CN106295334B - Ile repair method and device - Google Patents
Ile repair method and device Download PDFInfo
- Publication number
- CN106295334B CN106295334B CN201510307070.6A CN201510307070A CN106295334B CN 106295334 B CN106295334 B CN 106295334B CN 201510307070 A CN201510307070 A CN 201510307070A CN 106295334 B CN106295334 B CN 106295334B
- Authority
- CN
- China
- Prior art keywords
- file
- suspicious
- repair
- vulnerability
- repaired
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Virology (AREA)
- Health & Medical Sciences (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- General Health & Medical Sciences (AREA)
- Information Transfer Between Computers (AREA)
- Storage Device Security (AREA)
Abstract
本申请公开了一种文件修复方法及装置。其中,该方法包括:获取请求装置上传的具有第一格式的可疑文件;按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;依据所述令牌序列特征,确定所述至少一个字段组中的漏洞;将所述漏洞替换为预设的修复代码序列,得到修复后的所述至少一个字段组;将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。本申请解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。
The present application discloses a file repairing method and device. Wherein, the method includes: acquiring a suspicious file with a first format uploaded by a requesting device; according to the grammatical features of each field in the suspicious file, forming at least one field group of fields with the same grammatical feature; according to the grammar of each field group feature, obtain the token sequence feature corresponding to each grammatical feature; determine the vulnerability in the at least one field group according to the token sequence feature; replace the vulnerability with a preset repair code sequence, and obtain the repaired at least one field group; reorganizing the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file. The present application solves the technical problem that the accuracy of vulnerability repair is poor due to the implementation of the same patch code in the prior art.
Description
技术领域technical field
本申请涉及互联网领域,具体而言,涉及一种文件修复方法及装置。The present application relates to the field of the Internet, and in particular, to a file repairing method and device.
背景技术Background technique
随着互联网的快速发展,各个运营商的服务器运行着大量的web网站,出于技术上的考虑,这些web网站大多数直接采用目前市场上开源或者收费的CMS(ContentManagement System,内容管理系统)进行网站系统的搭建。而这些CMS由于源代码容易获得,常常遭到黑客的漏洞挖掘,在发现了可利用的漏洞之后,黑客会利用自己手上的ODAY(零日)漏洞对web网站进行攻击,进而获取大量的商业资料。With the rapid development of the Internet, a large number of web sites are running on the servers of various operators. For technical reasons, most of these web sites directly use the open source or paid CMS (Content Management System) on the market. The construction of the website system. These CMSs are often exploited by hackers due to their easy access to source code. After discovering exploitable vulnerabilities, hackers will use their own ODAY (zero-day) vulnerabilities to attack web sites, thereby obtaining a large number of commercial material.
在web攻防的对抗中,对于传统的二进制漏洞文件、或者是网站文本文件Patch(补丁)技术中,现有技术一般采用的是统一的替换模版的方法,即不管漏洞文件或漏洞代码有多少种变种,在服务器端都采用同一套Patch代码实行漏洞修复,这就导致漏洞修复准确性较差、系统安全性较低的问题。In the confrontation of web attack and defense, for traditional binary vulnerability files or website text file Patch (patch) technology, the prior art generally adopts a unified method of replacing templates, that is, regardless of the number of vulnerability files or vulnerability codes. Variants, the same patch code is used on the server side to implement vulnerability repair, which leads to the problem of poor vulnerability repair accuracy and low system security.
针对上述的问题,目前尚未提出有效的解决方案。For the above problems, no effective solution has been proposed yet.
发明内容SUMMARY OF THE INVENTION
本申请实施例提供了一种文件修复方法及装置,以至少解决由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。The embodiments of the present application provide a file repairing method and device, so as to at least solve the technical problem of poor accuracy of vulnerability repairing due to the implementation of the same patch code in the prior art.
根据本申请实施例的一个方面,提供了一种文件修复方法,包括:获取请求装置上传的具有第一格式的可疑文件;按照上述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;依据上述令牌序列特征,确定上述至少一个字段组中的漏洞;将上述漏洞替换为预设的修复代码序列,得到修复后的上述至少一个字段组;将修复后的上述至少一个字段组重组为对应于上述可疑文件的具有上述第一格式的修复文件。According to an aspect of the embodiments of the present application, a file repairing method is provided, which includes: acquiring a suspicious file with a first format uploaded by a requesting device; according to the grammatical features of each field in the suspicious file, forming fields with the same grammatical features at least one field group; according to the grammatical feature of each field group, obtain the token sequence feature corresponding to each grammatical feature; according to the above token sequence feature, determine the loophole in the above at least one field group; replace the above loophole with a preset Repair the code sequence to obtain the repaired at least one field group; and reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file.
根据本申请实施例的另一方面,还提供了一种文件修复方法,包括:将具有第一格式的可疑文件发送至文件修复装置,其中,由上述文件修复装置按照上述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据上述令牌序列特征,确定上述至少一个字段组中的漏洞,将上述漏洞替换为预设的修复代码序列,得到修复后的上述至少一个字段组,将修复后的上述至少一个字段组重组为对应于上述可疑文件的具有上述第一格式的修复文件;从上述文件修复装置中获取对应于上述可疑文件的具有上述第一格式的修复文件。According to another aspect of the embodiments of the present application, there is also provided a file repairing method, comprising: sending a suspicious file having a first format to a file repairing device, wherein the file repairing device according to the file repairing device according to each field in the suspicious file Grammatical features, the fields with the same grammatical features are formed into at least one field group, and according to the grammatical features of each field group, the token sequence features corresponding to each grammatical feature are obtained, and according to the above token sequence features, determine the at least one field group. Vulnerability, replace the above-mentioned vulnerability with a preset repair code sequence, obtain the above-mentioned at least one field group after repair, and reorganize the above-mentioned at least one field group after repair into a repair file corresponding to the above-mentioned suspicious file and having the above-mentioned first format; A repaired file in the first format corresponding to the suspicious file is obtained from the file repairing device.
根据本申请实施例的另一方面,还提供了一种文件修复装置,包括:获取单元,用于获取请求装置上传的具有第一格式的可疑文件;处理单元,用于按照上述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;第一确定单元,用于根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;第二确定单元,用于依据上述令牌序列特征,确定上述至少一个字段组中的漏洞;修复单元,用于将上述漏洞替换为预先配置的修复代码序列,得到修复后的上述至少一个字段组;重组单元,用于将修复后的上述至少一个字段组重组为对应于上述可疑文件的具有上述第一格式的修复文件。According to another aspect of the embodiments of the present application, there is also provided a file repairing device, including: an obtaining unit, configured to obtain a suspicious file with a first format uploaded by a requesting device; a processing unit, configured to The grammatical features of the fields, the fields with the same grammatical features are formed into at least one field group; the first determination unit is used to obtain the token sequence feature corresponding to each grammatical feature according to the grammatical feature of each field group; the second determination unit, with According to the above token sequence features, the loopholes in the above at least one field group are determined; the repair unit is used to replace the above loopholes with a pre-configured repair code sequence to obtain the above-mentioned at least one field group after repair; the reorganization unit is used for The repaired at least one field group is reorganized into a repaired file in the first format corresponding to the suspicious file.
根据本申请实施例的另一方面,还提供了一种请求装置,包括:第三发送单元,用于将具有第一格式的可疑文件发送至文件修复装置,其中,由上述文件修复装置按照上述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据上述令牌序列特征,确定上述至少一个字段组中的漏洞,将上述漏洞替换为预设的修复代码序列,得到修复后的上述至少一个字段组,将修复后的上述至少一个字段组重组为对应于上述可疑文件的具有上述第一格式的修复文件;控制单元,用于从上述文件修复装置中获取对应于上述可疑文件的具有上述第一格式的修复文件。According to another aspect of the embodiments of the present application, a requesting device is further provided, including: a third sending unit, configured to send a suspicious file having a first format to a file repairing device, wherein the file repairing device according to the above The grammatical feature of each field in the suspicious file, the fields with the same grammatical feature are formed into at least one field group, and according to the grammatical feature of each field group, the token sequence feature corresponding to each grammatical feature is obtained, and the above token sequence feature is determined according to the above token sequence feature. For loopholes in at least one field group, replace the above loopholes with a preset repair code sequence, obtain the above-mentioned at least one field group after repair, and reorganize the above-mentioned at least one field group after repair into a file corresponding to the above-mentioned suspicious file with the above-mentioned No. A repair file in a format; a control unit, configured to obtain a repair file in the first format corresponding to the suspicious file from the file repair device.
在本申请实施例中,采用获取请求装置上传的具有第一格式的可疑文件;按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;依据令牌序列特征,确定至少一个字段组中的漏洞;将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组;将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件的方式,通过按照语法特征对可疑文件进行拆分得到至少一个字段组之后,依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果,进而解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。In the embodiment of the present application, the suspicious file with the first format uploaded by the acquisition request device is adopted; according to the grammatical features of each field in the suspicious file, fields with the same grammatical features are formed into at least one field group; according to the grammar of each field group feature, obtain the token sequence feature corresponding to each grammatical feature; determine the vulnerability in at least one field group according to the token sequence feature; replace the vulnerability with a preset repair code sequence to obtain at least one field group after repair; The last at least one field group is reorganized into a repaired file with the first format corresponding to the suspicious file. After at least one field group is obtained by splitting the suspicious file according to the grammatical features, the corresponding token sequence features and The code sequence is repaired to find and repair the loopholes, so as to achieve the purpose of automatically repairing the loopholes at a ratio of 1:1, thereby achieving the technical effect of improving the accuracy of loophole repairing and system security, and solving the problem of using the same technology in the prior art. The technical problem of poor accuracy of vulnerability repair caused by the implementation of a set of Patch codes.
附图说明Description of drawings
此处所说明的附图用来提供对本申请的进一步理解,构成本申请的一部分,本申请的示意性实施例及其说明用于解释本申请,并不构成对本申请的不当限定。在附图中:The drawings described herein are used to provide further understanding of the present application and constitute a part of the present application. The schematic embodiments and descriptions of the present application are used to explain the present application and do not constitute an improper limitation of the present application. In the attached image:
图1是根据本申请实施例的一种运行文件检测方法的计算机终端的硬件结构框图;1 is a block diagram of a hardware structure of a computer terminal for running a file detection method according to an embodiment of the present application;
图2是根据本申请实施例的一种可选的文件修复方法的流程示意图;2 is a schematic flowchart of an optional file restoration method according to an embodiment of the present application;
图3是根据本申请实施例的另一种可选的文件修复方法的流程示意图;3 is a schematic flowchart of another optional file repair method according to an embodiment of the present application;
图4是根据本申请实施例的又一种可选的文件修复方法的流程示意图;4 is a schematic flowchart of another optional file restoration method according to an embodiment of the present application;
图5是根据本申请实施例的又一种可选的文件修复方法的流程示意图;5 is a schematic flowchart of another optional file restoration method according to an embodiment of the present application;
图6是根据本申请实施例的又一种可选的文件修复方法的流程示意图;6 is a schematic flowchart of another optional file restoration method according to an embodiment of the present application;
图7是根据本申请实施例的又一种可选的文件修复方法的流程示意图;7 is a schematic flowchart of another optional file repair method according to an embodiment of the present application;
图8是根据本申请实施例的一种可选的文件修复装置的结构示意图;FIG. 8 is a schematic structural diagram of an optional file restoration apparatus according to an embodiment of the present application;
图9是根据本申请实施例的另一种可选的文件修复装置的结构示意图;9 is a schematic structural diagram of another optional file restoration apparatus according to an embodiment of the present application;
图10是根据本申请实施例的一种可选的去重单元的结构示意图;10 is a schematic structural diagram of an optional deduplication unit according to an embodiment of the present application;
图11是根据本申请实施例的又一种可选的文件修复装置的结构示意图;11 is a schematic structural diagram of another optional file restoration apparatus according to an embodiment of the present application;
图12是根据本申请实施例的又一种可选的文件修复装置的结构示意图;FIG. 12 is a schematic structural diagram of another optional file restoration apparatus according to an embodiment of the present application;
图13是根据本申请实施例的一种可选的请求装置的结构示意图。FIG. 13 is a schematic structural diagram of an optional requesting apparatus according to an embodiment of the present application.
具体实施方式Detailed ways
为了使本技术领域的人员更好地理解本申请方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分的实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本申请保护的范围。In order to make those skilled in the art better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only The embodiments are part of the present application, but not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the scope of protection of the present application.
需要说明的是,本申请的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、系统、产品或设备不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或单元。It should be noted that the terms "first", "second", etc. in the description and claims of the present application and the above drawings are used to distinguish similar objects, and are not necessarily used to describe a specific sequence or sequence. It is to be understood that data so used may be interchanged under appropriate circumstances so that the embodiments of the application described herein can be practiced in sequences other than those illustrated or described herein. Furthermore, the terms "comprising" and "having" and any variations thereof, are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those expressly listed Rather, those steps or units may include other steps or units not expressly listed or inherent to these processes, methods, products or devices.
实施例1Example 1
根据本申请实施例,还提供了一种文件修复方法的方法实施例,需要说明的是,在附图的流程图示出的步骤可以在诸如一组计算机可执行指令的计算机系统中执行,并且,虽然在流程图中示出了逻辑顺序,但是在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤。According to the embodiments of the present application, a method embodiment of a file repairing method is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and , although a logical order is shown in the flowcharts, in some cases steps shown or described may be performed in an order different from that herein.
本申请实施例一所提供的方法实施例可以在移动终端、计算机终端或者类似的运算装置中执行。以运行在计算机终端上为例,图1是本申请实施例的一种文件修复方法的计算机终端的硬件结构框图。如图1所示,计算机终端10可以包括一个或多个(图中仅示出一个)处理器102(处理器102可以包括但不限于微处理器MCU或可编程逻辑器件FPGA等的处理装置)、用于存储数据的存储器104、以及用于通信功能的传输装置106。本领域普通技术人员可以理解,图1所示的结构仅为示意,其并不对上述电子装置的结构造成限定。例如,计算机终端10还可包括比图1中所示更多或者更少的组件,或者具有与图1所示不同的配置。The method embodiment provided in Embodiment 1 of the present application may be executed in a mobile terminal, a computer terminal, or a similar computing device. Taking running on a computer terminal as an example, FIG. 1 is a hardware structural block diagram of a computer terminal of a file repair method according to an embodiment of the present application. As shown in FIG. 1 , the computer terminal 10 may include one or more (only one is shown in the figure) processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA) , memory 104 for storing data, and transmission means 106 for communication functions. Those of ordinary skill in the art can understand that the structure shown in FIG. 1 is only a schematic diagram, which does not limit the structure of the above electronic device. For example, the computer terminal 10 may also include more or fewer components than shown in FIG. 1 , or have a different configuration than that shown in FIG. 1 .
存储器104可用于存储应用软件的软件程序以及模块,如本申请实施例中的文件修复方法对应的程序指令/模块,处理器102通过运行存储在存储器104内的软件程序以及模块,从而执行各种功能应用以及数据处理,即实现上述的应用程序的漏洞检测方法。存储器104可包括高速随机存储器,还可包括非易失性存储器,如一个或者多个磁性存储装置、闪存、或者其他非易失性固态存储器。在一些实例中,存储器104可进一步包括相对于处理器102远程设置的存储器,这些远程存储器可以通过网络连接至计算机终端10。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。The memory 104 may be used to store software programs and modules of application software, such as program instructions/modules corresponding to the file repair method in the embodiments of the present application. The processor 102 executes various software programs and modules by running the software programs and modules stored in the memory 104. Function application and data processing, namely, to realize the above-mentioned vulnerability detection method of the application program. Memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, memory 104 may further include memory located remotely from processor 102, which may be connected to computer terminal 10 through a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
传输装置106用于经由一个网络接收或者发送数据。上述的网络具体实例可包括计算机终端10的通信供应商提供的无线网络。在一个实例中,传输装置106包括一个网络适配器(Network Interface Controller,NIC),其可通过基站与其他网络设备相连从而可与互联网进行通讯。在一个实例中,传输装置106可以为射频(Radio Frequency,RF)模块,其用于通过无线方式与互联网进行通讯。Transmission means 106 are used to receive or transmit data via a network. A specific example of the above-mentioned network may include a wireless network provided by a communication provider of the computer terminal 10 . In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 may be a radio frequency (Radio Frequency, RF) module, which is used for wirelessly communicating with the Internet.
在上述运行环境下,本申请提供了如图2所示的文件修复方法。图2是根据本申请实施例一的文件修复方法的流程图。Under the above operating environment, the present application provides a file repairing method as shown in FIG. 2 . FIG. 2 is a flowchart of a file restoration method according to Embodiment 1 of the present application.
如图2所示,该文件修复方法可以包括如下实现步骤:As shown in Figure 2, the file repairing method may include the following implementation steps:
步骤S202,获取请求装置上传的具有第一格式的可疑文件。Step S202, obtaining a suspicious file in the first format uploaded by the requesting device.
本申请上述步骤S202中,请求装置可以是指安装在用户设备上的一个应用程序(例如客户端),该请求装置可以根据服务器端的配置,定时启动对用户设备进行扫描,当发现可疑文件时,通过预先配置的通道上传该可疑文件至文件修复装置,请求装置也可以是计算机终端或者类似的运算装置,定时启动对自身磁盘文件进行扫描,当发现可疑文件时,通过预先配置的通道将可疑文件发送给文件修复装置。In the above step S202 of the present application, the requesting device may refer to an application program (such as a client) installed on the user equipment, and the requesting device may periodically start scanning the user equipment according to the configuration of the server, and when a suspicious file is found, Upload the suspicious file to the file restoration device through a pre-configured channel. The requesting device can also be a computer terminal or a similar computing device, which regularly starts to scan its own disk file. Sent to the file restoration device.
其中,文件修复装置接收到来自请求装置的具有第一格式的可疑文件之后,可以对该可疑文件进行解析,以实现可疑文件的修复,文件修复装置例如可以为AliYunDun服务器。Wherein, after receiving the suspicious file in the first format from the requesting device, the file repairing device can parse the suspicious file to repair the suspicious file. The file repairing device can be, for example, an AliYunDun server.
以请求装置为AliYunDun(阿里云盾)为例,AliYunDun基于C/S(Client/Server,客户端/服务器)的网络架构,每台用户设备上都部署有一个独立的AliYunDun程序,并通过加密通道和AliYunDun服务器保持长连接。根据服务器的配置,AliYunDun定时从服务器下载最新AliVulfix(云盾附属组件)漏洞修复程序,替换本地的漏洞修复程序。根据服务器的配置,AliYunDun可以控制AliVulfix漏洞修复程序定时启动,对用户设备上的所有磁盘目录进行全盘遍历扫描,并根据服务器下发的配置信息收取指定目录的文件,例如配置项有一条为:/plus/mytag_js.php,则AliVulfix会扫描并通过AliYunDun的加密通过上报这个可疑文件。Take AliYunDun (Alibaba Cloud Shield) as the requesting device as an example. AliYunDun is based on the C/S (Client/Server, client/server) network architecture. Each user device is deployed with an independent AliYunDun program, which is encrypted through an encrypted channel. Keep a long connection with the AliYunDun server. According to the configuration of the server, AliYunDun regularly downloads the latest AliVulfix (a cloud shield accessory component) vulnerability repair program from the server to replace the local vulnerability repair program. According to the configuration of the server, AliYunDun can control the AliVulfix vulnerability repair program to start regularly, perform a full-disk traversal scan of all disk directories on the user device, and collect files in the specified directory according to the configuration information issued by the server. For example, one of the configuration items is: / plus/mytag_js.php, AliVulfix will scan and report this suspicious file through AliYunDun encryption.
步骤S204,按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组。Step S204, according to the grammatical features of each field in the suspicious file, the fields with the same grammatical feature are formed into at least one field group.
本申请上述步骤S204中,文件修复装置在获取该可疑文件之后,为了对漏洞采取一对一针对性修复并且提高修复效率,以免修复时间过长导致黑客利用该时间间隙入侵用户设备,文件修复装置可以按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组。In the above step S204 of the present application, after acquiring the suspicious file, the file repairing device performs one-to-one targeted repairs on the vulnerability and improves the repairing efficiency, so as to prevent the hacker from using the time gap to invade the user equipment due to the excessively long repairing time. According to the grammatical characteristics of each field in the suspicious file, fields with the same grammatical characteristics can be formed into at least one field group.
以文件修复装置为AliYunDun服务器为例,因为阿里云上用户大部分是电商、网站用户,用户常常有对自己网站代码文件做定制化修改的情况,为了保证漏洞修复不影响这些用户网站的正常运行,AliYunDun服务器采取了一对一针对性修复的策略,然而,一对一修复会产生一个问题,采用1∶1修复后,在阿里云数十万体量的用户数下,在服务器端会收到大量的存在漏洞的文件,即使进行过滤,文件数量还是很多,因此,AliYunDun服务器可以将上述可疑文件解析成语法树结构。Take the file repair device as the AliYunDun server as an example, because most of the users on Alibaba Cloud are e-commerce and website users, and users often make customized modifications to their website code files, in order to ensure that the vulnerability repair does not affect the normal operation of these user websites In operation, the AliYunDun server adopts a one-to-one targeted repair strategy. However, one-to-one repair will cause a problem. After a 1:1 repair, under the number of hundreds of thousands of users of Alibaba Cloud, there will be a problem on the server side. After receiving a large number of files with vulnerabilities, even after filtering, the number of files is still large. Therefore, the AliYunDun server can parse the above suspicious files into a syntax tree structure.
本申请实施例中,文件修复装置首先要对可疑文件进行语法分析,确定可疑文件中各个字段的语法特征,其中,语法分析指的是将代码扫描到一个容器中,然后对该容器中的字符在词法分析的基础上将字段组合成各类语法短语。在确定了各个字段的语法特征之后,文件修复装置可以将语法特征相同的字段组成至少一个字段组,进一步地,文件修复装置可以依据各个字段之间的父子关系,将至少一个字段组解析为语法树结构。In the embodiment of the present application, the file repairing device firstly performs syntax analysis on the suspicious file to determine the syntax characteristics of each field in the suspicious file, where the syntax analysis refers to scanning the code into a container, On the basis of lexical analysis, fields are combined into various grammatical phrases. After determining the grammatical features of each field, the file repairing apparatus may form at least one field group with fields with the same grammatical feature, and further, the file repairing apparatus may parse the at least one field group into a grammar according to the parent-child relationship between the fields tree structure.
步骤S206,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征。Step S206, according to the grammatical feature of each field group, obtain the token sequence feature corresponding to each grammatical feature.
本申请上述步骤S206中,令牌序列特征可以是由安全运营人员预先配置的,文件修复装置利用对应于各个语法特征的令牌序列特征,实现漏洞的查找。In the above step S206 of the present application, the token sequence feature may be pre-configured by security operators, and the file repairing device uses the token sequence feature corresponding to each grammatical feature to search for vulnerabilities.
步骤S208,依据令牌序列特征,确定至少一个字段组中的漏洞。Step S208, according to the token sequence feature, determine the vulnerability in at least one field group.
本申请上述步骤S208中,文件修复装置在获取到各个语法特征对应的令牌序列特征之后,可以依据令牌序列特征在至少一个字段组中进行漏洞的定位。In the above-mentioned step S208 of the present application, after acquiring the token sequence feature corresponding to each grammatical feature, the file repairing apparatus may locate the vulnerability in at least one field group according to the token sequence feature.
此处以通俗的例子来说明,假如有一百个人,目的是确定眼球颜色蓝色的人,即令牌序列特征是“眼球-蓝色”,那么按照本申请实施例提供的文件修复方法的思路,我们先将这一百个人的各个部分进行分组,例如,将一百个人的眼睛分为一组、鼻子分为一组、嘴巴分为一组等等,那么,在根据令牌序列特征进行漏洞查找时,只需要在眼睛这一组中进行查找,无需再搜索其他部分,达到提高漏洞查找效率的目的。Here is a popular example to illustrate, if there are 100 people, the purpose is to determine the person whose eyeball color is blue, that is, the token sequence feature is "eyeball-blue", then according to the idea of the file restoration method provided by the embodiment of the present application , we first group the various parts of the 100 people, for example, divide the eyes of 100 people into a group, nose into a group, mouth into a group, etc., then, according to the token sequence features When searching for loopholes, it is only necessary to search in the group of eyes, and there is no need to search for other parts, so as to improve the efficiency of loophole search.
可选地,依据令牌序列特征,确定至少一个字段组中的漏洞包括:在至少一个字段组中查找与令牌序列特征相同的字段,将与令牌序列特征相同的字段确定为漏洞。Optionally, determining a vulnerability in at least one field group according to the token sequence feature includes: searching for a field identical to the token sequence feature in the at least one field group, and determining the field identical to the token sequence feature as a vulnerability.
本申请实施例中,安全运营人员只需配置一次上述令牌序列特征,文件修复装置则可以自动化进行漏洞的定位,提高了安全运营的时间成本。In the embodiment of the present application, the security operator only needs to configure the above token sequence feature once, and the file repair device can automatically locate the vulnerability, which increases the time cost of security operation.
步骤S210,将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组。Step S210, replacing the vulnerability with a preset repair code sequence to obtain at least one field group after repair.
本申请上述步骤S210中,预设的修复代码序列也可以是安全运营人员预先配置的。文件修复装置在依据令牌序列特征,确定至少一个字段组中的漏洞之后,可以获取该预设的修复代码序列,进而,将漏洞替换为该预设的修复代码序列,实现可疑文件的修复。In the above step S210 of the present application, the preset repair code sequence may also be pre-configured by the security operator. After determining the vulnerability in at least one field group according to the token sequence feature, the file repairing device can obtain the preset repair code sequence, and then replace the vulnerability with the preset repair code sequence to realize repair of suspicious files.
本申请实施例的文件修复装置采用的1∶1的精确定点修复技术,即所有的可疑文件都直接基于请求装置原始文件进行针对性的修改,这样可以最大程度地避免因为漏洞修复造成代码逻辑的不一致从而导致用户的正常业务逻辑受到影响,甚至不可用。同时,安全运营人员只需要配置一个修复代码序列,在文件修复装置确定漏洞时,将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组。The file repairing device of the embodiment of the present application adopts the 1:1 precise point repairing technology, that is, all suspicious files are directly modified based on the original file of the requesting device, which can avoid the code logic caused by the vulnerability repair to the greatest extent. The inconsistency causes the normal business logic of the user to be affected or even unavailable. At the same time, the security operator only needs to configure a repair code sequence, and when the file repair device determines a vulnerability, replace the vulnerability with a preset repair code sequence to obtain at least one field group after repair.
步骤S212,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。Step S212, reorganizing the repaired at least one field group into a repaired file with the first format corresponding to the suspicious file.
本申请上述步骤S212中,由于上述文件修复过程中,文件修复装置将具有第一格式的可疑文件按照各个字段的语法特征拆分为了至少一个字段组,因此在得到修复后的至少一个字段组之后,文件修复装置可以按照其逆过程,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。In the above-mentioned step S212 of the present application, in the above-mentioned file repairing process, the file repairing device divides the suspicious file having the first format into at least one field group according to the grammatical characteristics of each field, so after obtaining the repaired at least one field group , the file repairing apparatus can reorganize the repaired at least one field group into a repaired file with the first format corresponding to the suspicious file according to its reverse process.
可选地,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件包括:按照修复后的至少一个字段组中各个字段的父子关系,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。Optionally, reorganizing the repaired at least one field group into a repaired file with the first format corresponding to the suspicious file includes: reorganizing the repaired at least one field according to the parent-child relationship of each field in the repaired at least one field group. The group is reorganized into repair files in the first format corresponding to suspicious files.
以文件修复装置为AliYunDun服务器为例,AliYunDun服务器可以将上述可疑文件解析成语法树结构之后,依据token序列特征(令牌序列特征)定位漏洞,进而在语法树中插入了预设的修复代码序列之后,然后重建可疑文件,完成本次可疑文件的漏洞修复,得到上述的修复文件。Taking the file repairing device as the AliYunDun server as an example, the AliYunDun server can parse the above suspicious file into a syntax tree structure, locate the vulnerability according to the token sequence feature (token sequence feature), and then insert a preset repair code sequence into the syntax tree. After that, rebuild the suspicious file, complete the vulnerability repair of the suspicious file, and obtain the above repaired file.
本申请实施例提供的文件修复方法,由于可疑文件的数量可能成千上万,因此采用上述的文件修复方法整个过程都可以通过程序代码实现自动化,实现整个漏洞修复。从发现,到审核、到修复的全过程自动化,理论上可以实现阿里云全网的用户设备在20分钟内全部修复某一个漏洞。In the file repairing method provided by the embodiment of the present application, since the number of suspicious files may be thousands, the whole process of using the above-mentioned file repairing method can be automated through program code, and the entire vulnerability repairing can be realized. From discovery, to auditing, to automating the whole process of repair, in theory, all user devices on Alibaba Cloud's entire network can be repaired for a certain vulnerability within 20 minutes.
本申请实施例的文件修复方法至少具有以下技术效果:The file restoration method of the embodiment of the present application has at least the following technical effects:
1、精确地针对每个用户的特定业务修复其中的漏洞;1. Fix the vulnerabilities precisely for each user's specific business;
2、漏洞修复全过程自动化,安全运营人员只需要专注于漏洞的研究,并进行一次配置,之后的全网修复动作完全是全自动化;2. The whole process of vulnerability repair is automated. Security operators only need to focus on vulnerability research and perform one configuration. After that, the entire network repair action is fully automated;
3、实现阿里云全网的机器在20分钟内全部修复某一个漏洞;3. Realize that all machines in the entire Alibaba Cloud network can repair a certain vulnerability within 20 minutes;
4、采用语法树的方式进行漏洞的定位和修复,可以避免正则、字符串搜索带来的误报,具有很高的准确率和很低的误报率;4. Use the syntax tree method to locate and repair vulnerabilities, which can avoid false positives caused by regular and string searches, with high accuracy and low false positive rate;
5、不影响请求装置待修复程序的正常运行。5. Does not affect the normal operation of the program to be repaired on the requesting device.
由上可知,本申请上述实施例一所提供的方案,通过按照语法特征对可疑文件进行拆分得到至少一个字段组之后,依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果,进而解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。As can be seen from the above, in the solution provided by the first embodiment of the present application, after at least one field group is obtained by splitting suspicious files according to grammatical features, loopholes are searched and repaired according to the corresponding token sequence features and repair code sequences of each grammatical feature. Repair, to achieve the purpose of 1:1 automatic repair of the vulnerability, thereby achieving the technical effect of improving the accuracy of vulnerability repair and system security, and then solving the vulnerability repair caused by the use of the same set of Patch codes in the existing technology. Technical issues with poor accuracy.
本申请上述实施例提供的一种可选方案中,如图3所示,在可疑文件的数量为至少两个的情况下,上述步骤S202获取请求装置上传的具有第一格式的可疑文件之后,上述步骤S204按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组之前,文件修复方法还可以包括:In an optional solution provided by the above embodiment of the present application, as shown in FIG. 3 , in the case where the number of suspicious files is at least two, after obtaining the suspicious files in the first format uploaded by the requesting device in the above step S202, In the above-mentioned step S204, according to the grammatical features of each field in the suspicious file, before the fields with the same grammatical features are formed into at least one field group, the file repairing method may further include:
步骤S302,提取各个可疑文件的元信息,其中,元信息包括对应可疑文件的文件路径及消息摘要算法MD5,文件路径是指可疑文件在请求装置所在的用户设备上的路径。Step S302: Extract the meta information of each suspicious file, wherein the meta information includes the file path corresponding to the suspicious file and the message digest algorithm MD5, and the file path refers to the path of the suspicious file on the user equipment where the requesting device is located.
本申请上述步骤S302中,文件修复装置获取到的可疑文件的数量可能成千上万,那么其中可能存在一些重复的文件,因此,在可疑文件的数量为至少两个的情况下,文件修复装置可以对可疑文件进行去重处理。In the above step S302 of the present application, the number of suspicious files acquired by the file repairing device may be thousands, and there may be some duplicate files. Therefore, when the number of suspicious files is at least two, the file repairing device may Suspicious files can be deduplicated.
那么,在可疑文件的数量为至少两个的情况下,文件修复装置可以提取各个可疑文件的元信息,并将元信息保存到分布式的指纹数据库中。其中,元信息可以包括对应可疑文件的文件路径及MD5(Message Digest Algorithm,消息摘要算法),文件路径是指可疑文件在请求装置所在的用户设备上的路径。Then, when the number of suspicious files is at least two, the file repairing apparatus can extract the meta information of each suspicious file, and save the meta information in the distributed fingerprint database. The meta information may include a file path and MD5 (Message Digest Algorithm) corresponding to the suspicious file, and the file path refers to the path of the suspicious file on the user equipment where the requesting apparatus is located.
步骤S304,根据文件路径及MD5,对各个可疑文件进行去重处理。Step S304, performing deduplication processing on each suspicious file according to the file path and MD5.
本申请上述步骤S304中,去重处理是指去掉重复的可疑文件。文件修复装置在提取了各个可疑文件的文件路径和MD5之后,可以根据文件路径及MD5判断该各个可疑文件之中是否存在重复的文件,进而对各个可疑文件进行去重处理。In the above step S304 of the present application, the deduplication process refers to removing duplicate suspicious files. After extracting the file path and MD5 of each suspicious file, the file repairing device can judge whether there are duplicate files in each suspicious file according to the file path and MD5, and then perform deduplication processing on each suspicious file.
本申请上述实施例提供的一种可选方案中,如图4所示,上述步骤S304,根据文件路径及MD5,对各个可疑文件进行去重处理可以包括:In an optional solution provided by the above-mentioned embodiment of the present application, as shown in FIG. 4 , in the above-mentioned step S304, according to the file path and MD5, performing deduplication processing on each suspicious file may include:
步骤S402,确定各个可疑文件中重复的可疑文件,其中,重复的可疑文件是指文件路径相同且MD5相同的文件。Step S402 , determining repeated suspicious files in each suspicious file, wherein the repeated suspicious files refer to files with the same file path and the same MD5.
本申请上述步骤S402中,针对如何根据文件路径及MD5,对各个可疑文件进行去重处理,本申请实施例提供的方法为文件修复装置通过判断各个可疑文件的文件路径是否相同,以及各个可疑文件的MD5是否相同,若文件路径相同且MD5相同,则确定为重复的可疑文件。In the above step S402 of the present application, with respect to how to perform deduplication processing on each suspicious file according to the file path and MD5, the method provided by the embodiment of the present application is that the file restoration device determines whether the file paths of each suspicious file are the same, and each suspicious file Whether the MD5 is the same, if the file path is the same and the MD5 is the same, it is determined to be a duplicate suspicious file.
例如,文件修复装置在提取各个可疑文件的文件路径和MD5之后,判断出可疑文件1、可疑文件7、可疑文件24及可疑文件30的文件路径相同且MD5相同,那么文件修复装置确定该可疑文件1、可疑文件7、可疑文件24及可疑文件30为重复的可疑文件。For example, after extracting the file path and MD5 of each suspicious file, the file repairing device determines that the file paths of suspicious file 1, suspicious file 7, suspicious file 24 and suspicious file 30 are the same and the MD5 is the same, then the file repairing device determines the suspicious file. 1. Suspicious file 7, suspicious file 24 and suspicious file 30 are duplicate suspicious files.
步骤S404,保留重复的可疑文件中的第一文件,将除第一文件以外的重复的可疑文件删除,其中,第一文件为重复的可疑文件中的任意一个。Step S404: Retain the first file among the repeated suspicious files, and delete the repeated suspicious files except the first file, where the first file is any one of the repeated suspicious files.
本申请上述步骤S404中,文件修复装置在确定了各个可疑文件中重复的可疑文件之后,需要只保留其中一个可疑文件,删除其他重复的可疑文件以实现去重处理。In the above step S404 of the present application, after determining the duplicate suspicious files in each suspicious file, the file repairing device needs to keep only one of the suspicious files, and delete the other duplicate suspicious files to realize deduplication processing.
例如,文件修复装置在确定了可疑文件1、可疑文件7、可疑文件24及可疑文件30为重复的可疑文件之后,可以保留可疑文件1、可疑文件7、可疑文件24及可疑文件30中的任意一个文件,例如保留可疑文件1,进而将除可疑文件1以外的重复的可疑文件删除,即删除可疑文件7、可疑文件24及可疑文件30,实现对可疑文件的去重处理。For example, after determining that suspicious file 1, suspicious file 7, suspicious file 24, and suspicious file 30 are duplicate suspicious files, the file repairing device can keep any one of suspicious file 1, suspicious file 7, suspicious file 24, and suspicious file 30. One file, for example, keep suspicious file 1, and then delete the duplicate suspicious files except suspicious file 1, that is, delete suspicious file 7, suspicious file 24 and suspicious file 30, so as to realize deduplication processing of suspicious files.
本申请上述实施例提供的一种可选方案中,如图5所示,上述步骤S212,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件之后,文件修复方法还可以包括:In an optional solution provided by the above-mentioned embodiment of the present application, as shown in FIG. 5 , in the above step S212, after the repaired at least one field group is reorganized into a repaired file in the first format corresponding to the suspicious file, the file is repaired. Methods can also include:
步骤S502,接收请求装置发送的第一请求,第一请求用于下载更新后的漏洞修复程序。Step S502: Receive a first request sent by the requesting device, where the first request is used to download the updated vulnerability repair program.
本申请上述步骤S502中,请求装置根据配置可以定时下载最新的漏洞修复重新,进而,文件修复装置可以接收到请求装置发送的用于下载更新后的漏洞修复程序的第一请求。In the above step S502 of the present application, the requesting device may periodically download the latest vulnerability repair program according to the configuration, and further, the file repairing device may receive a first request sent by the requesting device for downloading the updated vulnerability repair program.
以请求装置为AliYunDun、文件修复装置为AliYunDun服务器为例,AliYunDun基于C/S网络架构,通过加密通道和AliYunDun服务器保持长连接,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新AliVulfix漏洞修复程序。Take the requesting device as AliYunDun and the file repairing device as the AliYunDun server as an example. Based on the C/S network architecture, AliYunDun maintains a long-term connection with the AliYunDun server through encrypted channels. According to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server. .
步骤S504,向请求装置发送更新后的漏洞修复程序,其中,更新后的漏洞修复程序中包含修复文件,以便请求装置根据修复文件对可疑文件进行修复。Step S504: Send the updated vulnerability repair program to the requesting device, wherein the updated vulnerability repair program includes a repair file, so that the requesting device repairs the suspicious file according to the repair file.
本申请上述步骤S504中,文件修复装置在完成对可疑文件的修复之后,会得到一份最新的漏洞修复程序,例如,该漏洞修复程序的形式可以为:{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb34″,″action″:″delete″};{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb55″,″action″:″replace″}。这个最新的漏洞修复程序准确定位到上述的可疑文件的文件路径下,对应MD5的可疑文件,请求装置在下载了该更新后的漏洞修复程序之后,可以根据更新后的漏洞修复程序中包含的上述修复文件,对可疑文件进行修复,例如将可疑文件为上述修复文件。In the above step S504 of the present application, after completing the repair of the suspicious file, the file repairing device will obtain a copy of the latest vulnerability repair program. For example, the format of the vulnerability repair program may be: {"filename":"/webapps/manager /WEB-INF/web.xml","md5":"bc5ef661b746b0c55462353583a7eb34","action":"delete"};{"filename":"/webapps/manager/WEB-INF/web.xml","md5" : "bc5ef661b746b0c55462353583a7eb55", "action": "replace"}. The latest vulnerability repair program is accurately located under the file path of the above-mentioned suspicious file, corresponding to the suspicious file of MD5. After downloading the updated vulnerability repair program, the requesting device can Repair files, repair suspicious files, such as turning suspicious files into the above repaired files.
本申请上述实施例提供的一种可选方案中,如图6所示,上述步骤S502,接收请求装置发送的第一请求,第一请求用于下载更新后的漏洞修复程序之前,文件修复方法还可以包括:In an optional solution provided by the above-mentioned embodiment of the present application, as shown in FIG. 6 , in the above step S502, a first request sent by the requesting device is received, and the first request is used to download the updated vulnerability repair program. Can also include:
步骤S602,接收来自请求装置发送的第二请求,第二请求用于获取更新后的漏洞修复程序的标识信息。Step S602: Receive a second request sent from the requesting device, where the second request is used to obtain the identification information of the updated vulnerability repair program.
本申请上述步骤S602中,由于请求装置是根据配置定时下载漏洞修复程序,因此请求装置可以先判断该更新后的漏洞修复程序是否为最新的。In the above step S602 of the present application, since the requesting device downloads the vulnerability repair program periodically according to the configuration, the requesting device can first determine whether the updated vulnerability repair program is the latest.
仍旧以请求装置为AliYunDun、文件修复装置为AliYunDun服务器为例,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新AliVulfix漏洞修复程序,判断是否为最新的标准为,检查保存在AliYunDun服务器的AliVulfix漏洞修复程序的MD5是否和本机之前下载过的AliVulfix漏洞修复程序的MD5是否相同,如果不同,说明AliYunDun服务器进行了修改变动,则重新下载一次最新的AliVulfix漏洞修复程序,替换本地的AliVulfix漏洞修复程序。Taking the requesting device as AliYunDun and the file repairing device as the AliYunDun server as an example, according to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server, and the criterion for judging whether it is the latest is to check the AliVulfix vulnerability saved in the AliYunDun server. Whether the MD5 of the repair program is the same as the MD5 of the AliVulfix vulnerability repair program downloaded on the machine before, if it is different, it means that the AliYunDun server has been modified and changed, then download the latest AliVulfix vulnerability repair program again, and replace the local AliVulfix vulnerability repair program .
步骤S604,向请求装置发送更新后的漏洞修复程序的MD5,其中,由请求装置根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同,若相同,请求装置则发起第一请求。Step S604, sending the MD5 of the updated vulnerability repair program to the requesting device, wherein the requesting device determines whether the updated vulnerability repair program is the same as the vulnerability repair program stored by the requesting device according to the MD5 of the updated vulnerability repair program, If the same, the requesting device initiates the first request.
可选地,请求装置根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同可以包括:请求装置获取已存储的漏洞修复程序的MD5;请求装置判断更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5是否相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5不相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序不相同。Optionally, the requesting device, according to the MD5 of the updated vulnerability repair program, judging whether the updated vulnerability repair program is the same as the stored vulnerability repair program of the requesting device may include: requesting the device to obtain the MD5 of the stored vulnerability repair program; requesting The device determines whether the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program; if the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program, the updated vulnerability repair program is determined. It is the same as the bugfix already stored by the requesting device; if the MD5 of the updated bugfix is not the same as the MD5 of the stored bugfix, it is determined that the updated bugfix is different from the bugfix already stored by the requesting device. same.
在上述运行环境下,本申请还提供了一种文件修复方法。该文件修复方法可以包括如下实现步骤:Under the above operating environment, the present application also provides a file repairing method. The file repairing method may include the following implementation steps:
步骤S10,将具有第一格式的可疑文件发送至文件修复装置,其中,由文件修复装置按照可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据令牌序列特征,确定至少一个字段组中的漏洞,将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。Step S10, sending the suspicious file having the first format to the file repairing device, wherein the file repairing device forms at least one field group according to the grammatical features of each field in the suspicious file, and according to each field group grammatical features, obtain the token sequence feature corresponding to each grammatical feature, determine the vulnerability in at least one field group according to the token sequence feature, replace the vulnerability with a preset repair code sequence, and obtain the repaired at least one field group, The repaired at least one field group is reorganized into a repaired file having the first format corresponding to the suspicious file.
本申请上述步骤S10中,请求装置可以是指安装在用户设备上的一个应用程序(例如客户端),该请求装置可以根据服务器端的配置,定时启动对用户设备进行扫描,当发现可疑文件时,通过预先配置的通道上传该可疑文件至文件修复装置,请求装置也可以是计算机终端或者类似的运算装置,定时启动对自身磁盘文件进行扫描,当发现可疑文件时,通过预先配置的通道将可疑文件发送给文件修复装置。In the above step S10 of the present application, the requesting device may refer to an application program (such as a client) installed on the user equipment, and the requesting device may periodically start scanning the user equipment according to the configuration of the server, and when a suspicious file is found, Upload the suspicious file to the file restoration device through a pre-configured channel. The requesting device can also be a computer terminal or a similar computing device, which regularly starts to scan its own disk file. Sent to the file restoration device.
步骤S12,从文件修复装置中获取对应于可疑文件的具有第一格式的修复文件。Step S12, obtaining a repaired file in the first format corresponding to the suspicious file from the file repairing device.
可选地,步骤S12从文件修复装置中获取对应于可疑文件的具有第一格式的修复文件包括:Optionally, step S12 obtaining a repaired file in the first format corresponding to the suspicious file from the file repairing device includes:
步骤S20,向文件修复装置发送第一请求,第一请求用于下载更新后的漏洞修复程序。Step S20, sending a first request to the file repairing apparatus, where the first request is used to download the updated vulnerability repair program.
本申请上述步骤S20中,请求装置根据配置可以定时下载最新的漏洞修复重新,进而,文件修复装置可以接收到请求装置发送的用于下载更新后的漏洞修复程序的第一请求。In the above step S20 of the present application, the requesting device may periodically download the latest vulnerability repair program according to the configuration, and further, the file repairing device may receive a first request sent by the requesting device for downloading the updated vulnerability repair program.
以请求装置为AliYunDun、文件修复装置为AliYunDun服务器为例,AliYunDun基于C/S网络架构,通过加密通道和AliYunDun服务器保持长连接,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新AliVulfix漏洞修复程序。Take the requesting device as AliYunDun and the file repairing device as the AliYunDun server as an example. Based on the C/S network architecture, AliYunDun maintains a long-term connection with the AliYunDun server through encrypted channels. According to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server. .
步骤S22,接收文件修复装置返回的更新后的漏洞修复程序,其中,更新后的漏洞修复程序中包含修复文件。Step S22, receiving an updated vulnerability repair program returned by the file repairing device, wherein the updated vulnerability repair program includes a repair file.
本申请上述步骤S22中,文件修复装置在完成对可疑文件的修复之后,会得到一份最新的漏洞修复程序,例如,该漏洞修复程序的形式可以为:{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb34″,″action″:″delete″};{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb55″,″action″:″replace″}。这个最新的漏洞修复程序准确定位到上述的可疑文件的文件路径下,对应MD5的可疑文件,请求装置在下载了该更新后的漏洞修复程序之后,可以根据更新后的漏洞修复程序中包含的上述修复文件,对可疑文件进行修复,例如将可疑文件为上述修复文件。In the above step S22 of the present application, after completing the repair of the suspicious file, the file repair device will obtain a copy of the latest vulnerability repair program. For example, the format of the vulnerability repair program may be: {"filename":"/webapps/manager /WEB-INF/web.xml","md5":"bc5ef661b746b0c55462353583a7eb34","action":"delete"};{"filename":"/webapps/manager/WEB-INF/web.xml","md5" : "bc5ef661b746b0c55462353583a7eb55", "action": "replace"}. The latest vulnerability repair program is accurately located under the file path of the above-mentioned suspicious file, corresponding to the suspicious file of MD5. After downloading the updated vulnerability repair program, the requesting device can Repair files, repair suspicious files, such as turning suspicious files into the above repaired files.
可选地,在步骤S20,向文件修复装置发送第一请求之前,文件修复方法还包括:Optionally, in step S20, before sending the first request to the file repairing device, the file repairing method further includes:
步骤S30,向文件修复装置发送第二请求,第二请求用于获取更新后的漏洞修复程序的标识信息。Step S30, sending a second request to the file repairing apparatus, where the second request is used to obtain the identification information of the updated vulnerability repair program.
本申请上述步骤S30中,由于请求装置是根据配置定时下载漏洞修复程序,因此请求装置可以先判断该更新后的漏洞修复程序是否为最新的。In the above step S30 of the present application, since the requesting device downloads the vulnerability repair program periodically according to the configuration, the requesting device can first determine whether the updated vulnerability repair program is the latest.
仍旧以请求装置为AliYunDun、文件修复装置为AliYunDun服务器为例,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新AliVulfix漏洞修复程序,判断是否为最新的标准为,检查保存在AliYunDun服务器的AliVulfix漏洞修复程序的MD5是否和本机之前下载过的AliVulfix漏洞修复程序的MD5是否相同,如果不同,说明AliYunDun服务器进行了修改变动,则重新下载一次最新的AliVulfix漏洞修复程序,替换本地的AliVulfix漏洞修复程序。Taking the requesting device as AliYunDun and the file repairing device as the AliYunDun server as an example, according to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server, and the criterion for judging whether it is the latest is to check the AliVulfix vulnerability saved in the AliYunDun server. Whether the MD5 of the repair program is the same as the MD5 of the AliVulfix vulnerability repair program downloaded on the machine before, if it is different, it means that the AliYunDun server has been modified and changed, then download the latest AliVulfix vulnerability repair program again, and replace the local AliVulfix vulnerability repair program .
步骤S32,接收文件修复装置返回的更新后的漏洞修复程序的MD5。Step S32, receiving the MD5 of the updated vulnerability repair program returned by the file repairing device.
步骤S34,根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同,若相同,请求装置则发起第一请求。Step S34, according to the MD5 of the updated vulnerability repair program, determine whether the updated vulnerability repair program is the same as the vulnerability repair program stored by the requesting device, and if they are the same, the requesting device initiates a first request.
可选地,请求装置根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同可以包括:请求装置获取已存储的漏洞修复程序的MD5;请求装置判断更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5是否相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5不相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序不相同。Optionally, the requesting device, according to the MD5 of the updated vulnerability repair program, judging whether the updated vulnerability repair program is the same as the stored vulnerability repair program of the requesting device may include: requesting the device to obtain the MD5 of the stored vulnerability repair program; requesting The device determines whether the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program; if the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program, the updated vulnerability repair program is determined. It is the same as the bugfix already stored by the requesting device; if the MD5 of the updated bugfix is not the same as the MD5 of the stored bugfix, it is determined that the updated bugfix is different from the bugfix already stored by the requesting device. same.
在一种可选的方案中,以AliYunDun为例,结合图7,对本申请上述文件修复方法进行描述:In an optional solution, taking AliYunDun as an example, in conjunction with FIG. 7 , the above-mentioned file restoration method of the present application is described:
步骤A,AliYunDun基于C/S的网络架构,每台用户设备上都部署有一个独立的AliYunDun程序,并通过加密通道和AliYunDun服务器保持长连接。Step A, AliYunDun is based on the C/S network architecture, and an independent AliYunDun program is deployed on each user device, and maintains a long connection with the AliYunDun server through an encrypted channel.
本申请上述步骤A中,AliYunDun相当于上述的请求装置,AliYunDun服务器相当于上述的文件修复装置,请求装置可以根据服务器端的配置,定时启动对用户设备进行扫描,当发现可疑文件时,通过预先配置的通道上传该可疑文件。In the above step A of this application, AliYunDun is equivalent to the above-mentioned requesting device, and the AliYunDun server is equivalent to the above-mentioned file repairing device. The requesting device can periodically start scanning the user equipment according to the configuration of the server side. channel to upload the suspicious file.
步骤B,根据AliYunDun服务器的配置,AliYunDun定时从AliYunDun服务器下载最新的AliVulfix漏洞修复程序。Step B, according to the configuration of the AliYunDun server, AliYunDun regularly downloads the latest AliVulfix vulnerability repair program from the AliYunDun server.
本申请上述步骤B中,判断是否为最新的标准为,检查保存在AliYunDun服务器的AliVulfix漏洞修复程序的MD5是否和本机之前下载过的AliVulfix漏洞修复程序的MD5是否相同,如果不同,说明AliYunDun服务器进行了修改变动,则重新下载一次最新的AliVulfix漏洞修复程序,替换本地的AliVulfix漏洞修复程序。In the above step B of this application, the criterion for judging whether it is the latest is to check whether the MD5 of the AliVulfix vulnerability repair program saved in the AliYunDun server is the same as the MD5 of the AliVulfix vulnerability repair program that has been downloaded to the local machine before. If it is different, it means that the AliYunDun server If changes are made, download the latest AliVulfix vulnerability repair program again to replace the local AliVulfix vulnerability repair program.
由于请求装置是根据配置定时下载漏洞修复程序,因此请求装置可以先判断该更新后的漏洞修复程序是否为最新的,请求装置根据更新后的漏洞修复程序的MD5,判断更新后的漏洞修复程序与请求装置已存储的漏洞修复程序是否相同可以包括:请求装置获取已存储的漏洞修复程序的MD5;请求装置判断更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5是否相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序相同;若更新后的漏洞修复程序的MD5与已存储的漏洞修复程序的MD5不相同,则确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序不相同。Since the requesting device periodically downloads the vulnerability repair program according to the configuration, the requesting device can first determine whether the updated vulnerability repair program is the latest, and the requesting device determines whether the updated vulnerability repair program is the same as the updated vulnerability repair program according to the MD5 of the updated vulnerability repair program. Requesting whether the vulnerability repair programs stored by the device are the same may include: requesting the device to obtain the MD5 of the stored vulnerability repair program; requesting the device to determine whether the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program; The MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program, then it is determined that the updated vulnerability repair program is the same as the stored vulnerability repair program of the requesting device; if the MD5 of the updated vulnerability repair program is the same as the stored vulnerability repair program If the MD5 of the vulnerability repair program is not the same, it is determined that the updated vulnerability repair program is not the same as the vulnerability repair program stored in the requesting device.
在确定更新后的漏洞修复程序与请求装置已存储的漏洞修复程序不相同时,文件修复装置可以接收到请求装置发送的用于下载更新后的漏洞修复程序的第一请求,并向请求装置发送更新后的漏洞修复程序,其中,更新后的漏洞修复程序中包含修复文件,以便请求装置根据修复文件对可疑文件进行修复。When it is determined that the updated vulnerability repair program is not the same as the vulnerability repair program stored by the requesting device, the file repairing device may receive a first request sent by the requesting device for downloading the updated vulnerability repairing program, and send a request to the requesting device. The updated vulnerability repair program, wherein the updated vulnerability repair program includes a repair file, so that the device is requested to repair the suspicious file according to the repair file.
步骤C,根据AliYunDun服务器的配置,用户设备上的AliVulfix漏洞修复程序会定时启动执行。Step C, according to the configuration of the AliYunDun server, the AliVulfix vulnerability repair program on the user device will be started and executed regularly.
本申请上述步骤C中,AliYunDun可以根据服务器端的配置,定时启动对用户设备进行扫描,当发现可疑文件时,通过预先配置的通道上传该可疑文件。In the above step C of this application, AliYunDun can periodically start scanning the user equipment according to the configuration on the server side, and when a suspicious file is found, upload the suspicious file through a pre-configured channel.
步骤D,AliVulfix对用户机器上的所有磁盘目录进行全盘遍历扫描。Step D, AliVulfix performs a full-disk traversal scan on all disk directories on the user's machine.
本申请上述步骤D中,根据AliYunDun服务器下发的配置信息收取指定目录的文件,例如配置项有一条为:/plus/mytag_js.php,则AliVulfix会扫描并通过AliYunDun的加密通过上报这个可疑文件。In the above step D of this application, according to the configuration information issued by the AliYunDun server, the file in the specified directory is received. For example, if there is a configuration item: /plus/mytag_js.php, AliVulfix will scan and report the suspicious file through the encryption of AliYunDun.
步骤E,AliYunDun服务器收到AliYunDun上报的可疑文件后,提取可疑文件的元信息。Step E: After receiving the suspicious file reported by AliYunDun, the AliYunDun server extracts the meta information of the suspicious file.
本申请上述步骤E中,文件修复装置获取到的可疑文件的数量可能成千上万,那么其中可能存在一些重复的文件,因此,在可疑文件的数量为至少两个的情况下,文件修复装置可以对可疑文件进行去重处理。那么,在可疑文件的数量为至少两个的情况下,文件修复装置可以提取各个可疑文件的元信息,并将元信息保存到分布式的指纹数据库中。其中,元信息可以包括对应可疑文件的文件路径及MD5,文件路径是指可疑文件在请求装置所在的用户设备上的路径。In the above step E of the present application, the number of suspicious files acquired by the file repair device may be thousands, and there may be some duplicate files. Therefore, when the number of suspicious files is at least two, the file repair device may Suspicious files can be deduplicated. Then, when the number of suspicious files is at least two, the file repairing apparatus can extract the meta information of each suspicious file, and save the meta information in the distributed fingerprint database. The meta information may include the file path and MD5 corresponding to the suspicious file, and the file path refers to the path of the suspicious file on the user equipment where the requesting device is located.
去重处理是指去掉重复的可疑文件。文件修复装置在提取了各个可疑文件的文件路径和MD5之后,可以根据文件路径及MD5判断该各个可疑文件之中是否存在重复的文件,进而对各个可疑文件进行去重处理。针对如何根据文件路径及MD5,对各个可疑文件进行去重处理,本申请实施例提供的方法为文件修复装置通过判断各个可疑文件的文件路径是否相同,以及各个可疑文件的MD5是否相同,若文件路径相同且MD5相同,则确定为重复的可疑文件。Deduplication refers to removing duplicate suspicious files. After extracting the file path and MD5 of each suspicious file, the file repairing device can judge whether there are duplicate files in each suspicious file according to the file path and MD5, and then perform deduplication processing on each suspicious file. Regarding how to perform deduplication processing on each suspicious file according to the file path and MD5, the method provided by the embodiment of the present application is that the file repair device judges whether the file path of each suspicious file is the same, and whether the MD5 of each suspicious file is the same, if the file If the path is the same and the MD5 is the same, it is determined to be a duplicate suspicious file.
例如,文件修复装置在提取各个可疑文件的文件路径和MD5之后,判断出可疑文件1、可疑文件7、可疑文件24及可疑文件30的文件路径相同且MD5相同,那么文件修复装置确定该可疑文件1、可疑文件7、可疑文件24及可疑文件30为重复的可疑文件。For example, after extracting the file path and MD5 of each suspicious file, the file repairing device determines that the file paths of suspicious file 1, suspicious file 7, suspicious file 24 and suspicious file 30 are the same and the MD5 is the same, then the file repairing device determines the suspicious file. 1. Suspicious file 7, suspicious file 24 and suspicious file 30 are duplicate suspicious files.
可选地,文件修复装置在确定了各个可疑文件中重复的可疑文件之后,需要只保留其中一个可疑文件,删除其他重复的可疑文件以实现去重处理。Optionally, after determining the duplicate suspicious files among the various suspicious files, the file repairing apparatus needs to keep only one of the suspicious files, and delete the other duplicate suspicious files to realize deduplication processing.
例如,文件修复装置在确定了可疑文件1、可疑文件7、可疑文件24及可疑文件30为重复的可疑文件之后,可以保留可疑文件1、可疑文件7、可疑文件24及可疑文件30中的任意一个文件,例如保留可疑文件1,进而将除可疑文件1以外的重复的可疑文件删除,即删除可疑文件7、可疑文件24及可疑文件30,实现对可疑文件的去重处理。For example, after determining that suspicious file 1, suspicious file 7, suspicious file 24, and suspicious file 30 are duplicate suspicious files, the file repairing device can keep any one of suspicious file 1, suspicious file 7, suspicious file 24, and suspicious file 30. One file, for example, keep suspicious file 1, and then delete the duplicate suspicious files except suspicious file 1, that is, delete suspicious file 7, suspicious file 24 and suspicious file 30, so as to realize deduplication processing of suspicious files.
可选地,AliYunDun服务器在提取了可疑文件的元信息之后,可以将元信息保存到分布式的指纹数据库中。Optionally, after the AliYunDun server extracts the meta-information of suspicious files, the meta-information can be saved in a distributed fingerprint database.
步骤F,把可疑文件解析成token语法树结构。Step F, parse the suspicious file into a token syntax tree structure.
本申请上述步骤F中,因为阿里云上用户大部分是电商、网站用户,用户常常有对自己网站代码文件做定制化修改的情况,为了保证漏洞修复不影响这些用户网站的正常运行,AliYunDun服务器采取了一对一针对性修复的策略,然而,一对一修复会产生一个问题,采用1∶1修复后,在阿里云数十万体量的用户数下,在服务器端会收到大量的存在漏洞的文件,即使进行过滤,文件数量还是很多,因此,AliYunDun服务器可以将上述可疑文件解析成语法树结构。In the above step F of this application, because most of the users on Alibaba Cloud are e-commerce and website users, users often make customized modifications to their own website code files. The server adopts a one-to-one targeted repair strategy. However, one-to-one repair will cause a problem. After adopting a 1:1 repair, with hundreds of thousands of users of Alibaba Cloud, the server will receive a large number of The number of vulnerable files is still large even after filtering. Therefore, the AliYunDun server can parse the above suspicious files into a syntax tree structure.
本申请实施例中,文件修复装置首先要对可疑文件进行语法分析,确定可疑文件中各个字段的语法特征,其中,语法分析指的是将代码扫描到一个容器中,然后对该容器中的字符在词法分析的基础上将字段组合成各类语法短语。在确定了各个字段的语法特征之后,文件修复装置可以将语法特征相同的字段组成至少一个字段组,进一步地,文件修复装置可以依据各个字段之间的父子关系,将至少一个字段组解析为语法树结构。In the embodiment of the present application, the file repairing device firstly performs syntax analysis on the suspicious file to determine the syntax characteristics of each field in the suspicious file, where the syntax analysis refers to scanning the code into a container, On the basis of lexical analysis, fields are combined into various grammatical phrases. After determining the grammatical features of each field, the file repairing apparatus may form at least one field group with fields with the same grammatical feature, and further, the file repairing apparatus may parse the at least one field group into a grammar according to the parent-child relationship between the fields tree structure.
步骤G,安全运营人员只需要配置一次token序列特征,用于定位文件中存在的漏洞。In step G, the security operator only needs to configure the token sequence feature once to locate the vulnerability in the file.
本申请上述步骤G中,token序列特征相当于上述的令牌序列特征,令牌序列特征可以是由安全运营人员预先配置的,文件修复装置利用对应于各个语法特征的令牌序列特征,实现漏洞的查找。In the above step G of this application, the token sequence feature is equivalent to the above token sequence feature, the token sequence feature may be pre-configured by security operators, and the file repair device uses the token sequence feature corresponding to each grammatical feature to realize the vulnerability 's search.
文件修复装置在获取到各个语法特征对应的令牌序列特征之后,可以依据令牌序列特征在至少一个字段组中进行漏洞的定位。After acquiring the token sequence feature corresponding to each grammatical feature, the file repairing device can locate the vulnerability in at least one field group according to the token sequence feature.
此处以通俗的例子来说明,假如有一百个人,目的是确定眼球颜色蓝色的人,即令牌序列特征是“眼球-蓝色”,那么按照本申请实施例提供的文件修复方法的思路,我们先将这一百个人的各个部分进行分组,例如,将一百个人的眼睛分为一组、鼻子分为一组、嘴巴分为一组等等,那么,在根据令牌序列特征进行漏洞查找时,只需要在眼睛这一组中进行查找,无需再搜索其他部分,达到提高漏洞查找效率的目的。Here is a popular example to illustrate, if there are 100 people, the purpose is to determine the person whose eyeball color is blue, that is, the token sequence feature is "eyeball-blue", then according to the idea of the file restoration method provided by the embodiment of the present application , we first group the various parts of the 100 people, for example, divide the eyes of 100 people into a group, nose into a group, mouth into a group, etc., then, according to the token sequence features When searching for loopholes, it is only necessary to search in the group of eyes, and there is no need to search for other parts, so as to improve the efficiency of loophole search.
可选地,依据令牌序列特征,确定至少一个字段组中的漏洞包括:在至少一个字段组中查找与令牌序列特征相同的字段,将与令牌序列特征相同的字段确定为漏洞。Optionally, determining a vulnerability in at least one field group according to the token sequence feature includes: searching for a field identical to the token sequence feature in the at least one field group, and determining the field identical to the token sequence feature as a vulnerability.
本申请实施例中,安全运营人员只需配置一次上述令牌序列特征,文件修复装置则可以自动化进行漏洞的定位,提高了安全运营的时间成本。In the embodiment of the present application, the security operator only needs to configure the above token sequence feature once, and the file repair device can automatically locate the vulnerability, which increases the time cost of security operation.
步骤H,安全运营人员同时只需要配置一个patch token序列,用于在定位漏洞后插入patch token序列。In step H, the security operator only needs to configure a patch token sequence, which is used to insert the patch token sequence after locating the vulnerability.
本申请上述步骤H中,patch token序列相当于上述的预设的修复代码序列。预设的修复代码序列也可以是安全运营人员预先配置的。文件修复装置在依据令牌序列特征,确定至少一个字段组中的漏洞之后,可以获取该预设的修复代码序列,进而,将漏洞替换为该预设的修复代码序列,实现可疑文件的修复。In the above step H of the present application, the patch token sequence is equivalent to the above-mentioned preset repair code sequence. Preset repair code sequences can also be preconfigured by security operations personnel. After determining the vulnerability in at least one field group according to the token sequence feature, the file repairing device can obtain the preset repair code sequence, and then replace the vulnerability with the preset repair code sequence to realize repair of suspicious files.
本申请实施例的文件修复装置采用的1∶1的精确定点修复技术,即所有的可疑文件都直接基于请求装置原始文件进行针对性的修改,这样可以最大程度地避免因为漏洞修复造成代码逻辑的不一致从而导致用户的正常业务逻辑受到影响,甚至不可用。同时,安全运营人员只需要配置一个修复代码序列,在文件修复装置确定漏洞时,将漏洞替换为预设的修复代码序列,得到修复后的至少一个字段组。The file repairing device of the embodiment of the present application adopts the 1:1 precise point repairing technology, that is, all suspicious files are directly modified based on the original file of the requesting device, which can avoid the code logic caused by the vulnerability repair to the greatest extent. The inconsistency causes the normal business logic of the user to be affected or even unavailable. At the same time, the security operator only needs to configure a repair code sequence, and when the file repair device determines a vulnerability, replace the vulnerability with a preset repair code sequence to obtain at least one field group after repair.
步骤I,在token语法树中插入了patch token序列之后,然后重建可疑文件,完成本次文件的漏洞修复。In step I, after the patch token sequence is inserted into the token syntax tree, the suspicious file is then reconstructed to complete the vulnerability repair of this file.
本申请上述步骤I中,AliYunDun服务器可以将上述可疑文件解析成语法树结构之后,依据token序列特征(令牌序列特征)定位漏洞,进而在语法树中插入了预设的修复代码序列之后,然后重建可疑文件,完成本次可疑文件的漏洞修复,得到上述的修复文件。In the above-mentioned step 1 of the present application, after the AliYunDun server can parse the above-mentioned suspicious file into a syntax tree structure, locate the vulnerability according to the token sequence feature (token sequence feature), and then insert the preset repair code sequence in the syntax tree, then Rebuild the suspicious file, complete the vulnerability repair of the suspicious file, and obtain the above repaired file.
由于上述文件修复过程中,文件修复装置将具有第一格式的可疑文件按照各个字段的语法特征拆分为了至少一个字段组,因此在得到修复后的至少一个字段组之后,文件修复装置可以按照其逆过程,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。In the above-mentioned file repairing process, the file repairing apparatus divides the suspicious file in the first format into at least one field group according to the grammatical characteristics of each field, so after obtaining the repaired at least one field group, the file repairing apparatus can In the reverse process, the repaired at least one field group is reorganized into a repaired file in the first format corresponding to the suspicious file.
可选地,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件包括:按照修复后的至少一个字段组中各个字段的父子关系,将修复后的至少一个字段组重组为对应于可疑文件的具有第一格式的修复文件。Optionally, reorganizing the repaired at least one field group into a repaired file with the first format corresponding to the suspicious file includes: reorganizing the repaired at least one field according to the parent-child relationship of each field in the repaired at least one field group. The group is reorganized into repair files in the first format corresponding to suspicious files.
步骤J,完成可疑文件审核之后,在AliYunDun服务器就会得到一份最新的漏洞修复程序。Step J, after completing the audit of suspicious files, you will get the latest vulnerability fix on the AliYunDun server.
本申请上述步骤J中,文件修复装置在完成对可疑文件的修复之后,会得到一份最新的漏洞修复程序,例如,该漏洞修复程序的形式可以为:{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb34″,″action″:″delete″};{″filename″:″/webapps/manager/WEB-INF/web.xml″,″md5″:″bc5ef661b746b0c55462353583a7eb55″,″action″:″replace″}。这个最新的漏洞修复程序准确定位到上述的可疑文件的文件路径下,对应MD5的可疑文件,请求装置在下载了该更新后的漏洞修复程序之后,可以根据更新后的漏洞修复程序中包含的上述修复文件,对可疑文件进行修复,例如将可疑文件为上述修复文件。In the above step J of this application, after the file repairing device completes repairing the suspicious file, it will obtain a copy of the latest vulnerability repair program. For example, the format of the vulnerability repair program can be: {"filename":"/webapps/manager /WEB-INF/web.xml","md5":"bc5ef661b746b0c55462353583a7eb34","action":"delete"};{"filename":"/webapps/manager/WEB-INF/web.xml","md5" : "bc5ef661b746b0c55462353583a7eb55", "action": "replace"}. The latest vulnerability repair program is accurately located under the file path of the above-mentioned suspicious file, corresponding to the suspicious file of MD5. After downloading the updated vulnerability repair program, the requesting device can Repair files, repair suspicious files, such as turning suspicious files into the above repaired files.
步骤K,AliVulfix的每次定时启动运行的时候,会从AliYunDun服务器拉取最新的漏洞规则库文件,并在全盘扫描的时候对本机上对应匹配到的文件进行修复操作(包括删除、替换操作)。In step K, every time AliVulfix starts and runs regularly, it will pull the latest vulnerability rule base file from the AliYunDun server, and perform repair operations (including deletion and replacement operations) on the corresponding matching files on the local machine during a full-scale scan.
步骤L,完成对阿里云用户网站脚本的漏洞修复。Step L, complete the vulnerability repair of the script of the Alibaba Cloud user website.
本申请上述步骤L中,AliYunDun服务器从AliYunDun收取用户设备上的真实CMS漏洞文件(即可疑文件),并进行一对一的针对性修复,最大限度的保证了修复后和修复前的业务兼容性,不至于发生因为漏洞修复导致网站业务不可用;在AliYunDun服务器采取了自动化审核、以及基于Token语法树自动文件修复方式,极大提高的处理速度;AliYunDun基于文件路径、MD5定位可疑文件,避免因为出现误操作,对用户的网站造成影响。In the above step L of this application, the AliYunDun server receives the real CMS vulnerability file (that is, the suspicious file) on the user device from AliYunDun, and performs one-to-one targeted repairs, which maximizes the business compatibility after repair and before repair. , it will not happen that the website business is unavailable due to vulnerability repair; the AliYunDun server adopts automatic auditing and automatic file repair based on the Token syntax tree, which greatly improves the processing speed; AliYunDun locates suspicious files based on file paths and MD5, to avoid Misoperation occurs, which will affect the user's website.
本申请实施例的文件修复方法至少具有以下技术效果:The file restoration method of the embodiment of the present application has at least the following technical effects:
1、精确地针对每个用户的特定业务修复其中的漏洞;1. Fix the vulnerabilities precisely for each user's specific business;
2、漏洞修复全过程自动化,安全运营人员只需要专注于漏洞的研究,并进行一次配置,之后的全网修复动作完全是全自动化;2. The whole process of vulnerability repair is automated. Security operators only need to focus on vulnerability research and perform one configuration. After that, the entire network repair action is fully automated;
3、实现阿里云全网的机器在20分钟内全部修复某一个漏洞;3. Realize that all machines in the entire Alibaba Cloud network can repair a certain vulnerability within 20 minutes;
4、采用语法树的方式进行漏洞的定位和修复,可以避免正则、字符串搜索带来的误报,具有很高的准确率和很低的误报率。4. Using the syntax tree method to locate and repair vulnerabilities can avoid false positives caused by regular and string searches, with high accuracy and low false positive rates.
由上可知,本申请上述实施例一所提供的方案,通过按照语法特征对可疑文件进行拆分得到至少一个字段组之后,依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果,进而解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。As can be seen from the above, in the solution provided by the first embodiment of the present application, after at least one field group is obtained by splitting suspicious files according to grammatical features, loopholes are searched and repaired according to the corresponding token sequence features and repair code sequences of each grammatical feature. Repair, to achieve the purpose of 1:1 automatic repair of the vulnerability, thereby achieving the technical effect of improving the accuracy of vulnerability repair and system security, and then solving the vulnerability repair caused by the use of the same set of Patch codes in the existing technology. Technical issues with poor accuracy.
由此可知,现有技术存在的采用同一套Patch代码实行造成的漏洞修复准确性较差的问题,本申请提出一种基于语法特征对可疑文件的字段进行拆分的方法,进而依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果。From this, it can be seen that there is a problem in the prior art that the accuracy of vulnerability repair caused by the implementation of the same set of Patch codes is poor. Finding and repairing vulnerabilities corresponding to token sequence features and repair code sequences achieves the purpose of 1:1 automatic repair of vulnerabilities, thereby achieving the technical effect of improving the accuracy of vulnerability repair and system security.
需要说明的是,对于前述的各方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本申请并不受所描述的动作顺序的限制,因为依据本申请,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作和模块并不一定是本申请所必须的。It should be noted that, for the sake of simple description, the foregoing method embodiments are all expressed as a series of action combinations, but those skilled in the art should know that the present application is not limited by the described action sequence. Because in accordance with the present application, certain steps may be performed in other orders or concurrently. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到根据上述实施例的方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,或者网络设备等)执行本申请各个实施例所述的方法。From the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is better implementation. Based on this understanding, the technical solution of the present application can be embodied in the form of a software product in essence or in a part that contributes to the prior art, and the computer software product is stored in a storage medium (such as ROM/RAM, magnetic disk, CD-ROM), including several instructions to make a terminal device (which may be a mobile phone, a computer, a server, or a network device, etc.) execute the methods described in the various embodiments of this application.
实施例2Example 2
根据本申请实施例,还提供了一种用于实施上述方法实施例的装置实施例,如图8所示,该装置包括:According to an embodiment of the present application, an apparatus embodiment for implementing the foregoing method embodiment is also provided. As shown in FIG. 8 , the apparatus includes:
图8是根据本申请实施例的文件修复装置的结构示意图。FIG. 8 is a schematic structural diagram of a file restoration apparatus according to an embodiment of the present application.
如图8所示,该文件修复装置可以包括获取单元802、处理单元804、第一确定单元806、第二确定单元808、修复单元810以及重组单元812。As shown in FIG. 8 , the file repairing apparatus may include an acquiring unit 802 , a processing unit 804 , a first determining unit 806 , a second determining unit 808 , a repairing unit 810 and a reorganizing unit 812 .
其中,获取单元802,用于获取请求装置上传的具有第一格式的可疑文件;处理单元804,用于按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;第一确定单元806,用于根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;第二确定单元808,用于依据所述令牌序列特征,确定所述至少一个字段组中的漏洞;修复单元810,用于将所述漏洞替换为预先配置的修复代码序列,得到修复后的所述至少一个字段组;重组单元812,用于将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。Wherein, the obtaining unit 802 is used to obtain a suspicious file with the first format uploaded by the requesting device; the processing unit 804 is used to form at least one field group according to the grammatical features of each field in the suspicious file, with fields with the same grammatical features ; The first determining unit 806 is used to obtain the corresponding token sequence feature of each grammatical feature according to the grammatical feature of each field group; the second determining unit 808 is used to determine the at least one token sequence feature according to the token sequence feature The vulnerability in the field group; the repair unit 810 is used to replace the vulnerability with a pre-configured repair code sequence to obtain the repaired at least one field group; the reorganization unit 812 is used to repair the at least one field group. The field group is reorganized into a repair file in the first format corresponding to the suspect file.
由上可知,本申请上述实施例一所提供的方案,通过按照语法特征对可疑文件进行拆分得到至少一个字段组之后,依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果,进而解决了由于现有技术采用同一套Patch代码实行造成的漏洞修复准确性较差的技术问题。As can be seen from the above, in the solution provided by the first embodiment of the present application, after at least one field group is obtained by splitting suspicious files according to grammatical features, loopholes are searched and repaired according to the corresponding token sequence features and repair code sequences of each grammatical feature. Repair, to achieve the purpose of 1:1 automatic repair of the vulnerability, thereby achieving the technical effect of improving the accuracy of vulnerability repair and system security, and then solving the vulnerability repair caused by the use of the same set of Patch codes in the existing technology. Technical issues with poor accuracy.
此处需要说明的是,上述获取单元802、处理单元804、第一确定单元806、第二确定单元808、修复单元810以及重组单元812对应于实施例一中的步骤S202至步骤S212,六个模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the acquisition unit 802, the processing unit 804, the first determination unit 806, the second determination unit 808, the repair unit 810, and the recombination unit 812 correspond to steps S202 to S212 in the first embodiment, and six Examples and application scenarios implemented by modules and corresponding steps are the same, but are not limited to the content disclosed in the first embodiment above. It should be noted that, as a part of the apparatus, the above-mentioned modules may run in the computer terminal 10 provided in the first embodiment, and may be implemented by software or hardware.
可选地,如图9所示,文件修复装置还可以包括:提取单元902和去重单元904。Optionally, as shown in FIG. 9 , the file restoration apparatus may further include: an extraction unit 902 and a deduplication unit 904 .
其中,提取单元902,用于提取各个可疑文件的元信息,其中,所述元信息包括对应可疑文件的文件路径及消息摘要算法MD5,所述文件路径是指所述可疑文件在所述请求装置所在的用户设备上的路径;去重单元904,用于根据所述文件路径及所述MD5,对所述各个可疑文件进行去重处理。The extraction unit 902 is configured to extract the meta information of each suspicious file, wherein the meta information includes the file path corresponding to the suspicious file and the message digest algorithm MD5, and the file path refers to the suspicious file in the requesting device. The path on the user equipment where it is located; the deduplication unit 904 is configured to perform deduplication processing on each suspicious file according to the file path and the MD5.
此处需要说明的是,上述提取单元902和去重单元904对应于实施例一中的步骤S302至步骤S304,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the above-mentioned extracting unit 902 and deduplication unit 904 correspond to steps S302 to S304 in the first embodiment, and the modules and the corresponding steps have the same examples and application scenarios, but are not limited to the above-mentioned embodiments. a published content. It should be noted that, as a part of the apparatus, the above-mentioned modules may run in the computer terminal 10 provided in the first embodiment, and may be implemented by software or hardware.
可选地,如图10所示,去重单元904可以包括:确定模块1002和处理模块1004。Optionally, as shown in FIG. 10 , the deduplication unit 904 may include: a determination module 1002 and a processing module 1004 .
其中,确定模块1002,用于确定所述各个可疑文件中重复的可疑文件,其中,所述重复的可疑文件是指所述文件路径相同且所述MD5相同的文件;处理模块1004,用于保留所述重复的可疑文件中的第一文件,将除所述第一文件以外的所述重复的可疑文件删除,其中,所述第一文件为所述重复的可疑文件中的任意一个。Wherein, the determination module 1002 is used to determine the repeated suspicious files among the various suspicious files, wherein the repeated suspicious files refer to the files with the same file path and the same MD5; the processing module 1004 is used to retain For the first file in the repeated suspicious files, the repeated suspicious files other than the first file are deleted, wherein the first file is any one of the repeated suspicious files.
此处需要说明的是,上述确定模块1002和处理模块1004对应于实施例一中的步骤S402至步骤S404,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the above-mentioned determination module 1002 and processing module 1004 correspond to steps S402 to S404 in the first embodiment, and the modules and the corresponding steps have the same examples and application scenarios, but are not limited to the above-mentioned first embodiment. disclosed content. It should be noted that, as a part of the apparatus, the above-mentioned modules may run in the computer terminal 10 provided in the first embodiment, and may be implemented by software or hardware.
可选地,所述第一确定单元806用于执行以下步骤依据所述令牌序列特征,确定所述至少一个字段组中的漏洞:在所述至少一个字段组中查找与所述令牌序列特征相同的字段,将所述与所述令牌序列特征相同的字段确定为所述漏洞。Optionally, the first determining unit 806 is configured to perform the following steps to determine the loopholes in the at least one field group according to the token sequence feature: searching the at least one field group for the same as the token sequence A field with the same characteristics, and the field with the same characteristics as the token sequence is determined as the vulnerability.
可选地,所述重组单元812用于执行以下步骤将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件:按照所述修复后的所述至少一个字段组中各个字段的父子关系,将所述修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。Optionally, the reorganization unit 812 is configured to perform the following steps to reorganize the repaired at least one field group into a repaired file in the first format corresponding to the suspicious file: according to the repaired The parent-child relationship of each field in the at least one field group is reorganized, and the repaired at least one field group is reorganized into a repaired file in the first format corresponding to the suspicious file.
可选地,如图11所示,文件修复装置还可以包括:第一接收单元1102和第一发送单元1104。Optionally, as shown in FIG. 11 , the file repairing apparatus may further include: a first receiving unit 1102 and a first sending unit 1104 .
其中,第一接收单元1102,用于接收所述请求装置发送的第一请求,所述第一请求用于下载更新后的漏洞修复程序;第一发送单元1104,用于向所述请求装置发送所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件,以便所述请求装置根据所述修复文件对所述可疑文件进行修复。The first receiving unit 1102 is configured to receive a first request sent by the requesting device, where the first request is used to download the updated vulnerability repair program; the first sending unit 1104 is configured to send the requesting device to the requesting device. The updated vulnerability repair program, wherein the updated vulnerability repair program includes the repair file, so that the requesting device repairs the suspicious file according to the repair file.
此处需要说明的是,上述第一接收单元1102和第一发送单元1104对应于实施例一中的步骤S502至步骤S504,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the above-mentioned first receiving unit 1102 and first sending unit 1104 correspond to steps S502 to S504 in Embodiment 1, and the modules and corresponding steps have the same examples and application scenarios, but are not limited to The content disclosed in the first embodiment above. It should be noted that, as a part of the apparatus, the above-mentioned modules may run in the computer terminal 10 provided in the first embodiment, and may be implemented by software or hardware.
可选地,如图12所示,文件修复装置还可以包括:第二接收单元1202和第二发送单元1204。Optionally, as shown in FIG. 12 , the file restoration apparatus may further include: a second receiving unit 1202 and a second sending unit 1204 .
其中,第二接收单元1202,用于接收来自所述请求装置发送的第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;第二发送单元1204,用于向所述请求装置发送所述更新后的漏洞修复程序的MD5,其中,由所述请求装置根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。The second receiving unit 1202 is configured to receive a second request sent from the requesting device, where the second request is used to obtain the identification information of the updated vulnerability repair program; the second sending unit 1204 is configured to Send the MD5 of the updated vulnerability repair program to the requesting device, wherein the requesting device judges the updated vulnerability repair program and the requesting device according to the MD5 of the updated vulnerability repair program Whether the stored vulnerability repair programs are the same, if they are the same, the requesting device initiates the first request.
此处需要说明的是,上述第二接收单元1202和第二发送单元1204对应于实施例一中的步骤S602至步骤S604,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the above-mentioned second receiving unit 1202 and second sending unit 1204 correspond to steps S602 to S604 in Embodiment 1, and the modules and corresponding steps have the same examples and application scenarios, but are not limited to The content disclosed in the first embodiment above. It should be noted that, as a part of the apparatus, the above-mentioned modules may run in the computer terminal 10 provided in the first embodiment, and may be implemented by software or hardware.
可选地,所述请求装置根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同可以包括:所述请求装置获取所述已存储的漏洞修复程序的MD5;所述请求装置判断所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5是否相同;若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序相同;若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5不相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序不相同。Optionally, the requesting device judging, according to the MD5 of the updated vulnerability repair program, whether the updated vulnerability repair program is the same as the vulnerability repair program stored by the requesting device may include: the requesting device obtaining The MD5 of the stored vulnerability repair program; the requesting device determines whether the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program; The MD5 is the same as the MD5 of the stored vulnerability repair program, then it is determined that the updated vulnerability repair program is the same as the vulnerability repair program stored by the requesting device; if the MD5 of the updated vulnerability repair program is the same as the stored vulnerability repair program. If the MD5 of the stored vulnerability repair program is different, it is determined that the updated vulnerability repair program is different from the vulnerability repair program stored by the requesting device.
根据本申请实施例,还提供了一种用于实施上述方法实施例的装置实施例,如图13所示,该装置包括:According to an embodiment of the present application, an apparatus embodiment for implementing the foregoing method embodiment is also provided. As shown in FIG. 13 , the apparatus includes:
图13是根据本申请实施例的请求装置的结构示意图。FIG. 13 is a schematic structural diagram of a requesting apparatus according to an embodiment of the present application.
如图13所示,该请求装置可以包括第三发送单元1302和控制单元1304。As shown in FIG. 13 , the requesting apparatus may include a third sending unit 1302 and a control unit 1304 .
其中,第三发送单元1302,用于将具有第一格式的可疑文件发送至文件修复装置,其中,由所述文件修复装置按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组,根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征,依据所述令牌序列特征,确定所述至少一个字段组中的漏洞,将所述漏洞替换为预设的修复代码序列,得到修复后的所述至少一个字段组,将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件;控制单元1304,用于从所述文件修复装置中获取对应于所述可疑文件的具有所述第一格式的修复文件。The third sending unit 1302 is configured to send the suspicious file with the first format to the file repairing device, wherein the file repairing device, according to the grammatical features of each field in the suspicious file, sends the fields with the same grammatical features Form at least one field group, obtain the token sequence feature corresponding to each grammatical feature according to the grammatical feature of each field group, determine the loophole in the at least one field group according to the token sequence feature, and replace the loophole obtaining the repaired at least one field group for a preset repair code sequence, and reorganizing the repaired at least one field group into a repaired file with the first format corresponding to the suspicious file; the control unit 1304, for acquiring, from the file repairing apparatus, a repaired file in the first format corresponding to the suspicious file.
此处需要说明的是,上述第三发送单元1302和控制单元1304对应于实施例一中的步骤S10至步骤S12,该模块与对应的步骤所实现的示例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中,可以通过软件实现,也可以通过硬件实现。It should be noted here that the above-mentioned third sending unit 1302 and control unit 1304 correspond to steps S10 to S12 in the first embodiment, and the examples and application scenarios implemented by this module and the corresponding steps are the same, but are not limited to the above-mentioned implementation. Example 1 disclosed content. It should be noted that, as a part of the apparatus, the above-mentioned modules may run in the computer terminal 10 provided in the first embodiment, and may be implemented by software or hardware.
可选地,所述控制单元1304用于执行以下步骤从文件修复装置中获取对应于所述可疑文件的具有所述第一格式的修复文件:向所述文件修复装置发送第一请求,所述第一请求用于下载更新后的漏洞修复程序;接收所述文件修复装置返回的所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件。Optionally, the control unit 1304 is configured to perform the following steps to obtain a repaired file in the first format corresponding to the suspicious file from the file repairing device: sending a first request to the file repairing device, the The first request is for downloading the updated vulnerability repair program; and receiving the updated vulnerability repair program returned by the file repairing device, wherein the updated vulnerability repair program includes the repair file.
可选地,所述控制单元1304,还用于向所述文件修复装置发送第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;接收所述文件修复装置返回的所述更新后的漏洞修复程序的MD5;根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。Optionally, the control unit 1304 is further configured to send a second request to the file repair device, where the second request is used to obtain the identification information of the updated vulnerability repair program; receive the file repair device The returned MD5 of the updated vulnerability repair program; according to the MD5 of the updated vulnerability repair program, determine whether the updated vulnerability repair program is the same as the vulnerability repair program stored in the requesting device, and if the same , the requesting device initiates the first request.
由此可知,现有技术存在的采用同一套Patch代码实行造成的漏洞修复准确性较差的问题,本申请提出一种基于语法特征对可疑文件的字段进行拆分的方法,进而依据各个语法特征对应令牌序列特征及修复代码序列进行漏洞的查找及修复,达到了对漏洞进行1∶1的自动修复的目的,从而实现了提高漏洞修复的准确性及系统安全性的技术效果。From this, it can be seen that there is a problem in the prior art that the accuracy of vulnerability repair caused by the implementation of the same set of Patch codes is poor. Finding and repairing vulnerabilities corresponding to token sequence features and repair code sequences achieves the purpose of 1:1 automatic repair of vulnerabilities, thereby achieving the technical effect of improving the accuracy of vulnerability repair and system security.
实施例3Example 3
本申请的实施例还提供了一种存储介质。可选地,在本实施例中,上述存储介质可以用于保存上述实施例一所提供的文件修复方法所执行的程序代码。Embodiments of the present application also provide a storage medium. Optionally, in this embodiment, the above-mentioned storage medium may be used to store the program code executed by the file repairing method provided in the above-mentioned first embodiment.
可选地,在本实施例中,上述存储介质可以位于计算机网络中计算机终端群中的任意一个计算机终端中,或者位于移动终端群中的任意一个移动终端中。Optionally, in this embodiment, the above-mentioned storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
可选地,在本实施例中,存储介质被设置为存储用于执行以下步骤的程序代码:获取请求装置上传的具有第一格式的可疑文件;按照所述可疑文件中各个字段的语法特征,将语法特征相同的字段组成至少一个字段组;根据每个字段组的语法特征,获取各个语法特征对应的令牌序列特征;依据所述令牌序列特征,确定所述至少一个字段组中的漏洞;将所述漏洞替换为预设的修复代码序列,得到修复后的所述至少一个字段组;将修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。Optionally, in this embodiment, the storage medium is configured to store program codes for performing the following steps: obtaining a suspicious file with the first format uploaded by the requesting device; according to the grammatical features of each field in the suspicious file, The fields with the same grammatical feature are formed into at least one field group; according to the grammatical feature of each field group, the token sequence feature corresponding to each grammatical feature is obtained; according to the token sequence feature, the loopholes in the at least one field group are determined ; Replace the vulnerability with a preset repair code sequence, and obtain the repaired at least one field group; reorganize the repaired at least one field group into a file corresponding to the suspicious file with the first format repair file.
可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:提取各个可疑文件的元信息,其中,所述元信息包括对应可疑文件的文件路径及消息摘要算法MD5,所述文件路径是指所述可疑文件在所述请求装置所在的用户设备上的路径;根据所述文件路径及所述MD5,对所述各个可疑文件进行去重处理。Optionally, the storage medium is further configured to store program codes for performing the following steps: extracting meta-information of each suspicious file, wherein the meta-information includes a file path corresponding to the suspicious file and a message digest algorithm MD5, the file The path refers to the path of the suspicious file on the user equipment where the requesting device is located; according to the file path and the MD5, deduplication processing is performed on each suspicious file.
可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:确定所述各个可疑文件中重复的可疑文件,其中,所述重复的可疑文件是指所述文件路径相同且所述MD5相同的文件;保留所述重复的可疑文件中的第一文件,将除所述第一文件以外的所述重复的可疑文件删除,其中,所述第一文件为所述重复的可疑文件中的任意一个。Optionally, the storage medium is further configured to store program codes for performing the following steps: determining repeated suspicious files in each of the suspicious files, wherein the repeated suspicious files refer to the same file paths and the MD5 the same file; keep the first file in the repeated suspicious files, delete the repeated suspicious files except the first file, wherein the first file is in the repeated suspicious files any one of .
可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:在所述至少一个字段组中查找与所述令牌序列特征相同的字段,将所述与所述令牌序列特征相同的字段确定为所述漏洞。Optionally, the storage medium is further configured to store program codes for performing the steps of: searching for a field identical to the token sequence feature in the at least one field group, and comparing the field with the token sequence feature The same fields are identified as the said vulnerability.
可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:按照所述修复后的所述至少一个字段组中各个字段的父子关系,将所述修复后的所述至少一个字段组重组为对应于所述可疑文件的具有所述第一格式的修复文件。Optionally, the storage medium is further configured to store program codes for performing the following steps: according to the parent-child relationship of each field in the repaired at least one field group, the repaired at least one field The group is reorganized into a repair file in the first format corresponding to the suspect file.
可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:接收所述请求装置发送的第一请求,所述第一请求用于下载更新后的漏洞修复程序;向所述请求装置发送所述更新后的漏洞修复程序,其中,所述更新后的漏洞修复程序中包含所述修复文件,以便所述请求装置根据所述修复文件对所述可疑文件进行修复。Optionally, the storage medium is further configured to store program codes for performing the following steps: receiving a first request sent by the requesting device, where the first request is used to download an updated vulnerability repair program; The device sends the updated vulnerability repair program, wherein the updated vulnerability repair program includes the repair file, so that the requesting device repairs the suspicious file according to the repair file.
可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:接收来自所述请求装置发送的第二请求,所述第二请求用于获取所述更新后的漏洞修复程序的标识信息;向所述请求装置发送所述更新后的漏洞修复程序的MD5,其中,由所述请求装置根据所述更新后的漏洞修复程序的MD5,判断所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序是否相同,若相同,所述请求装置则发起所述第一请求。Optionally, the storage medium is further configured to store program codes for performing the following steps: receiving a second request sent from the requesting device, where the second request is used to obtain the identifier of the updated vulnerability repair program information; send the MD5 of the updated vulnerability repair program to the requesting device, wherein the requesting device judges the updated vulnerability repair program and the Whether the vulnerability repair programs stored by the requesting device are the same, if they are the same, the requesting device initiates the first request.
可选地,存储介质还被设置为存储用于执行以下步骤的程序代码:所述请求装置获取所述已存储的漏洞修复程序的MD5;所述请求装置判断所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5是否相同;若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序相同;若所述更新后的漏洞修复程序的MD5与所述已存储的漏洞修复程序的MD5不相同,则确定所述更新后的漏洞修复程序与所述请求装置已存储的漏洞修复程序不相同。Optionally, the storage medium is further configured to store program codes for executing the following steps: the requesting device obtains the MD5 of the stored vulnerability repair program; the requesting device judges the updated vulnerability repair program. Whether the MD5 is the same as the MD5 of the stored vulnerability repair program; if the MD5 of the updated vulnerability repair program is the same as the MD5 of the stored vulnerability repair program, it is determined that the updated vulnerability repair program is the same as the The vulnerability repair program stored by the requesting device is the same; if the MD5 of the updated vulnerability repair program is different from the MD5 of the stored vulnerability repair program, it is determined that the updated vulnerability repair program is the same as the The bugfixes already stored by the requesting device are not the same.
上述本申请实施例序号仅仅为了描述,不代表实施例的优劣。The above-mentioned serial numbers of the embodiments of the present application are only for description, and do not represent the advantages or disadvantages of the embodiments.
在本申请的上述实施例中,对各个实施例的描述都各有侧重,某个实施例中没有详述的部分,可以参见其他实施例的相关描述。In the above-mentioned embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference may be made to related descriptions of other embodiments.
在本申请所提供的几个实施例中,应该理解到,所揭露的订单信息的处理装置,可通过其它的方式实现。其中,以上所描述的装置实施例仅仅是示意性的,例如所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,单元或模块的间接耦合或通信连接,可以是电性或其它的形式。In the several embodiments provided in this application, it should be understood that the disclosed apparatus for processing order information may be implemented in other ways. The apparatus embodiments described above are only illustrative, for example, the division of the units is only a logical function division, and there may be other division methods in actual implementation, for example, multiple units or components may be combined or Integration into another system, or some features can be ignored, or not implemented. On the other hand, the shown or discussed mutual coupling or direct coupling or communication connection may be through some interfaces, indirect coupling or communication connection of units or modules, and may be in electrical or other forms.
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。The units described as separate components may or may not be physically separated, and components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution in this embodiment.
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated units may be implemented in the form of hardware, or may be implemented in the form of software functional units.
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可为个人计算机、服务器或者网络设备等)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、移动硬盘、磁碟或者光盘等各种可以存储程序代码的介质。The integrated unit, if implemented in the form of a software functional unit and sold or used as an independent product, may be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the present application can be embodied in the form of software products in essence, or the parts that contribute to the prior art, or all or part of the technical solutions, and the computer software products are stored in a storage medium , including several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and other media that can store program codes .
以上所述仅是本申请的优选实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本申请原理的前提下,还可以做出若干改进和润饰,这些改进和润饰也应视为本申请的保护范围。The above are only the preferred embodiments of the present application. It should be pointed out that for those skilled in the art, without departing from the principles of the present application, several improvements and modifications can also be made. It should be regarded as the protection scope of this application.
Claims (21)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510307070.6A CN106295334B (en) | 2015-06-05 | 2015-06-05 | Ile repair method and device |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510307070.6A CN106295334B (en) | 2015-06-05 | 2015-06-05 | Ile repair method and device |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN106295334A CN106295334A (en) | 2017-01-04 |
| CN106295334B true CN106295334B (en) | 2019-07-26 |
Family
ID=57659427
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201510307070.6A Active CN106295334B (en) | 2015-06-05 | 2015-06-05 | Ile repair method and device |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN106295334B (en) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109255243B (en) * | 2018-09-28 | 2022-06-21 | 深信服科技股份有限公司 | Method, system, device and storage medium for repairing potential threats in terminal |
| CN113852602B (en) * | 2021-08-11 | 2023-12-08 | 奇安信科技集团股份有限公司 | File reconstruction method, device, transmission equipment, electronic equipment and medium |
| CN119739356A (en) * | 2024-12-03 | 2025-04-01 | 珠海奔图电子有限公司 | Print data repair method, device, equipment, medium and program product |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102622556A (en) * | 2011-12-22 | 2012-08-01 | 南京邮电大学 | Web service security analysis method based on program slicing technique |
| CN103886258A (en) * | 2014-03-10 | 2014-06-25 | 珠海市君天电子科技有限公司 | Method and device for detecting viruses |
| CN103955449A (en) * | 2014-04-21 | 2014-07-30 | 安一恒通(北京)科技有限公司 | Target sample positioning method and device |
| CN104182689A (en) * | 2013-05-24 | 2014-12-03 | 阿里巴巴集团控股有限公司 | System repair and protection method and system |
| CN104199925A (en) * | 2014-09-01 | 2014-12-10 | 安一恒通(北京)科技有限公司 | File repair method and device |
-
2015
- 2015-06-05 CN CN201510307070.6A patent/CN106295334B/en active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102622556A (en) * | 2011-12-22 | 2012-08-01 | 南京邮电大学 | Web service security analysis method based on program slicing technique |
| CN104182689A (en) * | 2013-05-24 | 2014-12-03 | 阿里巴巴集团控股有限公司 | System repair and protection method and system |
| CN103886258A (en) * | 2014-03-10 | 2014-06-25 | 珠海市君天电子科技有限公司 | Method and device for detecting viruses |
| CN103955449A (en) * | 2014-04-21 | 2014-07-30 | 安一恒通(北京)科技有限公司 | Target sample positioning method and device |
| CN104199925A (en) * | 2014-09-01 | 2014-12-10 | 安一恒通(北京)科技有限公司 | File repair method and device |
Also Published As
| Publication number | Publication date |
|---|---|
| CN106295334A (en) | 2017-01-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11188635B2 (en) | File authentication method and apparatus | |
| CN110677381B (en) | Penetration testing method and device, storage medium, electronic device | |
| CN103607385B (en) | Method and apparatus for security detection based on browser | |
| CN107294924B (en) | Vulnerability detection method, device and system | |
| CN102752326B (en) | The method of deal with data, server and system in the time of download file | |
| CN110879891B (en) | Vulnerability detection method and device based on web fingerprint information | |
| CN110881024B (en) | Vulnerability detection method and device, storage medium and electronic device | |
| CN109922062B (en) | Source code leak monitoring method and related equipment | |
| CN104951480A (en) | Resource storage indexing device and method in CDN system | |
| CN111104579A (en) | Identification method and device for public network assets and storage medium | |
| CN106982188B (en) | Method and device for detecting malicious propagation source | |
| CN111182060A (en) | Message detection method and device | |
| CN102932391A (en) | Method and device for processing data in peer to server/peer (P2SP) system, and P2SP system | |
| CN104462968A (en) | Malicious application program scanning method, device and system | |
| CN111541647B (en) | Safety detection method, device, storage medium and computer equipment | |
| CN107332804A (en) | The detection method and device of webpage leak | |
| CN103310154B (en) | The method, apparatus and system that information security processes | |
| CN110768951A (en) | Method and device for verifying system vulnerability, storage medium, and electronic device | |
| CN106295334A (en) | Ile repair method and device | |
| CN110768950A (en) | Method and device for sending penetration instruction, storage medium, and electronic device | |
| CN106934290B (en) | Vulnerability detection method and device | |
| CN114254329A (en) | Digital asset vulnerability detection method based on 0day vulnerability and related equipment thereof | |
| CN106330979B (en) | Router login method and device | |
| CN107220262A (en) | Information processing method and device | |
| CN106487771B (en) | Network behavior acquisition method and device |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant |