Two-dimensional code phishing detection method and device

Through the extraction and analysis of the feature of data objects and target objects, combined with intention and object characteristics, the problem of QR code phishing detection lag is solved, and timely detection and high accuracy detection of phishing QR codes are achieved.

CN120474790APending Publication Date: 2025-08-12QI AN XIN TECHNOLOGY GROUP INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510678132.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the prior art, QR code phishing detection relies on matching of phishing feature databases, resulting in the inability to detect QR codes that do not include phishing features in time, and there is a significant detection lag and high success rate.

Method used

By extracting and analyzing intention features of data objects carrying QR codes, combining the object feature extraction of the target object, we will comprehensively detect whether the QR code is a phishing QR code for phishing attacks, including the analysis of social engineering, psychology, and semantic feature data of the data object, as well as the web page or file feature analysis of the target object.

Benefits of technology

Timely detection of known and unknown phishing QR codes is achieved, which reduces detection lag, improves detection accuracy, and reduces the success rate of QR code phishing attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474790A_ABST
    Figure CN120474790A_ABST
Patent Text Reader

Abstract

The invention discloses a two-dimensional code phishing detection method and device, relates to the technical field of network security, and mainly aims to reduce the hysteresis of two-dimensional code phishing detection. According to the main technical scheme, the method comprises the following steps: performing feature extraction processing on a data object carrying a two-dimensional code to obtain at least one type of intention feature data related to the intention of the data object; performing intention analysis based on the at least one intention feature data to obtain intention data of the data object, the intention data being related to an induction degree of the data object to induce a user to scan a two-dimensional code; feature extraction processing is carried out on a target object pointed by the two-dimensional code to obtain object feature data of the target object, and the object feature data is related to the malicious degree of the target object; and detecting whether the two-dimensional code is a phishing two-dimensional code for phishing attack based on the intention data and the object feature data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method and device for detecting QR code phishing. Background Art

[0002] The convenience and invisibility of QR codes make them a key vector for phishing attacks. Attackers often embed QR codes in data objects such as emails and web pages, tricking users into scanning and visiting malicious web pages or downloading malicious files, thereby stealing sensitive user information or conducting phishing scams.

[0003] Traditional QR code phishing detection mainly relies on phishing feature library matching, that is, extracting features such as the URL and domain name from the QR code to be tested, and matching them with the phishing features included in the phishing feature library (that is, the features of phishing QR codes known to be used for phishing attacks). If the match is successful, the QR code to be tested is detected as a phishing QR code. However, relying on phishing feature library matching means that only phishing QR codes corresponding to the included phishing features can be detected. Unknown phishing QR codes whose phishing features have not yet been included in the phishing feature library cannot be detected, and it is necessary to wait for the phishing features to be updated in the phishing feature library before detection. This passive QR code phishing detection method that relies on the update of the phishing feature library results in significant detection lag.

[0004] Therefore, how to reduce the lag in QR code phishing detection has become an urgent problem that needs to be solved. Summary of the Invention

[0005] This application proposes a QR code phishing detection method and device, the main purpose of which is to reduce the lag of QR code phishing detection.

[0006] In order to achieve the above objectives, this application mainly provides the following technical solutions:

[0007] In the first aspect, the present application provides a QR code phishing detection method. The QR code phishing detection method provided in this embodiment may include: performing feature extraction processing on a data object carrying a QR code to obtain at least one intention feature data related to the intention of the data object; performing intent analysis based on the at least one intention feature data to obtain the intention data of the data object, and the intention data is related to the degree to which the data object induces users to scan the QR code; performing feature extraction processing on the target object pointed to by the QR code to obtain object feature data of the target object, and the object feature data is related to the maliciousness of the target object; based on the intention data and the object feature data, detecting whether the QR code is a phishing QR code used for phishing attacks.

[0008] In a second aspect, the present application provides a QR code phishing detection device. The QR code phishing detection device provided in this embodiment may include:

[0009] A first extraction module is configured to perform feature extraction processing on a data object carrying a QR code to obtain at least one intention feature data related to the intention of the data object;

[0010] an analysis module, configured to perform intent analysis based on the at least one intention feature data to obtain intent data of the data object, wherein the intent data is related to the degree to which the data object induces a user to scan a QR code;

[0011] A second extraction module is configured to perform feature extraction processing on the target object pointed to by the QR code to obtain object feature data of the target object, wherein the object feature data is related to the maliciousness level of the target object;

[0012] A detection module is used to detect whether the QR code is a phishing QR code used for phishing attacks based on the intention data and the object feature data.

[0013] In a third aspect, the present application provides a computer-readable storage medium, which includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the QR code phishing detection method of the first aspect.

[0014] In a fourth aspect, the present application provides an electronic device comprising: a memory for storing a program; and a processor coupled to the memory for running the program to execute the QR code phishing detection method of the first aspect.

[0015] In a fifth aspect, the present application provides a computer program product, which includes: a computer program / computer executable instructions, which, when executed by a processor, implements the QR code phishing detection method of the first aspect.

[0016] The QR code phishing detection method and device provided in this application performs feature extraction on a data object carrying a QR code to obtain at least one intent feature data related to the intent of the data object. Intent analysis is then performed based on the obtained at least one intent feature data to obtain intent data related to the degree to which the data object induces a user to scan the QR code. Feature extraction is then performed on the target object pointed to by the QR code to obtain object feature data related to the maliciousness of the target object. Based on the intent data and object feature data, the QR code is detected as a phishing QR code used for phishing attacks. As can be seen, the solution provided in this embodiment does not require reliance on a phishing feature library for passive QR code phishing detection. Instead, active QR code phishing detection can be performed by combining the intent expressed by the data object itself and the object features of the target object itself. This allows both known and unknown phishing QR codes to be detected promptly, thereby reducing the lag in QR code phishing detection. Furthermore, by integrating the dimensions of the data object's user inducement and the maliciousness of the target object to comprehensively detect QR code phishing, the accuracy of QR code phishing detection can be improved.

[0017] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0019] Figure 1 A flowchart of a QR code phishing detection method provided by one embodiment of the present application is shown;

[0020] Figure 2 A flowchart of a QR code phishing detection method provided by another embodiment of the present application is shown;

[0021] Figure 3 A schematic structural diagram of a QR code phishing detection device provided by one embodiment of the present application is shown;

[0022] Figure 4 A schematic structural diagram of a QR code phishing detection device provided in another embodiment of the present application is shown. DETAILED DESCRIPTION

[0023] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0024] Traditional QR code phishing detection methods, which rely on matching phishing signature databases, can only detect phishing QR codes that have already been indexed. They are unable to detect unknown phishing QR codes whose signatures have not yet been included in the database. Detection requires waiting for the signatures to be updated in the database. This passive QR code phishing detection method, which relies on database updates, results in significant detection lags, leading to a high success rate for QR code phishing attacks.

[0025] Based on research findings, the intent expressed by data objects such as web pages or emails carrying QR codes is correlated with the degree to which the data objects induce users to scan the QR codes, reflecting the risk of QR code phishing from the perspective of data object inducement. The object characteristics of the target object, such as the web page or file to which the QR code points, are correlated with the degree of maliciousness of the target object, reflecting the risk of QR code phishing from the perspective of the malicious nature of the target object. By combining the intent of the data object and the object characteristics of the target object to detect whether a QR code is a phishing QR code, the following effects can be achieved: Passive QR code phishing detection can be performed by combining the intent expressed by the data object itself and the object characteristics of the target object itself. This allows for active QR code phishing detection, eliminating the need to rely on a phishing feature library. Both known and unknown phishing QR codes can be detected promptly, reducing the lag in QR code phishing detection and, in turn, the success rate of QR code phishing attacks.

[0026] Based on the above findings, an embodiment of the present application provides a technical solution for QR code phishing detection, which specifically includes: performing feature extraction processing on a data object carrying a QR code to obtain at least one intention feature data related to the intention of the data object. Performing intent analysis based on the at least one intention feature data to obtain the intention data of the data object, and the intention data is related to the degree to which the data object induces the user to scan the QR code. Performing feature extraction processing on the target object pointed to by the QR code to obtain object feature data of the target object, and the object feature data is related to the maliciousness of the target object. Based on the intention data and the object feature data, detecting whether the QR code is a phishing QR code used for phishing attacks.

[0027] The QR code phishing detection technology provided in this embodiment can be used to detect any data object carrying a QR code. This embodiment does not limit the type of data object. For example, the data object may include but is not limited to an email or a web page.

[0028] Based on the QR code phishing detection technical solution provided in this embodiment, this embodiment specifically provides a QR code phishing detection method and device. The QR code phishing detection method and device provided in this embodiment are described in detail below.

[0029] The present application embodiment provides a method for detecting phishing with a QR code. Figure 1 As shown, the QR code phishing detection method provided in this embodiment may include at least the following steps 101 to 104.

[0030] 101. Perform feature extraction processing on a data object carrying a QR code to obtain at least one intention feature data related to the intention of the data object.

[0031] The QR codes carried in emails or web pages may be phishing QR codes used in phishing attacks. Therefore, any email carrying a QR code or any web page carrying a QR code can be used as a data object in this embodiment to promptly detect and handle phishing QR codes, thereby reducing the success rate of QR code phishing attacks. The specific type of data object can be flexibly selected based on the application scenario of the QR code detection method, and this embodiment does not limit this. For example, if the QR code phishing detection method is applied to an email control scenario, the data object is an email carrying a QR code. If the QR code phishing detection method is applied to a web page control scenario, the data object is a web page carrying a QR code.

[0032] After determining the data object carrying the QR code, a feature extraction process is performed on the data object carrying the QR code to obtain at least one intention feature data related to the intention of the data object, so as to determine the intention data corresponding to the intention of the data object based on the intention feature data, and use the intention data as a basis for detecting the risk of QR code phishing from the dimension of inducing users by the data object, so as to facilitate subsequent detection of whether the QR code is a phishing QR code used for phishing attacks.

[0033] The specific execution process of performing feature extraction processing on a data object carrying a QR code to obtain at least one intention feature data related to the intention of the data object may include the following steps 101A to 101C.

[0034] 101A, select the type of intent feature data required to analyze the intent of the data object.

[0035] There are numerous types of intent feature data relevant to intent analysis. Therefore, in order to select intent feature data suitable for intent analysis of a data object, a step is required to select the types of intent feature data required for analyzing the data object's intent. This step can be implemented in at least three ways: First, all types related to intent analysis are selected as the types of intent feature data required for analyzing the data object's intent. This allows for more comprehensive acquisition of intent feature data for intent analysis, enabling more accurate analysis of the data object's intent. Second, all types related to intent analysis are made available to fishing control personnel for selection, with the selected types selected as the types of intent feature data required for analyzing the data object's intent. This allows for customized intent feature data to analyze the data object's intent, meeting customized QR code phishing detection requirements. Third, the business type corresponding to the data object is determined, and the types of intent feature data adapted to the business type are selected as the types of intent feature data required for analyzing the data object's intent. This allows for more targeted acquisition of intent feature data suitable for analyzing the data object's intent, enabling more targeted analysis of the data object's intent. Any of the three methods described above can be selected based on business needs, and this embodiment does not limit this.

[0036] The selected intent feature data types may include, but are not limited to, at least one of the following: social engineering feature data, psychological feature data, semantic feature data, and emotional feature data. Social engineering feature data indicates the attacker's deceptive tactics. Psychological feature data indicates the psychological impact of the data object on the recipient, i.e., the user. Semantic feature data indicates the true meaning and purpose of the content in the data object. Emotional feature data indicates the emotional state expressed by the content in the data object. Social engineering feature data, psychological feature data, semantic feature data, and emotional feature data each reflect the true intent of the data object from different dimensions.

[0037] 101B, selecting the extraction model that is suitable for the data object corresponding to each category.

[0038] The extraction model is used to identify corresponding types of intent feature data based on data analysis within the data object. Each type of intent feature data has its own corresponding extraction model. Based on this, the extraction model that is adapted to each data object is selected to extract the corresponding type of intent feature data using the adapted extraction model.

[0039] 101C, for each category, respectively execute: input the data object into the extraction model corresponding to the category, and determine the intention feature data identified by the extraction model based on data analysis in the data object as the intention feature data corresponding to the category.

[0040] In some embodiments, the extraction model corresponding to the category of social engineering feature data is used to take the data object as input and perform at least one of the following analyses on the data object: metadata analysis (for example, analysis of the recipient information of the email, analysis of the sending time, analysis of routing information (for example, analysis of the domain name and IP geographical location of the web page), language style analysis, content structure analysis, content layout analysis, and interaction behavior analysis, and output the social engineering feature data corresponding to the data object based on the analysis results. The extraction model corresponding to the category of social engineering feature data is obtained by training based on multiple groups of data, and each group of data includes a sample data object and the social engineering feature data corresponding to the sample data object.

[0041] Social engineering signature data is used to indicate an attacker's deceptive tactics. It can specifically indicate artificially designed social engineering features within a data object intended to trick users into scanning QR codes. Social engineering features typically exploit human psychological vulnerabilities (such as trust, fear, and greed) to achieve their attack objectives. Social engineering features may include, but are not limited to, at least one of the following: identity disguise features, psychological manipulation features, content deception features, and social relationship exploitation features.

[0042] For example, identity disguise features may include: first, disguised sender addresses. For example, the sender address may appear as ABC@abc.com, but in reality, it is a disguised sender address. Second, disguised authoritative identities. For example, the text "There is an anomaly with your account. Please contact your manager immediately for confirmation" is an identity disguise feature that disguises the authoritative identity "Manager."

[0043] Exemplary psychological manipulation features include: First, urgency-inducing features (which create time pressure to force users to make quick decisions), such as "Your account will be frozen in 2 hours." Second, scarcity-implying features (which use fictitious scarce resources to lure users), such as "Bonus for the first 100 registrants." Third, threat features (which threaten users to scan a QR code), such as "If you fail to verify your identity through the QR code within 2 hours, your account will be frozen."

[0044] Exemplary content deception features include: first, directing users to scan a QR code, such as "Scan the QR code to find your account information." Second, content logical inconsistencies, such as the domain name of an organization in a data object being an unofficial domain name.

[0045] For example, social relationship exploitation features may include: 1. Familiarity fabrication features (used to pretend the user knows or is familiar with an individual), such as "I am a contact recommended by your colleague" or "This email is from AA Bank, where your account is located." 2. Pseudo-social features (used to fabricate group behavior to induce user conformity), such as "95% of users have completed their application, please complete it as soon as possible."

[0046] In some embodiments, an extraction model corresponding to the category of psychological feature data is configured to take a data object as input, perform at least one of the following analyses on the data object: metadata analysis (e.g., analysis of email sending time and frequency; e.g., analysis of web page push time and frequency), language style analysis, content structure analysis, content layout analysis, and interactive behavior analysis, and output psychological feature data corresponding to the data object based on the analysis results. The extraction model corresponding to the category of psychological feature data is trained based on multiple data sets, each of which includes a sample data object and the psychological feature data corresponding to the sample data object.

[0047] Psychological feature data is used to indicate the psychological impact of a data object on the recipient, i.e., the user. It can specifically indicate psychological features extracted from the data object that can reflect the user's psychological state, cognitive biases, or behavioral tendencies. This can be used to demonstrate potential psychological impacts on the user or identify psychological manipulation strategies deliberately designed by attackers. Psychological features may include, but are not limited to, at least one of the following: cognitive bias features, emotion-driven features, and social relationship features.

[0048] For example, cognitive biases can include: 1. Authoritative service bias (trust in authoritative identities, using fake executive identities to induce execution of instructions), such as "The manager requires an immediate transfer." 2. Scarcity bias (describing scarce resources to create false competition to promote action), such as "The offer only lasts two days." 3. Confirmation bias (the tendency to accept information that aligns with existing beliefs, exploiting users' sensitivity to security incidents), such as "There is an anomaly in your account."

[0049] For example, emotion-driven features may include: 1. Fear arousal, used to trigger panic and lead to irrational actions, such as "Your account will be locked." 2. Reward expectation intensity, used to stimulate greed and ignore risk, such as "You will receive a 1,000 bonus." 3. Urgency, used to suppress rational thinking, such as "Please scan the code within 10 minutes."

[0050] For example, social relationship features may include: 1. Similarity attraction features, where users pretend to have something in common with the user to increase trust and reduce user vigilance, such as "We are colleagues at XX company." 2. Reciprocity-based penalty features, where users offer help before making requests, to induce a desire for return, such as "Your information has been submitted, please confirm your account." 3. Social proof strength features, where users fabricate evidence of group behavior to pressure users to conform, such as "95% of users have successfully registered."

[0051] In some embodiments, the extraction model corresponding to the semantic feature data category is configured to take a data object as input, perform at least one of the following analyses on the data object: syntactic analysis, deep semantic analysis, semantic coherence analysis (contextual logic), implicit semantic conflict analysis, language style analysis, and content topic distribution analysis, and output semantic feature data corresponding to the data object based on the analysis results. The extraction model corresponding to the semantic feature data category is trained based on multiple data sets, each of which includes a sample data object and the semantic feature data corresponding to the sample data object.

[0052] Semantic feature data is used to indicate the true meaning and purpose of the content in the data object. It specifically indicates the semantic features of the meaning and intention of the data included in the data object within the semantics. It is obtained by quantifying the deep semantics of the text in the data object through natural language processing technology.

[0053] In some embodiments, an extraction model corresponding to the category of emotional feature data is configured to take a data object as input, perform at least one of the following analyses on the data object: emotional keyword analysis, semantic analysis, language style analysis, content structure analysis, content layout analysis, and interactive behavior analysis, and output emotional feature data corresponding to the data object based on the analysis results. The extraction model corresponding to the category of emotional feature data is trained based on multiple data sets, each of which includes a sample data object and the emotional feature data corresponding to the sample data object.

[0054] Emotional feature data is used to indicate the emotional state of the content expressed in a data object. It specifically indicates emotional features extracted from the data object that can reflect the user's emotional state and emotional tendencies. Emotional features may include, but are not limited to, at least one of the following: basic emotional features and social engineering-related emotional features.

[0055] For example, basic sentiment features may include at least the following: 1. Sentiment polarity, which reflects the overall sentiment of the data object, such as a positive sentiment like "Congratulations on winning the lottery." 2. Sentiment intensity, which indicates the degree of activation of each emotion, such as a high level of anger like "Act immediately or your account will be closed." 3. Sentiment conflict index, which indicates the coexistence of opposing emotions within a data object, such as "Congratulations on winning 1,000 yuan, but you must pay a 10% participation fee."

[0056] Exemplary social engineering-related emotional features include: 1. Fear arousal features, used to indicate the degree of user coercion, such as "delete account" or "freeze account." 2. Greed induction features, used to induce users to perform specific actions by offering rewards, such as "free." 3. Urgency features, used to suppress users' rational thinking by using time pressure, such as "last chance," "within 24 hours," or "before 2:00."

[0057] 102. Perform intent analysis based on the at least one intention feature data to obtain intent data of the data object, where the intent data is related to the degree to which the data object induces the user to scan the QR code.

[0058] After obtaining the intent feature data in step 101, the key data for determining the intent of the data object is obtained. Therefore, the step of performing intent analysis based on the at least one intent feature data to obtain the data object's intent data can be continued. This intention data can be used to determine the degree to which the data object induces the user to scan the QR code. The at least one intent feature data obtained in step 101 may include, but is not limited to, at least one of the following: social engineering feature data, psychological feature data, semantic feature data, and emotional feature data.

[0059] The specific implementation method of performing intent analysis based on the at least one intention feature data to obtain the intention data of the data object may include at least the following method A1 and method A2.

[0060] Method A1, performing intent analysis based on the at least one intent feature data to obtain the intent data of the data object may include the following steps: determining the weight of each intent feature data in the intent analysis; fusing various intent feature data based on the weight to obtain the intent data of the data object.

[0061] The weight reflects the contribution of the corresponding intent feature data to the intent analysis. The specific process of determining the weight of each intent feature data in the intent analysis can include the following steps: obtaining the corresponding relationship between the intent feature data type and weight corresponding to the current time point, which is based on periodic adjustment; querying the corresponding relationship based on the type of each intent feature data to obtain the weight of each intent feature data in the intent analysis.

[0062] The specific process of fusing various intent feature data based on weights to obtain the intent data of a data object can include the following steps: determining the first vector corresponding to each type of intent feature data, where the first vector is used to indicate the data vector corresponding to the target data or the intent vector corresponding to the intent expressed by the schematic feature data; performing weighted processing on the first vector corresponding to each type of intent feature data based on the weight corresponding to the first vector to obtain a second vector; searching for the intent data corresponding to the second vector in a preset target correspondence relationship, and determining the found intent data as the intent data corresponding to the data. The target correspondence relationship is the correspondence between the sample vector and the intent data.

[0063] Method A2, performing intent analysis based on the at least one intention feature data to obtain the specific execution process of the intention data of the data object may include the following steps: determining a model that is compatible with the at least one intention feature data; inputting all intention feature data into the model as input to the model, and having the model identify the intention data of the data object based on the input analysis. The model is used to identify and output corresponding intention data based on the analysis of the at least one intention data, and is obtained through training of multiple groups of data, each group of data including sample intention data and at least one sample intention feature data corresponding to the sample intention data. It should be noted that the type of the sample intention feature data corresponding to each group of data should be consistent with the type of at least one intention feature data obtained in step 101.

[0064] At least one of the above methods A1 and A2 can be flexibly selected based on business needs, which is not limited in this embodiment. It should be noted that when both methods are selected, the intent data obtained by the two methods are mutually verified.

[0065] 103. Perform feature extraction processing on the target object pointed to by the QR code to obtain object feature data of the target object. The object feature data is related to the maliciousness level of the target object.

[0066] The QR code phishing detection method provided in this embodiment, in addition to determining the intention data of the data object, also needs to determine the object feature data of the target object pointed to by the QR code, so as to use the object feature data as the basis for detecting the QR code phishing risk from the dimension of maliciousness of the target object, for subsequent detection of whether the QR code is a phishing QR code used for phishing attacks.

[0067] In some embodiments, before performing feature extraction on the target object pointed to by the QR code, it is first necessary to determine the target object pointed to by the QR code, so that targeted feature extraction can be performed based on the specific type of the target object. Based on this, the QR code phishing detection method provided in this embodiment may also include a process of determining the target object pointed to by the QR code. The specific implementation steps of this process may include the following steps 103A to 103C.

[0068] 103A, parse the QR code and obtain the target link contained in the QR code.

[0069] A QR code typically contains a URL (i.e., a Uniform Resource Locator), which is used to guide users to access a specific online resource such as a webpage or file. Based on this, the QR code is parsed using a target QR code parsing tool to obtain the target link, i.e., the URL, contained in the QR code. The target QR code parsing tool can be flexibly selected based on business needs and is not limited in this embodiment.

[0070] 103B, access the target link and obtain link content information corresponding to the target link.

[0071] After obtaining the target link, an access request is sent to the target link in an isolated environment such as a sandbox. The access request is determined based on the protocol used by the target link (for example, if the protocol is HTTP, the access request is an HTTP request), and then the response content of the target link is obtained. The response content is the link content information.

[0072] 103C, if the link content information indicates a file, the file indicated by the link content information is determined as the target object pointed to by the QR code; if the link content information indicates a web page, the web page indicated by the link content information is determined as the target object pointed to by the QR code.

[0073] If the link content information includes fields such as application, pdf, etc. used to declare that the content type is a file (these fields are usually included in response headers such as Content-Type and Content-Disposition), then the link content information is determined to indicate a file, and the file indicated by the link content information is determined as the target object pointed to by the QR code.

[0074] If the link content information includes fields such as text and html used to declare that the content type is a web page (these fields are usually included in response headers such as Content-Type and Content-Disposition), then it is determined that the link content information indicates a web page, and the web page indicated by the link content information is determined as the target object pointed to by the QR code.

[0075] In some embodiments, the target object may be a file or a web page, and the feature extraction processing of files and web pages is different. Therefore, it is necessary to perform feature extraction processing on the target object pointed to by the QR code based on the specific type of the target object to obtain the object feature data of the target object.

[0076] One is that if the target object is a web page, then the target object pointed to by the QR code is subjected to feature extraction processing, and the specific process of obtaining the object feature data of the target object may include the following steps: determining at least one of the following web page feature data of the web page: URL structure feature data, page content feature data, external resource feature data, and behavior feature data; performing semantic analysis on the content of the web page to obtain target semantic data; and determining the web page feature data and the target semantic data as the object feature data of the target object.

[0077] Web page feature data is used to reflect the maliciousness of a web page from the web page content dimension. Web page feature data can select at least one of URL structure feature data, page content feature data, external resource feature data, and behavior feature data based on business needs, which is not limited in this embodiment. URL structure feature data is used to reflect the maliciousness of a web page from the URL structure dimension, which may include but is not limited to at least one of the following: domain name, URL length. Page content feature data is used to reflect the maliciousness of a web page from the content dimension, which may include but is not limited to at least one of the following: data for indicating hidden text, hidden elements, data for indicating keyword accumulation (keywords are related to phishing), and data for indicating the appearance of forged fields (forged fields are used to induce phishing). External resource feature data includes suspicious external links. Behavior feature data is used to reflect the maliciousness of a web page from the web page behavior dimension, which may include but is not limited to at least one of the following: data for indicating automatic pop-up situations, data for indicating redirection situations, and data for indicating sensitive API call situations.

[0078] Target semantic data is used to reflect the maliciousness of a webpage from the deep semantic dimension of its content. Specifically, the target semantic data can be obtained by semantically parsing the webpage's content using a webpage-adapted webpage semantic recognition model. The webpage semantic recognition model uses a webpage as input, identifies and analyzes its semantics, and outputs the identified semantic data. The webpage semantic recognition model is trained using multiple sets of data, each of which includes sample webpages and the corresponding semantic data.

[0079] The webpage feature data and the target semantic data are determined as the object feature data of the webpage. The object feature data obtained in this way can more accurately indicate the maliciousness level of the webpage.

[0080] Another is that, if the target object is a file, then the target object pointed to by the QR code is subjected to feature extraction processing, and the specific process of obtaining the object feature data of the target object may include the following steps: in the target isolation environment, static feature analysis is performed on the inherent attributes of the file to obtain the static feature data of the file; the file is run in the target isolation environment, and the running behavior of the file is dynamically analyzed to obtain the dynamic behavior feature data of the file, and the network communication of the file is dynamically analyzed to obtain the network behavior feature data of the file; the static feature data, dynamic behavior feature data and network behavior feature data are determined as the object feature data of the file.

[0081] When the target object is a file, it is downloaded to a target isolated environment such as a sandbox or virtual machine to prevent the file from endangering user data security during the feature extraction process. In the target isolated environment, the static feature data, dynamic behavior feature data, and network behavior feature data of the file are mainly extracted.

[0082] Static feature data is data obtained by analyzing only the inherent properties of a file without executing the file. This data is obtained using a static feature analysis tool. The static feature analysis tool can be flexibly selected based on business needs and is not limited to this in this embodiment. Static feature data may include, but is not limited to, at least one of the following: file size, file type, file extension, entropy value of the file content, file creation timestamp, file URL, file domain name, number of phishing keywords contained in the file, number of hidden elements such as forms in the file, file certificate, file digital signature, and the amount of malicious code contained in the file.

[0083] Dynamic behavior feature data is runtime behavior data collected by executing files in a controlled environment such as the target isolation environment. Dynamic behavior feature data may include, but is not limited to, at least one of the following: operating system behavior data, process behavior data. Operational behavior data reflects the various interactions and modification actions generated by the file on the operating system in the target isolation environment during execution, reflecting how the file interacts with the underlying resources of the operating system. These behaviors constitute the basic mechanism for implementing file functions and are the key basis for determining whether a file is malicious. Operational behavior data may include, but is not limited to, at least one of the following: data used to reflect registry modifications, data used to reflect file system changes, and data used to reflect privilege escalation attempts. Process behavior data reflects the dynamic performance of the operating system process level in the target isolation environment when the file is executed, revealing the file's true operating logic and execution intent, which is also the key basis for determining whether a file is malicious. Process behavior data may include, but is not limited to, at least one of the following: data used to reflect process injection behavior, data used to reflect child process creation, data used to reflect process hiding, data used to reflect API calls, and data used to reflect memory operations.

[0084] Network behavior signature data refers to data generated when a file interacts with external network entities during execution. It reflects the file's dynamic activity at the network level and is a key indicator for determining whether a file is malicious. Network behavior signature data may include, but is not limited to, at least one of the following: data indicating domain name connections, data indicating IP connections, data indicating protocol usage, and data indicating data transmission.

[0085] The static feature data, dynamic behavior feature data and network behavior feature data are determined as the object feature data of the file. The object feature data obtained in this way can more accurately indicate the maliciousness of the file.

[0086] 104. Based on the intent data and the object feature data, detect whether the QR code is a phishing QR code used for phishing attacks.

[0087] After obtaining the intent data and object feature data, the dimensions that can induce users from the data object and the dimensions of the malicious situation of the target object are explained, and a comprehensive detection is performed to determine whether the QR code carried by the data object is a phishing QR code used for phishing attacks, so as to improve the detection accuracy.

[0088] Based on the intention data and the object feature data, the implementation method of detecting whether a QR code is a phishing QR code used for phishing attacks may at least include the following method B1 and method B2.

[0089] Method B1, based on intention data and object feature data, the specific process of detecting whether a QR code is a phishing QR code used for phishing attacks may include the following steps: determining the degree of inducement of the data object to induce users to scan the QR code based on the intention data; determining the maliciousness of the target object based on the object feature data; weighting the degree of inducement and the degree of maliciousness based on their respective corresponding confidence weights to obtain the phishing risk degree of the QR code; based on the phishing risk degree, judging whether the QR code is a phishing QR code.

[0090] The intent data is input into the first model, which analyzes and identifies the intent data to obtain a degree of induction. The degree of induction output by the first model is determined as the degree of induction that the data object uses to induce the user to scan the QR code. The first model is trained based on multiple sets of data and is used to generate a corresponding degree of induction based on the input intent data. Each set of data includes sample intent data and the degree of induction corresponding to the sample intent data.

[0091] The object feature data is input to a second model, which analyzes and identifies the object feature data to determine a maliciousness level. The maliciousness level output by the second model is determined as the maliciousness level of the target object. The second model is trained based on multiple sets of data and is used to generate a corresponding maliciousness level model based on the input object feature data. Each set of data includes sample object feature data and the maliciousness level corresponding to the sample object feature data.

[0092] The confidence weight corresponding to the level of inducement reflects the credibility of the intent data in QR code phishing detection. The confidence weight corresponding to the level of maliciousness reflects the credibility of the object feature data in QR code phishing detection. These two confidence weights can be preset based on past experience and can be directly applied at the time of use.

[0093] After determining the degree of inducement, the degree of malice and their corresponding confidence weights, the degree of inducement and the degree of malice are weighted based on their respective confidence weights to obtain the phishing risk level of the QR code. The phishing risk level here can be reflected by a probability value.

[0094] After obtaining the phishing risk level, a step of determining whether the QR code is a phishing QR code based on the phishing risk level is performed. The specific implementation process of this step may include: determining whether the phishing risk level is not less than the target risk level. If it is not less than the target risk level, it indicates that the QR code poses a high risk of a phishing attack, and thus the QR code is detected as a phishing QR code. If it is less than the target risk level, it indicates that the QR code poses a low risk of a phishing attack, and thus the QR code is detected as a normal QR code, not a phishing QR code.

[0095] Method B2, based on intent data and object feature data, the specific process of detecting whether a QR code is a phishing QR code used for phishing attacks may include the following steps: based on the business type and object type corresponding to the data object and the target object, selecting a target model suitable for phishing detection of the QR code, the target model is used to analyze the intent data and the object feature data to output the corresponding phishing risk level; the intent data and the object feature data are used as model inputs and input into the target model; the phishing risk level output by the target model is determined as the phishing risk level corresponding to the QR code; based on the phishing risk level, judging whether the QR code is a phishing QR code.

[0096] Select a target model that is appropriate for the business type and object type corresponding to the data object and target object to more accurately detect QR code phishing. For example, if the data object's business type is "Bill" and the object type is "Email," and the target object's business type is "Repayment" and the object type is "Webpage," select a target model that is appropriate for "Bill," "Email," "Repayment," and "Webpage."

[0097] The target model is trained based on multiple data sets and is used to analyze and identify intent data and object feature data to output a corresponding phishing risk level. Each data set includes a sample phishing risk level, along with the intent data and object feature data corresponding to the sample phishing risk level. The intent data and object feature data are used as model inputs and fed into the target model. The phishing risk level output by the target model is then determined as the phishing risk level corresponding to the QR code. After determining the phishing risk level, the step of determining whether the QR code is a phishing QR code based on the phishing risk level is performed. The specific implementation process of this step is described in Method B2 above and will not be repeated here.

[0098] At least one of the above methods B1 and B2 can be selected based on business needs, which is not limited in this embodiment. It should be noted that when both methods are selected, the phishing risk levels obtained by the two methods are cross-checked to ensure the accuracy of the obtained phishing risk levels.

[0099] In some embodiments, further, considering that if the maliciousness of the target object reaches a certain level, scanning the QR code to access the target object is likely to cause losses to the user, based on this, the QR code phishing detection method provided in this embodiment may also include the following steps: determining whether the maliciousness of the target object indicated by the object feature data is not less than a target level threshold, which is the minimum maliciousness required to determine a malicious object; if not, detecting the QR code as a phishing QR code; if less, executing the steps of the above-mentioned methods B1 and B2 to determine whether the QR code is a phishing QR code based on the phishing risk level.

[0100] If the object feature data indicates that the maliciousness of the target object is not less than the target degree threshold, it means that scanning the QR code to access the target object is likely to cause losses to the user. Therefore, there is no need for subsequent detection, and the QR code is directly detected as a phishing QR code.

[0101] If the object feature data indicates that the maliciousness of the target object is less than the target degree threshold, it means that only by combining the maliciousness of the target object and the inducement degree of the data object can it be determined whether the QR code is a phishing QR code. Therefore, it is necessary to continue to execute the steps of determining whether the QR code is a phishing QR code based on the phishing risk level.

[0102] The QR code phishing detection method provided in an embodiment of the present application performs feature extraction processing on a data object carrying a QR code to obtain at least one intent feature data related to the intent of the data object. Intent analysis is then performed based on the obtained at least one intent feature data to obtain intent data related to the degree to which the data object induces the user to scan the QR code. Feature extraction processing is performed on the target object pointed to by the QR code to obtain object feature data related to the maliciousness of the target object. Based on the intent data and object feature data, it is detected whether the QR code is a phishing QR code used for phishing attacks. It can be seen that the solution provided in this embodiment does not need to rely on a phishing feature library for passive QR code phishing detection. By combining the intent expressed by the data object itself and the object features of the target object itself, active QR code phishing detection can be performed. In this way, both known and unknown phishing QR codes can be detected in a timely manner, thereby reducing the lag of QR code phishing detection. In addition, because the dimension of data object inducing users and the dimension of target object maliciousness are integrated to comprehensively perform QR code phishing detection, the accuracy of QR code phishing detection can be improved.

[0103] Furthermore, an embodiment of the present application provides a QR code phishing detection method, such as Figure 2 As shown, the QR code phishing detection method provided in this embodiment may further include the following steps 201 to 210.

[0104] 201. Determine a data object carrying a QR code; if the data object is a web page, execute step 202; if the data object is an email, execute step 204.

[0105] The data object to be determined depends on the application scenario of the QR code phishing detection method. If the QR code phishing detection method is applied to email control, the data object is the email containing the QR code. If the QR code phishing detection method is applied to web page control, the data object is the web page containing the QR code.

[0106] 202. Perform at least one target determination operation on the webpage.

[0107] The target judgment operation is used to determine whether a webpage has been attacked by a phishing attack. The target judgment operation can select at least one of the following operations A to C based on business needs.

[0108] Operation A performs semantic recognition on the content of the web page, determines the target use of the web page based on the semantic recognition result, obtains the registration information corresponding to the domain name of the web page from the first intelligence center, and determines whether the target use is a legitimate use declared in the registration information.

[0109] A pre-set semantic recognition model is used to perform semantic recognition on the webpage's content. The semantics indicated by the semantic recognition results are used to reflect the webpage's target purpose (e.g., billing, promotional offers, etc.). After determining the target purpose, the registration information corresponding to the webpage's domain name (e.g., registrant, registration location, registration date, etc.) is obtained from the primary intelligence center, which contains registration information corresponding to domain names.

[0110] Generally, the domain name declared in the registration information is for a legitimate purpose. If the target purpose is determined not to be a legitimate purpose as stated in the registration information, the webpage's domain name is likely a disguised phishing domain, the webpage is also a phishing attack webpage, and the QR code is likely a phishing QR code. If the target purpose is determined to be a legitimate purpose as stated in the registration information, the webpage's domain name is likely a legitimate domain name, and the QR code is likely not a phishing QR code.

[0111] Operation B: obtaining the information tag corresponding to the domain name of the webpage from the second information center, and determining whether the information tag is a legal domain name tag.

[0112] The Second Intelligence Center is used to collect intelligence tags corresponding to domain names. If the intelligence tag corresponding to the domain name of a webpage obtained from the Second Intelligence Center is not a legitimate domain tag, but a phishing domain tag, it means that the webpage is likely a phishing attack webpage, and the QR code is likely a phishing QR code. If the intelligence tag corresponding to the domain name of a webpage obtained from the Second Intelligence Center is a legitimate domain tag, it means that the QR code is likely not a phishing QR code.

[0113] Operation C: extracting at least one link attribute value from the web page links of the web page, and determining whether each link attribute value is a legal link attribute value.

[0114] From the web link At least one link attribute value (i.e., href attribute value) is extracted from a tag (i.e., a hyperlink tag). The at least one link attribute value may include, but is not limited to, at least one of the following: protocol, domain name, path, search parameter, etc. For example, if the network connection URL is https: / / sub.example.com / login? redirect=evil.com, the extracted link attribute value may include at least one of the following: protocol https, domain name sub.example.com, path / login, and search parameter redirect=evil.com.

[0115] After extracting the link attribute values, each link attribute value is compared against a phishing attribute value database, which is used to store link attribute values corresponding to phishing attacks. If, after comparison, it is determined that each link attribute value is not included in the phishing attribute value database, then each link attribute value is determined to be a legitimate link attribute value, indicating that there is a certain probability that the QR code is not a phishing QR code. If, after comparison, any link attribute value is included in the phishing attribute value database, then the link attribute value included in the phishing attribute value database is determined to be not a legitimate link attribute value, indicating that the QR code is likely a phishing QR code.

[0116] 203. Check whether the target quantity exists. If the result of the target determination operation is no, then execute step 210; if not, then execute step 205.

[0117] The target number can be flexibly selected based on business needs. For example, when the judgment is strict, the target number is 1. For example, when the judgment is not strict, the target data can be a value greater than 1.

[0118] If the result of the target determination operation is negative and the target quantity is detected, it indicates that the QR code is likely to be a phishing QR code, and therefore step 210 is executed.

[0119] If the result of the target judgment operation is negative and it is detected that the target quantity does not exist, it means that the QR code is probably not a phishing QR code, and further subsequent steps need to be performed for detection.

[0120] 204. Determine whether the email has the target condition. If so, execute step 210; if not, execute step 205.

[0121] If the data object is an email, then determining whether the email contains a target condition. The target condition may include, but is not limited to, at least one of the following: the presence of a first social engineering feature used for phishing attacks in the email data, or the presence of a second social engineering feature used for phishing attacks in the semantics expressed in the email body.

[0122] The first social engineering feature can be determined using a first social attack recognition model. Specifically, an email is input into the first social attack recognition model, which then identifies whether the email data contains the first social engineering feature used in phishing attacks. If the first social attack recognition model outputs the first social engineering feature, then the presence of the first social engineering feature used in phishing attacks is determined in the email data. The first social attack recognition model is trained based on multiple data sets, each of which includes sample emails and the first social engineering feature included in the sample emails.

[0123] The second social engineering feature can be determined using a second social attack recognition model. Specifically, an email is input into the second social attack recognition model, which then identifies whether the semantics of the email body contain the second social engineering feature used in phishing attacks. If the second social attack recognition model outputs the second social engineering feature, then the semantics of the email body contain the second social engineering feature used in phishing attacks. The second social attack recognition model is trained based on multiple data sets, each of which includes a sample email body and a corresponding second social engineering feature.

[0124] If the target is determined to be present, the QR code is likely to be a phishing QR code, and step 210 is executed. If the target is determined not to be present, the QR code is likely not to be a phishing QR code, and subsequent steps need to be further executed for detection.

[0125] 205. Perform feature extraction processing on the data object carrying the QR code to obtain at least one intention feature data related to the intention of the data object.

[0126] 206. Perform intent analysis based on the at least one intention feature data to obtain intent data of the data object, where the intent data is related to the degree to which the data object induces the user to scan the QR code.

[0127] 207 . Determine whether the data included in the target object contains a third social engineering feature used for phishing attacks. If so, execute step 210 ; if not, execute step 208 .

[0128] The third social engineering feature can be determined using a third social attack recognition model. Specifically, the target object is input into the third social attack recognition model, which then analyzes and identifies whether the data included in the target object contains the third social engineering feature used in phishing attacks. If the third social attack recognition model outputs the third social engineering feature, then the data included in the target object is determined to contain the third social engineering feature used in phishing attacks. The third social attack recognition model is trained based on multiple data sets, each of which includes a sample target object and a corresponding third social engineering feature.

[0129] If it is determined that the data included in the target object contains the third social engineering feature used for phishing attacks, it means that the QR code is likely to be a phishing QR code, and therefore step 210 is directly executed.

[0130] If it is determined that the data included in the target object does not contain the third social engineering feature used for phishing attacks, it means that there is a certain probability that the QR code is not a phishing QR code, and further subsequent steps need to be performed for detection.

[0131] 208. Perform feature extraction processing on the target object pointed to by the QR code to obtain object feature data of the target object. The object feature data is related to the maliciousness level of the target object.

[0132] 209. Based on the intent data and the object feature data, detect whether the QR code is a phishing QR code used for phishing attacks; if so, execute step 210; if not, end the current process.

[0133] 210. Detect that the QR code is a phishing QR code, and perform a disposal operation on the phishing QR code.

[0134] If a QR code is detected as a phishing QR code, a handling operation is required to reduce the harm of the QR code phishing attack. The handling operation can be selected based on business needs. At least one of the following handling operation 1 and handling operation 2.

[0135] Processing operation one: if the QR code is detected to be a phishing QR code, check whether the target business field is included in the data object; if it is included, process the QR code so that the user cannot view the QR code carried by the data object; if it is not included, intercept and process the data object.

[0136] The target business field is used to indicate that the QR code is maliciously embedded in the data object, and other data in the data object may still be needed by the user. The target business field can be flexibly selected based on business needs, and this embodiment does not limit this.

[0137] If the target business field is detected in the data object, it indicates that the QR code has been maliciously embedded in the data object, but the user still needs to use the other data in the data object. Based on this, to meet user needs, the QR code is processed so that the user cannot see the QR code carried in the data object. In this way, the user cannot scan the QR code to access the data, and thus cannot be attacked by phishing.

[0138] If it is detected that the data object includes the target business field, it means that the QR code is most likely not maliciously embedded in the data object, and the data object is most likely a malicious object generated by an attacker. Therefore, the data object is directly deleted or intercepted to prevent users from accessing the data object and being attacked by phishing.

[0139] The second processing operation is to determine the target feature data corresponding to the data object if the QR code is detected to be a phishing QR code, and search for the associated objects of the data object from other data objects other than the data object based on the target feature data, and determine that the QR code carried by the associated objects is a phishing QR code.

[0140] If the QR code is a phishing QR code, it indicates that the data object's associated objects may also carry phishing QR codes. Based on this, the target feature data corresponding to the data object is determined (for example, the domain name, the object feature data mentioned in the above steps, the intent feature data, etc., which are not limited to this embodiment). Based on the target feature data, the data object's associated objects are searched from data objects other than the data object. The similarity between the object feature data of the associated objects and the target feature data reaches a similarity threshold. If an associated object is found, the QR code carried by the associated object is determined to be a phishing QR code, and a disposal operation is performed on the phishing QR code. The disposal operation can be referred to as the disposal operation 1 above.

[0141] Embodiments of the present application Figure 2 In the QR code phishing detection method provided, the detailed explanation of each step in the execution process can be found in the above Figure 1 The corresponding detailed explanation of the QR code phishing detection method embodiment will not be repeated here.

[0142] Furthermore, an embodiment of the present application also provides a QR code phishing detection device, such as Figure 3 As shown, the QR code phishing detection device provided in this embodiment may include at least:

[0143] A first extraction module 31 is configured to perform feature extraction processing on a data object carrying a QR code to obtain at least one intention feature data related to the intention of the data object;

[0144] An analysis module 32 is configured to perform intent analysis based on the at least one intention feature data to obtain intent data of the data object, wherein the intent data is related to the degree to which the data object induces a user to scan a QR code;

[0145] A second extraction module 33 is configured to perform feature extraction processing on the target object pointed to by the QR code to obtain object feature data of the target object, wherein the object feature data is related to the maliciousness level of the target object;

[0146] The detection module 34 is configured to detect whether the QR code is a phishing QR code used for phishing attacks based on the intention data and the object feature data.

[0147] The QR code phishing detection device provided in an embodiment of the present application performs feature extraction processing on a data object carrying a QR code to obtain at least one intent feature data related to the intent of the data object. Intent analysis is then performed based on the obtained at least one intent feature data to obtain intent data related to the degree to which the data object induces the user to scan the QR code. Feature extraction processing is performed on the target object pointed to by the QR code to obtain object feature data related to the maliciousness of the target object. Based on the intent data and object feature data, it is detected whether the QR code is a phishing QR code used for phishing attacks. It can be seen that the solution provided in this embodiment does not need to rely on a phishing feature library for passive QR code phishing detection. By combining the intent expressed by the data object itself and the object features of the target object itself, active QR code phishing detection can be performed. In this way, both known and unknown phishing QR codes can be detected in a timely manner, thereby reducing the lag of QR code phishing detection. In addition, because the dimension of data object inducing users and the dimension of target object maliciousness are integrated to comprehensively perform QR code phishing detection, the accuracy of QR code phishing detection can be improved.

[0148] In some embodiments of the present application, Figure 4 As shown, the first extraction module 31 may include:

[0149] A selection unit 311 is configured to select the type of intent feature data required for analyzing the intent of the data object; select an extraction model corresponding to each type and adapted to the data object, the extraction model being configured to identify the corresponding type of intent feature data based on the data analysis in the data object;

[0150] The first extraction unit 312 is used to perform the following for each category: input the data object into the extraction model corresponding to the category, and determine the intention feature data identified by the extraction model based on data analysis in the data object as the intention feature data corresponding to the category.

[0151] In some embodiments of the present application, Figure 4As shown, the at least one intention feature data extracted by the first extraction module 31 includes at least one of the following: social engineering feature data, psychology feature data, semantic feature data, and emotion feature data.

[0152] In some embodiments of the present application, Figure 4 As shown, the analysis module 32 is specifically used to determine the weight of each intention feature data in the intention analysis; and to fuse various intention feature data based on the weight to obtain the intention data of the data object.

[0153] In some embodiments of the present application, Figure 4 As shown, if the target object is a web page, the second extraction module 33 may include: a second extraction unit 331, used to determine at least one of the following web page feature data of the web page: URL structure feature data, page content feature data, external resource feature data, and behavior feature data; perform semantic analysis on the content of the web page to obtain target semantic data; and determine the web page feature data and the target semantic data as object feature data of the target object.

[0154] In some embodiments of the present application, Figure 4 As shown, if the target object is a file, the second extraction module 33 may include: a third extraction unit 332, used to perform static feature analysis on the inherent attributes of the file in the target isolation environment to obtain static feature data of the file; run the file in the target isolation environment, and dynamically analyze the running behavior of the file to obtain dynamic behavior feature data of the file, and dynamically analyze the network communication of the file to obtain network behavior feature data of the file; and determine the static feature data, dynamic behavior feature data and network behavior feature data as object feature data of the file.

[0155] In some embodiments of the present application, Figure 4 As shown, the detection module 34 may include at least one of a first detection unit 341 and a second detection unit 342 as follows.

[0156] The first detection unit 341 is used to determine the degree of inducement of the data object in inducing the user to scan the QR code based on the intention data; determine the maliciousness of the target object based on the object feature data; perform weighted processing on the degree of inducement and the degree of maliciousness based on their respective corresponding confidence weights to obtain the phishing risk level of the QR code; and determine whether the QR code is a phishing QR code based on the phishing risk level.

[0157] The second detection unit 342 is used to select a target model suitable for phishing detection on the QR code based on the business type and object type corresponding to the data object and the target object, and the target model is used to analyze the intention data and the object feature data to output a corresponding phishing risk level; the intention data and the object feature data are used as model inputs and input into the target model; the phishing risk level output by the target model is determined as the phishing risk level corresponding to the QR code; and based on the phishing risk level, it is determined whether the QR code is a phishing QR code.

[0158] In some embodiments of the present application, Figure 4 As shown, the first detection unit 341 can also be used to determine whether the maliciousness of the target object indicated by the object feature data is not less than a target degree threshold, and the target degree threshold is the minimum maliciousness required to determine a malicious object; if it is not less than, the QR code is detected as a phishing QR code; if it is less than, the step of determining whether the QR code is a phishing QR code based on the phishing risk level is executed.

[0159] In some embodiments of the present application, Figure 4 As shown, the second detection unit 342 can also be used to determine whether the maliciousness of the target object indicated by the object feature data is not less than a target degree threshold, and the target degree threshold is the minimum maliciousness required to determine a malicious object; if it is not less than, the QR code is detected as a phishing QR code; if it is less than, the step of determining whether the QR code is a phishing QR code based on the phishing risk level is executed.

[0160] In some embodiments of the present application, Figure 4 As shown, if the data object is a web page, the QR code phishing detection device provided in this embodiment may further include:

[0161] The operation module 35 is configured to perform at least one of the following target determination operations: performing semantic recognition on the content of the webpage, determining the target purpose of the webpage based on the semantic recognition result, obtaining registration information corresponding to the domain name of the webpage from a first intelligence center, and determining whether the target purpose is a legitimate purpose declared in the registration information; obtaining an intelligence tag corresponding to the domain name of the webpage from a second intelligence center, and determining whether the intelligence tag is a legitimate domain name tag; extracting at least one link attribute value from the webpage links of the webpage, and determining whether each link attribute value is a legitimate link attribute value;

[0162] The judgment module 36 is used to detect that the QR code is a fishing QR code if the judgment result of the target judgment operation is no if the target number exists; if the judgment result of the target judgment operation is no if the target number does not exist, trigger the first extraction module 31 to perform feature extraction processing on the data object carrying the QR code, and obtain at least one intention feature data related to the intention of the data object.

[0163] In some embodiments of the present application, Figure 4 As shown, if the data object is an email, the QR code phishing detection device provided in this embodiment may further include: a first judgment module 37, used to determine whether the email has a target situation. If so, the QR code is detected as a phishing QR code; if not, the first extraction module 31 is triggered to perform feature extraction processing on the data object carrying the QR code to obtain at least one intention feature data related to the intention of the data object; the target situation includes at least one of the following: the presence of a first social engineering feature used for phishing attacks in the email data, and the presence of a second social engineering feature used for phishing attacks in the semantics expressed in the email body.

[0164] In some embodiments of the present application, Figure 4 As shown, the second extraction module 33 can also be used to parse the QR code to obtain the target link contained in the QR code; access the target link to obtain the link content information corresponding to the target link; if the link content information indicates a file, the file indicated by the link content information is determined as the target object pointed to by the QR code; if the link content information indicates a web page, the web page indicated by the link content information is determined as the target object pointed to by the QR code.

[0165] In some embodiments of the present application, Figure 4 As shown, the QR code phishing detection device provided in this embodiment may further include: a second judgment module 38, used to judge whether the data included in the target object contains a third social engineering feature used for phishing attacks; if so, the QR code is detected as a phishing QR code; if not, the second extraction module 33 is triggered to perform feature extraction processing on the target object pointed to by the QR code to obtain the object feature data of the target object.

[0166] In some embodiments of the present application, Figure 4As shown, the QR code phishing detection device provided in this embodiment may further include: a disposal module 39, which is used to detect whether the data object includes a target business field if the detection module 34 detects that the QR code is a phishing QR code, and the target business field is used to reflect that the QR code is maliciously embedded in the data object; if it is included, the QR code is disposed of so that the user cannot view the QR code carried by the data object; if it is not included, the data object is intercepted and disposed of.

[0167] In some embodiments of the present application, Figure 4 As shown, the QR code phishing detection device provided in this embodiment may further include: a search module 40, which is used to determine the target feature data corresponding to the data object if the detection module 34 detects that the QR code is a phishing QR code, and based on the target feature data, search for the associated object of the data object from other data objects other than the data object, and determine that the QR code carried by the found associated object is a phishing QR code.

[0168] In the QR code phishing detection device provided in the embodiment of the present application, the detailed explanations used during the operation of each functional module can be found in the corresponding detailed explanations of the above-mentioned QR code phishing detection method embodiment, and will not be repeated here.

[0169] Furthermore, an embodiment of the present application also provides a computer-readable storage medium, which includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the above-mentioned QR code phishing detection method.

[0170] Furthermore, an embodiment of the present application also provides an electronic device, which includes: a memory for storing a program; and a processor coupled to the memory for running the program to execute the above-mentioned QR code phishing detection method.

[0171] Furthermore, an embodiment of the present application also provides a computer program product, which includes: a computer program / computer executable instructions, which implement the above-mentioned QR code phishing detection method when executed by a processor.

[0172] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0173] It is understood that the relevant features of the above methods and devices can be referenced to each other. In addition, the terms "first" and "second" in the above embodiments are used to distinguish between the embodiments, and do not represent the advantages and disadvantages of the embodiments.

[0174] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0175] The algorithm and display provided herein are not inherently related to any particular computer, virtual system or other device. Various general-purpose systems can also be used together with the teachings based on this. According to the above description, it is obvious that the structure required for constructing such systems. In addition, the application is not directed to any specific programming language. It should be understood that various programming languages can be utilized to implement the content of the application described herein, and the above description of specific languages is for the purpose of disclosing the preferred embodiment of the application.

[0176] In addition, the memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0177] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0178] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data cutover device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data cutover device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0179] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data switching device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0180] These computer program instructions can also be loaded onto a computer or other programmable data switching device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0181] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0182] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0183] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0184] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0185] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0186] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A QR code phishing detection method, characterized in that: The method comprises: Performing feature extraction processing on a data object carrying a QR code to obtain at least one intention feature data related to the intention of the data object; Performing intent analysis based on the at least one intention feature data to obtain intent data of the data object, wherein the intent data is related to the degree to which the data object induces a user to scan a QR code; Performing feature extraction processing on the target object pointed to by the QR code to obtain object feature data of the target object, wherein the object feature data is related to the maliciousness level of the target object; Based on the intention data and the object feature data, it is detected whether the QR code is a phishing QR code used for phishing attacks.

2. The method according to claim 1, characterized in that Performing feature extraction processing on a data object carrying a QR code to obtain at least one intention feature data related to the intention of the data object, including: Select the type of intent feature data needed to analyze the intent of the data object; Selecting an extraction model for each category that is adapted to the data object, the extraction model being used to identify the corresponding category of intention feature data based on data analysis in the data object; For each category, the following steps are performed: inputting the data object into the extraction model corresponding to the category, and analyzing the intention feature data identified by the extraction model based on the data in the data object to determine it as the intention feature data corresponding to the category.

3. The method according to claim 1, characterized in that Performing intent analysis based on the at least one intention feature data to obtain the intention data of the data object includes: determining a weight of each intention feature data in the intention analysis; fusing the various intention feature data based on the weight to obtain the intention data of the data object; and / or, The at least one intention feature data includes at least one of the following: social engineering feature data, psychology feature data, semantic feature data, and emotion feature data.

4. The method according to claim 1, wherein If the target object is a web page, then feature extraction processing is performed on the target object pointed to by the QR code to obtain object feature data of the target object, including: determining at least one of the following web page feature data of the web page: URL structure feature data, page content feature data, external resource feature data, and behavior feature data; performing semantic analysis on the content of the web page to obtain target semantic data; and determining the web page feature data and the target semantic data as the object feature data of the target object; or, If the target object is a file, then feature extraction processing is performed on the target object pointed to by the QR code to obtain object feature data of the target object, including: in a target isolation environment, static feature analysis is performed on the inherent attributes of the file to obtain static feature data of the file; the file is run in the target isolation environment, and the running behavior of the file is dynamically analyzed to obtain dynamic behavior feature data of the file, and the network communication of the file is dynamically analyzed to obtain network behavior feature data of the file; the static feature data, dynamic behavior feature data and network behavior feature data are determined as the object feature data of the file.

5. The method according to claim 1, wherein Detecting, based on the intent data and the object feature data, whether the QR code is a phishing QR code used for a phishing attack includes: Determining, based on the intention data, the degree to which the data object induces a user to scan a QR code; determining, based on the object feature data, the degree of maliciousness of the target object; performing weighted processing on the degree of inducement and the degree of maliciousness based on their respective corresponding confidence weights to obtain a phishing risk level for the QR code; and determining, based on the phishing risk level, whether the QR code is a phishing QR code; and / or, Based on the business type and object type corresponding to the data object and the target object, a target model suitable for phishing detection on the QR code is selected, and the target model is used to analyze the intention data and the object feature data to output a corresponding phishing risk level; the intention data and the object feature data are used as model inputs and input into the target model; the phishing risk level output by the target model is determined as the phishing risk level corresponding to the QR code; based on the phishing risk level, it is determined whether the QR code is a phishing QR code.

6. The method according to claim 5, characterized in that The method further comprises: determining whether the maliciousness level of the target object indicated by the object feature data is not less than a target level threshold, where the target level threshold is a minimum maliciousness level required to determine a malicious object; If it is not less than, the QR code is detected as a phishing QR code; If it is less than, the step of determining whether the QR code is a phishing QR code based on the phishing risk level is executed.

7. The method according to claim 1, characterized in that If the data object is a web page, the method further includes: performing at least one of the following target determination operations: performing semantic recognition on the content of the webpage, determining a target use of the webpage based on the semantic recognition result, obtaining registration information corresponding to the domain name of the webpage from a first intelligence center, and determining whether the target use is a legitimate use declared in the registration information; Obtaining an intelligence tag corresponding to the domain name of the webpage from a second intelligence center, and determining whether the intelligence tag is a legitimate domain name tag; extracting at least one link attribute value from the web page links of the web page, and determining whether each link attribute value is a legal link attribute value; If the result of the target determination operation is no, the QR code is detected as a phishing QR code; If the result of the target determination operation of the target quantity does not exist is negative, performing a feature extraction process on the data object carrying the QR code to obtain at least one intention feature data related to the intention of the data object; or, If the data object is an email, the method further includes: determining whether the email has a target situation, and if so, detecting that the QR code is a phishing QR code; if not, performing feature extraction processing on the data object carrying the QR code to obtain at least one intention feature data related to the intention of the data object; the target situation includes at least one of the following: the presence of a first social engineering feature used for phishing attacks in the email data, and the presence of a second social engineering feature used for phishing attacks in the semantics expressed in the email body.

8. The method according to any one of claims 1 to 7, characterized in that The method further includes: parsing the QR code to obtain a target link contained in the QR code; accessing the target link to obtain link content information corresponding to the target link; if the link content information indicates a file, determining the file indicated by the link content information as the target object pointed to by the QR code; if the link content information indicates a web page, determining the web page indicated by the link content information as the target object pointed to by the QR code; and / or, The method further includes: determining whether the data included in the target object contains a third social engineering feature used for phishing attacks; if so, detecting that the QR code is a phishing QR code; if not, performing feature extraction processing on the target object pointed to by the QR code to obtain object feature data of the target object; and / or, The method further includes: if the QR code is detected to be a phishing QR code, detecting whether the data object includes a target service field, the target service field being used to indicate that the QR code is maliciously embedded in the data object; if the target service field is included, processing the QR code so that the user cannot view the QR code carried by the data object; if the target service field is not included, intercepting the data object; and / or, The method also includes: if the QR code is detected to be a phishing QR code, determining target feature data corresponding to the data object, searching for associated objects of the data object from other data objects other than the data object based on the target feature data, and determining that the QR code carried by the found associated object is a phishing QR code.

9. A QR code phishing detection device, characterized in that: The device comprises: A first extraction module is configured to perform feature extraction processing on a data object carrying a QR code to obtain at least one intention feature data related to the intention of the data object; an analysis module, configured to perform intent analysis based on the at least one intention feature data to obtain intent data of the data object, wherein the intent data is related to the degree to which the data object induces a user to scan a QR code; A second extraction module is configured to perform feature extraction processing on the target object pointed to by the QR code to obtain object feature data of the target object, wherein the object feature data is related to the maliciousness level of the target object; A detection module is used to detect whether the QR code is a phishing QR code used for phishing attacks based on the intention data and the object feature data.

10. A computer-readable storage medium, characterized in that The storage medium includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the QR code phishing detection method according to any one of claims 1 to 8.

11. An electronic device, characterized in that: The electronic device includes: a memory for storing a program; and a processor coupled to the memory for running the program to execute the QR code phishing detection method according to any one of claims 1 to 8.

12. A computer program product, characterized in that The computer program product includes: a computer program / computer executable instructions, which, when executed by a processor, implements the QR code phishing detection method described in any one of claims 1 to 8.