Detection method, device, equipment and product
By starting the security plug-in in the Tomcat middleware container and using the Hook instrumentation method to monitor and intercept memory horse injection behavior, the problem of insufficient real-time performance of memory horse detection and defense technology in the existing technology is solved, and real-time defense against memory horse attacks is achieved.
Patent Information
- Application Number
- CN202510929861.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-10-17
AI Technical Summary
Existing memory horse detection and defense technologies mainly focus on post-detection analysis, and lack real-time detection, defense, and interception capabilities, making them unable to effectively defend against fileless advanced attacks.
By starting the security plug-in in the Tomcat middleware container, the Hook plug-in method is used to monitor multiple plug-in monitoring points, load new components, determine whether it is a memory horse injection behavior based on the component information, and perform real-time interception processing.
It realizes real-time detection and defense against memory horse attacks, improves defense capabilities, and enhances the real-time and effectiveness of security defense.
Smart Images

Figure CN120805124A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of container security, in particular to a detection method, device, equipment and product. BACKGROUND
[0002] In the field of Java Web application security, attackers can implant malicious code in the memory of the application program through fileless advanced attack technology to achieve attacks without leaving any traces on the disk. This attack method makes the traditional file-based detection method invalid, so detecting and defending against memory horses has become a challenge. Tomcat middleware is a free and open source Web application server that supports the operation of Java program application Web services. It has become the target of fileless attacks by memory horses.
[0003] Existing memory horse detection and defense technology solutions usually include memory forensics analysis, static bytecode analysis, dynamic link process analysis, and other methods. All of these methods focus on post-detection analysis of memory horses and lack real-time detection, defense, and interception capabilities. SUMMARY
[0004] The purpose of the present application is to provide a detection method, device, equipment and product to solve the problem of insufficient real-time detection, defense and interception capabilities of existing memory horse detection and defense technology.
[0005] To achieve the above purpose, an embodiment of the present application provides a detection method, which includes:
[0006] During the operation of the business system, a security plug-in is started through the Tomcat middleware container;
[0007] The security plug-in uses a Hook plug-in method to monitor a plurality of plug-in monitoring points. When a business request is detected, a new component is loaded based on the plug-in monitoring points;
[0008] According to the component information of the new component, it is determined whether the new component is generated by memory horse injection behavior, and an analysis result is obtained;
[0009] According to the analysis result, it is determined whether to intercept and process the new component.
[0010] Optionally, the method, wherein the security plug-in uses a Hook plug-in method to monitor a plurality of plug-in monitoring points, includes:
[0011] The security plug-in obtains the context information of the first component in the Tomcat middleware container; wherein the first component is a suspicious component injected by the memory horse in the container;
[0012] acquire type information of the first component, class information of a suspicious class injected by the memory hook in the first component, and function information of a suspicious function injected by the memory hook in the first component according to the context information;
[0013] monitor the instrumentation monitoring point in a Hook instrumentation mode according to the type information, the class information, and the function information.
[0014] Optionally, the method, wherein the component information comprises one or more of:
[0015] a component type;
[0016] a package name;
[0017] a class feature;
[0018] a parent class feature;
[0019] a business function memory.
[0020] Optionally, the method, wherein the judgment of whether the new component is generated by the memory hook injection behavior according to the component information of the new component comprises:
[0021] judging whether the new component is a component allowed to be added in a system built-in library according to the component type to acquire a first judgment result; wherein the system built-in library is a set comprising components allowed to be added in the container;
[0022] in a case where the first judgment result is yes, judging whether the new component belongs to white list information according to the package name and the class feature of the new component to acquire a second judgment result; wherein the white list information is a set of package names and class features allowed to be added in a business system in advance;
[0023] in a case where the second judgment result is yes, judging whether the parent class feature and the business function memory of the new component do not exist high-risk characters to acquire a third judgment result; wherein the high-risk characters are characters that may appear in the container due to the memory hook injection;
[0024] in a case where the third judgment result is yes, determining that the analysis result is a non-memory hook injection behavior.
[0025] Optionally, the method further comprises:
[0026] in a case where any one of the first judgment result, the second judgment result, and the third judgment result is no, acquiring the analysis result as a memory hook injection behavior.
[0027] Optionally, in the case where the analysis result is the memory horse injection behavior, the method further includes determining, according to the analysis result, whether to perform interception processing on the new component.
[0028] determining a memory flag MemFlag parameter according to the memory horse injection behavior; the MemFlag parameter is a plurality of parameter values corresponding to a plurality of memory horse injection behaviors according to a preset;
[0029] in the case where the MemFlag parameter is a first preset value, performing interception and warning on the new component;
[0030] in the case where the MemFlag parameter is a second preset value, performing warning on the new component.
[0031] Optionally, in the case where the analysis result is the non-memory horse injection behavior, the method further includes determining, according to the analysis result, whether to perform interception processing on the new component.
[0032] acquiring the MemFlag parameter as a third preset value according to the non-memory horse injection behavior, and normally responding to the business request.
[0033] To achieve the above purpose, an embodiment of the present application provides a detection device, which comprises:
[0034] a first processing module configured to start a security plug-in through a Tomcat middleware container when a business system is running;
[0035] a second processing module configured to monitor a plurality of plug-in monitoring points by using a Hook plug-in method through the security plug-in, and load a new component based on the plug-in monitoring points when a business request is monitored;
[0036] a first obtaining module configured to determine whether the new component is generated by a memory horse injection behavior according to component information of the new component, and obtain an analysis result; the component information is information that can determine whether the new component is generated by the memory horse injection behavior;
[0037] a first determining module configured to determine whether to perform interception processing on the new component according to the analysis result.
[0038] To achieve the above purpose, an embodiment of the present application provides a detection device, which comprises a transceiver, a processor, a memory, and a program or instruction stored in the memory and executable on the processor; when the processor executes the program or instruction, the detection method described above is realized.
[0039] To achieve the above object, the embodiment of the present application provides a readable storage medium, which stores programs or instructions, wherein the programs or instructions are executed by a processor to realize the steps of the detection method.
[0040] To achieve the above object, the embodiment of the present application provides a computer program product, which comprises computer instructions, wherein the computer instructions are executed by a processor to realize the steps of the detection method.
[0041] The beneficial effects of the above technical solutions of the present application are as follows:
[0042] The embodiment of the present application adopts the Hook plugging method to monitor a plurality of plugging monitoring points through the security plug-in started by the Tomcat middleware container in the running of the business system, so that the memory horse injection behavior can be detected in real time, in the case of monitoring the business request, the newly added component is loaded based on the plugging monitoring point, whether the memory horse injection behavior is generated is judged according to the component information of the newly added component, and whether the newly added component is intercepted is determined according to the analysis result, so that the defense ability of the memory horse attack behavior is improved, and the security defense is left. BRIEF DESCRIPTION OF DRAWINGS
[0043] Figure 1 A schematic diagram of the detection method described in the embodiment of the present application is shown in the figure.
[0044] Figure 2 One of the flowcharts of the detection method described in the embodiment of the present application is shown in the figure.
[0045] Figure 3 The second flowchart of the detection method described in the embodiment of the present application is shown in the figure.
[0046] Figure 4 A schematic diagram of the detection device described in the embodiment of the present application is shown in the figure. DETAILED DESCRIPTION
[0047] To make the technical problems, technical solutions and advantages of the present application clearer, the following will be described in detail with reference to the drawings and specific embodiments.
[0048] It should be understood that the "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily mean the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner.
[0049] In various embodiments of the present application, it should be understood that the size of the serial number of the following processes does not mean the order of execution, the execution order of the processes should be determined according to its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0050] In addition, the terms "system" and "network" are often used interchangeably herein.
[0051] In the embodiments provided by the present application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that the determination of B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0052] For the convenience of understanding, some of the contents related to the embodiments of the present application are described as follows:
[0053] As shown in Figure 1 , a detection method of an embodiment of the present application, comprising:
[0054] S10, starting the security plug-in through the Tomcat middleware container when the business system runs;
[0055] It should be noted that, as Figure 2As shown, in step S10, step S1 is to load the memshell_rasp_tool.jar security plug-in in the Tomcat middleware, configure and initialize the memory horse injection attack monitoring and defense security plug-in program, and load and start the memshell_rasp_tool.jar security plug-in in the Tomcat middleware based on the Java Instrumentation (instrumentation) mechanism. In step S1.1, based on the Linux environment Tomcat configuration file bin / catalina.sh loading start parameter, the environment file configuration is performed: the security plug-in runs in the Linux operating system environment, and the Tomcat middleware container configuration file bin / catalina.sh is edited and configured. In step S1.2, the start parameter export CATALINA_OPTS="$CATALINA_OPTS-javaagent: / installation directory / memshell_rasp_tool.jar" is added, and the security plug-in start parameter is configured: the security plug-in is loaded when the Tomcat middleware starts through the Agent, and the initialization start running of the security plug-in is realized by adding the parameter export CATALINA_OPTS="$CATALINA_OPTS-javaagent: / installation directory / memshell_rasp_tool.jar". In step S1.3, the middleware is started through the script command nohup. / startup.sh&, and the middleware start script is configured: the Tomcat middleware container starts through the Shell script command, and the nohup. / startup.sh& command is used to realize the start running script of the security plug-in loaded by the Tomcat middleware. In step S1.4, the startup success is checked by checking the logs / catalina.out middleware log file, and the plug-in running state is confirmed: the detailed standard log output of the security plug-in of the memshell_rasp_tool.jar is output to the memshell.log file, and the "memory horse security plug-in startup success information" is printed in the log file after startup.
[0056] S20, the security plug-in is used to monitor a plurality of instrumented monitoring points by using a Hook instrumenting method, and in the case that a business request is acquired, a new component is loaded based on the instrumented monitoring points;
[0057] It should be noted that the functions of the Tomcat middleware that may be attacked and injected with memory horses are monitored by the Hook instrumenting method, the functions that may be maliciously used are comprehensively monitored, and the defense capability against the memory horse injection attack behavior of the Tomcat middleware is realized. For example Figure 2As shown, the attacker generally builds a malicious memory horse component program, builds a memory horse attack user request service through a business application system related deserialization vulnerability, file upload vulnerability, RCE vulnerability and other exploitable vulnerabilities, and forms a memory horse fileless attack injection behavior to the business system. Figure 2 In step S2 of step S20, the memory horse attack injection point function is hooked, in step S2.1, the context information of the HTTP request is obtained, and the context information is obtained: the attacker attempts memory horse injection through the request mode of the HTTP / HTTPS protocol, and obtains the context object through Java reflection technology: component type, package path information, class name information, parent class information, interface information, etc. The component type that may occur memory horse injection behavior is referred to as injection type, the class that may occur memory horse injection behavior is referred to as injection class, and the function that may occur memory horse injection behavior is referred to as injection function. Hooking is performed in the injection type, injection class and injection function, so as to monitor a plurality of said hooking monitoring points, and a memory horse defense system map is constructed. As shown in Figure 3 As shown in step S3, in step S3.1 (i.e. step S20), the new component method is triggered, the business request reflection information context object is obtained, the new component loaded based on the hooking monitoring point (Hook function) is triggered, therefore, if the component type of the new component belongs to the injection type, or the type of the class in the new component is input into the injection class, or the type of the function in the new component belongs to the injection function, the hooking monitoring point of the corresponding function, class and component is set. Hooking is a technical means of inserting custom code dynamically at runtime to achieve monitoring, modification or enhancement of original functions by hijacking target function call chains.
[0058] S30, according to the component information of the new component, judging whether the new component is generated by the memory horse injection behavior, obtaining the analysis result;
[0059] It should be noted that, as shown in Figure 3 In step S3.2 of step S3, the new component type is researched and judged, in step S3.3 (judgment) the dynamic component new type compliance is judged, and then in step S3.4 the memory horse injection behavior analysis result is encapsulated, that is, according to the component information of the new component, judging whether the new component is generated by the memory horse injection behavior, obtaining the analysis result.
[0060] S40, according to the analysis result, determining whether to intercept the new component;
[0061] It should be noted that, as shown in Figure 3As shown, in step S40 of handling the alarm in step S4, (judgment) whether it is a memory horse attack, based on the analysis result of the encapsulated memory horse injection behavior, it is determined whether to intercept the newly added component.
[0062] In this embodiment, when the business system is running, the security plug-in started by the Tomcat middleware container adopts the Hook plug-in method to monitor multiple plug-in monitoring points. When a business request is detected, a new component is loaded based on the plug-in monitoring point, and the component information of the new component is used to determine whether it is caused by memory horse injection behavior. Based on the obtained analysis results, it is determined whether the new component is intercepted and processed, thereby enabling real-time detection and defense of memory horse injection behavior, improving the defense capability of memory horse attack behavior, and shifting security defense to the left.
[0063] Optionally, in the method, step S20 includes:
[0064] Obtaining context information of a first component in the Tomcat middleware container through the security plug-in; wherein the first component is a suspicious component injected into the container by a memory horse;
[0065] Acquire, based on the context information, type information of the first component, class information of the suspicious class injected by the memory hacker in the first component, and function information of the suspicious function injected by the memory hacker in the first component;
[0066] The plug-in monitoring point is monitored using a Hook plug-in method according to the type information, the class information and the function information.
[0067] In this embodiment, Figure 2 As shown, in step S2.2, when the type information of the first component is an injection type, the first component is instrumented using the Hook instrumentation method to form the instrumentation monitoring point. The injection type includes one or more of the following: Listener type; Servlet type; Filter type; Value type; Upgrade type; Executor type.
[0068] In step S2.3, the Hook class, in the case of suspicious class information of the first component being an injection class, uses the Hook instrumentation method to instrumentally monitor the first component, forming the instrumentation monitoring point. The injection class includes one or more of the following: a standard context StandardContext class; a standard pipeline StandardPipeline class; a buffer endpoint NioEndpoint class; and a generic abstract AbstractHttp11Protocol class.
[0069] In step S2.4, the Hook function, in the case of suspicious function information of the first component being an injection function, uses the Hook instrumentation method to instrumentally monitor the first component, forming the instrumentation monitoring point. The injection function includes one or more of the following: Servlet types including one or more of the following: an add service program mapping addServletMapping function, a decoded service program mapping addition addServletMappingDecoded function, and an add child function addChild function; Filter types include an add filter definition addFilterDef function; Listener types include a dynamic registration listener addApplicationEventListener function; Upgrade types include a get upgrade protocol getUpgradeProtocol function; Executor types include a set executor setExecutor function; and Valve types include an add valve addValve function.
[0070] Optionally, the method, wherein the component information includes one or more of the following:
[0071] a component type;
[0072] a package name;
[0073] a class feature;
[0074] a parent class feature;
[0075] a business function memory.
[0076] In this embodiment, the newly added component is analyzed according to the component type, package name, class feature, parent class feature, and business function memory of the newly added component, and it is determined whether the newly added component is generated by a memory horse injection behavior.
[0077] Optionally, the method, wherein the step S30 includes:
[0078] According to the component type, it is judged whether the added component is a component allowed to be added in a system built-in library, and a first judgment result is obtained; the system built-in library is a set of components allowed to be added in the container;
[0079] In a case where the first judgment result is yes, it is judged according to the package name and the class feature of the added component whether it belongs to white list information, and a second judgment result is obtained; the white list information is a set of package names and class features of business systems allowed to be added and pre-set;
[0080] In a case where the second judgment result is yes, it is judged whether the parent class feature of the added component and the business function memory are free of high-risk characters, and a third judgment result is obtained; the high-risk characters are characters that may appear due to memory horse injection on the container;
[0081] In a case where the third judgment result is yes, it is determined that the analysis result is a non-memory horse injection behavior.
[0082] In this embodiment, as shown in Figure 3 In step S3.3, (judgment) of dynamic component addition type compliance, in the method body of the added component triggered by the business request entering the Hook function monitoring point, static JSON data of a white list knowledge base corresponding to the component type and static JSON data of a component type malicious feature knowledge base are obtained. All parameter contents required by the judgment logic are packaged. It is judged whether the component type can add the plug-in monitoring point component in the Tomcat middleware based on the system built-in library, and the first judgment result is obtained. In a case where the first judgment result is yes, that is, it is judged that the component type can be dynamically added, then secondary judgment and analysis are performed, and it is judged whether the component package name and the class feature belong to the business system white list information, as shown in Figure 3 In a case where the judgment is yes, business white list package name and class feature analysis are performed, and the second judgment result is obtained. In a case where the second judgment result is yes, it is judged that the white list information is entered into tertiary judgment and analysis, and it is analyzed whether the parent class feature of the added component and the business function memory have high-risk characters, as shown in Figure 3 Malicious feature analysis is performed, and it is judged whether the added component has malicious features, and the third judgment result is obtained. In a case where the third judgment result is yes, it is determined that the analysis result is a non-memory horse injection behavior, and in step S3.4, the memory horse injection behavior analysis result is packaged.
[0083] Optionally, the method further comprises:
[0084] In a case where any one of the first determination result, the second determination result, and the third determination result is no, the analysis result is determined as a memory horse injection behavior.
[0085] In the embodiment, in a case where any one of the first determination result, the second determination result, and the third determination result is no, the memory horse injection behavior is determined.
[0086] Optionally, the method, wherein in a case where the analysis result is the memory horse injection behavior, the step S40 comprises:
[0087] determining a memory flag MemFlag parameter according to the memory horse injection behavior; wherein the MemFlag parameter is a plurality of preset parameter values corresponding to a plurality of memory horse injection behaviors;
[0088] in a case where the MemFlag parameter is a first preset value, intercepting and warning the new component;
[0089] in a case where the MemFlag parameter is a second preset value, warning the new component.
[0090] In the embodiment, the response identifier MemFlag parameter is encapsulated for the memory horse attack behavior, the parameter is 1 (i.e. the first preset value) to intercept and warn, the parameter 2 (i.e. the second preset value) to only warn; the MemFlag parameter is obtained based on the encapsulation of the memory horse injection behavior analysis result identifier parameter to form a disposal warning, whether it is the memory horse injection attack behavior is determined, the injection behavior is determined whether to warn or warn and intercept based on the parameter, the alarm log is generated and then normally responded.
[0091] Optionally, the method, wherein in a case where the analysis result is a non-memory horse injection behavior, the step S40 comprises:
[0092] obtaining the MemFlag parameter as a third preset value according to the non-memory horse injection behavior, and normally responding to the business request.
[0093] In the embodiment, the non-memory horse attack behavior parameter is 3 (i.e. the third preset value) in the analysis result, and the business request is normally responded in a case where the MemFlag parameter is the third preset value and the non-injection behavior is determined.
[0094] As Figure 4 shown, to achieve the above purpose, an embodiment of the present application provides a detection device, which comprises:
[0095] The first processing module 401 is configured to start a security plug-in through a Tomcat middleware container when a business system is running.
[0096] The second processing module 402 is configured to monitor a plurality of hooking monitoring points by using a hooking method, and load a new component based on the hooking monitoring points when a service request is acquired.
[0097] The first obtaining module 403 is configured to determine whether the new component is generated by a memory horse injection behavior according to component information of the new component, and obtain an analysis result; wherein the component information is information that can determine whether the new component is generated by the memory horse injection behavior.
[0098] The first determining module 404 is configured to determine whether to perform interception processing on the new component according to the analysis result.
[0099] Optionally, the apparatus, wherein the second processing module 402 comprises:
[0100] The first obtaining unit is configured to obtain context information of a first component in the Tomcat middleware container by using the security plug-in; wherein the first component is a suspicious component injected by a memory horse in the container.
[0101] The second obtaining unit is configured to obtain type information of the first component, class information of a suspicious class injected by a memory horse in the first component, and function information of a suspicious function injected by a memory horse in the first component according to the context information.
[0102] The first processing unit is configured to monitor the hooking monitoring points by using a hooking method according to the type information, the class information, and the function information.
[0103] Optionally, the apparatus, wherein the component information comprises one or more of the following:
[0104] a component type;
[0105] a package name;
[0106] a class feature;
[0107] a parent class feature;
[0108] a business function memory.
[0109] Optionally, the apparatus, wherein the first obtaining module 403 comprises:
[0110] The third obtaining unit is configured to determine whether the new component is a component allowed to be added in a system built-in library according to the component type, and obtain a first determination result; wherein the system built-in library is a set comprising components allowed to be added in the container.
[0111] The fourth obtaining unit is configured to, in the case that the first determination result is yes, determine whether the package name and the class feature of the new component belong to white list information according to the package name and the class feature of the new component, and obtain a second determination result; the white list information is a set of package names and class features that are allowed to be added by a business system in advance;
[0112] The fifth obtaining unit is configured to, in the case that the second determination result is yes, determine whether the parent class feature and the business function memory of the new component do not contain high-risk characters, and obtain a third determination result; the high-risk characters are characters that are likely to appear in the case that the container is injected by a memory horse;
[0113] The first determining unit is configured to, in the case that the third determination result is yes, determine that the analysis result is a non-memory horse injection behavior.
[0114] Optionally, the apparatus further includes:
[0115] The second obtaining module is configured to, in the case that any one of the first determination result, the second determination result and the third determination result is no, obtain the analysis result as a memory horse injection behavior.
[0116] Optionally, in the case that the analysis result is a memory horse injection behavior, the first determining module 404 includes:
[0117] The second determining unit is configured to determine a memory flag MemFlag parameter according to the memory horse injection behavior; the MemFlag parameter is a plurality of preset parameter values corresponding to a plurality of memory horse injection behaviors;
[0118] The second processing unit is configured to, in the case that the MemFlag parameter is a first preset value, intercept the new component and issue an alarm.
[0119] The third processing unit is configured to, in the case that the MemFlag parameter is a second preset value, issue an alarm for the new component.
[0120] Optionally, in the case that the analysis result is a non-memory horse injection behavior, the first determining module 404 includes:
[0121] The fourth processing unit is configured to, according to the non-memory horse injection behavior, obtain the MemFlag parameter as a third preset value, and normally respond to the business request.
[0122] It should be noted that the above device provided by the embodiments of the present application can realize all the method steps achieved by the above method embodiments, and achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described in detail.
[0123] To achieve the above object, the embodiments of the present application provide a detection device, comprising a transceiver, a processor, a memory, and a program or instructions stored on the memory and executable on the processor; wherein the processor implements the detection method as described above when executing the program or instructions.
[0124] To achieve the above object, the embodiments of the present application provide a readable storage medium having a program or instructions stored thereon, wherein the program or instructions are executable by a processor to implement the steps of the detection method as described above.
[0125] To achieve the above object, the embodiments of the present application provide a computer program product, comprising computer instructions executable by a processor to implement the steps of the detection method as described above.
[0126] It should be further noted that the terminal described in the specification includes but is not limited to a smart phone, a tablet computer, etc., and many functional components described are referred to as modules in order to more particularly emphasize their independence of implementation.
[0127] In the embodiments of the present application, the modules can be implemented by software to be executed by various types of processors. For example, an identified executable code module can include one or more physical or logical blocks of computer instructions. For example, it can be structured as an object, a procedure or a function. However, the executable code of the identified module need not be physically located together, but can include different instructions stored in different locations which, as a whole, warrant the module and achieve the stated purpose of the module.
[0128] In fact, the executable code module can be a single instruction or many instructions, and can even be distributed over several different code segments, among different programs, and across several memory devices. Similarly, operational data can be identified within the module and can be organized in any suitable form and stored in any suitable type of data structure. The operational data can be collected as a single data set, or can be distributed over different locations including over different storage devices, and can exist at least in part only as electronic signals on a system or network.
[0129] When the modules can be implemented in software, hardware implementation of the modules can be done with the current level of technology, so that the modules implemented in software can be built into corresponding hardware circuit by those skilled in the art without considering the cost, including conventional very large scale integration (VLSI) circuit or gate array, and existing semiconductors such as logic chips, transistors and other discrete components. The modules can also be implemented by programmable hardware devices, such as field programmable gate array, programmable array logic, programmable logic device, etc.
[0130] The exemplary embodiments described above are described with reference to the accompanying drawings, many different forms and embodiments of which are possible without departing from the spirit and teachings of this disclosure. Accordingly, the disclosure should not be construed as limited to the particular exemplary embodiments described herein. Such embodiments are merely illustrative and are not intended to limit the scope of the present disclosure. Rather, the scope of the present disclosure is to be given by the appended claims along with their full scope of equivalents. In the drawings, the size and relative sizes of components can be exaggerated for clarity. Terms used herein are merely descriptive, and are not intended to be limiting. As used herein, unless specifically stated otherwise, the singular forms "a," "an," and "the" are intended to include the plural forms as well. It will be further understood that the terms "comprises," "comprising," "includes," and / or "including," as used herein, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. A value range specified when reciting a value range includes the upper and lower limits of the range and any sub-range therebetween, unless otherwise stated.
[0131] The above is the preferred embodiment of the present application, it should be pointed out that for those skilled in the art, without departing from the principles of the present application, can also make a number of improvements and refinements, these improvements and refinements should also be considered as the protection scope of the present application.
Claims
1. A detection method, characterized in that: include: When the business system is running, the security plug-in is started through the Tomcat middleware container; The security plug-in is used to monitor multiple monitoring points using a Hook plug-in method, and when a service request is detected, a new component is loaded based on the plug-in monitoring point; Determine, based on the component information of the newly added component, whether the newly added component is generated by a memory injection behavior, and obtain an analysis result; According to the analysis result, it is determined whether to intercept the newly added component.
2. The method according to claim 1, characterized in that The security plug-in uses the Hook plug-in method to monitor multiple plug-in monitoring points, including: Obtaining context information of a first component in the Tomcat middleware container through the security plug-in; wherein the first component is a suspicious component injected into the container by a memory horse; Acquire, based on the context information, type information of the first component, class information of the suspicious class injected by the memory hacker in the first component, and function information of the suspicious function injected by the memory hacker in the first component; The plug-in monitoring point is monitored using a Hook plug-in method according to the type information, the class information and the function information.
3. The method according to claim 1, characterized in that The component information includes one or more of the following: Component type; Package name; Class characteristics; Parent class characteristics; Business function memory.
4. The method according to claim 3, characterized in that Determining whether the newly added component is generated by a memory injection behavior based on the component information of the newly added component and obtaining an analysis result includes: Determining whether the newly added component is a component allowed to be added in a system built-in library according to the component type, and obtaining a first determination result; wherein the system built-in library is a collection of components allowed to be added to the container; If the first judgment result is yes, determine whether the newly added component belongs to the whitelist information based on the package name and the class characteristics, and obtain a second judgment result; wherein the whitelist information is a set of package names and class characteristics that are allowed to be added by the pre-set business system; If the second judgment result is yes, determining whether the parent class characteristics of the newly added component and the business function memory do not contain high-risk characters, and obtaining a third judgment result; wherein the high-risk characters are characters that may appear when the container is subjected to memory injection; When the third judgment result is yes, it is determined that the analysis result is a non-memory horse injection behavior.
5. The method according to claim 4, characterized in that The method further comprises: When any one of the first judgment result, the second judgment result, and the third judgment result is no, the analysis result is obtained as a memory horse injection behavior.
6. The method according to claim 5, characterized in that In the case where the analysis result is a memory malware injection behavior, determining whether to intercept the newly added component according to the analysis result includes: Determining a memory flag MemFlag parameter according to the memory horse injection behavior; wherein the MemFlag parameter is a plurality of parameter values preset according to a plurality of memory horse injection behaviors; When the MemFlag parameter is a first preset value, intercepting the newly added component and issuing an alarm; When the MemFlag parameter is the second preset value, an alarm is issued for the newly added component.
7. The method according to claim 6, characterized in that If the analysis result is non-memory malware injection behavior, determining whether to intercept the newly added component based on the analysis result includes: According to the non-memory horse injection behavior, the MemFlag parameter is obtained as a third preset value, and the service request is responded to normally.
8. A detection device, characterized in that: include: The first processing module is used to start the security plug-in through the Tomcat middleware container when the business system is running; The second processing module is used to monitor multiple plug-in monitoring points using the Hook plug-in method through the security plug-in, and load a new component based on the plug-in monitoring point when a service request is detected; A first acquisition module is configured to determine, based on component information of the newly added component, whether the newly added component is generated by a memory malware injection behavior, and obtain an analysis result; wherein the component information is information capable of determining whether the newly added component is generated by a memory malware injection behavior; The first determination module is used to determine whether to intercept the newly added component based on the analysis result.
9. A detection device comprising: A transceiver, a processor, a memory, and a program or instruction stored in the memory and executable on the processor; wherein the processor implements the detection method according to any one of claims 1 to 7 when executing the program or instruction.
10. A readable storage medium having a program or instruction stored thereon, characterized in that: When the program or instruction is executed by a processor, the steps in the detection method according to any one of claims 1 to 7 are implemented.
11. A computer program product, characterized in that The method comprises computer instructions, which, when executed by a processor, implement the steps of the container detection method according to any one of claims 1 to 7.
Citation Information
Cited By
Abnormal traffic cooperative detection method and system
CN121619181A