Network data detection method and device, computer equipment and readable storage medium
The method improves SQL injection attack detection accuracy by using symbol sequence analysis and AI models to filter and analyze binary data streams, reducing false positives and enhancing user experience.
Patent Information
- Application Number
- CN202510709612.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-07-15
AI Technical Summary
In the prior art, SQL injection attack identification methods have low accuracy, especially when processing binary flows, it is prone to false positives, affecting user experience and business continuity.
By obtaining the symbol sequence of network data to be detected, preliminary detection is performed using the preset keyword template and length threshold, and at least two dimensions are detected in combination with the preset analysis and detection model, including dimensions such as invisible character ratio, information entropy and maximum word length, and the final detection result is determined by weighted summing.
Improves the recognition accuracy of SQL injection attacks, reduces false positives, improves the compatibility and user experience of network attack detection, and ensures business continuity.
Smart Images

Figure CN120321026A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular, to a network data detection method, apparatus, computer device, and readable storage medium. Background Art
[0002] SQL (Structured Query Language) statements are a database query and programming language. By writing SQL statements, data can be operated on, which plays a very important role in modern program development. There are also a large number of important data in SQL databases. Due to its importance, it has become the target of attackers. SQL injection attacks are when attackers inject malicious SQL code into a database query of an application program to bypass security measures and obtain unauthorized data access rights, with characteristics such as great harm and many mutation forms. Therefore, SQL injection has also become the primary threat to Web (World Wide Web) application programs. To prevent such attacks, it is necessary to detect such attacks. In related technologies, there are mainly methods based on semantic analysis. This semantic-based method usually requires lexical analysis first to convert the SQL statement into a sequence of Tokens (the smallest syntactic unit in the source code). Based on the lexical analysis result, syntax analysis is then performed to determine whether the syntax is correct, and finally features are extracted to determine whether it is an SQL injection. Although the semantic analysis-based method can effectively identify and prevent the vast majority of SQL injection attacks, this method also has certain limitations. In actual production environments, there are scenarios where SQL injection attacks cannot be accurately identified. Therefore, the SQL injection attack recognition methods in related technologies have the problem of low accuracy. Summary of the Invention
[0003] Based on this, in view of the above technical problems, it is necessary to provide a network data detection method, apparatus, computer device, computer-readable storage medium, and computer program product that can improve the recognition accuracy.
[0004] In a first aspect, the present application provides a network data detection method, including:
[0005] Obtain a symbol sequence of the network data to be detected;
[0006] Detect the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result;
[0007] When the preliminary detection result characterizes the network data to be detected as normal network data, a preset analysis and detection model is used to detect the symbol sequence in at least two dimensions to obtain a target detection result; the target detection result includes that the network data to be detected is normal network data, or the network data to be detected is abnormal network data.
[0008] In one embodiment, the detecting the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result includes:
[0009] Detecting the symbol sequence according to the preset keyword template;
[0010] When the symbol sequence includes a sequence word matching the keyword template, the preliminary detection result is obtained as that the network data to be detected is abnormal network data;
[0011] When the sequence word in the symbol sequence fails to match the keyword template, the preliminary detection result is obtained as that the network data to be detected is network data to be determined.
[0012] In one embodiment, the detecting the symbol sequence according to at least one of a preset keyword template and a length threshold to obtain a preliminary detection result includes:
[0013] Detecting the symbol sequence according to the preset length threshold;
[0014] When the sequence length of the symbol sequence is greater than or equal to the preset length threshold, the preliminary detection result is obtained as that the network data to be detected is abnormal network data;
[0015] When the sequence length of the symbol sequence is less than the preset length threshold, the preliminary detection result is obtained as that the network data to be detected is normal network data.
[0016] In one embodiment, the method further includes:
[0017] Comparing the sequence length of the symbol sequence of the network data to be determined with the preset length threshold;
[0018] When the sequence length of the symbol sequence is greater than or equal to the preset length threshold, the preliminary detection result is obtained as that the network data to be detected is abnormal network data;
[0019] When the sequence length of the symbol sequence is less than the preset length threshold, the preliminary detection result is obtained as that the network data to be detected is normal network data.
[0020] In one embodiment, the preset analysis and detection model includes at least two analysis and detection sub-models;
[0021] The detecting the symbol sequence in at least two dimensions by using the preset analysis and detection model to obtain a target detection result includes:
[0022] Determining the analysis and detection sub-model corresponding to each dimension of the symbol sequence;
[0023] For each dimension of the symbol sequence, using the analysis and detection sub-model corresponding to the dimension to perform detection to obtain a target sub-detection result corresponding to each dimension;
[0024] Obtaining a target detection result according to the evaluation value determined according to the target sub-detection result corresponding to each dimension.
[0025] In one embodiment, the obtaining a target detection result according to the evaluation value determined according to the target sub-detection result corresponding to each dimension includes:
[0026] Obtaining a preset weight corresponding to each dimension;
[0027] Obtaining an evaluation value according to the target sub-detection result corresponding to each dimension and the corresponding preset weight;
[0028] Obtaining a target detection result according to the evaluation value and a preset evaluation threshold.
[0029] In one embodiment, the obtaining a target detection result according to the evaluation value and a preset evaluation threshold further includes:
[0030] When the evaluation value is greater than the preset evaluation threshold, determining that the target detection result is that the network data to be detected is normal network data;
[0031] When the evaluation value is less than or equal to the preset evaluation threshold, determining that the target detection result is that the network data to be detected is abnormal network data.
[0032] In a second aspect, the present application further provides a network data detection device, including:
[0033] A sequence acquisition module, configured to acquire a symbol sequence of network data to be detected;
[0034] A preliminary detection module, configured to perform detection on the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result;
[0035] An analysis and detection module, configured to, when the preliminary detection result indicates that the network data to be detected is normal network data, detect the symbol sequence in at least two dimensions by using a preset analysis and detection model, so as to obtain a target detection result; the target detection result includes that the network data to be detected is normal network data, or the network data to be detected is abnormal network data.
[0036] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0037] Obtain a symbol sequence of network data to be detected;
[0038] Detect the symbol sequence according to at least one of a preset keyword template and a preset length threshold, so as to obtain a preliminary detection result;
[0039] In a case where the preliminary detection result indicates that the network data to be detected is normal network data, detect the symbol sequence in at least two dimensions by using a preset analysis and detection model, so as to obtain a target detection result; the target detection result includes that the network data to be detected is normal network data, or the network data to be detected is abnormal network data.
[0040] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0041] Obtain a symbol sequence of network data to be detected;
[0042] Detect the symbol sequence according to at least one of a preset keyword template and a preset length threshold, so as to obtain a preliminary detection result;
[0043] In a case where the preliminary detection result indicates that the network data to be detected is normal network data, detect the symbol sequence in at least two dimensions by using a preset analysis and detection model, so as to obtain a target detection result; the target detection result includes that the network data to be detected is normal network data, or the network data to be detected is abnormal network data.
[0044] In a fifth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0045] Obtain a symbol sequence of network data to be detected;
[0046] Detect the symbol sequence according to at least one of a preset keyword template and a preset length threshold, so as to obtain a preliminary detection result;
[0047] When the preliminary detection result indicates that the network data to be detected is normal network data, a preset analysis and detection model is used to detect the symbol sequence in at least two dimensions to obtain a target detection result; the target detection result includes that the network data to be detected is normal network data, or the network data to be detected is abnormal network data.
[0048] The above network data detection method, device, computer device, computer-readable storage medium and computer program product. This method obtains the symbol sequence after lexical analysis of the network data to be detected, laying a foundation for subsequent detection of abnormal network data, and detects the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result. The preliminary screening can reduce the burden for subsequent detection; when the preliminary detection result indicates that the network data to be detected is normal network data, a preset analysis and detection model is used to detect the symbol sequence in at least two dimensions to obtain a target detection result, where the target detection result includes that the network data to be detected is normal network data, or the network data to be detected is abnormal network data. When the preliminary detection result is that the network data to be detected is normal network data, a second analysis and detection is performed, reducing the error of the preliminary detection, and detecting the network data to be detected in at least two dimensions, realizing a more comprehensive detection, and further improving the recognition accuracy of abnormal network data. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0050] Figure 1 It is a flowchart of a network data detection method in an embodiment;
[0051] Figure 2 It is a flowchart of a target detection result determination step in an embodiment;
[0052] Figure 3 It is a flowchart of an SQL injection false alarm analysis method for binary streams in an embodiment;
[0053] Figure 4 It is a structural block diagram of a network data detection device in an embodiment;
[0054] Figure 5Internal structure diagram of a computer device in an embodiment. Detailed implementation
[0055] In order to make the objectives, technical solutions and advantages of the present application more clearly understood, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0056] As described in the background art, in the network attack recognition method of the related art, there is a problem of low accuracy in identifying SQL injection attacks. Through research by the inventor, it is found that the reason for this problem is that SQL statements are a database query and programming language, and data can be operated by writing SQL statements, which plays a very important role in modern program development. There are also a large number of important data in the SQL database. It is precisely because of its importance that it has become the target of attackers. SQL injection attack is an attack in which an attacker injects malicious SQL code into the database query of an application program, thereby bypassing security measures and obtaining unauthorized data access rights, with characteristics such as great harm and many mutation forms. Therefore, SQL injection has also become the primary threat to Web application programs. To prevent such attacks, it is necessary to detect such attacks. The current SQL injection attack detection technologies mainly include methods based on regular expressions, rules, and semantic analysis. The methods based on regular expressions and rules are difficult to identify deformed SQL injection and 0day (zero-day vulnerability) SQL injection. And identifying potential SQL injection attempts based on semantic analysis is a relatively mainstream method at present. This method not only improves the accuracy but also reduces the false positive rate, and can also judge Oday SQL injection. This semantic-based method usually needs to perform lexical analysis first to convert the SQL statement into a Token sequence, and then perform syntactic analysis based on the result of lexical analysis to determine whether the syntax is correct, and finally extract features to determine whether it is SQL injection. This is also the method often used by WAF (Web Application Firewall) in detecting SQL injection. There is a network application attack detection method in the related art, including: preprocessing the received user request to obtain the payload to be detected; constructing the payload into a statement to be detected and performing structured query language SQL syntax analysis on the statement to be detected to determine whether the statement to be detected is a structured query language SQL statement; determining whether the statement to be detected is an injection attack statement based on a pre-established scoring model, and the scoring model outputs the scoring result of the keywords included in the statement to be detected according to the mapping relationship between the pre-set keywords and the weight scores corresponding to the keywords. According to the technical solution of the embodiment of the present application, by determining whether the payload can be constructed into an SQL statement to identify SQL injection attacks, the accuracy of detecting SQL injection is effectively improved. There is a network attack detection method in the related art, including: determining the target language from the request data according to the type of the target language; performing lexical analysis, syntactic analysis, and semantic analysis on the target language; and determining the risk level of the request data according to the results of lexical analysis, syntactic analysis, and semantic analysis.In the technical solution provided by the present invention, the target language is determined from the request data according to the type of the target language, so that the extraction operations for different types of target languages can be taken into account to adapt to different detection purposes, thereby improving the compatibility of network attack detection. Although the method based on semantic analysis can effectively identify and prevent the vast majority of SQL injection attacks, this method also has certain limitations. In an actual production environment, there is such a scenario. For example, what a user inputs on the front-end page is a file or a picture. When the WAF analyzes this traffic, it includes the analysis of binary streams such as files or pictures. If this binary data stream happens to conform to the SQL syntax structure and contains specific SQL features after a series of steps such as lexical analysis, syntax analysis, and feature extraction, the existing detection system will erroneously identify these data streams as potential SQL injection attacks. These false positives may intercept the user's business, causing unnecessary trouble and user experience to the user. This requires the detection system to be more intelligent so that it can accurately judge these false positives to improve the user experience and reduce customer churn, which is very important for WAF manufacturers. Although the existing technology can effectively identify whether it is an SQL injection attack through the semantic analysis method, the method for handling false positives of binary streams caused by semantic analysis is still relatively lacking. Using a scoring model to reduce false positives is a good idea, but it may not be applicable to short-circuit SQL statements. For example, the short-circuit of "1or1=1" may not be well matched with the set keywords, resulting in a low score in the end. Analogous to binary streams, after most binary streams undergo lexical analysis, the number of tokens is often small, which is very similar to short-circuiting. However, the above scoring model may reduce the false positive rate at the expense of accuracy.
[0057] For the above reasons, the present application provides a network data detection method, aiming to improve the recognition accuracy of SQL injection attacks.
[0058] In one embodiment, as Figure 1As shown in the figure, a network data detection method is provided. In this embodiment, the method is exemplified by being applied to a server system. It can be understood that the method can also be applied to a terminal, or to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. Among them, the terminal can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The portable wearable device can be a smart watch, a smart bracelet, a head-mounted device, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. The server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. In this embodiment, the method includes the following steps:
[0059] Step 102, obtain the symbol sequence of the network data to be detected.
[0060] Among them, the network data to be detected can be data input by users, database interaction data, etc. Among them, the data input by users includes files or pictures input by users at the web front end, which are binary data streams.
[0061] Among them, the symbol sequence can be a Token sequence. A Token sequence is the result generated by the process of decomposing the source code or input data stream into a series of tokens. A Token is the smallest syntactic unit in the source code and usually corresponds to the basic symbols of the language, such as keywords, operators, identifiers, numerical constants, etc.
[0062] Optionally, the system performs lexical analysis on the network data to be detected and converts it into a symbol sequence as a preparation for subsequent anomaly detection. Among them, lexical analysis refers to turning a piece of program text into a set of defined basic components.
[0063] Step 104, detect the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result.
[0064] Among them, the preset keyword template can be a keyword template for abnormal network data or a keyword template for normal network data summarized after comparative analysis of the symbol sequences of a large amount of network data and the symbol sequences of abnormal network data. The keyword template includes at least one keyword.
[0065] Among them, the preset length threshold can be the length of the symbol sequence of abnormal network data summarized through statistical analysis of the symbol sequence lengths of a large amount of abnormal network data.
[0066] Optionally, the system detects the symbol sequence according to at least one of a preset keyword template and a preset length threshold, including detecting the symbol sequence according to the preset keyword template to obtain a preliminary detection result; detecting the symbol sequence according to the preset length threshold to obtain a preliminary detection result; and detecting the symbol sequence according to the preset keyword template and the preset length threshold respectively to obtain a preliminary detection result.
[0067] Step 106, when the preliminary detection result indicates that the network data to be detected is normal network data, use a preset analysis and detection model to detect the symbol sequence in at least two dimensions to obtain a target detection result.
[0068] Among them, the target detection result includes that the network data to be detected is normal network data, or the network data to be detected is abnormal network data. Among them, normal network data can be normal data that does not cause a network attack. Among them, abnormal network data can be abnormal data that causes a network attack. It should be noted that in this embodiment, it mainly targets SQL injection attacks, which is a common network security threat. An attacker injects malicious SQL code into a database query of an application program to bypass security measures and obtain unauthorized data access rights.
[0069] Among them, the preset analysis and detection model can be a mathematical model constructed after statistical analysis and pattern analysis of network data (including normal network data and abnormal network data as samples), or an artificial intelligence model obtained by deep learning training of a neural network based on historical network data and their respective labels.
[0070] Optionally, when the preliminary detection result indicates that the network data to be detected is normal network data, the system further uses a preset analysis and detection model to detect the symbol sequence in at least two dimensions to obtain a target detection result.
[0071] In the above network data detection method, the method obtains the symbol sequence after lexical analysis of the network data to be detected, which serves as a basis for subsequent abnormal network data detection, and detects the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result. The preliminary screening can reduce the burden for subsequent detection. When the preliminary detection result indicates that the network data to be detected is normal network data, a preset analysis detection model is used to detect the symbol sequence in at least two dimensions to obtain a target detection result, where the target detection result includes that the network data to be detected is normal network data or the network data to be detected is abnormal network data. When the preliminary detection result is that the network data to be detected is normal network data, a second analysis detection is performed, which reduces the error of the preliminary detection, and detects the network data to be detected in at least two dimensions, achieving a more comprehensive detection and further improving the recognition accuracy of abnormal network data.
[0072] In an exemplary embodiment, step S104 detects the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result, including:
[0073] Detect the symbol sequence according to the preset keyword template; when the symbol sequence includes a sequence word that matches the keyword template, the preliminary detection result is that the network data to be detected is abnormal network data; when the sequence word in the symbol sequence fails to match the keyword template, the preliminary detection result is that the network data to be detected is to-be-determined network data.
[0074] Among them, in the Token sequence (symbol sequence), a keyword is a Token that plays a key role in understanding the text meaning, theme or intention, and usually has the following characteristics that can significantly affect text classification, summarization or retrieval results, measured by indicators such as word frequency and inverse document frequency, and has a strong correlation with other Tokens in the sequence (such as identified through an attention mechanism or dependency syntax analysis).
[0075] It should be noted that through the inventor's research, it is found that in binary streams, most binary streams often have a relatively small number of tokens after lexical analysis, which is very similar to short circuits. When identifying SQL injection attacks, false positives are likely to occur. The reason is that after the lexical analysis of the network data to be detected, the obtained token sequence (symbol sequence) is some syntax fragments, and these syntax fragments exactly conform to SQL syntax and may be fragments of function calls. Therefore, it is very easy to judge as SQL injection after lexical, syntactic, and feature extraction. The main reason for false positives is that the lexical analysis process converts the binary stream, which is originally an unordered and unstructured data stream, into a structured token sequence. This process from disorder to order is the main reason for the false positives of binary streams. In addition, through the inventor's statistics on the token sequences of a large number of binary data streams, it is found that the binary data streams corresponding to normal data such as pictures or files have the following characteristics in the token sequences after lexical analysis: no keywords of SQL statements: SELECT (query), UPDATE (upload), WHERE (filter data), FROM (specify the data source for query), etc.; the length of the token sequence is only a few, and it will not have a relatively long token sequence like most SQL statements, and is more similar to a short circuit like "1or1=1".
[0076] Optionally, the system compares each keyword in the preset keyword template with each sequence word in the symbol sequence for detection; when there is a sequence word in the symbol sequence that matches the keyword template, for example, each sequence word in the symbol sequence includes SELECT, it indicates that the network data to be detected is an SQL injection attack statement, and the preliminary detection result is that the network data to be detected is abnormal network data; when the sequence word in the symbol sequence fails to match the keyword template, the preliminary detection result is that the network data to be detected is network data to be determined, which serves as the basis for further detection.
[0077] In this embodiment, by using the preset keyword template to preliminarily detect the symbol sequence of the network data to be detected, abnormal network data can be quickly identified, and at the same time, an analysis basis is provided for subsequent further detection.
[0078] In an exemplary embodiment, step S104 detects the symbol sequence according to at least one of the preset keyword template and length threshold, and obtains a preliminary detection result, including:[[]]
[0079] Detect the symbol sequence according to the preset length threshold; when the sequence length of the symbol sequence is greater than or equal to the preset length threshold, the preliminary detection result is that the network data to be detected is abnormal network data; when the sequence length of the symbol sequence is less than the preset length threshold, the preliminary detection result is that the network data to be detected is normal network data.
[0080] Among them, the sequence length of the symbol sequence can refer to the sequence length of the Token sequence, which usually refers to the total number of Tokens (basic units such as words, symbols, etc.) in the sequence.
[0081] Optionally, through the analysis of the previous embodiment, it can be known that the Token length of the Token sequence corresponding to the binary stream data of normal network data such as files or pictures is usually relatively short. Therefore, the system compares the preset length threshold with the symbol sequence. When the sequence length of the symbol sequence is greater than or equal to the preset length threshold, the preliminary detection result is that the network data to be detected is abnormal network data. For example, the preset length threshold is , if the sequence length of the symbol sequence is greater than or equal to 7, the preliminary detection result is that the network data to be detected is abnormal network data; when the sequence length of the symbol sequence is less than the preset length threshold, the preliminary detection result is that the network data to be detected is normal network data.
[0082] In this embodiment, by initially detecting the sequence length of the symbol sequence of the network data to be detected through the preset length threshold corresponding to the characteristics of the entire network data, abnormal network data can be quickly identified, and at the same time, an analysis basis is provided for further detection in the follow-up.
[0083] In an exemplary embodiment, the method described in the above embodiment further includes:
[0084] Compare the sequence length of the symbol sequence of the network data to be determined with the preset length threshold; when the sequence length of the symbol sequence is greater than or equal to the preset length threshold, the preliminary detection result is that the network data to be detected is abnormal network data; when the sequence length of the symbol sequence is less than the preset length threshold, the preliminary detection result is that the network data to be detected is normal network data.
[0085] Optionally, the system compares the sequence length of the symbol sequence of the network data to be determined where the sequence words do not match the preset keyword module with the preset length threshold. When the sequence length of the symbol sequence is greater than or equal to the preset length threshold, the preliminary detection result is that the network data to be detected is abnormal network data; when the sequence length of the symbol sequence is less than the preset length threshold, the preliminary detection result is that the network data to be detected is normal network data.
[0086] In this embodiment, the system further uses the preset length threshold to monitor the network data to be determined where the sequence words do not match the preset keyword module, and uses double detection to ensure the accuracy of the preliminary detection result, further improving the recognition accuracy of abnormal network data.
[0087] In an exemplary embodiment, as Figure 2 shown, the preset analysis and detection model includes at least two analysis and detection sub-models; step S106 uses the preset analysis and detection model to perform detections on the symbol sequence in at least two dimensions to obtain a target detection result, including:
[0088] Step S202, determining the analysis and detection sub-model corresponding to each dimension of the symbol sequence.
[0089] Among them, the analysis and detection sub-model can be a mathematical model for detecting the corresponding dimension of the symbol sequence, and each dimension of the symbol sequence corresponds to each analysis and detection sub-model one by one.
[0090] Optionally, the system determines the analysis and detection sub-models corresponding to the respective dimensions of the symbol sequence that need to be detected.
[0091] Step S204, for each dimension of the symbol sequence, using the analysis and detection sub-model corresponding to the dimension to perform detection to obtain the target sub-detection result corresponding to each dimension.
[0092] Among them, the target sub-detection result can be the detection result corresponding to each dimension of the symbol sequence, and can be a scored value.
[0093] Among them, the dimensions of the symbol sequence can include dimensions such as the proportion of the number of invisible characters, information entropy, and the longest word length.
[0094] Optionally, the system evaluates the parameters corresponding to each dimension of the symbol sequence using the mathematical logic of the analysis and detection sub-model corresponding to the dimension to obtain the target sub-detection result corresponding to each dimension. For example, evaluating the parameters corresponding to the three dimensions of the proportion of the number of invisible characters, information entropy, and the longest word length. Among them, the expression of the analysis and detection sub-model corresponding to the proportion of the number of invisible characters includes:
[0095]
[0096] Among them, represents the target sub-detection result corresponding to the proportion of the number of invisible characters, represents the number of invisible characters in the network data to be detected corresponding to the symbol sequence, represents the preset invisible character threshold, represents the proportion of the number of invisible characters in the network data to be detected corresponding to the symbol sequence to the total number of characters. If represents if, guiding a conditional statement, and represents "and". Through the inventor's statistical analysis, it is found that if only analyzing the number of invisible characters in the symbol sequence, it is inconsistent in long and short binary stream data. Through statistical analysis, when the number of characters in the overall binary stream data is less than When the number is (=15), if the proportion of invisible characters is greater than 25%, it is most likely binary stream data (normal network data); if the total number of binary characters is greater than When the number is, if the proportion of invisible characters is greater than 20%, it is most likely binary stream data (normal network data).
[0097] In addition, the expression of the analysis and detection sub-model corresponding to the overall information entropy of the network data to be detected includes:
[0098]
[0099] Among them, is the target sub-detection result corresponding to the information entropy, is the overall information entropy of the data stream to be detected corresponding to the symbol sequence. If represents if, guiding a conditional statement, and and represents "and". Among them, the way to determine the overall information entropy is determined by the occurrence frequency of each character in the network data to be detected, and the corresponding expression is:
[0100]
[0101]
[0102] Among them, is the i-th byte The frequency of occurrence, is the network data to be detected, represents the statistical byte The number of times it appears in the network data to be detected, represents the data stream length of the network data to be detected.
[0103] In addition, the expression of the analysis and detection sub-model corresponding to the dimension of the longest word length of the symbol sequence includes:
[0104]
[0105] Among them, represents the target sub-analysis result corresponding to the dimension of the longest word length, is the longest word length in the symbol sequence, and and represents "and". It should be noted that after lexical analysis of the binary stream data, most of those unordered byte strings are converted into tokens of BAREWORD (pure word), that is, a pure word. And if the length of this pure word appears to be relatively long, it is most likely irregular binary stream data, such as a length greater than 100.
[0106] Step S206, obtain the target detection result according to the evaluation value determined by the target sub-detection results corresponding to each dimension.
[0107] Among them, the evaluation value can be the parameter value obtained after integrating the target sub-detection results of each dimension, or it can be the total score obtained by integrating the scores of the target sub-detection results.
[0108] Optionally, the system integrates the target sub-detection results corresponding to each dimension to obtain an evaluation value, and further determines the corresponding target detection result according to the evaluation value.
[0109] In this embodiment, the system performs further multi-dimensional detection on the network data to be detected after preliminary detection, and sets respective analysis and detection sub-models for each dimension, which can achieve accurate detection of each dimension. In addition, a scoring system is used to obtain the final target detection result, quantifying the degree of abnormality of the network data to be detected, and further improving the recognition accuracy of abnormal network data.
[0110] In an exemplary embodiment, step S206 obtains the target detection result according to the evaluation value determined by the target sub-detection results corresponding to each dimension, including:
[0111] Obtain the preset weight corresponding to each dimension; obtain the evaluation value according to the target sub-detection result corresponding to each dimension and its respective preset weight; obtain the target detection result according to the evaluation value and the preset evaluation threshold.
[0112] Among them, the preset weight can be the weight value set for each dimension by technicians after measuring the importance of different dimensions to the target detection result.
[0113] Optionally, the system obtains the preset weight corresponding to each dimension, and performs weighted summation according to the target sub-detection result corresponding to each dimension and its respective preset weight to obtain the evaluation value. For example, in the above embodiment, the proportions of the number of invisible characters, the information entropy, and the longest word length in the three dimensions are equally important to the target detection result, and the preset weight corresponding to each of the three dimensions is 1 / 3. Then the calculation method of the evaluation value is:
[0114]
[0115] Among them, is the evaluation value, represents the target sub-detection result corresponding to the proportion of the number of invisible characters, is the target sub-detection result corresponding to the information entropy, represents the target sub-analysis result corresponding to the dimension of the longest word length.
[0116] In addition, the system further determines the corresponding target detection result according to the evaluation value, such as comparing the evaluation value with a pre-set scoring table or scoring threshold to obtain the target detection result.
[0117] In this embodiment, the system supports the configuration of preset weights, and technicians can adjust the weights of different dimensions according to actual needs. In addition, the system converts multi-dimensional features into a unified evaluation value through weighted summation, realizing the quantification of complex features, which is convenient for subsequent comparison and judgment. Making decisions (such as determining normal / abnormal) based on a scoring table or threshold reduces subjective intervention, improves the objectivity and consistency of detection results, and thus further improves the recognition accuracy of abnormal network data.
[0118] In an exemplary embodiment, the step in the above embodiment of obtaining the target detection result according to the evaluation value and the preset evaluation threshold further includes:
[0119] When the evaluation value is greater than the preset evaluation threshold, it is determined that the target detection result is that the network data to be detected is normal network data; when the evaluation value is less than or equal to the preset evaluation threshold, it is determined that the target detection result is that the network data to be detected is abnormal network data.
[0120] Among them, the preset evaluation threshold can be set according to the actual detection needs of technicians.
[0121] Optionally, the system compares the evaluation value with a preset evaluation threshold (such as 70 points). When the evaluation value is greater than the preset evaluation threshold, it is determined that the target detection result is that the network data to be detected is normal network data; when the evaluation value is less than or equal to the preset evaluation threshold, it is determined that the target detection result is that the network data to be detected is abnormal network data.
[0122] In this embodiment, the system makes a decision on the target detection result based on the comparison result between the preset evaluation threshold and the evaluation value, reducing subjective intervention, improving the objectivity and consistency of the detection result, and thus further improving the recognition accuracy of abnormal network data.
[0123] In an exemplary embodiment, as Figure 3 shown, a method for analyzing false positives of SQL injection for binary streams is provided, including:
[0124] Step 1, macro filtering. Through research by the inventor, some characteristics of the Token sequence in binary stream lexical analysis are as follows: (1) There are no keywords of SQL statements: SELECT, UPDATE, WHERE, FROM, etc.; (2) The length of the Token sequence is only a few, and it will not have a relatively long Token sequence like most SQL statements, and is more similar to a short circuit like "1or1=1".
[0125] Therefore, a one-step rough screening process is carried out. If the SELECT keyword (preset keyword template) exists in the Token sequence (symbol sequence), it can generally be determined as a SQL injection (abnormal network data). Additionally, if the length of the Token sequence is less than (=7) (preset length threshold), then the following judgment is required. Such a filtering method mainly takes into account the characteristics of binary streams. It is almost impossible for binary streams (normal network data) to tokenize keywords of SQL statements; and the Token sequence length of binary streams is generally less than .
[0126] Step 2, Fine analysis. From the above cause analysis, we can know that the reason for the false alarm of binary streams lies in converting the disordered stream into an ordered and structured Token sequence. Therefore, to determine whether it is a binary stream, it is necessary to go back and make an unordered judgment. In this embodiment, several dimensions of unordered judgment are defined, including the proportion of the number of invisible characters, the overall information entropy, and the longest word length, and scores are given to various dimensions. The scoring results (target sub-detection results) of each dimension are integrated to obtain the fine analysis scoring result (evaluation value).
[0127] Step 3, Decision. If the score (evaluation value) calculated in Step 2 is greater than (=70), then it is determined as a non-SQL injection of binary stream (normal network data), otherwise it is a SQL injection (abnormal network data). Of course, as more data is collected, this embodiment can also adjust the parameters of the above formula in real time to more accurately determine whether it is a false alarm.
[0128] In this embodiment, the combination of order and disorder improves the accuracy of false alarm recognition: the binary stream is converted into an ordered and structured Token sequence through analysis; in the refined analysis, the proportion of invisible characters, information entropy, and the length of the longest word are used to calculate the score of the binary stream, so as to analyze the characteristics of the binary stream as comprehensively as possible and reduce the influence of a certain aspect. By combining the orderliness of the Token sequence and the disorderliness of the binary stream itself, from disorder to order, and then from order to disorder, false alarms can be more accurately reduced. This method is particularly suitable for processing complex or irregularly formatted data streams (such as binary data streams). In scenarios where semantic analysis-based SQL injection detection engines cause false alarms, it can effectively reduce the false alarm rate, help enterprises avoid business interruptions and resource waste caused by misprocessing normal data, and thus improve business continuity and system efficiency; make full use of the semantic analysis results: the false alarm analysis method for binary streams proposed in the present invention is mainly based on the background of semantic analysis, and the present invention makes full use of its result characteristics. For example, the macro filtering in step 1, the judgment of keywords and Token sequence length can be easily obtained. And since lexical and syntactic analysis has been done, if the keywords of SQL statements are still contained, then it is very likely to be an SQL statement. The first step also reduces more influence on the calculation of the second step; in step 2, the length of the longest word can also be obtained from the lexical analysis result, which improves the judgment performance.
[0129] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are displayed in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0130] Based on the same inventive concept, the embodiments of the present application also provide a network data detection device for implementing the above-mentioned network data detection method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the network data detection device provided below can refer to the limitations on the network data detection method in the above text, and will not be repeated here.
[0131] In an exemplary embodiment, as Figure 4As shown, a network data detection device 400 is provided, including: a sequence acquisition module 401, a preliminary detection module 402, and an analysis and detection module 403, where:
[0132] The sequence acquisition module 401 is configured to acquire the symbol sequence of the network data to be detected;
[0133] The preliminary detection module 402 is configured to detect the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result;
[0134] The analysis and detection module 403 is configured to, when the preliminary detection result indicates that the network data to be detected is normal network data, detect the symbol sequence in at least two dimensions by using a preset analysis and detection model to obtain a target detection result; the target detection result includes that the network data to be detected is normal network data, or the network data to be detected is abnormal network data.
[0135] Further, in one embodiment, the preliminary detection module 402 is further configured to detect the symbol sequence according to a preset keyword template; when the symbol sequence includes a sequence word that matches the keyword template, obtain a preliminary detection result that the network data to be detected is abnormal network data; when the sequence word in the symbol sequence fails to match the keyword template, obtain a preliminary detection result that the network data to be detected is to-be-determined network data.
[0136] Further, in one embodiment, the preliminary detection module 402 is further configured to detect the symbol sequence according to a preset length threshold; when the sequence length of the symbol sequence is greater than or equal to the preset length threshold, obtain a preliminary detection result that the network data to be detected is abnormal network data; when the sequence length of the symbol sequence is less than the preset length threshold, obtain a preliminary detection result that the network data to be detected is normal network data.
[0137] Further, in one embodiment, the preliminary detection module 402 is further configured to compare the sequence length of the symbol sequence of the to-be-determined network data with the preset length threshold; when the sequence length of the symbol sequence is greater than or equal to the preset length threshold, obtain a preliminary detection result that the network data to be detected is abnormal network data; when the sequence length of the symbol sequence is less than the preset length threshold, obtain a preliminary detection result that the network data to be detected is normal network data.
[0138] Further, in one embodiment, the analysis and detection module 403 is further configured to determine analysis and detection sub-models corresponding to each dimension of the symbol sequence; for each dimension of the symbol sequence, perform detection using the analysis and detection sub-model corresponding to the dimension to obtain target sub-detection results corresponding to each dimension; and obtain a target detection result according to the evaluation value determined based on the target sub-detection results corresponding to each dimension.
[0139] Further, in one embodiment, the analysis and detection module 403 is further configured to obtain preset weights corresponding to each dimension; obtain an evaluation value according to the target sub-detection results corresponding to each dimension and their respective corresponding preset weights; and obtain a target detection result according to the evaluation value and a preset evaluation threshold.
[0140] Further, in one embodiment, the analysis and detection module 403 is further configured to, when the evaluation value is greater than the preset evaluation threshold, determine that the target detection result is that the network data to be detected is normal network data; and when the evaluation value is less than or equal to the preset evaluation threshold, determine that the target detection result is that the network data to be detected is abnormal network data.
[0141] Each module in the above network data detection device 400 can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0142] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 5 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as the symbol sequence of the network data to be detected, the preliminary detection result, and the target detection result. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. The computer program, when executed by the processor, implements a network data detection method.
[0143] Those skilled in the art can understand, Figure 5The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0144] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0145] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0146] In one embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0147] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0148] Those of ordinary skill in the art can understand that all or part of the processes in the above-described method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the method embodiments as described above. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0149] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.
[0150] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A network data detection method, characterized in that, The method includes: Obtaining a symbol sequence of network data to be detected; Detecting the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result; When the preliminary detection result indicates that the network data to be detected is normal network data, using a preset analysis and detection model to detect the symbol sequence in at least two dimensions to obtain a target detection result; the target detection result includes that the network data to be detected is normal network data, or the network data to be detected is abnormal network data.
2. The method according to claim 1, wherein The step of detecting the symbol sequence according to at least one of a preset keyword template and a length threshold to obtain a preliminary detection result includes: Detecting the symbol sequence according to the preset keyword template; When the symbol sequence includes a sequence word matching the keyword template, obtaining the preliminary detection result that the network data to be detected is abnormal network data; When the sequence word in the symbol sequence fails to match the keyword template, obtaining the preliminary detection result that the network data to be detected is network data to be determined.
3. The method according to claim 1, wherein The step of detecting the symbol sequence according to at least one of a preset keyword template and a length threshold to obtain a preliminary detection result includes: Detecting the symbol sequence according to the preset length threshold; When the sequence length of the symbol sequence is greater than or equal to the preset length threshold, obtaining the preliminary detection result that the network data to be detected is abnormal network data; When the sequence length of the symbol sequence is less than the preset length threshold, obtaining the preliminary detection result that the network data to be detected is normal network data.
4. The method according to claim 2, characterized in that, The method further includes: Comparing the sequence length of the symbol sequence of the network data to be determined with the preset length threshold; When the sequence length of the symbol sequence is greater than or equal to the preset length threshold, obtaining the preliminary detection result that the network data to be detected is abnormal network data; When the sequence length of the symbol sequence is less than the preset length threshold, obtaining the preliminary detection result that the network data to be detected is normal network data.
5. The method according to claim 1, characterized in that, The preset analysis and detection model includes at least two analysis and detection sub-models; The step of using the preset analysis and detection model to detect the symbol sequence in at least two dimensions to obtain a target detection result includes: Determining the analysis and detection sub-model corresponding to each dimension of the symbol sequence; For each dimension of the symbol sequence, using the analysis and detection sub-model corresponding to the dimension to perform detection to obtain a target sub-detection result corresponding to each dimension; Obtaining a target detection result according to the evaluation value determined by the target sub-detection results corresponding to each dimension.
6. The method according to claim 5, wherein The step of obtaining a target detection result according to the evaluation value determined by the target sub-detection results corresponding to each dimension includes: Obtaining the preset weight corresponding to each dimension; Obtaining an evaluation value according to the target sub-detection results corresponding to each dimension and their respective corresponding preset weights; Based on the evaluation value and a preset evaluation threshold, a target detection result is obtained.
7. The method according to claim 6, wherein The obtaining of the target detection result based on the evaluation value and the preset evaluation threshold further includes: When the evaluation value is greater than the preset evaluation threshold, determining that the target detection result is that the network data to be detected is normal network data; When the evaluation value is less than or equal to the preset evaluation threshold, determining that the target detection result is that the network data to be detected is abnormal network data.
8. A network data detection device, characterized in that, The device includes: A sequence acquisition module, configured to acquire a symbol sequence of the network data to be detected; A preliminary detection module, configured to detect the symbol sequence according to at least one of a preset keyword template and a preset length threshold to obtain a preliminary detection result; An analysis and detection module, configured to, when the preliminary detection result indicates that the network data to be detected is normal network data, detect the symbol sequence in at least two dimensions by using a preset analysis and detection model to obtain a target detection result; the target detection result includes that the network data to be detected is normal network data or the network data to be detected is abnormal network data.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.