CN106295334A - Ile repair method and device - Google Patents

Ile repair method and device Download PDF

Info

Publication number
CN106295334A
CN106295334A CN201510307070.6A CN201510307070A CN106295334A CN 106295334 A CN106295334 A CN 106295334A CN 201510307070 A CN201510307070 A CN 201510307070A CN 106295334 A CN106295334 A CN 106295334A
Authority
CN
China
Prior art keywords
file
repair
suspicious
program
updated
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201510307070.6A
Other languages
Chinese (zh)
Other versions
CN106295334B (en
Inventor
郑瀚
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba Group Holding Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Priority to CN201510307070.6A priority Critical patent/CN106295334B/en
Publication of CN106295334A publication Critical patent/CN106295334A/en
Application granted granted Critical
Publication of CN106295334B publication Critical patent/CN106295334B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55—Detecting local intrusion or implementing counter-measures
    • G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
    • G06F21/562—Static detection

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Virology (AREA)
  • Health & Medical Sciences (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Information Transfer Between Computers (AREA)
  • Storage Device Security (AREA)

Abstract

本申请公开了一种文件修复方法及装置。其中,该方法包括:获取请求装置上传的具有第一格式的可疑文件;按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;依据所述令牌序列特征,确定所述至少一个字段组中的漏洞;将所述漏洞替换为预设的修复代码序列,得到修复后的所述至少一个字段组;将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。本申请解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。

The application discloses a method and a device for repairing files. Wherein, the method includes: obtaining a suspicious file with a first format uploaded by the requesting device; according to the grammatical characteristics of each field in the suspicious file, forming fields with the same grammatical characteristics into at least one field group; according to the grammatical characteristics of each field group, feature, to obtain the token sequence feature corresponding to each grammatical feature; according to the token sequence feature, determine the loophole in the at least one field group; replace the loophole with a preset repair code sequence, and obtain all the patched the at least one field group; and reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file. This application solves the technical problem that the accuracy of bug repair is poor due to the implementation of the same set of Patch codes in the prior art.

Description

文件修复方法及装置File restoration method and device

技术领域technical field

本申请涉及互联网领域,具体而言,涉及一种文件修复方法及装置。The present application relates to the field of the Internet, in particular, to a method and device for repairing files.

背景技术Background technique

随着互联网的快速发展,各个运营商的服务器运行着大量的web网站,出于技术上的考虑,这些web网站大多数直接采用目前市场上开源或者收费的CMS(ContentManagement System,内容管理系统)进行网站系统的搭建。而这些CMS由于源代码容易获得,常常遭到黑客的漏洞挖掘,在发现了可利用的漏洞之后,黑客会利用自己手上的ODAY(零日)漏洞对web网站进行攻击,进而获取大量的商业资料。With the rapid development of the Internet, the servers of various operators run a large number of web sites. Due to technical considerations, most of these web sites directly use open source or paid CMS (Content Management System, Content Management System) on the market. Construction of the website system. Because the source code of these CMSs is easy to obtain, they are often exploited by hackers. After discovering exploitable vulnerabilities, hackers will use their own ODAY (zero-day) vulnerabilities to attack web sites, and then obtain a large amount of business. material.

在web攻防的对抗中,对于传统的二进制漏洞文件、或者是网站文本文件Patch(补丁)技术中,现有技术一般采用的是统一的替换模版的方法,即不管漏洞文件或漏洞代码有多少种变种,在服务器端都采用同一套Patch代码实行漏洞修复,这就导致漏洞修复准确性较差、系统安全性较低的问题。In the confrontation of web attack and defense, for traditional binary vulnerability files or website text file Patch (patch) technology, the existing technology generally adopts a unified method of replacing templates, that is, no matter how many types of vulnerability files or vulnerability codes there are Variants, the same set of Patch codes are used on the server side to implement vulnerability repair, which leads to poor accuracy of vulnerability repair and low system security.

针对上述的问题,目前尚未提出有效的解决方案。For the above problems, no effective solution has been proposed yet.

发明内容Contents of the invention

本申请实施例提供了一种文件修复方法及装置,以至少解决由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。The embodiment of the present application provides a file repair method and device to at least solve the technical problem of poor bug repair accuracy caused by using the same set of Patch codes in the prior art.

根据本申请实施例的一个方面,提供了一种文件修复方法,包括:获取请求装置上传的具有第一格式的可疑文件;按照上述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;依据上述令牌序列特征,确定上述至少一个字段组中的漏洞;将上述漏洞替换为预设的修复代码序列,得到修复后的上述至少一个字段组;将修复后的上述至少一个字段组重组为对应于上述可疑文件的具有上述第一格式的修复文件。According to an aspect of the embodiment of the present application, a method for repairing a file is provided, including: obtaining a suspicious file in a first format uploaded by a requesting device; according to the grammatical features of each field in the suspicious file, combining at least one field group; according to the grammatical features of each field group, obtain the token sequence features corresponding to each grammatical feature; determine the loopholes in the above at least one field group according to the above token sequence features; replace the above loopholes with preset Repairing the code sequence to obtain the repaired at least one field group; reorganizing the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file.

根据本申请实施例的另一方面,还提供了一种文件修复方法,包括:将具有第一格式的可疑文件发送至文件修复装置,其中,由上述文件修复装置按照上述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据上述令牌序列特征,确定上述至少一个字段组中的漏洞,将上述漏洞替换为预设的修复代码序列,得到修复后的上述至少一个字段组,将修复后的上述至少一个字段组重组为对应于上述可疑文件的具有上述第一格式的修复文件;从上述文件修复装置中获取对应于上述可疑文件的具有上述第一格式的修复文件。According to another aspect of the embodiment of the present application, there is also provided a file restoration method, including: sending a suspicious file in a first format to a file restoration device, wherein the above-mentioned file restoration device according to each field in the above-mentioned suspicious file Grammatical features, combining fields with the same grammatical features into at least one field group, obtaining the token sequence features corresponding to each grammatical feature according to the grammatical features of each field group, and determining the at least one field group in the above-mentioned at least one field group according to the above-mentioned token sequence features Vulnerability, replacing the above-mentioned vulnerability with a preset repair code sequence, obtaining the above-mentioned at least one field group after repair, and reorganizing the above-mentioned at least one field group after repair into a repair file with the above-mentioned first format corresponding to the above-mentioned suspicious file; Obtain a repair file in the first format corresponding to the suspicious file from the file repair apparatus.

根据本申请实施例的另一方面,还提供了一种文件修复装置,包括:获取单元,用于获取请求装置上传的具有第一格式的可疑文件;处理单元,用于按照上述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;第一确定单元,用于根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;第二确定单元,用于依据上述令牌序列特征,确定上述至少一个字段组中的漏洞;修复单元,用于将上述漏洞替换为预先配置的修复代码序列,得到修复后的上述至少一个字段组;重组单元,用于将修复后的上述至少一个字段组重组为对应于上述可疑文件的具有上述第一格式的修复文件。According to another aspect of the embodiment of the present application, there is also provided a device for repairing a file, including: an acquisition unit, configured to acquire a suspicious file in the first format uploaded by the requesting device; The grammatical feature of the field is to form at least one field group with fields with the same grammatical feature; the first determination unit is used to obtain the token sequence feature corresponding to each grammatical feature according to the grammatical feature of each field group; the second determination unit uses According to the characteristics of the above-mentioned token sequence, the vulnerability in the above-mentioned at least one field group is determined; the repair unit is used to replace the above-mentioned hole with a pre-configured repair code sequence to obtain the repaired above-mentioned at least one field group; the reorganization unit is used for Reorganizing the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file.

根据本申请实施例的另一方面,还提供了一种请求装置,包括:第三发送单元,用于将具有第一格式的可疑文件发送至文件修复装置,其中,由上述文件修复装置按照上述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据上述令牌序列特征,确定上述至少一个字段组中的漏洞,将上述漏洞替换为预设的修复代码序列,得到修复后的上述至少一个字段组,将修复后的上述至少一个字段组重组为对应于上述可疑文件的具有上述第一格式的修复文件;控制单元,用于从上述文件修复装置中获取对应于上述可疑文件的具有上述第一格式的修复文件。According to another aspect of the embodiment of the present application, there is also provided a requesting device, including: a third sending unit, configured to send the suspicious file in the first format to the file repairing device, wherein the above-mentioned file repairing device according to the above-mentioned For the grammatical features of each field in the suspicious file, the fields with the same grammatical features are formed into at least one field group, and according to the grammatical features of each field group, the token sequence features corresponding to each grammatical feature are obtained, and the above token sequence features are used to determine the above Vulnerabilities in at least one field group, replacing the above-mentioned holes with a preset repair code sequence, obtaining the repaired at least one field group, reorganizing the repaired at least one field group into a file corresponding to the above-mentioned suspicious file with the above-mentioned A recovery file in a format; a control unit configured to acquire a recovery file in the first format corresponding to the suspicious file from the file recovery device.

在本申请实施例中,采用获取请求装置上传的具有第一格式的可疑文件;按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;依据令牌序列特征,确定至少一个字段组中的漏洞;将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组;将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件的方式,通过按照语法特征对可疑文件进行拆分得到至少一个字段组之后,依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果,进而解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。In this embodiment of the application, the suspicious file with the first format uploaded by the acquisition requesting device is used; according to the grammatical characteristics of each field in the suspicious file, fields with the same grammatical characteristics are formed into at least one field group; according to the grammatical characteristics of each field group features, to obtain the token sequence features corresponding to each grammatical feature; according to the token sequence features, determine the loopholes in at least one field group; replace the loopholes with the preset repair code sequence, and obtain at least one field group after repair; After at least one field group is reorganized into a repair file with the first format corresponding to the suspicious file, after the suspicious file is split according to the grammatical feature to obtain at least one field group, according to each grammatical feature corresponding token sequence feature and The repair code sequence is used to find and repair vulnerabilities, achieving the purpose of 1:1 automatic repair of vulnerabilities, thereby achieving the technical effect of improving the accuracy of vulnerability repair and system security, and further solving the problems caused by the use of the same system in the existing technology. The technical problem of poor accuracy of bug fixes caused by the implementation of Patch codes.

附图说明Description of drawings

此处所说明的附图用来提供对本申请的进一步理解,构成本申请的一部分,本申请的示意性实施例及其说明用于解释本申请,并不构成对本申请的不当限定。在附图中:The drawings described here are used to provide a further understanding of the application and constitute a part of the application. The schematic embodiments and descriptions of the application are used to explain the application and do not constitute an improper limitation to the application. In the attached picture:

图1是根据本申请实施例的一种运行文件检测方法的计算机终端的硬件结构框图;Fig. 1 is a block diagram of the hardware structure of a computer terminal running a file detection method according to an embodiment of the present application;

图2是根据本申请实施例的一种可选的文件修复方法的流程示意图;FIG. 2 is a schematic flow diagram of an optional file repair method according to an embodiment of the present application;

图3是根据本申请实施例的另一种可选的文件修复方法的流程示意图;FIG. 3 is a schematic flow diagram of another optional file repair method according to an embodiment of the present application;

图4是根据本申请实施例的又一种可选的文件修复方法的流程示意图;FIG. 4 is a schematic flowchart of another optional file repair method according to an embodiment of the present application;

图5是根据本申请实施例的又一种可选的文件修复方法的流程示意图;FIG. 5 is a schematic flowchart of another optional file repair method according to an embodiment of the present application;

图6是根据本申请实施例的又一种可选的文件修复方法的流程示意图;FIG. 6 is a schematic flowchart of another optional file repair method according to an embodiment of the present application;

图7是根据本申请实施例的又一种可选的文件修复方法的流程示意图;FIG. 7 is a schematic flowchart of another optional file repair method according to an embodiment of the present application;

图8是根据本申请实施例的一种可选的文件修复装置的结构示意图;FIG. 8 is a schematic structural diagram of an optional file repair device according to an embodiment of the present application;

图9是根据本申请实施例的另一种可选的文件修复装置的结构示意图;FIG. 9 is a schematic structural diagram of another optional file restoration device according to an embodiment of the present application;

图10是根据本申请实施例的一种可选的去重单元的结构示意图;FIG. 10 is a schematic structural diagram of an optional deduplication unit according to an embodiment of the present application;

图11是根据本申请实施例的又一种可选的文件修复装置的结构示意图;FIG. 11 is a schematic structural diagram of another optional file restoration device according to an embodiment of the present application;

图12是根据本申请实施例的又一种可选的文件修复装置的结构示意图;FIG. 12 is a schematic structural diagram of another optional file restoration device according to an embodiment of the present application;

图13是根据本申请实施例的一种可选的请求装置的结构示意图。Fig. 13 is a schematic structural diagram of an optional request device according to an embodiment of the present application.

具体实施方式detailed description

为了使本技术领域的人员更好地理解本申请方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分的实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本申请保护的范围。In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiment of the application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiment of the application. Obviously, the described embodiment is only It is an embodiment of a part of the application, but not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by persons of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.

需要说明的是,本申请的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、系统、产品或设备不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或单元。It should be noted that the terms "first" and "second" in the description and claims of the present application and the above drawings are used to distinguish similar objects, but not necessarily used to describe a specific sequence or sequence. It is to be understood that the data so used are interchangeable under appropriate circumstances such that the embodiments of the application described herein can be practiced in sequences other than those illustrated or described herein. Furthermore, the terms "comprising" and "having", as well as any variations thereof, are intended to cover a non-exclusive inclusion, for example, a process, method, system, product or device comprising a sequence of steps or elements is not necessarily limited to the expressly listed instead, may include other steps or elements not explicitly listed or inherent to the process, method, product or apparatus.

实施例1Example 1

根据本申请实施例,还提供了一种文件修复方法的方法实施例,需要说明的是,在附图的流程图示出的步骤可以在诸如一组计算机可执行指令的计算机系统中执行,并且,虽然在流程图中示出了逻辑顺序,但是在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤。According to the embodiment of the present application, a method embodiment of a file repair method is also provided. It should be noted that the steps shown in the flow chart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and , although a logical order is shown in the flowcharts, in some cases the steps shown or described may be performed in an order different from that shown or described herein.

本申请实施例一所提供的方法实施例可以在移动终端、计算机终端或者类似的运算装置中执行。以运行在计算机终端上为例,图1是本申请实施例的一种文件修复方法的计算机终端的硬件结构框图。如图1所示,计算机终端10可以包括一个或多个(图中仅示出一个)处理器102(处理器102可以包括但不限于微处理器MCU或可编程逻辑器件FPGA等的处理装置)、用于存储数据的存储器104、以及用于通信功能的传输装置106。本领域普通技术人员可以理解,图1所示的结构仅为示意,其并不对上述电子装置的结构造成限定。例如,计算机终端10还可包括比图1中所示更多或者更少的组件,或者具有与图1所示不同的配置。The method embodiment provided in Embodiment 1 of the present application may be executed in a mobile terminal, a computer terminal, or a similar computing device. Taking it running on a computer terminal as an example, FIG. 1 is a block diagram of the hardware structure of a computer terminal according to a method for repairing a file according to an embodiment of the present application. As shown in Figure 1, the computer terminal 10 may include one or more (only one is shown in the figure) processors 102 (the processors 102 may include but not limited to processing devices such as microprocessor MCU or programmable logic device FPGA, etc.) , a memory 104 for storing data, and a transmission device 106 for communication functions. Those of ordinary skill in the art can understand that the structure shown in FIG. 1 is only a schematic diagram, and it does not limit the structure of the above-mentioned electronic device. For example, computer terminal 10 may also include more or fewer components than shown in FIG. 1 , or have a different configuration than that shown in FIG. 1 .

存储器104可用于存储应用软件的软件程序以及模块,如本申请实施例中的文件修复方法对应的程序指令/模块,处理器102通过运行存储在存储器104内的软件程序以及模块,从而执行各种功能应用以及数据处理,即实现上述的应用程序的漏洞检测方法。存储器104可包括高速随机存储器,还可包括非易失性存储器,如一个或者多个磁性存储装置、闪存、或者其他非易失性固态存储器。在一些实例中,存储器104可进一步包括相对于处理器102远程设置的存储器,这些远程存储器可以通过网络连接至计算机终端10。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。The memory 104 can be used to store software programs and modules of application software, such as program instructions/modules corresponding to the file repair method in the embodiment of the present application, and the processor 102 executes various Functional application and data processing, that is, to realize the vulnerability detection method of the above-mentioned application program. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory that is remotely located relative to the processor 102 , and these remote memories may be connected to the computer terminal 10 through a network. Examples of the aforementioned networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

传输装置106用于经由一个网络接收或者发送数据。上述的网络具体实例可包括计算机终端10的通信供应商提供的无线网络。在一个实例中,传输装置106包括一个网络适配器(Network Interface Controller,NIC),其可通过基站与其他网络设备相连从而可与互联网进行通讯。在一个实例中,传输装置106可以为射频(RadioFrequency,RF)模块,其用于通过无线方式与互联网进行通讯。The transmission device 106 is used to receive or transmit data via a network. The specific example of the above-mentioned network may include a wireless network provided by the communication provider of the computer terminal 10 . In one example, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 may be a radio frequency (Radio Frequency, RF) module, which is used to communicate with the Internet in a wireless manner.

在上述运行环境下,本申请提供了如图2所示的文件修复方法。图2是根据本申请实施例一的文件修复方法的流程图。Under the above operating environment, the present application provides a file restoration method as shown in FIG. 2 . FIG. 2 is a flow chart of a file repair method according to Embodiment 1 of the present application.

如图2所示,该文件修复方法可以包括如下实现步骤:As shown in Figure 2, the file repair method may include the following implementation steps:

步骤S202,获取请求装置上传的具有第一格式的可疑文件。Step S202, obtaining a suspicious file in the first format uploaded by the requesting device.

本申请上述步骤S202中,请求装置可以是指安装在用户设备上的一个应用程序(例如客户端),该请求装置可以根据服务器端的配置,定时启动对用户设备进行扫描,当发现可疑文件时,通过预先配置的通道上传该可疑文件至文件修复装置,请求装置也可以是计算机终端或者类似的运算装置,定时启动对自身磁盘文件进行扫描,当发现可疑文件时,通过预先配置的通道将可疑文件发送给文件修复装置。In the above-mentioned step S202 of the present application, the requesting means may refer to an application program (such as a client) installed on the user equipment. The requesting means may regularly start scanning the user equipment according to the configuration of the server side. When suspicious files are found, Upload the suspicious file to the file repair device through a pre-configured channel. The requesting device can also be a computer terminal or similar computing device, which starts to scan its own disk files at regular intervals. Send to the file recovery device.

其中,文件修复装置接收到来自请求装置的具有第一格式的可疑文件之后,可以对该可疑文件进行解析,以实现可疑文件的修复,文件修复装置例如可以为AliYunDun服务器。Wherein, after the file repairing device receives the suspicious file in the first format from the requesting device, it can analyze the suspicious file to realize the repairing of the suspicious file. The file repairing device can be, for example, an AliYunDun server.

以请求装置为AliYunDun(阿里云盾)为例,AliYunDun基于C/S(Client/Server,客户端/服务器)的网络架构,每台用户设备上都部署有一个独立的AliYunDun程序,并通过加密通道和AliYunDun服务器保持长连接。根据服务器的配置,AliYunDun定时从服务器下载最新AliVulfix(云盾附属组件)漏洞修复程序,替换本地的漏洞修复程序。根据服务器的配置,AliYunDun可以控制AliVulfix漏洞修复程序定时启动,对用户设备上的所有磁盘目录进行全盘遍历扫描,并根据服务器下发的配置信息收取指定目录的文件,例如配置项有一条为:/plus/mytag_js.php,则AliVulfix会扫描并通过AliYunDun的加密通过上报这个可疑文件。Take AliYunDun (Alibaba Cloud Shield) as an example as the requesting device. AliYunDun is based on the network architecture of C/S (Client/Server, client/server). Each user device is equipped with an independent AliYunDun program, and through encrypted channels Keep a long connection with AliYunDun server. According to the configuration of the server, AliYunDun regularly downloads the latest AliVulfix (Cloud Shield subsidiary component) vulnerability fix program from the server to replace the local vulnerability fix program. According to the configuration of the server, AliYunDun can control the regular start of the AliVulfix vulnerability repair program, scan all the disk directories on the user device, and collect the files in the specified directory according to the configuration information sent by the server. For example, one of the configuration items is: / plus/mytag_js.php, AliVulfix will scan and report this suspicious file through the encryption of AliYunDun.

步骤S204,按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组。Step S204, according to the grammatical features of each field in the suspicious file, form fields with the same grammatical feature into at least one field group.

本申请上述步骤S204中,文件修复装置在获取该可疑文件之后,为了对漏洞采取一对一针对性修复并且提高修复效率,以免修复时间过长导致黑客利用该时间间隙入侵用户设备,文件修复装置可以按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组。In the above-mentioned step S204 of the present application, after the file repairing device obtains the suspicious file, in order to take one-to-one targeted repair of the vulnerability and improve the repair efficiency, so as to prevent the hacker from using the time gap to invade the user device due to too long repair time, the file repair device According to the grammatical features of each field in the suspicious file, fields with the same grammatical feature can be combined into at least one field group.

以文件修复装置为AliYunDun服务器为例,因为阿里云上用户大部分是电商、网站用户,用户常常有对自己网站代码文件做定制化修改的情况,为了保证漏洞修复不影响这些用户网站的正常运行,AliYunDun服务器采取了一对一针对性修复的策略,然而,一对一修复会产生一个问题,采用1∶1修复后,在阿里云数十万体量的用户数下,在服务器端会收到大量的存在漏洞的文件,即使进行过滤,文件数量还是很多,因此,AliYunDun服务器可以将上述可疑文件解析成语法树结构。Taking the AliYunDun server as the file repair device as an example, because most of the users on Alibaba Cloud are e-commerce and website users, users often make customized changes to their own website code files. Running, the AliYunDun server adopts a one-to-one targeted repair strategy. However, one-to-one repair will cause a problem. Received a large number of files with vulnerabilities, even after filtering, there are still a lot of files. Therefore, the AliYunDun server can parse the above suspicious files into a syntax tree structure.

本申请实施例中,文件修复装置首先要对可疑文件进行语法分析,确定可疑文件中各个字段的语法特征,其中,语法分析指的是将代码扫描到一个容器中,然后对该容器中的字符在词法分析的基础上将字段组合成各类语法短语。在确定了各个字段的语法特征之后,文件修复装置可以将语法特征相同的字段组成至少一个字段组,进一步地,文件修复装置可以依据各个字段之间的父子关系,将至少一个字段组解析为语法树结构。In the embodiment of the present application, the file repairing device first needs to perform grammatical analysis on the suspicious file to determine the grammatical features of each field in the suspicious file, wherein the grammatical analysis refers to scanning the code into a container, and then the characters in the container Combining fields into various grammatical phrases based on lexical analysis. After determining the grammatical features of each field, the file repairing device can form at least one field group with fields with the same grammatical feature, and further, the file repairing device can parse at least one field group into a grammatical tree structure.

步骤S206,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征。Step S206, according to the grammatical features of each field group, acquire token sequence features corresponding to each grammatical feature.

本申请上述步骤S206中,令牌序列特征可以是由安全运营人员预先配置的,文件修复装置利用对应于各个语法特征的令牌序列特征,实现漏洞的查找。In the above step S206 of the present application, the token sequence feature may be pre-configured by the security operator, and the file repair device uses the token sequence feature corresponding to each grammatical feature to realize the search for loopholes.

步骤S208,依据令牌序列特征,确定至少一个字段组中的漏洞。Step S208, according to the characteristics of the token sequence, determine the loopholes in at least one field group.

本申请上述步骤S208中,文件修复装置在获取到各个语法特征对应的令牌序列特征之后,可以依据令牌序列特征在至少一个字段组中进行漏洞的定位。In the above step S208 of the present application, after obtaining the token sequence features corresponding to each grammatical feature, the file repairing device can locate vulnerabilities in at least one field group according to the token sequence features.

此处以通俗的例子来说明,假如有一百个人,目的是确定眼球颜色蓝色的人,即令牌序列特征是“眼球-蓝色”,那么按照本申请实施例提供的文件修复方法的思路,我们先将这一百个人的各个部分进行分组,例如,将一百个人的眼睛分为一组、鼻子分为一组、嘴巴分为一组等等,那么,在根据令牌序列特征进行漏洞查找时,只需要在眼睛这一组中进行查找,无需再搜索其他部分,达到提高漏洞查找效率的目的。Here is a popular example to illustrate, if there are one hundred people, the purpose is to determine the person whose eyeball color is blue, that is, the token sequence feature is "eyeball-blue", then follow the idea of the file restoration method provided by the embodiment of this application , we first group the various parts of the one hundred people, for example, the eyes of one hundred people are grouped into one group, the nose is grouped into one group, the mouth is grouped into one group, etc., then, according to the token sequence feature When searching for vulnerabilities, you only need to search in the eye group, without searching other parts, so as to improve the efficiency of finding vulnerabilities.

可选地,依据令牌序列特征,确定至少一个字段组中的漏洞包括:在至少一个字段组中查找与令牌序列特征相同的字段,将与令牌序列特征相同的字段确定为漏洞。Optionally, according to the token sequence feature, determining the loophole in at least one field group includes: searching for fields identical to the token sequence feature in at least one field group, and determining the same field as the token sequence feature as a loophole.

本申请实施例中,安全运营人员只需配置一次上述令牌序列特征,文件修复装置则可以自动化进行漏洞的定位,提高了安全运营的时间成本。In the embodiment of this application, the security operation personnel only need to configure the above-mentioned token sequence feature once, and the file repair device can automatically locate the vulnerability, which improves the time cost of security operation.

步骤S210,将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组。Step S210, replacing the vulnerability with a preset repair code sequence to obtain at least one field group after repair.

本申请上述步骤S210中,预设的修复代码序列也可以是安全运营人员预先配置的。文件修复装置在依据令牌序列特征,确定至少一个字段组中的漏洞之后,可以获取该预设的修复代码序列,进而,将漏洞替换为该预设的修复代码序列,实现可疑文件的修复。In the above step S210 of the present application, the preset repair code sequence may also be pre-configured by security operators. After the file repairing device determines the loophole in at least one field group according to the characteristics of the token sequence, it can obtain the preset repair code sequence, and then replace the loophole with the preset repair code sequence to realize the repair of the suspicious file.

本申请实施例的文件修复装置采用的1∶1的精确定点修复技术,即所有的可疑文件都直接基于请求装置原始文件进行针对性的修改,这样可以最大程度地避免因为漏洞修复造成代码逻辑的不一致从而导致用户的正常业务逻辑受到影响,甚至不可用。同时,安全运营人员只需要配置一个修复代码序列,在文件修复装置确定漏洞时,将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组。The file repairing device in the embodiment of the present application adopts the 1:1 precise fixed-point repairing technology, that is, all suspicious files are directly modified based on the original file of the requesting device. Inconsistencies lead to the user's normal business logic being affected, or even unavailable. At the same time, security operators only need to configure a repair code sequence, and when the file repair device determines a vulnerability, replace the vulnerability with the preset repair code sequence to obtain at least one field group after repair.

步骤S212,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。Step S212, reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file.

本申请上述步骤S212中,由于上述文件修复过程中,文件修复装置将具有第一格式的可疑文件按照各个字段的语法特征拆分为了至少一个字段组,因此在得到修复后的至少一个字段组之后,文件修复装置可以按照其逆过程,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。In the above-mentioned step S212 of the present application, because in the above-mentioned file repairing process, the file repairing device splits the suspicious file with the first format into at least one field group according to the grammatical features of each field, so after obtaining the repaired at least one field group , the file repairing apparatus may follow the reverse process to reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file.

可选地,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件包括:按照修复后的至少一个字段组中各个字段的父子关系,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。Optionally, reorganizing the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file includes: according to the parent-child relationship of each field in the repaired at least one field group, the repaired at least one field group The group is reorganized into a repair file having a first format corresponding to the suspect file.

以文件修复装置为AliYunDun服务器为例,AliYunDun服务器可以将上述可疑文件解析成语法树结构之后,依据token序列特征(令牌序列特征)定位漏洞,进而在语法树中插入了预设的修复代码序列之后,然后重建可疑文件,完成本次可疑文件的漏洞修复,得到上述的修复文件。Take the AliYunDun server as an example for the file repair device. After the AliYunDun server parses the above-mentioned suspicious files into a syntax tree structure, locate the vulnerability according to the token sequence feature (token sequence feature), and then insert a preset repair code sequence into the syntax tree. Afterwards, rebuild the suspicious file, complete the repair of the vulnerability of the suspicious file, and obtain the above-mentioned repaired file.

本申请实施例提供的文件修复方法,由于可疑文件的数量可能成千上万,因此采用上述的文件修复方法整个过程都可以通过程序代码实现自动化,实现整个漏洞修复。从发现,到审核、到修复的全过程自动化,理论上可以实现阿里云全网的用户设备在20分钟内全部修复某一个漏洞。In the file repair method provided by the embodiment of the present application, since the number of suspicious files may be tens of thousands, the entire process of the above file repair method can be automated through program code to realize the entire vulnerability repair. The entire process of automation from discovery to audit to repair can theoretically enable all user devices on the Alibaba Cloud network to repair a certain vulnerability within 20 minutes.

本申请实施例的文件修复方法至少具有以下技术效果:The file restoration method of the embodiment of the present application has at least the following technical effects:

1、精确地针对每个用户的特定业务修复其中的漏洞;1. Fix the loopholes precisely for each user's specific business;

2、漏洞修复全过程自动化,安全运营人员只需要专注于漏洞的研究,并进行一次配置,之后的全网修复动作完全是全自动化;2. The entire process of vulnerability repair is automated. Security operators only need to focus on vulnerability research and perform one configuration. Afterwards, the entire network repair action is fully automated;

3、实现阿里云全网的机器在20分钟内全部修复某一个漏洞;3. Realize that all machines in the Alibaba Cloud network can repair a certain vulnerability within 20 minutes;

4、采用语法树的方式进行漏洞的定位和修复,可以避免正则、字符串搜索带来的误报,具有很高的准确率和很低的误报率;4. Use syntax trees to locate and repair vulnerabilities, which can avoid false positives caused by regular expressions and string searches, and have high accuracy and low false positive rates;

5、不影响请求装置待修复程序的正常运行。5. It does not affect the normal operation of the program to be repaired on the requesting device.

由上可知,本申请上述实施例一所提供的方案,通过按照语法特征对可疑文件进行拆分得到至少一个字段组之后,依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果,进而解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。As can be seen from the above, in the solution provided by the above-mentioned embodiment 1 of the present application, after at least one field group is obtained by splitting suspicious files according to grammatical features, loopholes are searched and repaired according to token sequence features and repair code sequences corresponding to each grammatical feature. Repair achieves the purpose of 1:1 automatic repair of vulnerabilities, thus achieving the technical effect of improving the accuracy of vulnerability repair and system security, and then solving the problem of vulnerability repair caused by the implementation of the same set of Patch codes in the existing technology Technical issues with poor accuracy.

本申请上述实施例提供的一种可选方案中,如图3所示,在可疑文件的数量为至少两个的情况下,上述步骤S202获取请求装置上传的具有第一格式的可疑文件之后,上述步骤S204按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组之前,文件修复方法还可以包括:In an optional solution provided by the above-mentioned embodiments of the present application, as shown in FIG. 3 , when the number of suspicious files is at least two, after the above-mentioned step S202 obtains the suspicious file in the first format uploaded by the requesting device, According to the grammatical features of each field in the suspicious file in the above step S204, before forming fields with the same grammatical features into at least one field group, the file repair method may also include:

步骤S302,提取各个可疑文件的元信息,其中,元信息包括对应可疑文件的文件路径及消息摘要算法MD5,文件路径是指可疑文件在请求装置所在的用户设备上的路径。Step S302, extracting the meta information of each suspicious file, wherein the meta information includes the file path of the corresponding suspicious file and the message digest algorithm MD5, and the file path refers to the path of the suspicious file on the user equipment where the requesting device is located.

本申请上述步骤S302中,文件修复装置获取到的可疑文件的数量可能成千上万,那么其中可能存在一些重复的文件,因此,在可疑文件的数量为至少两个的情况下,文件修复装置可以对可疑文件进行去重处理。In the above step S302 of the present application, the number of suspicious files obtained by the file repairing device may be tens of thousands, and there may be some duplicate files. Therefore, when the number of suspicious files is at least two, the file repairing device Suspicious files can be deduplicated.

那么,在可疑文件的数量为至少两个的情况下,文件修复装置可以提取各个可疑文件的元信息,并将元信息保存到分布式的指纹数据库中。其中,元信息可以包括对应可疑文件的文件路径及MD5(Message Digest Algorithm,消息摘要算法),文件路径是指可疑文件在请求装置所在的用户设备上的路径。Then, when the number of suspicious files is at least two, the file restoration device can extract the meta information of each suspicious file, and save the meta information in the distributed fingerprint database. Wherein, the meta information may include a file path corresponding to the suspicious file and MD5 (Message Digest Algorithm, message digest algorithm). The file path refers to the path of the suspicious file on the user equipment where the requesting device is located.

步骤S304,根据文件路径及MD5,对各个可疑文件进行去重处理。Step S304, according to the file path and MD5, deduplication processing is performed on each suspicious file.

本申请上述步骤S304中,去重处理是指去掉重复的可疑文件。文件修复装置在提取了各个可疑文件的文件路径和MD5之后,可以根据文件路径及MD5判断该各个可疑文件之中是否存在重复的文件,进而对各个可疑文件进行去重处理。In the above step S304 of the present application, de-duplication processing refers to removing duplicate suspicious files. After extracting the file path and MD5 of each suspicious file, the file restoration device can judge whether there are duplicate files in each suspicious file according to the file path and MD5, and then perform deduplication processing on each suspicious file.

本申请上述实施例提供的一种可选方案中,如图4所示,上述步骤S304,根据文件路径及MD5,对各个可疑文件进行去重处理可以包括:In an optional solution provided by the above-mentioned embodiment of the present application, as shown in FIG. 4, the above-mentioned step S304, according to the file path and MD5, performing deduplication processing on each suspicious file may include:

步骤S402,确定各个可疑文件中重复的可疑文件,其中,重复的可疑文件是指文件路径相同且MD5相同的文件。Step S402, determining duplicate suspicious files among the suspicious files, wherein the duplicate suspicious files refer to files with the same file path and the same MD5.

本申请上述步骤S402中,针对如何根据文件路径及MD5,对各个可疑文件进行去重处理,本申请实施例提供的方法为文件修复装置通过判断各个可疑文件的文件路径是否相同,以及各个可疑文件的MD5是否相同,若文件路径相同且MD5相同,则确定为重复的可疑文件。In the above step S402 of this application, for how to deduplicate each suspicious file according to the file path and MD5, the method provided by the embodiment of this application is that the file repair device judges whether the file paths of each suspicious file are the same, and whether each suspicious file Whether the MD5 is the same, if the file path is the same and the MD5 is the same, it is determined to be a duplicate suspicious file.

例如,文件修复装置在提取各个可疑文件的文件路径和MD5之后,判断出可疑文件1、可疑文件7、可疑文件24及可疑文件30的文件路径相同且MD5相同,那么文件修复装置确定该可疑文件1、可疑文件7、可疑文件24及可疑文件30为重复的可疑文件。For example, after the file repairing device extracts the file path and MD5 of each suspicious file, it is judged that the file paths of suspicious file 1, suspicious file 7, suspicious file 24 and suspicious file 30 are the same and the MD5 is the same, then the file repairing device determines that the suspicious file 1. Suspicious file 7, suspicious file 24 and suspicious file 30 are duplicate suspicious files.

步骤S404,保留重复的可疑文件中的第一文件,将除第一文件以外的重复的可疑文件删除,其中,第一文件为重复的可疑文件中的任意一个。Step S404, retaining the first file among the repeated suspicious files, and deleting the repeated suspicious files except the first file, wherein the first file is any one of the repeated suspicious files.

本申请上述步骤S404中,文件修复装置在确定了各个可疑文件中重复的可疑文件之后,需要只保留其中一个可疑文件,删除其他重复的可疑文件以实现去重处理。In the above step S404 of the present application, after the file restoration device determines the duplicate suspicious files among the suspicious files, it needs to keep only one of the suspicious files, and delete other duplicate suspicious files to realize the deduplication process.

例如,文件修复装置在确定了可疑文件1、可疑文件7、可疑文件24及可疑文件30为重复的可疑文件之后,可以保留可疑文件1、可疑文件7、可疑文件24及可疑文件30中的任意一个文件,例如保留可疑文件1,进而将除可疑文件1以外的重复的可疑文件删除,即删除可疑文件7、可疑文件24及可疑文件30,实现对可疑文件的去重处理。For example, after the file recovery device determines that suspicious file 1, suspicious file 7, suspicious file 24 and suspicious file 30 are duplicate suspicious files, any of the suspicious file 1, suspicious file 7, suspicious file 24 and suspicious file 30 can be retained. One file, for example, keep suspicious file 1, and then delete the duplicate suspicious files except suspicious file 1, that is, delete suspicious file 7, suspicious file 24 and suspicious file 30, so as to realize deduplication processing of suspicious files.

本申请上述实施例提供的一种可选方案中,如图5所示,上述步骤S212,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件之后,文件修复方法还可以包括:In an optional solution provided by the above-mentioned embodiment of the present application, as shown in FIG. 5, the above-mentioned step S212, after reorganizing at least one field group after repair into a repair file with the first format corresponding to the suspicious file, the file repair Methods can also include:

步骤S502,接收请求装置发送的第一请求,第一请求用于下载更新后的漏洞修复程序。Step S502, receiving the first request sent by the requesting device, the first request is used for downloading the updated vulnerability repair program.

本申请上述步骤S502中,请求装置根据配置可以定时下载最新的漏洞修复重新,进而,文件修复装置可以接收到请求装置发送的用于下载更新后的漏洞修复程序的第一请求。In the above step S502 of the present application, the requesting device can regularly download the latest bug fix program according to the configuration, and further, the file repair device can receive the first request for downloading the updated bug fix program sent by the request device.

以请求装置为AliYunDun、文件修复装置为AliYunDun服务器为例,AliYunDun基于C/S网络架构,通过加密通道和AliYunDun服务器保持长连接,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新AliVulfix漏洞修复程序。Take AliYunDun as the requesting device and AliYunDun server as the file repairing device as an example. Based on the C/S network architecture, AliYunDun maintains a persistent connection with the AliYunDun server through an encrypted channel. According to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server. .

步骤S504,向请求装置发送更新后的漏洞修复程序,其中,更新后的漏洞修复程序中包含修复文件,以便请求装置根据修复文件对可疑文件进行修复。Step S504, sending the updated vulnerability repair program to the requesting device, wherein the updated vulnerability repair program includes a repair file, so that the requesting device can repair the suspicious file according to the repair file.

本申请上述步骤S504中,文件修复装置在完成对可疑文件的修复之后,会得到一份最新的漏洞修复程序,例如,该漏洞修复程序的形式可以为:{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb34″,″action″:″delete″};{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb55″,″action″:″replace″}。这个最新的漏洞修复程序准确定位到上述的可疑文件的文件路径下,对应MD5的可疑文件,请求装置在下载了该更新后的漏洞修复程序之后,可以根据更新后的漏洞修复程序中包含的上述修复文件,对可疑文件进行修复,例如将可疑文件为上述修复文件。In the above step S504 of the present application, after the file repairing device finishes repairing suspicious files, it will obtain a copy of the latest vulnerability repair program. For example, the form of the vulnerability repair program can be: {"filename":"/webapps/manager /WEB-INF/web.xml", "md5": "bc5ef661b746b0c55462353583a7eb34", "action": "delete"}; {"filename": "/webapps/manager/WEB-INF/web.xml", "md5" : "bc5ef661b746b0c55462353583a7eb55", "action": "replace"}. This latest vulnerability repair program is accurately located under the file path of the above-mentioned suspicious file, corresponding to the suspicious file of MD5, after the requesting device has downloaded the updated vulnerability repair program, it can follow the above-mentioned Repair the file, and repair the suspicious file, for example, convert the suspicious file into the above-mentioned repaired file.

本申请上述实施例提供的一种可选方案中,如图6所示,上述步骤S502,接收请求装置发送的第一请求,第一请求用于下载更新后的漏洞修复程序之前,文件修复方法还可以包括:In an optional solution provided by the above-mentioned embodiment of the present application, as shown in FIG. 6, the above-mentioned step S502 receives the first request sent by the requesting device, and the first request is used to download the updated vulnerability repair program before the file repair method Can also include:

步骤S602,接收来自请求装置发送的第二请求,第二请求用于获取更新后的漏洞修复程序的标识信息。Step S602, receiving a second request from the requesting device, where the second request is used to obtain the identification information of the updated vulnerability repair program.

本申请上述步骤S602中,由于请求装置是根据配置定时下载漏洞修复程序,因此请求装置可以先判断该更新后的漏洞修复程序是否为最新的。In the above step S602 of the present application, since the requesting device regularly downloads the vulnerability repair program according to the configuration, the requesting device may first determine whether the updated vulnerability repair program is the latest.

仍旧以请求装置为AliYunDun、文件修复装置为AliYunDun服务器为例,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新AliVulfix漏洞修复程序,判断是否为最新的标准为,检查保存在AliYunDun服务器的AliVulfix漏洞修复程序的MD5是否和本机之前下载过的AliVulfix漏洞修复程序的MD5是否相同,如果不同,说明AliYunDun服务器进行了修改变动,则重新下载一次最新的AliVulfix漏洞修复程序,替换本地的AliVulfix漏洞修复程序。Still taking AliYunDun as the requesting device and AliYunDun server as the file repairing device, according to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server. Whether the MD5 of the repair program is the same as the MD5 of the AliVulfix vulnerability repair program downloaded on this machine before, if it is different, it means that the AliYunDun server has been modified and changed, and then re-download the latest AliVulfix vulnerability repair program to replace the local AliVulfix vulnerability repair program .

步骤S604,向请求装置发送更新后的漏洞修复程序的MD5,其中,由请求装置根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同,若相同,请求装置则发起第一请求。Step S604, sending the MD5 of the updated vulnerability repair program to the requesting device, wherein the requesting device determines whether the updated vulnerability repair program is the same as the stored vulnerability repair program according to the MD5 of the updated vulnerability repair program, If they are the same, the requesting device initiates a first request.

可选地,请求装置根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同可以包括:请求装置获取已存储的漏洞修复程序的MD5;请求装置判断更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5是否相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5不相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序不相同。Optionally, according to the MD5 of the updated vulnerability repair program, the requesting device determines whether the updated vulnerability repair program is the same as the stored vulnerability repair program may include: the requesting device obtains the MD5 of the stored vulnerability repair program; The device judges whether the MD5 of the updated bug fix program is the same as the MD5 of the stored bug fix program; if the MD5 of the updated bug fix program is the same as the MD5 of the stored bug fix program, then determine the updated bug fix program It is the same as the bug fix program stored on the requesting device; if the MD5 of the updated bug fix program is not the same as the stored bug fix program, it is determined that the updated bug fix program is different from the bug fix program stored on the requesting device. same.

在上述运行环境下,本申请还提供了一种文件修复方法。该文件修复方法可以包括如下实现步骤:Under the above operating environment, the present application also provides a file restoration method. The file repair method may include the following implementation steps:

步骤S10,将具有第一格式的可疑文件发送至文件修复装置,其中,由文件修复装置按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据令牌序列特征,确定至少一个字段组中的漏洞,将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。Step S10, sending the suspicious file in the first format to the file repairing device, wherein the file repairing device forms fields with the same grammatical features into at least one field group according to the grammatical features of each field in the suspicious file, and according to each field group grammatical features, obtain the token sequence features corresponding to each grammatical feature, determine the loopholes in at least one field group according to the token sequence features, replace the loopholes with the preset repair code sequence, and obtain at least one field group after repair, The repaired at least one field group is reorganized into a repaired file having a first format corresponding to the suspicious file.

本申请上述步骤S10中,请求装置可以是指安装在用户设备上的一个应用程序(例如客户端),该请求装置可以根据服务器端的配置,定时启动对用户设备进行扫描,当发现可疑文件时,通过预先配置的通道上传该可疑文件至文件修复装置,请求装置也可以是计算机终端或者类似的运算装置,定时启动对自身磁盘文件进行扫描,当发现可疑文件时,通过预先配置的通道将可疑文件发送给文件修复装置。In the above-mentioned step S10 of the present application, the requesting means may refer to an application program (such as a client) installed on the user equipment. The requesting means may regularly start scanning the user equipment according to the configuration of the server side. When suspicious files are found, Upload the suspicious file to the file repair device through a pre-configured channel. The requesting device can also be a computer terminal or similar computing device, which starts to scan its own disk files at regular intervals. Send to the file recovery device.

步骤S12,从文件修复装置中获取对应于可疑文件的具有第一格式的修复文件。Step S12, obtaining a repair file in the first format corresponding to the suspicious file from the file repair device.

可选地,步骤S12从文件修复装置中获取对应于可疑文件的具有第一格式的修复文件包括:Optionally, step S12 obtaining the repaired file in the first format corresponding to the suspicious file from the file repairing device includes:

步骤S20,向文件修复装置发送第一请求,第一请求用于下载更新后的漏洞修复程序。Step S20, sending a first request to the file repairing device, where the first request is used to download the updated vulnerability repair program.

本申请上述步骤S20中,请求装置根据配置可以定时下载最新的漏洞修复重新,进而,文件修复装置可以接收到请求装置发送的用于下载更新后的漏洞修复程序的第一请求。In the above step S20 of the present application, the requesting device can regularly download the latest vulnerability repairing program according to the configuration, and further, the file repairing device can receive the first request for downloading the updated vulnerability repairing program sent by the requesting device.

以请求装置为AliYunDun、文件修复装置为AliYunDun服务器为例,AliYunDun基于C/S网络架构,通过加密通道和AliYunDun服务器保持长连接,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新AliVulfix漏洞修复程序。Take AliYunDun as the requesting device and AliYunDun server as the file repairing device as an example. Based on the C/S network architecture, AliYunDun maintains a persistent connection with the AliYunDun server through an encrypted channel. According to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server. .

步骤S22,接收文件修复装置返回的更新后的漏洞修复程序,其中,更新后的漏洞修复程序中包含修复文件。Step S22, receiving the updated vulnerability repair program returned by the file repair device, wherein the updated vulnerability repair program includes the repair file.

本申请上述步骤S22中,文件修复装置在完成对可疑文件的修复之后,会得到一份最新的漏洞修复程序,例如,该漏洞修复程序的形式可以为:{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb34″,″action″:″delete″};{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb55″,″action″:″replace″}。这个最新的漏洞修复程序准确定位到上述的可疑文件的文件路径下,对应MD5的可疑文件,请求装置在下载了该更新后的漏洞修复程序之后,可以根据更新后的漏洞修复程序中包含的上述修复文件,对可疑文件进行修复,例如将可疑文件为上述修复文件。In the above-mentioned step S22 of the present application, after the file repairing device finishes repairing suspicious files, it will obtain a copy of the latest vulnerability repair program. For example, the form of the vulnerability repair program can be: {"filename":"/webapps/manager /WEB-INF/web.xml", "md5": "bc5ef661b746b0c55462353583a7eb34", "action": "delete"}; {"filename": "/webapps/manager/WEB-INF/web.xml", "md5" : "bc5ef661b746b0c55462353583a7eb55", "action": "replace"}. This latest vulnerability repair program is accurately located under the file path of the above-mentioned suspicious file, corresponding to the suspicious file of MD5, after the requesting device has downloaded the updated vulnerability repair program, it can follow the above-mentioned Repair the file, and repair the suspicious file, for example, convert the suspicious file into the above-mentioned repaired file.

可选地,在步骤S20,向文件修复装置发送第一请求之前,文件修复方法还包括:Optionally, in step S20, before sending the first request to the file repair device, the file repair method further includes:

步骤S30,向文件修复装置发送第二请求,第二请求用于获取更新后的漏洞修复程序的标识信息。Step S30, sending a second request to the file repairing device, where the second request is used to acquire the identification information of the updated vulnerability repair program.

本申请上述步骤S30中,由于请求装置是根据配置定时下载漏洞修复程序,因此请求装置可以先判断该更新后的漏洞修复程序是否为最新的。In the above step S30 of the present application, since the requesting device regularly downloads the vulnerability repair program according to the configuration, the requesting device may first determine whether the updated vulnerability repair program is the latest.

仍旧以请求装置为AliYunDun、文件修复装置为AliYunDun服务器为例,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新AliVulfix漏洞修复程序,判断是否为最新的标准为,检查保存在AliYunDun服务器的AliVulfix漏洞修复程序的MD5是否和本机之前下载过的AliVulfix漏洞修复程序的MD5是否相同,如果不同,说明AliYunDun服务器进行了修改变动,则重新下载一次最新的AliVulfix漏洞修复程序,替换本地的AliVulfix漏洞修复程序。Still taking AliYunDun as the requesting device and AliYunDun server as the file repairing device, according to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server. Whether the MD5 of the repair program is the same as the MD5 of the AliVulfix vulnerability repair program downloaded on this machine before, if it is different, it means that the AliYunDun server has been modified and changed, and then re-download the latest AliVulfix vulnerability repair program to replace the local AliVulfix vulnerability repair program .

步骤S32,接收文件修复装置返回的更新后的漏洞修复程序的MD5。Step S32, receiving the MD5 of the updated vulnerability repair program returned by the file repair device.

步骤S34,根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同,若相同,请求装置则发起第一请求。Step S34, according to the MD5 of the updated bug fix program, it is judged whether the updated bug fix program is the same as the bug fix program stored in the requesting device, and if they are the same, the request device initiates a first request.

可选地,请求装置根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同可以包括:请求装置获取已存储的漏洞修复程序的MD5;请求装置判断更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5是否相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5不相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序不相同。Optionally, according to the MD5 of the updated vulnerability repair program, the requesting device determines whether the updated vulnerability repair program is the same as the stored vulnerability repair program may include: the requesting device obtains the MD5 of the stored vulnerability repair program; The device judges whether the MD5 of the updated bug fix program is the same as the MD5 of the stored bug fix program; if the MD5 of the updated bug fix program is the same as the MD5 of the stored bug fix program, then determine the updated bug fix program It is the same as the bug fix program stored on the requesting device; if the MD5 of the updated bug fix program is not the same as the stored bug fix program, it is determined that the updated bug fix program is different from the bug fix program stored on the requesting device. same.

在一种可选的方案中,以AliYunDun为例,结合图7,对本申请上述文件修复方法进行描述:In an optional solution, taking AliYunDun as an example, in combination with Figure 7, the above-mentioned file repair method of this application is described:

步骤A,AliYunDun基于C/S的网络架构,每台用户设备上都部署有一个独立的AliYunDun程序,并通过加密通道和AliYunDun服务器保持长连接。Step A, AliYunDun is based on C/S network architecture, each user device is deployed with an independent AliYunDun program, and maintains a long-term connection with the AliYunDun server through an encrypted channel.

本申请上述步骤A中,AliYunDun相当于上述的请求装置,AliYunDun服务器相当于上述的文件修复装置,请求装置可以根据服务器端的配置,定时启动对用户设备进行扫描,当发现可疑文件时,通过预先配置的通道上传该可疑文件。In the above step A of this application, AliYunDun is equivalent to the above-mentioned requesting device, and the AliYunDun server is equivalent to the above-mentioned file repairing device. The requesting device can regularly start scanning the user equipment according to the configuration on the server side. channel to upload the suspicious file.

步骤B,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新的AliVulfix漏洞修复程序。Step B, according to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server.

本申请上述步骤B中,判断是否为最新的标准为,检查保存在AliYunDun服务器的AliVulfix漏洞修复程序的MD5是否和本机之前下载过的AliVulfix漏洞修复程序的MD5是否相同,如果不同,说明AliYunDun服务器进行了修改变动,则重新下载一次最新的AliVulfix漏洞修复程序,替换本地的AliVulfix漏洞修复程序。In the above step B of this application, the criterion for judging whether it is the latest is to check whether the MD5 of the AliVulfix vulnerability repair program saved on the AliYunDun server is the same as the MD5 of the AliVulfix vulnerability repair program downloaded before on this machine. If they are different, it means that the AliYunDun server If a modification is made, re-download the latest AliVulfix vulnerability fix program to replace the local AliVulfix vulnerability fix program.

由于请求装置是根据配置定时下载漏洞修复程序,因此请求装置可以先判断该更新后的漏洞修复程序是否为最新的,请求装置根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同可以包括:请求装置获取已存储的漏洞修复程序的MD5;请求装置判断更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5是否相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5不相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序不相同。Since the requesting device regularly downloads the vulnerability repair program according to the configuration, the requesting device can first determine whether the updated vulnerability repair program is the latest, and the requesting device judges the updated vulnerability repair program and Whether the stored vulnerability repair program of the requesting device is the same may include: the requesting device obtains the MD5 of the stored vulnerability repair program; the requesting device judges whether the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program; If the MD5 of the updated bug fix program is the same as the stored bug fix program, it is determined that the updated bug fix program is the same as the stored bug fix program; if the updated bug fix program’s MD5 is the same as the stored bug fix program If the MD5 of the bug fix program is different, it is determined that the updated bug fix program is different from the bug fix program stored in the requesting device.

在确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序不相同时,文件修复装置可以接收到请求装置发送的用于下载更新后的漏洞修复程序的第一请求,并向请求装置发送更新后的漏洞修复程序,其中,更新后的漏洞修复程序中包含修复文件,以便请求装置根据修复文件对可疑文件进行修复。When it is determined that the updated vulnerability repair program is different from the stored vulnerability repair program of the requesting device, the file repair device may receive the first request for downloading the updated vulnerability repair program sent by the requesting device, and send a request to the requesting device The updated vulnerability repair program, wherein the updated vulnerability repair program includes a repair file, so that the requesting device can repair the suspicious file according to the repair file.

步骤C,根据AliYunDun服务器的配置,用户设备上的AliVulfix漏洞修复程序会定时启动执行。Step C, according to the configuration of the AliYunDun server, the AliVulfix vulnerability repair program on the user device will be started and executed regularly.

本申请上述步骤C中,AliYunDun可以根据服务器端的配置,定时启动对用户设备进行扫描,当发现可疑文件时,通过预先配置的通道上传该可疑文件。In the above step C of this application, AliYunDun can regularly start scanning the user equipment according to the configuration of the server, and upload the suspicious file through the pre-configured channel when a suspicious file is found.

步骤D,AliVulfix对用户机器上的所有磁盘目录进行全盘遍历扫描。Step D, AliVulfix performs a full-disk traversal scan on all disk directories on the user's machine.

本申请上述步骤D中,根据AliYunDun服务器下发的配置信息收取指定目录的文件,例如配置项有一条为:/plus/mytag_js.php,则AliVulfix会扫描并通过AliYunDun的加密通过上报这个可疑文件。In the above step D of this application, the file in the specified directory is collected according to the configuration information issued by the AliYunDun server. For example, if there is a configuration item: /plus/mytag_js.php, then AliVulfix will scan and report this suspicious file through the encryption of AliYunDun.

步骤E,AliYunDun服务器收到AliYunDun上报的可疑文件后,提取可疑文件的元信息。In step E, the AliYunDun server extracts the meta information of the suspicious file after receiving the suspicious file reported by AliYunDun.

本申请上述步骤E中,文件修复装置获取到的可疑文件的数量可能成千上万,那么其中可能存在一些重复的文件,因此,在可疑文件的数量为至少两个的情况下,文件修复装置可以对可疑文件进行去重处理。那么,在可疑文件的数量为至少两个的情况下,文件修复装置可以提取各个可疑文件的元信息,并将元信息保存到分布式的指纹数据库中。其中,元信息可以包括对应可疑文件的文件路径及MD5,文件路径是指可疑文件在请求装置所在的用户设备上的路径。In the above step E of the present application, the number of suspicious files obtained by the file repairing device may be tens of thousands, and there may be some duplicate files. Therefore, when the number of suspicious files is at least two, the file repairing device Suspicious files can be deduplicated. Then, when the number of suspicious files is at least two, the file restoration device can extract the meta information of each suspicious file, and save the meta information in the distributed fingerprint database. Wherein, the meta information may include the file path and MD5 corresponding to the suspicious file, and the file path refers to the path of the suspicious file on the user equipment where the requesting device is located.

去重处理是指去掉重复的可疑文件。文件修复装置在提取了各个可疑文件的文件路径和MD5之后,可以根据文件路径及MD5判断该各个可疑文件之中是否存在重复的文件,进而对各个可疑文件进行去重处理。针对如何根据文件路径及MD5,对各个可疑文件进行去重处理,本申请实施例提供的方法为文件修复装置通过判断各个可疑文件的文件路径是否相同,以及各个可疑文件的MD5是否相同,若文件路径相同且MD5相同,则确定为重复的可疑文件。De-duplication processing refers to the removal of duplicate suspicious files. After extracting the file path and MD5 of each suspicious file, the file restoration device can judge whether there are duplicate files in each suspicious file according to the file path and MD5, and then perform deduplication processing on each suspicious file. For how to deduplicate each suspicious file according to the file path and MD5, the method provided by the embodiment of the present application is that the file restoration device judges whether the file path of each suspicious file is the same, and whether the MD5 of each suspicious file is the same, if the file If the path is the same and the MD5 is the same, it is determined to be a duplicate suspicious file.

例如,文件修复装置在提取各个可疑文件的文件路径和MD5之后,判断出可疑文件1、可疑文件7、可疑文件24及可疑文件30的文件路径相同且MD5相同,那么文件修复装置确定该可疑文件1、可疑文件7、可疑文件24及可疑文件30为重复的可疑文件。For example, after the file repairing device extracts the file path and MD5 of each suspicious file, it is judged that the file paths of suspicious file 1, suspicious file 7, suspicious file 24 and suspicious file 30 are the same and the MD5 is the same, then the file repairing device determines that the suspicious file 1. Suspicious file 7, suspicious file 24 and suspicious file 30 are duplicate suspicious files.

可选地,文件修复装置在确定了各个可疑文件中重复的可疑文件之后,需要只保留其中一个可疑文件,删除其他重复的可疑文件以实现去重处理。Optionally, after the file repairing device determines the duplicate suspicious files among the suspicious files, it needs to keep only one of the suspicious files, and delete other duplicate suspicious files to realize deduplication processing.

例如,文件修复装置在确定了可疑文件1、可疑文件7、可疑文件24及可疑文件30为重复的可疑文件之后,可以保留可疑文件1、可疑文件7、可疑文件24及可疑文件30中的任意一个文件,例如保留可疑文件1,进而将除可疑文件1以外的重复的可疑文件删除,即删除可疑文件7、可疑文件24及可疑文件30,实现对可疑文件的去重处理。For example, after the file recovery device determines that suspicious file 1, suspicious file 7, suspicious file 24 and suspicious file 30 are duplicate suspicious files, any of the suspicious file 1, suspicious file 7, suspicious file 24 and suspicious file 30 can be retained. One file, for example, keep suspicious file 1, and then delete the duplicate suspicious files except suspicious file 1, that is, delete suspicious file 7, suspicious file 24 and suspicious file 30, so as to realize deduplication processing of suspicious files.

可选地,AliYunDun服务器在提取了可疑文件的元信息之后,可以将元信息保存到分布式的指纹数据库中。Optionally, after the AliYunDun server extracts the meta information of the suspicious file, it can store the meta information in a distributed fingerprint database.

步骤F,把可疑文件解析成token语法树结构。In step F, the suspicious file is parsed into a token syntax tree structure.

本申请上述步骤F中,因为阿里云上用户大部分是电商、网站用户,用户常常有对自己网站代码文件做定制化修改的情况,为了保证漏洞修复不影响这些用户网站的正常运行,AliYunDun服务器采取了一对一针对性修复的策略,然而,一对一修复会产生一个问题,采用1∶1修复后,在阿里云数十万体量的用户数下,在服务器端会收到大量的存在漏洞的文件,即使进行过滤,文件数量还是很多,因此,AliYunDun服务器可以将上述可疑文件解析成语法树结构。In the above step F of this application, because most of the users on Alibaba Cloud are e-commerce and website users, users often make customized modifications to their own website code files. The server adopts a one-to-one targeted repair strategy. However, one-to-one repair will cause a problem. After the 1:1 repair is adopted, the server will receive a large number of There are still a lot of files with loopholes even after filtering. Therefore, the AliYunDun server can parse the above suspicious files into a syntax tree structure.

本申请实施例中,文件修复装置首先要对可疑文件进行语法分析,确定可疑文件中各个字段的语法特征,其中,语法分析指的是将代码扫描到一个容器中,然后对该容器中的字符在词法分析的基础上将字段组合成各类语法短语。在确定了各个字段的语法特征之后,文件修复装置可以将语法特征相同的字段组成至少一个字段组,进一步地,文件修复装置可以依据各个字段之间的父子关系,将至少一个字段组解析为语法树结构。In the embodiment of the present application, the file repairing device first needs to perform grammatical analysis on the suspicious file to determine the grammatical features of each field in the suspicious file, wherein the grammatical analysis refers to scanning the code into a container, and then the characters in the container Combining fields into various grammatical phrases based on lexical analysis. After determining the grammatical features of each field, the file repairing device can form at least one field group with fields with the same grammatical feature, and further, the file repairing device can parse at least one field group into a grammatical tree structure.

步骤G,安全运营人员只需要配置一次token序列特征,用于定位文件中存在的漏洞。In step G, the security operation personnel only need to configure the token sequence feature once to locate the loopholes in the file.

本申请上述步骤G中,token序列特征相当于上述的令牌序列特征,令牌序列特征可以是由安全运营人员预先配置的,文件修复装置利用对应于各个语法特征的令牌序列特征,实现漏洞的查找。In the above step G of this application, the token sequence feature is equivalent to the above-mentioned token sequence feature, and the token sequence feature can be pre-configured by the security operator, and the file repair device uses the token sequence feature corresponding to each grammatical feature to realize the loophole lookup.

文件修复装置在获取到各个语法特征对应的令牌序列特征之后,可以依据令牌序列特征在至少一个字段组中进行漏洞的定位。After obtaining the token sequence features corresponding to each grammatical feature, the file repairing device can locate vulnerabilities in at least one field group according to the token sequence features.

此处以通俗的例子来说明,假如有一百个人,目的是确定眼球颜色蓝色的人,即令牌序列特征是“眼球-蓝色”,那么按照本申请实施例提供的文件修复方法的思路,我们先将这一百个人的各个部分进行分组,例如,将一百个人的眼睛分为一组、鼻子分为一组、嘴巴分为一组等等,那么,在根据令牌序列特征进行漏洞查找时,只需要在眼睛这一组中进行查找,无需再搜索其他部分,达到提高漏洞查找效率的目的。Here is a popular example to illustrate, if there are one hundred people, the purpose is to determine the person whose eyeball color is blue, that is, the token sequence feature is "eyeball-blue", then follow the idea of the file restoration method provided by the embodiment of this application , we first group the various parts of the one hundred people, for example, the eyes of one hundred people are grouped into one group, the nose is grouped into one group, the mouth is grouped into one group, etc., then, according to the token sequence feature When searching for vulnerabilities, you only need to search in the eye group, without searching other parts, so as to improve the efficiency of finding vulnerabilities.

可选地,依据令牌序列特征,确定至少一个字段组中的漏洞包括:在至少一个字段组中查找与令牌序列特征相同的字段,将与令牌序列特征相同的字段确定为漏洞。Optionally, according to the token sequence feature, determining the loophole in at least one field group includes: searching for fields identical to the token sequence feature in at least one field group, and determining the same field as the token sequence feature as a loophole.

本申请实施例中,安全运营人员只需配置一次上述令牌序列特征,文件修复装置则可以自动化进行漏洞的定位,提高了安全运营的时间成本。In the embodiment of this application, the security operation personnel only need to configure the above-mentioned token sequence feature once, and the file repair device can automatically locate the vulnerability, which improves the time cost of security operation.

步骤H,安全运营人员同时只需要配置一个patch token序列,用于在定位漏洞后插入patch token序列。In step H, the security operation personnel only need to configure a patch token sequence at the same time, which is used to insert the patch token sequence after locating the vulnerability.

本申请上述步骤H中,patch token序列相当于上述的预设的修复代码序列。预设的修复代码序列也可以是安全运营人员预先配置的。文件修复装置在依据令牌序列特征,确定至少一个字段组中的漏洞之后,可以获取该预设的修复代码序列,进而,将漏洞替换为该预设的修复代码序列,实现可疑文件的修复。In the above step H of this application, the patch token sequence is equivalent to the above-mentioned preset repair code sequence. Preset repair code sequences may also be preconfigured by security operations personnel. After the file repairing device determines the loophole in at least one field group according to the characteristics of the token sequence, it can obtain the preset repair code sequence, and then replace the loophole with the preset repair code sequence to realize the repair of the suspicious file.

本申请实施例的文件修复装置采用的1∶1的精确定点修复技术,即所有的可疑文件都直接基于请求装置原始文件进行针对性的修改,这样可以最大程度地避免因为漏洞修复造成代码逻辑的不一致从而导致用户的正常业务逻辑受到影响,甚至不可用。同时,安全运营人员只需要配置一个修复代码序列,在文件修复装置确定漏洞时,将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组。The file repairing device in the embodiment of the present application adopts the 1:1 precise fixed-point repairing technology, that is, all suspicious files are directly modified based on the original file of the requesting device. Inconsistencies lead to the user's normal business logic being affected, or even unavailable. At the same time, security operators only need to configure a repair code sequence, and when the file repair device determines a vulnerability, replace the vulnerability with the preset repair code sequence to obtain at least one field group after repair.

步骤I,在token语法树中插入了patch token序列之后,然后重建可疑文件,完成本次文件的漏洞修复。Step I, after inserting the patch token sequence in the token syntax tree, rebuild the suspicious file, and complete the vulnerability repair of this file.

本申请上述步骤I中,AliYunDun服务器可以将上述可疑文件解析成语法树结构之后,依据token序列特征(令牌序列特征)定位漏洞,进而在语法树中插入了预设的修复代码序列之后,然后重建可疑文件,完成本次可疑文件的漏洞修复,得到上述的修复文件。In the above step I of this application, after the AliYunDun server can parse the suspicious file into a syntax tree structure, locate the vulnerability according to the token sequence feature (token sequence feature), and then insert a preset repair code sequence in the syntax tree, and then Rebuild the suspicious file, complete the vulnerability repair of the suspicious file, and obtain the above-mentioned repaired file.

由于上述文件修复过程中,文件修复装置将具有第一格式的可疑文件按照各个字段的语法特征拆分为了至少一个字段组,因此在得到修复后的至少一个字段组之后,文件修复装置可以按照其逆过程,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。In the above-mentioned file repair process, the file repair device splits the suspicious file with the first format into at least one field group according to the grammatical features of each field, so after obtaining the repaired at least one field group, the file repair device can be used according to its Reversing the process, reorganizing at least one repaired field group into a repaired file in the first format corresponding to the suspicious file.

可选地,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件包括:按照修复后的至少一个字段组中各个字段的父子关系,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。Optionally, reorganizing the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file includes: according to the parent-child relationship of each field in the repaired at least one field group, the repaired at least one field group The group is reorganized into a repair file having a first format corresponding to the suspect file.

步骤J,完成可疑文件审核之后,在AliYunDun服务器就会得到一份最新的漏洞修复程序。Step J, after completing the review of suspicious files, the AliYunDun server will get a copy of the latest vulnerability repair program.

本申请上述步骤J中,文件修复装置在完成对可疑文件的修复之后,会得到一份最新的漏洞修复程序,例如,该漏洞修复程序的形式可以为:{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb34″,″action″:″delete″};{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb55″,″action″:″replace″}。这个最新的漏洞修复程序准确定位到上述的可疑文件的文件路径下,对应MD5的可疑文件,请求装置在下载了该更新后的漏洞修复程序之后,可以根据更新后的漏洞修复程序中包含的上述修复文件,对可疑文件进行修复,例如将可疑文件为上述修复文件。In the above step J of the present application, after the file repairing device finishes repairing suspicious files, it will obtain a copy of the latest vulnerability repair program. For example, the form of the vulnerability repair program can be: {"filename":"/webapps/manager /WEB-INF/web.xml", "md5": "bc5ef661b746b0c55462353583a7eb34", "action": "delete"}; {"filename": "/webapps/manager/WEB-INF/web.xml", "md5" : "bc5ef661b746b0c55462353583a7eb55", "action": "replace"}. This latest vulnerability repair program is accurately located under the file path of the above-mentioned suspicious file, corresponding to the suspicious file of MD5, after the requesting device has downloaded the updated vulnerability repair program, it can follow the above-mentioned Repair the file, and repair the suspicious file, for example, convert the suspicious file into the above-mentioned repaired file.

步骤K,AliVulfix的每次定时启动运行的时候,会从AliYunDun服务器拉取最新的漏洞规则库文件,并在全盘扫描的时候对本机上对应匹配到的文件进行修复操作(包括删除、替换操作)。Step K, AliVulfix will pull the latest vulnerability rule base file from the AliYunDun server every time it starts running regularly, and perform repair operations (including deletion and replacement operations) on the corresponding matched files on the local machine during the full scan.

步骤L,完成对阿里云用户网站脚本的漏洞修复。Step L, complete the vulnerability repair of the Alibaba Cloud user website script.

本申请上述步骤L中,AliYunDun服务器从AliYunDun收取用户设备上的真实CMS漏洞文件(即可疑文件),并进行一对一的针对性修复,最大限度的保证了修复后和修复前的业务兼容性,不至于发生因为漏洞修复导致网站业务不可用;在AliYunDun服务器采取了自动化审核、以及基于Token语法树自动文件修复方式,极大提高的处理速度;AliYunDun基于文件路径、MD5定位可疑文件,避免因为出现误操作,对用户的网站造成影响。In the above step L of this application, the AliYunDun server receives the real CMS vulnerability files (that is, suspicious files) on the user's device from AliYunDun, and performs one-to-one targeted repair, which ensures the business compatibility after repair and before repair to the greatest extent. , so that the website business will not be unavailable due to vulnerability repair; the AliYunDun server adopts automatic auditing and automatic file repair based on the Token syntax tree, which greatly improves the processing speed; AliYunDun locates suspicious files based on file paths and MD5 to avoid Misoperation occurs and affects the user's website.

本申请实施例的文件修复方法至少具有以下技术效果:The file restoration method of the embodiment of the present application has at least the following technical effects:

1、精确地针对每个用户的特定业务修复其中的漏洞;1. Fix the loopholes precisely for each user's specific business;

2、漏洞修复全过程自动化,安全运营人员只需要专注于漏洞的研究,并进行一次配置,之后的全网修复动作完全是全自动化;2. The entire process of vulnerability repair is automated. Security operators only need to focus on vulnerability research and perform one configuration. Afterwards, the entire network repair action is fully automated;

3、实现阿里云全网的机器在20分钟内全部修复某一个漏洞;3. Realize that all machines in the Alibaba Cloud network can repair a certain vulnerability within 20 minutes;

4、采用语法树的方式进行漏洞的定位和修复,可以避免正则、字符串搜索带来的误报,具有很高的准确率和很低的误报率。4. Using syntax trees to locate and repair vulnerabilities can avoid false positives caused by regular expressions and string searches, with high accuracy and low false positive rates.

由上可知,本申请上述实施例一所提供的方案,通过按照语法特征对可疑文件进行拆分得到至少一个字段组之后,依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果,进而解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。As can be seen from the above, in the solution provided by the above-mentioned embodiment 1 of the present application, after at least one field group is obtained by splitting suspicious files according to grammatical features, loopholes are searched and repaired according to token sequence features and repair code sequences corresponding to each grammatical feature. Repair achieves the purpose of 1:1 automatic repair of vulnerabilities, thus achieving the technical effect of improving the accuracy of vulnerability repair and system security, and then solving the problem of vulnerability repair caused by the implementation of the same set of Patch codes in the existing technology Technical issues with poor accuracy.

由此可知,现有技术存在的采用同一套Patch代码实行造成的漏洞修复准确性较差的问题,本申请提出一种基于语法特征对可疑文件的字段进行拆分的方法,进而依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果。It can be seen from this that there is a problem in the prior art that the accuracy of vulnerability repair caused by the implementation of the same set of Patch codes is poor. This application proposes a method for splitting the fields of suspicious files based on grammatical features, and then according to each grammatical feature Corresponding to the token sequence features and the repair code sequence, the loopholes are searched and repaired, and the purpose of 1:1 automatic repair of the loopholes is achieved, thereby achieving the technical effect of improving the accuracy of the loophole patching and system security.

需要说明的是,对于前述的各方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本申请并不受所描述的动作顺序的限制,因为依据本申请,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作和模块并不一定是本申请所必须的。It should be noted that for the foregoing method embodiments, for the sake of simple description, they are expressed as a series of action combinations, but those skilled in the art should know that the present application is not limited by the described action sequence. Depending on the application, certain steps may be performed in other orders or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification belong to preferred embodiments, and the actions and modules involved are not necessarily required by this application.

通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到根据上述实施例的方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,或者网络设备等)执行本申请各个实施例所述的方法。Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general-purpose hardware platform, and of course also by hardware, but in many cases the former is better implementation. Based on such an understanding, the technical solution of the present application can be embodied in the form of a software product in essence or the part that contributes to the prior art, and the computer software product is stored in a storage medium (such as ROM/RAM, disk, CD) contains several instructions to enable a terminal device (which may be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present application.

实施例2Example 2

根据本申请实施例,还提供了一种用于实施上述方法实施例的装置实施例,如图8所示,该装置包括:According to the embodiment of the present application, a device embodiment for implementing the above method embodiment is also provided. As shown in FIG. 8, the device includes:

图8是根据本申请实施例的文件修复装置的结构示意图。Fig. 8 is a schematic structural diagram of a file restoration device according to an embodiment of the present application.

如图8所示,该文件修复装置可以包括获取单元802、处理单元804、第一确定单元806、第二确定单元808、修复单元810以及重组单元812。As shown in FIG. 8 , the apparatus for repairing a file may include an acquiring unit 802 , a processing unit 804 , a first determining unit 806 , a second determining unit 808 , a repairing unit 810 and a reorganizing unit 812 .

其中,获取单元802,用于获取请求装置上传的具有第一格式的可疑文件;处理单元804,用于按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;第一确定单元806,用于根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;第二确定单元808,用于依据所述令牌序列特征,确定所述至少一个字段组中的漏洞;修复单元810,用于将所述漏洞替换为预先配置的修复代码序列,得到修复后的所述至少一个字段组;重组单元812,用于将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。Wherein, the obtaining unit 802 is used to obtain the suspicious file with the first format uploaded by the requesting device; the processing unit 804 is used to combine the fields with the same grammatical characteristics into at least one field group according to the grammatical characteristics of each field in the suspicious file ; The first determining unit 806 is used to obtain the token sequence features corresponding to each grammatical feature according to the grammatical features of each field group; the second determining unit 808 is used to determine the at least one The loophole in the field group; the repairing unit 810 is used to replace the loophole with a pre-configured repair code sequence to obtain the repaired at least one field group; the reorganization unit 812 is used to replace the repaired at least one field group A field group is reorganized into a repair file having the first format corresponding to the suspect file.

由上可知,本申请上述实施例一所提供的方案,通过按照语法特征对可疑文件进行拆分得到至少一个字段组之后,依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果,进而解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。As can be seen from the above, in the solution provided by the above-mentioned embodiment 1 of the present application, after at least one field group is obtained by splitting suspicious files according to grammatical features, loopholes are searched and repaired according to token sequence features and repair code sequences corresponding to each grammatical feature. Repair achieves the purpose of 1:1 automatic repair of vulnerabilities, thus achieving the technical effect of improving the accuracy of vulnerability repair and system security, and then solving the problem of vulnerability repair caused by the implementation of the same set of Patch codes in the existing technology Technical issues with poor accuracy.

此处需要说明的是,上述获取单元802、处理单元804、第一确定单元806、第二确定单元808、修复单元810以及重组单元812对应于实施例一中的步骤S202至步骤S212,六个模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the acquisition unit 802, processing unit 804, first determination unit 806, second determination unit 808, repair unit 810, and reorganization unit 812 correspond to Step S202 to Step S212 in Embodiment 1, six The examples and application scenarios implemented by the modules and corresponding steps are the same, but are not limited to the content disclosed in the first embodiment above. It should be noted that, as a part of the device, the above-mentioned modules can run in the computer terminal 10 provided in Embodiment 1, and can be realized by software or by hardware.

可选地,如图9所示,文件修复装置还可以包括:提取单元902和去重单元904。Optionally, as shown in FIG. 9 , the file restoration apparatus may further include: an extraction unit 902 and a deduplication unit 904 .

其中,提取单元902,用于提取各个可疑文件的元信息,其中,所述元信息包括对应可疑文件的文件路径及消息摘要算法MD5,所述文件路径是指所述可疑文件在所述请求装置所在的用户设备上的路径;去重单元904,用于根据所述文件路径及所述MD5,对所述各个可疑文件进行去重处理。Wherein, the extracting unit 902 is used to extract the meta-information of each suspicious file, wherein the meta-information includes the file path corresponding to the suspicious file and the message digest algorithm MD5, and the file path refers to the file path of the suspicious file in the requesting device The path on the user equipment where it is located; the deduplication unit 904 is configured to perform deduplication processing on each suspicious file according to the file path and the MD5.

此处需要说明的是,上述提取单元902和去重单元904对应于实施例一中的步骤S302至步骤S304,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the above-mentioned extraction unit 902 and deduplication unit 904 correspond to steps S302 to S304 in the first embodiment, and the examples and application scenarios implemented by this module are the same as those of the corresponding steps, but are not limited to the above-mentioned embodiment a public content. It should be noted that, as a part of the device, the above-mentioned modules can run in the computer terminal 10 provided in Embodiment 1, and can be realized by software or by hardware.

可选地,如图10所示,去重单元904可以包括:确定模块1002和处理模块1004。Optionally, as shown in FIG. 10 , the deduplication unit 904 may include: a determining module 1002 and a processing module 1004 .

其中,确定模块1002,用于确定所述各个可疑文件中重复的可疑文件,其中,所述重复的可疑文件是指所述文件路径相同且所述MD5相同的文件;处理模块1004,用于保留所述重复的可疑文件中的第一文件,将除所述第一文件以外的所述重复的可疑文件删除,其中,所述第一文件为所述重复的可疑文件中的任意一个。Wherein, the determination module 1002 is used to determine the repeated suspicious files among the suspicious files, wherein the repeated suspicious files refer to files with the same file path and the same MD5; the processing module 1004 is used to retain The first file among the repeated suspicious files is to delete the repeated suspicious files except the first file, wherein the first file is any one of the repeated suspicious files.

此处需要说明的是,上述确定模块1002和处理模块1004对应于实施例一中的步骤S402至步骤S404,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the determination module 1002 and the processing module 1004 above correspond to steps S402 to S404 in the first embodiment, and the examples and application scenarios implemented by this module are the same as those of the corresponding steps, but are not limited to the first embodiment above What is disclosed. It should be noted that, as a part of the device, the above-mentioned modules can run in the computer terminal 10 provided in Embodiment 1, and can be realized by software or by hardware.

可选地,所述第一确定单元806用于执行以下步骤依据所述令牌序列特征,确定所述至少一个字段组中的漏洞:在所述至少一个字段组中查找与所述令牌序列特征相同的字段,将所述与所述令牌序列特征相同的字段确定为所述漏洞。Optionally, the first determining unit 806 is configured to perform the following steps to determine the loopholes in the at least one field group according to the characteristics of the token sequence: search for The field with the same feature as the token sequence is determined as the vulnerability.

可选地,所述重组单元812用于执行以下步骤将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件:按照所述修复后的所述至少一个字段组中各个字段的父子关系,将所述修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。Optionally, the reorganization unit 812 is configured to perform the following steps to reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file: according to the repaired the parent-child relationship of each field in the at least one field group, and reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file.

可选地,如图11所示,文件修复装置还可以包括:第一接收单元1102和第一发送单元1104。Optionally, as shown in FIG. 11 , the file restoration apparatus may further include: a first receiving unit 1102 and a first sending unit 1104 .

其中,第一接收单元1102,用于接收所述请求装置发送的第一请求,所述第一请求用于下载更新后的漏洞修复程序;第一发送单元1104,用于向所述请求装置发送所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件,以便所述请求装置根据所述修复文件对所述可疑文件进行修复。Wherein, the first receiving unit 1102 is used to receive the first request sent by the requesting device, and the first request is used to download the updated vulnerability repair program; the first sending unit 1104 is used to send the request to the requesting device The updated vulnerability repair program, wherein the updated vulnerability repair program includes the repair file, so that the requesting device can repair the suspicious file according to the repair file.

此处需要说明的是,上述第一接收单元1102和第一发送单元1104对应于实施例一中的步骤S502至步骤S504,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the above-mentioned first receiving unit 1102 and first sending unit 1104 correspond to Step S502 to Step S504 in Embodiment 1, and the examples and application scenarios implemented by this module are the same as those of the corresponding steps, but are not limited to The content disclosed in the first embodiment above. It should be noted that, as a part of the device, the above-mentioned modules can run in the computer terminal 10 provided in Embodiment 1, and can be realized by software or by hardware.

可选地,如图12所示,文件修复装置还可以包括:第二接收单元1202和第二发送单元1204。Optionally, as shown in FIG. 12 , the file repairing apparatus may further include: a second receiving unit 1202 and a second sending unit 1204 .

其中,第二接收单元1202,用于接收来自所述请求装置发送的第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;第二发送单元1204,用于向所述请求装置发送所述更新后的漏洞修复程序的MD5,其中,由所述请求装置根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。Wherein, the second receiving unit 1202 is configured to receive a second request sent from the requesting device, and the second request is used to obtain the identification information of the updated vulnerability repair program; the second sending unit 1204 is configured to sending the MD5 of the updated vulnerability repair program to the requesting device, wherein the requesting device judges that the updated vulnerability repair program is compatible with the requesting device according to the MD5 of the updated vulnerability repair program Whether the stored vulnerability repair programs are the same, if they are the same, the requesting device initiates the first request.

此处需要说明的是,上述第二接收单元1202和第二发送单元1204对应于实施例一中的步骤S602至步骤S604,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the above-mentioned second receiving unit 1202 and second sending unit 1204 correspond to step S602 to step S604 in the first embodiment, and the examples and application scenarios implemented by this module are the same as those of the corresponding steps, but are not limited to The content disclosed in the first embodiment above. It should be noted that, as a part of the device, the above-mentioned modules can run in the computer terminal 10 provided in Embodiment 1, and can be realized by software or by hardware.

可选地,所述请求装置根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同可以包括:所述请求装置获取所述已存储的漏洞修复程序的MD5;所述请求装置判断所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5是否相同;若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序相同;若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5不相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序不相同。Optionally, the requesting device, according to the MD5 of the updated vulnerability repair program, judging whether the updated vulnerability repair program is the same as the vulnerability repair program stored by the requesting device may include: the requesting device obtains The MD5 of the stored vulnerability repair program; the requesting device judges whether the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program; if the updated vulnerability repair program MD5 is the same as the MD5 of the stored vulnerability repair program, then it is determined that the updated vulnerability repair program is the same as the stored vulnerability repair program of the requesting device; if the MD5 of the updated vulnerability repair program is the same as the stored If the MD5 of the stored vulnerability repair program is different, it is determined that the updated vulnerability repair program is different from the stored vulnerability repair program of the requesting device.

根据本申请实施例,还提供了一种用于实施上述方法实施例的装置实施例,如图13所示,该装置包括:According to the embodiment of the present application, a device embodiment for implementing the above method embodiment is also provided, as shown in FIG. 13 , the device includes:

图13是根据本申请实施例的请求装置的结构示意图。Fig. 13 is a schematic structural diagram of a requesting device according to an embodiment of the present application.

如图13所示,该请求装置可以包括第三发送单元1302和控制单元1304。As shown in FIG. 13 , the requesting device may include a third sending unit 1302 and a control unit 1304 .

其中,第三发送单元1302,用于将具有第一格式的可疑文件发送至文件修复装置,其中,由所述文件修复装置按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据所述令牌序列特征,确定所述至少一个字段组中的漏洞,将所述漏洞替换为预设的修复代码序列,得到修复后的所述至少一个字段组,将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件;控制单元1304,用于从所述文件修复装置中获取对应于所述可疑文件的具有所述第一格式的修复文件。Wherein, the third sending unit 1302 is configured to send the suspicious file with the first format to the file repairing device, wherein, the file repairing device converts fields with the same grammatical feature into Forming at least one field group, obtaining the token sequence features corresponding to each grammatical feature according to the grammatical features of each field group, determining the loopholes in the at least one field group according to the token sequence features, and replacing the loopholes For a preset repair code sequence, obtain the repaired at least one field group, and reorganize the repaired at least one field group into a repair file in the first format corresponding to the suspicious file; a control unit 1304. Acquire a repair file in the first format corresponding to the suspicious file from the file repair apparatus.

此处需要说明的是,上述第三发送单元1302和控制单元1304对应于实施例一中的步骤S10至步骤S12,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the above-mentioned third sending unit 1302 and control unit 1304 correspond to Step S10 to Step S12 in Embodiment 1, and the examples and application scenarios realized by this module are the same as those of the corresponding steps, but are not limited to the above-mentioned implementation The content disclosed in Example 1. It should be noted that, as a part of the device, the above-mentioned modules can run in the computer terminal 10 provided in Embodiment 1, and can be realized by software or by hardware.

可选地,所述控制单元1304用于执行以下步骤从文件修复装置中获取对应于所述可疑文件的具有所述第一格式的修复文件:向所述文件修复装置发送第一请求,所述第一请求用于下载更新后的漏洞修复程序;接收所述文件修复装置返回的所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件。Optionally, the control unit 1304 is configured to perform the following steps to obtain the repair file in the first format corresponding to the suspicious file from the file repair device: sending a first request to the file repair device, the The first request is used for downloading an updated vulnerability repair program; receiving the updated vulnerability repair program returned by the file repair device, wherein the updated vulnerability repair program includes the repair file.

可选地,所述控制单元1304,还用于向所述文件修复装置发送第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;接收所述文件修复装置返回的所述更新后的漏洞修复程序的MD5;根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。Optionally, the control unit 1304 is further configured to send a second request to the file repairing device, where the second request is used to acquire the identification information of the updated vulnerability repairing program; receive the file repairing device The returned MD5 of the updated bug fix program; according to the MD5 of the updated bug fix program, it is judged whether the updated bug fix program is the same as the bug fix program stored in the requesting device, if they are the same , the requesting device initiates the first request.

由此可知,现有技术存在的采用同一套Patch代码实行造成的漏洞修复准确性较差的问题,本申请提出一种基于语法特征对可疑文件的字段进行拆分的方法,进而依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果。It can be seen from this that there is a problem in the prior art that the accuracy of vulnerability repair caused by the implementation of the same set of Patch codes is poor. This application proposes a method for splitting the fields of suspicious files based on grammatical features, and then according to each grammatical feature Corresponding to the token sequence features and the repair code sequence, the loopholes are searched and repaired, and the purpose of 1:1 automatic repair of the loopholes is achieved, thereby achieving the technical effect of improving the accuracy of the loophole patching and system security.

实施例3Example 3

本申请的实施例还提供了一种存储介质。可选地,在本实施例中,上述存储介质可以用于保存上述实施例一所提供的文件修复方法所执行的程序代码。The embodiment of the present application also provides a storage medium. Optionally, in this embodiment, the above-mentioned storage medium may be used to store the program code executed by the file repair method provided in the first embodiment above.

可选地,在本实施例中,上述存储介质可以位于计算机网络中计算机终端群中的任意一个计算机终端中,或者位于移动终端群中的任意一个移动终端中。Optionally, in this embodiment, the above-mentioned storage medium may be located in any computer terminal in the group of computer terminals in the computer network, or in any mobile terminal in the group of mobile terminals.

可选地,在本实施例中,存储介质被设置为存储用于执行以下步骤的程序代码:获取请求装置上传的具有第一格式的可疑文件;按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;依据所述令牌序列特征,确定所述至少一个字段组中的漏洞;将所述漏洞替换为预设的修复代码序列,得到修复后的所述至少一个字段组;将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。Optionally, in this embodiment, the storage medium is configured to store program codes for performing the following steps: obtaining a suspicious file in the first format uploaded by the requesting device; according to the grammatical features of each field in the suspicious file, Composing fields with the same grammatical features into at least one field group; according to the grammatical features of each field group, obtaining token sequence features corresponding to each grammatical feature; according to the token sequence features, determining vulnerabilities in the at least one field group ; Replace the vulnerability with a preset repair code sequence to obtain the repaired at least one field group; reorganize the repaired at least one field group into the first format corresponding to the suspicious file repair file.

可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:提取各个可疑文件的元信息,其中,所述元信息包括对应可疑文件的文件路径及消息摘要算法MD5,所述文件路径是指所述可疑文件在所述请求装置所在的用户设备上的路径;根据所述文件路径及所述MD5,对所述各个可疑文件进行去重处理。Optionally, the storage medium is also configured to store program codes for performing the following steps: extracting meta information of each suspicious file, wherein the meta information includes a file path corresponding to the suspicious file and a message digest algorithm MD5, the file The path refers to the path of the suspicious file on the user equipment where the requesting device is located; according to the file path and the MD5, deduplication processing is performed on each suspicious file.

可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:确定所述各个可疑文件中重复的可疑文件,其中,所述重复的可疑文件是指所述文件路径相同且所述MD5相同的文件;保留所述重复的可疑文件中的第一文件,将除所述第一文件以外的所述重复的可疑文件删除,其中,所述第一文件为所述重复的可疑文件中的任意一个。Optionally, the storage medium is also configured to store program codes for performing the following steps: determining duplicate suspicious files among the suspicious files, wherein the duplicate suspicious files refer to the same file path and the MD5 identical files; keep the first file in the repeated suspicious files, and delete the repeated suspicious files except the first file, wherein the first file is among the repeated suspicious files any of the .

可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:在所述至少一个字段组中查找与所述令牌序列特征相同的字段,将所述与所述令牌序列特征相同的字段确定为所述漏洞。Optionally, the storage medium is further configured to store program codes for performing the following steps: searching for a field identical to the token sequence feature in the at least one field group, and combining the field with the token sequence feature The same field is identified as the vulnerability.

可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:按照所述修复后的所述至少一个字段组中各个字段的父子关系,将所述修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。Optionally, the storage medium is further configured to store a program code for performing the following steps: according to the parent-child relationship of each field in the at least one field group after the repair, the at least one field after repair The group is reorganized into a repair file in the first format corresponding to the suspect file.

可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:接收所述请求装置发送的第一请求,所述第一请求用于下载更新后的漏洞修复程序;向所述请求装置发送所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件,以便所述请求装置根据所述修复文件对所述可疑文件进行修复。Optionally, the storage medium is also configured to store program codes for performing the following steps: receiving a first request sent by the requesting device, the first request being used to download an updated vulnerability repair program; The device sends the updated vulnerability repair program, wherein the updated vulnerability repair program includes the repair file, so that the requesting device repairs the suspicious file according to the repair file.

可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:接收来自所述请求装置发送的第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;向所述请求装置发送所述更新后的漏洞修复程序的MD5,其中,由所述请求装置根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。Optionally, the storage medium is further configured to store program codes for performing the following steps: receiving a second request sent from the requesting device, the second request being used to obtain the identifier of the updated vulnerability repair program Information; send the MD5 of the updated vulnerability repair program to the requesting device, wherein, the requesting device judges that the updated vulnerability repair program is consistent with the updated vulnerability repair program according to the MD5 of the updated vulnerability repair program Whether the vulnerability repair programs stored by the requesting device are the same, and if they are the same, the requesting device initiates the first request.

可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:所述请求装置获取所述已存储的漏洞修复程序的MD5;所述请求装置判断所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5是否相同;若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序相同;若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5不相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序不相同。Optionally, the storage medium is also configured to store program codes for performing the following steps: the requesting device acquires the MD5 of the stored vulnerability repair program; the requesting device judges the MD5 of the updated vulnerability repair program Whether the MD5 is the same as the MD5 of the stored bug fix program; if the MD5 of the updated bug fix program is the same as the MD5 of the stored bug fix program, then it is determined that the updated bug fix program is the same as The bug fix program stored by the requesting device is the same; if the MD5 of the updated bug fix program is different from the MD5 of the stored bug fix program, then it is determined that the updated bug fix program is the same as the The requesting device has different stored bug fixes.

上述本申请实施例序号仅仅为了描述,不代表实施例的优劣。The serial numbers of the above embodiments of the present application are for description only, and do not represent the advantages and disadvantages of the embodiments.

在本申请的上述实施例中,对各个实施例的描述都各有侧重,某个实施例中没有详述的部分,可以参见其他实施例的相关描述。In the above-mentioned embodiments of the present application, the descriptions of each embodiment have their own emphases, and for parts not described in detail in a certain embodiment, reference may be made to relevant descriptions of other embodiments.

在本申请所提供的几个实施例中,应该理解到,所揭露的订单信息的处理装置,可通过其它的方式实现。其中,以上所描述的装置实施例仅仅是示意性的,例如所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,单元或模块的间接耦合或通信连接,可以是电性或其它的形式。In the several embodiments provided in this application, it should be understood that the disclosed order information processing device can be implemented in other ways. Wherein, the device embodiments described above are only illustrative, for example, the division of the units is only a logical function division, and there may be other division methods in actual implementation, for example, multiple units or components can be combined or can be Integrate into another system, or some features may be ignored, or not implemented. In another point, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of units or modules may be in electrical or other forms.

所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, each unit may exist separately physically, or two or more units may be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可为个人计算机、服务器或者网络设备等)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、只读存储器(ROM,Read-OnlyMemory)、随机存取存储器(RAM,Random Access Memory)、移动硬盘、磁碟或者光盘等各种可以存储程序代码的介质。If the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium , including several instructions for enabling a computer device (which may be a personal computer, server or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: various media capable of storing program codes such as U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk.

以上所述仅是本申请的优选实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本申请原理的前提下,还可以做出若干改进和润饰,这些改进和润饰也应视为本申请的保护范围。The above description is only the preferred embodiment of the present application. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present application, some improvements and modifications can also be made. These improvements and modifications are also It should be regarded as the protection scope of this application.

Claims (21)

1.一种文件修复方法,其特征在于,包括:1. A file repair method, characterized in that, comprising: 获取请求装置上传的具有第一格式的可疑文件;obtaining a suspicious file in a first format uploaded by the requesting device; 按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;According to the grammatical features of each field in the suspicious file, the fields with the same grammatical features are formed into at least one field group; 根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;Obtain token sequence features corresponding to each grammatical feature according to the grammatical feature of each field group; 依据所述令牌序列特征,确定所述至少一个字段组中的漏洞;determining vulnerabilities in the at least one field group according to the token sequence characteristics; 将所述漏洞替换为预设的修复代码序列,得到修复后的所述至少一个字段组;replacing the vulnerability with a preset repair code sequence to obtain the repaired at least one field group; 将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。Reorganizing the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file. 2.根据权利要求1所述的方法,其特征在于,在所述可疑文件的数量为至少两个的情况下,在所述获取请求装置上传的具有第一格式的可疑文件之后,所述按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;之前,所述方法还包括:2. The method according to claim 1, wherein, in the case that the number of the suspicious files is at least two, after the suspicious files in the first format uploaded by the acquisition requesting device, the For the grammatical features of each field in the suspicious file, the fields with the same grammatical features are formed into at least one field group; before, the method also includes: 提取各个可疑文件的元信息,其中,所述元信息包括对应可疑文件的文件路径及消息摘要算法MD5,所述文件路径是指所述可疑文件在所述请求装置所在的用户设备上的路径;Extracting meta information of each suspicious file, wherein the meta information includes a file path corresponding to the suspicious file and a message digest algorithm MD5, the file path refers to the path of the suspicious file on the user equipment where the requesting device is located; 根据所述文件路径及所述MD5,对所述各个可疑文件进行去重处理。According to the file path and the MD5, deduplication processing is performed on each suspicious file. 3.根据权利要求2所述的方法,其特征在于,所述根据所述文件路径及所述MD5,对所述各个可疑文件进行去重处理包括:3. The method according to claim 2, wherein the deduplication processing of each suspicious file according to the file path and the MD5 comprises: 确定所述各个可疑文件中重复的可疑文件,其中,所述重复的可疑文件是指所述文件路径相同且所述MD5相同的文件;Determining repeated suspicious files among the suspicious files, wherein the repeated suspicious files refer to files with the same file path and the same MD5; 保留所述重复的可疑文件中的第一文件,将除所述第一文件以外的所述重复的可疑文件删除,其中,所述第一文件为所述重复的可疑文件中的任意一个。Retaining the first file among the repeated suspicious files, and deleting the repeated suspicious files except the first file, wherein the first file is any one of the repeated suspicious files. 4.根据权利要求1所述的方法,其特征在于,所述依据所述令牌序列特征,确定所述至少一个字段组中的漏洞包括:4. The method according to claim 1, wherein, according to the token sequence characteristics, determining the loopholes in the at least one field group comprises: 在所述至少一个字段组中查找与所述令牌序列特征相同的字段,将所述与所述令牌序列特征相同的字段确定为所述漏洞。Searching the at least one field group for a field with the same feature as the token sequence, and determining the field with the same feature as the token sequence as the vulnerability. 5.根据权利要求1所述的方法,其特征在于,所述将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件包括:5. The method according to claim 1, wherein said reorganizing said repaired at least one field into a repaired file corresponding to said suspicious file having said first format comprises: 按照所述修复后的所述至少一个字段组中各个字段的父子关系,将所述修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。According to the parent-child relationship of each field in the repaired at least one field group, reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file. 6.根据权利要求1所述的方法,其特征在于,在所述将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件之后,所述方法还包括:6. The method according to claim 1, characterized in that, after said repairing said at least one field group into a repaired file corresponding to said suspicious file having said first format, said Methods also include: 接收所述请求装置发送的第一请求,所述第一请求用于下载更新后的漏洞修复程序;receiving a first request sent by the requesting device, where the first request is used to download an updated vulnerability repair program; 向所述请求装置发送所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件,以便所述请求装置根据所述修复文件对所述可疑文件进行修复。Sending the updated vulnerability repair program to the requesting device, wherein the updated vulnerability repair program includes the repair file, so that the requesting device repairs the suspicious file according to the repair file. 7.根据权利要求6所述的方法,其特征在于,在所述接收所述请求装置发送的第一请求之前,所述方法还包括:7. The method according to claim 6, wherein before receiving the first request sent by the requesting device, the method further comprises: 接收来自所述请求装置发送的第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;receiving a second request sent from the requesting device, where the second request is used to obtain the identification information of the updated vulnerability repair program; 向所述请求装置发送所述更新后的漏洞修复程序的MD5,其中,由所述请求装置根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。sending the MD5 of the updated vulnerability repair program to the requesting device, wherein the requesting device judges that the updated vulnerability repair program is compatible with the requesting device according to the MD5 of the updated vulnerability repair program Whether the stored vulnerability repair programs are the same, if they are the same, the requesting device initiates the first request. 8.根据权利要求7所述的方法,其特征在于,所述请求装置根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同包括:8. The method according to claim 7, wherein the requesting device judges the updated vulnerability repair program and the stored vulnerability repair program according to the MD5 of the updated vulnerability repair program. Are the procedures the same including: 所述请求装置获取所述已存储的漏洞修复程序的MD5;The requesting device obtains the MD5 of the stored vulnerability repair program; 所述请求装置判断所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5是否相同;The requesting device judges whether the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program; 若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序相同;If the MD5 of the updated bug fix program is the same as the MD5 of the stored bug fix program, then determine that the updated bug fix program is the same as the stored bug fix program of the requesting device; 若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5不相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序不相同。If the MD5 of the updated bug fix program is different from the MD5 of the stored bug fix program, it is determined that the updated bug fix program is different from the stored bug fix program of the requesting device. 9.一种文件修复方法,其特征在于,包括:9. A file repair method, characterized in that, comprising: 将具有第一格式的可疑文件发送至文件修复装置,其中,由所述文件修复装置按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据所述令牌序列特征,确定所述至少一个字段组中的漏洞,将所述漏洞替换为预设的修复代码序列,得到修复后的所述至少一个字段组,将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件;Sending the suspicious file with the first format to the file repairing device, wherein, according to the grammatical feature of each field in the suspicious file, the file repairing device forms fields with the same grammatical feature into at least one field group, and according to each field The grammatical feature of the group, obtain the token sequence feature corresponding to each grammatical feature, determine the loophole in the at least one field group according to the token sequence feature, replace the loophole with a preset repair code sequence, and get repaired After the at least one field group, reorganize the repaired at least one field group into a repair file with the first format corresponding to the suspicious file; 从所述文件修复装置中获取对应于所述可疑文件的具有所述第一格式的修复文件。Obtain a repair file in the first format corresponding to the suspicious file from the file repair apparatus. 10.根据权利要求9所述的方法,其特征在于,所述从所述文件修复装置中获取对应于所述可疑文件的具有所述第一格式的修复文件包括:10. The method according to claim 9, wherein said obtaining the repaired file in the first format corresponding to the suspicious file from the file repairing device comprises: 向所述文件修复装置发送第一请求,所述第一请求用于下载更新后的漏洞修复程序;Sending a first request to the file repairing device, the first request is used to download an updated vulnerability repair program; 接收所述文件修复装置返回的所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件。receiving the updated vulnerability repair program returned by the file repair device, wherein the updated vulnerability repair program includes the repair file. 11.根据权利要求10所述的方法,其特征在于,在向所述文件修复装置发送第一请求之前,所述方法还包括:11. The method according to claim 10, wherein before sending the first request to the file repairing device, the method further comprises: 向所述文件修复装置发送第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;sending a second request to the file repairing device, where the second request is used to obtain the identification information of the updated vulnerability repair program; 接收所述文件修复装置返回的所述更新后的漏洞修复程序的MD5;receiving the MD5 of the updated vulnerability repair program returned by the file repair device; 根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。According to the MD5 of the updated bug fix program, it is judged whether the updated bug fix program is the same as the bug fix program stored by the requesting device, and if they are the same, the request device initiates the first request. 12.一种文件修复装置,其特征在于,包括:12. A file restoration device, characterized in that it comprises: 获取单元,用于获取请求装置上传的具有第一格式的可疑文件;An acquisition unit, configured to acquire the suspicious file in the first format uploaded by the requesting device; 处理单元,用于按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;A processing unit, configured to combine fields with the same grammatical features into at least one field group according to the grammatical features of each field in the suspicious file; 第一确定单元,用于根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;The first determining unit is used to obtain token sequence features corresponding to each grammatical feature according to the grammatical feature of each field group; 第二确定单元,用于依据所述令牌序列特征,确定所述至少一个字段组中的漏洞;A second determining unit, configured to determine the loopholes in the at least one field group according to the token sequence characteristics; 修复单元,用于将所述漏洞替换为预先配置的修复代码序列,得到修复后的所述至少一个字段组;A repair unit, configured to replace the vulnerability with a pre-configured repair code sequence to obtain the repaired at least one field group; 重组单元,用于将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。A recombination unit, configured to reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file. 13.根据权利要求12所述的装置,其特征在于,还包括:13. The device of claim 12, further comprising: 提取单元,用于提取各个可疑文件的元信息,其中,所述元信息包括对应可疑文件的文件路径及消息摘要算法MD5,所述文件路径是指所述可疑文件在所述请求装置所在的用户设备上的路径;An extracting unit, configured to extract meta-information of each suspicious file, wherein the meta-information includes a file path corresponding to the suspicious file and a message digest algorithm MD5, and the file path refers to the user's location where the suspicious file is located in the requesting device. the path on the device; 去重单元,用于根据所述文件路径及所述MD5,对所述各个可疑文件进行去重处理。The deduplication unit is configured to perform deduplication processing on each suspicious file according to the file path and the MD5. 14.根据权利要求13所述的装置,其特征在于,所述去重单元包括:14. The device according to claim 13, wherein the deduplication unit comprises: 确定模块,用于确定所述各个可疑文件中重复的可疑文件,其中,所述重复的可疑文件是指所述文件路径相同且所述MD5相同的文件;A determining module, configured to determine repeated suspicious files among the suspicious files, wherein the repeated suspicious files refer to files with the same file path and the same MD5; 处理模块,用于保留所述重复的可疑文件中的第一文件,将除所述第一文件以外的所述重复的可疑文件删除,其中,所述第一文件为所述重复的可疑文件中的任意一个。A processing module, configured to retain the first file among the repeated suspicious files, and delete the repeated suspicious files except the first file, wherein the first file is one of the repeated suspicious files any of the . 15.根据权利要求12所述的装置,其特征在于,所述第一确定单元用于执行以下步骤依据所述令牌序列特征,确定所述至少一个字段组中的漏洞:15. The device according to claim 12, wherein the first determining unit is configured to perform the following steps to determine the loopholes in the at least one field group according to the token sequence characteristics: 在所述至少一个字段组中查找与所述令牌序列特征相同的字段,将所述与所述令牌序列特征相同的字段确定为所述漏洞。Searching the at least one field group for a field with the same feature as the token sequence, and determining the field with the same feature as the token sequence as the vulnerability. 16.根据权利要求12所述的装置,其特征在于,所述重组单元用于执行以下步骤将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件:16. The device according to claim 12, wherein the reorganization unit is configured to perform the following steps to reorganize the repaired at least one field group into the first format corresponding to the suspicious file Repair file: 按照所述修复后的所述至少一个字段组中各个字段的父子关系,将所述修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。According to the parent-child relationship of each field in the repaired at least one field group, reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file. 17.根据权利要求12所述的装置,其特征在于,还包括:17. The apparatus of claim 12, further comprising: 第一接收单元,用于接收所述请求装置发送的第一请求,所述第一请求用于下载更新后的漏洞修复程序;a first receiving unit, configured to receive a first request sent by the requesting device, and the first request is used to download an updated vulnerability repair program; 第一发送单元,用于向所述请求装置发送所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件,以便所述请求装置根据所述修复文件对所述可疑文件进行修复。A first sending unit, configured to send the updated vulnerability repair program to the requesting device, wherein the updated vulnerability repair program includes the repair file, so that the requesting device can perform the repair according to the repair file The suspicious files are repaired. 18.根据权利要求17所述的装置,其特征在于,还包括:18. The apparatus of claim 17, further comprising: 第二接收单元,用于接收来自所述请求装置发送的第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;A second receiving unit, configured to receive a second request sent from the requesting device, where the second request is used to obtain the identification information of the updated vulnerability repair program; 第二发送单元,用于向所述请求装置发送所述更新后的漏洞修复程序的MD5,其中,由所述请求装置根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。The second sending unit is configured to send the MD5 of the updated vulnerability repair program to the requesting device, wherein the requesting device judges the updated vulnerability according to the MD5 of the updated vulnerability repair program Whether the repair program is the same as the vulnerability repair program stored by the requesting device, and if they are the same, the requesting device initiates the first request. 19.一种请求装置,其特征在于,包括:19. A requesting device, characterized in that it comprises: 第三发送单元,用于将具有第一格式的可疑文件发送至文件修复装置,其中,由所述文件修复装置按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据所述令牌序列特征,确定所述至少一个字段组中的漏洞,将所述漏洞替换为预设的修复代码序列,得到修复后的所述至少一个字段组,将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件;The third sending unit is used to send the suspicious file with the first format to the file repairing device, wherein the file repairing device forms at least one field with the same grammatical feature according to the grammatical feature of each field in the suspicious file Field groups, according to the grammatical features of each field group, obtain the token sequence features corresponding to each grammatical feature, determine the loopholes in the at least one field group according to the token sequence features, and replace the loopholes with preset repair code sequence, obtain the at least one field group after repair, and reorganize the at least one field group after repair into a repair file with the first format corresponding to the suspicious file; 控制单元,用于从所述文件修复装置中获取对应于所述可疑文件的具有所述第一格式的修复文件。A control unit, configured to acquire a repair file in the first format corresponding to the suspicious file from the file repair device. 20.根据权利要求19所述的装置,其特征在于,所述控制单元用于执行以下步骤从文件修复装置中获取对应于所述可疑文件的具有所述第一格式的修复文件:20. The device according to claim 19, wherein the control unit is configured to perform the following steps to obtain a repair file in the first format corresponding to the suspicious file from the file repair device: 向所述文件修复装置发送第一请求,所述第一请求用于下载更新后的漏洞修复程序;Sending a first request to the file repairing device, the first request is used to download an updated vulnerability repair program; 接收所述文件修复装置返回的所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件。receiving the updated vulnerability repair program returned by the file repair device, wherein the updated vulnerability repair program includes the repair file. 21.根据权利要求20所述的装置,其特征在于,所述控制单元,还用于向所述文件修复装置发送第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;接收所述文件修复装置返回的所述更新后的漏洞修复程序的MD5;根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。21. The device according to claim 20, wherein the control unit is further configured to send a second request to the file repair device, and the second request is used to obtain the updated vulnerability repair program receiving the MD5 of the updated vulnerability repair program returned by the file repair device; according to the MD5 of the updated vulnerability repair program, it is determined that the updated vulnerability repair program and the requesting device have Whether the stored vulnerability repair programs are the same, if they are the same, the requesting device initiates the first request.
CN201510307070.6A 2015-06-05 2015-06-05 Ile repair method and device Active CN106295334B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510307070.6A CN106295334B (en) 2015-06-05 2015-06-05 Ile repair method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510307070.6A CN106295334B (en) 2015-06-05 2015-06-05 Ile repair method and device

Publications (2)

Publication Number Publication Date
CN106295334A true CN106295334A (en) 2017-01-04
CN106295334B CN106295334B (en) 2019-07-26

Family

ID=57659427

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510307070.6A Active CN106295334B (en) 2015-06-05 2015-06-05 Ile repair method and device

Country Status (1)

Country Link
CN (1) CN106295334B (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109255243A (en) * 2018-09-28 2019-01-22 深信服科技股份有限公司 Restorative procedure, system, device and the storage medium of potential threat in a kind of terminal
CN113852602A (en) * 2021-08-11 2021-12-28 奇安信科技集团股份有限公司 File reconstruction method, file reconstruction device, transmission equipment, electronic device, program product and medium
CN119739356A (en) * 2024-12-03 2025-04-01 珠海奔图电子有限公司 Print data repair method, device, equipment, medium and program product

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102622556A (en) * 2011-12-22 2012-08-01 南京邮电大学 Web service security analysis method based on program slicing technique
CN103886258A (en) * 2014-03-10 2014-06-25 珠海市君天电子科技有限公司 Method and device for detecting viruses
CN103955449A (en) * 2014-04-21 2014-07-30 安一恒通(北京)科技有限公司 Target sample positioning method and device
CN104182689A (en) * 2013-05-24 2014-12-03 阿里巴巴集团控股有限公司 System repair and protection method and system
CN104199925A (en) * 2014-09-01 2014-12-10 安一恒通(北京)科技有限公司 File repair method and device

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102622556A (en) * 2011-12-22 2012-08-01 南京邮电大学 Web service security analysis method based on program slicing technique
CN104182689A (en) * 2013-05-24 2014-12-03 阿里巴巴集团控股有限公司 System repair and protection method and system
CN103886258A (en) * 2014-03-10 2014-06-25 珠海市君天电子科技有限公司 Method and device for detecting viruses
CN103955449A (en) * 2014-04-21 2014-07-30 安一恒通(北京)科技有限公司 Target sample positioning method and device
CN104199925A (en) * 2014-09-01 2014-12-10 安一恒通(北京)科技有限公司 File repair method and device

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109255243A (en) * 2018-09-28 2019-01-22 深信服科技股份有限公司 Restorative procedure, system, device and the storage medium of potential threat in a kind of terminal
CN113852602A (en) * 2021-08-11 2021-12-28 奇安信科技集团股份有限公司 File reconstruction method, file reconstruction device, transmission equipment, electronic device, program product and medium
CN113852602B (en) * 2021-08-11 2023-12-08 奇安信科技集团股份有限公司 File reconstruction method, device, transmission equipment, electronic equipment and medium
CN119739356A (en) * 2024-12-03 2025-04-01 珠海奔图电子有限公司 Print data repair method, device, equipment, medium and program product

Also Published As

Publication number Publication date
CN106295334B (en) 2019-07-26

Similar Documents

Publication Publication Date Title
CN113037777B (en) Honeypot bait distribution method and device, storage medium and electronic equipment
US11188635B2 (en) File authentication method and apparatus
CN110677381B (en) Penetration testing method and device, storage medium, electronic device
US8978137B2 (en) Method and apparatus for retroactively detecting malicious or otherwise undesirable software
CN103607385B (en) Method and apparatus for security detection based on browser
CN102307210B (en) Data downloading system and data management and downloading method thereof
CN105187394B (en) Proxy server and method with mobile terminal from malicious software action detectability
CN110879891B (en) Vulnerability detection method and device based on web fingerprint information
CN110881024B (en) Vulnerability detection method and device, storage medium and electronic device
CN107294924B (en) Vulnerability detection method, device and system
CN104462968B (en) Scanning method, device and system for malicious applications
CN111104579A (en) Identification method and device for public network assets and storage medium
CN104951480A (en) Resource storage indexing device and method in CDN system
Kumari et al. An insight into digital forensics branches and tools
CN111182060A (en) Message detection method and device
CN103248711A (en) File uploading method and server
CN106815135A (en) leak detection method and device
CN110149318B (en) Mail metadata processing method and device, storage medium and electronic device
CN104850784A (en) Method and system for cloud detection of malicious software based on Hash characteristic vector
CN110245273A (en) A method and corresponding device for acquiring APP service feature database
CN110768951A (en) Method and device for verifying system vulnerability, storage medium, and electronic device
CN103310154B (en) The method, apparatus and system that information security processes
CN106295334B (en) Ile repair method and device
CN104239798B (en) Mobile terminal, server end in mobile office system and its virus method and system
CN106934290A (en) leak detection method and device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant