Attack prediction method and device, sidecar container, system, medium and product
Through the behavior prediction model in the sidecar container, based on the unified resource locator and status code in the log data, whether there is attack information in the access request of the user's source address is detected in real time, solving the problem of inefficient log data analysis in the existing technology, and achieving efficient network attack prediction and security protection.
Patent Information
- Application Number
- CN202510705481.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-08-05
AI Technical Summary
The prior art is difficult to conduct real-time analysis of log data without affecting the performance of middleware servers, resulting in inefficient network attack protection.
The behavior prediction model in the sidecar container is adopted, based on the unified resource locator and status code in the log data, determine whether there is attack information in the access request of the user's source address, and use the address information and behavior prediction model to perform real-time attack detection.
Real-time analysis of log data without affecting normal service operation is achieved, improving the accuracy and network security of attack behavior prediction.
Smart Images

Figure CN120434019A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present disclosure relate to the field of network security technology, and more particularly to an attack prediction method, device, sidecar container, system, medium, and product. Background Art
[0002] With the rapid development of network technology and cyberspace, we are deploying more and more application services on the internet, and the cybersecurity risks we face are also increasing. Currently, protecting services exposed to the internet from potential cyberattacks is a major issue we face. Some of these attacks can be prevented through antivirus software or firewalls, while others can be blocked through traffic scrubbing by network devices. However, these methods are difficult to use to protect against low-frequency attacks targeting server middleware. Analyzing application logs directly on the middleware server will cause resource competition between the middleware and the analysis program, significantly hindering service stability and hindering log analysis efficiency. Existing technologies generally use log storage and analysis systems to collect application service logs into storage units and then perform log analysis. This approach cannot perform real-time log analysis, and the timeliness of log analysis depends on the frequency of log collection and the processing power of the storage unit, resulting in certain limitations. Summary of the Invention
[0003] The embodiments of the present disclosure provide an attack prediction method, apparatus, sidecar container, system, medium, and product, which can perform real-time analysis of log data without affecting normal service operation, thereby ensuring the security of services and Internet assets while providing services quickly.
[0004] In a first aspect, an attack prediction method is provided. The method is applied to a sidecar container and includes:
[0005] Determine address information corresponding to each user source address based on log data; the address information includes a uniform resource locator and / or a status code;
[0006] For the address information corresponding to each user source address, based on the address information, a behavior prediction model is used to determine whether there is attack information in the access request in the user source address; the attack information includes an attack flag and an attack location; the user source address is the address of the initiator of the access request.
[0007] In a second aspect, an attack prediction device is provided, comprising:
[0008] An address information determination module, configured to determine address information corresponding to each user source address based on log data; the address information includes a uniform resource locator and / or a status code;
[0009] An attack information determination module is used to determine, based on the address information corresponding to each user source address and using a behavior prediction model, whether there is attack information in the access request in the user source address; the attack information includes an attack flag and an attack location; the user source address is the address of the initiator of the access request.
[0010] In a third aspect, a sidecar container is provided, including:
[0011] at least one processor; and,
[0012] a memory communicatively connected to the at least one processor; wherein,
[0013] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the attack prediction method as described in the first aspect above.
[0014] In a fourth aspect, an attack prediction system is provided, which includes: a main container, a shared storage volume, and a sidecar container as described in the third aspect above, wherein the main container and the sidecar container belong to the same container group; the main container is used to generate log data, the shared storage volume is used to transfer the log data to the sidecar container, and the sidecar container is used to analyze the log data and perform attack prediction.
[0015] In a fifth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the attack prediction method as described in the first aspect is implemented.
[0016] In a sixth aspect, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the attack prediction method as described in the first aspect above.
[0017] The disclosed embodiments disclose an attack prediction method, apparatus, sidecar container, system, medium, and product. The method includes: determining address information corresponding to each user source address based on log data; the address information includes a uniform resource locator and / or a status code; for the address information corresponding to each user source address, based on the address information, determining whether attack information exists in the access request in the user source address using a behavior prediction model; the attack information includes an attack flag and an attack location; the user source address is the address of the initiator of the access request. Based on the address information, the technical solution uses a behavior prediction model in a sidecar container to determine whether attack information exists in the access request in the user source address. This allows for real-time analysis of log data without affecting normal service operation, ensuring the security of services and Internet assets while providing services quickly, and improving the accuracy of attack behavior prediction.
[0018] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the embodiments of the present disclosure. Other features of the embodiments of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0020] Figure 1 This is a flow chart of an attack prediction method provided in the first embodiment of the present disclosure;
[0021] Figure 2 This is a schematic diagram of the structure of an attack prediction device provided in the second embodiment of the present disclosure;
[0022] Figure 3 This is a schematic diagram of the structure of a sidecar container provided in the third embodiment of the present disclosure;
[0023] Figure 4 It is a structural diagram of an attack prediction system provided in Example 4 of the present disclosure. DETAILED DESCRIPTION
[0024] In order to enable those skilled in the art to better understand the solutions of the embodiments of the present disclosure, the technical solutions of the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of them. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the embodiments of the present disclosure.
[0025] It should be noted that the terms "first", "second", etc. in the description and claims of the embodiments of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0026] Example 1
[0027] Figure 1 This is a flowchart of an attack prediction method provided in the first embodiment of the present disclosure. This embodiment is applicable to the case of predicting attack behaviors of access requests. The method can be executed by an attack prediction device, which can be implemented in the form of hardware and / or software. The attack prediction device can be configured in a sidecar container, which includes but is not limited to computers, terminals, servers and other devices with data processing capabilities. Figure 1 As shown, the method includes:
[0028] S110 : Determine address information corresponding to each user source address based on log data; the address information includes a uniform resource locator and / or a status code.
[0029] In this embodiment, log data generally refers to various information recorded by the system during operation. The address information corresponding to each user's source address can be determined based on the log data. The source address generally refers to the Internet Protocol (IP) address or host name of the client that initiates the network request. It is usually recorded at the beginning of the log file to identify the initiator of the request.
[0030] Continuing with the above description, the address information may include a uniform resource locator and / or a status code. A uniform resource locator (URL) may use hypertext markup language to link hypertext and hypermedia between web pages within a website, within a system, or between different systems. A uniform resource locator may consist of multiple parts, typically including a protocol, a host name, a path, query parameters, and an anchor. The uniform resource locator may be recorded in the request line in the log file, indicating the requested resource path. The status code may be a 3-digit code used to indicate the hypertext transfer protocol response status of the web server, and is defined by the RFC2616 specification. The status code may be used to indicate the processing result of the request and may be recorded after the request line in the log file. For example, common status codes include 200: indicating a successful request, 404: indicating resource not found, and 500: indicating an internal server error.
[0031] It's important to note that you can use the status code to determine if there are any anomalies in the access request corresponding to the user's source address. For example, by analyzing the status code in the original log, you'll find that the status code should typically be between 200 and 400. If the status code 404 appears frequently in the log, be wary of access anomalies.
[0032] S120. For each user source address, based on the address information, determine using a behavior prediction model whether there is attack information in the access request in the user source address; the attack information includes an attack flag and an attack location; the user source address is the address of the initiator of the access request.
[0033] Specifically, for each user source address, the address information is used as input to a behavior prediction model. The behavior prediction model is then used to determine whether the access request from the user source address contains attack information and abnormal behavior. The behavior prediction model can be a neural network language model, and the user source address can be the address of the originator of the access request.
[0034] Continuing with the above description, attack information can include an attack flag and attack location. The attack flag is used to indicate whether an attack behavior exists in an access request, and the attack location can specifically describe or locate the attack behavior. For example, if the behavior prediction model determines that an access request contains an attack behavior, the attack flag is True, and corresponding attack location information is generated. If the behavior prediction model determines that an access request is normal, the attack flag is False. It should be noted that if an attack behavior exists in an access request, the user source address corresponding to the access request will be sent to the access layer network device as a basis for blocking.
[0035] This embodiment provides an attack prediction method, including: determining address information corresponding to each user source address based on log data; the address information includes a uniform resource locator and / or a status code; for the address information corresponding to each user source address, based on the address information, using a behavior prediction model to determine whether attack information exists in an access request in the user source address; the attack information includes an attack flag and an attack location; the user source address is the address of the initiator of the access request, and application logs can be analyzed in real time without affecting normal service operation, thereby ensuring the security of services and Internet assets while quickly providing services.
[0036] As an optional implementation of this embodiment, the attack prediction method provided in this embodiment further includes, before determining the address information corresponding to the user source address based on the log data:
[0037] 1) Get the log data of the main container;
[0038] In this embodiment, the main container can deploy and run a container for middleware services. Middleware can be software that sits between the application system and system software. It uses the basic services provided by the system software to connect various parts of the application system or different applications on the network. It is an independent system software service program that distributed application software uses to share resources between different technologies. The middleware configuration file can be mounted using configmap, which effectively prevents the configuration file from being tampered with. When the main container runs the middleware service, log data from the main container running the middleware can be obtained. The log data may include the source address corresponding to each access request, the URL accessed, and / or the status code.
[0039] 2) Determine the source address of each user based on the log data.
[0040] Specifically, after the log data is determined, each user source address in the log data can be counted to determine the non-repeating user source addresses (that is, it can be understood as parsing the log data, extracting each user source address, and removing the repeated parts, and finally obtaining a unique user source address list). At the same time, the frequency of occurrence of each user source address can also be determined.
[0041] It should be noted that the frequency of normal users accessing services is relatively fixed and has obvious access peaks and troughs. By counting the frequency of occurrence of each user's source address, it is possible to determine whether there is an attack behavior.
[0042] Optionally, the method further comprises: determining the source address of each user based on the log data;
[0043] 1) If the access request comes from an internal system, determine the user source address from the log data.
[0044] Specifically, an access request refers to a request initiated by a user or system to a server. If the access request comes from an internal system, the source address for the internal system can usually be an internally stored address. In this case, the source address stored in the log data can be directly determined as the user source address.
[0045] The internal system usually refers to the network environment within an organization, such as a company's internal office network, an enterprise's internal server cluster, etc. Access requests to the internal system usually come from internal users (such as employees) or internal services.
[0046] 2) If the access request comes from the customer-facing system, the user source address is determined based on the working mode of the load balancer when processing the access request and the log data.
[0047] In this embodiment, the customer-facing system refers to the system that directly faces customers (users), typically a front-end system that provides external services, such as a website, a mobile application backend, or an online service interface. When users initiate requests through the customer-facing system (for example, by visiting a website or using an online service), these requests first reach the load balancer. The load balancer's role is to rationally distribute these requests across multiple back-end servers to ensure high performance and high availability of the system.
[0048] Continuing from the above description, the user source address of the customer-facing system is relatively complex. It may be the real user source address transmitted by the load balancer, or it may be the address converted by the load balancer. If the access request comes from the customer-facing system, the user source address can be determined based on the working method of the load balancer when processing the access request and the log data.
[0049] Exemplary methods of processing access requests by the load balancer include: load balancing transparently transmitted user source address: the load balancer directly transparently transmits the user's real source address to the backend server; load balancing address after translation: the load balancer translates the user source address (for example, Network Address Translation (NAT)), and the backend server sees the load balancer's address or an internal address. If the user source address is based on load balancing transparent transmission, the source address field in the log data can be used as the user source address; for the address after translation, it is necessary to obtain the client source address field recorded in the log and use this field as the user source address for processing and statistics.
[0050] The uniform resource locator includes a first resource locator and a second resource locator. As an optional implementation of this embodiment, determining the uniform resource locator corresponding to each user source address based on log data includes:
[0051] 1) Determine the initial resource locator corresponding to each user source address based on log data.
[0052] Specifically, the initial resource locator corresponding to each user source address may be determined based on the log data, wherein the initial resource locator may be a resource locator in the processed log data.
[0053] 2) Based on the initial resource locator, determine the resource locator to be processed and the first resource locator according to preset processing conditions; the resource locator to be processed is the initial resource locator that does not meet the preset processing conditions; the first resource locator is the initial resource locator that meets the preset processing conditions.
[0054] Specifically, after obtaining the initial resource locator, since the length of each string of initial resource locators is different, the resource locator to be processed and the first resource locator can be determined based on a preset processing condition. The preset processing condition can be a pre-set condition for determining whether the initial resource locator needs to be processed. The resource locator to be processed is an initial resource locator that does not meet the preset processing condition, and the first resource locator can be an initial resource locator that meets the preset processing condition.
[0055] Exemplarily, the preset processing condition may be that the length of the initial resource locator is equal to a preset standard length. According to a normal distribution, the preset standard length may be determined based on the lengths of the individual initial resource locators in the log data. Exemplarily, a length that covers 95% of the initial resource locators may be selected as the preset standard length.
[0056] 3) Filling or trimming the resource locator to be processed to obtain the second resource locator.
[0057] Specifically, after the resource locator to be processed is determined, the resource locator to be processed may be padded or trimmed based on a preset standard length to obtain the second resource locator. For example, if the length of the resource locator to be processed is longer than the preset standard length, the resource locator to be processed may be trimmed; if the length of the resource locator to be processed is shorter than the preset standard length, padding may be performed at the beginning of the resource locator to be processed.
[0058] As an optional implementation of this embodiment, the method provided in this embodiment may further include a behavior prediction model training process, and the behavior prediction model training process includes:
[0059] 1) Determine historical address information corresponding to each historical user source address based on historical log data; the historical address information includes a historical uniform resource locator and / or a historical status code.
[0060] Specifically, the historical log data may be log data generated by historical access requests. By parsing the historical log data, each historical user source address can be extracted and duplicates removed to ultimately obtain a unique list of historical user source addresses. The historical address information corresponding to each historical user source address in the list of historical user source addresses can be determined based on the historical log data. The historical address information includes a historical uniform resource locator and / or a historical status code.
[0061] It should be noted that historical URLs may include URLs that have been padded or clipped. The original URL can be determined based on the historical user source address, and a length that covers 95% of the original URLs can be selected as a standard length for padding and clipping the original URLs to be processed. Through padding or clipping, all original URLs are standardized into historical URLs (with a uniform length), which makes subsequent analysis and processing more consistent and efficient.
[0062] 2) Determine the historical attack information corresponding to each historical user source address, wherein the historical attack information includes a historical attack flag and a historical attack location.
[0063] Specifically, historical log data may include data with attack behaviors and data without attack behaviors. By analyzing the log data, the attack behaviors in each access request can be identified, and then the historical attack information corresponding to each historical user source address in the historical user source address list can be determined. The historical attack information includes the historical attack flag and the historical attack location.
[0064] 3) Training an initial model based on the historical address information and the historical attack information to obtain a behavior prediction model.
[0065] Specifically, after determining the historical address information and historical attack information, the initial model can be trained based on the historical address information and historical attack information. Training can be terminated when a training cutoff condition is met, thereby obtaining a trained behavior prediction model. The training cutoff condition can be reaching a maximum number of training times and / or the model's recognition accuracy meets requirements.
[0066] Example 2
[0067] Figure 2 is a structural diagram of an attack prediction device provided in the second embodiment of the present disclosure; Figure 2 As shown, the device includes: an address information determination module 210 and an attack information determination module 220.
[0068] The address information determination module 210 is configured to determine the address information corresponding to each user source address based on the log data; the address information includes a uniform resource locator and / or a status code;
[0069] The attack information determination module 220 is used to determine, based on the address information corresponding to each user source address, whether there is attack information in the access request in the user source address using a behavior prediction model; the attack information includes an attack flag and an attack location; the user source address is the address of the initiator of the access request.
[0070] The second embodiment of the present disclosure provides an attack prediction device, which can perform real-time analysis on log data without affecting normal service operation, ensure the security of services and Internet assets while providing services quickly, and improve the accuracy of attack behavior prediction.
[0071] Furthermore, the device further comprises:
[0072] Data acquisition module, used to obtain log data of the main container;
[0073] The user source address determination module is used to determine each user source address based on the log data.
[0074] Furthermore, the user source address determination module is further configured to:
[0075] If the access request comes from an internal system, determining the user source address from the log data;
[0076] If the access request comes from the customer-facing system, the user source address is determined based on the working mode of the load balancer when processing the access request and the log data.
[0077] Furthermore, the uniform resource locator includes a first resource locator and a second resource locator;
[0078] The address information determining module 210 is further configured to:
[0079] Determine the initial resource locator corresponding to each user source address based on the log data;
[0080] Based on the initial resource locator, determining a resource locator to be processed and the first resource locator according to a preset processing condition; the resource locator to be processed is an initial resource locator that does not meet the preset processing condition; the first resource locator is an initial resource locator that meets the preset processing condition;
[0081] The resource locator to be processed is padded or trimmed to obtain the second resource locator.
[0082] Furthermore, the apparatus further comprises: a training module for determining historical address information corresponding to each historical user source address based on historical log data; the historical address information comprises a historical uniform resource locator and / or a historical status code;
[0083] Determine historical attack information corresponding to each historical user source address, wherein the historical attack information includes a historical attack flag and a historical attack location;
[0084] An initial model is trained based on the historical address information and the historical attack information to obtain a behavior prediction model.
[0085] The attack prediction device provided in the embodiments of the present disclosure can execute the attack prediction method provided in any embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects of the execution method.
[0086] Example 3
[0087] Figure 3 A schematic diagram of a sidecar container 10 that can be used to implement embodiments of the present disclosure is shown. The sidecar container is intended to represent various forms of digital computers, such as laptops, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the embodiments of the present disclosure described and / or claimed herein.
[0088] like Figure 3 As shown, the sidecar container 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 and a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the sidecar container 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0089] Multiple components in the sidecar container 10 are connected to an I / O interface 15, including an input unit 16, such as a keyboard and mouse; an output unit 17, such as various types of displays and speakers; a storage unit 18, such as a magnetic disk and optical disk; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the sidecar container 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0090] Processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any other suitable processor, controller, microprocessor, etc. Processor 11 executes the various methods and processes described above, such as the attack prediction method.
[0091] In some embodiments, the attack prediction method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the sidecar container 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the attack prediction method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the attack prediction method in any other appropriate manner (for example, by means of firmware).
[0092] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0093] The computer programs for implementing the methods of the embodiments of the present disclosure may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer programs are executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0094] In the context of the embodiments of the present disclosure, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. A computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0095] To provide interaction with a user, the systems and techniques described herein can be implemented on a sidecar container having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the sidecar container. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0096] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0097] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0098] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the embodiments of the present disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions of the embodiments of the present disclosure can be achieved, and this document is not limited here.
[0099] The above specific implementations do not constitute a limitation on the scope of protection of the embodiments of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the embodiments of the present disclosure shall be included within the scope of protection of the embodiments of the present disclosure.
[0100] The embodiments of the present disclosure also provide a computer program product, including a computer program and / or instructions, which, when executed by a processor, implements the attack prediction method provided in any embodiment of the present application.
[0101] During implementation, the computer program product may be written in one or more programming languages or a combination thereof to write computer program code for performing the operations of the disclosed embodiments, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0102] Note that the above are only preferred embodiments of the present disclosure and the technical principles used. Those skilled in the art will understand that the present disclosure is not limited to the specific embodiments herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present disclosure. Therefore, although the present disclosure is described in more detail through the above embodiments, the present disclosure is not limited to the above embodiments, and may include more other equivalent embodiments without departing from the concept of the present disclosure, and the scope of the present disclosure is determined by the scope of the appended claims.
[0103] Example 4
[0104] A fourth embodiment of the present disclosure provides an attack prediction system. The system includes: a main container, a shared storage volume, and a sidecar container as described in any of the above embodiments. The main container and the sidecar container belong to the same container group. The main container is used to generate log data, the shared storage volume is used to transfer the log data to the sidecar container, and the sidecar container is used to analyze the log data and perform attack predictions. The sidecar container can be a special container that runs in the same container group as the main container and shares the same network and storage space. The sidecar container can provide additional functionality, auxiliary services, or extend the functionality of the main application container. A container group can be a collection of one to multiple application containers, storage resources, dedicated addresses, and logical components that support container operation. The main container can deploy middleware services. Middleware can be software that sits between the application system and system software. It uses the basic services provided by the system software to connect various parts of the application system or different applications on the network. It is an independent system software service program that allows distributed application software to share resources between different technologies.
[0105] Specifically, Figure 4 This is a structural diagram of an attack prediction system 40 provided in the fourth embodiment of the present disclosure. Figure 4 As shown, the system includes: a main container 401, a shared storage volume 402, and a sidecar container 403. Log data is obtained by deploying a middleware service in the main container. The main container and the sidecar container are set to use a shared storage volume, and the middleware log data is written to the shared volume. Simultaneously, a behavior prediction model is deployed in the sidecar container. The sidecar container can obtain log data and, based on the log data, determine the address information corresponding to each user source address. The address information includes a uniform resource locator and / or a status code. For each user source address, the behavior prediction model is used to determine whether attack information exists in the access request corresponding to the user source address. The attack information includes an attack flag and an attack location. The user source address is the address of the initiator of the access request. The above solution uses a sidecar container approach to deploy the behavior prediction model and real-time logs in the same container group, eliminating the time consumption of log collection. It can perform real-time analysis of log data without affecting normal service operation, ensuring the security of services and Internet assets while providing services quickly, and improving the accuracy of attack behavior prediction.
[0106] The attack prediction system provided in the fourth embodiment can be used to execute the attack prediction method provided in any of the above embodiments, and has corresponding functions and beneficial effects.
Claims
1. An attack prediction method, characterized in that: The method is applied to a sidecar container and includes: Determine address information corresponding to each user source address based on log data; the address information includes a uniform resource locator and / or a status code; For the address information corresponding to each user source address, based on the address information, a behavior prediction model is used to determine whether there is attack information in the access request in the user source address; the attack information includes an attack flag and an attack location; the user source address is the address of the initiator of the access request.
2. The method according to claim 1, characterized in that Before determining the address information corresponding to the user source address based on the log data, the method further includes: Get the log data of the main container; The source addresses of the respective users are determined based on the log data.
3. The method according to claim 2, characterized in that Determining each user source address based on the log data includes: If the access request comes from an internal system, determining the user source address from the log data; If the access request comes from the customer-facing system, the user source address is determined based on the working mode of the load balancer when processing the access request and the log data.
4. The method according to claim 1, wherein The uniform resource locator includes a first resource locator and a second resource locator; Determine the Uniform Resource Locator (URL) corresponding to each user's source address based on log data, including: Determine the initial resource locator corresponding to each user source address based on the log data; Based on the initial resource locator, determining a resource locator to be processed and the first resource locator according to a preset processing condition; the resource locator to be processed is an initial resource locator that does not meet the preset processing condition; the first resource locator is an initial resource locator that meets the preset processing condition; The resource locator to be processed is padded or trimmed to obtain the second resource locator.
5. The method according to claim 4, characterized in that The training process of the behavior prediction model includes: Determine historical address information corresponding to each historical user source address based on historical log data; the historical address information includes a historical uniform resource locator and / or a historical status code; Determine historical attack information corresponding to each historical user source address, wherein the historical attack information includes a historical attack flag and a historical attack location; An initial model is trained based on the historical address information and the historical attack information to obtain a behavior prediction model.
6. An attack prediction device, characterized in that: include: An address information determination module, configured to determine the address information corresponding to each user's source address based on log data; The address information includes a uniform resource locator and / or a status code; an attack information determination module, configured to determine, for each user source address, based on the address information corresponding to the user source address and using a behavior prediction model to determine whether attack information exists in the access request in the user source address; The attack information includes an attack flag and an attack location; the user source address is the address of the initiator of the access request.
7. A sidecar container, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the attack prediction method according to any one of claims 1 to 5.
8. An attack prediction system, comprising: A main container, a shared storage volume, and a sidecar container as described in claim 7, wherein the main container and the sidecar container belong to the same container group; the main container is used to generate log data, the shared storage volume is used to transfer the log data to the sidecar container, and the sidecar container is used to analyze the log data and perform attack prediction.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the attack prediction method according to any one of claims 1 to 5 is implemented.
10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the computer program implements the attack prediction method according to any one of claims 1 to 5.