Network system defense method and device, storage medium and electronic equipment
By determining and adjusting the weight values of defense strategies in the network system, simulating attack behavior, and optimizing the defense mechanism, the problem of low network system security in existing technologies is solved, and more efficient network attack defense is achieved.
Patent Information
- Application Number
- CN202511194456.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-25
- Publication Date
- 2025-11-07
AI Technical Summary
In the existing network security architecture, firewalls and IDS rely on preset rule bases that cannot be updated in a timely manner, resulting in an inability to effectively defend against the complexity and stealth of modern network attacks, and thus low network system security.
By determining the defense weight values of candidate defense strategies, running the target defense strategy and calculating the evaluation value, and simulating network attacks, the defense strategy weights are adjusted to optimize the defense mechanism and adapt to different network attacks.
It improves the defense effectiveness of network systems, enabling continuous updates to defense strategies based on actual and simulated assessment results, thereby enhancing the adaptability and effectiveness against network attacks.
Smart Images

Figure CN120915565A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of artificial intelligence, in particular to a network system defense method and device, a storage medium and an electronic device. BACKGROUND
[0002] With the continuous expansion of network transactions and data processing scale, financial institutions are facing unprecedented network security challenges. Especially for the network penetration attacks on its core business systems, such as SQL injection, cross-site scripting (XSS) and port scanning, these attacks not only can quickly find and exploit system vulnerabilities, but also may long-term lurk without being detected, posing a serious threat to data security and business continuity. In the high-value financial transaction environment, attackers often take more covert and complex means to try to evade the monitoring of traditional defense mechanisms.
[0003] In the network security architecture of the prior art, the network environment is protected by preventing unauthorized access and monitoring abnormal traffic through firewalls and intrusion detection systems (IDS). However, firewalls and IDS rely on pre-set rule libraries to identify attacks, and in the face of the complexity and concealment of modern network attacks, the rule library often cannot be updated in time, resulting in defense failure.
[0004] In view of the low security of the network system in the related art, no effective solution has been proposed so far. SUMMARY
[0005] The main purpose of the present application is to provide a network system defense method and device, a storage medium and an electronic device to solve the problem of low security of the network system in the related art.
[0006] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a network system defense method is provided. The method comprises: in the case that the network system is subjected to a network attack, determining at least one candidate defense strategy each corresponding to a defense weight value, wherein the defense weight matches the type of the network attack; running a target defense strategy and calculating a first evaluation value of the target defense strategy, wherein the target defense strategy is the candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate the defense coverage value of executing the target defense strategy; simulating the network attack and calculating a second evaluation value corresponding to each of the at least one candidate defense strategy, wherein the second evaluation value is used to indicate the defense coverage value of executing the candidate defense strategy; and increasing the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and at least one second evaluation value.
[0007] In order to achieve the above object, according to another aspect of the present application, a defense device of a network system is provided. The device comprises: a weight determining unit configured to determine a defense weight value corresponding to each of at least one candidate defense strategy in a case where the network system is subjected to a network attack, wherein the defense weight matches a type of the network attack; a strategy executing unit configured to run a target defense strategy and calculate a first evaluation value of the target defense strategy, wherein the target defense strategy is a candidate defense strategy corresponding to a maximum defense weight value, and the first evaluation value is used to indicate a defense coverage value of executing the target defense strategy; a simulation unit configured to simulate the network attack and calculate a second evaluation value corresponding to each of the at least one candidate defense strategy, wherein the second evaluation value is used to indicate a defense coverage value of executing the candidate defense strategy; and a weight adjusting unit configured to increase the defense weight value of the candidate defense strategy corresponding to a maximum value among the first evaluation value and the at least one second evaluation value.
[0008] Optionally, the weight determining unit comprises: a data obtaining module configured to obtain a reference data set of the network system, wherein the reference data set is used to indicate an access record of the network system; an attack identifying module configured to determine that the network system is subjected to the network attack in a case where reference data in the reference data set meets a preset defense condition; and a weight determining module configured to determine the defense weight value corresponding to each of the at least one candidate defense strategy.
[0009] Optionally, the attack identifying module is further configured to: determine that the network system is subjected to the network attack in a case where a target interface is accessed, wherein the target interface is used to indicate an interface that needs to be accessed in a preset access manner; determine that the network system is subjected to the network attack in a case where an access parameter included in an access instruction of a reference interface exceeds a reference access parameter corresponding to the reference interface; determine that the network system is subjected to the network attack in a case where an access time of the reference interface does not meet a reference access time corresponding to the reference interface; determine that the network system is subjected to the network attack in a case where an access device of the reference interface does not meet a reference access device corresponding to the reference interface; determine that the network system is subjected to the network attack in a case where an access frequency of the reference interface is greater than a preset frequency; determine that the network system is subjected to the network attack in a case where a time interval of multiple accesses of the reference interface is less than a preset time interval; and determine that the network system is subjected to the network attack in a case where an access address change frequency of the multiple accesses of the reference interface is greater than a preset change frequency.
[0010] Optionally, the data obtaining module is further configured to: determine a data packet received and sent by the network system as the reference data; record a state of at least one application program running in the network system as the reference data; and determine log data generated in the network system as the reference data.
[0011] Optionally, the policy execution unit comprises a first policy execution module configured to increase the response frequency of the network system in the case of receiving a network attack; generate a reference response according to the network attack in the case of receiving a network attack on the application, wherein the reference response is a response generated according to the response format of the application; and send a notification response in the case of receiving a network attack, wherein the notification response is used to indicate that the network system has a running error.
[0012] Optionally, the policy execution unit further comprises: in the case of receiving a network attack, prohibiting access of a sending account of the network attack; and in the case of receiving a network attack, prohibiting access of a sending end address of the network attack.
[0013] In the embodiments of the present application, in the case of a network attack on the network system, the defense weight values corresponding to the at least one candidate defense strategy are determined, wherein the defense weight values match the types of the network attack; the target defense strategy is run, and a first evaluation value of the target defense strategy is calculated, wherein the target defense strategy is the candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate the defense coverage value of executing the target defense strategy; the network attack is simulated, and second evaluation values corresponding to the at least one candidate defense strategy are respectively calculated, wherein the second evaluation values are used to indicate the defense coverage values of executing the candidate defense strategies; and the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and the at least one second evaluation value is increased. In the case of facing a network attack, the corresponding defense strategy can be selected according to the weight for different network attacks, and after each attack, a simulated attack can be performed to update the weight of the defense strategy, so that the defense mode for different network attacks is constantly updated. Thus, the technical problem of low security of the network system is solved. BRIEF DESCRIPTION OF DRAWINGS
[0014] The accompanying drawings, which form a part of the present application, are intended to provide further understanding of the present application, and are used to interpret the illustrative embodiments of the present application and their descriptions, and do not constitute improper limitations to the present application. In the drawings:
[0015] Figure 1 Fig. 1 shows a hardware structure block diagram of a computer terminal for implementing a defense method of a network system;
[0016] Figure 2 Fig. 2 is a flowchart of a defense method of a network system according to an embodiment of the present application;
[0017] Figure 3 Fig. 3 is a schematic diagram of a defense device of a network system according to an embodiment of the present application;
[0018] Figure 4 Fig. 4 is a structure block diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0019] In order to make the personnel in the technical field better understand the scheme of the present application, the technical scheme in the embodiments of the present application will be clearly and completely described below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative labor should fall within the scope of protection of the present application.
[0020] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product, or device including a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0021] It should be noted that the collected information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for display, analyzed data, etc.) involved in the present application are information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of related data comply with relevant laws, regulations and standards, necessary security measures are taken, do not violate public order and good customs, and provide corresponding operation portal for user to choose authorization or refusal. For example, interfaces are provided between the system and related users or institutions to provide corresponding operation portals for users to choose to agree or refuse automatic decision results; if the user chooses to refuse, the expert decision process is entered.
[0022] Embodiment 1
[0023] According to the embodiments of the present application, a method embodiment for defense of a network system is also provided. It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.
[0024] The method embodiment provided by the embodiment of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device.Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing the defense method of the network system is shown. As shown in Figure 1 The computer terminal 10 (or mobile device) can include one or more processors 102 (the processor 102 can include but not limited to a microprocessor MCU or a programmable logic device FPGA processing device, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it can also include a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports in the BUS bus), a network interface, a power supply and / or a camera. Those skilled in the art can understand that Figure 1 The structure shown is only schematic, which does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 can also include more or less components than Figure 1 The structure shown is only schematic, which does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 can also include more or less components than Figure 1 The structure shown is only schematic, which does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 can also include more or less components than
[0025] It should be noted that the one or more processors 102 and / or other data processing circuits described above can be referred to herein as "data processing circuits" in general. The data processing circuit can be embodied in whole or in part as software, hardware, firmware or any combination thereof. In addition, the data processing circuit can be a single independent processing module, or any one of the other elements combined into the computer terminal 10 (or mobile device) in whole or in part. As referred to in the embodiments of the present application, the data processing circuit is a processor control (for example, the selection of the variable resistance terminal path connected with the interface).
[0026] The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the defense method of the network system in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the defense method of the network system described above. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 can further include a memory remotely disposed with respect to the processor 102, which can be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network and a combination thereof.
[0027] The transmission device 106 is configured to receive or send data via a network. The network can include, for example, a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network interface controller (NIC) that can connect to other network devices through a base station to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module that is configured to communicate with the Internet wirelessly.
[0028] The display can be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with the user interface of the computer terminal 10 (or mobile device).
[0029] In the above operating environment, the present application provides a defense method for a network system as shown in Figure 2 Figure 2 is a flowchart of a defense method for a network system according to an embodiment of the present application.
[0030] At step S101, in the case where the network system is under a network attack, determine a defense weight value corresponding to each of at least one candidate defense strategy, wherein the defense weight matches the type of the network attack;
[0031] It should be noted that the candidate defense strategy is a series of possible defense measures prepared by the system in advance when facing a network attack, and each strategy has different design and implementation mechanisms for different types or levels of network attacks.
[0032] The defense weight value is a numerical value assigned to each defense strategy, reflecting the priority and effectiveness of the strategy when facing a specific network attack. The higher the defense weight value, the more likely the strategy will be considered first in the defense decision.
[0033] In an optional implementation, in the initial stage of detecting a network attack, the specific type of attack is identified, and the corresponding defense weight values are assigned to a series of preset candidate defense strategies according to the information. The setting of these weight values takes into account the defense effect of different strategies on a specific attack type, so that the most suitable strategy for the current attack situation can be quickly selected from a large number of defense options.
[0034] When the network system is attacked, the characteristics of the attack behavior are first identified through various detection mechanisms, including but not limited to SQL injection, brute force cracking, port scanning, etc. Next, according to the detection results, the list of candidate defense strategies and their respective defense weights that match the attack type are read from the database. These strategies can include, but are not limited to, response camouflage, attack blocking, traffic control, encryption enhancement, etc.
[0035] The defense weight setting reflects the security team's confidence level and historical performance in countering specific attacks with different strategies. For example, for SQL injection attacks, a decoy response might have a higher defense weight because it can both confuse the attacker and provide time to analyze attack details, which can be more sophisticated and effective than simply blocking the IP.
[0036] In step S102, the target defense strategy is executed, and a first evaluation value of the target defense strategy is calculated, wherein the target defense strategy is the candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate a defense coverage value of executing the target defense strategy.
[0037] It should be noted that the target defense strategy is the best strategy to deal with a specific attack behavior among a series of candidate defense strategies according to certain evaluation criteria or weights. The target defense strategy refers to the strategy with the maximum defense weight, which is considered to be the most likely effective strategy against the current attack. The first evaluation value is a quantitative indicator of the defense effect of the system after executing the target defense strategy, usually represented as a defense coverage rate, which is used to reflect the degree of attack prevention by the strategy.
[0038] In an optional implementation, the candidate defense strategy with the maximum defense weight value is selected as the target defense strategy. Those strategies that have performed well in the past and can effectively prevent similar attacks will be given priority. While executing the target defense strategy, relevant defense data will be collected and analyzed, including the number of attack attempts, the number of successful defenses, and the efficiency of defense strategy execution. Based on these data, the first evaluation value of the target defense strategy, i.e., the defense coverage rate, is calculated. This value reflects the proportion of successful defense of attacks after executing the target defense strategy, thereby providing intuitive feedback on the effectiveness of the strategy.
[0039] For example, if it is monitored that during the execution of the target defense strategy, 95 out of 100 attack attempts are successfully defended, then the first evaluation value, i.e., the defense coverage rate, will be 95%. This provides valuable insights for the security team on the effectiveness of the strategy and provides a basis for further optimization and adjustment of the strategy.
[0040] In an optional implementation, the defense coverage rate is specifically calculated, including: during and after the attack defense, network traffic and system logs are continuously monitored to capture any attack behavior that has not been intercepted by defense measures. This includes observing whether there are any abnormal data transmissions, system response anomalies, or unhandled alerts recorded in the security event log. The response behavior and results are recorded in detail. Analyze these logs to confirm whether all identified attack behaviors have been properly responded to and whether there are any signs of bypassing the defense.
[0041] Coverage represents the percentage of attacks that were successfully prevented by the defense, i.e. the number of attacks that were successfully defended divided by the total number of attacks. The data before and after the attack is compared. For example, the number of attempts of attack behavior A before triggering the defense is counted, and the number of attempts that were successfully defended after the implementation of defense strategy A is counted.
[0042] If the total number of attempts of attack A is 200, and 190 of them were successfully defended by defense strategy A, then the defense coverage is 95%.
[0043] Step S103, simulate network attacks, and calculate the second evaluation value corresponding to each of the at least one candidate defense strategy respectively, wherein the second evaluation value is used to indicate the defense coverage value of the candidate defense strategy;
[0044] It should be noted that simulating network attacks is to reproduce known or suspected attack behaviors in a secure controlled environment through automated tools or manual methods, with the purpose of testing and evaluating the defense capability of the system. The second evaluation value can be a quantitative indicator of the defense effect of the candidate defense strategy after its execution in the simulated attack environment, which is specifically represented by the defense coverage value, i.e. the effective interception rate of the strategy.
[0045] In an optional implementation, the network attack behaviors that occurred before are simulated to create a simulated attack scenario. Then, for each possible candidate defense strategy, the defense effect in the simulated attack environment, i.e. the second evaluation value, is calculated, which is indicated by a quantitative indicator (defense coverage value) to indicate the defense capability of the strategy against attacks.
[0046] Specifically, detailed information of previously suffered network attack behaviors can be extracted from the database, including attack types, attack characteristics and attack attempt contexts. Based on the attack samples, a controlled virtual environment is created to safely execute attack simulation without affecting the production system. One or more candidate defense strategies are selected from the database, which can be selected based on previous attack types, frequencies, intensities, etc., or automatically generated by the system according to the latest discovered attack characteristics.
[0047] In the simulation environment, the response of the candidate defense strategy to the simulated attack is tested one by one. This includes observing whether the strategy can correctly identify the attack and whether it can effectively prevent or weaken the impact of the attack. For each candidate defense strategy, the defense coverage value after its execution is calculated. This value can intuitively reflect the defense capability of the strategy against a specific type of attack under ideal conditions, thereby helping the security team or the system to automatically decide and select the most effective strategy for defense.
[0048] Step S104, increasing the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and the at least one second evaluation value.
[0049] It should be noted that after the evaluation of the actual defense effect and the simulated defense effect is completed, if it is found that a candidate defense strategy performs optimally in the first evaluation value (actual defense effect) or the second evaluation value (simulated test effect), that is, the evaluation value is the maximum value, then the weight value of this strategy will be increased. The increase of the weight value means that in the future when encountering similar attacks, the strategy will be more preferentially selected, thereby improving the overall defense effectiveness.
[0050] In an optional embodiment, through continuous attack behavior monitoring and defense strategy evaluation, the system can continuously learn and optimize its defense mechanism. Not only the effectiveness of the current defense strategy (first evaluation value) is evaluated, but also the performance of other defense strategies (second evaluation value) under the same attack environment is simulated through traffic recording and playback technology. Based on these evaluations, the system can identify the best candidate defense strategy, that is, when there is one or more of the first evaluation value and the second evaluation value, the strategy with the highest evaluation value is selected. Subsequently, the weight value of the strategy will be adjusted to improve its priority in defense decision-making. It ensures that the system can automatically optimize the defense strategy selection based on actual defense feedback and simulation test results, so as to more effectively resist future network attacks and improve the overall security protection level. Through continuous iteration and learning, the system can intelligently adjust its defense configuration to better adapt to the changing network threat environment.
[0051] In an optional example, the core idea of defense strategy iteration is to optimize the effectiveness and adaptability of defense strategies through continuous learning and evaluation to cope with the evolving network attacks. Each attack behavior and the corresponding implementation of the defense strategy are comprehensively analyzed, the defense effect is evaluated, and the strategy is adjusted according to the evaluation results, so as to provide better defense effect when encountering similar attacks in the future.
[0052] When the system first encounters a certain network attack (such as attack behavior A), the most suitable defense means (such as actual defense strategy A) will be selected according to the preset strategy in the database. After the attack ends, the actual defense effect will be evaluated, such as finding that defense strategy A has achieved 95% defense coverage in this attack. In order to further explore other possible defense strategies, the system will use traffic recording and playback technology, that is, record the complete network traffic of this attack, and then replay these traffic in a safe environment to simulate attack behavior A. In this way, the system can test different defense strategies (such as simulated defense strategies B, C, D) and observe how each strategy performs under the same attack conditions.
[0053] Based on the traffic recording and playback, the defense coverage of each simulated defense strategy against attack behavior A is calculated respectively. For example, in the simulation test, defense strategy C achieves 100% defense, which means that if strategy C is adopted in real combat, attack behavior A can be completely prevented in theory.
[0054] According to the above evaluation results, the security team will re-evaluate the priority of various defense strategies. In this example, since the performance of defense strategy C is better than strategy A and other simulation strategies, the security team may decide to give strategy C a higher decision weight in the future when encountering similar attacks, or even directly replace the current defense strategy A to improve the defense success rate.
[0055] Through continuous iteration of defense strategies, the system can gradually accumulate experience in dealing with various attack types, and continuously improve the quality and depth of its defense strategy library through learning from historical attacks and defense practices. This mechanism is particularly suitable for highly dynamic and intelligent network defense systems, which can ensure that defense strategies keep up with the latest network threat trends and minimize potential security risks.
[0056] Optionally, in the defense method of the network system provided in the embodiments of the present application, in the case that the network system is attacked by a network attack, the defense weight value corresponding to each of the at least one candidate defense strategy is determined, comprising: obtaining a reference data set of the network system, wherein the reference data set is used to indicate access records of the network system; in the case that the reference data in the reference data set meets a preset defense condition, determining that the network system is attacked by a network attack; determining the defense weight value corresponding to each of the at least one candidate defense strategy.
[0057] It should be noted that the reference data set can be a set of access record data generated by the network system, which can include but is not limited to user access logs, network traffic information, system events, and security audit records, etc. These data are used to construct the normal behavior baseline of network activities. The preset defense condition can be a set of rules or standards that define the boundary between normal network behavior and potential malicious behavior, which is used to identify the characteristics of abnormal or attack behavior in network activities.
[0058] In the optional implementation, the system obtains the reference data set, i.e. a series of network access records, as the basis for judging the network state. When some records in these reference data show abnormal behavior described by the preset defense condition, the system will judge that the network system is under attack. Then, based on the attack type and historical defense effect, the defense weight value of the candidate defense strategy is determined to provide a reference for the next step of strategy selection and execution. The preset defense condition can include but is not limited to: a large number of requests in a short time, abnormal access to a specific sensitive interface, and the presence of known malicious code in data packets.
[0059] Once the reference data that meets the preset defense condition is detected, it is determined that the network system is in an attack state, and immediately enters the selection stage of the defense strategy. At this time, the module will query the strategy configuration in the database, including various candidate defense strategies and their historical effect records, to determine the defense weight value of each strategy. The defense weight value reflects the priority and effectiveness of the strategy in the face of the current attack type, and its numerical size is usually determined based on the success rate and efficiency of the strategy in the past defense of similar attacks.
[0060] It should be noted that network attacks and corresponding identification methods can include:
[0061] DDoS attack (Distributed Denial of Service attack): A large number of botnet nodes simultaneously send requests to the target server or network, causing bandwidth or resource exhaustion, making it impossible for legitimate users to access services. Identification method: Monitor the abnormal surge of network traffic, especially in the absence of expected traffic peaks; Observe the significant extension of server response time or service unavailability; Use specialized DDoS protection devices or services for real-time traffic analysis.
[0062] Zero-day attack: Exploiting unpublicized or unpatched software vulnerabilities for attack, which is often difficult to predict and defend. Identification method: Rely on advanced behavior analysis technology to monitor abnormal system behavior, data transmission mode or application program crash; Use sandbox technology to execute suspicious code in an isolated environment and observe its behavior; Regularly conduct security audits to detect unauthorized changes in the system.
[0063] APT attack (Advanced Persistent Threat): Long-term, covertly lurking in target systems, collecting information or destroying systems through social engineering, malware implantation, etc. Identification method: In-depth analysis of network and host logs to find abnormal network communication, file access patterns; Use anti-virus and anti-spyware solutions; Monitor abnormal account login behavior, especially administrator accounts.
[0064] SQL injection: By inserting malicious SQL statements in web forms, tricking the server to perform unauthorized operations such as data leakage, tampering, etc. Identification method: Monitor web application request parameters for abnormal characters or SQL keywords; Use Web Application Firewall (WAF) to detect and block malicious requests; Analyze abnormal database activity, such as unexpected queries or data modifications.
[0065] Code execution attack: attackers exploit application vulnerabilities to remotely execute arbitrary code and gain control of the system. Identification method: Monitor web logs for attempts to upload or execute scripts; analyze application requests to identify scripts or code blocks included; detect signs of unexpected processes or services running on the system.
[0066] Cross-site scripting (XSS): inject malicious scripts into web pages to exploit user browsers to execute attack code, potentially stealing user data or launching further attacks. Identification method: Monitor user interaction data for HTML or JavaScript code included; use WAF to block requests containing XSS characteristics; perform code audits to confirm that input data handling is secure.
[0067] Lateral movement attack: after initial breach, attackers attempt to spread within their internal network to find more valuable targets. Identification method: Monitor abnormal traffic patterns within the network; analyze host logs for unauthorized account login attempts; implement strict access controls to monitor and limit communication between internal networks.
[0068] Data breach attack: steal sensitive data through various means such as SQL injection, server configuration errors, internal personnel mistakes, etc. Identification method: Use data leakage prevention (DLP) tools to monitor data export behavior; monitor abnormal database access patterns; conduct strict audits of internal networks to prevent improper data leakage.
[0069] Through the above embodiments of the present application, in the case of network attacks on the network system, the defense weight value corresponding to each of the at least one candidate defense strategy is determined, wherein the defense weight matches the type of network attack; the target defense strategy is run, and the first evaluation value of the target defense strategy is calculated, wherein the target defense strategy is the candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate the defense coverage value of executing the target defense strategy; the network attack is simulated, and the second evaluation value corresponding to each of the at least one candidate defense strategy is calculated, wherein the second evaluation value is used to indicate the defense coverage value of executing the candidate defense strategy; the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and at least one second evaluation value is increased. In the case of network attacks, different network attacks can be selected according to the weight to select the corresponding defense strategy, and after each attack, a simulated attack can be performed to update the weight of the defense strategy, thereby continuously updating the defense method for different network attacks. Further, the technical problem of low security of the network system is solved.
[0070] Optionally, in the defense method of the network system provided by the embodiments of the present application, in the case that the reference data in the reference data set meets the preset defense condition, it is determined that the network system is attacked by a network attack, including at least one of the following:
[0071] 1) in the case that the target interface is accessed, it is determined that the network system is attacked by a network attack, wherein the target interface is used to indicate an interface that needs to be accessed in a preset access mode;
[0072] 2) in the case that the access parameter included in the access instruction of the reference interface exceeds the reference access parameter corresponding to the reference interface, it is determined that the network system is attacked by a network attack;
[0073] 3) in the case that the access time of the reference interface does not meet the reference access time corresponding to the reference interface, it is determined that the network system is attacked by a network attack;
[0074] 4) in the case that the access device of the reference interface does not meet the reference access device corresponding to the reference interface, it is determined that the network system is attacked by a network attack;
[0075] 5) in the case that the access frequency of the reference interface is greater than the preset frequency, it is determined that the network system is attacked by a network attack;
[0076] 6) in the case that the time interval of multiple accesses of the reference interface is less than the preset time interval, it is determined that the network system is attacked by a network attack;
[0077] 7) in the case that the access address change frequency of the multiple accesses of the reference interface is greater than the preset change frequency, it is determined that the network system is attacked by a network attack.
[0078] It should be noted that the target interface can be a specific application interface, whose access mode and rules are strictly regulated, and any attempt to deviate from the preset access mode will be considered suspicious behavior. The reference access parameters can be a set of well-defined access parameters for each reference interface, and any access request that exceeds or does not meet these parameters will be reviewed and may be considered part of an attack. The reference access time specifies that certain interfaces can only be accessed within a specific time period, and any access request outside the specified time will be flagged as abnormal. The reference access device specifies the device type or specific device identifier that can access the interface, and any access from an unapproved device will be considered a potential attack. The preset frequency system sets a normal access frequency limit, and access behavior exceeding this frequency will be suspected of being an attack, especially in scenarios such as attempting brute force cracking or DDoS attacks. The preset time interval can be a minimum reasonable time interval for consecutive access, and any multiple accesses shorter than this interval will be considered abnormal and may indicate the use of automated attack tools. The preset change frequency is for geographically sensitive interfaces, which defines an upper limit for the frequency of changing access addresses, and access addresses that change too frequently beyond this upper limit may indicate that the attacker is trying to launch attacks from different locations.
[0079] In the process of detecting network attacks, network activity is monitored and compared with a set of reference data in the database. If the network activity meets any of the preset defense conditions, the system will determine that the network system is under attack. These conditions include but are not limited to: the way the target interface is accessed does not meet expectations; access parameters exceed normal ranges; access interfaces at unauthorized times; use unauthorized devices to access interfaces; interface access frequency is abnormally high above the preset threshold; the time interval between multiple accesses is too short; access addresses change too frequently.
[0080] In an optional implementation, a special interface that is not normally used by any function can be created as a special interface (i.e., a target interface) to act as a detector to detect whether a third party is conducting a traffic sniffing or copying attack. This special interface usually carries a clear identifier, such as / api / get_password?ip=all, which is designed not to serve the needs of regular business logic or data interaction, but as a decoy to catch attackers who try to illegally obtain and use network communication information.
[0081] The access condition of this induced interface is very specific, it can only be accessed at a specific time period, by a specific server and through sending a set of predetermined parameters. This means that during normal operation, there is no reason for any application or user to call such an interface, as they have no business scenario that requires it. Normal business requests follow clear and predefined rules, and the design of the induced interface is precisely to break these conventions. For example, a normal business request might look like / api / function1?key1=value1&key2=value2, while the induced interface might require an additional or unusual combination of parameters, as in the example mentioned earlier.
[0082] When the system detects that the / api / get_password?ip=all interface is accessed more times than expected (for example, multiple requests in a day), or receives a request outside the preset time window, or the request source does not match the pre-defined device list, it is considered abnormal behavior, highly suspected of being a traffic replication attack. For triggered requests, no real password data or sensitive information is returned, but an error message, a blank response, or specific deception data may be returned to mislead potential attackers and collect information about the attack.
[0083] It should be noted that under normal circumstances, this interface should not be called, and any call to this interface is almost certainly abnormal. In particular, the presence of the ip=all parameter, which is clearly not required by a business scenario, further increases the suspiciousness of the calling behavior. Since there is no business logic that requires frequent calls to this interface, if more than one call is detected within a day, especially multiple calls, it indicates that there may be malicious behavior, i.e. the attacker may be trying to obtain sensitive information through traffic sniffing or replay attacks.
[0084] This strategy is suitable for highly secure network environments, especially in systems that transmit sensitive data, such as online transaction systems of financial institutions. It can help detect and prevent attacks that attempt to obtain sensitive data through traffic sniffing in a timely manner. By setting up an induced interface, the system can accurately identify and locate traffic replication attacks without affecting normal business, which is a proactive defense strategy that not only improves security awareness, but also quickly responds to attacks at an early stage, reducing potential losses. At the same time, since the design of the interface is not public, only internal systems know its existence and calling rules, so it can effectively prevent external attackers from detecting the existence of the interface through conventional means, increasing the stealth and effectiveness of defense.
[0085] In an optional implementation, in a case where an access parameter included in an access instruction of a reference interface exceeds a reference access parameter corresponding to the reference interface, it is determined that the network system is under a network attack.
[0086] In web service or API interface design, each interface usually defines a list of parameters it allows to receive. These parameters are the information necessary for the interface to function properly, such as user ID, password, or certain operation instructions. Parameter validation for each interface means that the system checks whether the parameters sent in each request meet the predefined specifications of the interface.
[0087] For example, / api / function1?key1=value1&key2=value2&key3=value3, the interface function1 is designed to only receive `key1`, `key2`, and `key3` three parameters, and these three parameters are required. When receiving a request, the system checks whether the key conditions are met: whether the request contains all the required parameters, i.e. `key1`, `key2`, and `key3`. Whether the request contains additional undefined parameters.
[0088] As mentioned earlier, SQL injection is an attack method that attackers use the vulnerability of web applications' inadequate handling of user input data to send malicious SQL instructions to the database. By adding or modifying SQL instructions in normal URL parameters, for example, by adding a condition like `or 1=1`, any unverified attempt can be considered as having passed verification, thereby accessing protected resources. By constructing specific SQL queries, attackers may obtain sensitive information in the database. Attackers can attempt to delete, modify data, or perform other database operations.
[0089] When detecting that the request contains additional parameters, such as / api / function1?key1=value1&key2=value2&key3=value3&user=admin&password=1111or1=1, the system considers it as abnormal behavior, which may be an attacker's SQL injection attempt.
[0090] The characteristics of such requests include: adding `user` and `password` parameters outside the predefined parameters. SQL syntax such as `or 1=1` appears in the parameter values, which is a typical SQL injection attempt.
[0091] It should be noted that once such an abnormal request is detected, the system can take the following measures according to its preset defense strategy: record the abnormal request, analyze its possible attack purpose and means. Return a seemingly legitimate but actually meaningless response to the attacker, while identifying and analyzing the attack pattern by further monitoring its subsequent behavior. If the system determines that this behavior is a high-risk attack, it can immediately take measures such as blocking access from the IP address, triggering higher-level security audits, etc. to prevent further damage.
[0092] In an optional implementation, in a case where the access time of the reference interface does not conform to the reference access time corresponding to the reference interface, it is determined that the network system is under a network attack.
[0093] In network security defense, time window as a defense strategy can effectively identify and defend against special network attack types, especially those hacker behaviors that rely on copying legitimate user requests or attempting automated and continuous attacks. A specific response time window is set for each key interface in the system, that is, under normal circumstances, the interface only accepts and responds to requests within a preset time period.
[0094] The time point of normal user access to a specific interface often conforms to the business process and daily operation mode, and has certain regularity and predictability. When hackers attempt penetration attacks, they may use packet capture, request replay, etc. to initiate requests without knowing the interface response time window, and the request time point often does not conform to the legitimate access mode.
[0095] The attacker does not know the specific response time window of each interface, so the request time is more likely to be in a non-preset time period. The setting of the response time window is hidden from the attacker, increasing the difficulty of attack identification and improving the defense level.
[0096] For example, an interface can be set to accept requests within the first 10 minutes of each hour, i.e. 00:00 to 00:10, 01:00 to 01:10, etc. Record all request times for the interface and monitor in real time whether they are within the preset time window. If a request is monitored outside the response time window, for example, an interface is requested at 13:15:00, and the response time window of the interface is 0-10 minutes per hour, this will be considered an abnormal request time point. When the abnormal time point request exceeds a certain threshold or frequency, the system will determine that it may be an attack behavior rather than normal user access.
[0097] In an optional implementation, in a case where the access device of the reference interface does not conform to the reference access device corresponding to the reference interface, it is determined that the network system is under a network attack.
[0098] A mechanism of a reference access device list of trusted requests can be established as one of the barriers to defend against network attacks. A device list is a strict security policy that only allows pre-verified and authorized entities (such as IP addresses, user accounts, or device signatures) to access specific network resources or interfaces. Any attempt to access outside the device list is considered a potential threat or attack behavior and will be blocked by the system.
[0099] Suppose there is an application interface (i.e., a reference interface) whose business logic only allows requests from the internal server IP `192.168.1.1`. This IP address is called the "reference access device list of trusted requests". System administrators or security experts will add these trusted IP addresses or other identifiers (such as MAC addresses, user agents, etc.) to the device list. Whenever a request is sent to this specific interface, the source IP of the request will be checked first to see if it is in the device list. This is done by comparing the source IP field in the request header with the list of trusted IPs stored in the database. If the IP of a request is not in the device list, the system immediately marks the request as abnormal and considers the access as unauthorized, which may be an attempt at a network attack. Such a request will be directly rejected and will not be forwarded to the application program in the back-end of the interface. The device list is not static and needs to be updated regularly by the system administrator to reflect new business needs or changes in network topology. Similarly, through analysis of historical attack data, the device list strategy can be continuously optimized, such as adding more lists of suspicious IPs.
[0100] When a legitimate request (for example, a request from `192.168.1.1`) arrives at the system, it is compared with the device list and found to match, allowing the request to pass and continue with the normal business process. Suppose the system suddenly receives a request with IP `10.0.0.2`, which is not in the preset list, and immediately identifies it as an abnormal request. At this time, the system will not pass the request to the real business interface, but will immediately activate the defense mechanism, such as returning a fake error message or conducting a deeper analysis to determine the nature and severity of the attack.
[0101] In an optional implementation, the network system is determined to be under a network attack when the access frequency of the reference interface is greater than a preset frequency; the network system is determined to be under a network attack when the access frequency of the reference interface is greater than a preset frequency.
[0102] Human operations are limited by natural reaction speed, thinking time, and possible network latency, etc. factors, resulting in predictable time interval patterns when users perform operations on web pages, such as browsing, clicking, submitting forms, etc. This pattern is broken in front of automated attack tools, as tools can perform a large number of operations in a very short time, and can evade or simulate the delay factors common in human operations.
[0103] The system records and analyzes the time intervals of user operations on web pages, such as clicking buttons, submitting forms, refreshing pages, etc. It establishes a baseline for normal human operation frequency and time interval by monitoring the timestamps of these operations and then calculating the interval time between adjacent operations. The system continuously monitors the access frequency of users to specific functions or interfaces. For example, a user attempts multiple times to confirm and pay for train ticket purchases in a short period of time, which is beyond the expected normal human operation and is likely to be an attack attempt.
[0104] And the interval time of human operation usually has a certain degree of randomness, because the reaction time and decision time of different users and different scenarios will be different. But automated tools can usually set precise time intervals to simulate human operations, but the precision and consistency of such intervals are fundamentally different from the randomness of human behavior, which can be an important feature for identifying attacks.
[0105] By comparing the actual operation time interval and frequency with the established baseline, the system can identify behaviors that do not conform to the normal operation pattern of humans. If it detects features such as excessively high operation frequency, abnormally consistent operation interval, or excessively short time interval, the system will consider it as a potential attack behavior.
[0106] The system not only focuses on the time interval of a single operation, but also on the interval time between a series of consecutive operations. For example, from selecting a train ticket to completing payment, a normal user will have an indefinite interval due to various factors, while an automated tool may exhibit regularity or extremely short intervals. Some automated attack tools add random delays to evade detection, but this is often a random value within a limited range, and in multiple operations it will show a certain regularity. The system can identify patterns that differ from human truly random behavior through statistical analysis of these delays. The system can also identify sequence patterns of operations, such as a user repeatedly submitting the same form in a short period of time, which is inconsistent with the behavior pattern of human users, which may be an attempt by the tool to brute-force login.
[0107] It is suitable for any web application that requires user interaction, such as online shopping, financial transactions, ticket reservation systems, etc., especially those involving sensitive operations or having explicit business processes.
[0108] In an optional embodiment, in the case where the access address change frequency of multiple accesses to the reference interface is greater than the preset change frequency, it is determined that the network system is under a network attack.
[0109] Under normal circumstances, the physical location of a user will not change rapidly, resulting in a rapid change in the source IP address of their requests. For example, when a user uses a computer or mobile phone to access a website at a fixed location, their IP address is usually stable. Even for mobile users, such as those using smartphones to move around a city, the change in IP address will have a certain regularity and will not suddenly span a large geographical range, as this is inconsistent with the current Internet infrastructure and the working principle of mobile devices. However, if the system monitors the physical address (IP address) of a user's requests and finds that it changes frequently within a short period of time and exceeds the speed and distance that a human can move, it may indicate that the account information has been compromised, and the attacker may be attempting to use the account simultaneously in multiple locations around the world. The motivation behind this abnormal behavior is usually that the attacker is trying to hide their true location or is using a distributed attack to bypass single-point defense mechanisms and increase the success rate of the attack.
[0110] Another important traffic anomaly detection indicator is the difference in request traffic within a unit of time compared to historical same-period data. Web services and applications typically have a certain stability and predictability in access patterns, especially during non-holiday or off-peak periods, where access traffic remains relatively constant. Therefore, the system can establish a baseline, which is the average level and range of normal traffic. When the number of requests within a unit of time is significantly higher or lower than this baseline, the system should be alert to possible network events: a significant increase may indicate that the system is experiencing a DDoS (Distributed Denial of Service) attack, in which attackers occupy service resources with a large number of invalid requests, preventing legitimate users from accessing the system. A significant decrease may indicate a network-level problem, such as traffic routing errors or the failure of intermediate network devices, but it may also be the result of an attacker performing traffic hijacking, redirecting traffic intended for legitimate servers to malicious sites.
[0111] In an optional embodiment, in the network security defense system, it is crucial to ensure the security and confidentiality of the defense strategies themselves. All defense strategies, attack features, and defense configuration information are stored in a central database rather than being embedded in the code of the application. This forms a system component that is isolated from business applications and focuses on security detection and response.
[0112] The defense strategy information is completely isolated from the application code, and the attack detection module is independently deployed, thereby constructing a multi-level and high-elasticity defense system, significantly enhancing the security protection capability of the system, and improving the confidentiality and flexibility of the defense strategy. The architecture design is crucial for preventing strategy information leakage, ensuring the continuous operation of the defense system, and coping with complex and variable network attacks.
[0113] In an optional embodiment, when an attack behavior such as SQL injection, brute force cracking or other types of attacks is identified, the attack behavior and defense strategy table in the database is consulted, and the best defense measure matching the specific attack type is intelligently selected according to the corresponding rules in the table. For example:
[0114] For SQL injection attacks, the "response camouflage" strategy is selected, and a reasonable but actually fake response is returned to the attacker, thereby misleading the attacker and making him believe that the attack is successful, but actually no sensitive information is obtained. For brute force cracking attacks, fake responses are repeatedly sent to the attacker to consume the attacker's resources and slow down the attack speed, and more information can be collected to assist subsequent defense decisions.
[0115] For high-risk attacks such as DDoS attacks or explicitly confirmed malicious intrusions, the "attack blocking" strategy is adopted, and the attack source is directly blocked, such as blocking the IP address, limiting the network communication of specific protocols, to prevent the system from being further damaged.
[0116] Through the above embodiments of the present application, the network attacks that the system may suffer and the categories of network attacks are identified through various identification methods, so that the corresponding defense strategy is more accurately selected to improve the security of the system.
[0117] Optionally, in the defense method of the network system provided in the embodiments of the present application, before the reference data set of the network system is obtained, at least one of the following is included:
[0118] 1) The data packets received and sent by the network system are determined as reference data;
[0119] 2) The state of at least one application program running in the network system is recorded as reference data;
[0120] 3) The log data generated in the network system is determined as reference data.
[0121] It is necessary to note that data packets are in network communication, information is packaged into a series of data units, each unit includes the sender, receiver, data content and its control information. Data packet is the basic unit of network communication. Application state record refers to the state information of application in the running process, including but not limited to the running parameters of application, user session information, service request and response state, etc. Log data can be the record file generated by system and application in the running process, which is used to record operation, event and exception, and is convenient for post analysis and troubleshooting.
[0122] In an optional embodiment, the data packets received and sent by the network system are determined as reference data.
[0123] Network traffic collection is the most direct way to monitor network activities, especially when defending B / S architecture of Internet application is more critical. It involves real-time capture and analysis of all data packets entering and exiting the application server, including but not limited to HTTP / HTTPS request and response, DNS query, FTP transmission, etc. By analyzing the characteristics of these traffic, such as the size, frequency, source / destination IP address, port number of data packets, abnormal network traffic patterns can be identified, which may be indicators of attack behavior. For example, a large number of requests may indicate DDoS attack, and scanning of specific ports may indicate potential network scanning behavior.
[0124] In an optional embodiment, the data packets received and sent by the network system are determined as reference data.
[0125] Application information collection focuses on the running state and behavior of application, which is to ensure the security of application itself. This includes but is not limited to the running configuration of application, code change in runtime, API interface call record, etc. In the field of security, application is often the most direct target of attack, therefore, by continuously monitoring the running state of application, intrusion or tampering behavior that application may suffer can be discovered in time. For example, if the code of application appears unauthorized change, or the call pattern of API interface is inconsistent with the expectation, it may indicate that the application is under attack. Once such abnormalities are found, the security team needs to immediately upgrade the defense strategy, such as implementing code review, changing API interface access strategy or enabling higher level authentication mechanism, to block attack behavior.
[0126] In an optional embodiment, the log data generated in the network system is determined as reference data.
[0127] Log information collection is another important means of monitoring system and application running status. Application in the process of running will generate a large number of log information, these information records the normal operation and abnormal activity of application, including but not limited to user activity, system error, security event, etc. By analyzing the abnormal behavior in these logs, it can assist in determining the existence of network attack. For example, if multiple failed login attempts, unknown file access attempts or abnormal system calls are found in the logs, they may be signs that attackers are trying to break through system security. Log information collection can also help security teams trace the path of attack, analyze the means and purpose of attackers, and provide basis for subsequent defense strategy.
[0128] It should be noted that the application in the process of running will produce a large number of logs, which contain important data such as system operation, user activity, error information, etc. In traditional log management, logs are usually scattered on various servers or application nodes, which not only increases the management difficulty, but also when facing attacks, logs may be tampered with or destroyed, affecting the traceability of security incidents. Collecting logs from different applications and transmitting them to a central log server or log analysis platform ensures the integrity and availability of logs, facilitating global analysis and security management.
[0129] Offline analysis of logs refers to not analyzing logs directly in real-time processing or application running environment, but saving log data to log centralized management system, and then using special tools and algorithms for batch processing and deep analysis. Offline analysis means that the original log data will not be affected by the application running environment during analysis, reducing the risk of log being destroyed by attackers, and also ensuring that complete log records can be preserved for subsequent analysis when the system is attacked. Offline analysis allows the use of more complex statistical models and machine learning algorithms to analyze log data at multiple levels, uncovering hidden attack patterns or abnormal behavior. For example, you can analyze the frequency of requests, time distribution, error codes, session duration, and other indicators to identify access patterns that are significantly different from normal user behavior, indicating possible attack activities. Log analysis in real-time environment may consume a lot of system resources, affecting application performance. Offline analysis can be performed during low peak periods, ensuring the comprehensiveness and depth of analysis, and avoiding the impact on production systems.
[0130] Through offline analysis of application access logs, potential security threats can be effectively identified and tracked, even if the application has been invaded or manipulated by attackers. This is because once attack behavior occurs, no matter how the attacker disguises, the traces left on the network level (such as abnormal data flow, non-normal time access pattern, excessive error request, etc.) will be recorded by the log system. By analyzing these data.
[0131] Through the above-mentioned embodiments of the present application, rich information basis is provided for subsequent attack behavior detection through different aspects and data sources. Network traffic collection focuses on network layer activities and can identify network layer attacks; application information collection focuses on application layer behaviors and can find signs of application attacks; log information collection provides in-depth event details and helps to restore the attack process. These information collection works are the premise of the effective operation of the defense system, ensuring that the system can timely and comprehensively understand the status of the network and the application, and providing strong support for subsequent attack detection and defense strategies.
[0132] Optionally, in the defense method of the network system provided by the embodiments of the present application, the target defense strategy is executed, including at least one of the following:
[0133] 1) in the case of receiving a network attack, increasing the response frequency of the network system;
[0134] 2) in the case of receiving a network attack on the application, generating a reference response according to the network attack, wherein the reference response is a response generated according to the response format of the application;
[0135] 3) in the case of receiving a network attack, sending a notification response, wherein the notification response is used to indicate that the network system has a running error.
[0136] It should be noted that the response frequency can be the speed of the network system or the application responding to the client request, that is, the number of times of processing requests and sending responses per unit time. The reference response can be a response that simulates real business interaction generated when the network system detects a potential attack on the application. Its format and content are similar to normal business responses, but the actual information carried is false, aiming to mislead the attacker. The notification response can be an alarm response sent by the system to the user or system administrator when detecting a network attack or other abnormal running state. Such a response usually contains detailed information about system running errors, indicating system health status or security events.
[0137] In the face of network attacks, running target defense strategies is the key response mechanism of network security systems. The selection and execution of strategies aims to protect system resources, data security and user privacy, while ensuring business continuity is not affected. When the system is attacked, by generating reference responses and adjusting the response frequency, the system can effectively confuse the attacker, delay the attack process, and at the same time give the defense team valuable time to analyze the attack means and develop more accurate blocking strategies. The flexibility and targeting of this strategy embody the principles of "active trapping" and "dynamic response" in modern network security defense concepts, by forging responses and adjusting system behavior, a dynamic protection network is built that can actively respond to threats and continuously optimize defense capabilities.
[0138] When suspicious network traffic is detected, these flows are redirected to specially designed decoy systems instead of directly flowing to critical production systems. By diverting, it can be ensured that even if the attacker tries to launch an attack, these attacks will not directly touch the production environment, thus protecting sensitive data and business operations from being affected. After directing attack traffic to the decoy system, the system can "interact" with the attacker in a safe environment, collecting more information about attack methods, attack frequency and attacker behavior, which is crucial for subsequent defense strategy adjustment and attack behavior analysis.
[0139] In an optional implementation, the response frequency of the network system is increased in the case of receiving a network attack.
[0140] In the face of attacks, by artificially increasing the response time, the efficiency of the attacker can be reduced. Attackers usually rely on sending requests quickly and in large quantities to probe or crack the system. By delaying the response, the attacker will need to wait longer before getting a response, which not only increases the operating cost of the attacker, but also may prompt the attacker to give up the attack, especially for those time-sensitive attack strategies. Additional time is provided for the defense side to analyze attack patterns, adjust defense strategies, and even in some cases, allow manual intervention to handle more complex attack scenarios.
[0141] In an optional implementation, in the case of receiving a network attack on an application, a reference response is generated according to the network attack, wherein the reference response is a response generated according to the response format of the application.
[0142] The format of the response (such as HTTP / HTTPS status code, JSON or XML data structure, etc.) is consistent with the real business response to avoid immediate detection of abnormalities by the attacker. The response content may contain non-real user data, operation results or system status, which seems valuable to the attacker, but actually has no operational meaning, and can induce the attacker to continue using the wrong strategy.
[0143] In an optional embodiment, in the case of receiving a network attack, a notification response is sent, wherein the notification response is used to indicate that the network system has a running error.
[0144] In addition to disguising normal business responses, fake error responses can also be sent to further confuse attackers. These error messages can be:
[0145] Interface returns empty response: deceive attackers to make them think their request is not processed or has an error, thereby affecting their decision and subsequent action.
[0146] Username and password inconsistency: even if the attacker uses the correct credentials, the system will return a "username or password error" message, which can mislead the attacker and make them think that their credentials have been leaked or changed.
[0147] Connection timeout: a fake timeout response can consume the patience of the attacker, especially for automated attack tools that rely on fast feedback.
[0148] Application unauthorized: even if the attacker obtains a seemingly correct access path or permission, the system will return an unauthorized error to prevent further exploration or attempts.
[0149] Through the above embodiments of the present application, in the case of facing network attacks, fake responses can be used as defense strategies, and by analyzing network attacks through fake responses, the accuracy of subsequent re-confrontation with the same type of network attack or defense for the current network attack is improved, thereby improving the security of the system.
[0150] Optionally, in the defense method of the network system provided in the embodiments of the present application, the running target defense strategy includes at least one of the following:
[0151] 1) In the case of receiving a network attack, prohibit access of the sending account of the network attack;
[0152] 2) In the case of receiving a network attack, prohibit access of the sending end address of the network attack.
[0153] It should be noted that the sending account refers to the account or authentication credential that the attacker may use in the network attack to attempt to access or manipulate the target system. The sending end address can refer to the network address of the attack source, such as the IP address, which is important information for the system to identify attack behavior and take action.
[0154] In optional embodiments, when an attack behavior is detected and the account used by the attacker is determined, the account will be immediately disabled. This can be a permanent ban or a temporary restriction, depending on the severity of the attack and the security policy of the system. After disabling the account, even if the attacker has the login information of the account, further access and control of the system through the account will not be possible.
[0155] In optional embodiments, another target defense strategy is to interrupt the attack by blocking access from specific IP addresses. When the source IP address of the attack is identified, an IP-level ban will be implemented. This effectively limits the attacker's ability to launch attacks on the system through that IP address, reducing the risk exposure of the system.
[0156] Through the above embodiments of the present application, various attack types can be flexibly dealt with, not only protecting core business from direct intrusion, but also collecting intelligence, inducing attackers by responding to false and fake error messages, while quickly blocking attacks when necessary, thus building a multi-level and efficient defense system.
[0157] It should be noted that the above-mentioned two core defense strategies of fake response and attack blocking are actually more extensive and detailed strategies that can be used to deal with different attack types and scenarios. The following are some candidate defense strategies that can be used alone or in combination to enhance the security of the system and the ability to deal with complex network threats:
[0158] 1. Access control: limit access from specific IP addresses, ports, protocols or user accounts, through lists, geofencing, role-based access control, etc. Preventive blocking of known malicious sources or fine-grained access permission management for specific resources.
[0159] 2. Dynamic response: dynamically adjust the content and format of the response according to the nature and strength of the attack, such as randomizing error messages, changing response delay time, etc. Used to confuse attackers and make it difficult for them to analyze the true state and weaknesses of the system, suitable for multiple attack types.
[0160] 3. Honeypot technology: set up fake environments or resources to attract and monitor the behavior of attackers, collect intelligence and disrupt their attack plans. Actively collect attacker information to understand their attack methods and targets, suitable for research and early warning purposes.
[0161] 4. Behavior analysis and learning: use machine learning and artificial intelligence technologies to analyze the operation patterns of normal users and attackers, continuously learn and adjust security strategies. Improve the ability to identify unknown or zero-day attacks, suitable for highly dynamic network environments.
[0162] 5. Multi-factor Authentication: Requires users to provide multiple forms of identity verification, such as passwords, fingerprints, one-time codes, etc., to increase the difficulty for attackers to break the authentication. Enhances the security of user authentication, suitable for systems involving sensitive information.
[0163] 6. Encryption and Protocol Strengthening: Encrypts data transmission and strengthens the security of network protocols, such as using TLS / SSL, DNSSEC, etc., to protect data and communication. Prevents eavesdropping and tampering of data during transmission, suitable for all network communications.
[0164] 7. Content Filtering and Cleaning: Screens and cleans potentially malicious code or non-compliant input before data enters the system. Resists SQL injection, XSS attacks, file upload vulnerabilities, etc., suitable for web applications and API interfaces.
[0165] 8. Secure Gateway and Border Protection: Deploys security devices such as firewalls, intrusion detection and prevention systems at the internal and external network boundaries to intercept and filter threats. Provides the first line of defense at the network entrance, suitable for all network architectures.
[0166] 9. Audit and Log Analysis: Records all system activities and analyzes logs periodically or in real time to identify abnormal behavior and potential attacks. Traces the source of attacks after the fact, evaluates the effectiveness of defense, suitable for all systems.
[0167] 10. Sandbox Technology: Runs suspicious applications or data in a closed environment to limit their direct impact on the core system. Safely tests and analyzes unknown software, code or data files, suitable for mail systems, file uploads, etc.
[0168] In an optional implementation, a defense architecture of a network system can be used, which includes:
[0169] D1 monitoring module: deployed at the network boundary and key servers of the financial institution, collects all incoming and outgoing packet information in real time, including but not limited to source IP, destination IP, port number, protocol type, packet size and frequency, etc. At the same time, the D1 module closely monitors the running state of the application, records log information of each user operation, service call, abnormal error and login activity. All these monitoring data are transmitted to the D2 database in real time.
[0170] D2 database: as the central repository, stores all network monitoring information collected from the D1 module, and builds a baseline model of normal traffic based on historical data. In addition, the D2 database also stores known network attack feature values, such as SQL injection, XSS, port scanning, etc. Attack pattern signature, and pre-configured defense strategy set.
[0171] D3 attack detection module: Based on the network attack characteristic values stored in the D2 database and the normal traffic model, the D3 module implements multiple monitoring strategies. For example, monitoring the large number of data packets sent by the same IP address in a short period of time, comparing the parameters in the data packet with the preset access parameters, and analyzing whether the frequency and time interval of the request conform to the mode of human operation. Once the monitored data deviates from the normal model or matches the attack characteristic value, the D3 module will immediately identify the potential network attack behavior, and find the corresponding defense strategy from the D2 database.
[0172] D4 scheduling module: After the D3 module sends out the attack identification signal, the D4 module intelligently selects the most suitable defense scheme from the D2 database according to the type of attack and the attack characteristic value. For example, for SQL injection attacks, the D5 response camouflage module is preferred to provide false database query results to confuse the attacker; for high-risk DDoS attacks, the D6 attack blocking module is quickly dispatched to block the attack source IP address through firewall rules to ensure the availability of critical services.
[0173] D7 defense feedback module: After the attack ends, the D7 module retrieves the detailed records of this attack from the D2 database, including the attack method, attack time, attack frequency, and the defense strategy selected by the D4 scheduling module and its implementation effect. By analyzing these data, the module evaluates the effectiveness of the defense strategy. If it is found that the existing strategy is not sufficient to completely defend against attacks, the D7 module will generate strategy optimization suggestions, such as adjusting the sensitivity of parameter detection, adding new response camouflage patterns or updating the threshold of blocked IP addresses, for the security team to reference, to continuously iterate and optimize the defense strategy, and improve the overall anti-attack ability of the system.
[0174] In an optional example, the D1 monitoring module records and transmits the abnormal traffic (such as a large number of requests from unknown sources) to the D2 database after detecting the abnormal traffic. The D3 module analyzes the characteristics of the abnormal traffic and finds that the request contains a pattern of SQL injection attempt, and immediately determines that it is a high-risk attack behavior. The D4 scheduling module retrieves the optimal defense strategy for SQL injection from the D2 database and decides to first use the D5 response camouflage module to generate a false database response to mislead the attacker, while preparing to block the attack source through the D6 module in case of attack escalation. The D5 response camouflage module starts working and generates a response with the same format as the real database query response but with completely random data content, thereby consuming the attacker's resources and time and reducing the attack efficiency. If the attack continues to escalate, the D6 attack blocking module will block the IP address of the attack source according to the instructions of the D4 scheduling module to avoid further damage. After the attack is over, the D7 defense feedback module analyzes the detailed records of this defense and finds that the response camouflage strategy effectively consumed the attacker's resources but failed to stop certain specific attacks. Based on this, the module suggests increasing the detection sensitivity to specific SQL statement patterns and adding more complex information confusion mechanisms in the response to further improve the defense effect.
[0175] In the embodiments of the present application, in the case that the network system is attacked by a network attack, a defense weight value corresponding to each of at least one candidate defense strategy is determined, wherein the defense weight matches the type of the network attack; a target defense strategy is run, and a first evaluation value of the target defense strategy is calculated, wherein the target defense strategy is a candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate a defense coverage value of executing the target defense strategy; the network attack is simulated, and a second evaluation value corresponding to each of the at least one candidate defense strategy is calculated, wherein the second evaluation value is used to indicate a defense coverage value of executing the candidate defense strategy; and the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and at least one second evaluation value is increased. In the case of facing a network attack, a corresponding defense strategy can be selected according to the weight for different network attacks, and after each attack, a simulated attack can be performed to update the weight of the defense strategy, so that the defense mode for different network attacks is constantly updated. Thus, the technical problem of low security of the network system is solved.
[0176] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown.
[0177] Embodiment 2
[0178] The embodiment of the present application further provides a defense device of a network system. It should be noted that the defense device of the network system in the embodiment of the present application can be used to execute the defense method for the network system provided by the embodiment of the present application. The defense device of the network system provided by the embodiment of the present application is introduced as follows.
[0179] According to the embodiment of the present application, a device for implementing the defense method of the network system is further provided, as shown in the following formula (1), the device comprises: Figure 3
[0180] a weight determination unit 302, configured to determine respective defense weight values of at least one candidate defense strategy in the case that the network system is attacked by a network attack, wherein the defense weight matches the type of the network attack;
[0181] a strategy execution unit 304, configured to execute a target defense strategy and calculate a first evaluation value of the target defense strategy, wherein the target defense strategy is a candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate a defense coverage value of executing the target defense strategy;
[0182] a simulation unit 306, configured to simulate the network attack and calculate respective second evaluation values of the at least one candidate defense strategy, wherein the second evaluation value is used to indicate the defense coverage value of executing the candidate defense strategy;
[0183] a weight adjustment unit 308, configured to increase the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and the at least one second evaluation value.
[0184] In the defense device of the network system in the above embodiment of the present application, in the case that the network system is attacked by a network attack, respective defense weight values of at least one candidate defense strategy are determined, wherein the defense weight matches the type of the network attack; a target defense strategy is executed, and a first evaluation value of the target defense strategy is calculated, wherein the target defense strategy is a candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate a defense coverage value of executing the target defense strategy; the network attack is simulated, and respective second evaluation values of the at least one candidate defense strategy are calculated, wherein the second evaluation value is used to indicate the defense coverage value of executing the candidate defense strategy; and the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and the at least one second evaluation value is increased. In the case of facing the network attack, the corresponding defense strategy can be selected according to the weight for different network attacks, and after each attack, the simulation attack can be performed to update the weight of the defense strategy, so as to continuously update the defense mode for different network attacks. Further, the technical problem of low security of the network system is solved.
[0185] Optionally, the weight determination unit 302 comprises: a data acquisition module, configured to acquire a reference data set of the network system, wherein the reference data set is used to indicate access records of the network system; an attack identification module, configured to determine that the network system is attacked by a network attack if reference data in the reference data set meets a preset defense condition; and a weight determination module, configured to determine a defense weight value corresponding to each of the at least one candidate defense strategy.
[0186] Optionally, the attack identification module is further configured to: determine that the network system is attacked by a network attack if a target interface is accessed, wherein the target interface is used to indicate an interface that needs to be accessed in a preset access mode; determine that the network system is attacked by a network attack if an access parameter included in an access instruction of a reference interface exceeds a reference access parameter corresponding to the reference interface; determine that the network system is attacked by a network attack if an access time of the reference interface does not meet a reference access time corresponding to the reference interface; determine that the network system is attacked by a network attack if an access device of the reference interface does not meet a reference access device corresponding to the reference interface; determine that the network system is attacked by a network attack if an access frequency of the reference interface is greater than a preset frequency; determine that the network system is attacked by a network attack if a time interval of multiple accesses of the reference interface is less than a preset time interval; and determine that the network system is attacked by a network attack if an access address change frequency of the multiple accesses of the reference interface is greater than a preset change frequency.
[0187] Optionally, the data acquisition module is further configured to: determine a data packet received and sent by the network system as the reference data; record a state of at least one application program running in the network system as the reference data; and determine log data generated in the network system as the reference data.
[0188] Optionally, the strategy execution unit 304 comprises: a first strategy execution module, configured to increase a response frequency of the network system if a network attack is received; generate a reference response according to the network attack if a network attack on an application program is received, wherein the reference response is a response generated according to a response format of the application program; and send a notification response if the network attack is received, wherein the notification response is used to indicate that a running error occurs in the network system.
[0189] Optionally, the strategy execution unit 304 further comprises: prohibit access of a sending account of the network attack if the network attack is received; and prohibit access of a sending end address of the network attack if the network attack is received.
[0190] It should be noted that the weight determination unit 302 to the weight adjustment unit 308 correspond to steps S101 to S104 in Embodiment 1, and the two modules have the same instances and application scenarios as the corresponding steps, but are not limited to the content disclosed in Embodiment 1. It should be noted that the above modules or units can be hardware components or software components stored in the memory (for example, the memory 104) and processed by one or more processors (for example, the processors 102a, 102b, …, 102n), and the above modules can also be run in the computer terminal 10 provided in Embodiment 1 as part of the device.
[0191] Embodiment 3
[0192] Embodiments of the present application can provide an electronic device, Figure 4 is a structural block diagram of an electronic device according to an embodiment of the present application. As shown in the figure, the electronic device can include one or more (only one is shown in the figure) processors 1002, a memory 1004, a storage controller, and a peripheral interface, wherein the peripheral interface is connected with a radio frequency module, an audio module, and a display. Figure 4 Figure 4 The memory can be used to store software programs and modules, such as program instructions / modules corresponding to the methods and devices in the embodiments of the present application. The processor executes various functions and data processing by running the software programs and modules stored in the memory, that is, implements the above-mentioned method. The memory can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory can further include a memory remotely arranged with respect to the processor, which can be connected to the terminal through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0193] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps:
[0194] S1, in the case that the network system is attacked by a network attack, determining a defense weight value corresponding to each of at least one candidate defense strategy, wherein the defense weight matches the type of the network attack;
[0195] S2, running a target defense strategy and calculating a first evaluation value of the target defense strategy, wherein the target defense strategy is a candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate a defense coverage value of executing the target defense strategy;
[0196] S2, running a target defense strategy and calculating a first evaluation value of the target defense strategy, wherein the target defense strategy is a candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate a defense coverage value of executing the target defense strategy;
[0197] S3, simulate the network attack, and calculate a second evaluation value corresponding to each of the at least one candidate defense strategy respectively, wherein the second evaluation value is used to indicate a defense coverage value of the candidate defense strategy;
[0198] S4, increase a defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and the at least one second evaluation value.
[0199] The processor can also call information and application programs stored in the memory through the transmission device to perform the following steps: obtaining a reference data set of the network system, wherein the reference data set is used to indicate access records of the network system; determining that the network system is attacked by the network attack in a case where reference data in the reference data set meets a preset defense condition; and determining a defense weight value corresponding to each of the at least one candidate defense strategy.
[0200] The processor can also call information and application programs stored in the memory through the transmission device to perform the following steps: determining that the network system is attacked by the network attack in a case where the target interface is accessed, wherein the target interface is used to indicate an interface that needs to be accessed in a preset access mode; determining that the network system is attacked by the network attack in a case where an access parameter included in an access instruction of the reference interface exceeds a reference access parameter corresponding to the reference interface; determining that the network system is attacked by the network attack in a case where an access time of the reference interface does not meet a reference access time corresponding to the reference interface; determining that the network system is attacked by the network attack in a case where an access device of the reference interface does not meet a reference access device corresponding to the reference interface; determining that the network system is attacked by the network attack in a case where an access frequency of the reference interface is greater than a preset frequency; determining that the network system is attacked by the network attack in a case where a time interval of multiple accesses of the reference interface is less than a preset time interval; and determining that the network system is attacked by the network attack in a case where an access address change frequency of the multiple accesses of the reference interface is greater than a preset change frequency.
[0201] The processor can also call information and application programs stored in the memory through the transmission device to perform the following steps: determining a data packet received and sent by the network system as the reference data; recording a state of at least one application program running in the network system as the reference data; and determining log data generated in the network system as the reference data.
[0202] The processor can also call information and application programs stored in the memory through the transmission device to perform the following steps: increasing a response frequency of the network system in a case where a network attack is received; generating a reference response according to the network attack in a case where a network attack on the application program is received, wherein the reference response is a response generated according to a response format of the application program; and sending a notification response in a case where the network attack is received, wherein the notification response is used to indicate that a running error occurs in the network system.
[0203] The processor can also call information and application programs stored in the memory through the transmission device to perform the following steps: in the case of receiving a network attack, prohibiting access of a sending account of the network attack; in the case of receiving a network attack, prohibiting access of a sending end address of the network attack.
[0204] In the embodiments of the present application, in the case of a network attack on a network system, a defense weight value corresponding to each of at least one candidate defense strategy is determined, wherein the defense weight matches the type of the network attack; a target defense strategy is run, and a first evaluation value of the target defense strategy is calculated, wherein the target defense strategy is a candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate a defense coverage value of executing the target defense strategy; the network attack is simulated, and a second evaluation value corresponding to each of the at least one candidate defense strategy is calculated respectively, wherein the second evaluation value is used to indicate a defense coverage value of executing the candidate defense strategy; and the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and at least one second evaluation value is increased. In the case of facing a network attack, a corresponding defense strategy can be selected according to the weight for different network attacks, and after each attack, a simulated attack can be performed to update the weight of the defense strategy, so that the defense mode for different network attacks is constantly updated. Thus, the technical problem of low security of the network system is solved.
[0205] Those skilled in the art can understand that, Figure 4 The structure shown is only schematic, and the electronic device can also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a palm computer, a Mobile Internet Device (MID), a PAD, or the like. Figure 4 It does not limit the structure of the above-mentioned electronic device. For example, the electronic device can further include more or fewer components (such as a network interface, a display device, etc.) than Figure 4 or have a different configuration than Figure 4 The structure shown.
[0206] Those skilled in the art can understand that all or part of the steps in the above-mentioned embodiments can be completed by a program instructing the related hardware of the terminal device, and the program can be stored in a computer readable storage medium, which can include a flash disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk or an optical disk, etc.
[0207] Embodiment 4
[0208] The embodiment of the present application further provides a storage medium. Optionally, in the embodiment, the storage medium can be used to save the program code executed by the defense method of the network system provided in the first embodiment.
[0209] Optionally, in the embodiment, the storage medium can be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.
[0210] The present application further provides a computer program product adapted to execute the defense method of the network system when executed on a data processing device.
[0211] The serial numbers of the embodiments of the present application are only for description, and do not represent the advantages or disadvantages of the embodiments.
[0212] In the above embodiments of the present application, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0213] In the several embodiments of the present application, it should be understood that the disclosed technology can be implemented in other ways. Of course, the above-described device embodiments are only schematic. For example, the division of units is only a logical function division, and there can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual coupling or direct coupling or communication connection between units can be indirect coupling or communication connection through some interface, unit or module, and can be electrical or other forms.
[0214] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiment.
[0215] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit.
[0216] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or say the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0217] The above is only the preferred embodiment of the present application, and it should be pointed out that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should be considered as the protection scope of the present application.
Claims
1. A defense method of a network system, characterized by, The method comprises the following steps: In the case of network attack on the network system, determining the defense weight value corresponding to each of at least one candidate defense strategy, wherein the defense weight matches the type of the network attack; Running a target defense strategy, and calculating a first evaluation value of the target defense strategy, wherein the target defense strategy is the candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate the defense coverage value of executing the target defense strategy; Simulating the network attack, and calculating a second evaluation value corresponding to each of at least one candidate defense strategy, wherein the second evaluation value is used to indicate the defense coverage value of executing the candidate defense strategy; Increasing the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and at least one second evaluation value.
2. The method of claim 1, wherein, The method comprises the following steps: Obtaining a reference data set of the network system, wherein the reference data set is used to indicate the access record of the network system; In the case that the reference data in the reference data set meets the preset defense condition, determining that the network system is attacked by a network attack; Determining the defense weight value corresponding to each of at least one candidate defense strategy.
3. The method of claim 2, wherein, In the case that the reference data in the reference data set meets the preset defense condition, determining that the network system is attacked by a network attack, comprising at least one of the following: In the case that a target interface is accessed, determining that the network system is attacked by a network attack, wherein the target interface is used to indicate an interface that needs to be accessed in a preset access mode; In the case that the access parameter included in the access instruction of the reference interface exceeds the reference access parameter corresponding to the reference interface, determining that the network system is attacked by a network attack; In the case that the access time of the reference interface does not meet the reference access time corresponding to the reference interface, determining that the network system is attacked by a network attack; In the case that the access device of the reference interface does not meet the reference access device corresponding to the reference interface, determining that the network system is attacked by a network attack; In the case that the access frequency of the reference interface is greater than a preset frequency, determining that the network system is attacked by a network attack; In the case that the time interval of multiple accesses of the reference interface is less than a preset time interval, determining that the network system is attacked by a network attack; In the case that the access address change frequency of multiple accesses of the reference interface is greater than a preset change frequency, determining that the network system is attacked by a network attack.
4. The method of claim 2, wherein, Before obtaining the reference data set of the network system, at least one of the following is included: Determining the data packet received and sent by the network system as the reference data; Recording the state of at least one application program running in the network system as the reference data; Determining the log data generated in the network system as the reference data.
5. The method according to any one of claims 1 to 4, characterized in that, The method comprises the following steps: In the case of receiving the network attack, increasing the response frequency of the network system; In the case of receiving the network attack on the application, a reference response is generated according to the network attack, wherein the reference response is a response generated according to a response format of the application; In the case of receiving the network attack, a notification response is sent, wherein the notification response is used to indicate that a running error occurs in the network system.
6. The method according to any one of claims 1 to 4, characterized in that, The running target defense strategy includes at least one of the following: In the case of receiving the network attack, access of a sending account of the network attack is prohibited; In the case of receiving the network attack, access of a sending end address of the network attack is prohibited.
7. A defense device of a network system characterized by comprising: Comprise: A weight determination unit is configured to determine a defense weight value corresponding to each of at least one candidate defense strategy in the case of a network attack on the network system, wherein the defense weight matches a type of the network attack; A strategy execution unit is configured to run a target defense strategy and calculate a first evaluation value of the target defense strategy, wherein the target defense strategy is the candidate defense strategy corresponding to the maximum defense weight value, and the first evaluation value is used to indicate a defense coverage value of executing the target defense strategy; A simulation unit is configured to simulate the network attack and calculate a second evaluation value corresponding to each of at least one candidate defense strategy, wherein the second evaluation value is used to indicate a defense coverage value of executing the candidate defense strategy; A weight adjustment unit is configured to increase the defense weight value of the candidate defense strategy corresponding to the maximum value of the first evaluation value and at least one second evaluation value.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium comprises a stored executable program, wherein the executable program controls the device where the computer readable storage medium is located to execute the defense method of the network system according to any one of claims 1 to 6 when the executable program is running.
9. An electronic device, comprising: Comprise: A memory storing an executable program; A processor configured to run the program, wherein the program is executed when the program is running to execute the method according to any one of claims 1 to 6.
10. A computer program product comprising computer instructions, characterized in that, The computer instructions are executed by the processor to implement the steps of the method according to any one of claims 1 to 6.