WO2014079307A1 - 网站源代码恶意链接注入监控方法及装置 - Google Patents
网站源代码恶意链接注入监控方法及装置 Download PDFInfo
- Publication number
- WO2014079307A1 WO2014079307A1 PCT/CN2013/086233 CN2013086233W WO2014079307A1 WO 2014079307 A1 WO2014079307 A1 WO 2014079307A1 CN 2013086233 W CN2013086233 W CN 2013086233W WO 2014079307 A1 WO2014079307 A1 WO 2014079307A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- link
- code
- malicious
- external
- website
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1466—Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/50—Network services
- H04L67/52—Network services specially adapted for the location of the user terminal
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2119—Authenticating web pages, e.g. with suspicious links
Definitions
- This publication relates to the website's Luquan technology, and in particular to a website source weight-intention link injection monitoring method and apparatus.
- the former widely used way of spreading viruses is to first use the operating system or third-party applications to extract the right to write the system, but then inject the malicious redirect network into the face code of the website.
- the current solution is mainly: fetching the content from the outside (era), and then describing whether the content of the page is intentional or not, such as: S yma nte s afeweb technology, McAfee's sit eadv i sor technology and more.
- the current development method of the website is basically a small amount of source code dynamically loading a large number of *column contents, and the fullness of the pre-numbered library, such as preventing SQL injection and XSS cross-site attacks, are currently more mature.
- a website source code malicious link injection monitoring method including: monitoring a website source code text The modified piece of code and the code fragment of the change; the code fragment of the changed content is extracted from the external link; whether the external link is ok or maliciously linked; and if the external link is determined to be condensable or malicious The link issues a warning message ⁇
- a website source code malicious connection injection monitoring device includes: a code monitoring unit monitoring a station code file modification operation and extracting a change; a key extraction unit, configured to distinguish the changed code piece The external key is extracted; the link folding unit is configured to determine whether the external link is a suspicious or intentional link; and the full warning unit is configured to issue a warning if the external link is determined to be a suspicious or malicious link
- the change content of the message such as the change of the source code contains some dangerous external link elements, ⁇ immediately issued a warning to the system administrator, so that the real-time monitoring of the website to be complete, and then effective through the use of ⁇ The system or third-party application ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ Avoid the spread of malicious links while waiting for
- ⁇ 1 A flow chart of a web site malicious code injection monitoring method provided by the first implementation side.
- Encircle 2 is the second real; a website source code provided by ife is intentionally linked to the flow of the monitoring device.
- the first embodiment provides a website source code malicious link injection monitoring method, and the foregoing monitoring methods include:
- Step S110 Monitor the modification of the website source code file and retrieve the changed code fragment'
- the source code files of the website will be stored in one or more fixed records.
- the source code files in these directories can be monitored in real time, and the changed code segments can be extracted when there are changes.
- the modification of the monitoring source code file is not limited to the above method, for example, the system can also be used to monitor the writing operation of the sheet metal, and when the operation of the file of the source code of the website is monitored, Take the changed code snippet
- Step S12 split the code segment of the change to extract rfi external link
- the step S120 may include: loading a corresponding code splitter according to a programming language adopted by the changed code segment; and using a code analyzer to parse the code piece to extract an external connection.
- Dociiment Object Model (DOM) loads fragmented HTML code snippets to extract external links
- Step S130 Determine whether the external link is a suspicious or malicious link.
- a malicious link ⁇ can determine whether the external link is located in a polygon element whose pixel value is ⁇ , or whether a polygon element whose coordinate position is significantly outside the screen is applied to these abnormal links, that is, a purchase surface with a pixel value of 0.
- External links in elements or in face elements whose coordinates are clearly outside the screen, can be disturbed as suspicious links
- a lii warning message can be sent in step S140.
- query _ i ndex provides an online malicious link verification service. If it is confirmed that all morning keys are secure external keys, step S140 may not be performed.
- Step S14 When it is determined that the external link is a suspicious or *intentional link, a warning message is issued.
- the protection mechanism can also be activated to prevent the source code monitoring system from being maliciously deleted, the service being maliciously unloaded or terminated.
- the station source code malicious link injection monitoring method of the embodiment monitors the change of the source code in real time, such as the change of the source code and the dangerous external link element, and immediately issues a warning to the system administrator, thereby real-time Monitor the security of your website and effectively block it A common type of virus transmission by using the operating system or the third-party application to extract the system write permission and then inject the malicious redirect URL into the face code of the legitimate website.
- the second embodiment of the present invention 4 provides a website «code malicious link injection monitoring device 200, comprising: a code monitoring unit 210. a link extracting unit 22, a link dividing unit t 230, and a full warning unit 240
- the code monitoring unit 2 1 0 is used to monitor the modification operation of the website source chicken file and retrieve the changed code fragment ⁇ — *:
- the network code file is stored in one or more directories, and is monitored in real time. These recorded source code files can be changed in the code segment when the change is made.
- the source code file of the website can be read and prepared, and the code files of all the backup files are indexed, and the modification is stored. when W 'and then pass seize comparison supervision ft recorded code files linked to known whether the passage «code file is already started when the modified ⁇ 3 ⁇ 4- ho modify the source code file and f 3 ⁇ 4 Weng prepared to compare two This content can extract 13 ⁇ 4 changed weight fragments.
- the modification of the monitoring source code file is not limited to the above method, for example, the side can monitor the writing operation of the disk, and monitor the website code storm. The code of the meat file is directly taken from the changed code fragment.
- Link extraction unit 220 with the predetermined piece of code changing points to draw off ⁇ 3 ⁇ 4 external links snippet changes may be taken in different programming languages ⁇ e.g. HTML, Javascr ipts, or the like prepared ⁇ . ⁇ not the complete ⁇ ft
- the programming language has a syntax of no, and the sub-dividing is required.
- the link extracting unit 220 can be used to: load the phase code divider according to the programming profile used by the changed code segment; The code segmenter unwraps the code snippet to extract the external link of i3 ⁇ 4.
- the document object type Document Objec t Model, D wish
- the parent element and can be accessed from their bond Attributes to distinguish whether the external link is a derogatory or malicious link, whether the new external link is in the polygon element of the pixel value, or whether it is placed in a more face element whose coordinate position is outside the screen.
- an external key in a page element with a pixel value of 0 or a face element whose coordinate position is significantly outside the screen can be a suspicious link ⁇
- the suspicious link related information can be sent to the full warning unit 240, and the warning unit is issued by the full warning unit.
- the link is sent to the third-party URL security check service to verify that the suspicious link is a known malicious link such as ht tp: //aq. qq. com/cE2/saf e ⁇ school/ ur l—query—index provides one kind of malicious link test ii £ service ⁇ If all suspicious links are confirmed to be all external links, then the full warning unit 240 ⁇ may not be called.
- the link extensions 230 can also send all the external links that extract tfc to the third-party website to be fully inspected. Pass the test. At this point, you can not divide the external connection from the attribute of the link itself and its parent element to the intentional link, but directly through the # ⁇ och. If the third-party URL security service returns, the result indicates that there is a * The link will send a suspicious or malicious link to the security alert t 240.
- the monitoring device 2 may comprise a full protection unit 250» for initiating a protection mechanism after the financial connection is linked to a suspicious or malicious link, "the monitoring device 200 is intentionally deleted, the service is intentionally uninstalled or terminated" , the safety protection unit 250 can be powered
- the external program is monitored and intercepted for monitoring the operation of each of the power storage units of the device 200 to prevent the monitoring device 200 from being intentionally deleted, and the service is intentionally uninstalled or terminated.
- the malicious source link of the website source code injects the monitoring device to monitor the change of the code in real time. If the change of the source code contains some dangerous external link elements, the warning administrator is immediately issued, so that the website can be monitored in real time. The security, chasing the effective way to use the operating system or third-party application vulnerabilities to extract the write permission and then inject the malicious redirect address to the website code of the website.
- the present invention provides a computer readable storage medium, in which a computer readable storage medium is stored, such as a non-volatile memory such as an optical disk, a hard disk, or a flash memory.
- a computer readable storage medium such as a non-volatile memory such as an optical disk, a hard disk, or a flash memory.
- the above-mentioned computer-executable instructions are used for t-upgrades or similar computing devices to complete the various operations in the website source code malicious link injection monitoring party*, which is a better implementation of the present invention.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- Information Transfer Between Computers (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
本发明涉及一种网站-源代码恶意链接注入监控方法,包括:监控对网站源代码文件的修改操作并获取变更的代码片段;分折所述变更的代码片段以抽取出外部链接;判断所述外部链接是否为可疑或者恶意链接;以及若判定所述外部链接为可疑或者恶意链接则发出警告消息。上述的网站源代码恶意链接注入监控方法可实时监控源代码的变更内容,有效的阻止了通过利用操作系统或第三方应用漏洞获取系统写权限后注入恶意的重定向网址到合法网站的页面代码中这样一类常见的病毒传播方式,此外,本发明还提供一种网站源代码恶意链接注入监控装置。
Description
网站源代码恶意链接注入监控方法及装置 技术领域
本发嚷涉及网站鲁全技术,尤其涉及一种网站源 Λ码悉意链接注入监 控方法及装置。
背景技术
闺前一种被普遍采用的传播病毒的方式是首先利用操作系 或第三 方应用漏 来 取系 的写权艮,然^注入恶意的重定向网 ¾到会法网站 的 面代码中 如何检測网 ¾是否被感染, 目前的方案主要是: 从外部抓 取(era冒 i ing )网站肉容, 然后 描页面肉容是否有 意代码 这类方法 比 ^典型, 如: S yma n t e 的 s afeweb技术, McAfee的 s i t eadv i sor技术 等。 ·
基予抓取技术的外部 测系统,存在着 #实时牲 漏!^误报等问题„ 病毒的 #播性很强》 可以在叛时间肉感柴大量的网站, 而从外部抓取网站 容无法在短时闰肉将财有 站内容抓取下来,被无'法实时承全測网站的鲁 全性; 途样会导襞已经感乘的页面因为非实时性而被误根为 然安全, 导 致误报。
目前的网站的开发方式基本上为少量的源代码动态加载大量的数 * 库内容, 对予数 *库肉容的要全性, 如防止 SQL注入、 XSS跨站攻击, 目 前都有较成熟的解决方案, 而对源代码的保护却不够, 而这部分也正是島 意网址注入的攻击点之一 β
发 内容
有鉴予此, 有必要提供一种网 * ¾代码恶意链接注入监控方法反装 置, 其可提升网站源代码的安全性。
一种网站源代码恶意链接注入监控方法, 包括: 监控对网站源代码文
件的修改搮作并袭取变更的代码片段;分折所迷变更的代码片段《抽取 ώ 外部链接; 判斷所途外部链接是否为可 或者恶意链接; 以及若判定所述 外部链接为可凝或者恶意链接则发出警告消息 β
一种网站源代码恶意健接注入监控装置, 包括: 代码监控单元 周于 监控对 站 代码文件 修改操作并羡取变更的観 t歡; 键接抽取单 元, 用于分祈所述变更的代码片歡以抽取 ώ外部键接; 链接分折单元, 用 于判断所述外部链接是否为可疑或者悉意链接; 以及要全警告单元, 用于 若判定所述外部链接为可疑或者恶意链接则发出警告消息《 的变更 容, 如杲源代码的变更内容包含一些危险 外部链接元素, Λ立 即发 ώ警告给系 管理員, 从而能够实时监控网站的要全性, 进而有效的 f且止了通过利用搡作系 或第三方应用譌詞羡取系 写权限后注入惡意 的重定向网址 合法网站的 面代码中途样一类常見的病毒传播方式 相 Λ于传 的外部抓取方式, 可以做到实时保护, 避免了在等待被抓 取期 |¾]恶意链接的传播。 此外, 由于网站源代码文件有限, 并且相对来 变更的频率较低, 本实施例的方法对系 的 影响较低
为让本发明的上述和其他目的、特輕和优点能更明显 懂, 下文特举 较 实施創, 并配合所 围式, 作#细 嚷如下
附图说明
闺 1 为第一实施侧提供的一种网站源 码恶意链接注入监控方法流 程图。
围 2 为第二实; ife倒提供的一种网站源代码悉意链接注入监控装置流 程图。
具体实旄方式
为更进一歩阐述本发明为实现预定发嚷胃的财采取的技术手段及功
效, 以下结合附围及较佳实施例, 对依据本发明的具体卖施方式、 结构、 特征及其功效, 详細说嚷如后
編 1
参闺图 1, 第一实施例提供一种网站源代码恶意链接注入监控方法, 上述的监控方法包括:
歩骤 S110 监控对网站源代码文件的修改操作并羡取变更的代码片 段',
—敫来说, 网站源代码文件会存镛在一个或多个固录下, 通遣实时监 控这些目录下的源代码文件, 可以在有变更的时候抽取变更的代码段。 例 如, 首先可将 «站¾代码文件进行备儉 并对所有备奮的源代码文件建立 索引, 存儲其修改时 «β 然 通遣比较监控的目录下源代码文 的修改时 逃一歩地, Λ较两个版本的肉容即可提取 变更的代码片段》
Α外, 可以理解, 监控源代码文件的修改并不限于上述方法, 例如, 还可监测系统对 Λ金的写操作,并在监测到对网站源代码目录肉的文件进 行的写操作时直接茨取变更的代码片段
歩骤 S12 、 分折所述变更的代码片段以抽取 rfi外部链接》
变更的我码 段可 是采用不同的編程语言 如 HTML Javascripts 或者 PHP等編写完成的 β 而不 的編程语言具有不阔 语法, 需要分则遭 行分析。 具体地 歩骤 S120例如可包括: 根据变更的代码片段所采用的 编程 言加载相应的代码分折器; 1¾ 采用 代码分析器解析所述代码片 歡以抽取 Λ所途外部健接„ 如, 釆用文件物件摸 ( Dociiment Object Model, DOM)加载分折 HTML 式的代碼片段以抽取 外部链接
歩骤 S130、 判斷所迷外部链接是否为可疑或者恶意链接。
首先,可从链接自身反其父元素的属性来分析外部链接是否属于可疑
或恶意链接 β 例如, 可判断外部链接是否位于像素值为 ΰ的 面元素中, 或者是否位于坐标位置明显在屏幕之外的 面元素申 对于这些反常的链 接》即位于像素值为 0的買面元素中或者坐标位置明显在屏幕之外的 面 元素中的外部链接, 均可扰为可疑链接
判定可疑链接后, 即可执行歩骤 S140发 lii警告消息。 此外, 为邊一 歩确认可疑链接的要全性, ¾可进一歩将可 健接发送至第三方网 ¾要全 驗证服务以验 该可 链接是否为 已知的恶意链接 例如 h u p: 11 aq. qq. com/cn2./ saf e _ s choo l /ur 1.query _ i ndex 就提供一种线上 恶意链接验证服务 若确认所有可晨键接均为安全外部键接, 則可不执行 步骤 S140e
此外,除了将上途的可疑链接发送至第三方 址安全验 it服务迸行验 证外,还可将所有提取 tfc的外部链接发送至第三: ^网址要全验 ΐ£服务邊行 验 此时, 可以不从链接翁身及其父元素的属性来分折外部链接是否属 亍可疑或恶意链接, 而直接透行线上验证 若第三方 fl址要全验 服务逞 回的结杲表明存在可疑或者恶意链接则执行歩骤 S 140 a
步骤 S14( 若判定所述外部链接为可疑或者 *意链接則发 ώ警告消 息。
如, 发送邮件或者采用即时通讯软件发送消息告知系 ί充管理员, 透 行人工确认。 '
此外, 一歩地, 在判定所迷外部链接为可疑或者 意链接后, 还可 启动保护机制以防止源代码监控系 文件被恶意删除、服务被恶意卸栽或 者终止。
本实施例的 站源代码恶意链接注入监控方法实时监控源代码的变 更内客, 如杲源代码的变更 ή容&含一些危险的外部链接元素, 則立即发 出警告給系 管理员, 从而能够实时监控网站的安全牲, 进而有效的阻止
了通过利用操作系 1¾或第三方应用漏酒羡取系统写权限后注入恶意的重 定向网址到合法网站的 面 码中这样一类常见的病毒传播方式„
相比予传 的外部抓取方式, 可以做到实时保 , 避免了在等待被抓 取期间恶意链接的传樁》 Λ外, 由予网站 *代码文件有限, 并且相对来说 变更的颔率较低, 本实 * 械系统的牲能影 较低《
实施倒 2 '
参 «围 2, 本发明第二实 4 提供一种网站 «代码恶意链接注入监控 装置 200, 包括: 码监控单元 210. 链接抽取单元 22 、 链接分祈单 t 230、 及要全警告单元 240
代码监控举元 2 1 0 用予监控对网站源代鸡文件的修改操作并羡取变 更的代码片段 β — *:来说, 网 代码文件会存储在一个或多个目录下, 通过实时监捶这些 录下的源代码文件,可以在有变更的时候袖取变更的 代码段 倒如, 首先可将网站源代码文件透行备儉, 并对所有备分的 码文件建立索引,存储其修改时 W„ 然 通迨比较监挂的 录下 代码文 件的修 ft时 f ¾与备翁的源代码文件的修改时 即可袭知 «代码文件是否 巳经被修改 β ¾—歩地,比较两个 本的内容即可提取 1¾变更的 Λ码片段 此外, 可以理解, 监控源代码文件的修改并不限于上述方法, 侧如, ¾可监测系 对 Λ盘的写操作,并在监 对网站 代码 暴肉的文件进行 的写操作时直接 取变更的我码片段
链接抽取单元 220用予分折所述变更的代码片 以抽取 ώ外部链接¾ 变更的代码片段可能是采 Λ不同的编程语言例如 HTML、 Javascr ipts , 或 者 Ρί.ΙΡ等编写完成的 β ft不 的编程 *言具有不 «的语法, 需要分则透行 分折„ 具体地, 链接抽取单元 220可用于: 根据变更的代码片段所釆用的 編程谱言加载相 的代码分折器;以 1采用 代码分折器解折所述代码片 段以抽取 i¾所迷外部链接》 侧如, 采 Λ文件物件摸型 ( Document Objec t
Model , D謹)加载分祈 HTML袼式的代码片段 抽取 Λ外部链接„ 链接分折单元 230用于判断所述外部链接是否为可疑或者恶意链接 β 首先,可从键接自身及其父元素的属性来分祈外部链接是否屬于可鍉或恶 意链接 倒如, 可 新外部链接是否位于像素值为 的 面元素中, 或者 是否位予坐标位置 显在屏幕之外的更面元素中„ 对于这些反常的链接, 即位于像素值为 0 的页面元素中或者坐标位置明显在 幕之外的 面元 素中的外部键接, 均可 为可疑链接 β
判定可疑链接后,即可将可疑链接相关信息发送至要全警告单元 240, 由要全警告单元发 1¾警告 息, 此外, 为透一歩确认可疑键接的要全性, 还可进一歩将可疑链接发送至第三方网址安全驗£服务以验证 可疑链 接是否为已知的恶意链接 倒如 ht tp: //aq. qq. com/cE2/saf e^ school/ ur l— query— index就提供一种载上恶意链接验 ii£服务 β 若确认所有可疑链 接均为要全外部链接, 則可不调用要全警告单元 240β
Λ外,链接分折单 230除了将上述的可疑链接发透至第三方《址要 全验 ϋ服务逃行验 *外 ,还可将所有提取 tfc的外部链接发送至第三方网址 要全驗 服务透行验 。 此时, 可以不从链接自身及其父元素的屬性来分 折外部健接是否屬于悉意链接, 而直接透 #鐵上验 „ 若第三方网址安全 验 服务逞回的結果表明存在可菱或者 *意链接則将可疑或者恶意链接 发送至安全警告举 t 240。
要全警告举元 240 用于若判定所逯外部链接为可疑或者恶意链接則 发出警告消息 β 倒如, 发递邮件或者采用即时通 敦件发送消息告知系统 管理灵, 遷行人工确认 β
此外, 监控装置 2 可包括要全 护单元 250» 用于在判定财途外 部链接为可疑或者恶意链接之后启动保护机制《方止监控装置 200被悉 意删除、 服务被悉意卸载或者终止„ 例如, 安全防护单元 250可以霍动服
务的形式加栽亍搮作系统内 ,监測并 截外部程序对于监控装置 200各功 倉 I摸块的操作, 以防止监控装置 200被悉意删除、服务被悉意卸载或者终 止。
本实施倒的网站源代码恶意链接注入监控装置实时监控 代码的变 更肉容, 如杲源代码的变更肉容包含一些危 外部链换元素, 則立即发 出警告 系克管理員, 从而能够实时监控网站的安全性, 追而有效 fa止 了通过利用操作系 或第三方应用漏洞羡取系 写权限后注入恶意的重 定向 址到会法网站的 面代码申这样一类常見的病毒传播方式
相 于传 的外部抓取方式, 可 Λ做到实时保护, 透免了在等待被抓 取期间恶意链接的传播。 此外, 由于网站源代码文件有限, 并且相对来说 变更的频率较低, 本实施 的方法对系 的性能影 较低
此外, 本发明实施倒 提供一种计算机可读存储介盾, 其内存储有计 算机可挑行指令,上述的计算机可读存 介质 如为非易失性存储器 如 光盘、 硬蠱、 成者闪存。 上速的计算机可执行指令用于 t升算机或者类似 的运算装置完成上途的网站源代码恶意链接注入监控方 *中的各种操作 上所述, 是本发明的被佳实施倒而已, 并 对本发明作任何形式 上的限制, 虽然本发嚷已《4吏佳实施销揭 如上, 然¾并非用以限定本发 任 本领域技术人员, 在不脱离本发明拔术方案范闺肉, 当可利用上 述揭示的拔术内容做 Λ些许更动或修饰为等 变化的等效实施倒, 凡是 未脱离本发明拔术方案肉容,依据本发 的技术实质对》¾上实施钢所作的 壬 介修 等同变化与修饰, 均仍属于本发明技术方案的范围肉。
Claims
1. —种网站源代码恶意链接注入监控方 felt;
监控对网站源代码文件的修改操作并 取变更的代码 段
分析所述变更的代码片段以抽取出外部链接
判斷所迷外部链接是否为可疑或者悉意健接; 以及
若判定所述外部链接为可疑或者恶意链接则发 警告 息 β
2. 如权利要求 1所逯的网站 St代码恶意链接注入监控方法, 其特 在于, 还包括: 在判定所述外部链接为可 或者恶意链接之^ , 启动保护机制以 防止系统文件被恶意删除、 服务被恶意卸载或者终止。
3. 如权利要求 1所述的网站源代码恶意链接注入监控方法, 其特輕在予, 判断所述外部链接是否为可疑或者恶意链接包括: 根握所迷外郜链接是否 为位于像素值为 0的 面 t素中所包含的链接, 或者为坐标位置明显在屏
接。
4. 如权利要求 1所迷的网站 ¾代码恶意链接注入监控方法, 其特征在予, 判斷所述外部链接是否为可疑或者恶意链接包括: 将所述外部键接发送至 第三方 fl址验 ΐ£服务以验 所述外部链接是否为可 #是或恶意链接 β
5. 如权利要求 1所途的网站源代码恶意链接注入监 *方 , 其特征在于, 分析所途变更的代码片歡以抽取 Λ外部键接包括: 根振所述代码片段所采 用的编程《言加载相应的代码分祈器; 以夏采用 *代码分折器解析所述代 码片 以抽取 Λ所述外部链接 β
6. —种网站源代码恶意链接注入监控装置, 包括:
代码盈控羊元 , 用予监 *对网站涯代码文件的修改操作并羡取变更的代码 片段;
链接抽取单元, 用于分折所逹变更的代码片段 抽取 Λ外部链接; 链接分折单元, 用予判断所途外部链接是否为可疑或者恶意链接;
安全警告单元, 用于若判定所迷外部链接为可 或者恶意链接则发 警告 消息《
7. 如秋利要求 6所途的网站 ¾代码恶意链接注入监 *装置, 其特 在于, ¾包括安全方护牟元, 用于在判定所迷外部链接为可疑或者恶意链接之后 启 保护机制以方止系克文件被恶意删除、 服务被悉意卸载或者终止
8. 如权利要求 6所途的 «站¾代码悉意键接注入监控装置, 其特 在于, 所述链接分折单元, 用于根据所途外部链接是否为位于像素值为 的 面 元素中所包含的链接 或者为坐标 置明 在 幕之外的買面元素所包舍 的链接判断所迷外部链接是否为可疑或者恶意链接
9. 如权利要求 6所述的网站源代码恶意链接注入监控装置, 其特輕在于, 所述链接分折单元, 用予将所迷外部链接发送至第三方网址验证服务 验 证所述外部链接是否为可疑或悉意链接 n
10. 如权 ]要求 6所迷的网站源代码恶意链接注入监控装置,其特粗在 f , 所途链接抽取单元, 用于裉 *所 代码片歡所采用的编程语言加载相应的
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US14/709,641 US10148689B2 (en) | 2012-11-21 | 2015-05-12 | Method and apparatus for monitoring malicious link injection into website source code |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201210475499.2A CN103839002A (zh) | 2012-11-21 | 2012-11-21 | 网站源代码恶意链接注入监控方法及装置 |
| CN201210475499.2 | 2012-11-21 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US14/709,641 Continuation US10148689B2 (en) | 2012-11-21 | 2015-05-12 | Method and apparatus for monitoring malicious link injection into website source code |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014079307A1 true WO2014079307A1 (zh) | 2014-05-30 |
Family
ID=50775515
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2013/086233 Ceased WO2014079307A1 (zh) | 2012-11-21 | 2013-10-30 | 网站源代码恶意链接注入监控方法及装置 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US10148689B2 (zh) |
| CN (1) | CN103839002A (zh) |
| WO (1) | WO2014079307A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9621677B1 (en) | 2015-11-20 | 2017-04-11 | International Business Machines Corporation | Monitoring accesses to computer source code |
Families Citing this family (21)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105471821B (zh) * | 2014-08-29 | 2019-09-17 | 腾讯科技(深圳)有限公司 | 一种基于浏览器的信息处理方法及装置 |
| CN104268085B (zh) * | 2014-10-24 | 2017-07-28 | 重庆邮电大学 | 一种基于属性提取的软件漏洞挖掘系统及方法 |
| CN105704142A (zh) * | 2016-03-18 | 2016-06-22 | 中国石油大学(华东) | 一种存在hub节点的微博网络中恶意url防御方法和防御装置 |
| CN106682506B (zh) | 2016-05-06 | 2020-03-17 | 腾讯科技(深圳)有限公司 | 一种病毒程序检测方法和终端 |
| CN106156616B (zh) * | 2016-06-24 | 2019-08-23 | 武汉斗鱼网络科技有限公司 | 一种网站脚本攻击的防御方法及防御系统 |
| WO2018085732A1 (en) * | 2016-11-03 | 2018-05-11 | RiskIQ, Inc. | Techniques for detecting malicious behavior using an accomplice model |
| CN108259416B (zh) * | 2016-12-28 | 2021-06-22 | 华为技术有限公司 | 检测恶意网页的方法及相关设备 |
| CN109714296A (zh) * | 2017-10-26 | 2019-05-03 | 中国电信股份有限公司 | 威胁情报分析方法和装置 |
| CN109729137A (zh) * | 2018-05-15 | 2019-05-07 | 平安普惠企业管理有限公司 | 页面数据显示方法、显示终端及存储介质 |
| US10289836B1 (en) * | 2018-05-18 | 2019-05-14 | Securitymetrics, Inc. | Webpage integrity monitoring |
| WO2019231457A1 (en) * | 2018-05-31 | 2019-12-05 | Visa International Service Association | Web site compromise detection |
| US11368477B2 (en) | 2019-05-13 | 2022-06-21 | Securitymetrics, Inc. | Webpage integrity monitoring |
| US11082437B2 (en) * | 2019-12-17 | 2021-08-03 | Paypal, Inc. | Network resources attack detection |
| CN111131244B (zh) * | 2019-12-24 | 2022-03-25 | 佰倬信息科技有限责任公司 | 防止恶意内容侵染网站页面的方法和系统以及存储介质 |
| US12513188B2 (en) * | 2021-02-25 | 2025-12-30 | Shopify Inc. | Method and system for protecting a checkout transaction from malicious code injection |
| US12079299B2 (en) * | 2021-10-29 | 2024-09-03 | International Business Machines Corporation | Content management system |
| US20240152625A1 (en) * | 2022-10-31 | 2024-05-09 | CodeNotary Inc. | Locating Potentially-Exploitable Software Dependencies |
| US12361123B1 (en) * | 2023-01-20 | 2025-07-15 | Gen Digital Inc. | Systems and methods for detecting cross-site leaks and restricting execution timing |
| CN116361748B (zh) * | 2023-04-03 | 2023-09-15 | 武汉金力软件有限公司 | 一种软件供应链安全检测方法和装置 |
| US20250358300A1 (en) * | 2024-05-17 | 2025-11-20 | Palo Alto Networks, Inc. | Ml based domain risk scoring and its applications to advanced url filtering |
| CN118796264B (zh) * | 2024-06-14 | 2025-10-28 | 国家计算机网络与信息安全管理中心 | 一种模板网站关键源码片段识别方法 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020010855A1 (en) * | 2000-03-03 | 2002-01-24 | Eran Reshef | System for determining web application vulnerabilities |
| CN1866817A (zh) * | 2006-06-15 | 2006-11-22 | 北京华景中天信息技术有限公司 | 网站安全风险评估方法和系统 |
| US20100192224A1 (en) * | 2009-01-26 | 2010-07-29 | International Business Machines Corporation | Sandbox web navigation |
| CN102662840A (zh) * | 2012-03-31 | 2012-09-12 | 天津大学 | Firefox浏览器扩展行为自动检测系统及方法 |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1988535B (zh) * | 2005-12-23 | 2010-08-11 | 腾讯科技(深圳)有限公司 | 文件存储同步方法、系统及客户端 |
| MY154409A (en) * | 2008-07-21 | 2015-06-15 | Secure Corp M Sdn Bhd F | Website content regulation |
| US8505094B1 (en) * | 2010-01-13 | 2013-08-06 | Trend Micro, Inc. | Detection of malicious URLs in a web page |
| KR101671795B1 (ko) * | 2010-01-18 | 2016-11-03 | 삼성전자주식회사 | 동적 링크 라이브러리 삽입 공격을 방지하는 컴퓨터 시스템 및 방법 |
| CN102402620A (zh) * | 2011-12-26 | 2012-04-04 | 余姚市供电局 | 一种恶意网页防御方法和系统 |
-
2012
- 2012-11-21 CN CN201210475499.2A patent/CN103839002A/zh active Pending
-
2013
- 2013-10-30 WO PCT/CN2013/086233 patent/WO2014079307A1/zh not_active Ceased
-
2015
- 2015-05-12 US US14/709,641 patent/US10148689B2/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020010855A1 (en) * | 2000-03-03 | 2002-01-24 | Eran Reshef | System for determining web application vulnerabilities |
| CN1866817A (zh) * | 2006-06-15 | 2006-11-22 | 北京华景中天信息技术有限公司 | 网站安全风险评估方法和系统 |
| US20100192224A1 (en) * | 2009-01-26 | 2010-07-29 | International Business Machines Corporation | Sandbox web navigation |
| CN102662840A (zh) * | 2012-03-31 | 2012-09-12 | 天津大学 | Firefox浏览器扩展行为自动检测系统及方法 |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9621677B1 (en) | 2015-11-20 | 2017-04-11 | International Business Machines Corporation | Monitoring accesses to computer source code |
Also Published As
| Publication number | Publication date |
|---|---|
| CN103839002A (zh) | 2014-06-04 |
| US20150244738A1 (en) | 2015-08-27 |
| US10148689B2 (en) | 2018-12-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2014079307A1 (zh) | 网站源代码恶意链接注入监控方法及装置 | |
| US10032025B1 (en) | Behavior-based ransomware detection | |
| Wurzinger et al. | SWAP: Mitigating XSS attacks using a reverse proxy | |
| US20110083181A1 (en) | Comprehensive password management arrangment facilitating security | |
| US20100251371A1 (en) | Real-time malicious code inhibitor | |
| JP5430747B2 (ja) | ネットワーク内容改竄防止設備、方法及びそのシステム | |
| US20120222117A1 (en) | Method and system for preventing transmission of malicious contents | |
| CN103473501B (zh) | 一种基于云安全的恶意软件追踪方法 | |
| CN105303107A (zh) | 一种异常进程检测方法及装置 | |
| CN104820801A (zh) | 一种保护指定应用程序的方法及装置 | |
| US8701195B2 (en) | Method for antivirus in a mobile device by using a mobile storage and a system thereof | |
| CN104468546B (zh) | 一种网络信息处理方法及防火墙装置、系统 | |
| CN111901337A (zh) | 文件上传方法、系统及存储介质 | |
| KR100912794B1 (ko) | 실시간 웹 서버 해킹 분석 및 홈페이지 위변조 감시를 위한 웹 위협관리 시스템 및 그 방법 | |
| US10176317B2 (en) | Method and apparatus for managing super user password on smart mobile terminal | |
| US20100107247A1 (en) | System and method for identification, prevention and management of web-sites defacement attacks | |
| WO2017107830A1 (zh) | 一种安装应用软件的方法、装置及电子设备 | |
| US10264000B2 (en) | Malicious website access method and apparatus | |
| CN102208002B (zh) | 一种新型计算机病毒查杀装置 | |
| CN103530559A (zh) | 一种Android系统的完整性保护系统 | |
| CN103679016A (zh) | 手机恶意程序的处理方法和系统 | |
| CN105574146A (zh) | 网址拦截方法及装置 | |
| CN107330328A (zh) | 防御病毒攻击的方法、装置及服务器 | |
| CN104239798B (zh) | 移动办公系统及其杀毒方法和系统中的移动端、服务器端 | |
| TWI470468B (zh) | 惡意程式及行為偵測的方法及系統 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13857154 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 29.09.2015) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 13857154 Country of ref document: EP Kind code of ref document: A1 |