Security vulnerability detection method and device, computer equipment and storage medium
By sending probe messages to the detected end, receiving response messages, and analyzing sparse byte values, the problem of easy circumvention by static comparison methods is solved, and efficient and accurate detection of vulnerabilities in complex protocol environments is achieved.
Patent Information
- Application Number
- CN202511124387.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-12
- Publication Date
- 2025-11-14
AI Technical Summary
Existing static field value comparison methods are susceptible to circumvention by field encoding distortion, field reorganization, and multi-stage triggering mechanisms in vulnerability detection, resulting in high false negative rates, low accuracy, and difficulty in identifying logical or temporal vulnerabilities in complex protocol environments.
By sending probe messages to the target device and receiving response messages, the security vulnerability detection results are determined based on the frequency of occurrence and reference value range of sparse byte values in the response messages. The precise identification is achieved by utilizing the correlation between timing and byte values, thereby improving detection accuracy and efficiency.
It effectively reduces false positives, improves the accuracy and efficiency of vulnerability detection, and can identify vulnerabilities in complex protocol environments that are difficult to detect using traditional methods.
Smart Images

Figure CN120956475A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vulnerability detection technology, and in particular to a security vulnerability detection method, apparatus, computer equipment, and storage medium. Background Technology
[0002] The field of vulnerability detection technology encompasses the detection, research, and implementation of potential security vulnerabilities in computer systems, network infrastructure, and software application environments. Its core technical content lies in identifying security weaknesses within information systems and discovering vulnerabilities that may be exploited by attackers by analyzing multi-dimensional data such as system configuration, code logic, network communication, and user behavior.
[0003] Currently, vulnerability detection typically relies on static field value comparisons to identify potential abnormal behavior. Specifically, the detection system usually pre-sets a set of "suspicious fields" as a comparison template, and matches each key protocol field in the data packets of the detected device. If a key protocol field contains a field that is identical to a suspicious field, the detected device is deemed to have a potential security vulnerability.
[0004] For example, in industrial communication protocols, if "Function Code Field 0x08 (Diagnosis)" is set as the comparison template, and "Function Code Field 0x08" is included in the key protocol fields, then since system information can be read through "Function Code Field 0x08", it is considered that the tested end may have a security vulnerability.
[0005] However, the aforementioned static rules are easily circumvented by field encoding distortion, field reorganization, or multi-stage triggering mechanisms. Attackers can evade static rule matching by making only minor changes to byte values, resulting in false negatives and low vulnerability detection accuracy. Summary of the Invention
[0006] Therefore, it is necessary to provide a security vulnerability detection method, device, computer equipment, and storage medium to address the aforementioned technical problems.
[0007] Firstly, this application provides a security vulnerability detection method, including:
[0008] Send at least one probe message to the detected end and receive a response message from the detected end based on each probe message;
[0009] For each response message, based on the number of times each byte value in the response message appears in each response message, a sparse byte value is selected from each byte value, and based on the field value of the target field to which the sparse byte value in the response message belongs and the reference value range, the security vulnerability detection result of the detected end under the response message is determined;
[0010] Based on the security vulnerability detection results of the detected endpoint under each response message, the target security vulnerability detection result of the detected endpoint is determined.
[0011] In one embodiment, determining the security vulnerability detection result of the detected terminal under the response message based on the field value and reference value range of the target field to which the sparse byte value belongs in the response message includes:
[0012] The process involves determining the length of the reference value range of the target field to which the sparse byte value belongs in the response message; determining the distance between the field value of the target field and the reference value range; determining the field value deviation of the target field based on the distance and the range length; and determining the security vulnerability detection result of the detected end under the response message based on the field value deviation.
[0013] In one embodiment, selecting sparse byte values from the byte values based on the number of times each byte value appears in each of the response messages includes:
[0014] Based on the number of times each byte value appears in each response message and the total number of byte values in each response message, the occurrence frequency corresponding to each byte value is determined. For each byte value, a frequency threshold corresponding to the byte value is determined based on the occurrence frequency corresponding to the byte value, the occurrence frequency of byte values at a specified position in a first number of response messages preceding the response message, and the occurrence frequency of byte values at a specified position in a first number of response messages following the response message. Wherein, the specified position is the same as the position of the byte value in the response message. The frequency threshold and occurrence frequency corresponding to each byte value are compared to filter out sparse byte values whose occurrence frequency is lower than the corresponding frequency threshold from each byte value.
[0015] In one embodiment, determining the frequency threshold corresponding to the byte value based on the occurrence frequency of the byte value, the occurrence frequency of the byte value at a specified position in a first number of response messages preceding the response message, and the occurrence frequency of the byte value at a specified position in a first number of response messages following the response message includes:
[0016] The frequency of occurrence of byte values at specified positions in a first number of response messages preceding the response message, and the frequency of occurrence of byte values at specified positions in a first number of response messages following the response message are obtained. The average frequency of each occurrence and the frequency of occurrence of the byte value is calculated. Based on the differences between each occurrence frequency and the frequency of occurrence of the byte value and the average frequency, and the frequency difference between two adjacent occurrence frequencies of each occurrence frequency and the frequency of occurrence of the byte value, the weight corresponding to the byte value is determined. A preset benchmark threshold is weighted based on the weight to obtain the frequency threshold of the byte value.
[0017] In one embodiment, the reference value range of the target field to which the sparse byte value belongs is determined in the following way:
[0018] From the field values contained in each historical response message, find the field value sequence corresponding to the target field; use a sliding window with a set sliding step size to slide on the field value sequence corresponding to the target field, and determine the first degree of change of the field value within the sliding window during the sliding process; based on the value range of the field value within the sliding window where the first degree of change is greater than the first degree of change threshold, determine the reference value range of the target field.
[0019] In one embodiment, determining the reference value range of the target field based on the value range of the field within a sliding window where the first degree of change is greater than a first degree of change threshold includes:
[0020] Based on the range of field values within a sliding window where the first degree of change is greater than a first degree of change threshold, and a comprehensive range of values, the maximum and minimum field values are determined, wherein the comprehensive range of values consists of a second consecutive number of ranges of field values within a sliding window where the first degree of change is greater than a second degree of change threshold; and based on the maximum and minimum field values, a reference range of values for the target field is determined.
[0021] In one embodiment, the use of a sliding window, with a set sliding step size, slides across the sequence of field values corresponding to the target field, and during the sliding process, determines a first degree of change of the field values within the sliding window, including:
[0022] Based on the field values contained in the field value sequence, the fluctuation degree of the field value of the target field is determined; if the fluctuation degree is greater than a preset degree, the second degree of change of the target field is determined; if the second degree of change is greater than the second degree of change threshold, a sliding window is used to slide on the field value sequence corresponding to the target field with a set sliding step size, and during the sliding process, the first degree of change of the field value within the sliding window is determined.
[0023] Secondly, this application also provides a security vulnerability detection device, comprising:
[0024] The transmission module is used to send at least one probe message to the detected end and receive a response message from the detected end based on each probe message.
[0025] The detection module is used to select sparse byte values from each byte value according to the number of times each byte value in the response message appears in each response message, and determine the security vulnerability detection result of the detected end under the response message according to the field value of the target field to which the sparse byte value belongs and the reference value range in the response message.
[0026] The determination module is used to determine the target security vulnerability detection result of the detected terminal based on the security vulnerability detection results of the detected terminal under each response message.
[0027] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the various method embodiments provided in the first aspect above.
[0028] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the various method embodiments provided in the first aspect above.
[0029] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the various method embodiments provided in the first aspect above.
[0030] The aforementioned security vulnerability detection methods, devices, computer equipment, computer-readable storage media, and computer program products involve the detection end actively sending at least one probe message to the detected end and receiving response messages from the detected end based on each probe message. Then, detection is performed on each response message to determine the security vulnerability detection result of the detected end under each response message. Based on the security vulnerability detection results of the detected end under each response message, the target security vulnerability detection result of the detected end is determined.
[0031] When inspecting each response message, firstly, based on the frequency of each byte value in each response message across all response messages, sparse byte values with fewer occurrences are selected from the byte values contained in the response messages. This fully explores the temporal and byte value correlations in each response message, thereby achieving accurate identification of sparse byte values. Then, based on the field value and reference value range of the target field to which the sparse byte value belongs in the response message, the security vulnerability detection result for the tested end is determined under the response message. By judging the byte value of the target field through a pre-determined reference value range, the security vulnerability detection result is determined, improving the accuracy and efficiency of vulnerability detection.
[0032] In the above method, sparse byte values contained in the current response message are filtered out based on the frequency of occurrence of the byte values in each response message. By fully utilizing the temporal and byte value linkage relationships between each response message, target fields containing sparse byte values that may be abnormal are initially screened out, improving the accuracy of target field identification. Then, the field value of the target field is detected to quickly obtain the security vulnerability detection results under the current response message. Combined with the security vulnerability detection results under each response message, the security vulnerability detection results of the detected end are obtained. By identifying vulnerabilities through layer-by-layer convergence, false positives are reduced, and the accuracy and efficiency of security vulnerability detection on the detected end are improved. Attached Figure Description
[0033] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0034] Figure 1 This is a diagram illustrating the application environment of a security vulnerability detection method in one embodiment.
[0035] Figure 2 This is a flowchart illustrating a security vulnerability detection method in one embodiment;
[0036] Figure 3 This is a flowchart illustrating the steps for determining security vulnerability detection results in one embodiment;
[0037] Figure 4 This is a flowchart illustrating the step of selecting sparse byte values in one embodiment;
[0038] Figure 5 This is a flowchart illustrating the steps for determining the frequency threshold corresponding to a byte value in one embodiment.
[0039] Figure 6This is a flowchart illustrating the steps for determining the reference value range of a target field in one embodiment;
[0040] Figure 7 This is a flowchart illustrating the step of determining the reference value range of the target field in another embodiment;
[0041] Figure 8 This is a schematic diagram of the overall process of a security vulnerability detection method in one embodiment;
[0042] Figure 9 This is a structural block diagram of a security vulnerability detection device in one embodiment;
[0043] Figure 10 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0044] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0045] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.
[0046] The design concept of this application is briefly introduced below:
[0047] The field of vulnerability detection technology encompasses the detection, research, and implementation of potential security vulnerabilities in computer systems, network infrastructure, and software application environments. Its core technological content lies in identifying security weaknesses within information systems. This is achieved by analyzing multi-dimensional data, including system configuration, code logic, network communication, and user behavior, to discover vulnerabilities that attackers may exploit. Static analysis primarily relies on scanning and analyzing source code or binary files.
[0048] Currently, vulnerability detection typically relies on static field value comparison and macro-level traffic statistics to identify potential abnormal behavior. Taking static field value comparison as an example, the detection system usually presets a set of "suspicious fields" as a comparison template, matching each key protocol field in the data packets of the detected endpoint. If a key protocol field contains a field identical to a suspicious field, the detected endpoint is deemed to have a potential security vulnerability. For example:
[0049] In the Hypertext Transfer Protocol (HTTP), if the "User-Agent" field contains strings such as "sqlmap" or "curl", it is marked as an automated scanning tool, indicating that the detected device may have security vulnerabilities.
[0050] In the Modbus communication protocol of programmable controllers, "Function Code Field 0x08 (Diagnosis)" is set as the comparison template. If "Function Code Field 0x08" is included in the key protocol fields, the system information can be read through "Function Code Field 0x08", so the tested end is considered to have a potential security vulnerability.
[0051] In the Domain Name System (DNS) protocol, if the query type is "0x00FF", it may trigger a DNS amplification attack. The detection end will reject or limit the query based on this, believing that the detected end may have a security vulnerability.
[0052] In the Simple Mail Transfer Protocol (SMTP), if the sender's domain name appears in a blacklist, such as "admin@evil.com", the connection request may be identified as a phishing attack, indicating that the detected end may have a security vulnerability.
[0053] However, the aforementioned static rules lack context and timing awareness, making them susceptible to evasion through field encoding distortion, field reorganization, or multi-stage triggering mechanisms. Furthermore, they struggle to effectively identify "logical" or "timing" vulnerabilities that require continuous interaction to expose. Especially in complex protocol environments, attackers can evade static rule matching by carefully configuring field dependencies, inserting legitimate spoofed requests, or making only minor changes to byte values, leading to false negatives. Additionally, overly broad rule definitions can increase false positive rates, posing a challenge to the detection accuracy of actual systems.
[0054] Furthermore, attackers can circumvent static matching rules by exploiting "byte fluctuations," specifically as follows:
[0055] Feature perturbation avoidance: Avoid keyword-based pattern matching by performing slight character transformations on sensitive fields (such as "sql_map", "sqlmap_v1", "sqlmap");
[0056] Field position offset avoidance: Insert extra fields into the data packet or change the protocol encapsulation order to make field detection based on fixed offsets in static rules ineffective, such as changing the function code from offset 1 to offset 2;
[0057] Content encoding avoidance: Use methods such as binary data encoding based on 64 specific characters (Base64 encoding), Uniform Resource Locator (URL) encoding, and hexadecimal segment concatenation to re-encode sensitive content, bypassing the matching engine based on plaintext rules;
[0058] Minor variation interference matching: Perturb 1 to 2 bits in the key byte of the response message, such as changing the key byte of the "Set-Cookie" field to "0x2E (".")" or replacing a letter, so that it cannot match the static feature;
[0059] These circumvention methods interfere with traditional matching mechanisms by creating "legitimate but abnormal" byte distributions, making them highly concealed and difficult to identify directly. Therefore, the aforementioned static detection methods have blind spots in actual attack detection, resulting in low vulnerability detection accuracy.
[0060] In view of this, embodiments of this application propose a security vulnerability detection method, apparatus, computer device, computer-readable storage medium, and computer program product. The detection end actively sends at least one probe message to the detected end and receives response messages from the detected end based on each probe message. Then, it performs detection on each response message to determine the security vulnerability detection result of the detected end under the response message. Based on the security vulnerability detection result of the detected end under each response message, it determines the target security vulnerability detection result of the detected end.
[0061] When inspecting each response message, firstly, based on the frequency of each byte value in each response message across all response messages, sparse byte values with fewer occurrences are selected from the byte values contained in the response messages. This fully explores the temporal and byte value correlations in each response message, thereby achieving accurate identification of sparse byte values. Then, based on the field value and reference value range of the target field to which the sparse byte value belongs in the response message, the security vulnerability detection result for the tested end is determined under the response message. By judging the byte value of the target field through a pre-determined reference value range, the security vulnerability detection result is determined, improving the accuracy and efficiency of vulnerability detection.
[0062] In the above method, sparse byte values contained in the current response message are filtered out based on the frequency of occurrence of the byte values in each response message. By fully utilizing the temporal and byte value linkage relationships between each response message, target fields containing sparse byte values that may be abnormal are initially screened out, improving the accuracy of target field identification. Then, the field value of the target field is detected to quickly obtain the security vulnerability detection results under the current response message. Combined with the security vulnerability detection results under each response message, the security vulnerability detection results of the detected end are obtained. By identifying vulnerabilities through layer-by-layer convergence, false positives are reduced, and the accuracy and efficiency of security vulnerability detection on the detected end are improved.
[0063] The security vulnerability detection method provided in this application embodiment can be applied to, for example... Figure 1 The application environment shown includes a monitored terminal 102 and a monitoring terminal 104. The monitored terminal 102 communicates with the monitoring terminal 104 via a network. A data storage system can store the data that the monitoring terminal 104 needs to process. The data storage system can be integrated into the monitoring terminal 104 or placed in the cloud or on other network servers. The monitored terminal 102 can be any device that needs to perform security vulnerability detection, such as a terminal or server, while the monitoring terminal 104 can be a server. Terminals can be, but are not limited to, various personal computers, laptops, smartphones, and tablets. Servers can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers providing cloud computing services.
[0064] The security vulnerability detection method in this embodiment can be executed by the detected end 102 alone, by the detection end 104 alone, or by both the detected end 102 and the detection end 104. Taking the joint execution by the detected end 102 and the detection end 104 as an example, the detection end 104 sends at least one probe message to the detected end 102 and receives the response message fed back by the detected end 102 based on each probe message. For each response message, the detection end 104 selects sparse byte values from each byte value according to the number of times each byte value in the response message appears in each response message, and determines the security vulnerability detection result of the detected end under the response message according to the field value of the target field to which the sparse byte value belongs and the reference value range. Based on the security vulnerability detection result of the detected end under each response message, the detection end 104 determines the target security vulnerability detection result of the detected end.
[0065] In one exemplary embodiment, such as Figure 2 As shown, a security vulnerability detection method is provided, which can be applied to... Figure 1 Taking the tested terminal 104 as an example, the explanation includes:
[0066] S201, send at least one probe message to the detected end, and receive a response message from the detected end based on each probe message.
[0067] The probe message is constructed using a probe payload and can also be called a probe data packet. The response message is the actual data returned after the probe payload has been applied; it consists of the actual byte stream collected during the detection process, including, for example, the server's (e.g., server) HTTP response headers and data return fields. The probe message is actively constructed and sent to the detected system by the detection end, which can also be called a vulnerability detection system. The detection end has both sending and receiving capabilities, and the detected system can be a server, a remote device, a communication protocol terminal, etc.
[0068] Optionally, the structure and content of each detection message can be the same or different. When the detection end sends a probe message to the detected end, the detected end can return a response message or multiple response messages to the detection end.
[0069] In one embodiment, when the detection end sends at least one probe message to the detected end, it selects the communication protocol to use, such as HTTP, initiates a construction request for a specific path, constructs a probe message, attempts to trigger an abnormal response from the detected end, and then analyzes the received response message to determine whether the detected end has vulnerabilities.
[0070] S202, for each response message, select sparse byte values from each byte value according to the number of times each byte value appears in each response message, and determine the security vulnerability detection result of the detected end under the response message according to the field value of the target field to which the sparse byte value belongs and the reference value range.
[0071] S202 describes the complete process of obtaining the security vulnerability detection result of a response message. First, sparse byte values are selected from the byte values contained in the response message. Sparse byte values refer to byte values that appear less frequently. In this embodiment of the application, sparse byte values are selected based on the number of times the byte value appears in each response message. A response message may contain one or more sparse byte values.
[0072] For example, a frequency threshold can be set. When the number of occurrences of a byte value is less than the frequency threshold, this byte value is determined to be a sparse byte value. Another example is to set a frequency ratio threshold, count the total number of byte values contained in each response message, determine the ratio of the number of occurrences of a byte value to the total number, and when the ratio is less than the ratio threshold, this byte value is determined to be a sparse byte value.
[0073] The field to which each sparse byte value belongs is called the target field. For each target field, a reference value range is pre-defined. Based on the relationship between the field value of the target field and the reference value range, it can be determined whether there is a security vulnerability on the detected end, that is, the security vulnerability detection result is determined.
[0074] For example, if the value of the target field is within the reference value range, it is determined that there is no security vulnerability on the tested end; if the value of the target field is not within the reference value range, it is determined that there is a security vulnerability on the tested end.
[0075] For example, the existence of a security vulnerability can be determined based on the distance between the target field value and the reference value range. Specifically, a distance threshold can be set; if the distance between the target field value and the reference value range is greater than the distance threshold, a security vulnerability is identified in the tested device. Alternatively, a distance ratio threshold can be set; if the ratio of the distance between the target field value and the reference value range to the range length is greater than the distance ratio threshold, a security vulnerability is identified in the tested device. Both the distance threshold and the distance ratio threshold can be set based on experience, multiple trials, and actual needs, and are not specifically limited here.
[0076] Taking a reference value range of (10, 50), a target field value of 60, and a distance ratio threshold of 20% as an example, the distance between the target field value and the reference value range is 10, the range length is 40, and the ratio of distance to range length is 25%, which is greater than the distance ratio threshold of 20%, thus confirming that there is a security vulnerability in the detected end.
[0077] S203. Based on the security vulnerability detection results of the detected end under each response message, determine the target security vulnerability detection results of the detected end.
[0078] Specifically, the target security vulnerability detection results can include detailed security vulnerability detection results from each response message. For example, the target security vulnerability detection results may include security vulnerability detection results indicating the existence of a security vulnerability. This allows security technicians to understand the relevant content of the detected vulnerability based on the security vulnerability detection results indicating the existence of a security vulnerability. Alternatively, the target security vulnerability detection results may simply include "vulnerability exists" or "vulnerability does not exist." This allows security technicians to intuitively understand whether the detected end has a security vulnerability. For example, when all security vulnerability detection results indicate that there is no security vulnerability, the target security vulnerability detection result indicates that there is no vulnerability. When all security vulnerability detection results include a security vulnerability detection result indicating the existence of a security vulnerability, the target security vulnerability detection result indicates that there is a vulnerability.
[0079] In this embodiment of the application, the detection end actively sends at least one probe message to the detected end and receives the response message fed back by the detected end based on each probe message. Then, it performs detection on each response message to determine the security vulnerability detection result of the detected end under the response message. Based on the security vulnerability detection result of the detected end under each response message, it determines the target security vulnerability detection result of the detected end.
[0080] When inspecting each response message, firstly, based on the frequency of each byte value in each response message across all response messages, sparse byte values with fewer occurrences are selected from the byte values contained in the response messages. This fully explores the temporal and byte value correlations in each response message, thereby achieving accurate identification of sparse byte values. Then, based on the field value and reference value range of the target field to which the sparse byte value belongs in the response message, the security vulnerability detection result for the tested end is determined under the response message. By judging the byte value of the target field through a pre-determined reference value range, the security vulnerability detection result is determined, improving the accuracy and efficiency of vulnerability detection.
[0081] In the above method, sparse byte values contained in the current response message are filtered out based on the frequency of occurrence of the byte values in each response message. By fully utilizing the temporal and byte value linkage relationships between each response message, target fields containing sparse byte values that may be abnormal are initially screened out, improving the accuracy of target field identification. Then, the field value of the target field is detected to quickly obtain the security vulnerability detection results under the current response message. Combined with the security vulnerability detection results under each response message, the security vulnerability detection results of the detected end are obtained. By identifying vulnerabilities through layer-by-layer convergence, false positives are reduced, and the accuracy and efficiency of security vulnerability detection on the detected end are improved.
[0082] In one embodiment, such as Figure 3 As shown, S202 determines the security vulnerability detection results of the detected endpoint in the response message, including:
[0083] S301, determine the length of the reference value range of the target field to which the sparse byte value in the response message belongs; and determine the distance between the field value of the target field and the reference value range.
[0084] S302, determine the deviation of the target field value based on the distance and interval length.
[0085] S303, determine the security vulnerability detection result of the detected end in the response message based on the deviation of the field value.
[0086] The interval length is the difference between the two endpoints of the reference value interval. Optionally, the two endpoints of the reference value interval include a first endpoint value and a second endpoint value; wherein the second endpoint value is greater than the first endpoint value. In an optional embodiment, the absolute value of the difference between the target field value and the target endpoint value can be determined as the distance between the target field value and the reference value interval, and the target endpoint value is either the first endpoint value or the second endpoint value. Optionally, the endpoint value closest to the target field value can be selected from the first endpoint value and the second endpoint value as the target endpoint value.
[0087] Field value deviation is used to characterize the degree to which the field value of a target field deviates from the reference value range.
[0088] For example, the field value deviation can be determined based on the relationship between distance and interval length. This can be done by determining the field value deviation based on the ratio of distance to interval length. For instance, if the field value of target field 1 is 15, the reference value interval is [20, 30], the distance between the field value and the reference value interval is 20 - 15 = 5, and the interval length is 10, then the field value deviation is 50%.
[0089] When determining the security vulnerability detection result based on the deviation of field values, the relationship between the field value deviation and a preset deviation threshold can be considered. For example, if the field value deviation is 50% and the deviation threshold is 30%, then the field value deviation is greater than the deviation threshold, and the security vulnerability detection result is determined to be a vulnerability. Conversely, if the field value deviation is 10% and the deviation threshold is 30%, then the field value deviation is not greater than the deviation threshold, and the security vulnerability detection result is determined to be a vulnerability that does not exist. The deviation threshold can be set based on experience, multiple experiments, and actual needs, and is not specifically limited here.
[0090] It should be noted that if the value of the target field is within the reference value range, the field value deviation is 0, and the security vulnerability detection result is that there is no vulnerability.
[0091] By using the above method, a vulnerability is identified when the value of the target field deviates significantly from the reference value range, rather than simply assuming that a vulnerability exists because the value of the target field does not belong to the reference value range. This fully considers the normal fluctuation of field values, avoids false positives, and improves the accuracy of vulnerability detection.
[0092] In practical applications, optionally, when multiple sparse byte values exist, i.e., multiple target fields may exist, the reference value range and the field value in the current response message are extracted for each target field. For example, the reference value range for field 1 is 10 to 50, and the parsed field value in the current response message is 34. It is compared with the reference value range to determine whether it is within the range. If the field value in the current response message falls within the reference value range, it is considered to have no deviation, and the offset is 0. If the field value in the current response message exceeds the upper limit of the reference value range or is lower than the lower limit, the field value deviation needs to be calculated. If the field value in the current response message is 60, which is higher than the upper limit of 10, the deviation is 10, the interval length of the reference value range is 40, and the field value deviation is 25%. If the field value is 5, which is lower than the lower limit of 5, the deviation is 5, and the field value deviation is 12.5%.
[0093] The deviation of each target field value is determined sequentially using the above method. The larger the deviation, the more obvious the deviation between the field value and the reference value range. The deviation of all target fields is stored using the field index as an identifier. For example, the deviation of field value for field index 1 is 0%, the deviation of field value for field index 2 is 25%, the deviation of field value for field index 3 is 12.5%, etc., which is used to locate abnormal fields.
[0094] Based on field value deviation, the system identifies fields that deviate from the reference value range. A deviation threshold of 10% is set, and each target field is filtered. Target fields with a deviation exceeding 10% are identified as deviating fields. The starting and ending offset positions of these target fields in the response message are extracted. For example, the target field corresponding to field index 2 has a field value deviation of 25%, with its starting and ending offset positions being offsets 6 to 9 respectively. The field name, field value deviation, and field index are combined to form abnormal field information entries. Multiple abnormal field information entries are compiled into a complete dataset. Each data record includes a field index, field name, and starting and ending offset positions. This dataset serves as the basis for subsequent vulnerability assessments. For example, it may include field index 2 named Field C with offsets 6 to 9, field index 4 named Field E with offsets 12 to 15, etc. This set of information is organized and output through a mapping structure to ensure that the identified vulnerabilities are locatable and verifiable.
[0095] It should be noted that the specific values of the reference ranges and deviation thresholds listed above are for illustrative purposes only and do not constitute a limitation on this application.
[0096] In one embodiment, such as Figure 4 As shown, in S202, sparse byte values are selected from each byte value, including:
[0097] S401, determine the frequency of occurrence of each byte value based on the number of times each byte value appears in each response message and the total number of byte values in each response message.
[0098] For example, each response message contains 64 bytes, and the response messages are response messages 1-10 ordered by the receiving time. Then the total number of byte values is 64*10=640. The current response message is response message 3. Among them, the number of times byte value 1 appears in response messages 1-10 is 16, so the frequency of occurrence of byte value 1 is 2.5%.
[0099] Optionally, after receiving each response message returned by the detected end, the offset position and byte value of each byte in the fields contained in the response message are extracted. For example, in the Content-Type field, the byte value of the byte at offset position 10 is 0x3A, the byte value of the byte at offset position 11 is 0x20, and so on, to construct a set of triples containing field name, offset position and byte value.
[0100] Subsequently, for all response messages, the byte values at each offset position are cumulatively counted according to the byte value range of 0 to 255. For example, the byte value at offset position 25 is 0x5C, which appears 7 times in 100 response messages, so its frequency is 7%. This process continues to traverse all positions and merge to determine the global occurrence frequency (i.e., the number of occurrences) of each byte value, and finally converts it into a unified frequency sequence. Each frequency reflects the relative proportion of the corresponding byte value in the overall response byte stream, such as 0x00 accounting for 3%, 0x2F accounting for 5%, 0x7A accounting for 12%, etc. This frequency sequence is used to subsequently evaluate which byte values in the response messages are relatively rare (i.e., sparse byte values). When detecting changes in the response of a certain type of application, such as a web application where the offset position of the Set-Cookie field near the injection point fluctuates greatly, abnormal byte areas that may be affected by the vulnerability can be identified.
[0101] S402, for each byte value, determine the frequency threshold corresponding to the byte value based on the occurrence frequency of the byte value, the occurrence frequency of the byte value at a specified position in the first number of response messages before the response message, and the occurrence frequency of the byte value at a specified position in the first number of response messages after the response message.
[0102] The first quantity can be set according to the requirements. Taking the current response message as response message 5 and the first quantity as 2 as an example, the first quantity of response messages before the current response message is the two response messages before response message 5, namely response message 3 and response message 4. The first quantity of response messages after the current response message is the two response messages after response message 5, namely response message 6 and response message 7.
[0103] The specified position is the same as the position of the byte value in the response message. For example, when determining the frequency threshold corresponding to byte value 10 in response message 5, byte value 10 is the 10th byte value in the response message, and the specified position is the 10th byte value in the response message. Thus, the frequency threshold corresponding to byte value 10 in response message 5 is determined based on the occurrence frequency of byte value 10, the occurrence frequency of the 10th byte value in response messages 3 and 4, and the occurrence frequency of the 10th byte value in response messages 6 and 7, a total of 5 occurrence frequencies.
[0104] For ease of description, the frequency of occurrence of the corresponding byte value, the frequency of occurrence of the byte value at a specified position in the first number of response messages before the response message, and the frequency of occurrence of the byte value at a specified position in the first number of response messages after the response message are collectively referred to as the frequency threshold-related frequency of occurrence. For example, when determining the frequency threshold 10 corresponding to the byte value 10 in response message 5, the frequency threshold corresponding to the byte value 10 in response message 5 is based on the frequency of occurrence of the byte value 10, the frequency of occurrence of the 10th byte value in response messages 3 and 4, and the frequency of occurrence of the 10th byte value in response messages 6 and 7, and is referred to as the frequency threshold 10-related frequency of occurrence.
[0105] After determining the frequency of occurrence of the correlation pairs, the average frequency of occurrence of each correlation can be used as the frequency threshold. Alternatively, the highest and lowest frequency of occurrence of a correlation can be removed, and the average frequency of occurrence of the remaining correlation pairs can be used as the frequency threshold. Other calculations can be performed on the frequency thresholds of each correlation pair to obtain the frequency threshold. No specific limitations are made here.
[0106] S403, compare the frequency threshold and occurrence frequency corresponding to each byte value to filter out sparse byte values whose occurrence frequency is lower than the corresponding frequency threshold from each byte value.
[0107] Understandably, if the frequency of a byte value is lower than the corresponding frequency threshold, it indicates that the byte value appears less frequently in each response message and is relatively rare. The probability that this byte value is abnormal is relatively high. Therefore, such byte values are called sparse byte values and are further detected.
[0108] By using the above method, the occurrence frequency of byte values in each response message and the total number of byte values in each response message are used to determine whether a byte value is a sparse byte value. Compared with the method of vulnerability detection based on only one response message, this method can fully explore the temporal sequence and byte value relationship of each response message, improve the accuracy of sparse byte value identification, and thus further detect vulnerabilities based on sparse byte values, thereby improving the accuracy of vulnerability detection.
[0109] Optionally, after filtering out sparse byte values from each byte value, the actual position of each sparse byte value in the response message is retrieved sequentially. The field name (i.e., the field name of the target field) and offset of the sparse byte value are located, and the total number of times it appears at that offset is recorded. For example, byte value 0x20 appears 9 times at offset position 18 in the Server field, and byte value 0x00 appears 3 times at offset position 22 in the ETag field. After recording each value, a data structure containing field name, offset position, byte value, and frequency of occurrence is established. Then, the data is categorized and organized by field. For example, the offset positions where the sparse byte values appear in the Header field are concentrated at positions 10, 14, and 17, etc. The byte values are 0x00, 0x2F, and 0x4B, with frequencies of 6, 4, and 2 respectively. This information is grouped into offset path indices, such as Header-10-0x00-6, Header-14-0x2F-4, and Header-17-0x4B-2, ultimately forming a sparse response byte list. This list can be used to help mark which locations might be overwritten by constructed data when analyzing whether a specific vulnerability affects a specific response field. For example, in the HTTP response header, some offset segments may have byte value distribution offsets due to injection testing. This list can be used to trace the source of abnormal bytes and combine them with the original response message data for difference tracking.
[0110] In one embodiment, when determining the target field to which each sparse byte belongs, if multiple sparse bytes belong to the same target field, then the multiple sparse bytes form a sparse byte segment. If the position of the sparse byte segment is from offset position 2 to offset position 5, combined with the field structure information of the response message, field A has a starting offset of 0 and a length of 2, field B has a starting offset of 2 and a length of 4, and field C has a starting offset of 6 and a length of 1. Converting the field structure to a byte range, we get: field A is 0 to 1, field B is 2 to 5, and field C is 6. The sparse byte segment overlaps with field B, confirming that the field index corresponding to this sparse segment is 1. Then, we compare the definition of field B in the field structure information of the segment, including the name, starting position, and length, to determine whether the field index accurately corresponds to the byte segment. The system verifies the sparse byte segment by comparing its start and end positions with the field definition. If the sparse byte segment falls entirely within the field definition, the field is considered a successful match. For example, if field B is defined as starting offset 2 and length 4, a sparse byte segment offset range of 2 to 5 would be a perfect match. Conversely, if the offset range is 3 to 6, the starting offsets are inconsistent and considered a mismatch. This method is used to analyze the mapping of each sparse byte segment, and the indexes of successfully matched fields and their corresponding byte segments are registered to generate a mapping table. For example, offset range 2 to 5 corresponds to field index 1, offset range 6 to 6 corresponds to field index 2, and so on. This ultimately forms a set of information on the correspondence between field indices and offset ranges, facilitating the analysis of the actual offset range in the response message corresponding to each sparse byte segment, thereby determining the target message.
[0111] In one embodiment, such as Figure 5 As shown, determining the frequency threshold corresponding to the byte value in S402 includes:
[0112] S501, obtain the frequency of occurrence of the byte value at a specified position in the first number of response messages before the response message, and the frequency of occurrence of the byte value at a specified position in the first number of response messages after the response message.
[0113] S502, perform an average calculation on the frequency of each occurrence and the frequency of each byte value to obtain the average frequency.
[0114] S503, based on the difference between the obtained occurrence frequency and the occurrence frequency of each byte value and the average frequency, and the frequency difference between two adjacent occurrence frequencies among the obtained occurrence frequencies and byte values, determine the weight corresponding to the byte value.
[0115] S504: The preset baseline threshold is weighted based on the weights to obtain the frequency threshold of the byte value.
[0116] To more accurately describe the process of determining the frequency threshold corresponding to the byte value described in S501-S504, this application embodiment will use the determination of the frequency threshold 3 corresponding to the byte value 3 in the response message 5 as an example for illustration.
[0117] First, obtain the frequency P of the third byte value in response message 3. 33 The frequency of occurrence P of the third byte value in response message 4 43 The frequency of occurrence P of the third byte value in response message 6 63 The frequency of occurrence P of the third byte value in response message 7 73 The frequency of the byte value 3 is P. 53 Secondly, regarding P 33 P 43 P 53 P 63 P 73 Perform a mean operation to obtain the frequency mean P. Then, the difference between the frequency of each occurrence and the frequency of each byte value and the frequency mean is: P. 33 P 43 P 53 P 63 P 73 The difference C between each and P 33 C 43 C 53 C 63 C 73The frequency difference between two adjacent frequencies among the obtained frequencies of occurrence and byte values is: P 33 and P 43 Frequency difference C 34 P 43 and P 53 Frequency difference C 45 P 53 and P 63 Frequency difference C 56 P 63 and P 73 Frequency difference C 67 Based on the obtained difference C 33 C 43 C 53 C 63 C 73 and frequency difference C 34 C 45 C 56 C 67 Determine the weight corresponding to byte value 3, and weight the baseline threshold based on the weight to obtain frequency threshold 3. The baseline threshold can be set according to requirements, and no specific limitation is made here.
[0118] By using the frequency of occurrence of byte values at the same position in each response message that is adjacent to the timing of the response message, the frequency threshold corresponding to the byte value is determined. This method can fully combine the local fluctuation characteristics and global dispersion of each occurrence frequency, and flexibly determine the frequency threshold. Compared with the fixed threshold method, it can more accurately distinguish between normal fluctuations and low-frequency anomalies of byte values, and improve the accuracy of sparse byte value identification.
[0119] Optionally, the frequency threshold corresponding to the byte value can also be called the adaptive threshold parameter, and the adaptive threshold parameter T adj The specific calculation formula is as follows:
[0120]
[0121] Among them, T base P represents the baseline threshold (dimensionless). k This represents the dimensionless frequency of the byte value appearing in the k-th response message at the specified position. The frequency mean (dimensionless) is represented by δ, where two adjacent frequencies are grouped together. m ε is the absolute value (dimensionless) of the frequency difference between two adjacent frequencies in the m-th group, ε is the minimum constant to prevent the denominator from being zero, and n is the number of groups of two adjacent frequencies. When the first number is 2, n is 4.
[0122] Specifically, T baseBy analyzing the distribution characteristics of low-frequency bytes in historical data, and based on publicly available datasets, it was determined that the frequency of sparse byte values generally falls between 0.01 and 0.05. The median value of 0.03 was selected as T. base .
[0123] δ m It is obtained by calculating the frequency difference between two adjacent occurrences. For example, if the occurrence frequencies of byte values 0x1A and 0x2B are 0.00488 and 0.00625 respectively, then δ... m-1 =|0.00488-0.00625| = 0.00137.
[0124] To obtain T adj Taking 0.3 as an example, this value represents the dynamically adjusted sparsity threshold (frequency threshold). When the frequency of a byte value is less than 0.3, it is judged as a sparse byte. The frequency threshold combines local fluctuation characteristics with global dispersion, making it more suitable for the byte characteristics in the message than a fixed threshold.
[0125] It should be noted that the specific values of the benchmark thresholds and frequencies of occurrence listed above are merely illustrative examples and do not constitute a limitation on this application.
[0126] The above formula (1) achieves dynamic threshold adjustment through the coordinated operation of the numerator and denominator, with the numerator using the benchmark threshold T. base The product of the sum of the absolute values of the frequency deviations within the data window (±2 offsets) strengthens the threshold response intensity in local mutation regions. The denominator quantifies the overall dispersion of the data by calculating the standard deviation of the frequency difference of the global occurrences and taking the square root. The square root operation is used to eliminate the dimensional square effect caused by the variance operation. The addition of a minimum constant ∈ ensures that the denominator is non-zero. Finally, a dimensionally unified dynamic adjustment mechanism is constructed by calculating the ratio of the local fluctuation intensity of the numerator to the global dispersion of the denominator. When the local mutation is significant, the numerator increases to improve the threshold tolerance. When the global dispersion increases, the denominator expands to suppress the artificially high threshold, forming an adaptive balance control relationship.
[0127] The adaptive threshold parameter is a dynamically adjusted filtering benchmark value, determined by both the local fluctuation characteristics and the global dispersion of each occurrence frequency. This parameter automatically adjusts the threshold level by calculating the ratio of the local deviation intensity (reflecting sudden anomalies) to the overall distribution dispersion (reflecting systemic fluctuations) of the proportion of byte values within the current data window in real time. When local byte values show concentrated abnormal fluctuations, the adaptive threshold parameter is increased accordingly to avoid over-filtering; when the overall data distribution tends to be dispersed, the adaptive threshold parameter is appropriately decreased to enhance filtering sensitivity. This dynamic balancing mechanism allows the adaptive threshold parameter to adapt to different data distribution characteristics, more accurately distinguishing between normal fluctuations and low-frequency anomalies compared to a fixed threshold.
[0128] In one embodiment, such as Figure 6 As shown, the reference value range of the target field to which the sparse byte value belongs is determined through the following steps:
[0129] S601: Search for the sequence of field values corresponding to the target field from the field values contained in each historical response message.
[0130] Specifically, historical response messages are response messages received by the detection end before sending probe messages. The sequence of field values corresponding to the target field consists of the field values of the target field in each historical response message. The order of each field value in the field value sequence is from the oldest to the most recent reception time of the corresponding historical response message.
[0131] S602 uses a sliding window to set a sliding step size, slides on the field value sequence corresponding to the target field, and determines the first degree of change of the field value within the sliding window during the sliding process.
[0132] Specifically, taking the field value sequence [field value 1 field value 2 field value 3 field value 4 field value 5 field value 6 field value 7 field value 8 field value 9 field value 10] as an example, with a sliding step size of 1 field value and the sliding window containing 3 field values, during the sliding process, the first sliding window contains field value 1, field value 2, and field value 3, the second sliding window contains field value 2, field value 3, and field value 4, ..., and the eighth sliding window contains field value 8, field value 9, and field value 10. Therefore, 8 first degrees of change can be obtained during the sliding process.
[0133] The first degree of change is used to characterize the degree of change (also known as the degree of fluctuation) of the field value within the corresponding sliding window. Optionally, the first degree of change is determined based on the size of each field value within the sliding window. The first degree of change can be the difference between the maximum and minimum field values, or it can be the ratio of the difference between the maximum and minimum field values to the number of field values. No specific limitation is made here.
[0134] Taking the difference between the maximum and minimum field values as the first degree of change, and with field value 1 being 11, field value 2 being 13, and field value 3 being 17 in the first sliding window, the first degree of change is 17-11=6.
[0135] S603, based on the range of field values within a sliding window where the first degree of change is greater than the first degree of change threshold, determine the reference value range of the target field.
[0136] The first variability threshold can be determined based on historical data statistics from similar communication systems, or it can be set based on experience and actual needs; no specific limitation is made here. For example, if the average difference between the maximum and minimum field values is determined to be 5 and the standard deviation of fluctuation is 2 based on historical data from similar communication systems, then the first variability threshold is 7.
[0137] The range of field values within a sliding window consists of the maximum and minimum field values within the sliding window. For example, if the first sliding window contains field value 1 as 11, field value 2 as 13, and field value 3 as 17, then the range of field values within the first sliding window is [11, 17].
[0138] The range of field values within a sliding window whose first degree of change is greater than the first degree of change threshold can be called the candidate value range of the target field. Based on each candidate value range of the target field, the target value range is determined. The target value range can be the intersection of each candidate value range, the union of each candidate value range, or the maximum and minimum field values contained in each candidate value range. No specific limitation is made here.
[0139] Using the above method, the reference value range for the target field is obtained based on the corresponding field values in all historical response messages. Compared with setting the reference range directly based on experience, this method can more accurately determine the value range of the target field, thereby determining whether there are any abnormalities in the field value of the target field in the current response message based on the reference value range, and improving the accuracy of vulnerability detection.
[0140] Historical response messages are the responses sent by the monitored endpoint after receiving historical probe messages. By analyzing historical probe messages and historical response messages, the aim is to determine how to construct probe messages in vulnerability detection that can trigger abnormal responses from the monitored endpoint, thereby identifying vulnerabilities. The following processing is performed on historical probe messages:
[0141] In practical applications, optionally, after acquiring the probe data packets (historical probe messages) constructed by the probe payload, the data receiving module needs to perform structural identification and numbering processing on the probe data packet content according to the communication protocol. Assuming a data packet is 64 bytes long and includes fields such as device identifier, data type, measurement value, and status control, during the numbering process, each byte is numbered sequentially from 0 to 63, and the byte content corresponding to each position number is read one by one. Then, each byte value is compared with the field identifier values preset by the communication protocol.
[0142] If the field identifier of field 'a' is hexadecimal AA, and the third byte in the probe data packet is also identified as AA during byte value comparison, then byte 3 is recorded as the starting byte number of field 'a'. This process is repeated iteratively through all bytes in the entire data packet, adding the matched byte to the corresponding field's byte number set each time a match is found. For example, if the field identifier of the device identifier is 0x01, and its matching byte position number is between 0 and 7, then the byte number set corresponding to the device identifier field is recorded as 0-7. If the field identifier of the data type is 0x02, and its matching byte position number falls between 8 and 15, then the byte number set corresponding to the data type field is recorded as 8-15. This method sequentially identifies the position index of each field in the probe data packet, ultimately forming a correspondence between the probe fields and the byte number set in the probe data packet. The byte number set records the byte position index information of each probe field in the probe data packet, serving as the basis for subsequent field content extraction and timestamp mapping processing.
[0143] After obtaining the correspondence between the probe fields and the byte number set, the byte stream of the corresponding probe field within the probe data packet is extracted based on this correspondence. The extraction process is based on the number range, directly extracting the byte fragments covered by the field. For example, if the field with position numbers 8 to 15 represents a data type field, then bytes 8 to 15 are extracted to form a continuous byte stream. Each byte stream needs to be paired with corresponding time information. The time information is usually recorded in the form of a collection timestamp by the system's real-time clock or synchronization signal, such as "June 30, 2015, 12:00 PM plus 123 milliseconds". The collection timestamp is then bound to the byte stream. For example, if the byte stream is 8 bytes of hexadecimal data "0102030405060708", then a pairing data is generated, recording the correspondence between the field content and the collection timestamp.
[0144] For multiple fields in the probe data packet, the same extraction and pairing process is executed for each. If multiple fields are in the same acquisition period, they can share the same acquisition timestamp. If there are time sequence differences in field acquisition, a different acquisition timestamp needs to be extracted and bound. For example, if the measurement data field corresponds to bytes 16 to 31, the corresponding acquisition timestamp is "June 30, 2015, 12:00 PM + 223 milliseconds". This completes the establishment of a multi-field, multi-acquisition timestamp pairing structure. This structure can save the one-to-one correspondence between all fields and acquisition timestamps, serving as a reference index for subsequent data tracing and analysis.
[0145] Specifically, based on the correspondence between the byte stream of each probe field and the acquisition timestamp, the byte position numbers corresponding to the probe fields are combined with the acquisition timestamps to form a data set, and the structured data content is organized using a unified format. During the operation, each set of byte position numbers and acquisition timestamps is organized, and all the byte position numbers occupied by the field are organized into a number set, which is then integrated with the corresponding acquisition timestamp into a record. For example, the byte position number set of the device identifier field is 0 to 7, and its corresponding acquisition timestamp is "June 30, 2015, 12:00 PM plus 123 milliseconds". This set of information is organized into an independent data item containing the byte position number set and the acquisition timestamp. The same organization and combination process is performed on all probe fields, combining the byte position number sets of each probe field with the acquisition time into multiple records, forming a complete data list. To ensure that the field number data is managed in chronological order, all records can be sorted in ascending order according to the acquisition timestamp, forming a probe payload time index list, which makes it more convenient to analyze the field change trends in chronological order later.
[0146] This data organization method is suitable for data analysis scenarios in remote sensing systems. For example, when spaceborne probes send back data packets, the consistency between data location and time can be compared by combining byte location numbers and acquisition timestamps to assist in analyzing transmission stability or field offset anomalies. The final probe payload time index list will contain records consisting of all byte location number sets and acquisition timestamps, which can be used for tasks such as backtracking and data correlation verification.
[0147] Based on the probe payload time index list, the acquisition timestamp of each probe field needs to be extracted sequentially from the probe data packet. The extraction order must strictly correspond to the position of the probe field in the probe data packet. For example, if the transmission times of fields A, B, and C are 10 milliseconds (ms), 20 ms, and 35 ms respectively, the acquisition time difference between the fields can be calculated sequentially. The acquisition time difference between field B and field A is 10 ms, and the acquisition time difference between field C and field B is 15 ms, thus obtaining the acquisition time difference sequence of 10 ms and 15 ms. During execution, firstly, the field time sequence extraction module extracts the acquisition timestamp of each probe field in the probe data packet to form a time sequence T. Then, the acquisition time difference between adjacent fields is calculated, that is, the acquisition timestamp of the next field is subtracted from the acquisition timestamp of the previous field, thus forming the acquisition time difference sequence. The time unit is uniformly set to milliseconds, and the precision is controlled within 1 ms. If a probe data packet generates an acquisition time sequence of 5 ms, 12 ms, 25 ms, and 38 ms, then the acquisition time difference is 7 ms, 13 ms, and 13 ms. Throughout the process, every difference calculation must be accurately recorded to avoid data omissions or calculation errors. The collected time difference sequence ultimately constitutes the time-series basic data between fields, which can be used for subsequent dependency analysis and judgment.
[0148] After obtaining the acquisition time difference sequence, each acquisition time difference needs to be compared with the round-trip time of the channel in which the protocol resides to determine whether there is a time dependency between the probe fields. Round-trip time can be obtained by measuring the link distance. For example, under standard communication rate conditions, the round-trip time of a signal at a physical distance of 3000m is approximately 20ms. If the acquisition time difference between a group of adjacent probe fields is 18ms and the round-trip time is 20ms, then the acquisition time difference is less than the round-trip time, indicating that there is a time dependency between the later probe field and the earlier probe field in this group of adjacent probe fields.
[0149] Conversely, if the acquisition time difference between a group of adjacent detection fields is 28ms, exceeding the round-trip time, then these adjacent detection fields do not have a close time dependency. This type of comparison process requires traversing the entire sequence of acquisition time differences and, in conjunction with the corresponding round-trip time, sequentially determining whether the acquisition time difference is less than the corresponding round-trip time. The result forms a Boolean sequence: "Yes" indicates that the acquisition time difference is less than or equal to the round-trip time, and "No" indicates that the difference is greater than the round-trip time. For example, if the acquisition time differences are 10ms, 15ms, and 25ms, and the corresponding round-trip times are 12ms, 14ms, and 20ms, the resulting sequence is "Yes," "No," and "No." Each result must be strictly compared to the channel round-trip time to ensure consistency in the comparison logic and form a complete sequence. In complex protocols where there is asynchronous processing or channel separation between fields, to avoid misjudgments, a field segmentation method can be used, grouping the fields and evaluating the round-trip time separately.
[0150] After generating the judgment sequence, each pair of adjacent probe fields needs to be classified, and its dependency nature needs to be determined based on the judgment result. If the judgment result is "yes", the corresponding field pair is marked as short-interval dependency; if the judgment result is "no", it is marked as loose dependency. During the dependency labeling process, corresponding field relationship identifiers are constructed based on the field order, such as "field 1-field 2", "field 2-field 3", etc., and the dependency category is marked according to the judgment result.
[0151] A time interval benchmark is set to clarify the classification criteria. If the difference is less than or equal to the corresponding round-trip time delay and does not exceed 20ms, it is classified as a short-interval dependency; if it exceeds the round-trip time delay or exceeds 20ms, it is classified as a loose dependency. For example, if the time difference of a pair of fields is 16ms and the corresponding delay is 17ms, it meets the criteria and is classified as a short-interval dependency; another pair has a difference of 22ms and a delay of 18ms, which is a loose dependency. The calibration data is ultimately recorded in pairs, recording the dependency type results. For example, "Field A - Field B" is a short-interval dependency, and "Field B - Field C" is a loose dependency. The dependency results can be imported into the subsequent protocol analysis module to form structured calibration data. Throughout the process, it is necessary to ensure the consistency between the field order, the acquisition time difference, and the round-trip time delay to avoid logical deviations in dependency classification. In this embodiment, the dependency type of the target field is a short-interval dependency.
[0152] After determining that the dependency type of the target field is a short-interval dependency, in one embodiment, such as Figure 7 As shown, the reference value range for determining the target field in S603 includes:
[0153] S701, determine the maximum and minimum field values based on the range of field values within the sliding window where the first degree of change is greater than the first degree of change threshold, and the comprehensive range of values.
[0154] Among them, the range of field values within the sliding window where the first degree of change is greater than the first degree of change threshold is the candidate value range mentioned above. The comprehensive value range is composed of a second number of consecutive ranges of field values within the sliding window where the first degree of change is greater than the second degree of change threshold. The second number can be set according to actual needs. The first degree of change threshold and the second degree of change threshold can be the same or different.
[0155] Taking a second quantity of 3 as an example, during the sliding window process, if the first degree of change of 3 consecutive sliding windows is greater than the first degree of change threshold, then the range of field values in these 3 sliding windows is taken to form a comprehensive range. For example, if the range of field values in these 3 sliding windows are [10,20], [15,26], and [17,28], then the comprehensive range is [10,28].
[0156] After determining the candidate value range and the comprehensive value range, take the maximum and minimum field values in the candidate value range and the comprehensive value range. For example, if the candidate value range is [5,14] and the comprehensive value range is [10,28], then the maximum field value is 28 and the minimum field value is 5.
[0157] S702, determine the reference value range of the target field based on the maximum and minimum field values.
[0158] Specifically, the maximum field value is used as the right endpoint of the reference value range for the target field, and the minimum field value is used as the left endpoint of the reference value range for the target field. For example, if the maximum field value is 28 and the minimum field value is 5, the reference value range is [5, 28].
[0159] By combining the candidate value range with the largest variation within a single sliding window and cross-observing within multiple sliding windows, a comprehensive value range with a significant fluctuation trend is identified, and the reference value area of the target field is determined. This approach can fully identify the fluctuation trend of the target field value in various historical response messages, accurately determine the reference value range of the target field, and thus determine whether there are any anomalies in the target field value in the current response message based on the reference value range, thereby improving the accuracy of vulnerability detection.
[0160] It should be noted that the specific values in the above reference range are for illustrative purposes only and do not constitute a limitation on this application.
[0161] In one embodiment, determining the first degree of change of the field value within the sliding window in S701 includes:
[0162] Based on the field values contained in the field value sequence, determine the fluctuation degree of the target field's field value; if the fluctuation degree is greater than a preset degree, determine the second degree of change of the target field; if the second degree of change is greater than the second degree of change threshold, use a sliding window with a set sliding step size to slide on the field value sequence corresponding to the target field, and determine the first degree of change of the field value within the sliding window during the sliding process.
[0163] In practice, before determining the first degree of change of field values within the sliding window, the fluctuation level of the target field's value is first determined based on the field values contained in the field value sequence to be greater than a preset level. The fluctuation level can be determined based on the variance of each field value, and is not specifically limited here. The fluctuation level reflects the overall fluctuation intensity of the target field's value within the time window of receiving each historical response message.
[0164] The fluctuation level of the target field value determined by the above method reflects the dynamic behavior of protocol data transmission, providing a quantitative assessment of network initiative and transmission stability. When the fluctuation level is determined to be greater than a preset level, a sliding window approach is used to determine the first degree of change, ensuring that the fluctuation range of the field value can be captured. This improves the accuracy of the determined reference value range.
[0165] In one embodiment, the degree of fluctuation in the field value of the target field can also be referred to as the time window feature parameter. Optionally, the calculation formula for the time window feature parameter is as follows:
[0166]
[0167] Where H represents the time window feature parameter (unit: milliseconds-1), and β tk β represents the k-th field value (dimensionless) in the sequence of field values. tk-1 Δt represents the (k-1)th field value (dimensionless). k This represents the time interval (in milliseconds) between the reception time of the response message containing the k-th field value and the reception time of the response message containing the (k-1)-th field value, where n is the number of field values in the field value sequence, and ω... k The linear weighting parameter (dimensionless) based on index position is determined by the following formula:
[0168]
[0169] In practical applications, for each field value in the target field's value sequence, the network protocol is monitored using data acquisition equipment to obtain the field values at specified positions in continuous response messages between time points t1 and tn. For example, when n is 5, the consecutive time point field values are 150, 130, 120, 140, and 160, all of which are clearly obtained from the records of the data acquisition equipment within a specific monitoring time window. In actual monitoring, each time interval is obtained as 100 milliseconds, 120 milliseconds, 110 milliseconds, and 130 milliseconds, with the average sampling duration used as the time interval.
[0170] First, the weight parameter ω k Set in a linear manner, ω is determined using the above method. k From the formula, we can obtain:
[0171]
[0172] The weight parameter reflects the contribution of each field value of the target field to the total field values of all target fields at different time points.
[0173] Secondly, determine the rate of change of each field value in the field value sequence relative to the previous field value. When k=2, the rate of change is:
[0174]
[0175] When k=3, the rate of change is:
[0176]
[0177] When k=4, the rate of change is:
[0178]
[0179] When k=5, the rate of change is:
[0180]
[0181] Substituting the above rate of change and weight parameters into formula (2), we get:
[0182]
[0183] The specific calculation process is as follows:
[0184] H=|-0.0133-0.0111+0.0364+0.0413|=|0.0533|
[0185] The result H is 0.0533, which means that the fluctuation of the target field within the preset time window is 0.0533.
[0186] It should be noted that the specific values of the above fields are for illustrative purposes only and do not constitute a limitation on this application.
[0187] As can be seen from the process of determining the time window characteristic parameters described above, the rate of change of the monitored field values reflects the dynamic behavior of protocol data transmission, providing a quantitative assessment of network initiative and transmission stability. This assessment result will guide subsequent data processing and optimization, impacting aspects such as optimizing the transmission process and resource allocation.
[0188] Formula (1) above quantifies the dynamic change characteristics of the protocol field (i.e., the target field) through a four-layer operation structure. First, it calculates the instantaneous change of the field value at adjacent time points to capture the data fluctuation trend. Then, it divides the value by the time interval to convert it into a rate of change to eliminate time scale differences. Subsequently, it multiplies the value by a weight parameter to enhance the contribution of recent data. Then, it aggregates the weighted rate of change of the entire time window through a summation operation to form a comprehensive feature quantity. Finally, it takes the absolute value to eliminate directional interference and converts it into an intensity characterization quantity. This operation chain transforms the original field value sequence into a time-sensitive scalar feature parameter (i.e., a time window feature parameter) through four stages of processing: difference, normalization, weighting, and aggregation.
[0189] The time window feature parameter characterizes the dynamic characteristics of protocol fields through a three-layer structure: the base layer uses differential operations to capture the instantaneous changes in byte values; the middle layer eliminates sampling interval differences and establishes a rate dimension through time normalization; and the top layer implements weight parameter superposition and absolute value integration to form a non-negative scalar, ultimately constructing a composite index that simultaneously includes change intensity, time sensitivity, and trend persistence. The essence of the time window feature parameter is to map the discrete time-domain field value sequence into a comparable continuous feature space quantity, whose numerical value directly reflects the overall fluctuation intensity of the target field within a preset time window.
[0190] Optionally, when the fluctuation level exceeds a preset level, to determine the second degree of variability of the target field, for the field value sequence of the target field, find the maximum and minimum field values. The difference between the two is the difference (i.e., the second degree of variability) of the target field. For example, the field value sequence of field 5 is [11, 13, 17], the maximum value is 17, the minimum value is 11, the difference is 6, and the difference benchmark (second degree of variability threshold) is 7. Compare the difference with 7. If the difference is greater than 7, then the field index and its field value range are retained. For example, the byte value sequence of field 8 is [20, 28], the difference is 8, which is higher than the difference benchmark. Therefore, the field index 8 and the field value range [20, 28] are retained. The byte value sequence of field 12 is [01, 0D], the difference is 12, and the index 12 and the field value range [01, 0D] are also retained. Finally, the field difference filtering result set is obtained, which includes the field index and its respective field value range, facilitating the determination of the first degree of variability in the next step.
[0191] In one embodiment, since the above field difference filtering results provide relevant information on fields with significant fluctuations (fluctuation fields), the reference value range for each fluctuation field can be determined in the following way:
[0192] First, the actual distribution positions of the field values contained in the field value sequence of each fluctuating field at different time points are statistically analyzed, and the field value distribution trajectory is constructed in chronological order. These trajectories are traversed by setting a sliding window. For example, if the sliding window consists of 3 sets of data, one set is slid at a time, and the changes in byte values in each sliding window are analyzed sequentially. If the byte value of a field changes from 20 to 2C within a sliding window, it is considered that there is a significant fluctuation in the field value within that time window. The time points before and after the fluctuation, and the corresponding field value intervals (as candidate field value intervals) can be recorded to extract its offset path. If the byte value change amplitude is greater than 3B in multiple consecutive sliding windows, it can be identified as a fluctuation segment. The field index, start time point, end time point, and field value intervals (as candidate field value intervals) within multiple sliding windows are recorded. For example, if field 12 fluctuates from 01 to 0D between sets 10 and 13, it can be recorded as: start time 10, end time 13, field value interval [01, 0D], and the corresponding field value intervals are used as reference value intervals for the field.
[0193] Based on the above embodiments, in one exemplary embodiment, for Figure 2 The security vulnerability detection methods in the text can be further refined, and optional methods include... Figure 8 As shown, it includes:
[0194] S801, send at least one probe message to the detected end, and receive a response message from the detected end based on each probe message.
[0195] S802, for each response message, determine the frequency of occurrence of each byte value based on the number of times each byte value appears in each response message and the total number of byte values in each response message.
[0196] S803, for each byte value, obtain the frequency of occurrence of the byte value at a specified position in the first number of response messages before the response message, and the frequency of occurrence of the byte value at a specified position in the first number of response messages after the response message; perform an average operation on the obtained frequencies of occurrence and the frequency of occurrence of the byte value to obtain the average frequency; determine the weight corresponding to the byte value based on the difference between the obtained frequencies of occurrence and the frequency of occurrence of the byte value and the average frequency, and the frequency difference between two adjacent frequencies of occurrence among the obtained frequencies of occurrence and the frequency of occurrence of the byte value; and weight the preset benchmark threshold based on the weight to obtain the frequency threshold of the byte value.
[0197] S804 compares the frequency threshold and occurrence frequency corresponding to each byte value to filter out sparse byte values whose occurrence frequency is lower than the corresponding frequency threshold from each byte value.
[0198] S805, determine the length of the reference value range of the target field to which the sparse byte value in the response message belongs; and determine the distance between the field value of the target field and the reference value range; determine the field value deviation of the target field based on the distance and the range length; and determine the security vulnerability detection result of the detected end under the response message based on the field value deviation.
[0199] S806 determines the target security vulnerability detection result of the detected end based on the security vulnerability detection results of the detected end under each response message.
[0200] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.
[0201] Based on the same inventive concept, this application also provides a security vulnerability detection device for implementing the security vulnerability detection method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more security vulnerability detection device embodiments provided below can be found in the limitations of the security vulnerability detection method described above, and will not be repeated here.
[0202] In one exemplary embodiment, such as Figure 9 As shown, a security vulnerability detection device is provided, including: a transmission module 901, a detection module 902, and a determination module 903, wherein:
[0203] The transmission module 901 is used to send at least one probe message to the detected end and receive a response message from the detected end based on each probe message.
[0204] The detection module 902 is used to select sparse byte values from each byte value according to the number of times each byte value in the response message appears in each response message, and determine the security vulnerability detection result of the detected end under the response message according to the field value of the target field to which the sparse byte value in the response message belongs and the reference value range.
[0205] The determination module 903 is used to determine the target security vulnerability detection result of the detected end based on the security vulnerability detection results of the detected end under each response message.
[0206] In one embodiment, the detection module 902 is specifically used for:
[0207] Determine the length of the reference value range of the target field to which the sparse byte value in the response message belongs; and determine the distance between the field value of the target field and the reference value range; determine the field value deviation of the target field based on the distance and the range length; and determine the security vulnerability detection result of the detected end under the response message based on the field value deviation.
[0208] In one embodiment, the detection module 902 is specifically used for:
[0209] Based on the number of times each byte value appears in each response message and the total number of byte values in each response message, the frequency of each byte value is determined. For each byte value, a frequency threshold is determined based on the frequency of the byte value, the frequency of the byte value at a specified position in the first number of response messages before the response message, and the frequency of the byte value at a specified position in the first number of response messages after the response message. The specified position is the same as the position of the byte value in the response message. The frequency threshold and the frequency of each byte value are compared to filter out sparse byte values whose frequency of occurrence is lower than the corresponding frequency threshold.
[0210] In one embodiment, the detection module 902 is specifically used for:
[0211] The process involves: acquiring the frequency of byte values at specified positions in the first number of response messages preceding the response message, and the frequency of byte values at specified positions in the first number of response messages following the response message; averaging the acquired frequencies of occurrence and byte values to obtain the average frequency; determining the weight of each byte value based on the differences between the acquired frequencies of occurrence and byte values and the average frequency, as well as the frequency difference between two adjacent frequencies of occurrence in the acquired frequencies of occurrence and byte values; and weighting a preset baseline threshold based on the weights to obtain the frequency threshold of the byte values.
[0212] In one embodiment, the security vulnerability detection device further includes a sliding module 904, used to determine the reference value range of the target field to which the sparse byte value belongs by means of:
[0213] From the field values contained in each historical response message, find the field value sequence corresponding to the target field; use a sliding window with a set sliding step size to slide on the field value sequence corresponding to the target field, and determine the first degree of change of the field value within the sliding window during the sliding process; based on the value range of the field value within the sliding window where the first degree of change is greater than the first degree of change threshold, determine the reference value range of the target field.
[0214] In one embodiment, the sliding module 904 is specifically used for:
[0215] Based on the range of field values within a sliding window where the first degree of change is greater than the first degree of change threshold, and the comprehensive range of values, the maximum and minimum field values are determined. The comprehensive range of values consists of a second consecutive number of ranges of field values within a sliding window where the first degree of change is greater than the second degree of change threshold. Based on the maximum and minimum field values, the reference range of values for the target field is determined.
[0216] In one embodiment, the sliding module 904 is specifically used for:
[0217] Based on the field values contained in the field value sequence, determine the fluctuation degree of the target field's field value; if the fluctuation degree is greater than a preset degree, determine the second degree of change of the target field; if the second degree of change is greater than the second degree of change threshold, use a sliding window with a set sliding step size to slide on the field value sequence corresponding to the target field, and determine the first degree of change of the field value within the sliding window during the sliding process.
[0218] Each module in the aforementioned security vulnerability detection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0219] In one exemplary embodiment, a computer device is provided, which may be a detection terminal, and its internal structure diagram may be as follows: Figure 10As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media. The database stores message data. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When executed by the processor, the computer program implements a security vulnerability detection method.
[0220] Those skilled in the art will understand that Figure 10 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0221] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the various method embodiments of the security vulnerability detection method described above.
[0222] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the steps of the various method embodiments of the security vulnerability detection method described above.
[0223] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the various method embodiments of the security vulnerability detection method described above.
[0224] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0225] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this application. The above embodiments only illustrate several implementation methods of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of this application. It should be noted that for those skilled in the art, several modifications and improvements can be made without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A security vulnerability detection method, characterized in that, Applied to the detection end, the method includes: Send at least one probe message to the detected end and receive a response message from the detected end based on each probe message; For each response message, based on the number of times each byte value in the response message appears in each response message, a sparse byte value is selected from each byte value, and based on the field value of the target field to which the sparse byte value in the response message belongs and the reference value range, the security vulnerability detection result of the detected end under the response message is determined; Based on the security vulnerability detection results of the detected endpoint under each response message, the target security vulnerability detection result of the detected endpoint is determined.
2. The method according to claim 1, characterized in that, The step of determining the security vulnerability detection result of the detected terminal under the response message based on the field value and reference value range of the target field to which the sparse byte value belongs in the response message includes: Determine the length of the reference value range of the target field to which the sparse byte value belongs in the response message; and, Determine the distance between the field value of the target field and the reference value range; The deviation of the target field value is determined based on the distance and the interval length. Based on the deviation of the field value, the security vulnerability detection result of the detected terminal under the response message is determined.
3. The method according to claim 1, characterized in that, The step of selecting sparse byte values from each byte value based on the number of times each byte value appears in each of the response messages includes: The frequency of occurrence of each byte value is determined based on the number of times each byte value appears in each response message and the total number of byte values in each response message. For each byte value, a frequency threshold corresponding to the byte value is determined based on the occurrence frequency of the byte value, the occurrence frequency of the byte value at a specified position in a first number of response messages preceding the response message, and the occurrence frequency of the byte value at a specified position in a first number of response messages following the response message; wherein, the specified position is the same as the position of the byte value in the response message; Compare the frequency threshold and occurrence frequency corresponding to each byte value to filter out sparse byte values whose occurrence frequency is lower than the corresponding frequency threshold from each byte value.
4. The method according to claim 3, characterized in that, The step of determining the frequency threshold corresponding to the byte value based on the occurrence frequency of the byte value, the occurrence frequency of the byte value at a specified position in a first number of response messages preceding the response message, and the occurrence frequency of the byte value at a specified position in a first number of response messages following the response message, includes: The frequency of occurrence of byte values at specified positions in a first number of response messages preceding the response message, and the frequency of occurrence of byte values at specified positions in a first number of response messages following the response message are obtained. The average frequency is obtained by averaging the frequency of each occurrence and the frequency of the byte value. Based on the differences between the obtained occurrence frequencies and the occurrence frequency of the byte value and the average frequency, as well as the frequency difference between two adjacent occurrence frequencies among the obtained occurrence frequencies and the occurrence frequency of the byte value, the weight corresponding to the byte value is determined. The preset baseline threshold is weighted based on the weights to obtain the frequency threshold of the byte value.
5. The method according to any one of claims 1 to 4, characterized in that, The reference value range of the target field to which the sparse byte value belongs is determined in the following way: From the field values contained in each historical response message, find the sequence of field values corresponding to the target field; A sliding window is used, with a set sliding step size, to slide on the field value sequence corresponding to the target field, and during the sliding process, the first degree of change of the field value within the sliding window is determined; The reference value range of the target field is determined based on the range of field values within a sliding window where the first degree of change is greater than the first degree of change threshold.
6. The method according to claim 5, characterized in that, The determination of the reference value range of the target field based on the value range of the field within the sliding window where the first degree of change is greater than the first degree of change threshold includes: The maximum and minimum field values are determined based on the range of field values within a sliding window where the first degree of change is greater than the first degree of change threshold, and the comprehensive range of values. The comprehensive range of values is composed of a second consecutive number of ranges of field values within a sliding window where the first degree of change is greater than the second degree of change threshold. Based on the maximum field value and the minimum field value, a reference value range for the target field is determined.
7. The method according to claim 5, characterized in that, The method employs a sliding window, setting a sliding step size, sliding across the sequence of field values corresponding to the target field, and determining the first degree of change of the field values within the sliding window during the sliding process, including: Based on the field values contained in the field value sequence, determine the degree of fluctuation of the field value of the target field; If the degree of fluctuation is greater than a preset degree, a second degree of change of the target field is determined; When the second degree of change is greater than the second degree of change threshold, a sliding window is used to slide on the field value sequence corresponding to the target field with a set sliding step size, and the first degree of change of the field value within the sliding window is determined during the sliding process.
8. A security vulnerability detection device, characterized in that, The device includes: The transmission module is used to send at least one probe message to the detected end and receive a response message from the detected end based on each probe message. The detection module is used to select sparse byte values from each byte value according to the number of times each byte value in the response message appears in each response message, and determine the security vulnerability detection result of the detected end under the response message according to the field value of the target field to which the sparse byte value belongs and the reference value range in the response message. The determination module is used to determine the target security vulnerability detection result of the detected terminal based on the security vulnerability detection results of the detected terminal under each response message.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.