Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

21 results about "Web attack" patented technology

A Web log-based intrusion analysis method and system

The present invention discloses a method and system for intrusion analysis based on web logs. The analysis method includes: cutting the original log into fields according to the default delimiter and the default quote character; automatically identifying the field format, performing rapid matching of the field format, parsing and storing in a database; reading the stored logs in batches and performing log matching rule detection; updating the logs and writing them back to the database; aggregating the logs to generate web attack events and determine whether the intruder's attack was successful; generating and submitting a protection and processing report based on the web attack time and the analysis results and the impact range of the intrusion confirmed manually. The present invention realizes intrusion analysis of the attacker's IP address by cutting the web logs, uniformly parsing, rule matching detection and log aggregation. The present invention adopts a method combining automatic detection and manual confirmation, which has the advantages of high efficiency, high result accuracy, high log parsing strength and convenience for secondary analysis, thereby greatly improving the efficiency of web analysis.
Owner:GUANGDONG YUNZHI ANXIN TECH CO LTD

Dynamic adaptive network security protection method based on Nginx

The invention discloses a dynamic self-adaptive network security protection method based on Nginx, which relates to the technical field of IT and software development, automatically analyzes access logs of an Nginx server periodically through a Lua analysis script, filters normal access through a predefined white list rule, deeply analyzes residual suspicious logs, and provides a dynamic self-adaptive network security protection method based on the Nginx. Intelligently identifying an abnormal IP address with an attack behavior and a novel attack load keyword from the suspicious log; the identified abnormal IP is automatically added to a system firewall to perform network layer shielding access to the IP, and meanwhile, the identified attack keyword is dynamically written into an access control strategy library of the Nginx server; whenever the Nginx server receives a real-time access request, the Nginx server carries out real-time protection through a Lua protection script, dynamically loads the latest keyword access control strategy library, carries out matching check on the content of the access request, and immediately intercepts the access request once the access request is hit to realize real-time protection. According to the method, dynamic, self-adaptive and efficient protection on Web attacks is realized.
Owner:SICHUAN LEWEI TECH CO LTD

An attack detection method, apparatus and electronic device

The application discloses an attack detection method and device and electronic equipment, and relates to the technical field of network security, to improve the accuracy and real-time performance of web attack detection, the method comprises the following steps: first, obtaining network request data to be identified, and preprocessing the network request data to be identified to obtain preprocessed network request data; then, a pre-trained target detection model is used to extract the deep semantic vector of the preprocessed network request data, and the similarity between the deep semantic vector and each semantic vector in a preset semantic vector library is calculated; finally, based on each similarity, the detection result of the network request data to be identified is determined. Through the above method, the detection model only needs to learn the semantic vectorization expression of the text, which reduces the training difficulty of the model, reduces the model parameters, and reduces the calculation amount of the model, thereby improving the detection efficiency.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

A method and system for verifying the effectiveness of WAF protection in a network security verification system

ActiveCN119728512BSecuring communicationAttackWeb attack
The application discloses a kind of network security authentication system WAF protection effectiveness verification method and system, method includes: attacker simulator extracts malicious HTTP message object list in local Web security authentication scenario parameter file, malicious HTTP message object list is cyclically handled, including: in the case of encryption, request message and response message are decrypted;Custom request header information is added in request message;And by Socket, send processed malicious HTTP request message to attacker simulator;Attacker simulator receives data at configuration port, for the message with custom request header information, extract the value corresponding to custom request header information, obtain corresponding response message, and return to attacker simulator;Attacker simulator judges whether simulation attack succeeds based on the comparison of response message.The application can be compatible with various Web attack request message, improve system stability and reliability.
Owner:SAINING WANGAN

Characterization of illegitimate web transactions

A device and method for configuring a web application firewall (WAF) based on characterization of web attacks are provided. The method includes receiving a plurality of hypertext transfer protocol transactions (HTTP) entities; tokenizing the received plurality of HTTP entities based on at least one delimiter; analyzing statistical distribution of each of the at least one delimiter in the tokenized HTTP entities; training a model based on an analysis of the tokenized HTTP entities, when a sufficient number of HTTP entities have been analyzed; and configuring, based on the trained model, the WAF with at least one detection rule to detect at least malicious HTTP transactions.
Owner:RADWARE LTD

A detection method, system, and device for defending against network attacks based on the Netfilter framework.

This application provides a detection method, system, and apparatus for defending against network attacks based on the Netfilter framework. The detection method is applied to a defense system between a client and a server to be accessed by the client. The method includes: sending access traffic from the client to an authentication tunnel module via a first detection point for authentication; after successful authentication, the defense system initiates a process to establish a secure communication tunnel with the client; sending data packets destined for the application layer to an application firewall module via a second detection point for web attack detection; the second and first detection points are respectively set on the PREROUTING chain of the Netfilter framework; and sending data packets detected by the application firewall module to a packet filtering module via a third detection point for network layer detection; the third detection point is set on the FORWARD chain of the Netfilter framework.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Artificial intelligence-based hosted web firewall service system and method for managing web server security in multi-cloud environment.

PCT designated stageWO2026038641A1Machine learningSecuring communicationEngineeringWeb attack
An embodiment of the present invention comprises a web firewall service component that is equipped with an attention-based neural network deep learning-based inference model and infers and detects web attacks by analyzing data collected from a web server in real time on the basis of training data generated by extracting features of web attacks for each set field.
Owner:F1 SECURITY INC

Webpage attack type detection method and device, equipment and storage medium

The embodiment of the invention discloses a webpage attack type detection method and device, equipment and a storage medium, and the method comprises the steps: obtaining target HTTP log data; extracting a plurality of target fields in the target HTTP log data, and respectively determining a first field vector corresponding to each target field; wherein the target field comprises at least one of a uniform resource locator, a user agent, a source page, a small text file and request body information; and inputting the first field vectors corresponding to all the target fields into a pre-trained target attack type detection model to obtain a target attack type detection result corresponding to the target HTTP log data. According to the technical scheme provided by the embodiment of the invention, the problem of high false alarm rate of attack behaviors in the prior art is solved, comprehensive analysis can be carried out by analyzing various fields in the HTTP log data, more types of Web attack behaviors can be found, and the comprehensiveness and accuracy of attack behavior detection are improved.
Owner:CHINA MOBILE (XIONGAN) ICT CO LTD +3

Webpage application attack detection method, device and computer equipment

The application relates to a webpage application attack detection method, device and computer equipment. The method comprises the following steps: when a user sends webpage access request information to the front end of a webpage application, collecting client fingerprint information and operation behavior data of the user, and identifying potential attack behavior information of the user based on the operation behavior data and the webpage access request information through an attack detection algorithm; encrypting and transmitting the potential attack behavior information, the client fingerprint information and the operation behavior data of the user, and identifying attack detection results of the user through an attack detection program of the server end; generating attack protection information of the webpage application for the user based on the attack detection results, and performing distributed attack protection processing on each browser node corresponding to the webpage application based on the attack protection information. The method can improve the low efficiency of Web attack detection in a high-concurrency and low-latency environment.
Owner:CHINA TELECOM CLOUD TECH CO LTD

A web attack detection method and apparatus

The application provides a Web attack detection method and device, and relates to the technical field of computers.The method comprises the following steps: receiving a Web request sent by a user; extracting a plurality of dimensional request features from the Web request; identifying the encoding mode of each request feature based on encoding detection; decoding the request features based on the encoding mode of the request features to obtain original features corresponding to the request features; determining whether there are original features matching a preset current attack rule, and if not, forwarding the Web request to a source station server, otherwise, extracting an attack payload from the original features matching the current attack rule, and updating the current attack rule based on the attack payload.The application can update the attack rule in a timely manner and improve the security of the source station server.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

A web attack detection method based on a gated Transformer

The application provides a Web attack detection method based on a gated Transformer, and relates to the technical field of network maintenance.The method provided by the application proposes a network model based on a gated Transformer, which combines a Transformer and a gated convolution module together, the Transformer extracts global semantic information of different spatial dimensions through a multi-head self-attention mechanism, the gated convolution extracts information of a local space through a one-dimensional convolution kernel, and a gating mechanism is adopted to screen and filter text information.The application can effectively extract multidimensional global features and local features, a mixed word vector table can contain more accurate and rich semantic information, can automatically extract effective data information features in a text sequence, does not need to manually screen information and replace a word table, further improves the accuracy of model multi-classification attack detection and reduces a false positive rate, and can fully protect the security of a Web server system.
Owner:NORTHEASTERN UNIV CHINA

Network attack detection method and device and electronic equipment

PendingCN121125244ASecuring communicationDomain nameQueries per second
The invention discloses a network attack detection method and device and electronic equipment. The method comprises the steps that a gateway access log is acquired, and the gateway access log comprises a website domain name, a source internet protocol IP address and a timestamp; obtaining a query per second (QPS) rate of the website domain name according to the timestamp; under the condition that the QPS is greater than a QPS peak value, acquiring a PV proportion of access times of a source IP address corresponding to the website domain name in a preset time interval; further judging whether the source IP address is a preset malicious IP address or not under the condition that the PV proportion is greater than the PV proportion threshold value; and under the condition that the source IP address is the malicious IP address, adding the source IP address into the IP address banning blacklist. According to the method and the device, the accuracy of network attack interception is improved, hardware resources are saved, the performance of a Web attack detection system is improved, meanwhile, the duration of attack interception response is shortened, and missing interception and mistaken interception are not easy to occur.
Owner:SINA TECH (CHINA) CO LTD

AI-based Web application attack detection and defense method and system

The embodiment of the invention discloses a Web application attack detection and defense method and system based on AI. The method comprises the following steps: extracting a minimum effective feature set of attack behaviors from historical Web attack traffic data, clustering, generating attack micro-feature clusters, and constructing an attack micro-feature cluster library; key features of the access traffic of the Web application are extracted, and the current occurrence frequency, the accumulated occurrence frequency and the combination mode of the key features are counted; matching the key features based on the attack micro-feature cluster library to obtain a matching result, constructing a structured numerical matrix in combination with statistical data, inputting the structured numerical matrix into a detection model for detection, and executing a blocking operation when a malicious attack is detected; and when the hostile attack is a novel unknown attack, updating the features of the hostile attack to the attack micro-feature cluster library. According to the method, the computing power consumption can be greatly reduced, the detection efficiency can be improved to adapt to a high-concurrency scene, deformation and fragmentation novel attacks can be accurately identified, feature library self-updating can be realized, and the problem of rule hysteresis can be solved.
Owner:WEBRAY TECH BEIJING CO LTD

Dual-channel Web attack detection method based on BERT pre-training model

The invention discloses a dual-channel Web attack detection method based on a BERT pre-training model, and the method comprises the steps: extracting a URL, a request method, a Payload and corresponding label information from an HTTP request message in a data set, and carrying out the standardization preprocessing; independently coding the URL and the Payload parameters by using the pre-trained URLBERT and SecBERT respectively, and generating context-aware embedded representations of a plurality of request parameters of the URL and the Payload respectively; fusing the embedded representations of the URL and the Payload, splicing to obtain a joint feature vector, and inputting the joint feature vector to a full connection layer for classification; a training set is used for training a model, a cross entropy loss function is used as an optimization target, the model is optimized through a back propagation mechanism, collaborative learning is synchronously carried out on URLBERT and SecBERT, and the detection performance is evaluated on a test set. By adopting the method and the device, the request URL and Payload characteristics in the Web attack detection task are fully mined, the parameter combination relationship is modeled, and the attack can be effectively traced.
Owner:SHANTOU UNIV

Web attack detection method and device, computer equipment and storage medium

The invention provides a web attack detection method and device, computer equipment and a storage medium, and belongs to the technical field of web attack detection. According to the scheme, the method comprises the following steps: acquiring an http request log generated when a user accesses a web service; analyzing and extracting a request resource url in the request log, and carrying out decoding and word segmentation processing on the url to obtain training data; after a Bert model is used for replacing an AE self-encoder in the DEC framework, an improved DEC classification model is obtained, the training data is used for carrying out clustering training on the improved DEC classification model to obtain a plurality of clusters, and the web attack category to which each cluster belongs is determined; and inputting the current to-be-classified data into the trained improved DEC classification model for classification to obtain a classification cluster to which the current to-be-classified data belongs, and judging whether the current to-be-classified data belongs to the web attack or not according to the web attack category to which the current classification cluster belongs. According to the scheme, the problem that in the prior art, due to the fact that some statistical features are extracted based on an http log to conduct classification or clustering analysis research, the extracted features are not comprehensive and remarkable enough, and the abnormal request detection precision of the model is affected to a great extent is solved.
Owner:DA FANG ELECTRONIC

Method and system for detecting Web attack based on ClickHouse

The invention provides a method and system for detecting Web attacks based on ClickHouse, and the method comprises the steps: carrying out the standardized analysis of a network card flow log, and storing the analyzed data in a ClickHouse database in real time; and writing a timed task program connected with the ClickHouse database, reading data from the ClickHouse at regular intervals, and executing a ClickHouse SQL (Structured Query Language) statement to carry out Web attack detection. According to the method, after the data are stored in the ClickHouse, the SQL engine of the ClickHouse is directly used for query analysis, data retrieval is accelerated, additional data carrying and a complex calculation framework are not needed, and the delay of detection result return can be greatly reduced. According to the method, under the condition of the same log data volume, the consumption of hardware resources can be remarkably reduced, and the defects that a non-real-time monitoring method is low in efficiency and large in resource investment are overcome.
Owner:CHINA RESOURCES NETWORKS (SHENZHEN) CO LTD

AI-based methods and systems for detecting and defending against web application attacks

This disclosure presents an AI-based method and system for detecting and defending against web application attacks. The method includes: extracting the minimum effective feature set of attack behavior from historical web attack traffic data, clustering it to generate attack micro-feature clusters, and constructing an attack micro-feature cluster library; extracting key features from the access traffic of web applications, and statistically analyzing the current occurrence frequency, cumulative occurrence frequency, and combination methods of the key features; matching the key features based on the attack micro-feature cluster library to obtain matching results, and combining the statistical data to construct a structured numerical matrix and inputting it into a detection model for detection; when a malicious attack is detected, a blocking operation is performed; when the malicious attack is a new and unknown attack, its features are updated in the attack micro-feature cluster library. This method can significantly reduce computational power consumption, improve detection efficiency to adapt to high-concurrency scenarios, accurately identify deformed and fragmented new attacks, and achieve self-updating of the feature library, solving the problem of rule lag.
Owner:WEBRAY TECH BEIJING CO LTD

A Transformer-based method for detecting unknown web attacks

This application proposes a Transformer-based method for detecting unknown web attacks. The method includes: real-time collection of HTTP requests, preprocessing them into a token sequence; inserting a special token at the beginning of the token sequence, converting each token in the expanded token sequence into an embedded representation, encoding the embedded representation using a multi-layer Transformer encoder to obtain an intermediate representation for each token; using the intermediate representation as the initial hidden state of a GRU decoder, and generating a reconstructed token sequence by performing sequence decoding on the GRU decoder; and determining whether a given HTTP request conforms to the pattern characteristics of a normal HTTP request by comparing the reconstruction error between the original token sequence and the reconstructed token sequence. This application, through unsupervised learning, can detect unknown web attacks without relying on manual rules or labeled data, and can effectively capture the structural information of HTTP requests, thus modeling the normal behavior patterns of web applications.
Owner:TSINGHUA UNIVERSITY

Method and device for automatically reconstructing stateful Web attack preposed step sequence

The invention particularly relates to a method and device for automatically reconstructing a stateful Web attack front step sequence, and the method comprises the steps: receiving a final attack request; based on the final attack request, constructing a target state portrait, and based on the target state portrait, calculating a state distance between the current application state and the target state; determining a shortest path of the target state portrait based on a preset data-driven guide model and the state distance, and generating a candidate request sequence by using a preset operation sequence generation engine based on the shortest path; and based on a preset comprehensive score function, evaluating the difference between the rear-end state after executing the candidate request sequence and the target state portrait to obtain a comprehensive score of the candidate request sequence, and when the comprehensive score meets a preset condition, taking the candidate request sequence as a request sequence corresponding to the comprehensive score. Therefore, the problems that automatic reconstruction of the stateful Web attack sequence is difficult, multi-step vulnerability verification efficiency is low, attack investigation depends on manpower and the like are solved.
Owner:TSINGHUA UNIVERSITY

Explainable web attack detection method based on deep learning

The application relates to the technical field of network security, and discloses an interpretable Web attack detection method based on deep learning, which comprises the following steps: an original HTTP request is received by a preprocessing module and is hierarchically parsed and converted into an ordered minimum semantic unit sequence; an embedding attribution module is used to convert the sequence into an embedding matrix which is input into a deep learning model, and an attribution matrix is generated based on gradient calculation when an anomaly occurs; a structure alignment module is used to perform double-layer feature aggregation of labels and protocol levels, and to calculate semantic unit attribution scores; a malicious payload positioning module is used to construct a positioning feature vector based on the attribution scores and text semantics, and the positioning feature vector is input into the model to determine the position of the malicious payload; and an automatic WAF rule generation module is used to cluster and regularly extract the positioning results to generate defense rules. The application realizes interpretable model decision through attribution analysis and structure alignment, and realizes accurate positioning of attack payloads and automatic generation of defense rules by fusing context and semantic features.
Owner:TSINGHUA UNIVERSITY