Security protection method and device, electronic equipment and storage medium

By obtaining the source code from the development team for static analysis and real-time scoring, the problem of isolated operations between the development team and the operations or security team was solved, enabling collaborative protection throughout the entire lifecycle and improving the project's security capabilities.

CN121744310APending Publication Date: 2026-03-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In the software development lifecycle, isolated operations between development teams, testing teams, and operations or security teams lead to security vulnerabilities and a lack of collaborative protection capabilities throughout the entire lifecycle.

Method used

By obtaining the source code from the development side for static analysis, vulnerabilities are identified, and when no vulnerabilities are found, policy files are sent to the operations side for deployment. Abnormal content is scored in real time, and security protection policies are fed back to the development side to achieve multi-party collaborative protection.

Benefits of technology

It improves security protection capabilities at each stage of the software development lifecycle, ensures direct interaction and collaboration between the operations or security team and the development team, and enhances the project's security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121744310A_ABST
    Figure CN121744310A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a security protection method and device, electronic equipment and a storage medium, and relates to the technical field of big data, and the method comprises the steps: obtaining a source code from a development end, determining an analysis type according to the development technology of the source code, and analyzing the source code according to the analysis type to obtain a vulnerability result; when the vulnerability result is no vulnerability, sending a source code and a strategy file corresponding to the source code to the operation end, so that the operation end carries out deployment according to the source code and the strategy file; and after deployment success information sent by the operation end is received, target content is determined according to the real-time request, abnormal scoring is performed on the target content, a security protection strategy for the real-time request is determined according to the abnormal score, and the security protection strategy is fed back to the development end. According to the method, other teams can be ensured to directly interact and cooperate with the operation and maintenance or security team, and finally, the security team feeds back the result to the development team to refine the source code, so that the security protection capability of the whole project on vulnerabilities in the whole period is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of big data technology, and in particular to a security protection method, device, electronic device and storage medium. Background Technology

[0002] With the development of internet technology, the World Wide Web (Web) has been widely applied across various industries. Currently, in modern development models, if no vulnerabilities are found in the code during the development phase, it is directly handed over to the operations or security team for handling; similarly, if no vulnerabilities are found during the testing phase, it is also directly handed over to the operations or security team for handling.

[0003] However, in actual development models, the development team, testing team, and operations or security team are only responsible for their own tasks, which leads to the use of isolated security tools and processes at different stages of the software development lifecycle, resulting in security vulnerabilities. Summary of the Invention

[0004] This invention provides a security protection method, device, electronic device, and storage medium, which relates to the field of big data technology and is applicable to the field of financial technology. It can ensure that other teams can directly interact and collaborate with the operation and maintenance or security team, and the security team will ultimately feed back the results to the development team to improve the source code, thereby improving the security protection capability against vulnerabilities of the entire project throughout the entire cycle.

[0005] In a first aspect, embodiments of the present invention provide a security protection method, the method comprising:

[0006] Obtain the source code from the development side, determine the parsing type based on the development technology of the source code, and parse the source code according to the parsing type to obtain the vulnerability results.

[0007] If the vulnerability result is no vulnerability, send the source code and the corresponding policy file to the operations team so that the operations team can deploy according to the source code and the policy file.

[0008] After receiving the deployment success message from the operations team, the target content is determined based on the real-time request, anomaly scoring is performed on the target content, and a security protection strategy for the real-time request is determined based on the anomaly score. The security protection strategy is then fed back to the development team.

[0009] The security protection method provided in this invention allows the operations or security team to directly obtain the source code from the development team and perform static analysis to identify vulnerabilities, or directly obtain the development records during the development process. This enables the operations or security team to participate jointly during the source code development phase, thereby achieving collaborative vulnerability protection between the operations or security team and the development team during the development phase. In this embodiment, after determining that the source code in the development phase is free of vulnerabilities, it is sent to the operations team for project deployment, and information about the deployment process is received from the operations team. This enables the joint participation and collaboration between the operations or security team and the corresponding team on the operations team during the project deployment phase. Furthermore, since the operations or security team can perform anomaly scoring on the target content in real time after successful deployment, it can monitor abnormal behavior during the runtime phase after project deployment. This ensures protection against anomalies at different stages of the software development lifecycle and provides a foundation for the development team to update security measures in the source code based on actual usage, thereby gradually increasing the security protection capabilities of the project afterward. The entire process described above solves the problem of isolated operations between the development team, testing team, and operations or security team, which leads to security vulnerabilities. It ensures that other teams can directly interact and collaborate with the operations or security team, and that the security team ultimately feeds back the results to the development team to refine the source code, thereby improving the overall project's security protection capabilities against vulnerabilities throughout the entire project lifecycle.

[0010] Secondly, embodiments of the present invention also provide a safety protection device, the device comprising:

[0011] The parsing module is used to obtain source code from the development side, determine the parsing type based on the development technology of the source code, and parse the source code according to the parsing type to obtain vulnerability results.

[0012] The deployment module is used to send the source code and the corresponding policy file to the operations team when the vulnerability result is no vulnerability, so that the operations team can deploy according to the source code and the policy file.

[0013] The protection module is used to determine the target content based on the real-time request after receiving the deployment success information sent by the operation side, to score the target content for anomalies, to determine the security protection strategy for the real-time request based on the anomaly score, and to feed the security protection strategy back to the development side.

[0014] Thirdly, embodiments of the present invention also provide an electronic device, the electronic device comprising:

[0015] At least one processor; and

[0016] A memory that is communicatively connected to at least one processor; wherein,

[0017] The memory stores a computer program that can be executed by at least one processor, such that the at least one processor is able to perform the security protection method of any embodiment of the present invention.

[0018] Fourthly, embodiments of the present invention also provide a computer-readable storage medium storing computer instructions that are used to cause a processor to execute and implement the security protection method of any embodiment of the present invention.

[0019] Fifthly, embodiments of the present invention also provide a computer program product, including a computer program that, when executed by a processor, implements the security protection method of any embodiment of the present invention.

[0020] It should be noted that the aforementioned computer instructions may be stored, in whole or in part, on a computer-readable storage medium. This computer-readable storage medium may be packaged together with the processor of the security protection device, or it may be packaged separately from the processor of the security protection device; this application does not impose any limitations on this.

[0021] The descriptions of the second, third, fourth, and fifth aspects in this application can be referred to the detailed description of the first aspect; and the beneficial effects of the descriptions of the second, third, fourth, and fifth aspects can be referred to the analysis of the beneficial effects of the first aspect, which will not be repeated here.

[0022] In this application, the names of the aforementioned safety protection devices do not limit the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those in this application, they fall within the scope of the claims of this application and their equivalents.

[0023] These or other aspects of this application will become more readily apparent in the following description. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 A schematic flowchart illustrating a security protection method provided in an embodiment of the present invention;

[0026] Figure 2 A flowchart illustrating another security protection method provided in an embodiment of the present invention;

[0027] Figure 3 This is a schematic diagram of the structure of a safety protection device provided in an embodiment of the present invention;

[0028] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0029] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.

[0030] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0031] The terms “historical” and “current” in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.

[0032] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0033] Before discussing the exemplary embodiments in more detail, it should be noted that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe the operations (or steps) as sequential processes, many of these operations can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the operations can be rearranged. The process can be terminated when its operation is completed, but may also have additional steps not included in the figures. The process can correspond to a method, function, procedure, subroutine, subroutine, etc. Moreover, without conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.

[0034] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0035] In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0036] Figure 1 This is a flowchart illustrating a security protection method provided by an embodiment of the present invention. This embodiment is applicable to situations where security protection is implemented throughout the entire software development lifecycle in an actual development model. The method can be executed by a security protection device, which can be implemented using software and / or hardware. In this embodiment, the security protection device is located in an electronic device, which can be a computer or server belonging to the operations and maintenance or security team; optionally, it is primarily implemented by the security team. The method specifically includes the following steps:

[0037] S101. Obtain the source code from the development side, determine the parsing type based on the development technology of the source code, and parse the source code according to the parsing type to obtain the vulnerability result.

[0038] In this embodiment, the development end refers to the electronic device belonging to the development team that created the source code. The source code is the source code of a web project. The development technology refers to the technology used to develop the project on a web server; in this embodiment, the development technology can be Hypertext Markup Language (HTML), JavaScript, or a server-side scripting language. The parsing type refers to the parsing method used to parse the source code.

[0039] Specifically, before submitting the project source code, the development team can send it to the operations or security team. The operations or security team will then perform static analysis on the source code, determining the parsing type based on the development technology and analyzing the source code accordingly to obtain the vulnerability results. In one implementation, if a vulnerability exists in the source code, the operations or security team can report it to the development team so they can correct the source code. In another implementation, if the source code no longer has vulnerabilities, then step S102 can be executed. Optionally, development records can be obtained from the development team, which contain data from debugging and vulnerability scanning of the code.

[0040] In this embodiment, the operations or security team can directly obtain the source code of the development team and perform static analysis to identify vulnerabilities, or directly obtain the development records of the development team during the development period. This enables the joint participation of the operations or security team in the source code development stage, thereby achieving collaborative vulnerability protection between the operations or security team and the development team during the source code development stage.

[0041] S102. When the vulnerability result is no vulnerability, send the source code and the corresponding policy file to the operations side so that the operations side can deploy according to the source code and the policy file.

[0042] In this embodiment, the vulnerability result can be either "vulnerable" or "no vulnerability". The "operation end" mainly refers to one end of the electronic equipment belonging to the operations and maintenance team; in this embodiment, the source code development phase is the responsibility of the development team (development end), and the deployment and operation phase is the responsibility of the operations and maintenance team (operation end) within the testing team / operations and maintenance or security team. The steps described in this embodiment are primarily executed by the security team within the operations and maintenance or security team. The policy file is a policy rule file that the project content developed based on the source code must adhere to.

[0043] Specifically, if the vulnerability result is "no vulnerability found," it means that the source code has passed vulnerability detection. Therefore, it can be further utilized for deployment in web projects. Consequently, the security team can directly send the source code and the policy files configured for the source code to the operations team, so that the operations team can deploy the policy files into the application during deployment.

[0044] S103. After receiving the deployment success message from the operations side, determine the target content based on the real-time request, score the target content for anomalies, determine the security protection strategy for the real-time request based on the anomaly score, and feed the security protection strategy back to the development side.

[0045] In this context, a real-time request refers to a Hypertext Transfer Protocol (HTTP) message received in real-time by the operations or security team. The target content in this embodiment primarily refers to anomalous content intended to bypass security restrictions, steal data, or damage the system for illegal purposes. The anomaly score is the total score of the target content within the real-time request, determined based on different target contents, and is used to characterize the degree of anomalousness of the real-time request.

[0046] Specifically, upon receiving a deployment success message from the operations team, users can log in to the developed project website via HTTP. However, in practice, to prevent users from attacking the project website or performing abnormal operations, the operations or security team needs to monitor HTTP requests for anomalies in real time. Therefore, anomalies in real-time requests can be identified, and these anomalies can be scored. Based on the score, it can be determined whether the real-time request needs to be blocked. Whether to block real-time requests constitutes the primary security protection strategy. Optionally, security protection strategies can also include restricting different permissions after login. Furthermore, after determining the security protection strategy, it can be fed back to the development team, allowing them to incorporate more security requirements into the source code based on anomalies encountered during actual use, thereby increasing the project's security capabilities.

[0047] In this embodiment, after confirming that the source code is free of vulnerabilities during the development phase, it is sent to the operations team for project deployment. The system receives information about the deployment process from the operations team, enabling joint participation and collaboration between the operations or security team and the corresponding operations team during the project deployment phase. Simultaneously, since the operations or security team can perform real-time anomaly scoring on the target content after successful deployment, it can monitor abnormal behavior during the runtime phase after project deployment. This ensures protection against anomalies at different stages of the software development lifecycle and provides a foundation for the development team to update security measures in the source code based on actual usage, thereby gradually increasing the project's security protection capabilities. The entire process achieves three-way collaborative interaction between the development team and the operations or security team, the operations team and the operations or security team, and the operations or security team and the development team. This solves the problem of isolated operations between the development team, testing team, and operations or security team, which can lead to security vulnerabilities. It ensures that other teams directly interact and collaborate with the operations or security team, and ultimately, the security team feeds back the results to the development team to refine the source code, improving the overall project's security protection capabilities throughout the entire lifecycle.

[0048] The security protection method provided in this invention allows the operations or security team to directly obtain the source code from the development team and perform static analysis to identify vulnerabilities, or directly obtain the development records during the development process. This enables the operations or security team to participate jointly during the source code development phase, thereby achieving collaborative vulnerability protection between the operations or security team and the development team during the development phase. In this embodiment, after determining that the source code in the development phase is free of vulnerabilities, it is sent to the operations team for project deployment, and information about the deployment process is received from the operations team. This enables the joint participation and collaboration between the operations or security team and the corresponding team on the operations team during the project deployment phase. Furthermore, since the operations or security team can perform anomaly scoring on the target content in real time after successful deployment, it can monitor abnormal behavior during the runtime phase after project deployment. This ensures protection against anomalies at different stages of the software development lifecycle and provides a foundation for the development team to update security measures in the source code based on actual usage, thereby gradually increasing the security protection capabilities of the project afterward. The entire process described above solves the problem of isolated operations between the development team, testing team, and operations or security team, which leads to security vulnerabilities. It ensures that other teams can directly interact and collaborate with the operations or security team, and that the security team ultimately feeds back the results to the development team to refine the source code, thereby improving the overall project's security protection capabilities against vulnerabilities throughout the entire project lifecycle.

[0049] Figure 2 This is a flowchart illustrating another security protection method provided by an embodiment of the present invention. This embodiment specifies the steps of obtaining vulnerability results, determining security protection strategies, and other optional steps based on the above embodiments. In this embodiment, the method specifically includes:

[0050] S201. Obtain the source code from the development side.

[0051] Specifically, before submitting the project code, the development team on the development side can obtain the source code from the development side for automatic scanning and parsing processes such as S202-S203. Optionally, in this embodiment, in addition to obtaining the source code from the development side, the development records of the development side during the source code development process can also be obtained to archive the security protection actions performed by the development side during development, so as to synchronize the entire program later.

[0052] S202. Determine the development language corresponding to the source code based on the development technology of the source code, and determine the parsing type based on the development language.

[0053] Specifically, since different development technologies correspond to different development languages, the development language of the source code can be determined based on its development technology. For example, it can be determined whether the source code is a markup language, a scripting language, or a general-purpose server-side programming language. Furthermore, the parsing type can be determined based on the development language. For instance, if it is a markup language, the parsing type can be determined to be a nested structure type with low syntactic complexity; if it is a scripting language, the parsing type can be determined to be a type with syntactic complexity including expressions, statements, functions, scope, dynamic typing, etc.; if it is a general-purpose server-side programming language, the parsing type can be determined to be a type containing complex type systems, class / module definitions, strict scope rules, etc.

[0054] S203. Determine the parsing target based on the parsing type, and use the parsing target to parse the source code to obtain the vulnerability result.

[0055] Specifically, the parsing target can be determined based on the parsing type. For example, if the parsing type is a nested structure type with low syntactic complexity, a syntax tree such as a document object model tree can be used as the parsing target. If the parsing type has syntactic complexity including expressions, statements, functions, scope, dynamic typing, etc., or contains complex type systems, class / module definitions, strict scope rules, etc., a syntax tree such as an abstract syntax tree can be used as the parsing target. Furthermore, by using the parsing target to parse the source code, potential vulnerability patterns can be identified, i.e., vulnerability results can be obtained.

[0056] In this embodiment, the operations or security team performs vulnerability detection on the source code developed on the development side. This solves the problem that current security detection methods for development applications are only applicable to the development stage and lack full lifecycle protection capabilities. It enables the operations or security team to directly scan and analyze the source code, ensuring the security performance of the source code during the development stage.

[0057] S204. When the vulnerability result indicates that a vulnerability exists, send the vulnerability result containing vulnerability information to the development team so that the development team can fix the vulnerability in the source code.

[0058] Specifically, when the vulnerability result indicates that a vulnerability exists, the vulnerability data is recorded, and the vulnerability result carrying vulnerability information is fed back to the development team so that the development team can fix the vulnerability in the source code.

[0059] S205: Receive the source code repaired by the development team; return to execute S202.

[0060] Specifically, the development team repairs the source code based on the vulnerability data and returns the repaired source code to the operations or security team. The repaired source code is then used as the source code to execute S202. This process continues until the vulnerability result is determined to be vulnerability-free, at which point S206 can be executed.

[0061] This embodiment addresses the problem in existing technologies where the development team only analyzes the source code to identify vulnerabilities and submits the project directly after confirming its absence, resulting in complete isolation from the work of the testing, operations, or security teams. It achieves collaborative interaction between the operations or security team and the development team. Furthermore, since most current security products only operate during the development phase (e.g., code auditing tools) or the runtime phase (e.g., web application firewalls), these tools suffer from heavy rule dependencies, poor adaptability, and a lack of full lifecycle collaborative protection capabilities. Consequently, the source code developed by the development team often lacks sufficient security protection. Therefore, this embodiment establishes security information synchronization between the operations or security team and the development team, providing more comprehensive and accurate guidance for adjusting the security protection functions in the source code based on actual conditions.

[0062] S206. When the vulnerability result is no vulnerability, obtain the application requirements and application framework sent by the operation side, and determine the target strategy based on the target configuration, application requirements and application framework in the source code.

[0063] Application requirements are the needs for using the project's product, defined during the project development phase based on actual conditions and development requirements. These requirements may include business needs, performance requirements, or compatibility requirements. The application framework is the framework corresponding to the architecture that the final project needs to deploy. Target configuration refers to the configuration information written in the configuration files within the source code.

[0064] Specifically, during the project development phase, the developer (i.e., the user actually developing the project) specifies the application requirements and selects a suitable application framework based on the application itself. These requirements and framework are then temporarily handed over to the operations team. If the vulnerability test results show no vulnerabilities, the application requirements and framework can be obtained from the operations team. Further, the target strategy can be determined based on the target configuration, application requirements, and application framework in the source code. For example, the source code is checked to see if any relevant configurations already exist, avoiding duplication or conflicts; the strategy content is determined: specific rules for the strategy are formulated based on the application requirements; and the configuration method is selected: an appropriate method is chosen based on the application architecture (framework, server, cloud service). Ultimately, based on these factors, the target strategy can be determined.

[0065] Optionally, standard security headers such as Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, and X-Content-Type-Options can also be included as information in the target policy. It is worth noting that the standard security headers used in this embodiment all comply with open-source licenses and are all legally and compliantly obtained from open-source sources.

[0066] S207. Generate the policy file corresponding to the source code based on the target policy.

[0067] Specifically, based on the above target strategy, the strategy file corresponding to the source code can be directly output. For example, a server can generate a middleware configuration file, an embedded web server can generate an application metadata file, or in a cloud-native environment, an infrastructure-as-code can be generated.

[0068] S208. Send the source code and the corresponding policy file to the operations team so that the operations team can deploy the system based on the source code and the policy file.

[0069] Specifically, source code and policy files can be sent directly to the operations team. The operations team can then automatically inject the HTTP response header policy file based on the source code and policy file to implement mechanisms such as page script origination, nesting restrictions, and mandatory HTTPS access by browsers. Ultimately, the operations team can successfully deploy the project.

[0070] Optionally, if a deployment failure message is received from the operations team, the operations or security team will send the deployment failure message to the development team so that the development team can check the source code. At the same time, the team will issue instructions to the operations team to check whether there are any anomalies in the infrastructure and network. Then, the team will receive the inspection results from the development team and the operations team respectively, formulate a repair plan based on the inspection results, and feed the repair plan back to both parties, and then re-execute the steps to determine the target strategy.

[0071] In this embodiment, by interacting with the operations team, collaboration can be achieved during the project deployment process, enabling timely monitoring of the deployment progress. Simultaneously, the security team determines the target strategy and delivers it to the operations team for deployment, allowing both parties to agree on the deployment strategy and providing a basis for subsequent feedback to the development team.

[0072] S209. After receiving the deployment success message from the operator, analyze the real-time request using input validation technology to obtain the target content.

[0073] Input validation technology is used to identify abnormal content in real-time requests. In this embodiment, input validation technology can include regular expression recognition, parameter length analysis, and keyword whitelisting. The target content is abnormal content in the real-time request.

[0074] Specifically, once the deployment success message is sent from the operations side, it can be confirmed that the project can be presented to users in the form of a webpage. In practice, users can then log in to the webpage in real-time to perform the necessary operations and achieve their desired goals. The operations or security team will then verify the real-time requests from different users to determine if they pose a threat and whether they need to be blocked. Therefore, for each real-time request, input validation technology is used to analyze the request and identify component strings of attack payloads or probe fingerprints, such as true / false conditions, abnormal script tags, or abnormal parent directories. These identified elements can then be used as target content.

[0075] S210. Input the target content into the anomaly scoring model to obtain the anomaly score corresponding to the target content.

[0076] The anomaly scoring model is used to assign weighted scores to all target content in a real-time request and obtain a total score that can characterize the degree of anomaly of the real-time request.

[0077] Specifically, taking all target content in a real-time request as input, the anomaly scoring model assigns corresponding weights to different target content based on the request attributes of the real-time request. It then calculates an individual score for each target content based on its proportion and weight within the real-time request. Finally, the anomaly score for each target content is obtained by summing all individual scores. In other words, the anomaly scoring model ultimately outputs the total anomaly score for all target content.

[0078] Optionally, the request attributes of a real-time request include: request time, request source, and related requests (those with the same request source, request time, or other similar attributes as the real-time request, used to determine whether a denial-of-service attack exists). The proportion of each target content in the real-time request can be either the proportion of character count or the proportion of importance.

[0079] S211. If the anomaly score does not exceed the anomaly score threshold, the security protection strategy for the real-time request shall be determined based on the amount of target content in the real-time request.

[0080] Specifically, if the anomaly score does not exceed the anomaly score threshold, it indicates that the target content in the real-time request may pose few security problems. Therefore, the security protection strategy for the real-time request can be further determined based on the amount of target content in the real-time request.

[0081] For example, determining the security protection strategy for a real-time request based on the amount of target content in the real-time request includes:

[0082] (i) If the number of target contents in a real-time request exceeds the preset number, the security protection strategy for the real-time request is determined to be to block the real-time request.

[0083] Specifically, if the amount of target content in a real-time request exceeds a preset limit, the real-time request can be blocked for security reasons.

[0084] (ii) If the number of target contents in a real-time request does not exceed the preset number, the security protection strategy for the real-time request is determined to be not to block the real-time request.

[0085] Specifically, if the amount of target content in a real-time request does not exceed the preset number, it can be determined directly that the real-time request does not need to be intercepted.

[0086] S212. If the abnormal score exceeds the abnormal score threshold, the security protection strategy for real-time requests is determined to be to block real-time requests.

[0087] Specifically, if the anomaly score exceeds the anomaly score threshold, it can be directly determined that there is a security problem with the real-time request, and therefore, the real-time request can be directly intercepted.

[0088] In this embodiment, the main focus is on determining the overall situation of abnormal content in real-time requests. When an anomaly is determined, the real-time request is directly intercepted, thus achieving security protection. When it is determined that the anomaly score does not exceed the anomaly score threshold, in order to further prevent attackers from successfully exploiting the number of abnormal content, the number of abnormal content can be further determined. This ensures the comprehensiveness and accuracy of anomaly detection of real-time requests from different angles, thereby improving security protection measures.

[0089] S213. Send the security protection policy carrying the real-time request, target content and anomaly score to the development end so that the development end can perform security updates to the source code.

[0090] Specifically, regardless of whether S211 or S212 has been executed, this step can be continued, which involves sending the security protection policy carrying the real-time request, target content, and anomaly score to the development team. In this way, the development team can continuously learn about the latest attack methods based on the target content and anomaly score in the real-time request, and update the source code accordingly to ensure the security of the entire project.

[0091] In this embodiment, not only can real-time requests be detected and intercepted during project runtime to ensure runtime security, but also recent security issues can be reported to the development team in real time, so that the development team can update the source code in a timely manner based on recent security issues, thereby enhancing the project's ability to protect against abnormal attacks.

[0092] Optionally, after determining the security protection strategy for real-time requests based on anomaly scores, the following further applies:

[0093] The system acquires real-time user operation data and inputs it into a normal behavior model to obtain user operation risk results. Based on these results, it determines a tiered response strategy for user access.

[0094] Real-time operation data refers to the user's actions after logging into the webpage, such as user operation paths, request frequency, and parameter patterns. The normal behavior model determines whether the user's actions after successfully logging in based on a real-time request are normal; its input is the real-time operation data, and its output is the user's operation risk result. The tiered response strategy is a policy of imposing different levels of access restrictions on user operations based on the user's risk level.

[0095] Specifically, after a real-time request is passed without being intercepted, the operations or security team can collect the user's real-time operation data and input it into a normal behavior model to determine the corresponding operational risk outcome. The operational risk outcome can correspond to a tiered response strategy; for example, if there are n corresponding tiered response strategies, then there can also be n possible operational risk outcomes.

[0096] For example, the tiered response strategy includes a Level 1 response strategy (forcing users to log out), a Level 2 response strategy (users can only browse pages but cannot perform any actual operations), a Level 3 response strategy (users can only perform operations on some preset pages), a Level 4 response strategy (limiting the number of user requests), and a Level 5 response strategy (no restrictions). Correspondingly, the operational risk outcome can be categorized as: Level 1 dangerous, relatively dangerous, dangerous, exhibiting abnormal operational behavior, and normal.

[0097] In this embodiment, even if the real-time request is approved, the user's real-time operation data can continue to be monitored to prevent the user from engaging in potentially security-critical actions, thereby further enhancing security protection capabilities.

[0098] It is worth noting that the "real-time operation data monitored by users" in this embodiment refers to operation data related to security protection that is legally and compliantly obtained and is not user privacy information, and is ultimately used only to determine operational risks. The information collected is authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, necessary confidentiality measures have been taken, and it does not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.

[0099] Optionally, the normal behavior model in this embodiment can be constructed based on historically collected information such as user operation paths, request frequencies, and parameter patterns. Furthermore, during actual use after successful construction, the normal behavior model can be corrected based on emerging attacks and human feedback to improve subsequent recognition rates.

[0100] Optionally, in this embodiment, the operations or security team can also display interception logs, scan reports, security trend charts, etc. in a graphical manner, while providing an export function to support integration with platforms such as security event management and auditing.

[0101] The above embodiments are intended to address the following shortcomings of existing technologies: (1) fragmented protection phases, with security capabilities limited to a single phase such as development or operation, making it impossible to achieve collaborative protection throughout the application lifecycle; (2) excessive rule dependence, relying on manually preset rules, making it difficult to effectively address zero-day vulnerabilities, attack variants, and highly customized business logic; (3) high false positives and false negatives, with insufficient generalization ability of the rule base, easily misjudging normal traffic as attacks and failing to identify all real threats, increasing the operational burden; (4) lack of intelligent evolution, making it impossible to achieve automated and intelligent continuous optimization of security strategies. In the above embodiments, based on the same execution end (such as the operations or security team), it can collaborate with other ends (such as the development end and the operations end) to achieve security protection through code scanning, deployment injection, runtime defense, and behavioral risk determination, forming a complete protection closed loop. An anomaly scoring model scores the target content in real-time requests, dynamically adjusting the weight of anomalous content based on the request attributes to arrive at a more accurate anomaly score. Simultaneously, the quantity of anomalous content further determines whether the real-time request is indeed anomaly, achieving a secondary assessment and reducing the probability of false positives. Furthermore, automated judgment reduces operational burden. A normal behavior model determines the risk of user actions, and by receiving more real-time operation data to adjust the normal behavior model, the model's accuracy is continuously improved while automatically identifying operational risks, enhancing security protection capabilities. Therefore, the above embodiments also enable automated and intelligent continuous optimization of security policies.

[0102] Figure 3 This is a schematic diagram of the structure of a safety protection device provided in an embodiment of the present invention, as shown below. Figure 3 As shown, the device includes:

[0103] The parsing module 301 is used to obtain source code from the development side, determine the parsing type based on the development technology of the source code, and parse the source code according to the parsing type to obtain vulnerability results.

[0104] Deployment module 302 is used to send the source code and the corresponding policy file to the operations side when the vulnerability result is no vulnerability, so that the operations side can deploy according to the source code and the policy file.

[0105] The protection module 303 is used to determine the target content based on the real-time request after receiving the deployment success information sent by the operation end, to score the anomaly of the target content, to determine the security protection strategy for the real-time request based on the anomaly score, and to feed the security protection strategy back to the development end.

[0106] Based on the above embodiments, the parsing module 301 is specifically used for:

[0107] The development language corresponding to the source code is determined based on the development technology of the source code, and the parsing type is determined based on the development language; the parsing target is determined based on the parsing type, and the source code is parsed using the parsing target to obtain the vulnerability results.

[0108] Based on the above embodiments, after obtaining the vulnerability result, the parsing module 301 is further used for:

[0109] When the vulnerability result indicates that a vulnerability exists, a vulnerability result carrying vulnerability information is sent to the development end so that the development end can fix the vulnerability in the source code; after receiving the fixed source code from the development end, the process returns to the step of determining the parsing type based on the development technology of the source code.

[0110] Based on the above embodiments, before sending the source code and the corresponding policy file to the operation end, the deployment module 302 is further configured to:

[0111] Obtain the application requirements and application framework sent by the operations team, and determine the target strategy based on the target configuration, application requirements and application framework in the source code; generate the corresponding strategy file in the source code based on the target strategy.

[0112] Based on the above embodiments, the protection module 303 is specifically used for:

[0113] Input validation technology is used to analyze real-time requests to obtain the target content;

[0114] The target content is input into the anomaly scoring model to obtain the anomaly score corresponding to the target content. If the anomaly score exceeds the anomaly score threshold, the security protection strategy for real-time requests is determined to be to block real-time requests. If the anomaly score does not exceed the anomaly score threshold, the security protection strategy for real-time requests is determined based on the amount of target content in the real-time request.

[0115] Based on the above embodiments, the security protection strategy for the real-time request is determined according to the amount of target content in the real-time request. The protection module 303 is specifically used for:

[0116] If the number of target contents in a real-time request exceeds a preset number, the security protection policy for the real-time request is determined to be to block the real-time request; if the number of target contents in a real-time request does not exceed the preset number, the security protection policy for the real-time request is determined to be to not block the real-time request.

[0117] The security protection strategy is fed back to the development team. Protection module 303 is specifically used for:

[0118] The security protection policy, which includes real-time requests, target content, and anomaly scores, is sent to the development team so that the development team can perform security updates to the source code.

[0119] Based on the above embodiments, after determining the security protection strategy for real-time requests according to the anomaly score, the protection module 303 is further configured to:

[0120] The system acquires real-time user operation data and inputs it into a normal behavior model to obtain user operation risk results. Based on these results, it determines a tiered response strategy for user access.

[0121] The safety protection device provided in the embodiments of the present invention can execute the safety protection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method.

[0122] It is worth noting that in the embodiments of the above-mentioned safety protection device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.

[0123] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Figure 4 A block diagram is shown of an exemplary electronic device 11 suitable for implementing embodiments of the present invention. Figure 4 The electronic device 11 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.

[0124] like Figure 4 As shown, the electronic device 11 is represented in the form of a general-purpose computing electronic device. The components of the electronic device 11 may include, but are not limited to: one or more processors or processing units 16, system memory 28, and bus 18 connecting different system components (including system memory 28 and processing unit 16).

[0125] Bus 18 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0126] Electronic device 11 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 11, including volatile and non-volatile media, removable and non-removable media.

[0127] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Electronic device 11 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media (… Figure 4 Not shown; usually referred to as a "hard drive"). Although Figure 4 As not shown, disk drives for reading and writing to removable non-volatile disks (e.g., "floppy disks") and optical disc drives for reading and writing to removable non-volatile optical discs (e.g., CD-ROMs, DVD-ROMs, or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. System memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.

[0128] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in system memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 42 typically perform the functions and / or methods described in the embodiments of the present invention.

[0129] Electronic device 11 can also communicate with one or more external devices 14 (e.g., keyboard, pointing device, display 24, etc.), and with one or more devices that enable a user to interact with electronic device 11, and / or with any device that enables electronic device 11 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed via input / output (I / O) interface 22. Furthermore, electronic device 11 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 20. Figure 4 As shown, network adapter 20 communicates with other modules of electronic device 11 via bus 18. It should be understood that, although... Figure 4 As not shown, other hardware and / or software modules may be used in conjunction with electronic device 11, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0130] The processing unit 16 executes various functional applications and page displays by running programs stored in the system memory 28, such as implementing the security protection method provided in this embodiment. Of course, those skilled in the art will understand that the processor can also implement the technical solutions of the security protection methods provided in any embodiment of this invention.

[0131] This invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements, for example, the security protection method provided in this invention. The computer storage medium of this invention can be any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. For example, a computer-readable storage medium can be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0132] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.

[0133] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0134] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the security protection method provided in any embodiment of this invention.

[0135] Computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0136] Those skilled in the art will understand that the modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby allowing them to be stored in a storage device for execution by a computing device, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.

[0137] Furthermore, the acquisition, storage, use, and processing of data in the technical solution of this invention all comply with the relevant provisions of national laws and regulations.

[0138] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A security protection method, characterized in that, The method includes: Obtain source code from the development side, determine the parsing type based on the development technology of the source code, and parse the source code according to the parsing type to obtain vulnerability results; When the vulnerability result is no vulnerability, the source code and the corresponding policy file are sent to the operation terminal so that the operation terminal can deploy according to the source code and the policy file. After receiving the deployment success message from the operations side, the target content is determined based on the real-time request, the target content is scored for anomalies, and a security protection strategy for the real-time request is determined based on the anomaly score. The security protection strategy is then fed back to the development side.

2. The method according to claim 1, characterized in that, The step of determining the parsing type based on the development technology of the source code, and parsing the source code according to the parsing type to obtain the vulnerability result includes: The development language corresponding to the source code is determined based on the development technology of the source code, and the parsing type is determined based on the development language; The parsing target is determined based on the parsing type, and the source code is parsed using the parsing target to obtain the vulnerability result.

3. The method according to claim 1, characterized in that, After obtaining the vulnerability results, the following is also included: When the vulnerability result indicates that a vulnerability exists, a vulnerability result carrying vulnerability information is sent to the development end so that the development end can fix the vulnerability in the source code; Receive the source code repaired by the development team, and return to the step of determining the parsing type based on the development technology of the source code.

4. The method according to claim 1, characterized in that, Before sending the source code and the corresponding policy file to the operations team, the process also includes: Obtain the application requirements and application framework sent by the operation terminal, and determine the target strategy based on the target configuration in the source code, the application requirements, and the application framework; Generate a strategy file corresponding to the source code based on the target strategy.

5. The method according to claim 1, characterized in that, The step of determining the target content based on the real-time request, performing anomaly scoring on the target content, and determining a security protection strategy for the real-time request based on the anomaly score includes: The real-time request is analyzed using input validation technology to obtain the target content; The target content is input into the anomaly scoring model to obtain the anomaly score corresponding to the target content; If the abnormal score exceeds the abnormal score threshold, then the security protection strategy for the real-time request is determined to be to block the real-time request. If the anomaly score does not exceed the anomaly score threshold, then the security protection strategy for the real-time request is determined based on the amount of target content in the real-time request.

6. The method according to claim 5, characterized in that, The step of determining the security protection strategy for the real-time request based on the amount of target content in the real-time request includes: If the number of target contents in the real-time request exceeds a preset number, then the security protection strategy for the real-time request is determined to be to block the real-time request. If the number of target contents in the real-time request does not exceed the preset number, then the security protection strategy for the real-time request is determined to be not to block the real-time request. The step of feeding back the security protection strategy to the development end includes: The security protection policy, which carries the real-time request, the target content, and the anomaly score, is sent to the development end so that the development end can perform a security update on the source code.

7. The method according to claim 5, characterized in that, After determining the security protection strategy for the real-time request based on the anomaly score, the method further includes: The system acquires real-time user operation data and inputs it into a normal behavior model to obtain the user's operation risk result. Based on the operation risk result, it determines a tiered response strategy for user access.

8. A safety protection device, characterized in that, The device includes: The parsing module is used to obtain source code from the development side, determine the parsing type based on the development technology of the source code, and parse the source code according to the parsing type to obtain vulnerability results; The deployment module is used to send the source code and the corresponding policy file to the operation terminal when the vulnerability result is no vulnerability, so that the operation terminal can deploy according to the source code and the policy file. The protection module is used to determine the target content based on the real-time request after receiving the deployment success information sent by the operation terminal, perform anomaly scoring on the target content, determine the security protection strategy for the real-time request based on the anomaly score, and feed the security protection strategy back to the development terminal.

9. An electronic device, characterized in that, include: One or more processors; Memory, used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the security protection method as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the security protection method as described in any one of claims 1 to 7.

11. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the security protection method as described in any one of claims 1 to 7.