Extranet newly-added interface discovery method and device, electronic equipment and storage medium

By obtaining access layer logs and using security interface data sets and dynamic filtering rules to identify new interfaces in the external network, the problem of low monitoring efficiency of new interfaces in the existing technology of Chinese and foreign networks is solved, and more efficient interface discovery and security monitoring are achieved.

CN120200805APending Publication Date: 2025-06-24DUXIAOMAN TECH (BEIJING) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510349860.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing technology is difficult to efficiently identify and monitor new interfaces in enterprise network security, and relies on manual sorting and automated scanning tools, and lacks unified means for monitoring.

Method used

By obtaining the access layer log, the interface information is matched and filtered based on the pre-set security interface data set and dynamic filtering rules, and new interfaces are identified and recorded on the external network.

Benefits of technology

It improves the discovery efficiency of new interfaces added to the external network, reduces the number of interfaces that need to be detected, reduces the dependence of manual monitoring, and enhances the automation and accuracy of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200805A_ABST
    Figure CN120200805A_ABST
Patent Text Reader

Abstract

The invention provides an external network newly-added interface discovery method and device. The invention discloses electronic equipment and a storage medium, and the method comprises the following steps: obtaining an access layer log, matching interface information contained in the access layer log based on a preset security interface data set, and screening out URL interface data which does not conform to the security interface data set; based on a preset dynamic filtering rule, filtering the URL interface data, and removing abnormal traffic interfaces to obtain candidate URL interface data; and if the candidate URL interface data does not exist in the security interface data set, determining that the candidate URL interface data is an external network newly-added interface. Since the access layer log records the interface information used in practical application, compared with a full-amount interface detection mode, the number of interfaces needing to be detected is reduced, the newly-added interface discovery efficiency is improved, and the interface information is filtered twice by using the preset security interface data set and the dynamic filtering rule, so that the detection efficiency is improved. The quantity of subsequent to-be-processed data is further reduced; and the newly-added interface discovery efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a method, device, electronic device and storage medium for discovering newly added external network interfaces. Background Art

[0002] An external network interface usually refers to a newly added connection point or channel in a server, network device or application program for communicating and interacting with an external network (such as the Internet). Since the external network interface is the first access object for external traffic and is very vulnerable to attacks, it is necessary to identify and monitor newly added external network interfaces in a timely manner.

[0003] In the monitoring of external network access interfaces in enterprise network security, the current common method is to manually sort through and uniformly audit the key code libraries of the external network to identify potential security threats. Such technologies mostly rely on manual screening and manual recording of the access frequencies of external network interfaces, and manually determine whether there are risks. In some enterprises, some automated scanning tools may be used to periodically detect static code library interfaces. In addition, for newly added code libraries on the external network, enterprises currently do not have a unified means of monitoring. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide a method, device, electronic device and storage medium for discovering newly added external network interfaces to improve the discovery efficiency of newly added external network interfaces.

[0005] According to one aspect of the present invention, there is provided a method for discovering newly added external network interfaces, the method comprising:

[0006] Obtain access layer logs, and store the data set of the access layer logs in local storage;

[0007] Match each interface information included in the access layer logs based on a pre-set security interface data set, and filter out URL interface data that does not conform to the security interface data set; the security interface data set includes interface information that is already under security monitoring;

[0008] Filter each of the URL interface data based on a preset dynamic filtering rule, and eliminate abnormal traffic interfaces to obtain candidate URL interface data;

[0009] Determine whether the candidate URL interface data exists in the security interface data set, and if not, record the candidate URL interface as a newly added external network interface.

[0010] In a possible embodiment, when the candidate URL interface data is in the secure interface data set, the candidate URL interface data is added to the access frequency record interface data set, and the access frequency record interface data set is used to store interface information that needs to be monitored for access frequency.

[0011] In a possible embodiment, the method further includes: when the access frequency of the candidate URL interface is higher than a preset threshold, sending the candidate URL interface data to a target client so that the target client performs a security audit on the candidate URL interface data.

[0012] In a possible embodiment, the matching based on the secure interface data set includes:

[0013] Setting a regular matching pattern based on each interface information included in the secure interface data set;

[0014] Matching the access layer logs based on the regular matching pattern to obtain each URL interface information that does not conform to the regular matching pattern.

[0015] In a possible embodiment, the preset dynamic filtering rules include static file filtering, short link filtering, pure digital path filtering, front-end request filtering, and external network scan filtering. Based on the preset dynamic filtering rules, filtering each of the URL interface data to eliminate abnormal traffic interfaces and obtain candidate URL interface data includes:

[0016] Filtering each of the URL interfaces using the preset dynamic filtering rules to obtain abnormal traffic interfaces corresponding to abnormal traffic. The abnormal traffic interfaces are test interfaces generated during a traffic attack, and the test interfaces do not belong to actual back-end interfaces;

[0017] Eliminating the abnormal traffic interfaces to obtain candidate URL interface data.

[0018] In a possible embodiment, the method further includes: when abnormal traffic is detected based on the preset dynamic filtering rules, sending the abnormal traffic to a preset instant alarm center to give an instant alarm for the abnormal traffic.

[0019] According to another aspect of the present invention, there is provided an external network new interface discovery device, and the device includes:

[0020] An acquisition module, configured to acquire access layer logs and store a data set of the access layer logs in local storage;

[0021] A matching module, configured to match each interface information included in the access layer log based on a preset security interface data set, and filter out URL interface data that does not conform to the security interface data set; the security interface data set includes interface information that is already under security monitoring;

[0022] A filtering module, configured to filter each of the URL interface data based on a preset dynamic filtering rule, eliminate abnormal traffic interfaces, and obtain candidate URL interface data;

[0023] A determining module, configured to determine whether the candidate URL interface data exists in the security interface data set. If not, record the candidate URL as a newly added external network interface.

[0024] In a possible embodiment, the determining module is further configured to, when the candidate URL is in the security interface data set, add the candidate URL to an access frequency record interface data set, and the access frequency record interface data set is used to store interface information that needs to be monitored for access frequency;

[0025] When the access frequency of the candidate URL is higher than a preset threshold, send the candidate URL interface data to a target client, so that the target client performs a security audit on the candidate URL interface data;

[0026] The matching based on the security interface data set includes:

[0027] Set a regular expression matching pattern based on each interface information included in the security interface data set;

[0028] Match the access layer log based on the regular expression matching pattern, and obtain each URL interface information that does not conform to the regular expression matching pattern;

[0029] The preset dynamic filtering rule includes static file filtering, short link filtering, pure digital path filtering, front-end request filtering, and external network scanning filtering. The filtering each of the URL interface data based on the preset dynamic filtering rule, eliminating abnormal traffic interfaces, and obtaining candidate URL interface data includes:

[0030] Filter each of the URL interfaces by using the preset dynamic filtering rule to obtain abnormal traffic interfaces corresponding to abnormal traffic. The abnormal traffic interfaces are test interfaces generated during a traffic attack, and the test interfaces do not belong to actual backend interfaces;

[0031] Eliminate the abnormal traffic interfaces to obtain candidate URL interface data;

[0032] In the case where abnormal traffic is detected based on the preset dynamic filtering rules, send the abnormal traffic to a preset instant alarm center to give an instant alarm for the abnormal traffic.

[0033] According to another aspect of the present invention, there is provided an electronic device, including:

[0034] a processor; and

[0035] a memory storing a program,

[0036] wherein, the program includes instructions which, when executed by the processor, cause the processor to execute any one of the above-mentioned methods for discovering new external network interfaces.

[0037] According to another aspect of the present invention, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute any one of the above-mentioned methods for discovering new external network interfaces.

[0038] In one or more technical solutions provided in the embodiments of the present invention, by screening for new interfaces based on access layer log data, since the access layer logs record the access traffic in actual applications, that is, the interface information used in actual applications is included. Compared with the full-scale interface detection method of static code, the number of interfaces to be detected is greatly reduced, which improves the efficiency of discovering new interfaces to a certain extent. Furthermore, by using a preset secure interface data set and dynamic filtering rules to filter the interface information twice, the amount of data to be processed subsequently is further reduced, further improving the efficiency of discovering new interfaces. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In the following description of exemplary embodiments with reference to the accompanying drawings, more details, features and advantages of the present invention are disclosed. In the drawings:

[0040] Figure 1 is a flowchart showing a method for discovering new external network interfaces provided by an embodiment of the present invention;

[0041] Figure 2 is another flowchart showing a method for discovering new external network interfaces provided by an embodiment of the present invention;

[0042] Figure 3 is a schematic logical structure diagram of a device for discovering new external network interfaces provided by an embodiment of the present invention;

[0043] Figure 4 shows a block diagram of the structure of an exemplary electronic device that can be used to implement the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] Embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.

[0045] It should be understood that the various steps recited in the method embodiments of the present invention can be executed in a different order and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.

[0046] The term "including" and its variants used herein are open-ended, that is, "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order of the functions executed by these devices, modules or units or their interdependent relationships.

[0047] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0048] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0049] To improve the efficiency of discovering newly added interfaces, embodiments of the present invention provide a method, apparatus, electronic device, and storage medium for discovering newly added interfaces on the external network. The method for discovering newly added interfaces provided by the embodiments of the present invention can be applied to any electronic device with the function of discovering newly added interfaces. The electronic device can be a server, a computer, a mobile terminal, etc. In a possible embodiment, the method for discovering newly added interfaces provided by the embodiments of the present invention can be applied to a distributed cluster to discover newly added interfaces in the distributed cluster. The solution of the present invention will be described below with reference to the accompanying drawings:

[0050] Figure 1 A flowchart of a method for discovering newly added interfaces provided by an embodiment of the present invention may include the following steps:

[0051] S101. Obtain the access layer logs and store the dataset of the access layer logs in the local storage;

[0052] S102. Match each interface information included in the access layer logs based on a pre-set security interface dataset, and filter out the URL interface data that does not conform to the security interface dataset; the security interface dataset includes interface information that is already under security monitoring;

[0053] S103. Filter each of the URL interface data based on a preset dynamic filtering rule, eliminate abnormal traffic interfaces, and obtain candidate URL interface data;

[0054] S104. Determine whether the candidate URL interface data exists in the security interface dataset. If not, record the candidate URL interface as a newly added external network interface.

[0055] Applying the embodiments of the present invention, by screening for newly added interfaces based on access layer log data, since the access layer logs record the access traffic in actual applications, that is, it includes the interface information used in actual applications. Compared with the full-volume interface detection method of static code, the number of interfaces to be detected is greatly reduced, which improves the discovery efficiency of newly added interfaces to a certain extent. Moreover, by using the pre-set security interface dataset and dynamic filtering rules to filter the interface information twice, the amount of data to be processed subsequently is further reduced, further improving the discovery efficiency of newly added interfaces.

[0056] The following is an exemplary description of the above S101 - S104:

[0057] The above access layer logs are used to record various traffic information of the access cluster. This traffic information may include visitor information, information of the target interface being accessed, access time, response results, etc. The above visitor information may be the IP address of the visitor, and the information of the target interface may include the name of the target interface, IP address, etc. In a possible embodiment, the above access traffic can be divided into different groups according to the time period in which the access time is located. Exemplarily, when processing requests, the requests to be processed can be divided by a timing task scheduler according to the time period, and the requests in the same time period are sent to a coroutine pool, which contains multiple coroutines, so that the multiple coroutines concurrently execute multiple requests in the same time period. The above time period can be divided according to the actual application scenario, such as dividing the time period every 15 minutes, 5 minutes, etc. By processing requests in parallel, the output efficiency of the access layer logs is improved, and thus the discovery efficiency of subsequent newly added interfaces is improved.

[0058] In a possible embodiment, during the process of concurrent processing of requests by coroutines, the coroutines can detect the target interfaces included in the requests based on a preset security interface dataset, and determine the target interfaces that do not belong to the security interface dataset. The above security interface dataset contains interface data that has already been in a security monitoring state within the enterprise. The above security monitoring state can include monitoring traffic data for the interfaces, monitoring the access frequency of the interfaces, etc. The above security interface dataset can include various types of interfaces, such as Java interfaces, PHP interfaces, Go interfaces, etc.

[0059] As a possible implementation, interface rules can be generated based on the formats of the interfaces included in the security interface dataset. Exemplarily, corresponding regular matching expressions can be generated based on the formats of the interfaces. Specifically, the regular matching expressions can be set based on the names of the interfaces in the security interface dataset or the method keywords used by the interfaces, etc. During the process of concurrent processing of requests by coroutines, after extracting the target interface information included in the requests, the coroutines can match each target interface information based on the above regular matching expressions, and eliminate the target interfaces that match successfully, obtaining the filtered target interfaces. The above successful matching means that the name or the included keywords of the target interface are the same as the interfaces in the security interface dataset. Eliminating the target interfaces that match successfully means removing the interfaces in the security monitoring dataset from the access traffic. In this way, the interfaces that have already been in a security monitoring state are deleted from the interface information that needs to be processed subsequently, avoiding further processing of these interfaces later, reducing the data processing volume, and improving the discovery efficiency of new interfaces.

[0060] In a possible embodiment, the above regular matching rules can be generated using a dynamic rule generator. Exemplarily, the dynamic rule generator can call a preset API interface, obtain the security interface dataset through this API interface, and generate the above regular matching rules based on the interface data included in the security interface data.

[0061] In a possible embodiment, the above target interface can be a URL (uniform resource locator) interface. URLs are used to uniquely identify and locate resources on the network. In practical applications, the client sends requests containing URLs to the server to obtain or operate on the corresponding resources. Correspondingly, the URL interface information included in the requests can be extracted and regular matching can be performed on this URL interface information, thereby obtaining URL interface data that does not conform to the regular matching expression.

[0062] In a possible embodiment, access layer logs can be obtained through a second preset API and stored in a local temporary storage pool, which can be a feasible storage medium such as memory storage, disk cache, or object storage. Correspondingly, URL interfaces that do not conform to the regular matching rules can be obtained from the local temporary storage pool through the above regular matching rules.

[0063] In a possible embodiment, after obtaining the URL interface data, it can be further filtered based on a preset dynamic rule. The preset dynamic filtering rule is used to filter invalid interface data in the URL interface data, and its specific content can be set according to the actual application scenario. As a possible implementation, the preset dynamic rule may include static file filtering, short link filtering, pure number path filtering, front-end request filtering, external network scan traffic filtering, etc. Among them, the static file filtering rule can filter access traffic for the static file directory, which can be the directory where files that are not allowed to be accessed externally are located. Since this directory is not allowed to be accessed, the URL interfaces for this directory are not new interfaces. By using the static file filtering rule to filter the interfaces for this static file directory, the processing of redundant interfaces can be reduced.

[0064] Short link filtering is to detect and process short links that appear in the network. It can identify and intercept short links that may contain malicious software, phishing websites, false information and other bad content. As a possible implementation, a short link blacklist can be established based on historical access traffic, which can include historical abnormal access requests. Then, the URL interface data can be filtered based on this short link blacklist, thereby filtering the URL interface data corresponding to abnormal access requests.

[0065] Pure number path filtering refers to screening the part of the URL path that consists only of numbers. In practical applications, in order to prevent users from illegally obtaining data by guessing digital IDs, the digital part of the access path is verified. Only digital IDs that conform to certain rules can normally access the corresponding page or resource, and these pure number paths may not belong to the paths in the cluster. Therefore, these paths can be filtered.

[0066] Front-end request filtering refers to adding request filtering logic in the front-end code. Exemplarily, a request interceptor can be integrated in the front-end code. For example, an authentication link can be added to preprocess the request to reduce the impact of irrelevant traffic on the discovery of new interfaces.

[0067] External network scanning traffic generally refers to the traffic generated by external-initiated port scanning, vulnerability detection, and other behaviors on the target network to which the cluster belongs. The external network scanning traffic may include interfaces that do not belong to the cluster. Therefore, the external network scanning traffic can be identified, and the URL interfaces included in the traffic can be excluded.

[0068] In a possible embodiment, when abnormal traffic is detected based on the preset dynamic filtering rule, the abnormal traffic can be sent to a preset instant alarm center to give an instant alarm for the abnormal traffic.

[0069] The above abnormal traffic can be scanning attack traffic, traffic with an abnormal status indicated by the status code, etc. For example, it can be traffic with a status code of 302 and a location (address) of a 404 page. After detecting the abnormal traffic, the corresponding traffic data can be sent to the instant alarm center, and the instant alarm center can send the alarm data corresponding to the abnormal traffic to a preset user through a preset alarm method. The above preset alarm method and preset user can be preset for different types of abnormal traffic. Exemplarily, the above alarm methods can include email, push, instant messaging, or generating a work order, etc. The above alarm data can include traffic data corresponding to the abnormal traffic, abnormal types, etc.

[0070] Through the above technical means, the URL interface is further filtered by the preset dynamic filtering rule to obtain the filtered URL interface data, further reducing the amount of data to be processed subsequently and improving the discovery efficiency of newly added interfaces subsequently.

[0071] In a possible embodiment, after obtaining the filtered candidate URL interface data, the candidate URL interface data can be matched one by one with the interface information included in the above security interface dataset to determine whether the candidate URL interface data exists in the security interface dataset. If not, it can be determined that the candidate URL interface data is a newly added interface on the external network; if the candidate URL exists in the security interface dataset, the candidate URL can be added to the access frequency record interface dataset, and the access frequency record interface dataset is used to store the interface information that needs to be monitored for access frequency.

[0072] In a possible embodiment, if the URL interface data belongs to the security interface dataset, it means that the URL interface data is not a newly added interface. However, since the interface is not recognized based on the regular matching rule, it indicates that the traffic for this interface may be difficult to analyze. Therefore, the monitoring of this interface can be enhanced. For example, the access frequency of this interface can be recorded to instantly discover abnormal traffic for this interface.

[0073] If the URL interface does not belong to the secure interface dataset, it indicates that the URL interface is a newly added external network interface. Therefore, this newly added external network interface can be added to the newly added external network interface dataset, and the interface can be sent to the real-time alarm center. Newly added external network interfaces usually refer to the newly added connection points or channels in servers, network devices, or applications to communicate and interact with external networks (such as the Internet). Timely alarming of newly added external network interfaces helps maintain network security.

[0074] At the same time, frequency monitoring can be added for this newly added external network interface, that is, monitor the access frequency of this newly added external network interface, so as to perform operation and maintenance on this newly added external network interface in a timely manner.

[0075] In a possible embodiment, when the access frequency of the candidate URL is higher than the preset threshold, the candidate URL interface data is sent to the target client, so that the target client can perform a security audit on the candidate URL interface data.

[0076] As a possible implementation method, a security operation center (SOC) can be pre-built in an enterprise. When it is detected that an interface needs to be security audited, the interface data can be sent to this security operation center, and the security operation center performs a security audit on this interface. Exemplarily, the security operation center can analyze this interface to perform risk assessment, early warning, etc. on this interface.

[0077] As Figure 2 shown, Figure 2 Another flowchart of the newly added interface discovery method provided by the embodiment of the present invention may include the following steps:

[0078] S201. The pre-configuration loads the local cookie.

[0079] Exemplarily, through pre-setting and initialization operations, the Cookie information stored locally can be loaded into the current application environment. This cookie information contains preset configurations, such as domain names, security flags, etc., to improve data communication security.

[0080] S202. Through a timing tasker, distribute the requests received in different time periods to the coroutine pool, so as to process the requests received within the same time period through each coroutine included in the coroutine pool.

[0081] S203. Each coroutine calls the dynamic rule generator, obtains the interface data included in the secure interface dataset through a preset API, and generates dynamic rules based on each interface data.

[0082] Exemplarily, the existing interface data in the enterprise can be obtained from the database through a preset API. The existing interface data in the enterprise is the interface data that has already been in a security monitoring state. For each interface data included in the security dataset, a regular expression can be created based on the name of the interface, the method applied by the interface, etc.

[0083] S204. The dynamic rule generator obtains the access layer log dataset through a second preset API and stores the interface data included in the access layer log dataset in the local temporary storage pool.

[0084] S205. Use the dynamic rule to match each interface included in the local temporary storage pool to obtain the URL interface data included in the access layer dataset.

[0085] S206. Filter the extracted URL interface data using a preset dynamic rule.

[0086] The preset dynamic rule may include static file filtering, short link filtering, pure digital path filtering, front-end request filtering, external network scanning traffic filtering, etc. Filtering the URL interface data through the preset dynamic rule can identify the abnormal traffic included in the URL interface data. The abnormal traffic may include the traffic of scanning attacks, the status code is 302 and the location (address) is the 404 page, etc.

[0087] S207. When abnormal traffic is detected, send the abnormal access traffic to the instant alarm center to send an instant alarm message for the abnormal traffic through the instant alarm center.

[0088] S208. Determine whether the filtered interface belongs to the secure interface dataset, that is, determine whether the filtered interface has already been in a security monitoring state. If not, record the newly added code library on the external network, that is, determine that the interface is a newly added interface on the external network, and send the interface to the instant alarm center. If the filtered interface belongs to the secure interface dataset, execute S209.

[0089] S209. Automatically increase the interface access frequency. Specifically, the access frequency of the interface can be monitored.

[0090] S210. Determine whether the interface needs to be security audited through a preset rule. If it needs to be security audited, the interface data can be sent to the security operation platform for relevant personnel to conduct a security audit on the interface. If security audit is not required, the process ends.

[0091] The above preset rule may be an access frequency rule, that is, if the access frequency of the interface exceeds the preset threshold, it is determined that the interface needs to be security audited.

[0092] Applying the embodiments of the present invention, for the automated interface comparison and tracking based on access layer logs, by comparing the external network access interfaces in the access layer logs with the interfaces in the existing known code library in real time, unknown interfaces can be automatically identified and saved, and dynamic tracking can be performed on the newly added or frequently accessed external network interfaces. This can not only quickly discover the newly added code libraries and interfaces on the external network, but also effectively monitor the abnormal access behaviors of external network interfaces, timely capture potential security threats, and significantly improve the automation and accuracy of security audits.

[0093] In addition, this solution can be deeply integrated with the existing security audit processes of enterprises, automate the monitoring and auditing of external network access interfaces, reduce the dependence on manual operations, and improve the overall security monitoring efficiency and coverage.

[0094] Based on the same inventive concept, the embodiments of the present invention also provide a device for discovering newly added external network interfaces, as Figure 3 shown. The device 300 may include:

[0095] An acquisition module 301, configured to acquire access layer logs and store the data set of the access layer logs in local storage;

[0096] A matching module 302, configured to match each interface information included in the access layer logs based on a preset security interface data set, and filter out URL interface data that does not conform to the security interface data set; the security interface data set includes interface information that has been under security monitoring;

[0097] A filtering module 303, configured to filter each of the URL interface data based on a preset dynamic filtering rule, eliminate abnormal traffic interfaces, and obtain candidate URL interface data;

[0098] A determination module 304, configured to determine whether the candidate URL interface data exists in the security interface data set. If not, record the candidate URL interface as a newly added external network interface.

[0099] In a possible embodiment, the determination module is further configured to, when the candidate URL is in the security interface data set, add the candidate URL to the access frequency record interface data set, and the access frequency record interface data set is used to store interface information that needs to be monitored for access frequency;

[0100] When the access frequency of the candidate URL is higher than a preset threshold, send the candidate URL interface data to a target client, so that the target client performs a security audit on the candidate URL interface data;

[0101] The matching based on the security interface data set includes:

[0102] Set a regular expression pattern based on each interface information included in the security interface dataset;

[0103] Match the access layer logs based on the regular expression pattern to obtain each URL interface information that does not conform to the regular expression pattern;

[0104] The preset dynamic filtering rules include static file filtering, short link filtering, pure digital path filtering, front-end request filtering, and external network scanning filtering. Based on the preset dynamic filtering rules, filter each of the URL interface data, eliminate abnormal traffic interfaces, and obtain candidate URL interface data, including:

[0105] Use the preset dynamic filtering rules to filter each of the URL interfaces to obtain abnormal traffic interfaces corresponding to abnormal traffic. The abnormal traffic interfaces are test interfaces generated during the traffic attack process, and the test interfaces do not belong to the actual back-end interfaces;

[0106] Eliminate the abnormal traffic interfaces to obtain candidate URL interface data;

[0107] In the case of detecting abnormal traffic based on the preset dynamic filtering rules, send the abnormal traffic to a preset instant warning center to give an instant warning for the abnormal traffic.

[0108] Among them, in the present invention, the collection, storage, use, processing, transmission, provision, and disclosure of user personal information and other processes all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0109] An exemplary embodiment of the present invention further provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program that can be executed by the at least one processor, and when the computer program is executed by the at least one processor, it is used to cause the electronic device to execute the method according to the embodiment of the present invention.

[0110] An exemplary embodiment of the present invention further provides a non-transitory computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the method according to the embodiment of the present invention.

[0111] An exemplary embodiment of the present invention further provides a computer program product, including a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the method according to the embodiment of the present invention.

[0112] Reference Figure 4, a block diagram of an electronic device 400 that can be a server or a client of the present invention will now be described. It is an example of a hardware device that can be applied to various aspects of the present invention. The electronic device is intended to represent various forms of digital electronic computer devices, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0113] As Figure 4 shown, the electronic device 400 includes a computing unit 401, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 402 or a computer program loaded from a storage unit 408 into a random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the electronic device 400 can also be stored. The computing unit 401, the ROM 402, and the RAM 403 are connected to each other via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0114] A plurality of components in the electronic device 400 are connected to the I / O interface 405, including: an input unit 406, an output unit 407, a storage unit 408, and a communication unit 409. The input unit 406 can be any type of device that can input information into the electronic device 400. The input unit 406 can receive input digital or character information, and generate key signal inputs related to the user settings and / or function controls of the electronic device. The output unit 407 can be any type of device that can present information, and can include but is not limited to a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 408 can include but is not limited to magnetic disks, optical disks. The communication unit 409 allows the electronic device 400 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks, and can include but is not limited to a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a BluetoothTM device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.

[0115] The computing unit 401 may be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 401 executes the various methods and processes described above. For example, in some embodiments, any of the above-described methods for discovering new external network interfaces may be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 408. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 400 via the ROM 402 and / or the communication unit 409. In some embodiments, the computing unit 401 may be configured to execute any of the above-described methods for discovering new external network interfaces in any other suitable manner (e.g., by means of firmware).

[0116] The program code for implementing the method of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to the processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0117] In the context of the present invention, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0118] As used in this invention, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., a magnetic disk, an optical disk, a memory, a programmable logic device (PLD)) used to provide machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.

[0119] In order to provide an interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide an interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0120] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0121] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other.

Claims

1. A method for discovering a newly added interface in an external network, characterized in that: The method comprises: Obtain access layer logs, and store the data set of the access layer logs in local storage; Matching each interface information contained in the access layer log based on a preset security interface data set, and filtering out URL interface data that does not conform to the security interface data set; the security interface data set includes interface information that is already under security monitoring; Based on the preset dynamic filtering rules, the URL interface data is filtered to remove abnormal traffic interfaces and obtain candidate URL interface data; Determine whether the candidate URL interface data exists in the security interface data set; if not, record the candidate URL interface as a newly added interface on the external network.

2. The method according to claim 1, characterized in that In the case where the candidate URL interface data is in the security interface data set, the candidate URL interface data is added to an access frequency record interface data set, where the access frequency record interface data set is used to store interface information that needs to be monitored for access frequency.

3. The method according to claim 2, characterized in that The method further comprises: When the access frequency of the candidate URL interface is higher than a preset threshold, the candidate URL interface data is sent to a target client, so that the target client performs a security audit on the candidate URL interface data.

4. The method according to claim 1, characterized in that The matching of each interface information contained in the access layer log based on the preset security interface data set to filter out URL interface data that does not conform to the security interface data set includes: Setting a regular matching formula based on each interface information contained in the security interface data set; The access layer log is matched based on the regular matching formula to obtain each URL interface information that does not meet the regular matching formula.

5. The method according to claim 1, characterized in that The preset dynamic filtering rules include static file filtering, short link filtering, pure digital path filtering, front-end request filtering and external network scanning filtering. Based on the preset dynamic filtering rules, each of the URL interface data is filtered to remove abnormal traffic interfaces to obtain candidate URL interface data, including: Filter each of the URL interfaces using the preset dynamic filtering rule to obtain an abnormal traffic interface corresponding to the abnormal traffic, wherein the abnormal traffic interface is a test interface generated during the traffic attack process, and the test interface does not belong to the actual backend interface; The abnormal traffic interface is eliminated to obtain candidate URL interface data.

6. The method according to claim 5, characterized in that The method further comprises: When abnormal traffic is detected based on the preset dynamic filtering rule, the abnormal traffic is sent to a preset instant alarm center to issue an instant alarm for the abnormal traffic.

7. A device for discovering a newly added interface in an external network, characterized in that: The device comprises: An acquisition module, used to acquire access layer logs and store the data set of the access layer logs in local storage; A matching module, for matching each interface information contained in the access layer log based on a preset security interface data set, and filtering out URL interface data that does not match the security interface data set; the security interface data set includes interface information that is already under security monitoring; A filtering module, used to filter the URL interface data based on preset dynamic filtering rules, remove abnormal traffic interfaces, and obtain candidate URL interface data; The determination module is used to determine whether the candidate URL interface data exists in the security interface data set. If not, the candidate URL interface is recorded as a newly added interface in the external network.

8. The device according to claim 7, characterized in that The determination module is further configured to add the candidate URL interface data to an access frequency record interface data set when the candidate URL interface data is in the security interface data set, wherein the access frequency record interface data set is used to store interface information that needs to be monitored for access frequency; When the access frequency of the candidate URL interface is higher than a preset threshold, the candidate URL interface data is sent to a target client, so that the target client performs a security audit on the candidate URL interface data; The matching based on the security interface data set includes: Setting a regular matching formula based on each interface information contained in the security interface data set; Matching the access layer log based on the regular matching formula to obtain each URL interface information that does not match the regular matching formula; The preset dynamic filtering rules include static file filtering, short link filtering, pure digital path filtering, front-end request filtering and external network scanning filtering. Based on the preset dynamic filtering rules, each of the URL interface data is filtered to remove abnormal traffic interfaces to obtain candidate URL interface data, including: Filter each of the URL interfaces using the preset dynamic filtering rule to obtain an abnormal traffic interface corresponding to the abnormal traffic, wherein the abnormal traffic interface is a test interface generated during the traffic attack process, and the test interface does not belong to the actual backend interface; Eliminate the abnormal traffic interface to obtain candidate URL interface data; When abnormal traffic is detected based on the preset dynamic filtering rule, the abnormal traffic is sent to a preset instant alarm center to issue an instant alarm for the abnormal traffic.

9. An electronic device, comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, cause the processor to perform the method according to any one of claims 1 to 6.

10. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to make a computer execute the method according to any one of claims 1-6.