WO2015100969A1 - 软件行为监控验证系统 - Google Patents

软件行为监控验证系统 Download PDF

Info

Publication number
WO2015100969A1
WO2015100969A1 PCT/CN2014/080494 CN2014080494W WO2015100969A1 WO 2015100969 A1 WO2015100969 A1 WO 2015100969A1 CN 2014080494 W CN2014080494 W CN 2014080494W WO 2015100969 A1 WO2015100969 A1 WO 2015100969A1
Authority
WO
WIPO (PCT)
Prior art keywords
behavior
software behavior
party
software
node
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2014/080494
Other languages
English (en)
French (fr)
Inventor
蒋昌俊
陈闳中
闫春钢
丁志军
于汪洋
钟珺竹
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Tongji University
Original Assignee
Tongji University
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tongji University filed Critical Tongji University
Priority to DE112014000263.1T priority Critical patent/DE112014000263T5/de
Priority to US14/441,115 priority patent/US20160171494A1/en
Priority to ZA2015/03032A priority patent/ZA201503032B/en
Publication of WO2015100969A1 publication Critical patent/WO2015100969A1/zh
Anticipated expiration legal-status Critical
Priority to US16/245,212 priority patent/US11113412B2/en
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/02Payment architectures, schemes or protocols involving a neutral party, e.g. certification authority, notary or trusted third party [TTP]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3829Payment protocols; Details thereof insuring higher security of transaction involving key management
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3821Electronic credentials
    • G06Q20/38215Use of certificates or encrypted proofs of transaction rights
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/405Establishing or using transaction specific rules
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection

Definitions

  • the present invention relates to the field of electronic network transaction security monitoring technology. Background technique
  • EBS Electronic Brokerage System
  • API application programming interface
  • the e-commerce model is mainly composed of B2C, B2B and C2C, but these models also generally adopt the third-party payment model.
  • Users, e-commerce websites, and third-party payment platforms are currently three in the electronic transaction process. Main subject.
  • the above three parties trust each other through signature, authentication, encryption and other technologies, and call each other to communicate, thus collaborating to complete the entire online transaction process.
  • due to the insufficiency of current software development technologies there may be certain communication interface vulnerabilities and logic errors in user client software, e-commerce websites, and even third-party payment platforms.
  • the present invention is directed to the fact that malicious users who are legally registered can often exploit these vulnerabilities to engage in illegal acts and seek illegal benefits for themselves. And because of the hidden nature of this vulnerability, the diversity and difficulty of prevention, the variability of user behavior, and the distributed and loose coupling of network platforms, these three factors are combined, resulting in traditional security methods that cannot guarantee today's electronic network transactions. Safety. Summary of the invention
  • the object of the present invention is to overcome the deficiencies of the prior art, and to disclose a software behavior monitoring and verification system, and propose a security assurance mode in which a user, an e-commerce platform, and a third-party payment platform cooperate with each other, and the transaction process is monitored in real time. alarm.
  • a software behavior monitoring and verification system is characterized in that: a software behavior certificate, a three-party software behavior monitor, and a software behavior real-time verification system are composed of three parts.
  • the software behavior certificate is a three-party communication data packet under the correct transaction process according to the user, the e-commerce website, and the third-party payment platform, so that the professional person artificially depicts the normal legal interaction behavior of the three parties to form a software behavior certificate.
  • the software behavior certificate is an e-commerce website, a third-party payment platform, and a user client, and includes an interaction mode formed between the two, forming a corresponding software behavior model.
  • the three-party software behavior monitor is installed on an e-commerce website, a third-party payment platform, and a user client.
  • the data packet monitor on the side is used to monitor the data packets transmitted between the three parties participating in the transaction in a complete transaction in real time, and extract and integrate the necessary parameter information (URL address, parameters, etc.) in the data packet. It is convenient to send key information to the software behavior real-time verification system.
  • the monitor is based on jpcap technology, mainly captures the http protocol data packet, and extracts the URL address and parameter information in the data packet, and the transaction three-party e-commerce number and the third-party payment platform number. Then, a socket connection is established with the software behavior real-time verification system, and the key information is sent to the software behavior real-time verification system in the form of tcp data packets.
  • the software behavior real-time verification system extracts and integrates the key sequence and information after receiving the transaction interaction information data packet submitted by the three-party monitor, and combines the user behavior interaction sequence and the software behavior according to the global unique order number.
  • the model performs real-time comparisons, and in the event of an out-of-order, illegal identity, etc., an alert is issued and the transaction is closed.
  • the software behavior described in the software behavior certificate has a certain behavior logic, which is embodied in:
  • Each transition-node in the software behavior certificate is a behavior node.
  • the data packets captured by either party are divided into two categories: received messages, sent messages, corresponding to input, output in transition_node. Both have the necessary logical order, the receiving message must precede the sending of the message; the captured sequence of actions is compared with the corresponding transition-node, and an alarm is issued once the above logical order is violated;
  • the software behavior real-time verification system also compares the current body of the received or sent message with the subject name recorded by the attribute attri in the certificate behavior node (transition-node). If it does not match, it means illegal user identity. Pretending to attack, alert immediately;
  • place_node depicts the logical sequence between the behavior node and the behavior node.
  • the behavior node transition-node
  • the behavior node must also be arranged in a certain transaction order. Once a jump occurs, the out-of-order means that the legal normal transaction flow is Breaking, there was a violation, and an immediate alert.
  • the innovation of the invention and its beneficial effects Using the key parameters such as the three-party interaction url, portraying the legal normal three-party transaction interaction process, and proposing a software behavior certificate.
  • the software behavior certificate is a three-party communication data packet under the correct transaction flow according to the user, the e-commerce website, and the third-party payment platform, so that the professional person can characterize the normal legal interaction behavior of the three parties and form a software behavior certificate.
  • the invention proposes a security guarantee mode in which the three parties of the user, the e-commerce platform and the third-party payment platform cooperate with each other, the whole process of the transaction process is monitored, and the real-time alarm is provided.
  • FIG. 1 is an overall architecture diagram of software behavior monitoring verification.
  • FIG. 2 is a flow chart of the three-party software behavior monitor.
  • FIG. 3 is a flow chart of a software behavior real-time verification system.
  • FIG. 1 The architecture of the entire software behavior monitoring and verification system is shown in FIG. 1.
  • the entire software behavior monitoring and verification system solidifies the behavior of the truly legitimate user to form a software behavior certificate. Then, based on the global unique order number, the three-way interactive behavior sequence in the transaction process is compared with the software behavior certificate in real time, and the single-step verification is performed. If any party has an illegal behavior such as disorder or fake identity, an alarm or certain measures are taken. .
  • a three-party software behavior monitor installing a packet monitor on an e-commerce website, a third-party payment platform, and a user client, for real-time monitoring of data packets transmitted between the three parties participating in the transaction in one complete transaction, and The extraction and integration of the necessary parameter information in the data packet facilitates the transmission of key information to the software behavior real-time verification system.
  • the monitor is based on jpcap technology, mainly captures the http protocol data packet, and extracts the URL address and parameter information in the data packet, as well as the transaction three-party e-commerce number and the third-party payment platform number. Then, a socket connection is established with the software behavior real-time verification system, and the key information is sent to the software behavior real-time verification system in the form of tcp data packets.
  • the three-party software behavior monitoring flow chart is shown in Figure 2:
  • Software behavior real-time verification system After establishing a socket connection with the three-party software behavior monitor, it receives the tcp data packet sent by the three-party software behavior monitor, extracts and integrates the key sequences and information. Then, according to the global unique order number, the user behavior interaction sequence and the software behavior model are verified in real time, and if an illegal behavior such as out-of-order, fake identity, etc. occurs, an alarm is issued and the transaction is closed.
  • Figure 3 The flow chart of the software behavior real-time verification system is shown in Figure 3:
  • the e-commerce website and the third-party payment platform, as well as the user client, include a software behavior certificate formed by the respective interaction modes between the two.
  • Software behavior certificates are manually built by professionals and stored in the server in an XML file format.
  • Input is a key parameter received by either party (user, e-commerce site, third-party payment platform)
  • Software behaviors portrayed in software behavior certificates have certain behavioral logic. This logic embodies the three-way interaction sequence, preconditions, and so on.
  • Each transition-node in the software behavior certificate is a behavior node.
  • the packets captured by either of the three parties are divided into two categories: received messages, sent messages. Corresponding to input, output in transition-node respectively, and both have the necessary logical order, the message must be sent before the message is received. We compare the captured sequence of actions to the corresponding transition-node and alert if the above logical order is violated.
  • the software behavior real-time verification system will also receive or send the current subject and certificate behavior node of the message.

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Finance (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computing Systems (AREA)
  • Economics (AREA)
  • Development Economics (AREA)
  • Software Systems (AREA)
  • General Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Health & Medical Sciences (AREA)
  • Databases & Information Systems (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Debugging And Monitoring (AREA)
  • Computer And Data Communications (AREA)

Abstract

一种软件行为监控验证系统,由软件行为证书、三方软件行为监控器、软件行为实时验证系统三个部分组成;软件行为证书是根据用户,电子商务网站,第三方支付平台在正确交易流程下的三方通信数据包;三方软件行为监控器,是安装于电子商务网站、第三方支付平台、用户客户端上的数据包监控器;软件行为实时验证系统在接收三方监控器分别提交的交易交互信息数据包后,提取并整合其中的关键序列与信息,并根据全球唯一订单号,将用户行为交互序列与软件行为模型进行实时对比,一旦发生乱序,假冒身份等非法行为则进行警报并关闭交易。利用三方交互url等关键参数,刻画合法正常三方交易交互流程,提出了软件行为证书。

Description

软件行为监控验证系统 技术领域
[0001] 本发明涉及电子商务网络交易安全监控技术领域。 背景技术
[0002] 随着 Internet的发展, 电子商务 (E— Commerce ) 已经逐渐成为人们进行商务活 动的新模式, 也越来越成为国际贸易中重要的经营模式。 它以计算机技术、 通信技术与网络 技术为基础, 利用电子数据交换、 电子邮件、 电子支付等方式实现了整个商务活动的电子 化、 数字化和网络化。 电子交易平台的出现, 使整个销售、 交易和确认的程序已被网上交易 所取代。 由从前第一代的银行交易系统 Electronic Brokerage System (EBS) , 发展至银行 自行研发的单一交易平台, 到今天由第三方提供的多主体交易平台, 以及由市场推动的应用 程序接口 (API ) , 都显示出电子交易迅猛发展的势头, 但它的发展还面临着许多机遇和调 整。
[0003] 近年来, 电子商务模式主要由 B2C,B2B和 C2C构成, 但这些模式也都普遍采用第 三方支付的模式, 用户、 电子商务网站、 第三方支付平台是目前电子交易过程中的三个主要 主体。 上述三方通过签名, 认证, 加密等技术相互信任, 互相调用接口进行通信, 从而协作 完成整个网上交易过程。 然而由于当今软件开发技术的不够完善, 在用户客户端软件, 电子 商务网站, 甚至是第三方支付平台都可能存在着一定的通信接口漏洞和逻辑错误等。
[0004] 本发明面向的情况是合法注册的恶意用户往往可以利用这些漏洞从事非法行为, 为自己谋取非法利益。 并且由于这种漏洞的隐藏性, 多样性和难以防范性、 用户行为的多变 性、 以及网络平台的分布式与松耦合性, 这三者因素综合, 导致传统的安全方法无法保证现 今电子网络交易安全。 发明内容
[0005] 本发明的目的在于克服现有技术的不足, 公开了一种软件行为监控验证系统, 提 出用户、 电子商务平台、 第三方支付平台三方相互协作的安全保证模式, 交易流程全程监 控, 实时警报。
[0006] 本发明给出的技术方案为:
一种软件行为监控验证系统, 其特征在于, 由软件行为证书、 三方软件行为监控器、 软 件行为实时验证系统三个部分组成。
[0007] 所述软件行为证书是根据用户, 电子商务网站, 第三方支付平台在正确交易流程 下的三方通信数据包, 从而由专业人员人为刻画三方正常合法交互行为, 形成软件行为证 书。 所述软件行为证书是电子商务网站、 第三方支付平台、 用户客户端三者, 包括两两之间 各自形成的交互模式, 形成对应的软件行为模型。
[0008] 所述三方软件行为监控器, 是安装于电子商务网站、 第三方支付平台、 用户客户 端上的数据包监控器, 用来实时监控在一次完整交易中参与交易的三方之间相互传递的数据 包, 并且进行数据包中的必要参数信息 (URL地址, 参数等) 的提取和整合, 便于将关键信 息发送给软件行为实时验证系统。 所述监控器以 jpcap为技术基础, 主要捕获 http协议数 据包, 并提取数据包中的 URL地址及参数信息, 以及交易三方中电商编号和第三方支付平台 编号。 随后与软件行为实时验证系统建立 socket连接, 将关键信息以 tcp数据包的形式发 送给软件行为实时验证系统。
[0009] 所述软件行为实时验证系统在接收三方监控器分别提交的交易交互信息数据包 后, 提取并整合其中的关键序列与信息, 并根据全球唯一订单号, 将用户行为交互序列与软 件行为模型进行实时对比,一旦发生乱序, 假冒身份等非法行为则进行警报并关闭交易。
[0010] 所述软件行为证书中刻画的软件行为有着一定的行为逻辑, 体现在:
1 ) 软件行为证书中每一个 transition—node 为一个行为结点, 三方中任一方所捕捉到 的数据包分为两大类: 接收的消息, 发送的消息, 分别对应 transition_node中的 input, output, 两者有着必要的逻辑顺序, 接收消息必须先于发送消息; 将捕获的到行为序列与相 对应的 transition—node相对比, 一旦违反上述逻辑顺序则进行警报;
2 ) 与此同时, 软件行为实时验证系统还将接收或者发送消息的当前主体与证书行为结 点 (transition—node ) 中属性 attri 所记录的主体名称进行对比, 如不相符则意味着非法 用户身份冒充攻击, 立即警报;
3 ) place_node 则刻画了行为结点与行为结点之间的逻辑顺序, 行为结点 ( transition—node ) 也必须按照一定的交易顺序排列, 一旦发生跳跃, 乱序则意味着合法 正常交易流程被打破, 出现了违规操作, 立即警报。
[0011] 本发明的创新点及其有益效果: 利用三方交互 url 等关键参数, 刻画合法正常三 方交易交互流程, 提出了软件行为证书。 软件行为证书是根据用户, 电子商务网站, 第三方 支付平台在正确交易流程下的三方通信数据包, 从而由专业人员人为刻画三方正常合法交互 行为, 形成软件行为证书。 本发明提出用户, 电子商务平台, 第三方支付平台三方相互协作 的安全保证模式, 交易流程全程监控, 实时警报。 附图说明
[0012] 图 1 是软件行为监控验证整体架构图。
[0013] 图 2 三方软件行为监控器流程图。
[0014] 图 3 软件行为实时验证系统流程图。
[0015] 图 4 软件行为证书格式 (place_node)。
[0016] 图 5 软件行为证书格式 (transition_node)。 具体实施方式
[0017] 整个软件行为监控验证系统的架构如图 1所示。
[0018] 整个软件行为监控验证系统将真正合法用户的行为固化下来形成软件行为证书。 然后主要根据全球唯一订单号, 将交易过程中的三方交互行为序列与软件行为证书进行实时 对比, 单步验证,一旦任何一方发生消息乱序或者假冒身份等非法行为则进行警报或采取一 定的措施。
[0019] 三方软件行为监控器: 在电子商务网站、 第三方支付平台以及用户客户端安装数 据包监控器, 用来实时监控在一次完整交易中参与交易的三方之间相互传递的数据包, 并且 进行数据包中的必要参数信息的提取和整合, 便于将关键信息发送给软件行为实时验证系 统。 所述监控器以 jpcap为技术基础, 主要捕获 http协议数据包, 并提取数据包中的 URL 地址及参数信息, 以及交易三方中电商编号和第三方支付平台编号。 随后与软件行为实时验 证系统建立 socket连接, 将关键信息以 tcp数据包的形式发送给软件行为实时验证系统。 三方软件行为监控流程图如图 2所示:
软件行为实时验证系统: 在与三方软件行为监控器建立 socket 连接之后, 接收三方软 件行为监控器发送过来的 tcp数据包, 提取并整合其中的关键序列与信息。 然后根据全球唯 一订单号, 将用户行为交互序列与软件行为模型进行实时验证, 一旦发生乱序, 假冒身份等 非法行为则进行警报并关闭交易。 软件行为实时验证系统流程图如图 3所示:
电子商务网站与第三方支付平台, 以及用户客户端三者, 包括两两之间各自的交互模式 所形成的软件行为证书。 软件行为证书由专业人员手动构建, 并以 XML文件格式存储在服务 器中。
[0020] 软件行为证书格式如图 4,图 5所示:
input 为三方 (用户, 电子商务网站, 第三方支付平台) 中任一方接收到的关键参数
(url等)。 output为当前方发送的关键参数。 这些交互信息代表了软件行为序列。
[0021] 软件行为证书中刻画的软件行为有着一定的行为逻辑。 这种逻辑体现了三方交互 顺序, 前提条件等。 软件行为证书中每一个 transition—node为一个行为结点。 三方中任一 方所捕捉到的数据包分为两大类: 接收的消息, 发送的消息。 分别对应 transition—node中 的 input, output . 而两者也有着必要的逻辑顺序, 接收消息必须先于发送消息。 我们将捕 获的到行为序列与相对应的 transition—node相对比, 一旦违反上述逻辑顺序则进行警报。 与此同时, 软件行为实时验证系统还将接收或者发送消息的当前主体与证书行为结点
( transition—node ) 中属性 attri 所记录的主体名称进行对比, 如不相符则意味着非法用 户身份冒充攻击, 立即警报。 place—node 则刻画了行为结点与行为结点之间的逻辑顺序。 也就是说行为结点 (transition—node ) 也必须按照一定的交易顺序排列, 一旦发生跳跃, 乱序则意味着合法正常交易流程被打破, 出现了违规操作, 立即警报。

Claims

权利要求书
1.一种软件行为监控验证系统, 其特征在于, 由软件行为证书、 三方软件行为监控 器、 软件行为实时验证系统三个部分组成;
所述软件行为证书是根据用户, 电子商务网站, 第三方支付平台在正确交易流程下的三 方通信数据包, 从而由专业人员人为刻画三方正常合法交互行为, 形成软件行为证书。 所述软件行为证书是电子商务网站、 第三方支付平台、 用户客户端三者, 包括两两之间 各自形成的交互模式, 形成对应的软件行为模型;
所述三方软件行为监控器, 是安装于电子商务网站、 第三方支付平台、 用户客户端 上的数据包监控器, 用来实时监控在一次完整交易中参与交易的三方之间相互传递的数 据包, 并且进行数据包中的必要参数信息 (URL地址, 参数等) 的提取和整合, 便于将 关键信息发送给软件行为实时验证系统; 所述监控器以 jpcap 为技术基础, 主要捕获 http协议数据包, 并提取数据包中的 URL地址及参数信息, 以及交易三方中电商编号和 第三方支付平台编号; 随后与软件行为实时验证系统建立 socket 连接, 将关键信息以 tcp数据包的形式发送给软件行为实时验证系统。
所述软件行为实时验证系统在接收三方监控器分别提交的交易交互信息数据包后, 提取并整合其中的关键序列与信息, 并根据全球唯一订单号, 将用户行为交互序列与软 件行为模型进行实时对比,一旦发生乱序, 假冒身份等非法行为则进行警报并关闭交 易。
2.根据权利要求 1所述的软件行为监控验证系统, 其特征在于, 所述软件行为证书 中刻画的软件行为有着一定的行为逻辑, 体现在:
1 ) 软件行为证书中每一个 transition_node 为一个行为结点, 三方中任一方所捕 捉到的数据包分为两大类: 接收的消息, 发送的消息, 分别对应 transition—node 中的 input , output , 两者有着必要的逻辑顺序, 接收消息必须先于发送消息; 将捕获的到 行为序列与相对应的 transition—node相对比, 一旦违反上述逻辑顺序则进行警报;
2 ) 与此同时, 软件行为实时验证系统还将接收或者发送消息的当前主体与证书行 为结点 (transition—node ) 中属性 attri 所记录的主体名称进行对比, 如不相符则意 味着非法用户身份冒充攻击, 立即警报;
3 ) place_node 则刻画了行为结点与行为结点之间的逻辑顺序, 行为结点 ( transition—node ) 也必须按照一定的交易顺序排列, 一旦发生跳跃, 乱序则意味着 合法正常交易流程被打破, 出现了违规操作, 立即警报。
PCT/CN2014/080494 2014-01-06 2014-06-23 软件行为监控验证系统 Ceased WO2015100969A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
DE112014000263.1T DE112014000263T5 (de) 2014-01-06 2014-06-23 Überwachungs- und Verifizierungssystem für Softwareverhalten
US14/441,115 US20160171494A1 (en) 2014-01-06 2014-06-23 Software behavior monitoring and verification system
ZA2015/03032A ZA201503032B (en) 2014-01-06 2015-05-04 Software behaviour monitoring and verification system
US16/245,212 US11113412B2 (en) 2014-01-06 2019-01-10 System and method for monitoring and verifying software behavior

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410014450.6A CN103714456B (zh) 2014-01-06 2014-01-06 软件行为监控验证系统
CN201410014450.6 2014-01-06

Related Child Applications (2)

Application Number Title Priority Date Filing Date
US14/441,115 A-371-Of-International US20160171494A1 (en) 2014-01-06 2014-06-23 Software behavior monitoring and verification system
US16/245,212 Continuation-In-Part US11113412B2 (en) 2014-01-06 2019-01-10 System and method for monitoring and verifying software behavior

Publications (1)

Publication Number Publication Date
WO2015100969A1 true WO2015100969A1 (zh) 2015-07-09

Family

ID=50407408

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/080494 Ceased WO2015100969A1 (zh) 2014-01-06 2014-06-23 软件行为监控验证系统

Country Status (6)

Country Link
US (2) US20160171494A1 (zh)
CN (1) CN103714456B (zh)
AU (1) AU2014101545A4 (zh)
DE (1) DE112014000263T5 (zh)
WO (1) WO2015100969A1 (zh)
ZA (1) ZA201503032B (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116069549A (zh) * 2023-01-09 2023-05-05 国网江苏省电力有限公司 一种基于有效配置信息的非同源配置一致性校验方法及系统

Families Citing this family (20)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103714456B (zh) * 2014-01-06 2015-08-19 同济大学 软件行为监控验证系统
CN104270359B (zh) * 2014-09-25 2018-04-17 同济大学 网络交易的可信认证系统与方法
CN104281674B (zh) * 2014-09-29 2017-07-11 同济大学 一种基于集聚系数的自适应聚类方法及系统
CN105184630A (zh) * 2015-08-28 2015-12-23 王子瑜 交易流程的合法性检测方法及系统
CN105260675B (zh) * 2015-10-16 2017-03-15 北京源创云网络科技有限公司 电子数据一致性验证方法、装置、系统及存证验证平台
US10356116B2 (en) * 2016-04-07 2019-07-16 IDfusion, LLC Identity based behavior measurement architecture
CN106875167B (zh) * 2016-08-18 2020-08-04 阿里巴巴集团控股有限公司 电子支付过程中资金交易路径的检测方法和装置
CN109560977A (zh) * 2017-09-25 2019-04-02 北京国双科技有限公司 网站业务监控方法、装置、存储介质、处理器及电子设备
CN108229964B (zh) * 2017-12-25 2021-04-02 同济大学 交易行为轮廓构建与认证方法、系统、介质及设备
US11070506B2 (en) * 2018-01-10 2021-07-20 Vmware, Inc. Email notification system
CN110120964B (zh) * 2018-02-07 2022-07-08 北京三快在线科技有限公司 用户行为监控方法和装置以及计算设备
US11336668B2 (en) * 2019-01-14 2022-05-17 Penta Security Systems Inc. Method and apparatus for detecting abnormal behavior of groupware user
CN109885485B (zh) * 2019-01-21 2022-08-05 中国光大银行股份有限公司 交易冲突检测方法和装置
DE102020213522A1 (de) * 2020-10-28 2022-04-28 Robert Bosch Gesellschaft mit beschränkter Haftung Verfahren zum Betreiben eines Sicherheitssystems
US11799857B2 (en) 2021-08-31 2023-10-24 Cisco Technology, Inc. Software posture for zero trust access
CN113888760B (zh) * 2021-09-29 2024-04-23 平安银行股份有限公司 基于软件应用的违规信息监控方法、装置、设备及介质
US12425436B2 (en) * 2021-11-29 2025-09-23 Zscaler, Inc. System and method thereof for generating a threat indicator of an agentless third-party application
US20240013127A1 (en) * 2022-07-05 2024-01-11 Bank Of America Corporation Dual artificial intelligence system for real-time benchmarking and predictive modeling
CN117081856B (zh) * 2023-10-13 2023-12-19 湖南视觉伟业智能科技有限公司 基于云计算的智慧空间分析平台及预警方法
CN118714058B (zh) * 2024-08-29 2025-01-10 山东云海国创云计算装备产业创新中心有限公司 总线控制器模块验证方法、系统、程序产品、装置及介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040034583A1 (en) * 2002-08-15 2004-02-19 Lanier Cheryl Lynn Systems and methods for performing electronic check commerce
CN101706937A (zh) * 2009-12-01 2010-05-12 中国建设银行股份有限公司 电子银行风险监控方法及系统
CN102194177A (zh) * 2011-05-13 2011-09-21 南京柯富锐软件科技有限公司 一种用于在线支付风险控制的系统
CN103279883A (zh) * 2013-05-02 2013-09-04 携程计算机技术(上海)有限公司 电子支付交易风险控制方法及系统
CN103714456A (zh) * 2014-01-06 2014-04-09 同济大学 软件行为监控验证系统

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1900963A (zh) * 2005-07-18 2007-01-24 中国银联股份有限公司 网上安全支付系统
JP4618263B2 (ja) * 2007-03-23 2011-01-26 株式会社豊田中央研究所 ソフトウェア挙動監視装置及びソフトウェア挙動監視システム
JP5081480B2 (ja) * 2007-03-28 2012-11-28 株式会社エヌ・ティ・ティ・ドコモ ソフトウェア挙動モデル化装置、ソフトウェア挙動モデル化方法、ソフトウェア挙動検証装置及びソフトウェア挙動検証方法
US20080294556A1 (en) * 2007-05-24 2008-11-27 Jim Anderson Mobile commerce service
WO2013018096A1 (en) * 2011-08-03 2013-02-07 Ramot At Tel-Aviv University Ltd. Use of integrase for targeted gene expression
WO2013184108A1 (en) * 2012-06-06 2013-12-12 Empire Technology Development Llc Software protection mechanism
CN103489101A (zh) * 2012-06-14 2014-01-01 海瑞斯信息科技(苏州)有限公司 基于融合通信技术的安全电子支付系统及支付方法
US9619346B2 (en) * 2013-10-31 2017-04-11 Assured Information Security, Inc. Virtual machine introspection facilities
US10440019B2 (en) * 2014-05-09 2019-10-08 Behaviometrics Ag Method, computer program, and system for identifying multiple users based on their behavior

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040034583A1 (en) * 2002-08-15 2004-02-19 Lanier Cheryl Lynn Systems and methods for performing electronic check commerce
CN101706937A (zh) * 2009-12-01 2010-05-12 中国建设银行股份有限公司 电子银行风险监控方法及系统
CN102194177A (zh) * 2011-05-13 2011-09-21 南京柯富锐软件科技有限公司 一种用于在线支付风险控制的系统
CN103279883A (zh) * 2013-05-02 2013-09-04 携程计算机技术(上海)有限公司 电子支付交易风险控制方法及系统
CN103714456A (zh) * 2014-01-06 2014-04-09 同济大学 软件行为监控验证系统

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116069549A (zh) * 2023-01-09 2023-05-05 国网江苏省电力有限公司 一种基于有效配置信息的非同源配置一致性校验方法及系统

Also Published As

Publication number Publication date
CN103714456A (zh) 2014-04-09
ZA201503032B (en) 2018-11-28
US11113412B2 (en) 2021-09-07
US20160171494A1 (en) 2016-06-16
AU2014101545A4 (en) 2015-07-02
US20190163925A1 (en) 2019-05-30
CN103714456B (zh) 2015-08-19
DE112014000263T5 (de) 2015-10-15

Similar Documents

Publication Publication Date Title
WO2015100969A1 (zh) 软件行为监控验证系统
US12041063B2 (en) Electronic interaction authentication and verification, and related systems, devices, and methods
Ellison Ceremony design and analysis
KR101133829B1 (ko) 인증서 레지스트리, 인증서 레지스트리 시스템 및 방법
JP6527590B2 (ja) オフライン・ネットワーク・トラフィックに基づいてカバート・チャネルのネットワーク侵入を検出するためのシステムおよび方法
CN101741860B (zh) 一种计算机远程安全控制方法
TW201031169A (en) Network reputation system and its controlling method
CN103973695A (zh) 一种与服务器验证的签名算法
JP2021168192A (ja) コンピュータ化された承認システムおよび方法
CN104883367B (zh) 一种辅助验证登陆的方法、系统和应用客户端
CN114616795B (zh) 用于防止重试或重放攻击的安全机制
CN108650077A (zh) 基于区块链的信息传输方法、终端、设备及可读存储介质
CN113852628A (zh) 一种去中心化的单点登录方法、装置及存储介质
CN106060078A (zh) 应用于云平台的用户信息加密方法、注册方法及验证方法
CN104079413A (zh) 增强型一次性动态口令的认证方法及系统
CN110213195A (zh) 一种登录认证方法、服务器及用户终端
WO2022057106A1 (zh) 数字资产数据包的可信性验证系统
CN106101092A (zh) 一种信息评估处理方法及第一实体
CN112862487A (zh) 一种数字证书认证方法、设备及存储介质
US20250284780A1 (en) Systems and methods for secure authentication
CN117829841A (zh) 基于区块链的业务交易监管方法、装置及电子设备
CN102811369A (zh) 在视频共享时进行安全认证方法及手持设备
CN112383737B (zh) 多人在线内容同屏的视频处理验证方法、装置和电子设备
US20250165569A1 (en) Systems and methods for secure authentication
CN116910826B (zh) 一种用于电力设备招标的采购数据存证及共享系统

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 2014331638

Country of ref document: AU

WWE Wipo information: entry into national phase

Ref document number: 14441115

Country of ref document: US

WWE Wipo information: entry into national phase

Ref document number: 112014000263

Country of ref document: DE

Ref document number: 1120140002631

Country of ref document: DE

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14876625

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 14876625

Country of ref document: EP

Kind code of ref document: A1

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205N DATED 02.12.2016)

122 Ep: pct application non-entry in european phase

Ref document number: 14876625

Country of ref document: EP

Kind code of ref document: A1