Method, device and equipment for identifying phishing mail attack, medium and product
By combining abnormal login analysis of office system data and phishing behavior identification of email system data in phishing email attack defense, high-risk accounts and phishing email accounts are identified, and the problems of false alarms and underreporting in the existing technology are solved, and the defense accuracy and overall defense capabilities are improved.
Patent Information
- Application Number
- CN202510230315.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art is prone to false alarms and missed reports when defending against phishing email attacks, and it is difficult to effectively identify phishing emails sent by internal accounts and phishing emails generated by secondary attacks caused by other internal office system defects.
By obtaining office system data, filtering target event data based on preset weak password characteristics, and performing data structured processing and abnormal login behavior analysis, obtaining a list of high-risk accounts. At the same time, the mail system data is obtained, phishing behavior analysis is performed based on preset phishing behavior rules, candidate phishing mail accounts are identified, and the target phishing mail accounts are determined when they exist in the high-risk account list.
It improves the recognition accuracy of phishing email attacks, improves the overall defense ability of phishing email attacks, and reduces false alarms and missed reports.
Smart Images

Figure CN120074931A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a method, device, equipment, medium and product for identifying phishing email attacks. Background Art
[0002] In phishing email attack activities, attackers will use various means to induce users to disclose sensitive information such as ID card numbers, bank account information, and passwords, thus bringing serious risks of personal information leakage to users. Attackers often cleverly take advantage of the negligence of victims, inducing them to make mistakes inadvertently to achieve their attack purposes.
[0003] Currently, the mainstream defense technologies against phishing email attacks mainly intercept and give early warnings to the senders of emails, the Internet Protocol addresses of senders, and the contents of emails by means of blacklists, feature libraries, etc. However, this interception strategy has certain limitations and is prone to false alarms, resulting in the failure of normal work emails to be delivered smoothly. To solve this problem, conventional technologies usually introduce a whitelist mechanism to allow internal senders and Internet Protocol addresses to pass. But in this way, it is difficult to trigger the alarm rules for phishing emails sent from internal accounts, which is likely to lead to missed alarms. Moreover, due to the lack of in-depth analysis of the data access relationships between internal office systems, phishing emails generated by secondary attacks caused by defects in other internal office systems are also likely to be missed. Summary of the Invention
[0004] The present invention provides a method, device, equipment, medium and product for identifying phishing email attacks, which can improve the identification accuracy of phishing email attacks and enhance the overall defense ability against phishing email attacks.
[0005] According to one aspect of the present invention, there is provided a method for identifying phishing email attacks, including:
[0006] Obtain office system data, and screen at least one target event data from the office system data based on a preset weak password feature;
[0007] Perform data structuring processing on each of the target event data, obtain the field values of each key feature field corresponding to each of the target event data, and perform abnormal login behavior analysis based on a preset abnormal behavior rule according to the field values of each key feature field corresponding to each of the target event data to obtain a list of high-risk accounts;
[0008] Obtain mail system data, and based on preset phishing behavior rules, perform phishing behavior analysis according to the mail system data to obtain candidate phishing mail accounts, and when it is detected that the candidate phishing mail accounts exist in the high-risk account list, determine the candidate phishing mail accounts as target phishing mail accounts.
[0009] According to another aspect of the present invention, there is provided an identification device for phishing mail attacks, including:
[0010] A data screening module, configured to obtain office system data, and based on preset weak password features, screen at least one target event data from the office system data;
[0011] An anomaly analysis module, configured to perform data structuring processing on each of the target event data, obtain the field values of each key feature field corresponding to each of the target event data, and based on preset anomaly behavior rules, perform anomaly login behavior analysis according to the field values of each key feature field corresponding to each of the target event data to obtain a high-risk account list;
[0012] A phishing behavior analysis module, configured to obtain mail system data, and based on preset phishing behavior rules, perform phishing behavior analysis according to the mail system data to obtain candidate phishing mail accounts, and when it is detected that the candidate phishing mail accounts exist in the high-risk account list, determine the candidate phishing mail accounts as target phishing mail accounts.
[0013] According to another aspect of the present invention, there is provided an electronic device, the electronic device includes:
[0014] At least one processor; and
[0015] A memory communicatively connected to the at least one processor; wherein,
[0016] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the identification method of phishing mail attacks according to any embodiment of the present invention.
[0017] According to another aspect of the present invention, there is provided a computer-readable storage medium, the computer-readable storage medium stores a computer program, and the computer program is used to enable a processor to execute the identification method of phishing mail attacks according to any embodiment of the present invention when executed.
[0018] According to another aspect of the present invention, there is provided a computer program product, including a computer program, and the computer program realizes the identification method of phishing mail attacks according to any embodiment of the present invention when executed by a processor.
[0019] In the technical solution of the embodiment of the present invention, by obtaining office system data and screening at least one target event data from the office system data based on a preset weak password feature; performing data structuring processing on each target event data, obtaining the field values of each key feature field corresponding to each target event data, and performing abnormal login behavior analysis based on a preset abnormal behavior rule according to the field values of each key feature field corresponding to each target event data to obtain a list of high-risk accounts; obtaining mail system data and performing phishing behavior analysis according to the mail system data based on a preset phishing behavior rule to obtain candidate phishing mail accounts, and when it is detected that a candidate phishing mail account exists in the list of high-risk accounts, determining the candidate phishing mail account as a target phishing mail account; by combining the identification of abnormal login accounts based on office system data and the identification of phishing mail accounts based on mail system data, the behavior analysis of the phishing mail attacker in the upstream office system is extended, the identification accuracy of phishing mail attacks can be improved, and the overall defense ability against phishing mail attacks can be enhanced.
[0020] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0022] Figure 1 is a flowchart of a method for identifying phishing mail attacks provided in Embodiment 1 of the present invention;
[0023] Figure 2 is a schematic diagram of an internal phishing attack process provided in Embodiment 1 of the present invention;
[0024] Figure 3 is a schematic diagram of the principle of an identification mechanism for phishing mail attacks provided in Embodiment 1 of the present invention;
[0025] Figure 4 is a schematic diagram of event data provided in Embodiment 1 of the present invention;
[0026] Figure 5 is a schematic diagram of event data provided in Embodiment 1 of the present invention;
[0027] Figure 6It is a schematic diagram of the structured processing result provided by Embodiment 1 of the present invention;
[0028] Figure 7 It is a schematic structural diagram of an identification device for phishing email attacks provided by Embodiment 2 of the present invention;
[0029] Figure 8 It is a schematic structural diagram of an electronic device for implementing the method for identifying phishing email attacks according to the embodiments of the present invention. Detailed implementation manners
[0030] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0031] It should be noted that the terms "first", "second", "target", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0032] Embodiment 1
[0033] Figure 1 This is a flowchart of a method for identifying phishing email attacks provided by Embodiment 1 of the present invention. This embodiment is applicable to the situation of identifying and warning phishing email attacks initiated via internal accounts. This method can be executed by an identification device for phishing email attacks, and the identification device for phishing email attacks can be implemented in the form of hardware and / or software. Typically, the identification device for phishing email attacks can be configured in an electronic device, such as a computer device or a server, etc. As Figure 1 shown, the method includes:
[0034] S110. Obtain office system data, and based on preset weak password features, screen at least one target event data from the office system data.
[0035] It should be noted that the internal phishing attack process can be as follows Figure 2 shown. Among them, the attacker usually launches two-layer attacks. In the first-layer attack, the purpose is to steal the account information of the internal communication system or tool; in the second-layer attack, the attacker uses the account of the internal communication system or tool obtained in the first-layer attack to launch a phishing attack on the target victim. Based on this, this embodiment constructs a complete recognition mechanism for phishing email attacks. The principle of this mechanism is as follows Figure 3 shown. First, through a preset early warning mechanism, according to the log data of the Virtual Private Network (VPN), Office Automation (OA) system or email system, as well as preset high-frequency login, abnormal login or other weak password feature rules, potential high-risk users or accounts are accurately identified; then, using the set alarm rules, according to the log data of the email system and the preset phishing email recognition rules, possible phishing email attack behaviors are keenly identified.
[0036] Specifically, first, network traffic data can be collected through the port mirroring function of the switch, enabling a traffic statistics protocol on the router or switch, a packet capture tool or a distributed probe, and filtering the data flowing through public office systems such as VPN and OA from the network traffic data to obtain office system data. Typically, the office system data can be the log data of public office systems. Then, event data that conforms to the preset weak password features can be screened from the office system data to be used as target event data.
[0037] Among them, the preset weak password features can include simple character combinations (such as pure numbers / characters, repeated or consecutive characters, etc.), common passwords or dictionary words (such as high-frequency weak passwords, system default passwords, etc.), personal information related (such as personal sensitive information, account-related information, etc.), belonging to keyboard mode combinations, having structural defects (such as insufficient length, insufficient complexity, etc.). Event data can be records of specific activities or states generated during the operation of a system, application program or network. For example, event data can be log data associated with operations such as login, resource access, and email sending.
[0038] Optionally, based on the preset weak password features, screening at least one target event data from the office system data may include:
[0039] Obtaining at least one event data according to the office system data;
[0040] If it is detected that the current event data contains a password field and / or the field value corresponding to the password field belongs to the weak password dictionary, then the current event data is determined as the target event data.
[0041] In an alternative embodiment, the preset weak password feature may be that the data contains a password field, and the field value corresponding to the password field belongs to a weak password dictionary. The password field may be characters such as Password, passwd, pwd, etc., and the weak password dictionary may be 888888, 123456, null value, etc.
[0042] Specifically, the office system data can be split according to events to obtain multiple event data; then, it can be determined whether each event data contains a password field. If so, it is further determined whether the field value corresponding to the password field belongs to the weak password dictionary. If so, the current event data can be determined as the target event data. For example, as shown in the event data Figure 4 below, the request body contains a Password field, and the field value 888888 corresponding to this field belongs to the category of the weak password dictionary, then this event data can be used as the target event data; or, as shown in the event data Figure 5 below, the request body contains a pwd field, then this event data can also be used as the target event data.
[0043] S120. Perform data structuring processing on each of the target event data, obtain the field values of each key feature field corresponding to each of the target event data, and based on the preset abnormal behavior rules, perform abnormal login behavior analysis according to the field values of each key feature field corresponding to each of the target event data, and obtain a list of high-risk accounts.
[0044] Among them, the key feature fields may include at least one of access protocol, source address, target address, source Media Access Control (MAC) address, target Media Access Control address, account name, password, source port, target port, and source geographical location. The source geographical location may be the geographical location associated with the source address. It can be understood that each key feature field may exist in the form of a unique corresponding English character in the event data. For example, the access protocol field corresponds to proto, and the source address field corresponds to sip, etc.
[0045] In this embodiment, structuring processing technologies such as regular expressions, key-value pairs, and Extensible Markup Language can be used to perform structuring processing on key feature fields such as the source address, target address, and account name in the target event data to obtain the field values corresponding to each key feature field. The structuring processing result can be as shown in Figure 6 below. Then, based on the preset abnormal behavior rules, the target event data can be analyzed from the dimension of abnormal login to obtain the accounts with abnormal login behavior as high-risk accounts, and all high-risk accounts are grouped into a high-risk account list.
[0046] It should be noted that after obtaining the field values of the key feature fields corresponding to the target event data, they can also be stored in a specified database. When determining high-risk accounts, the structured processing results corresponding to different event occurrence time points can be read from the database, and the high-risk account determination can be jointly performed in combination with the structured processing results.
[0047] Among them, the preset abnormal behavior rules can be the rule information preset for determining that an account has abnormal login behavior. For example, it can be that the source geographical location information used for account login has never appeared, or there are frequent logins within a short period of time, etc. By way of example, multiple preset abnormal behavior rules can be set. As long as an account meets any one of them, the account can be determined as a high-risk account; then, with the account as the primary key, the determination results of the preset abnormal behavior rules can be accumulated to generate a high-risk account list.
[0048] Optionally, based on the preset abnormal behavior rules, analyzing abnormal login behavior according to the field values of the key feature fields corresponding to the target event data to obtain a high-risk account list may include:
[0049] According to the field values of the key feature fields corresponding to the target event data, obtain the geographical location information corresponding to each account. If it is detected that the geographical location information corresponding to the current account exceeds the historical location baseline range, the current account is determined as a high-risk account;
[0050] According to the field values of the key feature fields corresponding to the target event data, obtain the number of logins of each account within the first preset duration. If it is detected that the number of logins of the current account within the first preset duration is greater than or equal to the first preset number threshold, the current account is determined as a high-risk account;
[0051] According to the field values of the key feature fields corresponding to the target event data, obtain the number of failed logins and the number of successful logins of each account within the second preset duration. If it is detected that the number of failed logins of the current account within the second preset duration is greater than the second preset number threshold and the number of successful logins is not 0, the current account is determined as a high-risk account.
[0052] In an optional implementation, the preset abnormal behavior rules may include that the geographical location information corresponding to the account exceeds the historical location baseline range, the login frequency of the account exceeds the historical baseline range, and there are multiple weak password attempt behaviors for the same account with traces of successful login. Specifically, the field value corresponding to the account name field can be used as an account, and with the account as the main dimension, the geographical location information corresponding to the Internet Protocol (IP) address used when the account logs in within a specified time window is statistically analyzed, that is, the field value corresponding to the source geographical location field. If there is a geographical location information that is not within the statistical range of the historical time window, that is, it has never appeared, it can be determined that the geographical location information exceeds the historical location baseline range, and the account can be determined as a high-risk account.
[0053] Alternatively, with the account as the main dimension, according to the year-on-year algorithm, the number of logins of the account within the first preset duration (for example, 5 minutes, etc.) within the historical same-period time window is statistically analyzed. If the number of logins is greater than or equal to the first preset number threshold, the account can be determined as a high-risk account. Or, the average value of the number of logins of each account within multiple historical time windows can be statistically analyzed, and based on the average value of the number of logins corresponding to each account, the minimum value and the maximum value of the average value are obtained to form an average value range; afterwards, if the current number of logins is within this average value range, it can be determined that the account is not a high-risk account, and if the current number of logins exceeds this average value range, it can be determined that the account is a high-risk account.
[0054] Alternatively, with the account as the main dimension, the number of failed logins and the number of successful logins of the account within the second preset duration, for example, the most recent 5 minutes, etc., are statistically analyzed. If the number of failed logins of the account is greater than 3 times and there is also a successful login record, the account can be determined as a high-risk account. Among them, different preset durations can be equal or unequal, and different preset number thresholds can be equal or unequal.
[0055] S130. Obtain the mail system data, and based on the preset phishing behavior rules, perform phishing behavior analysis according to the mail system data to obtain candidate phishing mail accounts, and when it is detected that the candidate phishing mail accounts exist in the high-risk account list, determine the candidate phishing mail accounts as target phishing mail accounts.
[0056] In this embodiment, the login behavior data and email sending behavior data of users can be collected from the operation logs of the email system and the records of the email gateway database as email system data. Then, based on the preset phishing behavior rules, it can be determined whether there is a phishing behavior for each email account according to the email system data. If it is determined that there is a phishing behavior for the current email account, it can be determined as a candidate phishing email account and enter the further research and judgment link. After that, the candidate phishing email accounts are associated and matched with high-risk accounts. If it is determined that a certain candidate phishing email account exists in the high-risk account list at the same time, it can be determined as the target phishing email account.
[0057] Among them, the preset phishing behavior rules can be the rule information preset for determining that there is a phishing behavior for an email account. For example, it can be sending emails to multiple accounts within a short period of time, the email body contains hyperlinks, etc.
[0058] Optionally, based on the preset phishing behavior rules, performing phishing behavior analysis according to the email system data to obtain candidate phishing email accounts may include:
[0059] According to the email system data, if it is detected that the current email account sends emails to multiple email accounts within the third preset time period, the current email account is determined as a candidate phishing email account;
[0060] According to the email system data, if it is detected that the sending time of the current email account is during non-working hours, the current email account is determined as a candidate phishing email account;
[0061] According to the email system data, if it is detected that the sent email contains a hyperlink, the current email account is determined as a candidate phishing email account;
[0062] According to the email system data, if it is detected that the file name of the email attachment contains sensitive characters, the current email account is determined as a candidate phishing email account.
[0063] In an optional implementation, the preset phishing behavior rules may include sending emails to multiple email accounts within a short period of time, the sending time of the email being outside working hours, the email body containing hyperlinks, the file name of the email attachment containing sensitive characters, etc. For example, if it is detected that the sending time of the email is outside working hours, such as 1 am, etc., then this email account can be determined as a candidate phishing email account; or, if it is detected that the file name of the email attachment contains sensitive characters, such as "Company Confidential Documents.docx", "Financial Statements.xlsx", "exe", etc., then this email account can be determined as a candidate phishing email account. In this embodiment, as long as it is detected that the email account meets any one of the preset phishing behavior rules, then this email account can be determined as a candidate phishing email account and enter the next judgment link.
[0064] The advantage of the above settings is that it can accurately identify suspected phishing email accounts and improve the recognition accuracy of phishing email attacks.
[0065] Optionally, after determining the candidate phishing email account as the target phishing email account, it may further include:
[0066] Judge whether the target phishing email account exists in the preset whitelist;
[0067] If it is detected that the target phishing email account does not exist in the preset whitelist, then generate a phishing email attack warning based on the target phishing email account.
[0068] In an optional implementation, after determining the target phishing email account, it can also be filtered by the whitelist once. If the target phishing email account does not exist in the preset whitelist, it means that it is still determined to be abnormal after the whitelist filtering. At this time, an alarm notification can be triggered to generate a phishing email attack warning corresponding to the target phishing email account. The specific form of the warning in this embodiment may not be specifically limited.
[0069] Among them, the whitelist is set by internal personnel and covers setting values such as accounts and sending time intervals. For example, on the A day of each month, account B will send out salary emails in bulk. It can be added to the whitelist. At this time, if account B sends an email on the A day and is determined as a target phishing email account, since it exists in the whitelist, no alarm notification will be triggered.
[0070] The advantage of the above settings is that it can prevent normal work emails that meet phishing characteristics from being misreported and reduce the false positive probability of phishing email attacks.
[0071] The technical solution of the embodiment of the present invention obtains office system data, and based on preset weak password features, screens at least one target event data from the office system data; performs data structuring processing on each target event data, obtains the field values of each key feature field corresponding to each target event data, and based on preset abnormal behavior rules, analyzes abnormal login behaviors according to the field values of each key feature field corresponding to each target event data to obtain a list of high-risk accounts; obtains email system data, and based on preset phishing behavior rules, analyzes phishing behaviors according to the email system data to obtain candidate phishing email accounts, and when it is detected that a candidate phishing email account exists in the high-risk account list, determines the candidate phishing email account as a target phishing email account; by combining the identification of abnormal login accounts based on office system data and the identification of phishing email accounts based on email system data, it expands the analysis of the behaviors of phishing email attackers in the upstream office system, can improve the identification accuracy of phishing email attacks, and can enhance the overall defense ability against phishing email attacks.
[0072] In this embodiment, the phishing email identification process is extended by incorporating the data analysis of the operation logs of the remote office system, forming a new method for screening suspicious users; in the process of phishing email identification, the operation logs of the remote office system are innovatively utilized to develop an effective means for screening suspicious users, and an associated technical method for establishing the relationship between the screening results of suspicious users in the remote office system and the phishing email identification in the email system is successfully established; in the phishing email identification process, an "information" verification mechanism (analogous to a third-party signature) is introduced to explore the application of verification technology in phishing email defense, and a comprehensive solution is constructed, significantly improving the identification accuracy of the log management platform in the face of phishing attacks.
[0073] Compared with the matching method of blacklist and feature combination adopted by current security products, the present invention focuses on strengthening the in-depth analysis of the protection weaknesses of the internal communication system, aiming to accurately identify and effectively prevent the malicious behavior of attackers who first compromise other internal communication systems and then use the accounts of these systems to send phishing emails. It deeply explores the transmission characteristics between internal and mutual trust objects with the highest success rate in phishing attacks. Through the effective extraction and analysis of multi-source data, the present invention can carefully analyze the attack chain information and accurately determine whether the phishing attack is launched through internal or mutual trust objects. This embodiment scheme not only relies on the feature library matching of email information, but also improves the context information of the data chain by analyzing the suspicious behavior of the email sender / attack IP in the upstream system, thereby greatly improving the accuracy of phishing attack identification; secondly, it expands the monitoring of potential upstream applications of the email system, such as VPN, OA system, etc., and performs upstream analysis on the possible paths of email attacks. Combined with different attack status results (unsuccessful attempt / ongoing attempt / successful attempt), targeted defense measures are strengthened, effectively improving the overall defense capability of phishing attacks.
[0074] Embodiment 2
[0075] Figure 7 This is a schematic diagram of the structure of a device for identifying phishing email attacks provided in the second embodiment of the present invention. Figure 7 As shown, the device includes: a data screening module 210, an abnormality analysis module 220 and a fishing behavior analysis module 230; wherein,
[0076] The data screening module 210 is used to obtain office system data and screen at least one target event data from the office system data based on preset weak password features;
[0077] The abnormal analysis module 220 is used to perform data structuring processing on each of the target event data, obtain the field values of each key feature field corresponding to each of the target event data, and perform abnormal login behavior analysis based on the field values of each key feature field corresponding to each of the target event data based on preset abnormal behavior rules to obtain a list of high-risk accounts;
[0078] The phishing behavior analysis module 230 is used to obtain email system data, and based on preset phishing behavior rules, perform phishing behavior analysis according to the email system data, obtain candidate phishing email accounts, and when it is detected that the candidate phishing email account exists in the high-risk account list, determine the candidate phishing email account as a target phishing email account.
[0079] The technical solution of the embodiment of the present invention obtains office system data, and based on preset weak password features, screens at least one target event data from the office system data; performs data structuring processing on each target event data, obtains the field values of each key feature field corresponding to each target event data, and based on preset abnormal behavior rules, performs abnormal login behavior analysis according to the field values of each key feature field corresponding to each target event data to obtain a list of high-risk accounts; obtains email system data, and based on preset phishing behavior rules, performs phishing behavior analysis according to the email system data to obtain candidate phishing email accounts, and when it is detected that a candidate phishing email account exists in the high-risk account list, determines the candidate phishing email account as a target phishing email account; by combining the identification of abnormal login accounts based on office system data and the identification of phishing email accounts based on email system data, it expands the behavior analysis of phishing email attackers in the upstream office system, can improve the identification accuracy of phishing email attacks, and can enhance the overall defense ability against phishing email attacks.
[0080] Optionally, the phishing email attack identification device further includes:
[0081] A whitelist judgment module, configured to judge whether the target phishing email account exists in a preset whitelist;
[0082] An alarm generation module, configured to generate a phishing email attack alarm according to the target phishing email account if it is detected that the target phishing email account does not exist in the preset whitelist.
[0083] Optionally, the data screening module 210 is specifically configured to obtain at least one event data according to the office system data;
[0084] If it is detected that the current event data contains a password field, and / or the field value corresponding to the password field belongs to a weak password dictionary, then determine the current event data as target event data.
[0085] Optionally, the abnormal analysis module 220 is specifically configured to obtain the geographical location information corresponding to each account according to the field values of each key feature field corresponding to each target event data, and if it is detected that the geographical location information corresponding to the current account exceeds the historical location baseline range, then determine the current account as a high-risk account;
[0086] Obtain the number of logins of each account within a first preset time period according to the field values of each key feature field corresponding to each target event data, and if it is detected that the number of logins of the current account within the first preset time period is greater than or equal to a first preset number threshold, then determine the current account as a high-risk account;
[0087] According to the field values of the key feature fields corresponding to the respective target event data, obtain the number of failed logins and the number of successful logins of each account within a second preset duration. If it is detected that the number of failed logins of the current account within the second preset duration is greater than a second preset number threshold and the number of successful logins is not zero, then determine the current account as a high-risk account.
[0088] Optionally, the phishing behavior analysis module 230 is specifically configured to, according to the mail system data, if it is detected that the current mail account sends emails to multiple mail accounts within a third preset duration, then determine the current mail account as a candidate phishing mail account;
[0089] According to the mail system data, if it is detected that the sending time of the emails of the current mail account is during non-working hours, then determine the current mail account as a candidate phishing mail account;
[0090] According to the mail system data, if it is detected that the emails sent by the current mail account contain hyperlinks, then determine the current mail account as a candidate phishing mail account;
[0091] According to the mail system data, if it is detected that the file names of the email attachments of the current mail account contain sensitive characters, then determine the current mail account as a candidate phishing mail account.
[0092] Optionally, the key feature fields include at least one of access protocol, source address, target address, source media access control address, target media access control address, account name, password, source port, target port, and source geographical location.
[0093] The phishing email attack recognition device provided by the embodiments of the present invention can execute the phishing email attack recognition method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0094] In the technical solution of the present disclosure, the processing of the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0095] Embodiment III
[0096] Figure 8The structural schematic diagram of an electronic device 30 that can be used to implement the embodiments of the present invention is shown. The electronic device 30 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device 30 can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0097] As Figure 8 shown, the electronic device 30 includes at least one processor 31, and a memory communicatively connected to the at least one processor 31, such as a read-only memory (ROM) 32, a random access memory (RAM) 33, etc. The memory stores a computer program executable by the at least one processor. The processor 31 can execute various appropriate actions and processes according to the computer program stored in the read-only memory 32 or the computer program loaded from the storage unit 38 into the random access memory 33. In the RAM 33, various programs and data required for the operation of the electronic device 30 can also be stored. The processor 31, the ROM 32, and the RAM 33 are connected to each other through a bus 34. An input / output (I / O) interface 35 is also connected to the bus 34.
[0098] Multiple components in the electronic device 30 are connected to the I / O interface 35, including: an input unit 36, such as a keyboard, a mouse, etc.; an output unit 37, such as various types of displays, speakers, etc.; a storage unit 38, such as a magnetic disk, an optical disc, etc.; and a communication unit 39, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 39 allows the electronic device 30 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0099] The processor 31 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 31 include but are not limited to a central processing unit, a graphics processing unit, various dedicated artificial intelligence computing chips, various processors running machine learning model algorithms, a digital signal processor, and any appropriate processor, controller, microcontroller, etc. The processor 31 executes the various methods and processes described above, such as the method for identifying phishing email attacks.
[0100] In some embodiments, the method for identifying phishing email attacks may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 38. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 30 via the ROM 32 and / or the communication unit 39. When the computer program is loaded into the RAM 33 and executed by the processor 31, one or more steps of the method for identifying phishing email attacks described above may be performed. Alternatively, in other embodiments, the processor 31 may be configured to perform the method for identifying phishing email attacks by any other suitable means (e.g., by means of firmware).
[0101] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays, application specific integrated circuits, application specific standard products, systems on a chip, programmable logic devices loaded with a program, computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0102] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer programs are executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0103] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical fiber, a portable compact disk read-only memory, an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0104] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device 30 having: a display device (e.g., a cathode ray tube or a liquid crystal display) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device 30. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0105] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of the communication network include: a local area network, a wide area network, a blockchain network, and the Internet.
[0106] The computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server.
[0107] This embodiment may further include a computer program product, which includes a computer program that, when executed by a processor, implements the method for identifying phishing email attacks provided in any embodiment of the present invention.
[0108] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitations are imposed herein.
[0109] The above specific implementation manners do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub - combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for identifying phishing email attacks, characterized in that: include: Acquire office system data, and based on preset weak password features, filter out at least one target event data from the office system data; Performing data structuring processing on each of the target event data, obtaining field values of each key feature field corresponding to each of the target event data, and performing abnormal login behavior analysis based on the field values of each key feature field corresponding to each of the target event data based on preset abnormal behavior rules, to obtain a list of high-risk accounts; Obtain email system data, and based on preset phishing behavior rules, perform phishing behavior analysis according to the email system data to obtain candidate phishing email accounts, and when it is detected that the candidate phishing email account exists in the high-risk account list, determine the candidate phishing email account as a target phishing email account.
2. The method according to claim 1, characterized in that After determining the candidate phishing email account as a target phishing email account, the method further includes: Determine whether the target phishing email account exists in a preset whitelist; If it is detected that the target phishing email account does not exist in the preset whitelist, a phishing email attack alert is generated according to the target phishing email account.
3. The method according to claim 1, characterized in that Based on the preset weak password features, at least one target event data is obtained by screening from the office system data, including: Acquire at least one event data according to the office system data; If it is detected that the current event data includes a password field, and / or the field value corresponding to the password field belongs to a weak password dictionary, the current event data is determined as target event data.
4. The method according to claim 1, characterized in that: Based on the preset abnormal behavior rules, abnormal login behavior analysis is performed according to the field values of each key feature field corresponding to each target event data to obtain a list of high-risk accounts, including: According to the field values of the key feature fields corresponding to the target event data, the geographical location information corresponding to each account is obtained, and if it is detected that the geographical location information corresponding to the current account exceeds the historical location baseline range, the current account is determined as a high-risk account; According to the field value of each key feature field corresponding to each target event data, the number of logins of each account within a first preset time period is obtained, and if it is detected that the number of logins of the current account within the first preset time period is greater than or equal to a first preset number threshold, the current account is determined as a high-risk account; According to the field value of each key feature field corresponding to each target event data, the number of failed logins and the number of successful logins of each account within the second preset time period are obtained. If it is detected that the number of failed logins of the current account within the second preset time period is greater than the second preset number threshold, and the number of successful logins is not 0, the current account is determined to be a high-risk account.
5. The method according to claim 1, characterized in that Based on the preset phishing behavior rules, phishing behavior analysis is performed according to the email system data to obtain candidate phishing email accounts, including: If it is detected, based on the email system data, that the current email account sends emails to multiple email accounts within a third preset time period, the current email account is determined as a candidate phishing email account; According to the email system data, if it is detected that the current email account sends emails during non-working hours, the current email account is determined as a candidate phishing email account; According to the email system data, if it is detected that the current email account has a hyperlink in the email sent, the current email account is determined as a candidate phishing email account; According to the email system data, if it is detected that the file name of an email attachment in the current email account contains sensitive characters, the current email account is determined as a candidate phishing email account.
6. The method according to claim 1 or 4, characterized in that: The key feature fields include at least one of access protocol, source address, destination address, source media access control address, destination media access control address, account name, password, source port, destination port and source geographic location.
7. A device for identifying phishing email attacks, characterized in that: include: A data screening module, used to obtain office system data, and based on preset weak password features, screen at least one target event data from the office system data; An abnormal analysis module is used to perform data structuring processing on each of the target event data, obtain the field values of each key feature field corresponding to each of the target event data, and perform abnormal login behavior analysis based on the field values of each key feature field corresponding to each of the target event data based on preset abnormal behavior rules to obtain a list of high-risk accounts; The phishing behavior analysis module is used to obtain email system data, and based on preset phishing behavior rules, perform phishing behavior analysis according to the email system data, obtain candidate phishing email accounts, and when it is detected that the candidate phishing email account exists in the high-risk account list, determine the candidate phishing email account as a target phishing email account.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor, and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the method for identifying phishing email attacks according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program is used to enable a processor to implement the method for identifying phishing email attacks according to any one of claims 1 to 6 when executed.
10. A computer program product, characterized in that The invention comprises a computer program, which, when executed by a processor, implements the method for identifying phishing email attacks according to any one of claims 1 to 6.
Citation Information
Cited By
Phishing behavior detection method and system, storage medium, equipment and program product
CN121356906A