Automatic directory scanning early warning method based on Nginx configuration and related equipment
By automatically parsing the Nginx configuration file and concatenating the Uniform Resource Locator (URL) address, and combining the directory scanning results for risk analysis, the problem of low path hit rate and high false alarm rate of existing tools has been solved, achieving a more accurate scanning scope and risk warning, and reducing security incidents.
Patent Information
- Application Number
- CN202511233735.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-11-28
AI Technical Summary
Existing directory scanning tools suffer from low path hit rates, redundant scanning ranges, high false alarm rates, and an inability to detect and warn of risks, leading to frequent security incidents.
By automatically parsing the Nginx configuration file and intelligently concatenating it into a Uniform Resource Locator (URL), risk analysis is performed based on the directory scanning results, and a risk warning report is generated and stored in the database.
Improve path hit rate, accurately locate scanning range, reduce false alarm rate, proactively detect risks, and reduce security incidents caused by configuration errors and path exposure.
Smart Images

Figure CN121029271A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and in particular to an automatic directory scanning early warning method based on Nginx configuration and related equipment. BACKGROUND
[0002] Currently, with the continuous expansion of enterprise information systems and the continuous evolution of Web service architecture, more and more applications provide access portals to the outside through Web servers such as Nginx.
[0003] In the related art, the existing directory scanning tool presets a path dictionary to perform "blind scanning". However, in actual applications, it is found that the existing directory scanning tool often has low path hit rate, redundant scanning range, high false positive rate, and cannot perceive and warn risks.
[0004] To sum up, the technical problems in the related art need to be improved. SUMMARY
[0005] The embodiments of the present application provide an automatic directory scanning early warning method based on Nginx configuration and related equipment, which can effectively improve the path hit rate and accurately locate the scanning range, perceive risks in advance, and reduce security incidents caused by configuration errors and path exposure.
[0006] In one aspect, the embodiments of the present application provide an automatic directory scanning early warning method based on Nginx configuration, which comprises the following steps: In response to a directory scanning start instruction, an Nginx configuration file is obtained, and the Nginx configuration file is parsed into structured data; Based on the structured data, a uniform resource locator address is obtained, and a directory scanning program is started according to the uniform resource locator address; Directory scanning results are obtained, which are structured and analyzed for risk identification, and a risk early warning report is generated and stored in a database.
[0007] Optionally, in response to the directory scanning start instruction, the Nginx configuration file is obtained, and the Nginx configuration file is parsed into structured data, which comprises: In response to a directory scanning start instruction, an Nginx configuration file is obtained; The Nginx parsing component is called to recursively parse the main configuration file and its references, and the field parsing results including domain name, listening port, and path matching rule are extracted by traversal; The field parsing results are stored as structured data.
[0008] Optionally, the step of converting the structured data to obtain a Uniform Resource Locator (URL) and starting a directory scanning program based on the URL includes: Obtain the structured data; Extract the domain name field resolution result from the structured data and use it as the hostname of the Uniform Resource Locator address; The parsing result of the listening port field in the structured data is used as the port and protocol of the Uniform Resource Locator address; Extract the path matching rule field parsing result from the structured data as the path of the Uniform Resource Locator address; The hostname, port, protocol, and path of the Uniform Resource Locator (URL) are concatenated to obtain the URL. Based on the Uniform Resource Locator address, invoke and start the directory scanning program.
[0009] Optionally, the method further includes: If the parsing result of the listening port field includes Secure Sockets Layer, the protocol for the Uniform Resource Locator address is determined to be Hypertext Transfer Security Protocol (HTTP). If the parsing result of the listening port field does not include Secure Sockets Layer, the protocol for the Uniform Resource Locator address is determined to be Hypertext Transfer Protocol. When the path matching rule is regular expression matching, a path is generated based on the regular expression, which serves as the path of the Uniform Resource Locator address.
[0010] Optionally, the step of obtaining the catalog scan results, performing structured processing and risk identification analysis, generating a risk warning report, and storing it in the database includes: Obtain the directory scan results; The directory scan results are structured to extract field data including Uniform Resource Locator address, response status code, response time, response length, and redirection information; Based on the field data, risk identification analysis is performed according to preset risk identification rules, thereby recording the risk identification analysis results of each directory scan result and pushing the risk identification analysis results of items with risks. Generate risk warning reports and record and store them in the database.
[0011] Optionally, the method further includes: In response to the Nginx configuration update command, the updated Nginx configuration file is retrieved again, and the updated Nginx configuration file is parsed into structured data.
[0012] On the other hand, embodiments of this application provide an automatic directory scanning and early warning device based on Nginx configuration, the device comprising: The configuration parsing module is used to respond to the directory scan startup command, obtain the Nginx configuration file, and parse the Nginx configuration file into structured data; The address conversion module is used to convert the structured data into a Uniform Resource Locator (URL) address and start a directory scanning program based on the URL address. The scanning and early warning module is used to obtain the catalog scanning results, perform structured processing and risk identification analysis, generate risk early warning reports, and store them in the database.
[0013] On the other hand, embodiments of this application provide an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described method.
[0014] On the other hand, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method.
[0015] On the other hand, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0016] This application embodiment automatically parses the Nginx configuration file and intelligently concatenates it to form a unified resource locator address, which effectively improves the path hit rate and accurately locates the scanning range. Combined with the directory scanning results, risk analysis is performed to reduce the false alarm rate, detect risks in advance, and reduce the occurrence of security incidents caused by configuration errors, path exposure, etc. Attached Figure Description
[0017] Figure 1 This is a schematic diagram of the implementation environment of an automatic directory scanning and early warning method based on Nginx configuration provided in an embodiment of this application; Figure 2 This is a flowchart illustrating an automatic directory scanning and early warning method based on Nginx configuration provided in an embodiment of this application. Figure 3 This is a schematic diagram of a process for parsing an Nginx configuration file provided in an embodiment of this application; Figure 4 This is a schematic diagram of a URL construction process provided in an embodiment of this application; Figure 5 This is a schematic diagram of a directory scanning early warning process provided in an embodiment of this application; Figure 6This is a schematic diagram of an automatic directory scanning and early warning device based on Nginx configuration provided in an embodiment of this application; Figure 7 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.
[0019] It is understood that the terms “first,” “second,” etc., used in this application may be used herein to describe various concepts, but unless otherwise stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if,” “when,” or “in response to a determination” as used herein may be interpreted as “when…” or “when…” or “in response to a determination.”
[0020] As used in this application, the terms "at least one", "multiple", "each", "any", etc., "at least one" includes one, two or more, "multiple" includes two or more, "each" refers to each of the corresponding multiples, and "any" refers to any one of the multiples.
[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0022] Currently, with the continuous expansion of enterprise information systems and the ongoing evolution of Web service architecture, more and more applications are providing access points to the outside world through Web servers such as Nginx.
[0023] In related technologies, existing directory scanning tools perform "blind scanning" using preset path dictionaries. However, in practical applications, it has been found that existing directory scanning tools often suffer from problems such as low path hit rate, redundant scanning range, high false alarm rate, and inability to detect and warn of risks.
[0024] In view of this, this application provides an automatic directory scanning early warning method and related equipment based on Nginx configuration. By automatically parsing the Nginx configuration file and intelligently concatenating it to form a unified resource locator address, the method effectively improves the path hit rate and accurately locates the scanning range. Combined with the directory scanning results, risk analysis is performed to reduce the false alarm rate, detect risks in advance, and reduce the occurrence of security incidents caused by configuration errors, path exposure, etc.
[0025] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirection to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.
[0026] The specific implementation methods of the embodiments of this application will be described in detail below with reference to the accompanying drawings. First, an automatic directory scanning and early warning method based on Nginx configuration provided in the embodiments of this application will be described with reference to the accompanying drawings.
[0027] Please refer to Figure 1 , Figure 1 This is a schematic diagram of the implementation environment for an automatic directory scanning and early warning method based on Nginx configuration provided in this application embodiment. In this implementation environment, the main hardware and software components involved include a terminal processor 110 and a server 120.
[0028] Specifically, the terminal processor 110 may have a control program for an automatic directory scanning and early warning method based on Nginx configuration installed, and the server 120 is the backend server for this control program. The terminal processor 110 and the backend server 120 are connected for communication. The automatic directory scanning and early warning method based on Nginx configuration provided in this embodiment can be executed on the terminal processor 110 side.
[0029] Server 120 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0030] In addition, server 120 can also be a node server in a blockchain network.
[0031] The terminal processor 110 and the server 120 can establish a communication connection via a wireless network. This wireless network uses standard communication technologies and / or protocols. The network can be the Internet or any other network, including but not limited to a Local Area Network (LAN), Metropolitan Area Network (MAN), Wide Area Network (WAN), mobile, or any combination of wireless networks, private networks, or virtual private networks. Furthermore, these hardware and software components can use the same or different communication connection methods; this application does not impose specific limitations in this regard.
[0032] Of course, this is understandable. Figure 1 The implementation environment described in this application is only one of the optional application scenarios for the automatic directory scanning and early warning method based on Nginx configuration provided in this embodiment. The actual application is not fixed. Figure 1 The software and hardware environment shown is not specifically limited in this application.
[0033] like Figure 2 As shown, Figure 2 This is a flowchart illustrating an automatic directory scanning and early warning method based on Nginx configuration provided in an embodiment of this application, specifically including but not limited to steps 100 to 300.
[0034] Step 100: In response to the directory scan startup command, obtain the Nginx configuration file and parse the Nginx configuration file into structured data.
[0035] In this embodiment, the directory scan initiation command can be triggered by a directory scan task that starts periodically at a preset frequency, or it can be triggered by a relevant operator actively executing a directory scan task. Furthermore, the processor, as the execution entity, can recognize and respond to the directory scan initiation command, automatically obtain the Nginx configuration file, and can call the nginxparser component as a parsing tool to parse the Nginx configuration file into structured data.
[0036] The Nginx configuration file is a set of configuration directives used to control the behavior of the Nginx server. It configures and defines parameters such as the listening port of the web service, domain name mapping, reverse proxy rules, load balancing strategy, caching, SSL encryption, and access control, serving as the core basis for the Nginx server to implement request processing logic. Directory scanning refers to automatically sending a series of pre-constructed path requests to the target server in a programmatic manner to determine whether certain directories, files, or interface resources exist on the target server. It can be used to probe paths such as backend management systems, configuration files, backup files, test interfaces, and unpublished APIs, providing basic information for penetration testing or risk assessment.
[0037] Specifically, as an optional implementation, the step of responding to the directory scan startup command, obtaining the Nginx configuration file, and parsing the Nginx configuration file into structured data includes: In response to the directory scan startup command, retrieve the Nginx configuration file; The Nginx parsing component is invoked to recursively parse the main configuration file and its references, traversing and extracting the parsing results of fields including domain name, listening port, and path matching rules; The parsing results of the fields are stored as structured data.
[0038] In the embodiments of this application, please refer to Figure 3 , Figure 3 This is a flowchart illustrating an Nginx configuration file parsing process provided in this application embodiment. The Agent program, a runtime component deployed on the host operating system, receives and responds to the directory scan start command, collects the contents of the Nginx configuration file nginx.conf as the starting point for configuration parsing, and calls the nginxparser parsing component to parse the contents of nginx.conf into structured data.
[0039] First, it checks if an include directive exists in the nginx.conf file. If it does, it extracts the path rules specified in the include directive, collects the corresponding sub-configuration file content based on the path rules, parses the collected sub-configuration file content, and fills it back into the original structure where the include directive is located, thus merging the configuration logic and completing the recursive parsing of the main configuration file and its references. It then further locates the http block in the nginx.conf file. If no include directive exists, it directly proceeds to locate the http block in the nginx.conf file.
[0040] Furthermore, by locating the http block in the nginx.conf content, it is determined whether an upstream configuration block exists. If an upstream configuration block exists, the server group definition within it is read, an address mapping is constructed for subsequent reference, and the process proceeds to extract all domain name configuration blocks in the http block, resolving them one by one. If no upstream configuration block exists, the process directly proceeds to extract all domain name configuration blocks in the http block.
[0041] Furthermore, in each server domain configuration block, the parsing results of fields such as domain name, listening port (listen), and path matching rules (location) are extracted in turn. The proxy_pass directive statement is parsed in the location field. If the upstream name is referenced, the actual address is restored by reverse parsing based on the previously constructed address mapping.
[0042] Finally, the parsing results of the fields obtained are stored in the database for subsequent analysis, configuration management, and directory scanning tasks, thus ending the Nginx configuration file parsing process.
[0043] Therefore, this application automatically collects and structures the Nginx configuration file to provide accurate data support for subsequent URL construction and path scanning.
[0044] Step 200: Based on the structured data, convert it to obtain a Uniform Resource Locator (URL), and start the directory scanning program according to the URL.
[0045] In the embodiments of this application, a Uniform Resource Locator (URL) is a string used to identify the location of a resource on the Internet and is the basic identification method for Web requests and network resource access.
[0046] In practical applications, the structured data extracted from the Nginx configuration file parsing process is concatenated, and the protocol type (http / https), hostname (server_name), port (listen), path (location), and proxy_pass and upstream mapping are combined to construct a complete access path and generate a list of accessible URLs, which serve as direct input to the directory scanning engine.
[0047] For example, the step of converting the structured data to obtain a Uniform Resource Locator (URL) and starting a directory scanning program based on the URL includes: Obtain the structured data; Extract the domain name field resolution result from the structured data and use it as the hostname of the Uniform Resource Locator address; The parsing result of the listening port field in the structured data is used as the port and protocol of the Uniform Resource Locator address; Extract the path matching rule field parsing result from the structured data as the path of the Uniform Resource Locator address; The hostname, port, protocol, and path of the Uniform Resource Locator (URL) are concatenated to obtain the URL. Based on the Uniform Resource Locator address, invoke and start the directory scanning program.
[0048] In the embodiments of this application, please refer to Figure 4 , Figure 4 This is a flowchart illustrating a URL construction process provided in this application embodiment. The structured data extracted from the Nginx configuration file parsing process is extracted in batches, and the parsing result of the domain name field (server_name) is used as the hostname of the URL address. If there are multiple configurations in server_name, it can be split into multiple URL addresses.
[0049] Furthermore, it is determined whether the parsing result of the listening port (listen) field contains a Secure Sockets Layer (SSL) directive. If the parsing result of the listening port field includes SSL, the URL protocol is determined to be Hypertext Transfer Security Protocol (HTTPS); if the parsing result of the listening port field does not include SSL, the URL protocol is determined to be Hypertext Transfer Security Protocol (HTTP).
[0050] Furthermore, the parsing result of the listening port field is extracted as the port of the URL address. If there are multiple ports, it can be split into multiple URL addresses.
[0051] Furthermore, it determines whether the parsing result of the path matching rule (location) field is a regular expression match. If the match type is a regular expression match, a path is generated according to the regular expression, and the generated path is used as the path in the URL address, and then proceeds to concatenate the URL address. If the match type is not a regular expression match, the parsing result of the path matching rule field in the structured data is directly used as the path in the URL address.
[0052] Furthermore, based on the standard structure of a URL, the parsed hostname, port, protocol, and path are concatenated into a complete URL address, generating a list of accessible URLs.
[0053] Finally, the directory scanning engine (such as Dirsearch, FFUF, Gobuster, etc.) is invoked, and the directory scanning program is started by combining the constructed URL list.
[0054] Therefore, this application can effectively overcome the shortcomings of traditional directory scanning tools in the prior art, which mainly rely on preset path dictionaries for "blind scanning" and lack awareness of the actual configuration of the target system, resulting in low path hit rate, redundant scanning range, and high false alarm rate.
[0055] Step 300: Obtain the catalog scan results, perform structured processing and risk identification analysis, generate a risk warning report and store it in the database.
[0056] In this embodiment of the application, by performing structured processing and risk analysis on the results returned by the directory scan, a complete closed loop of "configuration awareness - automatic path generation - scan execution - result storage and analysis - risk path alarm" can be established, which significantly improves the coverage, accuracy and real-time performance of the directory scan and reduces the occurrence of security incidents caused by configuration errors, path exposure and other reasons.
[0057] Optionally, the step of obtaining the catalog scan results, performing structured processing and risk identification analysis, generating a risk warning report, and storing it in the database includes: Obtain the directory scan results; The directory scan results are structured to extract field data including Uniform Resource Locator address, response status code, response time, response length, and redirection information; Based on the field data, risk identification analysis is performed according to preset risk identification rules, thereby recording the risk identification analysis results of each directory scan result and pushing the risk identification analysis results of items with risks. Generate risk warning reports and record and store them in the database.
[0058] In the embodiments of this application, please refer to Figure 5 , Figure 5 This is a flowchart illustrating a directory scanning early warning system provided in this application embodiment. It receives scan result data returned by the directory scanning engine, performs structured processing and parsing, and extracts field data including key fields such as URL address, response status code, response time, response length, and redirection information.
[0059] Furthermore, responses are categorized based on status codes, such as: 200 (success), 301 / 302 (redirect), 403 (forbidden), 404 (not found), 500 (server error), etc.
[0060] Furthermore, by combining the field data and according to the preset risk identification rules, risk identification analysis is performed to determine whether the directory scan result of each URL address is a suspicious or sensitive response status. For example, if the response status code is 200 Success and the path is a sensitive resource, it can be determined that the current URL address has the risk of sensitive resource leakage, and it can be marked as a sensitive path, and the reason can be recorded.
[0061] Furthermore, by systematically reviewing and analyzing all scan results, all identification and analysis results (including normal and suspicious items) are archived into a unified database for easy retrieval, analysis, and visualization.
[0062] Furthermore, it can push risk identification and analysis results for items with risks, and can also determine whether alarm conditions are triggered based on preset rules (such as abnormal access control, exposure of high-risk paths, directory leakage, etc.). When the trigger conditions are met, alarm content is constructed, including information such as URL address, host information, risk level, discovery time, and suspicious reasons, thereby generating a risk warning report and pushing it.
[0063] Finally, the risk warning reports are recorded and stored in the database for easy archiving and analysis later.
[0064] In practical applications, different sets of rules for judging scanning results can be set according to specific scenario requirements, thereby enabling adaptive processing such as alarms and automated corrections.
[0065] Therefore, this application, by combining automatic parsing of Nginx configuration files with automated detection linked to directory scanning, can efficiently and accurately identify and construct valid access URLs, avoiding the blind scanning and false alarm problems of traditional path dictionary scanning. It can also accurately identify the exposed paths of Web services through directory scanning and prevent risks through alarm push.
[0066] Specifically, as an optional implementation, the method further includes: In response to the Nginx configuration update command, the updated Nginx configuration file is retrieved again, and the updated Nginx configuration file is parsed into structured data.
[0067] In this embodiment of the application, when the Nginx configuration file is updated, an Nginx configuration update instruction will be triggered. Correspondingly, after the Nginx configuration file is updated, the Nginx configuration file can be retrieved again, and the updated Nginx configuration file can be automatically parsed into structured data.
[0068] In other words, this application can also be configured with dynamic awareness of Nginx configuration files. After the Nginx configuration file is dynamically updated, it can automatically parse the updated Nginx configuration file into structured data, thereby effectively dealing with complex Nginx configuration structures and frequent service changes, achieving automated, low-error full configuration awareness, which helps to build accurate URL addresses and improve the accuracy and comprehensiveness of directory scanning.
[0069] The backlight control method of the lighting console provided in this invention will be explained and described in detail below, in conjunction with a specific application implementation process: This application provides an automatic directory scanning early warning method based on Nginx configuration. This method can be applied to directory scanning scenarios. By automatically parsing the Nginx configuration file and intelligently concatenating it to form a unified resource locator address, it can effectively improve the path hit rate and accurately locate the scanning range. Combined with the directory scanning results, risk analysis can be performed to reduce the false alarm rate, detect risks in advance, and reduce the occurrence of security incidents caused by configuration errors, path exposure, etc.
[0070] Specifically, the directory scan start command can be triggered by a directory scan task that starts periodically according to a preset frequency, or it can be triggered by relevant operators actively executing a directory scan task. Furthermore, the processor, as the execution entity, can recognize and respond to the directory scan start command, automatically obtain the Nginx configuration file, and can call the nginxparser component as a parsing tool to parse the Nginx configuration file into structured data.
[0071] For example, the Agent component deployed on the host operating system can receive and respond to the directory scan start command, collect the contents of the Nginx configuration file nginx.conf as the starting point for configuration parsing, and call the nginxparser parsing component to parse the contents of nginx.conf into structured data.
[0072] First, it checks if an include directive exists in the nginx.conf file. If it does, it extracts the path rules specified in the include directive, collects the corresponding sub-configuration file content based on the path rules, parses the collected sub-configuration file content, and fills it back into the original structure where the include directive is located, thus merging the configuration logic and completing the recursive parsing of the main configuration file and its references. It then further locates the http block in the nginx.conf file. If no include directive exists, it directly proceeds to locate the http block in the nginx.conf file.
[0073] Furthermore, by locating the http block in the nginx.conf content, it is determined whether an upstream configuration block exists. If an upstream configuration block exists, the server group definition within it is read, an address mapping is constructed for subsequent reference, and the process proceeds to extract all domain name configuration blocks in the http block, resolving them one by one. If no upstream configuration block exists, the process directly proceeds to extract all domain name configuration blocks in the http block.
[0074] Furthermore, in each server domain configuration block, the parsing results of fields such as domain name, listening port (listen), and path matching rules (location) are extracted in turn. The proxy_pass directive statement is parsed in the location field. If the upstream name is referenced, the actual address is restored by reverse parsing based on the previously constructed address mapping.
[0075] Finally, the parsing results of the fields obtained are stored in the database for subsequent analysis, configuration management, and directory scanning tasks, thus ending the Nginx configuration file parsing process.
[0076] Furthermore, by concatenating the structured data extracted from the Nginx configuration file parsing process, combining protocol type (http / https), hostname (server_name), port (listen), path (location), and parsing proxy_pass and upstream mappings, a complete access path is constructed, generating a list of accessible URL addresses, which serves as direct input to the directory scanning engine.
[0077] For example, by batch extracting the structured data from the Nginx configuration file parsing process, the parsing result of the domain name field (server_name) is used as the hostname of the URL address. If there are multiple configurations in server_name, they can be split into multiple URL addresses.
[0078] Furthermore, it is determined whether the parsing result of the listening port (listen) field contains a Secure Sockets Layer (SSL) directive. If the parsing result of the listening port field includes SSL, the URL protocol is determined to be Hypertext Transfer Security Protocol (HTTPS); if the parsing result of the listening port field does not include SSL, the URL protocol is determined to be Hypertext Transfer Security Protocol (HTTP).
[0079] Furthermore, the parsing result of the listening port field is extracted as the port of the URL address. If there are multiple ports, it can be split into multiple URL addresses.
[0080] Furthermore, it determines whether the parsing result of the path matching rule (location) field is a regular expression match. If the match type is a regular expression match, a path is generated according to the regular expression, and the generated path is used as the path in the URL address, and then proceeds to concatenate the URL address. If the match type is not a regular expression match, the parsing result of the path matching rule field in the structured data is directly used as the path in the URL address.
[0081] Furthermore, based on the standard structure of a URL, the parsed hostname, port, protocol, and path are concatenated into a complete URL address, generating a list of accessible URLs.
[0082] Finally, the directory scanning engine (such as Dirsearch, FFUF, Gobuster, etc.) is invoked, and the directory scanning program is started by combining the constructed URL list.
[0083] Furthermore, by performing structured processing and risk analysis on the results returned by the directory scan, a complete closed loop of "configuration awareness - automatic path generation - scan execution - result storage and analysis - risk path alarm" can be established, which can significantly improve the coverage, accuracy and real-time performance of the directory scan and reduce the occurrence of security incidents caused by configuration errors, path exposure and other reasons.
[0084] In practical applications, the scan results data returned by the directory scanning engine are received, and the data is parsed in a structured manner to extract key fields such as URL address, response status code, response time, response length, and redirection information.
[0085] Furthermore, responses are categorized based on status codes, such as: 200 (success), 301 / 302 (redirect), 403 (forbidden), 404 (not found), 500 (server error), etc.
[0086] Furthermore, by combining the field data and according to the preset risk identification rules, risk identification analysis is performed to determine whether the directory scan result of each URL address is a suspicious or sensitive response status. For example, if the response status code is 200 Success and the path is a sensitive resource, it can be determined that the current URL address has the risk of sensitive resource leakage, and it can be marked as a sensitive path, and the reason can be recorded.
[0087] Furthermore, by systematically reviewing and analyzing all scan results, all identification and analysis results (including normal and suspicious items) are archived into a unified database for easy retrieval, analysis, and visualization.
[0088] Furthermore, it can push risk identification and analysis results for items with risks, and can also determine whether alarm conditions are triggered based on preset rules (such as abnormal access control, exposure of high-risk paths, directory leakage, etc.). When the trigger conditions are met, alarm content is constructed, including information such as URL address, host information, risk level, discovery time, and suspicious reasons, thereby generating a risk warning report and pushing it.
[0089] Finally, the risk warning reports are recorded and stored in the database for easy archiving and analysis later.
[0090] In practical applications, different sets of rules for judging scanning results can be set according to specific scenario requirements, thereby enabling adaptive processing such as alarms and automated corrections.
[0091] Please see Figure 6 , Figure 6 This is a schematic diagram of an automatic directory scanning and early warning device based on Nginx configuration provided in an embodiment of this application. This application also provides an automatic directory scanning and early warning device based on Nginx configuration, which can implement the above-mentioned automatic directory scanning and early warning method based on Nginx configuration. The device includes: The configuration parsing module 610 is used to obtain the Nginx configuration file in response to the directory scan startup command and parse the Nginx configuration file into structured data; Address conversion module 620 is used to convert the structured data into a Uniform Resource Locator (URL) address and start a directory scanning program based on the URL address. The scanning and early warning module 630 is used to obtain the catalog scanning results, perform structured processing and risk identification analysis, generate risk early warning reports and store them in the database.
[0092] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The specific functions implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0093] Please see Figure 7 , Figure 7 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. The electronic device includes: The processor 701 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 702 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 702 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 702 and is called and executed by the processor 701 using the methods described in the embodiments of this application. The input / output interface 703 is used to implement information input and output; The communication interface 704 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 705 transmits information between various components of the device (e.g., processor 701, memory 702, input / output interface 703, and communication interface 704); The processor 701, memory 702, input / output interface 703, and communication interface 704 are connected to each other within the device via bus 705.
[0094] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method.
[0095] It is understood that the content of the above method embodiments is applicable to this storage medium embodiment. The specific functions implemented in this storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.
[0096] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0097] It is understood that the content of the above method embodiments is applicable to the embodiments of this program product. The specific functions implemented by the embodiments of this program product are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0098] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0099] This application provides an automatic directory scanning and early warning method and related equipment based on Nginx configuration. It automatically parses the Nginx configuration file and intelligently concatenates it to form a unified resource locator address, which effectively improves the path hit rate and accurately locates the scanning range. Combined with the directory scanning results, it performs risk analysis, reduces the false alarm rate, detects risks in advance, and reduces the occurrence of security incidents caused by configuration errors, path exposure, etc.
[0100] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0101] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0102] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0103] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0104] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0105] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0106] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0107] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0108] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0109] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0110] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.
Claims
1. An automatic directory scanning and early warning method based on Nginx configuration, characterized in that, The method includes the following steps: In response to the directory scan start command, the Nginx configuration file is obtained and parsed into structured data; Based on the structured data, a Uniform Resource Locator (URL) address is obtained, and a directory scanning program is started according to the URL address. Obtain the catalog scan results, perform structured processing and risk identification analysis, generate risk warning reports, and store them in the database.
2. The method according to claim 1, characterized in that, The step of responding to the directory scan start command, obtaining the Nginx configuration file, and parsing the Nginx configuration file into structured data includes: In response to the directory scan startup command, retrieve the Nginx configuration file; The Nginx parsing component is invoked to recursively parse the main configuration file and its references, traversing and extracting the parsing results of fields including domain name, listening port, and path matching rules; The parsing results of the fields are stored as structured data.
3. The method according to claim 1, characterized in that, The process of converting the structured data into a Uniform Resource Locator (URL) and then launching a directory scanning program based on the URL includes: Obtain the structured data; Extract the domain name field resolution result from the structured data and use it as the hostname of the Uniform Resource Locator address; The parsing result of the listening port field in the structured data is used as the port and protocol of the Uniform Resource Locator address; Extract the path matching rule field parsing result from the structured data as the path of the Uniform Resource Locator address; The hostname, port, protocol, and path of the Uniform Resource Locator (URL) are concatenated to obtain the URL. Based on the Uniform Resource Locator address, invoke and start the directory scanning program.
4. The method according to claim 3, characterized in that, The method further includes: If the parsing result of the listening port field includes Secure Sockets Layer, the protocol for the Uniform Resource Locator address is determined to be Hypertext Transfer Security Protocol (HTTP). If the parsing result of the listening port field does not include Secure Sockets Layer, the protocol for the Uniform Resource Locator address is determined to be Hypertext Transfer Protocol. When the path matching rule is regular expression matching, a path is generated based on the regular expression, which serves as the path of the Uniform Resource Locator address.
5. The method according to claim 1, characterized in that, The process of obtaining the catalog scan results, performing structured processing and risk identification analysis, generating a risk warning report, and storing it in the database includes: Obtain the directory scan results; The directory scan results are structured to extract field data including Uniform Resource Locator address, response status code, response time, response length, and redirection information; Based on the field data, risk identification analysis is performed according to preset risk identification rules, thereby recording the risk identification analysis results of each directory scan result and pushing the risk identification analysis results of items with risks. Generate risk warning reports and record and store them in the database.
6. The method according to claim 1, characterized in that, The method further includes: In response to the Nginx configuration update command, the updated Nginx configuration file is retrieved again, and the updated Nginx configuration file is parsed into structured data.
7. An automatic directory scanning and early warning device based on Nginx configuration, characterized in that, The device includes: The configuration parsing module is used to respond to the directory scan startup command, obtain the Nginx configuration file, and parse the Nginx configuration file into structured data; The address conversion module is used to convert the structured data into a Uniform Resource Locator (URL) address and start a directory scanning program based on the URL address. The scanning and early warning module is used to obtain the catalog scanning results, perform structured processing and risk identification analysis, generate risk early warning reports, and store them in the database.
8. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method according to any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 6.
Citation Information
Patent Citations
Distributed Nginx server management method and system
CN108494589A
Vulnerability management system based on multi-engine vulnerability scanning association analysis
CN108737425A
URL extraction method and device, equipment and computer readable storage medium
CN110472165A
Method for actively discovering distributed self-built system and scanning security vulnerabilities
CN112364355A
Vulnerability management system integrating vulnerability scanning engine and vulnerability work order management
CN113704767A