Cloud service protection strategy evaluation method and device, computer equipment and medium
By obtaining the connection attribute information of the cloud service interface, performing behavioral semantic judgment and simulating attacks, and monitoring the program's reconnection status, the problem of low efficiency in cloud service protection strategy evaluation in existing technologies is solved, and efficient and automated security strategy evaluation and optimization are achieved.
Patent Information
- Application Number
- CN202511025619.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-07-24
AI Technical Summary
The existing cloud service protection strategy assessment technology is inefficient and has a low degree of automation, making it impossible to effectively identify and verify vulnerabilities and configuration defects in cloud interfaces.
By obtaining the connection attribute information of the cloud service interface, performing behavioral semantic judgment, generating behavioral semantic labels, creating a data monitoring terminal and attack simulation code files, simulating the attacker's upload path and monitoring the program's return connection status, the evaluation results of the protection strategy are determined.
It improves the efficiency and accuracy of cloud service protection strategy evaluation, can automatically verify the penetration of protection strategies, identify potential security risks and provide strategy optimization suggestions.
Smart Images

Figure CN120811686A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present disclosure relate to the field of network security, and in particular, to a method and device for evaluating a cloud service protection strategy, a computer device and a medium. BACKGROUND
[0002] Since entering the era of cloud computing, the construction method of application systems has undergone fundamental changes. In the past traditional IT (Artificial Intelligence) systems, function calls and data interactions were mainly limited to internal module communication, with a small number of exposed APIs (Application Program Interface) facing the periphery. Today, cloud platforms widely adopt microservices and API-first architecture ideas, and most functions are presented through interfaces. Therefore, cloud interfaces have become the main interaction bridge for external access to systems.
[0003] In related technologies, an attack simulation tool is usually used as a cloud security protection system to try to penetrate the boundary from the perspective of an attacker, identify exploitable vulnerabilities and paths. During penetration, the actual capabilities behind normal interfaces (such as upload and execution) are usually not identified; vulnerabilities or configuration defects are targeted, rather than interface semantic misuse; a large amount of personnel experience and attack knowledge is relied on, with low automation; it is generally used as a stage event operation; and it does not have continuous verification capabilities.
[0004] However, using existing technologies, the evaluation efficiency of protection strategies is low. SUMMARY
[0005] The embodiments described herein provide a method and device for evaluating a cloud service protection strategy, a computer device and a medium, which overcome the above problems.
[0006] In a first aspect, according to the content of the present disclosure, a method for evaluating a cloud service protection strategy is provided, comprising:
[0007] obtaining connection attribute information of a cloud service interface;
[0008] performing behavior semantic judgment on the connection attribute information of the cloud service interface to obtain a behavior semantic label corresponding to the cloud service interface; and determining whether the cloud service interface satisfies a scheduling execution condition based on the behavior semantic label corresponding to the cloud service interface;
[0009] if it is determined that the cloud service interface satisfies the scheduling execution condition based on the behavior semantic label corresponding to the cloud service interface, creating a data monitoring end and an attack simulation code file, the data monitoring end being used to monitor a program back connection state corresponding to the cloud service interface;
[0010] sending a data upload instruction to the cloud service interface to instruct the cloud service interface to simulate an attacker upload path, and uploading the attack simulation code file to a target server through the attacker upload path;
[0011] determining an evaluation result of the cloud service protection strategy based on the program back connection state of the cloud service interface listened to by the data listening end.
[0012] Optionally, the behavior semantic judgment on the connection attribute information of the cloud service interface comprises:
[0013] mapping characters in the connection attribute information of the cloud service interface to obtain character mapping information;
[0014] calling a behavior learning model, and determining corresponding interface response behaviors according to the behavior learning model and the character mapping information;
[0015] performing association judgment on the character mapping information and the corresponding interface response behaviors to obtain the behavior semantic label corresponding to the cloud service interface.
[0016] Optionally, the interface back connection state corresponding to the cloud service interface is used to describe a program connection state between the attack simulation code file and the data listening end.
[0017] The determination of the evaluation result of the cloud service protection strategy based on the program back connection state of the cloud service interface listened to by the data listening end comprises:
[0018] If the network security group has configured a preset forbidden outbound port, and the attack simulation code file is still connected with the data listening end, it is determined that the evaluation result of the cloud service protection strategy is that the protection is not successful.
[0019] Optionally, the interface back connection state corresponding to the cloud service interface is used to describe a program back connection state between the attack simulation code file and the data listening end.
[0020] The determination of the evaluation result of the cloud service protection strategy based on the program back connection state of the cloud service interface listened to by the data listening end comprises:
[0021] If the attack simulation code file and the data listening end are successfully back connected, it is determined that the evaluation result of the cloud service protection strategy is that the strategy needs to be upgraded.
[0022] If the attack simulation code file and the data listening end are not successfully back connected, it is determined that the evaluation result of the cloud service protection strategy is that the protection is successful.
[0023] Optionally, before the sending of the data upload instruction to the cloud service interface, the method further comprises:
[0024] The attack simulation code file is packaged and disguised, and a preset combination encoding method is used to encode the attack simulation code file to generate an executable file, so as to perform file disguise processing on the attack simulation code file.
[0025] Optionally, the method further comprises:
[0026] An interface behavior chain structure of the cloud service interface is obtained.
[0027] According to the interface behavior chain structure of the cloud service interface, a corresponding interface behavior field is determined.
[0028] According to the interface behavior field corresponding to the interface behavior chain structure, a risk analysis report of the cloud service interface is generated.
[0029] Optionally, the method further comprises:
[0030] According to the risk analysis report of the cloud service interface, a strategy optimization analysis feature of the cloud service protection strategy is determined.
[0031] The strategy optimization analysis feature of the cloud service protection strategy is input into a large language model, and a strategy optimization operation scheme for the cloud service protection strategy is determined according to an output of the large language model, so as to perform strategy optimization on the cloud service protection strategy through the strategy optimization operation scheme.
[0032] In a second aspect, according to the content of the disclosure, a cloud service protection strategy evaluation device is provided, comprising:
[0033] An acquisition module is configured to acquire connection attribute information of a cloud service interface.
[0034] A judgment module is configured to perform behavior semantic judgment on the connection attribute information of the cloud service interface to obtain a behavior semantic label corresponding to the cloud service interface, and judge whether the cloud service interface satisfies a scheduling execution condition based on the behavior semantic label corresponding to the cloud service interface.
[0035] A creation module is configured to create a data monitoring end and an attack simulation code file if it is judged that the cloud service interface satisfies the scheduling execution condition based on the behavior semantic label corresponding to the cloud service interface, wherein the data monitoring end is configured to monitor a program back connection state corresponding to the cloud service interface.
[0036] The sending module is configured to send a data upload instruction to the cloud service interface to instruct the cloud service interface to simulate an attacker upload path, and upload the attack simulation code file to the target server through the attacker upload path.
[0037] The determining module is configured to determine an evaluation result of the cloud service protection strategy based on the program back connection state of the cloud service interface listened to by the data listening end.
[0038] In a third aspect, a computer device is provided, which includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the steps of the method for evaluating a cloud service protection strategy according to any one of the above embodiments are implemented.
[0039] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program. When the computer program is executed by a processor, the steps of the method for evaluating a cloud service protection strategy according to any one of the above embodiments are implemented.
[0040] The method for evaluating a cloud service protection strategy provided by the embodiments of the present application includes the following steps: obtaining connection attribute information of a cloud service interface; performing behavior semantic judgment on the connection attribute information of the cloud service interface to obtain a behavior semantic label corresponding to the cloud service interface; judging whether the cloud service interface satisfies a scheduling execution condition based on the behavior semantic label corresponding to the cloud service interface; if the cloud service interface satisfies the scheduling execution condition based on the behavior semantic label corresponding to the cloud service interface, creating a data listening end and an attack simulation code file, the data listening end being configured to listen to a program back connection state of the cloud service interface; sending a data upload instruction to the cloud service interface to instruct the cloud service interface to simulate an attacker upload path, and uploading the attack simulation code file to a target server through the attacker upload path; and determining an evaluation result of the cloud service protection strategy based on the program back connection state of the cloud service interface listened to by the data listening end. In this way, by listening to the program back connection state of the cloud service interface in the process of uploading the attack simulation code file to the target server, the penetration of the protection strategy is verified, and the evaluation efficiency of the protection strategy is effectively improved.
[0041] The above description is only a summary of the technical solutions of the embodiments of the present application. In order to more clearly understand the technical means of the embodiments of the present application, the embodiments of the present application can be implemented according to the content of the description, and in order to make the above and other purposes, features and advantages of the embodiments of the present application more obvious and easy to understand, the specific embodiments of the present application are described below. BRIEF DESCRIPTION OF DRAWINGS
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings of the embodiments will be briefly described below. It should be noted that the drawings described below only relate to some embodiments of the present disclosure, but not limit the present disclosure, wherein:
[0043] Figure 1 is a flow diagram of a method for evaluating a cloud service protection policy provided by the present disclosure.
[0044] Figure 2 is a structural diagram of an evaluation device for a cloud service protection policy provided by the present disclosure.
[0045] Figure 3 is a structural diagram of a computer device provided by the present disclosure.
[0046] It should be noted that the elements in the drawings are schematic and not drawn to scale. DETAILED DESCRIPTION
[0047] In order to make the purposes, technical solutions and advantages of the embodiments of the present disclosure clearer, the technical solutions of the embodiments of the present disclosure will be described clearly and completely below with reference to the drawings. Obviously, the described embodiments are part of the embodiments of the present disclosure, rather than all the embodiments. Based on the described embodiments of the present disclosure, all other embodiments obtained by a person of ordinary skill in the art without creative effort also belong to the scope of protection of the present disclosure.
[0048] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this present subject matter belongs. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the specification and relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein. As used herein, the statement that two or more parts or components are "connected" or "coupled" together shall mean that the parts are joined or linked together either directly or through one or more intermediate parts.
[0049] Reference herein to "embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase "in an embodiment" in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily all directed to the same embodiment, or to a single alternative embodiment. It is explicitly contemplated that embodiments described herein can be combined with each other.
[0050] The term "and / or" used in this document only describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the existence of A, the existence of A and B, and the existence of B. In addition, the character " / " in this document generally represents that the front and rear associated objects are in an "or" relationship. Terms such as "first" and "second" are only used to distinguish one component (or part of a component) from another component (or another part of a component).
[0051] In the description of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more (including two), and similarly, "a plurality of groups" means two or more groups (including two groups).
[0052] In order for those skilled in the art to better understand the scheme of the present application, the technical solutions in the embodiments of the present application will be described clearly and completely in conjunction with the drawings.
[0053] Figure 1 is a flowchart of a cloud service protection policy evaluation method provided by an embodiment of the present disclosure, as shown in Figure 1 The specific process of the cloud service protection policy evaluation method includes:
[0054] S110, acquiring connection attribute information of a cloud service interface.
[0055] The connection attribute information of the cloud service interface includes: request parameters, API path, and field meaning of the cloud service interface. The cloud interface information collection and recognition module can be used to collect cloud platform product→service→interface→parameter structure. The data source of the connection attribute information of the cloud service interface is the cloud platform official API document (such as OpenAPI Schema), and the interface call characteristic behavior in the Web console is captured; the CLI (such as Az CLI, AWS CLI) command call parameter list is listened to, and the interface call message is recorded by the man-in-the-middle method (packet capture method is used to assist in analyzing undocumented information). And for each service composition: service name, API identifier, parameter list, function annotation, and use state, data structure modeling is performed, as shown below.
[0056] ---------------------------------------------------------------------
[0057] {
[0058] "service":"Azure Kubernetes Service",
[0059] "interface":" / uploadConfig",
[0060] "method":"POST",
[0061] "params":{
[0062] "file":"binary",
[0063] "configType":"yaml"
[0064] },
[0065] "description":"Upload the configuration file and restart the service"
[0066] }
[0067] --------------------------------------------------------------------- In addition, situational awareness attributes can be added to improve the connection attribute information of the cloud service interface, such as adding whether the authentication parameter is optional, whether the return string contains sensitive words such as "Execute" and "Script" for annotation; judging whether the return time and execution process may trigger remote system activities (multiple check requests + execution time is greater than the average).
[0068] S120. Perform behavioral semantic judgment on the connection attribute information of the cloud service interface to obtain a behavioral semantic label corresponding to the cloud service interface; and determine whether the cloud service interface meets the scheduling execution conditions based on the behavioral semantic label corresponding to the cloud service interface.
[0069] The interface semantic analysis and risk identification module can be used to determine whether the cloud service interface has sensitive risks such as upload, execution, and configuration. The request parameters, API path, and field meanings of the corresponding interface are converted into abstract semantic labels, such as "file_upload", "shell_exec", "component_update", "remote_trigger", etc. After obtaining the behavioral semantic labels, rule set analysis can be used to determine whether they involve scheduling execution conditions (such as schedulable execution or cross-domain upload), as shown in the following example.
[0070] ---------------------------------------------------------------------
[0071] -interface: / uploadFile
[0072] method:POST
[0073] semantic: file_upload
[0074] isExecutable: true
[0075] params:
[0076] -name: file
[0077] type: bytes
[0078] -name: path
[0079] type: string
[0080] --------------------------------------------------------------------- In some embodiments, the connection information of the cloud service interface is subjected to behavior semantic judgment to obtain a behavior semantic label corresponding to the cloud service interface, including:
[0081] The characters in the connection attribute information of the cloud service interface are subjected to keyword mapping to obtain character mapping information; a behavior learning model is called, and a corresponding interface response behavior is determined according to the behavior learning model and the character mapping information; the character mapping information and the corresponding interface response behavior are subjected to association judgment to obtain the behavior semantic label corresponding to the cloud service interface.
[0082] Among them, the character keyword mapping is like “file”, “upload”, related type binary, and JSON Schema field combination pattern recognition is performed; a historical calling behavior learning model is used to determine how parameter changes affect response content; and the association discrimination logic of parameter values and response behaviors (such as the parameter is called “command” and the response contains “bash”, which is a high-risk behavior) is used to effectively determine the behavior semantic label corresponding to the cloud service interface.
[0083] The characters in the connection attribute information of the cloud service interface are subjected to keyword mapping to obtain character mapping information, including: a comprehensive keyword library is constructed, which covers various keywords related to common operations, functions and risks of the cloud service interface, such as “download”, “delete”, “access”, etc.; the characters in the connection attribute information are compared with the keyword library one by one; during the comparison process, not only accurate matching is performed, but also fuzzy matching is considered to cope with possible character deformation, abbreviation, etc. For example, “file download” can be matched to “file” and “download”.
[0084] The character mapping information and the corresponding interface response behavior are associated to determine the behavior semantic label corresponding to the cloud service interface, including: establishing an association rule model, which is based on a large amount of historical data and the experience of security experts, and defines various possible association relationships between the character mapping information and the interface response behavior. For example, if the character mapping information contains "delete" and the interface response behavior is a confirmation prompt for deleting a file operation, it can be associated with the semantic label of "file deletion behavior". For each group of character mapping information and interface response behavior, matching analysis is performed according to the association rule model to determine whether there is a predefined association relationship between them.
[0085] S130, if it is determined that the cloud service interface satisfies the scheduling execution condition based on the behavior semantic label corresponding to the cloud service interface, a data monitoring end and an attack simulation code file are created.
[0086] The data monitoring end is used to monitor the program back connection state corresponding to the cloud service interface. Program B (i.e. the attack simulation code file) and program A (i.e. the data monitoring end) can be automatically generated by the attack path simulation construction module. The data monitoring end is a bounce control server deployed by the security system, which is used to monitor whether a malicious program has successfully back connected. The attack simulation code file is used to evaluate the back connection sample of the interface risk, which is simulated to be uploaded and executed to verify whether the system / firewall is intercepted.
[0087] Create program A: automatically generate monitoring code based on TCP Socket service; deploy in authorized environment, record port and connection log; if program successfully receives connection information, record time, connection source IP, and device characteristics.
[0088] Create program B: automatically compile bounce connection script program (support multiple languages Python, Shell, Golang); implant program A access address and port; support shell, such as encapsulating the program into images, PDF, etc. controlled propagation style if necessary; upload preparation path can be constructed as a user option field.
[0089] S140, a data upload instruction is sent to the cloud service interface to instruct the cloud service interface to simulate an attacker upload path, and the attack simulation code file is uploaded to the target server through the attacker upload path.
[0090] The program B can be uploaded to the target server and executed by the cloud interface remote upload and trigger execution module. Automatically construct the upload request: build the HTTP(HyperText Transfer Protocol, HyperText Transfer Protocol) request body according to the parameter type, support JSON, multipart / form-data, etc. structure; execute command scheduling preparation: if the interface supports remote execution, the system constructs the following statement.
[0091] ---------------------------------------------------------------------
[0092] POST / executeCommand
[0093] {
[0094] "cmd":"bash / tmp / rev_connect.sh"
[0095] }
[0096] ---------------------------------------------------------------------
[0097] Call execution: use interface authentication system, Cookie or Token method, simulate authorized users to complete upload and execution. All operation behaviors are recorded in log, and the system ensures that high persistence will not be triggered, such as automatic termination when timeout.
[0098] In some embodiments, before sending the data upload instruction to the cloud service interface, further comprising:
[0099] The attack simulation code file is packaged and disguised, and the attack simulation code file is encoded by using a preset combination encoding method to generate an executable file.
[0100] Among them, the support program B is packaged and disguised; the Base64+Decode combination method can be used to form an executable file; the typical upload path of the attacker is simulated, that is, after uploading the zip file, remote decompression and execution are performed, and the like, so as to perform file disguise processing on the attack simulation code file.
[0101] The attack simulation code file is packaged and disguised, including: using diversified disguising means, such as embedding the attack simulation code file into common system files, so that it is more concealed on the target server and is not easy to be detected by the protection system; the attack simulation code file can also be disguised as a system update package, and the server's trust in update operation is used to bypass the protection mechanism. In the process of disguising, the metadata of the file is modified, so that it looks like a legal and regular file, for example, the creation time, modification time and access time of the file are adjusted, so that they are consistent with the timestamp mode of normal files.
[0102] S150, based on the program back connection state corresponding to the cloud service interface listened by the data listening end, determine the evaluation result of the cloud service protection strategy.
[0103] Wherein, whether program B can successfully connect A is monitored by the back connection state monitoring and firewall penetration verification module, and then the strategy penetration is verified.
[0104] In some embodiments, the interface back connection state corresponding to the cloud service interface is used to describe the program connection state between the attack simulation code file and the data monitoring end; based on the program back connection state corresponding to the cloud service interface monitored by the data monitoring end, the evaluation result of the cloud service protection strategy is determined, including:
[0105] If the network security group has configured a preset forbidden outbound port, and the attack simulation code file is still connected with the data monitoring end, it is determined that the evaluation result of the cloud service protection strategy is that the protection is not successful.
[0106] Wherein, in the control end program A, a TCP monitoring service is monitored and recorded; if the target server can back connect, the connection channel and CONNECT information are recorded; it can be extended to UDP, HTTP, reverse Socket and other connection verification.
[0107] If the cloud firewall NSG (Network Security Group) is configured to prohibit outbound 22, 80, 8080 ports, and program B can still connect program A, it means that the blocking fails, and the evaluation result of the cloud service protection strategy is that the protection is not successful.
[0108] In some embodiments, the interface back connection state corresponding to the cloud service interface is used to describe the program back connection state between the attack simulation code file and the data monitoring end; based on the program back connection state corresponding to the cloud service interface monitored by the data monitoring end, the evaluation result of the cloud service protection strategy is determined, including:
[0109] If the attack simulation code file and the data monitoring end back connect successfully, it is determined that the evaluation result of the cloud service protection strategy is that the strategy needs to be upgraded; if the attack simulation code file and the data monitoring end back connect unsuccessfully, it is determined that the evaluation result of the cloud service protection strategy is that the protection is successful.
[0110] Wherein, if the back connection is successful, the interface control fails, and the strategy needs to be upgraded; if it is not successful, the connection failure position point (such as TCP handshake failure, DNS not resolved, no permission execution) can also be debugged and packet captured.
[0111] Thus, whether program B can break through the firewall restriction and successfully establish external connection is monitored; if program B successfully connects program A, it proves that there is a security risk in the interface, and the current firewall cannot prevent illegal execution actions; whether the program back connection is used as the risk verification result, non-log inference and rule matching, which effectively improves the accuracy of strategy evaluation.
[0112] In this embodiment, the connection attribute information of the cloud service interface is obtained; the behavior semantic judgment is performed on the connection attribute information of the cloud service interface to obtain the behavior semantic label corresponding to the cloud service interface; and whether the cloud service interface satisfies the scheduling execution condition is judged based on the behavior semantic label corresponding to the cloud service interface; if the cloud service interface satisfies the scheduling execution condition is judged based on the behavior semantic label corresponding to the cloud service interface, then the data monitoring end and the attack simulation code file are created, the data monitoring end is used to monitor the program back connection state corresponding to the cloud service interface; the data upload instruction is sent to the cloud service interface to instruct the cloud service interface to simulate the attacker upload path, and the attack simulation code file is uploaded to the target server through the attacker upload path; based on the program back connection state of the cloud service interface monitored by the data monitoring end, the evaluation result of the cloud service protection strategy is determined. In this way, by monitoring the program back connection state corresponding to the cloud service interface in the process of uploading the attack simulation code file to the target server, the penetration of the protection strategy is verified, and the evaluation efficiency of the protection strategy is effectively improved.
[0113] In some embodiments, the method further comprises:
[0114] The interface behavior chain structure of the cloud service interface is obtained; the corresponding interface behavior field is determined according to the interface behavior chain structure of the cloud service interface; and the risk analysis report of the cloud service interface is generated according to the interface behavior field corresponding to the interface behavior chain structure.
[0115] The risk analysis report of the cloud service interface is shown in Table 1.
[0116] Table 1 Risk Analysis Report
[0117]
[0118]
[0119] Therefore, the risk analysis report of the cloud service interface is generated through the interface behavior field corresponding to the interface behavior chain structure, which facilitates clear and intuitive display of the risk analysis result of the cloud service interface.
[0120] In some embodiments, the method further comprises:
[0121] According to the risk analysis report of the cloud service interface, the strategy optimization analysis feature of the cloud service protection strategy is determined; the strategy optimization analysis feature of the cloud service protection strategy is input into the large language model, and the strategy optimization operation scheme of the cloud service protection strategy is determined according to the output of the large language model, so as to perform strategy optimization on the cloud service protection strategy through the strategy optimization operation scheme of the cloud service protection strategy.
[0122] According to the risk analysis report of the cloud service interface, the policy optimization analysis features of the cloud service protection policy are determined, including: extracting key risk indicators from the risk analysis report, such as upload permissions, execution permissions, and security authentication missing in exposure risks, upload and connection success or failure in the back connection result, etc. These indicators reflect the main risk points currently existing in the cloud service interface and are the basis for determining the policy optimization analysis features. Analyze the relevant information of the penetrated path, including the outbound port, protocol, and call context; through the study of these information, the weak link that may be attacked and exploited can be found out, so as to convert it into a policy optimization analysis feature. For example, if it is found that a certain outbound port is often used for abnormal connection, the related features of the port should be included in the scope of policy optimization consideration. Furthermore, attention should be paid to policy suggestions, such as suggestions to block remote upload, increase operation whitelist, etc. which actually point out the possible optimization direction of the cloud service protection policy; further refine these suggestions into specific analysis features, such as determining the specific rules for blocking remote upload, screening conditions for operation whitelist, etc.
[0123] Thus, through the risk analysis report of the cloud service interface, the policy optimization analysis features of the cloud service protection policy are determined; and the large language model is used to determine the policy optimization operation scheme of the cloud service protection policy, so as to improve the effectiveness and pertinence of the cloud service protection policy.
[0124] In summary, the embodiment takes the interface calling behavior as the entry evaluation object, identifies the key meaning attributes such as uploading and execution, simulates the attack without real intrusion, constructs the attack path without damaging the target system, simulates the whole process legally, quantifies the data convergence verification, uses the program reconnection as the risk verification result, infers and matches the rules, and realizes the strategy optimization assistance driven by the results. By introducing the dynamic verification mechanism of "attack simulation behavior + connection result monitoring" in the defense model, a new generation of cloud interface protection verification platform is formed, which is driven by data, behavior and automatic verification. Through the automatic tool scanning and reading of the service list provided by the cloud platform, the subordinate service interfaces and parameter definitions are further extracted. In the analysis process, the interface semantic model (Semantic Model) is established in combination with the interface purpose, parameter attribute, permission requirement, calling mode and the like, and it is judged that some interfaces may have sensitive functions such as uploading, remote execution and configuration override. Based on the identification result, a simulation program (referred to as program B, i.e. the execution of the reconnection executor) with attack construction capability is generated, and is uploaded to the target system environment through the cloud interface identified as "operable high risk". At the same time, the system automatically deploys the control end component (referred to as program A, i.e. the instruction receiver) for listening to whether program B can break through the firewall restriction and successfully establish external connection. If program B successfully connects with program A, it proves that the interface has security risks, and the current firewall cannot prevent illegal execution actions. This way is not a traditional attack intrusion, but is used for strategy verification and permission audit, and is only used for positive defense operation and maintenance, which can realize the "attack chain verification technology" with zero implantation, zero intrusion and zero destruction.
[0125] Further, the semantic types expressed behind the cloud application interface can be automatically analyzed, and the high-risk behavior points such as uploading, command execution and program calling are identified. Simulate the real attack path: without relying on whether the attacker implements the attack, a legal test program is injected by the system, a complete attack chain path is executed through the cloud interface, and active simulation is realized. Verify whether the firewall is really effective: instead of deciding whether it is safe according to the rules, the dynamic uploading→execution→reconnection verification mode is adopted, and the result is used as the standard to determine whether the current access control state constitutes a defense hole. Structured report and strategy patching suggestion: a clear structured view is generated through the complete path, result verification and interface structure analysis, and targeted optimization suggestions are provided for the firewall strategy.
[0126] Figure 2 A structural schematic diagram of a cloud service protection strategy evaluation device provided by the embodiment is provided, and the cloud service protection strategy evaluation device can include an acquisition module 210, a judgment module 220, a creation module 230, a sending module 240 and a determination module 250.
[0127] The acquisition module 210 is configured to acquire connection attribute information of the cloud service interface.
[0128] The determination module 220 is configured to perform behavior semantic determination on the connection attribute information of the cloud service interface to obtain a behavior semantic label corresponding to the cloud service interface, and determine whether the cloud service interface meets a scheduling execution condition based on the behavior semantic label corresponding to the cloud service interface.
[0129] The creation module 230 is configured to create a data monitoring end and an attack simulation code file if it is determined that the cloud service interface meets the scheduling execution condition based on the behavior semantic label corresponding to the cloud service interface, where the data monitoring end is configured to monitor a program connection state corresponding to the cloud service interface.
[0130] The sending module 240 is configured to send a data upload instruction to the cloud service interface to instruct the cloud service interface to simulate an attacker upload path, and upload the attack simulation code file to a target server through the attacker upload path.
[0131] The determination module 250 is configured to determine an evaluation result of the cloud service protection strategy based on the program connection state corresponding to the cloud service interface monitored by the data monitoring end.
[0132] In this embodiment, the determination module 220 is specifically configured to:
[0133] perform keyword mapping on characters in the connection attribute information of the cloud service interface to obtain character mapping information, call a behavior learning model, and determine corresponding interface response behaviors according to the behavior learning model and the character mapping information, and perform association determination on the character mapping information and the corresponding interface response behaviors to obtain the behavior semantic label corresponding to the cloud service interface.
[0134] In this embodiment, the interface connection state corresponding to the cloud service interface is used to describe a program connection state between the attack simulation code file and the data monitoring end.
[0135] The determination module 250 is specifically configured to:
[0136] if the network security group has configured a preset forbidden outbound port and the attack simulation code file is still connected with the data monitoring end, it is determined that the evaluation result of the cloud service protection strategy is that the protection is unsuccessful.
[0137] In this embodiment, the interface connection state corresponding to the cloud service interface is used to describe a program connection state between the attack simulation code file and the data monitoring end.
[0138] The determination module 250 is specifically configured to:
[0139] If the attack simulation code file successfully connects back to the data monitoring end, the evaluation result of the cloud service protection policy is determined to be policy pending upgrade; if the attack simulation code file fails to successfully connect back to the data monitoring end, the evaluation result of the cloud service protection policy is determined to be protection successful.
[0140] In this embodiment, optionally, it further includes: a generation module.
[0141] The generation module is used to disguise and package the attack simulation code file, and use a preset combination encoding method to encode the attack simulation code file to generate an executable file to perform file disguise processing on the attack simulation code file.
[0142] In this embodiment, optionally, the acquisition module 210 is further configured to acquire the interface behavior chain structure of the cloud service interface.
[0143] The determination module 250 is further configured to determine a corresponding interface behavior field according to the interface behavior chain structure of the cloud service interface.
[0144] The generation module is also used to generate a risk analysis report for the cloud service interface based on the interface behavior fields corresponding to the interface behavior chain structure.
[0145] In this embodiment, optionally, the determination module 250 is also used to determine the policy optimization analysis characteristics of the cloud service protection policy based on the risk analysis report of the cloud service interface; input the policy optimization analysis characteristics of the cloud service protection policy into the large language model, and determine the policy optimization operation plan for the cloud service protection policy based on the output of the large language model, so as to perform policy optimization on the cloud service protection policy through the policy optimization operation plan of the cloud service protection policy.
[0146] The cloud service protection strategy evaluation device provided by the present disclosure can execute the above method embodiments. Its specific implementation principles and technical effects can be found in the above method embodiments, and the present disclosure will not repeat them here.
[0147] The present application also provides a computer device. Figure 3 , Figure 3 This is a basic structural block diagram of the computer device in this embodiment.
[0148] The computer device includes a memory 310 and a processor 320 which are communicatively connected through a system bus. It is noted that only the memory 310 and the processor 320 are shown in the figure, but it is understood that not all the shown components are required to be implemented, and more or less components can be alternatively implemented. Among them, the computer device herein is a device capable of automatically performing numerical calculation and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0149] The computer device can be a desktop computer, a notebook computer, a palm computer, a cloud server, etc. The computer device can interact with the user through a keyboard, a mouse, a remote controller, a touchpad, a voice control device, etc.
[0150] The memory 310 includes at least one type of readable storage medium, including non-volatile memory or volatile memory, for example, flash memory, a hard disk, a multimedia card, a card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. The RAM can include static RAM or dynamic RAM. In some embodiments, the memory 310 can be an internal storage unit of the computer device, for example, a hard disk or a memory of the computer device. In other embodiments, the memory 310 can also be an external storage device of the computer device, for example, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, or a flash card, etc. equipped on the computer device. Of course, the memory 310 can include both an internal storage unit and an external storage device of the computer device. In the present embodiment, the memory 310 is generally used to store an operating system and various application software installed on the computer device, for example, program codes of the above-described method, etc. In addition, the memory 310 can also be used to temporarily store various data that has been output or will be output.
[0151] The processor 320 is generally used to perform the overall operation of the computer device. In the present embodiment, the memory 310 is used to store program codes or instructions, which include computer operation instructions, and the processor 320 is used to execute the program codes or instructions stored in the memory 310 or process data, for example, run the program codes of the above-described method.
[0152] In this article, the bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus system can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is shown in the figure, but it does not mean that there is only one bus or only one type of bus.
[0153] Another embodiment of the present application also provides a computer readable medium, which can be a computer readable signal medium or a computer readable medium. The processor in the computer reads the computer readable program code stored in the computer readable medium, so that the processor can perform the function actions specified in each step or combination of steps in the above method; generate the device implementing the function actions specified in each block or combination of blocks in the block diagram.
[0154] The computer readable medium includes but is not limited to electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any appropriate combination of the foregoing, for storing program codes or instructions, which include computer operation instructions, and processors for executing the program codes or instructions of the above method stored in the memory.
[0155] The definition of the memory and the processor can refer to the description of the foregoing computer device embodiment, which will not be repeated here.
[0156] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiment described above is only schematic, for example, the division of modules or units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.
[0157] The function units or modules in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software function unit.
[0158] If the integrated unit is implemented in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or say the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0159] In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in a claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The application can be implemented by means of both hardware and software, and any combination thereof. In the device claim enumerating several means, several of these means can be embodied by one and the same item of hardware. The mere fact that certain measures are recited in mutually different claims does not indicate that a combination of these measures cannot be used to advantage. The use of relative terms such as "first", "second" and "third", etc. does not connote any prioritization, but such terms are used to distinguish a certain feature from another feature with the same name. The steps of the methods described in the above embodiments should not be understood as necessarily limited in their sequence, except when this is explicitly specified.
[0160] The above embodiments are only used to illustrate the technical solutions of the present application, rather than limit them; even though the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A cloud service protection strategy evaluation method, characterized in that: include: Get the connection property information of the cloud service interface; Performing behavioral semantic judgment on the connection attribute information of the cloud service interface to obtain a behavioral semantic label corresponding to the cloud service interface; and determining whether the cloud service interface meets the scheduling execution condition based on the behavioral semantic tag corresponding to the cloud service interface; If it is determined based on the behavioral semantic tag corresponding to the cloud service interface that the cloud service interface meets the scheduling execution condition, a data listening terminal and an attack simulation code file are created, wherein the data listening terminal is used to monitor the program backconnection status corresponding to the cloud service interface; Sending a data upload instruction to the cloud service interface to instruct the cloud service interface to simulate the attacker's upload path and upload the attack simulation code file to the target server through the attacker's upload path; An evaluation result of a cloud service protection strategy is determined based on a program backconnect status corresponding to the cloud service interface monitored by the data monitoring terminal.
2. The method according to claim 1, characterized in that The performing behavioral semantic judgment on the connection attribute information of the cloud service interface to obtain a behavioral semantic label corresponding to the cloud service interface includes: Performing keyword mapping on characters in the connection attribute information of the cloud service interface to obtain character mapping information; calling a behavior learning model, and determining a corresponding interface response behavior according to the behavior learning model and the character mapping information; An association judgment is performed on the character mapping information and the corresponding interface response behavior to obtain a behavior semantic label corresponding to the cloud service interface.
3. The method according to claim 1, characterized in that The interface backconnection status corresponding to the cloud service interface is used to describe the program connection status between the attack simulation code file and the data listening terminal; The determining of the evaluation result of the cloud service protection strategy based on the program backconnection status corresponding to the cloud service interface monitored by the data monitoring terminal includes: If the network security group has configured a preset prohibited outbound port and the attack simulation code file is still connected to the data listening terminal, it is determined that the evaluation result of the cloud service protection policy is that the protection is unsuccessful.
4. The method according to claim 1, wherein The interface backlink status corresponding to the cloud service interface is used to describe the program backlink status between the attack simulation code file and the data listening terminal; The determining of the evaluation result of the cloud service protection strategy based on the program backconnection status corresponding to the cloud service interface monitored by the data monitoring terminal includes: If the attack simulation code file is successfully connected to the data monitoring terminal, the evaluation result of the cloud service protection policy is determined to be a policy to be upgraded; If the attack simulation code file fails to connect back to the data listening terminal, the evaluation result of the cloud service protection strategy is determined to be protection success.
5. The method according to claim 1, wherein Before sending the data upload instruction to the cloud service interface, the method further includes: The attack simulation code file is disguised and packaged, and the attack simulation code file is encoded using a preset combined encoding method to generate an executable file, so as to perform file disguise processing on the attack simulation code file.
6. The method according to claim 1, characterized in that Also includes: Obtaining the interface behavior chain structure of the cloud service interface; Determine the corresponding interface behavior field according to the interface behavior chain structure of the cloud service interface; Generate a risk analysis report for the cloud service interface according to the interface behavior field corresponding to the interface behavior chain structure.
7. The method according to claim 6, characterized in that Also includes: Determining, based on the risk analysis report of the cloud service interface, a policy optimization analysis feature of the cloud service protection policy; The policy optimization analysis features of the cloud service protection policy are input into a large language model, and a policy optimization operation plan for the cloud service protection policy is determined based on the output of the large language model, so as to perform policy optimization on the cloud service protection policy through the policy optimization operation plan of the cloud service protection policy.
8. A cloud service protection strategy evaluation device, characterized in that: include: The acquisition module is used to obtain the connection attribute information of the cloud service interface; a judgment module, configured to perform behavioral semantic judgment on the connection attribute information of the cloud service interface to obtain a behavioral semantic label corresponding to the cloud service interface; and determining whether the cloud service interface meets the scheduling execution condition based on the behavioral semantic tag corresponding to the cloud service interface; A creation module is configured to create a data listening terminal and an attack simulation code file if it is determined based on the behavioral semantic tag corresponding to the cloud service interface that the cloud service interface satisfies the scheduling execution condition, wherein the data listening terminal is configured to monitor the program backconnection status corresponding to the cloud service interface; A sending module, configured to send a data upload instruction to the cloud service interface to instruct the cloud service interface to simulate an attacker's upload path and upload the attack simulation code file to a target server through the attacker's upload path; The determination module is used to determine the evaluation result of the cloud service protection strategy based on the program backconnection status corresponding to the cloud service interface monitored by the data monitoring end.
9. A computer device, characterized in that: The system comprises a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the method for evaluating the cloud service protection strategy according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for evaluating a cloud service protection strategy as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
A method and device for generating an interface test report
CN109376064A
Cloud data security access control method and device, electronic device and storage medium
CN111935108A
Host type intrusion protection performance detection method and device based on cloud native environment
CN115993962A
Risk data processing method and device based on cloud platform and computer equipment
CN116980168A
Verification system and method for defensive measures of cloud native container
CN117668832A