when transferring from the current state to the next state; and determine the attack possibility index and the attack implementation degree index of the Web application according to the selection probability of each attack behavior.

[0157] In a possible implementation, the first processing module 11 is specifically configured to obtain the weight of each attack behavior between the current state and the next state when transferring from the current state to the next state; calculate the proportion of the weight of each attack behavior, and determine the selection probability of each attack behavior.

[0158] In a possible implementation, the first processing module 11 is specifically configured to determine the weight of the attack implementation degree according to the attack method, attack steps, harm degree of the vulnerability, and attack tool; when transferring from the current state to the next state, determine the weight of each attack behavior according to the weight of the attack implementation degree corresponding to each attack behavior between the current state and the next state.

[0159] The Web application security protection device provided in this embodiment can execute the method provided in the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.

[0160] Figure 6 It is a schematic structural diagram of the electronic device provided in this application. As Figure 6 shown, the electronic device 50 provided in this embodiment includes: at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. Among them, the processor 501, the memory 502, and the communication component 503 are connected through a bus 504.

[0161] In a specific implementation process, at least one processor 501 executes the computer execution instructions stored in the memory 502, so that at least one processor 501 executes the above method.

[0162] The specific implementation process of the processor 501 can refer to the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.

[0163] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU for short), or may also be other general-purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly implemented by the execution of the hardware processor, or can be implemented by the combination of the hardware and software modules in the processor.

[0164] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.

[0165] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience in representation, the bus in the drawings of this application is not limited to only one bus or one type of bus.

[0166] This application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0167] This application also provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the processor executes the computer-executable instructions, the above method is implemented.

[0168] The above-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk or an optical disk. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.

[0169] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be part of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuits (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in a device.

[0170] The division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Additionally, the couplings or direct couplings or communication connections shown or discussed between each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.

[0171] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0172] Furthermore, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0173] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.

[0174] Other embodiments of the present application will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.

[0175] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.

Claims

1. A security protection method for Web applications, characterized in that: The method comprises: Obtaining an attack path of a Web application, and calculating an attack possibility index and an attack realization index of the Web application according to the attack path; When the attack possibility index is greater than a first preset value, or the attack realization index is greater than a second preset value, corresponding security protection measures are taken for the browser layer, the transport layer, the server layer, and the database layer; The security protection measures corresponding to the browser layer include: at least one of single data verification, overall data verification and weak password detection; The security protection measures corresponding to the transport layer include: encrypting the transmitted data; The security protection measures corresponding to the server layer include: at least one of single data verification, overall data verification, token verification, server status verification, pre-compiled structured query statements and distributed deployment; The security protection measures corresponding to the database layer include: at least one of limiting database permissions and encrypting private data.

2. The method according to claim 1, characterized in that Take corresponding security protection measures for the browser layer, including: Perform weak password detection on user data received at the browser layer; After the weak password detection is passed, the single item of data in the user data is format checked and the preset characters are filtered; After the single data verification is passed, the user data is verified as a whole; After the overall verification is passed, a corresponding first verification code is generated, and the user data after the overall verification and the first verification code are sent to the transmission layer.

3. The method according to claim 2, characterized in that The corresponding security protection measures taken on the server layer include: Perform format check and preset character filtering on individual data items in the user data received by the server layer; After the single data verification is passed, the user data is verified as a whole; After the overall verification is passed, a corresponding second verification code is generated, and the second verification code is compared with the first verification code; After the comparison is consistent, the token verification is performed on the user data; After the token verification is passed, the user data is formatted through a precompiled structured query statement, and the filtered user data is sent to the database layer.

4. The method according to any one of claims 1 to 3, characterized in that The acquiring the attack path of the Web application and calculating the attack possibility index and the attack realization index of the Web application according to the attack path include: Acquire the attack behavior of the Web application, where the attack behavior is used to control the Web application to perform state transition, where the state of the Web application includes an initial state, an attack process state, an attack target state, and an attack success state; Constructing an attack graph model according to the state of the Web application and the attack behavior; The attack possibility index and attack realization index of Web applications are calculated based on the attack graph model.

5. The method according to claim 4, characterized in that The attack target state includes at least one of a data integrity destruction state, a confidentiality destruction state, and an availability destruction state; The attack process status includes at least one of a cross-site scripting attack status, a cross-site request forgery attack status, a structured query statement injection vulnerability status, a replay attack status, a distributed denial of service attack status, an oversized payload attack status, a network sniffing status, a hypertext transfer protocol hijacking status, an unknown vulnerability attack status, a Trojan horse injection status, and an attack springboard status.

6. The method according to claim 4, characterized in that The method of calculating the attack possibility index and the attack realization index of the Web application according to the attack graph model includes: Obtaining a selection probability of each attack behavior between the current state and the next state when transferring from the current state to the next state; The attack possibility index and the attack realization degree index of the Web application are determined according to the selection probability of each attack behavior.

7. The method according to claim 6, characterized in that The obtaining of the selection probability of each attack behavior between the current state and the next state when transferring from the current state to the next state includes: Obtaining the weight of each attack behavior between the current state and the next state when transferring from the current state to the next state; Calculate the weight of each attack behavior and determine the selection probability of each attack behavior.

8. The method according to claim 7, characterized in that The obtaining of the weight of each attack behavior between the current state and the next state when transferring from the current state to the next state includes: Determine the weight of the attack realization degree according to the attack method, attack steps, the severity of the vulnerability and the attack tool; When transferring from a current state to a next state, the weight of each attack behavior is determined according to the weight of the attack realization degree corresponding to each attack behavior between the current state and the next state.

9. A security protection device for a Web application, comprising: A first processing module, configured to obtain an attack path of a Web application, and calculate an attack possibility index and an attack realization index of the Web application according to the attack path; A second processing module is used to take corresponding security protection measures for the browser layer, the transport layer, the server layer and the database layer when the attack possibility index is greater than the first preset value or the attack realization index is greater than the second preset value; The security protection measures corresponding to the browser layer include: at least one of single data verification, overall data verification and weak password detection; The security protection measures corresponding to the transport layer include: encrypting the transmitted data; The security protection measures corresponding to the server layer include: at least one of single data verification, overall data verification, token verification, server status verification, pre-compiled structured query statements and distributed deployment; The security protection measures corresponding to the database layer include: at least one of limiting database permissions and encrypting private data.

10. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 9 when executed by a processor.

12. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 8 when being executed by a processor.