Prototype pollution vulnerability detection method and device, computing equipment and storage medium

By obtaining uncontaminated prototypes and comparing and replacing them, the problems of high cost of prototype pollution detection and poor user experience in the existing technology are solved, and high accuracy and low cost of prototype pollution vulnerability detection and recovery are achieved.

CN120597283APending Publication Date: 2025-09-05SHANGHAI BILIBILI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510696189.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The existing prototype pollution vulnerability detection solutions are costly, affect user experience, and cannot effectively restore contaminated prototype functions.

Method used

By obtaining the current prototype in the current running environment and the uncontaminated prototype in the uncontaminated environment, use inline framework elements or independent worker threads to bypass the browser extension plug-in, perform comparison detection and replace the current prototype to restore the original function.

Benefits of technology

Highly accurate and low-cost prototype pollution vulnerability detection is achieved, reducing the impact of user experience, and completing detection and recovery locally, improving reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597283A_ABST
    Figure CN120597283A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a prototype pollution vulnerability detection method and device, computing equipment and a storage medium, and the method comprises the steps: obtaining a current prototype in a current operation environment, and obtaining an unpolluted prototype in an unpolluted environment; detecting whether the current prototype is polluted or not according to the unpolluted prototype; and if the current prototype is polluted, replacing the current prototype by using an unpolluted prototype so as to recover all or part of the functions of the original prototype. Whether the current prototype in the current operation environment is polluted or not is detected according to the unpolluted prototype, whether the current prototype is polluted or not can be rapidly and accurately detected, accurate detection of prototype pollution vulnerabilities is achieved, the detection accuracy is effectively improved, and under the condition that pollution of the current prototype is detected, the prototype pollution vulnerabilities can be accurately detected. And the current prototype can be replaced by using the unpolluted prototype, so that prototype recovery is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of Internet technology, and specifically to a prototype contamination vulnerability detection method, apparatus, computing device, and storage medium. Background Art

[0002] With the development of science and technology, the internet has become deeply integrated into users' daily lives. As the primary gateway to the internet, web browsers are used by users in a wide range of scenarios, such as shopping, gaming, video viewing, and information browsing. To meet users' diverse functional needs for web browsers, a number of browser extensions have been developed, such as those for ad blocking, data security protection, and website check-in. Users can install browser extensions with the required functionality on the web browsers on their devices.

[0003] Many browser extensions work through prototype pollution in JavaScript. However, some browser extensions may disguise themselves as other features, such as ad blocking or website sign-in functionality. These features can replace website text input or network request functions through prototype pollution, allowing them to monitor or steal personal information such as user accounts and passwords without the user's knowledge. This poses a significant security risk.

[0004] To address the aforementioned security risks, several prototype contamination vulnerability detection schemes have been proposed in the prior art. One prototype contamination vulnerability detection scheme compares the user's web browser with the server-side web browser while the website is running to detect whether the browser environment has been tampered with. However, due to the rapid iteration speed of web browsers, this detection scheme requires running various versions of web browsers on the server side, which not only incurs a large amount of cost but also suffers from low reliability due to its strong reliance on the network for interactive verification. Another prototype contamination vulnerability detection scheme blacklists browser extensions that may affect website operation. If a user is found to have installed such a browser extension, a prompt will pop up or the user will be prevented from continuing to use it. However, this detection scheme may mistakenly blacklist browser extensions that do not affect code execution, affecting the user experience. Yet another prototype contamination vulnerability detection scheme uses sandboxing technology to run the code in an isolated environment to ensure environmental security. However, sandboxing technology often leads to a significant performance degradation, causing the user's device to overheat and freeze, affecting the user experience. Moreover, sandboxing technology cannot effectively address situations where the original functions of the web browser have been deleted through prototype contamination. It can be seen that the existing prototype contamination vulnerability detection scheme not only has problems such as high detection cost and impact on user experience, but also cannot restore all or part of the original functions of the contaminated prototype. Summary of the Invention

[0005] In view of the above problems, this application proposes a prototype contamination vulnerability detection method, device, computing device and storage medium to solve the following problems: Existing prototype contamination vulnerability detection solutions not only have high costs and affect user experience, but also cannot restore all or part of the original functions of the contaminated prototype.

[0006] According to one aspect of an embodiment of the present application, a prototype contamination vulnerability detection method is provided, comprising:

[0007] Get the current prototype in the current running environment and get the uncontaminated prototype in the uncontaminated environment;

[0008] Based on the uncontaminated prototype, detect whether the current prototype is contaminated;

[0009] If the current prototype is contaminated, it is replaced with an uncontaminated prototype to restore all or part of the original prototype's functions.

[0010] Furthermore, obtaining an uncontaminated prototype in an uncontaminated environment further includes:

[0011] Using the inline frame element, obtain the uncontaminated prototype in the uncontaminated environment from the specified URL;

[0012] Alternatively, use a worker thread independent of the main thread to obtain an uncontaminated prototype in an uncontaminated environment.

[0013] Furthermore, obtaining the uncontaminated prototype in the uncontaminated environment from the specified URL by using the inline frame element further includes:

[0014] Create an inline frame element, set the source address of the inline frame element to the specified URL, and mount the inline frame element into the document;

[0015] The context property of the inline frame element is used to obtain the unpolluted context of the inline frame element, and the unpolluted context is used as the unpolluted environment to obtain the unpolluted prototype in the unpolluted environment.

[0016] Furthermore, the method further comprises:

[0017] Sets the hidden property of an inline frame element.

[0018] Furthermore, the designated URL includes: a web browser internal page URL, a binary object uniform resource identifier, and a data uniform resource identifier.

[0019] Furthermore, the method further comprises:

[0020] Data with a media type of HTML document is selected as a binary object uniform resource identifier or a data uniform resource identifier.

[0021] Furthermore, based on the uncontaminated prototype, detecting whether the current prototype is contaminated further includes:

[0022] Compare the current prototype with the uncontaminated prototype to determine whether the current prototype is consistent with the uncontaminated prototype;

[0023] If they are consistent, it is determined that the current prototype is not contaminated;

[0024] If they are inconsistent, it is determined that the current prototype is contaminated.

[0025] According to another aspect of an embodiment of the present application, a prototype contamination vulnerability detection device is provided, comprising:

[0026] An acquisition module adapted to acquire the current prototype in the current operating environment and acquire the uncontaminated prototype in the uncontaminated environment;

[0027] A detection module, adapted to detect whether the current prototype is contaminated based on the uncontaminated prototype;

[0028] The restoration module is suitable for replacing the current prototype with an uncontaminated prototype if the current prototype is contaminated, so as to restore all or part of the original prototype functions.

[0029] Furthermore, the acquisition module is further adapted to:

[0030] Using the inline frame element, obtain the uncontaminated prototype in the uncontaminated environment from the specified URL;

[0031] Alternatively, use a worker thread independent of the main thread to obtain an uncontaminated prototype in an uncontaminated environment.

[0032] Furthermore, the acquisition module is further adapted to:

[0033] Create an inline frame element, set the source address of the inline frame element to the specified URL, and mount the inline frame element into the document;

[0034] The context property of the inline frame element is used to obtain the unpolluted context of the inline frame element, and the unpolluted context is used as the unpolluted environment to obtain the unpolluted prototype in the unpolluted environment.

[0035] Furthermore, the acquisition module is further adapted to:

[0036] Sets the hidden property of an inline frame element.

[0037] Furthermore, the designated URL includes: a web browser internal page URL, a binary object uniform resource identifier, and a data uniform resource identifier.

[0038] Furthermore, the acquisition module is further adapted to:

[0039] Data with a media type of HTML document is selected as a binary object uniform resource identifier or a data uniform resource identifier.

[0040] Furthermore, the detection module is further adapted to:

[0041] Compare the current prototype with the uncontaminated prototype to determine whether the current prototype is consistent with the uncontaminated prototype;

[0042] If they are consistent, it is determined that the current prototype is not contaminated;

[0043] If they are inconsistent, it is determined that the current prototype is contaminated.

[0044] According to another aspect of an embodiment of the present application, a computing device is provided, comprising: a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other via the communication bus;

[0045] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute operations corresponding to the above-mentioned prototype pollution vulnerability detection method.

[0046] According to another aspect of the embodiments of the present application, a computer storage medium is provided, in which at least one executable instruction is stored. The executable instruction enables a processor to perform operations corresponding to the above-mentioned prototype contamination vulnerability detection method.

[0047] According to another aspect of the embodiments of the present application, a computer program product is provided, comprising at least one executable instruction, wherein the executable instruction enables a processor to perform operations corresponding to the above-mentioned prototype contamination vulnerability detection method.

[0048] According to the prototype contamination vulnerability detection method, device, computing device and storage medium provided in the embodiments of the present application, it is possible to conveniently bypass browser extension plug-ins and directly obtain a clean, uncontaminated prototype in an uncontaminated environment. Based on the uncontaminated prototype, it is possible to detect whether the current prototype in the current running environment is contaminated. It is possible to quickly and accurately detect whether the current prototype is prototype contaminated, thereby achieving accurate detection of prototype contamination vulnerabilities, effectively improving detection accuracy, and effectively reducing detection costs, reducing the impact on user experience; moreover, the solution can completely perform prototype contamination vulnerability detection locally without relying on the network to enable interactive verification between the client and the server, overcoming the defect in the prior art that local prototype contamination cannot be detected locally, and greatly improving reliability; in addition, when the current prototype is detected to be contaminated, the uncontaminated prototype can be used to replace the current prototype, thereby conveniently restoring all or part of the original prototype function, realizing prototype recovery, and solving the problem in the prior art that even if prototype contamination is detected, prototype contamination cannot be fundamentally solved.

[0049] The above description is only an overview of the technical solution of the embodiment of the present application. In order to more clearly understand the technical means of the embodiment of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the embodiment of the present application more obvious and easy to understand, the specific implementation method of the embodiment of the present application is specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the embodiments of the present application. The same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0051] Figure 1 A schematic diagram of a process for detecting a prototype contamination vulnerability according to an embodiment of the present application is shown;

[0052] Figure 2 A schematic diagram of a process for detecting a prototype contamination vulnerability according to another embodiment of the present application is shown;

[0053] Figure 3 The following is a structural block diagram of a prototype contamination vulnerability detection device according to an embodiment of the present application;

[0054] Figure 4 A schematic structural diagram of a computing device according to an embodiment of the present application is shown. DETAILED DESCRIPTION

[0055] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0056] First, the terms involved in one or more embodiments of the present application are explained.

[0057] JavaScript (JS): is a multi-paradigm high-level interpreted programming language based on prototypes and first-class functions. It supports object-oriented programming, imperative programming, and functional programming. It is widely used in web development, mainly to enhance the interactivity and dynamism of web pages.

[0058] Prototype: In JavaScript, the prototype is a crucial concept, providing a mechanism for objects to inherit and share properties. Every JavaScript object has an associated prototype object, which enables the sharing of properties and methods, thereby reducing memory usage. Inheritance is achieved through the prototype chain, allowing objects to share properties and methods with other objects.

[0059] Prototype chain: It represents a relationship between an instance object and a prototype object, which is connected through the __proto__ prototype.

[0060] Prototype pollution: A security vulnerability in JavaScript that allows an attacker to add arbitrary properties to the global object prototype, which can then be inherited by user-defined objects. When accessing an object's property, if the object itself does not have the property, the prototype chain is searched upwards.

[0061] An API (Application Program Interface) is a computing interface that defines the interactions between multiple software intermediaries, including the types of calls or requests that can be made, how to make them, the data formats to be used, and the conventions to be followed. It is also known as an Application Programming Interface. An API also provides an extension mechanism, allowing users to extend existing functionality to varying degrees through various means.

[0062] Figure 1 FIG. 1 shows a flow chart of a prototype contamination vulnerability detection method according to an embodiment of the present application. Figure 1 As shown, the method includes the following steps:

[0063] Step S101, obtaining the current prototype in the current operating environment and obtaining the uncontaminated prototype in the uncontaminated environment.

[0064] In order to facilitate the understanding of this application, the application scenarios of this application are first introduced below. When JS declares a constructor function (i.e., a function used to instantiate an object), a corresponding object will be created in the memory. This object is the prototype of the original function. The constructor function has a prototype attribute (i.e., the prototype attribute) by default, and the value of the prototype attribute points to the prototype of the function. At the same time, there is also a constructor attribute (i.e., the constructor function attribute) in the prototype, and the value of the constructor attribute points to the function object. The object instantiated by the constructor function does not have a prototype attribute. It has a __proto__ attribute by default, and the value of the __proto__ attribute points to the prototype of the constructor function. Properties added or modified on the prototype can be shared on all instantiated objects. Through the prototype, data sharing and inheritance can be achieved, effectively saving memory space.

[0065] When accessing a property in an instantiated object, the property is first searched within the object itself—that is, within its own properties. If the property is not found, the property is searched in the prototype pointed to by its __proto__. If the property is still not found, the property is searched in the prototype's parent prototype pointed to by its __proto__, and so on, until it is found or reaches Object.prototype.__proto__ (which is null). This chain of processes is known as the prototype chain. An attacker can exploit the vulnerability of prototype pollution to add arbitrary properties to the global object prototype, which may then be inherited by user-defined objects. By modifying the prototype, an attacker can affect the behavior of all objects. While prototype pollution is typically unexploitable as a standalone vulnerability, it allows an attacker to control properties of an object that would otherwise be inaccessible. If the application subsequently handles the attacker-controlled properties in an unsafe manner, this can lead to other vulnerabilities. In client-side JavaScript, prototype pollution often leads to DOM-based Cross-Site Scripting (XSS), while server-side prototype pollution can even lead to remote code execution. DOM-based XSS is a special type of cross-site scripting attack in which the malicious code executes entirely on the client side, without involving a server-side response.

[0066] The embodiment of the present application proposes a solution that bypasses browser extension plug-ins, directly obtains a clean uncontaminated prototype in an uncontaminated environment, and detects whether the current prototype in the current running environment is contaminated based on the uncontaminated prototype. The solution can accurately detect whether the current prototype is contaminated, and the detection accuracy is extremely high.

[0067] Specifically, the prototype acquisition method commonly used in the prior art can be used to obtain the current prototype in the current running environment; the feature of the web browser that excludes browser extension plug-ins for certain environments such as worker threads and specified URLs can be used to obtain the uncontaminated prototype in the uncontaminated environment.

[0068] Step S102: Detect whether the current prototype is contaminated based on the uncontaminated prototype.

[0069] After obtaining the current prototype and the uncontaminated prototype, the uncontaminated prototype can be used as a reference to check whether the current prototype is contaminated. Specifically, the current prototype can be compared with the uncontaminated prototype to determine whether the current prototype is consistent with the uncontaminated prototype, thereby confirming whether the current prototype is contaminated. This processing method can completely perform prototype contamination vulnerability detection locally, without relying on the network for interactive verification between the client and the server, greatly improving reliability.

[0070] Step S103: If the current prototype is contaminated, the current prototype is replaced with an uncontaminated prototype to restore all or part of the original prototype function.

[0071] In the case that the current prototype is found to be contaminated by the detection in step S102, the uncontaminated prototype can be used to replace the contaminated current prototype in the current running environment, and all or part of the original prototype functions can be easily restored through prototype replacement. Among them, some original prototype functions cannot be restored through prototype replacement. In the embodiment of the present application, the original prototype functions that cannot be restored through prototype replacement are referred to as designated functions, and the designated functions may include functions for modifying the current context, etc. Specifically, in the case that the original prototype functions do not include the designated functions, replacing the current prototype with the uncontaminated prototype can restore all the original prototype functions; in the case that the original prototype functions include the designated functions, replacing the current prototype with the uncontaminated prototype can restore other functions in the original prototype functions except the designated functions.

[0072] If the current prototype is found to be free of contamination as detected in step S102 , it means that there is no need to restore the prototype, and the method ends.

[0073] According to the prototype contamination vulnerability detection method provided in the embodiment of the present application, it is possible to conveniently bypass browser extension plug-ins and directly obtain a clean, uncontaminated prototype in an uncontaminated environment. Based on the uncontaminated prototype, it is possible to detect whether the current prototype in the current running environment is contaminated. It is possible to quickly and accurately detect whether the current prototype is prototype contaminated, thereby achieving accurate detection of prototype contamination vulnerabilities, effectively improving detection accuracy, and effectively reducing detection costs, reducing the impact on user experience; moreover, the solution can completely perform prototype contamination vulnerability detection locally without relying on the network to enable interactive verification between the client and the server, overcoming the defect in the prior art that local prototype contamination cannot be detected locally, and greatly improving reliability; in addition, when the current prototype is detected to be contaminated, the uncontaminated prototype can be used to replace the current prototype, thereby conveniently restoring all or part of the original prototype function, realizing prototype recovery, and solving the problem in the prior art that even if prototype contamination is detected, prototype contamination cannot be fundamentally solved.

[0074] Figure 2 FIG. 1 shows a flow chart of a prototype contamination vulnerability detection method according to another embodiment of the present application. Figure 2 As shown, the method includes the following steps:

[0075] Step S201: Obtain the current prototype in the current running environment.

[0076] To facilitate detection of contamination of the current prototype, in step S201, the current prototype in the current runtime environment needs to be obtained. This can be done using commonly used prototype acquisition methods in the prior art. For example, for instance objects, the Object.getPrototypeOf() method can be used to obtain the current prototype of the instance object in the current runtime environment. For constructors, the current prototype of the constructor in the current runtime environment can be obtained by directly accessing the prototype property.

[0077] Step S202: using an inline frame element to obtain an uncontaminated prototype in an uncontaminated environment from a specified URL; or using a working thread independent of the main thread to obtain an uncontaminated prototype in an uncontaminated environment.

[0078] In this embodiment of the present application, the web browser's characteristic of excluding browser extensions in certain environments, such as specified URLs and worker threads, is exploited to obtain an uncontaminated prototype in an uncontaminated environment. This embodiment of the present application can conveniently obtain an uncontaminated prototype, overcoming the drawback of the prior art that the lack of a reference uncontaminated prototype results in an inability to accurately detect whether the current prototype is contaminated.

[0079] In an optional embodiment, an inline frame element can be used to obtain an uncontaminated prototype in an uncontaminated environment from a specified URL. In an embodiment of the present application, the specified URL refers to a URL that can exclude browser extension plug-ins. The specified URL may include: a web browser internal page URL, a binary object uniform resource identifier (i.e., Blob Uri), and a data uniform resource identifier (i.e., Data Uri). The inline frame element is specifically an iframe element. The inline frame element is an element in HTML that is used to embed another HTML page into the current page. In other words, the inline frame element supports embedding a page with another URL address in the current page.

[0080] Among them, the URL of the internal page of the web browser may include a blank page URL (i.e., "about:blank"), etc. The URL of the internal page of the web browser may also include the URL of other internal pages of the web browser that support embedding in an inline frame element, which is not specifically limited here. The binary object uniform resource identifier is a special URL used to represent a large block of binary data (Blob), which is generated on the client side, usually starts with "blob:", and contains a unique identifier for temporarily storing and accessing file data in a web browser, such as images, audio, and PDF files. The data uniform resource identifier is a technology used in web development that allows developers to embed small files (such as images, CSS files, or JavaScript code snippets) directly into HTML, CSS, or JavaScript documents, rather than loading them as external resources through HTTP requests.

[0081] In an embodiment of the present application, the inline frame element in HTML is used to support embedding a page with another URL address within the current page. Furthermore, the context attributes of the inline frame element (e.g., the contentWindow attribute) are used to obtain the window context characteristics to obtain an uncontaminated prototype in an uncontaminated environment from a specified URL. The window context refers to the global environment in which JavaScript code executes in a web browser. Each window object represents an independent JavaScript runtime environment, which determines the access rights to variables, functions, scopes, and APIs.

[0082] Specifically, an inline frame element is created, the source address of the inline frame element is set to a specified URL, and the inline frame element is mounted into the document. The uncontaminated context of the inline frame element is obtained using the context attribute of the inline frame element, and the uncontaminated context is used as the uncontaminated environment to obtain the uncontaminated prototype in the uncontaminated environment. The uncontaminated context refers to a JavaScript execution environment that has not been modified or contaminated, and which retains the original behavior of the JavaScript language and host environment.

[0083] Additionally, you can set the hidden property of the inline frame element, allowing it to be added to the page in a hidden manner, reducing the impact on the user experience and making it invisible to the user. In specific application scenarios, if you need to use it continuously in the window context, you need to keep the inline frame element present; if you only need it temporarily, you can delete it after use.

[0084] In the prototype contamination vulnerability detection solution provided in the embodiment of the present application, a blank page URL (i.e., "about:blank") can be selected as the internal page URL of a web browser that supports use in an inline frame element, and data with a media type (such as a mime type) of an HTML document can be selected as a binary object uniform resource identifier or a data uniform resource identifier. For example, the binary object uniform resource identifier and the data uniform resource identifier can select any data with a mime type of "text / html". Some web browsers also support other types with a "text / " prefix, which are not specifically limited here. The following lists the specific process of obtaining an uncontaminated context from three different specified URLs using an inline frame element and the corresponding sample code.

[0085] (1) Taking the URL of the page inside the web browser as a blank page URL, i.e. "about:blank", as an example, an inline frame element is created to embed another page in the page; then the source address of the inline frame element is set to the blank page URL; by setting the hidden attribute of the inline frame element to hidden, the inline frame element is visually rendered and invisible to the user, thus not affecting the user experience, but still exists in the DOM tree; then the inline frame element is mounted to the document; the context attribute (contentWindow attribute) of the inline frame element points to the global window object of the page inside the web browser, and the unpolluted context can be obtained by using the contentWindow attribute of the inline frame element, and the unpolluted context is stored in the clearWindow variable.

[0086] The sample code corresponding to the above content can be:

[0087] var iframe=document.createElement("iframe");

[0088] iframe.src="about:blank";

[0089] iframe.hidden = true;

[0090] document.body.appendChild(iframe);

[0091] var clearWindow=iframe.contentWindow;

[0092] (2) Taking the data uniform resource identifier "data:text / html," as an example, an inline frame element is created to embed another page in the page; then the source address of the inline frame element is set to "data:text / html," where the HTML content is an empty string, which is equivalent to a blank page; by setting the hidden attribute of the inline frame element to hidden, the inline frame element is visually rendered and invisible to the user, but still exists in the DOM tree; then the inline frame element is mounted to the document; the contentWindow attribute of the inline frame element points to the global window object of the page corresponding to the data uniform resource identifier, and the uncontaminated context can be obtained by using the contentWindow attribute of the inline frame element, and the uncontaminated context is stored in the clearWindow variable.

[0093] The sample code corresponding to the above content can be:

[0094] var iframe=document.createElement("iframe");

[0095] iframe.src="data:text / html,";

[0096] iframe.hidden = true;

[0097] document.body.appendChild(iframe);

[0098] var clearWindow=iframe.contentWindow;

[0099] (3) Taking a binary object uniform resource identifier with a mime type of "text / html" and empty data content as an example, an inline frame element is created to embed another page in a page; an empty Blob object is constructed and its mime type is set to "text / html" so that it can be processed as an HTML document; then the empty Blob object is converted into a URL and set as the source address of the inline frame element, wherein even if the Blob object is empty, a valid URL can still be generated; by setting the hidden attribute of the inline frame element to hidden, the inline frame element is visually rendered and invisible to the user, but still exists in the DOM tree; then the inline frame element is mounted to the document; the contentWindow attribute of the inline frame element points to the global window object of the page corresponding to the binary object uniform resource identifier, and the uncontaminated context can be obtained by using the contentWindow attribute of the inline frame element, and the uncontaminated context is stored in the clearWindow variable.

[0100] The sample code corresponding to the above content can be:

[0101] var iframe=document.createElement("iframe");

[0102] const blobType={

[0103] "type":"text / html"

[0104] };

[0105] const blob=new Blob([],blobType);

[0106] iframe.src=URL.createObjectURL(blob);

[0107] iframe.hidden = true;

[0108] document.body.appendChild(iframe);

[0109] var clearWindow=iframe.contentWindow;

[0110] In another optional implementation, a worker thread independent of the main thread can be used to obtain an uncontaminated prototype in an uncontaminated environment. Web Worker is a JavaScript multi-threaded solution in HTML. It can hand over computationally intensive code to the Worker thread without blocking the user's main thread. The main thread and the Worker thread can exchange data through an interface. The Worker thread is part of the Web Worker technology. It is a thread that runs in the background independent of the main thread. The Worker thread runs in an independent global environment, isolated from the main thread, and usually has its own global context. Use the Worker thread to obtain the uncontaminated context, use the uncontaminated context as the uncontaminated environment, and obtain the uncontaminated prototype in the uncontaminated environment.

[0111] In step S203, the current prototype is compared with the uncontaminated prototype to determine whether the current prototype is consistent with the uncontaminated prototype; if so, step S204 is executed; if not, step S205 is executed.

[0112] Whether the current prototype is contaminated can be determined by comparing the current prototype in the current operating environment (window) with the uncontaminated prototype in the uncontaminated environment (clearWindow). Specifically, the web browser can compare the current prototype with the uncontaminated prototype to determine whether the current prototype is consistent with the uncontaminated prototype; if consistent, a first comparison result indicating consistency can be output, and then step S204 is executed. For example, the first comparison result can include an identifier 1 for indicating consistency; if inconsistent, a second comparison result indicating inconsistency can be output, and then step S205 is executed. For example, the second comparison result can include an identifier 0 for indicating inconsistency. The second comparison result can further include the differences between the current prototype and the uncontaminated prototype, so as to determine which content in the current prototype has been modified, which content has been deleted, or even which content has been completely destroyed.

[0113] Step S204: determine that the current prototype is not contaminated.

[0114] If it is determined in step S203 that the current prototype is consistent with the uncontaminated prototype, it is determined that the current prototype is not contaminated, indicating that there is no need to restore the prototype, and the method ends.

[0115] Step S205 , determining whether the current prototype is contaminated, and replacing the current prototype with an uncontaminated prototype to restore all or part of the original prototype function.

[0116] If the current prototype is inconsistent with the uncontaminated prototype as determined in step S203, the current prototype is determined to be contaminated, indicating that prototype restoration is necessary. The current prototype is then replaced with the uncontaminated prototype to restore all or part of the original prototype's functionality. Specifically, if the original prototype's functionality does not include the specified functionality, replacing the current prototype with the uncontaminated prototype can restore all of the original prototype's functionality. If the original prototype's functionality includes the specified functionality, replacing the current prototype with the uncontaminated prototype can restore all of the original prototype's functionality except for the specified functionality.

[0117] The following describes the prototype contamination vulnerability detection solution provided by the embodiments of the present application using multiple specific application scenarios.

[0118] Application Scenario 1: WebRTC (Web Real-Time Communication) is a technology that enables real-time audio and video calls on web pages. It enables direct communication between users without going through the server, resulting in low-latency audio and video calls. However, some unscrupulous vendors use this technology to circumvent privacy protections and collect user IP addresses. As a result, some privacy protection plugins prevent privacy leaks by directly removing WebRTC functionality globally, a form of prototype pollution. This can cause websites that rely on WebRTC for their primary functionality, such as online conferencing sites, cloud gaming sites, and audio and video call sites, to become completely inoperable.

[0119] For this application scenario, the current prototype in the current running environment can be compared with the uncontaminated prototype in an uncontaminated environment to detect whether the current prototype is contaminated. For example, if the code "delete window.RTCPeerConnection;" is used in the current running environment to delete the WebRTC functionality in the current prototype, the uncontaminated prototype can be used to replace the current prototype to restore the WebRTC functionality in the current running environment. For example, the code "window.RTCPeerConnection = clearWindow.RTCPeerConnection;" can be used to restore the WebRTC functionality in the current running environment using the uncontaminated environment.

[0120] Application scenario two: There are advertisements on the interface of a certain website, and the advertisements are added to the interface through the "Create Interface Element API" (i.e., createElement). The ad blocking plug-in can replace "createElement" with an API that looks like "createElement", so that it can monitor the addition of all elements on the interface. If an element that may be an advertisement is found to be ready to be added, it will be blocked. In this application scenario, the role of the ad blocking plug-in is to "block advertisements", and the implementation method is a kind of prototype pollution. This pollution method affects the execution of all logic that needs to add interface elements, so it may cause several situations: when the replaced "createElement" does not implement all the original functions, an error may be reported when it is called; content that is not an advertisement may also be mistakenly judged as an advertisement. For example, when a user fills out a form, the submit button is judged as an advertisement, which affects the user's normal use of the website functions.

[0121] For this application scenario, the current prototype in the current running environment can be compared with the uncontaminated prototype in the uncontaminated environment to detect whether the current prototype is contaminated. For example, if the "createElement" API in the current running environment is found to have been replaced, the current prototype can be replaced with the uncontaminated prototype to restore the original "createElement" API functionality in the current running environment.

[0122] Application scenario three: Some browser extensions contain Trojan backdoors and may provide other functions as disguises, such as ad blocking or website sign-in functions. They can replace the website's text input or network request functions through prototype pollution, thereby monitoring or stealing users' personal information without their knowledge, which poses a huge security risk.

[0123] For this application scenario, the current prototype in the current running environment can be compared with the uncontaminated prototype in an uncontaminated environment to detect whether the current prototype is contaminated. For example, if the text input function and network request function in the current running environment are found to have been replaced, the uncontaminated prototype can be used to replace the current prototype to restore the text input and network request functions in the current running environment, effectively preventing the user's personal information from being monitored or stolen.

[0124] According to the prototype contamination vulnerability detection method provided by the embodiment of the present application, the characteristic of the web browser that it will exclude browser extension plug-ins for certain environments such as specified URLs and working threads is utilized to conveniently obtain the uncontaminated prototype in the uncontaminated environment, thereby overcoming the defect in the prior art that there is no uncontaminated prototype for reference and thus it is not possible to accurately detect whether the current prototype is contaminated; by comparing the current prototype with the uncontaminated prototype, it is determined whether the current prototype is prototype contaminated by judging whether the current prototype is consistent with the uncontaminated prototype; this scheme uses the uncontaminated prototype as a reference for prototype contamination vulnerability detection, thereby achieving accurate detection of prototype contamination vulnerabilities and effectively improving detection accuracy. , and effectively reduces the detection cost and reduces the impact on user experience; moreover, the solution can completely perform prototype pollution vulnerability detection locally, without relying on the network to enable interactive verification between the client and the server, overcoming the defect that local prototype pollution in the existing technology cannot be detected locally, and greatly improving reliability; in addition, when the current prototype is detected to be contaminated, the current prototype can be replaced with an uncontaminated prototype, thereby conveniently restoring part or all of the functions deleted or modified by the prototype pollution, realizing prototype recovery, and solving the problem that the existing technology cannot fundamentally solve the prototype pollution even if the prototype pollution is detected.

[0125] Figure 3 FIG. 1 shows a structural block diagram of a prototype contamination vulnerability detection device according to an embodiment of the present application. Figure 3 As shown, the device includes: an acquisition module 310, a detection module 320 and a recovery module 330.

[0126] The acquisition module 310 is adapted to: acquire the current prototype in the current operating environment, and acquire the uncontaminated prototype in the uncontaminated environment.

[0127] The detection module 320 is adapted to detect whether the current prototype is contaminated based on the uncontaminated prototype.

[0128] The restoration module 330 is adapted to: if the current prototype is contaminated, replace the current prototype with an uncontaminated prototype to restore all or part of the original prototype functions.

[0129] Furthermore, the acquisition module 310 is further adapted to: acquire the uncontaminated prototype in the uncontaminated environment from the specified URL using an inline frame element; or acquire the uncontaminated prototype in the uncontaminated environment using a working thread independent of the main thread.

[0130] Furthermore, the acquisition module 310 is further adapted to: create an inline frame element, set the source address of the inline frame element to a specified URL, and mount the inline frame element into a document; utilize the context attribute of the inline frame element to obtain an uncontaminated context of the inline frame element, use the uncontaminated context as an uncontaminated environment, and obtain an uncontaminated prototype in the uncontaminated environment.

[0131] Furthermore, the acquisition module 310 is further adapted to set a hidden attribute of the inline frame element.

[0132] Furthermore, the designated URL includes: a web browser internal page URL, a binary object uniform resource identifier, and a data uniform resource identifier.

[0133] Furthermore, the acquisition module 310 is further adapted to: select data whose media type is an HTML document as a binary object uniform resource identifier or a data uniform resource identifier.

[0134] Furthermore, the detection module 320 is further adapted to: compare the current prototype with the uncontaminated prototype to determine whether the current prototype is consistent with the uncontaminated prototype; if consistent, determine that the current prototype is not contaminated; if inconsistent, determine that the current prototype is contaminated.

[0135] The description of each module above refers to the corresponding description in the method embodiment and will not be repeated here.

[0136] According to the prototype contamination vulnerability detection device provided by the embodiment of the present application, the characteristic of the web browser that it will exclude browser extension plug-ins for certain environments such as specified URLs and working threads is utilized to conveniently obtain the uncontaminated prototype in the uncontaminated environment, thereby overcoming the defect in the prior art that there is no uncontaminated prototype for reference and thus it is not possible to accurately detect whether the current prototype is contaminated; by comparing the current prototype with the uncontaminated prototype, it is determined whether the current prototype is prototype contaminated by judging whether the current prototype is consistent with the uncontaminated prototype; this scheme uses the uncontaminated prototype as a reference to perform prototype contamination vulnerability detection, thereby achieving accurate detection of prototype contamination vulnerabilities and effectively improving detection accuracy. , and effectively reduces the detection cost and reduces the impact on user experience; moreover, the solution can completely perform prototype pollution vulnerability detection locally, without relying on the network to enable interactive verification between the client and the server, overcoming the defect that local prototype pollution in the existing technology cannot be detected locally, and greatly improving reliability; in addition, when the current prototype is detected to be contaminated, the current prototype can be replaced with an uncontaminated prototype, thereby conveniently restoring part or all of the functions deleted or modified by the prototype pollution, realizing prototype recovery, and solving the problem that the existing technology cannot fundamentally solve the prototype pollution even if the prototype pollution is detected.

[0137] An embodiment of the present application provides a non-volatile computer storage medium, which stores at least one executable instruction or computer program, which can enable a processor to perform operations corresponding to the prototype contamination vulnerability detection method in any of the above method embodiments.

[0138] An embodiment of the present application provides a computer program product, which includes at least one executable instruction or computer program, and the executable instruction or computer program can enable a processor to perform operations corresponding to the prototype contamination vulnerability detection method in any of the above method embodiments.

[0139] Figure 4 A schematic structural diagram of a computing device according to an embodiment of the present application is shown. The specific embodiment of the present application does not limit the specific implementation of the computing device.

[0140] like Figure 4 As shown, the computing device may include: a processor 402 , a communications interface 404 , a memory 406 , and a communication bus 408 .

[0141] Processor 402, communication interface 404, and memory 406 communicate with each other via communication bus 408. Communication interface 404 is used to communicate with other devices, such as clients or other server network elements. Processor 402 is used to execute program 410, which may specifically perform the steps described in the aforementioned embodiment of the prototype contamination vulnerability detection method for a computing device.

[0142] Specifically, the program 410 may include program codes, which include computer operation instructions.

[0143] Processor 402 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application. The one or more processors included in the computing device may be processors of the same type, such as one or more CPUs, or may be processors of different types, such as one or more CPUs and one or more ASICs.

[0144] The memory 406 is used to store the program 410. The memory 406 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0145] Program 410 can be specifically configured to cause processor 402 to execute the prototype contamination vulnerability detection method described in any of the aforementioned method embodiments. The specific implementation of each step in program 410 can be found in the corresponding descriptions of the corresponding steps and units in the aforementioned prototype contamination vulnerability detection embodiments and will not be repeated here. Those skilled in the art will clearly understand that, for ease and brevity of description, the specific operating processes of the devices and modules described above can refer to the corresponding process descriptions in the aforementioned method embodiments and will not be repeated here.

[0146] The algorithm and display provided herein are not inherently relevant to any particular computer, virtual system or other device. Various general-purpose systems can also be used together with the teachings based on this. According to the above description, it is obvious that the structure required for constructing this type of system. In addition, the embodiments of the present application are not directed to any specific programming language yet. It should be understood that various programming languages ​​can be utilized to realize the content of the embodiments of the present application described herein, and the description of the specific languages ​​above is for the purpose of disclosing the best mode of implementation of the embodiments of the present application.

[0147] In the description provided herein, a large number of specific details are described. However, it is understood that the embodiments of the present application can be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.

[0148] Similarly, it should be understood that in order to streamline the present disclosure and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the present application, the various features of the embodiments of the present application are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting the following intention: that the claimed embodiments of the present application require more features than the features explicitly recited in each claim. More precisely, as reflected in the claims below, inventive aspects lie in less than all the features of the individual embodiments disclosed above. Therefore, the claims following the detailed description are hereby expressly incorporated into the detailed description, with each claim itself serving as a separate embodiment of the embodiments of the present application.

[0149] Those skilled in the art will appreciate that the modules in the devices in the embodiments may be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments may be combined into one module or unit or component, and in addition may be divided into multiple submodules or subunits or subcomponents. All features disclosed in this specification (including the accompanying claims, abstracts and drawings) and all processes or units of any method or device disclosed herein may be combined in any combination, except that at least some of such features and / or processes or units are mutually exclusive. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstracts and drawings) may be replaced by an alternative feature providing the same, equivalent or similar purpose.

[0150] Furthermore, those skilled in the art will appreciate that although some embodiments described herein include certain features that are included in other embodiments but not other features, combinations of features from different embodiments are intended to be within the scope of the present invention and to form different embodiments. For example, in the claims below, any of the claimed embodiments may be used in any combination.

[0151] The various component embodiments of the embodiments of the present application can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. It should be understood by those skilled in the art that a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the embodiments of the present application. The embodiments of the present application can also be implemented as a device or apparatus program (e.g., computer program and computer program product) for performing a part or all of the methods described herein. Such a program implementing the embodiments of the present application can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0152] It should be noted that the above embodiments illustrate rather than limit the embodiments of the present application, and that a person skilled in the art may devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference symbols placed between brackets should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The embodiments of the present application may be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not indicate any order. These words may be interpreted as names.

Claims

1. A prototype contamination vulnerability detection method, comprising: Get the current prototype in the current running environment and get the uncontaminated prototype in the uncontaminated environment; Detecting whether the current prototype is contaminated based on the uncontaminated prototype; If the current prototype is contaminated, the uncontaminated prototype is used to replace the current prototype to restore all or part of the original prototype function.

2. The method according to claim 1, wherein obtaining an uncontaminated prototype in an uncontaminated environment further comprises: Using the inline frame element, obtain the uncontaminated prototype in the uncontaminated environment from the specified URL; Alternatively, use a worker thread independent of the main thread to obtain an uncontaminated prototype in an uncontaminated environment.

3. The method according to claim 2, wherein the step of obtaining the uncontaminated prototype in the uncontaminated environment from the specified URL using an inline frame element further comprises: Creating the inline frame element, setting the source address of the inline frame element to the specified URL, and mounting the inline frame element into the document; The uncontaminated context of the inline frame element is obtained by using the context attribute of the inline frame element, the uncontaminated context is used as an uncontaminated environment, and an uncontaminated prototype in the uncontaminated environment is obtained.

4. The method according to claim 3, further comprising: The hidden attribute of the inline frame element is set.

5. The method according to any one of claims 2 to 4, wherein the specified URL comprises: Web browser internal page URL, binary object uniform resource identifier and data uniform resource identifier.

6. The method according to claim 5, further comprising: Data with a media type of HTML document is selected as a binary object uniform resource identifier or a data uniform resource identifier.

7. The method according to any one of claims 1 to 6, wherein detecting whether the current prototype is contaminated based on the uncontaminated prototype further comprises: Comparing the current prototype with the uncontaminated prototype to determine whether the current prototype is consistent with the uncontaminated prototype; If they are consistent, it is determined that the current prototype is not contaminated; If they are inconsistent, it is determined that the current prototype is contaminated.

8. A prototype contamination vulnerability detection device, comprising: An acquisition module adapted to acquire the current prototype in the current operating environment and to acquire the uncontaminated prototype in the uncontaminated environment; a detection module, adapted to detect whether the current prototype is contaminated based on the uncontaminated prototype; The recovery module is adapted to replace the current prototype with the uncontaminated prototype if the current prototype is contaminated, so as to recover all or part of the original prototype function.

9. A computing device comprising: A processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute an operation corresponding to the prototype contamination vulnerability detection method according to any one of claims 1 to 7.

10. A computer storage medium, wherein at least one executable instruction is stored in the storage medium, wherein the executable instruction enables a processor to execute operations corresponding to the prototype contamination vulnerability detection method according to any one of claims 1 to 7.

11. A computer program product, comprising at least one executable instruction, wherein the executable instruction enables a processor to execute operations corresponding to the prototype contamination vulnerability detection method according to any one of claims 1 to 7.

Citation Information

Cited By

  • An automated vulnerability mining method for potential configuration attributes of internet of things devices

    CN122457374A