WO2018223797A1 - 数据响应方法、终端设备以及服务器 - Google Patents
数据响应方法、终端设备以及服务器 Download PDFInfo
- Publication number
- WO2018223797A1 WO2018223797A1 PCT/CN2018/085923 CN2018085923W WO2018223797A1 WO 2018223797 A1 WO2018223797 A1 WO 2018223797A1 CN 2018085923 W CN2018085923 W CN 2018085923W WO 2018223797 A1 WO2018223797 A1 WO 2018223797A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- honeypot
- server
- terminal device
- character
- encrypted information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/64—Protecting data integrity, e.g. using checksums, certificates or signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/552—Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/566—Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/602—Providing cryptographic facilities or services
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/604—Tools and structures for managing or administering access control systems
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1491—Countermeasures against malicious traffic using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment
Definitions
- This application relates to the field of computer security, and more particularly to data response.
- the server may generate a plurality of sets of keys, and the server may pass the user data of the terminal device to the generated multiple sets of keys.
- One key is encrypted to generate ciphertext data, and the ciphertext data is saved in the terminal device.
- the server needs to perform complex management on multiple sets of keys, and the server background occupies storage space of the server when storing multiple sets of keys, thereby reducing the operating efficiency of the server. Moreover, once the multiple sets of keys stored by the server are cracked, the server cannot perceive that the key is cracked, so that the attacker can tamper with the data of the terminal device arbitrarily and long-term.
- the embodiment of the present application provides a data response method, a terminal device, and a server that can obtain data of a terminal device that has been tampered in advance.
- a first aspect of the embodiments of the present application provides a data response method, including:
- a second aspect of the embodiments of the present application provides a data response method, including:
- the server receives the honeypot character, the encryption information, and the user data sent by the terminal device, where the encrypted information is information sent by the server to the terminal device;
- the server determines that the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information, the server responds to the user data.
- a third aspect of the embodiments of the present application provides a data response method, including:
- the server Transmitting the honeypot character, the encryption information, and user data to the server, so that if the server determines that the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information, Responding to the user data, if the server determines that the honeypot character sent by the terminal device is different from the honeypot character included in the encryption information, the server does not respond to the user data.
- a fourth aspect of the embodiments of the present application provides a data response method, including:
- the terminal device acquires the encrypted information sent by the server;
- the server Transmitting, by the terminal device, the honeypot character, the encryption information, and user data to the server, so that if the server determines that the honeypot character and the encrypted information are sent by the terminal device, If the honeypot character is the same, the server responds to the user data, and if the server determines that the honeypot character sent by the terminal device is different from the honeypot character included in the encryption information, the server does not respond to the User data.
- a fifth aspect of the embodiments of the present application provides a server, including:
- a first receiving unit configured to receive honeypot characters, encryption information, and user data sent by the terminal device, where the encrypted information is information sent to the terminal device;
- a calculating unit configured to perform decryption calculation on the encrypted information to obtain a honeypot character included in the encrypted information
- a determining unit configured to determine whether the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information
- the first determining unit is configured to respond to the user data if it is determined that the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information.
- a sixth aspect of the embodiments of the present application provides a terminal device, including:
- An obtaining unit configured to obtain encrypted information sent by the server
- a calculating unit configured to perform decryption calculation on the encrypted information to obtain a honeypot character included in the encrypted information
- a first sending unit configured to send the honeypot character, the encrypted information, and user data to the server, so that if the server determines that the honeypot character and the encrypted information sent by the terminal device are included If the honeypot characters are the same, the server responds to the user data, and if the server determines that the honeypot character sent by the terminal device is different from the honeypot character included in the encrypted information, the server does not respond to the user data.
- a seventh aspect of the embodiments of the present application provides a server, including:
- One or more central processing units a memory, a bus system, and one or more programs, the central processing unit and the memory being coupled by the bus system;
- the one or more programs are stored in the memory, the one or more programs comprising instructions that, when executed by the server, cause the server to perform as in the first aspect of the embodiments of the present application The method shown.
- An eighth aspect of embodiments of the present application provides a computer readable storage medium storing one or more programs, including one or more programs, the one or more programs including instructions that, when executed by a server The server performs the method as shown in the first aspect of the embodiments of the present application.
- a ninth aspect of the embodiment of the present application provides a terminal device, including:
- processor units One or more processor units, memory units, bus systems, and one or more programs, the processor units and the memory units being coupled by the bus system;
- the one or more programs are stored in the storage unit, the one or more programs including instructions that, when executed by the terminal device, cause the terminal device to perform the first embodiment of the present application The method shown in three aspects.
- a tenth aspect of embodiments of the present application provides a computer readable storage medium storing one or more programs, including one or more programs, the one or more programs including instructions, when executed by a terminal device The terminal device is caused to perform the method as shown in the third aspect of the embodiment of the present application.
- the terminal device, and the server shown in this embodiment because the encrypted information has a non-tamperable characteristic, the honeypot field and the encrypted information included in the terminal device are verified by the encrypted information. Whether the honeypot fields are consistent, in order to determine whether the terminal device tampers with the data, without occupying a large storage space of the server, the storage space of the server can be saved, thereby improving the operation of the server.
- Efficiency and the method shown in this embodiment is simple in operation, effectively improving the efficiency of the method shown in this embodiment, and the method shown in this embodiment can sense the tampering operation of the data of the terminal device before causing the loss, thereby
- the countermeasures can be taken in advance, thereby effectively avoiding leakage of user privacy data, realizing active defense against the integrity of the front-end data of the terminal device, and effectively ensuring the security of the communication system and avoiding the loss of the communication system.
- FIG. 1 is a schematic structural diagram of an embodiment of a communication system according to an embodiment of the present disclosure
- FIG. 2 is a schematic structural diagram of an embodiment of a terminal device according to an embodiment of the present disclosure
- FIG. 3 is a schematic structural diagram of an embodiment of a server according to an embodiment of the present disclosure.
- FIG. 4 is a flow chart of steps of an embodiment of a data response method according to an embodiment of the present application.
- FIG. 5 is a flow chart of another embodiment of a data response method according to an embodiment of the present disclosure.
- FIG. 6 is a schematic structural diagram of another embodiment of a server according to an embodiment of the present disclosure.
- FIG. 7 is a schematic structural diagram of another embodiment of a terminal device according to an embodiment of the present application.
- the embodiment of the present application provides a data response method, and the data response method shown in this embodiment is applied to a communication system, and the data response method shown in the embodiment of the present application is better understood.
- the communication system is described in detail as shown:
- FIG. 1 is a schematic structural diagram of a communication system in an embodiment of the present application.
- the communication system includes a server 100 and at least one terminal device 110.
- the server 100 and the terminal device 110 can perform data interaction, thereby implementing the data response method shown in this embodiment.
- FIG. 2 is a schematic structural diagram of an embodiment of a terminal device according to an embodiment of the present application.
- the terminal device includes components such as an input unit 205, a processor unit 203, an output unit 201, a communication unit 207, a storage unit 204, a radio frequency circuit 208, and the like.
- the structure of the terminal device shown in FIG. 2 does not constitute a limitation on the embodiment of the present application. It may be a bus-shaped structure or a star-shaped structure, and may also include more than the illustration. Or fewer parts, or combine some parts, or different parts.
- the terminal device may be any mobile or portable electronic device, including but not limited to a smart phone, a mobile computer, a tablet computer, a personal digital assistant (English full name: Personal Digital Assistant, English abbreviation: PDA), Media player, smart TV, etc.
- the terminal device includes:
- the output unit 201 is configured to output an image to be displayed.
- the output unit 201 includes but is not limited to the image output unit 2011 and the sound output unit 2012.
- the image output unit 2011 is for outputting text, pictures, and/or video.
- the image output unit 2011 may include a display panel, for example, a liquid crystal display (English name: Liquid Crystal Display, English abbreviation: LCD), an organic light emitting diode (English name: Organic Light-Emitting Diode, English abbreviation: OLED), field emission A display panel configured in the form of a display (English name: field emission display, FED for short).
- the image output unit 2011 may include a reflective display, such as an electrophoretic display, or a display using an Interferometric Modulation of Light.
- the image output unit 2011 may include a single display or multiple displays of different sizes.
- the touch screen can also serve as a display panel of the output unit 201 at the same time.
- the touch screen detects a touch or proximity gesture operation thereon, it is transmitted to the processor unit 203 to determine the type of the touch event, and then the processor unit 203 provides a corresponding visual output on the display panel according to the type of the touch event.
- the input unit 205 and the output unit 201 are two independent components to implement the input and output functions of the terminal device, in some embodiments, the touch device may be integrated with the display panel to implement the terminal device. Input and output functions.
- the image output unit 2011 can display various graphical user interfaces (English full name: Graphical User Interface, English abbreviated as GUI) as virtual control components, including but not limited to windows, scroll axes, icons, and scrapbooks. For users to operate by touch.
- GUI Graphical User Interface
- the image output unit 2011 includes a filter and an amplifier for filtering and amplifying the video output by the processor unit 203.
- the sound output unit 2012 includes a digital-to-analog converter for converting the audio signal output by the processor unit 203 from a digital format to an analog format.
- the processor unit 203 is configured to run a corresponding code to process the received information to generate and output a corresponding interface.
- the processor unit 203 is a control center of the terminal device, and connects various parts of the entire terminal device by using various interfaces and lines, by running or executing software programs and/or modules stored in the storage unit, and calling the storage. Data within the storage unit to perform various functions of the terminal device and/or process data.
- the processor unit 203 may be composed of an integrated circuit (English name: Integrated Circuit, English abbreviation: IC), for example, may be composed of a single packaged IC, or may be connected to a plurality of package ICs having the same function or different functions. composition.
- the processor unit 203 may include only a central processing unit (English name: Central Processing Unit, English abbreviation: CPU), or may be a graphics processor (English name: Graphics Processing Unit, English abbreviation: GPU).
- CPU Central Processing Unit
- GPU Graphics Processing Unit
- DSP Digital Signal Processor
- the CPU may be a single operation core, and may also include a multi-operation core.
- the storage unit 204 is configured to store code and data, and the code is run by the processor unit 203.
- the storage unit 204 can be used to store software programs and modules, and the processor unit 203 executes various functional applications of the terminal device and implements data processing by running software programs and modules stored in the storage unit 204.
- the storage unit 204 mainly includes a program storage area and a data storage area, wherein the program storage area can store an operating system, an application required for at least one function, such as a sound playing program, an image playing program, and the like; and the data storage area can be stored according to the terminal. Data created by the use of the device (such as audio data, phone book, etc.).
- the storage unit 204 may include a volatile memory, such as non-volatile dynamic random access memory (Nonvolatile Random Access Memory, NVRAM for short), phase change random access memory (English full name) :Phase Change RAM (PRAM), magnetoresistive random access memory (English full name: Magetoresistive RAM, English abbreviation MRAM), etc., may also include non-volatile memory, such as at least one disk storage device, electronically erasable Programmable read-only memory (English full name: Electrically Erasable Programmable Read-Only Memory, EEPROM for short), flash memory devices, such as reverse or flash memory (English full name: NOR flash memory) or reverse flash memory (English full name: NAND flash memory) .
- non-volatile dynamic random access memory Nonvolatile Random Access Memory
- PRAM Phase Change RAM
- MRAM Magnetoresistive random access memory
- EEPROM electrically Erasable Programmable Read-Only Memory
- flash memory devices such as reverse or flash memory (English full name: NOR flash
- the nonvolatile memory stores an operating system and applications executed by the processor unit 203.
- the processor unit 203 loads the running program and data from the non-volatile memory into the memory and stores the digital content in a plurality of storage devices.
- the operating system includes various components and/or drivers for controlling and managing conventional system tasks such as memory management, storage device control, power management, and the like, as well as facilitating communication between various hardware and software.
- the operating system may be an Android system of Google, an iOS system developed by Apple, a Windows operating system developed by Microsoft, or an embedded operating system such as Vxworks.
- the application includes any application installed on the terminal device, including but not limited to browsers, emails, instant messaging services, word processing, keyboard virtualization, widgets, encryption, digital rights management, voice recognition, Voice copying, positioning (such as those provided by GPS), music playback, and more.
- the input unit 205 is configured to implement interaction between the user and the terminal device and/or input information into the terminal device.
- the input unit 205 can receive numeric or character information input by a user to generate a signal input related to user settings or function control.
- the input unit 205 may be a touch screen, or may be other human-computer interaction interfaces, such as physical input keys, microphones, etc., and may also be other external information capture devices, such as cameras.
- the touch screen shown in the embodiment of the present application can collect an operation action touched or approached by the user.
- the user uses an action of any suitable object or accessory such as a finger, a stylus, or the like on the touch screen or near the touch screen, and drives the corresponding connecting device according to a preset program.
- the touch screen may include two parts: a touch detection device and a touch controller. Wherein the touch detection device detects a touch operation of the user, converts the detected touch operation into an electrical signal, and transmits the electrical signal to the touch controller; the touch controller receives the electrical signal from the touch detection device, and It is converted into contact coordinates and sent to the processor unit 203.
- the touch controller can also receive commands from the processor unit 203 and execute them.
- the touch screen can implement touch screens by using various types such as resistive, capacitive, infrared, and surface acoustic waves.
- the physical input keys used by the input unit 205 may include, but are not limited to, a physical keyboard, function keys (such as a volume control button, a switch button, etc.), a trackball, a mouse, a joystick, and the like.
- a physical keyboard such as a keyboard, function keys (such as a volume control button, a switch button, etc.), a trackball, a mouse, a joystick, and the like.
- function keys such as a volume control button, a switch button, etc.
- the input unit 205 in the form of a microphone can collect the voice input by the user or the environment and convert it into a command executable by the processor unit 203 in the form of an electrical signal.
- the input unit 205 may also be various types of sensor components, such as Hall devices, for detecting physical quantities of the terminal device, such as force, moment, pressure, stress, position, displacement, Speed, acceleration, angle, angular velocity, number of revolutions, speed, and time when the operating state changes, etc., are converted into electricity for detection and control.
- sensor components may also include gravity sensors, three-axis accelerometers, gyroscopes, electronic compasses, ambient light sensors, proximity sensors, temperature sensors, humidity sensors, pressure sensors, heart rate sensors, fingerprint readers, and the like.
- the communication unit 207 is configured to establish a communication channel, enable the terminal device to connect to the remote server through the communication channel, and download media data from the remote server.
- the communication unit 207 may include a wireless local area network (English name: Wireless Local Area Network, English short: wireless LAN) module, a Bluetooth module, a baseband module, and the like, and a radio frequency corresponding to the communication module (English name: Radio Frequency, English abbreviation: RF) circuit for wireless local area network communication, Bluetooth communication, infrared communication and/or cellular communication system communication, such as broadband code division multiple access (English full name: Wideband Code Division Multiple Access, English abbreviation: W -CDMA) and / or high-speed downlink packet access (English full name: High Speed Downlink Packet Access, English abbreviation HSDPA).
- the communication module is used to control communication of components in the terminal device and can support direct memory access.
- various communication modules in the communication unit 207 generally appear in the form of an integrated circuit chip (English name: Integrated Circuit Chip), and can be selectively combined without including all communication modules. And the corresponding antenna group.
- the communication unit 207 may include only a baseband chip, a radio frequency chip, and a corresponding antenna to provide communication functions in one cellular communication system.
- the wireless communication connection established by the communication unit 207 such as wireless local area network access or WCDMA access, may be connected to a cellular network (English name: Cellular Network) or the Internet.
- a communication module, such as a baseband module, in the communication unit 207 can be integrated into the processor unit 203, typically an APQ+MDM series platform such as that provided by Qualcomm.
- the radio frequency circuit 208 is configured to receive and transmit signals during information transmission and reception or during a call. For example, after the downlink information of the base station is received, it is processed by the processor unit 203; in addition, the data for designing the uplink is transmitted to the base station.
- the radio frequency circuit 208 includes well-known circuits for performing these functions, including but not limited to antenna systems, radio frequency transceivers, one or more amplifiers, tuners, one or more oscillators, digital signal processors, A Codec chipset, a Subscriber Identity Module (SIM) card, a memory, and the like.
- radio frequency circuitry 208 can also communicate with the network and other devices via wireless communication.
- the wireless communication may use any communication standard or protocol, including but not limited to a global mobile communication system (English full name: Global System of Mobile communication, English abbreviation: GSM), general packet radio service (English full name: General Packet Radio Service, English abbreviation: GPRS), code division multiple access (English full name: Code Division Multiple Access, English abbreviation: CDMA), wideband code division multiple access (English full name: Wideband Code Division Multiple Access, English abbreviation: WCDMA), high-speed uplink chain Road packet access technology (English full name: High Speed Uplink Packet Access, English abbreviation: HSUPA), long-term evolution (English full name: Long Term Evolution, English abbreviation: LTE), e-mail, short message service (English full name: Short Messaging Service , English abbreviation: SMS) and so on.
- GSM Global System of Mobile communication
- GPRS General Packet Radio Service
- CDMA Code Division Multiple Access
- WCDMA Wideband Code Division Multiple Access
- HSUPA High Speed Up
- a power source 209 is used to power different components of the terminal device to maintain its operation.
- the power source 209 can be a built-in battery, such as a conventional lithium ion battery, a nickel metal hydride battery, etc., and also includes an external power source that directly supplies power to the terminal device, such as an AC adapter.
- the power supply 209 may also be more widely defined, and may further include, for example, a power management system, a charging system, a power failure detection circuit, a power converter or an inverter, and a power status indicator. (such as light-emitting diodes), and any other components associated with the power generation, management, and distribution of the terminal equipment.
- the processor unit 203 and the storage unit 204 are connected by the bus system;
- the one or more programs are stored in the storage unit 204, the one or more programs including instructions that, when executed by the terminal device, cause the terminal device to perform the embodiment as shown in this embodiment Data response method.
- FIG. 3 is a schematic structural diagram of a server provided by an embodiment of the present application.
- the server 300 may generate a large difference due to different configurations or performances, and may include one or more central processing units (CPUs) 322 (for example, One or more processors and memory 332, one or more storage media 330 storing application 342 or data 344 (eg, one or one storage device in Shanghai).
- the memory 332 and the storage medium 330 may be short-term storage or persistent storage.
- the program stored on storage medium 330 may include one or more modules (not shown), each of which may include a series of instruction operations in the server.
- the central processor 322 can be configured to communicate with the storage medium 330 to perform a series of instruction operations in the storage medium 330 on the server 300.
- Server 300 may also include one or more power sources 326, one or more wired or wireless network interfaces 350, one or more input and output interfaces 358, and/or one or more operating systems 341, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM and more.
- the central processing unit 322 and the memory 332 shown in this embodiment are connected by the bus system;
- the one or more programs are stored in the memory 332, the one or more programs including instructions that, when executed by the server, cause the server to perform the data response shown in this embodiment method.
- the embodiment further provides a computer readable storage medium storing one or more programs, the computer readable storage medium comprising one or more programs, wherein the one or more programs include instructions, the instructions
- the server is caused to execute the data response method shown in this embodiment when executed by the server.
- Step 401 The terminal device determines whether an access operation is received, and if yes, step 402 is performed.
- the terminal device shown in this embodiment determines whether the front end interface of the terminal device receives the access operation.
- the terminal device shown in this embodiment may be configured with a protected front end interface.
- the protected front end interface shown in this embodiment is an interface for verifying data, even if the protected front end interface is stolen. , the attacker will not get the interface of the user's private data.
- the type of the front end interface shown in this embodiment may be a global wide area network web front end, a mobile phone software APP, a personal computer PC client, or the like.
- This embodiment does not limit the specific type of the front-end interface, as long as the front-end interface can detect whether the user inputs an access operation.
- Step 402 The terminal device generates request information.
- This embodiment does not limit the specific type of the request information and the specific content included, as long as the request information can request the encrypted information from the server.
- Step 403 The terminal device sends the request information to the server.
- the server shown in this embodiment can send the encrypted information to the terminal device after receiving the request information, and the specific sending process is shown in the following steps.
- Step 404 The server configures at least one honeypot.
- the server shown in this embodiment may configure at least one honeypot.
- the server shown in this embodiment is configured with at least one honeypot on the server based on honeypot technology.
- the honeypot technology shown in this embodiment is a behavior and technical details of analyzing the attacker or malicious code by masquerading as a service with a value and a defect to attract an attacker or malicious code to invade. Take defense.
- the honeypot is a security resource set by the network administrator on the server, the value of the honeypot is detected, attacked and damaged, thereby collecting evidence while hiding the real server address, and the honeypot may have The ability to detect attacks, the ability to generate warnings, the ability to record, the ability to deceive, and the ability to assist in investigations.
- honeypots make little contribution to protection, that is, honeypots do not shut out those who try to attack, but because the original intention of honeypot design is compromise, it will not reject intruders in the system.
- the honeypot is intended to be broken into the system for various records and analysis.
- the protective function of the honeypot is weak, it has a strong detection function. For many organizations, it is very difficult to detect suspicious behavior from a large number of system logs.
- IDS intrusion detection systems
- false alarms and false negatives in IDS have caused system administrators to deal with various warnings and false positives.
- honeypots don't have any effective behavior, in principle, any connection to a honeypot should be a type of listening, scanning, or attacking, which can greatly reduce the false positive rate and false negative rate, thus simplifying The process of detection. If the system in the server has been compromised, the system in which the accident occurred cannot be operated offline. In this case, all product services provided by the system will be stopped, and the system administrator cannot perform proper identification and Analysis, while honeypots can respond to intrusions, it provides a system with low data pollution and a sacrificial system that can work offline at any time. At this point, the system administrator will be able to analyze the offline system and apply the results and experience of the analysis to future systems.
- the most important function of the honeypot is to monitor and record all operations and behaviors in the server, so that the attacker does not know that all of his behavior is already under the supervision of the server after entering the server system.
- honeypot The following describes the type of honeypot:
- Honeypots are divided into product type honeypots and research honeypots.
- product type honeypots are generally used in the network of commercial organizations. Its purpose is to reduce the threat of attacks that organizations will be exposed to, and honeypots strengthen security measures for protected organizations. The job they do is to detect and deal with malicious attackers.
- honeypots are specifically designed to study and acquire attack information. This type of honeypot does not enhance the safety of a particular organization. On the contrary, honeypots need to expose research organizations to various types of cyber threats and find ways to deal with them better. The work they do is to collect Information about malicious attackers. It is generally used in military, security research organizations.
- the honeypot According to the interaction between the honeypot and the attacker, it can be divided into three categories: low-interaction honeypot, medium-interaction honeypot and high-interaction honeypot;
- honeypots the biggest feature of low-interaction honeypots is simulation. All the vulnerability and attack objects that honeypots show to attackers are not real product systems, but simulations of various systems and the services they provide. Because its services are simulated behaviors, honeypots have very limited information and can only respond to attackers simply. It is the safest type of honeypot.
- the interactive honeypot is a simulation of the various behaviors of a real operating system. It provides more interactive information and can also get more information from the attacker's behavior. In this simulated behavioral system, the honeypot can look no different from a real operating system. They are the target of a real system that is also plausible.
- the high-interaction honeypot has a real operating system. Its advantage lies in providing the real system to the attacker. When the attacker gains the ROOT permission, he is confused by the system and the authenticity of the data. His more activities and behaviors will be record it. The disadvantage is that the possibility of being invaded is very high. If the entire high-interaction honeypot is invaded, it will become a springboard for the attacker's next attack.
- the embodiment does not limit the number of the honeypots and the types of the honeypots.
- Step 405 The server determines a target honeypot.
- the server determines one of the honeypots as the target honeypot in at least one of the honeypots.
- the server may randomly determine one of the honeypots as the target honeypot in at least one of the honeypots.
- the server may determine the target honeypot in at least one of the honeypots according to a service type.
- the server shown in this embodiment is capable of acquiring an application service to be simulated, that is, the server uses an application service to set up a honeypot.
- the server may create a honeypot using a user identity authenticated service to enable the created honeypot to authenticate the user.
- the server can create a honeypot using the service of the online banking transaction to enable the created honeypot to be engaged in online banking transactions.
- the honeypot created by the server opens a known controllable security vulnerability of at least one application service, that is, the server can control a security vulnerability opened by the created honeypot, thereby enabling The attacker can attack the honeypot.
- the server shown in this embodiment may acquire the type of service required by the terminal device, and the application service that the server determines in the at least one of the honeypots that the target honeypot can provide The type matches the type of service required by the terminal device.
- Step 406 The server acquires honeypot characters belonging to the target honeypot.
- the server in the process of creating the honeypot, may be provided with a honeypot character in the honeypot.
- This embodiment does not limit the type and length of the honeypot character.
- the honeypot character is any one of the following or a combination of at least two:
- the honeypot character shown in this embodiment may be 02X, and may also be acdt or the like, which is not limited in this embodiment.
- the server in the process of configuring the honeypot, may be configured with different honeypot characters in different honeypots.
- the server may be configured with different honeypot characters in at least two different honeypots during the configuration of the honeypot.
- Step 407 The server generates encrypted information.
- the server shown in this embodiment performs encryption calculation on the honeypot characters belonging to the target honeypot to generate the encrypted information.
- Data encryption standard DES Data encryption standard DES, DES-based symmetric algorithm 3DES, digital signature algorithm DSA, RSA encryption algorithm, advanced encryption standard AES, etc.
- the description of the encryption algorithm in this embodiment is an optional example, which is not limited, as long as the server can encrypt the honeypot characters belonging to the target honeypot based on the encryption algorithm.
- the calculation is performed to generate the encrypted information, and the encrypted information can be decrypted.
- Step 408 The server sends the encrypted information to the terminal device.
- the encrypted information may be sent to the terminal device.
- step 403 and step 408 are performed as an example.
- the server first receives the request information sent by the terminal device, and then configures the request according to the request information.
- the description of the encrypted information is exemplified.
- the server may pre-configure the encrypted information, and after the server receives the request information sent by the terminal device, the configured encrypted information may be sent. To the terminal device.
- Step 409 The terminal device acquires a honeypot character included in the encrypted information.
- the terminal device may acquire the encrypted information sent by the server.
- the terminal device may perform decryption calculation on the encrypted information to obtain the honeypot character included in the encrypted information.
- the terminal device may perform decryption calculation on the encrypted information based on a decryption algorithm to obtain the honeypot character included in the encrypted information.
- the decryption algorithm is not limited in this embodiment, as long as the encrypted information can be decrypted and calculated.
- the decryption algorithm may be pre-defined between the server and the terminal device in this embodiment, so that the terminal device can perform decryption calculation on the encrypted information based on the agreed decryption algorithm.
- the terminal device may pre-store a correspondence relationship list, where the correspondence relationship list includes a correspondence between different decryption algorithms and different identifiers, and the server may send the target identifier to the terminal device.
- the terminal device may determine a target decryption algorithm corresponding to the target identifier according to the correspondence relationship list, and the terminal device may perform decryption calculation on the encrypted information based on the target decryption algorithm.
- the terminal device may analyze the encrypted information to obtain a decryption algorithm capable of performing decryption calculation on the encrypted information.
- Step 410 The terminal device sends the honeypot character, the encrypted information, and user data to the server.
- the front end of the terminal device can collect user data, and the user data is not limited in this embodiment.
- the user data may be data related to an access operation of the user accessing the front end interface.
- the user data may be related data that is generated by the front-end interface in response to the access operation, and, for example, the user data may be data that the user fills in according to requirements.
- the honeypot character shown in this embodiment is the honeypot character obtained by the terminal device decrypting the encrypted information to obtain the honeypot character, that is, the honeypot character is included in the encrypted information.
- the terminal device shown in this embodiment can send the acquired encrypted information, the honeypot character, and the user data to the server.
- Step 411 The server acquires a honeypot character included in the encrypted information.
- the server shown in this embodiment may perform decryption calculation on the encrypted information to obtain the honeypot character included in the encrypted information.
- the server shown in this embodiment may perform decryption calculation on the encrypted information based on a decryption algorithm to obtain the honeypot character included in the encrypted information.
- the decryption algorithm is not limited, as long as the server can perform decryption calculation on the encrypted information based on the decryption algorithm to obtain the honeypot character included in the encrypted information.
- the decryption algorithm shown in this embodiment may be a decryption algorithm pre-agreed by the server and the terminal device.
- Step 412 The server determines whether the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information. If yes, step 413 is performed, and if no, step 414 is performed.
- the server shown in this embodiment may determine whether the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information.
- the server sends the encrypted information to the terminal device to verify whether the terminal device tampers with the data, and if the terminal device tampers with the data, the terminal is caused to be The honeypot character sent by the device does not match the honeypot character included in the encrypted information;
- the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information.
- Step 413 The server responds to the user data.
- the server determines that the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information, that is, the terminal device does not tamper with the data, the server is The user data can be responsive.
- the server may respond to the user data, that is, determine whether the user name and password included in the user data are stored in the On the server, if so, the server can allow the user to log in to the personal computer PC client.
- Step 414 The server does not respond to the user data.
- the server determines that the honeypot character sent by the terminal device is different from the honeypot character included in the encrypted information, that is, the terminal device tampers with the data, so that the If the honeypot field has changed, the server does not respond to the user data.
- the encrypted information has a non-tamperable characteristic, it is verified whether the honeypot field sent by the terminal device is consistent with the honeypot field included in the encrypted information by using the encrypted information.
- the method shown in this embodiment can save the storage space of the server, thereby improving the server, in the process of determining whether the terminal device tampers with the data, and does not need to occupy a large storage space of the server.
- the operation efficiency, and the method shown in this embodiment is simple in operation, effectively improving the efficiency of the method shown in this embodiment, and the method shown in this embodiment can sense the tampering operation of the data of the terminal device before causing the loss. Therefore, countermeasures can be taken in advance, thereby effectively avoiding the leakage of user privacy data, realizing active defense against the integrity of the front-end data of the terminal device, and effectively ensuring the security of the communication system and avoiding the loss of the communication system.
- Step 501 The terminal device determines whether an access operation is received, and if yes, step 502 is performed.
- Step 502 The terminal device generates request information.
- Step 503 The terminal device sends the request information to the server.
- Step 504 The server configures at least one honeypot.
- the server shown in this embodiment may configure at least one honeypot.
- the server shown in this embodiment is configured with at least one honeypot on the server based on honeypot technology.
- honeypot technology and the honeypot type, please refer to the above embodiment, which is not described in detail in this embodiment.
- the server is provided with a preset field in the configured honeypot.
- the preset field shown in this embodiment may be a token, a key, a client type, or the like.
- the description of the preset field in this embodiment is an optional example, and is not limited, as long as the preset field can be performed. Assignment can be.
- Step 505 The server determines a target honeypot.
- step 505 shown in this embodiment please refer to step 405 shown in FIG. 4, and the specific implementation process is not described in this embodiment.
- Step 506 The server assigns the preset field included in the target honeypot to generate the honeypot character.
- the specific process of the server shown in this embodiment for acquiring the honeypot character belonging to the target honeypot may be:
- the server may assign the preset field included in the target honeypot to generate the honeypot character.
- the server shown in this embodiment may dynamically assign the preset field included in the target honeypot to generate the honeypot character.
- the server shown in this embodiment may perform random assignment on the preset field included in the target honeypot.
- the server may assign a certain value to a preset field located in the target honeypot, so that the assignment of the preset field may be completed.
- the specific value and the length of the value given to the preset field in this embodiment are not limited in this embodiment, as long as the value can be assigned to the preset field located in the target honeypot.
- Step 507 The server generates encrypted information.
- Step 508 The server sends the encrypted information to the terminal device.
- Step 509 The terminal device acquires a honeypot character included in the encrypted information.
- Step 510 The terminal device sends the honeypot character, the encrypted information, and user data to the server.
- Step 511 The server acquires a honeypot character included in the encrypted information.
- Step 512 The server determines whether the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information. If yes, step 513 is performed, and if no, step 514 is performed.
- the server shown in this embodiment may determine whether the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information.
- the server shown in this embodiment may determine whether the value of the honeypot character sent by the terminal device is equal to the value of the honeypot character included in the encrypted information.
- the server sends the encrypted information to the terminal device to verify whether the terminal device tampers with the data. If the terminal device tampers with the data, the terminal device sends the honey.
- the can character is not equal to the honeypot character included in the encrypted information;
- the honeypot character sent by the terminal device is equal to the honeypot character included in the encrypted information.
- Step 513 The server responds to the user data.
- the server determines that the honeypot character sent by the terminal device is equal to the honeypot character included in the encrypted information, that is, the terminal device does not tamper with the data, the server is The user data can be responsive.
- the server may respond to the user data, that is, determine whether the user name and password included in the user data are stored in the On the server, if so, the server can allow the user to log in to the personal computer PC client.
- Step 514 The server does not respond to the user data.
- the server determines that the honeypot character sent by the terminal device is not equal to the honeypot character included in the encrypted information, that is, the terminal device tampers with the data, so that the If the honeypot field has changed, the server does not respond to the user data.
- the encrypted information has a non-tamperable characteristic, it is verified whether the honeypot field sent by the terminal device is consistent with the honeypot field included in the encrypted information by using the encrypted information.
- the method shown in this embodiment can save the storage space of the server, thereby improving the server, in the process of determining whether the terminal device tampers with the data, and does not need to occupy a large storage space of the server.
- the operation efficiency, and the method shown in this embodiment is simple in operation, effectively improving the efficiency of the method shown in this embodiment, and the method shown in this embodiment can sense the tampering operation of the data of the terminal device before causing the loss. Therefore, countermeasures can be taken in advance, thereby effectively avoiding the leakage of user privacy data, realizing active defense against the integrity of the front-end data of the terminal device, and effectively ensuring the security of the communication system and avoiding the loss of the communication system.
- the preset field in the target honeypot can be dynamically assigned to generate the honeypot character by using the method shown in this embodiment. It can be seen that the honeypot character can be dynamically adjusted and improved in this embodiment.
- the foregoing embodiment describes the specific architecture of the server from the perspective of physical hardware.
- the specific structure of the server is described in detail from the perspective of the functional module as shown in FIG. 6 :
- the server includes:
- the first receiving unit 603 is configured to receive honeypot characters, encryption information, and user data sent by the terminal device, where the encrypted information is information sent to the terminal device;
- the calculating unit 604 is configured to perform decryption calculation on the encrypted information to obtain the honeypot character included in the encrypted information;
- the determining unit 605 is configured to determine whether the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information;
- the first determining unit 606 is configured to respond to the user data if it is determined that the honeypot character sent by the terminal device is the same as the honeypot character included in the encrypted information.
- the server may further include:
- the second determining unit 607 is configured to: if it is determined that the honeypot character sent by the terminal device is different from the honeypot character included in the encrypted information, does not respond to the user data.
- the second receiving unit 601 is configured to receive request information sent by the terminal device, where the request information is used to request the encrypted information from the server.
- the configuration unit 608 is configured to configure at least one honeypot, and the honeypot includes a preset field.
- the third determining unit 609 is configured to determine, in the at least one of the honeypots, one of the honeypots as the target honeypot.
- the obtaining unit 610 is configured to acquire a honeypot character belonging to the target honeypot, and the target honeypot is a honeypot in the pre-configured at least one honeypot.
- the obtaining unit 610 is specifically configured to assign the preset field included in the target honeypot to generate a honeypot character.
- the encryption unit 611 is configured to perform encryption calculation on the honeypot character to generate encrypted information.
- the sending unit 602 is configured to send the encrypted information to the terminal device according to the request information.
- the foregoing embodiment describes the specific architecture of the terminal device from the perspective of the physical hardware.
- the specific structure of the terminal device is described in detail from the perspective of the functional module in conjunction with FIG. 7 :
- the terminal device includes:
- the obtaining unit 704 is configured to obtain the encrypted information sent by the server.
- the calculating unit 705 is configured to perform decryption calculation on the encrypted information to obtain a honeypot character included in the encrypted information;
- a first sending unit 706, configured to send the honeypot character, the encrypted information, and user data to the server, so that if the server determines the honeypot character and the location sent by the terminal device And the honeypot character included in the encrypted information is the same, and responding to the user data, so that if the server determines the honeypot character sent by the terminal device and the honeypot included in the encrypted information If the characters are not the same, the user data is not responded.
- the terminal device may further include:
- the determining unit 701 is configured to determine whether an access operation is received
- the generating unit 702 is configured to: if it is determined that the access operation is received, generate the request information;
- the second sending unit 703 is configured to send the request information to the server, so that the server sends the encrypted information to the terminal device.
- the disclosed system, apparatus, and method may be implemented in other manners.
- the device embodiments described above are merely illustrative.
- the division of the unit is only a logical function division.
- there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
- the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
- the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
- each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
- the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
- the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
- a computer readable storage medium A number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present application.
- the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Bioethics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Virology (AREA)
- Medical Informatics (AREA)
- Databases & Information Systems (AREA)
- Automation & Control Theory (AREA)
- Information Transfer Between Computers (AREA)
- Telephonic Communication Services (AREA)
Abstract
本申请实施例公开了一种数据响应方法、终端设备以及服务器。本申请实施例方法包括:服务器接收终端设备发送的蜜罐字符、加密信息以及用户数据,服务器对加密信息进行解密计算以获取加密信息所包括的蜜罐字符,若服务器判断出终端设备发送的蜜罐字符与加密信息所包括的蜜罐字符相同,则服务器响应用户数据。可见,在判断终端设备是否对数据进行篡改的过程中,无需占用服务器较大的存储空间,从而提升了服务器的运行效率,且本实施例所示的方法能够在造成损失之前感知终端设备的数据的篡改操作,从而可以提前采取应对措施,从而有效的避免了用户隐私数据的泄漏。
Description
本申请要求于2017年6月9日提交中国专利局、申请号为201710433020.1、发明名称为“一种数据响应方法、终端设备以及服务器”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及计算机安全领域,尤其涉及的是数据响应。
随着互联网与移动通讯技术的飞速发展,终端设备所能够实现的功能越来越多样化。
为了保障终端设备上所存储的数据的安全,在相关技术所提供的方法中,服务器可生成多组密钥,所述服务器可将所述终端设备的用户数据经已生成的多组密钥中的一个密钥加密生成密文数据,并将所述密文数据保存于所述终端设备中。
但是,相关技术所提供的方案中,服务器需要对多组密钥进行复杂的管理,所述服务器后台在对多组密钥进行存储时占用了服务器的存储空间,降低了服务器的运行效率。而且一旦破解了服务器所存储的多组密钥,则因服务器无法感知到密钥被破解,从而使得攻击方能够随意且长期的对终端设备的数据进行篡改。
发明内容
本申请实施例提供了一种能够提前获取到终端设备的数据被篡改的数据响应方法、终端设备以及服务器。
本申请实施例第一方面提供了一种数据响应方法,包括:
接收终端设备发送的蜜罐字符、加密信息以及用户数据,所述加密信息为发送给所述终端设备的信息;
对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;
判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是 否相同;
若判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据。
本申请实施例第二方面提供了一种数据响应方法,包括:
服务器接收终端设备发送的蜜罐字符、加密信息以及用户数据,所述加密信息为所述服务器发送给所述终端设备的信息;
所述服务器对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;
所述服务器判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同;
若所述服务器判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则所述服务器响应所述用户数据。
本申请实施例第三方面提供了一种数据响应方法,包括:
获取服务器发送的加密信息;
对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;
将所述蜜罐字符、所述加密信息以及用户数据发送给所述服务器,以使若所述服务器在确定出终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据,若所述服务器判断出所述终端设备发送的所述蜜罐字符与所述加密信息所包括的所述蜜罐字符不相同,则不响应所述用户数据。
本申请实施例第四方面提供了一种数据响应方法,包括:
终端设备获取服务器发送的加密信息;
所述终端设备对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;
所述终端设备将所述蜜罐字符、所述加密信息以及用户数据发送给所述服务器,以使若所述服务器在确定出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据,若所述服务器判断出所述终端设备发送的所述蜜罐字符与所述加密信息所包括的所述蜜罐字符不相同,则不响应所述用户数据。
本申请实施例第五方面提供了一种服务器,包括:
第一接收单元,用于接收终端设备发送的蜜罐字符、加密信息以及用户数据,所述加密信息为发送给所述终端设备的信息;
计算单元,用于对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;
判断单元,用于判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同;
第一确定单元,用于若判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据。
本申请实施例第六方面提供了一种终端设备,包括:
获取单元,用于获取服务器发送的加密信息;
计算单元,用于对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;
第一发送单元,用于将所述蜜罐字符、所述加密信息以及用户数据发送给所述服务器,以使若所述服务器在确定出终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据,若所述服务器判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符不相同,则不响应所述用户数据。
本申请实施例第七方面提供了一种服务器,包括:
一个或多个中央处理器、存储器、总线系统、以及一个或多个程序,所述中央处理器和所述存储器通过所述总线系统相连;
其中所述一个或多个程序被存储在所述存储器中,所述一个或多个程序包括指令,所述指令当被所述服务器执行时使所述服务器执行如本申请实施例第一方面所示的方法。
本申请实施例第八方面提供了一种存储一个或多个程序的计算机可读存储介质,包括一个或多个程序,所述一个或多个程序包括指令,所述指令当被服务器执行时使所述服务器执行如本申请实施例第一方面所示的方法。
本申请实施例第九方面提供了一种终端设备,包括:
一个或多个处理器单元、存储单元、总线系统、以及一个或多个程序,所 述处理器单元和所述存储单元通过所述总线系统相连;
其中所述一个或多个程序被存储在所述存储单元中,所述一个或多个程序包括指令,所述指令当被所述终端设备执行时使所述终端设备执行如本申请实施例第三方面所示的方法。
本申请实施例第十方面提供了一种存储一个或多个程序的计算机可读存储介质,包括一个或多个程序,所述一个或多个程序包括指令,所述指令当被终端设备执行时使所述终端设备执行如本申请实施例第三方面所示的方法。
采用本实施例所示的所述数据响应方法、终端设备以及服务器,因加密信息具有不可篡改的特性,则通过加密信息校验所述终端设备发送的蜜罐字段与所述加密信息所包括的蜜罐字段是否一致,以判断出所述终端设备是否对数据进行篡改的过程中,无需占用所述服务器较大的存储空间,能够节省所述服务器的存储空间,从而提升了所述服务器的运行效率,而且本实施例所示的方法操作简单,有效的提升了本实施例所示的方法的效率,且本实施例所示的方法能够在造成损失之前感知终端设备的数据的篡改操作,从而可以提前采取应对措施,从而有效的避免了用户隐私数据的泄漏,能够对终端设备前端数据的完整性实现主动防御,且有效的保障了通信系统的安全,避免通信系统的损失。
图1为本申请实施例所提供的通信系统的一种实施例架构示意图;
图2为本申请实施例所提供的终端设备的一种实施例架构示意图;
图3为本申请实施例所提供的服务器的一种实施例架构示意图;
图4为本申请实施例所提供的数据响应方法的一种实施例步骤流程图;
图5为本申请实施例所提供的数据响应方法的另一种实施例步骤流程图;
图6为本申请实施例所提供的服务器的另一种实施例架构示意图;
图7为本申请实施例所提供的终端设备的另一种实施例架构示意图。
本申请实施例提供了一种数据响应方法,本实施例所示的所述数据响应方法应用于通信系统,为更好的理解本申请实施例所示的所述数据响应方法,以 下结合图1所示对所述通信系统进行详细说明:
图1为本申请实施例中通信系统的架构示意图。该通信系统包括服务器100和至少一台终端设备110。
所述服务器100与所述终端设备110能够进行数据交互,从而实现本实施例所示的数据响应方法。
以下结合图2所示对所述通信系统所包括的终端设备的具体结构进行说明,图2为本申请实施例所提供的终端设备的一种实施例结构示意图。
所述终端设备包括输入单元205、处理器单元203、输出单元201、通信单元207、存储单元204、射频电路208等组件。
这些组件通过一条或多条总线进行通信。本领域技术人员可以理解,图2中示出的终端设备的结构并不构成对本申请实施例的限定,它既可以是总线形结构,也可以是星型结构,还可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。
在本申请实施方式中,所述终端设备可以是任何移动或便携式电子设备,包括但不限于智能手机、移动电脑、平板电脑、个人数字助理(英文全称:Personal Digital Assistant,英文简称:PDA)、媒体播放器、智能电视等。
所述终端设备包括:
输出单元201,用于输出待显示的图像。
具体的,所述输出单元201包括但不限于影像输出单元2011和声音输出单元2012。
所述影像输出单元2011用于输出文字、图片和/或视频。所述影像输出单元2011可包括显示面板,例如采用液晶显示器(英文全称:Liquid Crystal Display,英文简称:LCD)、有机发光二极管(英文全称:Organic Light-Emitting Diode,英文简称:OLED)、场发射显示器(英文全称:field emission display,英文简称FED)等形式来配置的显示面板。或者所述影像输出单元2011可以包括反射式显示器,例如电泳式(electrophoretic)显示器,或利用光干涉调变技术(英文全称:Interferometric Modulation of Light)的显示器。
所述影像输出单元2011可以包括单个显示器或不同尺寸的多个显示器。在本申请的具体实施方式中,触摸屏亦可同时作为输出单元201的显示面板。
例如,当触摸屏检测到在其上的触摸或接近的手势操作后,传送给处理器单元203以确定触摸事件的类型,随后处理器单元203根据触摸事件的类型在显示面板上提供相应的视觉输出。虽然在图2中,输入单元205与输出单元201是作为两个独立的部件来实现终端设备的输入和输出功能,但是在某些实施例中,可以将触摸屏与显示面板集成一体而实现终端设备的输入和输出功能。例如,所述影像输出单元2011可以显示各种图形化用户接口(英文全称:Graphical User Interface,英文简称GUI)以作为虚拟控制组件,包括但不限于窗口、卷动轴、图标及剪贴簿,以供用户通过触控方式进行操作。
在本申请具体实施方式中,所述影像输出单元2011包括滤波器及放大器,用来将处理器单元203所输出的视频滤波及放大。声音输出单元2012包括数字模拟转换器,用来将处理器单元203所输出的音频信号从数字格式转换为模拟格式。
处理器单元203,用于运行相应的代码,对接收信息进行处理,以生成并输出相应的界面。
具体的,所述处理器单元203为终端设备的控制中心,利用各种接口和线路连接整个终端设备的各个部分,通过运行或执行存储在存储单元内的软件程序和/或模块,以及调用存储在存储单元内的数据,以执行终端设备的各种功能和/或处理数据。所述处理器单元203可以由集成电路(英文全称:Integrated Circuit,英文简称:IC)组成,例如可以由单颗封装的IC所组成,也可以由连接多颗相同功能或不同功能的封装IC而组成。
举例来说,所述处理器单元203可以仅包括中央处理器(英文全称:Central Processing Unit,英文简称:CPU),也可以是图形处理器(英文全称:Graphics Processing Unit,英文简称:GPU),数字信号处理器(英文全称:Digital Signal Processor,英文简称:DSP)、及通信单元中的控制芯片(例如基带芯片)的组合。在本申请实施方式中,CPU可以是单运算核心,也可以包括多运算核心。
存储单元204,用于存储代码和数据,代码供处理器单元203运行。
具体的,存储单元204可用于存储软件程序以及模块,处理器单元203通过运行存储在存储单元204的软件程序以及模块,从而执行终端设备的各种 功能应用以及实现数据处理。存储单元204主要包括程序存储区和数据存储区,其中,程序存储区可存储操作系统、至少一个功能所需的应用程序,比如声音播放程序、图像播放程序等等;数据存储区可存储根据终端设备的使用所创建的数据(比如音频数据、电话本等)等。
在本申请具体实施方式中,存储单元204可以包括易失性存储器,例如非挥发性动态随机存取内存(英文全称:Nonvolatile Random Access Memory,英文简称NVRAM)、相变化随机存取内存(英文全称:Phase Change RAM,英文简称PRAM)、磁阻式随机存取内存(英文全称:Magetoresistive RAM,英文简称MRAM)等,还可以包括非易失性存储器,例如至少一个磁盘存储器件、电子可擦除可编程只读存储器(英文全称:Electrically Erasable Programmable Read-Only Memory,英文简称EEPROM)、闪存器件,例如反或闪存(英文全称:NOR flash memory)或是反及闪存(英文全称:NAND flash memory)。
非易失存储器储存处理器单元203所执行的操作系统及应用程序。所述处理器单元203从所述非易失存储器加载运行程序与数据到内存并将数字内容储存于大量储存装置中。所述操作系统包括用于控制和管理常规系统任务,例如内存管理、存储设备控制、电源管理等,以及有助于各种软硬件之间通信的各种组件和/或驱动器。
在本申请实施方式中,所述操作系统可以是Google公司的Android系统、Apple公司开发的iOS系统或Microsoft公司开发的Windows操作系统等,或者是Vxworks这类的嵌入式操作系统。
所述应用程序包括安装在终端设备上的任何应用,包括但不限于浏览器、电子邮件、即时消息服务、文字处理、键盘虚拟、窗口小部件(Widget)、加密、数字版权管理、语音识别、语音复制、定位(例如由全球定位系统提供的功能)、音乐播放等等。
输入单元205,用于实现用户与终端设备的交互和/或信息输入到终端设备中。
例如,所述输入单元205可以接收用户输入的数字或字符信息,以产生与用户设置或功能控制有关的信号输入。在本申请具体实施方式中,输入单元 205可以是触摸屏,也可以是其他人机交互界面,例如实体输入键、麦克风等,还可是其他外部信息撷取装置,例如摄像头等。
本申请实施例所示的触摸屏,可收集用户在其上触摸或接近的操作动作。比如用户使用手指、触笔等任何适合的物体或附件在触摸屏上或接近触摸屏的位置的操作动作,并根据预先设定的程式驱动相应的连接装置。可选的,触摸屏可包括触摸检测装置和触摸控制器两个部分。其中,触摸检测装置检测用户的触摸操作,并将检测到的触摸操作转换为电信号,以及将所述电信号传送给触摸控制器;触摸控制器从触摸检测装置上接收所述电信号,并将它转换成触点坐标,再送给所述处理器单元203。
所述触摸控制器还可以接收处理器单元203发来的命令并执行。此外,所述触摸屏可以采用电阻式、电容式、红外线以及表面声波等多种类型实现触摸屏。
在本申请的其他实施方式中,所述输入单元205所采用的实体输入键可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆等中的一种或多种。麦克风形式的输入单元205可以收集用户或环境输入的语音并将其转换成电信号形式的、处理器单元203可执行的命令。
在本申请的其他一些实施方式中,所述输入单元205还可以是各类传感器件,例如霍尔器件,用于侦测终端设备的物理量,例如力、力矩、压力、应力、位置、位移、速度、加速度、角度、角速度、转数、转速以及工作状态发生变化的时间等,转变成电量来进行检测和控制。其他的一些传感器件还可以包括重力感应计、三轴加速计、陀螺仪、电子罗盘、环境光传感器、接近传感器、温度传感器、湿度传感器、压力传感器、心率传感器、指纹识别器等。
通信单元207,用于建立通信信道,使终端设备通过所述通信信道以连接至远程服务器,并从所述远程服务器下媒体数据。所述通信单元207可以包括无线局域网(英文全称:Wireless Local Area Network,英文简称:wireless LAN)模块、蓝牙模块、基带模块等通信模块,以及所述通信模块对应的射频(英文全称:Radio Frequency,英文简称:RF)电路,用于进行无线局域网络通信、蓝牙通信、红外线通信及/或蜂窝式通信系统通信,例如宽带码分多重接入(英文全称:Wideband Code Division Multiple Access,英文简称:W-CDMA)及/ 或高速下行封包存取(英文全称:High Speed Downlink Packet Access,英文简称HSDPA)。所述通信模块用于控制终端设备中的各组件的通信,并且可以支持直接内存存取。
在本申请的不同实施方式中,所述通信单元207中的各种通信模块一般以集成电路芯片(英文全称:Integrated Circuit Chip)的形式出现,并可进行选择性组合,而不必包括所有通信模块及对应的天线组。例如,所述通信单元207可以仅包括基带芯片、射频芯片以及相应的天线以在一个蜂窝通信系统中提供通信功能。经由所述通信单元207建立的无线通信连接,例如无线局域网接入或WCDMA接入,所述终端设备可以连接至蜂窝网(英文全称:Cellular Network)或因特网。在本申请的一些可选实施方式中,所述通信单元207中的通信模块,例如基带模块可以集成到处理器单元203中,典型的如高通(Qualcomm)公司提供的APQ+MDM系列平台。
射频电路208,用于信息收发或通话过程中接收和发送信号。例如,将基站的下行信息接收后,给处理器单元203处理;另外,将设计上行的数据发送给基站。通常,所述射频电路208包括用于执行这些功能的公知电路,包括但不限于天线系统、射频收发机、一个或多个放大器、调谐器、一个或多个振荡器、数字信号处理器、编解码(Codec)芯片组、用户身份模块(SIM)卡、存储器等等。此外,射频电路208还可以通过无线通信与网络和其他设备通信。
所述无线通信可以使用任一通信标准或协议,包括但不限于全球移动通讯系统(英文全称:Global System of Mobile communication,英文简称:GSM)、通用分组无线服务(英文全称:General Packet Radio Service,英文简称:GPRS)、码分多址(英文全称:Code Division Multiple Access,英文简称:CDMA)、宽带码分多址(英文全称:Wideband Code Division Multiple Access,英文简称:WCDMA)、高速上行行链路分组接入技术(英文全称:High Speed Uplink Packet Access,英文简称:HSUPA)、长期演进(英文全称:Long Term Evolution,英文简称:LTE)、电子邮件、短消息服务(英文全称:Short Messaging Service,英文简称:SMS)等。
电源209,用于给终端设备的不同部件进行供电以维持其运行。作为一般性理解,所述电源209可以是内置的电池,例如常见的锂离子电池、镍氢电池 等,也包括直接向终端设备供电的外接电源,例如AC适配器等。在本申请的一些实施方式中,所述电源209还可以作更为广泛的定义,例如还可以包括电源管理系统、充电系统、电源故障检测电路、电源转换器或逆变器、电源状态指示器(如发光二极管),以及与终端设备的电能生成、管理及分布相关联的其他任何组件。
所述处理器单元203和所述存储单元204通过所述总线系统相连;
其中所述一个或多个程序被存储在所述存储单元204中,所述一个或多个程序包括指令,所述指令当被所述终端设备执行时使所述终端设备执行本实施例所示的数据响应方法。
以下结合图3所示对所述通信系统所包括的服务器的具体结构进行说明:
图3是本申请实施例提供的一种服务器结构示意图,该服务器300可因配置或性能不同而产生比较大的差异,可以包括一个或一个以上中央处理器(central processing units,CPU)322(例如,一个或一个以上处理器)和存储器332,一个或一个以上存储应用程序342或数据344的存储介质330(例如一个或一个以上海量存储设备)。其中,存储器332和存储介质330可以是短暂存储或持久存储。存储在存储介质330的程序可以包括一个或一个以上模块(图示没标出),每个模块可以包括对服务器中的一系列指令操作。更进一步地,中央处理器322可以设置为与存储介质330通信,在服务器300上执行存储介质330中的一系列指令操作。
服务器300还可以包括一个或一个以上电源326,一个或一个以上有线或无线网络接口350,一个或一个以上输入输出接口358,和/或,一个或一个以上操作系统341,例如Windows ServerTM,Mac OS XTM,UnixTM,LinuxTM,FreeBSDTM等等。
本实施例所示的所述中央处理器322和所述存储器332通过所述总线系统相连;
其中所述一个或多个程序被存储在所述存储器332中,所述一个或多个程序包括指令,所述指令当被所述服务器执行时使所述服务器执行本实施例所示的数据响应方法。
本实施例还提供了一种存储一个或多个程序的计算机可读存储介质,所述 计算机可读存储介质包括一个或多个程序,其中,所述一个或多个程序包括指令,所述指令当被服务器执行时使所述服务器执行本实施例所示的数据响应方法。
以下结合图4所示对本实施例所提供的数据响应方法的具体执行过程进行详细说明:
步骤401、所述终端设备判断是否接收到访问操作,若是,则执行步骤402。
具体的,本实施例所示的所述终端设备判断所述终端设备的前端界面是否接收到所述访问操作。
其中,本实施例所示的所述终端设备可设置有被保护的前端界面,本实施例所示的被保护的前端界面为用于对数据进行验证的界面,即便被保护的前端界面被窃取,则攻击者也不会获取到用户的隐私数据的界面。
可选的,本实施例所示的所述前端界面的类型可为全球广域网web前端,手机软件APP,个人计算机PC客户端等。
本实施例对所述前端界面的具体类型不做限定,只要所述前端界面能够检测用户是否输入访问操作即可。
步骤402、所述终端设备生成请求信息。
本实施例对所述请求信息的具体类型以及所包括的具体内容不做限定,只要所述请求信息能够向所述服务器请求加密信息即可。
步骤403、所述终端设备将所述请求信息发送给所述服务器。
本实施例所示的服务器在接收到所述请求信息后即可将所述加密信息发送给所述终端设备,具体发送过程请详见下述步骤所示。
步骤404、所述服务器配置至少一个蜜罐。
本实施例所示的所述服务器在接收到所述请求信息后,即可配置至少一个所述蜜罐。
具体的,本实施例所示的所述服务器基于蜜罐技术在所述服务器上配置有至少一个蜜罐。
本实施例所示的所述蜜罐技术是一种通过伪装成有利用价值并带有缺陷的服务,吸引攻击者或恶意代码入侵,从而分析该攻击者或恶意代码的行为动机和技术细节以进行防御。
其中,蜜罐是网络管理员在服务器上设下的安全资源,所述蜜罐的价值在于被探测、攻击和损害,借此收集证据,同时隐藏真实的服务器地址,且所述蜜罐可具有发现攻击的能力、产生警告的能力、强大的记录能力、欺骗的能力、协助调查的能力。
以下对蜜罐的优势进行说明:
虽然蜜罐在防护中所做的贡献很少,即蜜罐不会将那些试图攻击的入侵者拒之门外,但因为蜜罐设计的初衷就是妥协,所以它不会将入侵者拒绝在系统之外,实际上,蜜罐是希望有人闯入系统,从而进行各项记录和分析工作。虽然蜜罐的防护功能很弱,但是它却具有很强的检测功能,对于许多组织而言,想要从大量的系统日志中检测出可疑的行为是非常困难的。虽然,有入侵检测系统(IDS)的存在,但是,IDS发生的误报和漏报,让系统管理员疲于处理各种警告和误报。而蜜罐的作用体现在误报率远远低于大部分IDS工具,也务须当心特征数据库的更新和检测引擎的修改。因为蜜罐没有任何有效行为,从原理上来讲,任何连接到蜜罐的连接都应该是侦听、扫描或者攻击的一种,这样就可以极大的减低误报率和漏报率,从而简化检测的过程。如果服务器内的系统已经被入侵的话,那些发生事故的系统不能进行脱机工作,这样的话,将导致系统所提供的所有产品服务都将被停止,同时,系统管理员也不能进行合适的鉴定和分析,而蜜罐可以对入侵进行响应,它提供了一个具有低数据污染的系统和牺牲系统可以随时进行脱机工作。此时,系统管理员将可以对脱机的系统进行分析,并且把分析的结果和经验运用于以后的系统中。
具体的来讲,蜜罐最为重要的功能是对服务器中所有操作和行为进行监视和记录,使得攻击者在进入到服务器系统后仍不知道自己所有的行为已经处于服务器的监视下。
以下对蜜罐的类型进行说明:
蜜罐分为产品型蜜罐和研究型蜜罐两类。
其中,产品型蜜罐一般运用于商业组织的网络中。它的目的是减轻组织将受到的攻击的威胁,蜜罐加强了受保护组织的安全措施。他们所做的工作就是检测并且对付恶意的攻击者。
而研究型蜜罐专门以研究和获取攻击信息为目的而设计。这类蜜罐并没有 增强特定组织的安全性,恰恰相反,蜜罐要做的是让研究组织面对各类网络威胁,并寻找能够对付这些威胁更好的方式,它们所要进行的工作就是收集恶意攻击者的信息。它一般运用于军队,安全研究组织。
根据蜜罐与攻击者之间进行的交互,可以分为3类:低交互蜜罐,中交互蜜罐和高交互蜜罐;
其中,低交互蜜罐最大的特点是模拟。蜜罐为攻击者展示的所有攻击弱点和攻击对象都不是真正的产品系统,而是对各种系统及其提供的服务的模拟。由于它的服务都是模拟的行为,所以蜜罐可以获得的信息非常有限,只能对攻击者进行简单的应答,它是最安全的蜜罐类型。
中交互蜜罐是对真正的操作系统的各种行为的模拟,它提供了更多的交互信息,同时也可以从攻击者的行为中获得更多的信息。在这个模拟行为的系统中,蜜罐可以看起来和一个真正的操作系统没有区别。它们是真正系统还要诱人的攻击目标。
高交互蜜罐具有一个真实的操作系统,它的优点体现在对攻击者提供真实的系统,当攻击者获得ROOT权限后,受系统,数据真实性的迷惑,他的更多活动和行为将被记录下来。缺点是被入侵的可能性很高,如果整个高交互蜜罐被入侵,那么它就会成为攻击者下一步攻击的跳板。
具体的,本实施例对所述蜜罐的数目以及各蜜罐的类型不做限定。
步骤405、所述服务器确定目标蜜罐。
具体的,所述服务器在至少一个所述蜜罐中确定一个所述蜜罐为所述目标蜜罐。
可选的,所述服务器可在至少一个所述蜜罐中随机确定一个所述蜜罐为所述目标蜜罐。
还可选的,所述服务器可根据服务类型在至少一个所述蜜罐中确定所述目标蜜罐。
具体的,本实施例所示的所述服务器能够获取所要模拟的应用服务,即所述服务器用应用服务来搭建蜜罐。
例如,所述服务器可利用用户身份认证的服务创建蜜罐,以使已创建的蜜罐能够进行用户身份认证。
又如,所述服务器可利用网银交易的服务创建蜜罐,以使已创建的蜜罐能够进行网银交易。
本实施例中,所述服务器所创建的所述蜜罐开放至少一个应用服务的已知可控制的安全漏洞,即所述服务器对已创建的蜜罐所开放的安全漏洞能够进行控制,从而使得攻击者能够攻击蜜罐。
本实施例所示的所述服务器可获取所述终端设备所需要的服务的类型,所述服务器在所述至少一个所述蜜罐中所确定出的所述目标蜜罐所能够提供的应用服务的类型与所述终端设备所需要的服务的类型相匹配。
步骤406、所述服务器获取属于目标蜜罐的蜜罐字符。
本实施例中,所述服务器在创建所述蜜罐的过程中,可在所述蜜罐中设置有蜜罐字符。
本实施例对所述蜜罐字符的类型和长度不做限定。
例如,所述蜜罐字符为以下所示的任一种或至少两种的组合:
字母、数字、字和符号。
本实施例所示的所述蜜罐字符可为02X,还可为acdt等,具体在本实施例中不做限定。
可选的,本实施例中,所述服务器在配置所述蜜罐的过程中,可在不同的所述蜜罐中设置有不同的所述蜜罐字符。
还可选的,所述服务器在配置所述蜜罐的过程中,可在至少两个不同的所述蜜罐中设置有不同的所述蜜罐字符。
步骤407、所述服务器生成加密信息。
具体的,本实施例所示的所述服务器对属于所述目标蜜罐的所述蜜罐字符进行加密计算以生成所述加密信息。
其中,本实施例所示的所述加密算法可为如下所示的任一种
数据加密标准DES、基于DES的对称算法3DES、数字签名算法DSA、RSA加密算法、高级加密标准AES等。
需明确的是,本实施例对所述加密算法的说明为可选的示例,不做限定,只要所述服务器能够基于所述加密算法对属于所述目标蜜罐的所述蜜罐字符进行加密计算以生成所述加密信息,且所述加密信息能够进行解密即可。
步骤408、所述服务器将所述加密信息发送给终端设备。
本实施例中,所述服务器在生成所述加密信息后,即可将所述加密信息发送给所述终端设备。
需明确的是,本实施例以先执行步骤403后执行步骤404至步骤408为例进行示例性说明,即所述服务器先接收所述终端设备发送的请求信息,再根据所述请求信息配置所述加密信息为例进行示例性说明。
在其他实施例中,也可所述服务器预先配置好所述加密信息,则在所述服务器接收到所述终端设备发送的所述请求信息后,即可将已配置完成的所述加密信息发送给所述终端设备。
步骤409、所述终端设备获取所述加密信息所包括的蜜罐字符。
具体的,所述终端设备可获取服务器发送的所述加密信息。
所述加密信息的具体说明请详见上述实施例所示,具体在本实施例中不做赘述。
所述终端设备可对所述加密信息进行解密计算以获取所述加密信息所包括的所述蜜罐字符。
其中,所述终端设备可基于解密算法对所述加密信息进行解密计算以获取到所述加密信息所包括的所述蜜罐字符。
本实施例对所述解密算法不做限定,只要能够对所述加密信息进行解密计算即可。
可选的,本实施例所述服务器和所述终端设备之间可预先对所述解密算法进行约定,从而使得所述终端设备能够基于已约定的解密算法对所述加密信息进行解密计算。
还可选的,所述终端设备可预先存储有对应关系列表,所述对应关系列表包括了不同的解密算法与不同的标识的对应关系,所述服务器可将目标标识发送给所述终端设备,所述终端设备根据所述对应关系列表即可确定出与所述目标标识对应的目标解密算法,所述终端设备即可基于所述目标解密算法对所述加密信息进行解密计算。
还可选的,所述终端设备可对所述加密信息进行分析,从而获取到能够对所述加密信息进行解密计算的解密算法。
步骤410、所述终端设备将所述蜜罐字符、所述加密信息以及用户数据发送给所述服务器。
本实施例中,所述终端设备的前端可对用户数据进行采集,本实施例对所述用户数据不做限定,例如,所述用户数据可为与用户访问前端界面的访问操作相关的数据,又如,所述用户数据可为所述前端界面可为对所述访问操作进行响应以生成的相关数据,又如,所述用户数据可为用户根据需要所填写的数据等。
本实施例所示的所述蜜罐字符为所述终端设备对所述加密信息进行解密计算以获取到的所述蜜罐字符,即所述蜜罐字符包括于所述加密信息。
可见,本实施例所示的所述终端设备可将已获取到的所述加密信息、所述蜜罐字符以及所述用户数据发送给所述服务器。
步骤411、所述服务器获取所述加密信息所包括的蜜罐字符。
具体的,本实施例所示的所述服务器可所述加密信息进行解密计算以获取所述加密信息所包括的所述蜜罐字符。
更具体的,本实施例所示的所述服务器可基于解密算法对所述加密信息进行解密计算以获取所述加密信息所包括的所述蜜罐字符。
本实施例对所述解密算法不做限定,只要所述服务器基于所述解密算法能够对所述加密信息进行解密计算以获取到所述加密信息所包括的所述蜜罐字符即可。
可选的,本实施例所示的所述解密算法可为所述服务器和所述终端设备预先约定的解密算法。
步骤412、所述服务器判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同,若是,则执行步骤413,若否,则执行步骤414。
具体的,本实施例所示的所述服务器可判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同。
更具体的,本实施例中,所述服务器通过向所述终端设备发送所述加密信息以验证终端设备是否对数据进行了篡改,若所述终端设备对数据进行了篡改,则使得所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是不相符的;
若所述终端设备对数据没有进行篡改,则使得所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是相同的。
步骤413、所述服务器响应所述用户数据。
本实施例中,若所述服务器判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,即说明所述终端设备对数据没有进行篡改,则所述服务器即可对所述用户数据进行响应。
例如,若所述用户数据包括用户需要登录个人计算机PC客户端的用户名和密码,则所述服务器即可对所述用户数据进行响应,即判断用户数据所包括的用户名和密码是否已存储在所述服务器上,若是,则所述服务器即可允许用户登录个人计算机PC客户端。
本实施例对所述服务器响应所述用户数据的具体方式的说明为可选的示例不做限定。
步骤414、所述服务器不响应所述用户数据。
本实施例中,若所述服务器判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符不相同,即说明所述终端设备对数据进行了篡改,则使得所述蜜罐字段发生了改变,则所述服务器不对所述用户数据进行响应。
可见,采用本实施例所示的方法,因所述加密信息具有不可篡改的特性,则通过加密信息校验所述终端设备发送的蜜罐字段与所述加密信息所包括的蜜罐字段是否一致,以判断出所述终端设备是否对数据进行篡改的过程中,无需占用所述服务器较大的存储空间,本实施例所示的方法能够节省所述服务器的存储空间,从而提升了所述服务器的运行效率,而且本实施例所示的方法操作简单,有效的提升了本实施例所示的方法的效率,且本实施例所示的方法能够在造成损失之前感知终端设备的数据的篡改操作,从而可以提前采取应对措施,从而有效的避免了用户隐私数据的泄漏,能够对终端设备前端数据的完整性实现主动防御,且有效的保障了通信系统的安全,避免通信系统的损失。
以下结合图5所示对本实施例所示的数据响应方法的另一种实施例进行详细说明:
步骤501、所述终端设备判断是否接收到访问操作,若是,则执行步骤502。
步骤502、所述终端设备生成请求信息。
步骤503、所述终端设备将所述请求信息发送给所述服务器。
本实施例所示的步骤501至步骤502的具体执行过程,请详见上述实施例所示的步骤401至步骤402所示,具体在本实施例中不做赘述。
步骤504、所述服务器配置至少一个蜜罐。
本实施例所示的所述服务器在接收到所述请求信息后,即可配置至少一个所述蜜罐。
具体的,本实施例所示的所述服务器基于蜜罐技术在所述服务器上配置有至少一个蜜罐。
所述蜜罐技术以及蜜罐类型的具体说明请详见上述实施例所示,具体在本实施例中不做赘述。
本实施例中,所述服务器在已配置的所述蜜罐中设置有预设字段。
本实施例所示的所述预设字段可为token,key,clienttype等,本实施例对所述预设字段的说明为可选的示例,不做限定,只要能够对所述预设字段进行赋值即可。
步骤505、所述服务器确定目标蜜罐。
本实施例所示的步骤505的具体执行过程,请详见图4所示的步骤405,具体执行过程在本实施例中不做赘述。
步骤506、所述服务器对所述目标蜜罐所包括的所述预设字段进行赋值以生成所述蜜罐字符。
具体的,本实施例所示的所述服务器获取属于目标蜜罐的蜜罐字符的具体过程可为:
所述服务器可对所述目标蜜罐所包括的所述预设字段进行赋值以生成所述蜜罐字符。
具体的,本实施例所示的所述服务器可对所述目标蜜罐所包括的所述预设字段进行动态赋值以生成所述蜜罐字符。
可选的,本实施例所示的所述服务器可对所述目标蜜罐所包括的所述预设字段进行随机的赋值。
本实施例中,所述服务器可将某一数值赋予给位于所述目标蜜罐中的预设 字段,从而可完成对所述预设字段的赋值。
本实施例对赋予给所述预设字段的具体数值以及数值长度在本实施例中不做限定,只要能够将数值赋予给位于所述目标蜜罐中的预设字段即可。
步骤507、所述服务器生成加密信息。
步骤508、所述服务器将所述加密信息发送给终端设备。
步骤509、所述终端设备获取所述加密信息所包括的蜜罐字符。
步骤510、所述终端设备将所述蜜罐字符、所述加密信息以及用户数据发送给所述服务器。
步骤511、所述服务器获取所述加密信息所包括的蜜罐字符。
本实施例所示的步骤507至步骤511的具体执行过程,请详见图4所示的步骤407至步骤411的具体执行过程,具体在本实施例中不做限定。
步骤512、所述服务器判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同,若是,则执行步骤513,若否,则执行步骤514。
具体的,本实施例所示的所述服务器可判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同。
更具体的,本实施例所示的所述服务器可判断所述终端设备所发送的蜜罐字符的数值与所述加密信息所包括的蜜罐字符的数值是否相等。
本实施例中,所述服务器通过向所述终端设备发送所述加密信息以验证终端设备是否对数据进行了篡改,若所述终端设备对数据进行了篡改,则使得所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是不相等的;
若所述终端设备对数据没有进行篡改,则使得所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是相等的。
步骤513、所述服务器响应所述用户数据。
本实施例中,若所述服务器判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相等,即说明所述终端设备对数据没有进行篡改,则所述服务器即可对所述用户数据进行响应。
例如,若所述用户数据包括用户需要登录个人计算机PC客户端的用户名和密码,则所述服务器即可对所述用户数据进行响应,即判断用户数据所包括的用户名和密码是否已存储在所述服务器上,若是,则所述服务器即可允许用 户登录个人计算机PC客户端。
本实施例对所述服务器响应所述用户数据的具体方式的说明为可选的示例不做限定。
步骤514、所述服务器不响应所述用户数据。
本实施例中,若所述服务器判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符不相等,即说明所述终端设备对数据进行了篡改,则使得所述蜜罐字段发生了改变,则所述服务器不对所述用户数据进行响应。
可见,采用本实施例所示的方法,因所述加密信息具有不可篡改的特性,则通过加密信息校验所述终端设备发送的蜜罐字段与所述加密信息所包括的蜜罐字段是否一致,以判断出所述终端设备是否对数据进行篡改的过程中,无需占用所述服务器较大的存储空间,本实施例所示的方法能够节省所述服务器的存储空间,从而提升了所述服务器的运行效率,而且本实施例所示的方法操作简单,有效的提升了本实施例所示的方法的效率,且本实施例所示的方法能够在造成损失之前感知终端设备的数据的篡改操作,从而可以提前采取应对措施,从而有效的避免了用户隐私数据的泄漏,能够对终端设备前端数据的完整性实现主动防御,且有效的保障了通信系统的安全,避免通信系统的损失。
而且,采用本实施例所示的方法能够对位于所述目标蜜罐中的预设字段进行动态赋值以生成所述蜜罐字符,可见,本实施例能够对蜜罐字符进行动态调整,提升了服务器对终端设备是否对数据进行篡改的感知能力。
上述实施例从实体硬件的角度对所述服务器的具体架构进行了说明,以下结合图6所示从功能模块的角度对所述服务器的具体结构进行详细说明:
所述服务器包括:
第一接收单元603,用于接收终端设备发送的蜜罐字符、加密信息以及用户数据,所述加密信息为发送给所述终端设备的信息;
计算单元604,用于对所述加密信息进行解密计算以获取所述加密信息所包括的所述蜜罐字符;
判断单元605,用于判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同;
第一确定单元606,用于若判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据。
在一些可能的实现方式中,所述服务器还可以包括:
第二确定单元607,用于若判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符不相同,则不响应所述用户数据。
第二接收单元601,用于接收所述终端设备发送的请求信息,所述请求信息用于向所述服务器请求所述加密信息。
配置单元608,用于配置至少一个所述蜜罐,所述蜜罐中包括有预设字段。
第三确定单元609,用于在至少一个所述蜜罐中确定一个所述蜜罐为所述目标蜜罐。
获取单元610,用于获取属于目标蜜罐的蜜罐字符,所述目标蜜罐为预先配置的至少一个蜜罐中的一个蜜罐。
获取单元610,可以具体用于对所述目标蜜罐所包括的所述预设字段进行赋值以生成蜜罐字符。
加密单元611,用于对所述蜜罐字符进行加密计算以生成加密信息。
发送单元602,用于根据所述请求信息将所述加密信息发送给所述终端设备。
本实施例所示的所述服务器执行所述数据响应方法的具体执行过程,请详见上述实施例所示,具体在本实施例中不做赘述。
上述实施例从实体硬件的角度对所述终端设备的具体架构进行了说明,以下结合图7所示从功能模块的角度对所述终端设备的具体结构进行详细说明:
所述终端设备包括:
获取单元704,用于获取服务器发送的加密信息;
计算单元705,用于对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;
第一发送单元706,用于将所述蜜罐字符、所述加密信息以及用户数据发送给所述服务器,以使若所述服务器在确定出所述终端设备发送的所述蜜罐字符与所述加密信息所包括的所述蜜罐字符相同,则响应所述用户数据,使得若 所述服务器判断出所述终端设备发送的所述蜜罐字符与所述加密信息所包括的所述蜜罐字符不相同,则不响应所述用户数据。
在一些可能的实现方式中,所述终端设备还可以包括:
判断单元701,用于判断是否接收到访问操作;
生成单元702,用于若判断出接收到所述访问操作,则所述生成请求信息;
第二发送单元703,用于将所述请求信息发送给所述服务器,以使所述服务器将所述加密信息发送给所述终端设备。
本实施例所示的所述终端设备执行所述数据响应方法的具体执行过程,请详见上述实施例所示,具体在本实施例中不做赘述。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统,装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申 请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,以上实施例仅用以说明本申请实施例的技术方案,而非对其限制;尽管参照前述实施例对本申请实施例进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本申请各实施例技术方案的精神和范围。
Claims (25)
- 一种数据响应方法,包括:接收终端设备发送的蜜罐字符、加密信息以及用户数据,所述加密信息为发送给所述终端设备的信息;对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同;若判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据。
- 根据权利要求1所述的方法,所述判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同之后,所述方法还包括:若判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符不相同,则不响应所述用户数据。
- 根据权利要求1或2所述的方法,所述接收终端设备发送的蜜罐字符、加密信息以及用户数据之前,所述方法还包括:接收所述终端设备发送的请求信息,所述请求信息用于所述终端设备向服务器请求加密信息;根据所述请求信息将所述加密信息发送给所述终端设备。
- 根据权利要求1至3任一项所述的方法,所述接收终端设备发送的蜜罐字符、加密信息以及用户数据之前,所述方法还包括:获取属于目标蜜罐的蜜罐字符,所述目标蜜罐为预先配置的至少一个蜜罐中的一个蜜罐;对所述蜜罐字符进行加密计算以生成加密信息。
- 根据权利要求4所述的方法,所述接收终端设备发送的蜜罐字符、加密信息以及用户数据之前,所述方法还包括:配置至少一个所述蜜罐,所述蜜罐中包括有预设字段;在至少一个所述蜜罐中确定一个所述蜜罐为所述目标蜜罐;所述获取属于目标蜜罐的蜜罐字符,包括:对所述目标蜜罐所包括的所述预设字段进行赋值以生成蜜罐字符。
- 一种数据响应方法,包括:服务器接收终端设备发送的蜜罐字符、加密信息以及用户数据,所述加密信息为所述服务器发送给所述终端设备的信息;所述服务器对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;所述服务器判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同;若所述服务器判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则所述服务器响应所述用户数据。
- 根据权利要求6所述的方法,所述服务器判断所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符是否相同之后,所述方法还包括:若所述服务器判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符不相同,则所述服务器不响应所述用户数据。
- 根据权利要求6或7所述的方法,所述服务器接收终端设备发送的蜜罐字符、加密信息以及用户数据之前,所述方法还包括:所述服务器接收所述终端设备发送的请求信息,所述请求信息用于所述终端设备向所述服务器请求加密信息;所述服务器根据所述请求信息将所述加密信息发送给所述终端设备。
- 根据权利要求6至8任一项所述的方法,所述服务器接收终端设备发送的蜜罐字符、加密信息以及用户数据之前,所述方法还包括:所述服务器获取属于目标蜜罐的蜜罐字符,所述目标蜜罐为所述服务器预先配置的至少一个蜜罐中的一个蜜罐;所述服务器对所述蜜罐字符进行加密计算以生成加密信息。
- 根据权利要求9所述的方法,所述服务器接收终端设备发送的蜜罐字符、加密信息以及用户数据之前,所述方法还包括:所述服务器配置至少一个所述蜜罐,所述蜜罐中包括有预设字段;所述服务器在至少一个所述蜜罐中确定一个所述蜜罐为所述目标蜜罐;所述服务器获取属于目标蜜罐的蜜罐字符,包括:所述服务器对所述目标蜜罐所包括的所述预设字段进行赋值以生成蜜罐 字符。
- 一种数据响应方法,包括:获取服务器发送的加密信息;对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;将所述蜜罐字符、所述加密信息以及用户数据发送给所述服务器,以使若所述服务器在确定出终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据,若所述服务器判断出所述终端设备发送的所述蜜罐字符与所述加密信息所包括的所述蜜罐字符不相同,则不响应所述用户数据。
- 根据权利要求11所述的方法,所述获取服务器发送的加密信息之前,所述方法还包括:判断是否接收到访问操作;若判断出接收到所述访问操作,则生成请求信息;将所述请求信息发送给所述服务器,以使所述服务器发送加密信息。
- 一种数据响应方法,包括:终端设备获取服务器发送的加密信息;所述终端设备对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;所述终端设备将所述蜜罐字符、所述加密信息以及用户数据发送给所述服务器,以使若所述服务器在确定出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据,若所述服务器判断出所述终端设备发送的所述蜜罐字符与所述加密信息所包括的所述蜜罐字符不相同,则不响应所述用户数据。
- 根据权利要求13所述的方法,所述终端设备获取服务器发送的加密信息之前,所述方法还包括:所述终端设备判断是否接收到访问操作;若所述终端设备判断出接收到所述访问操作,则所述终端设备生成请求信息;所述终端设备将所述请求信息发送给所述服务器,以使所述服务器将加密 信息发送给所述终端设备。
- 一种服务器,包括:第一接收单元,用于接收终端设备发送的蜜罐字符、加密信息以及用户数据,所述加密信息为发送给所述终端设备的信息;计算单元,用于对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;判断单元,用于判断所述终端设备发送的所述蜜罐字符与加密信息所包括的蜜罐字符是否相同;第一确定单元,用于若判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据。
- 根据权利要求15所述的服务器,所述服务器还包括:第二确定单元,用于若判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符不相同,则不响应所述用户数据。
- 根据权利要求15或16所述的服务器,所述服务器还包括:第二接收单元,用于接收所述终端设备发送的请求信息,所述请求信息用于所述终端设备向服务器请求所述加密信息;发送单元,用于根据所述请求信息将所述加密信息发送给所述终端设备。
- 根据权利要求15至17任一项所述的服务器,所述服务器还包括:获取单元,用于获取属于目标蜜罐的蜜罐字符,所述目标蜜罐为预先配置的至少一个蜜罐中的一个蜜罐;加密单元,用于对所述蜜罐字符进行加密计算以生成加密信息。
- 根据权利要求18所述的服务器,所述服务器还包括:配置单元,用于配置至少一个所述蜜罐,所述蜜罐中包括有预设字段;第三确定单元,用于在至少一个所述蜜罐中确定一个所述蜜罐为所述目标蜜罐;所述获取单元,具体用于对所述目标蜜罐所包括的所述预设字段进行赋值以生成蜜罐字符。
- 一种终端设备,包括:获取单元,用于获取服务器发送的加密信息;计算单元,用于对所述加密信息进行解密计算以获取所述加密信息所包括的蜜罐字符;第一发送单元,用于将所述蜜罐字符、所述加密信息以及用户数据发送给所述服务器,以使若所述服务器在确定出终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符相同,则响应所述用户数据,若所述服务器判断出所述终端设备发送的蜜罐字符与所述加密信息所包括的蜜罐字符不相同,则不响应所述用户数据。
- 根据权利要求20所述的终端设备,所述终端设备还包括:判断单元,用于判断是否接收到访问操作;生成单元,用于若判断出接收到所述访问操作,则所述生成请求信息;第二发送单元,用于将所述请求信息发送给所述服务器,以使所述服务器发送加密信息。
- 一种服务器,包括:一个或多个中央处理器、存储器、总线系统、以及一个或多个程序,所述中央处理器和所述存储器通过所述总线系统相连;其中所述一个或多个程序被存储在所述存储器中,所述一个或多个程序包括指令,所述指令当被所述服务器执行时使所述服务器执行如权利要求1至5任一项所述的方法。
- 一种存储一个或多个程序的计算机可读存储介质,包括一个或多个程序,所述一个或多个程序包括指令,所述指令当被服务器执行时使所述服务器执行如权利要求1至5任一项所述的方法。
- 一种终端设备,包括:一个或多个处理器单元、存储单元、总线系统、以及一个或多个程序,所述处理器单元和所述存储单元通过所述总线系统相连;其中所述一个或多个程序被存储在所述存储单元中,所述一个或多个程序包括指令,所述指令当被所述终端设备执行时使所述终端设备执行如权利要求11或12所述的方法。
- 一种存储一个或多个程序的计算机可读存储介质,包括一个或多个程序,所述一个或多个程序包括指令,所述指令当被终端设备执行时使所述终端 设备执行如权利要求11或12所述的方法。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/389,414 US11431684B2 (en) | 2017-06-09 | 2019-04-19 | Data response method, terminal device, and server |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201710433020.1 | 2017-06-09 | ||
| CN201710433020.1A CN109033885B (zh) | 2017-06-09 | 2017-06-09 | 一种数据响应方法、终端设备以及服务器 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US16/389,414 Continuation US11431684B2 (en) | 2017-06-09 | 2019-04-19 | Data response method, terminal device, and server |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018223797A1 true WO2018223797A1 (zh) | 2018-12-13 |
Family
ID=64565712
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2018/085923 Ceased WO2018223797A1 (zh) | 2017-06-09 | 2018-05-08 | 数据响应方法、终端设备以及服务器 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US11431684B2 (zh) |
| CN (1) | CN109033885B (zh) |
| WO (1) | WO2018223797A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113473243A (zh) * | 2020-03-31 | 2021-10-01 | 华为技术有限公司 | 数据处理方法及其设备 |
| CN113645242A (zh) * | 2021-08-11 | 2021-11-12 | 杭州安恒信息技术股份有限公司 | 一种蜜罐溯源方法、装置及相关设备 |
Families Citing this family (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP7060800B2 (ja) * | 2018-06-04 | 2022-04-27 | 日本電信電話株式会社 | 感染拡大攻撃検知システム及び方法、並びに、プログラム |
| US11032318B2 (en) * | 2018-08-06 | 2021-06-08 | Juniper Networks, Inc. | Network monitoring based on distribution of false account credentials |
| US11483318B2 (en) * | 2020-01-07 | 2022-10-25 | International Business Machines Corporation | Providing network security through autonomous simulated environments |
| CN111651757B (zh) * | 2020-06-05 | 2024-04-09 | 深圳前海微众银行股份有限公司 | 攻击行为的监测方法、装置、设备及存储介质 |
| CN113079492B (zh) * | 2021-03-22 | 2022-04-05 | 广东湾区智能终端工业设计研究院有限公司 | 一种信息共享的方法及装置 |
| US11924228B2 (en) * | 2021-06-23 | 2024-03-05 | AVAST Software s.r.o. | Messaging server credentials exfiltration based malware threat assessment and mitigation |
| CN114168947B (zh) * | 2021-12-14 | 2022-10-25 | Tcl通讯科技(成都)有限公司 | 一种攻击检测方法、装置、电子设备及存储介质 |
| CN114884730B (zh) * | 2022-05-07 | 2023-12-29 | 深信服科技股份有限公司 | 一种请求检测方法、装置、设备及可读存储介质 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101053198A (zh) * | 2004-09-24 | 2007-10-10 | 同步加株式会社 | 数据通信方法 |
| CN101052056A (zh) * | 2006-04-07 | 2007-10-10 | 华为技术有限公司 | 软交换系统及呼叫业务的鉴权处理方法 |
| CN106341819A (zh) * | 2016-10-10 | 2017-01-18 | 西安瀚炬网络科技有限公司 | 基于蜜罐技术的钓鱼WiFi识别系统与方法 |
| CN106651361A (zh) * | 2016-12-20 | 2017-05-10 | 张涉应 | 一种金融ic卡互联网终端及其交易方法 |
| US20170134405A1 (en) * | 2015-11-09 | 2017-05-11 | Qualcomm Incorporated | Dynamic Honeypot System |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6310873B1 (en) * | 1997-01-09 | 2001-10-30 | International Business Machines Corporation | Internet telephony directory server |
| US20130263226A1 (en) * | 2012-01-22 | 2013-10-03 | Frank W. Sudia | False Banking, Credit Card, and Ecommerce System |
| US9485276B2 (en) * | 2012-09-28 | 2016-11-01 | Juniper Networks, Inc. | Dynamic service handling using a honeypot |
| JP6546100B2 (ja) * | 2014-02-17 | 2019-07-17 | 富士通株式会社 | サービス提供方法、サービス要求方法、情報処理装置、及び、クライアント装置 |
| CN104978519A (zh) * | 2014-10-31 | 2015-10-14 | 哈尔滨安天科技股份有限公司 | 一种应用型蜜罐的实现方法及装置 |
| CN105426433A (zh) | 2015-11-02 | 2016-03-23 | 广州华多网络科技有限公司 | 排行榜数据响应方法、请求方法及排行榜数据展示系统 |
| US10129298B2 (en) * | 2016-06-30 | 2018-11-13 | Microsoft Technology Licensing, Llc | Detecting attacks using compromised credentials via internal network monitoring |
| CN106603541A (zh) * | 2016-12-21 | 2017-04-26 | 哈尔滨安天科技股份有限公司 | 一种基于差异化流量处理机制的蜜网系统 |
| CN106657165B (zh) * | 2017-03-09 | 2020-08-04 | 腾讯科技(深圳)有限公司 | 一种网络攻击的防御方法、服务器及终端 |
| US10607009B2 (en) * | 2017-04-05 | 2020-03-31 | Block Ransomware, Llc | System and method for blocking ransomware infections |
-
2017
- 2017-06-09 CN CN201710433020.1A patent/CN109033885B/zh active Active
-
2018
- 2018-05-08 WO PCT/CN2018/085923 patent/WO2018223797A1/zh not_active Ceased
-
2019
- 2019-04-19 US US16/389,414 patent/US11431684B2/en active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101053198A (zh) * | 2004-09-24 | 2007-10-10 | 同步加株式会社 | 数据通信方法 |
| CN101052056A (zh) * | 2006-04-07 | 2007-10-10 | 华为技术有限公司 | 软交换系统及呼叫业务的鉴权处理方法 |
| US20170134405A1 (en) * | 2015-11-09 | 2017-05-11 | Qualcomm Incorporated | Dynamic Honeypot System |
| CN106341819A (zh) * | 2016-10-10 | 2017-01-18 | 西安瀚炬网络科技有限公司 | 基于蜜罐技术的钓鱼WiFi识别系统与方法 |
| CN106651361A (zh) * | 2016-12-20 | 2017-05-10 | 张涉应 | 一种金融ic卡互联网终端及其交易方法 |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113473243A (zh) * | 2020-03-31 | 2021-10-01 | 华为技术有限公司 | 数据处理方法及其设备 |
| CN113473243B (zh) * | 2020-03-31 | 2022-10-04 | 华为技术有限公司 | 数据处理方法及其设备 |
| CN113645242A (zh) * | 2021-08-11 | 2021-11-12 | 杭州安恒信息技术股份有限公司 | 一种蜜罐溯源方法、装置及相关设备 |
Also Published As
| Publication number | Publication date |
|---|---|
| US11431684B2 (en) | 2022-08-30 |
| CN109033885B (zh) | 2022-11-18 |
| US20190245832A1 (en) | 2019-08-08 |
| CN109033885A (zh) | 2018-12-18 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11431684B2 (en) | Data response method, terminal device, and server | |
| US9672360B2 (en) | Secure computer architectures, systems, and applications | |
| US11500984B2 (en) | Systems and methods for providing configurable responses to threat identification | |
| US11188652B2 (en) | Access management and credential protection | |
| US9807066B2 (en) | Secure data transmission and verification with untrusted computing devices | |
| US9614839B2 (en) | Secure computer architectures, systems, and applications | |
| CN107222485B (zh) | 一种授权方法以及相关设备 | |
| EP3507962B1 (en) | Message protection | |
| US7996682B2 (en) | Secure prompting | |
| CN107451813B (zh) | 支付方法、支付设备和支付服务器 | |
| US20140281501A1 (en) | Application access control method and electronic apparatus implementing the same | |
| US11405367B1 (en) | Secure computer peripheral devices | |
| CN111475832B (zh) | 一种数据管理的方法以及相关装置 | |
| CN107615294A (zh) | 一种验证码短信显示方法及移动终端 | |
| Mohsen et al. | Android keylogging threat | |
| CN112987942B (zh) | 键盘输入信息的方法、装置、系统、电子设备和存储介质 | |
| CN114372801A (zh) | 一种生物特征信息的识别方法以及相关装置 | |
| CN107347059B (zh) | 一种漏洞检测的方法及检测终端 | |
| CN108737341B (zh) | 业务处理方法、终端及服务器 | |
| CN119167354A (zh) | 安全防护方法、装置、电子设备及计算机存储介质 | |
| WO2023138135A1 (zh) | 人机识别的方法和装置 | |
| US20250193236A1 (en) | Phishing protection | |
| Zheng et al. | SwitchMan: An Easy-to-Use Approach to Secure User Input and Output | |
| Hung et al. | Defend a System against Keyloggers with a Privilege-limited Account | |
| HK40025796B (zh) | 一种数据管理的方法以及相关装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18812817 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18812817 Country of ref document: EP Kind code of ref document: A1 |