WO2023273152A1 - 一种检测业务访问请求的方法及装置 - Google Patents
一种检测业务访问请求的方法及装置 Download PDFInfo
- Publication number
- WO2023273152A1 WO2023273152A1 PCT/CN2021/134623 CN2021134623W WO2023273152A1 WO 2023273152 A1 WO2023273152 A1 WO 2023273152A1 CN 2021134623 W CN2021134623 W CN 2021134623W WO 2023273152 A1 WO2023273152 A1 WO 2023273152A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- attack
- service access
- risk
- access request
- device attribute
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
Definitions
- Embodiments of the present invention relate to the field of financial technology (Fintech), and in particular to a method and device for detecting service access requests.
- Fetech financial technology
- the security detection system is mainly used to detect whether the service access request packet contains malicious characters to determine whether the IP has malicious access behavior, so as to determine whether The service access request of the IP is rejected, and the IP is recorded in the IP blacklist or IP whitelist according to the judgment result.
- the security detection system may misjudge normal visitors due to the historical IP blacklist, thus making the Other normal visitors of this temporary IP cannot use this temporary IP for normal access.
- Embodiments of the present invention provide a method and device for detecting service access requests, which are used to solve the problem in the prior art that decisions cannot be made in a timely and accurate manner when blocking IPs in batches.
- an embodiment of the present invention provides a method for detecting a service access request, including:
- attack behavior characteristics Based on the attack behavior characteristics, device attribute risk characteristics, and attack frequency characteristics corresponding to the IP, determine whether to allow the service access request corresponding to the IP.
- the service access request information of the IP accessing the service system within the set window period will be obtained immediately, And perform content detection on the service access request information of the IP within the set window period to determine the attack behavior characteristics corresponding to the IP. Then, according to the address attribute information and device attribute information corresponding to the IP, the risk characteristics of the device attribute corresponding to the IP are determined. Then, based on the attack behavior characteristics, device attribute risk characteristics, and attack frequency characteristics corresponding to the IP, it is determined whether to allow the service access request corresponding to the IP.
- the solution comprehensively evaluates IP from the three characteristic dimensions of attack behavior characteristics, device attribute risk characteristics, and attack frequency characteristics, and can more comprehensively and accurately evaluate the specific risk level corresponding to the IP, so as to realize the analysis of all IPs. Quantitatively describe the corresponding risk level. At the same time, according to the degree of risk, it can be timely and accurately determined whether to allow the service access request corresponding to the IP, so as to ensure the data security of the business system. In addition, since this solution can assess the specific risk level corresponding to the IP, each IP can be divided into a finer granularity based on the specific risk level corresponding to each IP, so that each IP can be displayed more intuitively and clearly , which can facilitate decision makers to make timely and accurate decisions.
- each IP can be displayed more intuitively and accurately, it can avoid the simple and rude ban of a temporary IP in the existing technology, which will cause other normal visitors to be unable to use the temporary IP to perform normal activities. Thereby, user experience can be improved.
- the content detection of the service access request information of the IP within the set window period, and determining the attack behavior characteristics corresponding to the IP include:
- the preset detection rules are used to detect the content of multiple service access request information of the IP within the set window period, and determine whether the service request initiated through the IP carries malicious characters (such as injected cross- The key characters corresponding to the script of the website), so as to determine whether the IP has obvious attack characteristics. Based on this, if the IP has obvious attack characteristics, the IP is marked with the first attack behavior characteristic; if the IP does not have obvious attack characteristics, the IP is marked with the second attack behavior characteristic. In this way, it can provide support for the subsequent timely and accurate assessment of the specific risk level corresponding to the IP.
- the determining the device attribute risk characteristics corresponding to the IP according to the address attribute information and device attribute information corresponding to the IP includes:
- the technical solution in the present invention combines the characteristics of attack behavior and attack frequency by introducing the characteristics of device attributes corresponding to IP. Jointly assess the specific risk level corresponding to IP. That is, use the port scanning tool to reverse trace the IP that accesses the business system through the port, determine the device attribute information corresponding to the IP, and query the address attribute information corresponding to the IP through the geographic location query interface. Then, according to the address attribute weight of the address attribute information corresponding to the IP and the device attribute weight of the device attribute information, the device attribute risk feature corresponding to the IP can be determined timely and accurately.
- each address attribute weight corresponding to each address attribute information and each device attribute weight corresponding to each device attribute information are determined in the following manner:
- the address attribute weights corresponding to the address attribute information and the device attribute weights corresponding to the device attribute information are stored.
- the weights of each influencing factor can be determined in a timely and effective manner by analyzing the influencing factors (such as address attribute information and equipment attribute information) for determining the weight of IP device attributes through the analytic hierarchy process, so as to provide timely and accurate information for follow-up. It can also provide support for the follow-up to intuitively and clearly reflect the specific risk degree of IP.
- the influencing factors such as address attribute information and equipment attribute information
- the determining the attack frequency feature corresponding to the IP according to the number of service access requests of the IP in each sub-period within the set window period includes:
- the number of service access requests of the IP in each sub-period is processed to determine the attack frequency feature corresponding to the IP.
- the attack behavior of illegal users is generally random behavior, it is not a fixed and continuous attack every day. For example, if a large number of malicious service request packets are sent to the business system on a certain day, the attack behavior will stop after the goal is achieved. That is to say, the attack behavior of illegal users is mixed in all service request packets of the service system, so the frequency of malicious service requests is a small probability event. Therefore, according to the statistics of a large number of historical service access requests of users, it can be found that the frequency of service access requests conforms to the normal distribution within the cycle time. Rules, in order to statistically process the number of service access requests of IP in each sub-period within the set window period (that is, within the cycle time), so that the attack frequency characteristics corresponding to the IP can be accurately determined.
- the number of service access requests of the IP in each sub-period is processed, and the attack frequency characteristics corresponding to the IP are determined, including:
- the first attack frequency is used to characterize the degree of central tendency of access behavior of the IP access service system
- the second attack frequency is used to characterize the access behavior of the IP access service system Degree of dispersion
- an attack frequency feature corresponding to the IP is determined.
- the second attack frequency corresponding to the IP satisfies the following form:
- var i is used to indicate the second attack frequency corresponding to any IP
- mean i is used to indicate the first attack frequency corresponding to the IP
- a n is used to indicate the total number of service access requests of the IP on the nth day
- W d It is used to indicate the setting window period.
- attack frequency feature corresponding to the IP satisfies the following form:
- ⁇ i is used to represent the attack frequency feature corresponding to any IP
- F i is used to represent the intermediate result value of the operation.
- the attack frequency characteristics corresponding to the IP can be determined in a timely and accurate manner, and it can also provide support for the subsequent intuitive and clear reflection of the specific risk degree of the IP, and of course it can also specifically reflect the IP risky behavior.
- determining whether to allow the service access request corresponding to the IP includes:
- attack behavior feature device attribute risk feature, attack frequency feature, the weight of the attack behavior feature, the weight of the device attribute risk feature, and the weight of the attack frequency feature corresponding to the IP, determine the IP to which the IP belongs.
- Risk behavior level the weight of the attack behavior feature, the weight of the device attribute risk sub-feature and the weight of the attack frequency feature are determined by the analytic hierarchy process;
- the risk behavior level to which the IP belongs determine whether to allow the service access request corresponding to the IP.
- the IP belongs after determining the risk behavior level to which the IP belongs, it also includes:
- the risk behavior level to which each IP in the database belongs is periodically updated according to a set time interval.
- the degree of risk that may actually be caused to the business system will gradually decrease, that is, the longer the attack behavior is, the actual risk to the current business system
- the degree of risk that may be caused will become smaller, so by re-evaluating the risk behavior levels of each IP that has been stored in history according to the set time interval, that is, the risk behavior levels of each IP that has been stored in history are respectively Updating can ensure the real-time validity of the risk behavior level to which each IP belongs, and also can make the risk behavior level to which each IP belongs have a more accurate time validity period.
- the embodiment of the present invention also provides a device for detecting service access requests, including:
- An acquisition unit configured to acquire service access request information for the IP to access the service system within a set window period when detecting the network protocol IP of the requester of any service access request to access the service system;
- a processing unit configured to detect the content of the service access request information of the IP within the set window period, and determine the attack behavior characteristics corresponding to the IP; Determine the attack frequency characteristics corresponding to the IP according to the number of service access requests; determine the device attribute risk characteristics corresponding to the IP according to the address attribute information and device attribute information corresponding to the IP; determine the attack behavior characteristics corresponding to the IP , device attribute risk characteristics, and attack frequency characteristics, to determine whether to allow the service access request corresponding to the IP.
- processing unit is specifically configured to:
- processing unit is specifically configured to:
- processing unit is specifically configured to:
- the address attribute weights corresponding to the address attribute information and the device attribute weights corresponding to the device attribute information are stored.
- processing unit is specifically configured to:
- the number of service access requests of the IP in each sub-period is processed to determine the attack frequency feature corresponding to the IP.
- processing unit is specifically configured to:
- the first attack frequency is used to characterize the degree of central tendency of access behavior of the IP access service system
- the second attack frequency is used to characterize the access behavior of the IP access service system Degree of dispersion
- an attack frequency feature corresponding to the IP is determined.
- processing unit is specifically configured to:
- var i is used to indicate the second attack frequency corresponding to any IP
- mean i is used to indicate the first attack frequency corresponding to the IP
- a n is used to indicate the total number of service access requests of the IP on the nth day
- W d It is used to indicate the setting window period.
- processing unit is specifically configured to:
- ⁇ i is used to represent the attack frequency feature corresponding to any IP
- F i is used to represent the intermediate result value of the operation.
- processing unit is specifically configured to:
- attack behavior feature device attribute risk feature, attack frequency feature, the weight of the attack behavior feature, the weight of the device attribute risk feature, and the weight of the attack frequency feature corresponding to the IP, determine the IP to which the IP belongs.
- Risk behavior level the weight of the attack behavior feature, the weight of the device attribute risk sub-feature and the weight of the attack frequency feature are determined by the analytic hierarchy process;
- the risk behavior level to which the IP belongs determine whether to allow the service access request corresponding to the IP.
- processing unit is also used for:
- the risk behavior level to which each IP in the database belongs is periodically updated according to a set time interval.
- an embodiment of the present invention provides a computing device, including at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processing The server executes the method for detecting service access requests described in any of the first aspects above.
- an embodiment of the present invention provides a computer-readable storage medium, which stores a computer program executable by a computing device, and when the program runs on the computing device, the computing device executes the above-mentioned first The method for detecting service access requests described in any aspect.
- FIG. 1 is a schematic diagram of a possible system architecture provided by an embodiment of the present invention
- FIG. 2 is a schematic flowchart of a method for detecting service access requests provided by an embodiment of the present invention
- FIG. 3 is a schematic structural diagram of a device for detecting service access requests provided by an embodiment of the present invention
- FIG. 4 is a schematic structural diagram of a computing device provided by an embodiment of the present invention.
- IP Internet Protocol, Internet Protocol or Network Protocol
- the IP address represents the Internet Protocol or Network Protocol address, and is a unified logical address provided for each network and host device according to the IP protocol.
- PC personal computer, personal computer
- PC personal PC
- ADSL Asymmetric Digital Subscriber Line, asymmetric digital subscriber line
- IDC Internet Data Center, Internet Data Center
- IDC equipment a professional server hosting area provided by Internet service providers, including websites and storage data service resource equipment provided for rent by enterprises or individuals.
- Router equipment mainly includes routers, firewalls, and some egress gateway equipment, etc., which are used to connect and serve network equipment with different architectures.
- IOT equipment Internet of Things, Internet of Things: refers to a combination of various information sensing equipment, such as radio frequency identification devices, infrared sensors, global positioning systems, laser scanners and other devices, and the Internet. Huge network.
- the system architecture for detecting service access requests may include an IP historical service access request information analysis and processing module 100, an IP device attribute portrait establishment module 200, a real-time determination module 300 of the risk behavior level of the IP, a database 400, and an IP Offline update module 500 of the risk behavior level to which it belongs.
- the historical service access request information analysis and processing module 100 of IP is used for collecting the historical service access request information of each IP, such as for each IP, collecting the IP within a set window period (such as within 1 day or within 5 days, etc.) Business Access Request Information.
- a set window period such as within 1 day or within 5 days, etc.
- Business Access Request Information After collecting the historical service access request information of each IP, for each IP, through the preset detection rules, detect whether the IP has malicious characters in the service access request information within the set window period, so as to determine the IP A Whether it has obvious attack characteristics.
- the IP device attribute image building module 200 is configured to reversely initiate a network scan for each IP by using common ports and web scanning tools. At the same time, through the associated network TCP (Transmission Control Protocol, Transmission Control Protocol)/IP protocol stack Banner information, operating system version, port opening status, geographical location, and web application layer fingerprint data and other multi-dimensional models, a portrait is established for the IP, And report the established IP device attribute profile (including the device attribute risk characteristics of each IP) to the real-time determination module 300 of the risk behavior level to which the IP belongs.
- TCP Transmission Control Protocol, Transmission Control Protocol
- IP protocol stack Banner information banner information, operating system version, port opening status, geographical location, and web application layer fingerprint data and other multi-dimensional models
- the established IP device attribute profile including the device attribute risk characteristics of each IP
- the real-time determination module 300 of the risk behavior level of the IP is used to determine the attack frequency characteristics corresponding to each IP according to the service access request times of each IP in each sub-period reported by the historical service access request information analysis processing module 100 of the IP, and according to the IP.
- the attack behavior characteristics, device attribute risk characteristics and attack frequency characteristics corresponding to each IP reported by the historical service access request information analysis processing module 100 are calculated to determine the risk behavior level to which each IP belongs (that is, the reputation value corresponding to each IP). Then, the risk behavior level to which each IP belongs is stored in the database 400 .
- the off-line update module 500 of the risk behavior level to which an IP belongs is used to regularly and dynamically update the risk behavior level to which each IP belongs according to a set time interval (such as 10 seconds, 30 seconds or 1 minute, etc.). That is, the risk behavior level of each IP that has been stored in history is obtained from the database 400, and the risk behavior level of each IP that has been stored in history is re-evaluated, and the updated risk behavior level of each IP is determined. , and store the updated risk behavior level of each IP in the database 400 .
- a set time interval such as 10 seconds, 30 seconds or 1 minute, etc.
- FIG. 1 is only an example, which is not limited in this embodiment of the present invention.
- FIG. 2 exemplarily shows the flow of a method for detecting a service access request provided by an embodiment of the present invention, and the flow can be executed by an apparatus for detecting a service access request.
- the process specifically includes:
- Step 201 when the network protocol IP of the requester of any service access request to access the service system is detected, obtain the service access request information of the IP to access the service system within a set window period.
- the network protocol (or Internet protocol) IP is parsed from the data packet of the service access request, and the IP is obtained based on the IP in setting Business access request information for accessing the business system within the window period.
- a detection period such as 1 minute, 5 minutes, 10 minutes, 30 minutes or one day, etc.
- the IP is obtained from the database based on the IP Access to the service access request information of the service system within the set window period.
- the service access request information may include source IP, network protocol (or Internet protocol) type, source port, data packet content, and service request access record.
- a certain user sends a service access request to the service system based on IP A through a certain physical machine device (such as a cloud server), and when the service access request is detected, the The IP A is parsed from the data packet, and based on the IP A, the service access request information of the IP A accessing the business system within the set window period (such as within 1 day, within 5 days, within 10 days, within 20 days or within 30 days, etc.) is obtained. Or, when the detection period (such as 5 minutes) arrives, for the IP A accessing the business system, the service access request information of the IP A accessing the business system within the set window period can be obtained from the database.
- a certain physical machine device such as a cloud server
- Step 202 Perform content detection on the service access request information of the IP within the set window period, and determine the attack behavior characteristics corresponding to the IP.
- content detection can be performed on the service access request information of the IP within the set window period, so as to determine the IP address.
- Corresponding attack behavior characteristics Specifically, through preset detection rules, it is detected whether the IP has malicious characters (such as key characters corresponding to injected cross-site scripting) in the service access request information within the set window period. If it is determined that there are malicious characters in the service access request information, then it is the first attack behavior feature corresponding to the IP tag; if it is determined that there are no malicious characters in the service access request information, then it is the second attack behavior feature corresponding to the IP tag. In this way, it can provide support for the subsequent timely and accurate assessment of the specific risk level corresponding to the IP.
- IP A For each service access request information of IP A within a set window period (for example, within 1 day), the data packet of the service access request information is analyzed in a 4-layer standardization, and it can be obtained To the network protocol (or Internet protocol) type, source IP (ie IP A), source port, data packet content, and service request access records, etc. Then, content detection is performed on the content of the data packet through the preset character string matching rules and regular content feature rules to determine whether there are malicious characters in the data packet content in the service access request information corresponding to IP A, so as to determine whether IP A has obvious The attack characteristics of , and denoted as ⁇ i .
- Step 203 Determine the attack frequency feature corresponding to the IP according to the number of service access requests of the IP in each sub-period within the set window period.
- the attack behavior of illegal users is generally random behavior, it is not a fixed and continuous attack every day. For example, if a large number of malicious service request packets are sent to the business system on a certain day, the attack behavior will be stopped after the goal is achieved. That is to say, the attack behavior of illegal users is mixed in all service request packets of the service system, so the frequency of malicious service requests is a small probability event. Therefore, according to the statistics of a large number of user historical service access requests, it can be found that the frequency of service access requests conforms to the normal distribution within the cycle time (such as within the set window period), that is, the service access of IP within the set window period The distribution of the number of requests conforms to the normal distribution.
- the technical solution in the present invention constructs a calculation rule for determining the characteristics of the attack frequency, so as to perform statistical processing on the number of service access requests of the IP in each sub-period within the set window period (that is, within the cycle time), Therefore, the attack frequency characteristics corresponding to the IP can be accurately determined. Specifically, for each IP, the number of service access requests of the IP in each sub-period of the set window period is counted, and based on the number of service access requests of the IP in each sub-period, the first attack frequency corresponding to the IP is determined. Then, based on the number of service access requests of the IP in each sub-period and the first attack frequency, the second attack frequency corresponding to the IP is determined.
- the attack frequency characteristics corresponding to the IP can be determined in a timely and accurate manner, which can also provide support for the subsequent intuitive and clear reflection of the specific risk degree of the IP, and of course it can also specifically reflect The risky behavior of exporting IP.
- the first attack frequency is used to characterize the degree of concentration of the access behavior of the IP access service system;
- the second attack frequency is used to represent the degree of dispersion of the access behavior of the IP access service system.
- the first attack frequency corresponding to the IP can be determined in the following manner:
- mean i is used to indicate the first attack frequency corresponding to a certain IP
- a n is used to indicate the total number of service access requests of a certain IP on the nth day
- W d is used to indicate the set window period, and the unit is day.
- the second attack frequency corresponding to the IP can be determined in the following manner:
- var i is used to indicate the second attack frequency corresponding to a certain IP. It should be noted that since the attack behavior of illegal users is mixed in all business request packets of the business system, the frequency of malicious business requests is a small probability event. The service access request traffic is highly suspicious, and the corresponding IP will also be marked as high risk. Based on this, the embodiment of the present invention defines the above calculation formula for determining the second attack frequency corresponding to the IP. In this way, if the number of IP's daily service access requests is relatively fixed, the lower the value of var i , the lower the degree of risk corresponding to the IP, and the higher the credibility.
- the first attack frequency corresponding to the IP may also be determined in the following manner:
- T i a 0 +a 1 +...+a n
- T i is used to represent the first attack frequency corresponding to a certain IP
- a n is used to represent the total number of service access requests of a certain IP on the nth day.
- the second attack frequency corresponding to the IP can also be determined in the following manner:
- M i is used to represent the second attack frequency corresponding to the IP.
- attack frequency characteristics corresponding to the IP can be determined in the following ways:
- ⁇ i is used to represent the attack frequency characteristic corresponding to a certain IP
- mean i is used to represent the first attack frequency corresponding to a certain IP
- var i is used to represent the second attack frequency corresponding to a certain IP
- F i is used for Indicates the intermediate result value of the operation.
- attack frequency characteristics corresponding to the IP can also be determined in the following ways:
- ⁇ i is used to represent the attack frequency characteristic corresponding to a certain IP
- T i is used to represent the first attack frequency corresponding to a certain IP
- M i is used to represent the second attack frequency corresponding to a certain IP
- D i is used for Indicates the intermediate result value of the operation.
- IP A IP B Day 1 100 times 0 times day 2 200 times 5000 times Day 3 150 times 20 times
- the second attack frequency corresponding to IP A can be calculated according to the first calculation method for determining the second attack frequency corresponding to IP, that is, At the same time, the second attack frequency corresponding to IP B can be calculated, namely Based on this, it can be seen that the second attack frequency value corresponding to IP B is significantly higher than the second attack frequency value corresponding to IP A. high.
- the corresponding frequency of IP A can be calculated by following the first calculation formula for determining the attack frequency characteristics corresponding to IP.
- the attack frequency feature that is, the attack frequency score
- the attack frequency feature corresponding to IP B that is, the attack frequency score
- Step 204 Determine the device attribute risk feature corresponding to the IP according to the address attribute information and device attribute information corresponding to the IP.
- the technical solution in the present invention combines the attack behavior characteristics and attack frequency characteristics by introducing the device attribute characteristics corresponding to the IP Let's jointly assess the specific risk level corresponding to IP. That is, use the port scanning tool to reverse trace the IP that accesses the business system through the port, determine the device attribute information corresponding to the IP, and query the address attribute information corresponding to the IP through the geographic location query interface. Then, according to the address attribute weight of the address attribute information corresponding to the IP and the device attribute weight of the device attribute information, the device attribute risk feature corresponding to the IP can be determined timely and accurately.
- each address attribute weight corresponding to each address attribute information and each device attribute weight corresponding to each device attribute information can be determined in the following manner: through the analytic hierarchy process, each address attribute information and each device attribute information corresponding to each IP are carried out. Analyzing and processing, determining each address attribute weight corresponding to each address attribute information and each device attribute weight corresponding to each device attribute information, and combining each address attribute weight corresponding to each address attribute information and each device attribute weight corresponding to each device attribute information to store.
- the weight of each influencing factor can be determined in a timely and effective manner by analyzing the influencing factors (such as address attribute information and equipment attribute information) for determining the weight of IP device attributes through the AHP, so as to obtain IP in a timely and accurate manner.
- the corresponding device attribute risk characteristics provide support, which can also provide support for the subsequent intuitive and clear reflection of the specific risk degree of IP.
- a reverse network scan is performed on the IP by using a common port and web scanning tool.
- TCP Transmission Control Protocol
- IP protocol stack Banner information, operating system version, port opening status, geographical location, and web application layer fingerprint data and other multi-dimensional models
- a portrait is established for the IP, And store the established IP device attribute image.
- the Banner, port number, operating system version, HTTP key fields and other information recorded above can be uploaded to the cloud analysis engine for offline judgment.
- clustering algorithms and decision models for PC, IDC, Router, IOT and other devices are different clustering algorithms and decision models for PC, IDC, Router, IOT and other devices.
- PC devices will perform scoring calculations based on IP historical survival (such as marking whether the same IP is online for a long time), while IDC devices will combine IP to open Correlation analysis is performed on the port protocol and the actual business conditions running on the physical machine.
- Router ⁇ IOT devices are different from the above types of devices, and will be customized according to different device manufacturers.
- Special network protocols MQTT (Message Queuing Telemetry Transport, message queue telemetry transmission) ⁇ REST(Representational State Transfer, resource presentation layer state transfer) ⁇ XMPP (Extensible Messaging and Presence Protocol, Extensible Communication and Presentation Protocol) ⁇ AMQP (Advanced Message Queuing Protocol, Advanced Message Queuing Protocol, etc.), port service and operating system version for correlation analysis.
- IP device portraits are divided into PC, IDC and IOT devices.
- IP of an overseas address and the device type is an IDC device or an IOT device is often a zombie host controlled by real malicious means, so the risk of using an overseas IP to access a business system through an IDC device or an IOT device is relatively higher.
- AHP Analytic Hierarchy Process
- IDC device attributes have a greater impact on the risk characteristics of IP-corresponding device attributes than PC device attributes, so the two are scored as 1/5 in terms of value.
- the matrix values of other device attributes can be scored according to the way of IDC device attributes relative to PC device attributes, and details will not be described here.
- the embodiment of the present invention determines the risk characteristics of the device attributes corresponding to the IP in the following manner:
- ⁇ i is used to represent the risk characteristics of device attributes corresponding to a certain IP
- W n is used to represent the weight ratio corresponding to each device attribute.
- the device attribute characteristics of IP A are domestic addresses and PC devices; and the device attribute characteristics of IP B are overseas addresses and IDC devices.
- the device attribute risk feature corresponding to IP B ie, the device attribute risk score
- the weight ratio corresponding to the domestic address is 0.
- Step 205 Determine whether to allow the service access request corresponding to the IP based on the attack behavior characteristics, device attribute risk characteristics, and attack frequency characteristics corresponding to the IP.
- the attack behavior characteristics, device attribute risk characteristics, and attack frequency characteristics corresponding to each IP are analyzed and processed through the AHP, and the weights of the attack behavior characteristics, the weights of the device attribute risk characteristics, and the attack frequency characteristics are determined.
- a comparison matrix of three influencing factors that is, attack behavior characteristics, device attribute risk characteristics, and attack frequency characteristics
- characteristics that is, attack behavior characteristics, device attribute risk characteristics, and attack frequency characteristics
- the three features are compared in pairs to form a third-order matrix, and then the eigenvector of the third-order matrix is calculated, and based on the eigenvector of the third-order matrix, the weight of the attack behavior feature, the weight of the device attribute risk feature, and the The weight of the attack frequency feature.
- the weight of the attack behavior feature, the weight of the device attribute risk feature, and the weight of the attack frequency feature can be set according to the experience value of those skilled in the art or the results obtained from multiple experiments.
- the risk behavior of the IP can be more comprehensively and accurately evaluated.
- Level in order to comprehensively evaluate the specific risk level corresponding to the IP, so as to realize the quantitative description of the risk level corresponding to each IP, and also store the risk behavior level of each IP in the database. Then, according to the risk behavior level to which the IP belongs, it can be timely and accurately determined whether to allow the service access request corresponding to the IP, so as to ensure the data security of the business system.
- the risk behavior level to which the IP belongs can be determined in the following ways:
- S i is used to represent the risk behavior level of a certain IP
- ⁇ i is used to represent the attack behavior characteristics corresponding to a certain IP
- ⁇ i is used to represent the risk characteristics of equipment attributes corresponding to a certain IP
- ⁇ i is used to represent Attack frequency characteristics corresponding to a certain IP
- w 0 is used to represent the weight of attack behavior characteristics
- w 1 is used to represent the weight of device attribute risk characteristics
- w 2 is used to represent the weight of attack frequency characteristics.
- the specific risk degree corresponding to each IP can be determined according to the risk behavior level to which each IP belongs. That is to say, the higher the risk behavior level of a certain IP, the greater the specific risk level corresponding to the IP.
- IP B has the attributes of overseas addresses and IOT devices, and has launched a large number of irregular attacks on business systems.
- the risk behavior level to which IP B belongs ie, the reputation value of IP B
- the risk behavior level to which IP A belongs ie, the reputation value of IP A
- the risk behavior level range can be set, that is, high risk behavior level, higher risk behavior level, medium risk behavior level, lower risk behavior level and low risk behavior level.
- the credit value of 80-100 is divided into high-risk behavior level
- the credibility value of 60-80 is divided into high-risk behavior level
- the credibility value of 40-60 is divided into medium-risk behavior level
- a credit value of 20 to 40 is classified as a low-risk behavior level
- a credit value of 0 to 20 is classified as a low-risk behavior level.
- different business access security protection rules are set according to different risk behavior levels.
- the risk behavior level of each IP can be determined, and different business access security protection rules can be selected according to the risk behavior level of each IP, so as to target
- Each IP adopts different security protection strategies. For example, taking IP A as an example, assuming that IP A triggers a high-risk behavior level security protection rule, the business system will immediately intercept and reject IP A’s business access request. Get banned. Alternatively, assuming that IP A triggers a security protection rule with a low-risk behavior level, the service system will allow IP A's service access request.
- the degree of risk that may actually be caused to the business system will gradually decrease, that is, the longer the attack behavior that may actually cause the current business system
- the degree of risk will become smaller, so by setting time intervals (such as 10 seconds, 30 seconds, 1 minute, 5 minutes, 30 minutes, 1 day or 5 days, etc.), the risk behavior level of each IP that has been stored in history (that is, the reputation value of each IP) is re-evaluated separately, that is, the risk behavior levels of each IP that have been stored in the history are updated separately, which can ensure the real-time validity of the risk behavior levels of each IP, and also can The risk behavior level to which each IP belongs has a more precise time validity period.
- the risk behavior level to which each IP belongs can be regularly and dynamically updated in the following ways:
- S j is used to represent the risk behavior level of an updated IP
- ⁇ is used to represent the update proportional constant, which can be adjusted according to the actual application scenario
- ⁇ d represents the date difference between S old and S new
- S new is used for Indicates the current risk behavior level of an IP
- S old is used to indicate the risk behavior level corresponding to the date closest to the current date of an IP.
- the above embodiment shows that when the network protocol IP of the requester of any service access request of the access service system is detected, the service access request information of the IP accessing the service system within the set window period will be obtained immediately, And perform content detection on the service access request information of the IP within the set window period to determine the attack behavior characteristics corresponding to the IP. Then, according to the address attribute information and device attribute information corresponding to the IP, the risk characteristics of the device attribute corresponding to the IP are determined. Then, based on the attack behavior characteristics, device attribute risk characteristics, and attack frequency characteristics corresponding to the IP, it is determined whether to allow the service access request corresponding to the IP.
- the solution comprehensively evaluates IP from the three characteristic dimensions of attack behavior characteristics, device attribute risk characteristics, and attack frequency characteristics, and can more comprehensively and accurately evaluate the specific risk level corresponding to the IP, so as to realize the analysis of all IPs. Quantitatively describe the corresponding risk level. At the same time, according to the degree of risk, it can be timely and accurately determined whether to allow the service access request corresponding to the IP, so as to ensure the data security of the business system. In addition, since this solution can assess the specific risk level corresponding to the IP, each IP can be divided into a finer granularity based on the specific risk level corresponding to each IP, so that each IP can be displayed more intuitively and clearly , which can facilitate decision makers to make timely and accurate decisions.
- each IP can be displayed more intuitively and accurately, it can avoid the simple and rude ban of a temporary IP in the existing technology, which will cause other normal visitors to be unable to use the temporary IP to perform normal activities. Thereby, user experience can be improved.
- FIG. 3 exemplarily shows a device for detecting a service access request provided by an embodiment of the present invention, and the device can execute the flow of the method for detecting a service access request.
- the device includes:
- the obtaining unit 301 is configured to obtain the service access request information of the IP accessing the service system within the set window period when detecting the network protocol IP of the requester of any service access request for accessing the service system;
- the processing unit 302 is configured to detect the content of the service access request information of the IP within the set window period, and determine the attack behavior characteristics corresponding to the IP; Determine the attack frequency characteristics corresponding to the IP according to the number of service access requests; determine the device attribute risk characteristics corresponding to the IP according to the address attribute information and device attribute information corresponding to the IP; determine the attack behavior corresponding to the IP feature, device attribute risk feature, and attack frequency feature to determine whether to allow the service access request corresponding to the IP.
- processing unit 302 is specifically configured to:
- processing unit 302 is specifically configured to:
- processing unit 302 is specifically configured to:
- the address attribute weights corresponding to the address attribute information and the device attribute weights corresponding to the device attribute information are stored.
- processing unit 302 is specifically configured to:
- the number of service access requests of the IP in each sub-period is processed to determine the attack frequency feature corresponding to the IP.
- processing unit 302 is specifically configured to:
- the first attack frequency is used to characterize the degree of central tendency of access behavior of the IP access service system
- the second attack frequency is used to characterize the access behavior of the IP access service system Degree of dispersion
- an attack frequency feature corresponding to the IP is determined.
- processing unit 302 is specifically configured to:
- var i is used to indicate the second attack frequency corresponding to any IP
- mean i is used to indicate the first attack frequency corresponding to the IP
- a n is used to indicate the total number of service access requests of the IP on the nth day
- W d It is used to indicate the setting window period.
- processing unit 302 is specifically configured to:
- ⁇ i is used to represent the attack frequency feature corresponding to any IP
- F i is used to represent the intermediate result value of the operation.
- processing unit 302 is specifically configured to:
- attack behavior feature device attribute risk feature, attack frequency feature, the weight of the attack behavior feature, the weight of the device attribute risk feature, and the weight of the attack frequency feature corresponding to the IP, determine the IP to which the IP belongs.
- Risk behavior level the weight of the attack behavior feature, the weight of the device attribute risk sub-feature and the weight of the attack frequency feature are determined by the analytic hierarchy process;
- the risk behavior level to which the IP belongs determine whether to allow the service access request corresponding to the IP.
- processing unit 302 is further configured to:
- the risk behavior level to which each IP in the database belongs is periodically updated according to a set time interval.
- the embodiment of the present invention also provides a computing device, as shown in FIG. 4 , including at least one processor 401 and a memory 402 connected to the at least one processor.
- the specific connection medium between the processor 401 and the memory 402, the bus connection between the processor 401 and the memory 402 in FIG. 4 is taken as an example.
- the bus can be divided into address bus, data bus, control bus and so on.
- the memory 402 stores instructions that can be executed by at least one processor 401, and at least one processor 401 can execute the steps included in the aforementioned method for detecting service access requests by executing the instructions stored in the memory 402 .
- the processor 401 is the control center of the computing device, which can use various interfaces and lines to connect various parts of the computing device, by running or executing instructions stored in the memory 402 and calling data stored in the memory 402, thereby realizing data deal with.
- the processor 401 may include one or more processing units, and the processor 401 may integrate an application processor and a modem processor.
- the call processor mainly handles issuing instructions. It can be understood that the foregoing modem processor may not be integrated into the processor 401 .
- the processor 401 and the memory 402 can be implemented on the same chip, and in some embodiments, they can also be implemented on independent chips.
- the processor 401 can be a general processor, such as a central processing unit (CPU), a digital signal processor, an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array or other programmable logic devices, discrete gates or transistors Logic devices and discrete hardware components can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present invention.
- a general purpose processor may be a microprocessor or any conventional processor or the like. The steps of the method disclosed in the embodiment of the method for detecting a service access request can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.
- the memory 402 can be used to store non-volatile software programs, non-volatile computer-executable programs and modules.
- Memory 402 can include at least one type of storage medium, for example, can include flash memory, hard disk, multimedia card, card memory, random access memory (Random Access Memory, RAM), static random access memory (Static Random Access Memory, SRAM), Programmable Read Only Memory (PROM), Read Only Memory (ROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Magnetic Memory, Disk , CD, etc.
- Memory 402 is, but is not limited to, any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer.
- the memory 402 in the embodiment of the present invention may also be a circuit or any other device capable of implementing a storage function, and is used for storing program instructions and/or data.
- an embodiment of the present invention also provides a computer-readable storage medium, which stores a computer program executable by a computing device, and when the program is run on the computing device, the computing device Execute the steps of the above method for detecting service access requests.
- the embodiments of the present invention may be provided as methods, systems, or computer program products. Accordingly, the present invention can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) having computer-usable program code embodied therein.
- computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
- These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing apparatus to operate in a specific manner, such that the instructions stored in the computer-readable memory produce an article of manufacture comprising instruction means, the instructions
- the device realizes the function specified in one or more procedures of the flowchart and/or one or more blocks of the block diagram.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
本发明实施例提供了一种检测业务访问请求的方法及装置,该方法包括获取IP在设定窗口时段内访问业务系统的业务访问请求信息,对IP的业务访问请求信息进行内容检测,确定IP的攻击行为特征,根据IP在设定窗口时段内各子时段的业务访问请求次数,确定IP的攻击频率特征,根据IP的地址属性信息和设备属性信息,确定IP的设备属性风险特征,基于IP的攻击行为特征、设备属性风险特征和攻击频率特征,确定是否允许IP的业务访问请求。如此,该方案从攻击行为特征、设备属性风险特征和攻击频率特征三个维度来综合评估IP,可以准确地评估出IP的具体风险程度,从而可以解决现有技术中在批量执行封禁IP时无法及时准确地做出决策的问题。
Description
相关申请的交叉引用
本申请要求在2021年06月30日提交中国专利局、申请号为202110730544.3、申请名称为“一种检测业务访问请求的方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本发明实施例涉及金融科技(Fintech)领域,尤其涉及一种检测业务访问请求的方法及装置。
随着计算机技术的发展,越来越多的技术应用在金融领域,传统金融业正在逐步向金融科技转变,但由于金融行业的安全性、实时性要求,也对技术提出的更高的要求。在金融领域中,为了便于用户浏览和查询相关金融业务数据,通常会提供金融业务服务平台给用户,然而,有一些不法分子利用爬虫或一些网络攻击手段等恶意窃取该相关金融业务数据,导致金融业务服务平台出现异常而影响正常用户的正常访问,并会给金融领域带来严重损失。因此,为了确保金融服务质量,如何及时有效地检测出异常IP成为急需解决的问题。
现阶段,在检测到某一IP发起的业务访问请求数据包时,主要是通过安全检测系统检测该业务访问请求数据包中是否包含恶意字符,来判断该IP是否存在恶意访问行为,从而确定是否拒绝该IP的业务访问请求,同时根据判断结果将该IP记录在IP黑名单或IP白名单中。然而,这种处理方式因缺乏精细粒度的划分IP,导致在批量执行封禁IP时无法及时准确地做出决策。此外,在某一被封禁的IP为公网临时IP时,因该封禁的IP已记录在历史IP黑名单中而导致安全检测系统因历史IP黑名单对正常访问者造成误判,从而使得基于该临时IP的其它正常访问者无法使用该临时IP进行正常访问。
综上,目前亟需一种检测业务访问请求的方法,用以解决现有技术中在批量执行封禁IP时无法及时准确地做出决策的问题。
发明内容
本发明实施例提供了一种检测业务访问请求的方法及装置,用以解决现有技术中在批量执行封禁IP时无法及时准确地做出决策的问题。
第一方面,本发明实施例提供了一种检测业务访问请求的方法,包括:
在检测到访问业务系统的任一业务访问请求的请求方的网络协议IP时,获取所述IP在设定窗口时段内访问所述业务系统的业务访问请求信息;
对所述IP在设定窗口时段内的业务访问请求信息进行内容检测,确定所述IP对应的攻击行为特征;
根据所述IP在所述设定窗口时段内各子时段的业务访问请求的次数,确定所述IP对应的攻击频率特征;
根据所述IP对应的地址属性信息和设备属性信息,确定所述IP对应的设备属性风险特征;
基于所述IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许所述IP对应的业务访问请求。
上述技术方案中,在检测到访问业务系统的任一业务访问请求的请求方的网络协议IP时,就会立即去获取该IP在设定窗口时段内访问所述业务系统的业务访问请求信息,并对该IP在设定窗口时段内的业务访问请求信息进行内容检测,确定IP对应的攻击行为特征。再通过根据IP对应的地址属性信息和设备属性信息,确定IP对应的设备属性风险特征。然后,基于IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许该IP对应的业务访问请求。如此,该方案从攻击行为特征、设备属性风险特征以及攻击频率特征三个特征维度进行综合评估IP,可以更加全面且准确地评估出IP所对应的具体风险程度,以此可以实现对各IP所对应的风险程度进行定量描述。同时,根据该风险程度就可以及时准确地确定是否允许该IP对应的业务访问请求,以此可以确保业务系统的数据安全性。此外,由于该方案可以评估出IP所对应的具体风险程度,因此可以基于各IP所对应的具体风险程度对各IP进行更精细粒度地划分,以此可以使得各IP能够更加直观清晰地进行展示,也就可以便于决策者及时准确地做出决策。而且,由于可以更加直观精确地展示出各IP所对应的具体风险程度,如此就可以避免现有技术简单粗暴的将某一临时IP进行封禁而导致其它正常访问者无法使用该临时IP进行正常,从而可以提升用户体验。
可选地,所述对所述IP在设定窗口时段内的业务访问请求信息进行内容检测,确定所述IP对应的攻击行为特征,包括:
通过预设的检测规则,检测所述IP在设定窗口时段内的业务访问请求信息中是否具有恶意字符;
若确定业务访问请求信息中具有恶意字符,则为所述IP标记对应的第一攻击行为特征;
若确定业务访问请求信息中不具有恶意字符,则为所述IP标记对应的第二攻击行为特征。
上述技术方案中,通过预设的检测规则,对该IP在设定窗口时段内的多个业务访问请求信息进行内容检测,确定通过该IP发起的业务请求是否携带有恶意字符(比如注入的跨站脚本所对应的关键字符),以此确定该IP是否具备明显的攻击特征。基于此,如果该IP具备明显的攻击特征,就为该IP标记上第一攻击行为特征;如果该IP不具备明显的攻击特征,就为该IP标记上第二攻击行为特征。如此,就可以为后续及时准确地评估该IP所对应的具体风险程度提供支持。
可选地,所述根据所述IP对应的地址属性信息和设备属性信息,确定所述IP对应的设备属性风险特征,包括:
利用端口扫描工具,对通过业务系统的端口访问所述业务系统的所述IP进行反向跟踪,确定出所述IP对应的设备属性信息,并查询出所述IP对应的地址属性信息;
根据所述地址属性信息对应的地址属性权重和所述设备属性信息对应的设备属性权重,确定所述IP对应的设备属性风险特征。
上述技术方案中,由于通过不同物理机设备的IP攻击业务系统所带来的风险性不同, 因此,本发明中的技术方案通过引入IP对应的设备属性特征来结合攻击行为特征、攻击频率特征一起共同评估IP对应的具体风险程度。也即是,利用端口扫描工具,对通过端口访问业务系统的该IP进行反向追踪,确定出该IP对应的设备属性信息,并通过地理位置查询接口查询出该IP对应的地址属性信息。然后,根据该IP对应的地址属性信息的地址属性权重以及设备属性信息的设备属性权重,就可以及时准确地确定出该IP对应的设备属性风险特征。
可选地,通过下述方式确定各地址属性信息对应的各地址属性权重和各设备属性信息对应的各设备属性权重:
通过层次分析法,对各IP对应的各地址属性信息、各设备属性信息进行分析处理,确定出所述各地址属性信息对应的各地址属性权重和所述各设备属性信息对应的各设备属性权重;
将所述各地址属性信息对应的各地址属性权重和所述各设备属性信息对应的各设备属性权重进行存储。
上述技术方案中,通过层次分析法对确定IP的设备属性权重的各影响因素(比如地址属性信息和设备属性信息)进行分析,可以及时有效地确定出各影响因素的权重,以便为后续及时准确地得到IP对应的设备属性风险特征提供支持,也就能为后续直观清晰地反映IP的具体风险程度提供支持。
可选地,所述根据所述IP在所述设定窗口时段内各子时段的业务访问请求次数,确定所述IP对应的攻击频率特征,包括:
基于IP在设定窗口时段内的业务访问请求次数的分布规律符合正态分布,构建出用于确定攻击频率特征的计算规则;
按照所述计算规则,对所述IP在各子时段的业务访问请求次数进行处理,确定出所述IP对应的攻击频率特征。
上述技术方案中,由于非法用户的攻击行为一般属于随机性行为,并不是每天固定持续性攻击,比如在某天对业务系统发送大量恶意业务请求包,便会在目的达成后停止攻击行为。也即是,非法用户的攻击行为混在业务系统的所有业务请求包中,所以恶意业务请求频率是一个小概率事件。因此,根据大量的用户历史业务访问请求统计,可以发现业务访问请求频率在周期时间内是符合正态分布的,基于此,本发明中的技术方案通过构建出一个用于确定攻击频率特征的计算规则,以便对IP在设定窗口时段内(即周期时间内)各子时段的业务访问请求次数进行统计处理,从而可以准确地确定出IP对应的攻击频率特征。
可选地,所述按照所述计算规则,对所述IP在各子时段的业务访问请求次数进行处理,确定出所述IP对应的攻击频率特征,包括:
基于所述IP在各子时段的业务访问请求次数,确定所述IP对应的第一攻击频率;所述第一攻击频率用于表征所述IP访问业务系统的访问行为集中趋势程度;
基于所述IP在各子时段的业务访问请求次数以及所述第一攻击频率,确定所述IP对应的第二攻击频率;所述第二攻击频率用于表征所述IP访问业务系统的访问行为离散程度;
根据所述第一攻击频率和所述第二攻击频率,确定所述IP对应的攻击频率特征。
可选地,所述IP对应的第二攻击频率满足下述形式:
其中,var
i用于表示任一IP对应的第二攻击频率,mean
i用于表示该IP对应的第一攻击频率,a
n用于表示第n天该IP的总业务访问请求次数,W
d用于表示设定窗口时段。
可选地,所述IP对应的攻击频率特征满足下述形式:
其中,γ
i用于表示任一IP对应的攻击频率特征,F
i用于表示运算中间结果值。
上述技术方案中,首先通过对IP在各子时段的业务访问请求次数进行统计处理,可以准确地确定用于表征IP访问业务系统的访问行为集中趋势程度的第一攻击频率,并根据IP在各子时段的业务访问请求次数以及第一攻击频率,可以准确地确定用于表征IP访问业务系统的访问行为离散程度的第二攻击频率。再根据第一攻击频率和第二攻击频率,就可以及时准确地确定IP对应的攻击频率特征,也就能为后续直观清晰地反映IP的具体风险程度提供支持,当然也能够具体地反映出IP的风险行为。
可选地,基于所述IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许所述IP对应的业务访问请求,包括:
根据所述IP对应的攻击行为特征、设备属性风险特征、攻击频率特征、所述攻击行为特征的权重、所述设备属性风险特征的权重和所述攻击频率特征的权重,确定所述IP所属的风险行为等级;所述攻击行为特征的权重、所述设备属性风险分特征的权重和所述攻击频率特征的权重是通过层次分析法确定的;
根据所述IP所属的风险行为等级,确定是否允许所述IP对应的业务访问请求。
上述技术方案中,通过基于攻击行为特征、设备属性风险特征、攻击频率特征、攻击行为特征的权重、设备属性风险特征的权重和攻击频率特征的权重,可以更加全面且准确的评估出IP所属的风险行为等级,以此综合评估出IP所对应的具体风险程度,从而可以实现对各IP所对应的风险程度进行定量描述。同时,根据IP所属的风险行为等级就可以及时准确地确定是否允许该IP对应的业务访问请求,以此可以确保业务系统的数据安全性。
可选地,在确定所述IP所属的风险行为等级之后,还包括:
将各IP所属的风险行为等级存储在数据库中;
按照设定时间间隔,对所述数据库中各IP所属的风险行为等级进行周期性的更新。
上述技术方案中,由于历史出现的各IP所属的风险等级随着时间的推移,对业务系统实际可能造成的风险程度会逐渐降低,也即是,时间越久远的攻击行为对当前的业务系统实际可能造成的风险程度会变小,因此通过按照设定时间间隔,对历史已存储的各IP所属的风险行为等级分别进行重新评定,也即是对历史已存储的各IP所属的风险行为等级分别进行更新,可以确保各IP所属的风险行为等级的实时有效性,也就可以使得各IP所属的风险行为等级有了更精确的时间有效期。
第二方面,本发明实施例还提供了一种检测业务访问请求的装置,包括:
获取单元,用于在检测到访问业务系统的任一业务访问请求的请求方的网络协议IP时,获取所述IP在设定窗口时段内访问所述业务系统的业务访问请求信息;
处理单元,用于对所述IP在设定窗口时段内的业务访问请求信息进行内容检测,确定所述IP对应的攻击行为特征;根据所述IP在所述设定窗口时段内各子时段的业务访问请 求的次数,确定所述IP对应的攻击频率特征;根据所述IP对应的地址属性信息和设备属性信息,确定所述IP对应的设备属性风险特征;基于所述IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许所述IP对应的业务访问请求。
可选地,所述处理单元具体用于:
通过预设的检测规则,检测所述IP在设定窗口时段内的业务访问请求信息中是否具有恶意字符;
若确定业务访问请求信息中具有恶意字符,则为所述IP标记对应的第一攻击行为特征;
若确定业务访问请求信息中不具有恶意字符,则为所述IP标记对应的第二攻击行为特征。
可选地,所述处理单元具体用于:
利用端口扫描工具,对通过业务系统的端口访问所述业务系统的所述IP进行反向跟踪,确定出所述IP对应的设备属性信息,并查询出所述IP对应的地址属性信息;
根据所述地址属性信息对应的地址属性权重和所述设备属性信息对应的设备属性权重,确定所述IP对应的设备属性风险特征。
可选地,所述处理单元具体用于:
通过层次分析法,对各IP对应的各地址属性信息、各设备属性信息进行分析处理,确定出所述各地址属性信息对应的各地址属性权重和所述各设备属性信息对应的各设备属性权重;
将所述各地址属性信息对应的各地址属性权重和所述各设备属性信息对应的各设备属性权重进行存储。
可选地,所述处理单元具体用于:
基于IP在设定窗口时段内的业务访问请求次数的分布规律符合正态分布,构建出用于确定攻击频率特征的计算规则;
按照所述计算规则,对所述IP在各子时段的业务访问请求次数进行处理,确定出所述IP对应的攻击频率特征。
可选地,所述处理单元具体用于:
基于所述IP在各子时段的业务访问请求次数,确定所述IP对应的第一攻击频率;所述第一攻击频率用于表征所述IP访问业务系统的访问行为集中趋势程度;
基于所述IP在各子时段的业务访问请求次数以及所述第一攻击频率,确定所述IP对应的第二攻击频率;所述第二攻击频率用于表征所述IP访问业务系统的访问行为离散程度;
根据所述第一攻击频率和所述第二攻击频率,确定所述IP对应的攻击频率特征。
可选地,所述处理单元具体用于:
其中,var
i用于表示任一IP对应的第二攻击频率,mean
i用于表示该IP对应的第一攻击频率,a
n用于表示第n天该IP的总业务访问请求次数,W
d用于表示设定窗口时段。
可选地,所述处理单元具体用于:
其中,γ
i用于表示任一IP对应的攻击频率特征,F
i用于表示运算中间结果值。
可选地,所述处理单元具体用于:
根据所述IP对应的攻击行为特征、设备属性风险特征、攻击频率特征、所述攻击行为特征的权重、所述设备属性风险特征的权重和所述攻击频率特征的权重,确定所述IP所属的风险行为等级;所述攻击行为特征的权重、所述设备属性风险分特征的权重和所述攻击频率特征的权重是通过层次分析法确定的;
根据所述IP所属的风险行为等级,确定是否允许所述IP对应的业务访问请求。
可选地,所述处理单元还用于:
在确定所述IP所属的风险行为等级之后,将各IP所属的风险行为等级存储在数据库中;
按照设定时间间隔,对所述数据库中各IP所属的风险行为等级进行周期性的更新。
第三方面,本发明实施例提供一种计算设备,包括至少一个处理器以及至少一个存储器,其中,所述存储器存储有计算机程序,当所述程序被所述处理器执行时,使得所述处理器执行上述第一方面任意所述的检测业务访问请求的方法。
第四方面,本发明实施例提供一种计算机可读存储介质,其存储有可由计算设备执行的计算机程序,当所述程序在所述计算设备上运行时,使得所述计算设备执行上述第一方面任意所述的检测业务访问请求的方法。
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例描述中所需要使用的附图作简要介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域的普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本发明实施例提供的一种可能的系统架构示意图;
图2为本发明实施例提供的一种检测业务访问请求的方法的流程示意图;
图3为本发明实施例提供的一种检测业务访问请求的装置的结构示意图;
图4为本发明实施例提供的一种计算设备的结构示意图。
为了使本发明的目的、技术方案和优点更加清楚,下面将结合附图对本发明作进一步地详细描述,显然,所描述的实施例仅仅是本发明的一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其它实施例,都属于本发明保护的范围。
下面首先对本发明实施例中涉及的部分用语进行解释说明,以便于本领域技术人员进行理解。
(1)IP(Internet Protocol,互联网协议或网络协议):IP地址表示互联网协议或网络协议地址,是根据IP协议为每个网络、主机设备提供的一个统一逻辑地址。
(2)PC(personal computer,个人计算机)设备:个人PC,普通用户设备通过ADSL(Asymmetric Digital Subscriber Line,非对称数字用户环路)拨号或其它宽带方式接入互联网。
(3)IDC(Internet Data Center,互联网数据中心)设备:互联网服务商提供的专业的服务器托管区域,包含为企业或个人提供租用的网站、存储数据服务资源设备。
(4)Router设备:主要包含路由器、防火墙以及部分出口网关设备等,用来连接和服务不同体系结构网络设备。
(5)IOT设备(Internet of Things,物联网):是指将各种信息传感设备,如射频识别装置、红外感应器、全球定位系统、激光扫描器等装置与互联网结合起来而形成的一个巨大网络。
如上介绍了本发明实施例中涉及的部分用语,下面对本发明实施例涉及的技术特征进行介绍。
为了便于理解本发明实施例,首先以图1中示出的系统结构为例说明适用于本发明实施例的检测业务访问请求的系统架构。如图1所示,该检测业务访问请求的系统架构可以包括IP的历史业务访问请求信息分析处理模块100、IP设备属性画像建立模块200、IP所属风险行为等级实时确定模块300、数据库400以及IP所属风险行为等级离线更新模块500。
其中,IP的历史业务访问请求信息分析处理模块100用于收集各IP的历史业务访问请求信息,比如针对每个IP,收集该IP在设定窗口时段内(比如1天内或5天内等)的业务访问请求信息。在收集好各IP的历史业务访问请求信息后,针对每个IP,通过预设的检测规则,检测该IP在设定窗口时段内的业务访问请求信息中是否具有恶意字符,以此确定IP A是否具备明显的攻击特征。同时,统计出该IP在设定窗口时段内每个子时段的业务访问请求次数。然后,将各IP的攻击行为特征以及每个子时段的业务访问请求次数上报给IP所属风险行为等级实时确定模块300。
IP设备属性画像建立模块200用于针对每个IP,通过利用常见的端口、web扫描工具,对该IP进行反向发起网络扫描。同时,通过关联网络TCP(Transmission Control Protocol,传输控制协议)/IP协议栈Banner信息、操作系统版本、端口开放情况、地理位置以及Web应用层指纹数据等多维度模型,为该IP进行建立画像,并将建立好的IP设备属性画像(包括各IP的设备属性风险特征)上报给IP所属风险行为等级实时确定模块300。
IP所属风险行为等级实时确定模块300用于根据IP的历史业务访问请求信息分析处理模块100上报的各IP在每个子时段的业务访问请求次数确定出各IP对应的攻击频率特征,并根据IP的历史业务访问请求信息分析处理模块100上报的各IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征进行计算,确定出各IP所属的风险行为等级(即各IP对应的信誉度值)。然后将各IP所属的风险行为等级存储至数据库400中。
IP所属风险行为等级离线更新模块500用于按照设定时间间隔(比如10秒、30秒或1分钟等),定期动态更新各IP所属的风险行为等级。也即是从数据库400中获取历史已存储的各IP所属的风险行为等级,并对历史已存储的各IP所属的风险行为等级分别进行 重新评定,确定出更新后的各IP所属的风险行为等级,并将更新后的各IP所属的风险行为等级存储至数据库400中。
需要说明的是,上述图1所示的结构仅是一种示例,本发明实施例对此不做限定。
基于上述描述,图2示例性的示出了本发明实施例提供的一种检测业务访问请求的方法的流程,该流程可以由检测业务访问请求的装置执行。
如图2所示,该流程具体包括:
步骤201,在检测到访问业务系统的任一业务访问请求的请求方的网络协议IP时,获取所述IP在设定窗口时段内访问所述业务系统的业务访问请求信息。
本发明实施例中,在检测到访问业务系统的某一业务访问请求时,从该业务访问请求的数据包中解析出网络协议(或互联网协议)IP,并基于该IP获取该IP在设定窗口时段内访问业务系统的业务访问请求信息。或者,可以设置一个检测周期(比如1分钟、5分钟、10分钟、30分钟或一天等),在该检测周期到达时,针对访问业务系统的每个IP,基于该IP从数据库中获取该IP在设定窗口时段内访问业务系统的业务访问请求信息。其中,该业务访问请求信息可以包括源IP、网络协议(或互联网协议)类型、源端口、数据包内容以及业务请求访问记录等。
示例性地,以IP A为例,某一用户通过某一物理机设备(比如云服务器)基于IP A向业务系统发送业务访问请求,在检测到该业务访问请求时,从该业务访问请求的数据包中解析出IP A,并基于该IP A获取该IP A在设定窗口时段内(比如1天内、5天内、10天内、20天内或30天内等)访问业务系统的业务访问请求信息。或者,在检测周期(比如5分钟)到达时,可以针对访问业务系统的IP A,从数据库中获取该IP A在设定窗口时段内访问业务系统的业务访问请求信息。
步骤202,对所述IP在设定窗口时段内的业务访问请求信息进行内容检测,确定所述IP对应的攻击行为特征。
本发明实施例中,在获取到某一IP在设定窗口时段内的业务访问请求信息后,就可以针对该IP在设定窗口时段内的业务访问请求信息进行内容检测,以此确定该IP对应的攻击行为特征。具体地,通过预设的检测规则,检测该IP在设定窗口时段内的业务访问请求信息中是否具有恶意字符(比如注入的跨站脚本所对应的关键字符)。若确定业务访问请求信息中具有恶意字符,则为该IP标记对应的第一攻击行为特征;若确定业务访问请求信息中不具有恶意字符,则为该IP标记对应的第二攻击行为特征。如此,就可以为后续及时准确地评估该IP所对应的具体风险程度提供支持。
示例性地,继续以IP A为例,针对IP A在设定窗口时段内(比如1天内)的每一个业务访问请求信息,对该业务访问请求信息的数据包进行4层标准化解析,可以获取到网络协议(或互联网协议)类型、源IP(即IP A)、源端口、数据包内容以及业务请求访问记录等。然后,通过预设的字符串匹配规则以及正则内容特征规则对数据包内容进行内容检测,确定IP A对应的业务访问请求信息中的数据包内容是否存在恶意字符,以此确定IP A是否具备明显的攻击特征,并记为α
i。如果该IP A对应的业务访问请求信息中的数据包内容存在恶意字符,则为该IP A标记上恶意标签,即该IP A对应的攻击行为特征(即攻击行为分值)α
i=100,IP A具备明显的攻击特征;如果该IP A对应的业务访问请求信息中的数据包内容不存在恶意字符,则为该IP A标记上正常标签,即该IP A对应的攻击行为特征(即攻击行为分值)α
i=0,IP A不具备攻击特征。例如,以IP A和IP B为例,假 设IP A的请求路径为http://xxx.com/login?username=luca;IP B的请求路径为http://xxx.com/login?username=alert(1)。通过预设的字符串匹配规则以及正则内容特征规则对IP A对应的业务访问请求信息中的数据包内容以及IP B对应的业务访问请求信息中的数据包内容分别进行内容检测,确定IP A对应的业务访问请求信息中的数据包内容不存在恶意字符,则IP A对应的业务访问请求为正常业务访问请求,即α
i=0,IP A不具备攻击特征;确定IP B对应的业务访问请求信息中的数据包内容存在恶意字符(即alert(1)等,为跨站脚本攻击),则IP B对应的业务访问请求为恶意业务访问请求,即α
i=100,IP B具备明显的攻击特征。
步骤203,根据所述IP在所述设定窗口时段内各子时段的业务访问请求的次数,确定所述IP对应的攻击频率特征。
本发明实施例中,由于非法用户的攻击行为一般属于随机性行为,并不是每天固定持续性攻击,比如在某天对业务系统发送大量恶意业务请求包,便会在目的达成后停止攻击行为。也即是,非法用户的攻击行为混在业务系统的所有业务请求包中,所以恶意业务请求频率是一个小概率事件。因此,根据大量的用户历史业务访问请求统计,可以发现业务访问请求频率在周期时间内(比如设定窗口时段内)是符合正态分布的,也即是IP在设定窗口时段内的业务访问请求次数的分布规律符合正态分布。基于此,本发明中的技术方案通过构建出一个用于确定攻击频率特征的计算规则,以便对IP在设定窗口时段内(即周期时间内)各子时段的业务访问请求次数进行统计处理,从而可以准确地确定出IP对应的攻击频率特征。具体地,针对每个IP,统计该IP在设定窗口时段内各子时段的业务访问请求次数,并基于该IP在各子时段的业务访问请求次数,确定该IP对应的第一攻击频率。再基于该IP在各子时段的业务访问请求次数以及第一攻击频率,确定该IP对应的第二攻击频率。然后,根据第一攻击频率和第二攻击频率,就可以及时准确地确定该IP对应的攻击频率特征,也就能为后续直观清晰地反映IP的具体风险程度提供支持,当然也能够具体地反映出IP的风险行为。其中,第一攻击频率用于表征IP访问业务系统的访问行为集中趋势程度;第二攻击频率用于表征IP访问业务系统的访问行为离散程度。
进一步地,可以通过下述方式确定IP对应的第一攻击频率:
其中,mean
i用于表示某一IP对应的第一攻击频率;a
n用于表示第n天某一IP的总业务访问请求次数;W
d用于表示设定窗口时段,单位为天。
可以通过下述方式确定IP对应的第二攻击频率:
其中,var
i用于表示某一IP对应的第二攻击频率。需要说明的是,由于非法用户的攻击行为混在业务系统的所有业务请求包中,所以恶意业务请求频率是一个小概率事件,对于攻击频率次数落在(μ-3σ,μ+3σ)之外的业务访问请求流量,可疑程度较高,对应的IP也将被标记为高风险,基于此,本发明实施例定义出上述用于确定IP对应的第二攻击频率的计算公式。如此,如果IP每天的业务访问请求次数相对固定,var
i值越低,IP对应的风险程度越低,可信度也就越高。
或者,也可以通过下述方式确定IP对应的第一攻击频率:
T
i=a
0+a
1+...+a
n
其中,T
i用于表示某一IP对应的第一攻击频率;a
n用于表示第n天某一IP的总业务访问请求次数。
或者,也可以通过下述方式确定IP对应的第二攻击频率:
其中,M
i用于表示IP对应的第二攻击频率。
基于上述内容可知,可以通过下述方式确定IP对应的攻击频率特征:
其中,γ
i用于表示某一IP对应的攻击频率特征;mean
i用于表示某一IP对应的第一攻击频率;var
i用于表示某一IP对应的第二攻击频率;F
i用于表示运算中间结果值。
或者,也可以通过下述方式确定IP对应的攻击频率特征:
其中,γ
i用于表示某一IP对应的攻击频率特征;T
i用于表示某一IP对应的第一攻击频率;M
i用于表示某一IP对应的第二攻击频率;D
i用于表示运算中间结果值。
示例性地,以IP A和IP B为例,假设IP A和IP B在3天内的业务访问请求量如表1所示。
表1
| 天数/次数 | IP A | IP B |
| 第1天 | 100次 | 0次 |
| 第2天 | 200次 | 5000次 |
| 第3天 | 150次 | 20次 |
以第一种确定IP对应的攻击频率特征的计算方式为例进行描述,即,按照上述第一种确定IP对应的第一攻击频率的计算方式可以计算出IP A对应的第一攻击频率,即mean
A=(100+200+150)/3=150,同时可以计算出IP B对应的第一攻击频率,即mean
B=(0+5000+20)/3=1673.33。按照上述第一种确定IP对应的第二攻击频率的计算方式可以计算出IP A对应的第二攻击频率,即
同时可以计算出IP B对应的第二攻击频率,即
基于此可知,IP B对应的第二攻击频率值明显高于IP A对应的第二攻击频率值,IP B访问业务系统的访问行为更 加离散,IP B所对应的风险程度也会相对IP A较高。
在计算出IP A对应的第一频率、第二频率以及IP B对应的第一频率、第二频率后,可以通过按照上述第一种确定IP对应的攻击频率特征的计算公式计算出IP A对应的攻击频率特征(即攻击频率分数),即
同时可以计算出IP B对应的攻击频率特征(即攻击频率分数),即
步骤204,根据所述IP对应的地址属性信息和设备属性信息,确定所述IP对应的设备属性风险特征。
本发明实施例中,由于通过不同物理机设备的IP攻击业务系统所带来的风险性不同,因此,本发明中的技术方案通过引入IP对应的设备属性特征来结合攻击行为特征、攻击频率特征一起共同评估IP对应的具体风险程度。也即是,利用端口扫描工具,对通过端口访问业务系统的该IP进行反向追踪,确定出该IP对应的设备属性信息,并通过地理位置查询接口查询出该IP对应的地址属性信息。然后,根据该IP对应的地址属性信息的地址属性权重以及设备属性信息的设备属性权重,就可以及时准确地确定出该IP对应的设备属性风险特征。
其中,可以通过下述方式确定各地址属性信息对应的各地址属性权重和各设备属性信息对应的各设备属性权重:通过层次分析法,对各IP对应的各地址属性信息、各设备属性信息进行分析处理,确定出各地址属性信息对应的各地址属性权重和各设备属性信息对应的各设备属性权重,并将各地址属性信息对应的各地址属性权重和各设备属性信息对应的各设备属性权重进行存储。如此,通过层次分析法对确定IP的设备属性权重的各影响因素(比如地址属性信息和设备属性信息)进行分析,可以及时有效地确定出各影响因素的权重,以便为后续及时准确地得到IP对应的设备属性风险特征提供支持,也就能为后续直观清晰地反映IP的具体风险程度提供支持。
示例性地,针对每个IP,通过利用常见的端口、web扫描工具,对该IP进行反向发起网络扫描。同时,通过关联网络TCP(Transmission Control Protocol,传输控制协议)/IP协议栈Banner信息、操作系统版本、端口开放情况、地理位置以及Web应用层指纹数据等多维度模型,为该IP进行建立画像,并将建立好的IP设备属性画像进行存储。具体地,可以将上述记录到的Banner、端口号、操作系统版本以及HTTP关键字段等信息上传到云端分析引擎进行离线判定。针对PC、IDC、Router、IOT等设备有不同的聚类算法和判定模型,PC设备会根据IP历史存活度进行打分计算(例如标记同一个IP是否处于长期在线),而IDC设备会结合IP开放的端口协议以及物理机上实际运行的业务情况进行关联分析。Router\IOT设备区别于以上类型的设备,会根据不同设备厂商定制的专用的网络协议(MQTT(Message Queuing Telemetry Transport,消息队列遥测传输)\REST(Representational State Transfer,资源表现层状态转移)\XMPP(Extensible Messaging and Presence Protocol,可扩展通讯和表示协议)\AMQP(Advanced Message Queuing Protocol,高级消息队列协议) 等)、端口服务以及操作系统版本进行关联分析。IP设备画像分为PC、IDC以及IOT设备。通常处于海外地址且设备类型为IDC设备、IOT设备的IP,往往为被真实恶意控制的僵尸主机,所以通过IDC设备或IOT设备利用某一海外IP访问业务系统所带来的风险性相对更高。因此,通过引入AHP层次分析法(Analytic Hierarchy Process),针对不同设备类型进行计算各设备类型对确定IP对应的设备属性风险特征的影响权重,设定了如表2所示的四阶矩阵风险权重。通过设置两两因素对比值,对不同属性画像进行1-10分标度法,最终获取到如表3所示的每个设备属性所对应的权重占比值。
表2
| 设备属性画像 | PC设备属性 | IDC设备属性 | IOT设备属性 | 海外地址属性 |
| PC设备 | 1 | 1/5 | 1/9 | 1/9 |
| IDC设备 | 5 | 1 | 1/5 | 1/5 |
| IOT设备 | 9 | 5 | 1 | 1/3 |
| 海外地址 | 9 | 5 | 3 | 1 |
其中,以IDC设备属性相对PC设备属性为例,IDC设备属性相对PC设备属性对IP对应的设备属性风险特征的影响程度更大,因此在数值上两者打分为1/5。其它设备属性的矩阵数值可以按照IDC设备属性相对PC设备属性的方式进行打分,在此不再赘述。
表3
| 海外地址 | IOT设备 | PC设备 | IDC设备 | 画像总权重值 |
| 0.5314 | 0.314 | 0.0382 | 0.1164 | 1 |
其中,基于表3可以看出,IP对应的设备属性具备海外地址、IOT设备的特性时,所占的风险权重比值更大,则IP对应的风险程度也更高。
此外,本发明实施例通过下述方式确定IP对应的设备属性风险特征:
β
i=(W
0+W
1+...+W
n)*100
其中,β
i用于表示某一IP对应的设备属性风险特征,W
n用于表示每个设备属性所对应的权重占比值。
示例性地,以IP A和IP B为例,假设IP A的设备属性特征为国内地址、PC设备;假设IP B的设备属性特征为海外地址、IDC设备。按照上述确定某一IP对应的设备属性风险特征的计算方式可以计算出IP A对应的设备属性风险特征(即设备属性风险分数),即β
A=(0+0.0382)×100=3.82。同时,可以计算出IP B对应的设备属性风险特征(即设备属性风险分数),即β
B=(0.5314+0.1164)×100=64.78。其中,国内地址对应的权重占比值为0。
步骤205,基于所述IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许所述IP对应的业务访问请求。
本发明实施例中,通过层次分析法对各IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征进行分析处理,确定攻击行为特征的权重、设备属性风险特征的权重以及攻击频率特征的权重,比如通过AHP层次分析法,针对各不同特征(即攻击行为特征、设备属性风险特征和攻击频率特征)构建三个影响因素(即攻击行为特征、设备属性风险特征和攻击频率特征)对比矩阵,即该三个特征两两比较,形成一个三阶矩阵,再计算这个三阶矩阵的特征向量,并基于这个三阶矩阵的特征向量,确定出攻击行为特征的权重、设备属性风险特征的权重以及攻击频率特征的权重。或者,可以根据本领域技术人员的经 验值或者根据多次实验所得出的结果进行设置攻击行为特征的权重、设备属性风险特征的权重和攻击频率特征的权重。再根据IP对应的攻击行为特征、设备属性风险特征、攻击频率特征、攻击行为特征的权重、设备属性风险特征的权重和攻击频率特征的权重,可以更加全面且准确的评估出IP所属的风险行为等级,以此综合评估出IP所对应的具体风险程度,从而可以实现对各IP所对应的风险程度进行定量描述,同时也会将各IP所属的风险行为等级存储在数据库中。然后,根据IP所属的风险行为等级,就可以及时准确地确定是否允许IP对应的业务访问请求,以此可以确保业务系统的数据安全性。
其中,可以通过下述方式确定IP所属的风险行为等级:
S
i=α
i*w
0+β
i*w
1+γ
i*w
2
其中,S
i用于表示某一IP所属的风险行为等级;α
i用于表示某一IP对应的攻击行为特征;β
i用于表示某一IP对应的设备属性风险特征;γ
i用于表示某一IP对应的攻击频率特征;w
0用于表示攻击行为特征的权重;w
1用于表示设备属性风险特征的权重;w
2用于攻击频率特征的权重。需要说明的是,在确定各IP所属的风险行为等级时,各IP所采用的攻击行为特征的权重是相同的、各IP所采用的设备属性风险特征的权重是相同的、以及各IP所采用的攻击频率特征的权重是相同的。
示例性地,以IP A和IP B为例,假设攻击行为特征α
i的权重为0.5,设备属性风险特征β
i的权重为0.2,攻击频率特征γ
i的权重为0.3。并假设IP A不具备攻击特征,即α
i=0,IP B具备明显的攻击特征,即α
i=100;假设计算出IP A对应的设备属性风险特征β
A=3.82,IP B对应的设备属性风险特征β
B=64.78。以及假设计算出IP A对应的攻击频率特征γ
A=73.24;计算出IP B对应的攻击频率特征γ
B=95.04。因此,可以计算出IP A所属的风险行为等级(即IP A的信誉度值)S
A=0×0.5+3.82×0.2+73.24×0.3=22.74;计算出IP B所属的风险行为等级(即IP B的信誉度值)S
B=100×0.5+64.78×0.2+95.04×0.3=91.108。如此,通过根据各IP所属的风险行为等级即可确定出各IP对应的具体风险程度。也即是,某一IP所属的风险行为等级越高,该IP对应的具体风险程度也越大。同时,基于这个计算结果也能够看出,IP B具备海外地址、IOT设备的属性特征,对业务系统发起了大量且不规律的攻击行为,同时针对业务系统的业务访问请求也存在部分恶意字符,因此IP B所属的风险行为等级(即IP B的信誉度值)也远远高于IP A所属的风险行为等级(即IP A的信誉度值)。
其中,在确定各IP所属的风险行为等级时,可以设置风险行为等级范围,即,高风险行为等级、较高风险行为等级、中风险行为等级、较低风险行为等级以及低风险行为等级。以信誉度值满分100分为例,信誉度值80~100分为高风险行为等级,信誉度值60~80分为较高风险行为等级;信誉度值40~60分为中风险行为等级;信誉度值20~40分为较低风险行为等级;信誉度值0~20分为低风险行为等级。同时,根据不同的风险行为等级设置不同的业务访问安全防护规则。也即是说,在确定出各IP的信誉度值后,就可以确定出各IP所属的风险行为等级,并根据各IP所属的风险行为等级能够选择出不同的业务访问安全防护规则,以便针对各IP采取不同的安全防护策略。例如,以IP A为例,假设IP A触发高风险行为等级的安全防护规则,则业务系统会立即针对IP A的业务访问请求进行拦截并拒绝IP A的业务访问请求,当前也有可能对IP A进行封禁。或者,假设IP A触发低风险行为等级的安全防护规则,则业务系统会允许IP A的业务访问请求。
示例性地,继续以IP A和IP B为例,假设计算出IP A的信誉度值S
A=22.74,IP B 的信誉度值S
B=91.108,也就可以确定IP A属于较低风险行为等级,以及确定IP B属于高风险行为等级。基于此,可以确定IP A会触发较低风险行为等级的安全防护规则,则业务系统也会允许IP A的业务访问请求。然而,IP B会触发高风险行为等级的安全防护规则,则业务系统会立即针对IP B的业务访问请求进行拦截并拒绝IP B的业务访问请求,当前也有可能对IP B进行封禁。
此外,由于历史出现的各IP所属的风险等级随着时间的推移,对业务系统实际可能造成的风险程度会逐渐降低,也即是,时间越久远的攻击行为对当前的业务系统实际可能造成的风险程度会变小,因此通过按照设定时间间隔(比如10秒、30秒、1分钟、5分钟、30分钟、1天或5天等),对历史已存储的各IP所属的风险行为等级(即各IP的信誉度值)分别进行重新评定,也即是对历史已存储的各IP所属的风险行为等级分别进行更新,可以确保各IP所属的风险行为等级的实时有效性,也就可以使得各IP所属的风险行为等级有了更精确的时间有效期。
其中,可以通过下述方式定期动态更新各IP所属的风险行为等级:
其中,S
j用于表示更新后的某一IP所属的风险行为等级;λ用于表示更新比例常量,可以根据实际应用场景进行调整;Δd表示S
old与S
new的日期差;S
new用于表示某一IP当前所属的风险行为等级;S
old用于表示某一IP距离当前日期最近的日期对应的风险行为等级。
上述实施例表明,在检测到访问业务系统的任一业务访问请求的请求方的网络协议IP时,就会立即去获取该IP在设定窗口时段内访问所述业务系统的业务访问请求信息,并对该IP在设定窗口时段内的业务访问请求信息进行内容检测,确定IP对应的攻击行为特征。再通过根据IP对应的地址属性信息和设备属性信息,确定IP对应的设备属性风险特征。然后,基于IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许该IP对应的业务访问请求。如此,该方案从攻击行为特征、设备属性风险特征以及攻击频率特征三个特征维度进行综合评估IP,可以更加全面且准确地评估出IP所对应的具体风险程度,以此可以实现对各IP所对应的风险程度进行定量描述。同时,根据该风险程度就可以及时准确地确定是否允许该IP对应的业务访问请求,以此可以确保业务系统的数据安全性。此外,由于该方案可以评估出IP所对应的具体风险程度,因此可以基于各IP所对应的具体风险程度对各IP进行更精细粒度地划分,以此可以使得各IP能够更加直观清晰地进行展示,也就可以便于决策者及时准确地做出决策。而且,由于可以更加直观精确地展示出各IP所对应的具体风险程度,如此就可以避免现有技术简单粗暴的将某一临时IP进行封禁而导致其它正常访问者无法使用该临时IP进行正常,从而可以提升用户体验。
基于相同的技术构思,图3示例性的示出了本发明实施例提供的一种检测业务访问请求的装置,该装置可以执行检测业务访问请求的方法的流程。
如图3所示,该装置包括:
获取单元301,用于在检测到访问业务系统的任一业务访问请求的请求方的网络协议IP时,获取所述IP在设定窗口时段内访问所述业务系统的业务访问请求信息;
处理单元302,用于对所述IP在设定窗口时段内的业务访问请求信息进行内容检测,确定所述IP对应的攻击行为特征;根据所述IP在所述设定窗口时段内各子时段的业务访问请求的次数,确定所述IP对应的攻击频率特征;根据所述IP对应的地址属性信息和设 备属性信息,确定所述IP对应的设备属性风险特征;基于所述IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许所述IP对应的业务访问请求。
可选地,所述处理单元302具体用于:
通过预设的检测规则,检测所述IP在设定窗口时段内的业务访问请求信息中是否具有恶意字符;
若确定业务访问请求信息中具有恶意字符,则为所述IP标记对应的第一攻击行为特征;
若确定业务访问请求信息中不具有恶意字符,则为所述IP标记对应的第二攻击行为特征。
可选地,所述处理单元302具体用于:
利用端口扫描工具,对通过业务系统的端口访问所述业务系统的所述IP进行反向跟踪,确定出所述IP对应的设备属性信息,并查询出所述IP对应的地址属性信息;
根据所述地址属性信息对应的地址属性权重和所述设备属性信息对应的设备属性权重,确定所述IP对应的设备属性风险特征。
可选地,所述处理单元302具体用于:
通过层次分析法,对各IP对应的各地址属性信息、各设备属性信息进行分析处理,确定出所述各地址属性信息对应的各地址属性权重和所述各设备属性信息对应的各设备属性权重;
将所述各地址属性信息对应的各地址属性权重和所述各设备属性信息对应的各设备属性权重进行存储。
可选地,所述处理单元302具体用于:
基于IP在设定窗口时段内的业务访问请求次数的分布规律符合正态分布,构建出用于确定攻击频率特征的计算规则;
按照所述计算规则,对所述IP在各子时段的业务访问请求次数进行处理,确定出所述IP对应的攻击频率特征。
可选地,所述处理单元302具体用于:
基于所述IP在各子时段的业务访问请求次数,确定所述IP对应的第一攻击频率;所述第一攻击频率用于表征所述IP访问业务系统的访问行为集中趋势程度;
基于所述IP在各子时段的业务访问请求次数以及所述第一攻击频率,确定所述IP对应的第二攻击频率;所述第二攻击频率用于表征所述IP访问业务系统的访问行为离散程度;
根据所述第一攻击频率和所述第二攻击频率,确定所述IP对应的攻击频率特征。
可选地,所述处理单元302具体用于:
其中,var
i用于表示任一IP对应的第二攻击频率,mean
i用于表示该IP对应的第一攻击频率,a
n用于表示第n天该IP的总业务访问请求次数,W
d用于表示设定窗口时段。
可选地,所述处理单元302具体用于:
其中,γ
i用于表示任一IP对应的攻击频率特征,F
i用于表示运算中间结果值。
可选地,所述处理单元302具体用于:
根据所述IP对应的攻击行为特征、设备属性风险特征、攻击频率特征、所述攻击行为特征的权重、所述设备属性风险特征的权重和所述攻击频率特征的权重,确定所述IP所属的风险行为等级;所述攻击行为特征的权重、所述设备属性风险分特征的权重和所述攻击频率特征的权重是通过层次分析法确定的;
根据所述IP所属的风险行为等级,确定是否允许所述IP对应的业务访问请求。
可选地,所述处理单元302还用于:
在确定所述IP所属的风险行为等级之后,将各IP所属的风险行为等级存储在数据库中;
按照设定时间间隔,对所述数据库中各IP所属的风险行为等级进行周期性的更新。
基于相同的技术构思,本发明实施例还提供了一种计算设备,如图4所示,包括至少一个处理器401,以及与至少一个处理器连接的存储器402,本发明实施例中不限定处理器401与存储器402之间的具体连接介质,图4中处理器401和存储器402之间通过总线连接为例。总线可以分为地址总线、数据总线、控制总线等。
在本发明实施例中,存储器402存储有可被至少一个处理器401执行的指令,至少一个处理器401通过执行存储器402存储的指令,可以执行前述的检测业务访问请求的方法中所包括的步骤。
其中,处理器401是计算设备的控制中心,可以利用各种接口和线路连接计算设备的各个部分,通过运行或执行存储在存储器402内的指令以及调用存储在存储器402内的数据,从而实现数据处理。可选的,处理器401可包括一个或多个处理单元,处理器401可集成应用处理器和调制解调处理器,其中,应用处理器主要处理操作系统、用户界面和应用程序等,调制解调处理器主要处理下发指令。可以理解的是,上述调制解调处理器也可以不集成到处理器401中。在一些实施例中,处理器401和存储器402可以在同一芯片上实现,在一些实施例中,它们也可以在独立的芯片上分别实现。
处理器401可以是通用处理器,例如中央处理器(CPU)、数字信号处理器、专用集成电路(Application Specific Integrated Circuit,ASIC)、现场可编程门阵列或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件,可以实现或者执行本发明实施例中公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者任何常规的处理器等。结合检测业务访问请求的方法实施例所公开的方法的步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。
存储器402作为一种非易失性计算机可读存储介质,可用于存储非易失性软件程序、非易失性计算机可执行程序以及模块。存储器402可以包括至少一种类型的存储介质,例如可以包括闪存、硬盘、多媒体卡、卡型存储器、随机访问存储器(Random Access Memory,RAM)、静态随机访问存储器(Static Random Access Memory,SRAM)、可编程只读存储器(Programmable Read Only Memory,PROM)、只读存储器(Read Only Memory,ROM)、 带电可擦除可编程只读存储器(Electrically Erasable Programmable Read-Only Memory,EEPROM)、磁性存储器、磁盘、光盘等等。存储器402是能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。本发明实施例中的存储器402还可以是电路或者其它任意能够实现存储功能的装置,用于存储程序指令和/或数据。
基于相同的技术构思,本发明实施例还提供了一种计算机可读存储介质,其存储有可由计算设备执行的计算机程序,当所述程序在所述计算设备上运行时,使得所述计算设备执行上述检测业务访问请求的方法的步骤。
本领域内的技术人员应明白,本发明的实施例可提供为方法、系统、或计算机程序产品。因此,本发明可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本发明是参照根据本发明的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
尽管已描述了本发明的优选实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例作出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本发明范围的所有变更和修改。
显然,本领域的技术人员可以对本发明进行各种改动和变型而不脱离本发明的精神和范围。这样,倘若本发明的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本发明也意图包含这些改动和变型在内。
Claims (10)
- 一种检测业务访问请求的方法,其特征在于,包括:在检测到访问业务系统的任一业务访问请求的请求方的网络协议IP时,获取所述IP在设定窗口时段内访问所述业务系统的业务访问请求信息;对所述IP在设定窗口时段内的业务访问请求信息进行内容检测,确定所述IP对应的攻击行为特征;根据所述IP在所述设定窗口时段内各子时段的业务访问请求的次数,确定所述IP对应的攻击频率特征;根据所述IP对应的地址属性信息和设备属性信息,确定所述IP对应的设备属性风险特征;基于所述IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许所述IP对应的业务访问请求。
- 如权利要求1所述的方法,其特征在于,所述对所述IP在设定窗口时段内的业务访问请求信息进行内容检测,确定所述IP对应的攻击行为特征,包括:通过预设的检测规则,检测所述IP在设定窗口时段内的业务访问请求信息中是否具有恶意字符;若确定业务访问请求信息中具有恶意字符,则为所述IP标记对应的第一攻击行为特征;若确定业务访问请求信息中不具有恶意字符,则为所述IP标记对应的第二攻击行为特征。
- 如权利要求1所述的方法,其特征在于,所述根据所述IP对应的地址属性信息和设备属性信息,确定所述IP对应的设备属性风险特征,包括:利用端口扫描工具,对通过业务系统的端口访问所述业务系统的所述IP进行反向跟踪,确定出所述IP对应的设备属性信息,并查询出所述IP对应的地址属性信息;根据所述地址属性信息对应的地址属性权重和所述设备属性信息对应的设备属性权重,确定所述IP对应的设备属性风险特征。
- 如权利要求3所述的方法,其特征在于,通过下述方式确定各地址属性信息对应的各地址属性权重和各设备属性信息对应的各设备属性权重:通过层次分析法,对各IP对应的各地址属性信息、各设备属性信息进行分析处理,确定出所述各地址属性信息对应的各地址属性权重和所述各设备属性信息对应的各设备属性权重;将所述各地址属性信息对应的各地址属性权重和所述各设备属性信息对应的各设备属性权重进行存储。
- 如权利要求1所述的方法,其特征在于,所述根据所述IP在所述设定窗口时段内各子时段的业务访问请求的次数,确定所述IP对应的攻击频率特征,包括:基于所述IP在各子时段的业务访问请求次数,确定所述IP对应的第一攻击频率;所述第一攻击频率用于表征所述IP访问业务系统的访问行为集中趋势程度;基于所述IP在各子时段的业务访问请求次数以及所述第一攻击频率,确定所述IP对应的第二攻击频率;所述第二攻击频率用于表征所述IP访问业务系统的访问行为离散程度;根据所述第一攻击频率和所述第二攻击频率,确定所述IP对应的攻击频率特征。
- 如权利要求1至7任一项所述的方法,其特征在于,基于所述IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许所述IP对应的业务访问请求,包括:根据所述IP对应的攻击行为特征、设备属性风险特征、攻击频率特征、所述攻击行为特征的权重、所述设备属性风险特征的权重和所述攻击频率特征的权重,确定所述IP所属的风险行为等级;所述攻击行为特征的权重、所述设备属性风险分特征的权重和所述攻击频率特征的权重是通过层次分析法确定的;根据所述IP所属的风险行为等级,确定是否允许所述IP对应的业务访问请求。
- 如权利要求8所述的方法,其特征在于,在确定所述IP所属的风险行为等级之后,还包括:将各IP所属的风险行为等级存储在数据库中;按照设定时间间隔,对所述数据库中各IP所属的风险行为等级进行周期性的更新。
- 一种检测业务访问请求的装置,其特征在于,包括:获取单元,用于在检测到访问业务系统的任一业务访问请求的请求方的网络协议IP时,获取所述IP在设定窗口时段内访问所述业务系统的业务访问请求信息;处理单元,用于对所述IP在设定窗口时段内的业务访问请求信息进行内容检测,确定所述IP对应的攻击行为特征;根据所述IP在所述设定窗口时段内各子时段的业务访问请求的次数,确定所述IP对应的攻击频率特征;根据所述IP对应的地址属性信息和设备属性信息,确定所述IP对应的设备属性风险特征;基于所述IP对应的攻击行为特征、设备属性风险特征以及攻击频率特征,确定是否允许所述IP对应的业务访问请求。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202110730544.3A CN113347205B (zh) | 2021-06-30 | 2021-06-30 | 一种检测业务访问请求的方法及装置 |
| CN202110730544.3 | 2021-06-30 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023273152A1 true WO2023273152A1 (zh) | 2023-01-05 |
Family
ID=77481562
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2021/134623 Ceased WO2023273152A1 (zh) | 2021-06-30 | 2021-11-30 | 一种检测业务访问请求的方法及装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN113347205B (zh) |
| WO (1) | WO2023273152A1 (zh) |
Cited By (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116192521A (zh) * | 2023-03-03 | 2023-05-30 | 北京赛博易安科技有限公司 | 一种基于身份映射的威胁源画像分析方法及系统 |
| CN116743444A (zh) * | 2023-05-31 | 2023-09-12 | 国家电网有限公司信息通信分公司 | 一种秒拨攻击事件识别方法 |
| CN117294530A (zh) * | 2023-11-24 | 2023-12-26 | 深圳市中燃科技有限公司 | 工业互联网标识解析二级节点数据安全管理方法及系统 |
| US20240333753A1 (en) * | 2020-04-08 | 2024-10-03 | Wells Fargo Bank, N.A. | Security model utilizing multi-channel data with vulnerability remediation circuitry |
| CN119182598A (zh) * | 2024-09-23 | 2024-12-24 | 济南浪潮数据技术有限公司 | 服务端安全访问方法、装置、电子设备及可读存储介质 |
| CN119232491A (zh) * | 2024-11-29 | 2024-12-31 | 浙江达古科技有限公司 | 一种基于神经网络模型的信息安全管理系统 |
| CN119363490A (zh) * | 2024-12-26 | 2025-01-24 | 北京长亭科技有限公司 | 一种分布式网络用户访问频率的控制方法及装置 |
| CN119484162A (zh) * | 2025-01-14 | 2025-02-18 | 江苏凤凰信息科技有限公司 | 基于大语言模型的网络安全日志分析方法 |
| CN119728231A (zh) * | 2024-12-19 | 2025-03-28 | 中国工商银行股份有限公司 | 跨站脚本xss攻击处理方法、装置、设备、介质及程序 |
| CN120896790A (zh) * | 2025-09-30 | 2025-11-04 | 智诚科技有限公司 | 一种网络安全策略优化方法及系统 |
Families Citing this family (15)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113347205B (zh) * | 2021-06-30 | 2022-10-28 | 深圳前海微众银行股份有限公司 | 一种检测业务访问请求的方法及装置 |
| CN113992356A (zh) * | 2021-09-28 | 2022-01-28 | 青岛海尔科技有限公司 | Ip攻击的检测方法、装置和电子设备 |
| CN113992358B (zh) * | 2021-09-29 | 2023-07-07 | 杭州迪普科技股份有限公司 | 网络安全策略的分配方法及装置 |
| CN114050922B (zh) * | 2021-11-05 | 2023-07-21 | 国网江苏省电力有限公司常州供电分公司 | 一种基于时空ip地址画像的网络流异常检测方法 |
| CN113965413A (zh) * | 2021-11-23 | 2022-01-21 | 湖南快乐阳光互动娱乐传媒有限公司 | 风险识别方法及装置、存储介质及电子设备 |
| CN113973087B (zh) * | 2021-11-24 | 2024-01-05 | 中国银联股份有限公司 | 一种网页访问限流方法、装置及计算机可读存储介质 |
| CN114422168A (zh) * | 2021-12-07 | 2022-04-29 | 全球能源互联网研究院有限公司 | 一种恶意机器流量识别方法及系统 |
| CN114157499B (zh) * | 2021-12-07 | 2025-01-17 | 中信银行股份有限公司 | 一种基于ip价值评价的弹性安全防护方法及系统 |
| CN114221799B (zh) * | 2021-12-10 | 2024-03-22 | 中国人民银行数字货币研究所 | 一种通信监控方法、装置和系统 |
| CN114363023A (zh) * | 2021-12-23 | 2022-04-15 | 国家电网有限公司 | 一种Web安全防护系统实施及策略调优方法、系统 |
| CN114760106B (zh) * | 2022-03-22 | 2024-07-09 | 恒安嘉新(北京)科技股份公司 | 网络攻击的确定方法、系统、电子设备及存储介质 |
| CN114615072B (zh) * | 2022-03-23 | 2023-01-20 | 国网山东省电力公司临清市供电公司 | 基于请求频率的安全态势感知方法、设备与系统 |
| CN114900330B (zh) * | 2022-04-07 | 2024-08-16 | 京东科技信息技术有限公司 | 一种页面防护的方法和装置 |
| CN115811415A (zh) * | 2022-09-28 | 2023-03-17 | 华能(浙江)能源开发有限公司玉环分公司 | 一种电厂物联安全接入方法及物联接入网关 |
| CN119135374A (zh) * | 2024-08-08 | 2024-12-13 | 中国移动通信集团设计院有限公司 | 接口访问控制方法、装置、设备、存储介质和程序产品 |
Citations (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7735116B1 (en) * | 2006-03-24 | 2010-06-08 | Symantec Corporation | System and method for unified threat management with a relational rules methodology |
| CN104113519A (zh) * | 2013-04-16 | 2014-10-22 | 阿里巴巴集团控股有限公司 | 网络攻击检测方法及其装置 |
| CN107666473A (zh) * | 2016-07-29 | 2018-02-06 | 深圳市信锐网科技术有限公司 | 一种攻击检测的方法及控制器 |
| CN109831459A (zh) * | 2019-03-22 | 2019-05-31 | 百度在线网络技术(北京)有限公司 | 安全访问的方法、装置、存储介质和终端设备 |
| CN112434304A (zh) * | 2020-12-02 | 2021-03-02 | 网宿科技股份有限公司 | 防御网络攻击的方法、服务器及计算机可读存储介质 |
| CN113014598A (zh) * | 2021-03-20 | 2021-06-22 | 北京长亭未来科技有限公司 | 对机器人恶意攻击的防护方法、防火墙、电子设备和存储介质 |
| CN113347205A (zh) * | 2021-06-30 | 2021-09-03 | 深圳前海微众银行股份有限公司 | 一种检测业务访问请求的方法及装置 |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102291411B (zh) * | 2011-08-18 | 2013-11-06 | 网宿科技股份有限公司 | 针对dns服务的防ddos攻击方法和系统 |
| US9674217B2 (en) * | 2013-05-03 | 2017-06-06 | John Wong | Method and system for mitigation of distributed denial of service (DDOS) attacks |
| CN104967629B (zh) * | 2015-07-16 | 2018-11-27 | 网宿科技股份有限公司 | 网络攻击检测方法及装置 |
| CN107465686A (zh) * | 2017-08-23 | 2017-12-12 | 杭州安恒信息技术有限公司 | 基于网络异质大数据的ip信誉度计算方法及装置 |
| CN112261046A (zh) * | 2020-10-22 | 2021-01-22 | 胡付博 | 一种基于机器学习的工控蜜罐识别方法 |
| CN112615863A (zh) * | 2020-12-18 | 2021-04-06 | 成都知道创宇信息技术有限公司 | 反制攻击主机的方法、装置、服务器及存储介质 |
| CN114050922B (zh) * | 2021-11-05 | 2023-07-21 | 国网江苏省电力有限公司常州供电分公司 | 一种基于时空ip地址画像的网络流异常检测方法 |
-
2021
- 2021-06-30 CN CN202110730544.3A patent/CN113347205B/zh active Active
- 2021-11-30 WO PCT/CN2021/134623 patent/WO2023273152A1/zh not_active Ceased
Patent Citations (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7735116B1 (en) * | 2006-03-24 | 2010-06-08 | Symantec Corporation | System and method for unified threat management with a relational rules methodology |
| CN104113519A (zh) * | 2013-04-16 | 2014-10-22 | 阿里巴巴集团控股有限公司 | 网络攻击检测方法及其装置 |
| CN107666473A (zh) * | 2016-07-29 | 2018-02-06 | 深圳市信锐网科技术有限公司 | 一种攻击检测的方法及控制器 |
| CN109831459A (zh) * | 2019-03-22 | 2019-05-31 | 百度在线网络技术(北京)有限公司 | 安全访问的方法、装置、存储介质和终端设备 |
| CN112434304A (zh) * | 2020-12-02 | 2021-03-02 | 网宿科技股份有限公司 | 防御网络攻击的方法、服务器及计算机可读存储介质 |
| CN113014598A (zh) * | 2021-03-20 | 2021-06-22 | 北京长亭未来科技有限公司 | 对机器人恶意攻击的防护方法、防火墙、电子设备和存储介质 |
| CN113347205A (zh) * | 2021-06-30 | 2021-09-03 | 深圳前海微众银行股份有限公司 | 一种检测业务访问请求的方法及装置 |
Cited By (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20240333753A1 (en) * | 2020-04-08 | 2024-10-03 | Wells Fargo Bank, N.A. | Security model utilizing multi-channel data with vulnerability remediation circuitry |
| US12452290B2 (en) * | 2020-04-08 | 2025-10-21 | Wells Fargo Bank, N.A. | Security model utilizing multi-channel data with vulnerability remediation circuitry |
| CN116192521A (zh) * | 2023-03-03 | 2023-05-30 | 北京赛博易安科技有限公司 | 一种基于身份映射的威胁源画像分析方法及系统 |
| CN116743444A (zh) * | 2023-05-31 | 2023-09-12 | 国家电网有限公司信息通信分公司 | 一种秒拨攻击事件识别方法 |
| CN117294530A (zh) * | 2023-11-24 | 2023-12-26 | 深圳市中燃科技有限公司 | 工业互联网标识解析二级节点数据安全管理方法及系统 |
| CN117294530B (zh) * | 2023-11-24 | 2024-05-14 | 深圳市中燃科技有限公司 | 工业互联网标识解析二级节点数据安全管理方法及系统 |
| CN119182598A (zh) * | 2024-09-23 | 2024-12-24 | 济南浪潮数据技术有限公司 | 服务端安全访问方法、装置、电子设备及可读存储介质 |
| CN119232491A (zh) * | 2024-11-29 | 2024-12-31 | 浙江达古科技有限公司 | 一种基于神经网络模型的信息安全管理系统 |
| CN119728231A (zh) * | 2024-12-19 | 2025-03-28 | 中国工商银行股份有限公司 | 跨站脚本xss攻击处理方法、装置、设备、介质及程序 |
| CN119363490A (zh) * | 2024-12-26 | 2025-01-24 | 北京长亭科技有限公司 | 一种分布式网络用户访问频率的控制方法及装置 |
| CN119484162A (zh) * | 2025-01-14 | 2025-02-18 | 江苏凤凰信息科技有限公司 | 基于大语言模型的网络安全日志分析方法 |
| CN120896790A (zh) * | 2025-09-30 | 2025-11-04 | 智诚科技有限公司 | 一种网络安全策略优化方法及系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN113347205B (zh) | 2022-10-28 |
| CN113347205A (zh) | 2021-09-03 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN113347205B (zh) | 一种检测业务访问请求的方法及装置 | |
| US12231458B2 (en) | Cybersecurity risk assessment on an industry basis | |
| US12058135B2 (en) | System and method for unauthorized activity detection | |
| US11948115B2 (en) | Systems and methods for monitoring information security effectiveness | |
| US12563061B2 (en) | Detection of anomalies associated with fraudulent access to a service platform | |
| US10681012B2 (en) | Methods and systems for deep learning based API traffic security | |
| AU2017221858B2 (en) | Graph database analysis for network anomaly detection systems | |
| US10574681B2 (en) | Detection of known and unknown malicious domains | |
| US9503469B2 (en) | Anomaly detection system for enterprise network security | |
| US10375026B2 (en) | Web transaction status tracking | |
| US8205255B2 (en) | Anti-content spoofing (ACS) | |
| US8356001B2 (en) | Systems and methods for application-level security | |
| US20180033009A1 (en) | Method and system for facilitating the identification and prevention of potentially fraudulent activity in a financial system | |
| US20180033089A1 (en) | Method and system for identifying and addressing potential account takeover activity in a financial system | |
| US9338187B1 (en) | Modeling user working time using authentication events within an enterprise network | |
| US20120072982A1 (en) | Detecting potential fraudulent online user activity | |
| US10419449B1 (en) | Aggregating network sessions into meta-sessions for ranking and classification | |
| US20180083999A1 (en) | Self-published security risk management | |
| US12395512B2 (en) | Detecting data exfiltration and compromised user accounts in a computing network | |
| US20250039209A1 (en) | Detecting data exfiltration and compromised user accounts in a computing network | |
| US12488144B2 (en) | System for providing personal-information-sharing platform service based on right to data portability | |
| US10192057B2 (en) | Misuseability analysis for it infrastructure | |
| US20250337762A1 (en) | Anomaly detection in network traffic data |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21948078 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 16.04.2024) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21948078 Country of ref document: EP Kind code of ref document: A1 |












