Network traffic security audit and defense method based on process injection and related equipment
By injecting interception code into the target process memory address, proxying network traffic and converting it into structured logs, combining the security audit rule engine to identify risks, and dynamically adjusting the interception code logic, it solves the deployment complexity and compatibility issues in existing technologies and realizes efficient and real-time network traffic security auditing and defense.
Patent Information
- Application Number
- CN202510593601.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-05-09
AI Technical Summary
Existing network traffic security auditing technology has problems such as high deployment complexity, incompatibility with existing operating systems, and impact on business system perception. In particular, performance bottlenecks are obvious in high concurrency and large data volume scenarios, and it is highly dependent on network architecture and difficult to adapt to dynamically changing network environments.
By dynamically injecting interception code into the memory address of the target process, proxying network traffic, capturing and converting it into structured logs, utilizing the security audit rule engine for risk identification, and dynamically adjusting the execution logic of the interception code based on threat events to respond to security risks.
It achieves in-depth monitoring and security protection of network traffic without changing the network deployment architecture, improves the efficiency and accuracy of security audits, detects potential threat events in real time, flexibly responds to different types of security threats, and ensures that system security does not affect the normal operation of business systems.
Smart Images

Figure CN120128424B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a network traffic security auditing and defense method based on process injection and related equipment. Background Art
[0002] In today's digital age, network traffic security auditing technology has become a critical component of network security. With the widespread adoption of the internet and the increasing sophistication of cyberattacks, businesses and organizations face unprecedented security challenges. Interception and rewriting are common network security defense technologies, including gateway mode, payload forwarding mode, and eBPF (Extended Berkeley Packet Filter) proxy technology.
[0003] However, existing technologies still have significant shortcomings in practical applications. For example, the gateway model requires adding additional hardware devices to the existing network architecture or making complex network topology adjustments, which not only increases implementation costs but can also lead to performance bottlenecks, especially in scenarios with high concurrency and large data volumes. Furthermore, this deployment method is highly dependent on the network architecture and struggles to adapt to dynamically changing network environments. The eBPF model requires a very high kernel version for the host operating system, while existing application systems use lower kernel versions, making them incompatible and incompatible. Furthermore, existing security auditing technologies often require restarting or reconfiguring business systems, which not only complicates implementation but can also cause business interruptions and impact user experience. Therefore, existing technologies suffer from high deployment complexity, incompatibility with existing operating systems, and a perceived impact on business systems.
[0004] The preceding description is intended to provide general background information and does not necessarily constitute prior art. Summary of the Invention
[0005] In response to the above technical problems, this application provides a network traffic security audit and defense method and related equipment based on process injection to solve the problems of high deployment complexity, incompatibility with existing operating systems and impact on business system perception in existing technologies.
[0006] To solve the above technical problems, the present application provides a network traffic security audit and defense method based on process injection, which includes the following steps:
[0007] Determine the memory addresses of the target process's network request and response functions, and dynamically inject interception code into the memory addresses to proxy network traffic;
[0008] Capturing the request and response data of the network traffic and converting them into structured logs;
[0009] Based on a predefined security audit rule engine, security risks are identified on the structured logs to generate threat events;
[0010] A control instruction is issued according to the threat event, and the execution logic of the interception code is dynamically adjusted according to the control instruction to respond to the security risk.
[0011] Furthermore, in some embodiments of the present application, determining the memory address of the network request and response function of the target process and dynamically injecting interception code into the memory address to proxy network traffic includes:
[0012] Locating the memory addresses of the network request and response functions of the target process using the function symbol information of the target process;
[0013] Inserting a custom code segment at the memory address to proxy the execution process of the network request and response function;
[0014] The custom code segment is run through an independent memory area.
[0015] Furthermore, in some embodiments of the present application, capturing the request and response data of the network traffic and converting them into structured logs includes:
[0016] Parsing the input parameters of the network request and response function to extract the original traffic message;
[0017] The original traffic message is converted into a structured log in a unified format and sent to a message queue for asynchronous processing.
[0018] Furthermore, in some embodiments of the present application, the security risk identification of the structured log based on the predefined security audit rule engine and the generation of threat events include:
[0019] Loading a security audit rule base from a cache, wherein the rule base includes matching conditions based on regular expressions, scripting languages, or statistical features;
[0020] Consuming the structured log from the message queue, performing multi-dimensional feature matching on the structured log through the security audit rule library according to a preset chain rule matching logic, generating a threat event and storing it in a threat event library;
[0021] The traffic data that triggers the threat event is marked, and the corresponding attack type and risk level are marked.
[0022] Furthermore, in some embodiments of the present application, the preset chain rule matching logic includes:
[0023] Distinguishing traffic types of the structured logs according to traffic type screening rules;
[0024] At least one detection operation among keyword matching, parameter format verification, and behavior pattern analysis is performed in sequence based on the traffic type.
[0025] Furthermore, in some embodiments of the present application, issuing a control instruction according to the threat event and dynamically adjusting the execution logic of the interception code according to the control instruction to respond to the security risk includes:
[0026] Converting the risk control strategy corresponding to the threat event into a control instruction, wherein the control instruction includes at least one of a blocking request instruction, a response rewriting instruction, and a data desensitization instruction;
[0027] The control instruction is sent to the target process through a reverse connection channel, so as to dynamically modify the execution logic of the interception code according to the control instruction.
[0028] Furthermore, in some embodiments of the present application, the method further includes:
[0029] Integrate the threat events and attack samples output by the security detection tool into a training data set;
[0030] Performing streaming learning on the training data set using a deep learning model to generate a risk identification model;
[0031] After the risk identification model is deployed as an online service, the risk identification model is used by the security audit rule engine to perform risk prediction to obtain a risk prediction result.
[0032] Accordingly, the present application provides a network traffic security audit and defense device based on process injection, comprising:
[0033] A process injection module is used to determine the memory addresses of the target process's network request and response functions and dynamically inject interception code into the memory addresses to proxy network traffic;
[0034] A data processing module, configured to capture the request and response data of the network traffic and convert them into structured logs;
[0035] A risk identification module, configured to identify security risks on the structured logs based on a predefined security audit rule engine and generate threat events;
[0036] A control module is used to issue control instructions according to the threat event and dynamically adjust the execution logic of the interception code according to the control instructions to respond to security risks.
[0037] The present application also provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the network traffic security audit and defense method based on process injection as described above are implemented.
[0038] The present application also provides a storage medium storing a computer program that can be loaded by a processor and execute the network traffic security audit and defense method based on process injection as described above.
[0039] The implementation of the embodiments of the present application has the following beneficial effects:
[0040] As described above, the present application provides a network traffic security audit and defense method, device, electronic device and storage medium based on process injection, the method comprising: first, determining the memory address of the network request and response function of the target process, and dynamically injecting interception code into the memory address to proxy network traffic; then, capturing the request and response data of the network traffic and converting them into structured logs; then, based on a predefined security audit rule engine, identifying security risks on the structured logs and generating threat events; finally, issuing control instructions based on the threat events, and dynamically adjusting the execution logic of the interception code according to the control instructions to respond to security risks. The network traffic security audit solution provided by the present application can directly proxy network traffic in the process where the business system is located without changing the network deployment architecture by dynamically injecting interception code into the memory address of the target process; by converting the request and response data into structured logs, the efficiency and accuracy of subsequent security audits can be effectively improved; by using the security audit rule engine to identify security risks on the structured logs, potential threat events can be quickly detected, improving the real-time and effectiveness of security audits, and after detecting threat events, control instructions can be issued to dynamically adjust the execution logic of the interception code, respond to security risks in a timely manner, and effectively protect the system from attacks. It can be seen that this application provides a flexible, efficient and real-time network traffic security audit and defense method based on process injection, which can deeply monitor and securely protect network traffic without affecting the normal operation of the business system. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The accompanying drawings herein are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for describing the embodiments. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without inventive work.
[0042] Figure 1This is a schematic diagram of an application scenario of the network traffic security audit and defense method based on process injection provided in an embodiment of the present application;
[0043] Figure 2 This is a flowchart of a network traffic security audit and defense method based on process injection provided by an embodiment of the present application;
[0044] Figure 3 Another flowchart of the network traffic security audit and defense method based on process injection provided in an embodiment of the present application;
[0045] Figure 4 This is a schematic diagram of the structure of a network traffic security audit and defense device based on process injection provided in an embodiment of the present application;
[0046] Figure 5 It is a structural diagram of an electronic device provided in an embodiment of the present application.
[0047] The purpose of this application, its features, and advantages will be further described in conjunction with the embodiments and with reference to the accompanying drawings. The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and the accompanying text are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of this application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0048] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0049] It should be noted that, in this document, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, components, features, and elements with the same name in different embodiments of the present application may have the same meaning or different meanings, and their specific meanings need to be determined based on their explanation in the specific embodiment or further combined with the context of the specific embodiment.
[0050] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0051] In the subsequent description, the use of suffixes such as "module", "component" or "unit" to represent elements is only for the purpose of facilitating the description of the present application and has no specific meaning. Therefore, "module", "component" or "unit" can be used interchangeably.
[0052] Existing network traffic security auditing technologies face several significant technical challenges in practical application, particularly deployment complexity, operating system compatibility, and business system awareness. First, deployment complexity is a major bottleneck for existing technologies. Traditional network traffic auditing technologies, such as gateway or load forwarding models, often require complex adjustments to the existing network architecture, such as adding additional hardware or reconfiguring the network topology. This deployment approach not only increases implementation costs but can also lead to performance bottlenecks, especially in scenarios with high concurrency and large data volumes. Furthermore, this reliance on network architecture limits the technology's flexibility, making it difficult to adapt to dynamically changing network environments. The eBPF model requires a very high kernel version for the host operating system, while existing application systems use lower kernel versions, making it incompatible and incompatible. Second, business system awareness is also a significant issue. Many existing security auditing technologies require restarting or reconfiguring business systems, which not only increases implementation complexity but can also cause business interruptions and impact user experience. This level of awareness is unacceptable for critical business systems, especially in scenarios requiring real-time monitoring and rapid response.
[0053] In order to solve the above technical problems, the present application provides a network traffic security audit and defense method, device, electronic device and storage medium based on process injection.
[0054] In order to facilitate understanding of the network traffic security audit and defense method based on process injection provided in the embodiments of the present application, some specialized terms are explained below.
[0055] Process injection: DMI (Dynamic Memory Injection) is a technique for injecting code or data into a running program at runtime. This technique is commonly used in debugging, reverse engineering, malware development, and other fields.
[0056] Memory Patching: Modifying program functionality by modifying data or instructions in memory while the program is running. For example, you can change the return address of a function or modify the value of a key variable.
[0057] Threat event: An attack request discovered on the network. After a security audit discovers it, the output log object is called a threat event.
[0058] Owasp: Open Web Application Security Project is an open project organization focusing on Web application security, dedicated to improving the security of computer and Internet applications.
[0059] See also Figure 1 , Figure 1 This is an application environment diagram of a network traffic security audit and defense method based on process injection in one embodiment. Figure 1 , the network traffic security audit and defense method based on process injection can be applied to a network traffic security audit system. Among them, the network traffic security audit system may include an application server 110 and a risk identification server 120. The application server 110 and the risk identification server 120 are connected through a network, and the application server 110 may specifically be an application system deployed. The risk identification server 120 can be implemented with an independent server or a server cluster composed of multiple servers. It is mainly used for the operation of the security audit engine and the consumption of structured logs in the consumption queue. Based on the predefined security audit rule engine, it identifies security risks for structured logs and generates threat events; issues control instructions according to threat events, and dynamically adjusts the execution logic of the interception code according to the control instructions to respond to security risks. The application server 110 is used to determine the memory address of the network request and response function of the target process, and dynamically injects interception code into the memory address to proxy network traffic; captures the request and response data of the network traffic, and converts it into structured logs, and receives control instructions sent by the risk identification server 120;
[0060] It should be noted that the order of description of the following embodiments does not limit the priority order of the embodiments.
[0061] See also Figure 2 , Figure 2 This is a flow chart of a network traffic security audit and defense method based on process injection provided by an embodiment of the present application. The network traffic security audit and defense method based on process injection provided by this embodiment may specifically include the following steps:
[0062] S1. Determine the memory address of the target process's network request and response functions and dynamically inject interception code into the memory address to proxy network traffic.
[0063] Specifically, in step S1, the target process requiring a security audit is identified and located through system calls or process management APIs, ensuring the targeted nature of the security audit and avoiding interference with non-relevant processes. Debugging tools or symbol table parsing are used to obtain symbolic information for the network request and response functions in the target process. Symbolic information identifies the function in memory, allowing the precise location of the function's entry point. Based on this symbolic information, the specific addresses of the network request and response functions in the target process's memory space are determined. This step is crucial for code injection, ensuring that the interception code is accurately inserted into the correct execution location. Using dynamic memory allocation and code injection techniques, customized interception code is inserted at the specified memory address. The interception code acts as a proxy for network traffic, executing network request and response operations on behalf of the original function. Furthermore, multi-process technology enables simultaneous location and injection into multiple target processes, enabling comprehensive monitoring of multiple network activities in complex systems. During the injection process, memory protection mechanisms are employed to ensure that the interception code executes smoothly without causing system anomalies.
[0064] This embodiment precisely injects interception code to ensure that the interception code can be accurately injected into the key function location of the target process, laying the foundation for subsequent traffic capture and security auditing; the target process and business system are unaware of the existence of the interception code, which does not affect the normal business process, thereby achieving transparency in security auditing.
[0065] S2. Capture network traffic request and response data and convert them into structured logs.
[0066] Specifically, for step S2, the interception code captures the original network data packets when proxying network requests and responses. The network data packets may specifically include key information such as request method, request path, request parameters, response status code, etc. The captured network data packets are parsed to extract structured data elements. For example, the request line, request header, and request body are extracted from the HTTP request. The parsed data is converted according to the predefined structured log format. Structured logs usually include fields such as timestamp, source IP, destination IP, request method, request path, response status code, etc. The converted structured logs are stored in the memory buffer or sent directly to the message queue to support subsequent security audit processing. In addition, an asynchronous mechanism can be used to send the logs to the message queue to avoid the delay effect of the capture and conversion process on the network request response. During the log transmission process, the log data is compressed and encrypted to improve transmission efficiency and data security.
[0067] This embodiment can capture network traffic data in real time to ensure the timeliness and completeness of security audits; and convert the original traffic data into a unified structured format to facilitate subsequent processing and analysis by the security audit rule engine.
[0068] S3. Based on the predefined security audit rule engine, security risks are identified in structured logs and threat events are generated.
[0069] Specifically, for step S3, a predefined security audit rule library is loaded, and the rule library contains a variety of security detection rules, such as keyword matching, regular expressions, statistical feature analysis, etc. Structured logs are consumed from the message queue, and multi-dimensional feature matching is performed on the log data according to the preset rule matching logic. When a feature that meets the security rules is matched, a threat event is generated. The threat event contains information such as threat type, threat source, threat timestamp, risk level, etc. The generated threat event is stored in the threat event library, and the control module is notified for subsequent processing. In addition, new security rules can be loaded in real time through hot updates of the rule engine to adapt to the ever-changing network security environment; the rule engine can be deployed in a distributed system to realize parallel auditing of large-scale network traffic and improve processing efficiency.
[0070] This embodiment can identify security risks of network traffic in real time and promptly discover potential threat events; through multi-dimensional feature matching, the accuracy and comprehensiveness of threat detection are improved.
[0071] S4. Issue control instructions based on threat events and dynamically adjust the execution logic of the interception code based on the control instructions to respond to security risks;
[0072] Specifically, for step S4, corresponding control instructions are generated according to the type and severity of the threat event. Control instructions include operations such as blocking requests, rewriting responses, and data desensitization. The control instructions are sent to the interception code in the target process through reverse connection or other communication mechanisms. The interception code dynamically adjusts its execution logic based on the received control instructions. For example, blocking malicious requests, rewriting response content to hide sensitive information, etc. After adjusting the execution logic, the interception code feeds back the execution results to the control end, while continuously monitoring network traffic to ensure the effective execution of security policies. In addition, by performing priority management on control instructions, high-priority security operations can be executed in a timely manner. The execution results of the interception code are audited and an execution log is generated for subsequent security analysis and policy optimization.
[0073] This embodiment can dynamically adjust the execution logic of the interception code according to the threat event, achieve a rapid response to security risks, flexibly respond to different types of security threats through a variety of control instructions, and improve the system's security protection capabilities.
[0074] Furthermore, in some embodiments, step S1 of “determining the memory address of the network request and response function of the target process, and dynamically injecting interception code into the memory address to proxy network traffic” may specifically include:
[0075] S11. Locate the memory address of the target process's network request and response function through the target process's function symbol information;
[0076] Specifically, debugging tools or symbol table parsing technology are used to extract symbolic information of network request and response functions from the target process. Symbolic information usually includes function name, parameter list, return value type, etc., which are the key to locating the memory address of the function. Based on the symbolic information obtained, the specific address of the function in the memory space of the target process is parsed through the API or memory mapping file provided by the system. This step needs to deal with possible memory protection mechanisms to ensure the accuracy of address resolution. The parsed memory address is verified to ensure its validity, including checking whether the address is within the legal memory range and whether it actually corresponds to the target function. This embodiment provides a basis for subsequent code injection by ensuring that the memory address of the target function can be accurately found; through symbolic information parsing, the compatibility of the method with different target processes is improved.
[0077] S12. Insert a custom code segment at the memory address to proxy the execution flow of the network request and response function;
[0078] Specifically, a custom code segment is written, which is used to proxy the execution of network request and response functions. The code segment usually includes logic for traffic capture, data conversion, and security auditing. A new memory area is allocated in the memory space of the target process to store the custom code segment. The custom code segment is copied to the allocated memory area, and the entry point of the target function is modified so that it jumps to the custom code segment for execution. When the target function is called, the execution process first jumps to the custom code segment, completes traffic capture and security auditing, and then calls the original function to continue execution. In addition, the custom code segment can be encrypted to prevent malicious analysis or tampering. And the custom code segment can be hot-updated at runtime to adapt to new security requirements. The target process of this embodiment is unaware of the existence of the custom code and does not affect the normal business process; through the custom code segment, the security audit logic can be flexibly expanded and modified.
[0079] S13. Run the custom code segment through the independent memory area;
[0080] Specifically, in the memory space of the target process, an independent memory area is allocated for running the custom code segment to ensure that the execution of the custom code does not interfere with the normal memory usage of the target process. Appropriate memory protection attributes are set for the independent memory area, such as readable, writable, and executable, to ensure that the code segment can run normally. The execution environment of the custom code segment is constructed in the independent memory area, including the necessary data structures and runtime libraries. The execution process is transferred to the custom code segment in the independent memory area to complete the proxy operation of the network request and response. In addition, memory isolation technology can be used to further protect the execution environment of the custom code segment to prevent it from being damaged by external attacks. And the allocation and use of independent memory areas are optimized to reduce the impact on the performance of the target process. The use of independent memory areas in this embodiment ensures the stable operation of the custom code and avoids conflicts with the target process memory; through memory protection and isolation technology, the security of the custom code segment is improved to prevent malicious use.
[0081] Furthermore, in some embodiments, step S2 of “capturing request and response data of network traffic and converting them into structured logs” may specifically include:
[0082] S21. Parse the input parameters of the network request and response function and extract the original traffic message;
[0083] Specifically, by analyzing the input parameter structure of network request and response functions, key fields are identified and parsed. For example, in an HTTP request, the request method (GET, POST, etc.), request path, request headers (such as User-Agent, Cookies, etc.), and request body (such as form data, JSON data, etc.) are parsed. The parsed parameters are combined into the original traffic message to ensure integrity and accuracy. This step requires handling possible data encoding issues, such as URL encoding and Base64 encoding. In addition, parameter parsing for multiple network protocols (such as HTTP, HTTPS, TCP, UDP, etc.) is supported to ensure effective processing of different types of network traffic. Machine learning technology can also be used to automatically identify and parse unknown or complex format network request parameters.
[0084] This embodiment can capture and parse network traffic data in real time to ensure the timeliness of security audits; completely extract network request and response data to ensure the comprehensiveness of audit data; and improve the accuracy of data extraction by accurately parsing parameters, providing a reliable data foundation for subsequent security audits.
[0085] S22. Convert the original traffic message into a structured log in a unified format and send it to the message queue for asynchronous processing;
[0086] Specifically, a unified structured log format is defined, which usually includes fields such as timestamp, source IP, destination IP, request method, request path, response status code, and request parameters. Data conversion logic is written to convert the original traffic message into the defined structured log format, including data type conversion, field mapping, and default value setting. The converted structured log is sent to the message queue, and an asynchronous processing mechanism is used to ensure that log processing does not affect the real-time nature of network requests. In addition, during the log transmission process, the log data is compressed and encrypted to improve transmission efficiency and data security. Dynamic adjustment of the format and content of the structured log is supported according to different security audit requirements. Intelligent routing to different message queues based on the type and priority of the log improves processing efficiency.
[0087] This embodiment converts raw traffic data into a unified structured format to facilitate subsequent processing and analysis by the security audit rule engine. The structured log format improves the processability of the data and supports the direct use of multiple analysis tools and engines. Through the asynchronous mechanism, the delay effect of log processing on network request responses is avoided, thereby improving the overall performance of the system.
[0088] Furthermore, in some embodiments, step S3 of “identifying security risks on structured logs based on a predefined security audit rule engine and generating threat events” may specifically include:
[0089] S31. Loading a security audit rule base from the cache, the rule base containing matching conditions based on regular expressions, scripting languages, or statistical features;
[0090] Specifically, the security audit rule base is preloaded into the cache for fast access. This caching mechanism can significantly reduce rule loading time and improve audit efficiency. The rule base contains multiple types of matching conditions, such as regular expressions for keyword matching, scripting languages (such as Groovy and Avatar) for complex logic matching, and statistical features for abnormal behavior analysis (such as request frequency and parameter randomness). Dynamic updates to the rule base are supported to ensure timely response to emerging security threats. Version control of the rule base is implemented, supporting rollback and comparison to ensure the reliability of rule updates. Deploying the rule base in a distributed system improves the efficiency and availability of rule loading.
[0091] This embodiment uses a caching mechanism to enable the rule base to be loaded quickly, reducing audit delays; supports multiple matching conditions to adapt to different types of security threats; and a dynamic update mechanism ensures that the rule base is always up to date, improving the timeliness of security audits.
[0092] S32. Consume structured logs from the message queue, perform multi-dimensional feature matching on the structured logs according to the preset chain rule matching logic through the security audit rule library, generate threat events and store them in the threat event library;
[0093] Specifically, structured logs are consumed from the message queue in real time to ensure timely log processing. Multi-dimensional feature matching is performed on structured logs according to the preset chain rule matching logic. For example, traffic type is matched first, then keywords are matched, and finally statistical feature analysis is performed. When a feature that meets the rules is matched, a threat event is generated. The threat event contains information such as threat type, threat source, threat timestamp, and risk level. The generated threat events are stored in the threat event library for subsequent analysis and processing. Multi-threaded or distributed parallel processing is supported to improve log consumption and matching efficiency. In addition, machine learning technology can be used to optimize the matching logic to improve matching accuracy and efficiency. Threat events are prioritized to ensure that high-priority events are processed first.
[0094] This embodiment ensures the timeliness of security audits through real-time consumption and matching; multi-dimensional feature matching improves the accuracy and comprehensiveness of threat detection; and structured storage of threat events facilitates subsequent query and analysis.
[0095] S33. Mark the traffic data that triggers the threat event, marking the corresponding attack type and risk level;
[0096] Specifically, traffic data that triggers threat events is tagged to identify the specific attack type (e.g., SQL injection, XSS attack, etc.) and risk level (e.g., high, medium, low). Tagging information is associated with traffic data and stored to facilitate subsequent auditing and analysis. This tagging information is fed back to the control module, which generates control instructions and dynamically adjusts the execution logic of the interception code. Furthermore, custom tagging information, such as the attack source IP address and attack timestamp, can be customized to enrich audit data. A visual interface is provided to intuitively display the distribution of tagged attack types and risk levels. Tagging information can be exported as reports or datasets for further analysis or compliance audits.
[0097] This embodiment can clearly identify the attack type and risk level, thereby improving the readability and usability of the audit; and through the feedback of the marking information, the generation of control instructions is optimized, thereby improving the pertinence of the security response.
[0098] Furthermore, in some embodiments, the preset chain rule matching logic includes:
[0099] Differentiate the traffic types of structured logs based on traffic type filtering rules;
[0100] At least one detection operation among keyword matching, parameter format verification, and behavior pattern analysis is performed in sequence based on the traffic type.
[0101] Specifically, the chain rule matching logic in this embodiment is divided into two levels. The first level execution logic is traffic type matching, and the second level execution logic is at least one detection operation among keyword matching, parameter format verification, and behavior pattern analysis.
[0102] The specific process is as follows: The traffic type field in structured logs is analyzed to identify request and response traffic. Management and monitoring traffic can also be identified. Based on the traffic type, corresponding rules are selected from the security audit rule library. For example, request traffic is subject to request-based rules, while response traffic is subject to response-based rules. A mapping relationship between traffic types and rule sets is established to ensure that the correct rules are applied to different traffic types. Machine learning techniques can be used to automatically classify traffic types, improving classification accuracy and efficiency. Traffic type screening ensures accurate rule application, reduces false positives, avoids full rule matching, and improves audit efficiency. After identifying the traffic type in structured logs, at least one detection operation among keyword matching, parameter format verification, and behavioral pattern analysis is sequentially performed. For example, regular expressions or keyword lists are used to match specific content in the traffic data, such as URLs and parameter values. Another example is to verify that request parameters conform to predefined formats, such as data types and length limits. Another example is to analyze behavioral characteristics of traffic data, such as request frequency and session duration, to identify anomalous behavior. Based on traffic type and security requirements, different detection operations are combined, such as keyword matching followed by behavioral pattern analysis. This embodiment provides comprehensive security protection through a combination of multiple detection operations; it supports flexible combination of detection operations according to traffic type and security requirements to adapt to different security scenarios.
[0103] Furthermore, in some embodiments, step S4 of "issuing a control instruction according to a threat event, and dynamically adjusting the execution logic of the interception code according to the control instruction to respond to the security risk" may specifically include:
[0104] S41. Converting the risk control strategy corresponding to the threat event into a control instruction, the control instruction including at least one of a blocking request instruction, a response rewriting instruction, and a data desensitization instruction;
[0105] Specifically, threat events can be categorized by attack type (such as SQL injection, XSS attacks, and sensitive data leakage) and risk level (high, medium, or low). High-risk events (such as malicious traffic) can trigger request blocking instructions, medium-risk events (such as suspicious behavior) can trigger response rewriting instructions, and low-risk events (such as potential sensitive data leakage) can trigger data redaction instructions. Risk control policies are also dynamically adjusted based on the frequency and type of real-time threat events. For example, if a certain type of attack occurs frequently, the system can automatically increase its priority, triggering stricter control instructions.
[0106] During implementation, machine learning models can be used to intelligently generate optimal control instructions based on historical threat events and response results. Predefined control instruction templates for common threats allow for rapid matching and generation of instructions, improving response speed.
[0107] This embodiment can quickly issue control instructions based on the type and severity of threat events to ensure that security incidents are handled in a timely manner; by dynamically adjusting control instructions, the system can adapt to the ever-changing threat environment and avoid security vulnerabilities caused by fixed policies.
[0108] S42 sends the control instruction to the target process through the reverse connection channel to dynamically modify the execution logic of the interception code according to the control instruction;
[0109] Specifically, the control server establishes a communication channel with the target process via a reverse connection (such as a WebSocket or persistent HTTP connection). The instruction control module in the target process receives and parses the control instructions. Based on the control instructions, the execution logic of the interception code is dynamically adjusted. For example, this can involve modifying the function jump table or updating the matching rules in the interception code. After the interception code execution is adjusted, the execution results are fed back to the control server, forming a closed-loop management system. Furthermore, reverse connections using multiple communication protocols can be used to ensure reliable instruction delivery in different network environments. The execution logic modification process of the interception code is monitored to ensure the correctness and stability of the modifications.
[0110] This embodiment dynamically modifies the interception code logic to flexibly respond to ever-changing security threats; the reverse connection mechanism reduces the time overhead of connection establishment and improves the efficiency of instruction issuance; instruction execution monitoring ensures the stable operation of the interception code and avoids system anomalies caused by logic modifications.
[0111] Furthermore, if Figure 3 As shown, in some embodiments, the network traffic security audit and defense method based on process injection provided by this embodiment may further include:
[0112] S51. Integrate threat events and attack samples output by security detection tools into a training dataset;
[0113] Specifically, identified threat event data is collected from the threat event library, including information such as attack type, attack source, attack timestamp, and risk level. Attack sample data, which typically contains the original traffic packets of the attack request, is obtained from security detection tools (such as IDS, IPS, and WAF). The threat event data and attack sample data are integrated to form a unified training dataset. The integration process includes steps such as data cleansing, deduplication, and format unification. The integrated data is labeled to clearly define the attack type and risk level corresponding to each data item, providing supervision information for model training. In addition, the training dataset can be expanded through data enhancement techniques (such as changing request parameters and simulating different attack variants) to improve the model's generalization ability. Data from different security tools and systems are integrated to form a more comprehensive training dataset.
[0114] This embodiment integrates multi-source data to enrich the training data set and improve the comprehensiveness of model training; through precise labeling, it provides high-quality supervision information for model training and improves the accuracy of the model; data enhancement technology improves the model's ability to identify new attacks.
[0115] S52. Use the deep learning model to perform streaming learning on the training dataset to generate a risk identification model;
[0116] Specifically, select a suitable deep learning model, such as a convolutional neural network (CNN), recurrent neural network (RNN), or Transformer model, to process sequential data and recognize complex patterns. Using an online learning approach, the model can be updated in real time to adapt to changing attack patterns. Use a training dataset to train the deep learning model, optimize model parameters, and improve recognition accuracy. Evaluate model performance using methods such as cross-validation and the Area Under Curve-Receiver Operating Characteristic (AUC-ROC) curve, and optimize based on the results. Furthermore, model training can be performed on distributed computing frameworks (such as TensorFlow Distributed and PyTorch Distributed) to improve training efficiency. Model compression techniques (such as pruning and quantization) are used to reduce model size and improve model deployment efficiency. The online learning mechanism in this embodiment ensures that the model can adapt to new attack patterns in real time, maintaining the timeliness of recognition capabilities. Distributed training improves model training efficiency and shortens training time. Optimization and compression techniques improve model performance and deployment efficiency.
[0117] S53. After deploying the risk identification model as an online service, the risk identification model is used by the security audit rule engine to perform risk prediction and obtain risk prediction results;
[0118] Specifically, the trained risk identification model is deployed as an online service, enabling it to perform risk predictions within real-time network traffic. The security audit rule engine invokes the risk identification model service, inputs the captured network traffic data into the model, and obtains risk prediction results. In a specific embodiment, the risk identification model is first deployed as an online service, which can be managed using containerization technologies (such as Docker) and microservice architectures (such as Kubernetes). An API interface is provided so that the security audit rule engine can conveniently invoke the model service. The security audit rule engine then sends the captured network traffic data to the risk identification model service in real time. The model service processes the data and returns the risk prediction results. Finally, the risk prediction results are fed back to the security audit rule engine for further security analysis and decision-making. Based on the risk prediction results, the rule base of the security audit rule engine is dynamically adjusted to optimize model performance.
[0119] This embodiment can process network traffic data in real time and return risk prediction results to ensure the timeliness of security audits; the risk identification model and the security audit rule engine work together to form a complete security audit and defense system; through the feedback mechanism, the system can dynamically adjust the rule base and model parameters according to the risk prediction results to achieve adaptive optimization.
[0120] In summary, the network traffic security audit and defense method based on process injection provided by this embodiment, first, by dynamically injecting interception code into the memory address of the target process, it can directly proxy network traffic in the process where the business system is located without changing the network deployment architecture; then, by converting request and response data into structured logs, it can effectively improve the efficiency and accuracy of subsequent security audits; then, through the security audit rule engine, security risks are identified on the structured logs, which can quickly detect potential threat events, improve the real-time and effectiveness of security audits, and finally, after the threat event is detected, control instructions are issued to dynamically adjust the execution logic of the interception code, respond to security risks in a timely manner, and effectively protect the system from attacks. It can be seen that this embodiment provides a flexible, efficient and real-time network traffic security audit and defense method based on process injection, which can deeply monitor and protect network traffic without affecting the normal operation of the business system.
[0121] To facilitate better implementation of the process injection-based network traffic security audit and defense method of the present application embodiment, the present application embodiment also provides a network traffic security audit and defense device. The meanings of the terms herein are the same as those in the process injection-based network traffic security audit and defense method described above. For specific implementation details, please refer to the description in the method embodiment.
[0122] See also Figure 4 , Figure 4 This is a schematic diagram of the structure of a network traffic security audit and defense device provided in an embodiment of the present application, wherein the network traffic security audit and defense device may specifically include a process injection module 201, a data processing module 202, a risk identification module 203, and a control module 204, which may be specifically as follows:
[0123] The process injection module 201 is used to determine the memory address of the network request and response function of the target process and dynamically inject interception code into the memory address to proxy the network traffic;
[0124] The data processing module 202 is used to capture the request and response data of the network traffic and convert it into a structured log;
[0125] The risk identification module 203 is used to identify security risks in structured logs based on a predefined security audit rule engine and generate threat events;
[0126] The control module 204 is used to issue control instructions according to threat events and dynamically adjust the execution logic of the interception code according to the control instructions to respond to security risks.
[0127] Furthermore, in some embodiments, the process injection module 201 may specifically include:
[0128] A positioning unit is used to locate the memory address of the network request and response function of the target process through the function symbol information of the target process;
[0129] An insertion unit, used to insert a custom code segment at a memory address to proxy the execution flow of network request and response functions;
[0130] Runtime unit, used to run custom code segments through independent memory areas.
[0131] Furthermore, in some embodiments, the data processing module 202 may specifically include:
[0132] A parsing unit, used to parse the input parameters of the network request and response function and extract the original traffic message;
[0133] The conversion unit is used to convert the original traffic messages into structured logs in a unified format and send them to the message queue for asynchronous processing.
[0134] Furthermore, in some embodiments, the risk identification module 203 may specifically include:
[0135] A loading unit, used to load a security audit rule base from a cache, where the rule base contains matching conditions based on regular expressions, scripting languages, or statistical features;
[0136] The matching unit is used to consume structured logs from the message queue, perform multi-dimensional feature matching on the structured logs through the security audit rule library according to the preset chain rule matching logic, generate threat events and store them in the threat event library;
[0137] The marking unit is used to mark the traffic data that triggers the threat event, marking the corresponding attack type and risk level.
[0138] Furthermore, in some embodiments, the preset chain rule matching logic includes:
[0139] Differentiate the traffic types of structured logs based on traffic type filtering rules;
[0140] At least one detection operation among keyword matching, parameter format verification, and behavior pattern analysis is performed in sequence based on the traffic type.
[0141] Furthermore, in some embodiments, the control module 204 may specifically include:
[0142] An instruction unit, configured to convert a risk control strategy corresponding to a threat event into a control instruction, wherein the control instruction includes at least one of a blocking request instruction, a response rewriting instruction, and a data desensitization instruction;
[0143] The modification unit is used to send control instructions to the target process through a reverse connection channel to dynamically modify the execution logic of the interception code according to the control instructions.
[0144] Furthermore, in some embodiments, the network traffic security audit and defense device may specifically include a risk identification model module, specifically configured to:
[0145] Integrate threat events and attack samples output by security detection tools into training datasets;
[0146] Use deep learning models to perform streaming learning on training datasets to generate risk identification models;
[0147] After the risk identification model is deployed as an online service, the risk identification model is used by the security audit rule engine to perform risk prediction and obtain risk prediction results.
[0148] In summary, the network traffic security audit and defense device provided by this embodiment can directly proxy network traffic in the process where the business system is located without changing the network deployment architecture by dynamically injecting interception code into the memory address of the target process; by converting request and response data into structured logs, the efficiency and accuracy of subsequent security audits can be effectively improved; by using the security audit rule engine to identify security risks in structured logs, potential threat events can be quickly detected, improving the real-time and effectiveness of security audits, and after detecting a threat event, control instructions can be issued to dynamically adjust the execution logic of the interception code, respond to security risks in a timely manner, and effectively protect the system from attacks. It can be seen that this embodiment provides a flexible, efficient, and real-time network traffic security audit and defense device that can perform in-depth monitoring and security protection of network traffic without affecting the normal operation of the business system.
[0149] To facilitate understanding of the network traffic security audit and defense method and device based on process injection provided in this embodiment, a network traffic security audit system is also provided in a specific embodiment. The system mainly includes an injection module, an instruction control module, a traffic capture module, and a traffic security identification module.
[0150] The instrumentation module is responsible for function memory addressing, function memory rewriting, injection, and exit. Instrumentation is performed at the routine level. Function-level instrumentation uses function symbol information to find the function's memory address and complete the instrumentation. After instrumentation is complete, network requests and responses triggered by the application call the instrumented function code; this code is stored in a separate memory area.
[0151] For the command control module, it is responsible for sending security defense instructions such as request interception and response data desensitization to the instrumentation module; it is responsible for sending instrumentation module entry and exit instructions to the instrumentation module; the command control module connects to the control end server in a reverse connection manner, and the control end service issues control instructions.
[0152] For the traffic capture module, the input parameters of the function are analyzed to extract the corresponding request or response traffic message parameters; after converting the obtained message parameters into structured logs, they are sent to the traffic security identification module for data security audit analysis.
[0153] For the traffic security identification module, it consumes the traffic data received from the traffic capture module and audits potential security analysis based on the security audit rule engine; for requests that have been identified as attacks, it sends control instructions to the control server, such as: blocking HTTP requests in the session for 1 minute; the control server load forwards the instruction control to the instrumentation module.
[0154] The following describes the implementation process of the network traffic security audit system. The instrumentation module injects code into the application process, locates and instruments functions through symbolic name queries, and completes the traffic capture code injection. This module receives command signals from the command control module and implements entry and exit, request interception, request rejection, and response rewriting control capabilities. The traffic capture module parses function input parameters and extracts the corresponding request data; after structuring the data format, it forwards it to the message queue. The consumption queue receives and consumes traffic data, allowing for repeated consumption in groups. The traffic security identification module consumes traffic data received from the traffic capture module and, based on the security audit rule engine and large-scale model identification, conducts audits and potential security analysis. For requests identified as attacks, it sends command control instructions to the control server. The control server receives and forwards the control instructions to the command control module. The command control module forwards the control instructions to the instrumentation module. This module sends entry and exit signals to the instrumentation module, as well as command signals for request interception and response data desensitization.
[0155] The security audit rule engine processes the following: loads the rule base from the cache and initiates each rule task; consumes data from the message queue in real time, decompresses the data, and restores it to an object structure. The data in the consumption queue is compressed and defined using protobuf. Data is distributed to all rules, with each rule executing a different matching expression. Expressions are matched using various methods, such as avatar, Groovy scripts, and regular expressions; threat events are generated; and each data stream entering the rule is matched against the conditional matching expressions defined in the rule through a chain matching method. Each conditional expression is represented using avatar, Groovy scripts, and regular expressions. For example, a rule defines two sets of matching conditions: Condition A and Condition B. Condition A determines whether the traffic type is a request; Condition B determines whether there are log4j injection attack keywords in the request payload; the chain matching method matches Condition A first, then matches Condition B; the rule generates a threat event through single feature matching; the rule combines multiple statistical features, including the number of requests per unit time greater than N, detecting whether the parameter value is a number, detecting whether the parameter value is enumerable, detecting whether the parameter value is random, detecting whether the payload contains special keywords, discovering sensitive types, discovering the 308 status code, and detecting whether the parameter value includes credentials.
[0156] In addition, this embodiment also provides a network traffic security audit and training method based on a closed loop of large modules and security detection tools. Data is queried from threat events generated by the rule engine and organized into training data; the data format complies with security risk classification and data packets; text reports exported from security detection tools are organized into training data; the data format complies with the question and answer model; training and evaluation are carried out using a large model pre-training method; the large model streaming service is released and run; the traffic security identification module loads the large model, performs risk judgment, and generates threat events.
[0157] In addition, the present invention also provides an electronic device, such as Figure 5 , which shows a schematic diagram of the structure of an electronic device involved in an embodiment of the present application. Specifically, the electronic device may include components such as a processor 301 with one or more processing cores, a memory 302 with one or more computer-readable storage media, a power supply 303, and an input unit 304. Those skilled in the art will understand that Figure 5 The electronic device structure shown in the figure does not constitute a limitation of the electronic device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange components differently.
[0158] The processor 301 is the control center of the electronic device. It connects all parts of the electronic device using various interfaces and lines. By running or executing software programs and / or modules stored in the memory 302 and accessing data stored in the memory 302, it performs various functions of the electronic device and processes data, thereby monitoring the electronic device as a whole. Optionally, the processor 301 may include one or more processing cores; preferably, the processor 301 may integrate an application processor and a modem processor, wherein the application processor primarily processes the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into the processor 301.
[0159] Memory 302 can be used to store software programs and modules. Processor 301 executes various functional applications and the process injection-based network traffic security audit and defense method by running the software programs and modules stored in memory 302. Memory 302 may primarily include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as sound playback or image playback); the data storage area may store data generated based on the use of the electronic device. Memory 302 may also include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, memory 302 may also include a memory controller to provide processor 301 with access to memory 302.
[0160] The electronic device also includes a power supply 303 for supplying power to various components. Preferably, the power supply 303 can be logically connected to the processor 301 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The power supply 303 can also include one or more DC or AC power supplies, a recharging system, a power failure detection circuit, a power converter or inverter, a power status indicator, and other arbitrary components.
[0161] The electronic device may further include an input unit 304, which may be configured to receive input digital or character information and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control.
[0162] Although not shown, the electronic device may further include a display unit, etc., which will not be described in detail here. Specifically, in this embodiment, the processor 301 in the electronic device will load the executable files corresponding to the processes of one or more application programs into the memory 302 according to the following instructions, and the processor 301 will run the application programs stored in the memory 302 to implement various functions as follows:
[0163] Determine the memory address of the target process's network request and response functions, and dynamically inject interception code into the memory address to proxy network traffic; capture the request and response data of the network traffic and convert it into structured logs; based on the predefined security audit rule engine, identify security risks in the structured logs and generate threat events; issue control instructions based on threat events, and dynamically adjust the execution logic of the interception code based on the control instructions to respond to security risks.
[0164] The specific implementation of the above operations can be found in the previous embodiments and will not be repeated here.
[0165] The embodiments of the present application dynamically inject interception code into the memory address of the target process, and can directly proxy network traffic in the process where the business system is located without changing the network deployment architecture; by converting request and response data into structured logs, the efficiency and accuracy of subsequent security audits can be effectively improved; by using the security audit rule engine to identify security risks in structured logs, potential threat events can be quickly detected, improving the real-time and effectiveness of security audits, and after detecting a threat event, control instructions are issued to dynamically adjust the execution logic of the interception code, respond to security risks in a timely manner, and effectively protect the system from attacks.
[0166] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments may be accomplished by instructions, or by controlling related hardware through instructions. The instructions may be stored in a computer-readable storage medium and loaded and executed by a processor.
[0167] To this end, an embodiment of the present application provides a storage medium storing a plurality of instructions that can be loaded by a processor to execute the steps of any of the network traffic security auditing and defense methods based on process injection provided in the embodiments of the present application. For example, the instructions can execute the following steps:
[0168] Determine the memory address of the target process's network request and response functions, and dynamically inject interception code into the memory address to proxy network traffic; capture the request and response data of the network traffic and convert it into structured logs; based on the predefined security audit rule engine, identify security risks in the structured logs and generate threat events; issue control instructions based on threat events, and dynamically adjust the execution logic of the interception code based on the control instructions to respond to security risks.
[0169] The specific implementation of the above operations can be found in the previous embodiments and will not be repeated here.
[0170] The storage medium may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. Since the instructions stored in the storage medium can execute the steps of any of the process injection-based network traffic security auditing and defense methods provided in the embodiments of the present application, the beneficial effects of any of the process injection-based network traffic security auditing and defense methods provided in the embodiments of the present application can be achieved. For details, please refer to the previous embodiments and will not be repeated here.
[0171] The above is a detailed introduction to a network traffic security audit and defense method based on process injection and related equipment provided in an embodiment of the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for technical personnel in this field, based on the ideas of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A network traffic security audit and defense method based on process injection, characterized in that: The steps include: Determine the memory addresses of the target process's network request and response functions, and dynamically inject interception code into the memory addresses to proxy network traffic; Capturing the request and response data of the network traffic and converting them into structured logs; Based on a predefined security audit rule engine, security risks are identified on the structured logs to generate threat events; issuing control instructions based on the threat event, and dynamically adjusting the execution logic of the interception code according to the control instructions to respond to the security risk; Integrate the threat events and attack samples output by the security detection tool into a training data set; Performing streaming learning on the training data set using a deep learning model to generate a risk identification model; After the risk identification model is deployed as an online service, the risk identification model is used by the security audit rule engine to perform risk prediction to obtain a risk prediction result.
2. The network traffic security audit and defense method based on process injection according to claim 1 is characterized in that: Determining the memory address of the network request and response function of the target process and dynamically injecting interception code into the memory address to proxy network traffic includes: Locating the memory addresses of the network request and response functions of the target process using the function symbol information of the target process; Inserting a custom code segment at the memory address to proxy the execution process of the network request and response function; The custom code segment is run through an independent memory area.
3. The network traffic security audit and defense method based on process injection according to claim 2 is characterized in that: The capture of the request and response data of the network traffic and conversion into structured logs includes: Parsing the input parameters of the network request and response function to extract the original traffic message; The original traffic message is converted into a structured log in a unified format and sent to a message queue for asynchronous processing.
4. The network traffic security audit and defense method based on process injection according to claim 3 is characterized in that: The predefined security audit rule engine is used to identify security risks on the structured logs and generate threat events, including: Loading a security audit rule base from a cache, wherein the rule base includes matching conditions based on regular expressions, scripting languages, or statistical features; Consuming the structured log from the message queue, performing multi-dimensional feature matching on the structured log through the security audit rule library according to a preset chain rule matching logic, generating a threat event and storing it in a threat event library; The traffic data that triggers the threat event is marked, and the corresponding attack type and risk level are marked.
5. The network traffic security audit and defense method based on process injection according to claim 4 is characterized in that: The preset chain rule matching logic includes: Distinguishing traffic types of the structured logs according to traffic type screening rules; At least one detection operation among keyword matching, parameter format verification, and behavior pattern analysis is performed in sequence based on the traffic type.
6. The network traffic security audit and defense method based on process injection according to claim 4 is characterized in that: The issuing of a control instruction according to the threat event, and dynamically adjusting the execution logic of the interception code according to the control instruction to respond to the security risk, includes: Converting the risk control strategy corresponding to the threat event into a control instruction, wherein the control instruction includes at least one of a blocking request instruction, a response rewriting instruction, and a data desensitization instruction; The control instruction is sent to the target process through a reverse connection channel, so as to dynamically modify the execution logic of the interception code according to the control instruction.
7. A network traffic security audit and defense device, characterized in that: include: A process injection module is used to determine the memory addresses of the target process's network request and response functions and dynamically inject interception code into the memory addresses to proxy network traffic; A data processing module, configured to capture the request and response data of the network traffic and convert them into structured logs; A risk identification module, configured to identify security risks on the structured logs based on a predefined security audit rule engine and generate threat events; A control module, configured to issue control instructions according to the threat event, and dynamically adjust the execution logic of the interception code according to the control instructions to respond to security risks; The risk identification model module is used to integrate threat events and attack samples output by security detection tools into a training dataset; Use deep learning models to perform streaming learning on training datasets to generate risk identification models; After the risk identification model is deployed as an online service, the risk identification model is used by the security audit rule engine to perform risk prediction and obtain risk prediction results.
8. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the process injection-based network traffic security audit and defense method according to any one of claims 1 to 6 are implemented.
9. A storage medium, characterized in that: The computer program storing the method for network traffic security audit and defense based on process injection according to any one of claims 1 to 6 can be loaded by a processor and executed.
Citation Information
Patent Citations
Transparent communication protection method and device for mobile application program
CN111132138A
Network protection and defense system
CN116405255A
High-level persistent threat-oriented digital substitute defense system design method and device
CN117978542A