Automatic revoking method, device and equipment for abnormal digital certificate based on CT log, storage medium and program product

By retrieving certificate records from the CT log server and using a fusion detection algorithm for multi-dimensional anomaly detection, abnormal certificates are automatically revoked. This solves the problem of low response efficiency in existing technologies, achieves real-time security detection and revocation, and improves network security.

CN121261900AActive Publication Date: 2026-01-02TRUSTASIA TECH INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511402689.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-28
Publication Date
2026-01-02
Estimated Expiration
2045-09-28

AI Technical Summary

Technical Problem

In existing technologies, the process of detecting and revoking digital certificates lacks automation, resulting in low response efficiency and an inability to promptly detect and handle unauthorized or abnormal certificates, thus increasing cybersecurity risks.

Method used

By obtaining certificate records from multiple CT log servers, using a fusion detection algorithm for multi-dimensional anomaly detection, and combining the anomaly detection results from multiple dimensions to determine whether there are abnormal certificates, the system automatically submits a revocation request to the CA to achieve automatic certificate revocation.

Benefits of technology

It enables real-time detection and revocation of unauthorized or abnormal certificates, improving the security of website access and authentication, and enhancing the efficiency and response speed of security detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121261900A_ABST
    Figure CN121261900A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, discloses an abnormal digital certificate automatic revoking method and device based on a CT log, electronic equipment, a readable storage medium and a program product, and is used for solving the technical problem that in the prior art, an abnormal digital certificate cannot be detected in time, so that the security risk is relatively high during website access or identity verification. The method comprises the following steps: acquiring CT logs from a plurality of CT log servers, and screening out a new certificate signing and issuing record related to a target domain name from the acquired CT logs; performing multi-dimensional anomaly detection on the newly added certificate signing and issuing record based on a fusion detection algorithm, and judging whether an abnormal certificate signing and issuing record is included or not by combining a multi-dimensional anomaly detection result; and when detecting that the abnormal certificate issuing record exists, submitting a certificate revoking request to the CA corresponding to the abnormal certificate issuing record, and revoking the digital certificate corresponding to the abnormal certificate issuing record. According to the method, the abnormal digital certificate can be timely identified and revoked.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to an abnormal digital certificate automatic revocation method and device based on CT logs, an electronic device, a computer storage medium, and a computer program product. BACKGROUND

[0002] In the current Internet environment, digital certificates are widely used for website encryption and identity verification, and are an important foundation for network security. In order to prevent someone from forging or misusing digital certificates, the industry has introduced certificate transparency logs (CT logs). CT logs record all issued certificates, which can be viewed by anyone, with the purpose of improving the transparency of certificate issuance and helping to identify suspicious certificates that have been issued without authorization. However, in existing practical applications, there are often various problems, such as: after the appearance of abnormal certificates, manual checking and analysis are usually required for manual processing; the process of revoking certificates is not automated, and time is easily wasted in the middle; only certificates can be recorded, and there is a lack of an alarm mechanism, so that operation and maintenance personnel cannot timely detect risks; there is a lack of automatic linkage between various links, resulting in low overall response efficiency.

[0003] Therefore, there is an urgent need for a more automated and efficient way to use CT logs to automatically revoke and timely issue warnings after discovering abnormal certificates, helping the system to respond more quickly to potential security problems and improve overall response speed and security protection capabilities. SUMMARY

[0004] The main purpose of the present application is to solve the technical problem that the prior art cannot automatically and in real time detect whether there is an unauthorized or abnormal certificate issuance record, resulting in the inability to timely detect abnormal digital certificates, and resulting in a high security risk when accessing a website or verifying identity.

[0005] The first aspect of the present application provides an abnormal digital certificate automatic revocation method based on CT logs, comprising: obtaining CT logs from a plurality of CT log servers, and screening newly issued certificate records related to a target domain name from the obtained CT logs; performing multi-dimensional anomaly detection on the newly issued certificate records based on a fusion detection algorithm, and combining the anomaly detection results of multiple dimensions to determine whether there is an abnormal certificate issuance record; When an abnormal certificate issuance record is detected, a certificate revocation request is submitted to the CA corresponding to the abnormal certificate issuance record, and the digital certificate corresponding to the abnormal certificate issuance record is revoked.

[0006] Optionally, in the first implementation manner of the first aspect, the obtaining the CT log from the plurality of CT log servers and screening the newly issued certificate record related to the target domain name from the obtained CT log comprises: obtaining the CT log information from the plurality of log servers through continuous subscription of the CT real-time stream mechanism; judging whether the corresponding newly issued certificate information in the CT log information is certificate information that has been subjected to abnormal detection; if the certificate information has not been subjected to abnormal detection, performing integrity verification on the certificate information to determine whether the certificate information is tampered data; if the certificate information has not been tampered, receiving a preset domain name screening requirement, and screening the newly issued certificate record related to the target domain name based on the domain name screening requirement.

[0007] Optionally, in the second implementation manner of the first aspect, the multi-dimensional abnormal detection of the newly issued certificate record based on the fusion detection algorithm comprises: calling a plurality of sub-models of a fusion detection model to perform multi-dimensional parallel detection, and respectively obtaining an abnormal probability score, a reconstruction error score, a Boolean detection score, and a confidence degree of each score, wherein the sub-models comprise an isolation forest model, a time series auto-encoding model, and a rule engine model; performing evaluation result fusion based on the abnormal probability score, the reconstruction error score, the Boolean detection score, and the confidence degree of each score to obtain an abnormal risk evaluation result and an evaluation result confidence degree; determining whether the certificate issuance record with the abnormality exists based on the abnormal risk evaluation result and the evaluation result confidence degree.

[0008] Optionally, in the third implementation manner of the first aspect, the evaluation result fusion based on the abnormal probability score, the reconstruction error score, the Boolean detection score, and the confidence degree of each score comprises: obtaining historical accuracy information of each sub-model in the fusion detection algorithm, a current abnormal evaluation scene feature, and model related information; calling a strategy adjustment algorithm to adjust the fusion weight based on the historical accuracy information, the abnormal evaluation scene feature, and the related information of each sub-model; performing evaluation result fusion based on the abnormal probability score, the reconstruction error score, the Boolean detection score, and the confidence degree of each score based on the adjusted fusion weight.

[0009] Optionally, in the fourth implementation manner of the first aspect, after the digital certificate corresponding to the certificate issuance record with the abnormality is revoked, the method further comprises: Based on the certificate revocation data information statistics in the preset time, false positive rate, false negative rate and revocation success rate are evaluated, and normalization is performed to obtain a state vector of the revocation behavior; An adjustment strategy is generated based on the state vector of the revocation behavior, and the configuration parameters of the fusion detection algorithm are modified based on the adjustment strategy.

[0010] Optionally, in the fifth implementation manner of the first aspect of the present application, after the digital certificate corresponding to the certificate issuance record with the abnormality is revoked, the method further comprises: The certificate details, abnormal risk assessment results and adjustment strategies of the digital certificate to be revoked are encapsulated to obtain risk warning information; The risk warning information is pushed to a preset risk warning platform, and is displayed and alarmed in real time.

[0011] The second aspect of the present application provides an abnormal digital certificate automatic revocation device based on CT logs, comprising: A certificate record acquisition module is configured to acquire CT logs from a plurality of CT log servers, and to screen out newly issued certificate records related to a target domain name from the acquired CT logs; An abnormality detection module is configured to perform multi-dimensional abnormality detection on the newly issued certificate records based on a fusion detection algorithm, and to determine whether the newly issued certificate records contain a certificate issuance record with an abnormality in combination with abnormality detection results of a plurality of dimensions; A certificate revocation module is configured to submit a certificate revocation request to a CA corresponding to the certificate issuance record with the abnormality when the certificate issuance record with the abnormality is detected, and to revoke a digital certificate corresponding to the certificate issuance record with the abnormality.

[0012] The third aspect of the present application provides an abnormal digital certificate automatic revocation device based on CT logs, comprising a memory and at least one processor, wherein the memory stores instructions; and the at least one processor invokes the instructions in the memory to enable the abnormal digital certificate automatic revocation device based on CT logs to perform the steps of the above-mentioned abnormal digital certificate automatic revocation method based on CT logs.

[0013] The fourth aspect of the present application provides a computer readable storage medium, wherein the computer readable storage medium stores instructions, and when the instructions are executed on a computer, the computer performs the steps of the above-mentioned abnormal digital certificate automatic revocation method based on CT logs.

[0014] The fifth aspect of the present application provides a computer program product, comprising computer programs / instructions, when the computer programs / instructions are executed by a processor, the steps of the above-mentioned abnormal digital certificate automatic revocation method based on CT logs are implemented.

[0015] The technical solution provided by the present application screens out the newly issued certificate records related to the target domain name from the CT logs obtained from the plurality of CT log servers; performs multi-dimensional anomaly detection on the newly issued certificate records based on a fusion detection algorithm, and judges whether the newly issued certificate records contain certificate issuance records with anomalies in combination with the anomaly detection results of the plurality of dimensions; when the certificate issuance records with anomalies are detected, submits a certificate revocation request to the CA corresponding to the certificate issuance records with anomalies, and revokes the digital certificate corresponding to the certificate issuance records with anomalies. The method can automatically and in real time detect whether there are unauthorized or abnormal certificate issuance records, can timely detect abnormal digital certificates and revoke them, can improve the security when accessing a website or verifying an identity, and can improve the efficiency of security detection.

[0016] Meanwhile, the device, the electronic device, the computer readable storage medium and the computer program product provided by the present application also solve the corresponding technical problems. BRIEF DESCRIPTION OF DRAWINGS

[0017] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the present application and serve to explain the principles of the present application, and do not limit the present application in any manner. In the drawings: Figure 1 a flowchart of a first embodiment of the method for automatically revoking abnormal digital certificates based on CT logs in the embodiments of the present application; Figure 2 a flowchart of a second embodiment of the method for automatically revoking abnormal digital certificates based on CT logs in the embodiments of the present application; Figure 3 a schematic diagram of one embodiment of the device for automatically revoking abnormal digital certificates based on CT logs in the embodiments of the present application; Figure 4 a schematic diagram of one embodiment of the device for automatically revoking abnormal digital certificates based on CT logs in the embodiments of the present application; Figure 5 a schematic diagram of one embodiment of the device for automatically revoking abnormal digital certificates based on CT logs in the embodiments of the present application; DETAILED DESCRIPTION

[0018] Exemplary embodiments of the present application will now be described more fully with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these exemplary embodiments are provided so that the present application will be thorough and complete, and will fully convey the scope of the application to those skilled in the art. Like reference numerals refer to like elements throughout the specification. Repetitive descriptions of like elements will be omitted for brevity.

[0019] In the premise of conforming to the technical concept of the present application, the features, structures, characteristics or other details described in a certain specific embodiment do not exclude that they can be combined in one or more other embodiments in a suitable manner.

[0020] In the description of specific embodiments, the features, structures, characteristics or other details described in the present application are to enable those skilled in the art to fully understand the embodiments. However, it does not exclude that one or more of the skilled in the art can practice the technical solution of the present application without a specific feature, structure, characteristic or other detail.

[0021] The flowchart shown in the accompanying drawings is only an exemplary illustration, and does not necessarily include all contents and operations / steps, nor does it necessarily execute in the order described. For example, some operations / steps can be further decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may be changed according to the actual situation.

[0022] The block diagram shown in the accompanying drawings is only a functional entity, which does not necessarily correspond to a physically independent entity. That is, these functional entities can be implemented in the form of software, or in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0023] The term "and / or" or "and / or" includes all combinations of any one or more of the associated listed items.

[0024] Please refer to Figure 1 The first embodiment of the abnormal digital certificate automatic revocation method based on CT log in the embodiment of the present application includes: S101, obtaining CT logs from a plurality of CT log servers, and screening newly issued certificate records related to a target domain name in the obtained CT logs; It can be understood that the execution subject of the present application can be an abnormal digital certificate automatic revocation device based on CT log, and can also be a terminal or a server, which is not limited here. The server is taken as an example for description in the embodiment of the present application.

[0025] The CT log described in the embodiment refers to a Certificate Transparency log, and the Certificate Transparency is a network security mechanism, which aims to enhance the security and transparency of SSL or TLS digital certificates by publicly recording and auditing the issuance process of digital certificates.

[0026] Specifically, when acquiring CT log information from multiple CT log sources, WebSocket streams of a CertStream or the like that can continuously subscribe to CT real-time stream tools can be connected to multiple CT log servers, so that certificate update data is continuously received in real time in the multiple CT log servers. When the certificate update data is received, the certificate update data is parsed and certificate information is extracted, wherein the certificate information includes certificate serial numbers, domain names, issuers, certificate validity periods, certificate issuance times, and the like. Based on a preset screening rule, some newly issued certificates of interest can be screened according to different information items In a specific implementation, when the content of interest is several domain names, the newly issued certificate records related to the target domain name can be obtained by screening based on the domain name field in the certificate information according to the preset target domain name information. Moreover, the screened newly issued certificate records related to the target domain name can be saved in a table form.

[0027] S102, performing multi-dimensional anomaly detection on the newly issued certificate records based on a fusion detection algorithm, and determining whether the newly issued certificate records contain an abnormal certificate issuance record based on the multi-dimensional anomaly detection results. The fusion detection algorithm in this embodiment is a scheme for performing multi-dimensional anomaly detection on the newly issued certificate records based on a fusion detection model. The fusion detection model is constructed by fusing multiple sub-models. This scheme can call multiple sub-models to respectively perform anomaly evaluation on the newly issued certificate records in different dimensions, output multiple anomaly evaluation scores, fuse the anomaly evaluation scores, and obtain a final anomaly risk evaluation result. Then, based on the anomaly risk evaluation result, it is determined whether the newly issued certificate records contain an abnormal certificate issuance record. Specifically, an anomaly evaluation threshold can be set in advance. If the anomaly risk evaluation result exceeds the anomaly evaluation threshold, it is considered that the certificate issuance record corresponding to the anomaly risk evaluation result contains an anomaly. If the anomaly risk evaluation result does not exceed the anomaly evaluation threshold, it is considered that the certificate issuance record corresponding to the anomaly risk evaluation result does not contain an anomaly.

[0028] In a specific implementation, the sub-models can be an isolation forest model, a time series autoencoder, and a rule engine. A strategy adjustment algorithm is called to fuse the evaluation scores output by the sub-models. The strategy adjustment algorithm in this embodiment can adaptively and dynamically adjust the fusion weight method of the evaluation scores output by the sub-models based on historical accuracy, scene features, and the like. The strategy adjustment algorithm can be implemented based on a deep learning intelligent agent Agent. The weights of the results output by the sub-models are adjusted when fusing, so as to improve the overall detection accuracy and the generalization ability of detection.

[0029] S103, when detecting that there is an abnormal certificate issuing record, submitting a certificate revocation request to the CA (Certificate Authority, Certificate Authority) corresponding to the abnormal certificate issuing record, and revoking the digital certificate corresponding to the abnormal certificate issuing record.

[0030] Based on the detection step in S102, when detecting that there is an abnormal certificate issuing record, the abnormal certificate issuing record is obtained, and according to the content recorded in the certificate issuing record, the CA issuing the certificate is found, and a certificate revocation request is submitted to it, and the corresponding digital certificate is revoked.

[0031] The method in the embodiment can automatically and in real time detect whether there is an unauthorized or abnormal certificate issuing record, can detect abnormal digital certificates in time and revoke them, can improve the security when accessing a website or authenticating, and can improve the efficiency of security detection.

[0032] Please refer to Figure 2 The second embodiment of the abnormal digital certificate automatic revocation method based on CT log in the embodiment of the application comprises: S201, obtaining CT logs from a plurality of CT log servers, and screening out newly issued certificate records related to a target domain name in the obtained CT logs; The CT log in the embodiment refers to a Certificate Transparency log, and the certificate transparency is a network security mechanism aiming to enhance the security and transparency of SSL or TLS digital certificates by publicly recording and auditing the issuance process of digital certificates.

[0033] In a specific embodiment, when obtaining CT log information from a plurality of CT log sources, the WebSocket stream of the CertStream tool can be connected to a plurality of CT log servers, and the CT log information from a plurality of log servers can be obtained through continuous subscription of the CT real-time stream mechanism, so that certificate update data is continuously received in real time in a plurality of CT log servers. When receiving the certificate update data, the certificate update data is parsed and the certificate information is extracted, wherein the certificate information includes: certificate serial number, domain name, issuer, certificate validity period, and certificate issuance time.

[0034] After obtaining the certificate information, the Bloom filter is also called to check each certificate item; wherein the Bloom filter can quickly judge whether a certificate has been subjected to abnormal detection, if it is a certificate information that has been subjected to abnormal detection, it is skipped; if it is a certificate information that has not been subjected to abnormal detection, subsequent processing is continued.

[0035] In another specific embodiment, tens of thousands of log stream parsing and message decoupling processing per second can be achieved based on a custom parallel computing framework, an asynchronous event-driven model (Event Loop with Non-blocking I / O), and a customized memory pool management mechanism. In combination with a Bloom filter and an incremental Merkle tree cache, fast duplicate detection and tree structure integrity verification are achieved. Specifically, when the CT log uses a Merkle tree structure to ensure the integrity of the log, an incremental Merkle tree cache is used in this embodiment to verify the tree structure of the certificate data. The server in this embodiment maintains an incremental Merkle tree cache to verify the tree structure of the received certificate update data, ensuring that the data has not been tampered with during transmission. If the certificate information has not been tampered with, the server receives the pre-set domain name screening requirements and filters the newly issued certificate records related to the target domain name based on the domain name screening requirements.

[0036] After obtaining the certificate information, the pre-set matching requirements and matching rules are also obtained, and the certificate information related to the target domain name of the company of interest is searched in the received certificate information. Based on the filtered certificate information, a list of newly issued certificate records is formed.

[0037] In a preferred embodiment, after receiving the certificate update data, each certificate update event is encapsulated into a message and placed in a message queue for decoupling to facilitate subsequent parallel processing.

[0038] S202, call multiple sub-models of the fusion detection model to perform multi-dimensional parallel detection to obtain abnormal probability scores, reconstruction error scores, and Boolean detection scores, as well as the confidence of each score. The fusion detection model in this embodiment is obtained by fusing sub-models such as isolated forest models, time series autoencoders, and rule engines. These models can be called for parallel detection, so that abnormal detection and scoring are performed from multiple dimensions and data processing methods based on multiple sub-models. The scoring results of each sub-model are obtained, and finally the scoring results are fused to obtain the final abnormal detection value. According to the obtained abnormal detection value, it is determined whether the newly issued certificate record list contains abnormal certificate issuance records.

[0039] Specifically, in this step, the isolated forest model, the time series autoencoder and the rule engine are called to perform parallel detection, respectively obtaining an abnormal probability score, a reconstruction error score and a Boolean detection score and a confidence of each score; the abnormal probability score, the reconstruction error score and the Boolean detection score and the confidence of each score are fused to output an abnormal score; after the judgment results of the multiple judgment models are spatially unified, the fusion strategy is used for fusion to obtain an abnormal voting result and a confidence, and whether the certificate issuance record containing the abnormality exists is determined based on the abnormal voting result and the confidence.

[0040] S203, performing evaluation result fusion based on the abnormal probability score, the reconstruction error score and the Boolean detection score and the confidence of each score to obtain an abnormal risk evaluation result and an evaluation result confidence; S204, determining whether the certificate issuance record containing the abnormality exists based on the abnormal risk evaluation result and the evaluation result confidence; The historical accuracy rate information of each sub-model in the fusion detection algorithm, the current abnormal evaluation scene features and the model related information are obtained; the strategy adjustment algorithm is called to adjust the fusion weight based on the historical accuracy rate information, the abnormal evaluation scene features and the model related information; the evaluation result fusion is performed based on the abnormal probability score, the reconstruction error score and the Boolean detection score and the confidence of each score based on the adjusted fusion weight. Then, whether the certificate issuance record containing the abnormality exists in the current newly issued certificate record is determined based on the abnormal risk evaluation result. Specifically, the abnormal evaluation threshold can be set in advance. If the abnormal risk evaluation result exceeds the abnormal evaluation threshold, it is considered that the certificate issuance record corresponding to the abnormal risk evaluation result contains the abnormality. If the abnormal risk evaluation result does not exceed the abnormal evaluation threshold, it is considered that the certificate issuance record corresponding to the abnormal risk evaluation result is not abnormal.

[0041] S205, when the certificate issuance record containing the abnormality is detected, a certificate revocation request is submitted to the CA (Certificate Authority, Certificate Authority) corresponding to the certificate issuance record containing the abnormality, and the digital certificate corresponding to the certificate issuance record containing the abnormality is revoked; In this embodiment, when the certificate issuance record containing the abnormality is detected, the system automatically calls the standardized revocation interface to realize the high-reliability revocation of the certificate.

[0042] Specifically, a unified abstract interface (such as Support CA-SDK and ACME v2) can be used to call down the revocation API (Application Programming Interface, application programming interface); the revocation API can be compatible with multiple CAs, and when the abnormal score exceeds the threshold value or the rule engine directly determines that it is high risk, the system immediately initiates a revocation request. In this way, a retry mechanism and exception handling can be integrated to ensure the success rate of the revocation request. In combination with the adaptive strategy module, the revocation result is used as feedback input to the reward function.

[0043] S206, based on the certificate revocation data information in the preset time, the false positive rate, the false negative rate and the revocation success rate are evaluated and normalized to obtain a state vector of the revocation behavior; S207, generating an adjustment strategy based on the state vector of the revocation behavior, and modifying the configuration parameters of the fusion detection algorithm based on the adjustment strategy; In this embodiment, an intelligent agent (Agent) constructed based on deep reinforcement learning is also included to optimize the fusion strategy.

[0044] In a specific embodiment, the present embodiment can include collecting artificial audit results through a human-computer collaborative labeling platform, regularly retraining the model in combination with an active learning strategy, and maintaining the adaptability of the system to new attack patterns. Through the labeling platform, a graphical interface is realized for operation and maintenance personnel to mark false positive / missed cases to form a labeled data set. Based on the labeled data, an active learning strategy is used to select high-value samples, and the DRL Agent (deep learning intelligent agent) and the detection model (such as Isolation Forest and Autoencoder) are regularly retrained. Through a closed-loop optimization method, feedback data is directly embedded into the DRL training process to dynamically adjust the model weight and threshold, realizing continuous self-evolution.

[0045] In a preferred embodiment, this step enhances the model collaboration efficiency at two levels of feature-level collaboration and decision-level voting: (1) Feature-level collaboration: uniformly embedding the intermediate features of Isolation Forest and Time Series Autoencoder into the same feature space, applying a multi-head attention mechanism for weighted fusion, and automatically learning the optimal combination weight of each model in different abnormal scenarios; (2) Decision-level voting: For the anomaly scores or Boolean results output by each sub-model (Isolation Forest, Time Series Autoencoder, Rule Engine), a strategy adjustment algorithm is used to realize the fusion decision. The strategy adjustment algorithm can be realized based on a deep learning intelligent agent (Agent). Specifically, based on the historical accuracy of each model, the current detection scene characteristics, and the correlation between models, the strategy adjustment algorithm calculates the importance information of each model in the current scene through a multi-head attention mechanism, dynamically adjusts the voting weight according to the importance information, forms a gating mechanism with a memory factor, and not only considers the current input, but also combines the past performance of the model in similar scenes for dynamic hierarchical weighting. At the same time, this mechanism has interpretability and can output the confidence evaluation and participation weight of each model for subsequent feedback learning. This fusion strategy is different from the traditional simple superposition method, and provides adaptive joint judgment logic with context awareness and strategy awareness, which improves the overall detection accuracy and generalization ability.

[0046] The embodiment also includes a function of real-time optimization of multiple parallel models in the fusion detection model, which is based on a deep reinforcement learning (Deep Reinforcement Learning, DRL) framework, and optimizes the threshold and rules of the anomaly detection module in real time. Through online + offline hybrid training, the strategy is adaptively adjusted to ensure detection accuracy and stability. Specifically, a strategy intelligent agent (Agent) is constructed in advance, combined with a Bayesian optimization algorithm, to pre-select a high-potential area in the local hyperparameter space, and then a deep learning intelligent agent (DRL Agent) is used to search for continuous actions in this area to ensure sampling efficiency and convergence speed. The performance indicator information (such as false positive rate, false negative rate, SLA delay, and suspension success rate) of the automatic suspension method in the embodiment is collected in real time, and the state vector is normalized and calculated, and the parameters of the fusion model are adjusted based on the state vector. Further, the feedback learning method used by the strategy intelligent agent (Agent) constructed in the embodiment not only adjusts based on overall false positive rate, false negative rate, and other indicator information, but also subdivides the "model + rule" combination pairs and automatically adjusts the corresponding fusion weight and threshold for different combinations.

[0047] Taking a specific example for illustration, the process of strategy optimization in the embodiment includes: (1) State acquisition: The environment evaluator aggregates the detection results and feedback of the last N times every minute, extracts performance indicators such as false positive rate, false negative rate, SLA delay, and suspension success rate, and normalizes them into a state vector ; (2) Action Generation: In this embodiment, the intelligent agent is based on a deep reinforcement learning (DRL) framework and adopts an Actor-Critic dual-network architecture. The Actor generates adjustment instructions, and the Critic evaluates the policy quality. In the action generation step, the Actor network receives... Output action (e.g., adjusting the isolated forest threshold, updating rule engine parameters); (3) Strategy execution: System application actions In real time, the parameters and other configurations of the fusion detection algorithm can be modified. (4) Reward feedback: Calculate the reward in the next time window. ;in The calculation expression is: and the reward Send it to the Critic network to update the value estimate; among which... , and All are weighting coefficients; (5) Online training: Micro-batch gradient updates are performed using experience replay and priority sampling to gradually optimize the Actor and Critic networks; (6) Offline fine-tuning: Daily scheduled training is performed on the best strategies in the strategy library to generate new strategies and push them to the intelligent agent.

[0048] In one specific implementation, when using a deep reinforcement learning framework to optimize strategies in real time, in order to prevent the new strategy from causing a surge in false alarms, the present invention also designs a "canary release" mechanism: the new strategy is only tested on a subset of mirror nodes (10% of traffic), and once it passes the acceptance tests for latency, accuracy and business metrics, it is then pushed to the full population.

[0049] S208. The certificate details of the digital certificate to be revoked, the abnormal risk assessment results, and the adjustment strategy are encapsulated to obtain risk warning information; S209. Push risk warning information to the preset risk warning platform and display and alert in real time.

[0050] The embodiment is based on a Kafka / Event Mesh distribution structure, encapsulates certificate details of a revoked digital certificate corresponding to a detected abnormal certificate record, an abnormal risk assessment result, and an adjustment strategy, obtains risk warning information containing a certificate fingerprint, a model score, and DRL action information, and realizes real-time warning information pushing to a preset risk warning platform and real-time alarm through pushing to an email, a Short Messaging Service (SMS), or an operation and maintenance platform Webhook.

[0051] The embodiment of the application constructs a full-link automatic and intelligent certificate security management system. The core innovation is to deeply integrate DRL and multi-model detection, introduce deep reinforcement learning into the abnormal detection strategy of CT logs, break through the simple threshold retraining mode, realize real-time self-optimization of detection rules, realize real-time self-optimization and end-to-end closed-loop response of the strategy, and significantly improve the efficiency of certificate revocation and the accuracy of risk warning. In addition, the embodiment of the application can realize real-time and rapid acquisition of CT log information by combining Bloom filtering and Merkle caching, and the response speed is accelerated; combined with the continuous online learning function of the intelligent agent (Agent) based on the deep learning algorithm, new types of abuse or phishing certificate scenarios can be quickly captured and disabled from artificial feedback.

[0052] The above describes the abnormal digital certificate automatic revocation method based on CT logs in the embodiment of the application, and the following describes the abnormal digital certificate automatic revocation device based on CT logs in the embodiment of the application. Please refer to Figure 3 One embodiment of the abnormal digital certificate automatic revocation device based on CT logs in the embodiment of the application includes: The certificate record acquisition module 301 is configured to acquire CT logs from a plurality of CT log servers, and filter out newly issued certificate records related to a target domain name in the acquired CT logs. The abnormal detection module 302 is configured to perform multi-dimensional abnormal detection on the newly issued certificate records based on a fusion detection algorithm, and judge whether the newly issued certificate records contain abnormal certificate issuance records in combination with abnormal detection results of a plurality of dimensions. The certificate revocation module 303 is configured to submit a certificate revocation request to a CA corresponding to the abnormal certificate issuance record when detecting the abnormal certificate issuance record, and revoke a digital certificate corresponding to the abnormal certificate issuance record.

[0053] The device in the embodiment can automatically and in real time detect whether there is an unauthorized or abnormal certificate issuance record, can detect an abnormal digital certificate in time and revoke it, can improve the security when accessing a website or authenticating, and can improve the efficiency of security detection.

[0054] In another embodiment of the present application, the certificate record acquisition module 301 is specifically configured to: acquire CT log information from a plurality of log servers by continuously subscribing to a CT real-time stream mechanism; determine whether corresponding newly issued certificate information in the CT log information is certificate information that has been subjected to abnormal detection; if the certificate information has not been subjected to abnormal detection, perform integrity verification on the certificate information to determine whether it is tampered data; if the certificate information has not been tampered, receive a preset domain name screening requirement, and screen newly issued certificate records related to a target domain name based on the domain name screening requirement.

[0055] In another embodiment of the present application, the abnormal detection module 302 is specifically configured to: call a plurality of sub-models of a fusion detection model to perform multi-dimensional parallel detection, respectively obtain an abnormal probability score, a reconstruction error score, and a Boolean detection score, and a confidence of each score, wherein the sub-models include an isolation forest model, a time series auto-encoding model, and a rule engine model; perform evaluation result fusion based on the abnormal probability score, the reconstruction error score, the Boolean detection score, and the confidence of each score to obtain an abnormal risk evaluation result and an evaluation result confidence; determine whether the certificate issuance record containing an abnormality exists based on the abnormal risk evaluation result and the evaluation result confidence.

[0056] In another embodiment of the present application, the evaluation result fusion based on the abnormal probability score, the reconstruction error score, the Boolean detection score, and the confidence of each score includes: acquire historical accuracy information of each sub-model in the fusion detection algorithm, a current abnormal evaluation scene feature, and model related information; call a strategy adjustment algorithm to adjust fusion weights based on the historical accuracy information, the abnormal evaluation scene feature, and the related information of each sub-model; perform evaluation result fusion based on the abnormal probability score, the reconstruction error score, the Boolean detection score, and the confidence of each score based on the adjusted fusion weights.

[0057] In another embodiment of the present application, the abnormal digital certificate automatic revocation device based on a CT log further includes a fusion adjustment module, and the fusion adjustment module is specifically configured to: Based on the certificate revocation data within a preset time period, the false alarm rate, false alarm rate, and revocation success rate are statistically evaluated, and normalization is performed to obtain the state vector of the revocation behavior. An adjustment strategy is generated based on the state vector of the revocation behavior, and the configuration parameters of the fusion detection algorithm are modified based on the adjustment strategy.

[0058] In another embodiment of this application, after revoking the digital certificate corresponding to the abnormal certificate issuance record, the method further includes: The certificate details, abnormal risk assessment results, and adjustment strategies of the digital certificate to be revoked are packaged to obtain risk warning information; The risk warning information is pushed to a preset risk warning platform and displayed and alerted in real time.

[0059] The device in this embodiment can automatically and in real time detect whether there are unauthorized or abnormal certificate issuance records, and can detect and revoke abnormal digital certificates in a timely manner, thereby improving the security of accessing websites or authenticating identity and increasing the efficiency of security detection.

[0060] Based on the same inventive concept, this invention also provides an automatic revocation system for abnormal digital certificates based on CT logs. The corresponding description of this system can be found in the above embodiments, and will not be repeated here.

[0061] Based on the same inventive concept, this specification also provides an electronic device for automatically revoking abnormal digital certificates based on CT logs. The electronic device for automatically revoking abnormal digital certificates based on CT logs in this embodiment of the invention will be described in detail below from the perspective of hardware processing.

[0062] Figure 4 This is a schematic diagram of an electronic device provided as an embodiment of this specification. Refer to the following... Figure 4 To describe the electronic device 400 according to this embodiment of the invention. Figure 4 The electronic device 400 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.

[0063] like Figure 4 As shown, the electronic device 400 is presented in the form of a general-purpose computing device. The components of the electronic device 400 may include, but are not limited to: at least one processing unit 410, at least one storage unit 420, a bus 430 connecting different system components (including storage unit 420 and processing unit 410), a display unit 440, etc.

[0064] The storage unit stores program codes which can be executed by the processing unit 410, so that the processing unit 410 performs the steps according to various exemplary embodiments of the present application described in the processing method part of the present specification. For example, the processing unit 410 can perform the steps as shown in the following. Figure 1

[0065] The storage unit 420 can include a readable medium in the form of a volatile storage unit, such as a random access memory (RAM) 4201 and / or a cache memory 4202, and can further include a read-only memory (ROM) 4203.

[0066] The storage unit 420 can further include a program / utility 4204 having a set of program modules 4205, including but not limited to, an operating system, one or more application programs, other program modules, and program data, each of which can include an implementation of a networking environment, or a combination thereof.

[0067] The bus 430 can represent one or more of several types of bus structures, including a storage unit bus or bus controller, a peripheral bus, a graphics acceleration port, a processing unit bus, or a local bus using any of a variety of bus architectures.

[0068] The electronic device 400 can also communicate with one or more external devices 100, such as a keyboard or a pointing device, a Bluetooth device, etc., and can also communicate with one or more devices that enable a user to interact with the electronic device 400. The communication can be carried out through an input / output (I / O) interface 450. In addition, the electronic device 400 can also communicate with one or more networks, such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet, through a network adapter 460. The network adapter 460 can communicate with other modules of the electronic device 400 through the bus 430. It should be understood that although not shown in the electronic device 400, other hardware and / or software modules can be used in conjunction with the electronic device 400, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc. Figure 4

[0069] ​​Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described in the present application can be implemented by software, or by software in combination with necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a computer readable storage medium (which can be a CD-ROM, an U disk, a mobile hard disk, etc.) or a network, and includes a number of instructions to make a computing device (which can be a personal computer, a server, or a network device, etc.) execute the above-mentioned method according to the present application. When the computer program is executed by a data processing device, the computer readable medium can realize the above-mentioned method of the present application, i.e., the method shown in Figure 1 or Figure 2 .

[0070] Figure 5 A schematic diagram of a computer readable medium provided for an embodiment of the present application.

[0071] The computer program for implementing the method shown in Figure 1 or Figure 2 may be stored on one or more computer readable media. The computer readable medium can be a readable signal medium or a readable storage medium. The readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any suitable combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0072] The computer readable storage medium can include a data signal carried in a baseband or as part of a carrier wave propagating through the transmission medium, in which the readable program code is carried. Such a propagated data signal can take on many forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The readable storage medium can also be any readable medium that can send, propagate or transmit the program for use by or in connection with an instruction execution system, apparatus or device. The program code contained on the readable storage medium can be transmitted by any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.

[0073] In addition, the present application also provides a computer program product, which includes computer programs / instructions, and the computer programs / instructions are executed by a processor to implement the CT log-based automatic revocation method of an abnormal digital certificate as described in any one of the above embodiments.

[0074] The program code, when executed, can implement one or more embodiments of the present application. The program code can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, C++, or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's computing device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device, such as through the Internet using an Internet Service Provider. The application program code can be downloaded to the user's computing device from an external device or through a network, including the Internet, or from a remote computer or server through any such interactive communication means, such as a modem, a cellular telephone system or digital subscriber line (DSL).

[0075] In light of the above, the present application can be implemented in hardware, or as software modules running on one or more processors, or as a combination of both. Those skilled in the art will appreciate that the various components in the embodiments described above can be implemented using a general purpose data processing apparatus, such as a microprocessor or Digital Signal Processor (DSP), or using a special purpose data processing apparatus, such as an Application Specific Integrated Circuit (ASIC) or a Field Programmable Gate Array (FPGA). Those skilled in the art will also appreciate that the various embodiments described above can be implemented using a combination of hardware and software, or as a combination of firmware and hardware. The present application can also be implemented as a computer program product, which can be executed on a computer or a processor, or a computer program product that can be executed on a computer or a processor. Such a computer program product can be stored on a computer readable medium, which can be a storage device or a memory, or can be a signal, which can be downloaded from an Internet website, or provided on a carrier signal, or in any other form.

[0076] The specific embodiments described above are examples of the present application and are not intended to limit the present application, which is defined by the claims. The above-described embodiments are illustrative of the principles of the present application and are not intended to limit the scope of the application. Any modification of the above-described embodiments, the substitution of equivalent elements for those provided, or the use of other forms apparent not depart from the spirit of the present application and the principles of the present application are intended to be included in the scope of the present application.

[0077] Each of the above-described embodiments is described in a progressive manner, and the same or similar parts between the embodiments can be mutually referred to. Each of the embodiments focuses on the differences from other embodiments.

[0078] If the technical solutions of the present application involve personal information, the product applying the technical solutions of the present application has been explicitly informed of the personal information processing rules before processing the personal information, and has obtained the personal independent consent. If the technical solutions of the present application involve sensitive personal information, the product applying the technical solutions of the present application has obtained the personal independent consent before processing the sensitive personal information, and at the same time meets the requirement of "explicit consent". For example, at the personal information collection device such as camera, a clear and prominent sign is set to inform that it has entered the personal information collection range and will collect personal information. If the individual voluntarily enters the collection range, it is considered to agree to collect personal information. Or, on the device for processing personal information, the personal information processing rules are informed by using obvious signs / information, and the personal authorization is obtained by means of pop-up information or asking the individual to upload his / her personal information. The personal information processing rules can include personal information processor, personal information processing purpose, processing method and personal information type, etc.

[0079] The above only describes the embodiments of the present application and is not intended to limit the present application. The present application can have various modifications and changes for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principles of the present application shall be included in the scope of claims of the present application.

Claims

1. A method for automatically revoking abnormal digital certificates based on CT logs, characterized in that, include: Obtain CT logs from multiple CT log servers, and filter out newly issued certificate records related to the target domain name from the obtained CT logs; The newly issued certificate records are subjected to multi-dimensional anomaly detection based on the fusion detection algorithm. The results of the anomaly detection in multiple dimensions are combined to determine whether there are abnormal certificate issuance records. When an abnormal certificate issuance record is detected, a certificate revocation request is submitted to the CA corresponding to the abnormal certificate issuance record to revoke the digital certificate corresponding to the abnormal certificate issuance record.

2. The method for automatic revocation of abnormal digital certificates based on CT logs as described in claim 1, characterized in that, The step of obtaining CT logs from multiple CT log servers and filtering out newly issued certificate records related to the target domain name from the obtained CT logs includes: CT log information from multiple log servers is obtained by continuously subscribing to the CT real-time stream mechanism; Determine whether the newly issued certificate information in the CT log information is a certificate information that has already undergone anomaly detection; If the certificate information has not undergone anomaly detection, then the certificate information is subjected to integrity verification to determine whether it has been tampered with. If the certificate information has not been tampered with, the preset domain name filtering requirements are received, and new certificate issuance records related to the target domain name are obtained based on the domain name filtering requirements.

3. The method for automatic revocation of abnormal digital certificates based on CT logs according to claim 1, characterized in that, The step of performing multi-dimensional anomaly detection on the newly issued certificate records based on the fusion detection algorithm, and determining whether there are abnormal certificate issuance records by combining the anomaly detection results from multiple dimensions, includes: Multiple sub-models of the fusion detection model are invoked to perform multi-dimensional parallel detection, and anomaly probability score, reconstruction error score, Boolean detection score and confidence of each score are obtained respectively. The sub-models include an isolated forest model, a temporal autoencoder model and a rule engine model. The evaluation results are fused based on the anomaly probability score, reconstruction error score, Boolean detection score, and the confidence level of each score to obtain the anomaly risk assessment result and the confidence level of the assessment result; Based on the aforementioned anomaly risk assessment results and the confidence level of the assessment results, it is determined whether the certificate issuance records contain any anomalies.

4. The method for automatic revocation of abnormal digital certificates based on CT logs according to claim 3, characterized in that, The fusion of evaluation results based on the anomaly probability score, reconstruction error score, Boolean detection score, and the confidence level of each score includes: Obtain historical accuracy information of each sub-model in the fusion detection algorithm, current anomaly assessment scenario features, and model-related information; The strategy adjustment algorithm is invoked to adjust the fusion weights based on the historical accuracy information, the characteristics of the abnormal evaluation scenario, and the relevant information of each sub-model; The evaluation results are fused based on the adjusted fusion weights, the anomaly probability score, the reconstruction error score, the Boolean detection score, and the confidence level of each score.

5. The method for automatic revocation of abnormal digital certificates based on CT logs according to claim 4, characterized in that, After revoking the digital certificate corresponding to the abnormal certificate issuance record, the process further includes: Based on the certificate revocation data within a preset time period, the false alarm rate, false alarm rate, and revocation success rate are statistically evaluated, and normalization is performed to obtain the state vector of the revocation behavior. An adjustment strategy is generated based on the state vector of the revocation behavior, and the configuration parameters of the fusion detection algorithm are modified based on the adjustment strategy.

6. The method for automatic revocation of abnormal digital certificates based on CT logs according to claim 5, characterized in that, After revoking the digital certificate corresponding to the abnormal certificate issuance record, the process also includes: The certificate details, abnormal risk assessment results, and adjustment strategies of the digital certificate to be revoked are packaged to obtain risk warning information; The risk warning information is pushed to a preset risk warning platform and displayed and alerted in real time.

7. An automatic revocation device for abnormal digital certificates based on CT logs, characterized in that, The automatic revocation device for abnormal digital certificates based on CT logs includes: The certificate record acquisition module is used to obtain CT logs from multiple CT log servers and filter out newly issued certificate records related to the target domain name from the obtained CT logs. An anomaly detection module is used to perform multi-dimensional anomaly detection on the newly added certificate issuance records based on a fusion detection algorithm, and to determine whether there are any abnormal certificate issuance records by combining the anomaly detection results from multiple dimensions. The certificate revocation module is used to submit a certificate revocation request to the CA corresponding to the abnormal certificate issuance record when an abnormal certificate issuance record is detected, and revoke the digital certificate corresponding to the abnormal certificate issuance record.

8. An automatic revocation device for abnormal digital certificates based on CT logs, characterized in that, The automatic revocation device for abnormal digital certificates based on CT logs includes: a memory and at least one processor, wherein the memory stores instructions; The at least one processor invokes the instructions in the memory to cause the CT log-based automatic revocation device for abnormal digital certificates to perform the steps of the CT log-based automatic revocation method for abnormal digital certificates as described in any one of claims 1-6.

9. A computer-readable storage medium storing a computer program / instructions thereon, characterized in that, When the program / instruction is executed by the processor, it implements the steps of the automatic revocation method for abnormal digital certificates based on CT logs as described in any one of claims 1-6.

10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the steps of the automatic revocation method for abnormal digital certificates based on CT logs as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Certificate transparentizing method and system for domain name owner self-defined verification strategy

    CN114422138A

  • Abnormal log detection method and device, electronic equipment and storage medium

    CN115048345A

  • Certificate transparency-based power grid certificate monitoring system and method, and electronic equipment

    CN120017276A

  • Safety verification method and system based on ACME protocol and related device

    CN120200817A

  • Methods and Systems for Certificate Filtering

    US20200287888A1