Component poisoning processing method and device, electronic equipment and computer program product

By obtaining the identity information and characteristic data of the component, hash value comparison and digital signature verification, combining static code analysis and dynamic behavior analysis, identifying and defending against component poisoning attacks, the hidden and destructive problems of component poisoning attacks are solved and the system security is improved.

CN120389882APending Publication Date: 2025-07-29INST OF COMPUTING TECH CHINA ACAD OF RAILWAY SCI +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510473441.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

Component poisoning attacks are highly concealed and destructive, and existing technologies are difficult to effectively detect and defend, which brings challenges to network security protection.

Method used

By obtaining the identity information and characteristic data of the component, hash value comparison and digital signature verification are performed, and static code analysis and dynamic behavior analysis are combined to identify poisoning behaviors, and defense actions are triggered according to preset defense strategies, such as data cleaning, denial of service, and quarantine users.

Benefits of technology

It improves the accuracy and defense efficiency of component poisoning detection, reduces the false alarm rate, enhances system security, and protects enterprise information data and business operation security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389882A_ABST
    Figure CN120389882A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a component poisoning processing method and device, electronic equipment and a computer program product, and relates to the technical field of system safety protection, the method can effectively detect a poisoning component, and the system safety is improved. The method specifically comprises the steps of obtaining a detection instruction submitted by a user; the detection instruction comprises identity information of at least one component serving as a current detection object; acquiring feature data of the at least one component according to the identity information of the at least one component; verifying the security of the at least one component according to the feature data; analyzing whether the at least one component or the verified component has a poisoning behavior or not; for the component which does not pass the verification or has the poisoning behavior, triggering a corresponding defense action according to a preset defense strategy; the defense strategy is used for indicating defense actions taken for various poisoning behaviors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of system security protection, and particularly relates to a method, device, electronic device and computer program product for component poisoning processing. Background Art

[0002] Component poisoning refers to an attacker publishing malicious component packages in an open-source component repository to induce users to download and install them, thereby achieving the purpose of controlling users' devices or stealing sensitive information. This attack method usually takes advantage of users' trust in open-source components and confuses the public by imitating the names or version numbers of well-known components, making it difficult for users to detect.

[0003] Component poisoning attack is a new type of attack that has emerged in the field of network security in recent years. This attack method has characteristics such as strong concealment and great destructiveness, posing a great challenge to network security protection. Given the severity and universality of component poisoning attacks, developing effective component poisoning detection and defense technologies has become one of the problems that need to be solved urgently by those skilled in the art. Summary of the Invention

[0004] In view of this, embodiments of this application provide a method, device, electronic device and computer program product for component poisoning processing to solve the above problems.

[0005] In a first aspect, embodiments of this application propose a method for component poisoning processing. The method includes: obtaining a detection instruction submitted by a user; the detection instruction contains the identity information of at least one component that is the object of this detection; obtaining the feature data of at least one component according to the identity information of at least one component; verifying the security of at least one component according to the feature data; analyzing whether there is a poisoning behavior in at least one component or the components that pass the verification; for the components that fail the verification or have a poisoning behavior, triggering corresponding defense actions according to a preset defense strategy; the defense strategy is used to indicate the defense actions taken for various poisoning behaviors.

[0006] In an implementable manner, obtaining the feature data of at least one component includes: calculating a first hash value corresponding to a first component; the first component is one of at least one component; verifying the security of at least one component includes: obtaining a legitimate second hash value corresponding to the first component according to the identity information of the first component; comparing the first hash value and the second hash value, if they are the same, the verification passes; if they are different, the verification fails.

[0007] In one implementable manner, obtaining feature data of at least one component includes: obtaining a digital signature carried by a first component; the digital signature is a signature obtained using a private key in an asymmetric encryption algorithm; verifying the security of at least one component includes: obtaining a public key corresponding to the first component according to the identity information of the first component; using the public key to verify the digital signature.

[0008] In one implementable manner, analyzing whether there is a poisoning behavior in at least one component includes: performing static code analysis on at least one component to determine whether there is a poisoning behavior in the component; wherein, the static code analysis includes one or more of the following operations: decomposing the source code of at least one component into lexical units; checking whether the combination of lexical units conforms to the syntax rules according to the syntax rules adopted by the source code; obtaining the definition and type information of at least one variable in the source code of at least one component; tracking whether the usage of the variable matches the definition and type information; checking whether the signature of a function in the source code of at least one component is correctly defined, whether the parameters in the function are correctly used inside the function, and whether the return value meets the expectation; parsing the control flow statements in the source code of at least one component to determine whether the execution path corresponding to the control flow statements is abnormal; searching in the source code of at least one component for code that matches a malicious code pattern in a predefined malicious code pattern library; the malicious code pattern library includes one or more of the following patterns: backdoor insertion, code obfuscation, abnormal system calls; identifying whether there is an unauthorized function in the source code of at least one component; tracking whether the flow direction of data in the source code of at least one component is abnormal, and the flow direction includes the generation to usage or storage of data; analyzing whether the dependency relationship between different data elements in the source code of at least one component is abnormal.

[0009] In one implementable manner, analyzing whether there is a poisoning behavior for at least one component includes: performing dynamic behavior analysis on at least one component to determine whether there is a poisoning behavior for the component; wherein, the dynamic behavior analysis includes: based on a pre-established test environment, running at least one component; the test environment is established using virtual machine or container technology and is isolated from the actual monitored environment; at least one monitoring tool is deployed in the test environment; wherein, the at least one monitoring tool includes one or more of the following tools: a system monitoring tool, a network monitoring tool, and a process monitoring tool; collecting various types of data during the running process of at least one component through the monitoring tool, including performing one or more of the following operations: monitoring the usage of system resources through the system monitoring tool; capturing network communication data packets between at least one component and the outside through the network monitoring tool; tracking the process status corresponding to at least one component through the process monitoring tool; identifying whether at least one component has one or more of the following anomalies based on the various types of data: abnormal system resource usage, abnormal network communication, and abnormal process behavior; wherein, abnormal system resource usage includes resource exhaustion anomaly and / or resource fluctuation anomaly; abnormal network communication includes one or more of unknown destination communication, abnormal port communication, and data transmission anomaly; abnormal process behavior includes one or more of abnormal process startup, abnormal resource occupation, and abnormal process execution path.

[0010] In one implementable manner, for a component that fails verification or has a poisoning behavior, according to a preset defense strategy, triggering corresponding defense actions, including: for a component with a poisoning behavior, according to a preset defense strategy, triggering one or more of the following actions: data cleaning, denial of service, and user isolation.

[0011] In one implementable manner, the method further includes: adding a component that fails verification or has a poisoning behavior to a pre-built blacklist; adding a component that passes verification and has no poisoning behavior to a pre-built whitelist.

[0012] In a second aspect, an embodiment of the present application further provides a component poisoning processing device, which includes: an interaction module, configured to obtain a detection instruction submitted by a user; the detection instruction contains the identity information of at least one component that is the object of this detection; a data verification module, configured to obtain the characteristic data of at least one component according to the identity information of at least one component; verifying the security of at least one component according to the characteristic data; a poisoning detection module, configured to analyze whether there is a poisoning behavior for a component that passes verification; a defense module, configured to, for a component that fails verification or has a poisoning behavior, trigger corresponding defense actions according to a preset defense strategy; the defense strategy is used to indicate the defense actions taken for various poisoning behaviors.

[0013] In a third aspect, an embodiment of the present application further provides an electronic device, which includes a processor configured to execute a computer program or instructions in a memory to implement the method described in any one of the above first aspects.

[0014] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which includes a stored program. When the program is executed by a processor, the method described in any one of the above first aspects is implemented.

[0015] In a fifth aspect, an embodiment of the present application further provides a computer program product, which includes a program. When the program runs on an electronic device, the electronic device is enabled to implement the method described in any one of the above first aspects.

[0016] In a sixth aspect, an embodiment of the present application further provides a chip system, which includes a communication interface for inputting and / or outputting data, and a processor for executing a computer-executable program, so that a device installed with the chip system executes the method described in any one of the above first aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0018] Figure 1 It is a schematic structural diagram of the electronic device provided by the embodiment of the present application;

[0019] Figure 2 It is a schematic flowchart of the component poisoning processing method provided by the embodiment of the present application;

[0020] Figure 3 It is a schematic diagram of the system architecture of the component poisoning processing method provided by the embodiment of the present application;

[0021] Figure 4 It is a schematic flowchart of the process that can be supplemented and implemented in some other embodiments of the component poisoning processing method provided by the embodiment of the present application;

[0022] Figure 5 It is a schematic diagram of the random forest algorithm provided by the embodiment of the present application;

[0023] Figure 6 It is a schematic diagram of the support vector machine hyperplane provided by the embodiment of the present application;

[0024] Figure 7Schematic diagram of the neural network structure provided by the embodiments of the present application. Detailed implementation manners

[0025] To better understand the technical solutions of the present application, the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0026] It should be clear that the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.

[0027] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms "a", "the" and "said" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0028] It should be understood that the term " / and / " used herein is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " herein generally represents an "or" relationship between the associated objects before and after.

[0029] Before introducing the embodiments of the present application, the related technologies and their technical problems will be described first.

[0030] In the current digital network environment, enterprise networks or systems, such as ticket service systems, etc., face various forms of threats, including the implantation of malicious software, the escalation of network attack means, the increase in social engineering attacks, and the prominent security threats of mobile devices. These threats not only pose serious threats to the normal operation and data security of enterprises, but also may lead to the leakage of sensitive information.

[0031] Among them, component poisoning attack is a new type of attack method that has emerged in the field of network security in recent years. Attackers deliberately introduce malicious code or incorrect data into the components of software or systems to disrupt the normal operation of the system or steal sensitive information. This attack method has the characteristics of strong concealment and great destructiveness, bringing great challenges to network security protection.

[0032] For example, the specific means of component poisoning attack can be as follows:

[0033] Imitating well-known components: Attackers will imitate well-known open-source components, such as BeautifulSoup, Pillow, Selenium, etc., and conduct phishing attacks by uploading malicious components with similar names.

[0034] Releasing malicious component packages: Attackers release malicious component packages in the Node Package Manager (NPM) repository, such as ws-paso-jssdk, pingan-vue-floating, etc. These component packages carry remote control scripts that can execute system commands to achieve remote control of the target machine. Here, Node can refer to a network node or Node.js (an open-source server-side JavaScript runtime environment).

[0035] Stealing sensitive information: Attackers release malicious packages in the Pypi repository, such as urllitelib, urtelib32, graphql32. The main purpose of these packages is to steal sensitive data in the victim's personal computer operating system, including system basic information, system screenshots, password cookies, etc.

[0036] Given the severity and prevalence of component poisoning attacks, it is particularly important to develop effective component poisoning detection and defense technologies. These technologies can help enterprises and organizations detect and respond to potential threats in a timely manner, thereby protecting the security of their information data and business operations.

[0037] Therefore, the embodiment of this application proposes a method for processing component poisoning. By obtaining the detection instructions submitted by the user, using at least one component included in the detection instructions as the detection object this time, and according to the identity information of at least one component included in the detection instructions, obtaining the characteristic data of at least one component, such as obtaining characteristic data such as hash values and digital signatures. Then, verify the security of at least one component according to the characteristic data. For the components that pass the verification, continue to analyze the poisoning behavior. For the components that fail the verification or have poisoning behavior, trigger corresponding defense actions according to the preset defense strategy. For example, the defense actions can be data cleaning, denial of service, isolating users, etc. Among them, the defense strategy is used to indicate the defense actions taken against various poisoning behaviors.

[0038] The method proposed in the embodiment of this application can be applied to application scenarios such as ticket service systems to deal with possible component poisoning attack behaviors in the ticket service system and improve the security of the ticket service system. The method proposed in the embodiment of this application can also be applied to other application scenarios, such as being applied to the air-rail intermodal system or other service systems.

[0039] The method proposed in the embodiment of this application can be applied to electronic devices. The electronic device can be, for example, a server. Exemplarily, Figure 1 shows a schematic structural diagram of the server. As Figure 1As shown, the server 100 may include: one or more processors 110, a communication interface 120, a memory 130, and a communication bus 140 that connects different components (including the memory 130, the communication interface 120, and the processor 110).

[0040] The communication bus 140 represents one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, or a local bus using any of the various bus structures. For example, the communication bus 140 may include, but is not limited to, an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MCA) bus, an Enhanced ISA bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnection (PCI) bus.

[0041] An electronic device typically includes a variety of computer system-readable media. These media can be any available media that can be accessed by the electronic device, including volatile and non-volatile media, removable and non-removable media.

[0042] The memory 130 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory. The memory 130 may include at least one program product having a set (e.g., at least one) of program modules that are configured to execute the video summary generation method provided in the embodiments of the present application.

[0043] A program / utility with a set (at least one) of program modules may be stored in the memory 130. Such program modules include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules typically execute the functions and / or methods in the embodiments of the present application.

[0044] The processor 110 executes various functional applications and data processing by running the programs stored in the memory 130, such as implementing the video summary generation method provided in the embodiments of the present application.

[0045] It should be understood that Figure 3The processor 110 in the server 100 shown may be a system-on-chip (SOC). The processor 110 may include a central processing unit (CPU), and may further include other types of processors, such as a graphics processing unit (GPU), etc.

[0046] A specific embodiment is listed below.

[0047] As Figure 2 shown, the component poisoning processing method proposed in the embodiments of the present application can be executed based on an electronic device, such as based on a server or other electronic devices as Figure 1 shown. Exemplarily, the method may include the following processes:

[0048] S101: Obtain a detection instruction.

[0049] An interaction module may be deployed in the electronic device, and the user receives a detection instruction input by the user.

[0050] The component poisoning processing method proposed in the embodiments of the present application may include component poisoning analysis and defense. The processing flow of this processing method may be started in response to a detection request submitted by the user, that is, when the user submits a detection request, poisoning detection and defense strategy implementation for the component starts. The electronic device obtains the detection instruction issued by the user, that is, obtains the detection request submitted by the user. The acquisition of the detection instruction may be implemented through the interaction module. For example, the interaction module is started and ready to receive user input, and the user may submit a detection instruction through the front-end interface.

[0051] Among them, the interaction module may be set in the same electronic device as the data verification module, the poisoning detection module, etc., or may be set in different electronic devices. For example, the interaction module may be set in another electronic device (supporting human-computer interaction), and the user may submit a detection instruction on another electronic device, and then another electronic device forwards the detection instruction to the electronic device where the data verification module and other modules are deployed.

[0052] The detection instruction carries component information indicating the component to be detected this time. The component information at least includes the identity information of the component to be detected. The identity information may be the component ID or the component name, etc., which can uniquely identify the component identity. Or, in other embodiments, the component information carried in the detection instruction may also carry feature data information, and the feature data information is used to indicate the category of the feature data that needs to be obtained for this detection, that is, which feature data needs to be obtained. For example, whether to obtain the hash value, whether to obtain the digital signature, and whether to obtain the source code of the component, etc.

[0053] S102: Forward the detection instruction.

[0054] The interaction module forwards the detection instruction to the data verification module.

[0055] S103: Obtain feature data.

[0056] The data verification module obtains the feature data corresponding to the corresponding component according to the identity information of the component included in the detection instruction.

[0057] The feature data can also be at least one of digital features such as hash values and digital signatures.

[0058] If only the component identity information is carried in the detection instruction, the data verification module can obtain the feature data corresponding to the component according to a preset rule. For example, the preset rule is to obtain only the hash value, or only the digital signature, or the preset rule indicates to obtain both the hash value and the digital signature. Or, other types of feature data can also be obtained.

[0059] If the detection instruction contains the identity information of the component and the feature data information to be obtained in this detection, the data verification module obtains the corresponding feature data according to the indication of the detection instruction. For example, if the detection instruction indicates to obtain only the digital signature, the data verification module only obtains the digital signature of the component. If the detection instruction indicates to obtain only the hash value, the data verification module only obtains the hash value. Or, if the detection instruction indicates to obtain the hash value, digital signature and other feature data (such as source code, etc.), the data verification module obtains the feature data of the category that matches the feature data information in the detection instruction.

[0060] Among them, obtain the legal hash value corresponding to the component.

[0061] S104: Perform data verification on the component.

[0062] In S103, the feature data is obtained. In S104, the component is verified according to the obtained feature data.

[0063] Exemplarily, the specific verification technical means can be hash value comparison and / or digital signature verification.

[0064] Hash value comparison:

[0065] Calculate the hash value (to be verified) of at least one component, and compare it with the legal hash value pre-stored in the trusted database. If they match, continue with the digital signature verification, or the verification passes; if the comparison result is inconsistent, the verification fails.

[0066] For example, the first component is one of at least one component to be detected this time. For a message with part or all of the source code of the first component as input, a first hash value is calculated using SHA-256. Additionally, according to the identity information of the first component, the legal hash value (second hash value) of the first component is obtained from a trusted database, and the first hash value is compared with the second hash value. If the comparison result is consistent, the verification passes; otherwise, the verification fails.

[0067] It should be noted that in practical applications, for at least one component to be detected, a legal hash value may not be pre-stored. Then, secondary development can be performed on the component without a pre-stored legal hash value. After determining the security and legality of the component, a hash algorithm is used on the source code in the component to calculate a legal hash value.

[0068] For example, in this embodiment, the SHA-256 algorithm can be used to calculate the hash value (legal hash value, i.e., the second hash value) of the component, and the calculated second hash value is recorded or saved in a trusted database. In this way, a unique legal hash value can be established for each component, and the hash value of the component is recalculated before each use of the component, and the newly calculated hash value is compared with the legal hash value pre-stored in the trusted database. If the hash values do not match, it indicates that the component may have been tampered with.

[0069] Digital signature verification:

[0070] Obtain the digital signatures of at least one component. The digital signature can be obtained by signing the component with the private key in the asymmetric encryption algorithm.

[0071] In practical applications, it can be required that all components come with valid digital signatures, and before use, the digital signature attached to the component is verified according to the pre-stored public key. The digital signature can ensure the integrity of the component and the authenticity of the source.

[0072] A legal component provider can publish the public key to the component user, and before publishing the component, sign the component with the private key and publish the component with the attached digital signature to the component platform. Before using the component, the component user can use the public key pre-published by the legal component provider to verify the digital signature attached to the component, that is, private key signature and public key verification. If the verification passes, the digital signature is a legal digital signature, indicating that the component is from a real and legal source. If the verification fails, it indicates that the component may be a non-legal source that has been tampered with or an unsafe component.

[0073] In this way, by using at least one of the above hash value verification or digital signature verification, the most basic security verification of the component can be performed.

[0074] In some embodiments, the components that have passed the verification can be further analyzed for poisoning behavior. In other embodiments, the components can be first analyzed for poisoning behavior and then data verification (hash value and / or digital signature verification) can be performed. Or, in some other embodiments, only data verification or only poisoning behavior analysis can be performed on the components.

[0075] S105: Analyze the components for poisoning behavior.

[0076] In this embodiment, the object of the poisoning behavior analysis can be the components that have passed the verification, that is, data verification is first performed, and after passing the verification, the poisoning behavior analysis is performed. In other embodiments, it can be that at least one component is first analyzed for poisoning behavior, and then the components without poisoning behavior are verified for data. Or, the poisoning behavior analysis and data verification are performed in parallel, and the present application specification does not limit the sequence of the poisoning behavior analysis and data verification.

[0077] In this embodiment, the poisoning behavior analysis can include static code analysis and / or dynamic behavior analysis. Among them, static code analysis can be to perform static code analysis on the source code of the component to find abnormal situations such as possible malicious code patterns, abnormal behaviors, or unauthorized functions. Dynamic behavior analysis can be understood as running the component in a controlled environment and monitoring its behavior and communication. Through behavior analysis, hidden malicious behaviors or abnormal communications can be discovered.

[0078] Exemplarily, the static code analysis can include one or more of analysis methods such as syntax analysis, semantic analysis, code pattern recognition, and data dependency analysis.

[0079] Among them, the syntax analysis can include the following steps:

[0080] S1051: Lexical analysis.

[0081] Specifically, the source code can be decomposed into multiple lexical units. The lexical units can be basic elements such as keywords, identifiers, constants, and operators. Decomposing into multiple lexical units means identifying the basic elements such as keywords, identifiers, constants, and operators in the code. For example, in a Python code, keywords such as "if", "else", "while", identifiers such as "my_variable", constants such as "123", and operators such as "+", "-", "==" are identified. This step is similar to splitting an article into individual words, laying the foundation for subsequent analysis.

[0082] S1052: Syntax rule matching.

[0083] Next, according to the syntax rules of the programming language adopted by the analyzed component object, check whether the combination of these lexical units conforms to the corresponding syntax specifications. For example, in Java, it can be checked whether the structure of the statement is correct, such as whether the correct conditional expression follows an "if" statement, and whether the definition of the method conforms to the syntax requirements (for example, including the correct return type, parameter list, etc.).

[0084] If situations that do not conform to the syntax rules are found, they will be marked as syntax errors, such as missing parentheses, misspelled keywords, etc. These errors may be abnormal situations caused by malicious tampering and may affect the normal operation of the code.

[0085] Among them, semantic analysis can include at least one of the following steps:

[0086] S1053: Variable and type analysis.

[0087] Track the definition, use, and type information of variables in the code. For each variable, determine the position where it is first defined and how it is used in subsequent code. For example, in C++ code, if an "int my_variable;" is defined, pay attention to whether this variable is correctly assigned later (such as "my_variable = 5;") and whether the types match when participating in operations (for example, an integer variable and a string cannot be directly added).

[0088] At the same time, check the scope of variables to ensure that variables are correctly used within the scope where they are defined, and situations such as accessing undefined variables across scopes do not occur.

[0089] S1054: Function and method analysis.

[0090] For functions and methods, examine aspects such as their definitions, parameter passing, return values, etc. It checks whether the signature of the function (including the function name, parameter types and numbers, return type) is correctly defined, whether the parameters are correctly used within the function (for example, whether there are unused parameters), and whether the return value meets the expectations (such as whether a value should be returned but actually is not).

[0091] In object-oriented programming, it also analyzes the methods of classes, including the impact of inheritance relationships on methods, such as whether subclasses correctly override the methods of the parent class, etc.

[0092] S1055: Control flow analysis.

[0093] Parse control flow statements in the code, such as "if", "else", "while", "for", etc., to understand the code execution flow. Also, determine the code execution paths under different conditions and whether there are any unreasonable control flow situations.

[0094] For example, check if there are code blocks that will never be executed (such as an "if" condition that is always false but contains important logic code), or if there are infinite loops (such as no proper exit condition in a "while" loop). These situations may be abnormal execution paths deliberately set by malicious code or caused by code errors.

[0095] Among them, code pattern recognition may include at least one of the following recognition steps:

[0096] S1056: Match common malicious code patterns.

[0097] Based on a predefined malicious code pattern library, search for matching cases in the source code. These malicious code patterns may include at least one of patterns such as backdoor insertion, code obfuscation, and abnormal system calls.

[0098] Backdoor insertion: Look for whether there are hard-coded special entry points or passwords in the code, such as a fixed combination of username and password in authentication-related code (e.g., "if (username == 'backdoor_user' && password =='secret_password') { return true;}"), or hidden URL paths or port numbers for unauthorized access to functions of components (e.g., "if (request.getPath () == ' / backdoor_path'){ executeMaliciousFunction ();}").

[0099] Code obfuscation: Identify whether the code has excessive obfuscation means, such as extensive use of randomly generated variable names, complex control flow structures (such as multi-layer nested "if-else" statements, "goto" statements, etc.), making the code difficult to understand and analyze, which may be to hide the true intention of malicious code.

[0100] Abnormal system calls: Check if there are unreasonable system calls. For example, in an ordinary business component, suddenly there are functions that call low-level operating system functions for dangerous operations such as deleting files and modifying system configurations (such as "system ("rm -rf / important_directory");"), and normally this component should not be involved in such operations.

[0101] S1057: Unauthorized function identification.

[0102] Based on the expected functions and permission settings of components, identify whether there are unauthorized functions in the code. This may involve checking the permission verification logic of function calls to see if there are operations that low-level users can perform with high-level user permissions. For example, if a regular user role can directly call an administrative-level function in the code, this may be due to malicious code tampering with the permission verification mechanism or the existence of vulnerabilities.

[0103] Among them, data dependency analysis may include at least one of the following steps:

[0104] S1058: Data flow tracing.

[0105] Trace the flow of data in the code from its generation (such as variable definitions, function return values, etc.) to its final usage or storage location. For example, in a database query operation, track how the query result data is processed, whether it is correctly stored in variables, and whether it is subsequently used for other legitimate operations (such as being displayed on the interface, performing further calculations, etc.).

[0106] Through data flow tracing, it is possible to discover whether there is a risk of data leakage, such as whether data is inappropriately transmitted externally (such as through an unencrypted network connection) or stored in an insecure place (such as a publicly accessible log file).

[0107] S1059: Data dependency determination.

[0108] Determine the dependency relationships between different data elements in the code. For example, the return value of a function may depend on multiple input parameters. By analyzing such dependency relationships, it can be understood how the change of a certain parameter will affect the running result of the entire function.

[0109] This is very helpful for discovering abnormal data dependency relationships that may be set by malicious code, such as triggering malicious functions by changing the value of a certain input parameter (such as causing a function to perform a file deletion operation instead of a normal business operation).

[0110] Exemplarily, dynamic code analysis may include the following steps:

[0111] Run the component in a pre-built test environment (or a controlled environment, isolation environment) and collect data.

[0112] S10510: In a pre-built test environment, run at least one component to be detected.

[0113] Specifically, a virtual machine (such as VMware, VirtualBox, etc.) or container technology (such as Docker, Kubernetes, etc.) can be used to build a test environment that is similar to the actual application environment but relatively isolated. This can ensure that the operation of the component will not affect the production system in the actual application (such as the ticket service system), and at the same time facilitate the independent observation and analysis of its behavior.

[0114] Configure the environment in the virtual machine or container to match the operating system, software dependencies, etc. required for the component to run, so as to simulate the actual running scenario as realistically as possible.

[0115] In addition, install various monitoring tools in the built test environment to collect various data during the operation of the component. These monitoring tools include one or more of the following tools:

[0116] System monitoring tools: such as Sysmon (for Windows systems), top (for Linux systems), etc., which are used to monitor the usage of system resources, including CPU usage, memory occupancy, disk I / O, network bandwidth, etc. Through these data, it is possible to understand the consumption of system resources by the component during operation and whether there are abnormal behaviors such as resource exhaustion.

[0117] Network monitoring tools: such as Wireshark, tcpdump, etc., which are used to capture network communication packets between the component and external systems. These tools can record information such as the source address, destination address, port number, protocol type, and transmitted data content of the communication, so as to analyze the communication behavior of the component.

[0118] Process monitoring tools: such as Process Explorer under Windows, ps and htop under Linux, etc., which are used to track the process status corresponding to the component, including the start time of the process, running status (running, paused, sleeping, etc.), and the system resources occupied. By observing the changes in the behavior of the process, abnormal process activities can be found, such as suddenly occupying a large amount of resources or frequently starting / stopping, etc.

[0119] After the test environment is built and the monitoring tools are deployed, the component can be started: start the component to be analyzed in the built controlled environment and make it run according to the normal business process. Ensure that the input data required for the component to run (such as user requests, configuration files, etc.) is provided so that it can carry out business activities normally, in order to comprehensively observe its behavior in the actual working state.

[0120] S10511: Continuously collect data using the monitoring tools.

[0121] Use monitoring tools deployed in a controlled environment to continuously collect various types of data during the operation of components. For example: The system monitoring tool records the usage of system resources at preset time intervals, forming a resource usage curve that changes over time. The preset time interval can be a few seconds or a few minutes, such as 5 - 10 seconds or 2 - 10 minutes, which can be set according to the specific situation of the actual application environment.

[0122] The network monitoring tool captures the network communication data packets of the component in real time and saves them to a local file or database for subsequent analysis. For components that run for a long time, it may be necessary to periodically clean or rotate the stored data packet files to avoid insufficient disk space.

[0123] The process monitoring tool continuously updates the status information of the monitored process and records its status changes at different time points, such as when it occupies more resources and when it enters the sleep state.

[0124] S10511: Analyze the monitoring data to identify anomalies.

[0125] Identifying anomalies can specifically be one or more of the following anomaly identifications:

[0126] S105111: System resource anomaly identification.

[0127] System resource anomalies include resource exhaustion anomalies and / or resource fluctuation anomalies.

[0128] Among them, resource exhaustion: If it is observed that the component continuously occupies a large amount of CPU during operation (such as the CPU usage rate remains above 90% for a long time), exhausts memory (such as the memory occupancy keeps climbing until the system prompts insufficient memory), causes a large amount of disk I / O (such as the disk read / write speed far exceeds the normal business requirements), or overconsumes network bandwidth (such as the network transmission speed has been at the peak and lasts for a long time), this may indicate that there is a potential risk of resource exhaustion attack or problems such as low code efficiency in the component, and it may be caused by malicious behavior.

[0129] Resource fluctuation anomaly: Under normal circumstances, the component's use of system resources should be relatively stable and fluctuate within a certain range. If it is found that the resource usage situation shows frequent and large fluctuations (such as the CPU usage rate soars from 20% to 80% in a short time and then drops rapidly), this may imply that there is abnormal logic inside the component or it is affected by external interference, and the reason needs to be further analyzed.

[0130] S105112: Network communication anomaly identification.

[0131] If one or more of the following anomalies exist, it is identified as a network communication anomaly:

[0132] Unknown destination communication: By analyzing the data packets captured by network monitoring tools, if it is found that a component communicates with some addresses outside the expected range (such as unknown external IP addresses, unauthorized internal IP addresses, etc.), this is very likely to be abnormal behavior, which may mean that the component has been implanted with a backdoor and is communicating with an external malicious server.

[0133] Abnormal port communication: If a component frequently communicates with some non-business-related ports (such as a Web application component frequently communicating with port 21 (FTP service port), while normal business should not involve this port), or communicates with some high-risk ports, this also indicates an abnormality, which may be that the component is being exploited for illegal activities. Among them, high-risk ports can be common hacker attack ports, such as 3389 (remote desktop port), etc.

[0134] Abnormal data transmission: Observe the data content transmitted in the data packets. If it is found that there is a large amount of unencrypted data transmission (when encryption should be used), the transmitted data format does not conform to the normal business specification (such as transmitting some garbled characters or unrecognizable formats), the amount of data transmitted far exceeds the normal business requirements (such as a simple query operation transmitting a large amount of data), etc., this may be a manifestation of malicious behavior, which may involve data leakage or other illegal activities.

[0135] S105112: Abnormal process behavior identification.

[0136] If one or more of the following abnormalities exist, it is identified as network communication abnormality:

[0137] Abnormal process startup: If it is found that the process corresponding to the component frequently starts and stops (such as restarting every few minutes), or starts at an abnormal time (such as suddenly starting during system idle time, while normal business does not need to start at this time), this may indicate that there is a problem with the component, and it may be abnormal behavior caused by malicious code.

[0138] Abnormal process resource occupancy: When it is observed that a process suddenly occupies a large amount of system resources (such as a process that was originally running normally suddenly occupies more than 90% of the CPU or a large amount of memory), and this situation persists, this may indicate that there is a problem inside the process, and it may be that malicious code is performing some resource-consuming malicious operations.

[0139] Abnormal process execution path: By analyzing the information provided by the process monitoring tool, if it is found that the execution path of the process is different from the execution path expected by the normal business process. For example, operation A should be executed, but operation B is actually executed, and operation B has nothing to do with the normal business, this may be that malicious code has tampered with the execution path of the process, resulting in abnormal behavior of the component.

[0140] Thus, based on the above static code analysis and / or dynamic behavior analysis, any one or more of the above abnormal behaviors of the component can be identified, and the component with the abnormal behavior is the component with the poisoning behavior.

[0141] In some embodiments, machine learning models can be used for auxiliary detection. For example, machine learning algorithms such as random forest, support vector machine (SVM), and neural network can be integrated. Using machine learning models significantly improves the recognition rate of covert poisoning behaviors, and the false positive rate is reduced by nearly 30%. To improve the accuracy and efficiency of poisoning behavior detection, the present method constructs a multi-dimensional analysis model by combining the following machine learning algorithms:

[0142] 1. Random Forest:

[0143] The random forest algorithm is suitable for classifying malicious code patterns and abnormal behavior characteristics. Figure 5 This is a schematic diagram of a random forest algorithm provided for an embodiment of the present invention. As Figure 5 shown in the figure, the random forest includes multiple decision trees. By constructing multiple decision trees and summarizing their prediction results, potential malicious components can be effectively identified. Specifically, in the feature extraction stage, the random forest classifies the static and dynamic features of the component to identify potential malicious code patterns.

[0144] 2. Support Vector Machines (SVM):

[0145] Figure 6 This is a schematic diagram of a support vector machine hyperplane provided for an embodiment of the present invention. As Figure 6 shown in the figure, it consists of an optimal hyperplane and multiple support vectors. Among them, the support vectors are several training sample points that are the closest to the optimal hyperplane and meet certain conditions. The SVM can be applied to the classification of malicious behaviors in high-dimensional data scenarios by finding the optimal hyperplane to separate the features of normal and abnormal components. Specifically, in the anomaly detection stage, the SVM classifies the feature vectors of the component to identify abnormal component behaviors.

[0146] 3. Neural Network:

[0147] Figure 7 This is a schematic diagram of a neural network structure provided for an embodiment of the present invention. As Figure 7 shown in the figure, the neural network consists of an input layer, several hidden layers, and an output layer. The input layer is used to receive external input data, the hidden layer is located between the input layer and the output layer, and is used to process the input data and extract features. The output layer generates the final result of the network.

[0148] Neural networks learn complex features through multi-layer non-linear transformations and can capture hidden poisoning patterns in the code (such as obfuscated code or abnormal dependencies). Specifically, in the feature extraction and anomaly detection phases, neural networks can deeply analyze the static and dynamic features of components to identify potential malicious components.

[0149] First, the neural network combines two different types of information. One is static code features, such as whether there are syntax errors in the code and whether there are patterns like malicious code; the other is dynamic behavior features, such as how much resources the program occupies during operation and whether there is behavior of secretly connecting to the network. The neural network puts these two types of information together to form a complex input vector.

[0150] Then, use the already labeled data (such as which data is normal and which is malicious) to train the model, and adjust the parameters through cross-validation to make the model more accurate.

[0151] During actual detection, the model will judge in real time whether a component is poisoned by calculating the "poisoning probability" and then judging whether it is an abnormal behavior according to the set threshold.

[0152] The advantages of this method are that the two algorithms of random forest and SVM are very good at processing structured features and can quickly identify known attack methods. The neural network can capture complex non-linear relationships and can discover relatively hidden new attack means, such as code obfuscation. The model can be updated online and can adapt to new attack means and will not be easily bypassed by new attack methods.

[0153] The method for auxiliary detection provided by the embodiments of the present invention can combine multiple features and advanced technologies and can efficiently detect and respond to various complex attack behaviors.

[0154] Optionally, in actual applications, in addition to the above means such as poisoning behavior analysis and data verification, supply chain monitoring can also be used to control the source of components. Specifically, it can be to monitor the download source and distribution channel of components to ensure the reliability and security of the component source. For unknown or untrusted sources, they should be carefully processed or refused to be used. Among them, an open-source platform or website address with the number of users less than a predetermined number and belonging to a website address with medium-high risk can be determined as a component with an untrusted source.

[0155] In some embodiments, the method for constructing a poisoning processing can be applied to the ticketing system of railway passenger tickets. At least one component in the above step 101 is a component in the ticketing system of railway passenger tickets. The ticketing system has unique characteristics such as data flow and operation mode compared with other systems. For example, the ticketing system designs a large number of key operations such as real-time intersections, user authentication, ticketing inventory management, and payment processing. These characteristics make the ticketing system a major target of attacks, especially through component poisoning attacks to steal user data, tamper with ticketing information, or disrupt the normal operation of the system.

[0156] For real-time transaction processing, the ticketing system needs to process a large number of real-time transactions. An attacker can poison the components of the ticketing system to tamper with transaction data or steal payment information.

[0157] For user authentication, the ticketing system usually involves sensitive operations such as user login and authentication. An attacker can poison the components to steal user credentials.

[0158] For ticketing inventory management, the ticketing system needs to manage a large number of ticket inventories. An attacker can poison the components to tamper with inventory data, resulting in over-selling of tickets or abnormal inventory.

[0159] For payment processing, the ticketing system involves payment processing in the ticket purchase link. An attacker can poison the components to steal payment information or tamper with the payment process.

[0160] Therefore, this embodiment proposes a poisoning behavior analysis method for the ticketing system according to the characteristics of the ticketing system. Specifically, first, a model is constructed according to the data flow characteristics of the ticketing system to obtain a data flow model of the ticketing system. By analyzing this data flow model, the key data flow nodes of the ticketing system are identified. For example, key data flow nodes such as user login, ticket query, and payment processing.

[0161] When performing poisoning behavior analysis, the pre-established data flow model of the ticketing system can be obtained. Then, the target key data flow nodes corresponding to at least one of the above components are determined. For example, if the component is mainly responsible for processing order data, the target key data flow node corresponding to this component can be payment processing. Then, based on the data flow model of the ticketing system, it is determined whether the target key data flow node has one or more of the following anomalies: abnormal login behavior, abnormal ticket purchase behavior, abnormal payment behavior, and abnormal modification behavior of the ticket inventory in the ticketing system.

[0162] Specifically, the ticket system data flow model conducts user behavior analysis on the data flow. By analyzing user behaviors such as login, ticket purchase, and payment, abnormal user behavior patterns are detected. For example, when it is detected that the same user attempts to log in multiple times or payment fails within a short period, it indicates that there is a malicious component being poisoned and attempting to steal user credentials.

[0163] For the anomaly detection of ticket inventory, abnormal inventory modification operations can be detected by monitoring the changes in ticket inventory. For example, when it is detected that the inventory quantity fluctuates significantly within a short period, it can be determined that there is a malicious component being poisoned and tampering with the inventory data.

[0164] For the verification of the payment process, abnormal payment requests can be detected by verifying the integrity of the payment process. For example, when it is detected that the payment information carried in the payment request does not match the user input, it can be determined that there is a malicious component being poisoned and tampering with the payment information.

[0165] In the embodiments of the present invention, by deeply analyzing the operation logic and data interaction mode of the ticket system, malicious attacks specifically targeting the ticket system, especially component poisoning attacks, can be captured and identified more precisely. Based on the data flow modeling, the data flow of the ticket system is monitored in real time to detect abnormal data interaction behaviors.

[0166] S106: Trigger a defense action for components that fail verification or have poisoning behavior.

[0167] Specifically, after the poisoning detection module identifies that a component has poisoning behavior, it sends an instruction to the defense module to trigger the defense module to take a defense action.

[0168] S107: Execute the defense action.

[0169] Specifically, it can be the defense module. For components that fail verification or have poisoning behavior, according to the preset defense strategy, corresponding defense actions are triggered. The defense strategy is used to indicate the defense actions to be taken against various poisoning behaviors.

[0170] For example, when poisoning behavior is detected, preset defense actions are triggered, such as data cleaning, denial of service, user isolation, etc.

[0171] Optionally, in S106, a defense action can also be triggered for components with untrusted or unknown sources.

[0172] Optionally, S108 and S109 can also be continued to be executed.

[0173] S108: Record the defense action.

[0174] For example, which defense action is executed for a component or a type of components can be recorded for subsequent query.

[0175] Recording defense actions can write logs of events related to defense actions into a logging system. The logging system can be a logging system provided by a third party.

[0176] S109: Generate and display a detection report and a defense report.

[0177] The detection report can include detected abnormal information, such as component information that fails verification, or components that detect poisoning behavior, or components with untrusted sources, which can be displayed on the detection report.

[0178] The defense report can include defense action information, and the defense action information is at least the name or category information of the defense actions taken for components with abnormalities.

[0179] Optionally, in some embodiments, other defense strategies can also be adopted, such as establishing whitelists and blacklists, as supplementary defense strategies.

[0180] For example, maintain a whitelist of trusted components and only allow the use of components in the whitelist. For components not listed in the whitelist, strict review and testing should be carried out. Also, establish a blacklist of components, listing components known to be poisoned or having serious security vulnerabilities. For components in the blacklist, their use should be prohibited and relevant teams should be notified for repair or replacement.

[0181] Among them, maintaining a whitelist of trusted components can be Figure 2 According to the process shown, components that pass verification and are determined to have no poisoning behavior through poisoning behavior analysis are added to the whitelist list, and components that fail verification or are determined to have poisoning behavior through poisoning behavior analysis are added to the blacklist.

[0182] As Figure 3 shown, in some embodiments, the component poisoning handling method proposed in the embodiments of the present application can be executed based on the system architecture shown in Figure 3 shown.

[0183] Among them, the data verification / poisoning detection module and the defense strategy module can be deployed in the same electronic device. For example, as Figure 3 shown, deployed in electronic device 2. In other embodiments, they can also be deployed in different electronic devices. The data verification / poisoning detection module means including a data verification module and / or a poisoning detection module.

[0184] Next, in combination with the Figure 3 shown system architecture, the poisoning behavior handling method proposed in the embodiments of the present application will be further described.

[0185] As Figure 3As shown, the user can issue a detection instruction to initiate the detection process. An interaction module can be deployed in the electronic device 1. After receiving the user's detection instruction, the electronic device 1 can send an execution command to the data verification / poisoning detection module. In response to this execution command, the data verification / poisoning detection module requests data from the database (a trusted database), mainly requests feature data, such as legitimate hash values, digital signatures, and other feature data, and receives the feature data returned by the database. Then, it executes the data verification and / or poisoning detection process for the component. Poisoning detection, that is, detecting whether there is a poisoning behavior in the component, can specifically refer to the description of the above poisoning behavior analysis steps.

[0186] Next, the data verification / poisoning detection module sends the analysis result to the defense strategy module. The analysis result at least includes the identity information of the components that fail verification or have poisoning behavior; the defense strategy module sends a defense instruction to the electronic device 1. The interaction module in the electronic device 1 supports human-computer interaction. The user can determine to execute the defense instruction through the interaction interface provided by the electronic device 1. Then, the electronic device 1 executes a defense action for the components indicated as abnormal (failing verification or having poisoning behavior) in the analysis result. After that, the status information of the components after the defense action is recorded in the database (trusted database). The database stores the log file corresponding to the event related to this defense action in the log database. The log data in the log database can be used to display log analysis to the user. The display of log analysis can be in response to a user request or can be automatically displayed after the defense action is executed.

[0187] As Figure 4 shown, in some embodiments, the component poisoning handling method proposed in the embodiments of the present application can also adopt the process as Figure 4 shown.

[0188] Specifically, this process can include: after the detection process starts, collect various types of data required for detection, then perform feature extraction on the collected data, based on the extracted features, perform anomaly detection. If an anomaly is found, immediately perform an alarm response, isolate and block the component with the anomaly, and analyze and trace the component. Repair or restore the component to obtain a legitimate component, and end the process after strengthening preventive measures. This process can be used as a supplementary process for the process as Figure 2 shown, or can be implemented independently.

[0189] In summary, the method proposed in the embodiments of the present application has proposed innovative methods and system designs in component poisoning detection and defense, including but not limited to detection algorithms, automated response mechanisms, user interface designs, and integration solutions with existing ticketing systems, etc.

[0190] For example, in the method proposed in the embodiments of the present application, a poisoning detection algorithm dedicated to the ticket system is adopted. The component poisoning processing method proposed in the embodiments of the present application is a poisoning detection algorithm designed according to the operation mode and data flow characteristics of the ticket system. By deeply analyzing the unique operation logic and data interaction mode of the ticketing system, this algorithm can more accurately capture and identify malicious attacks specifically targeting the ticketing system, especially component poisoning attacks. It can not only timely detect the poisoned components or abnormal data flows, but also effectively distinguish normal operations from potential threats, thus greatly improving the security protection ability of the ticketing system.

[0191] The method proposed in the embodiments of the present application can perform real-time monitoring on the security of ticket data. This method equips the ticket system with a mechanism for real-time monitoring of data, constantly monitoring every subtle change in the ticket data. It can quickly capture any abnormal behavior, such as abnormal modification of data or unauthorized access, and immediately respond to effectively prevent potential security threats. Through this immediate monitoring and response, the integrity and security of ticket data are ensured, enabling each ticket transaction to be carried out in a safe and trustworthy environment.

[0192] The method proposed in the embodiments of the present application is deeply integrated with the ticket system, carefully creating a defense solution deeply integrated with the passenger ticket system, which can seamlessly integrate into the existing ticket operation process. Through such deep integration, this defense mechanism not only does not interfere with the normal operation of the ticket system, but can more accurately identify and defend against potential security threats. This seamless integration method not only ensures the fluency of the ticket system, but also greatly improves the security protection ability of the system.

[0193] The method proposed in the embodiments of the present application conducts multi-dimensional security protection, adopting multi-dimensional security protection measures to build a comprehensive security protection system, which covers multiple levels such as the network layer, application layer, and data layer, ensuring the security and stability of the ticket system.

[0194] The method proposed in the embodiments of the present application can also provide detection reports and defense reports. It not only has powerful defense functions, but also particularly incorporates a reporting function to meet the strict requirements of ticket system operators in terms of security. Through this function, the security status of the system can be comprehensively recorded and analyzed, and it can provide a reliable basis for the traceability and investigation of incidents in the event of security incidents.

[0195] Therefore, the component poisoning processing method proposed in the embodiments of the present application can achieve at least one of the following technical effects:

[0196] (1) Timely discover malicious components.

[0197] By implementing continuous component monitoring and automated security analysis strategies, this approach enables real-time tracking and in-depth analysis of the status of each component in the system. This approach aims to promptly detect and identify components that may have been maliciously tampered with or "poisoned," allowing swift countermeasures to effectively prevent these contaminated components from adversely affecting the overall system or posing potential security risks. Leveraging advanced monitoring technology and automated analysis tools, comprehensive control of component status is ensured, building a solid defense for the secure and stable operation of the system.

[0198] (2) Accurately locate malicious code.

[0199] The poisoning detection system using the component poisoning treatment method proposed in the embodiments of this application, with its high-precision positioning capabilities, can quickly and accurately identify malicious code fragments lurking in the system. This function is crucial because it not only quickly pinpoints the specific location of security vulnerabilities but also significantly reduces the time required to remediate them. By promptly removing these malicious codes, they can effectively prevent their further spread, thereby protecting the integrity and security of the system.

[0200] (3) Improve system security.

[0201] The component poisoning treatment method proposed in the embodiments of this application can promptly detect and properly handle maliciously poisoned components, playing a crucial role in improving the security of the entire system. By quickly identifying and isolating these contaminated components, the further spread of malicious code can be effectively blocked, significantly reducing the risk of system attacks. This measure not only protects the integrity of the system's core functions and data, but also significantly reduces the economic losses and reputational damage that may be caused by malicious code attacks.

[0202] (4) Preventing data leakage

[0203] Many malicious components often target users' sensitive data, including but not limited to passwords, cookies, and browsing history. Once leaked, this data poses a serious threat to user privacy and security. However, by implementing a series of effective defenses, a solid barrier can be built to protect this sensitive information. These defenses can promptly detect and block malicious activity, ensuring that sensitive user data is not illegally obtained and leaked to attackers. This not only protects user privacy but also provides a more secure and reliable digital environment.

[0204] (5) Protecting system integrity

[0205] Component poisoning attack is a highly destructive security threat that can undermine the integrity of a system by tampering with or implanting malicious code, leading to system crashes or malfunction. However, by implementing effective defense measures, it is possible to ensure that the system remains stable in the face of such attacks. These defense mechanisms can detect and isolate poisoned components in a timely manner, preventing attackers from using the poisoned components to cause further damage to the system. In this way, not only can the stability and availability of the system be protected, but also a more reliable and uninterrupted service experience can be provided to users.

[0206] (6) Protecting the privacy of user data and system security

[0207] Actively implementing component poisoning defense measures is responsible for the security of user information data. Through the above defense means, enterprises can effectively monitor and prevent the intrusion of malicious components, thereby ensuring the confidentiality, integrity, and availability of user data, and avoiding a series of problems that may be caused by data leakage or system damage.

[0208] (7) Machine learning enhanced detection capabilities

[0209] By integrating random forest, SVM, and neural network, the recognition rate of covert poisoning behavior has been significantly improved, and the false positive rate has been reduced by 30%.

[0210] (8) Dynamically adapting to new types of attacks

[0211] The model supports incremental learning and can quickly adapt to new variants of malicious code, ensuring the effectiveness of long-term protection.

[0212] The embodiments of the present application also provide an electronic device, which includes: a processor, and the processor is used to execute computer programs or instructions in a memory to implement the method described in any one of the above embodiments.

[0213] The electronic device involved in this application can be one or more of the following devices: smart phones, tablet personal computers (Tablet PCs), laptops, desktop computers, wearable devices, extended reality (XR) devices such as augmented reality (AR), virtual reality (VR), and mixed reality (MR), ultra-mobile personal computers (UMPCs), netbooks, or personal digital assistants (PDAs). The specific type of the electronic device is not particularly limited in the embodiments of this application.

[0214] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in this application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk).

[0215] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the relationship between associated objects and indicates that three relationships may exist. For example, A and / or B may represent the cases where A exists alone, A and B exist simultaneously, or B exists alone. Here, A and B may be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one of the following" and its similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c may be single or multiple.

[0216] The above are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for processing component poisoning, characterized in that, The method includes: Obtaining a detection instruction submitted by a user; the detection instruction contains identity information of at least one component that is the object of this detection; According to the identity information of the at least one component, obtaining feature data of the at least one component; according to the feature data, verifying the security of the at least one component; Analyzing whether there is a poisoning behavior in the at least one component or the components that pass the verification; For the components that fail the verification or have poisoning behavior, triggering corresponding defense actions according to a preset defense strategy; the defense strategy is used to indicate the defense actions taken for various poisoning behaviors.

2. The method according to claim 1, characterized in that Obtaining the feature data of the at least one component includes: Calculating a first hash value corresponding to a first component; the first component is one of the at least one component; Verifying the security of the at least one component includes: According to the identity information of the first component, obtaining a legitimate second hash value corresponding to the first component; Comparing the first hash value and the second hash value, if they are the same, the verification passes; if they are different, the verification fails.

3. The method according to claim 1, wherein Obtaining the feature data of the at least one component includes: Obtaining a digital signature carried by a first component; the digital signature is a signature obtained using the private key in an asymmetric encryption algorithm; Verifying the security of the at least one component includes: According to the identity information of the first component, obtaining the public key corresponding to the first component; Using the public key to verify the digital signature.

4. The method according to claim 1, wherein Analyzing whether there is a poisoning behavior in the at least one component includes: Performing static code analysis on the at least one component to determine whether there is a poisoning behavior in the component; Among them, the static code analysis includes one or more of the following operations: Decomposing the source code of the at least one component into lexical units; according to the syntax rules adopted by the source code, checking whether the combination of the lexical units conforms to the syntax rules; Obtaining the definition and type information of at least one variable in the source code of the at least one component; tracking whether the usage of the variable matches the definition and type information; Checking whether the signature of the function in the source code of the at least one component is correctly defined, whether the parameters in the function are correctly used inside the function, and whether the return value meets the expectations; Parsing the control flow statements in the source code of the at least one component to determine whether the execution path corresponding to the control flow statements is abnormal; Searching in the source code of the at least one component for code that matches a malicious code pattern in a predefined malicious code pattern library; the malicious code pattern library includes one or more of the following patterns: backdoor insertion, code obfuscation, abnormal system calls; Identifying whether there is an unauthorized function in the source code of the at least one component; Tracking whether the data flow in the source code of the at least one component is abnormal, where the data flow includes the generation to use or storage of data; Analyzing whether the dependency relationship between different data elements in the source code of the at least one component is abnormal.

5. The method according to claim 1, characterized in that, Analyzing whether there is a poisoning behavior in the at least one component includes: Perform dynamic behavior analysis on the at least one component to determine whether there is a poisoning behavior in the component; Wherein, the dynamic behavior analysis includes: Based on a pre-built test environment, run the at least one component; the test environment is built using virtual machine or container technology and is isolated from the actual monitored environment; at least one monitoring tool is deployed in the test environment; wherein, the at least one monitoring tool includes one or more of the following tools: system monitoring tool, network monitoring tool, process monitoring tool; Collect various types of data during the running of the at least one component through the monitoring tool, including performing one or more of the following operations: monitor the usage of system resources through the system monitoring tool; capture network communication data packets between the at least one component and the outside through the network monitoring tool; track the process status corresponding to the at least one component through the process monitoring tool; According to the various types of data, identify whether the at least one component has one or more of the following anomalies: abnormal system resource usage, abnormal network communication, abnormal process behavior; wherein, abnormal system resource usage includes resource exhaustion anomaly and / or resource fluctuation anomaly; abnormal network communication includes one or more of unknown destination communication, abnormal port communication, data transmission anomaly; abnormal process behavior includes one or more of abnormal process startup, abnormal resource occupation, abnormal process execution path.

6. The method according to claim 1, wherein The at least one component is a component of the ticketing system; the analysis of whether there is a poisoning behavior in the at least one component includes: Obtain a pre-established data flow model of the ticketing system; the data flow model of the ticketing system contains at least one key data flow node; the key data flow node includes at least one or more combinations of user login, ticket query, and payment processing; Determine the target key data flow node corresponding to the at least one component; Based on the data flow model of the ticketing system, determine whether the target key data flow node has one or more of the following anomalies: abnormal login behavior, abnormal ticket purchase behavior, abnormal payment behavior, and abnormal modification behavior of ticket inventory in the ticketing system.

7. The method according to any one of claims 1-5, characterized in that, For components that fail verification or have poisoning behavior, trigger corresponding defense actions according to the preset defense strategy, including: For components with poisoning behavior, trigger one or more of the following actions according to the preset defense strategy: data cleaning, denial of service, user isolation.

8. The method according to any one of claims 1-6, characterized in that, The method further includes: Add components that fail verification or have poisoning behavior to a pre-built blacklist; Add components that pass verification and have no poisoning behavior to a pre-built whitelist.

9. Component poisoning treatment device, characterized in that, The device includes: An interaction module, configured to obtain a detection instruction submitted by a user; the detection instruction contains the identity information of at least one component that is the object of this detection; A data verification module, configured to obtain the characteristic data of the at least one component according to the identity information of the at least one component; verify the security of the at least one component according to the characteristic data; A poisoning detection module for analyzing whether there is a poisoning behavior in the components that have passed the verification; A defense module for triggering corresponding defense actions according to preset defense strategies for components that fail the verification or have poisoning behaviors; the defense strategies are used to indicate the defense actions taken against various poisoning behaviors.

10. An electronic device, characterized in that, The electronic device includes: A processor, which is configured to execute computer programs or instructions in a memory to implement the method according to any one of claims 1-8.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein when the program is executed by a processor, the method according to any one of claims 1-8 is implemented.

12. A computer program product, characterized in that, The computer program product includes a program that, when run on an electronic device, causes the electronic device to implement the method according to any one of claims 1-8.