Web application defense method based on webpage resource address dynamic hopping
By dynamically replacing the URL returned by the web server as a virtual URL and managing its usage count, combining redundant interfering nodes to simulate the behavior of real nodes, the problem of inability to block automated attacks in the existing technology is solved, and the security of web applications and the increase in attack costs are achieved.
Patent Information
- Application Number
- CN202510487967.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-07-04
AI Technical Summary
The existing technology cannot effectively block the continuous attacks of automated attack tools on web applications. Attackers find static URLs through brute force cracking or statistical analysis to launch an attack.
By dynamically replacing the URL returned by the web server as a virtual URL, managing the number of usage and survival time of the virtual URL, and deploying redundant interference nodes around key nodes to simulate the behavior of real nodes, realizing the hidden structure of the web application directory and dynamic changes in potential attack portals.
It realizes the hidden structure of the web application directory and the dynamic changes of potential attack portals, blocks attacks, improves the security of web applications, increases attack costs, and reduces the possibility of key nodes being attacked.
Smart Images

Figure CN120263502A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of URL defense, and particularly to a Web application defense method based on dynamic jump of web resource addresses. Background Art
[0002] A web resource address, namely URL (Universal Resource Locator), is a concise representation of the location and access method of resources that can be obtained from the Internet, and is the address of standard resources on the Internet. Each file on the Internet has a unique URL, which contains information indicating the location of the file and how the browser should handle it. By analyzing the URLs returned by a Web application, the directory structure and key technologies adopted by the Web application can be obtained, which helps attackers find potential attack points of the Web application. In addition, the URL is also the only way for the outside world to interact with the Web server, including obtaining resources on the Web server, submitting inputs and resources to the Web server, etc. In fact, the biggest threat faced by Web applications comes from external inputs. Currently, since the URLs of Web applications are static and unchangeable, attackers can easily use a specific URL as an attack entry, construct different malicious inputs to test whether the Web application has vulnerabilities and launch further attacks.
[0003] In the prior art, although there are some defense methods based on URL hiding, these methods are usually only implemented by simple URL replacement or encryption, and cannot change the URL dynamically. Attackers can still find the real URL through brute force cracking or statistical analysis. Therefore, the prior art cannot effectively block the continuous attacks of automated attack tools. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a Web application defense method based on dynamic jump of web resource addresses, which realizes the hiding of the Web application directory structure and the dynamic change of potential attack entries, blocks attacks, and ensures the security of the Web application.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions: A Web application defense method based on dynamic jump of web resource addresses, comprising the following steps:
[0006] Step 1: Dynamically replace the URL detected in the response returned by the Web server with a virtual URL;
[0007] Step 2: Manage the virtual URL pool, and the usage times and survival time of the virtual URLs are restricted and will automatically expire after exceeding the limit;
[0008] Step 3: Use an in-memory database to store the mapping relationship between virtual URLs and real URLs;
[0009] Step 4: Deploy redundant interference nodes around critical nodes to simulate the behavior of real nodes.
[0010] In a preferred embodiment, step 1 specifically includes:
[0011] Step 11: Obtain the response returned by the server;
[0012] Step 12: Obtain the URL to be replaced through web resource address detection technology;
[0013] Step 13: Determine whether the URL to be replaced is an absolute address;
[0014] Step 14: If the URL to be replaced is an absolute address, directly replace it with a virtual URL through dynamic replacement of web resource addresses; if the URL to be replaced is a relative address, first replace it with an absolute address through semantic analysis, and then obtain the virtual URL through dynamic replacement of web resource addresses; finally, set the available times of the virtual URL;
[0015] Step 15: Return the response containing the replaced virtual URL to the user;
[0016] Step 16: When receiving a request from the user to access a virtual URL, determine whether the requested virtual URL exceeds the set number of usage times;
[0017] Step 17: If the requested virtual URL does not exceed the set number of usage times, restore the virtual URL to the real URL and hand it over to the background server for processing; if the requested virtual URL exceeds the set number of usage times, reject the request.
[0018] In a preferred embodiment, step 2 specifically includes: URL virtualization needs to meet constraint conditions to ensure that normal functions are not disrupted and at the same time meet specified security requirements; use Ri to represent the minimum virtualization rate required for the uniform resource locator i, and the minimum virtualization rate is used to represent the probability that a certain URL is virtualized within a unit time; T is the security delay, indicating that after an interval of duration T, a certain virtual URL is reused, and any virtual URL that is alive within time T cannot be reused repeatedly. This constraint is expressed as:
[0019]
[0020] Among them, vurli ∈ T means that for a certain virtual URL, vurli is alive within the time interval T; formula (1) means that within a certain time interval T, each virtual URL appears at most once;
[0021] Let \(P_i\) denote the probability that resource \(i\) is accessed, and \(W\) denote the set of all website resources. Within the security delay \(T\), the number of resources accessed by a certain user on the entire website is expressed by the following formula:
[0022]
[0023] \(N_r\) is the number of real URLs accessed by a user within the security time interval \(T\); within the entire time interval \(T\), the number of virtual URLs required is calculated as:
[0024]
[0025] where \(N_v\) is the number of virtual URLs required within the security time interval \(T\); to meet the constraint conditions, the number of virtual URLs in the pre-allocated virtual URL pool must be much larger than the number of virtual URLs, and its constraint condition is expressed as:
[0026]
[0027] where \(N_{vpool}\) represents the capacity of the virtual URL pool; considering the existence of database garbage and the situation where virtual URLs cannot be recycled in a timely manner during operation, the above formula (4) represents the constraint conditions that the capacity of the virtual URL pool should meet.
[0028] In a preferred embodiment, step 3 specifically includes:
[0029] Step 31: Propose a URL dynamic virtualization security policy
[0030] Step 32: URL virtualization function design; the http request message is stored by Nginx, and the parameter information of the URL has been stripped; after taking out the URL from the structure, first query whether the URL exists; if it exists, it means that the URL requested by the user is a virtual URL, and the corresponding URL value is taken out; if it does not exist, it means that this is a real URL; when the number of uses is less than the maximum number of uses, increment its number of uses by 1 and update it back to the table; otherwise, it means that the virtual URL has reached the usage threshold, and this processing is directly exited; then the http request is sent to the security detection module; if the detection result shows that it is a normal http request, continue to use the default lifespan and number of uses without any processing; if the detection result is an uncertain http request threat, the security policy needs to be improved, that is, reduce the number of uses of the virtual URL; if the detection result is a malicious http request, then directly truncate the request message, do not respond, and then exit; for the first two detection results, the http request message needs to be reconstructed, replace the real URL with the original virtual URL, and then send it to the server;
[0031] Step 33: Function design of the URL filtering module; the URL filtering module processes the reverse data sent from the server to the client; for the web page information returned to the user, the entire web page source file needs to be traversed to extract the URLs therein, and then the qualified URLs are replaced with virtual URLs, and the http response message is reorganized and sent to the client;
[0032] Step 34: The movement mode of the virtual pool ensures that each virtual URL has an equal chance of corresponding to a certain real URL; attackers cannot estimate the correspondence of the current virtual URL through decryption or statistics; the interval between the use of each virtual URL and the last use is one entire movement cycle of the virtual URL pool; assuming that the daily throughput of the server is I, the movement cycle Tv of the virtual URL pool is estimated as
[0033]
[0034] In a preferred embodiment, step 4 specifically includes:
[0035] Step 41: Deploy multiple virtual mail servers and FTP servers around the database server;
[0036] Step 42: Collect samples, extract features, and conduct training and learning on the response data of various key nodes in the internal network, and construct a response traffic sample library consistent with real business behaviors to achieve a realistic simulation of the behaviors of real nodes;
[0037] Step 43: Replace the real key nodes with redundant interference nodes; identify the service types of sniffing packets; third, the redundant interference nodes forge response data packets of other different services to replace the key node responses, so that the key nodes present a mixed form to the attackers.
[0038] Compared with the prior art, the present invention has the following beneficial effects: Aiming at the characteristics that static URLs will expose the Web application directory structure and become attack entrances, combined with the dynamic idea of mimic defense, the dynamic jump technology of web page resource addresses is studied to keep the URLs in a constantly changing state, realize the hiding of the Web application directory structure and the dynamic change of potential attack entrances, block attacks, and ensure the security of Web applications. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 It is a schematic diagram of the mimic technology solution of the web page resource address of the preferred embodiment of the present invention;
[0040] Figure 2 It is a flow chart of the mimic technology of the web page resource address of the preferred embodiment of the present invention;
[0041] Figure 3 It is a system architecture diagram of the preferred embodiment of the present invention;
[0042] Figure 4 Flow chart of the URL virtualization module according to the preferred embodiment of the present invention;
[0043] Figure 5 Schematic diagram of the http response message recombination according to the preferred embodiment of the present invention;
[0044] Figure 6 Schematic diagram of the movement of the virtual URL pool according to the preferred embodiment of the present invention;
[0045] Figure 7 Deployment diagram of redundant interference nodes according to the preferred embodiment of the present invention. Detailed implementation manners
[0046] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0047] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which the present application belongs.
[0048] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary embodiments according to the present application; as used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0049] A Web application defense method based on dynamic jump of web resource addresses, referring to Figures 1-7 , including the following steps:
[0050] Step 1: Dynamically replace the URL in the response returned by the Web server with a virtual URL;
[0051] Step 2: Manage the virtual URL pool, where the usage times and survival time of the virtual URL are restricted and it will automatically become invalid after exceeding the limit;
[0052] Step 3: Use an in-memory database to store the mapping relationship between the virtual URL and the real URL;
[0053] Step 4: Deploy redundant interference nodes around the critical nodes to simulate the behavior of real nodes.
[0054] Specifically, the specific steps of Step 1 include:
[0055] (1) Web resource address detection
[0056] The web resource address detection traverses the responses returned by the web server and searches for , <link> Such tags as <link> are used to extract the URLs and wait for further processing.
[0057] (2) Dynamic replacement of web resource addresses
[0058] The dynamic replacement of web resource addresses adopts the method of retaining the domain name part in the URL and replacing the directory part and file name part in the URL with fixed-length strings, generating virtual URLs that can hide the directory structure and change over time.
[0059] However, in the currently deployed web applications, there are two cases for URLs: absolute addresses and relative addresses. When the URL to be replaced is an absolute address, it can be directly replaced with a virtual URL. When the URL to be replaced is a relative address, using the direct replacement method will result in an addressing error, affecting the normal business logic of the web application. The project plans to adopt a semantic analysis method, combined with the context of the web server's returned response, to convert the relative URL address into an absolute address, and finally use the direct replacement method to generate a virtual URL address.
[0060] For example Figure 1 As shown, by combining the web resource address detection technology and the web resource address dynamic replacement technology, a web resource address mimicry technology is generated to hide the directory structure of the web application and dynamically change potential attack entrances. The workflow of the web resource address mimicry is as Figure 2 shown, and the process description is as follows:
[0061] Step 11: Obtain the response returned by the server;
[0062] Step 12: Obtain the URL to be replaced through the web resource address detection technology;
[0063] Step 13: Determine whether the URL to be replaced is an absolute address;
[0064] Step 14: If the URL to be replaced is an absolute address, directly replace it with a virtual URL through the web resource address dynamic replacement; if the URL to be replaced is a relative address, first replace it with an absolute address through semantic analysis, and then obtain a virtual URL through the web resource address dynamic replacement; finally, set the available times of the virtual URL;
[0065] Step 15: Return the response containing the replaced virtual URL to the user;
[0066] Step 16: When receiving a request from the user to access the virtual URL, determine whether the requested virtual URL exceeds the set usage times;
[0067] Step 17: If the requested virtual URL does not exceed the set usage times, restore the virtual URL to the real URL and hand it over to the background server for processing; if the requested virtual URL exceeds the set usage times, reject the request.
[0068] Specifically, the said Step 2 specifically includes: The active defense technology aims to change the attack surface of the system, which is used to confuse or deceive opponents and increase the attack cost. All resources of the website are specified by URLs, and attackers launch attacks against specific URLs. After the real URL is randomly mapped into a virtual URL through URL virtualization, it is returned to the user. Since the virtual URL will change randomly, the old virtual URL is easily invalidated, and attackers can no longer launch attacks.
[0069] URL virtualization needs to meet the constraints to ensure that the normal functions are not disrupted and at the same time meet the specified security requirements; let Ri denote the minimum virtualization rate required for the uniform resource locator i, and the minimum virtualization rate is used to represent the probability that a certain URL is virtualized per unit time; T is the security delay, indicating that after the interval duration T, a certain virtual URL is reused, and any virtual URL that is alive within the time T cannot be reused repeatedly. This constraint is expressed as:
[0070]
[0071] Among them, vurli ∈ T means that for a certain virtual URL, vurli is alive within the time interval T; formula (1) means that within a certain time interval T, each virtual URL appears at most once;
[0072] Let Pi denote the probability that resource i is accessed, and W denote the set of all website resources. The number of resources accessed by a certain user for the entire website within the security delay T is expressed by the following formula:
[0073]
[0074] Nr is the number of real URLs accessed by a user within the security time interval T; within the entire time interval T, the number of virtual URLs required is calculated as:
[0075]
[0076] Among them, Nv is the number of virtual URLs required within the security time interval T; to meet the constraints, the number of virtual URLs in the pre-allocated virtual URL pool must be much larger than the number of virtual URLs, and its constraint is expressed as:
[0077]
[0078] Among them, Nvpool represents the capacity of the virtual URL pool; considering the existence of database garbage and the situation where virtual URLs cannot be recycled in a timely manner during operation, the above formula (4) represents the constraint that the capacity of the virtual URL pool should meet.
[0079] The processing of the database is closely related to the URL virtualization module. The real URLs and virtual URLs mentioned in the virtualization module are both stored in the database for easy processing. Considering that the data stored in the database (strings or string key-value pairs) is relatively simple, the in-memory database Redis is used to implement the storage function.
[0080] During the operation of the URL virtualization module, virtualization operations need to be performed on each newly discovered URL to generate corresponding virtual URLs. Considering the requirements of multi-concurrency and real-time response in actual applications, this process must consume as little time as possible. Therefore, a sufficient pre-allocated virtual URL pool is adopted. Each time a new virtual URL needs to be generated, a virtual URL is taken from the pool. To prevent the exhaustion of the virtual URL pool, each virtual URL is recycled into the virtual URL pool after its life cycle ends. This can ensure that the virtual URL pool will not be exhausted. The capacity of the virtual URL pool should be as large as possible under the allowable circumstances to prevent the frequent use of the same virtual URL.
[0081] Specifically, step 3 specifically includes:
[0082] The protection system is located between the gateway and the server. It processes the received server responses, replaces the real URLs in them with virtual URLs according to the security policy, and at the same time receives the requests from the client and replaces the virtual URLs in the requests with secure real URLs. Its location and architecture are as Figure 3 shown.
[0083] The URL virtualization function is divided into two parts. One is to process the http request data from the client to the server, which is called the URL module; the other is used to process the http response data returned by the server to the client, which is called the URL filtering module.
[0084] Step 31: Propose a URL dynamic virtualization security policy; To implement URL virtualization, it is not enough to simply replace real URLs with virtual URLs. The mapping relationship between the two remains unchanged, and this simple defense effect that only hides the resource path does not conform to the concept of increasing the attack cost in active defense. Therefore, each real URL needs to be dynamically corresponded to a virtual URL. The lifespan of a virtual URL is determined by two conditions: the number of uses and the survival time.
[0085] It is preset that a virtual URL can be used at most n times within a safe time interval T. After the virtual URL has been used the specified number of times, the system will recycle it, and at this time, no resources can be accessed by using this URL. This means that after an automated attack tool sends n attack messages for attempts, it can no longer carry out normal attacks.
[0086] For http requests with different security levels, different security policies should be available. The above has solved how to use URL random virtualization to increase the attack cost and resist automated attacks. The virtualization module provides two security policies according to the detection results of the security detection module:
[0087] 1) The detection result is safe, indicating no malicious injection. Considering that legitimate HTTP request messages in the form of password brute force cannot be detected by the security detection module, even if the detection result is safe, URL virtualization protection is still required. At this time, the security level is low, and the virtual URL can be used more times.
[0088] 2) The detection result is malicious. Under the condition that the HTTP request has been determined to be a malicious attack, URL virtualization security protection is not required. Using the powerful redirection function of Nginx, the malicious HTTP message is truncated and no longer responded to.
[0089] Step 32: URL virtualization function design; The virtualization module acts as a reverse proxy to intercept each HTTP request message. The algorithm flow of the URL module for processing forward data is as Figure 4 shown. The HTTP request message is stored by Nginx, and the parameters of the URL have been stripped; after retrieving the URL from the structure, first check whether the URL exists; if it exists, it means that the URL requested by the user is a virtual URL, and the corresponding URL value is retrieved; if it does not exist, it means that this is a real URL; when the number of uses is less than the maximum number of uses, increment its number of uses by 1 and update it back to the table; otherwise, it means that the virtual URL has reached the usage threshold, and directly exit the current processing; then send the HTTP request to the security detection module; if the detection result indicates a normal HTTP request, continue to use the default lifespan and number of uses without any processing; if the detection result is an uncertain HTTP request threat, the security policy needs to be improved, that is, reduce the number of uses of the virtual URL; if the detection result is a malicious HTTP request, then directly truncate the request message, do not respond, and then exit; for the first two detection results, the HTTP request message needs to be reconstructed, replace the real URL with the original virtual URL, and then send it to the server;
[0090] Step 33: Function design of the URL filtering module; the URL filtering module processes the reverse data sent from the server to the client; for the web page information returned to the user, the entire web page source file needs to be traversed to extract the URLs therein, and then the qualified URLs are replaced with virtual URLs, and the http response message is reorganized and sent to the client; there are various types of URLs in the web page source code, and it is very difficult to use only string comparison, so regular expressions are used to retrieve the URLs in the source code. The web page files are stored in a linked list of the ngx_chain_t type, and the data will be split into different parts. If all the web page files are taken out and concatenated each time for regular expression query, it will consume a large amount of memory. Instead, a part of the web page is taken out each time for URL query and reorganization, and then the next part is taken out, and finally a complete web page source file is reorganized. During the regular expression matching process, the http response message needs to be reorganized, as Figure 5 shown. Since the virtual URL cannot be inserted into the corresponding position, a buffer needs to be reallocated at this time. For each URL match, the data between the position at the end of the previously matched URL and the position at the beginning of the currently matched URL is taken out and spliced to the end of the http response message that is already being reorganized. For each group, the above operations are repeated, so that all qualified URLs within the group can be replaced with virtual URLs, a complete record is made in the database, and the reorganized http response message is sent to the client.
[0091] Step 34: The virtual URL pool needs to store a sufficient amount of virtual URLs, and the randomly generated MD5 hash value is used as the virtual URL. The storage order of the data in the virtual URL pool changes dynamically, and its corresponding relationship with the real URL is also random. Its recycling and use cause the data in the pool to move continuously in a certain direction, and the chance of each virtual URL being taken out is the same within a cycle of the pool. The movement of the virtual URL pool is as Figure 6 shown. The movement mode of the virtual pool ensures that each virtual URL has an equal chance of corresponding to a certain real URL; attackers cannot estimate the current corresponding relationship of the virtual URL through decryption or statistics; the interval between the use of each virtual URL and the last use is one entire movement cycle of the virtual URL pool; assuming that the daily throughput of the server is I, the movement cycle Tv of the virtual URL pool is estimated as
[0092]
[0093] Specifically, the said Step 4 specifically includes:
[0094] Nodes in the internal network that store key information or provide important services are often important targets for attackers to sniff and attack, such as mail servers and database servers. The protection of such nodes is particularly important. For attackers who have infiltrated the network, if they want to expand the attack surface and expand internal resources of the entire internal network, they must obtain relevant information about the internal network topology, core devices, and key service nodes through sniffing and other means. Therefore, using camouflage, hiding, and other means to protect key nodes during the attacker's sniffing phase can effectively cut off the attack chain and greatly reduce the possibility of key nodes being attacked.
[0095] To solve this problem, the key node mimicry hiding technology based on heterogeneous redundant interference is studied. Figure 7 As shown, this technology will use transition methods such as building a false network topology, deploying redundant interference nodes, false responses to node behaviors, and changing node behaviors to hide key nodes.
[0096] Step 41: Redundant interference nodes are virtual nodes deployed around key nodes to confuse attackers. These nodes can respond to network access or sniffing behaviors according to their attributes, thereby building multiple false targets for potential attackers near key nodes to hide key nodes. The interference modes of redundant interference nodes can be divided into two types: one is homogeneous redundant interference, which is to deploy multiple virtual nodes around key nodes with the same functions as key nodes but with different software or software versions. For example, deploy multiple virtual interference nodes that can simulate Oracle or Mysql 6.0 responses around a database server with Mysql 5.0 installed, making it difficult for attackers to determine the software environment that the vulnerability exploit relies on, and thus unable to carry out effective attacks; the other is heterogeneous redundant interference, which is to deploy multiple virtual nodes around key nodes with completely different functions from the key nodes, such as deploying multiple virtual mail servers, FTP servers, etc. around database servers, so as to achieve the purpose of diverting the attention of attackers.
[0097] Step 42: To prevent attackers from distinguishing virtual nodes from real nodes by observing the responses of each node, redundant interference nodes should be made to simulate the behavior of real nodes as much as possible to improve the hiding effect of key nodes. Therefore, the project proposes a false response method for redundant interference nodes, so that redundant interference nodes can implement realistic response behaviors. This technology will collect samples, extract features, and train and learn the response data of various key nodes in the internal network, build a response traffic sample library consistent with real business behaviors, and achieve realistic simulation of real node behaviors.
[0098] Step 43: When a large number of abnormal sniffing packets appear in the network, it indicates that the attacker may use an infected host as a springboard to conduct footprint reconnaissance on the internal nodes of the network. At this time, the camouflage and hiding of key nodes should be strengthened, and active defense should be implemented against potential attack behaviors. When abnormal sniffing packets are detected, the redundant interference node behavior transformation steps will be executed: First, replace the real key node with a redundant interference node; Second, identify the service type of the sniffing packet; Third, the redundant interference node forges other different service response packets to replace the key node response, so that the key node presents a mixed form to the attacker.
Claims
1. A Web application defense method based on dynamic jump of web resource addresses, characterized in that, It includes the following steps: Step 1: Dynamically replace the URL in the response returned by the Web server with a virtual URL; Step 2: Manage the virtual URL pool. The usage times and survival time of virtual URLs are restricted and will automatically become invalid after exceeding the limit; Step 3: Use an in-memory database to store the mapping relationship between virtual URLs and real URLs; Step 4: Deploy redundant interference nodes around key nodes to simulate the behavior of real nodes.
2. The Web application defense method based on dynamic jump of web resource addresses according to claim 1, characterized in that, The specific content of Step 1 includes: Step 11: Obtain the response returned by the server; Step 12: Obtain the URL to be replaced through web resource address detection technology; Step 13: Determine whether the URL to be replaced is an absolute address; Step 14: If the URL to be replaced is an absolute address, directly replace it with a virtual URL through dynamic replacement of web resource addresses; if the URL to be replaced is a relative address, first replace it with an absolute address through semantic analysis, and then obtain a virtual URL through dynamic replacement of web resource addresses; finally, set the available times of the virtual URL; Step 15: Return the response containing the replaced virtual URL to the user; Step 16: When receiving a request from the user to access a virtual URL, determine whether the requested virtual URL exceeds the set usage times; Step 17: If the requested virtual URL does not exceed the set usage times, restore the virtual URL to the real URL and hand it over to the background server for processing; if the requested virtual URL exceeds the set usage times, reject the request.
3. A Web application defense method based on dynamic jump of web resource addresses according to claim 1, characterized in that, The specific content of Step 2 includes: URL virtualization needs to meet the constraint conditions to ensure that the normal functions are not disrupted and at the same time meet the specified security requirements; use Ri to represent the minimum virtualization rate required for the uniform resource locator i. The minimum virtualization rate is used to represent the probability that a certain URL is virtualized within a unit time; T is the security delay, which means that after an interval of duration T, a certain virtual URL is reused, and any virtual URL that survives within time T cannot be reused repeatedly. This constraint is expressed as: Among them, vurli∈T means that for a certain virtual URL, vurli survives within the time interval T; formula (1) means that within a certain time interval T, each virtual URL appears at most once; Use Pi to represent the probability that resource i is accessed, and W represents the set of all website resources. The number of resources accessed by a certain user for the entire website within the security delay T is expressed by the following formula, Nr is the number of real URLs accessed by a user within the safe time interval T; within the entire time interval T, the number of virtual URLs required is calculated as: Among them, Nv is the number of virtual URLs required within the safe time interval T; in order to meet the constraint conditions, the number of virtual URLs in the pre-allocated virtual URL pool must be much larger than the number of virtual URLs, and its constraint condition is expressed as: Among them, Nvpool represents the capacity of the virtual URL pool; considering the database garbage existing during the operation process and the situation that virtual URLs cannot be recycled in time, the above formula (4) represents the constraint conditions that the capacity of the virtual URL pool should meet.
4. A Web application defense method based on dynamic jump of web resource addresses according to claim 1, characterized in that The specific content of Step 3 includes: Step 31: Propose the URL dynamic virtualization security policy Step 32: URL virtualization function design; The http request message is stored by Nginx, and the parameters of the URL have been stripped; After the URL is retrieved from the structure, first check whether the URL exists; If it exists, it means that the URL requested by the user is a virtual URL, and the corresponding URL value is retrieved; If it does not exist, it means that this is a real URL; When the usage times is less than the maximum usage times, increment its usage times by 1 and update it back to the table; Otherwise, it means that the virtual URL has reached the usage times threshold, and directly exit the current processing; Then send the http request to the security detection module; If the detection result shows that it is a normal http request, continue to use the default lifespan and usage times without any processing; If the detection result is an uncertain http request threat, the security policy needs to be improved, that is, reduce the usage times of the virtual URL; If the detection result is a malicious http request, then directly truncate the request message, do not respond, and then exit; For the first two detection results, the http request message needs to be reconstructed, replace the real URL with the original virtual URL, and then send it to the server; Step 33: URL filtering module function design; The URL filtering module processes the reverse data sent from the server to the client; For the web page information returned to the user, traverse the entire web page source file, extract the URLs in it, and then replace the qualified URLs with virtual URLs, reconstruct the http response message, and send it to the client; Step 34: The movement mode of the virtual pool ensures that each virtual URL has an equal chance of corresponding to a certain real URL; Attackers cannot estimate the correspondence of the current virtual URL through decryption or statistical methods; The virtual URL used each time is separated from the last use by a whole movement cycle of the virtual URL pool; Assume that the daily throughput of the server is I, then the movement cycle Tv of the virtual URL pool is estimated as 5. A Web application defense method based on dynamic jump of web resource addresses according to claim 1, characterized in that, The specific steps of step 4 include: Step 41: Deploy multiple virtual mail servers and FTP servers around the database server; Step 42: Collect samples, extract features, and train and learn the response data of various key nodes in the internal network, and build a response traffic sample library consistent with real business behaviors to achieve a realistic simulation of real node behaviors; Step 43: Replace the real key node with a redundant interference node; Identify the sniffing packet service type; Third, the redundant interference node forges other different service response data packets to replace the key node response, so that the key node presents a mixed form to the attacker.