Protection rule access method and device, storage medium and processor

By automating the process of code inspection, validity testing, and performance testing of RASP protection rules, the problems of low efficiency and insufficient accuracy in updating protection rules have been solved, achieving efficient and accurate rule deployment and ensuring business continuity and performance stability.

CN120880731APending Publication Date: 2025-10-31AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511024484.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

The existing RASP protection rules are inefficient to update, lack accuracy, lack a system testing framework, and fail to assess business impact, resulting in long update cycles, false positives and false negatives, and high deployment risks.

Method used

Through automated processes of code inspection, validity testing, gray-scale verification, and performance testing, we ensure that RASP protection rules meet preset conditions before deployment, including static and dynamic detection, simulated attack scenarios, gray-scale environment verification, and performance indicator evaluation, to ensure the accuracy of the rules and the assessment of their business impact.

Benefits of technology

It improves the efficiency and accuracy of updating protection rules, shortens the update cycle, reduces deployment risks, ensures business continuity and performance stability, and provides reliable security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880731A_ABST
    Figure CN120880731A_ABST
Patent Text Reader

Abstract

The invention discloses a protection rule access method and device, a storage medium and a processor. According to the scheme, an RASP protection rule is obtained; the RASP protection rule is detected, and if the RASP protection rule meets a first preset condition, the RASP rule is deployed to a production environment; the detection comprises code detection, validity test, gray level verification and performance test. Compared with the prior art that RASP protection rule updating is low in protection rule updating efficiency, insufficient in protection rule accuracy and lack of evaluation of influence of protection rules on services, the method and the device have obvious advantages.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, storage medium and processor for protection rule access control. Background Technology

[0002] Runtime Application Self-Protection (RASP) is a technology that protects applications during runtime by monitoring and protecting their security, detecting and preventing potential attacks such as SQL injection and cross-site scripting.

[0003] With the continuous evolution of network attack methods, especially the increase in zero-day vulnerabilities and targeted attacks, large enterprises are facing increasingly severe network security challenges, and the application of RASP protection technology has also brought new problems. Among them, RASP protection rules, as the core content of RASP protection technology, need to be constantly updated in order to better deal with network security threats. The main problems with the current RASP protection rule updates are: (1) Low efficiency of protection rule updates. The process of updating protection rules involves development, testing, and production stages. Currently, it mainly relies on human initiative to promote it. Some processes may not be promoted for a long time, resulting in long rule update and deployment cycles and difficulty in responding quickly to new security threats. (2) Insufficient accuracy of protection rules. There is a lack of system testing frameworks and methods for RASP protection rules. New rules may not be able to accurately identify attacks, leading to false positives and false negatives, which affects the accuracy of protection rules. (3) Lack of assessment of the impact of protection rules on business. There is a lack of effective risk control measures, which makes the deployment of new rules high-risk, and the impact of new rules on business has not been assessed.

[0004] In response to the above problems, how to balance the efficiency and accuracy of updating protection rules with business impact in order to improve the overall performance of RASP protection technology is an urgent technical issue to be addressed. Summary of the Invention

[0005] To address the aforementioned issues, this application provides a protection rule admission method, apparatus, storage medium, and processor, aiming to balance the update efficiency, accuracy, and business impact of protection rules, thereby improving the overall performance of RASP protection technology.

[0006] The embodiments of this application disclose the following technical solutions:

[0007] The first aspect of this application provides a method for granting access to protection rules, the method comprising:

[0008] Obtain RASP protection rules;

[0009] The RASP protection rules are tested. If the RASP protection rules meet the first preset conditions, the RASP rules are deployed to the production environment. The testing includes code inspection, validity testing, gray-scale verification, and performance testing. The process of testing the RASP protection rules and deploying them to the production environment if they meet the first preset conditions includes:

[0010] The code of the RASP protection rules is inspected to obtain the code inspection results;

[0011] If the code detection result meets the second preset condition, the RASP protection rule is tested by simulating attack scenarios and business request scenarios to obtain test results;

[0012] If the test results meet the third preset condition, the effectiveness of the RASP protection rule is verified in a grayscale environment to obtain the grayscale verification result.

[0013] If the grayscale verification result meets the fourth preset condition, then individual performance testing and integrated performance testing are performed on the RASP protection rule pair to obtain the performance testing result;

[0014] If the performance test results meet the fifth preset condition, the RASP protection rule will be deployed to the production environment.

[0015] Optionally, the step of detecting the code of the RASP protection rule to obtain the code detection result includes:

[0016] Static analysis is performed on the code of the RASP protection rules to obtain static analysis results; the static analysis includes code quality testing.

[0017] If the static detection result indicates that the code of the RASP protection rule is qualified, test cases are automatically generated, and the test cases are used to dynamically detect the code of the RASP protection rule, and the dynamic detection result is used as the code detection result.

[0018] Optionally, if the code detection result meets the second preset condition, the RASP protection rule is tested by simulating attack scenarios and business request scenarios to obtain test results, including:

[0019] If the code detection result meets the second preset condition, create a test case that is expected to generate an attack alarm and a test case that is expected not to generate an attack alarm. Execute the test cases that are expected to generate an attack alarm and the test cases that are expected not to generate an attack alarm to simulate attack scenarios and business request scenarios, respectively. Use the obfuscation matrix to quantify the triggering of the RASP protection rule to obtain the test result.

[0020] Optionally, if the test result meets the third preset condition, the effectiveness of the RASP protection rule is verified in a grayscale environment to obtain a grayscale verification result, including:

[0021] If the test results meet the third preset condition, the RASP protection rules are introduced into a portion of the actual business environment. The effectiveness of the RASP protection rules is verified based on the actual situation in the portion of the actual business environment. The effectiveness of the RASP protection rules is then quantified to obtain the grayscale verification results.

[0022] Optionally, if the grayscale verification result meets the fourth preset condition, then individual performance testing and integrated performance testing are performed on the RASP protection rule pair to obtain performance testing results, including:

[0023] If the grayscale verification result meets the fourth preset condition, then the individual performance test is performed on the RASP protection rule pair to obtain the individual performance test result;

[0024] If the individual performance test result meets the sixth preset condition, the RASP protection rule is added to the baseline protection rule set, multiple integrated performance indicators are calculated, and the integrated performance test result is obtained as the performance test result; the multiple integrated performance indicators include system response time indicator, transaction processing capacity indicator, system availability indicator, and resource utilization indicator.

[0025] A second aspect of this application provides a protection rule access control device, the device comprising:

[0026] The protection rule acquisition module is used to acquire RASP protection rules;

[0027] The protection rule admission module is used to detect the RASP protection rule. If the RASP protection rule meets the first preset condition, the RASP rule is deployed to the production environment. The detection includes code detection, validity testing, gray-scale verification, and performance testing.

[0028] Optionally, the protection rule admission module is specifically used for:

[0029] The code of the RASP protection rules is inspected to obtain the code inspection results;

[0030] If the code detection result meets the second preset condition, the RASP protection rule is tested by simulating attack scenarios and business request scenarios to obtain test results;

[0031] If the test results meet the third preset condition, the effectiveness of the RASP protection rule is verified in a grayscale environment to obtain the grayscale verification result.

[0032] If the grayscale verification result meets the fourth preset condition, then individual performance testing and integrated performance testing are performed on the RASP protection rule pair to obtain the performance testing result;

[0033] If the performance test results meet the fifth preset condition, the RASP protection rule will be deployed to the production environment.

[0034] A third aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the protection rule access method provided in any implementation of the first aspect.

[0035] The fourth aspect of this application provides a processor for running a computer program that, when running, executes a protection rule access method as provided in any implementation of the first aspect.

[0036] Compared with the prior art, this application has the following beneficial effects:

[0037] This application provides a protection rule admission method that, through code inspection, validity testing, gray-scale verification, and performance testing of RASP protection rules, deploys RASP rules that meet the first preset conditions to the production environment. This improves network security protection capabilities, enables precise attack defense, enhances the management efficiency of protection rules, shortens the update cycle of protection rules, ensures business continuity and performance stability, avoids negative impacts of protection rules on business and system performance, reduces deployment risks, and optimizes the quality of protection rules based on data-driven approaches to adapt them to complex network security environments, providing enterprises with reliable and secure protection. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0039] Figure 1 A flowchart illustrating a protection rule admission method provided in this application embodiment;

[0040] Figure 2 A flowchart illustrating yet another protection rule access method provided in this application embodiment;

[0041] Figure 3 This is a schematic diagram of a protection rule access device provided in an embodiment of this application. Detailed Implementation

[0042] As described above, the main problems with current RASP protection rule updates are: (1) Low efficiency of protection rule updates. The protection rule update process involves development, testing, and deployment stages. Currently, it mainly relies on human initiative to drive it. Some processes may not be promoted for a long time, resulting in long rule update and deployment cycles and difficulty in responding quickly to emerging security threats. (2) Insufficient accuracy of protection rules. There is a lack of system testing frameworks and methods for RASP protection rules. New rules may not be able to accurately identify attacks, leading to false positives and false negatives, which affects the accuracy of protection rules. (3) Lack of assessment of the impact of protection rules on business. There is a lack of effective risk control measures, which makes the deployment of new rules high-risk, and the impact of new rules on business has not been assessed.

[0043] In view of the above problems, the inventors have proposed a protection rule access method, device, storage medium and processor to obtain RASP protection rules; to detect the RASP protection rules; and to deploy the RASP rules to the production environment if the RASP protection rules meet the first preset conditions; the detection includes code detection, validity testing, gray-scale verification and performance testing.

[0044] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0045] See Figure 1 This figure is a flowchart of a protection rule access method provided in an embodiment of this application. Figure 1 As shown, the method includes the following steps:

[0046] S101. Obtain RASP protection rules.

[0047] S102. The RASP protection rule is tested. If the RASP protection rule meets the first preset condition, the RASP rule is deployed to the production environment.

[0048] The detection includes code detection, validity testing, gray-scale verification, and performance testing.

[0049] The first preset condition refers to the RASP protection rule's detection result being qualified. The RASP protection rule's detection result includes code detection result, validity test result, grayscale verification result, and performance test result.

[0050] Code inspection leverages continuous integration / continuous deployment processes to automate the testing and deployment of rules. It employs an automated testing framework to enable rapid testing and verification of rules, improving response speed and accuracy, as well as testing efficiency and deployment speed.

[0051] Effectiveness testing involves testing RASP protection rules in a simulated environment to ensure that the rules can accurately identify attack behaviors before actual deployment, reducing false positives and false negatives, and improving the accuracy of the rules.

[0052] Gray-scale verification validates RASP protection rules in a gray-scale environment. By analyzing alarms triggered by actual business operations, it assesses the accuracy of RASP protection rules and their impact on business operations.

[0053] Performance testing assesses the impact of RASP protection rules on business applications and server system performance, including alarm trigger volume, false alarm rate, business response time, transaction processing capacity, and system availability. This ensures that the new rules will not negatively affect system stability and performance.

[0054] This application provides a protection rule admission method that, through code inspection, validity testing, gray-scale verification, and performance testing of RASP protection rules, deploys RASP rules that meet the first preset conditions to the production environment. This improves network security protection capabilities, enables precise defense against attacks, enhances the management efficiency of protection rules, shortens the update cycle of protection rules, ensures business continuity and performance stability, avoids negative impacts of protection rules on business and system performance, reduces deployment risks, and optimizes the quality of protection rules based on data-driven approaches to adapt them to complex network security environments, providing enterprises with reliable and secure protection.

[0055] To improve the protection rule admission method described in the above embodiments, the step of "detecting the RASP protection rule and deploying the RASP rule to the production environment if the RASP protection rule meets the first preset condition" has been refined.

[0056] See Figure 2 This figure is a flowchart of another protection rule access method provided in an embodiment of this application. Figure 2 As shown, the method includes the following steps:

[0057] S201. Obtain RASP protection rules.

[0058] Before performing code detection on the RASP protection rules and obtaining the code detection results, the process also includes:

[0059] Obtain the basic information of the RASP protection rules.

[0060] The basic information for RASP protection rules includes the specific threat or attack type they are designed to detect, as well as the expected behavior and triggering conditions of the rule. The specific information required is as follows:

[0061] Basic rule information: The rule's description and purpose, including the specific threat or attack type it aims to detect; the rule's logic and conditions to simulate the attack behavior that triggers the rule. Ensure that the specific threat or attack type the rule aims to detect is clearly defined.

[0062] Detailed interface and parameter information: Developers are required to provide detailed information about the API or system call, including the interface name, input parameter types, expected output parameter types, and the range of valid and invalid values ​​for the parameters.

[0063] Pre-trigger condition specification: Developers are required to specify the specific conditions for triggering rules, including logical conditions and environmental factors, as well as the application class methods expected to be triggered when the rule is triggered.

[0064] Attack scenarios and test cases: Developers are required to provide a series of detailed attack scenarios and specific test cases, including attack steps, expected attack results, and expected log output.

[0065] The rules define the specific threat or attack types they detect, along with the rule's logic and conditions, to simulate the attack behavior that triggers the rule. Ensure that the specific threat or attack types the rules are intended to detect are clearly defined.

[0066] The following is an example of basic information for RASP protection rules:

[0067]

[0068]

[0069]

[0070] S202. The code of the RASP protection rule is detected to obtain the code detection result.

[0071] In one feasible implementation:

[0072] Static analysis is performed on the code of the RASP protection rules to obtain static analysis results; the static analysis includes code quality testing.

[0073] If the static detection result indicates that the code of the RASP protection rule is qualified, test cases are automatically generated, and the test cases are used to dynamically detect the code of the RASP protection rule, and the dynamic detection result is used as the code inspection result.

[0074] There are no restrictions on the static analysis methods here. For example, you can use PMD to detect consistency issues, potential errors, and potential performance problems in the code; Checkstyle to check for non-standard parts in the code; or SpotBugs to detect potential errors and security vulnerabilities in the code.

[0075] By automating code style standardization, errors and potential defects are detected in the code. This identifies potential security vulnerabilities, coding errors, logical flaws, and defects that could cause system crashes. The code is then configured to conform to specific coding standards, ensuring consistency in code style and structure, and facilitating later maintenance of protection rules. Furthermore, identifying problems early in development reduces later testing workload, improves rule development efficiency, and lowers testing costs.

[0076] After the protection rules pass static code analysis, tools such as EvoSuit and Spring Boot Mock are used to dynamically generate n test cases based on different testing strategies, such as equivalence class partitioning and boundary value analysis, to perform dynamic code analysis on the code logic of the protection rules.

[0077] The following is a typical example of dynamic test information:

[0078] testCases contains multiple test cases, each designed to test different input scenarios.

[0079] input: Defines the input parameters for the test, such as user input.

[0080] expected: Defines the expected output, including whether the target is vulnerable and error messages.

[0081] Mocks: Define the methods that need to be mocked, as well as the expected behavior and parameters.

[0082] `callRecords`: This is an array used to record the call parameters and their order for each mock method. During test execution, this array will be populated with the actual call parameters.

[0083] `expectedCallOrder`: This is an array that defines the expected order of method calls. This array will be used after the test to verify whether the actual call order matches the expectation.

[0084] callSequenceCheck: This is a boolean value that indicates whether call order verification is required.

[0085]

[0086]

[0087]

[0088]

[0089] Based on the protection rule information provided by the protection rule developer, automated production covers the input scenarios of the entire testing strategy, including edge cases and abnormal cases. During the testing process, the parameters and calling order of these simulated methods are recorded to verify whether the test object is called in the correct order and according to the expected parameters.

[0090] By executing defined test cases, the actual call parameters and order are recorded and compared with the expected results. If the results match the expectations, the test case passes; otherwise, a detailed error report and correction suggestions are provided so that developers can promptly modify the rule code. If all test cases pass, the RASP protection rule code passes dynamic detection; otherwise, it fails, and the process is returned to the user for modification. Once the user modifies the rules, the above process is triggered again.

[0091] Automated test case generation reduces human error introduced by manually writing test cases, improving the accuracy of code inspection. It ensures that RASP protection rules undergo rigorous quality control and security verification before actual operation, thereby enhancing the reliability and effectiveness of protection rules and reducing security risks in the production environment.

[0092] S203. If the code detection result meets the second preset condition, the RASP protection rule is tested by simulating attack scenarios and business request scenarios to obtain test results.

[0093] In one feasible implementation:

[0094] If the code detection result meets the second preset condition, create a test case that is expected to generate an attack alarm and a test case that is expected not to generate an attack alarm. Execute the test cases that are expected to generate an attack alarm and the test cases that are expected not to generate an attack alarm to simulate attack scenarios and business request scenarios, respectively. Use the obfuscation matrix to quantify the triggering of the RASP protection rule to obtain the test result.

[0095] The second preset condition refers to the code inspection result being qualified, which means that the code of the RASP protection rule passes dynamic detection.

[0096] The intended use cases for generating attack alerts are based on the developer's protection rule information. Requests marked as attacks by the security alert platform are matched, and test cases containing malicious payloads are generated by randomly modifying the non-payload content of the requests. For example, in an SQL injection scenario, two requests marked as "SQL injection attack" are found in the security alert platform. The payload is "id=-1'or 1=1#", a basic boolean SQL injection payload, and "id=-1'+or+1=1+%23", a URL-encoded payload used to test URL-encoded SQL injection. The requests are modified and sent to the application to verify whether the RASP protection rules can accurately identify and respond to these attack patterns.

[0097] For use cases that are not expected to generate attack alerts, test cases are generated by randomly modifying requests that are not marked as attacks by the security alert information platform. For example, id=1 is a normal user request that does not contain any attack characteristics. These test cases verify whether the RASP protection rules will generate false alarms for normal business operations, thereby assessing the accuracy of the rules and their impact on business.

[0098] The following is a typical test case, containing two expected attacks and two expected non-attacks:

[0099]

[0100]

[0101] Based on dynamically generated "expected attack alert use cases" and "expected non-attack alert use cases", the detection capability of RASP protection rules can be comprehensively tested, ensuring that RASP protection rules can accurately identify attacks before deployment and avoid interfering with normal business processes, thereby maintaining business continuity and efficiency while ensuring system security.

[0102] To more effectively evaluate the effectiveness of RASP protection rules, understand their actual performance in an objective and quantitative way, and accurately measure their performance, this study compares the detection results of actual RASP protection rules with dynamically generated "expected attack alert use cases" and "expected non-attack alert use cases." A confusion matrix is ​​used to quantify the effectiveness of RASP protection rules. Specifically, the method for quantifying the effectiveness of RASP protection rules using a confusion matrix is ​​as follows:

[0103] Define the true positive (TP), false positive (FP), false negative (FN), and true negative (TN) in the confusion matrix.

[0104] TP refers to the RSAP protection rules correctly identifying attack instances. A high TP rate indicates that the security system can efficiently and reliably identify and respond to actual attacks, which is a direct indicator of the effectiveness of RSAP protection rules.

[0105] FP refers to the fact that RASP protection rules identify non-attack instances as attack instances, which may lead to "alarm fatigue" and make security systems slow to respond to real threats. This is because they may treat real alerts as false alarms, wasting resources and time. Furthermore, since RASP protection rules have the ability to intercept, they may have an impact on production applications.

[0106] FN refers to RSAP protection rules identifying attack instances as non-attack instances. Failure to report such instances may lead to security vulnerabilities being overlooked, thereby increasing the risk of data leakage or system damage.

[0107] TN refers to correctly identifying non-attack instances. A high TN ratio indicates that the security system has high specificity and will not generate false alarms for normal behavior, thereby reducing interference with business processes.

[0108] In production systems, the order of impact on production stability from largest to smallest is: FP, TP, TN, FN. Considering the impact of RASP protection rules on business operations, the impact on normal business should be minimized as much as possible, i.e., a certain amount of false negatives should be tolerated, while false positives should be reduced as much as possible.

[0109] Therefore, the availability of RASP protection rules is calculated using a weighted F1 score. In this embodiment, a weighted F1 score is used to determine the availability of RASP protection rules, and a threshold for the F1 score is set. For example, if the F1 score is greater than 0.99, the RASP protection rule meets the deployment conditions on the detection logic side.

[0110] The formula for calculating the weighted F1 score is as follows:

[0111]

[0112] Where β is the weighting factor, Precision is the precision, and Recall is the recall. Considering that Precision has a greater impact, β is set to 0.2.

[0113] Precision is the ratio of TP to (TP+FP), and recall is the ratio of TP to (TP+FN).

[0114] The weighted F1 score F1_weighted is compared with a preset threshold. If the weighted F1 score is lower than the preset threshold, the test result of the RASP protection rule is unqualified; if the weighted F1 score is higher than or equal to the preset threshold, the test result of the RASP protection rule is qualified.

[0115] For example, the "SQL injection rule" is tested. Based on requests marked as "SQL injection attacks" by the security alert information platform, 100 attack test cases are randomly generated; based on requests not marked as attacks by the security alert information platform, 100 normal business test cases are randomly generated. Among them, 90 attack test cases are correctly identified as attacks, 10 attack tests are incorrectly identified as non-attacks, 100 non-attack samples are correctly identified as non-attacks, and 0 non-attack samples are incorrectly identified as attack tests, i.e., TP=90, FN=10, FP=0, TN=100.

[0116] Precision = 1, Recall = 0.9.

[0117] When β = 0.2, F1 ≈ 0.996 > 0.99.

[0118] By quantifying the effectiveness of RASP protection rules using a confusion matrix, it ensures that only those RASP protection rules that meet preset thresholds are included in subsequent processes, thereby improving overall security capabilities. This data-driven evaluation method provides security systems with a scientific approach to optimize and adjust RASP protection rules to adapt to the ever-changing network threat environment.

[0119] S204. If the test result meets the third preset condition, the effectiveness of the RASP protection rule is verified in a grayscale environment to obtain the grayscale verification result.

[0120] In one feasible implementation:

[0121] If the test results meet the third preset condition, the RASP protection rules are introduced into a portion of the actual business environment. The effectiveness of the RASP protection rules is verified based on the actual situation in the portion of the actual business environment. The effectiveness of the RASP protection rules is then quantified to obtain the grayscale verification results.

[0122] The third preset condition refers to the test result being qualified. The qualified test result means that the weighted F1 score obtained by quantifying the triggering of the RASP protection rule using the confusion matrix is ​​higher than or equal to the preset threshold of the weighted F1 score.

[0123] The effectiveness of the RASP protection rules was quantified, and the grayscale verification results were obtained as follows:

[0124] Based on 1 million logs generated by the business over d days, the triggering of RASP protection rules was statistically observed, resulting in a total of m alarms. Among them, manual analysis of the triggering situation revealed that n alarms did not meet expectations. If m is less than or equal to 10d and n is less than or equal to 10, the rule is approved. Otherwise, the designed score calculation formula is used to determine whether the rule is approved.

[0125] The formula for calculating the design score S is:

[0126] When m≤10d and n≤10, the RASP protection rule passes the test with a score of S=100.

[0127] When m > 10d, the pass rate decreases rapidly as m increases; when n > 10, the probability of failure increases dramatically as n increases. That is, when m > 10d or n > 10:

[0128] S = 100 × e -(m-10d) / k1 ×e -(n-10) / k2 ;

[0129] For example, the threshold of S is set to 80:

[0130] If k1 = 100, k2 = 10, d = 10, m = 120, n = 10

[0131] Then S = 100 × e -20 / 100 ×e 0 ≈81.87>80, the grayscale verification result of this RASP protection rule is passed.

[0132] If k1 = 100, k2 = 10, d = 10, m = 100, n = 20,

[0133] Then S = 100 × e 0 ×e -10 / 10 ≈36.79<80, the grayscale verification result of this RASP protection rule is "failed".

[0134] The above method quantifies the performance of RASP protection rules in a gray-scale environment, ensuring that only RASP protection rules meeting specific thresholds can proceed to subsequent stages. This approach involves deploying RASP protection rules in a subset of systems first, collecting real-time data on rule performance without impacting the entire production environment. Validating the rules in the gray-scale environment, by analyzing alarms triggered by actual business operations, assesses the accuracy of the rules and their business impact. This method not only reduces the risk of RASP protection rules affecting production but also identifies and corrects potential problems before full deployment, reducing the probability of non-compliant rules entering benchmark testing and lowering testing costs.

[0135] S205. If the grayscale verification result meets the fourth preset condition, then perform individual performance testing and integrated performance testing on the RASP protection rule pair to obtain the performance testing result.

[0136] In one feasible implementation:

[0137] If the grayscale verification result meets the fourth preset condition, then the individual performance test is performed on the RASP protection rule pair to obtain the individual performance test result;

[0138] If the individual performance test result meets the sixth preset condition, the RASP protection rule is added to the baseline protection rule set, multiple integrated performance indicators are calculated, and the integrated performance test result is obtained as the performance test result.

[0139] The integrated performance metrics include system response time, transaction processing capacity, system availability, and resource utilization.

[0140] The fourth preset condition refers to the grayscale verification result being qualified. The qualified grayscale verification result means that the effectiveness of the RASP protection rule is verified based on the actual situation in the actual business environment, and the score obtained by quantifying the effectiveness of the RASP protection rule is greater than or equal to the preset threshold of the score.

[0141] Individual performance testing includes single-rule testing and passing threshold determination.

[0142] Single rule testing involves performing performance tests on each rule in the RASP protection rules individually, running it under a stress test environment for 7 days to evaluate its impact on system performance.

[0143] The pass threshold determination is to test each rule in the RASP protection rules by setting a performance pass threshold. If the test result of each rule does not reach the set performance pass threshold, the rule will not pass the acceptance.

[0144] The sixth preset condition refers to the individual performance test result being qualified. The individual performance test result being qualified means that the single rule test is passed and the passing threshold is determined.

[0145] Integrated performance testing includes rule set integration testing and performance change testing.

[0146] Rule set integration testing involves integrating RASP rules that have passed individual performance testing into a rule set, running it under a stress test environment for 15 days, and obtaining the rule set integration test results.

[0147] The performance change test examines whether the performance metrics of the rule set integrated with RASP protection rules exceed the corresponding performance thresholds. If any performance metric exceeds the corresponding performance threshold, the integration performance test fails. If all performance metrics do not exceed the corresponding performance thresholds, the performance change rate of each performance metric is calculated based on the baseline value of the rule set before integrating RASP protection rules, and the performance change test results are obtained.

[0148] The formula for calculating the rate of change in performance is:

[0149] Performance change rate = (Performance index of test baseline rule set - Performance index of baseline rule set) / Performance index of baseline rule set × 100%.

[0150] If the performance change rate of each performance metric is less than or equal to the performance change rate threshold, the RASP protection rule passes the performance change test, is added to the "baseline rule set," and the "baseline rule set performance metrics" are updated.

[0151] New baseline rule set performance metrics = (baseline rule set performance metrics + test performance metrics) / 2.

[0152] The system response time metric uses the application system's TP9999 (99.99% request response time) as the indicator. For example, the performance threshold for the system response time metric is 200 milliseconds, and the baseline rule set system response time value does not exceed 100 milliseconds.

[0153] The transaction processing capacity metric is the number of transactions (TPS) that the system can process per unit of time. For example, the performance threshold for the transaction processing capacity metric is 2000 TPS, and the transaction processing capacity of the baseline rule set is no less than 3000 TPS.

[0154] The system availability metric is the ratio of the time the system can operate normally within a preset time to the preset time. For example, the performance threshold of the system availability metric is 99.9%, and the percentage of normal uptime for the baseline rule set system availability is less than 99.99%.

[0155] Resource utilization is the ratio of the time during which the system's CPU, memory, and disk are in good condition (CPU and memory utilization not exceeding 70%, and disk utilization not exceeding 90%) to the specified time. For example, the performance threshold for resource utilization is 80%, and the baseline rule set requires that the proportion of good system availability operation time is not less than 70%.

[0156] By conducting performance tests on RASP protection rules, we can ensure that while improving network security, the RASP protection rules will not negatively impact business performance, thus achieving a balance between security and efficiency.

[0157] S206. If the performance test result meets the fifth preset condition, then the RASP protection rule is deployed to the production environment.

[0158] The fifth preset condition refers to the performance impact result being qualified. The qualified performance test result means that both the rule set integration test result and the performance change test result in the integrated performance test result are qualified.

[0159] In one feasible implementation:

[0160] RASP protection rules will be deployed in phases. They will first be deployed on non-core systems within the intranet, then gradually expanded to non-core internet systems, core intranet systems, and finally to core internet systems. The deployment process will employ a multi-batch, multi-window approach, deploying RASP protection rules sequentially at 10%, 30%, 60%, and 100% coverage rates.

[0161] 10% Deployment: During the first window period, i.e., the first day after deployment begins, deploy 10% of the RASP protection rules to the production environment.

[0162] 30% Deployment: During the second window, i.e., the third day after the first day, expand the deployment to 30% of the production environment.

[0163] 60% Deployment: In the third window, which is the first week after day 3, the deployment will be further expanded to 60% of the production environment.

[0164] 100% Deployment: In the fourth window, i.e. the second week after the first week, complete the remaining 40% of the deployment to achieve full deployment.

[0165] Throughout the deployment process, the systems involved in the deployment are monitored in real time to ensure that the performance of the RASP protection rules meets expectations. The number of false alarms triggered by the RASP protection rules is monitored to ensure that the false alarm rate is kept within an acceptable range. Once the abnormal alarm exceeds the threshold or a manual rollback is initiated, further deployment of the RASP protection rules is immediately stopped, and the deployed rules are rolled back as needed.

[0166] The deployment adopts a phased, multi-batch, and multi-window approach, gradually expanding from non-core intranet systems to core internet systems. Real-time monitoring is implemented with thresholds for false alarms and alarms, combined with manual analysis to ensure business continuity and system stability. Problem rules are optimized and retested.

[0167] This application provides another method for admitting protection rules. By performing code inspection, validity testing, gray-scale verification, and performance testing on RASP protection rules, RASP rules that meet the first preset conditions are deployed to the production environment. This improves network security protection capabilities, enables precise defense against attacks, enhances the management efficiency of protection rules, shortens the update cycle of protection rules, ensures business continuity and performance stability, avoids negative impacts of protection rules on business and system performance, reduces deployment risks, and optimizes the quality of protection rules based on data-driven approaches to adapt them to complex network security environments, providing enterprises with reliable and secure protection.

[0168] Based on the protection rule access method described in the preceding embodiments, this application also provides a protection rule access device. Figure 3 This is a schematic diagram of the device. Figure 3 As shown, the protection rule access control device includes:

[0169] The protection rule acquisition module 301 is used to acquire RASP protection rules.

[0170] The protection rule admission module 302 is used to detect the RASP protection rule. If the RASP protection rule meets the first preset condition, the RASP rule is deployed to the production environment. The detection includes code detection, validity testing, gray-scale verification and performance testing.

[0171] Optionally, the protection rule admission module is specifically used for:

[0172] The code of the RASP protection rules is inspected to obtain the code inspection results;

[0173] If the code detection result meets the second preset condition, the RASP protection rule is tested by simulating attack scenarios and business request scenarios to obtain test results;

[0174] If the test results meet the third preset condition, the effectiveness of the RASP protection rule is verified in a grayscale environment to obtain the grayscale verification result.

[0175] If the grayscale verification result meets the fourth preset condition, then individual performance testing and integrated performance testing are performed on the RASP protection rule pair to obtain the performance testing result;

[0176] If the performance test results meet the fifth preset condition, the RASP protection rule will be deployed to the production environment.

[0177] The code detection of the RASP protection rules, and the resulting code detection results, include:

[0178] Static analysis is performed on the code of the RASP protection rules to obtain static analysis results; the static analysis includes code quality testing.

[0179] If the static detection result indicates that the code of the RASP protection rule is qualified, test cases are automatically generated, and the test cases are used to dynamically detect the code of the RASP protection rule, and the dynamic detection result is used as the code detection result.

[0180] Optionally, if the code detection result meets the second preset condition, the RASP protection rule is tested by simulating attack scenarios and business request scenarios to obtain test results, including:

[0181] If the code detection result meets the second preset condition, create a test case that is expected to generate an attack alarm and a test case that is expected not to generate an attack alarm. Execute the test cases that are expected to generate an attack alarm and the test cases that are expected not to generate an attack alarm to simulate attack scenarios and business request scenarios, respectively. Use the obfuscation matrix to quantify the triggering of the RASP protection rule to obtain the test result.

[0182] Optionally, if the test result meets the third preset condition, the effectiveness of the RASP protection rule is verified in a grayscale environment to obtain a grayscale verification result, including:

[0183] If the test results meet the third preset condition, the RASP protection rules are introduced into a portion of the actual business environment. The effectiveness of the RASP protection rules is verified based on the actual situation in the portion of the actual business environment. The effectiveness of the RASP protection rules is then quantified to obtain the grayscale verification results.

[0184] Optionally, if the grayscale verification result meets the fourth preset condition, then individual performance testing and integrated performance testing are performed on the RASP protection rule pair to obtain performance testing results, including:

[0185] If the grayscale verification result meets the fourth preset condition, then the individual performance test is performed on the RASP protection rule pair to obtain the individual performance test result;

[0186] If the individual performance test result meets the sixth preset condition, the RASP protection rule is added to the baseline protection rule set, multiple integrated performance indicators are calculated, and the integrated performance test result is obtained as the performance test result; the multiple integrated performance indicators include system response time indicator, transaction processing capacity indicator, system availability indicator, and resource utilization indicator.

[0187] Furthermore, embodiments of this application also provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the protection rule access method as described in any of the method embodiments.

[0188] Furthermore, this application embodiment also provides a processor for running a computer program, which executes the protection rule access method as described in any of the foregoing method embodiments.

[0189] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments. The device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separate. The components indicated as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment solution according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0190] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for granting access based on protection rules, characterized in that, include: Obtain RASP protection rules; The RASP protection rules are tested. If the RASP protection rules meet the first preset conditions, the RASP rules are deployed to the production environment. The testing includes code inspection, validity testing, gray-scale verification, and performance testing.

2. The method according to claim 1, characterized in that, The step of detecting the RASP protection rule, and if the RASP protection rule meets the first preset condition, then deploying the RASP rule to the production environment, includes: The code of the RASP protection rules is inspected to obtain the code inspection results; If the code detection result meets the second preset condition, the RASP protection rule is tested by simulating attack scenarios and business request scenarios to obtain test results; If the test results meet the third preset condition, the effectiveness of the RASP protection rule is verified in a grayscale environment to obtain the grayscale verification result. If the grayscale verification result meets the fourth preset condition, then individual performance testing and integrated performance testing are performed on the RASP protection rule pair to obtain the performance testing result; If the performance test results meet the fifth preset condition, the RASP protection rule will be deployed to the production environment.

3. The method according to claim 2, characterized in that, The code detection of the RASP protection rules, and the resulting code detection results, include: Static analysis is performed on the code of the RASP protection rules to obtain static analysis results; the static analysis includes code quality testing. If the static detection result indicates that the code of the RASP protection rule is qualified, test cases are automatically generated, and the test cases are used to dynamically detect the code of the RASP protection rule, and the dynamic detection result is used as the code detection result.

4. The method according to claim 2, characterized in that, If the code detection result meets the second preset condition, the RASP protection rule is tested by simulating attack scenarios and business request scenarios to obtain test results, including: If the code detection result meets the second preset condition, create a test case that is expected to generate an attack alarm and a test case that is expected not to generate an attack alarm. Execute the test cases that are expected to generate an attack alarm and the test cases that are expected not to generate an attack alarm to simulate attack scenarios and business request scenarios, respectively. Use the obfuscation matrix to quantify the triggering of the RASP protection rule to obtain the test result.

5. The method according to claim 2, characterized in that, If the test result meets the third preset condition, the effectiveness of the RASP protection rule is verified in a grayscale environment to obtain a grayscale verification result, including: If the test results meet the third preset condition, the RASP protection rules are introduced into a portion of the actual business environment. The effectiveness of the RASP protection rules is verified based on the actual situation in the portion of the actual business environment. The effectiveness of the RASP protection rules is then quantified to obtain the grayscale verification results.

6. The method according to claim 2, characterized in that, If the grayscale verification result meets the fourth preset condition, then individual performance testing and integrated performance testing are performed on the RASP protection rule pair to obtain performance testing results, including: If the grayscale verification result meets the fourth preset condition, then the individual performance test is performed on the RASP protection rule pair to obtain the individual performance test result; If the individual performance test result meets the sixth preset condition, the RASP protection rule is added to the baseline protection rule set, multiple integrated performance indicators are calculated, and the integrated performance test result is obtained as the performance test result; the multiple integrated performance indicators include system response time indicator, transaction processing capacity indicator, system availability indicator, and resource utilization indicator.

7. A protection rule access control device, characterized in that, include: The protection rule acquisition module is used to acquire RASP protection rules; The protection rule admission module is used to detect the RASP protection rule. If the RASP protection rule meets the first preset condition, the RASP rule is deployed to the production environment. The detection includes code detection, validity testing, gray-scale verification, and performance testing.

8. The apparatus according to claim 7, characterized in that, The protection rule access module is specifically used for: The code of the RASP protection rules is inspected to obtain the code inspection results; If the code detection result meets the second preset condition, the RASP protection rule is tested by simulating attack scenarios and business request scenarios to obtain test results; If the test results meet the third preset condition, the effectiveness of the RASP protection rule is verified in a grayscale environment to obtain the grayscale verification result. If the grayscale verification result meets the fourth preset condition, then individual performance testing and integrated performance testing are performed on the RASP protection rule pair to obtain the performance testing result; If the performance test results meet the fifth preset condition, the RASP protection rule will be deployed to the production environment.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the protection rule access method as described in any one of claims 1-6.

10. A processor, characterized in that, Used to run a computer program, which executes the protection rule access method as described in any one of claims 1-6 when it runs.