Methods, devices, and equipment for preventing Redis injection in application systems
Patent Information
- Application Number
- CN202610965207.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-30
- Publication Date
- 2026-09-01
AI Technical Summary
[0003]具体的,存在问题:(1)安全防护薄弱:大多数应用系统未对Redis操作进行安全校验,开发人员缺乏专业防护知识,代码中存在明显的注入漏洞;(2)防护手段不全面:即便有防护措施的系统,也往往只针对某一种攻击方式(如命令分隔符),未覆盖Lua脚本注入、配置篡改、键名污染等多种攻击场景;(3)缺乏标准化与复用性:各系统独立实现防护逻辑,重复建设严重,且防护策略不一致,难以维护和升级;(4)扩展性与灵活性不足:现有方案难以根据业务场景灵活调整校验策略,无法平衡安全性与系统性能
[0016]本申请实施例提供的技术方案带来的有益效果包括:
Smart Images

Figure CN122674036A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of databases, specifically to a method, apparatus, and device for preventing Redis injection in application systems. Background Technology
[0002] With the widespread use of Redis (an open-source, in-memory, key-value NoSQL database) as a high-performance key-value database in various application systems, its security issues have become increasingly prominent. Redis injection attacks refer to attackers constructing malicious input to influence Redis command execution logic or obtain sensitive data. Common attack methods include command separator injection, Lua script injection, and configuration keyword tampering. Currently, most application systems have significant shortcomings in Redis operation security protection.
[0003] Specifically, the problems are as follows: (1) Weak security protection: Most application systems do not perform security verification on Redis operations, developers lack professional protection knowledge, and there are obvious injection vulnerabilities in the code; (2) Incomplete protection measures: Even systems with protection measures often only target one type of attack (such as command separators) and do not cover multiple attack scenarios such as Lua script injection, configuration tampering, and key name pollution; (3) Lack of standardization and reusability: Each system implements protection logic independently, resulting in serious duplication of construction and inconsistent protection strategies, making it difficult to maintain and upgrade; (4) Insufficient scalability and flexibility: Existing solutions are difficult to flexibly adjust verification strategies according to business scenarios and cannot balance security and system performance.
[0004] Therefore, how to effectively prevent Redis injection in application systems has become an urgent problem to be solved. Summary of the Invention
[0005] This application provides a method, apparatus, and device for preventing Redis injection in application systems. Through multiple security verification mechanisms and flexible configuration strategies, it provides a ready-to-use, highly secure anti-Redis injection component that supports rapid integration and unified protection across various business systems.
[0006] In a first aspect, embodiments of this application provide a method for preventing Redis injection in an application system, the method comprising: An anti-Redis injection component is obtained by encapsulating the anti-Redis injection function based on the Spring Boot technology stack. The anti-Redis injection component includes preset verification and interception mechanisms. The system retrieves requests involving Redis operations and verifies and intercepts these requests using the anti-Redis injection component, thereby preventing Redis injection from affecting the application system.
[0007] In conjunction with the first aspect, in one implementation, the anti-Redis injection component, which encapsulates the anti-Redis injection functionality based on the Spring Boot technology stack, specifically includes: Based on the Spring Boot technology stack, the Redis injection prevention function is encapsulated as an independent component, resulting in the Redis injection prevention component; Package the anti-Redis injection component and upload it to a Maven private repository or central repository; The application system enables the Redis injection prevention function by importing the anti-Redis injection component through a dependency.
[0008] In conjunction with the first aspect, in one implementation, the verification and interception mechanism includes delimiter verification, Lua script verification, configuration keyword verification, and key name compliance verification.
[0009] In conjunction with the first aspect, in one implementation method, The separator verification involves identifying and verifying the separators in the input content. The Lua script validation is to identify and verify whether the input content contains Lua script keywords; The configuration keyword verification involves identifying and verifying whether the input content contains the keywords configParam and requirepass. The key name compliance check verifies whether the input key contains the keyword "pattern".
[0010] In conjunction with the first aspect, in one implementation, the process of obtaining requests involving Redis operations, and verifying and intercepting these requests through the anti-Redis injection component to prevent Redis injection in the application system, specifically includes: Intercept requests involving Redis operations and perform separator validation, Lua script validation, configuration keyword validation, and key name compliance validation in sequence; Based on the verification results: If any verification fails, the operation will be blocked and a security error message will be displayed. If all validations pass, the request will be forwarded to the business logic execution.
[0011] In conjunction with the first aspect, in one implementation, the interception of requests involving Redis operations specifically includes: Anti-Redis injection components use AOP aspects or interceptors to intercept requests involving Redis operations.
[0012] In conjunction with the first aspect, in one implementation method, the method for preventing Redis injection in an application system further includes: Conduct security testing and performance evaluation based on actual business scenarios, and optimize the verification rules in the verification and interception mechanisms.
[0013] In conjunction with the first aspect, in one implementation, the anti-Redis injection component also supports custom verification rules, whitelist configuration, and verification switch control.
[0014] Secondly, embodiments of this application provide an apparatus for preventing Redis injection in an application system, the apparatus comprising: The configuration module is used to encapsulate the anti-Redis injection function based on the Spring Boot technology stack to obtain an anti-Redis injection component, which includes preset verification and interception mechanisms; The execution module is used to obtain requests involving Redis operations, and to verify and intercept the obtained requests through the anti-Redis injection component to realize the anti-Redis injection of the application system.
[0015] Thirdly, embodiments of this application provide a device for preventing Redis injection in an application system. The device includes a processor, a memory, and a program for preventing Redis injection in an application system stored in the memory and executable by the processor. When the program for preventing Redis injection in an application system is executed by the processor, it implements the steps of the method for preventing Redis injection in an application system described above.
[0016] The beneficial effects of the technical solutions provided in this application include: Unified protection avoids redundant development: Standardized components provide comprehensive Redis injection protection, eliminating the need for repetitive development across business systems, thus improving development efficiency and security baseline. Multi-layered defense enhances security: Integrated multi-dimensional verification mechanisms comprehensively cover attack methods such as command injection, script injection, and configuration tampering, significantly improving the application system's resistance to attacks. Flexible and configurable with strong adaptability: Supports custom verification rules and strategy combination configurations, allowing for flexible adjustment of protection strength and performance overhead according to business needs. Zero-intrusive integration reduces access costs: Based on the Spring Boot ecosystem, integration is achieved through annotations or configuration without modifying business code, facilitating rapid deployment. Attached Figure Description
[0017] Figure 1 A flowchart illustrating the method for preventing Redis injection in the application system as described in this application; Figure 2 A diagram illustrating verification and interception; Figure 3A complete flowchart illustrating the method for preventing Redis injection in the application system as described in this application; Figure 4 A schematic diagram of the functional modules of the device for preventing Redis injection in the application system according to this application; Figure 5 This is a schematic diagram of the hardware structure of the device used to prevent Redis injection in the application system according to this application. Detailed Implementation
[0018] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.
[0019] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0020] In a first aspect, embodiments of this application provide a method for preventing Redis injection in application systems. Through multiple security verification mechanisms and flexible configuration strategies, a ready-to-use, highly secure anti-Redis injection component is achieved, supporting rapid integration and unified protection across various business systems.
[0021] In one embodiment, reference is made to Figure 1 , Figure 1 This is a flowchart illustrating the method for implementing Redis injection prevention in the application system according to this application. Figure 1 As shown, the methods for preventing Redis injection in application systems include: S1: Based on the Spring Boot technology stack, the anti-Redis injection function is encapsulated to obtain an anti-Redis injection component, which includes preset verification and interception mechanisms; S2: Obtain requests involving Redis operations, and verify and intercept the obtained requests through the anti-Redis injection component to achieve anti-Redis injection for the application system.
[0022] Furthermore, in one embodiment, an anti-Redis injection component is obtained by encapsulating the anti-Redis injection function based on the Spring Boot technology stack, specifically including: S101: Based on the SpringBoot (a rapid development scaffolding based on the Spring framework) technology stack, the anti-Redis injection function is encapsulated as an independent component, resulting in the anti-Redis injection component; S102: Package the anti-Redis injection component and upload it to a Maven private repository (local private repository server) or central repository; S103: The application system introduces the anti-Redis injection component through a dependency to enable the anti-Redis injection function.
[0023] Specifically, the process begins with component development. This can be done using Spring Boot to develop a Redis injection prevention component that integrates various validation and interception mechanisms. Then, the component is deployed by packaging the completed Redis injection prevention component and uploading it to a Maven private repository or central repository for use by various application systems. Finally, system integration is performed, with each application system importing the Redis injection prevention component as a dependency and enabling the protection function through annotations or configuration files.
[0024] Furthermore, in one embodiment, the verification and interception mechanism includes delimiter verification, Lua script verification, configuration keyword verification, and key name compliance verification.
[0025] Separator validation identifies and validates separators in the input content, including \r and \n separators; Lua script validation identifies and validates whether the input content contains Lua script keywords; configuration keyword validation identifies and validates whether the input content contains the keywords configParam (all dynamically modifiable configuration parameters in Redis) and requirepass (Redis global password authentication configuration item); key name compliance validation validates whether the input key (key name) contains the pattern (wildcard) keyword.
[0026] Furthermore, in one embodiment, see [reference needed]. Figure 2 As shown, requests involving Redis operations are obtained, and the anti-Redis injection component verifies and intercepts these requests to prevent Redis injection in the application system. Specifically, this includes: S201: Intercept requests involving Redis operations, and sequentially perform separator validation, Lua script validation, configuration keyword validation, and key name compliance validation; among them, intercepting requests involving Redis operations specifically includes: the anti-Redis injection component intercepts requests involving Redis operations through AOP (Aspect Oriented Programming) aspects or interceptors; S202: Based on the verification result: If any verification fails, the operation will be blocked and a security error message will be displayed. If all validations pass, the request will be forwarded to the business logic execution.
[0027] Specifically, when a user initiates a request involving Redis operations, the anti-Redis injection component intercepts it through AOP aspects or interceptors, performing multiple checks in sequence, including separator verification, Lua script verification, configuration keyword verification, and key name compliance verification. If any check fails, the operation is blocked and a security exception is displayed. If all checks pass, the request is forwarded to the business logic for execution.
[0028] Furthermore, in one embodiment, the method for preventing Redis injection in an application system according to this application further includes: conducting security testing and performance evaluation based on actual business scenarios, and optimizing the verification rules in the verification and interception mechanisms. That is, conducting security testing and performance evaluation based on actual business scenarios, and optimizing verification strategies and configuration parameters.
[0029] Furthermore, in one embodiment, the anti-Redis injection component of this application also supports custom verification rules, whitelist configuration, and verification switch control.
[0030] This application presents a method for preventing Redis injection in application systems, featuring a component-based design: based on the Spring Boot technology stack, the anti-Redis injection functionality is encapsulated as an independent component, supporting zero-code intrusion, annotation-based, or configuration-based integration; multiple verification mechanisms: integrating multi-dimensional security controls such as separator verification, Lua script verification, configuration keyword verification, and key name compliance verification; standardized protection rules: a built-in library of common Redis attack characteristics supports standardized protection strategies, ensuring consistent protection across application systems; and high scalability and flexible configuration: supporting custom verification rules, whitelist configuration, and verification switch control to adapt to the security and performance requirements of different business scenarios.
[0031] See Figure 3 The diagram shown is a complete flowchart of the method for implementing Redis injection prevention in application systems according to this application. Unified protection avoids redundant development: Standardized components provide comprehensive Redis injection protection, eliminating the need for repetitive development across business systems, thus improving development efficiency and security baseline. Multi-layered defense enhances security: Integrating multi-dimensional verification mechanisms comprehensively covers attack methods such as command injection, script injection, and configuration tampering, significantly improving the application system's resistance to attacks. Flexible and configurable with strong adaptability: Supports custom verification rules and strategy combination configurations, allowing for flexible adjustment of protection strength and performance overhead according to business needs. Zero-intrusive integration reduces access costs: Based on the Spring Boot ecosystem, integration is achieved through annotations or configuration without modifying business code, facilitating rapid deployment.
[0032] Secondly, embodiments of this application also provide a device for preventing Redis injection in application systems.
[0033] In one embodiment, reference is made to Figure 4, Figure 4 This is a schematic diagram of the functional modules of the device for preventing Redis injection in an application system, as described in this application. Figure 4 As shown, the device for preventing Redis injection in application systems includes: a configuration module and an execution module.
[0034] The configuration module is used to encapsulate the anti-Redis injection function based on the Spring Boot technology stack to obtain an anti-Redis injection component, which includes a preset verification and interception mechanism; the execution module is used to obtain requests involving Redis operations, and to verify and intercept the obtained requests through the anti-Redis injection component to realize the anti-Redis injection of the application system.
[0035] In this application, a Redis injection prevention component is encapsulated based on the Spring Boot technology stack to obtain the Redis injection prevention function, specifically including: Based on the Spring Boot technology stack, the Redis injection prevention function is encapsulated as an independent component, resulting in the Redis injection prevention component; Package the anti-Redis injection component and upload it to a Maven private repository or central repository; The application system enables the Redis injection prevention function by importing the anti-Redis injection component through a dependency.
[0036] Specifically, the process begins with component development. This can be done using Spring Boot to develop a Redis injection prevention component that integrates various validation and interception mechanisms. Then, the component is deployed by packaging the completed Redis injection prevention component and uploading it to a Maven private repository or central repository for use by various application systems. Finally, system integration is performed, with each application system importing the Redis injection prevention component as a dependency and enabling the protection function through annotations or configuration files.
[0037] In this application, the verification and interception mechanism includes delimiter verification, Lua script verification, configuration keyword verification, and key name compliance verification.
[0038] The separator verification involves identifying and verifying the separators in the input content. The Lua script validation is to identify and verify whether the input content contains Lua script keywords; The configuration keyword verification involves identifying and verifying whether the input content contains the keywords configParam and requirepass. The key name compliance check verifies whether the input key contains the keyword "pattern".
[0039] In this application, requests involving Redis operations are obtained, and the anti-Redis injection component is used to verify and intercept these requests, thereby preventing Redis injection in the application system. Specifically, this includes: Intercept requests involving Redis operations and perform separator validation, Lua script validation, configuration keyword validation, and key name compliance validation in sequence; Based on the verification results: If any verification fails, the operation will be blocked and a security error message will be displayed. If all validations pass, the request will be forwarded to the business logic execution.
[0040] Specifically, when a user initiates a request involving Redis operations, the anti-Redis injection component intercepts it through AOP aspects or interceptors, performing multiple checks in sequence, including separator verification, Lua script verification, configuration keyword verification, and key name compliance verification. If any check fails, the operation is blocked and a security exception is displayed. If all checks pass, the request is forwarded to the business logic for execution.
[0041] In this application, intercepting requests involving Redis operations specifically includes: the anti-Redis injection component intercepting requests involving Redis operations through AOP aspects or interceptors.
[0042] In this application, security testing and performance evaluation were conducted based on actual business scenarios to optimize the verification rules in the verification and interception mechanisms. The anti-Redis injection component also supports custom verification rules, whitelist configuration, and verification switch control.
[0043] Component-based design: Based on the Spring Boot technology stack, the anti-Redis injection functionality is encapsulated as an independent component, supporting zero-code intrusion, annotation-based, or configuration-based integration; Multi-layered verification mechanisms: Integrates multi-dimensional security controls such as separator verification, Lua script verification, configuration keyword verification, and key name compliance verification; Standardized protection rules: Built-in common Redis attack signature library, supporting standardized protection strategies to ensure consistent protection across application systems; High scalability and flexible configuration: Supports custom verification rules, whitelist configuration, verification switch control, etc., adapting to the security and performance requirements of different business scenarios.
[0044] Thirdly, embodiments of this application provide a device for preventing Redis injection in application systems. The device for preventing Redis injection in application systems can be a personal computer (PC), a laptop, a server, or other device with data processing capabilities.
[0045] Reference Figure 5 , Figure 5This is a schematic diagram of the hardware structure of a device for preventing Redis injection in an application system, as described in an embodiment of this application. In this embodiment, the device for preventing Redis injection in an application system may include a processor, memory, a communication interface, and a communication bus.
[0046] The communication bus can be of any type and is used to interconnect the processor, memory, and communication interface.
[0047] Communication interfaces include input / output (I / O) interfaces, physical interfaces, and logical interfaces used for interconnecting internal devices within the application system to prevent Redis injection attacks, as well as interfaces used for interconnecting the application system's Redis injection prevention device with other devices (such as other computing devices or user equipment). Physical interfaces can be Ethernet interfaces, fiber optic interfaces, ATM interfaces, etc.; user equipment can be displays, keyboards, etc.
[0048] Memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.
[0049] The processor can be a general-purpose processor, which can call a program stored in memory to implement Redis injection prevention for the application system and execute the method for implementing Redis injection prevention for the application system provided in the embodiments of this application. For example, the general-purpose processor can be a central processing unit (CPU). The method executed when the program for implementing Redis injection prevention for the application system is called can refer to the various embodiments of the method for implementing Redis injection prevention for the application system in this application, and will not be repeated here.
[0050] Those skilled in the art will understand that Figure 5 The hardware structure shown does not constitute a limitation of this application and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0051] The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus. The terms "first," "second," and "third," etc., are used to distinguish different objects, etc., and do not indicate a sequence, nor do they limit "first," "second," and "third" to different types.
[0052] In the description of the embodiments of this application, terms such as "exemplary," "for example," or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplary," "for example," or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary," "for example," or "for instance" is intended to present the relevant concepts in a concrete manner.
[0053] In the description of the embodiments of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. The "and / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this application, "multiple" means two or more.
[0054] In some processes described in the embodiments of this application, multiple operations or steps are included in a specific order. However, it should be understood that these operations or steps may not be executed in the order they appear in the embodiments of this application, or they may be executed in parallel. The sequence number of the operation is only used to distinguish different operations, and the sequence number itself does not represent any execution order. In addition, these processes may include more or fewer operations, and these operations or steps may be executed sequentially or in parallel, and these operations or steps may be combined.
[0055] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device to execute the methods described in the various embodiments of this application.
[0056] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A method for preventing Redis injection in application systems, characterized in that, The methods for preventing Redis injection in application systems include: An anti-Redis injection component is obtained by encapsulating the anti-Redis injection function based on the Spring Boot technology stack. The anti-Redis injection component includes preset verification and interception mechanisms. The system retrieves requests involving Redis operations and verifies and intercepts these requests using the anti-Redis injection component, thereby preventing Redis injection from affecting the application system.
2. The method for preventing Redis injection in an application system as described in claim 1, characterized in that, The anti-Redis injection component, which encapsulates the anti-Redis injection functionality based on the Spring Boot technology stack, specifically includes: Based on the Spring Boot technology stack, the Redis injection prevention function is encapsulated as an independent component, resulting in the Redis injection prevention component; Package the anti-Redis injection component and upload it to a Maven private repository or central repository; The application system enables the Redis injection prevention function by importing the anti-Redis injection component through a dependency.
3. The method for preventing Redis injection in an application system as described in claim 1, characterized in that: The verification and interception mechanism includes delimiter verification, Lua script verification, configuration keyword verification, and key name compliance verification.
4. The method for preventing Redis injection in an application system as described in claim 3, characterized in that: The separator verification involves identifying and verifying the separators in the input content. The Lua script validation is to identify and verify whether the input content contains Lua script keywords; The configuration keyword verification involves identifying and verifying whether the input content contains the keywords configParam and requirepass. The key name compliance check verifies whether the input key contains the keyword "pattern".
5. A method for preventing Redis injection in an application system as described in claim 3, characterized in that, The process of obtaining requests involving Redis operations is implemented by the anti-Redis injection component, which verifies and intercepts these requests to prevent Redis injection in the application system. Specifically, this includes: Intercept requests involving Redis operations and perform separator validation, Lua script validation, configuration keyword validation, and key name compliance validation in sequence; Based on the verification results: If any verification fails, the operation will be blocked and a security error message will be displayed. If all validations pass, the request will be forwarded to the business logic execution.
6. The method for preventing Redis injection in an application system as described in claim 5, characterized in that, The interception of requests involving Redis operations specifically includes: Anti-Redis injection components use AOP aspects or interceptors to intercept requests involving Redis operations.
7. The method for preventing Redis injection in an application system as described in claim 1, characterized in that, The methods for preventing Redis injection in application systems also include: Conduct security testing and performance evaluation based on actual business scenarios, and optimize the verification rules in the verification and interception mechanisms.
8. A method for preventing Redis injection in an application system as described in claim 1, characterized in that: The anti-Redis injection component also supports custom verification rules, whitelist configuration, and verification switch control.
9. A device for preventing Redis injection in an application system, characterized in that, The device for preventing Redis injection in application systems includes: The configuration module is used to encapsulate the anti-Redis injection function based on the Spring Boot technology stack to obtain an anti-Redis injection component, which includes preset verification and interception mechanisms; The execution module is used to obtain requests involving Redis operations, and to verify and intercept the obtained requests through the anti-Redis injection component to realize the anti-Redis injection of the application system.
10. A device for preventing Redis injection in application systems, characterized in that, The device for implementing Redis injection prevention in an application system includes a processor, a memory, and a program for implementing Redis injection prevention in an application system stored in the memory and executable by the processor, wherein when the program for implementing Redis injection prevention in an application system is executed by the processor, it implements the steps of the method for implementing Redis injection prevention in an application system as described in any one of claims 1 to 8.